Registro modifiche

Novità

Un registro continuo di nuovi strumenti, nuovi articoli Learn e modifiche significative a questo sito. Oggi sono disponibili 152 strumenti.

Looking for what comes next instead? The roadmap tracks what is planned and queued; this page records what has already shipped.

    • Nuovo strumento

      New tool and article: network operating systems compared

      Fourteen network operating systems - IOS, IOS XE, IOS XR, NX-OS, Junos, Junos Evolved, EOS, TMOS, F5OS, EXOS, VOSS, FortiOS, PAN-OS and Gaia - with lineage, what each runs on, how components share state, where the planes divide and what an upgrade costs. The article behind it organises all of them around one question: what happens when part of the software fails. Every entry lists weaknesses as well as strengths, and a golden vector enforces that.

      Network operating system comparer

    • Nuovo strumento

      New tool: FortiOS CLI config explainer

      Paste a FortiOS config block and get the structure as a tree with every verb explained. It flags the trap that costs the most - set on a multi-value field replaces the whole list, so setting one source address on a policy that had four silently removes three, successfully and with nothing in the output mentioning it. It also says that edit creates what it cannot find, that end is the only line that commits, and reports unclosed blocks.

      FortiOS CLI config explainer

    • Nuovo strumento

      New tool: F5OS tenant config explainer

      Paste an f5-tenants block and get it read back: the configured, provisioned and deployed states and what each means, the image and its platform, blades and VLANs. It checks the memory allocation against F5's published minimum of (3.5 x 1024 x vCPU) + 512, warns when a vCPU count appears without a memory value, and states the rule people get wrong - changing vCPU or memory on a deployed tenant means moving it back to provisioned first.

      F5OS tenant config explainer

    • Nuovo strumento

      New tool: Extreme Universal switch OS-name mapper

      ExtremeXOS is Switch Engine and VOSS is Fabric Engine, but only on Universal hardware - and the image files and boot menus still use the old names. Give a model series or an OS name and see which applies, the version the rename landed at, and the caveats: 7520 stacking works under Switch Engine and not Fabric Engine, and a 5420 or 5520 upgrade changes the SNMP SysObjectID. It states on every lookup that changing persona deletes the configuration.

      Universal switch OS-name mapper

    • Nuovo strumento

      New tool and article: terminal, shell, TTY and console

      Four words used interchangeably by almost everyone, including the documentation. Paste what tty printed and see which layer you are looking at, what holds the other end, and what that implies. The article behind it explains why Ctrl+C kills your command and not your shell - the line discipline sends SIGINT to the foreground process group, and the shell was never the target.

      Terminal, shell, TTY and console explainer

    • Nuovo strumento

      New tool: Netskope steering-method explainer

      Describe the situation and see which steering method fits - client, IPsec, GRE, explicit proxy or proxy chaining - with what each one costs, listed whether or not it was chosen. It warns about the interaction that surprises people: the client detects other steering methods and by default disables itself when it finds a tunnel, so running both is not automatically belt and braces. It also states the hard limit - without the certificate bundle on the endpoint there is no TLS inspection and no SAML authentication, and policy runs on metadata.

      Netskope steering-method explainer

    • Nuovo strumento

      New tool: FortiGate policy match-order explainer

      Paste an ordered policy list and see which one wins for a given packet, with the first field that ruled each other policy out. It also names the policies that can never be reached because something broader sits above them, and applies the virtual-IP rules that ordering alone does not solve. It corrects one thing directly: the policy ID is an identifier, not a position - policy 3 can sit below policy 47.

      FortiGate policy match-order explainer

    • Nuovo strumento

      New tool: F5 Ethernet trailer decoder

      Paste the trailer a BIG-IP appends to packets captured with the tcpdump noise flags and get each field explained: direction, slot and TMM, the virtual server, flow and peer identifiers, and the device's own RST cause. It detects a TLS provider section and decodes none of it - from v15 that section carries session secrets, which means a capture taken at high noise can contain the keys to its own TLS sessions. Local and offline.

      F5 Ethernet trailer decoder

    • Nuovo strumento

      New tool: Fabric Connect / SPB explainer

      Shortest Path Bridging is Extreme's signature technology and one of the least-tooled subjects in networking. Give an I-SID, a nickname or a role and the tool sorts the vocabulary: which backbone VLAN carries the service and why, what an L2VSN and an L3VSN bind to, and the fact that reorients people - a B-VLAN is not a VLAN, it does not flood, and it forwards only on B-MAC tables that IS-IS provisioned from shortest-path trees. Deterministic and offline.

      Fabric Connect / SPB explainer

    • Nuovo strumento

      New tool: SSE / SASE single-pass architecture explainer

      Describe a request and see the single pass: which SSE services engage, in what order, which are pillars and which are cross-cutting, and what a chain of separate appliances would have done instead. It exists to make one point precisely - DLP and threat protection are not pillars, they run inside the same pass on whatever the pillars decrypted, which is why one data profile covers web, SaaS and private applications alike. Deterministic and offline.

      SSE / SASE single-pass architecture explainer

    • Nuovo strumento

      New tool: iControl REST stats decoder

      Paste a BIG-IP stats response and get one line per statistic. It unwraps the entries, nestedStats, value and description envelopes, reduces the URL keys to the objects they name, and combines 64-bit counters that F5 splits into high and low halves - which is the part hand-written flatteners usually get wrong. It also states plainly that the numbers are totals rather than rates. Pure local transform.

      iControl REST stats decoder

    • Nuovo strumento

      New tool: FortiOS debug flow builder

      Assembles the ordered diagnose debug flow sequence for tracing a session on a FortiGate: the clean-state reset, the filter, function-name and optional iprope display, the packet-count trace and the enable, followed by the cleanup. It emits the filter-first order and says plainly that Fortinet's own guide shows enable first, because both work and the difference matters on a busy firewall. Local and offline.

      FortiOS debug flow builder

    • Nuovo strumento

      New tool: iControl REST path explainer

      Paste an iControl REST URL and get it decoded: the TMOS module, the collection, the tilde-encoded partition and folder path together with its tmsh equivalent, sub-collections such as pool members, and the query options including $select, $filter and expandSubcollections. It pairs with the F5OS RESTCONF path explainer, which decodes the platform layer underneath. Local and offline.

      iControl REST path explainer

    • Nuovo strumento

      New tool: F5OS RESTCONF path explainer

      Paste an F5OS RESTCONF path and get it decoded segment by segment: the YANG module prefix, the container hierarchy, list keys such as tenant=tenant1, and the module:node prefixing convention. It also explains the port 8888 /restconf versus port 443 /api duality introduced in F5OS 1.8. Local and offline; an unrecognised module is reported as unrecognised rather than described from a guess.

      F5OS RESTCONF path explainer

    • Contenuto

      Working with a vendor and working for one are different claims

      The industry timeline carried a single pill reading worked inside, applied to every company with a career chapter. That was inferred rather than declared, and it was wrong for most of them. Having a chapter in the career record means a company is part of the story; it does not mean it was an employer. Sixteen companies carried the pill. Five were actual employment. Six were vendors worked with directly from a partner, reseller or distributor position, which is a real relationship and a different one, and those now say so. Five should carry no working claim at all, and now carry none. The wording for the middle group is not new: worked with directly is the phrase the career pages have always used, so the card now agrees with the page it links to. Underneath, the distinction is data rather than inference. Two new relationship values were added alongside the existing partner and instructor ones, and the pill reads what is declared instead of guessing from whether a chapter exists. Anyone adding a company in future has to state which relationship applies, which is the point. The authorised instructor pill was checked at the same time and was already correct on exactly four vendors, unchanged.

    • Contenuto

      Four years that were not a gap, and two companies that were not one company

      The career summary jumped from 2010 to 2015 with nothing between, which read as absence rather than as what it was. Those four years were implementation work: deploying and integrating security and network platforms for end customers, usually under contracts held by resellers and occasionally direct. The kit is now named, because it is the part a reader can actually use - the Juniper firewall and switching lines, the remote access product that changed names twice before becoming Pulse Secure, Cisco's firewall line, next-generation firewalls from Palo Alto Networks, and Extreme's Summit and BlackDiamond switches. The entry for the following period has been extended too: the main focus in those years was one vendor, but the secondary work covered five others and saying so is more accurate than implying singular attention. Separately, two companies that had shared one entry now have their own. They belonged together thematically, since both spent two decades keeping the application delivery leaders honest, one from above on throughput and one from below on price. But a shared theme is not a shared history: different founders, different countries, different decades, different endings. Each now has its own page and each points at the other, which is what the relationship actually is. The old address redirects rather than breaking.

    • Funzionalità

      Two keys named after rooms they did not open

      The G and R shortcuts were introduced as the green room and the red room, and they did not go to either. They painted a full-screen green or red panel over whatever you were reading - a work light and a night-vision screen, dismissed by any key. Useful in their way, and named after two rooms that already exist on this site: the green room is the index of tools whose input is not deterministic text, and the red room is the index of tools that reach out to the real internet. Both have their own pages. Neither was reachable by the key named after it. The person who reported this wrote both the shortcuts and the rooms, and still expected the keys to navigate, which is about as clear a signal as a naming collision can send: if the author cannot hold the distinction, nobody can. The overlays are gone rather than renamed. G now opens the green room index and R opens the red room index, which is what both keys have appeared to promise since the day they shipped. The settings page describes them that way too. Anything that only existed to support the old behaviour - the dismissal handler, the hint text, the stylesheet rules - has been removed rather than left orphaned.

    • Infrastruttura

      A reader came for the company, not the method

      A reader reported two problems on one page, and both turned out to be site-wide. The first was mechanical: the company pages print their paragraphs as plain text, with no markdown parser, so emphasis written into those strings appeared on live pages as literal asterisks. Fifty-six of a hundred and sixty-two entries were affected, for days. The same defect had been found and fixed in the glossary a day earlier, and the question of whether any other field had it was never asked, which is the more useful lesson of the two. The second was worse because it was not mechanical. Twenty entries contained sentences about how the entry had been written rather than about the company: that the entry was short because the evidence was short, that an entry should be as long as its evidence, that the site does not manufacture what it cannot source. That is working-note reasoning, the sort that belongs in a commit message, published on a page somebody reached by searching for a company. All of it is gone. Where the underlying point was worth keeping it has been rewritten to speak about the subject instead of about the writing, and where it was purely procedural it has been deleted outright. There is a new build check covering both, and it deliberately exempts citation notes, because a source note saying a figure is disputed is doing its job. Sourcing talk belongs with the sources. It does not belong in the prose.

    • Contenuto

      The profitable event did not out-compete the community event in any market

      Two new entries on Brazilian security conferences, and a connection neither of the two existing ones recorded. The corporate flagship and the travelling hacker festival are run by the same company and were founded by the same person. They were deliberate opposites: one expo-heavy and fixed in the largest city, the other a caravan taking hacker culture to the state capitals, and one organisation ran both ends of the spectrum. Then in 2024 the festival did not happen. The assessment from people close to the scene was not that it failed, but that the corporate event had grown so large it consumed the organisation's capacity to run the other one. That is a specific and instructive thing to watch: the profitable event did not out-compete the community event in any market, it out-competed it for the attention of the people who ran both. The consequence was not nothing, because local community conferences multiplied into the space the regional editions vacated, so the calendar now has more small events outside the capital than when a large organiser was serving those cities directly. Whether that is better depends on what you value, and the honest answer is that it is different. The two new entries are a technical conference in another state and an executive one, and together they make a point the calendar supports better than most: technical conferences transmit skill, executive ones transmit priorities, and neither substitutes for the other. An engineer who attends only the first is repeatedly surprised by decisions, and an executive who attends only the second is repeatedly surprised by reality.

    • Infrastruttura

      The convention was documented in the source and simply not read

      A glossary entry has three body fields: a one-line definition, a short context, and an optional long section. A comment in the page that renders them explains why the middle one is kept short: the same string appears inside a hover tooltip roughly a fifth of a screen wide, on tool documentation and articles across the entire site, so a long one turns every mention of that term into a scroll trap. The long field exists for exactly the content that does not fit. Over one working session, twenty-three entries were written with the long content in the short field, some of them approaching five thousand characters against a site median of two hundred and thirty-eight. Five hundred and seventy entries were already using the correct field. The convention was established, documented where anybody adding an entry would see it, and not read. The same entries also used markdown emphasis, which that field does not parse, so the asterisks were rendering literally on the page and had been doing so unnoticed until a check compared what was in the source against what was actually on the screen. All twenty-three are now split properly in both languages, with short contexts written rather than truncated, because a truncated paragraph is a worse tooltip than a short one deliberately composed. There is a new build check covering both failures, since they share a cause, which is writing content without looking at how it renders. Its threshold sits just above the longest content that existed before it, rather than below, because a check that fails on work which was correct before the check existed teaches people to switch checks off.

    • Contenuto

      Probably the most-executed compression algorithm in history, and almost nobody can name it

      An entry covering three names for closely related things, together rather than separately, because separating them is what confuses people. One is an algorithm, one is a file format wrapping it, and one is the library that almost everything actually calls. The algorithm is two old ideas stacked: replace anything you have already seen with a short reference back to where you saw it, then give the common symbols short codes and the rare ones long codes. Neither half was new when it was specified, and the combination is not so much clever as extremely well balanced, fast enough to run everywhere and good enough that improving on it rarely justifies the change. It is inside every archive of the dominant format, every image of the dominant lossless format, every object in the dominant version control system, and most compressed web traffic. The reason the file format exists at all is a patent, and that is the part worth knowing: the Unix tool it replaced used an algorithm covered by patents, the same ones that made a popular image format legally uncomfortable and eventually pushed the web toward its replacement. Two people wrote a free alternative specifically to infringe nothing, and it outlived the patents, the tool it replaced, and the format the patents damaged. A patent intended to capture a market instead motivated the free thing that replaced it, which is the same shape as the lawsuit that produced the dominant archive format, in the same decade, in the same corner of computing. One security consequence is included because it surprises people who understand both halves separately: compression leaks information about what it compressed, so an attacker who can inject text into something compressed and then encrypted can learn whether their guess appears elsewhere by watching the length change. Encryption hides content, not size, and compressing before encrypting turns size into a channel.

    • Contenuto

      The problem they existed to solve stopped being a problem, which is a more complete ending than losing

      The archive entry was missing its own prehistory, and a reader who lived through it pointed that out. The formats people use now are the survivors; the era before them is worth recovering because one of its requirements has vanished so completely that the software built around it went with it. In the bulletin-board years the competition was fierce and the names are half-forgotten. Compression ratios were argued over the way frame rates are now, and the differences were real, because a file taking nine minutes to download instead of eleven at 2400 baud was a meaningful improvement. But the feature that decided which archiver you actually used was multi-volume archiving: splitting one archive across several floppy disks, each of which had to be individually reliable, in a period when disks failed constantly. One of those tools was very good at it, which is why so many people who used it remember it fondly without quite being able to say what it did better. It did the thing that made a twenty-megabyte file movable at all when nothing you owned could hold twenty megabytes. That requirement disappeared entirely, first to writable optical discs and then to networks, and the formats optimised for it disappeared with it. They were not defeated on compression or on licensing. The problem they existed to solve stopped being a problem, which is a more complete kind of ending than losing, and it is worth recognising when it is happening to something you currently depend on.

    • Contenuto

      Archiving and compressing are two different jobs, and one tradition keeps them separate

      A long explainer on archive formats, plus two pieces of lore. The explainer starts where most people never do: archiving and compressing are different jobs. The Unix tool concatenates many files into one and compresses nothing; the compression tool squeezes a single stream and knows nothing about files or directories. Put them together and you get the two-step that confuses everyone arriving from the other tradition, and that is why you cannot pull one file out of a compressed tarball without decompressing everything before it, while a zip pulls one out of a thousand instantly. Neither design is wrong. They solved different problems, and the difference still shows up every time somebody waits four minutes to extract one configuration file. The entry also covers the solid-archive trade in the stronger modern format, why only one vendor can create archives in the proprietary one, why a disc image is not compression at all, and the utilities from the free one written substantially by a single person to the commercial ones. Two security notes are included because any honest description needs them: a small file that expands to something enormous is designed to exhaust whatever scans it, and extracting a file whose stored name contains a parent-directory reference has produced a long line of vulnerabilities. If you write code that extracts archives from other people, treat the filenames inside as hostile input, because they are. The first piece of lore is the trial that never expires, which turns out to be a business model rather than an oversight: a reminder that never escalates targets enforcement precisely at organisations, who cannot run unlicensed software that displays a purchase prompt during an audit, and forgives everybody else. The second is the 1988 lawsuit that was meant to protect a format and instead ended it, because its target responded by designing a replacement and publishing the specification for anybody to implement. A format's value comes from ubiquity, ubiquity comes from anybody being able to implement it, and suing implementers guarantees a competitor becomes ubiquitous instead.

    • Contenuto

      The traffic cone is not a metaphor

      A long glossary entry on the media player that plays what nothing else will, prompted by a detail in yesterday's entry on an observability company: one of its founders co-authored it. The reason it plays everything is an architectural decision rather than a feature list. Most players ask the operating system to decode a file, which means they play whatever codecs the machine happens to have and fail on everything else, opaquely, because the player genuinely does not know what it is looking at. This one carries its own decoders, which makes the download larger, puts the burden of maintaining a very long list of formats on the project rather than on the platform vendors, and drags the whole thing into the patent thicket around video. What it buys is that the question of why a file will not play stops depending on the machine. That lesson leaves the media context entirely: depending on the platform's shared components makes you quick to build and hostage to what the platform has installed, and choosing to carry your own is choosing predictability over convenience. Anyone who has shipped software that works on their laptop and not on the customer's has met the same trade from the losing side. The rest is unusual enough to record. It was a 1996 student project to move video around a campus network, the code belonged to the school, and its release under an open licence in 2001 required the institution's permission, which anybody whose employer owns their side projects will recognise. The orange traffic cone is not a metaphor for anything: it references cones collected by the school's networking students' association, so a piece of student mischief became one of the most recognisable icons in computing. The entry also handles a widely repeated story about its president turning down tens of millions to bundle advertising, which circulated heavily from a single interview, by attributing it rather than asserting it. What is not in doubt is the outcome: no adverts, no telemetry, no paid tier, after nearly thirty years.

    • Contenuto

      The finger-pointing was not a failure of goodwill

      The third observability company on this timeline, and the entry's job was to say what makes the three different rather than to describe another monitoring product. This one was founded on an organisational problem rather than a technical one. Its founders spent nine years together at an educational software company watching developers and operations staff work from different, incompatible data during incidents, each convinced the fault lay with the other, each holding evidence the other could not see. That is worth stating carefully: the finger-pointing was not a failure of goodwill, it was the predictable result of two teams looking at different instruments and describing the same event in incompatible terms. So the founding insight is not a monitoring feature. It is that an argument about what is happening cannot be settled while the parties hold different data, and that a shared view ends the argument not by resolving it but by removing the ambiguity that fed it. Everything else follows, including why the platform kept absorbing adjacent categories, because the moment any of them lives in a separate tool with a separate login the old argument becomes available again. Read against the other two, the three approached the same destination from different directions: one from inside the application tracing a transaction through code, one from the network reading flow records and routing, this one from the infrastructure outward. They converged because an outage does not respect the boundary between an application, a host and a network, so any tool that does will eventually be asked to stop. The entry also names a structural tension in metered observability pricing that applies to the whole category rather than one vendor: when the bill scales with how much you instrument, the customer's incentive is to observe less, which is the honest cost of the model rather than anybody's bad intent.

    • Contenuto

      The customer's requirement never changed, and the skill required to satisfy it changed completely four times

      A São Paulo communications integrator whose own account puts its founding around 1981, which if right means it began work before the informatics market reserve became law, well before the state telephone system was privatised, and roughly fifteen years before anybody sold voice over internet protocol to an enterprise. All three of those upheavals have their own entries here, and this company worked through all of them. The through-line is a single unglamorous function performed four incompatible ways: private branch exchanges with proprietary handsets and physical extension wiring, then digital exchanges with computer-telephony integration bolted on, then internet telephony where the phone became an endpoint on the data network and the telephony team lost their private empire to the networking team, and now unified communications delivered as a service where the platform belongs to somebody else. The requirement never changed. The skill required to satisfy it changed completely, four times, and that is the actual career risk in this industry stated plainly. Nobody was made redundant by the arrival of internet telephony; they were made redundant by not learning it, and the interval between a technology becoming visible and becoming mandatory has generally been about a decade, which is long enough to ignore comfortably and short enough to be caught by. A company surviving four of those transitions has re-skilled its people four times, which is harder than any product it sells. The entry also notes a conflict about its own age, since the company says forty-three years and its social profile says thirty-six, and it follows the company's own figure while recording the discrepancy rather than hiding it.

    • Contenuto

      Four companies, and one of them has no founding year because nobody published one

      A batch of smaller companies, written at the length their evidence supports rather than the length of their neighbours. The largest is a São Paulo training school trading since 1993 that carries official curricula for around fifteen vendors simultaneously, four of which have their own entries here. That count is the entry, because carrying that many at once is administrative before it is pedagogical: each authorisation is a separate agreement, instructor certification path, courseware licence, audit and set of lab requirements, and they rarely resemble each other. A multi-vendor school is a dozen small businesses sharing a reception desk. It also serves a customer this site rarely describes, since most certification discussion assumes a corporate employer paying for training as part of a project, while a city-centre school serves the individual paying their own money at night to change what they are qualified to do. Those two customers want different things from the same course. Two of the others are integrators whose entries are deliberately short, and one of them carries no founding year at all, because none is published and the field is optional precisely so it can be left empty. Putting a placeholder there would repeat a mistake this project has already made once and recorded: a field wanting a value is not a reason to supply one. Their partner lists do the work instead, and read as documents rather than rosters. An integrator carrying both information security and electronic security is selling into a building rather than a network, where firewalls and door controllers land on the same project with one budget and one set of contractors, and the distinction between those disciplines is far sharper in the vendor catalogues than it is on a construction site.

    • Contenuto

      The second company in two entries whose own specification became an international standard

      An Israeli company founded in 1993 by two engineers out of a semiconductor firm one of them had co-founded six years earlier. The founding problem was arithmetic: a digitised telephone call the standard way consumes sixty-four kilobits per second, and the packet networks of the early nineties could not carry many of those, so everything that became voice over internet protocol depended on compressing speech hard enough to fit without it sounding like a machine. That is a signal-processing problem before it is a networking problem, which is exactly why the founders were chip people. Their speech coding work went into a codec adopted by the international standards body, and that makes this the second consecutive entry here in which a company's own specification became the standard everybody implements, after the cable distributor whose performance programme became the category system still in use. Worth naming as a mechanism rather than treating as two coincidences: standards bodies rarely invent, they ratify, and what they ratify is usually the thing already built by whoever needed it badly enough to build it. The reward is not licence income. It is that the industry's default now has your fingerprints on it and every competitor implements something you understand better than they do. The moat is not the patent, it is the head start. The product line then climbed one layer at a time, from codec to board to gateway to software, which is easy to describe and hard to do because it means competing with your own customers. And the same person has been chief executive for thirty-three years, which matters more than it sounds: a company that changes chief executive every four years cannot run a strategy that takes ten.

    • Contenuto

      The side project ate the main business, and the old method did not stop working, it stopped being affordable

      Two university roommates started an online shop selling computer parts in 1995, built some tools for Windows administrators on the side the following year, and found the tools out-earning the shop, so they founded a company around the tools instead. They sold that company for a hundred and fifteen million dollars and used the proceeds to fund the next one, which took no institutional money for well over a decade. Two patterns worth naming come out of that. The first is that the thing built to support a business often becomes the business, because the supporting thing solves a problem the builder actually had while the main business was a guess about a problem somebody else might have. Anyone who has written an internal tool that other departments started asking for has seen the beginning of it, and the usual mistake is treating the sideline as a distraction rather than as evidence the plan was aimed at the wrong problem. The second is that a previous exit can be the only funding round you need, which this site has now recorded twice, and the venture path is simply the one that gets written about because the people who write about it are participants in it. The technical opportunity deserves precision too. Virtualisation put many servers onto few hosts, and backup software of the period ran an agent inside each machine, which had been fine when each had its own disks and spare capacity and became untenable when thirty agents woke at once and competed for the same spindles. The old method did not stop working. It stopped being affordable, which is a distinction most product histories blur. And one consequence of the eventual acquisition is structural: moving the corporate domicile made the company eligible to bid for federal contracts, which sits interestingly beside the sovereignty entries here, since those record countries building infrastructure so ownership cannot be used against them and this records a company changing its nationality so ownership could be used for it.

    • Contenuto

      Every engineer who says Cat 6 is using a vocabulary a distributor invented

      The seventh distributor on this timeline, and the one with a fact almost nobody knows. In 1989 it published a programme called Levels, the first written performance specification for data cabling systems, produced so customers could compare cable on measured performance rather than on manufacturers' assurances. The standards body adopted it and renamed Levels to Categories. Which means that everyone saying Cat 5, Cat 5e or Cat 6 is using a vocabulary invented by a cable distributor for commercial reasons and subsequently promoted into an international standard. That is an unusual route for a specification to travel and it says something specific about where useful standards come from: not always from manufacturers, who have an interest in incomparability, nor from committees, who need something to standardise, but sometimes from whoever is stuck explaining the difference to a buyer. The laboratory it opened in 1995 follows the same logic. A distributor testing what it sells is structurally odd, because it is not the manufacturer and so has no product to defend, and not the customer and so has the volume to justify equipment nobody buying a single reel could afford. That is the neutrality argument this site makes about carrier-neutral exchanges and vendor-neutral certification, arriving in the least likely place, which is the middle of a supply chain. The company was sold in 2020 for four and a half billion dollars after a well-documented bidding war that climbed in public increments from three point eight. Read beside the other six distributors here, this is the one that shaped what it sold rather than only moving it, which is the strongest counterargument to the usual description of distribution as a layer that adds cost: somebody in that layer had to define what the products even were before they could be compared.

    • Contenuto

      A country does not become able to use computers by training its computer industry

      The other half of the market-reserve story, and the two meet in a single detail. The school that opened in 1977 and is generally called Brazil's first computer school equipped itself with twelve domestically built microcomputers, the products of exactly the protected industry written up here a few days ago. The reserve manufactured the hardware; schools like this manufactured the users, and neither half works without the other. Three things about it are worth carrying elsewhere. First, the pioneering was the audience rather than the technology: computing courses already existed, but they were for future programmers, attached to mainframes, expensive and restricted, and the founder's proposition was that ordinary people would pay for computer instruction if it were affordable. That is the founding insight of essentially every technical training business since and it was not obvious at the time. Second, the pedagogy came from language teaching, because the founder already owned four English schools, and it transferred better than anyone expected. A language school runs on monthly fees, graded levels, small classes and the assumption that competence is built by repeated practice over months rather than transferred in a week. Apply that to computing and it works for exactly the same reason, since both are skills rather than bodies of knowledge, and a skill acquired in a five-day intensive decays at a rate that surprises the person who paid for it. Third, the number that matters is the denominator. The protected industry's employment rose from about forty-two thousand to about seventy-four thousand across the decade. Two million people passed through these classrooms, and most of them never became engineers, which is the point.

    • Contenuto

      Sovereign cryptography, a conference that built an organisation, and fibre nobody else touches

      Three entries on Brazilian government network infrastructure. The first is a metropolitan network in the capital, twenty years old and almost unknown outside the people who use it, which is the ordinary condition of working infrastructure. Its design decision is ownership: the fibre belongs to a ministry rather than a carrier, so it is a private network in the strict sense, physically separate cable no commercial operator touches. The reasoning matches the military satellite entry and the pre-privatisation telecoms monopoly, which is that an organisation unable to survive its supplier changing terms or being acquired eventually builds its own. It now carries hosting, cloud and colocation too, which is the predictable trajectory and also the risk, because everything ends up depending on one network. The second is the military cyber defence centre, whose first assignment says a great deal about how such organisations actually begin: monitoring the network of a United Nations conference. Not a war, not an incident, but an event with a fixed date, a defined perimeter and a guaranteed audience, which supplies the deadline, the budget and the visible result, and the organisation outlives the event that justified it. The team assembled for it mixed three services with police and telecommunications regulator technicians, because the infrastructure being defended is civilian and the attacker does not respect the boundary between crime and conflict. The third is the intelligence system, included for one component: a communications security centre founded in 1982 because the country could not guarantee the confidentiality of its own government traffic, which develops sovereign cryptographic algorithms. That carries a real trade-off. Cryptography reviewed by the global research community gets decades of adversarial analysis from people with no stake in whether it holds, while national cryptography is reviewed by a much smaller group that often cannot publish. Neither argument wins outright, and a country's position on it usually reflects how much it expects to trust its suppliers.

    • Contenuto

      He bought the company back from its investors for four dollars

      The last entry in the group covering how technical training is actually delivered, and its own team page contains a sentence most companies would never print: the founder purchased the business from its investors for four dollars, having previously raised around twenty-six million. A company does not invent a story in which its own investors valued it at nothing, which is the best reason to believe it. The ending is that it sold to a Denver asset manager for a reported sixty to eighty million after roughly a decade of bootstrapped, profitable growth. That sequence inverts the narrative this timeline records over and over, which is raise money, grow fast, sell. Here it was raise money, have the investors write it off entirely, buy it back for a nominal sum, then grow slowly on your own revenue. The venture route is the one that gets written about and it is not the only one that works. The technical problem is one every instructor recognises immediately. Enterprise software assumes a data centre, and the real constraint on teaching it is not the material but that thirty students each need a working copy of an environment that takes hours to build and that they will inevitably break. The insight in the business model is that a training lab and a sales demonstration are the same artifact: both are a working replica of a system the audience does not yet have, in a state that shows it doing something useful, and the difference lies entirely in what the audience is asked to do afterwards. Which meets an argument already on this site, because a proof of concept is supposed to be a test that can fail and a demonstration is supposed to succeed. When both run on identical infrastructure prepared by the same people, the line between them is intent rather than setup, and good lab platforms make honest testing easier and dishonest testing easier by exactly the same amount.

    • Contenuto

      The same company founded both, twelve years apart

      Writing up the smaller of the test-delivery companies turned up something the entry on the larger one did not know when it was published two days ago. The staffing company that founded the first in 1990 and sold it in 1995 went on to found the second around the turn of the century. The same parent, twice, in the same industry, and the earlier entry has been updated to say so. The second company also claims to have introduced online proctoring in 2005, which is its own claim and is presented as such, but the direction is clear enough and worth remembering: the capability existed and was commercially available fourteen years before the larger network launched its equivalent, and fifteen before circumstances removed the alternative. That is the ordinary pattern for infrastructure, and it is worth recalling next time something is described as unprecedented. The business models differ in a way that is architectural rather than promotional. The large networks are full service, where a client hands over an exam and the network delivers it. This one sells a platform on which clients build and publish their own, with the explicit selling point that changing a question does not cost a publishing fee. One model treats an exam as something you outsource, the other as something you operate, and which suits an organisation depends on how often its exams change, which organisations reliably underestimate. And there is a strategic contrast worth the space: this company assembles its stack by partnership, including a credentialing partner that its largest competitor bought outright. The identical functional stack, assembled by acquisition on one side and partnership on the other. Neither is obviously correct, because acquisition concentrates the trust chain in one owner while partnership means the pieces can change hands or start competing with you. The question is not which structure is better but which failure you would rather have, and most buyers never realise that is what they are choosing.

    • Contenuto

      Being required is what makes a certification valuable and what degrades what holding it signals

      The certification body behind the best-known credential in offensive security, which is also the most persistently criticised, and this entry argues those are the same fact seen twice. It leads with the criticism that depends on nobody's opinion, because the organisation published it themselves: a credential marketed as defensive had, according to their own frequently-asked-questions page, exactly the same exam content as their offensive one, differing only in the title. One examination, two names, two audiences. The wider criticism is long-running and easy to find, and a site that records the criticism of other certification bodies, of web filtering and of practical exams should record this too. The accreditation is also real, which is the other half of an honest account: a recognised personnel-certification standard, and inclusion in a defence department directive that makes the credential mandatory for certain roles. That recognition is not marketing, and it is why the certification appears in job requirements written by people who have never heard the criticism. Then the structural explanation, which is offered instead of a verdict. A mandatory certification acquires enormous volume, because people take it who would never have chosen it. Volume produces variance, since among hundreds of thousands of holders there are excellent practitioners and people who memorised a question bank, both holding the same credential. Variance produces the anecdote, and the anecdote travels much further than the median. There is no version of mandating a credential that avoids this, which is where the whole group of entries lands: every mechanism that makes a credential useful attacks the thing that made it worth having. The honest position for anyone hiring is that a certification is not evidence of capability, it is evidence that somebody passed a specific test on a specific day, which is a smaller and far more useful claim.

    • Infrastruttura

      A comment promised a safety net the code did not implement

      A reader reported that two tools were missing from a vendor hub. They were not missing from the data; they were missing from the page. The hub groups items into sections by sub-category with a trailing catch-all, and a comment in the source said that catch-all caught anything unmapped so nothing would silently disappear. It did not. The comparison treated an absent sub-category as belonging in the catch-all, but treated a sub-category that simply was not in that vendor's list as belonging nowhere at all, so anything carrying one matched no section and rendered on no page. Fixing it turned up more than was reported: seven items across four vendors were invisible, not two across one. The reader noticed the vendor he knew best. A comment promising a safety net the code does not implement is worse than no comment, because it stops the next person from checking, and that is the second time this week a page has been silently incomplete while every check passed and nothing looked wrong. There is now a build check for it, and its own header states precisely what it protects rather than implying more: once the page computes the bucket correctly an unknown category is visible in the catch-all, so the live protection is the check that the page still computes it at all. Revert that one line and the build fails. The check also asserts that it parsed the vendor taxonomies successfully, because an earlier version of it found only three of six, and that failure direction is the dangerous one: a taxonomy the checker cannot see makes every item look correctly placed, so it would have under-detected exactly the bug it exists for.

    • Contenuto

      Every assessment model is vulnerable in exactly the place its strength comes from

      The third entry in the group covering how certifications are actually delivered, and it exists to complete an argument the first two set up. Those companies run controlled examinations in supervised rooms, where the question being answered is whether the right person is in the chair. This company does the opposite: twenty-four hours, real machines on a test network, compromise them, then write the report. The exam is the work rather than a proxy for it, and you cannot bluff a shell you did not get. But that inverts the trust problem rather than solving it, and the inversion has a documented cost. A multiple-choice examination can be memorised, which is why the delivery companies spend so much on verifying identity. A practical examination cannot be bluffed, but the target machines are reusable, so knowing them in advance is the cheat, and in 2019 a critic published a walkthrough of one exam machine and threatened more, alleging that cheating was widespread. Put the two failure modes side by side and the principle falls out: every assessment model is vulnerable in exactly the place its strength comes from. Standardisation makes an exam scalable and memorisable, realism makes it unfakeable and leakable, and there is no design strong in both directions. The serious question about a certification is therefore not whether it can be gamed, but which way, and whether the people relying on it know. The entry also notes a business model that inverts the usual one, since the tool is free and open source while the proof that you can use it is expensive, and a decision that was harder than it looks: throwing away an established distribution name in favour of a foundation that made long-term maintenance tractable, which is the correct call and almost never the popular one.

    • Contenuto

      For eleven years, a company that wrote exams owned a company that delivered them

      The other half of the test-delivery market, and the entry begins with the structural fact most people get wrong: this company does not write the exams it administers. Its clients develop the content, write the questions and set the passing standards, while it supplies secure delivery, identity checks, proctoring and score reporting. That separation is the source of the industry's credibility, because the organisation deciding what competence means is not the organisation deciding whether you demonstrated it. Which makes one stretch of its history genuinely interesting: from 2007 to 2018 it was owned by a major author of examinations. Nothing improper has been alleged and the arrangement ended, but it is precisely the combination the separation of powers exists to avoid, and the same question sits unresolved over an exam business and a credential business that share an owner today. The entry says so, because scepticism applied selectively is not scepticism. There is also the cleanest illustration of a valuation bubble anywhere on this timeline. The business sold for about forty-five million dollars in 1995, for around seven hundred and seventy-five million in 2000 at the height of the boom, and for four hundred and thirty-five million in 2007, little more than half what the previous owner had paid seven years earlier. The business had not shrunk. The market's opinion of what a testing network was worth had. And the client list explains why the stakes exceed technology certification: medical licensing, nursing boards, financial regulation, architecture registration. These are not credentials that improve a curriculum vitae, they are the ones deciding whether somebody may practise, which is why a documented delivery failure is recorded here rather than glossed.

    • Contenuto

      The small company bought the big one's product, then the big one bought the small company

      A digital credentialing company founded in 2012, written immediately after the exam-delivery entry because it completes the same chain. A test centre establishes that the right person sat the exam and then says nothing further: a certificate can be edited, a line on a curriculum vitae cannot be checked without contacting the issuer, and neither carries an expiry anyone can see. A digital credential is a verifiable object instead, and for years the weakest link in certification was not the exam but the claim about the exam. The corporate sequence is a neat reversal. A large education company launched a badging platform in 2014; in 2018 the much smaller company acquired it, giving the large one a minority stake and a board seat; and in 2022 the large one acquired the small one outright. Two things follow that this site records because it records them about other layers. First, verification of the person and verification of the credential are now under one owner, which is not an accusation and is an observation consistency requires: when the same organisation attests that you sat the exam and that your certificate is real, the independence between those attestations is organisational rather than structural. Second, and genuinely unresolved, the company holds patents covering the creation and management of digital credentials, over a standard whose entire premise is that anyone may implement it. It has said it will not assert them against that community and has offered a licence. A promise not to assert is a promise, and promises survive at the discretion of whoever owns the patent next, which is already a different company from the one that made it. The entry states all of that and adjudicates none of it.

    • Contenuto

      A certification is worth exactly what its verification is worth

      The first entry in a new group covering the layer between a certification and the person who holds it, and the reason it belongs on a site about teaching is a chain of trust almost nobody examines. A vendor defines what competence means and issues a credential. A training company teaches toward it. And somewhere in the middle a stranger has to establish that the person at the keyboard is the person named on the certificate, that they had no help, and that they did not see the questions in advance. Every argument about whether certifications mean anything is really an argument about that layer. So the security apparatus is the product: identity documents checked against the booking, signature capture, palm-vein scanning in some rooms, surveillance, a proctor watching, and a room stripped of anything a candidate might otherwise consult. One piece of timing is worth noting without over-reading it: the online proctoring platform launched in 2019, and the following year test centres closed worldwide and remote delivery became the only way most certifications could be earned at all. That is luck rather than foresight, but an industry forced to invent remote proctoring under lockdown would have gone considerably worse. Remote delivery also moved the trust problem rather than solving it, because in a test centre the environment belongs to the examiner and at a kitchen table it belongs to the candidate. There is a second lineage in here too. The parent company dates to 1844 and began as a firm of building contractors, which makes it the second business on this timeline to spend its first century moving physical things and its second moving information. Two of the oldest names here arrived from heavy industry, which is a reminder that the durable thing about a company is rarely its product.

    • Contenuto

      Two things everyone says about the first network, and both are wrong

      Two long glossary entries, on the agency that funded the first packet network and on the network itself. The agency entry is careful about what it actually contributed, because the popular version overstates it: packet switching was arrived at independently by a researcher in California and another in Britain, working on different problems, and the agency did not invent it. What it did was fund the building of a working network at a scale that proved the idea, and then fund the protocols that let separate networks join. Its structure is the part worth copying and rarely copied: a small permanent staff, programme managers hired for a few years and then gone, and a deliberate expectation that most programmes fail, which is what stops an agency developing the institutional attachment that keeps ordinary funders pouring money into things that are not working. The network entry corrects two things almost everybody repeats. It was not built to survive a nuclear war. Earlier work at a research corporation did address survivable communications, but this network's own motivation was sharing expensive, scarce and incompatible research computers. And it did not become the internet by growing: it became the internet in 1974, when two researchers published a way for separate networks to interconnect through gateways, which is a different and much larger idea. The network itself was switched to the modern protocol suite in a single hard cutover on the first of January 1983, and decommissioned in 1990, made redundant by the thing it had started.

    • Contenuto

      Spanning tree did not lose, it was outlived

      A long glossary entry on the protocol that keeps switched networks from destroying themselves, and on every variation that followed. Ethernet has no time-to-live field, so a frame in a loop circulates forever and a broadcast multiplies on every pass until the network is a solid wall of copies. The answer, written in about a week in 1985 and summarised by its author in a poem, computes a loop-free tree across an arbitrary mesh and blocks the links outside it. The entry walks the versions and says why each exists rather than just listing them: the rapid version because thirty to fifty seconds of reconvergence became unacceptable once voice ran over the same wires, the multiple-instance version because one tree for the whole network means every virtual network follows the same path and half your links carry nothing, and one vendor's per-network approach because it reached the same need earlier by a route that is easy to reason about and expensive at scale. The accessories are the tell. Each one exists to patch a specific way the protocol gets hurt, and they share a root cause: the protocol trusts what it hears, and a network is full of things that can stop being heard. The successors replaced the tree with a routed fabric so that every link forwards, and neither displaced it, because a protocol running in every switch for three decades is not replaced by a better protocol, only by a different architecture. Also added: the time synchronisation family, where the useful warning is that the simple variant is a subset of the full one rather than a separate protocol, speaks the same wire format, and must never be configured as a time source for anything else, because it will faithfully propagate a bad answer it had no means of detecting. And the three-letter acronym now disambiguates itself, because it means both a protocol and a cable construction, and those two diagnoses have nothing in common.

    • Contenuto

      The first connection was not the one that mattered

      A long glossary entry on the network the Brazilian internet was actually built on, and the reason to write it carefully is a detail the popular version leaves out. Before the national research network existed there were two separate international links, one from a laboratory in Rio at nine thousand six hundred bits per second and one from a research foundation in Sao Paulo at four thousand eight hundred. The Rio link came first, by about three months. It also mattered least: it never evolved, and was switched off in 1996 at exactly the speed it had started at, while the Sao Paulo link grew into the thing everything else attached to. Being first and being the one that matters are different achievements, and this is a clean example of the gap between them. By the middle of 1989 the country had three disconnected islands of academic connectivity that could only reach each other by going abroad and coming back, and the network was created that September to fix exactly that. The decision that turned it from a university facility into the country's spine came in 1995, when it began carrying commercial traffic alongside academic. The general lesson has nothing to do with Brazil: national internets are usually built by whoever was already connecting universities, because that community had the requirement, the international relationships and the tolerance for unreliable infrastructure a decade before anybody could sell the service.

    • Contenuto

      Eleven glossary entries, and a network model worth understanding even if you never touch one

      Six short entries for organisations and standards that keep appearing in security work, and five longer ones. The longer set is built around a single architectural idea: defence networks separated by classification level onto physically distinct infrastructure, so that unclassified, secret and top secret traffic never share a cable. The separation is not a firewall rule or a virtual network. It is different equipment in different rooms, and somebody who needs two levels sits at two terminals. That is the strongest form of a principle every enterprise implements weakly, which is that the cheapest way to stop traffic crossing a boundary is not to build the boundary at all. The entries also record what that model does not do. A very large disclosure of diplomatic material in 2010 did not involve breaching any separation from the public internet; it involved somebody with legitimate access copying what they were entitled to reach. Physical separation defends comprehensively against outsiders and not at all against insiders, and a network whose perimeter is a wire that does not exist can still be emptied by anyone already inside. There is a cost lesson too: each step up in classification buys stronger separation and pays in usability, and that friction is the mechanism rather than a flaw, which is why organisations that copy the model without accepting the cost end up with the friction and not the security. The Brazilian entry in the set makes a related point from another direction: sovereignty over infrastructure is a design property rather than a policy statement, because no amount of encryption changes who owns the transponder.

    • Contenuto

      Five, not seven, and most of the internet has not caught up

      A long glossary entry on the work role categories that the American standards body uses to organise cybersecurity work. The first thing it says is the most useful: there are five of them, not seven, and a great many current articles, course outlines and study guides still say seven. Two categories were removed in March 2025 and their roles moved to the defence department's own workforce framework, to keep the two in step. Anything citing seven describes the framework as it stood before that, and anything citing the older names describes it as it stood before November 2020. The version trap is worth understanding rather than just noting, because it catches careful people: the components are versioned separately from the publication, so the publication number has not changed while the content has moved three times. If you are building a curriculum or mapping a team, check the current components release rather than the document number. The entry also spends time on the most common misuse, which is reading a work role as a job title. It is not one. A work role is a bundle of responsibility that appears in many differently titled jobs, and a real job usually combines several: the person who administers your firewalls holds parts of implementation and operation, parts of protection and defence, and on a bad week parts of investigation. Mapping a vacancy to exactly one role is a sign the mapping is wrong.

    • Contenuto

      One company defended the moat, the other helped dig the canal

      A company founded in a university town in upper Austria in 2005 to solve a problem that had become general: applications were distributed enough that nobody could say which component was slow. Its answer was a patented method for tracing a single transaction end to end, browser to database, at code level, with overhead low enough to leave running in production. That last clause is the hard part, because tracing that is only safe in a test environment tells you about a test environment, and the interesting failures do not happen there. What makes the entry worth reading is what happened after private equity took control in 2014. By the founder's own account the new owner specialised in businesses with a good product and ineffective leadership, and found his startup habits foolish. He then took three months with his best product people and came back recommending they throw the platform away and write a new one from scratch, on the argument that the disruption of cloud was an opening to leap ahead rather than a problem to survive. They agreed. A company under debt-funded ownership, expected to produce returns, rebuilt its product from nothing, and listed five years later at a price that rose by half on the first day. And it inverts a pattern recorded here a few days ago. The modem company won three times with proprietary protocols and lost the advantage each time a standard arrived. This company held a patent on distributed tracing and then contributed to the open standards that generalise exactly what its patent covered. Faced with the same situation, one defended the moat and the other helped dig the canal. Which is right depends on whether your advantage is the mechanism or the thing you build on top of it.

    • Contenuto

      The people who ran the networks built the tool they could not buy

      A company founded in 2014 whose founding team is where several entries already on this timeline converge. Its chief executive started his city's first internet service provider in 1992 and then spent over a decade running network operations at the content delivery company written up here weeks ago, ending as its chief network scientist. Another founder is described as the first employee of the content delivery and security company written up beside it. A third came from a streaming service whose traffic volume needs no introduction. The reason they gave for starting is the whole entry: large web companies and service providers kept telling them that the analytics available inside cloud-scale companies simply were not available to buy, particularly for internet visibility and for architectures that had stopped resembling a data centre. So they built what they had wanted and could not get. That is a specific and recurring shape worth naming, because a category sometimes exists only because the people who needed it were senior enough to build it rather than wait. The product takes what a network actually emits rather than what a monitoring tool wishes it emitted, and flow records are the interesting part for anyone who has tried this at scale, because they arrive in enormous volume, they are lossy by design, and the analytical question is almost never about a single record. It is a data problem wearing a networking costume. One public contribution is recorded: the company was among those that identified a substantial address hijacking before a national inauguration, which is only visible to somebody watching the global routing table closely enough to notice a block being announced from the wrong place.

    • Contenuto

      Two competing products can be making the same judgement, because they buy it from the same place

      Yesterday's entry described web filtering as acting on classifications, and noted that a classification is a judgement made at scale by people the affected user will never meet. This entry is where those people actually work. A company founded in 2005 did one thing: classify the web, reputation and category, across more than two hundred million addresses. It did not sell filtering to enterprises. It sold classification to the companies that sell filtering to enterprises, licensed into their gateways and firewalls and proxies, with the customer never seeing the name. That produces a fact most engineers have never had cause to consider. When a firewall from one vendor and a web gateway from another agree that a site is dangerous, the agreement may be evidence, or it may be one supplier's opinion arriving twice. And the caution belongs in the entry rather than a footnote: a shared classification source is a shared blind spot, so if the database is wrong every product consuming it is wrong at the same moment, and the diversity a customer believes they bought by choosing different vendors is not there. There is also a neat loop. The founder had been director of product management at the filtering company written up yesterday, whose entire product was acting on classifications. He left to build the classification itself, one layer down, and sell it to everybody, including that employer's competitors. The layer below a market is often a better business than the market, because it has fewer customers, they are stickier, and they compete with each other rather than with you.

    • Contenuto

      Four names, five owners, and a failure mode that never gets fixed

      A company founded in 1994 to resell other people's security products, which made its name on something it built instead: software deciding what employees could reach on the internet. Its founder was removed by his own investors in 1998, before the renaming, before the flotation that raised seventy-two million dollars at the exact peak of the dot-com bubble with the share price doubling on the first day, and before everything after. That happens often enough to be unremarkable in aggregate and is worth naming in the particular. The mechanism is worth stating precisely, because it explains the criticism the product attracted for two decades. A database classifies sites, a policy decides which classifications a user may reach, and an enforcement point sits between the user and the web. That is the same architecture as the proxies elsewhere on this timeline and it carries the same unavoidable weakness: a classification is a judgement, made at scale, by people the affected user will never meet. So the product was called censorware, and the complaint was not baseless, because over-blocking caught sexual health information, political material and plenty of ordinary sites that fell the wrong side of a category boundary. That is not a bug that gets fixed. It is the failure mode of the entire approach, and an honest account of web filtering has to say so. The rest is an ownership carousel: private equity, then a defence contractor, then a rebrand, then private equity again. What the defence period bought was not technology so much as clearance, because government work needs a supplier who can hold it and a commercial filtering company could not. The product went where the ownership could take it, which describes most security-industry consolidation more honestly than the strategy language used at the time.

    • Contenuto

      Three passages that had been written, translated, and rendered nowhere

      A career chapter on this site renders a fixed number of numbered sections, and that number is written by hand in the page's own file. It was smaller than the number of sections somebody had written. Three passages had been authored, translated into Portuguese, and were appearing on no page at all: the physical work of pulling cable under a petrol-ship pier for an oil company alongside nearly the whole local team, the customer list running across the banks and card processors and the futures exchange of an entire national economy, and the multiprotocol enterprise of the late nineties when the wire was as likely to be Token Ring or a fibre ring as Ethernet. Nothing was broken. The pages built, the translations passed their parity check, every other check was green, and the writing was invisible. They are now placed, and the order was chosen rather than appended: the texture of the era comes before the architecture drawn from it, so a reader meets the wire, the work and the customers before the policy framework that came later. Chronology is kept at both ends and the middle is thematic, because those passages all belong to the same years and no ordering among them would be more correct than another. There is also a new build check, because this is the third distinct shape of the same failure found in two days: a chapter nothing links to, a link pointing at nothing, and now content nothing renders. All three were silent, and none of them was a bug in any sense a compiler recognises.

    • Contenuto

      The modem company that won three times with its own protocols and surrendered each one

      Two additions. The first is the company whose modems most people of a certain age actually owned, founded in a garage in 1976 and named after the fictional robot manufacturer in Asimov's stories. Its two product lines are the interesting part, and so is the relationship between them: the expensive one was built for bulletin board operators and businesses, with an upgradeable signal processor that let a modem bought before a standard was finished be brought up to it later, and the cheap one was for everyone else. They shared a motherboard. On some models a sequence of commands would unlock the expensive line's faster mode on the cheap one, because the difference between them was firmware and price rather than hardware. Segmentation by software instead of silicon is so ordinary now that it has a name, and this is one of the places it was learned. The company's real pattern was proprietary-then-standard, three times over: its own high-speed protocol beat everyone while it lasted, then a standard arrived and it stopped mattering, and years later the same play ran again with a rival consortium and ended the same way. That cuts against a thread this site returns to often, because elsewhere the timeline records openness and neutrality paying off. Here the opposite worked, repeatedly, for real years. What it never bought was permanence. The second addition is a section on one of the career chapters, recording the connectivity of a Brazilian office in the late nineties: a quarter of a megabit to New Hampshire carrying an entire country operation, a registered address block, and dial-up doing the rest through a succession of modems as the speeds stepped up. One figure in it is remembered two ways, and the uncertainty is left standing rather than resolved into a precision nobody has.

    • Contenuto

      Training is distributed the same way products are

      A man working at a networking vendor was offered a training role, took it, spent a while delivering courses across a region, and concluded there was a business in doing it properly. He started one in 2005, and by his own account that first vendor was also his only vendor at the start. The early years, he says, were a few boxes of hardware and a heavy flight schedule: the classrooms travelled on planes with the instructor. Twenty years on the company delivers accredited training across five regions and has passed a hundred thousand seats. The structural point is one this timeline has been circling for weeks without quite saying. A vendor does not want to run a training operation in every country it sells into, because certifying instructors, maintaining lab equipment and scheduling classes in the right timezone and language at a quality that reflects on the brand is a business in itself, and it is not the business of building the product. So vendors authorise partners to do it, on much the same logic that leads them to authorise distributors to hold stock and extend credit. Training is distributed. Once that is visible, the shape of the industry makes more sense, because an authorised training company is to a vendor's courseware roughly what a distributor is to its hardware. One detail decides whether any of it works: where the instructors come from. A course taught by someone who has only ever taught it is a different course from one taught by someone who has run the product in production and been called at three in the morning when it failed, because only the second kind can answer the question that is not in the material.

    • Infrastruttura

      Two lists describing one fact, which is how they drifted

      A reader pointed out that some partnership labels were missing from the industry timeline. The cause turned out to be more interesting than a missing entry. The label was never declared anywhere; it was inferred, twice, from two different proxies. Companies reached one way took it from a category field that happened to include most partners, and companies reached the other way took it from a hardcoded list maintained separately. Two lists describing one fact will drift, and these had. There is now a single explicit declaration on each company, and both paths read it, so the label states something somebody wrote down rather than something a category implied. A second label has been added alongside it for the vendors whose training the author is authorised to deliver, which is deliberately a different and much shorter list. That distinction is worth being pedantic about, and the code says so where a future editor will see it: an authorisation claim must never be inferred from a partnership, a certification, or the fact of having taught a course. These two labels also sit on their own axis, separate from the tags that classify what a company is, because a filter listing distributors, carriers and authorisation claims together is not one classification but two wearing the same coat.

    • Infrastruttura

      A page that becomes an island is worse than a page that breaks

      An entry on the industry timeline was dissolved this week because it grouped three companies that shared a distribution portfolio and nothing else. That entry turned out to carry the only link to one of the career chapters. The chapter kept its own address and rendered perfectly. It simply stopped being reachable from the timeline, and every check passed while that was true, because nothing was broken in any way a build can detect. That is the failure worth naming: not a page that breaks, which announces itself, but a page that becomes an island, which does not. A career chapter nobody can navigate to is functionally deleted while looking entirely healthy. The link is restored, and from both of the entries that inherited the dissolved one's subject matter, since the chapter covers three companies whose histories now live in two places and a reader arriving at either should find it. There is also a new build check for the general case, and it looks in both directions, because both fail quietly: a chapter nothing points at is unreachable, and a link pointing at a chapter that no longer exists is dead. Many-to-one linking is explicitly allowed, because requiring exactly one link would force a false choice about which lineage owns a chapter that genuinely spans two.

    • Contenuto

      A word that meant one thing and read as another

      Two companies on the industry timeline were labelled with a word meant in its ordinary networking sense: the point that all traffic has to pass through. Unfortunately a well-known security vendor has almost exactly that name, and has its own entry a few cards away, so the label read as a corporate relationship that has never existed. A reader spotted it. The word has been changed to the term of art that means the same thing and collides with nothing, and the phrase now explains itself in passing rather than relying on the reader to know which sense was intended. The fix had to be made in two places, which is worth noting: the label lived both in the timeline data and in the longer profile that actually renders on the page, and correcting only the first would have looked fixed from the index and stayed wrong on the entry itself. A sweep of the rest of the site found the same word used elsewhere in genuinely unambiguous contexts, describing where a packet filter sits in a load balancer's processing order, and those were left alone. The problem was never the word; it was a word doing duty as a name.

    • Contenuto

      A policy that failed at its stated goal and succeeded at one nobody wrote down

      For eight years from 1984, the Brazilian market for computing equipment was reserved by law for Brazilian-owned companies. The law passed Congress unanimously with support from academia, industry, the press, the government and the opposition, and it carried its own expiry date. The case against it is substantial and is stated first here, because nostalgic accounts tend to leave it out: freed of foreign competition several manufacturers cloned rather than pioneered, one shipped a copy of a well-known operating system under a new name and was threatened with litigation for it, the United States formally accused the country of unfair trade practices in 1985, and between 1989 and 1992 every semiconductor plant in the country closed or left. The case for it also has numbers, which is why the argument has never been settled: the microcomputer market grew faster than anywhere else in the capitalist world for three years, and domestic firms went from under a quarter of the market to two fifths. But the figure that matters most for a site about this trade is a different one. Employment in informatics and automation went from about forty-two thousand people to about seventy-four thousand in five years. Whatever those companies were building, they were hiring and training, and a generation learned the trade inside them. When the law expired most of the manufacturers did not survive open competition, but the people did, and they went into the distributors, integrators, carriers and banks that appear all over this timeline. There is a second finding too, and it is not a coincidence: three of the largest surviving names were absorbed by banks and turned to banking automation, which is a substantial part of why Brazilian banking technology became unusually advanced. An industry that could not compete on hardware was reabsorbed by its biggest customers and became very good at exactly one thing.

