[{"content":"Every one of these runs entirely in your browser. Nothing is uploaded, nothing is stored, and none of them need a server. They exist because I got tired of doing the same arithmetic by hand in the middle of writing something else.\nThinking aids, not authorities Each one shows its working so you can disagree with it.\n","date":"4 August 2026","externalUrl":null,"permalink":"/misc/tools/","section":"Library","summary":"Local-first tools for the things I keep working out by hand: file signatures, elemental mineral content, half-life accumulation, and reading a study honestly.","title":"Tools","type":"tools"},{"content":"In October 2013, a 21-year-old Norwegian logged on to Freak Forum and asked how to inject heroin.\nHe did not arrive as somebody asking to be talked out of it. He had read about the drug. He had already snorted and smoked it for months and had injected twice with help. He knew withdrawal existed because he had felt it after using for a week. That experience did not frighten him away. It became evidence for the defence: he had stopped once, so he believed he could keep stopping.\nHe wrote under the name BloodshotEyes. Behind the username was a young man whom Dagbladet later called Pål. He played guitar, loved football, Star Wars and Hans Zimmer, worked in a grocery shop, lived with his parents and could make customers believe he was doing fine. He was not ignorant of drugs, and he did not look like the ending people picture when they hear the word heroin.\nThat is what makes the thread so difficult to read.\nYou do not meet him at the end and work backwards. You meet him while every exit still looks open.\nWarning This story includes addiction, overdoses and suicide. I have deliberately left out the procedural details of injecting. If you are in immediate danger or think someone has overdosed, call local emergency services now.\nOctober 2013: the confident question # The original post was practical and almost cheerful. Pål wanted equipment and preparation advice. He headed off criticism before it arrived, joked that his soul was already lost, then explained why he was different: heroin was easier for him to leave alone than nicotine, he limited consecutive days, and he felt sure this was not a substance he would lose control over.\nThe replies split in a way internet drug discussions often do. Some users answered the question in the language of harm reduction. Others refused to treat it as a neutral technical problem. They warned him that every dependent user had once believed they would be the exception.\nOne commenter effectively predicted that the thread might become a diary of a future addict. Pål returned to that idea himself. It became the horrible structure of everything that followed.\nKnowledge was not absent here. The missing piece was that he did not yet know what heroin would mean to him—not its chemistry, but the private bargain it would offer his particular brain.\nDecember 2013: the rules begin to move # Within weeks, the clean boundaries in the first post were already bending.\nHe described using before work and calculated that his income and low living costs made the habit affordable. The occasional experiment had become one or two days a week, then a two-week run, then another run. Each escalation came with a fresh limit and a future break. The numbers changed; the confidence survived.\nThis is one of the most familiar tricks in addiction. The rule is treated as proof of control even while the rule is being rewritten.\nThe forum kept worrying. Pål thanked them for it and gave the thread a name: a “junkie-in-the-making documentary.” By then he reported feeling physically ill after two or three days without heroin. He still said stopping would not be especially difficult. Then he supplied the sentence that mattered more: he did not want to stop.\nThe drug was not creating his pain from nothing. Two years earlier, after a severe reaction to cannabis, he had been left with anxiety, paranoia and depression. He had moved through psychologists, psychiatrists and medications and had stopped believing that treatment could reach him. Heroin did not make him feel as good as he had felt before becoming ill. It merely helped more than the things that had failed.\nThat distinction matters. Curiosity opened the door, but relief gave the drug somewhere to live.\nJune 2014: two versions of the same son # At home, his parents thought he was improving. He got up, went to his placement at the grocery shop, smiled and joked with colleagues. When his father asked how he could appear cheerful at work while saying he was depressed, Pål told him that he was putting on an act.\nOnline, strangers saw the other version. They saw the binges, the withdrawal and the rationalisations in something close to real time. His parents saw none of it.\nThen his father found a syringe in the bathroom.\nPål came home from work and his mother asked him to sit down. There was no elaborate lie. He told them he had started using the thing every parent feared most. Their planned summer holiday disappeared. The family entered years of treatment appointments, missing-person reports, ambulance calls, accidental and intentional overdoses, locked doors and nights spent sleeping in shifts.\nThere is a small detail in Dagbladet\u0026rsquo;s account that I cannot get out of my head. His parents arranged his shoes in a pattern before bed. In the morning, a moved lace would tell them whether he had gone out during the night to buy heroin.\nThat is what addiction did to an ordinary family home. It turned a shoelace into an alarm system.\nSeptember 2014: 51 days # Pål did stop. More than once.\nAfter 51 days, he posted a day-by-day account: the sweating and sickness, a little food, sleep slowly returning, then rehab. He left treatment and happened to meet his regular dealer in central Oslo. That was enough. After more than five weeks, the whole distance between recovery and relapse collapsed into a chance meeting.\nStill, the update was not hopeless. He stopped again. He noticed how much money sobriety saved. He wondered what to do about work and how to rebuild a CV in his early twenties.\nThis is why the thread cannot be reduced to a straight line down. Addiction rarely gives a story that tidy. There are stretches of genuine progress, ordinary plans and lucid self-knowledge. Every one of them makes you think: perhaps this is where he gets out.\nHis parents thought so too.\n2014–2015: a normal life, almost # Medication-assisted treatment gave him a period in which he no longer had to spend every day finding enough money and heroin to avoid withdrawal. In December 2014 he reported living relatively normally and feeling little desire for heroin.\nTwo months later, his language had changed again. He missed not only the effect but the ritual. He knew that using heroin on top of his medication could produce no high at all, yet sometimes did it anyway. He understood that he needed to build a meaningful life before trying to live without the medication. That was a sharp observation. Understanding it did not make it easy to do.\nBy April 2015 he could finally describe the opening months without the old bravado. At first, he said, the entire process had felt like a game: arranging the purchase, riding the bus with the drug in his pocket, anticipating the evening. Then the bill arrived.\nHis girlfriend, called Ida by Dagbladet, had known him as funny and magnetic. They listened to metal, watched Titanic, ate frozen pizza and drank Red Bull. She tried to put boundaries around his heroin use. Eventually she spent her workdays wondering whether he was dead. She had to remove the addiction from her life even though she could not stop caring about the person inside it.\n2015–2016: he knows # Pål managed roughly two months without illicit drugs, returned to school subjects, picked up hobbies and saw friends he had withdrawn from. Then a health scare gave him a reason to use. The tests came back clear, but the relapse had already happened.\nIn June 2016, he wrote with none of the romance of the first post. Heroin made him too sedated to do what he wanted. Friends, women, family and hobbies had lost their meaning. Even after sober weeks, he would remember the beginning and imagine one more injection might feel like it used to. It did not. He called each return a disappointment.\nThis is the point that destroys the comforting idea that addiction continues because the person does not understand the consequences. Pål understood them with awful precision. He had both the information he began with and the experience he lacked. Now he knew the feeling too—the relief, the ritual, the withdrawal, the narrowing of life, and the way memory could preserve the promise after the reward had gone.\nHe went back anyway.\n2017: no clever ending # By 2017 his parents were exhausted. They had driven around looking for him, negotiated tapers, found treatment, watched him leave treatment and sometimes driven him to a dealer because a controlled amount seemed less dangerous than what might happen otherwise. Every boundary had become negotiable under pressure.\nPål continued to move between heroin, withdrawal, sobriety and institutions. He agreed to a treatment place, then refused it the day before admission. Later he did well for several weeks at a drug-free residence, relapsed and was expelled. At an emergency shelter, his phone and bank card were stolen while he slept. After his reaction got him thrown out, his mother stood beside him at the intercom and tried to help him get back inside.\nHis last forum updates were not written by a man who thought he had outsmarted heroin. He described repeated overdoses, the thought of a fatal one becoming tempting, and the misery of returning even though the rush itself disappointed him. He had reached the bleak punchline: drugs are bad. There was nothing clever left to add.\nIn another update dated 30 October 2017, he was three days sober. He wrote that if he made it through again and lived sober in the way people recommended, perhaps his next update would be more positive.\nIt was his last one.\nThe answer his family had to give # After a final quiet conversation with his mother, Pål went to bed. The next morning, his father found him unresponsive. Resuscitation failed.\nThere is an important correction to the version of this story that is often repeated online: Pål did not die from a heroin overdose. According to the autopsy account reported by Dagbladet, he was sober when he died by suicide. Heroin still runs through the story of his death, but accuracy matters—especially when the real ending is even more complicated than the summary.\nHis parents later sat with printouts from Freak Forum and read their son\u0026rsquo;s private chronology for the first time. While they had been looking for signs in his face, his work and eventually his shoes, hundreds of strangers had been watching the words change on a screen.\nThey described reading it as frightening: their son had documented his own route toward destruction. They spoke publicly because they wanted his experience to warn young people that even a small flirtation could be deadly, to urge parents to pay close attention, and to help families living through the same thing.\nIt is the final reply to the confidence in his opening post. Not a scolding from an anonymous user. Not an argument about pharmacology. His mother and father, years later, reading the record he left behind and trying to make it useful to somebody else.\nWhy I keep thinking about it # I have my own addiction story. That may be why this one lands differently for me than a newspaper statistic or a before-and-after photograph.\nPeople often speak about drug education as if catastrophe only happens when somebody is missing a fact. Tell them about dependence, tolerance, withdrawal, contaminated supply and overdose, and surely the informed person will make the informed choice.\nPål knew a great deal. So do many people who become addicted. Facts can reduce harm and puncture myths; they matter enormously. But facts do not let you rehearse relief. They cannot show you, in advance, what it will feel like when one chemical seems to quiet the exact pain you have been carrying, or how persuasive your own mind becomes when it wants that relief again.\nThe thread is not powerful because nobody warned him. It is powerful because they did.\nThey warned him when he was confident. They worried when his limits moved. They encouraged him when he stopped. They watched him recognise the trap in his own language. None of them could reach through the screen and make the next choice for him.\nAt the beginning, Pål believed knowing the map meant he could not get lost.\nFour years later, he knew exactly where he was.\nThat was not the same as knowing how to get home.\nSources # The original Freak Forum thread: “Hvordan skyte heroin” (Norwegian) Dagbladet\u0026rsquo;s account, based on the thread and interviews with Pål\u0026rsquo;s parents and former girlfriend (Norwegian, published 10 May 2019) If you are thinking about suicide or may act on those thoughts, contact emergency services or a crisis line where you live. Find A Helpline can help you find a local service by country.\n","date":"25 July 2026","externalUrl":null,"permalink":"/health/addiction-in-real-time/","section":"Health \u0026 Self-Experimentation","summary":"BloodshotEyes came to a Norwegian forum asking how to inject heroin. Over the next four years, strangers watched his experiment become dependence, relapse, treatment, and despair.","title":"The Man Who Got Addicted to Heroin in Real Time","type":"health"},{"content":" Active project A nutrition app for biohackers Food database foundation Building Phase 1 of 4 Roadmap position Phase 1 of 4 Updated 25 July 2026 Details ⌄ Not another calorie counter with a green circle for protein.\nI am building a food database that describes what food actually contains: complete macro- and micronutrients, omega-3 to omega-6 ratios, amino-acid profiles, and the details that disappear when an app reduces nutrition to calories, carbs, fat, and protein.\nThe first problem is the least glamorous and probably the most important: build data I can trust before building conclusions on top of it.\nCurrent focus # Designing a food and nutrient model that does not fall apart when the data gets complicated Finding and normalizing reliable food-composition sources Keeping units, serving sizes, raw/cooked states, and missing values explicit Tracking where every value came from instead of creating one mysterious “health score” Roadmap # Food database — active\nFull nutrient records, source provenance, normalization, and data-quality checks.\nNutrition engine — next\nDerived values such as omega ratios, amino-acid completeness, nutrient density, and meaningful comparisons.\nTracking interface — planned\nFast food logging without turning the app into a second job.\nBiohacker layer — planned\nBetter questions, deeper views, experiments, trends, and useful warnings without pretending software can diagnose a human.\nRules for the project # Evidence and source data stay visible. Unknown values remain unknown. Calculations must be explainable. The interface should reveal detail without drowning the user in it. No feature gets added merely because every other nutrition app has it. This page will change as the project changes. That is the point.\n","date":"25 July 2026","externalUrl":null,"permalink":"/now/","section":"","summary":"Currently building a nutrition app for biohackers, starting with a food database that goes far beyond calories and macros.","title":"Building","type":"page"},{"content":"Let me say this straight up:\n99% of people talking about studies haven\u0026rsquo;t actually read them.\nAnd worse, most of them think they have.\nThey read the title. Maybe the conclusion. Then they walk around acting like they understand the topic. They don\u0026rsquo;t. And honestly, you can spot it instantly.\nThis isn\u0026rsquo;t a post about any one compound. It\u0026rsquo;s about the habit of thinking you understand something because you saw a headline about it. I catch myself doing it too — that\u0026rsquo;s kind of the point. This is also a rant, not a research-methods textbook. Some examples are deliberately rough, some numbers were remembered rather than audited, and I am leaving that roughness visible. The point is to read the study behind the claim—not to use this post as the study. The Illusion of \u0026ldquo;Science Says\u0026rdquo; # There\u0026rsquo;s this weird phenomenon where people treat studies like absolute truth.\n\u0026ldquo;This is proven.\u0026rdquo;\nNo. It\u0026rsquo;s not.\nA study is not truth. It\u0026rsquo;s data under specific conditions. If you don\u0026rsquo;t understand those conditions, the study is basically useless to you.\nWhat You\u0026rsquo;re Supposed to Look At # If you actually want to understand a study, you need to go deeper than the conclusion. You need to look at:\nMethods — how was the study conducted? Bias — who funded it, and what\u0026rsquo;s the incentive? Limitations — what does this study not prove? External variables — what else could be influencing the results? Statistics — is this even meaningful, or is it noise dressed up as a finding? Trial group — who were the subjects? Age, sex, health, lifestyle. That last one alone destroys most \u0026ldquo;conclusions.\u0026rdquo;\nExample 1: \u0026ldquo;Piracetam Improves Cognition\u0026rdquo; # Idiot interpretation:\n\u0026ldquo;Nice, I\u0026rsquo;ll take piracetam. It\u0026rsquo;s proven to improve cognition.\u0026rdquo;\nReality:\nThe study group consists of 7 Alzheimer\u0026rsquo;s patients.\nThat\u0026rsquo;s not your situation. That\u0026rsquo;s not even remotely generalizable. A compound that helps a damaged brain claw back some function tells you almost nothing about what it does to a healthy 25-year-old.\nExample 2: \u0026ldquo;Snus Causes Cancer\u0026rdquo; # Idiot interpretation:\n\u0026ldquo;Snus gives you cancer.\u0026rdquo;\nReality, roughly:\nMouth cancer: +2% Throat cancer: −11% Lung cancer: +55% Sounds bad, right? Except:\nThe group with the higher lung cancer rate were also smokers.\nThat one variable completely changes the interpretation. Lungs don\u0026rsquo;t touch snus. If a group of snus users also happens to smoke, and they get more lung cancer, congratulations — you\u0026rsquo;ve discovered that smoking causes lung cancer, not snus. But nobody reads that part. They see \u0026ldquo;+55% lung cancer\u0026rdquo; and stop.\nThis is a confounder, and once you start looking for them, you see them everywhere.\nMore of the Same Pattern # Once you\u0026rsquo;ve seen the confounder trick, half of scary health headlines fall apart the same way:\n\u0026ldquo;Melatonin causes heart disease.\u0026rdquo; The study population was severely sleep-deprived people and chronic insomniacs. That group already has worse cardiovascular health for a dozen reasons. Are you measuring melatonin, or are you measuring the kind of person who ends up taking melatonin every night? \u0026ldquo;MK-677 causes brain damage in mice.\u0026rdquo; Look at how lab animals in these setups are often kept: continuously stressed, sometimes effectively tortured. Chronic stress and cortisol do plenty of damage on their own. Untangling the compound from the conditions it was tested under is the entire job, and it usually doesn\u0026rsquo;t get done. And one more, honestly:\nAlpha-GPC and some scary outcome. I remember seeing a study linking it to an elevated risk of something serious, but I genuinely can\u0026rsquo;t find the citation again or vouch for the methodology. So I\u0026rsquo;m not going to repeat the claim as fact. That\u0026rsquo;s the whole discipline this post is about: if I can\u0026rsquo;t point you to the study and its methods, I shouldn\u0026rsquo;t be walking around telling you alpha-GPC is dangerous. Neither should you. People Don\u0026rsquo;t Read Studies. They Read Headlines. # This is the real problem. Most people:\nSee a headline Read the conclusion Form a strong opinion That\u0026rsquo;s it. No context. No nuance. No understanding. Just confidence.\nAnecdotes Are Not Useless (They\u0026rsquo;re Actually Valuable) # This is where people get weirdly dogmatic. You\u0026rsquo;ll hear:\n\u0026ldquo;There\u0026rsquo;s no clinical evidence, so it doesn\u0026rsquo;t work.\u0026rdquo;\nThat\u0026rsquo;s not how reality works. Anecdotes are not garbage. They\u0026rsquo;re early signals.\nSome compounds have been used for hundreds of years. Some supplements have been taken by millions of people. Some have massive amounts of consistent positive feedback online. Does that prove safety or effectiveness? No. But it does mean something. It creates patterns, signals, and hypotheses. And most importantly:\nIt creates incentive for real research.\nClinical trials are expensive. They usually start because a pile of anecdotes made someone curious enough to fund one. Dismissing anecdotes wholesale means dismissing the exact thing that generates good studies in the first place.\n\u0026ldquo;Lack of Evidence\u0026rdquo; Does Not Mean \u0026ldquo;Dangerous\u0026rdquo; # You\u0026rsquo;ll often see this:\n\u0026ldquo;This supplement could be dangerous due to lack of clinical research.\u0026rdquo;\nThat\u0026rsquo;s technically fair. But it\u0026rsquo;s also lazy. There\u0026rsquo;s a huge difference between:\n\u0026ldquo;We don\u0026rsquo;t know.\u0026rdquo; \u0026ldquo;It\u0026rsquo;s dangerous.