<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[The Weekly Tinkerer]]></title><description><![CDATA[Things I build out of utility for myself. Software some weeks, the farm other weeks. Output first, process as subplot.]]></description><link>https://theweeklytinkerer.com</link><image><url>https://substackcdn.com/image/fetch/$s_!ubT6!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F491f2404-dd18-4eeb-9093-fe9046b9dedf_256x256.png</url><title>The Weekly Tinkerer</title><link>https://theweeklytinkerer.com</link></image><generator>Substack</generator><lastBuildDate>Tue, 15 Sep 2026 19:28:17 GMT</lastBuildDate><atom:link href="https://theweeklytinkerer.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Kevin Ebert]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[weeklytinkerer@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[weeklytinkerer@substack.com]]></itunes:email><itunes:name><![CDATA[Kevin Ebert]]></itunes:name></itunes:owner><itunes:author><![CDATA[Kevin Ebert]]></itunes:author><googleplay:owner><![CDATA[weeklytinkerer@substack.com]]></googleplay:owner><googleplay:email><![CDATA[weeklytinkerer@substack.com]]></googleplay:email><googleplay:author><![CDATA[Kevin Ebert]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Big Mistake. Big. Huge.]]></title><description><![CDATA[Building a custom email gatekeeper, breaking the cardinal rule of software deployment, and surviving the fallout.]]></description><link>https://theweeklytinkerer.com/p/big-mistake-big-huge</link><guid isPermaLink="false">https://theweeklytinkerer.com/p/big-mistake-big-huge</guid><dc:creator><![CDATA[Kevin Ebert]]></dc:creator><pubDate>Sat, 29 Aug 2026 12:51:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ubT6!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F491f2404-dd18-4eeb-9093-fe9046b9dedf_256x256.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Deploying <a href="https://bwak.news">bwak.news</a> to the public landed differently. The level of abstraction between the users and me lowered the stakes. They are people I don&#8217;t know sitting on the other side of a computer monitor.</p><p>So when I decided to deploy bwak.email to my family&#8217;s email domain, theeberts.us, I was naturally terrified of how my wife, Charlotte, would accept the change.</p><div><hr></div><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://theweeklytinkerer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Weekly Tinkerer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><p>There was no hiding behind a screen of anonymity like <a href="https://bwak.news">bwak.news</a> afforded me. This time, the user lives under the same roof.</p><p>She watched me toil over its development. I reported the progress to her as I tested it on my personal email domain, k3bert.net.</p><p>She understands the concept; it&#8217;s a tool for controlling who sends you emails. You get an email from our bank, approve it. You get an email from a Prince from Sub-Saharan Africa; you deny it. The difference is, these decisions are made before the email lands in your inbox.</p><p>Not a spam filter.</p><p>Not inbox rules.</p><p>Just a gate; you control who gets to enter your inbox.</p><p>The software flips the script; instead of anyone with your address emailing you, they have to pass through a gate that you hold the key to. You don&#8217;t let them in; their email never sees the light of day in your inbox.</p><p>Until last week, the concepts were just that, concepts to her. She lacked any hands-on experience. The things I told her about what the software would do had no meaning until now.</p><p>This was the first time I got to launch software where the primary user lived under the same roof as I did. Her ability to understand and operate the software is the litmus test I&#8217;ll use to decide whether to take the software public.</p><p>So, I was excited and nervous.</p><p>I hit the deploy button and in the immortal words of Vivian Ward (played by Julia Roberts) in the movie &#8220;Pretty Woman&#8221;</p><blockquote><p>Big mistake. Big. Huge.</p></blockquote><p>You see, I did something stupid. Not only did I deploy bwak.email to the theeberts.us domain, but I also decided to move our primary email provider from Proton Mail to Apple&#8217;s iCloud Plus (iCloud+) at the same time.</p><p>You never deploy two breaking changes at the same time. Never. Full stop.