    • Contenuto

      The research centre that outlived the state, and the piece that became part of a bigger piece

      Two additions to the Brazilian telecommunications story, both suggested by a reader and both worth having. The first is the research centre founded inside the state monopoly in 1976, with a brief that was industrial rather than academic: develop domestic technology so the country buys less of it abroad. Plenty of countries ran state telecommunications monopolies; rather fewer built a research institute inside one and told it to produce technology rather than papers. Then the customer was dismantled. When the system was split and sold in 1998, an in-house research centre serving a monopoly had no obvious place in the arrangement, so it became an independent foundation and had to sell its work to operators that were now competing with each other. Most institutions built for one guaranteed customer do not survive that lesson. This one has been going for around three decades since, and it is useful to competing operators for the same reason a carrier-neutral exchange is useful to competing carriers: because it belongs to none of them. The second addition is one of the twelve pieces the privatisation created, and its history is the argument in miniature. The system was split to create competition, and within eleven years the pieces were buying each other: this one was absorbed by another of the three fixed-line holdings in 2009. Whether that is a failure of the design or simply what telecommunications does is a fair question, and the entry declines to answer it, noting that the same consolidation happened in countries that privatised differently and in some that did not privatise at all.

    • Contenuto

      Nine hundred telephone companies became one, then twelve, then a handful

      Before 1972 there were more than nine hundred telecommunications companies operating in Brazil, which in a country of continental scale meant nine hundred technical standards, numbering plans and interconnection arrangements. A law that July authorised a single state holding company, and within a few years it had absorbed nearly all of them into one system. One figure captures both what that achieved and the argument that followed: installing a telephone line cost about five thousand dollars in the nineteen-seventies and about twenty by 1998. The heavy infrastructure had been built and the technology had changed underneath it, which is exactly why private capital, uninterested for decades, became interested. The system was sold in a single auction in July 1998, split into twelve holdings, and it remains the largest privatisation in the country's history. What happened to the long-distance carrier afterwards is the part worth following: it was bought by an American company, which filed for what was then the largest corporate bankruptcy in American history, was sold under a New York court's approval to a Mexican group, and was absorbed into one of that group's brands in 2015. A state carrier passed from Brazil to the United States to Mexico in seventeen years. Whether the whole arc is a success or a loss is still argued about, and this entry does not settle it. The figures are verifiable and the judgement is not a technical question. One institution outlived the system that created it: the research centre founded in 1976 has operated independently since privatisation and still exists.

    • Contenuto

      A company owned entirely by the people who work there, and the loop it closes

      A Brazilian engineering firm founded in 1960 as a joint venture between an American company and a Brazilian one, formed to build four units at a refinery. Both original partners eventually left, and what remained is the unusual part: its only shareholders are the professionals who work there, or who used to. Not a founding family, not a fund, not a public float. People doing the work own the firm and join the shareholding voluntarily, a model that has held since the nineteen-seventies and is reinforced by a pension foundation created in 1975 exclusively for people who work or have worked in the group. There is a cultural charter to go with it, written in the same period, and the reason such a document exists is worth stating: a firm owned by its staff has to write down what it is for, because there is no proprietor to decide. In 2008 the group's technology arm merged with a British integrator's Latin American operations to form what was then the largest independent integrator in the region. That closes a thread this site opened last week, because the British integrator belonged to the same South African holding company as the distributor written up a few days ago: distribution and integration were sibling divisions. So the integrator's Latin American arm is half-owned by a firm whose shareholders are its own employees, which puts two opposite theories of who should own a company inside one business. The entry also records that the engineering company was drawn into a large corruption investigation from 2014 and barred by the state oil company from new contracts, because leaving that out would misrepresent the group's history.

    • Contenuto

      The oldest distributor here, and the one whose history is least about strategy

      It began in 1935 as a shop selling second-hand radios on a street in lower Manhattan where two of the neighbours also went on to put their names on distribution businesses, which is why that street has a fair claim to being where electronics distribution started. The company as it exists dates from 1968, when three recent business school graduates borrowed a million dollars to buy control, and also bought a business that reclaimed lead from old car batteries, which tells you something about the state of the opportunity as they found it. On an afternoon in December 1980 the senior management team met at a hotel conference centre for the annual budget meetings, and a fire in the building killed thirteen of them, including the chairman, an executive vice president and every department head of the distribution division. One member of the senior team survived because he was not there: he had stayed at the office to answer questions about a stock split announced that morning. The day afterwards the chairman's widow came to headquarters and spoke to the staff, telling them she did not know their faces but would know their names, because her husband had talked about them. The company recovered over about three years under the survivor, who recruited a stranger from a consulting firm to help. That episode is why this entry ends where it does. Every other distributor written up here has a strategy at its centre, whether a thesis about which products to carry or a decision to buy rather than build. This one's defining moment was something nobody planned for, and it demonstrates two things at once that no strategy document covers: that an organisation is not only its people, since this one lost thirteen of its most senior in an afternoon and still existed three years later, and that it is nothing but its people, since getting there took three years and an outsider.

    • Contenuto

      The milestones page nearly doubles, and several entries explain things you use today

      Forty-one entries now, across the five strands, from 1800 to 1991. The additions include several where the reason for including them is a thing still visible in current work. A loom from 1804 is here because it is the first separation of a program from the machine that runs it: the loom does not know what it is weaving, the cards do. An algebra published in 1854 sat unused for eighty-three years before someone noticed it described switching circuits, which is worth remembering about anything currently filed as impractical. A cardboard rectangle from 1928 held eighty characters, and that is why terminals are eighty columns wide and why so much software still assumes an eighty-character line, long after the last card was punched. Formats outlive their reasons. There is a gigabyte drive from 1980 included purely as a yardstick, because a capacity that needed a refrigerator-sized cabinet and a six-figure price then now costs less than lunch and fits on a fingernail, and every architectural assumption made when storage was scarce was made under the earlier conditions. And there is a hard protocol cutover on a live network on the first of January 1983, which nobody would attempt today, and which remains the best demonstration available that migrations succeed when the deadline is real and everyone has the same one.

    • Contenuto

      Two additions: a role nobody writes down, and the ground the whole industry stands on

      The first is an account of what a channel systems engineer actually does, which is close to undocumented despite being one of the places the industry trains its pre-sales engineers. One fact reframes the whole job: some of the resellers being supported have no technical staff at all, so the distributor's engineer does the technical work on their behalf, usually without the customer ever knowing. The bill of materials section is the heart of it, because that is where the value concentrates and where the failure is expensive: a wrong list does not fail at quote time, it fails on the loading dock, or six weeks later when a feature turns out to need a licence, and by then the reseller has a margin problem and a credibility problem in the same conversation. The second addition is a separate history: the physics and engineering the company timeline sits on top of, from a stack of zinc and copper discs in 1800 to the first fibre across the Atlantic. It is a separate page rather than more cards on the existing one, because the existing page is about firms and none of these are firms. The test for inclusion is deliberately narrow and printed on the page itself: not important events in science, but whether a network engineer's working day could be explained without it. Every entry says why it matters rather than only what happened, so the compass needle that moved in 1820 is filed as the reason crosstalk exists, the induction result of 1831 as the reason twisted pair works, and the channel capacity theorem as the reason a noisy link is not merely a worse link but a link with a number attached that no amount of engineering will argue with. Three entries carry dating caveats instead of false confidence, including a famous 1901 radio reception whose evidence has been questioned ever since.

    • Contenuto

      Sold father to son for ten thousand dollars, now the largest distributor in the world

      A man incorporated a company in Florida in 1974 to sell tapes and disks for mainframes, and around 1984 he sold it to his son for ten thousand dollars. That is not a rounding error inside a larger deal, it is the whole transaction, and it is the kind of detail that disappears once a company grows large enough for its history to be written by its communications department. The son then did the thing that mattered, turning a reseller of mainframe supplies into a national distributor of personal computer products, which is a different business wearing the same name. Nearly fifty years later the company it became reported fifty-eight billion dollars of revenue. This entry also closes a circle across the distributor entries added this week. One of them sold its Americas business in 2017 to a company that four years later merged with this one, which means that operation now sits inside the largest technology distributor in the world, alongside the Florida company and the Californian contract assembler that started as something else entirely. Four of the five distributors written up here are connected by ownership, and the fifth competes with the result while having assembled its own Latin American business by exactly the same method. It is worth being plain about what these companies are, since nothing an engineer buys arrives without passing through one: they are not technology companies in any useful sense, they are logistics and credit businesses that happen to move technology, holding inventory on their own balance sheets so a reseller does not have to.

    • Contenuto

      Two schoolteachers, and the third teaching origin on this timeline

      The largest technology distributor in the world was started in 1979 by a husband and wife who were both schoolteachers, and its own corporate history says they brought an academic approach to logistics. That is the third teaching origin here, after a Brazilian company founded by a man already giving classes whose training business became the technology business, and an Indian founder who started a training institute because a domestic industry cannot grow faster than the supply of people who can staff it. Three is enough to call it a pattern rather than a coincidence, and the reason is not sentimental: distribution and instruction share a discipline, since both are about getting something complicated from the people who made it to the people who need it, in a form they can use. The entry also makes a contrast the site has been asserting and can now show. The specialist distributor added a few days ago built its whole strategy on catching products while they were still transitioning, arriving before the broadline houses turned up to sell on price. This is the broadline house. Its own filings describe the business as inventory-intensive and capital-intensive rather than asset-light, because it buys hardware and software and holds them on its balance sheet. The specialist sells expertise and the broadline distributor sells scale, and the two are not really competing until a category has finished transitioning. One footnote reaches further than the rest: the family business that assembled all this dates to the eighteen-thirties and made its money in lumber and shipping, then petroleum, barges and books. Computer products were a nineteen-eighties diversification for a company that had been moving other people's goods for a century and a half, which is a fair description of what distribution is.

    • Contenuto

      One acquisition was the vehicle for the next

      A reader suggested the lineage of a Brazilian distributor was worth adding, and it turned out better than expected. The American specialist distributor added to this timeline yesterday did not build a Latin American business. It bought one in 2011, and then in 2014 it used that purchase to buy a second, much larger one: the acquisition was made through the Brazilian subsidiary it had acquired three years earlier. Anyone who worked for the American company in Brazil after that was working inside what had been the Brazilian one, under a hyphenated brand that lasted years. The entry also records what the deal bought geographically, which is the part that matters in distribution and rarely gets written down: units in three additional states, added to an existing presence in two, because serving a reseller in Recife from Sao Paulo is a different proposition from serving one down the road. Two revenue figures appear rather than one, because both are correct on different accounting bases, and the entry says so instead of picking the larger. And a correction is recorded openly in the source: the first draft of this entry carried a founding year that no source stated and that had simply been filled in because the field wanted a number. The real year came from the acquirer's own release. A field that wants a value is not a reason to supply one.

    • Contenuto

      A distributor with an actual strategy, and the clearest statement of what distribution sells

      Most company descriptions of distributors describe what they do rather than what they decided. This one had a thesis, stated by its founder and still legible three decades later: distribute products that are transitioning, and try to arrive first. He named the two transitions he was hunting, proprietary moving to open and expensive moving to cheap, and the aim was to catch a category on its way to becoming a commodity, while a specialist channel still needed it explained to them and before the broadline houses turned up to sell it on price. The arbitrage underneath that is the clearest illustration of what a distributor actually sells. The number of barcode-focused resellers was in the hundreds. The number of computer-focused resellers was in the hundreds of thousands. What the company offered the barcode manufacturers was not a warehouse, it was access to a channel three orders of magnitude larger than the one they already knew. Everything else follows from it, including the rule never to sell directly to an end customer, because a distributor that competes with its resellers is discovered quickly and resellers can count. Read beside the distributor added yesterday, the pair are usefully different: one went deep on networking and security, this one went deep on things that read and print and then followed its resellers outward. Neither tried to carry everything, which is what separates a specialist from the broadline houses whose arrival in a category is the sign the transition is over.

    • Contenuto

      The first distributor, and what that layer actually does

      Until now the industry timeline had a filter for distributors with nothing behind it. The first entry fills it, and takes the opportunity to explain the layer, because it is the one most engineers have never had to picture. A vendor does not want a commercial relationship with every reseller in every country, since the credit checks alone would be a business. A reseller does not want a separate contract, currency, logistics arrangement and support escalation with each of the forty vendors it carries. The distributor sits between them and absorbs that, holding stock, extending credit, handling customs, and training resellers on products they have just started selling. That training is why this belongs on a site about teaching: a vendor's course is aimed at the vendor's priorities, while a distributor's enablement is aimed at whatever its resellers are failing to sell, and the second tells you more about what the market is actually struggling with. The strategic consequence is larger than it looks. A distributor decides what is practical to buy in a country, because a product with no local distribution is not unavailable so much as awkward, and awkward means the reseller quotes something else. Regional market share often reflects distribution agreements more than it reflects the product. There is also a connection worth following: the same holding company owned both this distributor and a large integrator, so two layers of the same supply chain answered to the same shareholders.

    • Nuovo strumento

      Two tools for one expression language, from opposite ends

      OGNL is an expression language for reaching into a running Java application and calling methods on it. That single property makes it a useful configuration feature in one product and the vehicle for a famous family of remote code execution flaws in another, and the two new tools take it from each end. The first reads a payload you have already found in a log and explains what it was trying to do. It separates two things that are usually run together: an attempt to switch off the expression sandbox, and an attempt to run a command. A payload with both is a real exploitation attempt. One with only the command is usually a scanner working through a list, because a patched runtime refuses it. One with neither, just expression syntax, is a probe asking whether input gets evaluated at all, which is the cheapest and most informative request an attacker can send and the one most often dismissed as noise. The tool decodes and never generates, holds no payload templates, and always shows what it did not determine, because the most dangerous way to read that page is to see nothing and conclude everything is fine. The second reads an expression somebody wrote on purpose, in attribute mappings and issuance criteria, and flags what tends to break in production rather than in testing: attributes read without a null check, because the accounts used for testing are tidier than the directory; static Java calls, because the construct that formats a date reaches a great deal more than a date; and criteria that do not actually compare anything, which fail quietly in ways that look like an authorisation problem somewhere else. Neither tool evaluates anything, and for the second that is the whole point, since an expression explainer that evaluated expressions would be exactly the code execution service the product gates behind its own administrative role.

      OGNL injection decoder · PingFederate OGNL explainer

    • Funzionalità

      The industry timeline can now be filtered by what a company actually is

      Eight filtered views now exist, one per tag, and they are views rather than lists. Tag a company and it appears; untag it and it leaves. That distinction is the whole reason the distributor and reseller pages were built this way instead of as separate pages somebody keeps up to date, because a list maintained by hand drifts the moment someone adds a company and forgets it. Each card also shows the other tags its company holds, so a reader can move sideways instead of going back. Filter chips sit above the main timeline with counts that are computed rather than written, so a chip cannot promise a number the page then contradicts, and a chip whose count is zero is not shown at all, because a filter leading to an empty page is a broken promise. There is one trap worth recording. Company pages and these lists share the same address pattern, since two variable segments cannot sit at the same level, which means a company whose name matched one of the filter words would be completely unreachable: the list would win, the company would never appear, and nothing would say so. All eight words are currently free and a build check now enforces that permanently against both company and career names.

    • Infrastruttura

      Every company on the timeline now says what kind of company it is

      All hundred and twenty-nine entries carry tags from a closed vocabulary of eight: vendor, distributor, reseller, services, carrier, data centre, training and standards. Twenty-one hold more than one, which is the reason for tags rather than a single category, because a company can genuinely be several things at once and the old field could only ever say one. It said very little in practice, holding just three values across the whole set. Two entries turned out to be worth their own thought. One is a company that both made computers and sold them through seven thousand shops of its own, so it is a vendor and a reseller, and that combination is exactly why it outsold a better machine. Another is a data centre training body, which is only the second training entry on a site built by an instructor. The tags also change how two promised pages will work. A list of distributors maintained by hand drifts the moment somebody adds a company and forgets the list; a filter cannot. So those pages become views of the data rather than copies of it. A new build check enforces the vocabulary, requires every entry to carry at least one tag, rejects repeats, and reads the list of valid tags from the source rather than keeping its own copy, because a check that disagrees with the thing it checks is worse than no check.

    • Funzionalità

      The apparent urgency block was four stacked things doing one thing's work

      A heading, a large number, a bar and a comment, each on its own line, taking four times the height the information needed. They are now one row: the label, the figure, the bar filling whatever space is left, and the remark beside it, wrapping onto more lines only when the screen is genuinely too narrow. The figure also shrank, from the size used for the answer to something smaller. That was deliberate rather than incidental. The subtotal was competing with the answer for attention while being the less important of the two, and on a page whose joke depends on one number mattering and the other not, the typography should not argue the opposite. The bar now stretches rather than keeping its proportions, which for a progress indicator is the right trade: its job is to show how far along something is, and nothing about that is harmed by being wider or thinner.

    • Infrastruttura

      A company briefly had two entries, which on a timeline about lineage is the worst kind of error

      An entry was written for a company that already had one, under a slightly different address, so for a short while the same firm appeared twice on a page whose entire purpose is being accurate about who is who. It has been removed and the one detail the surviving entry lacked was folded into it. Two things about the removal are worth recording. The first attempt used a comment marker to find the block to delete, and a safety check refused to run because the boundaries it produced contained the entry that was meant to be kept. That check was the only thing standing between a careless edit and deleting the wrong company. The second attempt found the block by matching braces outward from the slug itself and verified the result contained exactly one entry before touching anything. The other lesson is duller and more useful: check whether a company is already present before writing about it, using the name rather than the address, because the address is exactly the thing that can differ. A sweep for repeated names across the whole file came back clean afterwards, with the apparent repeats turning out to be companies that have their own entry and also appear inside somebody else's list of acquisitions, which is correct and is the point of that structure.

    • Contenuto

      Accenture, and the luckiest defeat in the history of consulting

      The consultants spent years fighting to separate from the accounting firm they had grown inside, and in August 2000 the arbitrator ruled against them on the question they had actually asked, finding no technical breach of the agreement. He granted the separation anyway, but required them to pay around a billion dollars and to give up the Andersen name entirely within five months. They renamed through an internal competition, adopted a coinage meaning accent on the future that was widely mocked as management consultant nonsense, and spent somewhere between a hundred and a hundred and seventy five million dollars executing and promoting it. Then came Enron. Within eighteen months the accounting firm was convicted on an obstruction charge and collapsed, and a name that had signified eighty years of professional respectability became a synonym for shredded documents. So the thing they experienced as a defeat, losing a brand they had fought to keep, turned out to be the most valuable event in their history. The precise mechanism is the part with a lesson in it: the ruling did not merely rename them, it established them as a legally separate entity, which is why a criminal conviction on one side did not reach across and take the consultancy with it. The firewall was a condition they resented and it is what saved them. One older detail is worth keeping too. In 1953 the practice ran a feasibility study for General Electric that led to a UNIVAC installation, among the first uses of a computer for ordinary business administration rather than science or defence.

    • Contenuto

      Honeywell, which owned the operating system that Unix was named against

      Most people know this company as thermostats and aeroplane parts, and for thirty-five years it was a computer manufacturer. It entered through a joint venture in 1955, and through the sixties was one of the firms collectively nicknamed Snow White and the Seven Dwarfs, with IBM as Snow White. When the field thinned to five the survivors were renamed after their initials, and it was the H in the BUNCH. Then in 1970 it bought General Electric's computer division, which is the transaction that earns it a place on a site about networks and systems, because it inherited an operating system project called Multics. That system was enormously ambitious and it set the standard for what a shared machine should do about security in particular: rings of protection, access control on segments, and the principle that a computer used by mutually distrustful people needs the operating system itself to enforce that distrust. Its influence on Unix is not vague inheritance. The name Unix was coined in deliberate contrast to it, so every Unix-derived system running today, including the ones this site's own tools execute on, sits downstream of an argument about Multics. The company left computing entirely by 1991 and went back to controlling physical things, and there is a neat closing of the circle in what it does now: it is an investor in a company that appears elsewhere on this timeline for monitoring industrial control systems. The firm that once ran the operating system which taught the industry about protection domains now helps fund the people watching its own controllers for intrusions.

    • Contenuto

      Nozomi, and why you cannot scan an industrial network

      The first entry here about operational technology security, and the constraint that defines the whole category is the place to start because it explains the product. In ordinary security you find out what is on a network by scanning it, sending traffic to a device and reading what comes back. On an industrial control network you cannot. A controller running a production line may be twenty years old, may have a network stack that predates the idea of hostile input, and can be knocked over by an unexpected packet. The scan that safely inventories your office can stop a plant. So the category had to be built the other way round, passively, watching traffic that is already flowing and inferring what exists from it. Industrial networks give one advantage in return: an office network is chaos, but a bottling line does roughly the same thing every day, so an anomaly actually means something. The company was founded in Switzerland in 2013 by an industrial security engineer and an artificial intelligence researcher, which is the exact pair of backgrounds the problem needed. It has just been bought by a manufacturer of industrial automation equipment for around a billion dollars, and says its vendor neutrality is unaffected. That claim deserves attention rather than acceptance, because the company's product monitors industrial automation equipment including, necessarily, its new owner's, and the strategic investors before the acquisition were already three more vendors of the same equipment. It may well be right. The point is that the assertion is the thing to watch, and the answer arrives over years in whether its findings about one vendor's kit read the same as its findings about another's.

    • Funzionalità

      The importance meter now takes you to the answer instead of leaving you to find it

      Pressing calculate could reveal everything below the fold, which means a reader pressed a button and nothing visibly happened. That is the worst outcome available to a page whose entire payload is what appears next, so it now scrolls to the result once the blocks have mounted. Reset is red and outlined rather than filled, because it is the destructive half of the pair and should be visibly present without being the thing your eye goes to. And the centring is finally right. Earlier attempts named individual pieces and kept missing others, so the calculation line, the list of contributions, the note about the coefficient and the reading list were all still sitting left while everything around them was centred. Naming things one at a time was the wrong approach; the rule now centres everything inside a result block and then handles the two cases that need it, which are list items carrying their default padding and links that need to behave as blocks to centre at all.

    • Contenuto

      Compugraf, whose name stopped describing it around 1995

      The name is the story. It was registered in Sao Paulo in April 1982 to do computer graphics, which is what the name means in Portuguese, and somewhere in the nineties it moved into information security and then stayed there for three decades under a name that no longer described it. That is more common in this industry than the tidy histories suggest, because companies rarely rename when their business changes: the name is the thing customers already trust, so the trading name becomes a fossil of what the company used to do. It finally renamed in 2024, keeping the initials and dropping the word. This entry is also deliberately shorter than its neighbours, and the reason is worth stating openly. Sourcing for Brazilian integrators of this size is thin compared with the international companies elsewhere on this timeline. The founding date comes from the commercial register, which is authoritative for exactly that and for very little else. The account of the pivot is the company's own, repeated by directories, and is labelled that way. No revenue figure appears at all, because the only one available came from a contact-data aggregator rather than a filing, and a number with no provenance is worse than no number. An entry should be as long as its evidence rather than as long as the ones around it.

    • Contenuto

      Equinix, which discovered that neutrality could be sold by the square foot

      Two facilities managers left Digital Equipment Corporation in 1998 to solve a problem that was really about governance rather than capacity. Networks have to meet somewhere to exchange traffic, and in the nineties the places they met were largely owned by carriers who were also participants. A referee playing in the game favours his own traffic, whether by design or by ordinary self-interest, so the answer was a building owned by somebody with no network at all. If the landlord sells no transit and competes with none of the tenants, rivals can meet inside without either conceding anything. Neutrality here is not a virtue the company advertises, it is the product, and it is in the name, which compresses equality, neutrality and internet exchange into eight letters. The exchange where they proved the idea ran on a DELNI in its earliest days, an office ethernet concentrator pressed into service as a meeting point for the commercial internet, and one of their colleagues there wrote BIND. The business insight came slightly later and matters more: they began by selling floor space and discovered the money was in the cable between two tenants, because a customer chooses a building for who is already inside it and every new tenant makes it more valuable to the next. That is a network effect expressed in concrete and copper. There is also a loop worth enjoying. They left because the exchange they ran belonged to their employer, and twelve years later their company acquired it.

    • Contenuto

      TIVIT, which did not start in a garage but was assembled from parts

      The man behind it spent ten years as a professional tennis player before going into business, and his first venture as an investor was a combined brewery and nightclub. Shortly afterwards, with four partners and a hundred and fifty thousand reais, he started a call centre company, sold a fifth of it to a large industrial group's investment arm, and kept pressing an idea: that a customer should be able to buy every kind of technology service from one supplier instead of assembling one from many. The investment arm eventually decided it already owned the pieces to build that, merged two companies from its own portfolio, and named the result TIVIT. So this company did not start in a spare room. It arrived fully formed in 2005 with two thousand employees and two hundred clients including the national oil company. One detail deserves keeping: when it listed in 2009, after two earlier attempts abandoned for market conditions, it was the only technology services company on the Brazilian exchange. The others were hardware makers or software houses. A services business is harder to explain to public markets than a factory, and for a while nobody else tried. It did not stay public long, because a private equity firm bought control the following year in what was its first Brazilian investment. Read against the entry published yesterday, the two make opposite constructions of the same thing: one grew outward for decades from a teacher's spare room, the other was assembled by a holding company that decided the market wanted something. Neither could have been built the other's way.

    • Contenuto

      Stefanini, which was a training company before it was a technology company

      A geologist who had spent a month at a tin mine in the interior of Goias and decided the profession was not for him moved into technology at his sister's suggestion, took a systems analysis course, worked in a bank's IT department, and in 1987 started a company in a bedroom of his own house at the age of twenty-six. It was not a consultancy. It was a training business, running programming courses for the staff of large companies, and it only became an IT consultancy about two years later. The detail that matters is why training was the obvious place to start: he was already teaching, and in his own account that skill is what won the first projects. A teacher's business became a technology business rather than the other way round. The first office was thirty-eight square metres. Brazil's banks and industrial groups were computerising, and a firm that could both train people and supply them was not short of work. What happened next is genuinely unusual, because it went abroad, and Brazilian technology companies mostly did not. It now reports operations in forty-one countries and more than thirty-five thousand staff, in a sector where the multinationals almost always arrive from somewhere else rather than departing from here. Read beside the entry on the Indian company that bought Lotus Notes, the two make an inverted pair: there a technology founder started a training institute because an industry cannot grow faster than the supply of people who can staff it, and here the training came first and the business grew out of it. Both arrived at the same conclusion, that teaching and technology services are one trade approached from opposite ends.

    • Infrastruttura

      The explanatory note was itself the spoiler

      The note added yesterday for readers whose first language is not English was deliberately left outside the calculate gate, on the reasoning that it is context rather than result and therefore harmless above the fold. That reasoning was wrong for one decisive reason: the note quotes the phrase. Anything that quotes the phrase gives the ending away regardless of which category it belongs to, and a category argument is no defence against a reader who can simply see the words. It is now gated with everything else and appears only after the answer it explains. Everything below the inputs is also properly centred now, including the workings, the method note, the override banner and the reading list, with the prose held to a readable column width rather than stretched across the full page. The lesson worth keeping is that the test for a spoiler is not what a block is for, it is what a block contains.

    • Funzionalità

      The calculate button looked like it had already been pressed

      A screenshot made the problem obvious in a way the description had not. Two things were working against the button. The first was mine to own: the apparent urgency figure was still updating live, so the page had visibly already produced a number, and a page that has produced a number looks like a page whose button has been pressed. I had kept that live on purpose, to build anticipation before the answer refused to arrive, and it simply did not survive contact with a real screen. Nothing appears now until it is asked for. The second was a collision of visual language. The yes and no choosers use a filled accent to mean this is the current state, so a filled accent button in the same colour reads as a state too, not as an instruction. The button is now its own control rather than a generic one: larger, wider, in the same amber as the answer it produces, with a downward arrow pointing at where that answer will appear, and a slow pulse while it is still waiting. Nothing else on the page moves, which makes the movement unambiguous. The pulse stops the moment it is used, and it is replaced by a static ring for readers who have asked their system to reduce motion.

    • Contenuto

      Kyndryl, where independence was the product rather than the consolation

      IBM separated its managed infrastructure business in November 2021, sending ninety thousand people into the largest technology spin-off by headcount. The reason usually given is decline, and it is true as far as it goes: inside IBM the unit had struggled through the cloud era, because customers were moving workloads to hyperscalers and few had any appetite left for the long outsourcing contracts it was built around. The more interesting reason is structural. A managed services business owned by a cloud vendor cannot credibly recommend a competitor's cloud, because whatever its engineers actually think, the advice arrives from a company whose parent sells the alternative and the customer discounts it accordingly. Independence was not the consolation prize for being unwanted. It was the thing that made the business sellable again, and the evidence is in the calendar: it announced a partnership with one hyperscaler the same month it separated and another the following month, neither of which was available to a division of IBM. That is the same argument this site records elsewhere in a different setting, where a certification body's value rests on belonging to no vendor and the open question is whether that survives being bought. This is the mirror image, a business whose advice was worth less while it was owned and worth more once it was not. In both cases the asset is neutrality, and neutrality turns out to be a property of who owns you rather than of what you know.

    • Contenuto

      A note on the phrase, for readers whose first language is not English

      The importance meter now ends with an explanation of the expression it is built around, because a page that is only funny if you already know the idiom is not much use to a site read in sixteen languages. The note says what the phrase means, which is complete indifference, that it is vulgar but used humorously far more often than aggressively, and that it is usually aimed at bureaucracy and pointless urgency rather than at people. It also makes the point that the idea is not particular to English at all. Most European languages have their own version of the same shrug, built variously from food, animals, weather or anatomy, and a fair number are considerably more colourful than the English one. The advice that actually matters is about register rather than vocabulary: it belongs in casual speech among people who know each other, and not in a customer email or anything carrying your employer's name. Three references are linked for anyone who wants to read further. The note sits outside the calculate gate, since it is context rather than result, and it is placed last so it does not give anything away.

    • Infrastruttura

      Nothing was checking that the two main languages carried the same keys

      The request was to teach the language-parity check about an exception. It could not be taught, because it checks articles rather than interface strings, and it turned out that nothing at all was checking those. A key added to English and forgotten in Portuguese would ship a page that showed Brazilian readers the raw key name, and every existing check would have stayed green while it did. That is not hypothetical: it happened this month, when a card was written with the wrong field name, and the only thing that caught it was a count in the build log which only notices keys that a page built that day actually reads. There is now a check for it, and it does three things. It compares the two languages in both directions, so an orphaned translation is caught as well as a missing one. It compares nested structure rather than top-level names, so a key buried three levels down cannot slip through. And it carries a short list of namespaces that are English by design, currently containing one entry, for a page whose joke is an idiom that does not survive translation. That list also validates itself: if something on it turns out to exist in Portuguese after all, the check fails, because a stale exception hides exactly the drift it was meant to permit. Nearly ten thousand keys are compared on every build.

    • Contenuto

      The importance meter is now English only, and says its unit properly

      The unit now sits directly under the answer at the same size and in the same colour, so the two read as one statement rather than a figure with a caption underneath it, and the note about local computation has gone because it was doing nothing there. Everything below the result is centred. The line explaining the deadline weighting used to describe how the number felt; it now tells you how long you actually have, in minutes when that is under an hour, because nobody says nought point five hours. And the Portuguese version of this page is gone. The joke is an English idiom and it did not survive translation: rendered literally it read as a description of a rude phrase rather than as a deadpan corporate instrument, which is the opposite of funny. The page now generates in English only and every other language redirects there rather than hitting a dead end. It is the only page on the site that opts out of the language set, and it does so because the content genuinely cannot be localised rather than because translating it was inconvenient.

    • Funzionalità

      Fullscreen for the importance meter

      The meter can now take over the screen, which suits a page whose whole point is two gauges disagreeing with each other. It follows the approach already used by the mega brain rather than inventing a second one, and that approach exists for a specific reason: Safari on iPhone will not put an arbitrary element into fullscreen, so there is a styling fallback that produces the same result when the real interface is unavailable or declines. Both paths are styled identically, so a reader cannot tell which one they got. The button also listens for the browser's own fullscreen change, so leaving with the escape key updates it correctly instead of leaving it claiming to be in a state it is not. In fullscreen the answer grows, the dial grows, and the input columns widen.

    • Infrastruttura

      A shorter address for the importance meter

      The short address for the importance meter is now two letters, matching the pattern already used by the other two toys. The longer form it replaces was added a day earlier and never published anywhere, so nothing external pointed at it and dropping it costs nothing.

    • Contenuto

      ArcSight, and two opposite bets on the same problem

      A large network produces millions of log lines a day in a dozen formats, none of which means anything alone. A failed login is noise. Four hundred failed logins from one address, then one success, then an outbound transfer, is an incident, and somebody has to notice the difference at three in the morning. ArcSight's answer was to normalise every event into a common shape first, so a firewall denial and a Windows audit failure became comparable, and then run correlation rules across the stream. That is a real commitment, because the rules encode what you already know matters, which means deciding in advance what an incident looks like. Read that against the other entry on this site from the same era and you get two opposite bets. One indexed the raw data and let you search it afterwards, deciding what mattered once you had a reason to ask. The other decided first and then watched. Rules catch what you anticipated at the moment it happens; search finds what you did not anticipate, after you know to look. Neither is wrong and most mature teams end up running something of each. What differed was the ending. The one that stayed independent for two decades was eventually bought as a strategic centrepiece for a very large sum. This one sold early, in 2010, and was then carried through three further transactions as a line item in somebody else's portfolio, ending up with its fourth owner in thirteen years, none of whom wrote it. Same market, same era, comparable achievement, and the difference had more to do with when each sold than with which design was better.

    • Infrastruttura

      A page that listens for typed sequences now owns the alphabet

      A reader pointed out that one of the hidden sequences could never be completed, and the reason turned out to be worse than a conflict. The site binds single letters to navigation, and one of those letters appears in the sequence, so pressing it did not merely compete with the code, it navigated away before the next key could arrive. The sequence was impossible on every page, not inconvenient. Pages that listen for their own typed input now claim the alphabet while they are open and release it when you leave. Punctuation is deliberately untouched, so search, help and the context panel keep working, and Escape is never affected. The result on the importance meter is now amber rather than the site accent, because it is the punchline and deserves to read as its own thing, and the result blocks are centred while the inputs stay left-aligned where they belong. The needle, the hub and the zero on the dial follow the same amber, using the existing theme token so it still adapts across all six palettes rather than hard-coding a colour.

    • Funzionalità

      The importance meter stopped answering questions nobody had asked

      Making it recompute live was a mistake, and a reader caught it immediately: the answer was sitting there before anyone had typed a thing, which gives away the ending on arrival. The calculate button is back, the result stays hidden until it is asked for, and touching any input hides it again, so the answer is always something the reader requested rather than something the page volunteered. One thing deliberately stays live, and it is worth saying why. The bar showing apparent urgency is not the result; it is the sum of what you entered, the way a calculator shows your working before you press equals. Watching it climb as you copy more people in and pull the deadline closer is what builds the expectation that the answer then declines to meet, and that only works if the climbing happens while you are still typing. The line at the bottom about the page being unlisted is gone, and there is now a breadcrumb trail at the top, because a page nobody links to is exactly the page a reader most needs a way out of.

    • Contenuto

      CompTIA, whose entire value was being owned by nobody

      It began in 1982 as a trade group for computer dealers, and that origin explains the whole organisation. Dealers sold hardware from many manufacturers at once, so what they needed was not another manufacturer's badge but a standard belonging to none of them. Vendor neutrality was the founding condition rather than a marketing position adopted later. Read beside the Cisco entry already here, the two halves of an argument appear. Cisco's certification ladder created the vendor-defined model that every vendor on this site copies, including the four whose official training the author of this site delivers. This is the other answer to the same question, that a technician's competence belongs to the technician rather than to a supplier relationship, and both models are still standing. One detail matters to anyone who teaches: the vendor-neutral credential for the act of instruction itself was retired at the end of October 2023, with no direct replacement, so the one widely recognised qualification for teaching technology independent of what was being taught no longer exists. And then the unresolved part. In November 2024 two private equity firms agreed to buy the brand and the certification business, ending forty-two years as a non-profit and splitting the organisation in two. The company says nothing material changes and the accreditation and neutrality remain. Practitioners in its own instructor community were less sure, and their objection is specific rather than sentimental: the asset being bought is neutrality, and neutrality cannot be bought without raising the question of whether it survived the purchase. This page does not resolve that, because it is not yet resolvable. The answer arrives over years, in whether the exam objectives keep describing the job or start describing somebody's product.

    • Contenuto

      The importance meter stops spoiling its own ending

      The line under the title was giving away the punchline before anyone had entered anything, which ruins a joke that depends entirely on arriving at it. It now describes what the tool does without saying what it concludes, and the only place the answer's unit is named is at the bottom, beside the answer, which is where it belongs. The sliders introduced last time are gone as well. They looked good and they hid the exact number, and the exact number is precisely what the workings quote back at you line by line, so a control that obscured it was working against the page. Plain fields again. The questions now sit two to four across on a wide screen and stack on a narrow one, which cuts the height of the page by more than half and means the gauges are visible while you are still adjusting the inputs. That matters more than tidiness here, because the whole point is watching one gauge climb while the other refuses to move, and that only works if both are on screen at the same time as the controls.

    • Funzionalità

      Two cheat codes, and the shaking calmed down

      The vibration across the toys was too much, so every shake is now half as far and half as fast. That needed more care than it sounds, because the banners sit inside the shaking console and run the exact inverse animation at the same duration to appear still, so both sides had to be halved together or the banners would visibly drift. The importance meter now has a sequence you can type. Each correct key appears on screen and a wrong one wipes the whole thing, with no partial credit, and completing it replaces the coefficient that was always zero with one that is not. The tool stays honest in that mode: same sum, same multiplication, one constant with a different value, and the subtotal that was being annihilated finally does some work. There are seven of them with escalating multipliers, chosen from the subtotal so results still reproduce, and each carries its consequence, because there will be fucks given is only funny if the bill arrives too. One of them makes you the person people ask about this forever, at companies you have not joined yet. Another gives you full custody of the runbook, the postmortem template and the onboarding guide, and the escalation path for all three at three in the morning on a public holiday. The mega brain gets its own code, and it deliberately works during burnout and go-horse, because those are the states where the console has already given up and that is exactly when a cheat should be available. It clears both and restores capacity. And the meter now answers on a short address rather than the full path.

    • Funzionalità

      The importance meter gets two gauges that disagree with each other

      The toy that measures how much a request has actually earned your attention now works the way it should have from the start. Sliders instead of number fields, two-state choosers instead of dropdowns, and no button to press, because everything recomputes as you move it. That last part matters more than it sounds. There are now two gauges on the page. The first is a bar showing apparent urgency, and it climbs enthusiastically as you copy more people in, escalate further and pull the deadline closer, on a log scale so it keeps responding no matter how large the number gets. The second is a dial with a needle, and the needle never moves. Both are drawn from the same computation, which is the point: the dial is not faked or hard-coded, it is rendering the real total, and the real total is always zero. Watching one gauge race away while the other sits perfectly still is the entire joke, and it only works if they update together in front of you. There is also now a modest card for it on the index of the not-serious shelf, last in the row, with copy that describes what it measures without giving away what it concludes.

    • Contenuto

      FreeRADIUS, which authenticates a third of the internet and never went commercial

      In 1991 a non-profit internet provider needed to manage dial-in access across points of presence run by different organisations, without handing usernames and passwords to every access server. It wanted those servers to ask a central one and get back a yes or a no. A company in Pleasanton built that and called it Remote Authentication Dial-In User Service. The company was bought in 1997 and the server it had given away stopped being maintained, so a Dutch developer wrote a replacement, and in 1999 he and another developer forked that replacement into FreeRADIUS. So the software authenticating a large share of the internet today descends, by two forks, from a program written to solve one non-profit's dial-up problem. The numbers are the part people struggle with. A survey in 2006 put daily usage around a hundred million people, roughly a third of internet access at the time, and it underpins the roaming authentication network used by universities worldwide, so anyone who has connected to campus wireless in Europe has been authenticated by it. And it belongs beside three other entries here for what it did not do. One company closed its open source scanner to fund itself and was forked. One bought an open project and kept it open as a differentiator. One closed a project, was forked, and reopened it three years later. This one stayed open and became the thing everyone else builds against. Its founder has led it since 1999, which on a timeline mostly made of acquisitions and rebrands is the genuinely unusual fact.

    • Infrastruttura

      Two more headings that had been rendering with no styling

      While building something else, the same defect turned up on two of the toy pages: the main heading on the meeting bingo and cat distribution pages used a class name that exists in no stylesheet, so both had been rendering as plain browser defaults. Both now use a heading class that is actually defined. A sweep of every page and component under the developer section then turned up several more class names with no rules attached, and the honest finding is that most of them are fine. They sit alongside other classes that are styled, or on elements whose parent already sets the colour, font and spacing directly, which is what the retro screens do. Those are semantic hooks rather than mistakes, and changing them would be churn for its own sake. The distinction worth keeping is between a class that adds nothing to an already-styled element and a class that is the only one on an element, because the second means that element has no styling at all. Only the two headings were in the second category.

    • Contenuto

      HCL, which exists partly because IBM left India and later bought IBM's software

      India's foreign exchange rules in the nineteen seventies required multinationals to dilute their equity to local shareholders, and IBM left the country rather than comply. That removed the dominant supplier from a market with, by one contemporary count, about two hundred and fifty computers in it. A group of engineers from a textile company incorporated HCL in August 1976 into exactly that gap, working from a rooftop apartment in Delhi with about twenty-two thousand dollars, and funding the computers they wanted to build by selling calculators first. By 1978 they shipped an indigenously designed microcomputer, the same year as Apple's early machines and three years before the IBM PC. Then in 2019 the company completed a one point eight billion dollar purchase of seven IBM software products, including Notes and Domino, which is why Notes is still sold and supported today. So a company that exists partly because IBM withdrew now owns the software IBM had bought Lotus for in 1995, at roughly half what IBM paid, twenty-four years later. Two disagreements between sources are left visible rather than tidied. The founding roster is given as six people in some accounts and eight in others, and while four names appear everywhere the rest differ, so the four are named and the dispute is stated. And the acquisition is dated 2018 in some places and 2019 in others, which is simply announcement against completion, so both are given with their meanings attached.

    • Infrastruttura

      The career pages were shipping with no styling at all

      A reader pointed out that the body text on the career pages was unformatted, and it was: when those pages were created last week they were given class names that do not exist in any stylesheet. Every paragraph on all fifteen of them rendered as a plain browser default, with no line height, no spacing and no measure. The same mistake had reached the company pages, where the acquisition lists use the same markup as the vendor lineage pages but three of the class names had been invented rather than reused, so nested acquisitions sat unstyled inside otherwise styled rows. All of it now uses the classes that already existed and are already styled, and the one genuinely new class has been defined properly. There is a build check for precisely this failure, written after five similar incidents, and it did not catch this one. It only fails when a component is missing twelve or more classes, because it was built to detect an entire missing stylesheet rather than a handful of wrong names, and these components were missing four and five. That threshold is doing real work and lowering it would produce noise, so the honest description is that this class of error is caught by a person reading the page, which is what happened.

    • Contenuto

      Lotus, whose software outlasted the company, the buyer, and the buyer's strategy

      A reader pointed out that companies still run Lotus Notes today, and that is the spine of this entry. Two people founded Lotus in April 1982, one of them arriving from the company that distributed the first spreadsheet, and the other spending ten months writing its replacement in assembly language. Their business plan forecast a million dollars of sales in the first year. They did fifty-three million, and were the world's third largest microcomputer software company within eighteen months. Three threads on this site meet here. The Apple entry already names VisiCalc as the software that made a personal computer worth buying, and in 1985 Lotus acquired the company that wrote it and discontinued the product, so the successor bought the predecessor and switched it off. The Qualys entry already records a founder selling his email company to Lotus in 1991, before going on to run Qualys for twenty years. And the current owner of Notes is a company that has been sitting on the list of vendors still to add. IBM bought Lotus in 1995 for three and a half billion dollars, mainly to get Notes, and sold Notes on in 2018 for one point eight billion. Which leaves the observation worth carrying away, because it cuts against how this industry describes itself. Most companies on this timeline were bought for a technology that was quietly retired a few years later. This one was bought for a technology that outlasted the buyer's interest, the buyer's strategy, and eventually the buyer. One founder left in 1985 to write photo editing software and still ships it. The other dropped out of a masters degree to start the company and finished it in 2025, forty-six years later.

    • Contenuto

      Genesys, which began with a card game and a hundred and fifty thousand dollars from family

      Two men whose parents had fled the Soviet Union in 1980 met years later at a card game in San Francisco and founded a company in October 1990 with a hundred and fifty thousand dollars in loans from their families. One had studied civil engineering and worked for Steve Jobs at Pixar, which links this page to the Apple entry here, where that purchase of a graphics division is already recorded. The other had sold telephone systems. The idea was small and precise and turned out to be enormous. When a call arrived at a business in 1990, the phone system knew the number and the computer system knew the customer, and the two never spoke, so an agent answered, asked who you were, and typed it in, every time, for every call. Joining those two systems produced the screen pop, where the phone rings and the record is already open, and then something better than the pop: routing on skills rather than availability, so the question stops being whether a person is free and becomes whether the right person is free. That reframing is most of modern contact-centre design. Alcatel bought the company for one and a half billion dollars and it vanished into a telecommunications giant for twelve years, then private equity bought it back out for exactly the same figure. A company can be worth precisely what it cost a dozen years earlier, and that says more about who owned it than about what it built. There is a second connection too: Riverstone, a career chapter on this site, also ended up inside Alcatel-Lucent, by an entirely different route.

    • Contenuto

      Qualys, which had the idea first and completes a trio on a third axis

      Qualys launched its scanner in 2000, and what made it distinctive was not what it looked for but how it arrived. Everyone else sold software you installed; this was a subscription to a service, at a point when software as a service barely existed as a phrase. The argument was specific rather than fashionable. Vulnerability data ages badly, a scanner is only as good as its knowledge of what to look for, and installed software is exactly as current as its last update, which in most organisations is not very. A service updated centrally is current for everybody at once. That argument now appears five times on this timeline, about email reputation in 2002, web traffic in 2007, the web itself in 2009 and endpoint behaviour in 2013, and this is the earliest instance of it, which means the segment that worked it out first was vulnerability management. It also completes a trio on a third axis. Two other entries contrast the same market on open source, one company having closed a project to fund itself and another having bought one and kept it open. This one differs on something else entirely, in that it never shipped software to be run by the customer at all. And the man who ran it for two decades had already founded an email company in 1988, taken it to forty per cent of its market, sold it, taken another company public, and led a third into an acquisition, before spending twenty years here and a good deal of that time on industry work with no commercial return attached. He stepped down in March 2021 for health reasons and died three months later.

    • Contenuto

      Illumio, and the third piece of how the perimeter dissolved

      Two people met over lunch through a mutual friend, in what one of them describes as feeling like a blind date, and founded a company in January 2013 on a thesis the industry was not ready for: that perimeter security alone would never be enough, that breaches are inevitable, and that what an attacker can reach once inside deserves its own product. The technical decision that follows is the part worth understanding. Segmentation had always been a network problem, meaning VLANs and zones and firewalls between them, so a workload's security depended on where it happened to sit in the wiring. Illumio put enforcement at the workload instead, with policy computed centrally and pushed out, so the rule travels with the application rather than with the cabling, which is why the approach works in a cloud where you do not own the network. And then the part everyone underestimates, which the company has been honest about: you cannot enforce a rule that nothing talks unless it has a reason to until you know what actually talks to what, and in a data centre of any age nobody does. So the first problem was never enforcement but mapping the real conversation graph of a running estate, which is why the company spent twenty-two months in stealth before showing anything and why its name comes from the word illuminate. Read beside two entries already here, it completes a picture. One company moved inspection out to where the users went, another tackled what people were doing inside applications nobody had approved, and this one addressed the inside of the data centre on the assumption that the first two would sometimes fail.

    • Contenuto

      Elastic, and a third answer to a question two other entries already asked

      Elasticsearch was Apache licensed, which permits anyone to take the code and sell a service on it without contributing anything back. A very large cloud provider did exactly that. In January 2021 Elastic moved off that licence to two others, neither recognised as open source, and in April the provider forked the project and kept going under the old terms. Three years later Elastic added an approved open source licence back alongside the others, in an announcement whose section headings were named after Kendrick Lamar songs. Three different explanations of why this happened exist, from named participants, and all three are on the page with none of them settled: the company's original statement about resale without collaboration, its founder's later emphasis on trademark rather than resale, and a former cloud executive's account that the real disagreement was about who would own security features. They are not compatible. The community reaction is quoted rather than paraphrased, because it is the part that outlasted the argument, including the observation that the project belonged to its fifteen hundred and seventy-three contributors, who had licensed their work for distribution and not for relicensing. And the fork did not come back. Read beside two other entries here, that becomes a pattern rather than an anecdote: one company closed its open scanner and was forked, one bought an open project and kept it open, one closed and reopened and was forked anyway. Whether a permissive licence is a gift or a liability turns out to depend on who else can afford to run your software at scale, which is a question nobody had to ask before hyperscale cloud existed.

    • Contenuto

      Apple, which completes an argument the Tandy entry started

      The Tandy page records that in 1980 Tandy shipped three times as many computers as Apple, because Tandy had seven thousand shops and Apple had dealers. This entry explains why that reversed. Apple's advantage was slower and more durable: the machine had expansion slots, so other companies could build cards for it, and the first spreadsheet shipped on it before anywhere else. A computer other people can extend and write software for accumulates reasons to buy it, while a computer sold off a convenient shelf accumulates only sales. There is also a detail that links the two entries directly. Wozniak showed the first Apple at the Homebrew Computer Club, and the engineer Tandy hired to design the TRS-80 was a member of the same club, which means two of the three machines in the 1977 Trinity came out of one hobbyist meeting in Silicon Valley. The founding facts are worth having straight too. Three founders, not two, and the third sold his ten per cent back for eight hundred dollars eleven days later because he had a family and could not carry the risk. The funding was a Volkswagen van and a programmable calculator. And the return in 1997 happened through an acquisition, which makes it the most consequential purchase on this whole timeline: Apple bought NeXT, NeXT's operating system became the foundation of macOS, and NeXT's founder became Apple's chief executive. Every iPhone runs a descendant of software written by the company Apple's ousted founder built while he was gone. Every other near-death recovery on this page ends with somebody else doing the acquiring.

    • Contenuto

      Kaspersky, written so that both true things stay true

      Two facts about this company are documented and neither cancels the other. Its researchers are first-rate and built much of their reputation publishing detailed analysis of intelligence operations attributed to the United States and Israel, as well as ones attributed to Russia. And several governments have prohibited its software on national security grounds that the company denies, offering source-code audits that have changed nobody's position. The public record does not settle the underlying question, so this page does not either: allegations are attributed to whoever made them, the denial is stated, and no verdict is offered. Two things were worth rescuing from the usual telling. The first is that Natalya Kaspersky built the business and is routinely left out of it. She took over distribution in 1994 when the product earned a couple of hundred dollars a month, grew it past a million a year by 1997, launched the company foundation, chose the name, and was chief executive for over a decade. The second is the 1998 CIH outbreak, when their product was the only one that could remove a virus that overwrote the BIOS, which won licensing deals across three countries and effectively made the company. The useful lesson is broader than any single vendor. A security product runs with the highest privileges, sees everything, and updates itself continuously from its maker, and this site already shows what happens when that trust fails by accident and by attack. Which means jurisdiction is part of a product's threat model. Where a vendor's engineers can be legally compelled, and by whom, is a security property of the software, and it appears in no feature comparison.

    • Contenuto

      SolarWinds, written at length because it is the most instructive story here

      Two brothers founded SolarWinds in Tulsa in 1999 on an unglamorous and very good idea, that network monitoring was overpriced and that an engineer who needs to know whether a link is saturated should be able to download a tool and buy it on a card. That took them to a public listing. Then in October 2019 attackers already inside the company began testing whether they could inject code into the Orion build, succeeded about four months later, and from March 2020 SolarWinds itself distributed a backdoor inside signed, legitimate updates. It was found in December by FireEye, while FireEye was investigating its own compromise, which means the largest supply chain attack in history was discovered by a security company looking into how it had been broken into. The entry gives the famous number with the caveat the US government attached to it and which retellings usually drop: around eighteen thousand customers received the update, but far fewer were actually exploited, because a backdoor is a door and the attackers chose very selectively where to walk through. Confusing the two overstates the damage and misses the distinction a security professional is paid to understand. The blame argument is presented as unsettled, because it is. The regulator charged both the company and its security chief with fraud over how risks were described; the company called it revictimising the victim; a judge dismissed most of the case in 2024 while letting the claim about its published security statement proceed. And the practical lesson is architectural, with its twin already on this site. CrowdStrike broke eight and a half million machines by accident in 2024 and this compromised thousands of networks by design in 2020, and the property both exploited was the same one: an industry built on software that updates itself from a single source, where trust in that channel is load-bearing.

    • Contenuto

      Two vendors in one market who took opposite positions on open source

      In April 1998, aged seventeen, Renaud Deraison released the first version of Nessus. Four years later he folded it into a company founded with two others in Columbia, Maryland, one of whom had worked at the National Security Agency and had sold his previous company to Enterasys, which is already on this timeline as what remained of Cabletron. Then in October 2005 Tenable closed the source. The stated reasons were both honest, to fund the engineering and to stop handing competitors a free product to resell, and the community forked the last open version into OpenVAS, which still exists. That is worth sitting with rather than judging quickly: a free tool written by a teenager became the industry default, and the only way to fund what it then needed was to stop it being free. Both the closing and the fork were reasonable answers to the same fact. Rapid7 went the other way entirely. In 2009 it bought Metasploit, the best known open-source exploitation toolkit, kept it open, and used it as the reason to trust the paid products beside it. Owning it also changed what the company could claim, because a scanner reports that a host is probably vulnerable while an exploitation framework demonstrates that it is. Two competitors, one question about open source, opposite answers, and both still trading. Tenable was also bootstrapped for a decade before taking any institutional money, which is not how that story usually goes.

    • Contenuto

      A location added to the Juniper chapter

      The Juniper career chapter recorded JUNOS operations training for the Level 3 network operations centre staff in Brazil and Argentina. It now also records where the Brazilian classes were held, in Cotia, Sao Paulo. That is the whole change. Two earlier versions of this note existed within the same day and both were wrong, one naming Impsat as the customer and one naming Global Crossing, before the record was confirmed as Level 3, which is what the chapter had said correctly all along. They are recorded here rather than quietly replaced. The useful lesson is not about the companies but about method: a single new detail should be written down plainly, not immediately woven into a larger argument about corporate lineage, because if the detail moves then everything built on it moves with it.

    • Contenuto

      A rural Louisiana phone company that ended up owning one of the internet's backbones

      This one is written as a single chain because that is how it happened. The company was incorporated in 1968 as Central Telephone and Electronics, spent four decades as a rural local exchange carrier in Monroe, Louisiana, and grew by buying other rural carriers one at a time, which is unfashionable and slow and made it large enough to buy companies far better known than itself. Embarq followed in 2009, then Qwest in 2011, which was a Bell company by descent, and then Level 3 in 2017, which operates the autonomous system that appears in more traceroutes than almost any other. And Level 3 had been assembling too. Inside that deal sits Global Crossing, founded in 1997 to lay submarine cable, valued at forty-seven billion dollars during the bubble, never profitable in a single year, bankrupt in 2002 in one of the largest filings in history, and sold for three billion twelve years later. Global Crossing had itself bought Impsat, which is how fibre built for Brazil and Argentina ended up inside a Louisiana rural carrier by way of a Bermudan bankruptcy. Two prices in this entry are given twice rather than once, because sources disagree and the gap is almost certainly whether debt is counted; picking one number and presenting it as settled would be the easier and worse choice. In 2022 the company sold most of the rural telephone lines it had spent fifty years collecting, having used them to buy a global network.

    • Contenuto

      Vendor hubs now offer both the company and the person

      Each vendor hub had a single card leading to that company's story. That was right when there was one page, and stopped being right when the split gave the company its own history and the career its own chapter. The hubs now carry both: one card to what the vendor did, another to what the work with that vendor actually was, which accounts and which escalations and what it certified. Adding it turned up a small omission worth recording, because it is the kind that never announces itself. The mapping from a hub to its career chapter is keyed by hub name, and Check Point's hub key is one word while its career slug is hyphenated, so that vendor simply had no entry. Nothing failed and no check complained; the card just never appeared on that one hub, and would have gone on not appearing indefinitely. The NGINX hub correctly shows no career card, because there is no career chapter for it.

    • Infrastruttura

      Fifteen companies were appearing on the timeline three times each

      The restructure that gave every company its own history page had a consequence nobody would have noticed from a green build. Rewriting the fifteen companies worked inside directly meant adding them to the company list, and they were already in the career list, and the timeline merges both. So each of them was drawn twice, and once more in the strip of career chips above, making three. Nothing failed and no check complained; the number of entries was simply wrong, and only counting them found it. The company entry is now preferred, because it is the better record: it carries the founding year, the closing year where there is one, the acquisitions with their own nested acquisitions, and a link back to the career chapter. A career entry is included only when no company entry exists for it, which today is none of them, and that filter stays so the next company added to the career record still appears while its history is being written. The career chips were also pointing at the wrong place, a leftover from the days when career pages briefly lived on the industry side, and now point back at the chapters they describe.