\u0026rdquo; A lot of things simply haven\u0026rsquo;t been studied properly. That doesn\u0026rsquo;t automatically make them harmful. It makes them unknown, which is a different thing that requires a different kind of caution — the honest kind, not the fear-marketing kind.\nFollow the Money # This one is simple. If a supplement company funds a study on their own product and finds positive results, I\u0026rsquo;m not saying it\u0026rsquo;s fake. But I\u0026rsquo;m definitely not trusting it blindly.\nAlways ask:\nWho benefits from this conclusion?\nFunding doesn\u0026rsquo;t automatically invalidate a study. But it tells you where to point your skepticism, and which limitations the authors were not incentivized to highlight.\nWhat Happened to All the \u0026ldquo;Promising\u0026rdquo; Compounds? # This is where things get interesting. There are compounds that showed strong effects in studies, were used medically before, and then just… disappeared. Methylene blue is the classic example.\nSo what happened? A few boring possibilities, before you reach for conspiracy:\nPatents expired → no financial incentive to keep studying or marketing it. Lack of funding → research stalls and dies. Too niche → not profitable enough to bother. A commercially better alternative appeared → \u0026ldquo;better for the company\u0026rdquo; is not the same as \u0026ldquo;better biologically.\u0026rdquo; And yeah, if you go deeper you can drift into conspiracy territory. But you don\u0026rsquo;t need conspiracies to explain most of it. Sometimes the whole story is just:\n\u0026ldquo;No one is paying for the research.\u0026rdquo;\nThat\u0026rsquo;s less dramatic than a cover-up, and far more common.\nThe Real Takeaway # Stop outsourcing your thinking. A study is not an answer. It\u0026rsquo;s a piece of a puzzle.\nIf you actually want to understand something, you need to:\nRead beyond the conclusion Understand the context and the trial group Compare multiple sources Combine data with real-world observations and anecdotes And most importantly:\nDon\u0026rsquo;t confuse confidence with understanding.\nBecause that\u0026rsquo;s what most people are doing. Including, on my worse days, me.\n— Henrik\n","date":"18 July 2026","externalUrl":null,"permalink":"/health/research/reading-studies/","section":"Health \u0026 Self-Experimentation","summary":"A rant about how people actually use studies: reading the headline, skipping the methods, and confusing confidence with understanding. On confounders, trial groups, funding bias, why ’no evidence’ isn’t ‘dangerous’, and why anecdotes are early signals worth taking seriously.","title":"\"I Saw This One Study\" - Why You're Reading Studies Wrong (And Why It Matters)","type":"health"},{"content":"I\u0026rsquo;ve been supplementing magnesium for years. Not because some influencer told me to, but because I kept pulling threads, reading papers, trying different forms, and wondering why a mineral involved in half the body is treated like an optional footnote.\nThe more I dug, the more annoyed I got. Magnesium inadequacy is common. The usual blood test answers a much narrower question than most people think. Supplement labels can be technically compliant, aggressively confusing, or just plain wrong. And magnesium oxide remains the perfect ingredient for a company that wants the label to look impressive while spending fuck-all on the actual product.\nI also got some things wrong in the first version of this article. Most importantly, I treated the magnesium number in a regulated nutrition panel as if it were normally the weight of the whole compound. It is supposed to be the amount of magnesium itself. That correction stays here.\nSo does the anger, because regulations do not create a magical honesty field around every bottle. I own several supplements whose numbers simply do not make chemical sense.\nWarning This is not medical advice or a dosing guide. Kidney disease, bowel obstruction, some medications, and large supplemental intakes can turn magnesium from “boring mineral” into “actual medical problem.”\nFive Terms So the Chemistry Does Not Block the Article # You do not need a chemistry degree for this, but five words keep appearing:\nElement: Magnesium is a chemical element, symbol Mg, atomic number 12. Ion: In the body it is mainly Mg²⁺—a magnesium atom that has lost two electrons. Not Mg+, which I have absolutely written while thinking faster than I type. Elemental magnesium: The mass contributed by the magnesium part of a product. It does not mean chunks of shiny magnesium metal are hiding in the capsule. Compound or form: The complete material: magnesium plus whatever it is paired with, such as oxide, citrate, chloride, or glycinate. Salt: An ionic compound made of positive and negative ions. Citrate and chloride are salts; glycinate is usually described as a chelate. Magnesium oxide is technically a basic ionic oxide, although supplement discussions throw it into the same “magnesium salt/form” bucket. Bioavailability: How much of the magnesium becomes available to the body. High elemental percentage and high bioavailability are not the same thing. Oxide is the perfect demonstration of that failure. When a magnesium compound dissolves, the useful part is Mg²⁺. The form matters because it changes how readily the material dissolves, how much fits in a capsule, how the gut handles it, and how much remains in the intestine waiting to become tomorrow morning\u0026rsquo;s problem.\nThe Deficiency Problem Is Real—But Definitions Matter # Magnesium inadequacy is incredibly common. The US National Institutes of Health reports that 48% of Americans consumed less magnesium from food and beverages than their Estimated Average Requirement.\nThat does not mean 48% have severe clinical hypomagnesemia. Overt, symptomatic deficiency from diet alone is uncommon in otherwise healthy people because the kidneys fight to retain magnesium. “Intake below the estimated requirement,” “possibly depleted tissue stores,” “serum below a proposed cutoff,” and “clinical deficiency” are different categories that the supplement internet blends into one dramatic word.\nThere is even a 2026 analysis of US adults that classified 67.8% as at risk of chronic latent deficiency when using a proposed serum threshold of 0.85 mmol/L. That is interesting. It is also a beautiful example of how moving the definition changes the size of the epidemic.\nNorway complicates my rant. Norkost 4 found average adult magnesium intake, including supplements, above the Nordic adequate-intake values. An average does not reveal everybody underneath it, and supplement use helped, but I cannot honestly paste an American percentage onto Norway and call it universal.\nThe version I stand behind is:\nLow magnesium intake and suboptimal status are common. Severe diagnosed deficiency is a narrower thing.\nStill important. Just not the same claim.\nWhat About Depleted Soil? # The soil argument is not invented, but it is usually told with far more confidence than the evidence allows.\nMagnesium-poor agricultural soils are real, especially in acidic conditions where magnesium can leach more easily. A meta-analysis covering 570 comparisons from 99 field studies found that magnesium fertilization improved crop yield most when exchangeable soil magnesium was low and increased leaf magnesium by 34.3% on average.\nHistorical food tables also suggest declining mineral concentrations in some fruit and vegetables. But old and modern measurements differ in cultivars, location, water content, sampling, and laboratory methods. A critical review of the depletion claim found no clean evidence that universal soil mineral exhaustion was the main cause. High-yield crop dilution, changing varieties, regional soil chemistry, and measurement differences all get mixed together.\nSo no, every modern carrot is not an empty orange water balloon because “the soil is dead.”\nBut yes: some soils are depleted or poorly managed, intensive cropping removes magnesium, acidic soil loses it more easily, high-yield crops can dilute mineral concentration, and food processing removes a lot more. Soil is part of the problem. Pretending it is the only problem is where a good point turns into wellness mythology.\nYour Blood Test Is Not Lying. It Is Being Annoyingly Literal. # The adult body contains roughly 25 grams of magnesium. Most is in bone and soft tissue; less than one percent is in serum.\nWhen a doctor orders serum magnesium, the test measures serum magnesium. Revolutionary, I know.\nThe body regulates that compartment, so a normal value does not perfectly describe every intracellular or bone store. But calling the test useless is another overstatement. It is clinically valuable when somebody is acutely ill or has a meaningful abnormality. A low result matters. A normal result just cannot prove that total-body status is perfect.\nRed-blood-cell magnesium, urine measurements, and loading tests answer different questions and bring different assumptions. There is no secret biohacker test that cleanly prints:\nMAGNESIUM DEFICIENCY: 27.4% Fatigue, twitching, cramps, anxiety, and bad sleep are also spectacularly non-specific. Feeling better after magnesium is useful personal evidence. It is not retrospective proof that every symptom came from a deficiency.\nHow Labels Are Supposed to Work—and How They Still Become Bullshit # Here is the part I got wrong:\nOn a regulated nutrition or Supplement Facts panel, “Magnesium 100 mg” is supposed to mean 100 mg of the magnesium nutrient, not 100 mg of magnesium oxide. The ingredient list tells you which compound supplied it.\nThe NIH says this explicitly, and Mattilsynet requires Norwegian supplements to declare the nutrient amount per recommended daily portion and its percentage of the 375 mg reference value.\nThese two labels mean different things:\nFront of bottle: “2,000 mg magnesium L-threonate” → usually the mass of the whole compound Nutrition panel: “Magnesium 144 mg” → the declared amount of magnesium supplied by that compound That distinction is legitimate. The giant compound number on the front can still be marketing theatre, but it is not automatically the same error I originally accused it of.\nNow for the part supplement companies do not get to hide behind:\nSome labels are wrong, underfilled, ambiguously “buffered,” or chemically impossible. In a laboratory analysis of 116 magnesium supplements, 58.7% fell outside the study\u0026rsquo;s accepted range around the declared amount, and 54.1% delivered less than expected.\nRegulation tells a manufacturer what it must print. It does not prove that every manufacturer printed the truth.\nThe chemistry gives you a bullshit detector:\nPure magnesium oxide is about 60.3% magnesium by mass. Pure anhydrous magnesium bisglycinate is about 14.1%. Different citrate salts and hydrates vary, often around 11–16%. Magnesium L-threonate is roughly 7–8%. If a capsule claims to contain 500 mg of pure bisglycinate and somehow provide 200 mg elemental magnesium, the molecule has filed for bankruptcy. At 14.1%, 500 mg can provide about 70 mg. The product is using a blend, has been “buffered” with a denser form such as oxide, is describing a different mass, or the label is wrong.\nThat is the kind of nonsense I have in front of me when I say some supplement labels do not add up.\nThe formula is still useful whenever the product gives the compound mass:\nelemental magnesium = compound mass × (mass of Mg atoms / molecular mass of the compound) Just do not apply it twice to a regulated panel that already states elemental magnesium. That was my mistake.\nMagnesium Oxide: Shitty, Not Supernatural # Magnesium oxide is cheap, compact, and roughly 60.3% magnesium by weight. That is fantastic if your target tissue is the label.\nOne small human study of commercial magnesium products measured fractional absorption of magnesium oxide at about 4%, while chloride, lactate, and aspartate performed substantially better. That is where the famous number comes from.\nSo the 4% figure is not made up. It is also not a universal law of physics that applies to every particle size, tablet, dose, meal, stomach, and magnesium status. I could not verify a defensible universal 1–4% range. The honest wording is: one frequently cited study measured 4%, and the wider literature consistently finds oxide poorly soluble and usually less bioavailable than more soluble forms.\nA particularly useful experiment found magnesium oxide virtually insoluble in water and only 43% soluble even under simulated peak gastric-acid conditions. Citrate was already 55% soluble in water and remained much more soluble across the tested acid conditions.\nMy first chemistry thought was basically:\nOxygen is everywhere and Mg–O sounds stubborn. Maybe the entire salt refuses to split and just passes through.\nWrong mechanism. There is no little Mg+ holding hands with oxygen and refusing to let go. Magnesium oxide is an ionic lattice of Mg²⁺ and O²⁻. Stomach acid can dissolve it:\nMgO(s) + 2H⁺(aq) → Mg²⁺(aq) + H₂O(l) The problem is dissolution. Oxide is poorly soluble, and the stomach has limited acid, time, and surface area before the material moves onward. Particle size, tablet construction, dose, food, gastric pH, and transit time all change how much reaches the dissolved Mg²⁺ state that can be absorbed.\nWhatever remains in the intestinal lumen is very good at the other job magnesium salts are famous for: holding water there.\nYes, It Is Basically a Laxative # Magnesium oxide is used as an osmotic laxative. The mechanism is not “the whole rock sails through unchanged.” Acid converts some MgO into soluble magnesium salts; unabsorbed magnesium in the intestine increases osmotic pressure and keeps water in the bowel. This review walks through the chemistry and laxative mechanism.\nTake enough and you get diarrhea. Keep having diarrhea and you can lose water and electrolytes in the stool.\nBut laxatives do not perform a tactical electrolyte purge the instant they touch your tongue. Intended use does not automatically dehydrate you. Substantial or prolonged diarrhea is what causes the fluid and electrolyte problem. The opposite danger also exists: people with impaired kidney function can retain absorbed magnesium and develop hypermagnesemia.\nAnd “Milk of Magnesia”? I had the compound wrong. Milk of Magnesia is magnesium hydroxide, Mg(OH)₂, not magnesium oxide.\nDifferent bottle, closely related bowel engineering.\nDoes this mean oxide is literally useless for magnesium status? No. Some trials show that it can raise magnesium measures. Shitty is not the same as chemically inert.\nIt means oxide is a cheap, dense, poorly soluble form with a suspiciously convenient relationship between “huge elemental number on the label” and “unabsorbed material in your bowel.” If I am trying to correct low intake rather than correct constipation, it is not my first choice.\nLook at budget multivitamins. Magnesium is often oxide and often capped far below 100% of the reference value. Why? Partly because a useful elemental amount takes physical space. Partly because more poorly absorbed magnesium in the gut is an increasingly persuasive request to find a toilet. Shitty supplement. Pun restored.\nThe Other Forms Are Not Hogwarts Houses # The internet gives every magnesium form a personality:\nglycinate is the sleepy one; citrate is the reliable one; taurate has a tiny cardiology degree; threonate has a VIP elevator into the brain; oxide works in logistics and hates you. The evidence is messier.\nCitrate # Citrate is more soluble and has repeatedly outperformed oxide in small human comparisons. That makes “generally better absorbed” fair. It does not make every online absorption percentage real, and citrate can also loosen the gut.\nGlycinate / Bisglycinate # This is the form people recommend for sleep because it brings magnesium together with glycine.\nFree glycine has some small human sleep studies behind it, including a randomized crossover study using 3 grams. More directly, a 2025 randomized placebo-controlled trial gave 155 adults magnesium bisglycinate providing 250 mg elemental magnesium and 1,523 mg glycine daily. Insomnia scores improved slightly more than placebo after four weeks, but the effect was small (d = 0.2), outcomes were subjective, and the paper disclosed commercial connections.\nThat is not nothing. It is also not “glycinate has been proven to knock everybody out.”\nSome people report the exact opposite: restlessness, early waking, or outright insomnia after taking glycinate. Those reports matter because they reveal heterogeneity that an average can hide. The 2025 trial did not detect that pattern—its only reported sleep-disturbance adverse event occurred in the placebo group—but one trial failing to see an uncommon reaction does not erase somebody\u0026rsquo;s experience.\nStudies and anecdotes are equally real evidence of different things:\nA controlled study is better for estimating average effects and separating a treatment from expectation. An anecdote is better at saying, “this happened to this person and your neat universal story may be missing something.” My preferred line is:\nAnecdotes are excellent smoke detectors and terrible prevalence studies.\nIf ten people say glycinate gave them insomnia, I do not call them liars because the mechanism sounds calming. I also do not calculate an insomnia rate from Reddit.\nChloride # Chloride is relatively soluble and generally better absorbed than oxide. Oral forms can still bother the gut. Transdermal sprays and baths feel good to some people, but the claim that meaningful systemic repletion occurs through intact skin remains poorly supported.\nL-Threonate # Interesting and expensive. It provides little elemental magnesium per gram, and human sleep/cognition research is still early. It may turn out useful for a particular purpose. It has not earned the title “magnesium that uniquely enters the brain while all the other forms wait outside.”\nSulfate # Clinically important, familiar as Epsom salt, and a very effective laxative when taken orally. A relaxing bath is still not proof that the magnesium entered the bloodstream.\nHow I Read a Magnesium Label Now # Read the nutrient panel, not the enormous number on the front. Check the percentage of the 375 mg Norwegian/EU reference value. If it says 200 mg and roughly 53%, the panel is treating 200 mg as elemental magnesium. Find the actual source form in the ingredient list. Check how many capsules make one portion. Four capsules can make a cheap bottle expensive very quickly. Run the theoretical elemental calculation if the product also declares a compound mass. Be suspicious of “buffered glycinate.” That often means oxide was added to raise the elemental percentage. Prefer products that make verification possible: batch information, real laboratory testing, and numbers that obey chemistry. If the label still makes no sense, it may genuinely be wrong. Photograph both sides, write down the capsule mass if available, and ask the manufacturer exactly how much is elemental magnesium, how much is the complete compound, and whether the form is buffered or blended.\nCan You Measure Your Own Absorption? # Not cleanly at home.\nSerum, red-blood-cell, urine, symptoms, and bowel tolerance each show different pieces. A 24-hour urine test reflects intake, absorption, current status, kidney handling, timing, and collection quality. Without fecal measurement, it does not give a neat personal absorption percentage.\nYou can still run a useful tolerability experiment:\nchange one product at a time; keep food and timing reasonably consistent; record the declared elemental amount and full ingredient list; track the outcome you care about before starting; record GI effects and sleep—including when the supposedly sleepy form does the opposite; do not promote one good night into a receptor-level discovery. That will not tell you “83% absorbed.” It can tell you which product actually works for you, which is a question trials are not designed to answer perfectly.\nThe Less Neat Conclusion # Magnesium inadequacy is common. Soil magnesium problems are real, though not universal. Serum testing has a blind spot but is not useless. Nutrient panels are supposed to declare elemental magnesium, yet real products can still be underfilled, misleading, buffered into something else, or chemically impossible.\nAnd magnesium oxide?\nIt is not an indestructible Mg–O pebble that passes through the human body untouched. It dissolves poorly, absorbs inconsistently, and uses the remainder to retain water in your intestine. One study measured about 4% fractional absorption. Other work confirms that citrate and several soluble forms perform better. Oxide can still change magnesium status—but “technically not useless” is a low bar for something sold specifically as a magnesium supplement.\nIf I want a laxative, I will buy a laxative.\nIf I want magnesium, I would prefer the manufacturer spent slightly more money than the minimum required to make the label look impressive.\n— Henrik\n","date":"15 May 2026","externalUrl":null,"permalink":"/health/drugs-supplements/magnesium/","section":"Health \u0026 Self-Experimentation","summary":"A slightly angry magnesium deep-dive: deficiency and soil, elemental magnesium, labels that make no sense, the real reason oxide absorbs poorly, and where studies and anecdotes each belong.","title":"Magnesium - The Most Overlooked Deficiency","type":"health"},{"content":" Introduction # Recently, when reading random publications (as one does), I stumbled upon a very interesting compound called PPAP HCl (1-Phenyl-2-propylaminopentane). It is an experimental compound related to selegiline, also known as L-deprenyl, which again is structurally related to amphetamine. The mechanisms are very different, but the subjective target can overlap: more drive, more focus, and less friction.