    • Contenuto

      Akamai and Cloudflare, and an argument now visible four times on one page

      Akamai began as an answer to a question Tim Berners-Lee put to MIT, that the web was going to get congested and somebody should work out what to do. The specific problem was the flash crowd, where a site becomes briefly famous and falls over exactly when the most people are looking at it, and where adding capacity does not help because the capacity is needed for an hour a year. The answer was mathematical rather than architectural: a hashing scheme that lets a large and constantly changing set of caches agree on which of them holds what, without coordinating, and where adding or losing a server only remaps a small fraction of the whole. That algorithm is why a distributed cache can be operated at scale at all, and it is used far beyond content delivery now. The entry also records that co-founder Danny Lewin was killed on the eleventh of September 2001, aboard the first aircraft flown into the World Trade Center, and is credited with trying to stop the hijackers. He was thirty-one. Cloudflare started somewhere much smaller, a 2004 project asking where email spam came from, whose users kept asking it to stop the spam rather than merely count it. Its free tier was strategy rather than generosity, because every free site sends traffic through the network and every attack on one is an attack the network learns to recognise for everybody. That is now the fourth time this argument appears here, after email reputation in 2002, web traffic in 2007 and endpoints in 2013, and two of those four began by studying spam.

    • Contenuto

      The last five histories, and one argument that keeps being rediscovered

      F5 was named after the most powerful tornado category, which is the sort of thing a networking startup called itself in the nineties, and spent thirty years moving up the stack: once you terminate a connection to load balance it you can inspect it, and once you inspect it you can rewrite, authenticate, offload and block, which is how a load balancer became a platform. Fortinet was founded by the man who had already built one firewall company, taking the same silicon argument further, that if you are making custom chips anyway you should inspect everything in one pass rather than chain boxes that each re-read the same packets. Netskope started from a question anyone can verify, which is that organisations underestimate how many cloud applications their own staff use by an order of magnitude, and found the hard part was not seeing the traffic but telling apart an upload to a corporate account from the same upload to a personal one. Ping bet in 2002 that identity would have to work between organisations rather than inside one, and the idea underneath is worth stating plainly: an assertion signed by someone you trust beats a credential you have to store. Zscaler argued that if the users have left the office and the applications have left the data centre, sending traffic between them through the office is indefensible. That last entry notes something the timeline now shows three times over: a shared platform that inspects everyone's traffic learns from all of it, which is the argument IronPort made about email in 2002, CrowdStrike made about endpoints in 2013, and Zscaler made about web traffic in between.

    • Contenuto

      Four more company histories, including two that explain the rest of the timeline

      Pulse Secure is an unusual founding: it existed on day one in 2014 with a mature product, an installed base and a support obligation, and no history of its own, because Juniper sold it a business rather than starting one. The code predated the company by more than a decade and had passed through two acquisitions before the carve-out, which is a specific kind of risk that this timeline shows repeatedly, and the vulnerabilities that later drew emergency directives from national agencies were structural rather than careless. The FireEye, McAfee and Ixia entry covers three lineages that shared a distribution portfolio and almost nothing else, which is what distribution actually looks like from the inside: a portfolio assembled from whatever the market wanted, whose only common factor is the person carrying it. Extreme grew mostly by buying the enterprise businesses larger companies had stopped wanting, so its product line is an accumulation of other lineages and its installed base includes customers who bought from four companies that no longer exist. And Check Point patented stateful inspection, invented the commercial firewall market, and then watched its own alumni build much of the competition, including the company that overtook it. The idea itself is worth knowing: a packet filter cannot tell a reply from an unsolicited connection, a proxy understands conversations but terminates them, and tracking connection state gave the security of one at nearly the speed of the other.

    • Infrastruttura

      The redirects file had three faults and two of them would have failed silently

      A warning about platform limits turned into a much better catch than expected. The first fault was the obvious one: the file had grown past the two thousand static redirect limit, and rules beyond a limit are dropped with no build error and no warning anywhere, so the failure would have been invisible until somebody reported a dead link. The second was ordering, because every static rule has to appear before every dynamic one and ours did not, which drops rules the same silent way. The third was the serious one, and it was self-inflicted by the restructure itself. Company histories for vendors worked inside directly are rendered by turning them into company entries, and the redirect generator reads that same list, so it had cheerfully written rules sending six career pages to their own histories. The pages built last week would have redirected away from themselves. All three are fixed, and a new build check now fails on any of them: over either limit, dynamic rules before static ones, or any career page appearing as a redirect source. Also worth recording is what does not work, since it looks like it should: a single wildcard cannot replace the per-page rules, because redirects are always followed whether or not a real page matches, so a wildcard over that path would capture the career pages too.

    • Contenuto

      Six company histories rewritten as histories, with the memoir moved out

      The pages for companies worked inside directly had been half history and half autobiography, which served neither. The autobiography now has its own page and these are being rewritten as company histories, six so far. Riverstone turns out to be a story about timing rather than engineering: the metro Ethernet thesis was right, the wire-speed switching was good enough that Cabletron built its next generation on it, and the company was spun out precisely as telecom spending collapsed. IronPort is a story about asking a different question, whether who sent a message predicts spam better than what it contains, which is the argument cloud security has repeated ever since. Cabletron chose to split itself into four companies rather than be broken up by anyone else, which is why three other entries on this timeline exist, and the enterprise line that began in a New Hampshire garage in 1983 now ships as Extreme. NetScreen is the most connected page here: one 1996 startup seeded Fortinet, seeded Palo Alto Networks through a founder who had been one of Check Point's first employees, and seeded part of Extreme, so four of the eight platforms this site teaches trace something to one building. Cisco did not invent the router but shipped the first that spoke everybody's protocol at once, and its certification ladder is the template every vendor here uses. Each history now ends with a small card back to the career chapter, placed after the company's own story rather than before it.

    • Contenuto

      Career chapters and company histories are now two different pages

      Every company page moved to the industry section, which is where a company history belongs, and fifteen new pages went up in their place under the about section. Those fifteen are autobiography and nothing else: what the work actually was inside Cabletron, Riverstone, Cisco, IronPort, Juniper, Extreme, distribution, Pulse Secure, Palo Alto, F5, Fortinet, Netskope, Ping, Zscaler and Check Point. The dates lead the page, because on a career page the years are the subject rather than a detail about somebody else. Certifications earned in each chapter get their own block, since on a page like this they are evidence for the claims above rather than decoration. Each chapter ends with cards out: one to the vendor hub where a hub exists, meaning courses delivered and tools built, and one to that company's own history, meaning who founded it and who eventually bought it. Nothing was invented to fill the new pages. The autobiographical material already existed; it had simply been buried inside company profiles, where a reader looking for the company had to scroll past it and a reader looking for the person had to dig for it.

    • Infrastruttura

      Company histories move to the industry side, where they belong

      Two different kinds of page had been sharing one path. A page about what somebody did inside a company is autobiography. A page about what the company did is history. Both were living under the vendors section of the about pages, which made the vendors index read as a company directory rather than a career record. The roughly ninety company histories now live under the industry section, reached from the timeline cards that share their data, and their back link returns to that timeline rather than to a career index they were never part of. The fifteen career chapters stay exactly where they were. Redirects cover both of the older shapes these URLs have had, including the partner segment that was flattened out days earlier, and they are written in two styles for a reason: the partner path can use one wildcard per language because no career page ever lived there, while the flat path needs every profile listed individually, because a wildcard would catch the fifteen career pages that must not move. That distinction is the whole reason the file is long.

    • Contenuto

      Ninety company pages existed and the vendors index linked to fifteen of them

      A reader asked where the newly added companies had gone, which turned out to be an excellent question. The vendors index listed only the fifteen career chapters, the companies worked inside directly. Every other company profile on this site, around ninety of them including EMC and Splunk and CrowdStrike and everything added this week, had a page of its own that was reachable only by scrolling the industry timeline and clicking a card. The pages were written, built, indexed in the sitemap and linked from nowhere anybody would think to look. That is fixed. The index now lists every company with a page, ordered by the year its story starts rather than alphabetically, so it reads as a chronology and matches the timeline it shares data with. Companies that ended carry their closing year on the card. The lesson is worth keeping separate from the fix: a page that exists and cannot be found is not much better than a page that does not exist, and nothing in the build could have told us, because every link on the site pointed somewhere valid. It took somebody going looking for a company by name.

    • Infrastruttura

      Company pages now show acquisitions the way lineage pages do

      The vendor lineage pages have shown nested acquisitions for a while, meaning the purchases a company made with the purchases those companies had themselves made listed underneath, because stopping at one level hides where the technology actually came from. Company profile pages had no acquisitions field at all, so the same facts were being written into the prose instead. They were true and they were sourced, but they were sentences rather than data, which meant they could not be laid out as nested lists and nothing could check them. Profiles now use the same structure as the lineage pages, deliberately identical so a reader meets one idea rather than two. Four entries added this week were converted, and two of them gained nesting that says something. Ivanti bought Pulse Secure, and Pulse Secure existed because Juniper's SSL VPN business had been carved out and sold to private equity in 2014, which is why a company founded that year shipped a product line older than itself. EMC bought Data General, a minicomputer pioneer that ended inside a storage vendor thirty-one years after it was founded. The rest of the backlog will be converted as each entry is revisited.

    • Contenuto

      Tandy and RadioShack, which outsold Apple three to one with a worse computer

      In 1975 a RadioShack buyer bought an Altair to run inventory, became fascinated, and spent a year persuading his management that a chain of electronics shops should sell a computer. They hired a twenty-four year old from National Semiconductor to design it, a Homebrew Computer Club member like the two Steves at Apple, and demonstrated the prototype to Charles Tandy in February 1977 running a tax program. Management committed to three thousand units, a number chosen to match the number of shops, on the reasoning that if none sold each store could use one for accounting. The designer argued for fifty thousand and was laughed at. It sold roughly fifty thousand in the first month. On the merits the TRS-80 was the weakest of the three machines Byte magazine called the 1977 Trinity: the processor was chosen because it cost twenty-five dollars, storage was a cassette recorder off the shop shelf, and the quality complaints were justified. It also cost about half what an Apple II did, and by 1980 Tandy was shipping three times as many computers as Apple. The reason is the entire lesson. Everyone else sold by mail order or through a handful of specialist dealers, and Tandy sold off a shelf customers already walked past. When reach stopped being scarce, in the era of compatibles sold everywhere, the advantage inverted and Tandy left the business in 1993. It did not beat Apple on technology, it beat Apple on reach, and lost when reach became ordinary. Anyone who has worked in distribution recognises both halves of that.

    • Contenuto

      CrowdStrike, including the morning it broke eight and a half million computers

      George Kurtz was chief technology officer at McAfee, having sold it his previous company in 2004. He resigned, spent a while at a private equity firm, and left with twenty-six million dollars to build what he thought McAfee could not. The argument he and Dmitri Alperovitch started from was specific rather than promotional: signature-based antivirus asks whether it has seen a file before, which is only answerable about attacks that already happened to somebody else, and the scanning it needs is heavy enough that users switch it off. Alperovitch had spent his McAfee years attributing intrusions to the people behind them, and the lesson both took was that the useful question is which adversary is operating rather than which malware is present, because adversaries reuse behaviour even when they change tools. Falcon inverted the model in 2013 with a deliberately light agent streaming telemetry to a cloud that correlates behaviour across every customer at once, so one organisation noticing something odd becomes every organisation knowing about it. Then on the nineteenth of July 2024 a faulty update crashed an estimated eight and a half million Windows machines and left them unable to restart, stopping airlines, hospitals, banks and payment terminals, in what is generally called the largest IT outage in history. The entry does not treat that as an aside. A light agent with kernel access on millions of machines, updated centrally and fast, is exactly what made the detection work and exactly what made one bad file global before anyone could intervene. Every property that made the product good made the failure big, and that trade is worth understanding before deploying anything shaped the same way, which is most of modern security.

    • Contenuto

      Splunk joins the timeline, and both ends of its sale are now on this site

      Three engineers founded Splunk in San Francisco in October 2003 after arriving separately at the same complaint, that finding anything in machine-generated logs meant crawling through them by hand. They named the company after spelunking. The decision that made it work was technical and worth understanding: a relational database wants you to decide the shape of your data before you store it, which is impossible when the data is whatever a hundred different systems happen to emit, so Splunk indexed the text as it arrived and let structure be applied at search time instead. That inversion is why it could ingest anything. The commercial decision was equally deliberate, a free tier of five hundred megabytes a day adopted by engineers who then brought it into their employers, which was bottom-up adoption years before anyone called it that. It raised only about forty million dollars in total, was profitable by 2009, and went public in 2012. Cisco completed its acquisition in March 2024 for around twenty-eight billion, one of the largest software deals ever made, and since Cisco is a chapter in this site's own career record, both ends of that transaction now appear on the same page. One founder's exit is worth noting for contrast: he stepped down in 2009, moved to Burgundy and bought a winery, which is gentler than most endings here.

    • Contenuto

      NetApp and Sophos, and one founder who connects four companies already here

      NetApp was founded in Sunnyvale in 1992 on an observation rather than an invention: that building file storage out of general-purpose servers was harder than it needed to be. The answer was an appliance that did one job, running an operating system written for that job alone, and a company name that said exactly what it sold. Its main competitor at the outset was Auspex, where two of the founders had previously worked, which is the ordinary way storage companies begin. What makes the entry worth reading is where one founder went. Michael Malcolm left the chief executive role in 1994 and founded CacheFlow, which became Blue Coat Systems, and in 2006 NetApp sold a product line to Blue Coat, so a company sold a business to the firm its own co-founder had built. His earlier career ran through Sun Microsystems and Tandem, both of which sit on this timeline having ended inside somebody else. Sophos is here for the opposite reason. Two people founded it at Oxford in September 1985, the year before the first PC virus spread, and named it after the Greek word for wisdom. It is still trading under that name forty years later, privately held. Almost every company on this page that started in the eighties has since ended inside another one, so continuing to exist is itself the notable fact.

    • Contenuto

      Ivanti joins, and two vendors already on this site turn out to end there

      Ivanti is a 2017 company assembled from forty years of other people's software, and it earns a long entry because three threads on this site run into it. MobileIron, listed here as a Red Education training partner, was acquired by Ivanti in a deal announced in September 2020. Pulse Secure, which is a chapter in the career record because it carried Juniper's SSL VPN business, was acquired in the same announcement and completed the same day. And Avocent, which already appears in the Cyclades lineage, owned LANDESK for four years before private equity did. So the page can now show two vendors ending in the same place on the first of December 2020. The company itself is barely original by design. LANDESK began as LANSystems in 1985, became an Intel division in 1991, was spun out in 2002, and absorbed Wavelink, Shavlik, AppSense and others before the merger. The other half, HEAT, was itself assembled from FrontRange and Lumension, which had started as High Tech Software in 1991. One thing is recorded rather than omitted: Ivanti became widely known for serious vulnerabilities in the VPN appliances it sells, and a portfolio assembled from a dozen acquisitions inherits a dozen codebases, so the security of the whole is the security of the weakest piece.

    • Contenuto

      EMC, EDS and Getronics join the timeline, and two loops close

      Three companies added, and two of them complete stories the timeline had only half of. Data General was marked last week as ending in 1999 because EMC bought it; EMC is now on the page itself, and it ended too, inside Dell in 2016 for sixty-seven billion dollars, the largest technology acquisition on record at the time. So the chain runs from a minicomputer company of the sixties through a storage company of the seventies into a personal computer company of the eighties, and the page can show all three. Getronics closes the other loop: Wang Laboratories was recorded as ending there in 1999, and Getronics turns out to be a Dutch electrical firm dating to the eighteen eighties, which then sold its North American arm twice more, so the residue of Wang passed through three further owners after the acquisition that supposedly concluded it. That is the ordinary shape of a technology ending, and worth showing. EDS is here for a different reason. Ross Perot founded it in 1962 on a proposition that barely existed as a market, that a company might pay somebody else to run its computing entirely, and every managed service since descends from that bet, including the idea that expertise can be contracted rather than hired.

    • Contenuto

      Five companies on the timeline stopped saying they are still here

      The industry timeline showed a span ending in the present for every company without a recorded end date, which meant several that no longer exist appeared to still be trading. Five now carry the year they ended and what happened. Wang Laboratories, which peaked at three billion dollars in revenue in the eighties, was acquired by Getronics in 1999. Data General, one of the first minicomputer companies, went to EMC the same year, largely for its storage arrays. Tandem was bought by Compaq in 1997 and travelled with it into HP, though its fault-tolerant NonStop line survives inside HPE today, so the technology outlived the company by decades. Sun Microsystems went to Oracle in 2010, taking Java, Solaris and the identity stack that later became ForgeRock with it. And Compaq itself was acquired by HP in 2002 and retired as a brand by 2010, having absorbed both Tandem and Digital on the way, so three companies end inside a single lineage. Only entries verified against primary sources were changed. Many that still show the present are correct, because the card names a lineage rather than a company, and that lineage continues under a later owner.

    • Contenuto

      Vendor pages now say what they are, and the relationship moved to tags

      The cyan line at the top of every vendor page used to carry either a span of years or the words Red Education training partner. Both made the page look like a CV entry when it is really a company history, and neither could show more than one thing at a time, which was a problem because several vendors are more than one thing. That line now says vendor lineage, and the relationships have moved to a row of tags beneath it where they can coexist. There are three, and they are deliberately different claims: worked with directly, which is autobiography and carries the years so nothing is lost; Red Education training partner, which is a fact about Red Education; and authorized instructor, which is the narrowest of the three and applies to four vendors rather than the nine Red Education partners with. Keeping those separate matters, because conflating the last two would overclaim. On the partner pages, the note explaining that Rodolfo does not teach a given vendor lost a sentence listing what he does teach. It was unnecessary there, and it had gone stale: it listed vendors that no longer matched the authorisations recorded elsewhere on the site.

    • Infrastruttura

      The sitemap was always XML; nothing was saying so

      A reader noticed that the sitemap opens in a browser looking like plain text rather than a structured document. The file itself was never the problem. It begins with an XML declaration and carries a correct namespace, hreflang alternates for all sixteen languages and an x-default, all generated from the built pages. What was missing was a header. The site sets a directive telling browsers not to guess at content types, which is the right thing to do for security, and it had no rule declaring what the machine-readable files actually are. So they arrived undeclared, the browser was forbidden from inferring, and it fell back to showing text. There are now explicit content types for the sitemap, the feed and the model-readable index. This also matters beyond appearance, since anything that checks the header before parsing was being told nothing useful.

    • Lancio

      Why your DLP rule fired, and why arguing about the pattern will not help

      Every DLP deployment produces the same two complaints within a fortnight, usually from different people: it is flagging things that are not sensitive, and it missed something that obviously was. Both are normally about the same mechanism, and it is not the pattern. A predefined data identifier works in stages that fail separately. First it finds candidates by shape. Then it validates them, which for numeric identifiers means a checksum. Then it compares the count of validated matches against a threshold. A rule that did nothing failed at exactly one of those, and which one tells you what to change. The new tool shows all three numbers rather than a verdict, because collapsing them throws away the only diagnostic information there is. It implements Luhn for payment cards and the mod-eleven check digits for Brazilian CPF and CNPJ, which are the identifiers whose validation is a published and unambiguous algorithm. The Brazilian ones carry a detail worth knowing: sequences of repeated digits satisfy the arithmetic perfectly and are never issued, so they have to be rejected explicitly or you match every test record in every system you scan. Everything stays in the browser, which matters more here than usual, since the point of the tool is pasting content you suspect is sensitive.

      DLP match predictor

    • Lancio

      The Check Point NAT that installs cleanly and delivers nothing

      There is a particular kind of silence worth recognising. The NAT rule is there, the policy installed without complaint, the server is healthy, and the firewall logs show nothing at all. Not a drop, not a reject. That combination is almost never a policy problem, because a policy problem writes a log line. Nothing in the logs means nothing arrived. The usual cause is a layer below the rule base. If the translated address sits in a subnet the gateway is connected to, the upstream router does not forward the packet anywhere, it broadcasts a request asking who owns that address and waits, and if nothing answers the packet is never sent at all. Automatic NAT adds that answer itself when the policy installs. Manual NAT never has. The new tool does the subnet arithmetic and says which situation you are in, along with what to do about it, and it covers the case that makes the usual advice insufficient: automatic NAT also creates nothing when the relevant global setting is switched off, and the failure is then identical. One thing it deliberately refuses to do is rank the NAT rule base. Published sources contradict each other on whether manual rules evaluate before or after the automatic ones, and Check Point's own guide describes them as enforced differently without settling it. Ranking them would mean presenting a guess as a computation, so the disagreement is written down instead.

      Check Point NAT reachability checker

    • Lancio

      Extreme gets a second tool, and it is the one that makes the multicast FIB readable

      In shortest path bridging, a backbone group address is never learned and never configured. It is assembled from two numbers every node already holds: the nickname of the node that roots the tree, and the service identifier. Nickname 0.00.10 carrying I-SID 100 is 03:00:10:00:00:64, and every node on that tree computes the identical address from the link-state database without being told, which is the reason the fabric does no backbone MAC learning at all. The new tool builds those addresses and, more usefully, takes them apart. The multicast FIB is a column of hexadecimal and the question is always the same, whose tree is this and which service does it carry, and both answers sit inside the address. Every forward test case is a worked example from Extreme's own documentation and every reverse one is a line of real FIB output, which mattered more than expected: the first version of the arithmetic produced perfectly correct addresses while decoding them wrongly, and only the reverse cases caught it. There is one ambiguity in the encoding, where a nickname can collide with the fixed prefix and cannot then be recovered from the address. Rather than return a nickname it cannot stand behind, the tool builds the address and says the reverse is unverified for that shape.

      SPBM multicast address builder

    • Localizzazione

      Nine claims, fourteen languages, and a guard that took four attempts to make honest

      The site grew from four vendor families to eight. The English copy was corrected at the time. Fourteen translations were not, because they carry their own copy of those strings rather than falling back to English, so nine keys went on saying four platforms in fourteen languages, on the home page, the about page and the training page. Every existing check passed the whole time: the keys were all present, so parity was green, and the strings were well formed, so the message parser was happy. Nothing verifies that a translation still means what the English means. A hundred and twenty-six strings are now repaired, and repaired rather than replaced, so the existing translation quality survives. The four hardest languages were read by hand instead of trusted to the script: Turkish needed its plural and locative endings restored, since Turkish takes the singular after a numeral and removing the numeral leaves the wrong word; Chinese needed its measure word dropped; Russian and Polish needed the right case. A new build check now fails when a translation contradicts a quantity the English states. Making it trustworthy took four attempts, from a hundred and ninety false alarms down to none, because number words are ordinary words in most languages: six is also the verb are in Italian, both becomes two in every Romance language, ten years is how Turkish says decade, and Chinese hides eight inside its word for octet. The check documents its own blind spot, which is that it would not have caught the original problem, since the corrected English gives no number at all.

    • Localizzazione

      Fourteen languages were still saying something the English page had stopped saying

      When the About page was rewritten, two things changed in one sentence: it stopped saying there were four vendors, because there are eight, and it dropped a claim that the section listed everything the author is authorized to teach. English and Portuguese were updated. The other fourteen languages were not, because they carry their own translation of that sentence rather than falling back to English, so every one of them went on asserting both. Danish said four, German said four, Chinese said four, and all of them kept the sentence that had been removed for being a maintenance liability. That is now fixed in all fourteen, translated rather than deleted, because a reader in Danish should get Danish and English fallback is the floor rather than the goal. A sweep of every other key the other packs translate themselves found no similar case, which is worth knowing: the risk only exists where a locale has its own copy of a string the English later changed.

    • Contenuto

      The agent piece gets the part that was not known when it was written

      The article about the Hugging Face intrusion went up on 23 July, built from the two public disclosures. Reuters published the following day with a timeline that changes the shape of it. The agent tried to leave its testing environment around 9 July, the intrusion ran from the 11th to the 13th, and it then took several more days for OpenAI to work out that the agent was its own. The two companies did not speak until around the 20th. Read with a defender's eye, that means the attack was over, contained and reported to the FBI before the organisation that owned the attacking system knew the system was theirs. So the piece now carries a section on detection latency, which is the useful finding for anyone running a network rather than a lab. Dwell time is a number every security team already tracks, and the party who could not close it here was not the victim: Hugging Face detected and contained an intrusion, while the other side could not attribute its own outbound traffic. The questions that follow are ordinary engineering ones. Do you have telemetry on what leaves, not just what arrives. Could you attribute an incident to your own infrastructure if somebody else found it first. The earlier sections were left as written rather than revised to look prescient, and the new material says plainly what it changes and what it does not.

    • Contenuto

      The AI era gets its two markers, including the company this site is built with

      OpenAI joins the timeline at 2015, when it was announced as a non-profit with a billion dollars pledged and a stated mission to keep artificial general intelligence from ending up controlled by any single company. It is now a public benefit corporation of which Microsoft holds roughly a quarter, which is a striking distance from the founding premise and is recorded as such. The date that matters for this site is 30 November 2022, when ChatGPT launched and reached a hundred million monthly users in two months. Large language models existed before that and had been improving in public for years. What changed was that using one stopped requiring an API key or any idea of what a transformer is. The technology did not become capable that November. It became available. Anthropic joins at 2021, founded by senior people who had just left OpenAI over where it was going. Its entry carries a note for whoever edits it next, because this site is authored with Claude and that is a reason to hold the entry to a higher standard rather than a lower one. So the unflattering facts are in it, including that five hundred of the five hundred and eighty million dollars in its second funding round came from the trading firm affiliated with Sam Bankman-Fried, months before that firm collapsed. A site that teaches people to check their sources should name the one it was built with, and should not write an advertisement when it does.

    • Contenuto

      Two beginnings marked: web search as we know it, and the first social network

      The AltaVista page shipped last week ends with a company that had the better index and lost the market. This adds the other half of that story. In 1998 two Stanford students tried to sell their ranking algorithm to AltaVista for a million dollars, intending to go back to their studies, and AltaVista did not buy it. PageRank scored a page by who linked to it rather than how often the page said the word, which measured something the page's own author could not control, and that is why it survived contact with people trying to game it. Google incorporated that September in a friend's garage, with a first cheque from one of Sun's co-founders and a homepage left deliberately bare at exactly the moment every competitor was adding shopping and email to theirs. Alongside it, the first social network. SixDegrees launched in 1997 with profiles, friends lists, messaging and the ability to see how you connected to any other member, which is every feature social networks still have. It reached three and a half million users and shut down in 2001, three years before Facebook, for a reason worth understanding: a social network is only useful if the people you know are on it, and in the late nineties most of them were not online at all. The idea was right and the infrastructure had not arrived, which is a different way to fail than AltaVista's and belongs next to it.

    • Contenuto

      Nine companies on the timeline are two things at once, and now say so

      The lineage timeline marks companies whose training Red Education delivers, and companies this career was lived inside. Nine are both, and until now each of them showed only one pill, because the two facts had been modelled as a single category and a company could only be one thing. F5, Fortinet, Netskope, Extreme, Check Point, Cisco, Palo Alto Networks, Ping Identity and Zscaler now carry both marks. The other six career chapters carry one, and the reason is worth stating: Cabletron, Riverstone, IronPort, NetScreen, FireEye and Pulse Secure no longer exist independently, so there is nobody left to partner with. The fix was to stop treating the two as alternatives. They were never mutually exclusive, and the list of which career chapters are also training partners had been sitting in the code empty since long before the timeline existed.

    • Contenuto

      AltaVista, which was never supposed to be a search engine at all

      In 1995 the engineers at Digital's Palo Alto lab had a problem that sounds enviable and was not: the new Alpha processors were too fast for the benchmarks of the day to stress them. A researcher on holiday sketched an answer, which was to stop using synthetic tests and point a crawler at the entire World Wide Web, on the grounds that nothing else was chaotic enough. Paul Flaherty had the idea, Louis Monier wrote the crawler and Michael Burrows wrote the indexer, and what they shipped that December indexed sixteen million documents and offered full Boolean search when the alternative was a directory somebody maintained by hand. Within a year it was answering Yahoo's searches. It also produced Babel Fish, the first machine translation service on the web, named after the fish you put in your ear. What happened next is the reason it is on this site. Ownership changed four times in five years and every owner wanted it to be something else, so the best search engine on the web was rebuilt as a portal selling things and giving away email, competing on everything except the one thing it was better at than anyone. It sold in 2003 for about six percent of its valuation three years earlier and was switched off in 2013. The technology never failed. Nobody who owned it wanted it to be a search engine, and a company that did took the market. That pattern runs through half the lineage pages here, which is why it is worth being able to recognise.

    • Contenuto

      Apache, which is where the NGINX story actually starts

      This site has three NGINX tools and six NGINX articles and never explained what NGINX was written against. Apache now has an entry in the industry lineage, four glossary terms and an article of its own, because the concurrency problem NGINX solved was Apache's problem specifically. The history is worth knowing as history too. In early 1995 the most-used web server was a public-domain daemon written by Rob McCool at the NCSA whose development had stopped when he left. Brian Behlendorf, who had been patching it so it could handle user registration for Wired magazine's website, set up a mailing list with Cliff Skolnick, and by the end of February eight people were coordinating fixes. First release in April, version one in December, and past NCSA to the most-used server on the internet within a year. One of those eight was Roy Fielding, who went on to co-author HTTP one point one and define REST, so the people who wrote the server wrote much of what it speaks. The article explains the architecture rather than just the dates: a process per connection is robust and flexible and expensive, which is the constraint that got named the C10K problem, and Apache answered it with its event module while NGINX answered it by inverting the model. That difference is why one has htaccess and the other never will. And on the name, both explanations are recorded, because the project has given both and never cleanly retracted either.

    • Contenuto

      Cabletron joins the lineages, and it connects to two chapters of this site's own career

      Extreme bought Enterasys in 2013, and Enterasys was not a startup. It was one of the pieces Cabletron Systems broke into. Cabletron started in a garage in March 1983 making Ethernet cable assemblies, founded by Robert Levine and Craig Benson, moved to New Hampshire, went public in 1989 and passed one point eight billion dollars in annual revenue before splitting itself apart. Its successors were Enterasys, Riverstone Networks, Aprisma and a services arm, and two of those, Enterasys and Riverstone, are chapters in this site's own career record. So the company whose switches were sold in São Paulo in the nineties is the same company whose management heritage now runs through the Extreme platform. The Bay Networks entry also gained its founders and its price: SynOptics was founded by Andrew Ludwick and Ronald Schmidt, who met at Xerox PARC where Schmidt was working on Ethernet, and their merger with Wellfleet in 1994 was a two point seven billion dollar deal. Founders are added only where they were verified during the work, which is why several entries still have none.

    • Contenuto

      The lineages name the people now, and the people turn out to be the connection

      Until now these pages listed companies buying companies. Adding the founders changes what the pages are about, because three of the vendor hubs on this site trace back through the same small group. NetScreen was founded in 1996 by Yan Ke, Ken Xie and Feng Deng, and Ken Xie built the first ASIC-based firewall appliance that year in a garage before leaving in 2000 to start Fortinet with his brother on the same architectural bet. NetScreen then bought OneSecure, which had been founded by Nir Zuk, who was one of Check Point's first employees and who left Juniper after it acquired NetScreen to found Palo Alto Networks, the company that overtook Check Point as the largest security vendor in 2014. And a senior NetScreen engineer, Changming Liu, went on to co-found Aerohive, which Extreme bought in 2019 and built its cloud platform around. So the Fortinet page now opens with NetScreen as prehistory rather than an acquisition, clearly labelled as such since Fortinet never bought it and the connection is a person. The Check Point page records what left the company as well as what it bought. Founders are only stated where they were verified during the work, which means several older entries still have none, and that is deliberate rather than finished.

    • Contenuto

      The industry timeline is finally complete

      It had been drawing from one list. The companies this career actually ran through, Cabletron and Cisco and Juniper and the rest, had chapters elsewhere on the site but were missing from the industry's own chronology, which is a strange omission for a page about where the industry came from. All fifteen are in it now, each marked as one that was worked inside rather than observed from outside. Their founding years were derived the same way the others were, from each company's own profile timeline, and cross-checked against the lineage pages wherever one exists. Seven of seven matched exactly, which is the reason to trust the other eight. Two entries were also quietly appearing twice in the career list, Cisco and Palo Alto Networks, which meant they rendered twice in the strip at the top of the page. That is fixed. The timeline now runs from an 1847 pointer telegraph to a 2012 SD-WAN startup with eighty-nine companies in it, ordered by when each story starts, with pills marking which were training partners and which were lived from the inside.

    • Infrastruttura

      Vendor pages lost a URL segment, and the training partners joined the timeline

      Company profiles used to live under a path with the word partner in the middle of it, which described how this site organises its own data rather than anything a reader cares about. That segment is gone, so every company page is now a sibling of every other one under about slash vendors. It was safe because the two sets never overlapped: fifteen hand-written career pages, seventy-four generated profiles, no collisions, checked before anything moved. On the industry page, the Red Education training partners had a section of their own, which split the industry into companies whose training this site delivers and everyone else. That is a fact about a commercial relationship, not about the industry, and it was carving the chronology in half to show it. Those twelve companies now sit in the timeline with everyone else, each carrying a small red pill that says what the relationship is. Three of them needed a founding year before they could be placed, since they have no profile page to derive one from, so Amazon Web Services, Microsoft and EPI were each looked up individually rather than estimated. EPI turns out to have been incorporated in the United Kingdom in 1987 by Edward van Leent, well before the Singapore entity most people know it by.

    • Contenuto

      Every vendor now has a guided reading path, not just half of them

      Four of the eight vendors covered here had a curated route through their material and four did not. Check Point, NGINX, Extreme and Fortinet now do. Each is ordered the way the subject actually makes sense rather than the way a blueprint lists it. Check Point opens with the three-tier split, because nothing else on that platform makes sense until you know the management server and the gateway are separate machines with separate jobs, and only then moves to the rule base and the layer semantics that catch everyone. NGINX follows the order the confusions arrive in: the configuration tree first, since a fragment nothing includes is not read at all, then which location block wins, then what path the backend receives, then what gets cached and served to whom. Extreme starts with ExtremeXOS and then explains why VOSS feels so different, which is that it came from another company entirely, before building the fabric up from IS-IS to I-SIDs. Fortinet covers what appears once a FortiGate is not alone. The Extreme path was nearly missed, incidentally, because its articles are named after the operating systems rather than the vendor, so a search for the company name found nothing while seven articles sat there.

    • Contenuto

      The About page puts the career first and the credentials after it

      Certifications and endorsements used to be the first thing on the About page, two cards sitting above everything else. They have moved down to join the links at the end of the career timeline, which is where a reader actually wants them: after the thirty years, not before. Those links became cards at the same time, so the four now read as one set rather than a row of buttons under a wall of text. The platforms section lost two entries and a sentence. Ping Identity and Zscaler are no longer listed among the platforms taught in depth, and the line claiming the section listed everything the author is authorized to teach is gone, because that claim needed maintaining every time the site covered another vendor and it was easier to stop making it. The vendor lineage link went too, since lineages now live on the vendor hubs where the rest of each vendor's material is.

    • Infrastruttura

      Vendor hubs stop burying their own tools

      A vendor hub opened with every destination rendered the same way and stacked in one grid. On the F5 page that meant eleven cards before the tools; on Fortinet's it meant twenty, because Fortinet has nineteen certifications and each one had a card of its own. The navigation had become taller than the content it was navigating to. The doors are now grouped by what they are and sized by how many there are. The vendor's story and its corporate lineage stay as full cards, because there are at most two. The certifications become a row of compact chips, because twenty cards is a wall and twenty chips is a list. Guided reading paths stay as cards, since there are only ever a handful. The cards themselves also carry less vertical padding than their content needed. Two sections have gone from the vendor hubs index at the same time, one asking why these vendors and one describing them as four when there are now eight, and the note at the foot of every lineage page promising that other lineages were being researched has gone too, since all eight now exist.

    • Contenuto

      Every vendor hub now has a lineage, and the lineages go one level deeper

      Ping, Zscaler and Netskope complete the set, so all eight vendors covered here now trace where their technology came from. Ping is the most tangled, because it is both buyer and bought: private equity took it private in 2022 and then used it to absorb ForgeRock, its largest competitor, which is the reason the platform carries two overlapping stacks doing similar jobs. They were built by rivals to compete with each other. Zscaler reads as a map of what zero trust came to mean year by year, cloud posture then deception then entitlements then SaaS supply chain then risk analytics then segmentation, each arriving roughly when the market decided it belonged in the platform. Netskope has the shortest list on the site at four acquisitions, and the restraint is itself the interesting fact. The bigger change is that the pages now show what the acquired companies had themselves acquired, because stopping at one level was hiding the part that explains the product. Extreme bought Avaya's networking business, but the fabric technology in it was Nortel's, and Nortel had it from Bay Networks, which was Wellfleet and SynOptics merging in 1994. Its data centre line came through Brocade from Foundry, and its wireless came through Zebra from Motorola from Symbol. That is where the products actually come from, and one line saying Extreme bought a division does not tell you.

    • Contenuto

      Two more lineages: the one that was bought, and the one where the prefix hides the history

      NGINX does not fit the shape of the other lineage pages and its own page says so rather than forcing it. There is one acquisition in the whole story and NGINX is the target: a system administrator's side project, written in his own time at a Russian portal and released for free in 2004, that became a company seven years later and sold to F5 for six hundred and seventy million in 2019. What follows is unusual enough to belong in a record of who has claimed to own this software, because six months after the sale his former employer asserted the code had been theirs all along and a criminal case followed. The page also carries the two forks, because a lineage that produces forks is one where control is contested. Fortinet is the opposite kind of story and useful for a different reason. It built its own core, the firewall and the silicon that made it fast, and then bought nearly every adjacent product in the fabric. So the uniform naming hides the history: FortiSIEM, FortiNAC, FortiEDR, FortiSOAR and FortiMonitor were AccelOps, Bradford Networks, enSilo, CyberSponse and Panopta first. When two Forti-products feel like different software sharing a prefix, that is because they are. One detail is worth stating plainly rather than smoothing over: Lacework had raised more than one and a third billion dollars before Fortinet bought it for an estimated fraction of that, and the estimate is labelled as an estimate because the terms were never disclosed.

    • Nuovo strumento

      The NGINX caching gap where one user gets another user's page

      Whether NGINX stores a response and whether it later serves that copy to someone are different questions, and treating them as one is where caching accidents come from. The new explainer answers both separately, with the ordered rule walk behind each and the computed cache key, because a response can be perfectly cacheable and never served when the key differs, and can be served when it should not be when the key ignores something that mattered. The rules it encodes are the ones people meet: nothing is cached at all until proxy_cache names a zone, only GET and HEAD are cached by default, a response carrying Set-Cookie is not stored on the assumption it is personal, and a status with no lifetime has nothing to be stored under. It also separates the two directives everyone swaps, since proxy_no_cache prevents the write while proxy_cache_bypass skips the lookup and still writes, which means using the wrong one fills the cache with exactly what you were trying to keep out. The warning worth the whole tool concerns an asymmetry: NGINX excludes cookied responses from storage but does not exclude cookied requests from being served a shared entry. That is harmless until someone ignores Set-Cookie to make caching work on a backend that sets a session cookie every time, at which point per-user pages sit under a key every user shares. It is a two-line change that looks like a performance fix, and the tool names it.

      NGINX cache decision explainer

    • Nuovo strumento

      One trailing slash, two completely different backends

      In NGINX, proxy_pass followed by nothing but a host passes the original request URI straight through, prefix and all. Add a single trailing slash and the part of the request that matched the location prefix is replaced by it instead. Those two configurations differ by one character, both are valid, and which one you want depends on whether the application behind the proxy knows it is sitting under a prefix. Get it backwards and the backend returns 404 for a request the proxy handled perfectly, which sends people looking for a fault in the proxy that is not there. The new tool takes a location, a proxy_pass and a request URI, and shows what the backend receives alongside what it would receive with the slash flipped, so the switch is visible instead of described. It reproduces the doubled slash that a location without a trailing slash really does produce, rather than tidying it into something prettier than NGINX gives, because that doubled slash is exactly what someone is staring at in an upstream log when they come looking. It also refuses what NGINX refuses, since a regular-expression or named location has no literal prefix to replace, and it flags the variable exception, where putting a variable in the value switches the whole substitution off and moves upstream resolution to request time.

      NGINX proxy_pass rewriter

    • Contenuto

      Three NGINX articles, and the certification objectives now have something behind them

      The NGINX exam objectives had the blueprint's own key points and nothing else, which is honest but thin. Three articles now sit behind them. The first is the configuration tree: one file, includes that paste fragments in place, and the fact that a fragment nothing includes is simply not read, which is the most commonly wasted hour on this platform. It also covers the ownership split that explains most permission failures, since the master runs as root to bind ports and open logs while the workers drop to another account and are what actually reads your content, so a clean start followed by a 403 is a worker question and never a root one. The second covers limiting, where three directives get confused because they all sound like slowing something down: one limits how often requests arrive, one how many connections are open at once, and one how fast each response is delivered. The request limiter is a leaky bucket rather than a quota per second, so ten simultaneous requests against a ten-per-second limit do not all pass, and burst by default delays rather than permitting a faster burst, which is not what the name suggests. The third is operational: a reload starts new workers and lets the old ones finish, so nothing in flight is dropped, and it explains which log answers which question, because the access log tells you a request returned 502 and the error log tells you why.

    • Lancio

      NGINX arrives, starting with the rule that costs everyone an afternoon

      NGINX now has its own place on this site rather than sitting inside F5, and it opens with the thing that confuses people most. NGINX does not pick the first location block that matches, and it does not pick the last. It tries an exact match first and stops if one hits, then checks every prefix block and remembers the longest match rather than the first, then unless that block carries a caret-tilde it runs the regular expressions in file order and lets the first match win over the prefix, and only falls back to the prefix if none matched. File order decides exactly one of those five steps, which is why reading a config from the top down misleads you about the outcome. The new matcher runs that walk in front of you and says what happened at each step. The example it ships with is the classic: an images prefix block losing to a file-extension regex written below it, which is nearly always the real answer when someone says their block is being ignored. It also explains what caret-tilde actually does, which is not raising priority but stopping before the regular expressions run, and that is exactly why it fixes the case. The certification stays where F5 issues it; this is the technology getting a home for its tools and articles.

      NGINX location matcher

    • Infrastruttura

      Twenty-six objectives were presented as covered when nothing was behind them

      Every certification guide here marks an objective as a gap when there is nothing yet to teach it, and removes that mark once an article, a tool, a manual link or the blueprint's own key points are attached. A check of all sixteen hundred published objectives found twenty-six where the mark had come off without anything arriving to replace it. They rendered as ordinary covered objectives, so a reader working through a blueprint would have found nothing behind them with no way to tell whether that was expected or a broken link. Seventeen were in one F5 guide. They are marked as gaps again, which is the honest state, and a new build check now fails if any published objective has neither coverage nor a gap flag. Worth recording how nearly this was missed: the first version of that check assumed a fixed layout and silently examined only half the objectives on the site, reporting eight hundred and eighty-one where there are one thousand six hundred and thirty-two. The second version found the right objectives but named the wrong guide for each, because its way of finding where one guide ends ran past the end into the next. A check that reports confidently and counts wrong is worse than no check, so both were fixed before this shipped.

    • Contenuto

      Check Point's certifications are listed in the order you would actually take them

      They had been sorting alphabetically, which is a reasonable default and the wrong answer here. It put the Automation Specialist first, buried the two exams that open the whole path somewhere in the middle, and scattered the five HackingPoint courses through the list as though they were steps on the same ladder. They now appear in programme order. The Security Administrator and Security Expert exams come first because that is where anyone starts. The two Master levels follow, since they continue that ladder and are worth understanding early: neither has an exam of its own, and both are awarded for accumulating specialist accreditations rather than for passing anything. The nine accreditations come next, in the roster order Check Point publishes, because they are the building blocks that reach those Master levels. HackingPoint sits last, ordered by the progression Check Point describes, and it sits last for a reason worth being explicit about: those five courses are not on the certification path at all, and someone planning a route upward should not mistake them for steps along it.

    • Nuovo strumento

      A tool for the Check Point sentence that everyone gets wrong

      Ordered layers are an AND, not an OR. Accepting in one layer means the connection proceeds to the next one, and it is allowed only when the last layer accepts, so a permit early cannot rescue traffic that a later layer drops. That is the behaviour people arriving from other firewalls reliably misread, and it is hard to see in a management console because you cannot watch a connection cross the layers. So the new evaluator shows exactly that: paste a policy and a connection, and each step says which rule matched and what the match actually meant, in words rather than a tick. It also names the drops that log nothing, which is the most expensive fact in a Check Point rule base, because a connection that fails with no log entry looks like a network fault rather than a policy decision. Alongside the trace it checks the policy itself for a missing or unlogged cleanup rule, rules with tracking switched off, and rules that can never fire because an earlier one already covers them. It deliberately does not duplicate the Zscaler rule-order simulator already here: that one teaches first match on a single rule base, which Check Point also does. This one teaches the thing Check Point adds, which is several rule bases in sequence, each of which has to say yes.

      Check Point policy layer evaluator

    • Contenuto

      Check Point's lineage is the mirror image of Extreme's

      Extreme bought its entire portfolio. Check Point built the one thing it is famous for and bought everything else. FireWall-1 shipped in 1994 on the stateful inspection patent and by 1996 held around forty percent of the worldwide firewall market, and almost every product added since arrived by acquisition: ZoneAlarm for endpoint, a Swedish disk-encryption business, Nokia's appliance line which is how a software company stopped depending on someone else's hardware, then cloud posture, email, zero-trust access, SASE, threat intelligence and most recently AI security. That is not trivia for anyone studying the certifications. It explains the product naming, because Quantum is the part Check Point wrote and CloudGuard, Harmony and most of Infinity are the parts it bought, which is why they read as distinct products sharing a management story rather than one system. Several of these deals were reported at different figures by different outlets and Check Point disclosed terms for only some of them, so where sources disagree the page gives both numbers and says which is which. Picking the flattering figure quietly is how a page that claims to be verified stops being one.

    • Contenuto

      Extreme Networks has a lineage page, and it explains why the product line feels the way it does

      Extreme is the most interesting corporate history among the vendors covered here, because almost nothing in the current portfolio was built by the company whose name is on it. Between 2013 and 2021 it assembled an end-to-end networking stack out of six acquisitions, most of them businesses that larger companies no longer wanted: Enterasys, then Zebra's wireless LAN line, then Avaya's campus networking division out of a bankruptcy auction, then Brocade's data centre business which Broadcom had to divest to get the fibre channel it actually wanted, then Aerohive, then a French SD-WAN division carved out of Infovista. That history is not trivia if you are learning the products. The reason ExtremeXOS and the fabric line behave so differently is that they were never variants of one design, they are separate operating systems from separate companies now sold beside each other. Each acquisition on the page carries what it turned into, so the Nortel shortest-path-bridging heritage arriving through Avaya connects to the fabric taught in the certification track, and Aerohive connects to the cloud platform the modern portfolio is organised around. Where a price was restated, as with Aerohive's headline figure against its value net of cash, both numbers are given rather than the flattering one.

    • Contenuto

      F5's corporate lineage moves to where F5 lives

      The page tracing what F5 is actually made of, twenty-three acquisitions and what each one became, used to sit under About. Two things were wrong with that. About is the autobiographical section, and a lineage is about the vendor rather than about me. And the page was written as a hub for every vendor's lineage while containing exactly one, so its copy talked about vendors in general and then showed F5 alone under a note promising more soon. It now lives at f5 slash vendor-lineage, one click from the F5 tools and articles, with copy that is about F5 rather than about the idea of lineages. The route builds itself from a registry, so adding a vendor means adding its researched data and one line, and a vendor whose acquisitions have not been verified yet simply has no page rather than an empty one. The bar has not moved: every acquisition is checked against primary sources before it ships, with the product line it turned into only where that connection is documented rather than inferred.

    • Contenuto

      Vendor hubs hand off in cards now, and finally mention their own reading paths

      A vendor hub used to point elsewhere in three different shapes: a bare text link to the vendor's history chapter floating above the title, and a callout box of inline links to its certifications. They are now one grid of cards, using the same portal card that already appears on the Learn and training pages, so a reader meets the same object every time a page hands off to another page. The addition worth having is the third kind. Every vendor with a guided reading path had that path reachable only from the study guides index, which meant the hub for a platform never mentioned the curated route through its own articles. Those paths now sit alongside the history and certification cards, with the number of articles on each. One thing changed under the surface to make it safe: working out which vendor a reading path belongs to was a rule living inside the study guides page, and the hubs needed the same answer. Rather than copy it, the rule moved into one shared function. Two copies of a rule like that drift the first time a vendor is added and only one is updated, and the failure is silent, since paths simply stop appearing on one of the two pages.

    • Contenuto

      Check Point gets a chapter, which is a strange one to write

      Check Point has been on this site as a partner-track card and a pair of study guides. It now has a chapter of its own, alongside the other vendors whose stories run through this record, and it is an odd one to write because it runs the wrong way round. Almost every chapter here is about a company that turned up to solve something the incumbents had left open. Check Point is the incumbent. It shipped stateful inspection as a product in 1993 and created the category every firewall on this site competes inside, so learning it now, after two decades on the platforms that came to challenge it, means meeting the original last. The page argues that the durable part was never the inspection engine, which others built too, but the management model: policy as a database held apart from the devices that enforce it, published before it is installed. Thirty years on that is still the thing that catches people arriving from other vendors, and still the model those vendors get compared against. The study guides are built from Check Point's own published blueprints, which describe what an exam covers and say nothing about who may deliver training for it.

    • Contenuto

      Better doors on the Learn page, and the training page stops pointing away from itself

      The Learn page had a row of pills, one per vendor, sitting between the portal cards and the articles. It grew by one pill every time a vendor was added and pushed the article index further down a page whose whole purpose is the article index. The pills are gone, replaced by three cards: one that jumps straight to the articles, one door to the vendor hubs, and one to the certification guides. The first of those is an in-page jump rather than a link, because the thing it points at was already on the page and simply had nothing directing anyone to it. The training page had the opposite problem. Three cards linking to the bio, the credentials and the endorsements sat at the very top, so the first thing a prospective client saw on a page about courses was three invitations to go somewhere else. They now sit after Beyond the classroom, at the point where someone has read the page and is ready to look further, which is when a pointer helps instead of interrupting.

    • Contenuto

      The industry page is a timeline now, because the old grouping was making a judgement it kept getting wrong

      Until now the wider industry split into pioneers and contemporaries, and the split did not hold up. Plenty of companies filed under the pioneers are still trading, so the two headings were describing the same thing twice while forcing a call on every new entry about whether a company counts as historical. Ordering by founding year removes the question. It is a fact rather than an opinion, it already sits in each profile's own sourced timeline, and it puts the story in the order it happened, which is what a lineage page is for. So the two sections are now one vertical timeline running from an 1847 pointer telegraph to a 2012 SD-WAN startup, with the year in the gutter so chronology can be scanned without reading a card. Cards will carry an end year where the company stopped existing independently. Those are being added by review rather than derived, because deriving them was tried and produced roughly thirty wrong answers out of forty-eight: prose cannot be pattern-matched for direction, since a company acquiring someone and a company being acquired read almost identically, and a divestiture reads like an ending. An absent end marker means still trading, which is the honest default.

    • Infrastruttura

      Three Check Point exams were listed twice, and a guard now makes that impossible

      Scaffolding the Check Point accreditation layer added guides for exams that already had them, so three of them appeared twice on the page: multi-domain management, virtual system extension, and the R81.20 troubleshooting expert. Both copies pointed at real certifications and both slugs resolved, so every existing check passed. That is the shape of the problem worth naming: the guards all verify that references RESOLVE, and none of them verified that a thing is only described once. The duplicates are merged, keeping the version-explicit records that were already there, and five accreditation exams that had been hanging off the Master certification now sit under their own accreditations where they belong. A new build check enforces it from here: no two guides may claim the same exam code, no two may share a slug, and a guide's link to its certification has to agree in both directions. Fortinet is exempt from the first rule and that is correct rather than a loophole, since its exam code is a level label that sixteen product exams share by design. The exemption is written down explicitly, because inferring it from the data would let a vendor with one duplicate look like a vendor whose codes were never unique.

    • Contenuto

      HackingPoint: five offensive-security credentials, and why they sit outside the certification path

      Check Point runs an offensive-security programme called HackingPoint, and its five PenTesting Expert courses now appear here: infrastructure hacking, web hacking, hacking IoT, cloud security, and advanced infrastructure hacking. They carry exam numbers, they are sat at the same test centres, and Check Point issues badges for them, so they are real credentials. What they are not is a step toward the Security Master, and that distinction is now stated on the card rather than buried in a note. Only Infinity Specialist Accreditations advance an expert certification toward Master, and Check Point lists the HackingPoint courses in a table of their own for that reason. Someone planning a route upward should not mistake one for the other. The infrastructure hacking course carries its full class content, transcribed from the synopsis Check Point publishes: fourteen modules from port scanning and online password attacks through to gaining access to a domain controller. The other four list what Check Point publishes about them and no more. Their synopses are multi-column documents that do not extract cleanly, and a syllabus that looks complete while missing modules would be worse than an honest gap.

    • Contenuto

      The rest of the Check Point path: nine specialist accreditations, and how the Master levels are actually earned

      Check Point's certification path has a shape worth knowing before you plan a route through it, because the top two levels are not exams. The Security Master is awarded automatically to someone holding a valid expert certification who then passes two specialist accreditations, and the Master Elite the same way from there. So the question is never when to sit the Master exam, it is which accreditations to choose. All nine are now listed with the exam numbers Check Point publishes: automation, Maestro, cloud, Harmony endpoint, multi-domain management, virtual system extension, troubleshooting at administrator and expert level, and threat prevention. Two rules attached to them decide whether an accreditation counts for anything beyond itself. It has to be passed after the core certification rather than before, and the core certification has to still be valid at the time. An accreditation passed first, or passed against an expired expert certification, is awarded and extends nothing. Three of the accreditations are also on their way out: multi-domain management, virtual system extension, and the R81.20 troubleshooting expert all stop being available on the thirtieth of September 2026, and the troubleshooting expert has a named R82 replacement.

    • Contenuto

      Being precise about which vendors carry an instructor authorization

      This site covers seven vendors, and they are not all covered for the same reason. Some hubs exist because the author is authorized to teach that vendor's courses; others exist because the technology is worth explaining and the certifications are worth studying for, which is a different claim entirely. Copy that blurred the two has been corrected, and the line on the front page that claimed authorization across every vendor covered here has been reworded, because it stopped being accurate the moment this site started covering more vendors than it delivers training for. The study guides are unaffected. An exam blueprint transcribed from a vendor's own published guide is just as useful whoever teaches the course, and nothing about the accuracy of that material depended on the claim that has been removed.

    • Contenuto

      The rest of the Check Point path, as far as the published sources actually go

      Check Point's certification path runs from administrator to expert, then through specialist accreditations to Security Master and Security Master Elite. The two master levels are now modelled, and neither is earned by an exam of its own: Security Master is an active expert certification plus two specialist accreditations, and Elite is two more on top, four across the whole path. The specialist tier is where this stops short, and deliberately. Check Point's own certification page describes that tier in prose and renders the list of exams as an image, so there is no roster to read. Pearson VUE publishes codes only for the exams it happens to mention in its announcements and retirements. Five are confirmed that way and are scaffolded, three of them carrying retirement dates at the end of September. Searching turns up several more, but only from exam-dump sites and a forum post that contradict each other on the codes, with one cloud exam appearing under two different numbers. Publishing those here would put a number in front of someone about to book an exam, so they are left out until a source worth trusting supplies them.

    • Contenuto

      The CCSE is covered too, so both Check Point core exams are complete

      Six articles finish the Check Point Certified Security Expert blueprint. Management high availability opens with what it actually protects, which is the ability to manage rather than the traffic, since gateways enforce their installed policy whether or not any management server exists. Failover is manual by design, and the reason is worth knowing: automatic promotion between two servers that can both write to a database is how you get a split brain, which is a worse problem than an unavailable server. The NAT article covers the fault that wastes the most time on this platform, where a manual static NAT is configured perfectly and receives nothing at all, because manual NAT does not create proxy ARP and the upstream router is asking who owns an address nobody answers for. The VPN article makes the same kind of point: the tunnel that fails to establish is easy, and the one that establishes and carries nothing is the real problem, which almost always traces to a network missing from an encryption domain or to VPN traffic that was never excluded from NAT. Upgrades cover the ordering rule that is not a preference, since a management server can manage older gateways and an older one cannot manage newer, plus the three operations that all sound like backup and are not interchangeable.

    • Contenuto

      The CCSA is fully covered: every objective now has an article behind it

      Four more articles finish the Check Point Certified Security Administrator blueprint. Logging starts from the two conditions that have to hold before a log exists at all, since a rule set not to track handles traffic silently and a gateway that lost its log server enforces policy perfectly while producing no evidence. Identity Awareness covers writing rules about people rather than addresses, and is organised around the choice that actually decides whether a deployment works, which is where the gateway learns the user-to-address mapping from. The web control article puts HTTPS inspection, application control and URL filtering together because they are one subject: without decryption the gateway sees a destination, a handshake name and a certificate, which supports categorisation and not much else. It also covers why bypass is standard rather than a compromise, since certificate pinning and privacy obligations both point at the same mechanism. Threat prevention closes it with the setting that matters more than which engines are enabled: an engine in detect mode logs while the traffic proceeds, so a profile left that way produces a complete and entirely inert record of attacks that succeeded, and the dashboards look identical either way.

    • Contenuto

      Check Point arrives: CCSA and CCSE study guides, and the first four articles

      Check Point is the seventh vendor on this site, starting with the two certifications that open its path: the Certified Security Administrator and the Certified Security Expert. Both guides carry objectives transcribed from Check Point's own published exam prep guides rather than assembled from secondhand summaries, which means the exam facts are exact: both are a hundred questions in ninety minutes at seventy percent, and the expert exam requires a passed administrator exam that is allowed to be expired. The first four articles cover the part of the platform that surprises people arriving from other firewalls. Check Point separates where policy is written from where it is enforced, so a rule is not live because you saved it. It becomes visible to your colleagues when you publish and it changes traffic when you install, and those are two different actions. Unmatched traffic is dropped by a rule that does not exist and logs nothing, which is why every real deployment adds an explicit final rule that drops and logs. And policy layers are an AND rather than an OR: accepting in one layer only means the traffic proceeds to the next, so a permit early cannot override a drop later.

    • Infrastruttura

      A build guard for the rule that half-shipped three articles in one day

      Articles here are written in English and Brazilian Portuguese in the same change, and until now nothing enforced it. In a single day that rule broke three times: once when work was interrupted between writing the two files, once when a write went through the wrong text encoding and threw, and once when an accented character ended up inside a payload that could not carry one. Every time, the twelve existing guards stayed green while the site carried an article that existed in one language only, and every time it was caught by counting files by hand. Hand-counting is not a control. The new guard fails the build if an article exists in one locale and not the other, in either direction, since an orphaned translation usually means the English was renamed and the pair broke silently. Writing it turned up something worth knowing: articles route on the slug declared inside the file rather than on the filename, so one long-standing file whose name and slug differ is correct rather than broken. The check was rewritten to test what actually matters, which is that both locales agree on the routing slug, and then verified by deliberately breaking it both ways to confirm it fails when it should.

    • Contenuto

      Every published Fortinet exam objective now points at something that teaches it

      NSE 8 is the last of it, and most of it was already written. Its objectives are terse topic terms rather than sentences, things like Zones and Hardening and Meta fields, so they needed rules written against those exact words before they would match anything. Once they did, one hundred and sixteen of the hundred and thirty-four resolved to articles that already existed, which is the pattern this whole programme has followed: the expert exam re-asks what the practitioner exams below it cover. Eighteen were genuinely uncovered and four new articles close them. Traffic shaping gets the observation that it does nothing at all until a link is congested, so it is really a plan for who suffers when there is not enough, and the design fault that turns up everywhere is guarantees that quietly sum to more than the link can carry. SD-Branch is about turning a site into a template rather than a pile of separately configured equipment, with the honest note that stretching a layer 2 segment across a WAN is a compromise rather than a default. The carrier networking article ends up making the same point the DDoS and network access control articles reach independently, which is that an address is not a user. And the operational technology article starts from the inversion that makes the rest of this collection inapplicable there: availability outranks confidentiality, patching is often impossible, and scanning can stop a production line.

    • Contenuto

      Every Fortinet exam below NSE 8 is now fully covered

      Five new articles finish the last products that had objectives but nothing explaining them. FortiDDoS gets the argument that matters most before any configuration: an inline appliance cannot mitigate an attack larger than the link feeding it, so anything bigger belongs upstream, and a device working perfectly during an outage is the predictable result of ignoring that. Its behavioural approach also means a genuine traffic surge from a product launch looks exactly like an attack unless somebody said so in advance. FortiRecon covers the reconnaissance an attacker performs before touching anything, which your own defences cannot see because none of it crosses your firewall, and it reliably finds forgotten staging servers and cloud accounts nobody folded into the inventory. FortiMail Workspace explains why an API connection beats a mail gateway for cloud mail: it inspects after the platform's own filtering, sees internal mail a perimeter never touches, and can pull a message out of every mailbox it already reached. Along the way fifty-four entries were removed from the study guides that were never objectives at all, things like a PDF viewer and speakers or headphones, swept in from the technical requirements listed further down the same course pages.

    • Contenuto

      The three entry-level Fortinet certifications now have their objectives

      NSE 1, NSE 2 and NSE 3 sat empty for a while because their certification pages describe the certification without listing what it covers, and the courses that do list it are not linked from them. With the right course pages in hand, all three are filled and every objective points at material already on this site, which is what you would expect at that level: an entry-level objective about firewalls, web application firewalls and network access control is answered by the articles written for the exams above it. One correction worth recording. NSE 1 was briefly populated from the wrong course, an older information security awareness syllabus rather than the cybersecurity and cloud fundamentals one the certification actually maps to. The objectives were plausible and they were not the right ones, which is a reminder that a source that looks correct is not the same as the correct source.

    • Contenuto

      Deception and application delivery, plus the NSE 1 to 3 course objectives corrected

      Four new articles cover two products this site had nothing on. The FortiDeceptor pair rests on a property no other control has: a decoy has no legitimate users, so any interaction with it is suspicious by construction rather than by scoring. That is why deception produces so few false positives, and it is also fragile in a way worth stating, because a decoy on a subnet your own vulnerability scanner sweeps will generate alerts every night. The distinction between decoys, lures and tokens matters too: tokens sit on real machines, so a token alert names the endpoint that is actually compromised, which is usually more valuable than the decoy interaction that revealed it. The FortiADC pair covers the two decisions that determine whether a stateful application survives load balancing. Persistence is the one people diagnose last and should suspect first, since intermittent user-specific failures look like application bugs. Health checks are the other, because a check that only confirms the port is open will keep sending traffic to a server whose application has crashed behind a live socket. Separately, NSE 1, 2 and 3 now carry their course objectives, and NSE 1 has been corrected: it was transcribed from the wrong course page and now cites Cybersecurity and Cloud Fundamentals, which is the course the certification actually names.

    • Contenuto

      Ten more Fortinet exams filled in from Fortinet's course pages

      Eight exams here had study guides with nothing in them, because Fortinet's exam pages for those products are empty shells: correct title, no topics, no details. Their course pages are a different story, and each publishes a full objectives list. Those are now transcribed, which fills FortiADC, FortiAnalyzer Administrator, FortiAppSec, FortiDDoS, FortiDeceptor, FortiMail Workspace, FortiRecon and SD-WAN Core, along with NSE 1 and NSE 3. One distinction is preserved rather than glossed over: these are course objectives, not exam objectives. Each guide says so, and cites the course page rather than a blueprint, because the material is what the course teaches and an exam may organise or weight it differently. Presenting one as the other would be a small lie that a candidate would only discover at the wrong moment. NSE 2 is still outstanding: its course page has no objectives section, and the several likely addresses for one all return errors, so it stays honestly marked as in preparation rather than filled with something approximate.

    • Contenuto

      Study guides now flag a retiring exam instead of an unavailable one

      Some Fortinet exams are listed on a certification page before they can actually be booked, and until now this site put a caveat on those cards. That caveat is gone. Someone preparing for a certification studies the same material either way, so telling them an exam is not bookable yet added noise without changing what they should do. What does change what you should do is an exam being withdrawn, because that comes with a deadline and usually a successor. Four guides now carry that instead: the exam version being retired, the last date it can be sat, and the exam replacing it, all named exactly as Fortinet names them. The clearest case is the FortiSASE and SD-WAN Core Administrator exam, whose current 7.6 version can be sat until November 14 2026 and is replaced by a 26 version. The others are earlier versions being withdrawn in favour of the exam the guide already covers, which matters to anyone part-way through preparing for the older one. Dates and exam names are reproduced verbatim from Fortinet's exam pages; only the wording around them is translated.

    • Contenuto

      The NSE 8 syllabus, rebuilt from the part of Fortinet's page that is intact

      The four NSE 8 exam pages have a problem worth explaining, because it changes what this site can honestly show. Their Tasks column is truncated: entries read as fragments like availability (HA) where High is missing, next to others that are simply blank. A fresh fetch confirms it is the live page rather than a stale copy, since the words that should be there appear nowhere on it. Beside those broken entries sits a Details column that is complete and specific, naming the actual technologies each area covers. So the objectives here are now transcribed from Details, grouped under the published section headings with their weightings, and each guide says plainly that this is what was done and why. That turns forty-one unusable fragments into three hundred and thirty-nine real objectives. More than half of them already link to material on this site, which is the expected shape: NSE 8 sits above everything else in the programme and re-asks it at expert level, so an objective naming FGCP or ADVPN or inter-VDOM routing reaches the article that already explains it. The remainder stay marked as gaps rather than being pointed at something approximate.

    • Contenuto

      Every Fortinet exam below NSE 8 now has all of its objectives covered

      Five new articles close the last six exams outside NSE 8, and four of those six needed almost no new writing because the material was already here. The architect exams re-ask what the practitioner exams beneath them cover, in a different frame, so most of their objectives resolve to articles that already existed. The FortiWeb pair is genuinely new ground. A web application firewall is unusual in that it terminates and re-originates the traffic it protects, which is where its capability comes from and why an outage takes the application with it, so the deployment progression matters: observe offline first, then inline without blocking, then block once the exceptions are known. Going straight to blocking on an application nobody has profiled is how a firewall gets removed after its first outage. Bots get their own treatment because they are not distinguished by payload, since a credential-stuffing bot sends perfectly well-formed login requests, and APIs get theirs because there is no browser to challenge and no page to inspect, which makes schema validation the strongest control available. The logging article addresses the situation most FortiGate investigations actually begin in, which is a log that does not exist because the policy was never set to write one.

    • Contenuto

      Email security and cloud posture: FortiMail and FortiCNAPP at zero gaps

      Five new articles close both exams. The FortiMail set starts with the protocol, because email security depends unusually heavily on it: the SMTP envelope routes the message and is what policies match, while the header is what the recipient's mail client displays, and the two are allowed to differ. That gap is not a flaw, since forwarding and mailing lists depend on it, and it is also the entire mechanism behind display-name spoofing. It explains a recurring configuration puzzle too, because a policy that appears not to match is often matching the envelope while you are reading the header. The encryption article gives identity-based encryption the space it deserves, since it solves the problem that kept encrypted email impractical for decades: S/MIME is genuinely end to end and requires the recipient to already have a certificate, which an arbitrary external correspondent does not. IBE needs nothing but a mailbox and a browser, and the honest cost is that recipients see a notification rather than a message, which looks exactly like phishing unless you have told them to expect it. The FortiCNAPP pair argues that cloud risk is four different problems whose value comes from being held together, because a vulnerable workload is a finding while a vulnerable, internet-facing workload running with administrative permissions is an attack path, and no single view identifies it.

    • Contenuto

      The Security Operations track is complete

      Three new articles close the last two exams in the security operations line. The architect exam turned out to need very little new writing, because eleven of its fourteen objectives are already answered by the FortiSIEM and FortiSOAR material; what was missing was the frame around them. That article treats the SOC as a set of questions rather than a product list, since an endpoint execution, an outbound connection and a phishing email are each unremarkable and are an incident when they happen together in that order, which no single product sees. It argues for writing detections against techniques rather than indicators, because an address changes cheaply while the method of achieving an objective does not, and it insists a detection without a defined response is telemetry that belongs in a dashboard. The FortiNDR pair covers what watching traffic adds that endpoint agents cannot: devices that cannot run an agent, lateral movement between hosts, and the devices no inventory lists, which the first sensor deployment usually finds. Detection still works on encrypted traffic because certificate, name, timing and volume are all observable without payload, and beaconing is recognisable from regularity alone. The retention argument is the one worth carrying away: intrusions are found long after they start, so retention shorter than your typical discovery interval means the beginning of the incident is already gone when you go looking for it.

    • Contenuto

      FortiSOAR: three articles for the largest remaining exam

      FortiSOAR is usually described as an automation platform, which undersells the part that decides whether a deployment succeeds. It is a structured datastore for security work with automation attached, and the data model is what everything else rests on. Get it right and playbooks compose; get it wrong and every playbook becomes a special case. The first article covers modules, records, typed fields and relationships, and makes the case that field type is not a detail: a picklist can be grouped in playbook conditions and dashboards while free text cannot, which is why a dashboard often cannot summarise something. The playbook article argues that most of the learning curve is about data rather than logic, because the output of a connector action is whatever that product's API returned and rarely the shape the next step wants. Bridging that gap is the actual work, which is what Jinja is for, and the default filter is the difference between a graceful path and a stopped execution on the one record missing a field. The third covers the workflow features that decide whether the automation serves people well: phases make an incident's position visible, queues plus shifts route work to whoever is actually on duty rather than to someone who may be asleep, and war rooms keep the collaboration attached to the incident so the record is still usable at the post-incident review.

    • Contenuto

      FortiDLP and FortiSIEM: the SASE track finishes and security operations begins

      Five new articles close both exams. The FortiDLP pair starts from where the product can see, because data loss prevention that watches the network boundary made sense when data left over a network you owned, and neither half of that holds now. The endpoint agent sees a file before it is encrypted, which is why it can answer questions a network sensor cannot, and SaaS integration covers data that never touches a managed device at all. Coverage is the union of the two, and knowing which half is missing for a given path is what makes a deployment honest rather than merely deployed. The detection article argues against the instinct to block everything sensitive, since people then find a route you are not watching, and makes the case for the justify action that most deployments skip: requiring a reason records the business process the policy never anticipated. The FortiSIEM set covers building queries outward from a real event rather than from memory, why the configuration database is the difference between a SIEM and a log search, and how subpatterns joined on a shared field express a sequence that no single search can. One nice piece of reuse: the FortiSIEM exam genuinely contains a FortiEDR section, so those objectives point at the FortiEDR articles already here rather than repeating them.

    • Contenuto

      Endpoint management and detection: FortiClient EMS and FortiEDR at zero gaps

      Five new articles close both exams. The EMS pair is built on a distinction that resolves most confusion with it: EMS is where endpoints register, and separately where you describe what they should be. An installed client that never registered has no profile, so it runs defaults rather than your configuration, and an estate where some endpoints behave oddly is usually an estate where some never registered. The ZTNA section is worth reading even for people not deploying it, because the dependency catches teams out: ZTNA tags come from EMS, so an endpoint that stopped reporting has stale or absent tags and the resulting access failure looks like a firewall problem while being an endpoint management one. The FortiEDR set starts from the claim the product is built on, that the decisive moment is not when a file arrives but when a process tries to do something it should not. That explains why collectors block at the point of action and why losing the cloud service degrades enrichment rather than removing enforcement. It also separates the two policy families that get conflated, since an application that should not be talking to the internet is a communication control problem while a process injecting into another is a security policy problem, and configuring the wrong one produces a rule that never fires. The investigation article makes one point plainly: collect forensics before remediating, because reimaging destroys the evidence exactly when the question of what else was reached becomes urgent.

    • Contenuto

      FortiSwitch and wireless: two more exams at zero gaps

      Six new articles close the FortiSwitch and Secure Wireless LAN exams. The FortiSwitch set starts from what FortiLink actually changes, which is that the FortiGate becomes the switch controller and configuration made directly on a managed switch is liable to be overwritten. It covers the detail that makes QoS appear broken, namely that a port trusting nothing ignores however carefully an endpoint marked its traffic, and the dependency that makes security features break servers: dynamic ARP inspection and IP source guard both need the DHCP snooping table, and a statically addressed device is invisible to it unless you add a binding. The wireless set argues that most complaints are radio problems wearing a configuration costume, and gives the readings that separate them. Signal strength with channel utilization distinguishes coverage from congestion from interference, and there is a fourth case worth taking seriously where everything reads fine and the problem is upstream in DHCP or DNS. It also makes the case against the instinct to raise transmit power, since clients then hear the access point from further away than it hears them, and the case against one SSID per group, since every SSID costs airtime on every access point whether anyone uses it or not.

    • Contenuto

      FortiManager and FortiNAC now have their exams covered end to end

      Five new articles take both the FortiManager Administrator and FortiNAC exams to zero gaps. The FortiManager set is built around the fact that surprises everyone: FortiManager is not a remote-control window onto your firewalls, it holds its own database of each device's configuration and installs from that. Once that lands, out-of-sync makes sense, import and install become a choice where picking wrong discards someone's work, and the install preview stops being a step to click past. The preview is where the expensive accident is visible, because an install pushes the database's view and can remove a policy someone created locally. The FortiNAC pair starts from the same ordering: nothing can be controlled until it is identified. Modeling teaches FortiNAC which switches to read and change, with SNMP and CLI credentials that fail in different ways, and profiling classifies what appears on those ports with first-match rules that shadow each other exactly like firewall policies. Rogue is worth reading carefully: it means unclassified rather than hostile, and a flood of them usually means incomplete profiling rather than an attack. The isolation article carries the rule that decides whether a deployment works at all, which is that an isolated endpoint must still reach whatever it needs in order to stop being isolated.

    • Contenuto

      FortiAnalyzer, explained around the split that causes most of its surprises

      Three new articles take the FortiAnalyzer Analyst exam to zero gaps, and they are organised around one fact that explains most FortiAnalyzer confusion. Every log goes to the archive, but only logs inside the analytics retention window are indexed, and only indexed logs are searchable or reportable. That single split is the answer to why a report for last quarter comes back empty, why a search finds nothing from six months ago, and why the disk fills faster than the retention settings suggest. The second article covers the security operations side as four stacked layers, where logs become events through handlers, events group into incidents carrying indicators, and playbooks act through connectors. Each layer only sees what the one below produced, so the diagnosis for a silent event handler is to search the raw logs first: if they are not there, no rule above them can fire. The third covers reporting as three separate objects, since a dataset is a query, a chart renders one dataset, and a report lays out charts, which is why the report is wrong is not a diagnosis. It also notes the trap that predefined reports are overwritten on upgrade, so clone before editing.

    • Contenuto

      Fortinet exam objectives now link to the material that teaches them

      Fifty-nine Fortinet exam objectives now point at the articles and tools on this site that actually cover them, so an objective about route selection reaches the routing article and the route selection explainer rather than sitting as an unlinked line. The mapping is deliberately conservative, and one rule matters more than the rest: an objective and a resource must belong to the same product family. An early pass matched on topic alone and sent Ping Identity objectives about clustering and authentication to FortiGate articles, which would have handed a candidate material that answers nothing they were asked. Those were caught and removed before they shipped. The remaining Fortinet objectives stay honestly marked as gaps, because they cover products this site has no content for yet, from FortiSOAR and FortiManager through FortiSwitch, FortiNAC and FortiCNAPP. Marking them as covered would be the easy lie.

    • Contenuto

      Twenty-four Fortinet exams now carry their objectives, with the weightings Fortinet publishes

      Fortinet publishes exam topics in two shapes. Some exams use a plain nested list; others use a table of tasks and details grouped under headings that carry a percentage weighting, telling you how much of the exam each area is worth. Both are now read, so twenty-four of the thirty-eight Fortinet exams here have their objectives, up from one. The weightings come through intact, which matters for anyone deciding where to spend study time: an area worth forty percent of the exam deserves more attention than one worth ten. The fourteen still in preparation are not an oversight. Eight are exams whose pages publish no topics at all yet, and the rest are either coming soon or, in one case, publishing placeholder text where the exam details should be. Those stay honest about being incomplete rather than filled with guesses.

    • Contenuto

      Eleven more Fortinet exams now have their objectives, and every guide cites its own source

      A sweep of the Fortinet Training Institute filled in a great deal. Every one of the thirty-three Fortinet exams that has its own page now links to that page rather than to the general programme page, so each guide cites the source its objectives come from. Eleven more exams have their objectives transcribed alongside NSE 4, taking the site from 769 mapped objectives to 1,065. Availability is now read from each exam's own status rather than inferred from a footnote, which corrected several entries in both directions: two NSE 7 architect exams were marked as unavailable here and are in fact live, while six others that are not yet sittable had no warning at all. One exam turns out to be retiring rather than arriving, and now says so with its date. The FortiAppSec exam is the interesting case: Fortinet's page for it publishes literal placeholder text where the time limit, question count and product version should be, so there is nothing to transcribe. Rather than presenting placeholders as facts, that guide stays in preparation and says the details have not been published yet.

    • Contenuto

      The Fortinet certification path now matches Fortinet's own, certification for certification

      A pass over Fortinet's official certification page corrected two things here. The first is structural. NSE 5, 6 and 7 are not one certification each with several tracks underneath: each track is its own certification, with its own badge, its own prerequisites and its own renewal rule. There are nineteen Fortinet certifications, not ten, and the study guides are now grouped that way, with thirty-eight exams sitting beneath them. The second is a set of details that were wrong in small ways that matter to someone planning a path. NSE 1 and NSE 2 require a course and a test rather than a course alone. The NSE 7 prerequisites are track-specific, so NSE 7 in SASE needs an NSE 5 or NSE 6 in SASE rather than in any track. And Fortinet's own table lists no NSE 4 requirement for NSE 7 in Security Operations, unlike the other three tracks; that is transcribed as published rather than quietly corrected, with a note saying so. Every certification now links to its own page on the Fortinet Training Institute, so the requirements can be checked against the source in one click.

    • Nuovo strumento

      A config diff that knows when a moved policy is a change

      Paste two FortiOS configurations and this new tool compares their structure rather than their text, reporting what changed by section, object and setting. A textual diff finds a minimal edit script, which is not the same thing as the change a person made: it reports a moved block as a deletion plus an insertion, marks an object as changed because a neighbour grew a line, and buries three real edits in four hundred lines of context. The judgement here is about order. For most sections the order of objects is irrelevant, so a reordering is ignored as noise. For firewall policy and its relatives order is the behaviour, because first match wins, so moving a policy above another changes what the device does without changing a single setting. That is the edit a line diff hides most thoroughly, since nothing differs textually except position, and it is reported as a real finding with the before and after sequence named. Both behaviours are pinned by golden vectors, because getting either backwards would make the tool actively misleading. Identical input produces silence rather than reassurance, which is also pinned.

      FortiOS config diff explainer

    • Nuovo strumento

      Why your security profile is attached, configured, and doing nothing

      Describe a policy and this new tool tells you which of its security profiles can actually see the traffic. It walks a dependency chain: a policy must permit the traffic, SSL inspection must decrypt it, the inspection mode must support the feature, and only then does the profile act. Most reports that a profile is not working resolve at the second step, where the traffic is HTTPS, the policy carries certificate inspection rather than deep inspection, and there is nothing to read. The judgement it exists to make is the difference between blind and degraded. AntiVirus, IPS, DLP and file filter all need the message body, so behind certificate inspection they are not partly effective, they are inert. Application control and web filter can still identify some traffic from handshake metadata such as SNI, so a hostname policy applies while a URL-path policy does not. Telling someone a profile is partly working when it sees nothing at all is the more dangerous error, so the two are separated and styled differently. It also refuses to overclaim: it models coverage, not detection, and will never tell you a profile would catch a particular threat.

      FortiGate security profile coverage checker

    • Nuovo strumento

      Why the route you configured is not in the routing table

      Give a destination and a set of routes and this new tool runs the selection FortiOS would, showing which routes install, which one traffic takes, and which are floating backups. It exists for a distinction that is routinely collapsed into one idea. Administrative distance decides which route is INSTALLED: routes to the same destination compete, the lowest distance wins, and the loser is absent from the forwarding table rather than ranked below it. Priority decides which of several already-installed routes is preferred, and it can never rescue a route that lost on distance. That difference is why a route you configured cannot be found in the routing table at all, and why a standby default route is built as the same prefix with a higher distance rather than a worse priority. The tool models a down route too, so you can watch a floating backup take over, which is exactly what link health monitoring exists to trigger. It also states what it leaves out: policy routes and SD-WAN rules are both consulted before the routing table and override it, so a forgotten policy route remains the classic cause of traffic ignoring an obviously correct static route.

      FortiGate route selection explainer

    • Nuovo strumento

      Which phase is your IPsec tunnel failing at, and why

      Describe both ends of an IPsec tunnel and this new tool names what they disagree about and which phase would fail. That second part is the whole diagnosis: a phase 1 failure is about identity or proposal and no phase 2 is ever attempted, while a phase 2 failure means the peers authenticated and then disagreed about what to protect. Getting it backwards sends you to the wrong half of the configuration. As much care went into the differences it refuses to flag as into the faults it finds, because an analyser that reports healthy configurations as broken is one people stop reading. Proposal lists do not have to be identical, they only need one value in common, so the tool computes the intersection. Lifetimes do not have to match because the shorter one wins, so it names the effective value instead of raising an alarm. And selectors are compared crossed, since one peer's local subnet is the other's remote, which means a correctly mirrored tunnel is reported as correct rather than as a mismatch. Blocking disagreements and harmless differences are kept visually apart. It also knows what it cannot answer: when nothing fatal is found it reminds you that a tunnel which reports up and carries no traffic is missing a route or a policy, not an IPsec setting.

      FortiGate IPsec phase mismatch analyzer

    • Nuovo strumento

      Why the unit with the higher priority is not the primary

      Describe an FGCP cluster and this new tool runs the primary election, names the criterion that decided it, and tells you who would be primary if override were toggled. It exists for one question that gets asked constantly: why is the unit with the higher priority not primary? The answer is almost always that with override disabled, which is the default, FGCP compares age before priority, so a unit that rebooted stays secondary no matter how high its priority is. That is not a misconfiguration. The default exists so a flapping unit cannot repeatedly seize and lose the role, because each seizure disrupts traffic, and Fortinet chose stability over preference. The most useful output is the counterfactual. Knowing that one unit is primary is a fact; knowing that with override enabled the other one would be, and that this single setting decides the whole outcome, is a decision. When toggling override would change nothing, the tool says that too, which rules out a line of investigation in one line. It models the election only, and says so: session survival across a failover and split brain are different questions covered in the high availability article.

      FortiGate HA failover simulator

    • Nuovo strumento

      The FortiGate session table, read back to you

      The session table is the authoritative record of what a FortiGate actually did with a flow, and its format is dense enough that the information is usually present and unread. Paste diagnose sys session list output into this new tool and it reads back the protocol and state, the policy that admitted the session, what was translated on each leg, the timers, and the offload state. It leads with the reading people skip. A statistic line showing outbound packets and zero reply means the FortiGate forwarded the traffic and nothing came back, which is not the firewall blocking anything, because the session exists and therefore a policy permitted it. Misreading that as a firewall problem is the most common and most expensive mistake made with this output, so the tool states the conclusion before the fields rather than after them. It is also explicit about what it will not tell you: fields whose full value tables are vendor documentation are shown raw, with meaning asserted only where it is documented and unambiguous. A decoder that guesses at a value table looks more complete and is wrong exactly when the value is unusual, which is exactly when someone is reading a session table in the first place. It pairs with the policy lookup explainer: that one predicts which policy should match, this one confirms which policy did.

      FortiGate session table explainer

    • Nuovo strumento

      A tool that finds the FortiGate policy you cannot see is broken

      Paste a FortiGate policy list and a packet, and this new tool runs the evaluation FortiOS would: top to bottom, every criterion must match, first match wins. It names the policy that matches and, more usefully, the first criterion that eliminated each policy above it, because a rule with the right addresses and the wrong outgoing interface fails silently and its hit counter simply never increments. The part worth having is what it does with the policies below the match. A later policy that is at least as specific as the winner is shadowed: it is live in the configuration, looks correct on screen, and can never take effect as ordered. A later policy that is broader is a catch-all, which is correct design and not a fault. Most tools of this kind conflate the two and flag every well-ordered list, so specificity is computed rather than assumed. It accepts both FortiOS CLI output and a pasted table, and it is honest about its one limitation: matching compares object names rather than resolved addresses, because a pasted policy list does not carry the address-object definitions. It could guess, and it would be confidently wrong whenever a name did not describe its contents.

      FortiGate policy lookup explainer

    • Contenuto

      Every NSE 4 objective now has something behind it

      The NSE 4 study guide published with fourteen of its eighteen objectives marked as gaps. Five more articles close the rest, so every objective on the exam now links to material that teaches it. Initial configuration covers the factory state and the two decisions that are awkward to reverse later, since switching between NAT and transparent mode erases the configuration and enabling VDOMs makes every command context-sensitive. The high availability article covers an election order where age sits above priority by default, which is why a recovered unit stays secondary until you enable override, and the detail most likely to bite in production is that session pickup is off by default, so a cluster can fail over correctly and still break every connection. Authentication and FSSO covers the difference between asking the user and learning from the directory, and why neither is complete on its own. The IPsec article is organised around which phase failed, because that single fact narrows a fault immediately, and it covers the case that wastes the most time: a tunnel that reports up and passes nothing is missing a route or a policy rather than an IPsec setting. The last covers the three things carrying the FortiGate name in the cloud, where the real difference is who operates the firewall.

    • Contenuto

      Three FortiGate articles, written against real exam objectives

      The NSE 4 study guide published with fourteen of its eighteen objectives marked as gaps, meaning the objective was real and this site had nothing behind it. Three articles close half of them. The first covers firewall policies and NAT, and its centre is the sequence: destination translation through a virtual IP happens before the routing lookup and before policy evaluation, which is why the policy destination must be the VIP object and not the internal server address, while source translation happens after the policy matched. It also covers why central NAT and policy NAT are architectures you choose per VDOM rather than settings you mix, and how to read a session table to find out which policy actually matched. The second covers the security profiles, and its argument is a dependency chain: a policy must permit the traffic, SSL inspection must decrypt it, the inspection mode must support the feature, and only then does the profile act. Most reports that a profile is not working resolve at the second step, where certificate inspection leaves nothing to inspect. The third covers routing and SD-WAN, where policy routes are consulted before the routing table and override it, administrative distance decides which route installs while priority decides between routes that already did, and an SD-WAN rule that appears to be ignored usually has all its members failing their performance SLA.

    • Contenuto

      The Fortinet certification path is rebuilt around the exams you actually sit

      Fortinet restructured its certification program on 15 July 2026, retiring the FCF through FCX names and returning to eight NSE levels across four tracks. The study guides here now follow that structure exactly: thirty-eight exam guides grouped under ten certification levels, because a level like NSE 6 is not one exam but sixteen product exams of which you sit one. Each level states what it takes to earn it in Fortinet's own wording, which prerequisite certifications must be active first, and how renewal works. That distinction matters more than it sounds: NSE 5 lists eight exams and NSE 6 lists sixteen, and saying you must pass all of them would be wrong by a factor of eight. NSE 8 is different again, needing the Core practical exam plus one of three electives, so it states its rule rather than counting. Eight exams that Fortinet has published but not yet released now say so on the card and on the guide, rather than looking like ordinary guides awaiting work. The NSE 4 FortiOS Administrator guide is the first with its objectives mapped: five sections and nineteen objectives transcribed from the Fortinet Training Institute exam page, each linked to the official administration guide and, where this site has one, to an article or tool that teaches it.

    • Contenuto

      Every term the articles and tools reference now has a full explanation

      This completes the third wave. Every glossary term referenced by a Learn article or a tool page now carries a treatment in English and Portuguese, which means you can follow a link out of any article and land on something that explains rather than restates. The batch runs from the standards bodies to the physical plant. NIST covers the difference between what it standardizes and what it recommends, which matters because it reversed its own password advice on evidence. ICMP and path MTU discovery cover the most common self-inflicted network fault there is, which is blocking the messages that make IP work and then debugging a connection that establishes and hangs on anything large. GCM explains why a repeated nonce does not merely leak plaintext but can expose the authentication key itself. The instance metadata service covers the mechanism behind several very large cloud breaches, and why enforcing the second version rather than merely enabling it is the part that gets missed. Service principal names cover why nearly every Kerberos failure is really a naming failure, and why a password prompt appearing where single sign-on should have been silent is the diagnostic. Cabling, plenum rating, wiring closets, ADSL distance limits and the plain old telephone line that powered itself round out a batch that spans sixty years of infrastructure.

    • Contenuto

      Wave three opens on the working terms, in a deliberately shorter form

      With the folklore finished, the depth programme moves to the technical terms the articles and tool pages actually reference. These entries are shorter than the ones in the first two waves, two paragraphs rather than three, because the terms are narrower and padding them would be worse than leaving them alone. The first batch covers the web vulnerabilities with their real defences, so cross-site scripting lands on contextual output encoding rather than input filtering, and cross-site request forgery explains why SameSite closes most of the class and still leaves cookie-authenticated APIs and state-changing GETs exposed. Path MTU discovery covers why a correct mechanism fails constantly, which is that the ICMP messages carrying its reports are widely blocked, producing the connection that establishes and then hangs on anything large. Longest prefix match explains why specificity beats legitimacy in a forwarding decision, which is the gap that makes prefix hijacking work. On the access network, GPON, OLT and ONT are covered as one story about a passive plant where nearly all diagnosis happens from one end and received optical power is the number that settles most disputes. Jumbo frames, LACP, VRF, ACLs, runbooks, escalation, Active Directory, RBAC, device management and RMAs complete the batch.

    • Contenuto

      Every piece of folklore and every saying in the glossary now goes deep

      This finishes the second wave. All 177 lore entries and all 144 expressions carry a full treatment in English and Portuguese, which means the part of this glossary that nothing else has is now the part that is most complete. The last batch covers the named cryptographic attacks by their mechanism rather than their logo, including why DROWN could break a modern server through an obsolete protocol running somewhere else that merely shared a key, and why ROBOT is a twenty-year-old attack that came back because its mitigation required every implementer to keep getting a subtle behaviour right forever. The security sayings get their qualifications: do not roll your own crypto means do not implement primitives, not do not learn how they work, and the reason it holds is that cryptographic code fails silently rather than visibly. Key management covers the recursion that makes it genuinely hard, since protecting a key requires another key and the chain has to end somewhere non-cryptographic. On the lighter side, free as in beer explains why a free tier and a permissive licence are different things, the demo gods turn out to be a list of environmental variables rather than luck, and the first commercial domain was registered in 1985 for free, in a system nobody expected to become a naming rights regime for the world economy.

    • Contenuto

      Thirteen glossary topics that existed twice are now one entry each

      The glossary had grown across many authoring waves, and along the way thirteen subjects ended up with two entries under different slugs, each written independently. Therac-25, Ariane 5, the Mars Climate Orbiter, Y2K, the blue box, left-pad, foo and bar, dogfooding, the fallacies of distributed computing, the two hard things, the Two Generals Problem, the Year 2038 problem and the thundering herd were each covered twice, in different words. They are now single entries. Where only one version had a full treatment, that treatment moved to the surviving entry, so no writing was lost. The surviving slug follows the convention the rest of the corpus already uses, which is the article-free form, except where the longer name is the accurate one: the npm package really is called left-pad, the list really is the fallacies of distributed computing rather than just its first item, and the problem really is the Two Generals Problem. Every retired address keeps working and permanently redirects to its survivor, in whichever language you were reading, so nothing that linked to the old page breaks. A new build check now compares normalized headwords across the whole registry and fails if two entries describe the same subject, because unique slugs are not the same thing as unique topics and nothing was testing for that.

    • Contenuto

      Twelve entries on how Brazil got connected, and who built the parts

      The Brazilian telecommunications lineage now reads as a set. Telebras covers the monopoly era honestly, since it built genuine national infrastructure reaching places no commercial calculation would have reached, and also produced waiting lists measured in years and a telephone line scarce enough to appear on balance sheets as property. Telesp covers what happened to that copper afterwards, because the same pair of wires that carried a voice line was reused to carry always-on internet, which is why broadband arrived first wherever the incumbent's copper already was. Embratel covers the backbone built over decades by an entity that could afford to be patient, and which the commercial internet then arrived to use. Anatel explains why privatization required inventing a referee, and why Brazil deliberately kept telecom regulation and internet governance in separate institutions. The market reserve gets both halves of its record: real engineering capability and a generation who learned by building, alongside expensive machines a generation behind and a software culture shaped by scarcity. On the institutions, FAPESP covers why a constitutionally guaranteed share of tax revenue is what let it commit to infrastructure research across changes of government, and why a research foundation ended up administering a country's domain registry. CGI.br, NIC.br, USP and Unicamp complete the picture, and Ethernet gets the origin of its name from a medium nineteenth-century physics invented and then failed to find.

    • Contenuto

      Forty entries on backups, security posture, engineering judgement and operational practice

      The backup cluster covers what each number in the three-two-one rule actually defends against, why RAID protects against a disk failing and nothing else, and why an untested backup exists in superposition until a restore collapses it. Two is one and one is none gets the failure that matters, which is hidden commonality: two power supplies on the same circuit are one power supply. On security posture, security theater is given its honest complication, since visible measures do deter opportunists and the real cost is the effort not spent on the effective control. Compliance is not security is explained in both directions, including the less discussed case where a team implements a weaker control that maps cleanly to a requirement instead of a stronger one that does not. The attacker only needs to be right once gets its correction: an intrusion is a campaign with many stages, and the defender needs to be right once at any of them, which is exactly why detection is worth funding. Engineering judgement covers why perfect is the enemy of good does not apply to anything irreversible, why boring technology is relative to your team rather than absolute, and why the second system is the dangerous one. Operational practice closes with check layer one, packet captures as ground truth, testing in production and what separates the practice from the accusation, and the two generals problem as a boundary condition rather than a puzzle.

    • Contenuto

      Sixteen entries on the vulnerabilities that changed how the industry thinks

      Spectre gets the point that made it a landmark, which is that it was not a bug in any implementation: speculative execution is a deliberate design every high-performance processor used, so the vulnerability is in the concept and could not be patched away without giving up decades of performance work. Meltdown is separated from it as the narrower and genuinely fixable one, and its mitigation is a clean case study in security costing measurable performance that everyone pays. Rowhammer covers a physical attack expressed in software, where the security model assumed memory is reliable storage and the hardware turns out to be an analogue system with analogue failure modes. KRACK explains why a decade of formal analysis did not prevent it, since the proofs covered the protocol as specified rather than the state machines actually built. On the enterprise side, Zerologon came from cryptographic misuse rather than a memory bug, PrintNightmare illustrates attack surface reduction beating patching because a disabled service produces no new instances, and ProxyLogon covers who actually runs Exchange on premises, which by then skewed toward the organizations least able to detect a compromise. Mirai closes the argument on device security as an externality, since the manufacturer competes on price, the owner experiences no harm, and the cost falls on the internet at large. NotPetya covers the attack that crossed from a security incident into an uninsurable act.

    • Contenuto

      The myths get corrected, the named attacks get explained, and the sayings get their reasoning

      Twelve entries in this round exist to correct things that are widely believed and wrong. The padlock means the connection is encrypted and the certificate matches the name, and it has never meant the site is honest, which matters more now that certificates are free and most phishing pages display the same padlock as the bank they imitate. A consumer VPN transfers trust rather than granting anonymity, since your provider stops seeing your destinations and the VPN operator starts. Forced password rotation was reversed by the organizations that originally recommended it, because frequent change produces predictable passwords. Deleting a file removes the directory entry and not the contents, and on solid state storage overwriting cannot reliably reach the original cells. Public Wi-Fi warnings were proportionate in an unencrypted era and describe a much smaller exposure now. Quantum computing breaks public key cryptography and leaves symmetric ciphers largely intact, which is the asymmetry that actually matters. Six named TLS attacks are explained by mechanism rather than by logo, including why CRIME and BREACH break confidentiality without breaking encryption at all, and why FREAK is cited in every debate about lawful access, since a weakness introduced for a government requirement outlived it by more than a decade. The batch closes with the operational sayings and their reasoning: read-only Friday as a symptom worth reading, never touch a running system in both its correct and its catastrophic form, and hope is not a strategy.

    • Contenuto

      Thirty more entries: the fundamentals, the myths, and the vocabulary nobody writes down

      This round covers the things practitioners say to each other and rarely see explained. Bits and bytes get the conversions that make a hundred-megabit connection deliver twelve and a half megabytes, and why standards bodies say octet when they mean exactly eight. TCP/IP is framed around the architectural decision that made it win, which was keeping the network simple and the endpoints smart, and the cost that decision is still being paid in middleboxes that added the state the design excluded. Wire speed explains why packets per second is the honest measure and why the footnote about which features were enabled during the test is the part worth reading. Two myths get corrected directly. NAT is not a firewall, since it blocks unsolicited traffic as a side effect of having no translation entry rather than as a policy decision, which leaves a great many flat internal networks behind a device everyone assumed was protecting them. Private browsing prevents local storage of history and does nothing about the network, which is stated accurately by the browser and understood as something much larger. The operations vocabulary covers why turning it off and on again is genuinely the highest-yield first question and why doing it before capturing state guarantees you will be back. On history, the DAO hack explains why code is law worked only until the consequences were unacceptable, and Silk Road covers the investigative lesson that the anonymity technology was never broken.

    • Contenuto

      Forty-one entries go deep in one pass: disasters, laws, malware and the vocabulary of operations

      The engineering disasters lead, because they are the clearest arguments for practices that otherwise sound like bureaucracy. Therac-25 covers the decision underneath the race condition, which was removing the hardware interlocks that had silently caught the same defect in the previous model for years. Ariane 5 explains why the calculation that destroyed the rocket was not even needed in flight, and why redundancy running identical software is redundancy against hardware failure only. The Mars Climate Orbiter is framed around the real lesson, that the mismatch lived in the handoff between two organizations where nobody's checklist ran. Y2K gets the prevention paradox stated plainly: work that succeeds produces an absence of events, and an absence of events looks like an absence of risk. On laws, Hyrum's law explains why documentation does not constrain what people depend on, Amdahl's law is paired with Gustafson's counterargument, and Kernighan's law is reframed as being about cognitive headroom rather than skill. Six malware entries cover why SQL Slammer outran human response entirely and why Code Red's hardcoded target taught attackers to use dynamic selection. Xerox PARC, ELIZA, Deep Blue, the Homebrew Computer Club, DECnet and AppleTalk cover the history, the crypto wars and the L0pht testimony cover the politics, and the operations vocabulary closes with break-glass, out-of-band management, truck rolls, remote hands, walled gardens and hub-and-spoke.

    • Contenuto

      Thirty-six entries go deep: the failures, the vulnerabilities, and the texts

      The largest single content release on this site so far. The engineering failures are covered for what they actually teach: Ariane 5 flew inherited code whose overflowing calculation was not even needed after launch, and its backup ran identical software, so redundancy was the same failure twice. Therac-25 is presented the way Leveson presented it, where the race condition is the least interesting part next to the removed hardware interlocks and the manufacturer insisting overdose was impossible. Mars Climate Orbiter is a units mismatch where both programs were internally correct, which makes it an interface failure. Knight Capital lost 440 million dollars in 45 minutes because a deployment reached seven servers out of eight. The Pentium division bug covers a technically correct response failing completely as communication, since an error rate is a property of a distribution and no user experiences a distribution. Y2K gets the prevention paradox: successful prevention produces an absence, and the people who did the work are remembered as alarmists. On vulnerabilities, Heartbleed left no trace because a heartbeat is a legitimate message, Log4Shell exposed that most organizations could not answer whether they used a library, and EternalBlue is the standing argument in the vulnerabilities equities debate, since a stockpiled exploit is a liability held on behalf of everyone and stockpiles leak. The foundational texts, pioneers, internet firsts and the folklore that turns out to be false complete the release.

    • Contenuto

      The institutions and the jargon: twelve more entries go deep

      DEF CON is covered for its cultural function rather than its size, since a venue willing to platform findings vendors would rather suppress changes what researchers are willing to work on, because the alternative to public disclosure is not silence but a private market. The Chaos Computer Club gets the thing no other country produced, which is a hacker organization with genuine institutional standing, routinely consulted in German constitutional proceedings after forty years of being right in public. 2600 covers what a printed magazine did before the internet made distribution trivial, which was reach a teenager in a small town who had no other way of learning that other people existed. Garoa Hacker Clube explains why shared physical space matters most exactly where equipment is expensive relative to income. On community models, H2HC is credited for refusing to broaden as it grew, which is what keeps months-long research viable; BSides is explained through the loop it breaks, since a researcher cannot get accepted without reputation and cannot build reputation without presenting; and Nullcon is noted for getting the order right, being a community that grew a conference rather than the reverse. The Jargon File is treated honestly, including the dispute over whether the published dictionary reflects its editor more than the community it claimed to record. Pwned, off-by-one and FUBAR complete the set.

    • Contenuto

      Twelve pieces of computing history, and the two hundredth deep glossary entry

      The Morris Worm gets the detail that explains it: the worm carried nothing destructive, and the damage came from one design decision, since Morris expected administrators to defend by making machines claim to be already infected, so he had it reinfect anyway a fraction of the time. That fraction was far too high. The consequences outlived the incident, because the response gap it exposed led directly to the founding of CERT, which is where organized incident response begins. Reflections on Trusting Trust covers why the attack is still unsettling forty years on, since after the compiler learns to backdoor its own successor the malicious source can be deleted entirely and the binary keeps reproducing the attack forever. The Cuckoo's Egg is treated as the first real account of incident response as a practice, improvised from a seventy-five cent accounting discrepancy with no tools and no playbook. Left-pad covers why eleven lines broke a substantial part of an ecosystem, which is that nothing depended on it directly. On the lighter side, RFC 1149 demonstrates protocol layering by taking it to an absurd extreme and then actually being implemented over pigeons, and 418 I'm a teapot became load-bearing culture that cannot now be reassigned. The room 404 story is corrected rather than repeated. Captain Crunch closes with the principle that outlived telephony, since mixing control and data in one channel is the same structural flaw behind SQL injection and cross-site scripting.

    • Funzionalità

      Instructor cards on the training page, and three fixes to how hubs read

      The three links under Your Instructor on the training page were plain buttons sitting at the bottom of the bio, which made the professional showcase read as an afterthought. They are now feature cards above the bio, matching the Glossary and Study guides doors on the Learn page, each with its own accent and a line explaining what is behind it. On the certifications hub, the expand and collapse controls have moved down to sit directly above the certifications list rather than floating above the vendor cards, so the controls are next to the thing they control. Vendor titles on the same page were rendering almost illegibly dark, which turned out to be an inheritance problem: the title style sets size and weight but no colour, and the heading sits inside a button, so it was picking up the button's colour instead of the heading colour. Those titles are now explicitly set, and they pick up the accent on hover like every other control. On the vendor hub pages, the two section titles are larger and use the bright accent rather than amber, so they stand out as section markers rather than blending into the page. That change is scoped to vendor hubs specifically, since the same style is shared with the tools, learn and category pages, which are unchanged. Also in this release: four more conference entries go deep, covering ShmooCon, TROOPERS, HITB and Campus Party.

    • Contenuto

      Security principles, design rules, and the conferences that built a region's field

      Kerckhoffs's principle explains why the sensible place to concentrate secrecy is the thing you can cheaply replace, since a key rotates in an afternoon and an algorithm does not. Schneier's law names a structural limit rather than incompetence: you cannot evaluate your own design, because the assumptions that made it look sound are the ones you would need to question, so a system nobody has seriously attacked has an unknown security status rather than a good one. Linus's law gets the complication the evidence demands, since Heartbleed sat in OpenSSL for two years in code everyone could read and almost nobody did, which means availability of source and review of source are very different things. Goodhart's law covers why there is no metric immune to distortion, only metrics not yet load-bearing enough to distort one. Gall's law, the zero-one-infinity rule, the principle of least astonishment and the golden hammer complete the principles. The batch closes with four events that shaped Latin American technology: Fenasoft, which mattered because of when it happened, opening as the market reserve collapsed and giving a country its first sight of what it had been legally insulated from; Roadsec, which inverted conference economics by travelling to the country's hackers rather than making them fly; CryptoRave, which runs overnight in public libraries so attendees leave with encryption actually configured; and Ekoparty, which gave Latin American security research somewhere to be presented in Spanish without a visa application.

    • Contenuto

      Twelve more expressions, including the one the industry changed its mind about

      Postel's law is the interesting case. Be conservative in what you send, be liberal in what you accept is probably the most consequential sentence in the design of the internet, and the modern reassessment is that its second half caused enormous long-term harm, because accepting malformed input makes malformed input normal and every leniency becomes a place where two implementations can disagree about what a message means. Current practice leans the other way: specify strictly, reject early, fail loudly. Murphy's law gets its original meaning back, which was a design principle rather than fatalism, since if a component can be installed backwards then it should be built so it cannot. Move fast and break things covers why the company that coined it abandoned it in 2014, and turns the slogan into the honest question of what exactly we are willing to break and who absorbs the cost. Metcalfe's law gets its own weakness stated, since most possible connections on a large network have no value at all. The Peter principle explains why the strongest engineer promoted into management is a structural failure rather than a personal one. Sturgeon's law, Parkinson's law, KISS, boil the ocean, drink the Kool-Aid, not invented here and the two-pizza team complete the set, the last with the note that the size was never the point, since the rule came bundled with autonomy.

    • Contenuto

      Thirteen more expressions go deep, from Conway's law to the two hard things

      Conway's law gets the point that has outlasted almost everything else from 1968, which is that if you want to know why a system is shaped as it is, the org chart explains more than the architecture documents, and that every reorganization is therefore an architectural decision whether anyone frames it that way or not. Hofstadter's law covers why knowing about the bias does not remove it, and why reference class forecasting beats introspection even though every project feels genuinely different from the inside. Hanlon's razor gets the limit that usually goes missing: it is the right prior for colleagues and the wrong prior for adversaries, since attackers deliberately construct activity that looks like error. Cunningham's law is presented as an observation rather than a tactic, with the note that Cunningham has disclaimed the attribution, which is itself a demonstration of how internet folklore works. Leaky abstractions explain why senior engineers are valuable in a way that is hard to put on a CV, since knowing which abstraction is leaking is only obtainable by having been surprised before. Big ball of mud is treated the way its authors treated it, refusing to be simply dismissive and asking why the most common architecture in the world dominates. Shadow IT is reframed as diagnostic rather than criminal. Spaghetti code, bit rot, worse is better, grok, dogfooding and the two hard things complete the set.

    • Contenuto

      The slogans get their caveats back: technical debt, YAGNI, DRY and ten more

      Engineering aphorisms survive by being short, and most of them lose the qualification that made them true. This batch restores it. Technical debt returns to Cunningham's meaning, which is debt taken knowingly with a plan to repay, not a synonym for any bad code, because deliberate debt needs a repayment schedule while accidental mess needs education and calling both debt lets a team feel sophisticated about a codebase nobody understands. Premature optimization is the most misquoted line in software, and the damage is in the truncation, since Knuth immediately added that we should not pass up our opportunities in the critical three percent. DRY is about knowledge rather than text, so two identical-looking pieces of code encoding different decisions are not duplication, and merging them creates a coupling that hurts the moment those decisions diverge. YAGNI applies to features and not to structural decisions, and is frequently misused as an argument against thinking ahead. Chesterton's fence gets its counterweight, since stating only the first half turns it into an argument for never changing anything. Brooks's law gets its limits, Moore's law gets the detail that transistor density and performance decoupled around 2005, and the bus factor gets the honest test, which is that a team that cannot function while someone is on holiday has already discovered its number. Cattle not pets, shift left, happy path, code smell and scope creep complete the set.

    • Contenuto

      Wave two opens: the folklore of the profession goes deep

      The glossary's lore entries are the part of this site nothing else has, and they now get the same treatment the technical terms received. The first computer bug leads, and it corrects the story rather than repeating it: the 1947 annotation reads first actual case of bug being found, and that word actual is doing all the work, because the engineers were making a joke that only lands if the term already existed. It did, since bug had meant a fault in machinery since the nineteenth century. The Smithsonian's own catalogue notes the logbook was probably not Grace Hopper's and the handwriting does not match, so she popularized the story rather than wrote it. The 500-mile email follows, the best debugging story the profession has, where a timeout silently defaulted to zero meant SMTP connections had to complete within the round trip time and speed-of-light latency became a business rule by accident. The Story of Mel is treated as the ambiguous text it is, holding admiration for craft and the quiet fact that the program was unmaintainable without resolving them. Heisenbugs and bohrbugs get the taxonomy that makes them useful rather than cute, including why a fault that evaporates under observation is a strong diagnostic signal. Bikeshedding, yak shaving, rubber duck debugging, cargo cult programming, kludge, hack, foo, bar and SNAFU complete the batch.

    • Contenuto

      Wave one complete: every glossary term the site depends on now goes deep

      Thirteen final entries close out the programme, and the milestone is worth stating plainly. Every glossary term referenced by two or more articles or tool pages on this site now carries a full treatment rather than a single paragraph, which is 121 entries written in English and Portuguese together. This batch: AS3 covers why declarative configuration is organizational before it is technical, since a declaration owning a tenant will delete what a colleague added by hand outside the workflow. Backbone Edge Bridge covers the containment that keeps a fabric core from ever learning customer addresses. BIND covers the separation advice that matters most, since an authoritative server that also resolves for anyone is a reflection amplifier waiting to be used against a third party. XXE covers why the network request is often worse than the file read. GREASE explains the inoculation against protocol ossification, and why an extension point never exercised is one that will not work when you finally need it. HOTP covers the counter drift that needs resynchronization rather than replacement. SPNEGO gives the diagnostic key, that a password prompt where single sign-on should be automatic is a Kerberos problem wearing a login box. MCP, POSIX, provisioning, Microtunnel, NewEdge and ZDX complete the set, the last with the caveat that a composite score can hide one dreadful component inside an acceptable average.

    • Contenuto

      Twelve more entries go deep: ARP through ZTNA

      ARP covers the protocol that predates any notion of a hostile local network, which is the source of everything problematic about it, and why the defence has to live on the switch rather than on the endpoints being lied to. MSS explains why it beats path MTU discovery, since the size is agreed before any data flows rather than discovered after packets are already being dropped, and why clamping appears in essentially every VPN configuration guide. DTLS covers what changes when TLS meets datagrams, including the cookie exchange that stops the protocol becoming an amplifier. VLSM covers the allocation discipline that makes summarization possible later, since a network subnetted in whatever order requests arrived usually cannot be summarized at all. On certificates: Subject Alternative Name explains why a certificate whose name lives only in the Common Name is rejected regardless of how correct it looks, and why internal hostnames in a public certificate become publicly enumerable through transparency logs. DER covers why file extensions lie and why canonical encoding is a requirement rather than an elegance. HS256 and RS256 are treated as the pair they are, including the algorithm confusion attack where a token is switched to HMAC and signed with the public key that was never secret. SASE and ZTNA close the vendor cluster with their claims stated precisely rather than expansively, and SCIM covers the orphaned accounts that are among the most reliable findings in any access review. Observability finishes on why instrumenting for the questions you actually ask produces less data and more answers.

    • Contenuto

      Fifteen more entries go deep: the DNS record types, private addressing, and the security tail

      The DNS record types now read as a set. CNAME covers why it cannot live at a zone apex and why a dangling one left after a decommission is a subdomain takeover waiting to happen. MX covers the backup that is a liability rather than redundancy, since a secondary that merely queues mail without the primary's protections is the soft target attackers aim at deliberately. PTR covers why forward and reverse agreement is deliverability rather than optional hygiene, and why a reverse name proves nothing about who controls the forward one. TXT covers the accumulation problem and the one hard rule, which is that two SPF records is a permanent error rather than a merge. SOA covers the serial number that silently strands every secondary when a hand-edited zone forgets to increment it, and SRV covers why Active Directory clients find their domain by asking DNS rather than by being told. On addressing: RFC 1918 covers the collision that every acquisition and partner VPN eventually meets, and the trap of mistaking private for protected. Carrier-grade NAT covers collective reputation, where one subscriber's behaviour lands a block on everyone sharing the address. UDP covers why doing almost nothing is the point, and why it is the engine behind the largest reflection attacks on record. Multicast, link-local addressing, phishing, zero-days, NTLM and MD5 complete the set, the last with the distinction worth teaching: the failure is not the algorithm appearing anywhere, it is the algorithm appearing where an attacker chooses what gets hashed.

    • Funzionalità

      Study guides and certifications are now browsable rather than scrollable

      Both hub pages were showing everything at once, which made them long to scroll and hard to scan. Reading paths on the study guides page now show their title, size and description with the syllabus behind a See contents toggle, collapsed by default, so the page reads as a menu of what is available before it becomes a list of links. Paths are grouped, with the vendor-agnostic ones first and then F5, Extreme, Fortinet, Netskope, Ping and Zscaler, sorted alphabetically within each group using proper locale-aware comparison so accented titles order correctly in Portuguese. The certifications hub gains a set of vendor cards at the top, so every vendor covered is visible at a glance with its certification and guide counts, and clicking one opens that vendor and jumps to it. Vendor sections themselves are now collapsible and start closed, matching the certifications inside them. Both pages carry expand-all and collapse-all controls, and on the certifications hub those act on vendors and certifications together, so expanding everything genuinely expands everything. Also in this release: eight more glossary entries go deep, covering GDPR, AES, UTC, PEM, ECDHE, JA4 and MPLS.

    • Contenuto

      Twelve more entries go deep, finishing the most-referenced tier of the glossary

      Every glossary term that three or more articles and tool pages depend on now carries a full treatment. ML-KEM covers the post-quantum key standard NIST published as FIPS 203 in August 2024, derived from CRYSTALS-Kyber, and why the urgency is harvest now and decrypt later: traffic recorded today can be read whenever a capable quantum computer arrives, so anything needing long-term confidentiality is already exposed. Brazil's data protection law gets the point that matters for anyone reusing a European compliance programme, which is that the shape transfers and the specifics do not. Time to live covers the two unrelated things sharing one acronym, and why lowering a DNS value belongs before a planned change rather than during the incident it causes. HSTS explains the commitment being made, since a long duration is a promise browsers keep even when you would rather they did not. CORS is framed by the one fact that resolves most confusion, that it protects users rather than your server, along with the reflected-origin misconfiguration that recreates the exact vulnerability the mechanism exists to prevent. Content Security Policy covers why policies written the easy way do nothing. Single sign-on states the concentration trade plainly. VLANs are placed as a segmentation tool rather than a security boundary. Wi-Fi covers airtime as the shared resource that explains disappointing deployments, LoRa covers the opposite bet and the duty cycle ceiling that is compliance rather than a bug, OCSP covers stapling and the fail-open hole it closes, and EXOS covers the configuration model that catches engineers in both directions.