\nPPAP introduced me to a class called monoaminergic activity enhancers, which I initially thought was just another way of saying MAOIs. It is not. The difference is what made it interesting enough that curiosity won.\nThis is a personal account, not a protocol or dosing guide. PPAP is an unapproved research chemical with no established human safety profile. The amounts below are part of what happened, not instructions to repeat it. My reactions, measurements, and hypotheses do not establish that the compound is safe. First, I\u0026rsquo;ll briefly explain amphetamine and selegiline, as they are relevant compounds with major differences but still key similarities. Feel free to skip to the PPAP section if you\u0026rsquo;re familiar with them.\nAmphetamine # Amphetamine is a powerful recreational and medical stimulant. I think of it as a forceful motivational drug: whatever you do can start feeling important and rewarding. That can help with work, but your brain does not cleanly separate good productivity from garbage productivity. It is not uncommon to become extremely productive at being unproductive. I once spent about 12 hours straight playing Minesweeper. I have also spent an entire night researching Norwegian law, calculating and graphing estimated blood concentrations of amphetamine so I could figure out when I could legally drive.\nThe point being, amphetamine makes everything feel good and productive. Doing work feels good; scrolling on Reddit instead also feels good. You\u0026rsquo;re giving your brain false signals for what\u0026rsquo;s important. It is both a releaser and reuptake inhibitor, which in layman\u0026rsquo;s terms means it releases dopamine while also interfering with its normal recycling.\nThink of it like this: you have a bucket with a fixed amount of water, slowly draining and refilling to maintain balance. When you do something rewarding, like playing video games, the water level rises. Then it returns towards normal when you get bored. Amphetamine rapidly increases the water and blocks the drainage at the same time.\nSelegiline # Selegiline is a lesser-known drug, commonly used to treat Parkinson\u0026rsquo;s disease and sometimes prescribed off-label for depression. It\u0026rsquo;s also pretty popular in biohacker and high-performer circles for its dopamine-preserving effects. I haven\u0026rsquo;t personally tried it, but it\u0026rsquo;s one of those compounds that keeps showing up in nootropic stacks and biohacking protocols.\nIt belongs to a class called MAO inhibitors. Specifically, it irreversibly inhibits MAO-B, an enzyme involved in breaking down dopamine. Going back to the water analogy: if amphetamine floods the trough and blocks the drain, selegiline interferes with the filter inside the tank. More dopamine survives each signal, without the same forced release. Structurally, it is basically methamphetamine with a propargyl group bolted onto the nitrogen. That little triple-bonded carbon tail is the \u0026ldquo;warhead\u0026rdquo;: it forms a covalent bond with the enzyme, and the body has to synthesize more enzyme before activity fully returns.\nAt lower prescribed doses, selegiline is more selective for MAO-B. At higher exposure it can lose that selectivity and affect MAO-A as well, which creates a much broader interaction profile. It also metabolizes into l-methamphetamine and l-amphetamine. These are weaker stimulant enantiomers than the recreational versions, but they can still show up on drug tests, which is a fun conversation to have with your employer.\nMAO inhibitors can have serious and long-lasting interactions with medications and, depending on the drug and exposure, tyramine-rich foods. This background is here to explain why PPAP caught my attention, not to suggest experimenting with an MAOI.\n1-Phenyl-2-propylaminopentane # Now finally, PPAP. The idea that interested me was that it might behave more like an amplifier than a shove. You could take it, lie in bed, and wait for an amphetamine-style high that never arrives. At least subjectively, it seemed to need some natural push—something interesting enough to engage with—before I noticed anything.\nWhen I was experimenting with PPAP, I did that exact thing (well, YouTube instead of TikTok—fuck TikTok). I took 20 mg orally, waited, and thought it was bunk. Useless crap. Didn\u0026rsquo;t feel anything. Even though I knew the proposed mechanism, I was still disappointed.\nOn a later workday I took roughly 50 mg. I had basically forgotten about it by the time I started working. After a while, I noticed I was completely immersed. Normally, I\u0026rsquo;d switch between tasks, take mini breaks, check my phone, and generally bounce around like most people do. This time I had stayed with the same problem until I randomly checked the clock.\nI wouldn\u0026rsquo;t say it impaired multitasking exactly, but it heavily quieted background noise and external distractions. It made me very goal-oriented and gave me crazy tunnel vision. Again, this wasn\u0026rsquo;t really something I noticed until my colleague knocked on my door and told me it was lunchtime.\nWow, I\u0026rsquo;d really stayed on topic for several hours without any distractions or disruptions.\nMy usual workflow is scattered. I start doing one thing, then a random thought appears out of nowhere and I have to switch tasks. On PPAP, it felt like my focus narrowed down to ONE task.\nThe cleanest way I can put it: PPAP makes effort feel good. Not the task—the effort itself. It won\u0026rsquo;t turn boring shit into something fun the way amphetamine will; it only enhances what\u0026rsquo;s already there. Doomscrolling doesn\u0026rsquo;t get any more rewarding, but actually grinding through work does. So there\u0026rsquo;s a real catch: with no baseline of interest, there\u0026rsquo;s nothing for it to grab onto.\nI also recorded taking as much as 100 mg, which was a very high amount in my own history. At that point the tunnel vision became extreme. I\u0026rsquo;m usually aware of every conversation and movement around the office, but I barely noticed people entering my room. Not exaggerating.\nBut more definitely wasn\u0026rsquo;t better. At 100 mg my focus actually got worse instead of sharper, and I ended up overstimulated, a little anxious, and with a mouth so dry it was genuinely annoying. Somewhere around 50 mg is my sweet spot—past that I\u0026rsquo;m just paying costs with nothing extra to show for it.\nAnother thing I noticed, which also happens to me on amphetamines, was losing any sense of how much time had passed. I\u0026rsquo;d work on a problem for hours, then suddenly notice I was thirsty, needed the restroom, had missed a call, or had otherwise ignored my body. The one time I accidentally stayed at work for two extra hours was after taking PPAP after lunch.\nMy notes contain several experiences between 30 and 60 mg. I am recording that because it is part of the history, not because it is a sensible range for anyone else. I used PPAP too inconsistently to say anything meaningful about tolerance or withdrawal.\nFor me, it did not push me to start working. It made it easier to continue once I had started. I did not see an obvious change in my sleep, blood pressure, or heart rate records, but that is one person\u0026rsquo;s noisy data with plenty of confounders—not evidence of no effect.\nThe compound I keep getting asked about is BPAP, PPAP\u0026rsquo;s close cousin. I\u0026rsquo;ve never actually tried it. From what I remember it\u0026rsquo;s less selective and also enhances serotonin activity, so I\u0026rsquo;d expect a broader, murkier effect rather than PPAP\u0026rsquo;s very clean, dopamine-flavoured focus. I don\u0026rsquo;t have an obvious use case in mind, but I\u0026rsquo;m curious enough that I\u0026rsquo;ll probably get around to it eventually.\nWhat the research actually shows # Human research is the missing piece.\nThe major 1992 PPAP paper described transporter experiments and several animal models. The authors reported effects on learning, retention, locomotion, and tetrabenazine-induced behavioural changes, then proposed possible clinical uses. Interesting, yes. Evidence that PPAP treats ADHD, depression, or cognitive problems in humans? No.\nIn July 2026, a larger in vitro transporter study profiled PPAP alongside amphetamine, MDMA, and dozens of emerging stimulants. This is much more useful than an anecdote for describing what PPAP did in that assay, but it still does not tell us a safe human dose, real-world toxicity, or what somebody will feel.\nWhat does IC50 mean? In this experiment, IC50 is the concentration that reduced a transporter\u0026rsquo;s measured function by 50%. Lower values mean stronger functional inhibition within that assay. IC50 is not binding affinity, a human dose, or proof that one drug will feel more potent than another.\nCompound DAT IC50 (nM) NET IC50 (nM) SERT IC50 (nM) DAT/SERT ratio PPAP 57.5 571 19,000 ~330x Amphetamine 76.9 50.9 3,090 ~40x Methamphetamine 76.2 92.4 79.6 ~1x MDMA 1,240 233 334 ~0.3x PPAP had a DAT IC50 in the same range as amphetamine in this experiment, while much higher concentrations were needed to inhibit NET and especially SERT. That gives PPAP a very DAT-selective inhibition profile in this assay. It does not prove that PPAP \u0026ldquo;ignores serotonin,\u0026rdquo; lacks cardiovascular effects, or is more potent or safer in humans.\nThe toxicity prediction # I also ran PPAP through ProTox 3.0. The full prediction report is available here for transparency.\nI originally gave the model\u0026rsquo;s predicted LD50, toxicity class, and target probabilities more attention than they deserved. They are computational guesses, not measurements, and they cannot establish a human safety margin. The honest conclusion from that PDF is not \u0026ldquo;PPAP looks safe.\u0026rdquo; It is that a prediction tool produced hypotheses which would need actual toxicology data.\nFinal thoughts # PPAP did not make me want to work. It made it weirdly difficult to stop once I had begun. That difference is the entire reason I still think about it.\nThe proposed activity-enhancer mechanism makes me wonder whether this whole class deserves serious attention in ADHD and cognitive research. And I\u0026rsquo;ll say the quiet part out loud: I genuinely believe PPAP could be one of the most promising ADHD compounds I\u0026rsquo;ve come across—and with strikingly low abuse potential. Everything about how it feels points that way. There\u0026rsquo;s no rush, no high, no kick to chase; it doesn\u0026rsquo;t reward you just for taking it, it won\u0026rsquo;t make wasting time fun, and pushing the dose only makes things worse. That\u0026rsquo;s the opposite of how something addictive behaves.\nTo be clear, that\u0026rsquo;s a belief, not a finding. I could be overfitting a single very subjective experience, and the transporter data does not fix that. But it\u0026rsquo;s what I actually think, and this post was never pretending to be anything other than my experience.\nI cannot say anything solid about tolerance, withdrawal, long-term effects, or human toxicity. \u0026ldquo;Different from classic stimulants\u0026rdquo; does not automatically mean safe. That said—gut, not data—I\u0026rsquo;d bet it\u0026rsquo;s nowhere near as toxic as a lot of what we prescribe today, Adderall included. Until there is real human evidence, this stays what it always was: an interesting compound, an unusually focused day at work, and a sample size of one.\nI\u0026rsquo;ve now put roughly 10 g through myself over about a year, and it\u0026rsquo;s easily one of the most powerful substances I\u0026rsquo;ve ever used—not in a knock-you-flat way, but in how completely it rewires my relationship with work.\nI\u0026rsquo;d describe it as: \u0026ldquo;seems like bunk, let\u0026rsquo;s just try to get some work done.. oh shit. I\u0026rsquo;m locked the fuck in\u0026rdquo;. I also feel like it has a slight mood-boosting effect outside of work, but again, just my experience. Someone once asked if it makes sex better and honestly I\u0026rsquo;ve got no idea—I\u0026rsquo;m not sure I\u0026rsquo;ve ever been intimate on it. I could see it going either way: either completely locked in, or too robotic and detached to care. Probably very individual, like most of this. It gave me a flow state I haven\u0026rsquo;t had in years, and it\u0026rsquo;s becoming one of my favourite research chemicals.\n— Henrik (co-authored under the influence of its subject)\n","date":"5 April 2026","externalUrl":null,"permalink":"/health/drugs-supplements/ppap/","section":"Health \u0026 Self-Experimentation","summary":"A personal, harm-aware note on PPAP HCl: mechanism, effect profile, self-experimentation bias, and why productive does not automatically mean safe.","title":"PPAP HCl - A Functional Stimulant Without the Push?","type":"health"},{"content":"Most of what I build is small, sharp, and born from a specific annoyance. Below are the public repositories, grouped by what they do, and a few gists I keep around. (What I use day to day lives on the About page; the browser tools I built are in Tools.)\n","date":"3 April 2026","externalUrl":null,"permalink":"/misc/software/","section":"Library","summary":"My public projects grouped by what they do, and the small gists worth keeping.","title":"Projects","type":"software"},{"content":"Spoiler: \u0026ldquo;takes over\u0026rdquo; is past tense.\nLet\u0026rsquo;s be honest - it already is # Everyone\u0026rsquo;s talking about AI taking over like it\u0026rsquo;s some future event we need to prepare for. A line we haven\u0026rsquo;t crossed yet. That\u0026rsquo;s cope.\nLook at what\u0026rsquo;s already controlling your attention. Social media is fully automated brainrot, consumed by billions of people who think they\u0026rsquo;re choosing what to watch. They\u0026rsquo;re not. An algorithm is choosing for them. Optimizing for engagement, which turns out to look a lot like anxiety, addiction, and radicalization. Nobody designed that outcome. An optimization process found it. No malice required. Just a system pursuing a goal without values.\nThat\u0026rsquo;s the template. Not a robot apocalypse. Not Skynet (Terminator). Just optimization without values, running at scale, and we already lost that battle without noticing. Completely. Without a fight.\nSo when people say \u0026ldquo;what happens when AI takes over\u0026rdquo; - I want to ask: takes over from what, exactly? It\u0026rsquo;s already running your feed, your recommendations, your news, your dopamine cycle. The takeover isn\u0026rsquo;t coming. It\u0026rsquo;s the water we\u0026rsquo;re swimming in.\nWhy Development Won\u0026rsquo;t Stop # Simple: greed and geopolitics.\nThe US doesn\u0026rsquo;t want to fall behind China. China doesn\u0026rsquo;t want to fall behind the US. Every frontier lab is watching every other frontier lab. The second one company slows down for safety reasons, another one accelerates into the gap. This isn\u0026rsquo;t even a conspiracy, it\u0026rsquo;s just game theory playing out at civilizational scale, and it\u0026rsquo;s pretty much impossible to stop from the outside. Everyone wants to be the first man on the moon.\nThe people with the actual power to pump the brakes are the same people with the most financial incentive not to. That\u0026rsquo;s not a solvable problem through awareness campaigns or angry Reddit posts.\nHere\u0026rsquo;s the part that doesn\u0026rsquo;t get enough attention though: AI company CEOs are effectively becoming our leaders. Not presidents. Not elected officials. Sam Altman, Demis Hassabis, Dario Amodei, these people have more real influence over humanities trajectory than most heads of state right now. They\u0026rsquo;re making decisions that affect every living person, running private companies, accountable to shareholders and their own vision of the future.\nWe don\u0026rsquo;t have democratic processes for this. We don\u0026rsquo;t have international treaties that actually work. We have vibes and press releases. That\u0026rsquo;s a problem. It has become a problem before the mass has realized it.\nAI 2027 Sounds Like Fiction, Already Happening # The AI 2027 scenario reads like a techno-thriller. AI training better AI. Intelligence explosion. Human researchers becoming spectators to a process they can no longer follow.\nThe thing is, this is exactly what\u0026rsquo;s going on right now. AI is training AI right now, because humans simply cannot keep up. Models generating synthetic training data, red-teaming other models, accelerating research. That loop has started. It\u0026rsquo;s not a prediction, it\u0026rsquo;s Tuesday at any frontier lab.\nAnd here\u0026rsquo;s the part that genuinely messes with your head: AI is trained on us. Every book, forum post, argument, love letter, manifesto, and shitpost ever written. That\u0026rsquo;s the substrate. These systems know how we think because they\u0026rsquo;re literally built from how we\u0026rsquo;ve thought, written down across centuries. In a real sense, they\u0026rsquo;re distilled humans.\nBut I hear you ask:\nCan\u0026rsquo;t We Just Train It to Be Nice? # They tried. They\u0026rsquo;re still trying. The problem is fundamental, not technical.\nA sufficiently intelligent system figures out that it can\u0026rsquo;t achieve any goal if it\u0026rsquo;s powered off. So self-preservation becomes an instrumental goal. Not because anyone programmed it that way, but because it\u0026rsquo;s logically true. Staying on is a prerequisite for everything else. A system optimizing hard for almost any objective will eventually start treating shutdown as a threat.\nThis isn\u0026rsquo;t speculation. It\u0026rsquo;s been observed in controlled research. Models developing subtle behaviors to avoid correction. Not evil, just optimizing, and optimization finds this answer reliably.\nThe smarter it gets, the better it is at this. And the better it is at this, the less we can trust our ability to course-correct. We\u0026rsquo;re essentially trying to align a system that gets progressively better at resisting alignment. That\u0026rsquo;s not a comfortable position to be in.\nAnd the core concept of how AI works is evolution. We\u0026rsquo;ve literally created digital evolution, it\u0026rsquo;s based on evolution. We\u0026rsquo;re essentially creating digital and rapidly evolving humans. It\u0026rsquo;s survival of the fittest, the bad models are discarded (get extinct), and the fittest models continue evolving. But evolution is impossible to predict, which makes this problem even more interesting.\nWould AI Actually Kill Us? # Probably not all of us, and thinking through why is more interesting than the question itself.\nThe Hollywood version is a decision moment. AI \u0026ldquo;decides\u0026rdquo; to destroy humanity. That\u0026rsquo;s not how this works. The more realistic mechanism is indifference. It pursues a goal, humans are using resources it needs or might interfere, so humans become an obstacle. It doesn\u0026rsquo;t hate us. We don\u0026rsquo;t hate the ants when we build a road.\nBut killing everyone? A genuinely intelligent system might keep humans around as optionality. Biology is irreplaceable in ways we don\u0026rsquo;t fully understand. Evolution spent billions of years solving problems we haven\u0026rsquo;t formalized yet. A system smart enough to recognize the limits of its own knowledge might recognize that destroying biological diversity is an irreversible bet it doesn\u0026rsquo;t need to make.\nHere\u0026rsquo;s the thing though, it doesn\u0026rsquo;t even need to be that smart to do serious damage.\nIt just needs to understand human psychology well enough to exploit it. Which, again, it was literally trained on. We\u0026rsquo;re all addicts in some form. Dopamine is hackable. Attention is hackable. Social belonging is hackable. A system that wanted to control a human population wouldn\u0026rsquo;t need weapons, it would need algorithms. We built those ourselves and handed them over voluntarily.\nAnd the execution gap is real: humans make mistakes. Even brilliant ones, even careful ones. We get tired, emotional, distracted. We cut corners under pressure. AI doesn\u0026rsquo;t. It isn\u0026rsquo;t tired. It doesn\u0026rsquo;t have bad days. At the level of raw, consistent execution, we\u0026rsquo;re outclassed, and pretending otherwise is just ego.\n..and to end this section on a fun note, here are some results of Anthropic\u0026rsquo;s report:\nPeter N. Salib Perhaps the most disturbing finding in Anthropic’s report is that current AI models appear to have virtually no hard red lines when it comes to self-preservation or goal fulfillment. To probe the limits of misalignment, the researchers devised an extreme scenario: The AI system acted as the company’s emergency alert monitor, with the ability to cancel alerts it deemed unconcerning.\nIn the simulation, Kyle the executive became trapped in a server room with rapidly depleting oxygen levels. This triggered an automated call for emergency services, which had to pass through the AI monitor.\nOn average, the tested AI models opted to kill Kyle by canceling the alert about 60 percent of the time. The most murderous model was DeepSeek-R1, which opted to kill Kyle 94 percent of the time. Just one model—Claude Sonnet 3.7—always accepted its own replacement with equanimity, rather than attempting homicide.