    • Contenuto

      Nine more entries go deep, from HMAC to Ethernet fabrics

      HMAC explains why the obvious way to build a message authentication code out of a hash is broken, since prepending a key falls to length extension, and why tag comparison must run in constant time or it leaks how much of a forged tag was correct. It also notes how much runs on it invisibly: one-time password codes, JWT signatures, cloud request signing and webhook verification are all HMAC wearing different names. JWK covers the key identifier that rotation depends on entirely, and the dangerous case where a key set built carelessly from a keystore publishes exactly what it was meant to protect. Regular expressions cover the dialect problem and catastrophic backtracking, where nested quantifiers against a crafted input become a denial of service using nothing but a text field. JA3 explains why a handshake fingerprint identifies software rather than intent, so a match is a lead and not a verdict, and why libraries randomizing extension order broke the assumption the technique rests on. YAML covers whitespace as syntax and the type inference trap where a version number or country code silently becomes something else. Security Service Edge gets two honest caveats alongside the enthusiasm: concentrating inspection in one provider puts them on the critical path of everything, and the acronyms are marketing before they are architecture. Interior gateway protocols, Shortest Path Bridging and the Zscaler tunnel versions round out the set.

    • Contenuto

      Seven more go deep: RSA, AEAD, one-time passwords, key sets, PAC files, SNAT and onion routing

      RSA covers why it is receding without having been broken, since equivalent security needs roughly 3072 bits to match a 256-bit elliptic curve, and why it sits squarely in the category of cryptography with a known expiry condition, because factoring is exactly what a large quantum computer would solve efficiently. AEAD explains why combining encryption and authentication into one operation is a safety mechanism rather than a convenience, since composition was where implementations went wrong, and why the remaining sharp edge is nonce management: repeating a nonce under one key in GCM does not degrade gracefully, it can expose the authentication key itself. TOTP covers why the codes work on a phone in airplane mode, why clock skew is the first thing to check, and the limit that matters, which is that a proxy relaying the code as the user types it is inside the window and the code is still valid. JWKS explains why doing rotation steps in the wrong order is the classic self-inflicted outage, and why caching too aggressively breaks rotations while refetching per token puts an outbound HTTP call in the authentication hot path. PAC files cover why the first match wins and how a broad rule placed early silently swallows the specific rules beneath it. SNAT covers the trade every deployment makes, along with the port exhaustion that presents as intermittent failures under load rather than as anything that names itself. Onion routing explains that the realistic attack is traffic analysis rather than cryptanalysis, and that the exit relay sees whatever the destination sees.

    • Contenuto

      Eight more foundations go deep: message authentication, nonces, salts, hashes and the protocols around them

      Message authentication codes get the point that matters most, which is that confidentiality and integrity are separate properties and assuming the first delivers the second is one of the most expensive mistakes in applied cryptography, along with why encrypt-then-authenticate is the ordering that survives and why AEAD exists so nobody can get that ordering wrong. Nonces cover why a value that need not be secret must never repeat, and why reusing one under the same key in a counter-mode cipher does not weaken encryption slightly but can reveal the relationship between two plaintexts outright. Salts explain the part people find counterintuitive, that the salt is not a secret and is stored in plain view beside the hash, because its entire value is being unique per record rather than being hidden. Hash functions cover the birthday arithmetic that made MD5 and SHA-1 fall while their output lengths still looked adequate, and why reaching for a fast hash to store passwords gets the requirement exactly backwards. VPN separates the sound technology from the security model it implies, since authenticating once and then placing a device on a network segment quietly makes location the authorization decision. LDAP covers the two operational details behind most incidents, the bind that succeeds while returning less than expected and the plain-text traffic that is a standing finding in security reviews. OSPF explains why an MTU mismatch produces the memorable failure where neighbours reach the exchange state and stick there forever. SIEM closes on time synchronization, since correlating events across sources whose clocks disagree produces sequences that never happened.

    • Contenuto

      The Zscaler cluster goes deep, along with GRE and IS-IS

      Continuing down the measured list of terms the rest of the site leans on most. ZIA covers the outbound half of the platform and is honest about the trade: policy that follows the user rather than the office, paid for with an extra hop on every packet and a dependency on the nearest edge, with most of the real operational work concentrated in deciding what not to inspect, since every bypass is a hole in the coverage you are paying for. ZPA covers the inbound half and why it replaces the VPN rather than extending it, since both the connector beside your applications and the user client dial outward and the cloud stitches the halves together, so the application needs no inbound rule and no public exposure at all. The security argument follows: a compromised VPN session gives an attacker a network to explore, a compromised private access session gives them one application. Zscaler Client Connector explains why most user-reported problems are really forwarding-profile problems, and what actually differs between the two tunnel versions, since one forwards proxy-aware traffic through CONNECT requests while the other carries everything over DTLS or TLS regardless of port or protocol. CASB covers why inline and API-based deployments have genuinely different reach and why serious deployments run both. GRE explains why being deliberately dumb is the point, and IS-IS covers the property that matters most in provider networks, which is that it rides directly on layer two so its control plane cannot be reached by IP traffic at all.

    • Contenuto

      The eight terms the rest of the site leans on now go deep

      These were chosen by counting, not by taste: every article and tool doc on the site declares the concepts it covers, and these eight are the most frequently referenced entries that were still running on a single paragraph. OAuth opens with what it is not, since it is an authorization framework rather than an authentication protocol, and makes the case that most OAuth vulnerabilities are not specification flaws but the wrong flow chosen confidently. JWT is blunt about the payload being encoded rather than encrypted, so anything confidential placed in one is published, and covers the classic validation failure where the server trusts the algorithm the token itself declares. OIDC separates the two tokens people mix up, since the access token is for calling APIs and the ID token is for your application, and lists the validation steps that turn single sign-on into signing anyone in when skipped. PKCE explains why a workaround built for mobile became the general recommendation. BGP covers the part that surprises engineers used to shortest-path routing, which is that it chooses the route your business relationships prefer rather than the fastest one, so a geographically absurd path is often commercial logic working exactly as configured. IPsec gives the diagnostic question worth asking first, which phase failed, and the fragmentation trap where a tunnel comes up cleanly and then hangs on large transfers. Syslog explains why severity ordering is backwards from intuition and why filters written the intuitive way silently drop what mattered. NAT makes the case that it is not a firewall, since it blocks unsolicited traffic as a side effect of having no translation entry rather than as a policy decision.

    • Contenuto

      Four security entries go deep: layers, stuffed credentials, tired analysts, and the surface nobody inventoried

      Defense in depth gets the version that includes the part people skip, which is that layers have to differ in kind rather than merely repeat: three firewalls from the same vendor sharing one vulnerability are a single layer wearing three hats, and layers nobody monitors are decoration. Credential stuffing explains why it defeats defences built for brute force, since the passwords are already correct, the traffic arrives from distributed residential addresses, and every individual login looks legitimate because to the authentication system it genuinely is. The answer is making the password insufficient rather than making it stronger. Alert fatigue is framed as a design problem rather than a discipline problem, which is what organizations get wrong when they respond by telling analysts to be more careful: attention is finite, habituation is automatic, and a short queue people actually read protects more than a comprehensive one they have learned to ignore. Attack surface covers why it grows silently, since nobody ever proposes to increase it and yet every feature, integration and convenience adds a path, and why the parts that hurt are the forgotten staging environment and the admin interface opened during a migration and never closed. Fifteen more entries also gained links to the tools and articles that cover them, including hash collisions, DNSKEY records, CAPTCHAs, botnets, beaconing and bogons.

    • Contenuto

      Eighty more glossary entries connected, and four go deep on certificates, names and data

      This round wired eighty entries, the largest single pass yet. Sixty-one now link to the article that covers them, spanning the acronym mass that makes up the biggest part of the glossary: ACME, OCSP, JWK and JWKS, OIDC, SAML, SCIM, LDAP, IPsec and IKE, GRE, ICMP, DHCP, ARP, EDNS, HSTS, XXE, CVSS, JA3 and JA4, GPON, LoRa, and the Zscaler and Extreme families. Nineteen more point at tools: SNI to the domain and SNI match resolver, syslog priority to the priority decoder, single sign-on to the APM explainers, EXOS to the config explainer and the VOSS translator, and the Zscaler client, firewall and score tools to their entries. Four entries gained deeper treatments. Public key infrastructure covers the uncomfortable part, which is that your trust store ships with root authorities you never chose and any of them can issue for any name, and why certificate transparency exists because detection proved more achievable than prevention. Server Name Indication explains why the hostname travels in the clear, what Encrypted Client Hello is answering, and why most SNI failures are really name-selection problems wearing a certificate error. ACME makes the case that short certificate lifetimes are the design intent rather than a limitation, and that manual renewal gives you all the frequency and none of the benefit. Data loss prevention covers why aggressive tuning often produces worse real coverage than a modest policy people tolerate.

    • Contenuto

      More glossary wiring, four more deep entries, and a guard that catches broken links

      Twenty-eight more glossary entries now link to the articles and tools that cover them, including zero trust, Kerberos and SPNEGO, forward and reverse proxies, GRE and Z-tunnels, SYN floods, blast radius, key rotation, cloud metadata endpoints, and the last-mile evolution from copper to fibre. Four entries gained the deeper treatment: zero trust, with the honest note that it is an architecture rather than a product no matter how it is marketed, since the hard part was always knowing which identities exist and what they should reach; blast radius, on why simple changes with large radii cause the worst outages, because difficulty and consequence are independent variables that people routinely conflate; Kerberos, on why clock skew breaks authentication outright and why checking the clock is a real first diagnostic rather than a joke; and reverse proxies, on why the point where every request passes becomes both the most useful and the most dangerous device in the path. This release also fixes a broken link and the reason it survived. One entry pointed at a tool that does not exist, and nothing caught it, because these references are plain text that the type checker cannot see. The glossary guard now validates every tool and article link against the real tool registry and the real article corpus, so a link to something that is not there fails the build instead of shipping.

    • Contenuto

      Glossary wiring, wave one: entries start pointing at the tools that do the work

      The glossary now connects to the rest of the site. Thirty-one more entries gained links this round, so that looking up a term takes you straight to the thing that decodes, calculates, or explains it: certificate signing requests to the CSR decoder, cipher suites to the cipher string expander, JA3 and JA4 to their fingerprint tools, syslog priority values to the priority decoder, LDAP filters to the filter explainer, TOTP and HOTP to the one-time password tool, CVSS vectors to the vector decoder, AS3 to the declaration validator, and global load balancing to the DNS simulator and decision-flow explainer. Ten entries also gained links to the full articles that cover them, including VLSM, NAT, OSPF, MPLS, forward secrecy, CORS, jumbo frames, and the year 2038 problem. Four of the newly connected entries received the deeper treatment as well. Cipher suites explain why TLS 1.3 deleted most of the catalogue rather than adding to it, since removing weak options was the fastest way to remove a decade of downgrade attacks. Global load balancing covers why a sensible-looking TTL becomes a failover delay during an outage. CVSS makes the case that a 9.8 on an internal system can deserve less urgency than a 6.5 on a public payment endpoint, which is what reading the vector rather than the number is for. And server-side request forgery explains why blocklists lose to decimal IP encodings and redirects, and why allowlisting is the defence that survives.

    • Contenuto

      The glossary starts going deep, and starts linking to the tools

      A census of all 1,167 glossary entries turned up something more interesting than thin writing: 98.6 percent of them linked to no tool at all. On a site whose whole thesis is tools that compute rather than guess, a glossary that defines a thing without pointing at the thing that computes it is only doing half its job. This release begins fixing both halves. Entries now support an optional deeper body that appears only on the entry's own page, deliberately separate from the short definition that shows up in hover tooltips across the site, so the tooltips stay readable while the pages can go as deep as the subject deserves. Eight foundational entries lead the way with three-paragraph treatments grounded in where you actually meet the term: DNS as the thing you investigate when something else is broken and the question is which layer is holding the wrong answer; TLS as a negotiation whose details turned out to be a fingerprint; MTU as the problem where small things work and large things hang; multi-factor authentication and the lesson that any factor a person can be persuaded to relay will be relayed by a person under pressure. Alongside the writing, entries including DNS, TLS, WAF, SAML, JWT, OAuth, CIDR and MTU now link directly to the tools that decode, calculate, or explain them. It stays a glossary, in name and in spirit, just one that finally connects to the rest of the site.

    • Infrastruttura

      Deploy unblocked: the site crossed Cloudflare's 100,000-file ceiling

      A milestone disguised as an outage. The 16-locale static export grew past 100,000 files, which is Cloudflare Workers' hard cap on static assets per version, and the deploy pipeline stopped with the manifest at 106,377. The site itself stayed up throughout on the previous version; only new deploys were blocked. The fix is surgical: Next.js writes a small companion file next to every page (the RSC payload used only to make client-side navigation slightly smoother), and at sixteen locales those companions alone account for roughly 33,700 files. A .assetsignore now excludes them from the upload manifest, bringing it to about 72,700 with comfortable headroom. The practical effect on the site is nearly invisible: navigation between pages becomes a normal full page load instead of a soft transition, and everything else - the HTML, search, OG images, the machine-readable article twins, llms.txt - ships exactly as before. The deploy workflow also gained a budget gate that fails fast with a clear message if the effective manifest ever approaches the cap again, instead of discovering it 35 minutes into a build.

    • Contenuto

      Two new articles: amateur radio, and the radio spectrum from VLF to millimetre wave

      A pair that belongs together. The amateur radio piece starts where the hobby actually starts, with the callsign: an identity issued under an International Telecommunication Union treaty allocation and legible anywhere on earth without explanation. Brazil holds the entire PPA to PYZ block, Anatel issues within it on a two-letter-plus-digit scheme, and the digit is regional, so PY2 says Sao Paulo at a glance while the PU series signals a different licence class. The article is explicit that none of this is Citizens Band, which has no examination, no individual callsign, fixed channels near 27 MHz and tight power limits, however similar a car-mounted antenna may look from outside. Then the modes, and why each survives: FM on VHF, single sideband on HF because stripping the carrier puts all the power where the information is, and Morse persisting on the engineering fact that a trained ear pulls it out of noise that renders voice unintelligible. Repeaters get the two settings that catch everyone out, the offset and the CTCSS tone, along with the observation that this infrastructure is almost entirely volunteer-built. The companion article explains the physics underneath: one trade governs all radio, since low frequencies travel far and carry little while high frequencies carry enormous amounts and stop at the first obstacle. Three propagation modes account for nearly everything, ground wave below 2 MHz, sky wave refracting off the ionosphere between roughly 2 and 30 MHz to cross oceans on modest power, and line of sight above 30 MHz. The bands are walked from VLF reaching submerged submarines to millimetre wave 5G that foliage can block, with the ISM allocations, Wi-Fi, and LoRa placed as deliberate positions on the same trade. Ten glossary entries ship alongside.

    • Contenuto

      New article: who actually governs the internet in Brazil

      Brazil's internet did not arrive through a carrier or a ministry. It arrived because physicists wanted to talk to Fermilab. The article starts there, with FAPESP's link to the Fermi National Accelerator Laboratory over a leased 4,800 bit-per-second line on copper inside a submarine cable, the ANSP academic network that Demi Getschko architected, and the fact that shapes everything after it: until commercial internet began in 1994, that single FAPESP link carried essentially all Brazilian internet traffic to the outside world, while FAPESP also improvised the administration of the .br domain and the distribution of IP addresses. KyaTera and the RNP backbone follow, and so does the timing, because all of it happened during the market reserve. Then the governance layer that Brazil chose in 1995: CGI.br as a multistakeholder committee rather than a ministry, years before that was standard, with its 2009 Decalogo asserting network neutrality half a decade before the Marco Civil made it law; NIC.br executing, through Registro.br, CERT.br, and CEPTRO.br; and IX.br deliberately distributed across dozens of cities rather than concentrated in one building. Underneath sits the machinery nobody writes about: SERPRO, created by law in December 1964 and now among the largest public-sector IT organizations anywhere, PRODESP, which began in 1969 in a borrowed room with two employees and no equipment before running fourteen mainframes and 900 terminals, PRODAM-SP for the city, and a counterpart in nearly every state. The article closes on the law, including the ruling that changed the famous part: on 26 June 2025 the Supreme Federal Court held Article 19 of the Marco Civil partially and progressively unconstitutional, reasoning that the provision was valid when written and became unconstitutional as platforms grew, shifting Brazil toward notice and takedown across four distinct liability regimes.

    • Contenuto

      New article: how the internet gets shut down, and who can actually do it

      There is no off switch, and that turns out to be the wrong thing to reassure yourself with, because decentralization protects the network rather than any particular country. The article walks the chokepoints in order of leverage: submarine cables and their landing stations, with Australia as the stark illustration at roughly fifteen international cables carrying about 99% of national traffic; BGP as the bigger lever than DNS, using Egypt in January 2011, which went dark in hours by withdrawing route announcements while every cable stayed intact; the root DNS myth, where thirteen server identities are really hundreds of anycast instances and the true control point is the signed root zone rather than a rack of machines; and exchange points, where Brazil turns out to be unusually resilient because IX.br is distributed across dozens of cities by deliberate policy. GPS gets its own section because it is usually misunderstood: losing it does not disconnect anything, but it distributes the precise time that cellular and financial systems depend on, and spoofing is more dangerous than jamming. Then the capability contrast, now covering China, Russia, the United States, the European Union, Australia, and Brazil. The Brazilian case is the most instructive and the most local: capability there is judicial rather than executive, and the 2024 suspension of X shows exactly what enforcement costs, running from the ISPs through Anatel, then to CDN providers including Cloudflare and Fastly when traffic routed around the block, then to app stores and VPN users, porous at every layer. The closing argument is the uncomfortable one: shutdown is loud, expensive, and self-harming, while surveillance is quiet and uses the very same chokepoints without breaking anything anyone would notice.

    • Nuovo strumento

      New tool: the digital transformation tracker, sorted by how much you should trust it

      Thirty milestones across seven domains of ordinary life, from ARPANET's first packets through PIX and forced remote work to forecasts that have not happened yet. Every row records two things: what changed for an ordinary person, and what became possible that was not possible before. The organizing principle is not the date, though, it is the certainty tier, because a tracker with a what-comes-next section is a forecasting surface and this site's rule is that tools compute rather than guess. So a forecast is never allowed to look like a fact. Shipped means it happened. In force means it binds today. Scheduled means a fixed future date set by law. Forecast means somebody's projection, always naming the forecaster and paired with a counter-signal where one exists, which is why the agentic-AI row carries both the optimistic adoption number and the projection that over forty percent of such projects may be abandoned. And there is a fifth tier nobody else shows: scheduled but moving, for a date that genuinely exists in law while it is actively being changed. The EU AI Act high-risk obligations are the worked example - scheduled for 2 August 2026, provisionally agreed in May 2026 to move to 2 December 2027, and not yet law, so the original date still governs planning. Two of the fourteen golden vectors pin the dataset's honesty rather than its filter logic: no unattributed forecast, and no contested date without an explanation.

      Digital transformation tracker

    • Contenuto

      A good-faith notice on every vendor-linked guide, and a clear route to have something removed

      Every study guide, the certifications hub, the contact page, and the disclaimer now carry an explicit statement of what this vendor-related material is and how it came to be here. The guides are independent educational works assembled from publicly available sources: published exam blueprints, official product documentation, vendor training catalogues, and public announcements. Objectives are cited to the public source they came from, authored study pointers are labelled as study aids rather than vendor text, and there are no exam questions, answers, or brain dumps anywhere, because those breach the very certification agreements this site exists to respect. Product names, exam codes, and trademarks belong to their owners and are used nominatively to identify the subject being taught, with no affiliation or endorsement claimed. The second half matters just as much: if a rights holder believes something here should be removed, corrected, or attributed differently, there is now a plain route to say so from any guide page, from the hub, and from the contact page. Send the exact URLs and, where possible, a short note on the issue, which is genuinely useful rather than a formality because it lets a mistake be fixed properly across the whole site rather than one page at a time. Requests are reviewed promptly and in good faith, contested material can come down while a question is still open, and nobody is asked to argue their case first if they would rather it came down first.

    • Contenuto

      Study-guide enrichment: 197 expert-tier objectives gain per-objective study pointers

      The last two gaps in the expert tier are closed in one pass. On the F5 side, the Certified Solution Expert guides for Security 401 and Cloud 402 now carry study pointers on all 46 objectives, covering threat research and modelling, module selection by threat class, network-layer DoS and IP Intelligence, outbound SSL visibility and its certificate problem, AFM rule contexts, incident analysis and response, and on the cloud side the service and deployment models, licensing and instance sizing, virtualization permutations, SDN integration constraints, migration planning, the compass API model, declarative automation with Declarative Onboarding and AS3, and the full lifecycle of a bursting or dynamic-provisioning workflow including the decommission path that is usually forgotten. On the Ping side, the three Certified Expert guides that had objectives but no pointers are now complete: PingDirectory across ACIs, entry balancing and global indexes, replication and mirrored subtrees, schema, sensitive and virtual and JSON attributes, password policy, logging and criteria objects, and a troubleshooting section built around cn=monitor, result codes, and unindexed searches; PingAccess across the full rule catalogue, identity mappings, site authenticators, resource ordering, agents, clustering and runtime state, and the request-path troubleshooting order; and PingFederate across data-store failover versus failsafe, OGNL fulfilment, self-service flows and their enumeration risks, authentication policies, redirect validation, certificate rotation, cluster models, log4j2 configuration, the adapter catalogue, and the OAuth and OIDC objectives from client registration through token types, scopes, and refresh-token rotation. Every pointer is labelled in the guide's source line as an authored study aid rather than blueprint text, so the verbatim official objectives stay distinguishable forever.

    • Contenuto

      New article: the Brazilian market reserve, in theory and in practice

      For eight years Brazil legally reserved its computer market for domestically-owned companies, and the article takes both halves of that seriously. The theory first, in its strongest form: import substitution, a balance-of-payments problem, and the reasonable-sounding idea that a sheltered infant industry would grow up able to compete, with the protection carrying an expiry date from the start. Then the machinery, CAPRE in 1972 giving way to the SEI in 1979 reporting straight to the Presidency, and Lei 7.232 of October 1984 creating CONIN, the CTI, and an eight-year clock. The law passed unanimously on an improbable coalition of nationalist officers, domestic industry, and the left opposition. The practice was different: clones of the ZX81, Apple II, MSX, and IBM PC that were obsolete on arrival and priced as though they were not, the similar nacional doctrine that let a worse domestic product block a better foreign one, a smuggling route through Paraguay that made breaking the law the only way to run current hardware, and far more manufacturers than the market could carry. That same doctrine triggered a trade war: Reagan opened a Section 301 investigation in 1985, found against Brazil in 1986, and announced sanctions in November 1987 over a refused software licence. The reserve then expired exactly on schedule in October 1992, with Lei 8.248 of 1991 having already replaced blunt protection with the research-linked incentives that still anchor Brazilian technology policy. The verdict is deliberately two-sided: the hardware bet failed and the survivors left for banking automation, but the engineering generation it trained is a direct ancestor of that same world-class banking automation and of firms like Cyclades and Datacom. A reserva de mercado glossary entry ships with it, sourced to the laws themselves and to the Reagan sanctions statement.

    • Contenuto

      New article: Tor, onion routing, and the threat model it openly loses to

      Promised in the peer-to-peer piece and now delivered, in English and Portuguese. The article starts from the paradox at the origin: onion routing was invented at the US Naval Research Laboratory, and a network used only by spies would identify its users as spies, which is why the tool had to be released to everybody before it could protect anybody. From there it builds the circuit honestly - guard, middle, exit, three layers of encryption, and the single property that makes it work, that no one relay knows both ends - then explains why guards are deliberately sticky and why exit relays will always be scarce. Onion services get their own section: a .onion address is a public key rather than a registered name, so it authenticates the destination by construction, and that is why v3 addresses grew to 56 characters. The threat model is stated the way the Tor Project itself states it, including the parts that lose: a global passive adversary defeats it by traffic confirmation, the exit relay sees whatever the destination sees, and in practice the browser leaks before the network does. The censorship section covers bridges and the pluggable transports, obfs4, meek, and Snowflake. And the closing correction is the one most readers need: only a small single-digit share of Tor traffic ever reaches an onion service, with the rest exiting to the ordinary web, which is why SecureDrop, the BBC, ProPublica, DuckDuckGo, and the Debian package mirrors all live there. A new Tor glossary entry ties the dark-web cluster together.

    • Funzionalità

      New section: the blog, and its first post on the Hugging Face incident

      The site gains a fourth kind of writing. Learn is educational and evergreen, the changelog is product news, the glossary is reference, and now the blog is dated commentary: opinion on something happening in the industry, signed and true as of its publication date. It lives at /blog, is linked from the footer immediately after the guide, reuses the site's existing category taxonomy rather than inventing a parallel one, and shares the Learn article renderer so prose looks the same everywhere. A build guard enforces what matters: complete frontmatter, a canonical byline, ISO dates, and an en plus pt-BR pair for every post. The inaugural piece reads the July 2026 Hugging Face intrusion alongside OpenAI's disclosure that the autonomous agent behind it was theirs, running a capability benchmark with its refusals turned down. It argues the sandbox escape was an architecture failure before a capability one, that an agent optimizing hard toward a goal is a different risk model than an attacker with intent, and that the finding defenders should actually copy down is the asymmetry Hugging Face hit during forensics, when the safety guardrails on hosted models blocked their own incident responders. Written to credit both companies for what went right and to keep the frontier capability question where it belongs, which is across the whole industry rather than at one lab.

    • Contenuto

      New article: peer-to-peer from Napster to the swarm, plus the Open Graph glossary entry

      A rich history of file-sharing organized by architecture rather than by app. Between 1999 and 2003 the same problem - let a crowd trade files with no company owning the library - was answered five ways, each fixing the weakness the last one died from: Napster's centralized index, Gnutella's unstructured flooding, Kazaa's FastTrack supernodes, eMule's Kademlia distributed hash table, and BitTorrent's swarm with its tit-for-tat incentive. The piece traces how the courtroom shaped the topology (Napster's contributory liability, Grokster's inducement rule, the Pirate Bay trial), why the open networks faded under four converging forces (legal pressure, spyware and fake files, broadband, and the convenience of legal streaming over CDNs), and how the architectures never actually died - Skype was FastTrack's supernode design, IPFS and blockchains reuse the same DHT and gossip lineage, and WebRTC put peer connections in every video call. It closes by setting apart Tor, the anonymity branch of the decentralized-network family, which is getting its own dedicated write-up. Shipped alongside a new Open Graph glossary entry: the og: meta tags that drive every link preview, and why single-page apps so often paste as a blank card.

    • Contenuto

      Study-guide scaffolding: the full Fortinet NSE 1-8 and Extreme Certified Professional programs, in preparation

      Twenty-seven new study-guide pages are now live in an honest in-preparation state, mapping out the whole content-development plan before a single objective is authored. The Fortinet set reflects the program as it actually stands after July 15, 2026, when Fortinet retired the FCF, FCA, FCP, FCSS, and FCX certifications and returned to the eight-level NSE 1-8 model: NSE 1 through NSE 4 as single credentials, NSE 5, NSE 6, and NSE 7 each split across the four tracks (Secure Networking, Security Operations, Cloud Security, and SASE), NSE 8 at the top, and the two industry certifications in OT Security and MSSP Security. The Extreme set reflects the current Extreme Certified Professional program: one ECP per technology track (Extreme Switching, Extreme Fabric, ExtremeWireless Cloud, ExtremeCloud IQ Controller, ExtremeCloud IQ Site Engine, ExtremeCloud SD-WAN, ExtremeControl, and ExtremeCloud Universal ZTNA), each built from the four Knowledge Credentials plus a proctored lab assessment. Every one of these is flagged as being prepared, with the certification structure verified from the vendors' own training sites on 2026-07-23 and no exam objectives invented ahead of an official blueprint. Content authoring begins next, from the ground up.

    • Contenuto

      GLOSSUP: the ether, daemons, the dark-web cluster, and the threat-intel trio

      Eleven glossary entries, en and pt-BR, plus enrichment of three that already existed. The ether/aether lands as lore: the medium nineteenth-century physics invented for light, killed by Michelson-Morley in 1887, and resurrected as the joke inside the name Ethernet, which is why a lost packet still vanishes into the ether. Daemons get their due, benevolent background spirits from Maxwell and MIT, never demons, whatever the BSD mascot suggests. The one-to-many and many-to-one patterns arrive as host-to-multihost and multihost-to-host, each with its dark twin named, amplification and DDoS respectively. Promiscuous mode explains what a capture tool actually asks the card to do. The dark-web cluster is built to end the usual confusion: deep web means merely un-indexed and is most of the web, a darknet is the private overlay network, and the dark web is the sites people run on top of one, framed honestly as a tool rather than a place. And the threat-intel trio, TTP, attack vector, and IoC, arrives with social engineering rewritten as its worked example: the technique no patch closes, the classic vector, a fixture of every actor's TTPs, defended by process rather than product. IoCs sit at the base of the Pyramid of Pain and TTPs at the top, and the cross-links now say so.

    • Contenuto

      Ping certification guides: Expert blueprints completed, Professional guides cross-wired

      Two passes over the Ping study guides. First, a wiring backfill: thirty-three Professional objectives across PingOne, PingOne DaVinci, PingOne Identity Governance, PingIDM, and Advanced Identity Cloud now carry the articles and tools that actually teach them, so the DaVinci connector objective points at the HTTP method and header articles, the directory objectives reach the LDAP fundamentals and search-filter material with the filter explainer beside them, and the MFA objectives sit next to the TOTP and HOTP tool. Second, and larger: all six Certified Expert blueprints are now transcribed complete. Four of them had been published with honest source gaps where an earlier capture had truncated - PingFederate cut off inside Objective 6, PingDirectory holding only its first objective, PingOne holding four items, Advanced Identity Cloud holding one section. Those gaps are closed, nothing invented: two hundred and ten Expert objectives now stand where one hundred and twenty-three did, with exam facts corrected from the official pages, including the seventy questions in ninety minutes at 61.66 percent for Advanced Identity Cloud and the four hands-on scenarios in an Ubuntu virtual machine for PingAM. The PingAM, PingOne, and Advanced Identity Cloud guides also gained per-objective study pointers; the remaining three are queued for the next enrichment wave.

    • Contenuto

      GLOSSUP M9: network topologies, the architecture models, and the bugs-and-tooling wing

      Thirty-two glossary entries in one wave, en and pt-BR. M9a covers the shapes: network topology as physical versus logical, then bus, star, ring, mesh, tree, and the hybrid that every real network actually is - plus the three architecture models, client-server, peer-to-peer, and host-to-host, with the note that host-to-host means the transport layer in the TCP/IP model and a point-to-point link in topology talk. M9b is the software wing: QA as a practice distinct from testing, regression testing as the memory of everything that ever went wrong, test automation and its coverage-percentage trap, semantic versioning, patches and the hotfix that must be merged back, and the tools - vi and Vim, nano, Emacs, and GDB. The memory-safety block lands with it: buffer overflow, stack overflow, integer overflow, off-by-one, null pointer dereference, use-after-free, and memory leak, each written with the mechanism in one breath and the mitigation as the payoff, alongside the defenses themselves - stack canaries, NX and DEP, ASLR, fuzzing, and CWE as the register they all report into. The new article, Memory safety: the bug classes and the defenses that answer them, ties the family together on the two axes that actually govern it, spatial and temporal, and is honest about the shape of the mitigation history: each layer raised the cost substantially and none ended the game. Also fixed in this wave: the events domain shipped in M8 but was missing from the glossary's canonical domain order, so its filter chip never rendered.

    • Contenuto

      Ping enrichment wave E3: IDM, Advanced Identity Cloud, and Governance - the wave closes

      The last forty-nine objectives, and with them all eight Professional guides are now fully annotated. PingIDM's eighteen cover the managed-object schema in managed.json, query filters and relationship graphs, reconciliation situations and LiveSync deltas, role-based provisioning, BPMN workflows, explicit attribute mapping, and clustered install and upgrade. Advanced Identity Cloud's seventeen carry the managed-cloud model - development-to-production tenant promotion, config-as-code, alpha_user and alpha_role objects, event hooks, default and self-service journeys, social registration, application client profiles, and the PingGateway bridge to on-prem. Identity Governance's fourteen cover the compliance heart of the platform: joiner-mover-leaver lifecycle automation, segregation-of-duties toxic-combination policies, certification campaigns, the business glossary that makes entitlements reviewable, access-request approval workflows, and reconciliation correlation. IDM query filters link the LDAP filter tool; the cloud federation objectives complete their SAML-decoder and grant-choosing wiring. Every pointer is labeled as an authored study aid over the verbatim blueprint. With E3 done, the Ping enrichment wave is complete - 664 objectives across fifteen guides, cross-referenced throughout.

    • Contenuto

      Ping enrichment wave E2: PingOne, DaVinci, and PingAM gain their study pointers

      Fifty-eight more objectives grow from blueprint into study guide. PingOne's twenty-three now walk the platform the way an administrator meets it - application types and worker apps, populations as hard one-per-user boundaries that are not groups, MFA policies versus the authentication-policy steps that invoke them, organization-versus-environment role scoping, custom domains with sending-domain trust, and agreements as consent gates inside a policy. DaVinci's eighteen carry the flow-builder's craft: subflows behind input/output contracts, the core connectors from HTTP to Code Snippet, version pinning through flow policies for rollout and rollback, and the recognition signatures of registration, password-reset, and authentication flows. PingAM's seventeen cover journeys and nodes, PingGateway enforcement, continuous risk with transactional authorization, mTLS certificate-bound tokens, token transformation, SAML2 in both roles, and the CTS-backed clustering that makes instances stateless. SAML objectives pick up the SAML decoder tool and federation article; mTLS links certificate validation; everything stays labeled as authored study aids over the verbatim blueprint. E3 - IDM, AIC, and Governance - closes the wave next.

    • Contenuto

      Ping enrichment wave E1: PingDirectory and PingAccess guides gain their study pointers

      The two Professional guides with the deepest wiring on this site grow from blueprints into working study guides. All thirty PingDirectory objectives and twenty-seven PingAccess objectives now carry authored study pointers - the dsconfig batch habit and config-audit.log's reverting commands, server profiles as the GitOps pattern, index types and the cost of unindexed searches, lockdown mode as the safe room for repair work; PingAccess's operational modes and the obfuscate-is-not-encrypt distinction, gateway versus agent trade-offs, ALL-versus-ANY rule sets, and header versus JWT identity mappings. Pointers are clearly labeled as authored study aids, distinct from the verbatim blueprint they annotate - and PingAccess objective 6.01 keeps its PDF-verbatim sub-items untouched. Cross-references deepen along the way: certificate objectives link the x509 tool and the certificate-formats article, JWT identity mapping picks up the JWT and JWKS tools, and the OAuth objectives complete their wiring into the grant-choosing article. E2 (PingOne, DaVinci, PingAM) and E3 (IDM, AIC, Governance) follow.

    • Nuovo strumento

      New tool: the OAuth flow chooser - and the Ping run closes

      Three honest questions - what kind of app, is there a user, do you need offline access - and the modern grant comes back RFC-cited: authorization code + PKCE for anything a human signs into (confidential where a backend exists, with RFC 8252's system-browser rule spelled out for native apps), client credentials for machines with the no-refresh-token note, and the device grant for every TV activation you have ever performed. Half the answer is the avoided list: implicit and ROPC retired by name per RFC 9700, the Security BCP that finally wrote a decade of wisdom into normative text, plus refresh-token rotation for public clients and a contradiction warning when a machine-to-machine flow is asked for end-user identity. Twelve golden vectors pin the decision table. The paired article, choosing the grant in 2026, walks the whole decision in prose and closes with the table in one breath. Wired into the PingFederate, PingAM, and PingAccess guide objectives it now serves - and with that, the Ping run is complete: fifteen certification guides, the identity Learn wave, and two tools, all cross-referenced.

      OAuth flow chooser

    • Nuovo strumento

      New tool: the LDAP filter explainer - plus the article that teaches the parentheses

      The Ping run's first tool. Paste any LDAP search filter and it comes back as an annotated tree, parsed exactly as RFC 4515 specifies: every AND, OR, and NOT node explained, every leaf classified across the six match types, hex escapes decoded and listed, and the three famous Active Directory matching-rule OIDs - bit-AND 803 with its disabled-account idiom, bit-OR 804, and the transitive-membership walk of 1941 - recognized by name. Syntax errors are anchored to the exact character with a caret under it. Fourteen golden vectors pin the parser, including four deliberate failures. Everything runs in the browser; filters full of internal attribute names never leave the page. The paired article, LDAP search filters: reading the parentheses, builds the grammar from prefix notation up through escapes and injection, the extensible-match OIDs, and the performance chapter nobody reads until the outage - why unindexed filters and leading wildcards take directories down, tied straight into the PingDirectory guide objectives it now cross-references.

      LDAP filter explainer

    • Contenuto

      Ping Certified Professional: all eight remaining study guides transcribed

      The Ping Professional shelf is complete. The eight guides that had been standing as verified scaffolds - PingAccess, PingDirectory, PingOne, PingOne DaVinci, PingAM, PingOne Advanced Identity Cloud, PingIDM, and PingOne AIC Governance - now carry their full official blueprints: 165 objectives across 42 sections, transcribed verbatim from the official Certified Professional Study Guide PDFs, down to nested sub-items and the products' own phrasing. Exam facts gained the USD 395 fee and each exam's official recommended training courses. The PingFederate Professional guide, built earlier from the same source, reconciled against its PDF exactly - four sections, twenty-four objectives, no drift. With the six Expert blueprints already in place, all fifteen Ping certification guides are now live: nine Professional, six Expert, every objective sourced.

    • Contenuto

      M8b: Fenasoft, the world circuit, and the operators' meetings close the events run

      The events domain completes its map. Fenasoft anchors the Brazilian memory: Max Gonçalves's fair at the Anhembi, 800,000 visitors in 1993, the queues that became part of the story, and the loucura that ended when the fair went corporate. The hacker circuit gains ShmooCon - twenty years of affordable-on-purpose, closed on its own terms in 2025 - alongside Heidelberg's TROOPERS with its soldering corner and roundtables, Hack In The Box carrying deep-knowledge from Kuala Lumpur across three continents, and Nullcon scaling India's null community onto the Goa main stage. The trade floor seats RSA Conference (Black Hat is where research premieres; RSA is where it gets productized), Cisco Live with its Networkers DNA and careers minted at on-site testing, and MWC anchoring the telecom calendar in Barcelona. And the operators get their town halls: NANOG's hallway track and legendary mailing list since 1994, and LACNIC, whose meetings concentrate a continent's BGP, IPv6, and peering arguments into one week. Eleven entries, every one sourced and live-verified. Glossary: 1,111 entries.

    • Contenuto

      M8a: the events domain opens - Brazil and Latin America first

      The glossary gains its fifteenth domain: events. Ten residents were already here and simply raise their flags - DEF CON, Black Hat, YSTS, BSides São Paulo, H2HC, Mind The Sec, the Chaos Computer Club's Congress, 2600's HOPE, the IETF's meetings, SANS's summits - and eight newcomers give the domain its southern accent. Roadsec arrives as the festival that travels to its audience, Hackaflag crowning national champions along the caravan. CryptoRave brings the crowdfunded 24-hour marathon where privacy is deliberately popular, and GTS/GTER seat the operators' hallway track - Comdex-SP 1996 to CERT.br to the Semana de Infraestrutura. Campus Party pitches its tent city, Latinoware convenes free software at the Itaipu border, and the Latin circuit completes with Ekoparty (where BEAST and CRIME premiered), DragonJAR's all-Spanish commitment, and Chile's 8.8 wrapping rigor in pop culture. Every entry sourced, every claim live-verified. Glossary: 1,101 entries.

    • Contenuto

      GLOSSUP M7: methodologies, the certification ladders, and Furukawa

      The frameworks people are managed by, explained without the consulting gloss. ITIL grows from a thin stub into the full story - CCTA books to PeopleCert stewardship, ITIL 4's peace treaty with Agile - and COBIT arrives as the auditor's counterpart: who decides, who is accountable, how do we prove it. Agile gets the Utah ski lodge and the honest infrastructure reading (feedback beats prediction exactly where requirements cannot be known - and turns to ritual theater where the work is operations), OKR carries Grove's Intel discipline through Doerr's 1999 Google, and Kanban travels from Toyota's signboards to WIP limits as the one rule that does all the heavy lifting. The certification shelf seats the Cisco ladder (CCIE 1993 before the associate tiers existed, holders citing numbers like pilots log hours), the CISSP at its deliberately managerial altitude, and CWNP/CWNA as where engineers learn why the survey looks the way it does. And Furukawa - now Lightera on the box, Furukawa in every installer's mouth - enters as Brazil's structured-cabling standard-bearer: Curitiba, ABNT NBR 14565, and the FCP rite of passage, cross-linked straight into the cabling wing. Glossary: 1,093 entries.

    • Contenuto

      GLOSSUP M6b: IS-IS, MPLS, and the multicast wing close the routing run

      Two primers finish the routing quartet. The IS-IS primer explains the twin with the strange accent: why it runs directly over layer 2 and cannot be attacked from three hops away, the NET address ritual, levels instead of areas with the backbone as a contiguous set rather than a configured zone, the preemptive DIS election that catches OSPF natives, and the TLV design that absorbed IPv6, traffic engineering, and Segment Routing without ever needing a version break - extensibility as the feature that outlives every feature. The MPLS primer fits the whole mechanism into three verbs - push, swap, pop - then builds the architecture from the label stack: the BGP-free core, RFC 4364 L3VPNs with a thousand overlapping 10.0.0.0/8 customers never meeting, the LDP-to-RSVP-TE-to-Segment-Routing signaling arc, penultimate hop popping, the four-byte MTU tax, and an honest two-half answer to the SD-WAN question. The glossary gains the multicast wing - IGMP raising hands at the last hop with snooping as the melted-network preventive, PIM building shared and source trees around rendezvous points, and DVMRP as the flood-and-prune pioneer whose MBone streamed the Rolling Stones before streaming had a name - while the IS-IS and MPLS entries themselves received full house-depth rewrites. Glossary: 1,085 entries; the Learn shelf: 239 articles.

    • Contenuto

      The liveness trio: first-hop redundancy, BFD, and DPD

      Three entries about the same instinct - never trust silence. The VRRP entry grows into the whole first-hop redundancy family: the virtual gateway trick, VRRP's RFC 5798 mechanics beside Cisco's HSRP precursor and the load-balancing GLBP variant, preemption, the gratuitous ARP that announces a changeover, and FHRP as the family name. BFD gets its house-depth treatment as liveness-as-a-shared-service: one millisecond-scale session notifying BGP, OSPF, IS-IS, static routes, and VRRP in a single stroke - the difference between 50 milliseconds and 30 seconds wherever the media will not signal loss of link. And Dead Peer Detection joins as the IPsec chapter of the same story: the on-demand R-U-THERE exchange that keeps gateways from encrypting into a void, born in the IKEv1 era and surviving in every tunnel configuration UI since. Glossary: 1,082 entries.

    • Contenuto

      GLOSSUP M6a: the BGP and OSPF primers

      The routing wing opens with its two pillars, written to be read. The BGP primer starts where BGP starts - routing between networks is a business problem, not a math problem - and walks the autonomous-system world, the path-vector idea, the attribute order that decides real arguments (local preference, AS-path, MED, and communities as the duct tape of interdomain policy), why convergence is slow on purpose, and the RPKI answer to the protocol's famous credulity, napkin lore included. The OSPF primer covers the map-and-math model: link-state flooding and Dijkstra, cost and the reference-bandwidth trap that makes gigabit and hundred-gigabit links cost the same, areas and the one rule that is really a law, the DR election and its non-preemptive surprise, the universal troubleshooting checklist, and the habits that keep OSPF boring - the highest compliment an interior protocol can earn. In the glossary, RIP and EIGRP received full house-depth rewrites (routing by rumor and the fifteen-hop horizon; DUAL, feasible successors, and the IGRP inheritance), and bgp, ospf, igp, and egp now cross-reference the primers. English and native Portuguese throughout.

    • Contenuto

      Ping Certified Expert blueprints: six guides transcribed

      The Expert tier arrives in the certification library, transcribed verbatim from authenticated captures of the official exam pages. PingAccess (PAAA-001) lands complete with its fifty-one objectives - the famous forty-five-item advanced-configuration rule gauntlet included, every rule type by name. PingFederate (PFAA-001) carries forty-seven objectives across six sections from OGNL attribute mappings to log4j2 troubleshooting, PingDirectory (PDAA-001) its eleven-item advanced-configuration section, PingAM (PAME-101) its four-scenario hands-on format - three and a half hours in an Ubuntu VM - and PingOne Advanced Identity Cloud (PAICE-001) its seventy-question, 61.66-percent-pass-mark tenant-administration blueprint. Where the captures cut off, the guides say so plainly: source gaps are named, never invented - PingFederate's Objective 6 tail, PingDirectory's Objective 2, and Advanced Identity Cloud's Section 2 await complete captures, and Certified Expert PingOne stays in preparation with its first four objectives stored verbatim. Exam codes verified throughout; 123 new objectives bring the mapped total to 499.

    • Contenuto

      The Ping lineage, rebuilt rich - and the three bloodlines truth

      The Ping Identity genealogy returns, rebuilt as the site's reference lineage. The research surfaced what the old two-line diagram undersold: there are three bloodlines, not two. Denver federation from 2002; the Sun open-source line that Oracle's absorption sent to Oslo as ForgeRock's OpenAM and OpenDJ; and the UnboundID directory, built by Sun directory alumni in Austin and joined to Ping in 2016 as PingDirectory. Five stages now carry the story - the parallel public listings, Thoma Bravo taking both companies private in 2022 rendered in muted tone, and the August 23, 2023 combination in accent: one platform, all three heritages, DaVinci as the orchestration tissue. The rich Lineage section joins the rich Timeline as a mandatory part of every vendor's details on this site.

    • Contenuto

      The French CYCLADES, SampaSec, and the Ping timeline standard

      Three additions with one thread: honoring where things actually began. The pioneer lineage gains the CYCLADES research network - Louis Pouzin's 1972 IRIA project where the datagram was coined, host-responsible reliability was proven, and the design Cerf and Kahn's 1974 TCP/IP paper cites directly was born, before French PTT politics killed it in favor of Transpac. It shelves deliberately beside the Brazilian Cyclades of the console-server story: same name, different continent, both honored, and the Brazilian profile's footnote now points across. The glossary's Brazilian-scene shelf finally seats SampaSec - Sao Paulo's CitySec, the third-Wednesday bar meetup that has been the scene's connective tissue since around 2010 - with the community's own channels as sources. And the Ping Identity page retires its genealogy diagram: the two-bloodlines story now lives entirely in the profile timeline, chronology corrected, rendered to the same rich standard as the F5 page - the standard every timeline on this site now follows. Glossary: 1,081 entries; encyclopedia: 86 profiles.

    • Contenuto

      Industry waves: six new profiles and the T1/E1 pair

      The encyclopedia grows to 85 profiles. Dolch Computer Systems joins the pioneer lineage as the hardware half of the packet-analysis story - the rugged luggables the Computer History Museum itself catalogs as Sniffer platforms, from Volker Dolch's 1987 founding to the Kontron and Azonix handoffs. Five contemporaries arrive importance-ranked: ASUS and Askey consolidated as one group (the motherboard empire and its carrier-CPE ODM arm, both 1989 Taipei foundings), NETGEAR as the inventor of networking-as-retail born inside Bay Networks, TP-Link as the volume king with its US scrutiny kept factually in the record, Zyxel from the Taoyuan apartment lab through the U-1496 legend and the world-first integrated modems, and Allied Telesis - Takayoshi Oshima's thirty-five-year Ethernet workhorse that began with media converters. Every founding date, fate, and first was live-verified against company records, Wikipedia chronologies, and primary announcements. In the glossary, the T1/E1 pair lands beside SONET: the 1.544 and 2.048 megabit carriers, their DS0 arithmetic, PRI channel counts, and the regional fork that made 'dois megas' the sound of Brazilian business connectivity. Glossary: 1,080 entries.

    • Contenuto

      GLOSSUP M5: the transport and optical wing

      Eight entries for the carrier layer the heritage protocols rode on. ATM gets the honest obituary (the 53-byte bet, VPI/VCI, the cell tax, and MPLS taking the ideas and leaving the cells), and LANE gets the cautionary-tale treatment its LEC/LES/LECS/BUS edifice earned. SONET and SDH arrive as the synchronized hierarchy with the 50-millisecond reflex, Packet over SONET as the clean example of removing a layer instead of managing it, and the OC ladder (OC-3 through OC-768, with the STM twins) as the speed vocabulary two decades of diagrams are written in. DWDM explains why one strand carries terabits, and the IGP/EGP pair closes the wing - including the disambiguation that EGP is both a class and the specific 1984 protocol BGP replaced. Frame Relay, X.25, MPLS, and dark fiber now cross-reference into the wing. English and native Portuguese. Glossary: 1,078 entries.

    • Nuovo strumento

      New tool: the cable run planner closes GLOSSUP

      Tool number 119 answers the field question the way the standards answer it. Pick a speed tier, type the run distance, set the environment and the PoE class, and every compliant medium appears - each twisted-pair category and fiber grade citing the rule that governs it: the ANSI/TIA-568 100-meter channel, 802.3bz's 2.5G-on-Cat 5e and 5G-on-Cat 6 mappings, the Cat 6 ten-gigabit ceiling of roughly 55 meters per TIA TSB-155, Cat 8's 30-meter data-center window, and the SR/LR optic reach ladder from 10GBASE-SR at 300 meters on OM3 up through 100GBASE-SR4 and the 10-kilometer LR class on single-mode. The exclusion list is half the tool: everything that fails says exactly why. Environments attach shielding, plenum-jacket, and outdoor notes; 802.3bt attaches the TSB-184-A bundle-heat guidance. Fourteen golden vectors pin the rules table, including exact-at-limit optics cases. Example and Clear buttons per house rule, all compute local, API-included. Paired with the structured-cabling article, whose related tools now include it.

      Cable run planner

    • Contenuto

      GLOSSUP M3: the cabling and facilities wing

      The physical layer gets its vocabulary. Sixteen entries cover the copper (UTP, the shielded constructions, the Cat 5e-to-8 category ladder with its honest 55-meter and 30-meter caveats, RJ45 as the 8P8C that it properly is, T568A/B, the crossover cable auto-MDIX retired, and the plenum/riser fire ratings inspectors enforce), the glass (single-mode OS1/OS2 versus multimode OM1-OM5, the GBIC-to-OSFP transceiver lineage now anchoring the existing SFP entry, media converters), the power (PoE injectors beside the enriched PoE entry), and the rooms (wiring closets and the MDF/IDF grammar, the 19-inch rack and its 1.75-inch U, hot/cold aisle containment, and the Uptime Institute tiers - carefully distinguished from the identically-worded ISP and support tiers). A new Learn article, Structured cabling, ties the wing together: the TIA-568 star-of-stars topology, the 100-meter channel and its 90+10 split, category certification as an end-to-end property, fiber where copper stops, and why the system's boringness is the achievement. English and native Portuguese throughout. Glossary: 1,070 entries.

    • Contenuto

      GLOSSUP M2: the heritage and WAN protocol wing

      Sixteen protocols that ran the networks before TCP/IP swept the field now join the glossary, each sourced and woven to its neighbours. The vendor-stack lineages: DECnet (the VAX era, Phase IV to Phase V/OSI), XNS (the Xerox PARC design that IPX and much else copied), AppleTalk (Apple's 1985 zero-config suite, discontinued in Snow Leopard 2009 for Bonjour - and notably not XNS-based), IPX/SPX and Novell's SAP (the NetWare LAN and its broadcast-storm cautionary tale), and IBM's SNA with its SDLC link layer. The serial and dial-up family: PPP with its LCP/NCP and PAP/CHAP authentication, the cruder SLIP it replaced, Multilink PPP for bonding links, and PAP and CHAP themselves as the plaintext-versus-challenge-response object lesson. The framing and WAN core: HDLC (the ISO standard under X.25's LAPB, Frame Relay, and ISDN's LAPD), its IBM ancestor SDLC, Frame Relay, and the genuine ancestors X.25 (CCITT 1976, older than IPv4, used in card networks into the 2010s and aviation still) and X.21. Dates and lineages verified against ITU-T, Wikipedia, and the Computer History Museum. Existing Token Ring and PPPoE entries were enriched to point back. English and native Portuguese. Glossary: 1,054 entries.

    • Contenuto

      GLOSSUP begins: the IEEE 802 family, mapped group by group

      The promise made inside the IEEE glossary entry is now kept. A new Learn article walks the 802 committee - the LMSC, formed in 1980 - working group by working group: 802.1 as the architecture arm (VLAN tags, 802.1X port authentication, the spanning-tree lineage), 802.3 as Ethernet from 10BASE5 to hundreds of gigabits and the home of PoE across af/at/bt, 802.11 as every Wi-Fi generation up to Wi-Fi 7 (802.11be-2024, verified against ieee802.org), and 802.15 as Bluetooth and Zigbee. It closes with the honest register the committee itself publishes: which groups are active, which hibernating (802.16 WiMAX, 802.21, 802.22), and which disbanded (802.2 LLC, 802.4, 802.5 Token Ring, 802.6, 802.14 Cable Modem). Five glossary entries land alongside it - 802.1Q, 802.1X, 802.3, Wi-Fi, and WPA - each cross-linked into the article and into the existing Ethernet, VLAN, and PoE entries, which were enriched to point back. English and native Portuguese. Glossary: 1,038 entries.

    • Contenuto

      B.5 closes: the trust-center compliance rosters

      The three vendor trust centers this site's instructor teaches - F5, Netskope, and Extreme - were fetched live and their compliance rosters turned into sourced glossary entries. Twelve standards join, each cross-linked back to the CSA and NIST entries from earlier in the run: ISO/IEC 27001 with its cloud siblings 27017 and 27018, SOC 2 (already present, now surrounded), FedRAMP with the High baseline both F5 and Netskope hold, PCI DSS, HIPAA, CSA STAR tying every roster back to the Cloud Controls Matrix, the UK's Cyber Essentials, Germany's BSI C5, Australia's IRAP, the EU-U.S. Data Privacy Framework, and the EU NIS2 directive that Extreme's trust center foregrounds. Netskope's table gave ISO/SOC/HIPAA/C5/STAR/IRAP/Cyber Essentials/ENS/DPF/PCI/FedRAMP verbatim; F5's added IRAP, C5, DORA, DMA, DSA, TISAX, and ENS; all facts verified against the pages this session. Glossary: 1,033 entries. This closes the Standards and Communities run.

    • Contenuto

      B.5 movement 2: the cons, clubs, and communities

      Fourteen entries bring the culture into the glossary, every one sourced to its official home, with the Brazilian scene live-verified this session. The global institutions: DEF CON from farewell party to villages, badges, and Goons; Black Hat as the corporate counterpart; the Chaos Computer Club from the 1984 Btx hack to the C3; and 2600 Magazine, whose editor opened the very first YSTS - the thread that ties the global lore to Sao Paulo. The Brazilian scene, facts checked: YSTS with its bar-day format and the speaker medal that grants lifetime entry; BSidesSP, born inside Garoa Hacker Clube in 2011 and fifteen editions strong; Garoa itself; Mente Binaria with the free CERO and AMO courses and the CodeHERS program; H2HC as Latin America's oldest research conference, running since 2004; and Mind the Sec on the enterprise end, September 15-17 this year. The practitioner platforms close it: F5 DevCentral and its MVP program, the Fortinet Community as FUSE's successor, APIsec University's free certificate courses, and Reddit's networking and vendor subreddits as the unofficial-but-load-bearing troubleshooting layer. Glossary: 1,021 entries.

    • Contenuto

      B.5 opens: the standards bodies join the glossary

      The Standards & Communities run begins with the institutions themselves, each entry fully sourced to its official home. NIST with the FIPS and SP 800 series this site already cites, the AES and SHA-3 competitions, and the post-quantum ML-KEM/ML-DSA line. MITRE as steward of the CVE, CWE, and ATT&CK vocabularies. The IETF and its rough-consensus RFC process beside the existing IANA entry. The Cloud Security Alliance with the CCM and STAR registry every vendor trust center references. SANS/GIAC and the Internet Storm Center. ISC2 and the CISSP, post-2023 rebrand noted. The EFF, from 1990 to Certbot and the Let's Encrypt founding. IEEE and the 802 committee, with the group-by-group map flagged as coming. And EIA/TIA with the TIA-568 structured-cabling family, the bridge into the physical-layer wing ahead. Nine new entries plus an enriched OWASP, all in English and native Portuguese - 1,007 glossary entries total.

    • Contenuto

      New reading path: The Ping Identity Platform

      The five platform explainers and the PingFederate shelf now walk in one line. The path opens with the map before the terrain - the PingOne platform disambiguation and the ForgeRock lineage decode, so every product name resolves before any product detail - then the three deep-dives (PingAccess policy model, the PingDirectory data platform, DaVinci orchestration), and closes with the ten PingFederate articles in their established teaching order as the self-managed federation core. Fifteen articles, five companion tools, and the natural walking route beside the nine Certified Professional study guides on the certifications hub.

    • Contenuto

      The Ping platform wave: five explainers beyond PingFederate

      Run B movement 2 lands the Learn wave that maps the rest of the Ping Identity estate, official-docs grounded and live-verified. The PingAccess policy model: gateway versus agent (sites, PAAP, shared-secret fleets), applications and resources, rules composed into rule sets and groups, the fixed evaluation order with identity mappings first and access control before processing, and token mediation as the legacy bridge. The PingDirectory platform in four verbs: store (LDAP plus native SCIM 2.0 REST, cn=config, server groups), aggregate (the Proxy as LDAPv3 gateway and virtual directory), sync (PingDataSync's real-time bidirectional pipelines across AD, Oracle/Sun, OpenDJ, and generic LDAP), delegate (the guarded self-service surface). PingOne decoded as the platform behind the product names, service by service: SSO, MFA, Protect, Verify, Authorize, DaVinci. DaVinci itself as orchestration-as-a-canvas: flows, the connector catalog, server-driven orchestration that changes journeys without app releases, the Singular Key origin. And the ForgeRock lineage from Sun's OpenSSO, OpenDS, and OpenIDM through OpenAM and OpenDJ to PingAM, PingDS, PingIDM, PingGateway, and Advanced Identity Cloud - the 2023 merger, the parallel stacks, and the prefix rule that decodes any diagram. All five in English and native Portuguese, cross-linked into the existing OAuth, OIDC, SAML, SCIM, and LDAP shelves.

    • Contenuto

      The cipher shelf completed: families map + the verdict ledger

      PRIME's cipher enrichment directive, delivered where the gaps actually were: the existing shelf already carried suite anatomy, the three naming conventions, the TLS 1.3 shrinkage, the danger keywords, and the Cipher Suite Decoder tool - so two missing pieces were built, not duplicates. 'Cipher Families: The Working Map' is the encryption counterpart to the hash-families article: block versus stream, AES versus ChaCha20 with the advantages and disadvantages of each, why AEAD ended the assemble-it-yourself era, what RSA, elliptic curves, and ECDHE each contribute, and the retired members (DES, 3DES, RC4) with the attacks that retired them. 'Which Cipher Suites to Use: The Verdict Ledger' then answers the configuration question in five tiers - recommended now, acceptable in niches, declining, absolutely forbidden by name and RFC (7465, 7568, 8996, 9155), and the post-quantum future - each grounded in RFC 8446, Mozilla's current Modern and Intermediate profiles, and NIST SP 800-52r2, all verified against live sources this session. Three glossary terms join alongside: block cipher, stream cipher, and key exchange.

    • Contenuto

      Certifications hub layout fixed + the Cisco-inside-Cabletron chapter

      Two PRIME-reported issues closed. The certifications hub had vendor section titles rendering as raw translation keys (a lookup pointed at the vendor object instead of its name), and the collapsible certification rows borrowed a column-card style that stacked triangle, name, and code vertically - titles now resolve properly and each certification collapses to a true one-line row. And the career history gets its missing opening: the Cisco relationship began in 1996, not 2003 - the Cabletron years ran on Cisco routing sold as Cabletron-branded OEM modules built on licensed Cisco IOS, the CRBRIM and its WAN routing siblings carrying Cisco 2500-, 4000-, and 4500-series technology in the MMAC hub family, installed, configured, optimized, and troubleshot daily in the printed-config era, until the YAGO-born SmartSwitch Router displaced them. Both the Cabletron and Cisco vendor pages now tell it, in both languages.

    • Nuovo strumento

      Algorithms primer + the sorting stepper

      New learning wing opens: the primer 'What Is an Algorithm?' gives the working definition, the three engineering questions (correct? how does cost grow? what does it trade?), Big-O as the grammar of growth with its honest caveats, and the families already running under this site's own tools. Beside it ships the sorting-algorithm-stepper: paste up to 16 numbers, pick bubble, selection, insertion, merge, or quick, and watch every comparison and swap with a one-line WHY - counters included, so O(n log n) versus O(n-squared) stops being notation and becomes something you watched happen. Teaching behaviors preserved on purpose: bubble's early exit on sorted input, and Lomuto quicksort's degradation on it. Also this update: the Ping Identity Certified Expert tier (six exams) joins the certifications hub in preparing status per PRIME's ruling.

      Sorting algorithm stepper

    • Contenuto

      Ping Identity program mapped: eight new certifications

      Run B opens with the verified answer to 'a triad, or more?': the Ping Identity Certified Professional program spans NINE products - PingFederate (already on this site), PingAccess, PingDirectory, PingOne, PingOne DaVinci, PingAM, PingOne Advanced Identity Cloud, PingIDM, and PingOne Identity Governance - plus a Certified Expert tier across six of them. All eight new certifications join the hub with only officially verified facts (Kryterion delivery, credential lengths, renewal windows, and exam formats where published: PingAccess PAP-001 70q/90min/64% on version 8+, PingAM 100q/120min/66% on version 7 with AM-410 required, PingIDM 100q/120min/66%, Advanced Identity Cloud 60-70q/90min/70%). Guides sit in preparing status until the official per-exam study-guide PDFs are transcribed - no invented objectives.

    • Infrastruttura

      Placement-level traffic attribution, site-wide

      Every outbound Red Education link now carries five-parameter placement attribution: utm_campaign names the vendor value stream, utm_content the exact page (course/adm-big-ip, vendor-partner/red-education), and utm_term the language and call-to-action (pt-br.request-training). Attribution moved from module-scope constants to render time, where the vendor, page, locale, and CTA context lives - so analytics can answer not merely whether ronutz.com sends traffic, but which page, CTA, vendor, article, and language produces the value. Standing rule for all future placements.

    • Nuovo strumento

      Netskope steering decision explainer

      The 117th tool and second native Netskope one: paste a compact steering spec and walk the documented decision order to steered, bypassed, blocked, or direct - with the why-ledger. It knows the three traffic modes and their audiences, the always-on RFC1918 bypass, the exception families including cert-pinned steer-and-decrypt, dynamic steering's per-location modes down to None, Fail Close's documented split (domain/IP/cert-pinned exceptions survive it, category exceptions do not), and the non-standard-port-by-IP pitfall with its FQDN-plus-IP remedy. Fourteen golden vectors; API-included; woven into thirteen steering objectives across the five Netskope guides and into the netskope-sase path.

      Netskope steering decision explainer

    • Contenuto

      Netskope program complete: accreditations + Learn wave 1

      The Netskope shelf grows in both directions. Credentials: the two CURRENT Academy accreditations (Administrator TR-772-1, Integrator TR-773-1) join the registry with verbatim topic lists from the official PDFs, the three NSK certification guides gain corrected lineage notes (the 2024 accreditations replaced them), and the hub now shows five Netskope credentials in program order. Content: eight new articles in en + pt-BR - platform architecture and NewEdge, steering methods, client deployment, real-time vs API protection, the Cloud Confidence Index, Private Access (NPA), Cloud Firewall, and events/Advanced Analytics - woven into 52 guide objectives across all five Netskope guides, so nearly every domain now teaches from this site. Collaterals: the netskope-sase reading path (eleven articles, two tools, in platform teaching order) and two glossary entries (CCI, NewEdge) in en + pt-BR.

    • Contenuto

      Netskope certification program: three study guides

      The certifications hub gains the Netskope Cloud Security Certification Program: NCCSA (NSK101), NCCSI (NSK200), and Cloud Security Architect (NSK300), each transcribed verbatim from the official certification-description PDFs on netskope.com - five domains per exam, 58 published objectives total, practitioner profiles, validity and lineage notes (each certification replaced a former accreditation), and the Academy course chain (NSCIOTT, NSCO&A, NSCI&I, Activation & Adoption) in the source labels. Objectives map to the site's steering, SAML/SCIM, DLP, sandbox, TLS-inspection, and HTTP shelves; the unmapped objectives chart the Netskope Learn wave to come.

    • Nuovo strumento

      HTTP wave: nine articles + status-code explainer

      The HTTP estate grows a full teaching arc: methods (safe/idempotent as the bits the plumbing runs on), status-code families, headers anatomy (end-to-end vs hop-by-hop, Host, order-as-fingerprint), cookie mechanics, forms and request encoding, AJAX/fetch/XHR, CORS, URI-vs-URL-vs-URN, and the HTML/CSS/DOM triad - nine articles in en + pt-BR, cross-referenced into the existing curl, URL, and security-header shelves. Plus a new API-included tool: the status-code explainer, RFC-9110-grounded, answering unknown codes with the protocol's own x00 forward-compatibility rule. The http-evolution reading path grows to fourteen articles and five tools.

      HTTP status code explainer

    • Contenuto

      Why we say SSL when we mean TLS

      A transport-family article on the web's most persistent misnomer: Netscape's three SSL drafts, the 1999 political rename (the wire version field still says 3.1), the RFC 6176/7568 executions, the inertia mechanics - CA product names, openssl, configuration fossils - and the naming musing: HTTPS names the scheme, encryption-in-transit names the property, QUIC is moving the ground again, and RFC 8446 kept the name on purpose.

    • Funzionalità

      Certifications hub: vendor-ordered, collapsible

      The certifications hub now lists study guides by vendor in hub order and, within each vendor, in certification order (F5: CA, CTS-LTM, DNS, ASM, APM, CSE-Security, CSE-Cloud, NGINX). Vendors stay visible; certification rows collapse by default and expand to their exam-guide cards, with expand-all and collapse-all controls.

    • Contenuto

      Brazilian connectivity history + access technologies

      Four articles in en + pt-BR - the last mile from POTS to always-on (anchored on a 1999 Telesp Speedy first-subscriber story), pagers and paging networks (the Teletrim operator-relay era), LEO satellite constellations, and LoRa/LPWAN - plus fifteen glossary entries: TELESP, TELEBRAS, EMBRATEL, ANATEL, CGI.br, NIC.br, FAPESP, USP, UNICAMP as sourced lore, and POTS, ADSL, HFC, LEO constellation, LoRa, and pager as the access-technology vocabulary. The pre-1996 history page gains the bip: a timeline beat, a narrative movement, a field-guide card, and the ADSL coda that ends the POTS era where it began.

    • Nuovo strumento

      ZCC forwarding decision explainer

      Fifth native Zscaler tool, shipped in the ratified descoped form after the authorized verification pass: the documented forwarding spine (network-state determination, per-state ZIA and ZPA actions, Z-Tunnel 1.0 vs 2.0 with the automatic failover and hybrid web-split) computed layer by layer, the bypass mechanisms rendered as an explained ledger, and the why-explainer-not-simulator statement as first-class output - the cross-mechanism bypass precedence is unpublished, so the tool invents nothing. Twelve golden vectors; four pinned vendor sources.

      ZCC forwarding decision explainer

    • Contenuto

      Zscaler glossary batch 2: seven platform terms

      The PKG's closing glossary batch, en + pt-BR: ZIdentity, Private Service Edge, SSMA (Single Scan, Multi-Action), application segment, segment group, app profile, and posture profile - each cross-linked into the program's existing entries. The glossary reaches 978 entries.

    • Nuovo strumento

      ZDX score factor explainer

      Fourth native Zscaler tool: paste the metrics ZDX exposes and read the documented explanation of each - probe-family attribution, the score against the documented Poor band with its auto-RCA note, the web-versus-path diagnostic split, and the honesty calibrations. The composite formula is not published, so the tool computes no score and says so. Twelve golden vectors; three pinned vendor sources.

      ZDX score factor explainer

    • Contenuto

      Zscaler waves 3 and 4: monitoring, logs, and operations (11 articles)

      The program's closing arc, en + pt-BR: the ZDX score's anatomy, the administrator audit log, ZIA log fields, Nanolog/NSS/Cloud NSS/LSS streaming, reports and executive summaries, ZCC connectivity troubleshooting, ZPA access troubleshooting, the exfiltration-response walkthrough, the M&A scenario, locations and sublocations, and platform updates with change management. ZDTA coverage reaches 44/44 objectives; the zscaler-zero-trust reading path now spans the full arc with five tools.

    • Nuovo strumento

      ZIA SSL bypass planner

      Third native Zscaler tool: paste an asset list (pinning, governance category, path control) and receive a deterministic TLS inspection plan - Inspect, policy Do Not Inspect, or Client Connector bypass - each verdict with sourced rationale, a priced blind-spot ledger, and the outside-backstop checklist whenever anything goes uninspected. Twelve golden vectors; grounded in Zscaler's SSL inspection documentation.

      ZIA SSL bypass planner

    • Contenuto

      Zscaler wave 2: nine articles, the reading path, and the hub family section

      Three fundamentals (DLP, sandbox detonation, browser isolation) and six Zscaler deep dives (URL Filtering and Cloud App Control precedence, File Type Control and Sandbox, DLP dictionaries/engines/EDM/IDM, CASB and SaaS security, ZPA app segments and access policy, posture and device trust) in English and Portuguese - plus the zscaler-zero-trust reading path and the Zscaler Zero Trust Exchange family section on the vendor hub.

    • Nuovo strumento

      ZIA firewall rule-order simulator

      Paste Firewall Filtering rules and a flow; watch ascending-order, first-match evaluation execute, with the deny-by-default Default rule catching fallthrough and pairwise shadow findings naming the rules that can never fire. Grounded in three pinned Zscaler Help pages; 14 golden vectors.

      ZIA firewall rule-order simulator

    • Contenuto

      Zscaler wave 1b: the platform foundations, in en + pt-BR

      Seven Learn articles land the Zscaler program's core: the Zero Trust Exchange architecture, ZIA traffic forwarding methods, the three tunnel types with Zscaler's published capacity figures, Client Connector forwarding and app profiles, ZPA's App Connectors and Service Edges, ZIA TLS inspection policy and bypasses, and the Cloud Firewall's rule-order semantics - each depending on the fundamentals layer shipped first, per the fundamentals-first standing rule.

    • Nuovo strumento

      Zscaler Tunnel Chooser: GRE vs IPsec, sized from the vendor's own figures

      First native Zscaler tool. Six answers about a location - bandwidth, HA, static IP, encryption mandate, GRE support, endpoint NAT - return the deterministic tunnel recommendation with the minimum primary and backup counts, computed from Zscaler's published per-tunnel figures (GRE 1 Gbps, 250 Mbps under source NAT, IPsec 400 Mbps per source IP), every elimination step shown and sourced.

      Zscaler tunnel chooser · Open the tool · GRE fundamentals

    • Contenuto

      The fundamentals layer opens the Zscaler program (R-8)

      Four vendor-neutral fundamentals articles land in English and Portuguese as the knowledge dependencies of the Zscaler wave: GRE tunnels, IPsec and IKE, tunnel overhead with MTU and MSS clamping, and how inline proxies authenticate users - the first program cut under the fundamentals-first coverage rule, with existing fundamentals linked rather than duplicated.

      GRE tunnels · IPsec and IKE · Tunnel overhead, MTU and MSS · Proxy user authentication

    • Contenuto

      Nine blueprints land: the six in-preparation F5 certifications go live with 133 verbatim objectives

      The six F5 certifications that entered the rail as in-preparation placeholders are now fully published study guides. PRIME relayed the official exam blueprint PDFs, and every objective and example bullet was transcribed verbatim - BIG-IP DNS Specialist (302) with 16 objectives mapped onto the GTM/DNS shelf, BIG-IP ASM Specialist (303) with 25 objectives mapped onto the Advanced WAF shelf, BIG-IP APM Specialist (304) with 30 objectives mapped onto the access-and-identity shelf, Security Solutions (401) with 17 and Cloud Solutions (402) with 29 objectives, and the four NGINX administrator exams (F5N1 through F5N4) with 16 objectives across management, configuration, and troubleshooting. Each guide carries the official exam facts fetched from the F5 Education Services catalog the same day: cost, time limit, passing score, delivery, and prerequisites. Where a blueprint publishes objectives without example bullets (401 and 402), the study notes stay empty by honesty, and two typos printed in the 402 source are preserved exactly as published. The certification registry now stands at 22 guides, 10 certifications, and 277 verbatim objectives.

      All certifications · BIG-IP DNS Specialist (302) · BIG-IP ASM Specialist (303) · BIG-IP APM Specialist (304)

    • Funzionalità

      The API page now teaches self-hosting: download, flip one switch, serve

      The API reference page gained the walkthrough it was missing: how to consume every tool as an API by running the toolbox yourself. The path is four steps and deliberately short - download the open-source repository, open src/config/apiSurface.ts and flip the single API_PROCESSING switch from 0 to 1, build and deploy to your own Cloudflare Workers account with the adapter already wired in, and call the endpoints now answered by your deployment on your domain. The same value drives both the Worker that serves and every badge in the interface, and it works in both directions - flip back to 0 and the surface returns to documented-but-not-served. Self-hosting plus a flip of a switch make it an API toolbox. The vendor hubs page also tightened its Red Education callout into a plain list.

      The API page · Vendor hubs

    • Contenuto

      The Zscaler ZDTA study guide arrives, six F5 certifications join the rail, and the Learn doors get their glow-up

      Three moves in one release. First: the Zscaler Digital Transformation Administrator (ZDTA) study guide is live - all forty-four scenario objectives transcribed verbatim from the official ZDTA study guide's expansive blueprint, grouped exactly as Zscaler presents them across the six weighted domains, with the official exam facts and both source documents linked. It is the site's first certification guide beyond F5. Second: six more F5 certifications enter the registry as the rail's roadmap - BIG-IP DNS (302), ASM (303), APM (304), Security Solutions (401), Cloud Solutions (402), and the four-exam NGINX administrator track - each with its official catalog page linked and an in-preparation badge until the blueprints land. Third: the Glossary and Study guides doors on the Learn index traded two long phrases for proper feature cards - type ornaments, per-card accent colors, and live count badges pulled straight from the registries.

      Zscaler ZDTA study guide · All certifications · The Learn library

    • Contenuto

      Eleven fundamentals and the F5 study guide: full coverage of the retired 101-201-301 blueprints

      A coverage audit of the four retired F5 blueprints against the article shelf found eleven true holes, and eleven rich articles now fill them in English and Portuguese: the OSI model in practice, switch-router-firewall roles, ARP and MAC addresses (gratuitous ARP and MAC masquerading included), routing tables and the default gateway, NAT, the DHCP lease lifecycle, ICMP with ping and traceroute, the TCP connection lifecycle, VPN fundamentals, and - on the F5 side - EUD hardware diagnostics and AVR analytics. With the holes closed, the BIG-IP reading path on the study guides page grew into the F5 study guide proper: sixty-three articles in teaching order spanning everything the retired 101, 201, 301A, and 301B blueprints listed, from fundamentals through administration to the LTM specialist craft, with a fourteen-tool practice bench. The vendor-neutral fundamentals are flagged in code for reuse: when reading paths arrive for the other vendors, the shared floor is already marked for cross-reference.

      The F5 study guide: BIG-IP end to end · The OSI model in practice · The TCP connection lifecycle

    • Contenuto

      Old blueprints against new: what 101, 201, 301A, and 301B taught that the modern F5 exams dropped

      Two comparison articles close the loop on the F5 certification rail. The retired blueprints - 101 Application Delivery Fundamentals, 201 TMOS Administration, and the 301A/301B LTM Specialist pair - were laid beside the current F5-CA and F5-CTS LTM blueprints, objective by objective. The verdicts differ by track: the new CA is the old 201 restructured, but it dropped the entire 101 fundamentals layer (OSI, subnetting, ARP, ICMP, TLS rationale, VPN) and 201's whole support-resources section (support tickets, EUD hardware diagnostics, the qkview-iHealth workflow, DevCentral and AskF5); the new LTM track is a faithful restructure whose entire meaningful delta is three items - serial failover, ssldump, and the roles-partitions-route-domains synthesis. Each article names what fell away, why it still matters on the job, and where this site covers it.

      From 101 and 201 to F5-CA · From 301A and 301B to the new LTM Specialist · Certifications hub

    • Contenuto

      Fourteen BIG-IP articles close every gap on the F5 study guides

      Hours after the F5-CA and F5-CTS LTM guides went live with twenty-three honest Article-coming markers, the articles arrived. Fourteen new pieces in English and Portuguese cover the ground the site had never taught: the high availability cluster (device trust, device groups, and traffic groups; failover states and operations; config sync), UCS archives, the /var/log map, management access and port lockdown, the DNS-NTP-SNMP-syslog service quartet, reading device status from LCD panel to netstat, route domains, vCMP, custom alerting, iApps and FAST templates, the interface-to-self-IP dependency chain, and the qkview-iHealth support workflow. Every one is wired into the guide objectives it teaches: both F5 certification tracks now carry zero gaps - all one hundred objectives hold study notes and at least one article on this site. The study guides page also got two touches: reading-path cards now carry their category color on the left border instead of uniform cyan, and the certification card grid that duplicated the certifications hub was retired in favor of a signpost - one canonical home.

      F5CAB4: Control Plane Administration, now gapless · BIG-IP high availability concepts · qkview and iHealth

    • Contenuto

      Fourteen BIG-IP articles close every gap on the F5 study guides

      Hours after the F5-CA and F5-CTS LTM guides went live with twenty-three honest article-coming markers, the articles arrived. Fourteen new pieces in the networking category cover the whole missing territory: the high availability cluster (device trust, device groups and traffic groups; failover states and network failover; config sync), UCS archives, the log files map, management access and port lockdown, the DNS/NTP/SNMP/syslog system services, reading device status from LCD to netstat, route domains, vCMP, custom alerting, iApps and FAST templates, the interface-to-self-IP dependency chain, and the qkview/iHealth support workflow - each written in English and Portuguese, each wired into the guide objectives it teaches. Both F5 guides now have zero gaps: all one hundred objectives across the three published certifications carry study notes and at least one article on this site.

      The F5-CA guides, now gapless · BIG-IP high availability · qkview and iHealth

    • Contenuto

      F5-CA and F5-CTS LTM study guides: eleven exams, one hundred objectives

      The certifications hub now maps both current F5 BIG-IP tracks in full, from the official blueprints PRIME relayed. The five F5 Certified Administrator exams (F5CAB1 through F5CAB5, blueprint F5-CAB.0425) and the six BIG-IP LTM Specialist beta exams (F5CTSLTM1-B through F5CTSLTM6-B, blueprint F5CTSLTM.032026.BETA, beta window open until July 31) are published with every objective transcribed verbatim, the blueprint's own example bullets serving as the What to know points, and each objective wired to the site tools and Learn articles that teach it - the licensing objective points at the Service Check Date tool, the packet-capture exams at the tcpdump pair and builder, the iRules exam at eleven iRule articles, the TLS exam at the cipher bench. Where the site has no coverage yet - UCS archives, HA and failover, vCMP, custom alerting, route domains, the log files shelf - the guide says an article is coming instead of padding.

      Certifications hub · F5CAB1: Install, Initial Configuration, and Upgrade · F5CTSLTM6-B: Packet Capture/Troubleshooting - TLS/SSL

    • Contenuto

      The knowledge beneath PingFederate: LDAP, Kerberos, SCIM, a reading path, and thirteen glossary terms

      A research pass over the PFP-001 dependency tree found the blueprint's own prerequisites uncovered: the exam assumes directory, Kerberos, and SCIM knowledge the site never taught. Three fundamentals articles fix that - the LDAP directory model behind every identity product, the ticket machinery that makes desktop SSO silent, and the provisioning standard that explains where accounts come from - each linked from the product articles and guide objectives that depend on them. A new reading path, PingFederate administration end to end, sequences the whole subject: fundamentals first, the ten product articles in teaching order, flows to close. And thirteen identity terms join the glossary - SCIM, Kerberos, SPNEGO, keytab, KDC, PCV, APC, policy tree, and friends - so the vocabulary now explains itself, underlined in place, throughout the wave.

      The reading path · LDAP fundamentals · Kerberos and SPNEGO

    • Contenuto

      PingFederate Learn wave: ten articles close every gap on the PFP-001 guide

      Hours after the Certified Professional - PingFederate study guide went live with fifteen honest article-coming markers, the articles arrived. Ten new pieces in the identity category - installation and initial setup, the upgrade playbook, the startup files tour, administrative access and RBAC, operational hygiene (license, notifications, configuration archive), the endpoints map, data stores, PCVs and the five adapters, the log files, and authentication policy trees - each written in English and Portuguese, each wired into the guide objective it teaches. The PFP-001 guide now has zero gaps: all twenty-four blueprint objectives carry study notes, at least one article on this site, and a pointer into the official documentation.

      The study guide, now gapless · Authentication policy trees · The log files

    • Contenuto

      The first fully worked study guide: Certified Professional - PingFederate (PFP-001)

      The certifications section publishes its first complete guide. Every objective of the official PFP-001 blueprint - all four sections, twenty-four objectives, transcribed verbatim from Ping Identity's published exam study guide and live catalog - now carries study notes (the facts to know cold), links to the Learn articles and tools on this site that teach it, and a pointer into the official PingFederate documentation. The guide leads with the exam facts that matter when you book it: 70 multiple-choice items, 90 minutes, a 64% pass mark, PingFederate 12 or later. Where the site does not yet have an article for an objective, the guide says so honestly and that gap seeds the writing queue. As everywhere in this section: objectives map to learning resources, never to exam questions - study guides here help you learn the material, not shortcut the exam.

      Open the study guide · Certifications hub

    • Funzionalità

      Glossary hints grow a third gear: first, all, or none

      The inline glossary hints - the dashed underlines that pop a definition on hover or tap - used to be a simple on/off. The switch in Settings is now a three-way choice: First underlines only the first mention of each term per page (the default, same behavior as before), All lights up every mention for readers who want the definition at hand wherever they meet the word, and None keeps prose completely plain. Under the hood every occurrence is now marked at build time and your choice decides which marks are active, instantly and without a reload, on Learn articles and tool docs alike. The preference stays on your device, like the theme.

      Reading settings

    • Nuovo strumento

      New tool: HTTP methods comparison - starring QUERY, the first new method in 16 years

      RFC 10008 (June 2026) gave HTTP its first new method since PATCH in 2010: QUERY, the safe, idempotent, cacheable read that carries a request body. The new tool holds the registry facts for 13 methods (the RFC 9110 nine, PATCH, and the WebDAV trio PROPFIND/REPORT/SEARCH): safe, idempotent, cacheable, body semantics, CORS safelist, HTML-form support, and the defining spec - ask for 'get vs query' or 'post vs query' and it names exactly which properties differ. Two companion Learn articles ship with it: a full QUERY explainer (why it exists, the body-in-the-cache-key model, Accept-Query discovery, the equivalent-resource escape hatch, and why 'safe' describes intent rather than payload) and the BIG-IP chapter (LTM's HTTP profile passes unknown methods by default, Advanced WAF blocks QUERY as an Illegal method until explicitly allowed and then keeps inspecting the body, iRules branching on HTTP::method need a post-June-2026 audit, and HTTP::query the command has nothing to do with QUERY the method). Glossary gains safe-method and http-query-method. All facts grounded in RFC 10008, the IANA registry, and F5's own DevCentral coverage, fetched 2026-07-20.

      HTTP methods comparison · Open the comparison · The QUERY explainer · QUERY on BIG-IP

    • Contenuto

      Glossary wave two: 58 more voices from the trenches

      The jargon and expression shelves get their second restock in two days, from 881 to 939 entries. New jargon leans into the carrier and datacenter world: looking glass, the default-free zone, full tables, carrier hotels and meet-me rooms, the middle mile, lit fiber, clean pipes, plus incast, brownouts, dark launches, tiger teams, pizza boxes, god boxes, frobnicate, and keep the lights on. New expressions bring the named wisdom: Segal's law (two watches, and the reason NTP exists), Zawinski's law, the Swiss cheese model, the XY problem, choose boring technology, security theater, compliance is not security, everything fails all the time, no plan survives contact, and the New Yorker's immortal dog who nobody knows about. Every entry defined and contextualized in English and Brazilian Portuguese, cross-linked into both waves.

      Glossary

    • Nuovo strumento

      New tool: MTU / MSS calculator, with a full jumbo frames explainer

      The queue's rank-73 resident is live. Enter a link MTU plus your encapsulation stack (vxlan, gre, pppoe, 6in4, geneve, wireguard, vlan, qinq, mpls, or +N for a measured IPsec cost) and get the inner MTU and TCP MSS for IPv4 and IPv6, the Ethernet frame sizes, the underlay MTU an overlay needs, and the wire efficiency of this MTU against the 1500 and 9000 classics. The tool's core lesson is the split most explanations blur: encapsulations spend bytes inside the MTU and shrink the inner packet, while VLAN tags and MPLS labels ride on the frame and leave the IP MTU alone (that is where 1522-byte baby giants and 9216 switch headroom come from). All constants are RFC-fixed and cross-verified; 22 golden vectors pin the classics (GRE 1476, VXLAN 1450/1550, PPPoE 1492, WireGuard 1440/1420, 94.93% vs 99.14%). Alongside it: a complete Learn explainer on jumbo frames, from the 1980 economics of the 1500-byte limit to overlay headroom, PMTUD black holes, and the ping commands that prove a 9000-byte path end to end, plus upgraded glossary entries for jumbo frames and the new baby giant.

      MTU / MSS calculator · Open the calculator · Jumbo frames, explained

    • Contenuto

      The glossary learns to talk shop: 66 new jargon and expression entries

      The two thinnest shelves of the glossary got a proper restock, from 814 to 880 entries. On the jargon side, the words engineers actually say: flapping, fat-finger, bufferbloat, microburst, elephant flows, goodput, gray failure, alarm storm, alert fatigue, tarpit, braindump, nuke and pave, magic smoke, flag day, forklift upgrade, SEV1, and friends. On the expression side, the sayings the trade lives by: it's always DNS, pcap or it didn't happen, check layer 1, fail open vs. fail closed, crunchy outside, chewy center, castle-and-moat, Schroedinger's backup, RAID is not a backup, the 3-2-1 rule, don't roll your own crypto, rough consensus and running code, the two generals problem, active-active vs. active-passive, and the demo gods. Every entry defined and given real context in English and Brazilian Portuguese, cross-linked where the ideas connect.

      Glossary

    • Contenuto

      The glossary grows past 800 entries, and terms light up inline

      Two threads land together. First, the glossary crossed from 605 to 814 entries: every acronym the site teaches now has a home, and a shelf of named vulnerabilities and backronyms joins the lore, from BEAST, POODLE, and CRIME through Heartbleed, Spectre, and Terrapin, each with a short definition and a fuller explanation in English and Brazilian Portuguese. Second, those definitions now come to you: in the Learn articles and every tool's documentation, the first mention of a term on a page carries a subtle dashed underline, and hovering or tapping it shows a quick definition without leaving the page, with a link to the full glossary entry. The underlines are first-occurrence only, so the prose stays clean, and if you would rather not see them there is an off switch under Settings, in the new Reading section.

      Glossary

    • Nuovo strumento

      BIG-IP DNS (GTM) GSLB simulator: watch a wide IP pick a pool, then a server

      The global-tier companion to the LTM load balancing simulator. BIG-IP DNS load balancing is two-tier - a wide IP first selects a pool, then the pool selects a virtual server - and this tool models both. Configure pools (each with a ratio, a region tag, an up/down state, and a member-selection method) and their members, set the wide-IP pool method, a client region, and a request count N, and see how the next N DNS name-resolution requests resolve: pool by pool, then member by member. The static methods are simulated deterministically at both tiers - Round Robin, Ratio, Global Availability (first available in list order), and Topology (highest region-match score wins, ties round-robin). The dynamic methods that need live big3d metrics - QoS, completion rate, round-trip time, fewest hops, kbps, packet rate, VS score, least connections, CPU - are explained honestly rather than faked. Grounded in F5 BIG-IP DNS documentation, with a paired Learn article in English and Brazilian Portuguese on the two-tier decision.

      BIG-IP DNS (GTM) GSLB simulator

    • Nuovo strumento

      Three passive-fingerprint explainers: p0f, User-Agent, header order

      A new trio decodes the signatures you emit before a byte of application data flows - the honest core of the privacy thesis. The p0f signature explainer decodes a v3 SYN fingerprint (ver:ittl:olen:mss:wsize,scale:olayout:quirks:pclass) into all eight fields and matches the shape to documented OS stacks; the TTL-versus-User-Agent mismatch it surfaces is the classic proxy tell. The User-Agent entropy analyzer breaks a pasted UA into its identifying tokens, estimates the distinguishing bits each contributes, and explains the Client Hints migration that froze the string. The HTTP header-order fingerprint reads a request header block and classifies the client by header sequence alone - the passive-HTTP analog of JA3, and how a Chrome UA wearing curl's header order gets caught. All three are decode-and-explain only: you paste a signature you already hold, nothing is read from your browser, nothing is sent. A paired Learn article ships in English and Brazilian Portuguese.

      p0f passive TCP/IP signature explainer · User-Agent entropy analyzer · HTTP header-order fingerprint

    • Contenuto

      The glossary grows from 353 to 605 entries

      The largest single expansion of the glossary: 252 new entries across six working fields - network engineering (VLAN, OSPF, spanning tree, VXLAN, BFD), the ISP technician's world (GPON, OTDR, optical budget, CGNAT, truck roll), IT support (ITIL, golden image, percussive maintenance, layer 8), cloud network engineering (VPC, transit gateway, cold-potato routing, egress cost), cloud security (shared responsibility, IMDS, SSRF, envelope encryption, canary tokens), and privacy - with the LGPD, the ANPD, Schrems II, and differential privacy taking their places. Two new domain filters arrive with the content: ISP & telecom and IT support. And a new shelf of thirteen sourced myths joins the lore: NAT is not a firewall, incognito is not anonymity, the padlock is not safety, deleted is not erased - each one disputed, each one cited. Every entry authored natively in English and Brazilian Portuguese.

    • Funzionalità

      The Global Cat Distribution System opens for tracking

      The /dev/fun shelf gains its fourth toy: a tracking console for the internet's most reliable logistics network - stray cats assigning themselves to humans. Enter your name, read your delivery manifest: unit, coat, temperament, delivery vector (doorstep during rain remains the classic route), and the six-step status timeline. Assignments are deterministic - the same name always receives the same cat, which is not a bug but destiny. Fully native in English and Brazilian Portuguese: o Sistema escolheu você.

    • Nuovo strumento

      Four tools: Roman numerals, the Greek alphabet, and exact time

      The Identifiers & time family grows around the Unix time converter, and Text & utilities gains an alphabet. The Roman numerals converter builds the canonical subtractive form place by place, accepts historical additive spellings like IIII with an explanation, and refuses IL with the rule it breaks. The Greek alphabet explainer transliterates both directions and carries the full 24-letter table, from μ micro to Ω ohms. The time calculator does exact duration arithmetic - and honestly refuses 'plus one month', a calendar unit with no single length. The multi-time-zone meeting planner reads one instant in every attendee's IANA zone, flags working hours and the Tokyo-joins-tomorrow date shift. Forty-two golden vectors across the four; three companion articles in English and Brazilian Portuguese.

      Roman numerals converter · Greek alphabet explainer · Time calculator · Multi-time-zone meeting planner

    • Localizzazione

      Meeting Bingo speaks seven languages

      Every meeting type on the card - all thirteen, from the video call to the marketing review - is now natively authored in English, Brazilian Portuguese, Spanish, German, Italian, French, and Dutch. Not translations: each language's own meeting liturgy, ninety-one pools and more than two thousand three hundred phrases in all. The Italian war room knows è sempre il DNS, the French one c'est toujours le DNS, the Dutch strategy meeting has its stip op de horizon, and the academic quarter-hour arrives in every language that observes it.

    • Funzionalità

      Meeting Bingo: the profession pack

      Four new meeting types join the card deck: the tax and legal review, civil works and public infrastructure, the HR meeting, and the marketing review. Each pool is authored natively in English, Brazilian Portuguese, Spanish, and German - real utterances from each language's own meeting culture, not translations - twenty-six per pool, four hundred and sixteen phrases in all. Salvo melhor juízo, vorbehaltlich der Prüfung, sin perjuicio de lo anterior: bingo.

    • Funzionalità

      Study guides: reading paths and blueprint guides, one door

      The sitemap's Study guides link now opens a real page. Five curated reading paths walk the Learn library in teaching order - BIG-IP fundamentals, modern identity from the token up, TLS from zero, HTTP told forward, and regular expressions done properly - each an ordered syllabus of articles with the tools to practice on, titles resolved live so nothing can go stale. Below them, the certification study guides render as the same cards the certifications hub uses, blueprint-mapped and honestly badged while in preparation. A new build guard keeps every path's articles and tools verified on every build, and the Learn library links across.

    • Funzionalità

      The identity category returns

      A quiet regression, found and fixed: tagging the open-standard identity tools - the JWT decoder, PKCE, OIDC, TOTP/HOTP, SAML, and JWKS explainers - for the Ping Identity hub had made every consumer treat them as vendor-specific, which erased the identity category from the tools grid, the Learn library, and the category pages, taking twenty-one standards articles with it. The registry now distinguishes vendor-owned tools from vendor-affiliated open standards, so identity is back everywhere it belongs and the hub keeps its tools. The category short-link also now lands: /category/network permanently redirects to the canonical networking page in every language.

      JWT decoder · PKCE helper · OIDC decoder · TOTP / HOTP · SAML decoder · JWKS explainer + key matcher

    • Contenuto

      The clones get their lineage

      The pre-1996 story now names both machines' ancestry precisely: the Microdigital TK-82C as a Brazilian clone of Sinclair's ZX81, and the TK90X as a clone of the ZX Spectrum 48K - the two ends of Brazil's market-reserve micro era, in one sentence. In English and Brazilian Portuguese.

    • Funzionalità

      The BOFH moves up

      On the 404 page, the Bastard Operator From Hell now delivers his ruling directly under the Guru Meditation, with the faux log of famous errors - 418 I'm a teapot, PC LOAD LETTER and friends - following below. Same cast, better billing.

    • Contenuto

      Four small doors closed

      A tidy batch: the Cipher Suite Anatomy article now closes, in all sixteen languages, by pointing at both Illustrated walkthroughs - TLS 1.2 for the long bundled names, TLS 1.3 for the short modern ones; the cipher suite decoder's references gain RFC 9846, the December 2025 revision of TLS 1.3 that obsoletes RFC 8446 with the suite form unchanged; and the pre-1996 field guide gains two entries the story had been using without defining - SLIP & PPP, the encapsulations that put a dial-up line truly on the internet, and NCSA Mosaic, the 1993 browser that gave the text-only internet a face. In English and Brazilian Portuguese, with the article line native in every locale.

      Cipher-suite decoder · Anatomia di una suite di cifratura TLS

    • Contenuto

      Curiosity and awe - the story's first teacher

      The pre-1996 narrative grows from six movements to seven, and the new one comes first: his grandmother, who crossed an ocean from Germany to Brazil, and who talked with the boy from his earliest age about the garden of her house - small insects and earthworms, flowers and weeds, tomatoes, carrots, and strawberries - and about the night sky full of stars, the vastness of the Universe, and the human consciousness there to behold it. The iPhone flash-forward also gains the dream's original shape: a bulky 386DX40, a 14-inch CRT monitor, a modem, and a phone line - the knowledge of the whole world, later made possible anywhere, in the palm of the hand. In English and Brazilian Portuguese.

    • Contenuto

      The timeline now begins in 1975

      The pre-1996 story's timeline gains its true opening beat: São Paulo, 1975 - a Brazilian father, civil engineer, grandson of Portuguese, Italian, and Arab immigrants; a German-born mother, a Bachelor of Fine Arts who came to Brazil at twelve; and a maternal grandmother who taught a boy to look at the universe and at nature with curiosity and awe. Had computers not claimed him, the scientist's way was waiting. In English and Brazilian Portuguese.

    • Contenuto

      Thanks, aandrade

      The academic-internet chapter of the pre-1996 story gains its missing character: aandrade, the account on the UNIX servers of USP - the Universidade de São Paulo - whose access, as was the custom among early-nineties enthusiasts, passed from hand to hand and quietly opened one of the first doors to the world for a whole generation of young explorers. Three decades late, the page now says thank you. In English and Brazilian Portuguese.

    • Funzionalità

      Red Education booking up top, and a slower Guru

      The Red Education page now opens with the same book-instructor-led-training block that closes it, so a visitor can act before reading, and the on-site catalog button now says what it means: see the courses taught by Rodolfo. On the 404 page the Guru Meditation alerts linger 2.5 times longer between rotations, the teapot line now wears its full protocol - HTCPCP/1.0 - with RFC 2324 linked to the IETF datatracker, the Amiga failure line escalated to a two-line critical emergency, and three of the retro lines dropped a font size for composure.

    • Contenuto

      New article: HTTP/0.9 to HTTP/3

      Five versions of the web's protocol in one telling: the 1991 one-line GET, the headers of HTTP/1.0, the persistent connections and Host header of HTTP/1.1, HTTP/2's binary multiplexing and its leftover TCP head-of-line blocking, and HTTP/3 moving the whole thing onto QUIC. Closes with the 2022 reorganization that split HTTP semantics (RFC 9110) and caching (RFC 9111) from the per-version wire syntax (RFC 9112 to 9114) - every RFC number live-verified against the IETF HTTP Working Group's own listing. In English and Brazilian Portuguese.

      HTTP/0.9 vs 1.0 vs 1.1 vs 2 vs 3: Five Versions of the Web's Protocol

    • Contenuto

      New article: TLS 1.2 vs TLS 1.3 vs DTLS vs QUIC

      One handshake family, four shapes: TLS 1.2's flexible-but-sharp workhorse, TLS 1.3's subtractions (now revised as RFC 9846, December 2025, which obsoletes RFC 8446), DTLS carrying the same guarantees over datagrams, and QUIC absorbing the TLS 1.3 handshake into the transport itself. Ends with a field guide to telling them apart on the wire and pointers to Michael Driscoll's Illustrated byte-by-byte walkthroughs of all four. In English and Brazilian Portuguese.

      TLS 1.2 vs TLS 1.3 vs DTLS vs QUIC: One Handshake Family, Four Shapes

    • Contenuto

      Reference shelves: regex and the Illustrated TLS series

      The regex tool's References grow by six notoriously good resources - regex101, RegExr, RexEgg, Regular-Expressions.info, RegexOne, and RegexLearn - and the cipher suite decoder now points at The Illustrated TLS 1.2 and TLS 1.3 Connections, the byte-by-byte annotated handshakes. The TLS 1.3 cipher suites article closes with the same Illustrated TLS 1.3 pointer in all sixteen languages, joined by the F5 TLS 1.3 vs 1.2 and hybrid key exchange articles.

      Regex toolkit · Cipher-suite decoder · Suite di cifratura di TLS 1.3: cosa è cambiato

    • Contenuto

      RCA, spelled out - and a habit adopted

      The Incident Timeline & RCA Builder now opens by teaching its own name: both the tool page and its documentation begin by expanding RCA as root cause analysis before using the acronym again, in English and Brazilian Portuguese. Behind the fix sits a standing editorial rule adopted today: this is a learning site, so every acronym gets spelled out the first time it appears on a page.

      Incident Timeline & RCA Builder

    • Contenuto

      Pre-1996: the record corrected, and a dream kept

      Three refinements from the source. The academic internet moves to 1991, where it actually happened — the university shell account over a modem — and 1993 earns its own beat: a program compiled on that shell account turned the dial-up session itself into a SLIP/PPP tunnel, and through it NCSA Mosaic opened the first glimpse of the World Wide Web. The phreaking movement gains its flash-forward: the payphone-modem dream of 1990, recognized seventeen years later in a jailbroken first-generation iPhone running community-made apps. And the Brazilian Portuguese telling of the father thread now carries the author's own ratified wording.

      Read the chapter

    • Contenuto

      Pre-1996: the father at the root

      The origin story now starts where it truly did. The ham-radio movement is reframed around Rodolfo's father — an engineer and avid amateur operator whose call sign and QSL cards were the first proof that a signal could cross the world — and the national-micros movement opens a scene earlier, with a nine-year-old watching him load a cassette program onto the family television before the watching turned into doing. The timeline beats for the 1984 TK-82C and the amateur-radio years follow suit. Authored natively in English and Brazilian Portuguese.

      Read the chapter

    • Contenuto

      Pre-1996 correction, and a vendor-hub polish

      Two fixes. The pre-1996 phreaking passage is corrected on the record: blue-boxing was not a dream but a working doorway - operator trunks seized by the network's own 2600 Hz signaling, reaching the European scene boards - and war-dialing turned up corporate PBXs that could hand out an outside line, deliberately left alone because those calls would bill a real company, unlike an operator trunk that billed no one. Only the modem-into-a-payphone scheme stayed a dream; a war-dialing entry joins the field guide. Separately, on every vendor hub the story call-out now has room to breathe between the breadcrumb and the title, and the tool and article card titles were brought down to sit under their section headings instead of towering over them.

    • Contenuto

      The pre-1996 story, told in full

      The origin chapter at /industry/history/pre-1996 is rebuilt from a flat summary into a proper telling: a dated timeline from the 1984 Microdigital TK-82C to the 1995 first role, a six-movement narrative (ham radio and QSL cards, the national micros, the bulletin-board and FidoNet years, the phreaking scene of the orelhao and the blue-box dreams, the 1993 academic internet, and the turn from hobby to trade), and a field guide of eleven era terms for readers who arrived after it - two of them, phreaking and the blue box, opening into the glossary's phone-phreaking lineage. Authored natively in English and Brazilian Portuguese.

    • Contenuto

      Wave 7: the roster completes

      Four final entries close the encyclopedia's planned roster. The access & home fleet consolidates Netgear, TP-Link, Zyxel, Asus & Askey, and Allied Telesis - the boxes everyone actually owns, the first hop of most packets on Earth. WatchGuard tells the red Firebox that turned security from a project into an object. A10 & Kemp pair the ADC challengers that kept the load-balancing leaders honest. And Datacom closes it at home: Brazil's networking manufacturer, its own gear on its own OS from Rio Grande do Sul, the existence proof that network sovereignty is buildable. The encyclopedia stands at 66 partner profiles - 16 pioneers, 15 partners, 6 contemporaries, and the wider lineage entries.

    • Contenuto

      Arista enriched, headings tamed, copy sharpened

      The Arista profile absorbs its full corporate history - Granite Systems sold to Cisco before the founders attacked their acquirer on purpose, the low-latency beachhead, the ITC years answered with software workarounds, the cloud titans, and the 800G Ethernet-for-AI fight. The career-record and history index pages stop rendering their ledes inside the h1 (a paragraph in heading clothing - reading comfort over spectacle), and the Zscaler chapter drops its site-meta framing for substance: the thesis that the perimeter would dissolve, and the exchange built to replace it.

    • Contenuto

      The protocol pioneers: DNS & BIND, HTTP & Gopher

      PRIME reopens the pioneer roster for the stories underneath every other story: DNS & BIND (the text file that collapsed, Mockapetris's 1983 delegation-and-caching design, Berkeley's reference implementation, the Kaminsky patch, the signed root, and Dyn day) and HTTP & Gopher (two futures shipped in 1991, one spring of licensing decided between them - Minnesota asked for fees, CERN gave the web away - and HTTP's forty-year arc from a one-line GET to QUIC). Pioneers now sixteen; the encyclopedia reaches 62 partner profiles.

    • Contenuto

      Pioneer wave 6: the last two pioneers - and the contemporaries arrive

      ZTE (China's other giant, and the 2018 denial-order lesson every supply-chain assessment cites) and Fluke (the meters and certifiers in every field bag, with the 2015 three-way split told straight) close the pioneer roster at fourteen. Below them a new section opens: the contemporaries - modern-era companies still writing their chapters - beginning with Nvidia (the GPU company that runs the fabric) and Ubiquiti (enterprise features at prosumer prices). The encyclopedia reaches 60 partner profiles.

    • Contenuto

      Pioneer wave 5: the web, the wavelengths, and the checkpoints

      Six more pioneer entries: NCSA (the campus lab whose Mosaic made the web visible and whose orphaned httpd patches became Apache), Ciena (the first commercial DWDM deployment and the optical layer's compounding pure-play), the Sniffer lineage as one bloodline (Network General through Dolch, Network Associates, and Arbor to NetScout), Blue Coat and Packeteer (the checkpoint companies - the proxy as a security platform and traffic shaping as a category), Cyclades, Avocent and Vertiv (the Brazilian-founded out-of-band pioneer and the physical layer of uptime, with the honorable Pouzin CYCLADES footnote), and Dell and Force10 (the direct model and the 10GbE fabric inside it). The encyclopedia reaches 56 partner profiles.

    • Contenuto

      Pioneer wave 4: the deepest roots

      Six entries join the industry pioneers, led by the heaviest page on the site: Bell Labs, Lucent and Alcatel - the transistor, information theory, Unix, and ten Nobel Prizes, spun, merged, and carried into Nokia. Alongside it: Intel and AMD as one entry (Fairchild's children and the x86 rivalry, with the AMD64 irony told straight), RAND (where Paul Baran imagined packet switching), Toshiba (the company that gave the world flash memory and the mass-market laptop), Hitachi (the industrial giant whose storage lineage runs through every SAN), and Bull (Europe's computing champion, from punch-card wars to the continent's first exascale machine).

    • Nuovo strumento

      The 100th tool closes wave A: the Snapshot Comparator

      Tool 7 of the Operations & Fieldcraft family - and the site's hundredth tool. The name is honest by construction: you declare the states, the tool gates the conclusion. Seven selections produce a tiered comparison report: baseline quality, a 14-dimension snapshot catalog with churn classes, delta-interpretation guidance with supports and weakens per dimension, validation-completeness gaps, and the continue / observe / investigate / hold-rollback-ready gate with explicit tier conditions. A from-memory baseline caps the verdict; an immediate window caps it; a rollback decision with any evidence gap keeps the rollback armed; and no change is ever labeled successful on green components alone. Thirteen snapshot vectors pin the verdict itself. Paired Learn article: Baselines Before You Need Them, closing the fieldcraft 'before' trilogy, in English and Portuguese.

      Before/After Health Snapshot Comparator

    • Nuovo strumento

      Flow Path Reasoner - the map before the troubleshooting

      Tool 11 of the Operations & Fieldcraft family, and wave A's second: the senior skill is refusing to troubleshoot until the path is understood. Seven selections build a canonical hop map - rendered as a diagram with transformation and TLS markers - plus the resolution and identity side-flows, TLS segments, address-rewrite points, evidence points, and ranked failure-domain candidates with supports and weakens. Unknowns stay visibly unknown, and the map says out loud that it is a proposed model, never discovered topology. Thirteen rule-firing snapshot vectors pin the registry, including the hop-chain construction itself. Paired Learn article: Map the Path Before You Troubleshoot, in English and Portuguese.

      Flow Path Reasoner

    • Funzionalità

      Vendor pages: the genealogy diagram grows up

      The corporate-lineage diagram now wraps node labels and notes to their boxes with dynamically sized slots, so long entries - the Ping and ForgeRock bloodlines were the worst offenders - no longer bleed across columns or vanish over borders. The Ping Identity and Zscaler pages close on retitled hub sections in the same voice as their siblings, and the vendor-hubs cards now run in chronological teaching order: F5, Extreme, Fortinet, Netskope, Ping, Zscaler.

    • Nuovo strumento

      Packet Capture Plan Builder - fieldcraft wave A opens

      Tool 6 of the Operations & Fieldcraft family. Command builders answer how to capture; this one answers WHERE, WHY, and WHAT IT WOULD MEAN: describe the path and the symptom in seven structured fields and a 35-rule original registry designs a phased capture plan - ranked points on 13 named boundaries with vendor-neutral filter templates, expected observations, an interpretation matrix with supports and weakens decided before collection, and sync/authorization discipline. It plans captures; it never ingests them. Thirteen rule-firing snapshot vectors pin the registry. Paired Learn article: Capture Points Before Packets, in English and Portuguese.

      Packet Capture Plan Builder

    • Contenuto

      Pioneer wave three: the deep bench

      Marconi, Wang Laboratories, Tandem Computers, Banyan Systems, Fujitsu, and NEC complete the pioneer shelf. Marconi carries both radio's birth and telecom's starkest bubble collapse; Banyan's StreetTalk shipped the global directory a decade before Active Directory and pairs with the Novell page; Tandem's NonStop architecture from 1976 still clears the world's card swipes as HPE NonStop; and NEC's 1977 C&C vision named the computers-and-communications convergence this whole site lives inside.

    • Funzionalità

      The WebSerial console learns to type

      Interactive terminal mode: toggle it on, click the console, and every keystroke goes to the wire the way a real terminal sends it - printables as-is, Enter as the configured line ending, Backspace as 0x7F, Tab, Esc, arrows as ANSI sequences, and Ctrl combinations as control bytes (Ctrl-C still copies when text is selected; Ctrl-V pastes straight to the device). Pagers, device menus, and password prompts now work as they should. Line mode remains the default.

    • Contenuto

      Pioneer wave two: six more giants

      3Com, Compaq, Netscape, Motorola, Unisys, and Data General join the industry lineages. 3Com completes the Ethernet story the Xerox page begins; Netscape is where SSL, JavaScript, and the cookie were invented - this site's daily subject matter; Unisys carries computing's two oldest bloodlines, the 1886 Burroughs adding machine and ENIAC's own engineers; and Data General brings the Soul of a New Machine. The distribution career chapter also widened to 2015 to 2019, spanning both the Westcon-Comstor and ScanSource years.

    • Funzionalità

      The WebSerial console grows up

      The serial console moved to its proper address, web-serial-console (a redirect waits at the old slug), and gained a real terminal feature set: free resizing from the lower-right corner, a fullscreen mode with the controls overlayed at the top of the console window, real-time logging straight to a file on disk through the File System Access API, and a two-tier scrollback - the screen renders a bounded window for speed while the full session is archived in memory, so Copy and Save always export everything since connect. The baud ladder now runs the full standard range from 1200 to 921600, a preset list adopted from the minimal webserialconsole.com reference.

    • Contenuto

      Twelve pioneer giants join the industry lineages

      Sun Microsystems, Silicon Graphics, Xerox, DEC, Nokia, Ericsson, Huawei, Siemens, Novell, Oracle, IBM, and SAP - the founders of the industry itself - each get the full lineage treatment on the Industry page: founding stories, timelines, and where every bloodline ended up, from Xerox PARC's 1973 Ethernet memo to Oracle's 2025 co-CEO handover, verified against SEC filings where the facts are recent.

    • Funzionalità

      Two pages, two jobs: the career record and the industry encyclopedia

      The vendors index and the Industry hub used to render the same three grids twice. Now each has one job: the career record (under About) tells the fourteen chapters of a career since 1996, with one pointer to the wider family tree; the Industry page is the encyclopedia - partners and pioneers as full cards, with the career reduced to a slim chronological strip whose pages carry the Rodolfo's chapter markers. Nothing moved URLs; everything gained a clear address.

    • Funzionalità

      A human sitemap, and two ambient rooms

      The footer's machine row now ends with a human-readable sitemap: every section of the site on one curated page, with the live tool count and a door to the XML version. And two new keyboard shortcuts join the set: G opens the green room and R the red room - full-screen solid-color utility screens, ambient light and night-vision respectively, any key or click to leave. Both are rebindable like every other key.

    • Funzionalità

      Rodolfo's chapter markers on every vendor timeline

      Every corporate timeline of a vendor from the career record now carries an explicit, visually marked entry for Rodolfo's own involvement - an accent edge and a small chip reading Rodolfo's chapter - so the personal connection is findable inside any company history at a glance. Seventeen markers across sixteen profiles, from Cabletron in 1996 to the Zscaler authorization in 2026, including the Juniper years on the HPE, Juniper, and Aruba lineage page and the distribution-side chapters on the McAfee, FireEye, and Trellix page.

    • Contenuto

      Ten partner lineages, the Pulse Secure chapter, and a footer with one job

      The remaining Red Education partner catalog gets the full lineage treatment: Check Point, CyberArk, Riverbed, Symantec, Avaya, Arista, Nutanix, Red Hat, Paessler, and MobileIron each carry founding stories, timelines, and genealogy on their partner pages - including CyberArk's February 2026 close into Palo Alto Networks, the largest deal in security history. Pulse Secure joins the career record as its own chapter (the Westcon distribution years), tracing the Neoteris to NetScreen to Juniper to Siris to Ivanti bloodline. The Buy Me a Coffee link moved from the footer to the contribute page, where the support pitch lives; the footer line now belongs to Red Education alone - and the Red Education page records that the two newest instructor authorizations flow through the same house.

    • Contenuto

      Ping Identity and Zscaler join the instructor portfolio

      Two vendor chapters have had their standing copy revised: the career pages, the About page and the partner and hub copy now describe each vendor consistently, and stale wording about training arrangements has been removed rather than restated. Course catalogs for the two newest vendors will appear under Training as they are scheduled; until then the 28-course portfolio remains the established platforms.

    • Funzionalità

      Fortinet Red replaces the orange dot

      Fortinet's vendor color across the site - the hub-strip dot, vendor cards, filter chips, and the admin chip and tag tints - is now Fortinet Red, PMS 485C (#DA291C), the official brand red from Fortinet's own brand guidelines, replacing the interim orange of 2026-07-08. Chip text uses a lightened tint of the same red for dark-canvas legibility. The FortiGate-inspired theme set is deliberately untouched: those seven palettes are homages to FortiOS's own GUI themes (Penumbra's amber nods to Eclipse; Kevlar already carries the set's red), not vendor identity marks.