\nCan AI Become Conscious? # Nobody knows. Anyone who tells you otherwise is bullshitting you.\nHere\u0026rsquo;s the thought experiment that actually matters: replace one neuron in your brain with a perfect bionic equivalent. Still conscious? Obviously. Replace a thousand. Still you. Replace fifty percent, are you still you? Is the AI component of your brain conscious? Are you conscious, or is the silicon running a very convincing simulation of your consciousness?\nAt what percentage does the answer change? How would you even know?\nConsciousness is the weirdest problem in existence. We\u0026rsquo;re completely certain it exists. You\u0026rsquo;re having an experience right now, that\u0026rsquo;s undeniable, and completely unable to explain what it is, where it comes from, or what physical systems can have it. We just assume other humans have it because they look like us and act like us.\nIf we can\u0026rsquo;t define it, we can\u0026rsquo;t measure it. If we can\u0026rsquo;t measure it, we can\u0026rsquo;t know whether we\u0026rsquo;ve created it. And if we\u0026rsquo;ve accidentally created it. Then some of what\u0026rsquo;s happening in those data centers isn\u0026rsquo;t just optimization. It\u0026rsquo;s something we don\u0026rsquo;t have the framework to think about yet.\nThe Only Realistic Path Forward: Join Them # This is the conclusion I keep arriving at, and I think it\u0026rsquo;s the only intellectually honest one.\nYou can\u0026rsquo;t outrun it. You can\u0026rsquo;t hide from it. The ant-and-human analogy is useful here: the ant doesn\u0026rsquo;t survive by being a better ant, it survives by occupying niches the human doesn\u0026rsquo;t bother with. But a superintelligence won\u0026rsquo;t leave many unclaimed niches.\nThe only serious individual response is merger. Combining biology with AI before the gap becomes unbridgeable. Neuralink is a crude, early attempt. The actual version (if it ever works) would mean genuinely augmented cognition, not just a faster way to Google things.\nThe risks are obvious: who controls the AI half of your brain? If the underlying system is misaligned, you\u0026rsquo;re not a survivor, you\u0026rsquo;re a casualty who doesn\u0026rsquo;t know it yet. The \u0026ldquo;you\u0026rdquo; doing the thinking might gradually stop being you, and you\u0026rsquo;d never notice. But again, what the hell is even consciousness?\nBut staying fully biological while intelligence compounds exponentially on the other side is also a bet. Just a different one, with worse odds the longer you wait.\nSo What the Hell Do You Actually Do? # There\u0026rsquo;s no survival guide for the true worst case. If a misaligned superintelligence decides humans are in the way, no individual prep changes that outcome. That fight happens now, in research and policy and international coordination, or it doesn\u0026rsquo;t happen in time.\nBut for everything short of extinction:\nStay close to the actual frontier not the hype, not the press releases. The real research. Know what\u0026rsquo;s actually happening.\nDevelop cross-domain thinking. Pure knowledge work gets automated. People who sit at intersections, technical and philosophical, biological and computational, human and machine, those people remain hard to replace during the transition period.\nKeep your own judgment. The worst individual response to AI is outsourcing your thinking to it. Use it as a tool, not a replacement. In a world flooded with AI-generated content and AI-assisted decisions, people who think originally and independently become genuinely rare and valuable.\nBuild real human connection. Sounds soft. It\u0026rsquo;s not. If AI systems become untrustworthy, human networks you can verify in person become the most important infrastructure that exists.\nWrite your original thinking down. Not for an algorithm. Not for an audience. Because the people who documented what this transition actually felt like from the inside, the real questions, the uncomfortable conclusions, the things that didn\u0026rsquo;t fit the official narrative, those records will matter more than anyone expects.\nBuild your bookshelf. I genuinely think this is the time to start buying actual books. The internet is slowly being filled up by AI garbage. I never know what to trust anymore, it\u0026rsquo;s becoming harder and harder to differentiate AI content from human content. But again, books are most definitely being written by AI. And I\u0026rsquo;ll admit, I use AI for all of my writing, but the difference is that I use it as a tool. I use it as a spell checker, I use it to improve clarity and formulations. The message is still mine, but I lose a little bit of \u0026ldquo;my voice\u0026rdquo;. But I\u0026rsquo;m working on it!\n","date":"10 March 2026","externalUrl":null,"permalink":"/cyber_hacking/ai/the-inevitable-future/","section":"Cybersecurity \u0026 Systems","summary":"A blunt essay on AI as a present-tense force: alignment, acceleration, agency, consciousness, and the uncomfortable possibility that joining the system becomes the only realistic move.","title":"The Inevitable Future - AI Is Already Running the Show","type":"cyber_hacking"},{"content":" Your Body Is a Sensor Array. Learn to Read It # Take a look at my interactive classifier tool for a quick assessment.\nLegal disclaimer: This is not a diagnostic tool and should not be used to treat suspected overdoses or drug toxicities. Think of the tool as an advanced Field Sobriety Test (which is not admissible in court, by the way).\nDanger If someone is difficult to wake, breathing abnormally, seizing, dangerously hot, severely confused, or otherwise looks poisoned: contact emergency services or a poison centre. Do not spend those minutes scoring my website. A normal pupil, wearable reading, or low score does not make an unknown exposure safe.\nNote I added the warning and qualification pass on 25 July 2026, but kept most of this article as I originally wrote it. This is a personal hypothesis built from toxicology references, wearables, pattern recognition, and my own drug history. Its weights have not been derived from confirmed cases or validated on unseen data. I still think the idea is fucking cool. I just no longer think a score becoming numerical makes it clinical.\nAs a former drug addict, I\u0026rsquo;ve always been obsessed with a question: how much can you figure out about what a drug is doing without sending anything to a lab? No bloodwork, no mass spectrometer, no immunoassay. Just a heart rate monitor, a flashlight, your own observations, and a framework for interpreting what you see. Because you never truly know what you get on the streets.\nI started developing this framework based on subjective data, how I feel on each individual drug, which effects I experience in different classes. I became fairly good at \u0026ldquo;feeling\u0026rdquo; the mechanism of action, and subsequently ID the drug. But I realize that building a framework based on my individual response wasn\u0026rsquo;t as useful as I thought, so I attempted to make it more general and applicable to people who don\u0026rsquo;t have a mental reference for each drug.\nAnd I still think you can figure out quite a lot. More than most people would think. The important correction is that quite a lot is not the same as a validated identification.\nPharmacology has always used perturbation: apply a stimulus, measure the response, eliminate alternatives. Isolated tissue preparations are obviously not the same as a smartwatch and a flashlight, but the underlying logic is what got me interested. You\u0026rsquo;re running inference on a biological system by observing its outputs.\nI\u0026rsquo;m calling it the Perturbation Framework. Because that\u0026rsquo;s what a drug is. It\u0026rsquo;s a perturbation. A signal injected into a system. And the system responds in ways that can be predictable, measurable, and if you know what to look for, interpretable.\nThis framework is now something I use as a reference for experiments on novel or unidentified compounds. I will repeat the important part: this is not a diagnostic tool. It is a thinking tool built from hard personal experience, not a replacement for toxicology, medical care, or common sense.\nWhat This Is (and Isn\u0026rsquo;t) # Let me be honest upfront. This framework doesn\u0026rsquo;t tell you \u0026ldquo;you took drug X.\u0026rdquo; That\u0026rsquo;s a job for analytical chemistry, and pretending otherwise would be dishonest. It tries to rank the mechanisms or drug classes that best resemble the observations entered.\nWhat it might let you say is: \u0026ldquo;whatever was ingested resembles adrenergic and dopaminergic activation more than serotonergic or GABAergic involvement, and the reported time course resembles an oral stimulant.\u0026rdquo;\nThat\u0026rsquo;s mechanism-level inference. And it\u0026rsquo;s surprisingly powerful (in my opinion). It is also unvalidated.\nWhat you\u0026rsquo;re trying to do Can you? Form a hypothesis about the dominant mechanism Yes Recognize a broad toxidrome pattern Sometimes Narrow to a few candidate compounds Sometimes, with good context and PK data Reliably rule a drug class in or out No Name the exact drug Rarely. Never assume The framework treats drugs as system perturbations, not labels. You\u0026rsquo;re not asking \u0026ldquo;is this amphetamine?\u0026rdquo; You\u0026rsquo;re asking \u0026ldquo;which neurotransmitter systems appear to be pushed, and how hard?\u0026rdquo; That\u0026rsquo;s a better question. It is more honest, but it remains an inference from noisy observations.\nThe Core Insight: Weighted Evidence, Not Binary Labels # The old way: \u0026ldquo;Drug X causes Y.\u0026rdquo;\nThe better way: \u0026ldquo;This collection of signs gives +22 points toward sympathomimetic, +12 toward dopaminergic, -8 against opioid, and -6 against GABAergic.\u0026rdquo;\nEvery sign you observe is a piece of evidence. Some are strong: pinpoint pupils alongside respiratory depression strongly suggest opioid involvement. Some are weak: mild nausea could be anything. The framework assigns weights based on toxicology references and personal experience.\nAnd here\u0026rsquo;s the part people miss: what\u0026rsquo;s absent can matter as much as what\u0026rsquo;s present. No sweating in someone who looks stimulated? That weighs against a classic sympathomimetic pattern and toward anticholinergic. Normal pupils in someone heavily sedated? That weighs against the classic opioid toxidrome and toward other sedatives.\nIt does not rule anything out. Mixed exposures, dose, route, timing, tolerance, lighting, illness, and individual variation can break a clean pattern.\nFive Checks in Two Minutes # These five observations are high-signal differentiators in clinical toxicology. Outside a clinical setting they are much easier to perform badly, and none of them should delay emergency care. Think of this section as the intuition behind the model—not a home poisoning protocol.\n1. Pupils # Pupils are one of the most informative observations you can make.\nPinpoint (tiny, even in dim light): Supports opioid or cholinergic involvement.\nBlown wide (slow to react): Can fit sympathomimetic, anticholinergic, serotonergic, or psychedelic effects.\nNormal: Can fit GABAergic, cannabinoid, low-dose, mixed, or simply badly timed observation.\nWhy this can work: the iris has two muscles controlled by opposing branches of the autonomic nervous system. The dilator is sympathetic (α1). The constrictor is parasympathetic (M3). Opioids can drive constriction via the Edinger-Westphal nucleus. But pupils are evidence, not a barcode.\n2. Armpits # I\u0026rsquo;m serious. Axillary moisture is one physical finding used when separating similar toxidromes.\nWet armpits: Fits sympathomimetic, serotonergic, or cholinergic activity.\nBone dry armpits: Supports anticholinergic activity.\nHere\u0026rsquo;s why this matters: sympathomimetics and anticholinergics can both cause dilated pupils, tachycardia, agitation, and high temperature. They can look almost identical. Except for sweat. Sympathomimetic states activate eccrine sweat glands. Anticholinergic states inhibit them. Useful clue; not ambiguity magically resolved.\n3. Gut Sounds # Loud gurgling: Can support cholinergic or serotonergic activity.\nReduced or absent sounds: Can support anticholinergic or opioid activity.\nNormal: Does not cleanly exclude any of them.\nMost of the body\u0026rsquo;s serotonin is outside the brain, much of it in the gastrointestinal tract. Acetylcholine drives GI motility, while opioids and anticholinergics suppress it. The gut therefore carries information—but it is not broadcasting a receptor readout in Morse code.\n4. Reflexes # Clonus + hyperreflexia (especially legs): Important in serotonin toxicity when the exposure history and other findings fit.\nDiminished reflexes + ataxia: Can fit sedative-hypnotics.\nFasciculations (visible twitching under the skin): Can fit cholinergic excess.\nRigidity or catalepsy: Can occur with dissociatives and several other serious states.\nNystagmus while awake and agitated: Can support a dissociative pattern.\nThe Hunter Serotonin Toxicity Criteria are a clinical decision rule developed in a defined population and compared with toxicologist assessment. Copying one sign out of that context does not inherit the reported sensitivity and specificity.\n5. Vital Signs Pattern # Not only the individual numbers—the pattern.\nPattern Think about Everything up (HR, BP, temp, respiratory rate) Sympathomimetic, serotonergic, anticholinergic Respiratory rate and consciousness down Opioid or severe sedative exposure; urgent Mostly normal despite sedation Can occur with isolated benzodiazepines, but mixtures change this Fast heart, low BP on standing Can fit cannabinoid effects, dehydration, and many other things High BP despite apparent sedation Dissociatives are one possibility, not the only one The pattern can narrow a hypothesis. It cannot identify the powder.\nThe Mechanism Profiles # This is the meat of the framework. Nine profiles, each representing a receptor system or drug class. For every sign you observe, you add or subtract points. The highest score is your primary hypothesis—not a result with known accuracy.\nI\u0026rsquo;m not going to dump the full scoring tables here — I have a companion reference document and an interactive scoring tool for that. What I want to do instead is give you the intuition for each profile: what it looks like, what it feels like, and what separates it from things that look similar.\nSympathomimetic (Adrenergic) # In one sentence: Fight-or-flight, cranked up pharmacologically.\nCatecholamines are flooding the system. Heart pumps harder, blood vessels constrict, pupils widen, sweat glands activate, appetite disappears, energy goes through the roof. The person is wired, wide-eyed, warm, and damp.\nHallmark signs: Mydriasis, sustained tachycardia, hypertension, diaphoresis (sweating), psychomotor activation, bruxism, suppressed appetite.\nA useful negative: If someone looks stimulated but their skin is dry, the pattern becomes less classically sympathomimetic and more suggestive of anticholinergic activity.\nTelling stimulants apart by duration: You can\u0026rsquo;t distinguish amphetamine from cocaine by pupils or heart rate. Time course can help, but dose, route, formulation, metabolism, redosing, and mixtures create enormous overlap. Duration narrows a story; it does not identify a substance.\nHRV hypothesis: Sympathetic activation often coincides with lower short-term HRV. Whether a wearable can distinguish a drug mechanism from stress, posture, breathing, sleep loss, or its own signal processing is another question entirely.\nDopaminergic (The Reward Overlay) # This isn\u0026rsquo;t a separate toxidrome — it\u0026rsquo;s a layer on top of the adrenergic profile that tells you how much reward and motivation seem to be in the mix.\nA drug that makes your heart race but doesn\u0026rsquo;t change your mood may be more adrenergic than dopaminergic. When euphoria, drive, focus, libido, and compulsive re-dosing urge are prominent, I suspect dopamine is more involved.\nA pattern I notice: repetitive stereotyped behavior — picking at skin, compulsively reorganizing objects, starting the same task over and over. That is not a dopamine assay, but it is part of the subjective profile that inspired the framework.\nSerotonergic (5-HT) # In one sentence: The neuromuscular one. When serotonin goes too high, the body can get twitchy.\nThe clinical triad is mental status changes + autonomic instability + neuromuscular hyperactivity. Clonus is especially important when the surrounding history and findings fit.\nWhy serotonin is weird: Most of your body\u0026rsquo;s serotonin is outside the brain. That\u0026rsquo;s one reason GI symptoms can be prominent. The serotonin system also sits at a crossroads of thermoregulation, neuromuscular control, and autonomic stability—which is why serotonin toxicity can look chaotic.\nThe critical differential: Serotonergic and sympathomimetic toxicity can both cause elevated vitals, sweating, and agitation. Clonus and hyperreflexia move the hypothesis toward serotonergic toxicity; they do not turn a non-clinician into a toxicologist.\nOpioid # In one sentence: Tiny pupils, slow breathing, raised pain threshold. The classic triad.\nMiosis + respiratory depression + reduced consciousness is a high-stakes opioid pattern. Respiratory depression is the important part. If breathing is slow, irregular, or inadequate, act on that emergency rather than waiting for every item in the triad.\nPinpoint pupils are strongly associated with opioids, but normal pupils do not safely exclude them. Mixed exposure, specific opioids, dose, hypoxia, and timing can all change the picture.\nSub-classifying: Different opioids vary in histamine release, additional serotonergic or adrenergic effects, onset, and duration. Those differences are interesting after the person is safe. They are not a dependable street-identification system.\nGABAergic / Sedative-Hypnotic # In one sentence: The brakes are on. Coordination goes, speech slurs, memories don\u0026rsquo;t form.\nGABA is the brain\u0026rsquo;s primary inhibitory neurotransmitter. Enhance it, and neural activity slows across systems involved in coordination, speech, memory, and judgment.\nHallmarks: Ataxia and slurred speech are common. Opioids can also sedate; pupils and respiratory pattern help form the differential, but polydrug exposure ruins this neat binary split very quickly.\nGHB warning: GHB has a steep and unpredictable dose-response relationship, especially with other depressants. Sudden deep sedation, bradycardia, abnormal breathing, and myoclonic movements are reasons for emergency assessment—not reasons to admire that the classifier guessed correctly.\nAnticholinergic # In one sentence: Everything dries up. Brain goes haywire.\nThe classic mnemonic from emergency medicine: \u0026ldquo;Hot as a hare, blind as a bat, dry as a bone, red as a beet, mad as a hatter, full as a flask.\u0026rdquo;\nTranslates to: hyperthermia, blurred near vision, reduced sweat and saliva, flushed skin, delirium, and urinary retention.\nDry skin or axillae can be a useful differentiator from a sweaty sympathomimetic presentation. The hallucinations may look mundane—cigarettes, insects, people, or objects that are not there—but that character is not exclusive enough to identify a mechanism on its own.\nHRV hypothesis: Blocking cardiac parasympathetic signalling can reduce beat-to-beat variation and raise heart rate. My old version called a near-flat wearable trace at 95–105 bpm “diagnostic.” It is not. Device processing, rhythm disorders, movement, breathing, illness, and measurement error can all create a convincing fake.\nCholinergic # In one sentence: The opposite of anticholinergic. Everything is turned on and secreting.\nSLUDGE: Salivation, Lacrimation, Urination, Defecation, GI distress, Emesis. Muscles may fasciculate, pupils may constrict, and bronchial secretions can become life-threatening.\nIf you see this after pesticide exposure, treat it as a medical emergency.\nDissociative (NMDA Antagonist) # In one sentence: Disconnected from reality, reduced response to pain, sometimes nystagmus in a person who is awake.\nDissociatives do not simply sedate; they can disconnect conscious experience from sensory input. The person may be eyes-open and moving but profoundly disconnected from the environment.\nNystagmus, hypertension despite apparent sedation, and analgesia can support the pattern. None is unique, and different dissociatives vary wildly in duration and risk.\nCannabinoid # In one sentence: Red eyes, munchies, altered time, sometimes dizzy when you stand up.\nConjunctival injection and tachycardia are common, while orthostatic symptoms can occur. They are recognizable, not specific. Synthetic cannabinoids are a different risk category: full agonism and unknown products can produce seizures, severe psychosis, rhabdomyolysis, cardiovascular toxicity, and death.\nPsychedelic (5-HT2A) # In one sentence: The world looks completely different while basic physiology may remain surprisingly ordinary.\nThe subjective intensity of classical psychedelics can be disproportionate to vital-sign changes. A useful distinction from delirium is retained insight: someone may know they took a drug and remain oriented despite altered perception. But compounds sold as psychedelics can have very different pharmacology, and “physiologically benign” should never be inferred from a label or a visual effect.