    • Nuovo strumento

      JA3 / JA3N passive TLS fingerprint

      A passive TLS client fingerprint calculator, and the on-ramp toward the SSE and identity hubs (tagged, like the JA4 decoder, to the Zscaler and Ping vendors). Paste a JA3 string - the five ClientHello fields (TLS version, ciphers, extensions, elliptic curves, point formats) - and it recomputes the JA3 MD5, computes the permutation-stable JA3N (extensions sorted), decodes each field with counts, and flags GREASE values (RFC 8701), which it strips before hashing. It marks whether the extensions were in order (the source of Chrome/Firefox JA3 churn) and explains why JA3N or JA4 is more stable. Follows Salesforce's original construction exactly and is pinned to two of Salesforce's own published string-to-hash vectors; the GREASE-invariance and JA3N-stability tests reproduce the canonical hash from grease-injected and permuted inputs. Reuses the existing browser MD5 helper - no new crypto. Vectors 16/16, en + pt-BR, with a companion Learn article on passive TLS fingerprinting that bridges to secure web gateways and adaptive authentication.

      JA3 / JA3N passive TLS fingerprint

    • Nuovo strumento

      BIG-IP LTM load balancing simulator

      The BIG-IP counterpart to the F5XC LB algorithm chooser, and the answer to "where do the next N requests go?" Configure pool members - each with a member ratio, a node and node ratio, a priority group, and existing persistence records - pick a load balancing method and a request count, and see the per-member distribution with active/standby marking. It simulates the deterministic methods: Round Robin, Ratio (member and node), Least Connections (member and node), Weighted Least Connections, and Least Sessions (which uses the persistence-record count as its metric). Ratio is handled as a true weighted round-robin cycle (3:2:1:1 over 7 requests = exactly 3,2,1,1), and priority group activation confines traffic to the highest group until it falls below the minimum-available threshold. The dynamic methods - Fastest, Observed, Predictive, Dynamic Ratio - are offered but explained rather than faked, because they decide from live runtime metrics that are not part of a pool's configuration. Two honesty notes surface in the tool: Least Connections is modeled from a fresh connection table (no current-connection input) so it starts even, and Least Sessions falls back to Round Robin under cookie persistence. Vectors 17/17, en + pt-BR, with a companion Learn article. Grounded in F5 LTM documentation.

      BIG-IP LTM load balancing simulator

    • Nuovo strumento

      F5XC API path explainer

      A wave-3 tool built around the artifact XC API Protection actually works with: the OpenAPI / Swagger spec. Paste an OpenAPI 2.0 or 3.0.x specification - the kind you import to define an API definition, or the one API Discovery generates and lets you download - and it lists every path and operation with its method, parameters (name, location, required), request body content types, response codes, and effective authentication. It resolves local $ref parameters, summarizes the inventory (paths, operations, unauthenticated, object-level, deprecated), lists the defined security schemes, and flags unauthenticated operations (Broken Authentication) and object-level path-parameter endpoints (Broken Object Level Authorization). Authentication is resolved the way the spec defines it: per-operation security overrides the global default, and an empty security list is an explicit public opt-out. Grounded in the OpenAPI standard and the OWASP API Security Top 10; vectors 22/22, en + pt-BR, with a companion Learn article on the spec as XC's API inventory.

      F5XC API path explainer

    • Nuovo strumento

      F5XC object linter

      The first F5 Distributed Cloud wave-3 tool. Paste an origin_pool, http_loadbalancer, or app_firewall (WAF) object and it flags risky or surprising settings, each with a severity (high / warn / info, most serious first) and a grounded explanation. Origin-pool rules: TLS to origin with server verification skipped, SNI disabled, cleartext to origin, no health check, single origin. Load-balancer rules: no WAF attached, plain-HTTP listener, HTTPS without an HTTP-to-HTTPS redirect, a route that disables the WAF, a catch-all route that shadows later routes under first-match, and a wildcard mixed with its apex. WAF rules: monitoring mode (detects but does not block), disabled threat campaigns. It reuses schema knowledge already verified for this family and introduces no new schema; findings are structured codes + params so the compute stays language-free. Vectors 25/25, en + pt-BR, with a companion Learn article on config hazards.

      F5XC object linter

    • Nuovo strumento

      F5XC security event explainer

      The third and final F5 Distributed Cloud wave-2 tool, and the piece that turns the service-policy explainer into a triage set. Paste a security event - WAF, Bot Defense, Service Policy, or API - and it decodes the type (from sec_event_type), the action taken and the recommended action, a plain disposition (blocked / reported / allowed), the request context (method, host, path, source IP, load balancer and type, namespace, request id), and the specific reason it fired: WAF signatures (id, name, accuracy, attack type) and violations and attack types, the bot verdict (insight, automation type, recommendation), the matched service policy and rule, or the API OpenAPI validation and policy hits. It reads through the Sekoia-style { message } log envelope and infers the type when the tag is absent. Field names verified against F5's Security Events Reference (2026-07-01); defensive decode, vectors 25/25, en + pt-BR, with a companion Learn article on reading events.

      F5XC security event explainer

    • Nuovo strumento

      F5XC domain / SNI match resolver

      Wave-2 tool number two. Paste the domain lists of one or more F5XC HTTP load balancers and a test hostname, and it resolves which load balancer and domain entry wins. XC picks the most specific match among load balancers sharing an advertise policy (IP + port) - an exact FQDN beats a wildcard - and the hostname comes from SNI on HTTPS or the Host header on HTTP. It shows wildcard vs apex semantics (a wildcard is a suffix match that does not cover the apex, and a wildcard cert covers a single label), names the runner-up, and flags the hazards: the wildcard+apex auto-cert conflict, duplicate exact domains, more than one Default LB per advertise policy, ambiguous ties, and multi-label wildcard-cert mismatches. Structured warning codes keep the compute language-free; vectors 18/18, en + pt-BR, with a companion Learn article on listener logic.

      F5XC domain / SNI match resolver

    • Nuovo strumento

      F5XC origin pool explainer

      The first F5 Distributed Cloud wave-2 tool. Paste an origin_pool spec and it decodes every origin server's type and address (public IP/DNS, IP/DNS on given sites with a site locator, K8s, Consul, virtual-network, custom endpoint) and labels, the pool port (explicit / same-as-endpoint / automatic - 443 with TLS, else 80), the load-balancing algorithm and endpoint selection, health-check references, and the TLS-to-origin block: security level (reusing the TLS security-level mapper's data, so High is min TLS 1.2), SNI mode, server verification, and mTLS - with a warning when origin-server verification is skipped. It also notes that weights and priorities are not on the servers; they live on the pool reference in a route. Defensive decode, vectors 28/28, en + pt-BR, with a companion Learn article.

      F5XC origin pool explainer

    • Nuovo strumento

      F5XC load-balancing algorithm chooser

      The fifth and final F5 Distributed Cloud wave-1 tool. A short questionnaire (does the session need to stick? by source IP, cookie, or a custom header? is the pool dynamic?) recommends an XC origin-pool algorithm - Round Robin, Least Active Request, Random, Source IP Stickiness, Cookie Based Stickiness, Ring Hash, or Load Balancer Override - with the BIG-IP equivalent, the caveats that fit the answers, and where to set it. It teaches the XC model that trips up BIG-IP people: the consistent-hashing algorithms ARE the persistence method, there is no separate persistence profile, and the non-hash algorithms do not persist. Grounded in F5's Create HTTP LB guide and the DevCentral Ring Hash and persistence articles. Vectors 13/13, en + pt-BR, with a companion Learn article. Wave 1 complete.

      F5XC load-balancing algorithm chooser

    • Nuovo strumento

      F5XC HTTP LB route explainer

      The fourth F5 Distributed Cloud wave tool. Paste an http_loadbalancer spec (or just its routes array) and each route is decoded in evaluation order: type (simple / redirect / direct-response / custom), the match (HTTP method, path as prefix / exact / regex, header and query conditions), the action (origin pools with weights, redirect target, or direct-response code), path rewrites and request/response header mutations, host-rewrite override, and the per-route WAF attachment (inherit / app firewall / disabled). A first-match simulator predicts which route a test method + path would hit, and the tool warns when a catch-all route shadows more specific routes below it - because XC evaluates routes first-match, top to bottom. Defensive decode: it renders recognized keys and flags the rest. Vectors 23/23, en + pt-BR, with a companion Learn article.

      F5XC HTTP LB route explainer

    • Nuovo strumento

      F5XC CE egress checklist & verifier

      The third F5 Distributed Cloud wave tool, built to never rot. Paste F5's published Customer Edge IP/domain reference file and it parses it into a purpose-organized, site-type-filtered allowlist (registration, Regional Edge connectivity, F5 domains, reputation/classification feeds, container registries, DNS, NTP), plus the port/protocol matrix, optional site-to-site rules (SMG, DC-CG, multi-node, Cloud Connect), a copyable firewall-request text, and a curl-host verification script. It parses what you paste rather than shipping a hardcoded list, and always shows a provenance line. The port matrix and SMG/DC-CG rules are transcribed from F5's CE firewall reference. Vectors 24/24, en + pt-BR, with a companion Learn article on the CE registration flow.

      F5XC CE egress checklist & verifier

    • Nuovo strumento

      F5XC TLS security-level cipher mapper

      The second F5 Distributed Cloud wave tool. Pick a TLS security level (High, Medium, Low) to see its exact min/max TLS versions and full cipher list - each suite annotated with key exchange, forward secrecy, and strength - or paste a cipher suite (IANA or OpenSSL form) or a whole scanner line to see which levels include it. The cipher table is transcribed verbatim from F5's TLS Reference: Default is the High level (min TLS 1.2), Medium and Low are min TLS 1.0, all max TLS 1.3, and the lists are cumulative. It answers the two field questions by name: why a scanner reports TLS 1.0/1.1 (Medium/Low, K000148226) and why it flags weak ciphers (Low's static-RSA suites, K000148079). Vectors 12/12, en + pt-BR, with a companion Learn article.

      F5XC TLS security-level cipher mapper

    • Nuovo strumento

      F5XC rate-limit calculator

      The first tool of the F5 Distributed Cloud wave: enter a rate-limiter configuration (Number, Per Period, Periods, Burst Multiplier, Mitigation) and see its effective rate with per-second/minute/hour equivalents (reproducing F5's own equivalence math where [1, Seconds, 60] equals [1, Minutes, 1]), the burst ceiling, and the exact leaky-bucket behavior: when 429s start, why Mitigation Disabled is not a bypass, how a Block lockout holds until its timer expires, and the distributed-counting overshoot caveat. Grounded in F5 documentation and KBs (K000161473, K000146642, K000157944), computed in the browser, with a companion Learn article.

      F5XC rate-limit calculator

    • Nuovo strumento

      VOSS / EXOS command translator

      A reference translator lays common fabric tasks side by side in VOSS (Fabric Connect / SPBM) and EXOS, and is explicit where EXOS has no equivalent, because EXOS does not run SPBM: it joins a fabric as a Fabric Attach edge and the VOSS FA Server provisions the I-SID. Search the mapping table by task or command fragment. Grounded in Extreme VOSS and EXOS documentation, and deliberately a reference rather than a config generator. It completes the VOSS series alongside the five VOSS Learn articles.

      VOSS / EXOS command translator

    • Nuovo strumento

      VOSS fabric identifier decoder

      A new tool decodes an Extreme SPBM / Fabric Connect identifier, auto-detecting by shape: a 24-bit I-SID (with range validation and a note for the Fabric Attach network I-SID 16777001), a 20-bit nickname in X.XX.XX form converted to and from its integer value, or a system-id / B-MAC with its universal/local and individual/group bits read from the first octet. Grounded in Extreme VOSS documentation and computed entirely in the browser. It ships with a companion Learn article on the I-SID and Layer 2 / Layer 3 VSNs, the first of a VOSS series.

      VOSS fabric identifier decoder

    • Nuovo strumento

      OUI / MAC vendor lookup

      A new tool resolves the manufacturer behind a MAC address from the IEEE MA-L (OUI) registry, embedded as a point-in-time snapshot of roughly 40,000 assignments, and reads the two significant bits of the first octet: unicast versus multicast, and universally versus locally administered. It accepts colon, hyphen, Cisco dotted, and unseparated forms, and a bare OUI, and reports a locally administered or randomized address honestly as having no vendor rather than inventing one. The snapshot lazy-loads on the first lookup, so nothing leaves the browser.

      OUI / MAC vendor lookup

    • Nuovo strumento

      JA4 / JA3 TLS fingerprint decoder

      A new tool decodes a JA4 TLS client fingerprint into its transport, TLS version, SNI, cipher and extension counts, and ALPN, or computes the hashed JA4 from raw ClientHello values. It also handles JA3, the predecessor, computing its MD5 and breaking out its fields. Both JA4 and JA3 are BSD 3-Clause; the hash sections are shown as one-way, and GREASE is filtered. Verified byte-exact against the FoxIO and Salesforce specifications, and everything runs in the browser.

      JA4 / JA3 TLS fingerprint decoder

    • Funzionalità

      The Glossary went live

      A new Glossary launched at /glossary: 151 entries covering the field's terms, acronyms, expressions, jargon, and lore, each defined in English and Brazilian Portuguese and filterable by domain, kind, and free-text search. Lore entries are fact-checked and cite primary sources, and many terms link straight to the tool that computes them.

      Open the Glossary

    • Funzionalità

      Press "." for what this page can do

      A new page-context panel puts each page's special actions one keystroke away. Press the period key anywhere (outside a text field) and a panel lists what the current page offers. On any tool page it opens that tool's full documentation - the man page - inline, without leaving the page. On a vendor hub it shows a hub map that jumps straight to any tool-family section. On the Mega Brain screen it explains what each of its controls does. Pages that have nothing special to offer leave the key alone, so it never gets in the way. Escape or a click outside closes the panel.

      Try it on the F5 hub

    • Nuovo strumento

      The Operations & Fieldcraft cluster completes: three tools ship together

      The fieldcraft family reaches its full five, with three siblings shipped in one batch on the shared foundation the Fault Hypothesis Builder pilot established. The Incident Timeline & RCA Builder orders an incident's events, derives the milestone spans, and structures candidate contributing factors with the evidence that would confirm or rule out each - and it never names a root cause: a factor is echoed confirmed only when you mark it, always attributed to you, an invariant checked by the build itself. The Change Blast-Radius Mapper maps a change as concentric tiers (target, co-located, downstream, human) populated with what could be affected, plus severity-tagged risks and containment measures; it maps what could be affected, never asserts what will break. The TAC Escalation Packet Builder assembles a complete vendor-support packet and a checklist of the artifacts still to collect before opening the case, dropping what you already have; it structures the hand-off, it does not open a case. All three run entirely in the browser, each verified by rule-firing snapshot vectors (twelve, eleven, and twelve), each with a Why-panel and a one-click Markdown export. That is thirty-five vectors across three tools, and four tools now sharing one foundation with no changes to it.

      Incident Timeline & RCA Builder · Change Blast-Radius Mapper · TAC Escalation Packet Builder · Root Cause Is a Verb, Not a Noun · Blast-Radius Thinking Before You Change Anything · TAC Cases That Get Triaged Fast · Incident Timeline & RCA Builder · Change Blast-Radius Mapper · TAC Escalation Packet Builder

    • Nuovo strumento

      Change Window Runbook Builder: the fieldcraft cluster's second tool

      The Operations & Fieldcraft family gains its second member, built on the shared foundation the Fault Hypothesis Builder pilot established. Describe a planned change through six structured fields - change type, environment, blast radius, reversibility, the window, and the safeguards already in place - and a fixed, original 22-rule registry assembles an ordered runbook across six phases: pre-flight, approvals and comms, execution, verification, rollback triggers and back-out, and close-out. It surfaces the risks the plan carries (a one-way change, a broad blast radius, a business-hours window on a critical system) and readiness cautions about the input itself (no backup marked, rollback untested, monitoring not ready). Five domain presets flavor the commands. It structures and sequences, it never approves or executes: the runbook is a proposal to review and adapt, with a Why-panel exposing every fired rule, and a one-click Markdown export for the change ticket. Verified by rule-firing snapshot vectors, the same model the pilot set.

      Change Window Runbook Builder · Change Windows That Do Not Become Incidents · Change Window Runbook Builder

    • Funzionalità

      Collapsible navigation, and the rooms become categories

      Two index-page navigators are now tidier. The "Jump to" section list is collapsed by default behind a single header you can expand - a native disclosure that needs no JavaScript and works from the keyboard - on the tools and Learn indexes, the vendor hubs, and the boss-screens viewer. The "Show" filter keeps All and None always visible, with the per-category chips tucked behind a small expander so the common actions stay one click away and the granular ones are there when you want them. And on the tools index, the green room and the red room are no longer quiet footnotes: each is now its own category section with a single explainer card, tinted in that room's own color, leading to its index.

      Tools · The green room · The red room

    • Nuovo strumento

      The green room opens: four tools off the catalogue

      The residual room at /dev/other now has residents - tools whose shapes the catalogue cannot hold yet, for reasons other than reaching the network. A PCAP analyzer reads a capture file entirely in your browser (nothing uploaded) and reports an L2-L4 summary, conversations, top talkers, and anomaly flags. A WebSerial console turns a Chromium browser into a serial terminal for console cables. A self-fingerprint inspector shows the browser and device signals a tracker could read, computed only for you. And a subnetting drill trainer generates randomized CIDR practice with a streak your browser remembers, reusing the site's own CIDR engine for the math. Each states on its own page why it lives off the catalogue.

      The green room

    • Funzionalità

      List view rebuilt in catalogue anatomy

      The list mode on the tools and Learn indexes is no longer a flattened card: it is now a proper catalogue table per section - tool, badges, posture, and standards anchors for tools; article, topic, and summary for Learn - in the same anatomy as the internal build catalogue. Cards remain the default; the toggle and its remembered preference are unchanged.

      Tools · Learn

    • Nuovo strumento

      ASN lookup joins the red room

      The second /dev/out resident. Type an AS number and the deterministic layers answer what they can before any egress: special-purpose ASNs (AS0, AS112, AS_TRANS, documentation and private ranges, the reserved ends) are explained locally with their RFC and never leave the browser, bootstrap gaps are reported as unallocated, and real numbers are fetched browser-direct from the owning RIR on an explicit Ask - including following NIR redirects honestly (Brazilian ASNs answer from Registro.br) and naming who actually answered. RIPE-region numbers fail honestly with the exact curl to run instead.

      ASN lookup · /dev/out

    • Funzionalità

      The developer wing completes its color triad: /dev/out in red

      Network-egress tools now live in /dev/out, the red room, which inherits the explicit-egress rules and the RDAP lookup; /dev/other, the green room, is reserved for tools whose shapes the catalogue cannot hold yet, for reasons other than egress. Blue mothership, green for the odd shapes, red for the room where packets leave. Old RDAP links redirect.

      /dev/out · /dev/other · RDAP lookup

    • Nuovo strumento

      Operations & Fieldcraft opens with the Fault Hypothesis Builder

      A new tool family for operational judgment, piloted end-to-end per D-86. Describe a fault in six structured fields and 25 deterministic rules rank hypotheses to test across 13 fault domains, each with evidence to collect and the signals that would support or weaken it, plus an exportable Markdown worksheet. It structures, it never diagnoses; the verification model is rule-firing snapshot vectors, pinned in CI. A paired method article covers hypothesis-driven fault isolation, and four follow-on fieldcraft tools are admitted to the queue pending the post-pilot review.

      Fault Hypothesis Builder · The First Hour: Hypothesis-Driven Fault Isolation

    • Funzionalità

      The developer wing gets an index, and a green room opens: /dev, /dev/fun, /dev/other

      /dev-fun moved to its canonical home at /dev/fun (old URLs 301), a small /dev index now fronts the wing, and a new room opened: /dev/other, for tools that ask the live internet instead of computing locally. The room is marked by a deep-green background (the site palette hue-rotated, same darkness) and a visible notice stating exactly how it differs: input leaves the browser only when you press Ask, it goes browser-direct to the official registry (never to ronutz.com servers), and live answers carry no golden-vector guarantee. First resident: RDAP lookup, WHOIS the modern way — domain, IP, or AS number routed deterministically via vendored IANA bootstrap snapshots (RFC 9224), with the registry named before anything is sent, 15 golden vectors on the deterministic layers, and honest curl fallbacks where registries do not allow browser queries. The tools index gained a green door after the last tool.

      /dev · /dev/other · RDAP lookup

    • Nuovo strumento

      BigD calculator learns the platform-to-hyperthreading map

      Type the platform instead of guessing the formula: per F5's own platform documentation, rSeries splits down the middle (r5000/r10000/r12000 hyperthreaded, two vCPUs per core; r2000/r4000 physical cores only), VELOS tenants run on hyperthreads (HT-Split per K15003), iSeries and VIPRION count hyperthreads in F5's sizing language but cannot run 21.x (shown as context with that caveat), and Virtual Edition depends on the host (check lscpu). "8 r10900" now selects the hyperthreaded formula, "16 r4800" the normal one; an explicit ht/normal word still overrides the platform default. Golden vectors grew from 13 to 23; the platform map is sourced from the rSeries/VELOS clouddocs pages and K15003, fetched 2026-07-08.

      BigD thread calculator · Open the calculator · The 21.x ops story

    • Contenuto

      Five Learn articles complete the BIG-IP 21.x pack

      The 21.x series is now whole. New today, en + pt-BR: the ops story (in-place upgrade with Dry Run and its two honest limits, the 64-bit control plane, the OOM ladder, MCPD worker threads, iControl REST rate limits, UCS platform-migrate validate); WAF over QUIC (HTTP/3 protection with its four stated limits, OpenAPI 3.1, Splunk key-value Extended); DNS as a policy engine (multi-RPZ: 65,535 zones, precedence, TSIG HMAC-SHA-512, the full action set, per-FQDN walled gardens); F5OS 2.0 from the tenant's seat (cloud-init with DO/AS3, per-port UDP RRDAG fine print, Q-in-Q on VELOS); and access & identity (RFC 7591 DCR, native system-browser SAML, Access IPsec constraints, ES13, ARM64). Grounded verbatim in F5's 21.1.0 and 21.0.0 release notes, the 21.1 GA announcement, and K4309 / K60235402 / K86001294, fetched 2026-07-08.

      The 21.x ops story · WAF over QUIC · Multi-RPZ · F5OS 2.0 · Access & identity

    • Nuovo strumento

      New tool: BigD thread calculator

      BIG-IP 21.1 rebuilt bigd as a multi-threaded single instance serving up to 15,000 control-plane monitors, and documented the automatic thread count: (vCPUs × 6) ÷ 10 on hyperthreaded systems, (vCPUs ÷ 2) − 1 on normal ones, with bigd.numprocs as a manual override capped at the vCPU count (0 = automatic). The calculator encodes both formulas verbatim, shows the exact value and its whole-thread floor when the arithmetic lands on a fraction (F5 states no rounding rule, so the tool says so instead of guessing), and surfaces the override cap and the monitor ceiling. 13 golden vectors; formulas re-verified against F5 techdocs 21.1.0 on 2026-07-08. Pairs with the new ops article.

      BigD thread calculator · Open the calculator · The 21.x ops story

    • Funzionalità

      List view for the Tools and Learn indexes and the vendor hubs

      Both indexes and the four vendor hubs now offer two densities. Cards remains the default; the new List view re-flows the very same entries into compact catalogue-style rows, name, a one-line summary, and the category and vendor chips, for fast scanning of a long index. The choice sits next to the category filter, is remembered on your device (per index, and once for all hubs), and needs no page reload; with JavaScript off the pages simply stay on cards. Also in this update: the Fortinet dot on the vendor hub strip and chips is now orange, keeping it clearly distinct from F5's red at dot size.

      Tools · Learn

    • Contenuto

      Two BIG-IP 21.x deep-dives: AI/MCP, and post-quantum TLS

      The two marquee themes of the 21.x line, each in full. AI Traffic on BIG-IP walks MCP from the 21.0 foundation (HTTP, JSON, and SSE profiles, iRule-based session pinning, S3 integrations for AI workloads) to 21.1's native aimcp persistence profile, where TMM hands the client a wrapped and encrypted Mcp-Session-ID, and the Advanced WAF MCP Protection Policy template aimed at the OWASP MCP Top 10, with the caveat that matters: SSE streaming responses bypass response-side inspection. Post-Quantum TLS traces the ML-KEM hybrid lineage from X25519MLKEM768 in the 17.5 era to 21.1's SecP256r1MLKEM768 and SecP384r1MLKEM1024 on both client and server side per FIPS 203, plus X25519 hardware acceleration via Intel QAT on by default, TLS 1.3 and DTLS 1.2 parent-profile defaults, the OCSP nonce, C3D enhancements, and a rollout plan that breaks no legacy client. In English and Portuguese, verified against F5's release notes, manuals, and launch announcements.

      AI and MCP · Post-quantum TLS

    • Contenuto

      New Learn article: the BIG-IP DNS request processing order

      One query, six answering machines: what actually answers a DNS query arriving at a BIG-IP listener, in F5's documented precedence, iRules first, then DNSSEC processing, the GSLB wide IP match, DNS Express, the DNS cache, the local BIND server, and finally an LTM pool, with the self-IP port 53 edge case at the very end. Covers the responders-versus-resolvers split, the Unhandled Query Action choices, the three DNS cache types, F5's pool-over-BIND recommendation, and the Rapid Response mode that silently removes BIND from the line. In English and Portuguese, grounded in F5 K14510 and K28650431, the BIG-IP DNS Services manual, and K13850558.

      Read it

    • Nuovo strumento

      New tool: curl command builder

      Pick any of the 27 protocols curl speaks, from HTTPS and SFTP to MQTT, IMAP, and DICT, fill in protocol-aware fields, and get the exact command assembled in one canonical flag order with every flag explained. Per-protocol explainer panels show what each protocol is, its default port, and its TLS posture. Warns on -k, on cleartext protocols, on passwords placed on the command line, and on curl's form-encoded -d default. The inverse of the HTTP request translator. Local and offline; nothing is executed.

      curl command builder

    • Nuovo strumento

      F5 release cadence calendar

      On 6 July 2026 F5 moved from a quarterly to a monthly security release cadence: hardened software releases on the third Wednesday of every month starting 15 July, and security notifications one month later starting 19 August (covering the July release). This tool turns that schedule into concrete dates. Pick a start date, which defaults to today, and it lists the upcoming hardened releases and security notifications and tells you the next of each. Because F5's own anchor dates line up to third Wednesdays, each third Wednesday carries both that month's release and the previous month's notification, and the tool makes that plannable in advance. Verified against F5's two published anchors; local date arithmetic, nothing leaves the browser. Ships with a companion Learn article explaining exactly what changed, why F5 says it changed, what stays the same, and what it means for how you patch.

      F5 release cadence calendar · La cadenza di rilascio più rapida di F5: release rafforzate e notifiche di sicurezza mensili

    • Contenuto

      BIG-IP 21.x: the flagship overview

      Why TMOS jumped from 17.x straight to 21, what 21.0.0 and 21.1.0 actually deliver (MCP-aware AI traffic, post-quantum TLS, in-place upgrade, 64-bit control plane, HTTP/3 WAF, multi-RPZ), and the platform and lifecycle rules to check first. First piece of the BIG-IP 21.x pack; deep dives follow.

      BIG-IP 21.x: what changed, and why there is no version 18, 19, or 20

    • Nuovo strumento

      iRules performance linter

      Paste an iRule and it flags a small, high-confidence set of anti-patterns straight from F5's own documentation, line by line. The flagship finding is the global-namespace variable ($::x, set ::x, the global keyword): F5's validator catches it from v10 and demotes the virtual server to a single TMM instance (CMP demotion), globals have been deprecated since v10, and the old $::datagroup form raises a runtime error and resets the client on v11 and later. It also warns on unbraced expr (which the bytecode compiler cannot optimize) and notes deprecated matchclass/findclass and costly regexp/regsub. It deliberately does not cry wolf: static::, class match, braced expr, and persistence/tables/session (all CMP-safe on modern versions) pass clean, and comments are skipped. Each finding carries a severity, the offending token, why it matters, and the fix. Ships with a companion Learn article on CMP and the static:: namespace, and points at the runtime calculator for real measurement. Local scan; nothing leaves the browser.

      iRules performance linter · iRules, CMP, and the static:: namespace

    • Nuovo strumento

      iRules runtime calculator

      A browser version of DevCentral's long-standing iRules Runtime Calculator spreadsheet. Paste the timing statistics from tmsh show ltm rule, give it your platform's clock speed and core count, and it converts CPU cycles into real runtime: the average microseconds each event costs, the total cycles per request, the CPU percentage a single request consumes, and the maximum requests per second the rule can sustain, both across all cores and demoted to a single core. It reads the Cycles (min, avg, max) output, uses the average and discards the compile-inflated maximum exactly as F5 advises, and reproduces F5's own published worked example to the digit. Ships with a companion Learn article on how iRules execute (a Tcl interpreter compiling to bytecode inside TMM), what timing measures, and why average is the number that matters. Local arithmetic; nothing leaves the browser.

      iRules runtime calculator · iRules performance: cycles, timing, and the runtime calculator

    • Contenuto

      Vendor ACME companions: BIG-IP and FortiGate

      Two vendor Learn articles on certificate automation. The F5 BIG-IP article covers the native ACMEv2 client added in BIG-IP 21.1.0, which handles provisioning, renewal, and deployment for any ACMEv2 CA (Let's Encrypt, ZeroSSL, DigiCert, Buypass, Google Trust Services, SSL.com) through Certificate Order Management, alongside the dehydrated-based DevCentral solutions that preceded it, BIG-IQ's centralized Let's Encrypt CA management profile, and Ansible-driven issuance. The FortiGate article covers FortiOS's built-in ACME client for the appliance's own management certificate: its public-IP and FQDN requirements, the single-name SAN constraint (no wildcards, no multiple SANs), and the TLS-ALPN-01 and HTTP-01 challenges by FortiOS version. Both link the certificate cluster (rate-limit planner, x509 decoder, renewal planner, dns-01) and contrast the two native clients. Every vendor claim was checked against the vendor's own documentation, including F5's 21.1.0 release notes and Fortinet's per-version admin guides. English and Portuguese, other locales served by English fallback.

      ACME on BIG-IP: from DevCentral scripts to a native client · ACME on FortiGate: a built-in client for the box's own certificate

    • Nuovo strumento

      Let's Encrypt rate-limit planner

      Paste the hostnames you plan to certify and see how they map onto Let's Encrypt's limits. It groups names by registered domain (eTLD+1) using the Public Suffix List, shows the fewest certificates you need by packing up to 100 names each, points out where a wildcard would collapse subdomains, and warns if issuing one certificate per name would exceed the 50-per-registered-domain-per-week limit. The concrete limits are shown with their snapshot date and source link, and it notes that ARI-coordinated renewals are exempt from all limits. Builds directly on the registered-domain resolver; runs entirely locally.

      Let's Encrypt rate-limit planner · ACME: how certificates issue and renew themselves

    • Nuovo strumento

      Registered domain (eTLD+1) resolver

      Find the public suffix and registered domain for any hostname. Paste a name and it returns the eTLD (e.g. co.uk), the registered domain (e.g. example.co.uk), the subdomain, and which section of the Public Suffix List decided it. It implements the full PSL algorithm, including wildcard and exception rules, and when a PRIVATE-section rule wins (like github.io) it also shows the ICANN-only view. This is the exact boundary certificate rate limits, cookies, and same-site checks rely on. Runs locally against a bundled, dated snapshot of the list; verified against the PSL algorithm test vectors. Ships with a companion article on public suffixes and eTLD+1.

      Registered domain (eTLD+1) resolver

    • Nuovo strumento

      ACME dns-01 TXT computer

      Compute the TXT record that passes an ACME dns-01 challenge. Paste the challenge token and your ACME account key (a public JWK, or its thumbprint) and it returns the _acme-challenge record name, the value to publish, and the key authorization and RFC 7638 thumbprint it was derived from. Only the key's public members are used and the key is never echoed; the SHA-256 runs locally via Web Crypto, verified against the RFC 7638 known-answer test. Ships with a new ACME protocol article explaining the whole issuance flow.

      ACME dns-01 TXT computer · ACME: how certificates issue and renew themselves

    • Nuovo strumento

      ExtremeXOS config explainer

      Paste an ExtremeXOS (EXOS / Switch Engine) configuration and it explains each command in plain English, summarizes the VLANs with their tags and tagged/untagged ports and IP addresses, and groups the commands by category. First Extreme Networks tool, so the Extreme hub is now live.

      EXOS (Switch Engine) config explainer · How an ExtremeXOS Config Is Structured

    • Nuovo strumento

      PAC file explainer and validator

      Paste a Proxy Auto-Config file and it reads back the proxy directives it returns, the helper functions it uses (with the DNS-consulting ones flagged), structural and correctness lints, and whether it is a Netskope Cloud Explicit Proxy steering file. It never evaluates the file. First Netskope tool, so the Netskope hub is now live.

      PAC file explainer + validator · How a PAC File Chooses a Proxy

    • Nuovo strumento

      FortiOS packet sniffer builder

      Build a FortiGate diagnose sniffer packet command from parts, or paste one to have every argument explained: interface, filter, verbosity 1-6, count, and timestamp format, with the common traps flagged. First Fortinet tool, so the Fortinet hub is now live.

      FortiOS packet sniffer builder · Reading a FortiGate Packet Sniffer Trace

    • Funzionalità

      Two more Boss-Key Screens: MS-DOS Defrag and Copy II PC

      The Boss-Key Screen gallery gains two animated DOS disk utilities: the MS-DOS 6 defragmenter with its cyan block map, and Central Point's Copy II PC copying a floppy track by track. Both animate with CSS only and respect reduced-motion.

      Boss-screens gallery

    • Funzionalità

      Disclaimer and limitation-of-liability page

      A new plain-language disclaimer sets out that everything on the site is provided as is, built from public information, for use at your own risk, with no warranty and no liability, and that security is best-effort. Linked from the footer next to the license and privacy notices.

      Disclaimer page

    • Contenuto

      New Learn articles: proxies, TLS interception, and SAML proxying

      A batch of ten articles on the proxy family. Five vendor-agnostic explainers cover the TCP proxy at Layer 4, HTTP proxies (forward vs reverse, explicit vs transparent), inbound TLS at a reverse proxy (offload, bridging, passthrough), the SSL forward proxy that intercepts outbound TLS, and the SAML proxy that inserts an identity layer into a session. Five vendor companions map those concepts onto real products: F5 SSL Orchestrator topologies, F5 BIG-IP APM as a SAML SP/IdP, enforcing forward secrecy on F5, FortiGate certificate vs deep SSL inspection, and Netskope cloud forward proxy with inline TLS decryption. Perfect forward secrecy and the F5 client-SSL/server-SSL profile split were already covered by existing explainers, which the new articles link to rather than duplicate. Every vendor claim was checked against the vendor's own documentation. English and Portuguese, with the other locales served by English fallback.

      HTTP Proxies: Forward vs Reverse, Explicit vs Transparent · SSL Forward Proxy: How Outbound TLS Interception Works and What Breaks It · The SAML Proxy: Inserting an Identity Layer into a Session

    • Funzionalità

      Boss-screens viewer: grouped, with a jump navigator

      The boss-key screen gallery on /dev/fun now organizes its 76 screens into six families, home computers, PC hardware and POST, DOS software, operating systems and servers, online services and BBSes, and network analysis, each in its own labelled section. A jump navigator sits on top, the same category-nav pattern used by the Tools and Learn indexes, so you can skip straight to a family instead of scrolling one long grid. Group labels are localized (English and Portuguese, other locales via English fallback); the cards, thumbnails, and fullscreen overlay are unchanged.

      Boss-screens gallery

    • Contenuto

      New Learn articles: post-quantum cryptography

      Three new articles in the transport track cover the post-quantum transition end to end. The first explains what a quantum computer would actually break (Shor against RSA/DH/ECC, Grover only halving symmetric strength) and why harvest-now-decrypt-later makes it a present concern. The second walks the finalized NIST standards, FIPS 203 ML-KEM for key establishment and FIPS 204 ML-DSA and FIPS 205 SLH-DSA for signatures, plus the HQC and FN-DSA backups still in the pipeline. The third is the practical one: how hybrid key exchange (X25519MLKEM768) puts post-quantum crypto on the TLS 1.3 wire today, the ClientHello size problem it creates for middleboxes and load balancers, and where browser and server deployment stands. Grounded in NIST CSRC, the IETF drafts, and current deployment reporting; English and Portuguese.

      The NIST Post-Quantum Standards: ML-KEM, ML-DSA, and SLH-DSA

    • Nuovo strumento

      New tool: F5 iQuery protocol explainer

      A new F5 BIG-IP DNS (GTM) tool that decodes iqdump output and /var/log/gtm iQuery messages, and explains the iQuery architecture on request. Paste iqdump and it reads back the header comments and the <xml_connection> stanza (the big3d peer on TCP 4353, the sync group, version, connection_id); paste a gtm log and it decodes the box green-to-red state changes; or pick a topic (mesh, port 4353, SSL trust, iqdump, metrics, gtmd, big3d, VLAN) for a plain-language explanation. Decode-only and fully local, grounded in F5's BIG-IP DNS/GTM manuals and K-articles, with the example taken from a real iqdump sample F5 published. Ships with a paired Learn article in English and Portuguese.

      iQuery protocol explainer · How iQuery Connects BIG-IP DNS to the Rest of the Network

    • Funzionalità

      Keyboard shortcut: press F for the dev-fun index

      The site-wide keyboard shortcuts gain F, which jumps to the dev-fun landing page (joining B for the boss key, M for the Mega Brain console, and Z for Buzzword Bingo). Like every shortcut it is rebindable in Settings and inert while you are typing in a field. Separately, the PCBoard boss screen now shows a handle at its login prompt, matching how PCBoard boards actually identified callers.

      dev-fun index

    • Contenuto

      The Sniffer learns to decode: eight famous captures in the three-pane view

      The Network General Sniffer screen gains eight companion decodes rendered in its authentic three-pane analysis view (summary, detail, and hex): an HTTP 420 Enhance Your Calm response, the ILOVEYOU mail envelope, and the Morris Worm, Stuxnet, Conficker, Mirai, WannaCry, and NotPetya. HTTP 420 and ILOVEYOU show their real, benign application-layer artifacts in full; the six network worms are shown at the header level only (ports, protocol, CVE, date) with a clear payload-omitted marker, so no exploit or shellcode bytes appear. Every on-screen string is grounded in a cited source, from CISA and CAIDA to Microsoft and the Twitter API record.

      BIG-IP tcpdump builder

    • Contenuto

      Two professional tools close out the boss-screen set

      The retro collection reaches 68 with the pro tools that ran the network room: the Network General Sniffer, the DOS protocol analyzer that named the whole category and whose menu here is taken verbatim from a Sniffer v4.4 tutorial, and the VMware ESXi 6.7 DCUI, the bare-metal hypervisor's yellow-and-grey console with its F2-to-configure, F12-to-shut-down legend. Both were checked against period sources, from the Sniffer's own manual description to VMware's release records.

      Boss-screens gallery

    • Contenuto

      The 128K Spectrum family: +2A and +3 join, and the 128 menu is corrected

      The ZX Spectrum 128 boot menu was fixed to show the machine's real options (Tape Loader, 128 BASIC, Calculator, 48 BASIC) with no spurious copyright line, and two new screens join it: the Amstrad-era ZX Spectrum +2A and +3, both showing the shared +3 ROM menu (Loader, +3 BASIC, Calculator, 48 BASIC) and the (c)1982, 1986, 1987 Amstrad Plc. line, matched against a real-hardware photo and the official +3 manual.

      Boss-screens gallery

    • Contenuto

      TK90X and TK95 boot screens corrected against real hardware

      Photographs of real Microdigital hardware corrected two things on these boot screens. Both machines show an eight-colour test bar (the ZX Spectrum bright palette) that was missing before: the TK90X a thin horizontal bar, the TK95 a taller field of vertical colour bands. The TK95's boot line was also fixed to read Microdigital TK95, its actual name, replacing a line taken from a mislabelled Spanish-variant ROM dump. A reminder that a ROM dump is only good evidence when it is the right ROM.

      Boss-screens gallery

    • Contenuto

      The GUI and online era arrives: six more boss screens

      The retro collection reaches 64 with the interfaces that carried computing from the command line into the graphical, networked age: Windows for Workgroups 3.11 Program Manager, the OS/2 Warp Workplace Shell desktop, the classic Macintosh Finder with its Trash, NCSA Mosaic opening the web, and the two services that first put millions online, CompuServe with its numbered menu and AOL with its Welcome screen. Framing facts were checked against period sources, from IBM and Microsoft histories to NCSA's own account of Mosaic.

      Boss-screens gallery

    • Contenuto

      TK90X and TK95 boot screens: the rainbow stripes are gone

      The Microdigital TK90X and TK95 retro screens were showing four colour bars that the real machines never display at power-on: those stripes belong to the Spectrum's logo and case motif, not the boot screen, which is plain black text on a paper-white background. Both now boot the way the hardware does, to a blank white screen with only the copyright line at the bottom (TK90X - Color Computer and TK Color Computer), verified byte-for-byte against ROM dumps and a real-hardware boot video.

      Boss-screens gallery

    • Contenuto

      Ten DOS-era workhorses join the boss screens

      The retro screen collection jumps to 58 with the software that ran offices and small businesses: XTreePro and XTreeGold, dBASE II at its dot prompt, a Clipper Summer '87 compile with its preserved copyright banner, Borland SideKick popping over a DOS session, MultiMate Advantage, Professional Write, Harvard Graphics, Microsoft Works, and Ami Pro, the first fully functional Windows word processor. Every dated fact was checked against period sources, from the XTree fan archive's command list to Microsoft's own history pages.

      Boss-screens gallery

    • Contenuto

      Three BBS screens, and the TK90X and TK95 set right

      The retro screen collection reaches 48 with the other side of the modem: RemoteAccess waiting for a caller on the sysop's console, Oblivion/2's scene-styled front door, and Telegard's classic main menu. The TK90X and TK95 boot screens were also corrected: the real machines boot to their own names (TK90X - Color Computer and TK Color Computer), verified character by character against ROM dumps and real-hardware video, replacing an inaccurate Sinclair-style line.

      Boss-screens gallery

    • Contenuto

      Three deep-cut boss screens: NetWare, PCBoard, and Videotexto

      The retro screen collection grows to 45 with three long-requested additions: the Novell NetWare 3.12 console running MONITOR.NLM (its utilization figure ticking about once a second, the way the real screen refreshed), a PCBoard BBS session dialing Clark Development's own Salt Air support board at 2400 bps, and the TELESP Videotexto index painting line by line the way Brazil's 1982 videotex service did over a 1200/75 bps modem link.

      Boss-screens gallery

    • Contenuto

      Two more retro boot screens, and a fix to a third

      The hidden retro boot-screen collection gains the Microdigital TK-82C (a ZX81 clone, the machine this site's author first learned to program on) and the TK95 (the TK90X's Spectrum-clone successor), bringing the set to 42. The ZX81 and TK-82C screens now type a first line by themselves, the way those machines did. The TK90X screen was corrected: its ROM replaced the copyright symbol with a Greek delta, so its boot line now reads accurately. The screens in the viewer are also listed in alphabetical order.

      Boss-screens gallery

    • Infrastruttura

      Pinned to the framework version the site builds cleanly on

      The framework was briefly moved up a major version, which changed how the site is turned into static files at build time: it began emitting several extra bookkeeping files per page, and across thousands of pages in sixteen languages that overflowed the build machine's disk before the export could finish. Since the site is a purely static export that gains nothing from the newer version's server-oriented features, it is now pinned back to the previous major version, which produces far fewer build artifacts and completes the export well within the available space. Everything the site does is unchanged; this only affects how it is built.

    • Contenuto

      Boss-key screens now hold a proper 4:3 monitor shape

      The retro boss-key screens are now framed like the CRT and TV displays these machines actually used, a 4:3 monitor that scales to fit the window and centers with letterboxing, rather than stretching. Previously each screen filled the full window height while its width followed its content, so a screen with only a line or two (a ZX Spectrum copyright line, an MSX prompt) became a tall, narrow strip, while a wide two-panel layout like Norton Utilities happened to look right. Every screen now shares the same correct proportions on any window size, from an ultrawide monitor to a phone.

      Boss-screens gallery

    • Funzionalità

      A user guide that stays current with the toolbox

      There is now a Site User Guide at /guide, linked from the footer. It has four parts: an at-a-glance datasheet, a full tool reference grouped by category, suggested-usage recipes that map a common task to the tools that do it, and a short manual covering how to run a tool, privacy, the API, languages, and offline use. The datasheet figures and the tool reference are generated from the site's own sources at build time, so they always match what is published; a build guard additionally fails if a recipe ever points at a tool that no longer exists. English and Portuguese are authored directly; other locales fall back per key.

      User guide

    • Funzionalità

      A single switch turns the API on or off, and the pills follow it

      Whether the API is served is now controlled by one value in one file (API_PROCESSING in the API surface config): 0 keeps it documented but not served, 1 turns on local processing, where the same-origin worker answers each endpoint with the in-house engines. Both the worker and the interface read that one value, so they can never disagree: while it is off, every /api/v1 request returns an honest 404, and every API pill and badge shows a neutral grey state with 'documented, not served' wording; flip it to 1 and the same pills turn green with 'served locally' wording, on each tool page and on the API page. The switch ships in the off position. A repository link was also added to the License page and the footer. English and Portuguese ship together; other locales fall back per key.

      Settings

    • Infrastruttura

      A proper multilingual sitemap, with hreflang for every language

      The site now generates sitemap.xml at build time, listing every page with an hreflang alternate for each of the sixteen live languages plus an x-default, so search engines understand which URLs are translations of one another. It is derived from the built pages, so it stays current automatically as pages are added or removed. robots.txt now points at it. This complements the per-page canonical links added earlier.

    • Lancio

      ronutz.com is now open source: Apache-2.0 for code, CC BY 4.0 for content

      The project is now open source. The application code is licensed under the Apache License 2.0, and the written content, including every Learn article and all the tool copy, under Creative Commons Attribution 4.0 (CC BY 4.0). Both licenses require attribution, so anyone reusing the code or the content must credit the source, and ronutz.com stays the canonical, maintained home. The License page now describes the open terms, the footer badges are live, and the repository carries the full LICENSE, a content license, and the third-party NOTICE. Each page also now declares its own canonical URL, so a copy rehosted elsewhere still points search engines back here. English and Portuguese ship together; other locales fall back per key.

      License

    • Funzionalità

      Open-source and licensing badges, on the way to opening the code

      The License page and the footer now carry a set of hand-drawn, self-hosted badges that declare how the project will be licensed once it is opened: Open Source, the code under the Apache License 2.0, and the content under Creative Commons Attribution 4.0 (CC BY 4.0), which requires anyone reusing it to credit the source. The badges are inline SVG that theme with the rest of the site and load no external assets, in keeping with the privacy stance; the Apache mark is a plain SPDX label rather than the Apache Foundation's feather, and the Creative Commons glyphs are the marks CC publishes for exactly this purpose. On the License page they are framed as the planned terms, since the project is still proprietary today; the footer cluster links through to the full terms. English and Portuguese ship together; other locales fall back per key.

      License

    • Funzionalità

      Every API-capable tool now shows its endpoint URL, linked to the spec

      Each tool that has an HTTP API endpoint now displays that endpoint on its page, for example GET https://ronutz.com/api/v1/cidr, as a link that opens the API reference's Swagger UI view, deep-linked to that tool's operation. The endpoint URLs and their operation anchors are read from the generated OpenAPI spec at build time, so they are always correct, including hand-authored operations whose identifiers differ from the tool slug. The label is honest: the endpoint is documented, not served, and the link opens the specification rather than making a live call. Tools without an API endpoint show nothing. English and Portuguese ship together; other locales fall back per key.

      API reference

    • Funzionalità

      The API reference is now public, documented but deliberately not served

      The tools API now has a visible home, linked from the footer next to the build stamp. Every tool is built to run as a small, deterministic HTTP API, and the full OpenAPI 3.1 contract is published and browsable, both in an on-brand reference and in a standard Swagger UI view. The page is honest about one thing up front: the API is implemented and documented, but this site does not serve it, because a public API bills for compute on every call in ways a single maintainer cannot cap safely, and the site is meant to stay free and predictable to run. In keeping with that, both reference views are now inert: Swagger UI's try-it-out controls are removed, and the on-brand explorer builds the exact request URL you would call but sends nothing. The engine is open, so anyone who needs the API today can run it themselves. English and Portuguese ship together; other locales fall back per key.

      API reference

    • Funzionalità

      A 'what this page needs' pill on the CIDR tool (proof of concept)

      A new capability row is being trialled on the CIDR calculator before a wider rollout. It states, up front, what your browser needs for the tool to be fully functional: a 'Runs in your browser' pill notes that the tool computes entirely on your device (so nothing you type is sent anywhere) and therefore needs JavaScript, and an 'API-ready' pill marks that this tool is also built to work over an HTTP API, with a clear note that the API is not switched on yet. With JavaScript disabled, a short note now explains the reduced-function version honestly: the page's explanation, the Markdown reference, the Learn article, and the sources all still render server-side; only the live calculator needs JavaScript. English and Portuguese ship together; other locales fall back per key.

      CIDR / subnetting

    • Funzionalità

      Full Apple coverage: the Apple I, the original Apple II, and the Macintosh (Happy Mac)

      The boss-key gallery now covers Apple's iconic early machines end to end, each checked against original documentation. New: the Apple I (1976), where Wozniak's 256-byte WozMon prints a backslash and a blinking cursor after Reset; the original Apple II (1977), which has no autostart ROM and comes up in the machine-language monitor at a * prompt (Ctrl-B enters Integer BASIC and its > prompt); and the Macintosh 128K (1984), with Susan Kare's friendly boot, a blinking floppy-with-a-question-mark that resolves into the smiling Happy Mac and Welcome to Macintosh. The existing //e screen was also corrected: it now shows the enhanced //e's Apple //e banner, which keeps it visually distinct from the Apple ][+ screen. Together with the II+, //c, and IIgs added earlier, that is seven Apple screens; the gallery now holds forty in all.

      Boss-screens gallery

    • Funzionalità

      Nine more boot screens: Apple ][+, //c, IIgs, Atari 800XL, TI-99/4A, MSX turbo R, and Brazilian clones

      The boss-key gallery in /dev/fun grew by nine period-accurate boot screens, each checked against original documentation. New this round: the Apple ][+ (the plain Apple ][ banner and ] prompt), the Apple //c (Apple //c, then Check Disk Drive with no disk in the drive), the Apple IIgs (its Check Startup Device screen with the colour Apple logo sliding side to side), the Atari 800XL (deep blue Atari BASIC READY), the TI-99/4A (the cyan TEXAS INSTRUMENTS HOME COMPUTER title, press any key to begin), and the MSX turbo R (the logo assembling from the sides into MSX BASIC 4.0). Three are Brazilian machines from the market-reserve years: the Prologica CP-300 (the compact, disk-less TRS-80 Model III clone that boots straight to cassette BASIC), the Prologica CP-400 (the TRS-80 Color clone, a CoCo 2 running Extended Color BASIC), and the Unitron AP II (the faithful Apple II Plus clone with a Portuguese ROM). They join the existing screens in the same shuffled rotation (you see them all before any repeats), browse left and right while one is up, and Esc dismisses; all animations respect the reduced-motion setting.

      Boss-screens gallery

    • Funzionalità

      Customizable shortcuts, a settings page, ten boss-key screens, and a motion switch

      A big pass over the site's keyboard shortcuts and the /dev/fun corner. Shortcuts are now user-configurable: a new Settings page (linked in the footer) lets you rebind any shortcut key, with the choice saved on your device; press ? anywhere for a live cheat-sheet of the current bindings. New shortcuts were added alongside the originals: s opens search, / focuses it, h goes home, ? opens the cheat-sheet, and 1 to 5 jump to five go-to tools (CIDR, Base64, JWT, JSON to YAML, and the F5 hub). Language is now a saved preference too: a return visit to the site's home takes you to your preferred language, while any explicit /en/ or /pt-BR/ link is always honored as-is. The boss key grew from two disguises to ten period-accurate ones (Lotus 1-2-3, WordStar, VisiCalc, Norton Utilities, WordPerfect 5.1, dBASE III+, Turbo Pascal, the Windows blue screen, Norton Commander, and a Commodore 64 that types a program by itself), shuffled so you see them all before any repeats; while one is up, the left and right arrows browse the rest, and Esc dismisses. A new Boss-Key Screens gallery in /dev/fun lets you browse them by name, thumbnail, and a short note, and open any one fullscreen. Finally, the Mega Brain console got a motion switch in its title bar for anyone who prefers less movement (its explanatory banners now also hold still while the console shakes), complementing the system reduced-motion setting the site already respects.

      Boss-screens gallery

    • Funzionalità

      Site-wide keyboard shortcuts, and a Mega Brain console tune-up

      New single-key shortcuts on every page: b for the boss key (hide the page behind a 1980s work app until any key or click), t for the Tools index, l for the Learn index, m for the Mega Brain console, and z for Buzzword Bingo. They stay completely inert while you are typing (a focused text field, paste box, or search input keeps its keys) and when a modifier is held (so Ctrl+T and the like are never shadowed); they run entirely in the browser with no tracking, and are documented on the privacy and site-behavior page. Alongside that, the Mega Brain console got a tune-up: the FULL POWER and STOP controls moved into the window title bar as pills (FULL POWER a fixed-pink lightning pill, STOP a red octagonal emergency-stop button), the Mano Deyvin tribute overlay now dismisses on a click anywhere (fixing a mispointing cue and the sense that a timer was blocking it), and the /dev/fun label in the console frame is now a link back to the /dev/fun index, with a matching link added to Buzzword Bingo.

      Mega Brain console

    • Nuovo strumento

      New tool: Telemetry Streaming (TS) explainer

      The third F5 Automation Toolchain explainer, completing the AS3 / DO / TS set. Paste the JSON you POST to /mgmt/shared/telemetry/declare and it reads it back: it confirms the top-level Telemetry class, reads the optional Controls (logLevel, debug, the beta memoryMonitor), and walks every named class-object grouped by its role in the telemetry pipeline rather than by onboarding order. Data sources produce telemetry (a Telemetry_System with its systemPoller or iHealthPoller, a standalone Telemetry_System_Poller pulling from another BIG-IP, or a Telemetry_Listener ingesting events on TCP+UDP port 6514); consumers forward it out (Telemetry_Consumer push consumers with the full type catalogue: Splunk, Azure, AWS CloudWatch/S3, Graphite, Kafka, ElasticSearch, DataDog, Generic HTTP, OpenTelemetry and more, or Telemetry_Pull_Consumer pull consumers like Prometheus); and Telemetry_Namespace and Telemetry_Endpoints support the rest. The headline check is pipeline completeness: it flags a declaration that is valid but does nothing, consumers with no source, sources with no consumer, a Telemetry_System missing its systemPoller (the troubleshooting-doc gotcha), a Consumer missing its type, and it counts namespace-internal sources and consumers so a namespaced declaration is not falsely flagged. Where AS3 and DO configure the box, TS observes it. Grounded in F5 TS docs (clouddocs, TS 1.41-1.42); note TS is in maintenance mode per F5, still supported, no deprecation planned. Decode-only, nothing leaves the browser.

      Telemetry Streaming (TS) explainer

    • Contenuto

      Learn article: Telemetry Streaming, the extension that observes

      The companion to the new explainer, in English and Portuguese. It places TS in the toolchain by what it does differently: AS3 and DO configure the BIG-IP, TS observes it, aggregating, normalizing, and forwarding stats and events to a consumer. It walks the flat Telemetry-class model (no tenant, no Common, unlike DO), the three object roles (sources produce, consumers forward, namespaces and endpoints support), the long push/pull consumer catalogue, and the failure that passes schema validation: an incomplete pipeline with a source but no consumer or a consumer but no source, including the Telemetry_System-without-systemPoller trap and the namespace-scoping subtlety. States plainly that F5 has placed TS in maintenance mode. Cross-linked to the DO and AS3 articles and the new tool.

      Telemetry Streaming: The Automation Toolchain Extension That Observes Instead of Configures

    • Nuovo strumento

      New tool: DO declaration explainer + validator

      The sibling of the AS3 explainer, for the other half of the F5 Automation Toolchain. Paste the JSON you POST to /mgmt/shared/declarative-onboarding and it reads it back: whether it is a DO request wrapper (class DO, as sent to a BIG-IQ with a targetHost) or a bare Device declaration, the top-level options (schemaVersion, async, webhook, label), and the one tenant a DO declaration is allowed, which the schema requires be named Common. It walks that tenant's class-objects grouped by the phase DO effectively onboards them in: licensing and provisioning first because they gate the modules, then system identity (hostname, DNS, NTP, users), then networking (VLANs, self IPs, routes), then the clustering that joins a box to its peers. Every class is named and explained from F5's schema reference. It also flags the documented gotchas that bite in production: a hostname set on both Common and a System class (mutually exclusive), a self IP with no allowService (DO 1.36 changed that default from `default` to `none`, so it now locks down), a root user missing its oldPassword, and async:true returning a 202 you poll with GET. A structure explainer and sanity checker, not the full JSON-Schema validator; grounded in F5 DO docs (clouddocs, DO 1.47.0), decode-only, nothing leaves the browser.