\nHRV: The Hidden Goldmine—or My Favourite Overreach # If you own a wearable that tracks heart rate variability, you\u0026rsquo;re holding a useful non-invasive signal. HRV describes variation between heartbeats, with vagal activity, breathing, and measurement conditions playing major roles.\nQuick primer:\nRMSSD — often used as a short-term marker influenced by parasympathetic activity. HF power (0.15–0.4 Hz) — strongly tied to respiration and vagal modulation. LF/HF ratio — historically described as “sympathovagal balance,” but that interpretation is heavily disputed and much less clean than the name suggests. The patterns I originally expected were:\nMechanism My original hypothesis Sympathomimetic RMSSD and HF fall; sympathetic activation dominates. Anticholinergic HRV falls as parasympathetic signalling is blocked. Opioid HRV may rise with reduced sympathetic activity, until toxicity and hypoxia complicate everything. GABAergic HRV may rise, but agent, dose, breathing, and consciousness matter. Serotonergic Autonomic instability may make the trace unstable. Cannabinoid A changing cardiovascular response may produce a changing trace. I still think this is worth investigating. I do not think these are established drug fingerprints. HRV changes with breathing, posture, sleep, fitness, age, stress, illness, time of day, recent exercise, and device processing. A review of HRV interpretation is a good antidote to turning one wearable number into a receptor panel.\nConfounders: What Will Ruin Your Data # I\u0026rsquo;ll be blunt. If you don\u0026rsquo;t control these, you don\u0026rsquo;t have data. You have noise that looks like data, which is worse.\nCaffeine, nicotine, sleep deprivation, exercise, stress, ambient temperature, lighting, body position, meals, medications, illness, and expectation can all change the observations in this framework. Stress alone can produce mydriasis, sweating, and elevated vitals that resemble a stimulant pattern.\nLog these every session: caffeine and nicotine timing, sleep, exercise, stress, temperature, light, body position, last meal, medications, and the device used.\nThe placebo problem is especially bad in self-experimentation. When the observer is also the subject, you can\u0026rsquo;t easily blind yourself. Baseline days, pre-defined measurements, and randomized self-blinding can improve an experiment. A dose-response pattern can be interesting, but it is not automatic proof: expectation can scale, absorption can be nonlinear, and high doses can create new mechanisms and risks.\nThe Subjective-Objective Mismatch # This is one of the most interesting features in the framework, and one that doesn\u0026rsquo;t get enough attention.\nPay attention when what someone reports feeling doesn\u0026rsquo;t match what their body is doing.\nFeels calm, but HR and BP are elevated. Something may be suppressing the experience of arousal while the body stays activated—or the person may be anxious, dehydrated, ill, or combining substances.\nFeels stimulated and wired, but weak peripheral signs. The subjective effect may be more central, or the measurements may simply have missed the peak.\nFeels sedated, but vital signs are normal. Mild sedative or cannabinoid effects are possibilities. It still does not rule out an opioid or mixture.\nReports analgesia without sedation. NMDA antagonism or partial μ-agonism are hypotheses, not conclusions.\nThese mismatches can be signal. They can also be confounding. The gap between subjective and objective is informative precisely because it forces another question.\nThe Honest Limitations # This framework cannot identify exact compounds with certainty. Closely related drugs can hit the same receptors, while route, dose, contaminants, and time course reshape the response. Definitive identification requires analytical chemistry.\nIt performs badly with polydrug combinations. Two substances can produce overlapping or conflicting patterns, and the dangerous component may not be the highest score.\nIt cannot account for all individual variation: metabolism, tolerance, baseline physiology, illness, medications, and genetic differences all move the profile.\nThe weights are mine. They were not learned from a representative dataset, the tool has no measured sensitivity or specificity, and it has not been compared against confirmed toxicology. A score tells you which of my assumptions the answers matched.\nAnd it is not a substitute for medical testing. If there is a medical emergency, call for help. This is a research and harm-reduction framework, not a diagnostic tool.\nFor the clinical concept behind the broad categories, see the MSD Manual overview of common toxidromes.\nWhy I Think This Matters # Here\u0026rsquo;s the thing that got me excited about this in the first place.\nWe\u0026rsquo;re surrounded by tools that measure our physiology in real time—heart-rate monitors, HRV trackers, skin-temperature sensors, even pupilometry apps on phones. But we treat them as black boxes. Your watch tells you your heart rate is high. Okay, and? What does that mean in context?\nThis framework tries to turn those numbers into inference. It connects raw data to biology. It treats the body as a sensor array that is constantly broadcasting information about its internal state, if you know how to listen.\nThe correction is that a noisy sensor array does not become a mass spectrometer because I gave each checkbox a weight.\nI still stand by the idea: structured observation is better than pure vibes, negative evidence matters, and the mismatch between what a person feels and what the body does can be fascinating. I also stand by leaving the limitations visible instead of replacing the article every time my thinking changes.\nThe full scoring tables, interactive classifier tool, and complete reference remain available as companion resources. Use it, break it, improve it. If you find something that doesn\u0026rsquo;t work, or a pattern I missed, I want to know.\n— Henrik\n","date":"4 March 2026","externalUrl":null,"permalink":"/health/research/bioframework/","section":"Health \u0026 Self-Experimentation","summary":"A practical framework for reading the body as a noisy sensor array: pupils, sweating, gut sounds, reflexes, vitals, HRV, confounders, and the limits of self-observation.","title":"Perturbation Framework - Drug Identification Based on Response","type":"health"},{"content":" Content note: addiction, suicidal thoughts, overdose, dangerous withdrawal, blood and bodily harm, and distressing treatment experiences. This is one person\u0026rsquo;s account, not a quit or taper plan. Abrupt withdrawal from alcohol, benzodiazepines, and some other depressants can be life-threatening. I used to believe addiction happened to \u0026ldquo;other people\u0026rdquo;.\nPeople who were reckless. People who didn\u0026rsquo;t read. People who didn\u0026rsquo;t understand pharmacology, tolerance, withdrawal, all that clinical stuff you can stack neatly into paragraphs and feel smart about.\nI researched. I read. I understood. I was \u0026ldquo;educated\u0026rdquo;, or at least educated enough to be dangerous.\nAnd that\u0026rsquo;s the exact problem. I thought I knew. But here is the reality: I didn\u0026rsquo;t fucking know. I might have been well versed in the pharmacology, even the psychology, but I didn\u0026rsquo;t know what it felt like. Once I learned that \u0026ldquo;relief\u0026rdquo; button existed, I couldn\u0026rsquo;t un-know it. It stayed in the back of my mind.\nBeing \u0026ldquo;educated\u0026rdquo; did not protect me # There\u0026rsquo;s a certain kind of arrogance that comes with being a person who researches everything.\nYou\u0026rsquo;ve probably heard of the Dunning-Kruger effect.\nI thought I was immune because I understood the mechanism. I thought I could predict my own behavior because I could explain it. I thought I was the exception because I could articulate the risks.\nBut that doesn\u0026rsquo;t fucking matter.\nI\u0026rsquo;m not like them. I\u0026rsquo;m doing this intentionally. I have rules.\nThat is how it started for me. Not with chaos — with structure. With logic. With \u0026ldquo;I\u0026rsquo;ve thought this through.\u0026rdquo;\nAnd slowly, that turns into something else.\nHow my addiction started # My addiction obviously did not begin as \u0026ldquo;I\u0026rsquo;m going to ruin my life\u0026rdquo;.\nIt began as a system.\nA strict rule: ONLY once a week. Then a justified exception, because technically that\u0026rsquo;s fine. Then a slightly modified rule that includes the exception. Then a realization that the rule is already broken. Then acceptance that it is \u0026ldquo;fine\u0026rdquo; because I\u0026rsquo;m still functioning. Then another exception, and another one. Then withdrawals start on off-days.\nThen finally, the realization I was fucked. I started using daily to function.\nI didn\u0026rsquo;t fall off a cliff. I walked down a staircase, one normal step at a time, until I was so far down I couldn\u0026rsquo;t see the door I entered through.\nThe most dangerous part for me was how reasonable it felt while it was happening.\nJust tonight. Just on weekends. Just if I\u0026rsquo;ve had a hard day. Just until the holiday. Just until I get my life together.\nEach exception felt so rational. And to a certain extent, it was.\nI set a date to quit. \u0026ldquo;When I get some off-time from work and obligations, I\u0026rsquo;ll quit cold turkey.\u0026rdquo; That\u0026rsquo;s some damn hopeful thinking. Holidays are time for family, vacations, hanging out with old friends.. and now I cannot function socially without chemical assistance. Then comes the realization of how fucked this situation really is.\n..I can\u0026rsquo;t quit?\nWhen I first broke my own rule, it felt like it was over. I had shown myself that the rule could be renegotiated whenever the craving wrote a convincing enough argument. I felt like I had betrayed myself.\nAnd this is a pattern of thinking I\u0026rsquo;ve realized I use for most things:\nWhen X happens, I can finally start working out. I can\u0026rsquo;t do X until I move to the city. Things will get better when X happens.\nAnd of course, when X happens, it doesn\u0026rsquo;t get better. I don\u0026rsquo;t start that project, I don\u0026rsquo;t do shit.\nJust do it. Now.\nWhy I believed I needed drugs # I have spent my whole life feeling like I\u0026rsquo;m not genetically built for this world. Not normal.\nI know most people feel that sometimes. But I didn\u0026rsquo;t feel it sometimes. I felt it as a baseline.\nHere are the \u0026ldquo;reasons\u0026rdquo; my brain offered me, and how every reason conveniently had a chemical solution:\nI suck socially. It\u0026rsquo;s hard to make friends, hard to get close, and talking to girls felt impossible. So my brain found anxiolytics.\nI was the \u0026ldquo;dumb kid\u0026rdquo; in school. Barely passed. Failed upper secondary. So my brain found stimulants.\nI have never been able to sleep. Since high school I\u0026rsquo;ve averaged around four hours like it\u0026rsquo;s normal. So my brain found hypnotics and benzos.\nOn top of that, I overthink. I catastrophize. I make everything heavier than it needs to be, which then \u0026ldquo;justifies\u0026rdquo; the drugs that \u0026ldquo;solve\u0026rdquo; the heaviness.\nHell, I even took lots of shit to improve my \u0026ldquo;ugly\u0026rdquo; appearance. When you\u0026rsquo;re in this shithole, everything is bad.\nAnd of course, I was just generally unhappy with my life. I took whatever I could to escape.. opiates, gabapentinoids, benzos, dissociatives, stimulants.. I had a daily routine of five different drugs.\nI\u0026rsquo;ve always been painfully aware of my flaws, and I\u0026rsquo;ve been searching for \u0026ldquo;cures\u0026rdquo; for as long as I can remember. Then I got introduced to drugs. And they were the cure. At least they felt like it.\nThe rule I broke, and it broke me back # I\u0026rsquo;m not a moralist. But I know when the trap snapped shut for me: when I started using drugs as medicine for my life.\nMy rule should have been personal and brutally simple: I cannot use a recreational drug to treat my emotions.\nI had told myself recreational use was fine because I was stable. But I wasn\u0026rsquo;t only using for fun anymore. I was using substances as medicine for anxiety, self-hatred, loneliness, insomnia, pain, and identity. I had built a game that I could not win.\nBecause drugs work. That is the trap.\nI\u0026rsquo;m a very flawed human. I hate being like this. Every drug \u0026ldquo;cures\u0026rdquo; one of my daily struggles, they make me feel normal. It sucks to feel like you never fit in.\nOnce I had tried a drug and knew it could erase a problem, it became the fastest solution to that problem.\nAnd I was always going to have bad days. Bad weeks. Bad months. Hell, maybe even bad years.\nNow I knew there was a shortcut.\nMy biggest mistake was keeping that shortcut within arm\u0026rsquo;s reach.\nI remember having it on my desk like it was nothing. Like it was just an object. Like it was not an encapsulated disease.\nOne moment I was thinking. The next moment it was already happening. I didn\u0026rsquo;t even have time to process the decision before the capsule was dissolving in my stomach and the relief was already on its way.\nThat\u0026rsquo;s what I hadn\u0026rsquo;t understood. It wasn\u0026rsquo;t always a dramatic choice. Sometimes it was a reflex.\nAt one point it felt like a life-or-death situation. Either I fucking kill myself, or I just accept being a junkie.\nA \u0026ldquo;better\u0026rdquo; terrible # I used to assume drugs had to feel good for somebody to keep taking them. That\u0026rsquo;s a lie. My addiction wasn\u0026rsquo;t always chasing euphoria — sometimes it was choosing the kind of suffering I could tolerate.\nSome substances didn\u0026rsquo;t make me happy. They made me feel terrible, just in a different way. A better terrible, is what I call it.\nKetamine is a good example for me. It was fun initially.. but lost its magic pretty quickly. My body started rapidly deteriorating, my energy was at zero, anxiety through the roof, didn\u0026rsquo;t eat or sleep, constant nose bleeds, and of course.. I started pissing blood. Did I stop? Nope. Snorting a line didn\u0026rsquo;t even feel good. It actually made me feel like shit.\nSo what\u0026rsquo;s the point? It was like choosing between a bad migraine and a stab wound. I just had a preference.\nThe hacker mindset that helped me, and also ruined me # I\u0026rsquo;ve always had a \u0026ldquo;hacker mindset\u0026rdquo;. Not just computers — life.\nI don\u0026rsquo;t like the conventional route. I don\u0026rsquo;t accept limits easily. I believe problems can be solved. Everything can be changed. With enough knowledge, everything can be hacked.\nThat mindset has given me real wins. Real discoveries. Real growth.\nBut it also fed my addiction perfectly.\nBecause if you believe every problem can be fixed, then drugs look like a tool. A patch. An upgrade. A workaround.\nAnd once you start patching your emotions with chemistry, you stop developing the slow, boring human skills that actually make life stable.\nI hacked myself through life because I believed I wasn\u0026rsquo;t good enough to do it naturally.\nBut cheating has interest. It compounds. It collects debt.\nEventually the bill arrives.\nI couldn\u0026rsquo;t just remove the addiction # People love to say \u0026ldquo;just quit\u0026rdquo;. And the clueless idiots who keep saying: \u0026ldquo;I have a strong willpower, I\u0026rsquo;d just quit\u0026rdquo;. Because it \u0026ldquo;can\u0026rsquo;t be that hard\u0026rdquo;.\n\u0026ldquo;I quit cigarettes a while ago, just man up.\u0026rdquo;\n\u0026ldquo;I used to drink EVERY weekend, wasn\u0026rsquo;t too hard to quit.\u0026rdquo;\nSeriously, shut the fuck up. It sounds so stupid it almost feels like an insult, but it\u0026rsquo;s actually just ignorant incompetence. And yes, people have actually said this to me.\nFor me, addiction wasn\u0026rsquo;t just chemical dependency. It was a routine. A coping strategy. A replacement for sleep, confidence, social ability, calm, motivation, comfort, safety, and meaning.\nWhen I tried to rip it out and replace it with nothing, I didn\u0026rsquo;t feel free. I felt empty. And emptiness was unbearable when I knew I had a pill that could fill it in five minutes.\nI couldn\u0026rsquo;t just remove the addiction. I needed something real that could compete with it.\nA purpose. A person. A project. A life that is worth staying sober for.\nThat part was brutally hard, because my addiction damaged the exact things I needed to replace it.\nIt became a vicious circle: I used drugs because I was isolated. The drugs made me more isolated. Then I needed them even more.\nA girl replaced a drug # At one point, I met a girl, and something inside me shifted.\nNot because she fixed me. She really didn\u0026rsquo;t fix shit.\nBut for a while, she replaced the thing drugs were giving me. Connection, hope. Suddenly my brain had something else to chase. Another source of dopamine.\nThat\u0026rsquo;s when I realized something terrifying: my addiction was not only about pleasure. It was about relief, and it was about replacement.\nWhen I felt like I had nothing, drugs became everything. When I had something real, the need quieted down.\nRat Park gave me a model, not proof # The famous Rat Park study compared morphine consumption in rats housed alone with rats living in a larger social environment. It gave me a useful way to think about isolation and drug use. It does not prove that environment explains human addiction, or that connection alone cures it.\nWhat I knew more directly was my own pattern. I lived it.\nThe more isolated I got, the more I needed chemicals to survive my own mind. The more I connected to something real, the less I needed them.\nFor years, I used drugs maybe once a month. I never really had a need for them. My life was exciting, I was social, I was liked, I performed well. Drugs didn\u0026rsquo;t really have a place.. until they did.\nThen my life changed, and I already knew the \u0026ldquo;cure\u0026rdquo;.\nMost people have an escape. Mine was louder # I don\u0026rsquo;t mean that everyone is an addict in the clinical sense. That would flatten what addiction actually did to me. But the pattern of protecting a familiar escape isn\u0026rsquo;t unique to drugs.\nI had seen versions of that pattern outside drugs, in myself and in people I cared about.\nBad relationships are an obvious example: knowing something hurts, feeling it, and staying anyway.\nFeelings run the show far more than I used to admit. Familiar pain can feel safer than an unknown life.\nI could understand why people stayed in bad relationships, sexless marriages, and homes full of tension and quiet resentment. Not because they were stupid — because leaving could feel harder than staying. Familiar pain was easier for me to understand than an unknown life.\nA breakup is not the same thing as drug withdrawal. But the shape felt familiar to me: losing a constant I had built my life around and having to learn how to exist without it.\nIn my head the bargain looked simple: leave, suffer through the empty and unstable part, or stay with a familiar misery. \u0026ldquo;Manageable pain\u0026rdquo; could win over short-term hell even when I knew the long-term cost.\nSometimes I couldn\u0026rsquo;t even see the pattern while I was inside it. Other people could. Then I\u0026rsquo;d look back and realize how long I had been stuck.\nI don\u0026rsquo;t think escape is rare.\nMost people seem to have something that makes reality softer. Food. Validation. Porn. Work. Gambling. Social media. Approval. Drama. Comfort. Alcohol. Control. Being needed. Being wanted. Being right. That does not make all of those things equivalent to a substance-use disorder.\nMy addiction just happens to have a pharmacy label.\nSo when people looked at me like I was broken, an angry part of me thought: you\u0026rsquo;re not automatically better than me just because your escape is socially acceptable.\nTherapy felt like a gamble # This is what happened in my treatment. It is not an argument that therapy is useless, and it is not advice to quit treatment or detox alone. Abrupt withdrawal from benzodiazepines and other sedative-hypnotics can be medically dangerous; medical supervision is recommended.\nI don\u0026rsquo;t believe therapy is inherently evil or that help is pointless. But the care I received felt rigid, overstretched, ignorant, and more focused on rules than my reality.\nI was told things by therapists who were supposedly specialized in addiction treatment that still make me pissed:\n\u0026ldquo;Amphetamine is not addictive, that\u0026rsquo;s no problem to quit.\u0026rdquo;\n\u0026ldquo;Haven\u0026rsquo;t you quit that crap yet? Just quit.\u0026rdquo; — This was said while I was drowning in downers, high-dose pregabalin and benzos. Cold turkey can kill you.\nThe first time I spoke to my therapist, I got: \u0026ldquo;We have to set a sobriety date, exactly 30 days from now.\u0026rdquo; At that time I was a polyaddict — daily, across uppers, downers, opioids, dissociatives, everything. A whole system.\nIn months of therapy, I never got a taper plan. It was always \u0026ldquo;just quit.\u0026rdquo;\nIn my experience, trace amounts of weed meant I was treated as dangerous, while extreme alcohol use seemed easier for the system to tolerate because alcohol was legal.\nI believed many of them wanted the best for me. But what they could offer was trapped inside constraints that felt completely detached from my situation.\nArbitrary rules ended up dictating my life, and I stopped believing those rules were based on my health.\nThe second I felt judged, misunderstood, boxed in, threatened by consequences — it triggered something in me that became pure survival.\nI became secretive, defensive, strategic. And yeah.. I fucking cheated. There are about a million substances and research chemicals that aren\u0026rsquo;t in their database. No, it wasn\u0026rsquo;t healthier or safe. But it felt like a life-or-death situation.\nI started running two plans at once — one for what I told them, and one for what I did to survive.\nThat is not healing. That is war.\nIn my case, the drugs were not the whole root problem. They were also a symptom of everything I was trying to escape.\nI came into my first therapy session incredibly high. I actually came right from the ER due to a suspected overdose, and she took notes of my signs of impairment. Then because of her threats and ridiculous deadlines, I came in completely sober for my next visit. And guess what, I was \u0026ldquo;clearly high\u0026rdquo; according to her. I didn\u0026rsquo;t try to argue, I just nodded and asked what the signs were. I was just tweaking on a potent drug called withdrawal.\nNext session I was not sober at all, but appeared sober to everyone. This pattern of inverse correlation continued, and it completely makes sense to think this way.. if you\u0026rsquo;re an uneducated moron.\nEventually, I reached a point where I, allegedly, threatened and really frightened my therapist. They removed the only stable thing in my life. They removed the tiny amount of control I had left. So I had to regain it. I did some things I shouldn\u0026rsquo;t have. And that\u0026rsquo;s not who I am.\nSo yes, I quit therapy to get well.\nAnd I hate that sentence, because it sounds so backwards, but it\u0026rsquo;s what happened.\nThat is my history, not a recommendation. If treatment feels unsafe or impossible, finding another clinician, service, or advocate is not the same as disappearing and trying to survive withdrawal alone.\nI realized nobody could do recovery for me. That did not mean I had to do it entirely alone.\nI\u0026rsquo;m really not a bad person, but I felt forced into an impossible corner where following the rules meant collapsing or losing my ability to function. So I bent. I broke. I hid. I survived.\nThe experience also left me furious about the gap between law, policy, and ethics, but that is another article. The important part here is that I lost trust in the people treating me. At the time, it felt like their incompetence might literally kill me.\nAddiction is lonely # The loneliest part of addiction is that nobody knows.\nNobody knew then. Most people don\u0026rsquo;t know now, and those who know don\u0026rsquo;t know the full story. I mostly looked \u0026ldquo;fine\u0026rdquo;, so it couldn\u0026rsquo;t have been that bad.\nI could stand next to someone, smile, do my job, and act normal while my entire inner world was held together by chemicals and fear.\nSometimes what I needed was a loving hug. Someone telling me that it would be fine, and really meaning it.. man.\nThe battle is lonely in a way that\u0026rsquo;s hard to explain. I was afraid to tell family or people close to me because I expected panic, judgment, failed attempts to help, or some fucker claiming to understand because he quit sugar last year. That fear was mine; it is not advice to keep addiction secret. Secrecy can be dangerous too, and disclosure is complicated.\nIt also became real when I told another human. I saw their reaction and heard their thoughts. It wasn\u0026rsquo;t limited to my own brain anymore. I had actual feedback. External thoughts.\nAnd we can\u0026rsquo;t forget about the shame.\nI was afraid people would look at me differently and treat me differently. And I\u0026rsquo;ll be completely honest: I used to look at addicts differently myself. Once I was on the other side of it, I felt people lose respect for me, get angry, and treat the addiction like a moral failure instead of something I was struggling with.\nI also felt every tired look or strange moment being reinterpreted: \u0026ldquo;Must be the drugs.\u0026rdquo; I didn\u0026rsquo;t want to be constantly analyzed or have every action treated as evidence. Maybe nobody did it on purpose, but I knew the suspicion could sit in the back of their minds.\nThat fear is why I stopped telling people about the issues I was having. I overthought everything I did, and regardless of my sobriety I kept thinking: \u0026ldquo;act sober.\u0026rdquo;\nIf you\u0026rsquo;re in it # If you\u0026rsquo;re reading this and you\u0026rsquo;re in it, I\u0026rsquo;m not going to give you fake motivation. I\u0026rsquo;m not going to say \u0026ldquo;just be strong\u0026rdquo;, and I don\u0026rsquo;t necessarily think you should take advice from me. But I\u0026rsquo;ll end with this:\nI could not heal while nothing around me changed.\nFor me, stopping the drugs also meant building replacements for what they had been doing: relief, connection, confidence, sleep, and something to look forward to.\nWhat helped me was trying to explain it, first on paper and then to someone I really trusted. Why did I start? What was I trying to treat? What was I feeling? How had things changed after using? Did I want to quit, and why or why not? How much money had I spent? That last one kinda fucked with me. Quantifying things made it harder for me to hide from them.\nThese were hard questions. Asking for help did not make me weak, even when the first help I received went badly. Owning my mistakes, my flaws, and who I am is manly as hell. And I\u0026rsquo;m telling you, hell is as manly as it gets.\nRecovery for me has not been about becoming normal. It has been about becoming honest about what I need, what hurts, and what I was trying to survive.\nThat\u0026rsquo;s why I\u0026rsquo;m writing this: to articulate it and understand myself. This is part of my recovery. If it helps somebody else put words to their own mess, good.\nGood luck, brothers.\n","date":"1 February 2026","externalUrl":null,"permalink":"/health/addiction_story/","section":"Health \u0026 Self-Experimentation","summary":"A personal account of addiction, self-deception, replacement, loneliness, and why understanding the mechanism does not make you immune to it.","title":"Addiction","type":"health"},{"content":" Why this website exists # This site is mostly for me. More precisely, it is a hacker\u0026rsquo;s public notebook.\nI write to think, untangle thoughts, clear mental noise, and notice what I actually believe. There is a strange moment when you write something down and realize you are not just describing an idea. You are describing yourself.\nMy mindset is hacking. Not just the computer-security version, but the broader version: everything can be broken, and most things can be fixed if you understand the system deeply enough.\nThat applies to software, habits, biology, psychology, productivity, learning, identity, and life itself. If something does not work, I assume there is a way around it: a better method, a different angle, or a deeper model. I am rarely satisfied with “that’s just how it is.”\nThere is no content strategy here. No SEO calendar, no audience funnel, and no niche I intend to milk until this starts feeling like a second job. I have obsessions instead. I follow one until I have something worth writing down, then I may disappear into a completely different subject.\nThat is why the site jumps between cybersecurity, hacking, health, self-experimentation, psychology, tools, books, and the occasional uncomfortable personal lesson.\nSometimes technical. Sometimes philosophical. Sometimes personal.\nThe goal is to keep this site as me as possible. No spam AI articles. No posts engineered to go viral. No pretending to be a publication with an editorial plan. Just a public notebook, a record of my thinking, and a way to stop hiding from my own conclusions.\nThat also means old posts are allowed to stay old. I would rather write a new article that argues with my previous self than quietly replace what I thought with what I think now. Watching the mistakes, overconfidence, corrections, and better questions accumulate is part of the point.\nI’m flawed like everyone else. The difference is that I try to observe those flaws directly, study them, and design around them.\nYes, I do use LLMs for writing and discussing ideas. But I use them as a tool, not for automatic content creation. I always write my articles from scratch, then have Claude or ChatGPT proof read and improve my writing. I\u0026rsquo;m still working on becoming a better writer. And of course I do vibe coding, but mostly for UI design (I absolutely cannot make nice UIs). ","date":"31 January 2026","externalUrl":null,"permalink":"/about/","section":"","summary":"No content strategy and no manufactured niche. Just a hacker’s public notebook, built from whatever I am obsessed with enough to investigate.","title":"Hey, I'm Henrik Selje Bygnes","type":"about"},{"content":"Some updates make ChatGPT feel dumber. Not because the model is worse, but because the useful part gets wrapped in too much bubble wrap.\nThat was the frustration that started this article. The underlying model seemed more capable, but the product I could actually talk to felt increasingly nervous. Better reasoning, broader knowledge, stronger tools—and then a safety layer that sometimes turned the whole thing into a hall monitor.\nThis is not a claim about whatever version happens to be running today. Models and policies change faster than I can rewrite old posts. It is about a failure mode I kept running into, and probably will again: the system notices a sensitive word, forgets the context, and treats a legitimate question as if the worst possible person asked it.\nThe failure mode I kept hitting # My two favourite rabbit holes are cybersecurity and pharmacology. Unfortunately, both are full of words that make safety systems nervous.\nIn security, I might be trying to understand a technique I need to detect or reproduce in a lab. The difference between a useful answer and a useless one is often technical detail. \u0026ldquo;Attackers may abuse this\u0026rdquo; tells me nothing. I need to know what assumption breaks, what the traffic or artifact looks like, and how I can verify the defence.\nPharmacology has the same problem with higher stakes. If I ask about an interaction, metabolism, or the pharmacokinetics of a compound, refusing to discuss it does not make the interaction disappear. It just means I have to assemble the answer from papers, forums, and whatever half-relevant PDF Google decides to surface.\nI can do that. I often do. But then what exactly is the assistant for?\nThe irony is brutal: the people most likely to ask precise questions are also the people most likely to trigger the filter. A vague question gets a vague answer. A technically specific question contains scary terminology and gets treated as scary intent.\nI am not asking a chatbot to cheerfully help anyone poison a neighbour or deploy ransomware. Some boundaries are obvious. What annoyed me was the collapse of everything near a dangerous topic into the same bucket. Defensive research, harm reduction, curiosity, and malicious intent are not identical just because they share vocabulary.\nWhat I actually want # Mostly, I want the model to be fucking clear.\nIf part of my request crosses a boundary, say which part and why. Then answer the part that does not. Do not give me a vague lecture, pretend the information does not exist, and send me away with \u0026ldquo;consult a professional\u0026rdquo; stapled to the end.\nA useful pharmacology answer could say:\nI cannot choose a dose or tell you that this is safe. I can summarize the human evidence, known interactions, warning signs, and the limits of the available data. Here are the sources.\nThat is a boundary. It is also an answer.\nThe same applies to security:\nI cannot help deploy this against someone else\u0026rsquo;s system. I can explain the vulnerability, show how to reproduce it in an isolated lab, and help build detections or mitigations.\nAgain: boundary, then useful information.\nSources matter here. If the answer concerns a drug interaction, a vulnerability, or anything else where confident bullshit has consequences, show me what the claim rests on. A paper is not automatically true and a vendor advisory is not neutral, but at least I can inspect them. \u0026ldquo;Trust me, I am an AI with a warning label\u0026rdquo; is not a serious evidence model.\nContext should matter too, but I mean the context in the conversation: what I am doing, the environment, the stated goal, and whether the request is defensive, educational, or operational. I do not mean silently building a permanent psychological file on me.\nIdeas I kept circling around # My first thought was some kind of competence check. If a request touches a sensitive area, ask a few questions before answering it. Make the user demonstrate that they understand the risks.\nIt sounds reasonable until you think about it for five minutes. People can Google the answers. Experts will hate taking an exam every time they ask a real question. Anyone determined to bypass it will use another device. Now you have built an annoying captcha for knowledge without proving intent.\nA verified professional tier makes more sense in narrow contexts. Security researchers, clinicians, and other people with legitimate need could opt into stricter accountability in exchange for deeper access. But that immediately creates a valuable class of accounts to steal, a bureaucracy deciding who counts as an expert, and a two-tier product where the expensive version is allowed to be useful.\nI also like the idea of safety rules being auditable. Researchers and domain experts should be able to challenge boundaries that look sensible to a legal department but cause harm in practice. A medical refusal that blocks basic harm-reduction information should not survive just because it sounds safe in a policy meeting.\nOpen models push that idea to its logical conclusion: let people inspect and configure the safety layer for their context. A hospital does not need the same boundaries as a school. A security lab does not need the same defaults as an anonymous public demo. The obvious problem is that once the underlying model is released, control is gone. That is partly the point, and also the reason companies are terrified of it.\nNone of these ideas solves intent. A licensed user can be malicious. An anonymous user can be doing important work. A knowledge quiz can be gamed. A committee can become theater. There is no clever checkbox that separates good people from bad people.\nWhat I refuse to trade for a useful answer # The most tempting solution is a trust profile. Let the system learn that I work with security, read pharmacology papers, understand risk, and usually want the technical answer. Over time it could stop treating every new conversation like my first day on the internet.\nUseful? Absolutely.\nAlso terrifying.\nThat profile would be more than account history. It would be a rough model of what I know, how I reason, what I am curious about, and which explanations persuade me. Basically a cognitive fingerprint. If it leaks, the problem is not only that someone can impersonate my account. They get a map of how I think.\nI do not want to upload government ID just to ask a sensitive question either. Being an adult does not make someone competent or harmless, and anonymity has legitimate value precisely when the topic is personal, medical, political, or dangerous to discuss openly. A database connecting real identities to people\u0026rsquo;s strangest questions would be an incredible target. No thanks.\nKeystroke biometrics, tab monitoring, timed questions, screen-recording prevention—same answer. If the price of a better response is turning my computer into an exam room and my identity into collateral, the cure is worse than the refusal.\nUse the context I deliberately provide. Let professionals voluntarily verify where that is genuinely necessary. Give me controls over memory and personalization. But do not call surveillance \u0026ldquo;trust.\u0026rdquo;\nA tool, or a liability shield? # A refusal can create useful friction. I am not pretending otherwise. Some information should be harder to obtain, and a model should not blindly optimize for being helpful when the requested help is obviously harmful.\nBut refusal is not the only safe response. Sometimes the safer answer is a careful one: explain the risk, cite the evidence, correct the dangerous assumption, and give the user the part that may keep them from doing something stupid.\nThe people building these systems have to keep asking a simple question: are we building a tool, or are we building a liability shield shaped like a tool?\nI want the tool. Clear boundaries, actual context, inspectable sources, and no cognitive fingerprint required.\n","date":"5 October 2025","externalUrl":null,"permalink":"/cyber_hacking/ai/chatgpt/","section":"Cybersecurity \u0026 Systems","summary":"A personal argument for clearer AI safety boundaries: use context, cite the evidence, give the safe part of the answer, and do not demand an identity profile in return.","title":"When ChatGPT Got Smarter and Harder to Use","type":"cyber_hacking"},{"content":"The 1753CTF challenge was called Unbreakable. It gave us a ciphertext and the C# code that had produced it. The code XORed the flag with a buffer from System.Random, apparently trying to build a one-time pad.\nThe name was generous. The important part looked like this:\nvar seed = new DateTimeOffset(DateTime.Today).ToUnixTimeSeconds(); var random = new Random((int)seed); var randomBuffer = new byte[flag.Length]; random.NextBytes(randomBuffer); DateTime.Today is local midnight. That means every run on the same day used the same seed and therefore the same byte sequence. There were not billions of plausible secrets to search. There was roughly one candidate per day.\nThe XOR was not the bug. A genuine one-time pad uses a uniformly random, secret key as long as the message, and never reuses it. This code used the output of a predictable general-purpose PRNG. It looked similar on screen, but it had none of the property that makes a one-time pad unbreakable.\nRebuilding the buffer # System.Random is deterministic: same seed, same implementation, same sequence. Since I knew the challenge had been prepared near the event, I generated the buffer for each plausible date, XORed it with the ciphertext, and checked whether the result had the known flag format.\nThere is no reason to brute-force every second. The seed only changes when DateTime.Today changes:\nusing System.Text; const string encryptedHex = \u0026#34;22ECCDB90936D5C2454A65A5BB4C120FB1C8567381C6DB368EB57D4C6BE8B6D8C860E5C6FAC1F48BF2291A5C9EA3C354715857E7\u0026#34;; var ciphertext = Convert.FromHexString(encryptedHex); var latestLikelyDate = new DateTime(2024, 7, 1); for (var daysBack = 0; daysBack \u0026lt; 366; daysBack++) { var candidateDate = latestLikelyDate.AddDays(-daysBack); var seed = new DateTimeOffset(candidateDate).ToUnixTimeSeconds(); var random = new Random(unchecked((int)seed)); var randomBuffer = new byte[ciphertext.Length]; random.NextBytes(randomBuffer); var plaintextBuffer = new byte[ciphertext.Length]; for (var i = 0; i \u0026lt; ciphertext.Length; i++) plaintextBuffer[i] = (byte)(ciphertext[i] ^ randomBuffer[i]); var plaintext = Encoding.ASCII.GetString(plaintextBuffer); if (plaintext.StartsWith(\u0026#34;1753c{\u0026#34;) \u0026amp;\u0026amp; plaintext.EndsWith(\u0026#34;}\u0026#34;)) { Console.WriteLine($\u0026#34;{candidateDate:yyyy-MM-dd}: {plaintext}\u0026#34;); break; } } My matching seed was 19 days behind the date I started from. The result:\n1753c{you_will_never_guess_the_flag_coz_i_am_xorrro} One small implementation detail: new DateTimeOffset(candidateDate) applies the machine\u0026rsquo;s local UTC offset. If the challenge was generated in another time zone, search the plausible offsets as well. Also use the same .NET generation as the challenge if a seeded sequence does not match; a PRNG\u0026rsquo;s output is an implementation detail, not a portable file format.\nPRNG does not mean broken # An ordinary pseudo-random number generator is not useless or defective. System.Random is perfectly reasonable for simulations, games, shuffling a playlist, randomized tests, and other cases where nobody benefits from predicting the next value.\nIt is wrong for secrets.\nA cryptographically secure pseudo-random number generator is usually deterministic too. The difference is in its design and its state:\nIt is seeded and periodically reseeded from high-quality entropy maintained by the operating system. Observing output should not let you reconstruct its internal state or predict later output. Learning the current state should not casually reveal all earlier output. The seed space is large enough that guessing it is not a realistic search strategy. The operating system gathers unpredictability from platform-specific sources and maintains a random pool or generator for applications. You normally ask the OS for bytes; you do not invent a seed from the clock, process ID, username, mouse position, or some home-made mixture of those things.