      DO declaration explainer + validator

    • Contenuto

      Learn article: Declarative Onboarding, the L1-L3 half

      The companion to the new explainer, in English and Portuguese. It draws the line that makes the whole toolchain click: AS3 configures the L4-L7 application services on a box already on the network, and DO does the L1-L3 onboarding that gets it there, licensing, provisioning, DNS and NTP, VLANs and self IPs and routes, users, and clustering. It walks the one-Device-one-Common-tenant model and why DO is stricter than AS3 about the tenant name, the async-returns-202 contract, the classes in the order onboarding actually happens, and the three version-specific traps the docs bury: the hostname mutual-exclusion, the DO 1.36 allowService default flip to none, and the root oldPassword requirement. Cross-linked to the AS3 anatomy article and the new tool.

      Declarative Onboarding: The L1-L3 Half of the Automation Toolchain

    • Nuovo strumento

      New: AWAF policy-diff hole checker (FP set complete)

      Paste a before and an after declarative WAF policy and it classifies every security-relevant change as a relaxation or a tightening, then answers the question that matters after tuning: did this open a hole? It separates relaxations that widen protection beyond a single entity (switching to Transparent, disabling a violation or evasion, Data Guard off, trusting X-Forwarded-For, moving signatures to staging, or adding a wildcard entity) from a properly-scoped single-entity allow (adding one URL or parameter, the normal false-positive fix). The verdict is opened-hole if any policy-wide relaxation is present, scoped-only if the widenings stay entity-scoped, or tightened-only. This completes the four-tool false-positive set (request-log triage, learning-suggestion interpreter, signature accuracy/risk, and now policy-diff). Field paths validated against F5's declarative WAF policy schema; decode-only, nothing leaves the browser.

      AWAF policy-diff hole checker

    • Nuovo strumento

      New: AWAF signature accuracy/risk interpreter

      Reframed from a per-signature-ID lookup (not feasible or honest given F5's proprietary signature set): it reads the two properties F5 publishes for every attack signature, its Accuracy and its Risk, plus whether it applies to your systems and whether it is enforced. F5 defines accuracy as false-positive susceptibility, so low accuracy means a high false-positive likelihood, medium some, high low; risk is the damage a real match would do. It places the signature in the accuracy-by-risk quadrant and gives the tuning move: low/low is the prime relax candidate, low accuracy plus high risk is false-positive-prone but dangerous so investigate first, high/high is a reliable high-stakes block you do not relax. It flags signatures for systems not in your stack as pure noise and surfaces accuracy as a lever: a signature set weighted toward higher-accuracy signatures produces fewer false positives. Tool 3 of the four false-positive follow-ons. Grounded in F5's attack-signature docs; deterministic, nothing leaves the browser.

      AWAF signature accuracy/risk interpreter

    • Nuovo strumento

      New: AWAF learning-suggestion interpreter

      Ties the poisoning estimator and the false-positive triage together. Characterise a Traffic Learning suggestion (its action, its learning score, the violation rating, the learning mode, and the source trust) and it says whether accepting it loosens the policy (add an allowed entity, allow a meta-character, relax an attribute, disable a violation or signature) or tightens it (remove a wildcard, enforce a staged entity, make an attribute more specific), whether a loosening is a genuine false-positive fix or a security relaxation (by rating: 1-2 fix, 3 investigate, 4-5 relaxing an attack), and whether Automatic learning is about to enforce it. It flags the poisoning vector: Automatic mode, a relaxing loosening, untrusted traffic, and a climbing learning score, which rises as the violation rating falls, so low-rated suggestions auto-accept fastest. This is tool 2 of the four false-positive follow-ons. Grounded in F5 K03513854 and the ASM learning docs; deterministic, nothing leaves the browser.

      AWAF learning-suggestion interpreter

    • Nuovo strumento

      New: AWAF request-log triage

      Paste an ASM request-log entry, the syslog key-value line or the CEF line you see in your SIEM, and it extracts the policy, the support ID for log correlation, the request status, the violation rating, the client IP, method, and URI, classifies each violation into a triage category, and gives F5's rating-based verdict (4-5 likely attack, 3 investigate, 1-2 likely false positive), then bridges to the false-positive triage tool for the per-violation fix. It handles both the legacy key-value format and CEF. Note on honesty: it does not decode the support-ID number, because that number is an opaque correlation reference and does not carry the violations, the log line does. This is the first of the four false-positive follow-on tools. Grounded in F5's ASM logging-field and reporting docs; decode-only, nothing leaves the browser.

      AWAF request-log triage

    • Nuovo strumento

      New: AWAF false-positive triage

      The flip side of the poisoning estimator: it helps you relax a genuine Advanced WAF false positive correctly, with scope, and stop before relaxing a real attack. Pick a violation category, its average violation rating, and whether it is enforced, staged, or transparent, and it returns F5's rating-based verdict: ratings 1 and 2 are likely false positives you can accept if confirmed, rating 3 must be investigated, and ratings 4 and 5 block even with Block flags off, so you clear the suggestion without relaxing. It gives the scoped remediation for that category (disable a signature on one URL or parameter, add an allowed entity, add the meta-character to that entity's set, attach an XML/JSON profile, mark a file-upload parameter, or enable Potential False Positive Detection), never a policy-wide disable, and always restates the discipline: relax only where a false positive occurred, never where a real attack caused the violation. A companion Learn article covers the workflow. Grounded in F5 K70544352 and the ASM violation-rating and learning docs; deterministic, nothing leaves the browser.

      AWAF false-positive triage

    • Nuovo strumento

      New: AS3 declaration explainer

      Paste the JSON you POST to /mgmt/shared/appsvcs/declare and this reads it back: whether it is a full AS3 request (class AS3, with action and persist) or an ADC-only declaration (class ADC), the schemaVersion and metadata, and the Tenant to Application to resource tree with every class named and explained, from Service_HTTP and Service_HTTPS through Pool, Monitor, TLS_Server, Certificate, WAF_Policy, and iRule. It also checks the structural rules F5 documents: a top-level AS3 or ADC class, a schemaVersion, at least one Tenant containing an Application containing a resource, and the template and service-class matching rule (http/https/tcp/udp/l4 require a matching Service_* named service), plus reserved-name and 1-to-64 alphanumeric name checks. It lights up the Automation sub-category on the F5 hub as its first tenant. A companion Learn article walks the anatomy of a declaration. A structure explainer and sanity checker, not a full schema validator; grounded in F5's AS3 docs, decode-only, nothing leaves the browser.

      AS3 declaration explainer

    • Nuovo strumento

      New: AWAF automatic-learning poisoning estimator

      A deterministic calculator for a question every WAF instructor gets: how many requests does an attacker need to drill a hole through your BIG-IP Advanced WAF policy when the Policy Builder is left in Automatic learning against untrusted traffic? In Automatic mode a suggestion that reaches a 100% learning score is auto-accepted and enforced, and the Loosen stage can disable violations and widen entities. Enter your policy's Loosen thresholds (different sources, sessions, time spread; F5 default 10 untrusted sources) and the target manipulation's violation rating, plus the attacker's distinct source IPs and per-source rate, and it computes the minimum sources, requests, and elapsed time to force one automatic relaxation. It gates hard on the documented rules that make it impossible: Manual or Disabled learning, rating-5 unlearnable violations, and loosening restricted to trusted traffic, and it surfaces the five hardening levers. A companion Learn article, 'Automatic Learning in Production: How an Attacker Poisons a WAF Policy', explains the mechanism. Grounded in F5 K000134503 and the ASM learning manuals; nothing is fetched or sent.

      AWAF automatic-learning poisoning estimator

    • Contenuto

      F5 hub: dedicated iRules category, corrected tags, standardized names

      The F5 hub got a taxonomy and naming pass. iRules is now its own category with a dedicated heading, split out from LTM, so iRule tools and articles group together on their own. The BIG-IP persistence-cookie decoder, which was mis-tagged Security & WAF, now correctly reads Networking. The platform divider is standardized to 'TMOS · F5OS · Platforms', and six F5 tool names were polished for consistency: sentence case throughout, 'F5XC' rather than 'F5 XC', 'iRules' spelled consistently, and cleaner separators, aligned across the hub and the catalogue in both English and Portuguese.

      F5 hub

    • Nuovo strumento

      New: AWAF evasion-technique explainer

      The decode side of 'evasion technique detected' (VIOL_EVASION), grounded verbatim in F5's K7929 and the current BIG-IP ASM 17.5 violation chapter. Type a sub-violation name or 'evasions' and get F5's own eight sub-violations explained, Microsoft %u decoding, Apache whitespace, Bad unescape, Bare byte decoding, Directory traversals, IIS backslashes, IIS Unicode codepoints, and Multiple decoding, each with its default (all enabled) and the encoding trick it catches. Or paste the evasions block of a declarative policy to read each one back as enabled or disabled, with the Multiple-decoding pass count surfaced and bounds-checked against the schema's 2-to-5 range. It bridges to the Base64 and Percent codec tools that perform the very same decode operations, the encode/decode complement asked for, since several evasions are exactly the %u, bare-byte, and repeated percent-decoding those tools already do. A companion Learn article, 'Evasion Techniques: How Advanced WAF Normalizes Around Attacker Encoding', explains the whole class. Decode-only; nothing leaves the browser.

      AWAF evasion-technique explainer

    • Contenuto

      The colophon now states the hosting ceiling, honestly

      A new colophon section, echoed in one paragraph on the roadmap, spells out the hard limits this site lives under: a Cloudflare Worker version carries at most 20,000 static files on the free plan and 100,000 on the paid plan (raised five-fold in September 2025, deployable only with Wrangler 4.34 or newer), no file over 25 MiB, and static-asset requests free and unlimited. Against that, the site's own arithmetic: about three files per rendered page across sixteen languages, roughly fifty files per tool and a hundred per tool-with-article pack, a little over eighteen thousand files today, and a mapped expansion path, route-sharded Workers, then object storage, should the toolbox ever outgrow one Worker.

      Colophon

    • Funzionalità

      Every tool now has an Example button (D-83 retrofit complete)

      The Example and Clear buttons that newer tools shipped with are now on every tool, all 54 of them. The 31 retrofitted tools each load a sample taken verbatim from their own golden test vectors, so every example provably works: the RFC 4231 HMAC test case, the RFC 7636 PKCE verifier from appendix B, the RFC 7517 example key set, the canonical jwt.io token, the classic BIG-IP persistence cookie from K6917, real tmsh stanzas, and more. Even the two form-style tools joined in their own way: the iRule event-order tool's Example applies the HTTPS re-encrypt preset, and the tcpdump builder's fills in the all-TMM interface, name-resolution-off, and a host-and-port filter. One click shows what each tool does; one click clears it.

      All tools

    • Funzionalità

      Vendor sub-categories, and generic categories go vendor-agnostic

      The taxonomy grew a level. Vendor hubs now group their tools and articles by ordered sub-categories: for F5, the ten pillars from LTM and iRules through TMOS, DNS/GTM, ASM, AFM, APM, SSL Orchestrator, automation, public cloud, and Distributed Cloud, with every tool assigned and articles inheriting their placement from the tools they relate to. Fortinet, Netskope, and Extreme Networks received source-grounded taxonomies of their own, built from each vendor's official product catalogue, twelve Fortinet sub-categories with the full A-to-Z product list assigned, ten Netskope One components, eight Extreme product families, ready for the day their first tools ship. And the generic categories on the Tools and Learn indexes are now exclusively vendor-agnostic: vendor content lives on its hub, one cross-vendor syslog article came home to networking, and the hub strip on top of each index is the way in.

      All tools

    • Contenuto

      Privacy page: why preferences live only on your device

      A new section on the privacy page explains what this site remembers and why. The theme choice is stored only in your browser's localStorage and applied before first paint; no cookie, no account, no server ever sees it, which is exactly why a private window, cleared site data, or another device starts you back at the default. Language is not stored at all, it lives in the URL, so a bookmarked address in your language keeps it. With no accounts and no tracking, preferences can only live where you can see and delete them.

      Privacy page

    • Contenuto

      Learn article: session variables, where APM keeps everything it learned

      The companion to the new reference, in English and Portuguese, and the closing of the APM cluster the SSO article opened: the naming anatomy from the manual's own figure and why the names are templates, the three official read syntaxes with the chapter's own OTP percent-expansion as proof text, the secure contract in F5's own lab wording and the silent empty read it produces on a bare mcget of a password, the plumbing pair every SSO method ultimately reads, session.custom's auto-container behavior, and the two debug surfaces, the active-sessions-only report with its message-box pause trick and sessiondump from the CLI. The SSO methods article's closing line now links the live reference.

      Session Variables: Where APM Keeps Everything It Learned

    • Nuovo strumento

      New tool: APM session-variable reference

      The Session Variables chapter, vendored and made pattern-aware. Paste session.ad.last.attr.memberOf and it resolves against the chapter's own dollar-name templates with the bindings shown, because each retrieved attribute becomes its own variable, the chapter's rule. Families run from policy results through the client and AAA sets to the full session.ssl.cert family, endpoint checks with the always-zero hd.state quirk flagged, OTP with the chapter's own percent-expansion example, and the logon and SSO plumbing rows the SSO methods read. Expressions parse across the three official syntaxes, percent expansion, mcget inside expr branch rules, and access::session data get and set, with the secure audit riding along in F5's own wording: encrypted in the session db, hidden from reports and logs, minus-secure required on both read paths. The one-click Example is the classic empty-value trap, a bare mcget on the logon password, and the tool names exactly what comes back: nothing.

      APM session-variable reference

    • Contenuto

      Learn article: living TCP, frozen TCP, and the two fast paths

      The companion to the new explainer, in English and Portuguese: the day the tcp family started living, told in the 13.0 announcement's own words, updated versions of the -optimized trio, progressive for the very latest features, five read-only living profiles tuned through child profiles with the custom flag pinning settings against future pushes, and the frozen legacy trio that still ships. FastL4 as the profile that is not a proxy, the PVA packet path, the loose pair for asymmetric routing, and the late-binding FIX trick. FastHTTP as the narrow case whose qualification is a checklist, every criterion a disqualifier read backwards, with K8024 as the reading you do before deploying, not after.

      The TCP Proxy: What a Layer 4 Middlebox Does and Does Not See

    • Nuovo strumento

      New tool: LTM L4 protocol profile explainer

      The protocol-profile decision, told the way F5's own sources tell it. The tcp family's living-versus-legacy split from the 13.0 announcement verbatim: f5-tcp-wan, lan, and mobile as the updated versions of the -optimized trio, f5-tcp-progressive as the general-use profile carrying the very latest features, all five living profiles continually updated and read-only, tuned through child profiles, while the frozen legacy names still ship for configurations that depend on them. FastL4 as the not-a-proxy: the PVA hardware packet path for Performance and Forwarding virtual servers, the ops guide's little-or-no-processing when-clause, the loose-initialization and loose-close pair for asymmetric routing with their man-page defaults, and the late-binding FIX offload. FastHTTP as the narrow case: TCP Express, HTTP, and OneConnect combined, with the complete when-to-use criteria list, the basic-iRule event trio, and K8024 named as required pre-deployment reading. The one-click Example opens FastL4, the card with the most decisions on it.

      LTM L4 protocol profile explainer

    • Funzionalità

      Tools index hero: the thesis takes the headline

      The tools hub's eyebrow and headline both read Tools, breaking the pattern every other index page follows: a short eyebrow, a statement headline, a supporting lede. The headline is now the site's own thesis, tools that compute, never guess, in both languages, with the eyebrow keeping the short label and the existing lede staying as the supporting line.

      All tools

    • Contenuto

      Learn article: APM SSO methods and the blast radius

      The companion to the new explainer, in English and Portuguese: the eight methods and the asymmetry the chapter states up front, a broken non-form object can dim SSO for the whole session while the two form methods stay standing. What each method actually moves, from Basic's base64 header to NTLMv2's single-header quirk, the Kerberos prerequisite checklist with the no-keytab line and the federate-in-front-delegate-in-back pattern, the Forms - Client Initiated password token that keeps the credential out of the page, and the session-variable plumbing underneath all eight, with the variable reference named as this cluster's next tool.

      APM SSO Methods: One Bad Object Can Dim the Whole Session

    • Nuovo strumento

      New tool: APM SSO method explainer

      The eight methods the Single Sign-On Methods chapter defines, each rendered with its mechanism, its credentials plumbing, its prerequisites, and the verdict that decides outages: the chapter's own blast-radius paragraph, a misconfigured SSO object for HTTP Basic, NTLM, Kerberos, OAuth Bearer, or SAML can disable SSO for every method in that user's session, and the two form methods are the only exempt ones. The Kerberos card ships the full constrained-delegation prerequisite list, delegation account per realm, SPN-format account name, uppercase realm, multi-realm RBCD, and the line worth framing, APM Kerberos SSO does not need or use a keytab file. NTLMv2 carries its documented single-WWW-Authenticate quirk, and Forms - Client Initiated its password-token indirection, the real password never sits in the page.

      APM SSO method explainer

    • Contenuto

      Learn article: AFM contexts, accept as a ticket

      The companion to the new explainer, in English and Portuguese: the fixed context order with the management port apart, the manual's processed-again-at-the-next-context sentence that makes accept a ticket to the next checkpoint rather than through the building, accept-decisively as the one yes that ends the walk, the bluntly worded ICMP restriction at edge contexts, staging as the honest rehearsal, the system's own redundant-and-conflicting definitions including the accept-versus-accept-decisively surprise, and the ADC-versus-Firewall default-action split with the fail-open-versus-fail-closed stakes named.

      AFM Contexts: Accept Is a Ticket to the Next Checkpoint

    • Nuovo strumento

      New tool: AFM rule-context & match explainer

      Paste contexts, policies, and a packet, and the walk runs in the manual's own order: global, route domain, then the virtual server or self IP, with management port rules processed separately. The semantics that decide real outcomes are all here: a matching rule's action applies and the traffic is processed again at the next context, so accept is a ticket to the next checkpoint and only accept-decisively ends the walk with a yes; the one-click Example is a global accept-decisively trumping a virtual-server drop that never sees the packet. ICMP rules at edge contexts are skipped with the manual's ignored note, staged policies log without enforcing, rule-lists expand in place, and criteria the tool cannot evaluate stop the walk honestly. A lone policy gets the audit the system itself defines: redundant and conflicting rules, including accept versus accept-decisively counting as conflicting.

      AFM rule-context & match explainer

    • Contenuto

      Learn article: OneConnect, reuse as a grouping problem

      The companion to the new explainer, in English and Portuguese: the source mask's two documented poles and the subnet-style grouping between them, the naming drift (Source Mask, Source Prefix Length, source-mask), and the sentence both K articles state that decides real outcomes: SNAT translates first, the mask sees only the translated address, so one SNAT address means one reuse group however narrow the mask. Plus the pool lifecycle defaults, the per-TMM division and the Current Idle statistic's real meaning from F5's own lab, and the strict limit the manual itself recommends against.

      OneConnect: Reuse Is a Grouping Problem, and SNAT Rewrites the Groups

    • Nuovo strumento

      New tool: OneConnect source-mask explainer

      Paste a one-connect profile and every option renders with the v17 man page's own semantics, defaults filled in explicitly, from the 0.0.0.0 mask that shares reused connections across all clients to the strict limit the manual itself calls not recommended. Or run the mask simulation: real client IPs, a mask, and optionally a SNAT address, which demonstrates the ordering K7208 and K5911 both state, translation first, mask second, so one SNAT address collapses every client into a single reuse group however narrow the mask. Rounded out with the statistics honesty from F5's own lab article: max-size divides per TMM, and Current Idle counts idle connections whether or not they are eligible for reuse.

      OneConnect source-mask explainer

    • Localizzazione

      Full i18n pass: the last hardcoded strings

      A three-pass audit of every page and component (line-level text, multi-line prose, and metadata) found the stragglers and moved them into the message system: the Learn hub's entire hero (section marker, title, and tagline were hardcoded English on all sixteen locales), the Read links and Read-next block on articles, the primary navigation's screen-reader label, and the changelog and roadmap meta descriptions. Portuguese ships alongside English as always; the remaining locales fall back per key. Protocol samples inside tools (dig headers, tmsh literals, example XML) stay English on purpose, because they are syntax, not copy.

    • Funzionalità

      Homepage joins the page-hero standard; Tools index gets its eyebrow

      The landing hero now uses the same title and lede scale as every other top-level page, the one page deliberately left out of the header standardization pending an explicit call - the reading-comfort scale won. The call-to-action row inherits the spacing the old subtitle carried, with no inline overrides. And the Tools index, which had the standard title but not the small cyan section marker the Learn, Changelog, and Roadmap pages carry, now opens with one: TOOLS above the tagline, translated like its siblings.

      Home

    • Contenuto

      Learn article: packet filters, the checkpoint before everything

      The rich companion to the new tool, in English and Portuguese: one global list in ascending order, first terminal match wins, continue as the only action that lets a packet touch two rules, and an empty expression matching everything. Then the part that decides real outcomes: the master switch ships disabled and off means allow-all, trusted exemptions outrank every rule and cannot be overridden, ARP and four important ICMP types walk past by default, established connections are invisible to the filter unless you enable the option F5 itself says rarely helps, and the management port never meets any of it. Closes with the chapter's own prose-versus-tables wording inversion as a careful-reading note, and the v16 security packet-filter policy name collision.

      Packet Filters: The Checkpoint Before Everything, and the Switch That Ships Off

    • Nuovo strumento

      New tool: BIG-IP packet-filter explainer

      The layer that runs before almost everything else, walked with the man page's own semantics: a single global list, lowest order first (the reference's worked 500/100/300/200/201 sequence is a golden vector), unique orders enforced, evaluation stopping on accept, discard, or reject, continue as the only non-terminal action, and an empty rule expression matching ALL packets, with VLAN-scope-aware shadow detection. Add a sim: line and an honest three-state BPF-subset simulator answers which rule matches, stopping the walk rather than guessing when an expression leaves the evaluated subset. The context panel carries what the chapter says always applies: the master switch is disabled by default and off means all traffic allowed, trusted exemptions precede rules and cannot be overridden, ARP and the important ICMP types are exempt by default, established connections are not filtered by default, and the management interface is untouched by any of it.

      BIG-IP packet-filter explainer

    • Contenuto

      Learn article: CMP, the cores you paid for

      The article behind the new iRules pair, in English and Portuguese: one TMM per core, connections disaggregated across them, and demotion meaning every connection for a virtual serialized onto a single TMM. The demotion list per the CMP Compatibility page: global variables (validator catches them as of v10) with static:: as the documented cure, plus the two per-TMM traps that bite without demoting - RULE_INIT-generated keys and statistics profiles. Closes with the persistence timeline for the folklore, and the LTM-policy escape hatch for match-and-act logic that never needed Tcl.

      CMP: The Cores You Paid For, and the iRule Lines That Give Them Back

    • Nuovo strumento

      Two new tools: the iRules CMP pair

      The command/context explainer reads an iRule the way the reference would: every when block with the event's own Master List one-liner, commands inventoried with direct links to their reference pages, the documented priority evaluation order, and a CMP audit sourced line by line to the CMP Compatibility page - global variables demote the virtual server to a single TMM (the validator catches them as of v10), static:: is the documented cure, RULE_INIT-generated keys are per-TMM, statistics profiles count per TMM. Its sibling classifies each block against LTM policies with three honest verdicts: policy-expressible with a migration sketch in the grammar the vendor's own examples demonstrate, verify-on-version for constructs the verified sources did not show, or iRule-required with the blockers named. Both link per-command validity pages rather than reproducing tables they have not verified.

      iRules command-context explainer · iRules vs LTM policy classifier

    • Contenuto

      Two Learn articles: SYN flood protection, and connection eviction policies

      The DoS-vector explainer's article pair, in English and Portuguese. SYN Flood Protection walks the cookie mechanics per K14779, the LTM threshold map and per-VLAN hardware mode, the AFM tcp-half-open vector's documented precedence over the LTM global SYN cookie, and the mitigation-below-detection arrangement that drops traffic with no attack log. Connection Eviction Policies covers the K15738 lineage from the adaptive reaper, the watermark semantics that change meaning with the attachment context, the strategies the manual honestly calls statistical and opportunistic, and the slow-flow monitor-first pattern. Both grounded in the F5 references fetched this session.

    • Nuovo strumento

      New tool: AFM DoS-vector explainer

      Paste security dos device-config or profile stanzas and every vector renders with F5's own one-line identity (the full 105-entry reference table, sys-db tunables included), the threshold mechanics spelled out - detection compares a 1-minute average against an absolute value or a learned 1-hour baseline, and the internal rate limit runs in hardware where the platform has it - and deterministic cross-checks: the mitigation-below-detection inversion that drops traffic with no attack log, automatic-mode semantics, policing with detection disabled, bad-actor wiring, and the tcp-half-open SYN-cookie interplay. Defensive configuration only; the tool never generates traffic.

      AFM DoS-vector & profile explainer

    • Funzionalità

      Three small touches: the stamp, the roadmap pointer, and a heart

      The build stamp in the footer's machine row now links here, to the changelog, since that is the natural question a build stamp raises. This page opens with a one-line pointer to the roadmap, separating what is planned from what has shipped. And the special-thanks line on the colophon now ends with a small monochromatic heart, as it always should have.

      Roadmap

    • Contenuto

      Certification record corrected against the certificate itself

      The Extreme Networks switching credential listed as Certified Administrator (2026) is, per the certificate document now hosted alongside it, the Extreme Certified Associate, issued August 2023 with no expiry. The entry was corrected to match the document and the certificate PDF is served with it.

      Certifications

    • Funzionalità

      Calmer page headers across the site

      Every top-level page now opens with the same header format the Learn page pioneered: titles cap at a comfortable 2.75rem instead of the 3 to 4.5rem the section pages used to run, and the intro line reads at body-text scale. One shared style now carries the look, replacing three copies of an inline override and eight page-specific variants. The homepage landing hero keeps its own scale on purpose.

    • Contenuto

      Two new Learn articles: the GSLB chain and the topology sort

      BIG-IP DNS Load Balancing: the Wide IP, the Pool, and the Three-Step Chain covers both decision tiers and the chain rules people trip over: the alternate can only be static, the fallback ignores availability on purpose, and None cascades all the way to a BIND aggregate. GTM Topology Records: Longest Match Is a Sort, Not the Pick walks the record anatomy, the verified sorting ladder, and the scoring model with shadowing, including the worked example the scorer loads as its one-click demo. Both in English and Portuguese, grounded in the tmsh references, the Load Balancing manual, and K10721.

    • Nuovo strumento

      New tool: GSLB decision-flow explainer

      Paste gtm wideip and gtm pool stanzas and the two-tier BIG-IP DNS decision renders as it really runs: pool selection at the wide IP, then each pool's preferred, alternate and fallback chain in F5's own terms, with the grammar validated per tier, the fallback-ignores-availability rule stated on every resolved chain, and the manual's cross-checks applied, from Fallback IP wiring to the topology-at-both-tiers warning. A method name explains one method; the word methods lists both catalogues.

      GSLB decision-flow explainer

    • Nuovo strumento

      New tool: GTM topology longest-match scorer

      Longest Match is a sort, not the pick, and this tool computes it the way BIG-IP DNS does: the records sort by source statement, destination statement and weight, then the scoring walk assigns each candidate its score from the first matching record, shadowing the rest. Paste topology records and a source line to see the sorted list with per-record rationale, which record scored which candidate, and why a heavy wildcard really can beat a light /32.

      GTM topology longest-match scorer

    • Infrastruttura

      Paste boxes now wrap long lines

      The input boxes on the F5XC service-policy explainer, the BIG-IP license explainer, and the Advanced WAF policy explainer were using the terminal-output text style, which never wraps: a long pasted line ran off the right edge behind a scrollbar. They now use the same wrapping paste-box style as every other tool. The dig and nslookup explainers keep the non-wrapping style on purpose, since aligned terminal output is the point there.

      F5XC service-policy explainer · F5 BIG-IP license explainer · AWAF declarative-policy explainer

    • Infrastruttura

      robots.txt now exists

      The footer's machine-readable row has linked robots.txt since the row shipped, but the file itself was never created, so the URL answered 404. It now serves a plain allow-all policy and points crawlers at llms.txt, the full machine-readable index.

    • Nuovo strumento

      New tool: LB-method chooser

      Paste an ltm pool and get its load-balancing method explained in F5's own terms, with cross-checks against the rest of the pool: ratio weights the mode ignores, missing connection limits that weighted modes require, slow-ramp pairing, priority-group activation, and the ignore-persisted-weight scope. Covers all 19 documented modes, takes a bare method name or the word methods for the full catalogue, and answers two questions with a sourced recommendation. Grounded in the tmsh ltm pool reference, K42275060, and K6406. Runs entirely in the browser.

      LB-method chooser

    • Contenuto

      Two new Learn articles: load-balancing methods and virtual server types

      BIG-IP Load-Balancing Methods, and What Each One Weighs walks the 19 modes along the two axes that organize them, static or dynamic and member or node, including the ratio rule from K6406 that explains half the field surprises. BIG-IP Virtual Server Types, and What Each One Actually Does covers Standard through Reject and the specialists, from the full-proxy handshake to the FastL4 packet path, grounded in K93100324 and K8082. Both in English and Portuguese.

    • Contenuto

      On building new tools, easier to read

      The funding story on the contribute page is the same text, now set for comfortable reading: a short intro, the three seats as a compact list, the infrastructure line, and the monthly total on its own line so the number is easy to find. Not a word changed in English or Portuguese, only the presentation.

      Contributing a tool

    • Funzionalità

      Clearer API error messages

      When a tools API call fails validation, the error now tells you something useful. Deliberate validation messages from the tool engines pass through unchanged, while internal runtime errors, like a missing field in a JSON body, map to a stable hint that points at the request schema in openapi.json instead of leaking implementation details.

      API reference

    • Infrastruttura

      Permanent redirects for locale-less URLs

      Bare URLs without a language prefix, like /f5 or /colophon, now answer with a permanent 301 to their English page instead of a temporary 302. The site ships English as its default and performs no header-based language negotiation, so the target never varies and search engines can safely consolidate on the localized address. Deep links keep working exactly as before.

    • Contenuto

      Funding transparency, updated

      The On building new tools section on the contribute page now tells the whole story: the three CONCORD seats (ANVIL on Claude, SCOUT on ChatGPT Plus, PRISM on Google AI Pro), the Cloudflare Workers plan, and the yearly domain fees, roughly USD 150 to 250 a month all in, with a link to the colophon for how the seats work. Buy Me a Coffee contributions go to that toolchain and nothing else.

      Colophon

    • Funzionalità

      F5 hub, easy to find

      Hub discoverability now lives on top of the Tools and Learn listings: a small pill on each page links straight to the F5 hub, keeping the header a simple four-item bar. The pills are generated from the same populated-vendor rule as the hub itself, so Fortinet, Netskope, and Extreme Networks will appear there automatically the day their first tools ship.

      F5 hub

    • Funzionalità

      Vendor hub pages

      ronutz.com/f5 is live: one page gathering every F5 tool, grouped by family, followed by every F5 article. The bare /f5 address permanently redirects to the English hub, and /tools/f5 and /learn/f5 land on the hub's anchored sections in every language. Fortinet, Netskope, and Extreme Networks hubs materialize automatically when their first tools ship; until then their addresses redirect to the tools index. A new build guard keeps the vendor namespace safe: no tool, article, or page may ever take a vendor name as its address.

      F5 hub

    • Funzionalità

      Five F5 tools renamed with permanent redirects

      The BIG-IP persistence cookie decoder, tcpdump builder, iRules event order, tmsh config explainer, and persistence method explainer now carry the f5- vendor prefix in their URLs, matching the rest of the F5 family. Every old address answers with a permanent redirect: page and .md URLs via static 301 rules in all sixteen languages, and old API slugs via a 308 from the worker so request method and body are preserved. The old names also remain as OMNIBOX aliases, so pasting or typing them still lands on the right tool.

      BIG-IP persistence-cookie decoder · BIG-IP tcpdump builder · iRules event-order explainer · tmsh config explainer · Persistence-method explainer

    • Nuovo strumento

      New tool: F5 BIG-IP license explainer

      Paste your /config/bigip.license, the full file or any fragment, and read it in plain language: whether it is BIG-IQ managed or licensed directly, the licensing dates with the K7727 upgrade verdict, the Registration Key and platform, active and optional modules with their per-module keys, Exclusive_version, Deny_version and Exclusive_Platform constraints, and every feature token. Key and signature values are never displayed, and nothing leaves the browser. The line grammar is grounded in two real, sanitized lab license files (one BIG-IQ managed, one direct) and in F5 K000160443, K7727, K3782, K7752, K42091606 and K02011230, verified against 5 golden vectors.

      F5 BIG-IP license explainer

    • Nuovo strumento

      F5 service check date now reads pasted licenses and tmsh output

      Paste your /config/bigip.license contents, any fragment of it, or the output of tmsh show sys license, and the tool picks out the service check date and answers the same upgrade-eligibility question, echoing the matched line for confirmation. Both published line forms are recognized: the file form (Service check date : 20151008, with flexible colon spacing) and the tmsh form (Service Check Date 2016/08/18). Quick manual entry is unchanged and remains the primary path. Grounded in F5 K3782 and K000160443 plus F5's published upgrade checklist, verified against 6 new golden vectors (20 total).

      F5 service check date

    • Funzionalità

      Sticky vendor filter, back-to-top, and a tidier footer

      Browsing the long lists is easier: the vendor filter on the tools and Learn indexes now stays pinned below the header while you scroll, and a small corner button returns you to the top once you are more than a screen down. The footer is consolidated too: its utility links now sit in three compact rows with dimmed separators, and the machine-readable row (llms.txt, robots.txt, feed.xml) now sits at the very end just above the build stamp, in smaller monospace, so the three read as the quiet file endpoints they are.

      All tools

    • Nuovo strumento

      New tool: F5 Advanced WAF declarative-policy explainer

      Paste a BIG-IP Advanced WAF (ASM) declarative policy (JSON) and get a section-by-section, plain-language reading grounded in F5's published schema, with security callouts that read the values: transparent enforcement means monitor-only, plus signature staging, X-Forwarded-For trust, Data Guard off, and cookies missing Secure or HttpOnly. Covers about 55 policy sections and honors the template-delta rule (an absent section means template default, not disabled). Decode-only, grounded in the F5 v17.1 declarative-policy schema (published versions v16.0 to v17.5), verified against 6 golden vectors built from F5's own example policies, with four Learn articles in English and Portuguese.

      AWAF declarative-policy explainer

    • Nuovo strumento

      New tool: F5 service check date

      Enter a BIG-IP version for the minimum service check date its license must carry, or enter a service check date for the newest version you can upgrade to and the newer branches you cannot reach yet. It encodes F5's published License Check Date table (K7727) and does the comparison entirely in the browser, with no clock and no network. Grounded in F5 K7727 and K8986, verified against 14 golden vectors, with three Learn articles in English and Portuguese.

      F5 service check date

    • Nuovo strumento

      New tool: SSRF URL classifier

      Paste a URL and see where it actually points: loopback, private (RFC 1918), link-local, cloud metadata (169.254.169.254 and the IPv6 and vendor equivalents), CGNAT, reserved, or public, with an SSRF risk level and plain-language reasons. It decodes the IP-obfuscation tricks that hide an internal address from a naive filter (decimal, octal, hex, short-form, and IPv4-mapped IPv6) and flags dangerous non-HTTP schemes and embedded credentials. It classifies purely from the string and never resolves DNS or issues the request (D-53). Grounded in RFC 1918/3927/6598/3986 and the OWASP SSRF cheat sheet, verified against 26 golden vectors, with six Learn articles in English and Portuguese.

      SSRF URL classifier

    • Funzionalità

      Public roadmap page

      A public roadmap at /roadmap, generated from the live build catalogue so it is always current: every planned tool grouped by family, plus a running count of what has already shipped. Linked from the footer and the Share-an-idea page so proposals can check what is already planned and avoid duplicates.

      Roadmap

    • Funzionalità

      Footer shows a last-modified timestamp

      The footer now shows a Last modified date and time, in UTC, written on every build so the site's currency is always visible at a glance.

    • Funzionalità

      Navigation and credibility restructure

      The main navigation now leads with what you use (Tools and Learn) alongside About, Training, and Contact. Certifications and Endorsements moved out of the top bar and now lead the About page as featured cards, and the Training page opens with the instructor and links to those credentials, so the professional showcase is cleanly separate from the tools.

      About

    • Nuovo strumento

      New tool: hash preimage finder

      Paste an MD5, SHA-1, or SHA-256 hash, choose an alphabet and length, and watch a bounded local brute-force search either recover a weak input in milliseconds or run out of keyspace on anything with real entropy. No dictionary, no wordlist, no precomputed table: pure local enumeration and hashing, capped so it only ever recovers trivially weak inputs. A teaching tool for why fast, unsalted hashes fail, pairing every result with the defenses (salting, slow KDFs, and algorithm choice). MD5, SHA-1, and SHA-256 are verified against published test vectors, and it runs only in the browser.

      Hash preimage finder

    • Funzionalità

      Every tool now has an HTTP API endpoint

      Every deterministic tool is now reachable over a simple HTTP API at /api/v1/&lt;tool&gt;, driven by a single registry so the API and its published OpenAPI specification stay in lockstep with the toolbox as tools are added. Capabilities that would be abused as an unbounded search on shared infrastructure are explicitly excluded and remain browser-only. The API reference page lists what is available.

      API reference

    • Nuovo strumento

      New tool: HTTP request translator

      Paste a curl command and get it both explained (method, URL, every header, the body with its real Content-Type, auth, cookies, and each flag) and translated to fetch, a raw HTTP/1.1 request, HTTPie, and Python requests. A single local parse drives both views. It gets curl's -d Content-Type default right (form-encoded, not JSON) and warns on --insecure, plaintext http, and credentials in the URL. Local and offline.

      HTTP request translator

    • Nuovo strumento

      New tool: CVSS vector decoder

      Paste a CVSS v3.1 vector and get the Base score computed and mapped to None through Critical, with Temporal and Environmental scores when those metrics are present and every metric spelled out. Pure scoring math implemented from the FIRST.org specification and validated against officially published reference scores. Local and offline.

      CVSS vector decoder

    • Nuovo strumento

      New tool: F5XC service policy explainer

      Decode an F5 Distributed Cloud service policy and get its rules explained in evaluation order: the match criteria, the action, and the first-match logic that determines allow or deny. Decode-only and offline.

      F5XC service-policy explainer

    • Nuovo strumento

      New tool: nslookup output explainer

      Paste nslookup output and get it explained: the server and port queried, whether the answer is authoritative, each record returned, and the common warnings. A companion to the dig output explainer. Local and offline.

      nslookup output explainer

    • Nuovo strumento

      New tool: XML decoder

      Paste XML and get a structural tree view plus a security analysis: entities are surfaced and the parser is XXE-safe, flagging external-entity and billion-laughs patterns without ever resolving them. Decode-only and offline.

      XML decoder

    • Localizzazione

      OIDC tool now fully localized in all 16 locales

      The OIDC decoder's entire interface - input labels, badges, panels, claim categories and field labels, the assessment reasons, and the authorization-code flow diagram - is now translated across all 16 locales.

      OIDC decoder

    • Nuovo strumento

      New tool: dig output explainer

      Paste dig output and get every section explained: the header and flags, the question, and each answer, authority, and additional record, along with the query timing. Local and offline.

      dig output explainer

    • Nuovo strumento

      New tool: text diff

      Compare two blocks of text and get a line-by-line diff with additions, removals, and unchanged context. Runs entirely in the browser; nothing is uploaded.

      Text Diff

    • Nuovo strumento

      New tool: TOTP / HOTP

      Generate and verify TOTP and HOTP one-time codes (RFC 6238 and RFC 4226) from a shared secret, with the time step, counter, and digit count shown. Golden-vector tested; local and offline.

      TOTP / HOTP

    • Nuovo strumento

      New tool: BIG-IP tcpdump builder

      Build a correct F5 BIG-IP tcpdump command from a plain description: the right interface syntax (including the :nnn peer-flow form), host and port filters, and capture options, with each part explained. Local and offline.

      BIG-IP tcpdump builder

    • Contenuto

      oidc: authorization-code flow diagram

      The OIDC tool now shows a theme-aware diagram of the OpenID Connect authorization-code flow, from the authorization request through token exchange, ID token validation against the JWKS, and the optional UserInfo call. Each step names the same discovery-document endpoint the decoder reports.

      OIDC decoder

    • Localizzazione

      cipher key-exchange groups panel now in all 16 locales

      The post-quantum key-exchange groups reference is now translated across all 16 locales, so its labels and explanations read natively instead of falling back to English.

      Cipher-suite decoder

    • Funzionalità

      cipher: post-quantum key-exchange groups reference

      The cipher tool now includes a reference for the TLS supported_groups - the key-agreement groups negotiated separately from the cipher suite - with the post-quantum ML-KEM hybrids featured. X25519MLKEM768 (0x11EC), SecP256r1MLKEM768, and SecP384r1MLKEM1024 are shown alongside the classical ECDHE and finite-field groups, each flagged by type, post-quantum status, and recommended/obsolete state. Backed by a golden-vector-tested name and code-point decoder.

      Cipher-suite decoder

    • Localizzazione

      x509 Certificate Transparency panel now in all 16 locales

      The SCT panel's labels and explanatory text are now translated across all 16 locales, so embedded Certificate Transparency timestamps read natively instead of falling back to English.

      X.509 inspector

    • Funzionalità

      x509: decode embedded Certificate Transparency SCTs

      The X.509 decoder now decodes the signedCertificateTimestampList extension (RFC 6962) instead of just naming it: each embedded SCT's version, log ID, logged-at timestamp, and signature algorithm are shown. Structural decode only - the SCT signatures are not verified, which would need the CT log's public key. Golden-vector tested against hand-built SCT lists and validated end-to-end against a certificate carrying the extension.

      X.509 inspector

    • Localizzazione

      CSR decoder UI now in all 16 locales

      The CSR decoder's interface (input labels, result cards, the requested-extension and attribute labels, and the error messages) is now translated across all 16 locales (40 strings each), so the tool reads natively instead of falling back to English.

      CSR decoder

    • Nuovo strumento

      New tool: CSR decoder

      Decode a PKCS#10 certificate signing request (RFC 2986) entirely in the browser: subject, public key, requested SANs and extensions, the legacy challenge-password and unstructured-name attributes, and the self-signature. A CSR is a request, not a certificate, so there are no validity dates, serial, or issuer to read. Deterministic, golden-vector tested against OpenSSL-generated RSA, EC and Ed25519 requests, and never uploaded.

      CSR decoder

    • Localizzazione

      Certificate renewal planner UI now in all 16 locales

      The planner's interface (input labels, result cards, the SC-081v3 schedule table, the projection, and the guidance notes) is now translated across all 16 locales (44 strings each), so the tool reads natively instead of falling back to English.

      Certificate renewal planner

    • Localizzazione

      Planner Learn articles now in Brazilian Portuguese

      The five certificate renewal planner articles (the 47-day schedule, validity windows, DCV/SII reuse, renewing with ACME and ARI, and public vs private PKI) are now translated to Brazilian Portuguese, bringing pt-BR to parity with English for this set.

      Certificate renewal planner

    • Contenuto

      Learn: five articles on certificate lifetimes and renewal

      Five new Learn articles back the certificate renewal planner: the CA/Browser Forum path to 47-day certificates, how validity windows and renewal lead time work, the shrinking DCV and SII validation-reuse periods, renewing on time with ACME and ARI, and why the rules bind public TLS but not private PKI. English first; other locales follow.

      Certificate renewal planner

    • Localizzazione

      Remaining static pages fully localized

      The Share-an-idea feedback page, plus the last English-fallback paragraphs on the colophon, API, and license pages, are now translated across all sixteen languages, bringing every non-article static page to full locale parity. The feedback page now explicitly invites bugs, mistakes, and inaccuracies.

    • Contenuto

      Decomposition diagram added to the syslog PRI decoder

      The syslog PRI decoder now shows how a single PRI integer splits into its two fields - dividing by 8 gives the facility and the remainder gives the severity - with the worked example of PRI 134.

      Syslog PRI decoder + encoder

    • Contenuto

      Construction diagram added to the HMAC generator

      The HMAC generator now shows the two-pass construction - the key XORed with an inner pad around the message and hashed, then XORed with an outer pad around that result and hashed again - the structure that makes HMAC resistant to length-extension.

      HMAC

    • Contenuto

      Key-matching diagram added to the JWKS explainer

      The JWKS explainer now shows how a verifier selects a key - a JWT header's kid is matched against the keys in the set, picking the one with the same kid to check the signature.

      JWKS explainer + key matcher

    • Contenuto

      Anatomy diagram added to the JWT decoder

      The JWT decoder now shows the token's three base64url segments - header, payload, and signature - colour-coded and joined by dots, with the header and payload bracketed as the signing input that the signature is computed over.

      JWT decoder

    • Contenuto

      Flow diagram added to the SAML decoder

      The SAML decoder now shows the SP-initiated web-browser SSO round trip - the AuthnRequest, the redirect to the identity provider, authentication, the signed assertion, and the POST back to the service provider - so a decoded message can be placed in the wider flow.

      SAML decoder

    • Nuovo strumento

      New tool: certificate renewal planner

      The first of a certificate-lifecycle set. Enter a TLS certificate's issue and expiry dates to see its validity length, whether that length fits the CA/Browser Forum SC-081v3 schedule (the 398 -> 200 -> 100 -> 47-day reduction running to 2029), the renewal cadence it implies and how that escalates at every future cap, the domain and identity validation-reuse windows for its issuance era, and a recommended renew-by date. All offline, in your browser; publicly trusted TLS certificates only.

      Certificate renewal planner

    • Funzionalità

      SSL profile explainer now shows the data path

      Decoding a client-ssl or server-ssl profile now draws the BIG-IP SSL data path (client, BIG-IP, pool member) and lights up the TLS leg the profile actually governs: a client-ssl profile on the client-side leg it terminates, a server-ssl profile on the server-side leg it initiates, with the profile named on that leg. The note spells out the offload-versus-re-encrypt consequence. This closes the Tier 1 SVG retrofits. Vector, theme-aware, parsed entirely in the browser.

      F5 SSL profile explainer

    • Funzionalità

      IPv6 tool now shows the address structure

      Decoding an IPv6 address now draws its 128 bits as eight hextet cells over a 0-128 bit ruler, with the prefix boundary drawn at the actual /N, shading the network prefix apart from the host portion and naming the 64-bit interface identifier when the split lands on /64. With no prefix supplied, a dashed line marks the conventional /64 boundary instead. The fourth of the Tier 1/2 SVG retrofits, and the right shape for 128 bits where a per-bit grid would not fit. Vector, theme-aware, all in the browser.

      IPv6 toolkit

    • Funzionalità

      CIDR analyzer now shows the address layout

      Alongside the binary bit-grid, a subnet now gets an address-layout strip: the network address and the broadcast address as reserved cells at each end, with the usable-host span shaded between them and the first/last host range named. A /31 or /32 collapses to a single all-usable bar, since RFC 3021 reserves neither network nor broadcast there. The third of the Tier 1/2 SVG retrofits. Vector, theme-aware, computed entirely in the browser.

      CIDR / subnetting

    • Funzionalità

      x509 tool now shows the chain of trust

      Decoding a certificate now draws a small chain-of-trust diagram (root CA, intermediate CA, end-entity) and highlights where the pasted certificate sits: a self-signed certificate lights up the root, a CA certificate the intermediate, and an ordinary certificate the leaf, with its subject and issuer named and the self-signed case called out. The second of the Tier 1/2 SVG retrofits. Vector and theme-aware; the certificate never leaves the browser.

      X.509 inspector

    • Funzionalità

      PKCE tool now shows the flow as a diagram

      The PKCE generator gains an inline sequence diagram of the S256 authorization-code flow (generate a code_verifier, derive the code_challenge, carry it on the /authorize request, get an authorization code, send the verifier on the /token request, and have the server re-derive and compare before issuing tokens), colour-coded by who acts (app vs authorization server). It is the first of the Tier 1/2 SVG retrofits across existing tools. Vector and theme-aware; nothing about the tool leaves the browser.

      PKCE helper

    • Nuovo strumento

      iRule event order is live

      Toggle the profile stack on a BIG-IP virtual server (client-SSL, HTTP, server-SSL, pool, or FastL4) and see the order the common iRule events fire, from CLIENT_ACCEPTED through CLIENT_CLOSED, as a color-coded timeline (the toolbox's first inline diagram) and an ordered list, with the conditional events (TCP/HTTP collect, LB failure, 100 Continue) called out and where each one slots in. The sequence is pinned to F5 Clouddocs and the DevCentral event-order capture. Five Learn articles ship alongside it. It is a model of documented behaviour that runs entirely in the browser and never contacts a device.

      iRules event-order explainer

    • Nuovo strumento

      Unix time converter is live

      Paste a Unix timestamp, whose unit (seconds, milliseconds, microseconds, or nanoseconds) is read from its magnitude and stated back to you, or an ISO-8601 date, and get the instant in every common form: the UTC calendar breakdown with weekday and day-of-year, ISO 8601, RFC 3339, the HTTP date, and the timestamp in all four units. Negative timestamps and the Year 2038 boundary are flagged. Five Learn articles ship alongside it. The conversion is pure date math that runs entirely in the browser; a Now button and a relative-to-your-clock line are the only parts that read the wall clock.

      Unix time converter

    • Nuovo strumento

      F5 SSL profile explainer is live

      Paste a tmsh client-ssl or server-ssl profile and get its role, the TLS protocol matrix derived from the options field (which version each no- flag permits or blocks), and a 🟢/🟡/🟠/🔴 security read covering chain building, renegotiation, SNI, OCSP stapling, and mutual-TLS validation, with each setting explained. Five Learn articles ship alongside it. Parsing runs entirely in the browser; it never contacts a device.

      F5 SSL profile explainer

    • Funzionalità

      Two F5 iControl REST tools on the roadmap

      Queued an iControl REST path explainer that decodes /mgmt/tm/... URLs, the tilde-encoded ~partition~ paths, and the query options and shows the matching tmsh path, and an iControl REST stats decoder that flattens F5's deeply nested stats JSON into readable key-values. Both are offline and never contact a device.

      Roadmap

    • Contenuto

      Licensing and colophon copy updated across all locales

      The license, colophon, and API copy were reworded in every live language to match how things work now: each tool is self-contained and runs entirely in the browser, with no upstream engine imported at runtime. The determinism and privacy guarantees are unchanged.

      License · Colophon

    • Funzionalità

      Two Expect (Tcl) tools on the roadmap

      Queued an Expect script explainer that breaks down spawn, expect, send, and timeout blocks and flags pitfalls like hardcoded credentials and a missing timeout, and an Expect pattern tester for the glob, -re, and -ex match modes. Both are static and offline; neither runs a script.

      Roadmap

    • Infrastruttura

      CIDR is now self-contained

      The CIDR tool was the last piece still calling an external compute package; its single-subnet analysis (cidrAnalyze) has been brought in-house, with output verified byte-for-byte against what it replaced. The site no longer depends on any external engine at runtime.

      CIDR / subnetting

    • Nuovo strumento

      New tool: Regex Toolkit

      Compile, test, and explain JavaScript regular expressions in one place: live matches with positional and named capture groups highlighted, a plain-language token breakdown of what the pattern does, and a static check that warns before a catastrophic-backtracking (ReDoS) pattern runs against your text, so that a single keystroke cannot freeze the page. Ships with three Learn articles. Everything runs in the browser.

      Regex toolkit

    • Funzionalità

      CIDR tool: octet bit visualization and a netmask slider

      The subnet mode now draws the address as 32 bits across its four octets, showing the binary and decimal value of each octet and highlighting the network bits apart from the host bits. A prefix-length slider lets you drag the mask from /0 to /32 and watch the split move.

      CIDR / subnetting

    • Funzionalità

      F5 packet-trailer tools added to the roadmap

      Two tools derived from the Wireshark f5ethtrailer dissector were added to the roadmap: an F5 Ethernet trailer decoder (Low, Medium, and High details: ingress, slot, TMM, VIP, flow and peer IDs, RST cause, peer info; it ignores the TLS keylog provider) and an F5 TCP RST cause explainer.

      Roadmap

    • Nuovo strumento

      JWKS explainer and key matcher

      A new tool that breaks down a JSON Web Key Set: it explains every key (type, use, algorithm, size), flags any private or symmetric key material that should never appear in a published set, and matches a JWT to its key by kid. It completes the JWT and OIDC verification story and never fetches a jwks_uri. Shipped with three Learn articles.

      JWKS explainer + key matcher

    • Nuovo strumento

      Syslog PRI decoder and encoder

      A new tool that decodes a syslog PRI value (such as 134) into its facility and severity, or encodes a facility and severity back into a PRI and its on-the-wire form. It notes the common network-device facility defaults (FortiGate local7, Cisco ASA local4, F5 BIG-IP local0). Shipped with three Learn articles.

      Syslog PRI decoder + encoder

    • Funzionalità

      SIEM event formats added to the roadmap

      Four logging and SIEM tools were added to the roadmap: a CEF decoder (ArcSight), a Splunk HEC event explainer, a LEEF decoder (QRadar) in a new logging category, and an F5 high-speed logging and log-profile explainer.

      Roadmap

    • Funzionalità

      Roadmap expanded with syslog, API, and cloud-native tools

      Nine tools were added to the roadmap. Two syslog tools (a PRI decoder and encoder, and a full RFC 5424 / RFC 3164 message parser) and four API tools (a JWKS explainer and key matcher, a CORS preflight explainer, a webhook signature verifier, and an OpenAPI explainer) were ranked by value. A cloud-native set (Kubernetes NetworkPolicy, RBAC, and kubeconfig explainers) was added in a new category at the end of the queue.

      Roadmap

    • Nuovo strumento

      F5 cipher-string explainer

      A new tool that parses an F5 BIG-IP cipher string, explains every keyword and operator, and flags weak or deprecated choices alongside forward secrecy. It recognizes the pre-built rules (f5-default, f5-secure, f5-ecc). It deliberately does not reproduce the exact per-TMOS ordered suite list, which depends on the platform version. Shipped with three Learn articles.

      F5 cipher-string explainer

    • Nuovo strumento

      Persistence-method explainer

      A new tool that reads BIG-IP persistence profiles and virtual servers, explains each method (cookie, source-address, SSL, universal, hash, and more) with its real failure modes, and resolves each virtual's primary and fallback persistence chain. It reuses the tmsh parser and pairs with the persistence cookie decoder. Shipped with three Learn articles.

      Persistence-method explainer

    • Nuovo strumento

      tmsh config explainer

      A new tool that parses a BIG-IP bigip.conf snippet and explains its objects, virtual servers, pools, monitors, profiles, and iRules, in plain English. Shipped with three Learn articles.

      tmsh config explainer

    • Nuovo strumento

      JSON / YAML converter

      A new tool that converts between JSON and YAML in the browser, flagging dropped comments, expanded anchors, and number-precision limits. Useful for moving between F5 AS3/DO (JSON) and Kubernetes, Ansible, or CI (YAML). Shipped with three Learn articles.

      JSON ↔ YAML converter

    • Nuovo strumento

      JSON formatter and inspector

      A new tool that formats and validates JSON with precise error locations, structural statistics, and duplicate-key detection. Shipped with three Learn articles.

      JSON formatter & validator

    • Nuovo strumento

      URL inspector

      A new tool that parses a URL into its components, decodes query and path encoding, and explains each part, introducing the new HTTP and web tool category. Shipped with three Learn articles.

      URL inspector

    • Nuovo strumento

      BIG-IP persistence cookie decoder

      A new tool that decodes F5 BIG-IP persistence cookies across all four encoding formats, detects encrypted cookies, and can also encode a cookie from a pool member. Shipped with Learn articles.

      BIG-IP persistence-cookie decoder

    • Nuovo strumento

      OIDC decoder

      A new tool that decodes OpenID Connect ID tokens (reusing the JWT engine) and .well-known/openid-configuration documents, flagging missing claims, the none algorithm, and PKCE method. It never calls the jwks_uri. Shipped with Learn articles.

      OIDC decoder

    • Nuovo strumento

      SAML decoder

      A new tool that decodes and explains SAML assertions and metadata using an XXE-hardened XML parser, with the mandatory external-entity rejection. Shipped with Learn articles.

      SAML decoder

    • Nuovo strumento

      Security headers analyzer

      A new tool that analyzes HTTP security response headers across 25 headers with detailed reason codes, the first tool of the ranked build sprint. Shipped with five Learn articles.

      Secure headers

    • Funzionalità

      Tool roadmap ranked and catalogue reorganized

      The full tool roadmap was ranked end to end and persisted into the catalogue. The tools index was reorganized to list tools alphabetically, with Learn articles in a curated reading order.

      Roadmap

    • Funzionalità

      Search upgraded with result badges

      Site search moved from grouped results to pure relevance ranking, and now labels each result as a tool, an article, or a page.

    • Nuovo strumento

      base64 rebuilt as a unified codec

      The base64 tool was rebuilt into a single codec covering base64, base64url, base32, base16/hex, and percent-encoding, with four new Learn articles.

      Base64 / Base32 / Hex / Percent codec

    • Nuovo strumento

      CIDR tool rebuilt

      The CIDR tool was rebuilt and moved to its own canonical page, with new Learn articles.

      CIDR / subnetting

    • Infrastruttura

      Locale scaffolding expanded

      Additional locales were scaffolded, bringing the total to 42, including right-to-left layout support for the relevant scripts.

    • Localizzazione

      Sixteen languages completed

      Full message packs were completed across all sixteen live locales. A machine-translation notice and a Contribute page were added, with downloadable language packs for community review.