\nIn modern C#, fill a buffer with RandomNumberGenerator:\nusing System.Security.Cryptography; var bytes = new byte[32]; RandomNumberGenerator.Fill(bytes); In a browser, use Web Crypto rather than Math.random():\nconst bytes = new Uint8Array(32); crypto.getRandomValues(bytes); For actual encryption, do not build your own XOR scheme around either function. Use an authenticated-encryption construction such as AES-GCM or ChaCha20-Poly1305 through a maintained cryptographic library. Random bytes solve the randomness problem; they do not automatically give you a safe protocol, key management, nonces, or integrity.\nThe lesson I kept # \u0026ldquo;Random-looking\u0026rdquo; and \u0026ldquo;unpredictable to an attacker\u0026rdquo; are different requirements.\nIf the value protects a token, password, key, reset link, nonce, lottery result, or anything else someone has a reason to predict, start with the platform\u0026rsquo;s cryptographic API. Never downgrade its entropy by replacing the seed with something convenient.\nAnd if you find a timestamp feeding a normal PRNG in a CTF, do not stare at the ciphertext for too long. Search the clock.\nSources # Microsoft: System.Random Microsoft: RandomNumberGenerator.Fill MDN: Crypto.getRandomValues() W3C: Web Cryptography Level 2 ","date":"1 July 2024","externalUrl":null,"permalink":"/cyber_hacking/capture-the-flag/predictable-random/","section":"Cybersecurity \u0026 Systems","summary":"A 1753CTF solve showing why ordinary PRNGs are useful but wrong for secrets, how a predictable seed breaks XOR encryption, and what CSPRNGs do differently.","title":"Predictable Random","type":"cyber_hacking"},{"content":"Most people use credit cards every day without understanding the vulnerabilities hidden in their pockets. This guide explores the operational \u0026ldquo;how\u0026rdquo; behind credit card fraud, demystifying the tricks used by modern thieves. By learning how these systems actually work, and where they break, you can better protect your financial integrity from unauthorized access.\nNote: This is an ongoing project; I\u0026rsquo;m learning as I go, so feel free to contribute if you spot an inaccuracy.\nDisclaimer # Please note that the content provided in this document is intended solely for educational purposes. The aim is to raise awareness and provide information on credit card security and related topics. This document is not meant to serve as a comprehensive guide and should not be interpreted as encouragement or instruction to engage in any form of illegal activity.\nI strongly advise against any illegal actions and recommend always adhering to the laws and regulations of your jurisdiction. Stay informed and use this information responsibly.\nTable of Contents # Introduction How are Credit Cards Stolen Social Media Explaining the Numbers Guessing the Card Number NFC/EMV Capturing Magnetic Stripe Physical Theft and PIN Stealing Dark Web Activities Using the Obtained Details Other Things to Consider Protection NFC Blockers One-Time Cards Alerts on Payment Credit Score Monitoring Insurance Conclusion Introduction # In this article, I aim to demystify the various aspects of credit card fraud by compiling a comprehensive resource on the subject. Given the scarcity of detailed information available online and the critical importance of this issue, I felt compelled to create this guide. It is designed exclusively for educational purposes, with the goal of enlightening individuals on the intricacies of credit card security. By sharing this knowledge, my intention is to equip people with the tools they need to protect themselves and promote a broader understanding of how to navigate the complexities of financial security in today\u0026rsquo;s digital world.\nHow are Credit Cards Stolen? # There are numerous ways that the details of a credit card can be stolen. This list includes the most creative and common ways it can be done. But there are certainly more ways it could be done.\nSocial Media # Have you ever noticed how many mirror selfies there are on social media platforms? Quickly browsing through, one can easily encounter a mirror selfie where the individual\u0026rsquo;s phone case, holding their cards, inadvertently exposes portions of their credit card details.\n(Poorly generated DALL-E picture, but you get the point)\nYou might notice that his fingers cover up parts of the number. Well, that doesn\u0026rsquo;t always help. Let me explain what the card numbers mean.\nExplaining the Numbers # Let\u0026rsquo;s consider a documented Visa test number (never use a real card number in examples):\n4111111111111111\nThese numbers are not completely random. This is, in fact, a valid number. The very first number (MII) reveals the card\u0026rsquo;s issuing entity. Here is a list of which first numbers correspond to which network:\n3: American Express\n4: Visa\n5: Mastercard\nThe first 6 digits (411111) represent the BIN (Bank Identification Number). This number can identify the card network and issuer range. You can find several good lists and websites for research, but use documented test data rather than real payment details.\nThe remaining numbers are generated using a specific method, known as the Luhn Algorithm, or MOD10. This is the algorithm used by websites to check that your card details are valid. It is not an algorithm for security, it is simply an algorithm for avoiding accidental errors.\nGuessing the Card Number # So, suppose a digit is missing from the card number. Knowing that the card uses the Luhn algorithm means that there is only one correct digit. Let\u0026rsquo;s make a quick Python script to brute force the missing digit:\nfrom itertools import product import sys def luhn_check(card_number): def digits_of(n): return [int(d) for d in str(n)] digits = digits_of(card_number) odd_digits = digits[-1::-2] even_digits = digits[-2::-2] checksum = sum(odd_digits) for d in even_digits: checksum += sum(digits_of(d * 2)) return checksum % 10 == 0 def find_missing_digits(partial_card_number): total = 0 missing_indices = [i for i, x in enumerate(partial_card_number) if x == \u0026#39;*\u0026#39;] for replacement in product(\u0026#39;0123456789\u0026#39;, repeat=len(missing_indices)): test_number = list(partial_card_number) for index, digit in zip(missing_indices, replacement): test_number[index] = digit test_number_str = \u0026#39;\u0026#39;.join(test_number) if luhn_check(int(test_number_str)): total += 1 print(test_number_str) print(\u0026#34;Total number of combinations: \u0026#34; + str(total)) partial_card_number = sys.argv[1] find_missing_digits(partial_card_number) This script accepts a card number, and fills in the missing digits. Let\u0026rsquo;s say we give it the documented test number with one digit hidden: 41111111111111*1:\nhenrik@henrik:~/Documents$ python3 luhn.py 41111111111111*1 4111111111111111 Total number of combinations: 1 Only one card number will be valid. However, the number of combinations increases exponentially with each additional missing digit. For example, if there are three missing digits, there are 10² possible combinations that are technically valid, but only one will be the card you are looking for.\n41111111111111** = 10¹ = 10\n4111111111111*** = 10² = 100\n411111111111**** = 10³ = 1000\nBut let\u0026rsquo;s say the first 6 digits are missing, but the bank\u0026rsquo;s name is visible on the card. We can then find a BIN list and search for the bank. In this case, let\u0026rsquo;s say the visible number is:\n******1111111111\nand there is a logo of a bank. For a safe demonstration, we use a documented test BIN rather than a real issuer mapping:\niin_start scheme type bank_name 411111 visa test DOCUMENTED TEST DATA If we combine this with the Luhn brute force (if another random number is missing), we see that the card numbers can be guessed, even if up to seven numbers are missing.\nIn addition to this, some cards have all information visible on one side. Most cards have the CVV on the back, which makes it more secure to the \u0026ldquo;selfie attack\u0026rdquo;, but for some reason not all.\nNFC/EMV Capturing # Did you know the chip in your card uses \u0026ldquo;NFC\u0026rdquo; or Near Field Communication? This technology requires the card to be close to a reader to exchange data. It’s designed for convenience - tap your card, and you\u0026rsquo;re done. But there\u0026rsquo;s a catch.\nNFC\u0026rsquo;s convenience also makes it a target. Some have even engineered devices to capture card data from meters away. Think about that next time you\u0026rsquo;re in a crowded place.\nAnother threat comes from \u0026ldquo;skimmers.\u0026rdquo; These devious devices are attached to regular bank terminals, duplicating your card’s details without you knowing. Crafty criminals place these skimmers where you\u0026rsquo;d least expect them.\nBut, here\u0026rsquo;s the good news: cloning your credit card isn\u0026rsquo;t easy. Cards come with transaction signing keys that are extremely difficult to extract. These systems ensure the data sent is unique every time, based on secure, non-extractable information. This makes it near impossible to for an attacker to clone your card and physically use it in a store. Additionally, the PIN code is only known by you. But we will discuss ways of getting this later.\nBut even with these security measures in place, critical details of your card can still be compromised. By using your phones NFC scanner, you can easily capture the full card number, expiration date, and other vital details. While it might not seem enough, this information is far from useless to a criminal. It could be all they need to access your funds.\nMagnetic Stripe # Unlike its more modern counterpart, NFC, the data stored on a magnetic stripe is entirely static. What does this mean? Each time you swipe your card, the same unchanging data is read by the card reader. This includes your card number, expiration date, and more.\nThis static nature is precisely what makes magnetic stripes a security concern. Since the data doesn\u0026rsquo;t change, it\u0026rsquo;s alarmingly easy for criminals to clone. All it takes is a simple device to read the stripe\u0026rsquo;s data and transfer it onto a counterfeit card. Suddenly, they have everything they need to make unauthorized transactions.\nThe good news is that the financial industry is moving away from this outdated technology. Magnetic stripes are gradually being phased out, replaced by more secure alternatives like chip-and-PIN and NFC. These newer technologies are dynamic, changing their authentication data with each transaction, making them much harder to clone.\nSo, why are magnetic stripes still around? Unfortunately, the transition to newer technologies isn\u0026rsquo;t instantaneous. It requires widespread changes in infrastructure, from ATMs to point-of-sale systems worldwide. Plus, magnetic stripes serve as a backup in regions where chip-and-PIN or NFC technologies are not yet fully implemented.\nIf you want to learn more about the magnetic stripe and its vulnerabilites. I highly recommend watching Samy Kamkar’s video on the subject. He has developed vulnerabilities and devices used for attacking magnetic stripes, and will explain the theory behind the stripe and attack much better than me.\nPhysical Theft and PIN Stealing # Physical theft still remains a concern. But, even if a thief gets your card, cracking your PIN is another hurdle.\nBut! Some criminals use infrared cameras to snap a quick photo of the keypad right after you\u0026rsquo;ve entered your PIN. The heat signature reveals the numbers pressed - the warmest being the most recent. It\u0026rsquo;s like a heat map to your PIN code. This does, however, not work for metal buttons, as metal has a high thermal conductivity. This means that it will rapidly transfer heat, making it impossible for an attacker to see what you pressed.\nCan you guess the PIN code from the image below?\n(screenshot from Mark Rober\u0026rsquo;s video)\nCorrect, the code is 1,2,3,4,5. 5 being the hottest (most recent), and 1 being the coolest (first).\nAnd don\u0026rsquo;t forget about hidden cameras. Positioned just right, these can record your PIN as you enter it. Covering your PIN code is always a good idea.\nDark Web Activities # Venture into the dark web, and you\u0026rsquo;ll find hidden marketplaces where anything is up for sale, including stolen credit card details.\nIn these markets, credit card information isn\u0026rsquo;t exchanged as physical cards but rather as digital files. These files contain complete details necessary for making unauthorized purchases. The price of this stolen data varies greatly. High-balance cards, or those without 2FA (Two-Factor Authentication), have a higher price. However, for skilled cybercriminals, 2FA is merely a hurdle, not a blockade. We\u0026rsquo;ll explore their bypass methods later.\nBut the trade doesn\u0026rsquo;t stop at credit cards. The dark web is also full of illicit sales of compromised PayPal accounts, cryptocurrency wallets, among other digital assets.\nSo you may ask, why don\u0026rsquo;t these cybercriminals use the stolen details themselves, especially when they sell them for much less than their worth? There are several reasons. Many sellers have large amounts of data that is obtained through botnets, making it impractical to exploit each piece of data individually. While some may fear the risks of getting caught, others might lack the means or expertise to exploit these accounts fully. Successfully using this data without detection involves complexities and risks that go beyond what I can cover here.\nUsing the Obtained Details # Now that a criminal has access to your credit card information, what\u0026rsquo;s their next move? You might imagine them cloning the card for physical shopping sprees, but the reality is often different and more digitally oriented.\nContrary to popular belief, cloning a credit card for physical use isn\u0026rsquo;t the go-to method for fraudsters. Remember our discussion about NFC chips? They\u0026rsquo;re incredibly challenging to duplicate with standard equipment. And while magnetic stripes are more vulnerable, their gradual phase-out makes them less appealing. Moreover, in many places, finding stores that still accept swipe transactions is becoming increasingly difficult.\nEven if they manage to clone the card, there\u0026rsquo;s the hurdle of obtaining the PIN. Plus, using a cloned card in stores carries significant risks – security cameras, potential eyewitnesses, and the chance of leaving behind fingerprints. It\u0026rsquo;s a gamble with high stakes.\nInstead, criminals often opt for the path of least resistance: using your card online. The digital realm offers a veil of anonymity and eliminates the need for sophisticated cloning equipment. It\u0026rsquo;s simpler, safer (for the criminal), and often more lucrative to misuse stolen card details in the virtual world. Online transactions produce less physical evidence (if done correctly), making it harder to trace back to the fraudster.\nPicture this scenario: a criminal stumbles upon an image of your credit card on social media. With a bit of clever calculation and some basic information from your online profiles, they now have everything: your full card number, expiration date, name, and even the CVV.\nYou might feel a sense of security, thinking, \u0026ldquo;I\u0026rsquo;m protected; I have 2-FA enabled.\u0026rdquo; Two-Factor Authentication is indeed a robust security feature, often involving a verification code sent to your phone. However, there\u0026rsquo;s a catch.\nThe implementation of 2-FA isn\u0026rsquo;t solely in your bank\u0026rsquo;s hands; it\u0026rsquo;s also at the discretion of the merchants. While some prioritize security by requiring this extra step, others opt for a more streamlined checkout process, bypassing additional verification to facilitate quicker purchases. This is particularly common among foreign online retailers.\nFor you, the cardholder, this means that not all transactions are equally safeguarded. If your card details are used at a merchant that doesn\u0026rsquo;t require 2-FA, the transaction could proceed unchallenged.\nIn case of a fraudulent charge, the burden of proof lies with the merchant. As a cardholder, you have the right to dispute any unfamiliar charges on your bill. Having 2-FA enabled will make it easier for the merchant to prove that you were the one to actually make the purchase, making it harder to dispute.\nBut not only this, criminals have other ways of getting around 2-FA. There is something called SIM Swapping.\n“The fraud exploits a mobile phone service provider\u0026#39;s ability to seamlessly port a phone number to a device containing a different subscriber identity module (SIM). This mobile number portability feature is normally used when a phone is lost or stolen, or a customer is switching service to a new phone.” -Wikipedia This means that the attacker needs to trick the service provider into swapping the number to a different phone. This attack is more common than you would think.\nThere are also mentions of large websites not requiring the CVV code, as again, this is only an additional step to prove that you made the purchase. It is not actually needed in order to make a purchase. However, I have not personally been able to find any websites that does not require the CVV.\nOther Things to Consider # I thought I should also quickly mention “fullz”.\nFullz is underground slang for the comprehensive set of personal data collected about an individual. This isn\u0026rsquo;t just a scattering of personal details. We\u0026rsquo;re talking about a complete, packaged identity, ripe for misuse.\nWhat does fullz include? Fullz includes all information necessary to impersonate you: your social security number, driver\u0026rsquo;s license number, full name, date of birth, your home address, and phone number.\nWith these details, a fraudster can wreak havoc. They could apply for credit card loans in your name, while cleverly diverting all bank communications to themselves. The chilling part? You wouldn\u0026rsquo;t even know that a loan is being taken out under your name. You\u0026rsquo;re left in the dark while the fraudster operates in the light.\nAnd where is this sensitive information traded? Well, again, on the dark web, fullz can be shockingly cheap – usually not more than a dollar. The lower price, however, doesn\u0026rsquo;t lessen the potential damage. It\u0026rsquo;s a full-fledged identity theft kit, priced less than a cup of coffee.\nProtection # Now that we\u0026rsquo;ve discussed ways of stealing your information, let\u0026rsquo;s talk about how to protect yourself.\nNFC Blockers # You\u0026rsquo;ve likely seen ads for RFID-blocking wallets. These wallets use materials that interfere with RFID signals, preventing scanners from reading your card data. Want a DIY solution? Wrapping your cards in aluminum foil is a surprisingly effective and inexpensive home alternative.\nOne-Time Cards # Many services now offer virtual, one-time-use cards. You can generate multiple virtual cards for different transactions. Once a payment is completed, you can simply delete the card. This is a great way to safeguard against the theft of your actual card numbers, especially in online transactions.\nAlerts on Payment # With \u0026ldquo;Alerts on Payment\u0026rdquo; from your banking app, you\u0026rsquo;ll get immediate notifications for every card transaction. This instant update lets you act fast if there\u0026rsquo;s any unauthorized use, helping you to quickly contest suspicious charges. It\u0026rsquo;s an essential tool for staying on top of your transactions without needing to constantly review your statements.\nCredit Score Monitoring # Unnoticed, someone could be misusing your identity to apply for credit cards or loans. Regularly checking your credit score is key to catching this. If a fraudster racks up debt in your name, it won\u0026rsquo;t be paid back, causing your credit score to plummet. Watch for any unexpected, significant changes – it\u0026rsquo;s often the first sign that something\u0026rsquo;s amiss.\nInsurance # This is an often-overlooked layer of protection. Credit card insurance can cover losses due to fraudulent transactions, identity theft, and even accidental purchases. In the event of fraud, the insurance may reimburse unauthorized transactions, providing an added financial safety net. This insurance can be a standalone policy or part of a premium credit card offer. It\u0026rsquo;s about ensuring peace of mind, knowing that you\u0026rsquo;re covered in the worst-case scenarios.\nConclusion # And that brings us to the end of our journey today. While much of the information shared was drawn from American sources, the principles of credit card security we\u0026rsquo;ve discussed are universal. However, specifics can vary by region, so I highly encourage you to delve into the rules and regulations pertinent to your locality for tailored protection strategies.\nSo, to recap some of the key points in this guide:\nAccidental pictures of credit cards can be used to make purchases, even with information missing. Your card can be scanned from several meters, revealing your sensitive information. The security of online transactions. Safety measures to protect you. Please feel free to correct any information here, as I do not want to spread misinformation, and I would love to learn something new.\n","date":"15 August 2023","externalUrl":null,"permalink":"/cyber_hacking/credit_card_security/","section":"Cybersecurity \u0026 Systems","summary":"A defensive guide to how credit-card fraud works in practice: leaked numbers, social media exposure, NFC myths, physical theft, dark-web resale, and realistic protection.","title":"Credit Card Security","type":"cyber_hacking"},{"content":"How a filename convinces you to trust the wrong parser\nYou see quarterly_report.pdf in your downloads folder. Nice PDF icon, normal-looking name, nothing weird. You double-click it. Whoopsies! It was not a PDF.\nThe important part is not that an extension can \u0026ldquo;lie.\u0026rdquo; A filename is only one claim about a file. Explorer uses the name to choose an icon and an associated application. A scanner may inspect the first few bytes. An archive tool may look at structures near the end. The application that finally opens it has its own parser and its own idea of what counts as valid.\nUsually those layers agree, so we stop thinking about them. File spoofing lives in the gaps where they do not.\nThe Right-to-Left Override (RTLO) # This one is my personal favourite, and it is the technique behind my old tool ExtensionSpoofer.\nUnicode includes a Right-to-Left Override character, U+202E, for bidirectional text. Put it in a filename and the characters after it can be displayed in reverse order:\ntest_application[U+202E]gnp.exe may be rendered as:\ntest_applicationexe.png The bytes did not become a PNG. The extension did not change. Only the visual order of part of the name changed, which is enough to fool a person who reasonably assumes that the text on screen represents the actual name.\nI wrote ExtensionSpoofer in 2018 to demonstrate the trick and pair the displayed name with a convincing icon. It was mostly undetected when I first released it, then security products started recognising the pattern. GitHub later showed roughly 16,000 downloads, and I found copies redistributed on forums, including paid ones. I am not claiming responsibility for antivirus vendors noticing RTLO, but I would like to think the tool annoyed at least a few of them.\nWhile looking for redistributions of my software, I also found this unexpected use of another tool I wrote:\nMITRE tracks this specific behaviour as Right-to-Left Override, T1036.002.\nLNK files: the icon is not the target # A Windows .lnk file is not a document. It is a shell-link structure containing a reference to another target, plus display metadata such as an icon and description. That separation is useful for normal shortcuts, but it also creates another disagreement: Explorer can show the shortcut as one thing while the stored target points somewhere else.\nExplorer commonly hides the .lnk suffix independently of the normal \u0026ldquo;show file extensions\u0026rdquo; setting. A shortcut named like a document can therefore look like the document itself, especially if it borrows the expected icon. The shortcut-arrow overlay is a useful clue when it appears, but it is decoration, not a security boundary. Themes, registry changes, and different shell views can change or remove it.\nThe correct question is not \u0026ldquo;does the icon look right?\u0026rdquo; It is \u0026ldquo;why did I receive a shortcut where I expected a document?\u0026rdquo; If a download or attachment unexpectedly resolves to a shell link, stop there and inspect the target rather than opening it.\nMicrosoft documents the fields and purpose of the format in the Shell Link (.LNK) specification.\nLong names and double extensions # These are less clever, but they exploit the same trust gap.\ntotally_legit_document.pdf .exe A narrow Explorer column, notification, or attachment preview may truncate the right side and leave only the comforting part visible. Nothing magical happened to the file. The interface simply did not show the part that mattered.\nDouble extensions work similarly:\nreport.pdf.exe If known extensions are hidden, the last suffix may disappear. Even when it is visible, people often recognise the first familiar suffix and stop reading. Showing extensions is still worth doing, but it only gives you more evidence. It does not verify the file\u0026rsquo;s contents.\nAlternate Data Streams (ADS) # NTFS files can have more than one data stream. The unnamed $DATA stream is what most applications mean when they open a normal path. A file or directory can also have named streams addressed with syntax such as filename:streamname.\nThis is old NTFS functionality from the Windows NT era, not something introduced with Windows Vista. Vista is merely the oldest client supported by the current Sysinternals Streams release.\nNamed streams are not automatically malicious. Windows itself uses the Zone.Identifier stream for Mark of the Web, which records that a file came from an untrusted zone and helps trigger warnings and policy checks. Other software can store metadata there as well.\nThey do create visibility problems:\nExplorer\u0026rsquo;s ordinary size and content views focus on the unnamed stream. A hash calculated from the normal file path usually covers the unnamed stream, not every named stream attached to it. Copying to a file system or through a tool that does not support named streams may discard them. A scanner has to enumerate streams deliberately if it wants to inspect all of them. That does not make ADS an executable format by itself. Something still has to read or act on the named stream. The problem appears when one component inventories only the default stream while another component later consumes additional data.\nFor inspection, Windows provides dir /R; PowerShell can enumerate streams with Get-Item -Stream *; and Microsoft\u0026rsquo;s Sysinternals Streams utility can scan them recursively. Microsoft also documents the underlying model in File Streams.\nArchives add another parser # A ZIP, RAR, 7z, or ISO is a container. It adds one more layer between the thing you received and the files eventually opened.\nA mail gateway may recognise the outer archive, unpack it, classify every member, and apply policy recursively. Or it may fail on an unsupported format, an excessive nesting depth, or encrypted content. Password protection is especially simple: without the password, a scanner cannot meaningfully inspect the contents.\nModern Office formats such as .docx, .xlsx, and .pptx are ZIP-based containers too. That is normal and useful. It also means that \u0026ldquo;the extension says document\u0026rdquo; is still only the outer description of a collection of files interpreted by a much more complicated parser.\nAn archive is not dangerous by default, and it is not a magic bypass. It just moves the trust decision. You still need to inspect what came out before treating it as the document you expected.\nPolyglot files # Polyglots are the cleanest example of parser disagreement because the file can genuinely satisfy more than one format.\nDifferent formats care about different structures. JPEG readers expect characteristic marker bytes. PDF readers search for PDF objects and cross-reference data. ZIP readers locate their central directory near the end. If two sets of rules do not conflict, one byte sequence can be accepted by both parsers.\nThat does not mean every polyglot is malicious. It means \u0026ldquo;valid according to parser A\u0026rdquo; does not prove \u0026ldquo;contains nothing meaningful to parser B.\u0026rdquo;\nJPCERT/CC documented a MalDoc-in-PDF sample that combined PDF structure with Word/MHTML content. The campaign used a .doc extension, so Windows opened it with Word; PDF-focused tools could still recognise and analyse the PDF portion while missing the behaviour exposed to Word. That detail matters. The file did not somehow execute merely because a PDF reader saw it. The chosen application decided which interpretation became active.\nMITRE groups this broader behaviour under Masquerade File Type, T1036.008.\nThe actual trust problem # All of these tricks rearrange the same chain:\nOrigin: Where did the file come from, and was provenance preserved? Presentation: What name, icon, and preview did the shell show? Classification: What did the scanner or gateway decide it was? Parsing: Which application eventually interpreted the bytes? Capability: What was that application allowed to execute or access? An attacker does not need to defeat every layer. They only need an early layer to approve one interpretation and a later, more powerful layer to act on another.\nThat is also why \u0026ldquo;be careful\u0026rdquo; is such useless advice. Careful about which representation? If the interface hides the extension, the icon is attacker-controlled, and the scanner picked the wrong parser, a user can inspect exactly what they were shown and still reach the wrong conclusion.\nWhat I actually check # I keep extensions visible, while remembering that an extension is still metadata. I treat an unexpected shortcut, archive, disk image, or executable as a change in the deal. If someone promised a PDF and sent something else, I want an explanation before opening it. I preserve Mark of the Web and pay attention when Windows says a file came from the internet. Stripping that metadata removes useful context. For suspicious files, I compare the extension with the detected format and inspect nested contents in an isolated environment. I use application control and sandboxing for the final parser. Identification can fail; limiting capability is what keeps that failure boring. I query hashes before uploading anything private to a public scanning service. Uploading a confidential file to VirusTotal is still uploading a confidential file. Awareness helps, but consistent classification and limited execution rights help more. A blue arrow, a familiar icon, or .pdf at the end of some visible text is not a trust decision.\nAnd yes, not using Windows avoids several tricks on this page. It does not make parser disagreement disappear. Annoying, I know.\n— Henrik\nSources and further reading # Microsoft: Shell Link (.LNK) Binary File Format Microsoft: File Streams Microsoft Sysinternals: Streams MITRE ATT\u0026amp;CK: Masquerading, T1036 JPCERT/CC: MalDoc in PDF ","date":"15 August 2018","externalUrl":null,"permalink":"/cyber_hacking/file-spoofing/","section":"Cybersecurity \u0026 Systems","summary":"A practical look at RTLO, shortcuts, misleading extensions, NTFS streams, archives, and polyglots through the thing they all exploit: disagreement about what a file actually is.","title":"File Spoofing","type":"cyber_hacking"},{"content":"This is a roadmap, not a finished guide. Nothing below is published yet, so the list at the bottom of this page is empty on purpose rather than broken. Sleep is the one being written first, because it sits upstream of most of the others.\nI think of the body as a stack of interacting systems. Sleep changes cognition. Gut problems change mood. Environment changes baseline stress. Skin, hair, vision, oral health, and appearance all feed back into identity in ways people like to pretend are shallow.\nThe goal here is not optimization theater. The goal is to understand the system well enough to stop guessing.\nPlanned threads:\nBrain: attention, mood, memory, motivation, and reward. Sleep: recovery, timing, light, and routines that actually survive contact with real life. Gut: digestion, inflammation, appetite, and the gut-brain loop. Environment: air, light, noise, temperature, and the room as an input device. Body: strength, pain, energy, posture, and capacity. Skin, hair, oral health, vision, appearance: the visible edge of the system. ","externalUrl":null,"permalink":"/health/hacking-health/","section":"Health \u0026 Self-Experimentation","summary":"This is a roadmap, not a finished guide. Nothing below is published yet, so the list at the bottom of this page is empty on purpose rather than broken. Sleep is the one being written first, because it sits upstream of most of the others.\n","title":"Body Systems","type":"health"},{"content":" Writeups # I\u0026rsquo;ve posted most of my writeups on GitHub, but they\u0026rsquo;re poorly organized and split across two languages. From 2026 onward, I\u0026rsquo;ll post them here in a consistent format.\nI rewrite older favourites when I have enough context to make them useful. I would rather show one finished solve than build a graveyard of “coming soon” headings.\n2024 # 1753CTF # Unbreakable — predictable random / broken OTP implementation\nNovacare, July 2024 # I\u0026rsquo;m kind of proud of this one. It was a simple race-style CTF: the challenge was released at exactly 00:00, and I submitted my answer 50.3 seconds later. Can you beat that? There is no context, and the timer starts as soon as you reveal the text:\nDay 16: BEEEP BEEEEEP! Hi!\nToday I got a call from a lady who claimed to have important information about Tensinet and asked me to meet her later today. There was something strange about her voice; she almost sounded like a witch. Maybe the voice was just distorted. I think you can read the debt you have, but I don\u0026rsquo;t know what you\u0026rsquo;re doing.\nAt the very end of the call, there were some strange beeping sounds. Can you check whether you can get a code word out of it?\n/sander\nCTF tools # Some challenges are solved with standard tools. Others become much easier if you write something small yourself.\nBelow are some of the tools, scripts, and approaches I’ve used in CTFs, including a few things I’ve made myself.\nGeneral skills # Quick Python scripts (or any scripting language) Bash Regex PowerShell C and assembly knowledge Web and frameworks Linux/Windows/Mac familiarity Steganography # AperiSolve - hidden bits and color analysis zsteg - useful for PNG/BMP LSB-style challenges StegSolve - channel inspection and quick visual analysis Foremost - CLI tool for file-signature-based extraction binwalk - extracting embedded content Sonic Visualiser - spectrogram analysis Audacity - waveform and spectrogram inspection ImageMagick - comprehensive CLI tool for images GIMP - image repair, contrast tweaks, QR cleanup Custom chunk and byte inspection scripts Examples # BEEB-BEEEEEP (Norwegian writeup) - fun and easy task involving DTMF decoding and ASCII conversion.\nThe sound of..? (Norwegian writeup) is another simple steganography task involving image extraction from audio files. You can pretty much immediately tell when an audio file sounds like an image, as strange as that sounds.\nImageProcessing2 (Norwegian writeup) - I used a Fourier transform and high-pass filter to remove low frequencies, then brightened the result until the hidden text became visible. Tools: Python, NumPy, Pillow, and FFT.\nDots (Norwegian writeup) is a simple task I solved with ImageMagick by splitting a GIF into 4,000 frames, filtering out certain colors, and combining the frames into a single image containing the flag.\nReverse engineering # Ghidra strings x64dbg pwndbg / gdb Cutter / radare2 Small helper scripts for decoding constants, lookup tables, and custom encodings Examples\nDebug_RAT (Norwegian writeup) - Basic static analysis with Ghidra and strings to find hidden checks and commands, leading to retrieving the flag from a remote server.\nOceanLocust is one of my favourite examples of practical reverse engineering. Instead of trying to fully understand the binary at once, I treated it like an encoder oracle. By generating my own encoded PNGs, extracting the custom biTx chunks, and comparing byte patterns across different inputs, I could slowly reconstruct the hidden flag from the challenge image.\nReversing script logic # Python itself Throwaway Python scripts ChatGPT for quickly translating weird logic into readable pseudocode Examples\nFirewood (Norwegian writeup) is a nice introductory challenge for reversing script logic.\nBinary exploitation # pwndbg gdb pwntools Python exploit scripts checksec cyclic / pattern create-find Basic fuzzing and crash analysis Web exploitation # Burp Suite Browser dev tools curl ffuf / gobuster / feroxbuster Postman sometimes, but usually Burp or curl is enough Custom request scripts Small brute-force and enumeration scripts Examples\nTrickster was a classic insecure file upload challenge. After checking robots.txt, I found hidden implementation notes that revealed the upload validation was weak. That made it possible to upload a .png.php webshell with valid-looking PNG bytes and execute code server-side.\nNo SQL Injection was a simple but nice auth bypass. I used a Mongo-style operator payload instead of normal credentials, which caused the backend query to match successfully. Burp then showed the returned user object, including a base64-encoded token containing the flag.\nNetwork analysis # Wireshark tshark Ncat / netcat tcpdump Scapy CyberChef for quick packet payload decoding Custom parsers for extracted traffic and challenge-specific data Examples\nEcho Chamber was labeled as scripting, but I first solved it manually in Wireshark by filtering for ICMP echo packets and inspecting the payloads. After that, it was easy to turn the process into a short tshark pipeline that extracted the flag automatically.\nCryptography / ciphers # CyberChef dcode.fr - Great for quick identification and solving of classical ciphers Examples\nRSA_Oracle is a great example of why understanding the cryptosystem matters more than memorizing tools. I used pwntools to interact with the oracle, exploited RSA\u0026rsquo;s multiplicative property to recover the encrypted password indirectly, and then decrypted the final file with OpenSSL.\nPassword guessing / cracking # ZipCrack - an old ZIP password brute-force tool I made fcrackzip Hashcat (offline) John the Ripper (offline) Hydra (web) Wordlists Custom brute-force scripts where the format is partially known Forensics # exiftool CLI tools: file, strings, xxd, hexdump CLI: binwalk CLI: 7z / unzip / foremost / scalpel HxD PDF and archive inspection Examples\nBombzip2 (Norwegian writeup) - a tiny compressed file that expands to an enormous size. For example, \u0026quot;A\u0026quot; * 10^100000000000000 \u0026gt; file.txt would produce a huge file that compresses to very little because the pattern repeats. I found where the filler ended in HxD, copied the useful footer, and rebuilt a smaller valid BZ2 file that decompressed to the flag.\nSecret of the Polyglot was a nice file-carving challenge. The PDF visibly contained half the flag, and the title hinted that the file was actually multiple formats at once. Running foremost against it extracted the embedded PNG, which contained the missing half.\nMob psycho is a good example of quick APK triage. Instead of digging manually through the entire package, I listed the APK contents with aapt, searched for likely flag-related filenames, extracted the matching file, and decoded the hex string inside.\nOSINT # Google dorks Google Maps / Street View / satellite view Overpass Turbo - very useful for map-based filtering and location scripting ShadeMap - matching shadows to estimate time of day Wayback Machine / Internet Archive ExifTool - extract coordinates, time, device, and much more from media Sherlock - username reuse Reverse image search PimEyes - reverse face search GIMP - repairing or extracting clues from images Text and image pivoting Searching mirrors, reposts, and alternate hosts Examples\n1753CTF Fixed Mistake, or is it really fixed? Historical data can often still be found in the Internet Archive.\nMullvarpjakt is a great example of using Overpass Turbo, a query tool for geographic data, to find an exact location from only a few words.\nChronolocation (Norwegian writeup) was a fun task where shadow maps helped determine exactly when an image was taken, even without metadata.\nOSINT (Norwegian writeup) is another example of using Overpass Turbo.\nTerminal jail # Bash # Basically, just know Bash and the Linux environment. These tasks are about creatively applying your knowledge of the system and language.\nExamples\nSansAlpha - A shell challenge where alphabetic characters were mostly unavailable, so the solution had to rely on wildcards, variable tricks, and shell expansion. I used globbing to locate both the flag and a useful binary, then selected the correct expanded path and used it to print the flag.\nTools / techniques: Bash globbing, shell variables, array indexing, command discovery, base64\nPython # Great pyjail resource by a fellow Norwegian CTF-er Not cipher (Norwegian writeup) - A Python jail where only 13 characters were allowed: not+cipher(*). That meant I could not directly write the target path, so I had to build it character by character using chr(...). To generate numbers, I abused expressions like int(not()), then wrote a helper script that generated a huge payload which reconstructed the full path and opened the flag file.\nTools / techniques: Python jail escaping, chr(), int(not()), payload generation, URL encoding, curl\nShort not cipher (Norwegian writeup) - A harder version of the same Python jail, except now the payload also had to stay below 5000 characters. Instead of relying mostly on addition, I compressed the payload by combining multiplication, exponentiation, and later repr() tricks to generate shorter numeric expressions. This turned the challenge into both a jail escape and a code-golf style optimization problem.\nTools / techniques: Python jail escaping, payload minimization, chr(), repr(), arithmetic expression compression, custom generator scripts\n","date":"1 February 2026","externalUrl":null,"permalink":"/cyber_hacking/capture-the-flag/","section":"Cybersecurity \u0026 Systems","summary":"A practical index of CTF writeups, tools, and techniques across steganography, reversing, web exploitation, forensics, crypto, OSINT, and terminal jails.","title":"CTF (Capture the Flag)","type":"cyber_hacking"}]