</p><p>So, it won&#8217;t come as a surprise to you when I tell you that she went to the USPS website and signed up to receive delivery notifications for a package she was receiving later in the week. Bwak.email sent her the approval request, &#8220;Let <a href="mailto:USPostalService@usps.com">USPostalService@usps.com</a> through&#8221; and she clicked the link to approve, and nothing happened.</p><p>I swear you could see the blood leave my face. Something I had tested hundreds of times before didn&#8217;t work.</p><p>Digging through the logs gave me the error.</p><blockquote><p>Blocked due to content: The message was rejected because it contained content that the recipient&#8217;s server doesn&#8217;t allow</p></blockquote><p>And as if the software gods were watching and laughing at me, another approval request came in, this time from our bank alerting us to a new statement.</p><p>She approved it.</p><p>And again, nothing delivered.</p><p>I sent my own test message in from my Gmail account, approved it, and it works!</p><p>After digging through the Resend API documentation and a few expletives later, I found the root cause.</p><p>The way Resend forwarded the email to the inbox after approval broke the email&#8217;s chain of custody and removed the original DKIM signature. Apple was interrogating the message, recognizing it originated from the USPS. But without the original DKIM signature, it flagged the message as spoofed and would not deliver the forwarded message from bwak.email.</p><p>This behavior was different. All my testing to date used Proton Mail as my mail provider, but as part of this changeover, I moved the domain to Apple&#8217;s iCloud+ service for our mail hosting, essentially negating the months of testing I did with k3bert.net.</p><p>I had a choice to make: roll back to the last known good state, which meant moving back to Proton Mail and undeploying bwak.email from theeberts.us domain. This didn&#8217;t excite me; by now it was 1:30 AM and any rollback would be a three- to four-hour process.</p><p>Emails weren&#8217;t being lost; I still had the failed messages in the logs, but my wife couldn&#8217;t see them.</p><p>So I did the next logical thing, I forged ahead.</p><p>Forging ahead meant finding another mailing service, Mailgun, that had an API that supported forwarding original MIME-type messages, which meant the DKIM would remain intact.</p><p>On paper, it should work.</p><p>It took 12+ hours to set up the Mailgun account. There was a verification process I had to go through to prove ownership of the domain I was using, and to describe the system I built, which required a human to review and approve.</p><p>In the end, I swapped out Resend for Mailgun, and I was ready to test again.</p><p>I might be making it up, but I swear I saw the clouds part and the sun come through the moment Charlotte hit approve on the same USPS message from the day before, and bwak.email delivered the message.</p><p>You could hear Katrina and the Waves&#8217; song &#8220;Walking on Sunshine&#8221; start up in the background. That was me, walking on sunshine and partying like you&#8217;d expect a 54-year-old retired technologist would party.</p><p>A few days later, Charlotte is managing our email domain theeberts.us like a boss. I&#8217;ve purposefully stepped back to let her go at it. I spent 60 seconds explaining how to use the app, and here she was a few days later, owning it, approving and blocking senders like the pro she is.</p><div><hr></div><h3>Interesting Read</h3><p>This week, I&#8217;m adding a new section to the newsletter that you&#8217;ll see from time to time. It&#8217;s part experiment and part advertisement for <a href="https://bwak.news">bwak.news</a>, the first app I built to bring to market. </p><p>The whole point of this section is that it&#8217;s a quick take on something I read over the last week that got me thinking, and I want to share.</p><h4>Hiding Out &#8212; Seth Godin</h4><p>Originally published via Seth&#8217;s Blog Newsletter: <a href="https://app.bwak.news/share/aoci2PpJ10w">https://app.bwak.news/share/aoci2PpJ10w</a></p><p><strong>My Take<br></strong>I have a long history of playing things safe, or at least holding things close to my chest.</p><p>Safe works until it doesn&#8217;t.</p><p>Being reminded that time is batting a thousand for outing safety motivates you to bet on yourself.</p><p>Truer words couldn&#8217;t be spoken for where I&#8217;m at in my life at this point. I&#8217;m calling myself retired, but I&#8217;m learning I have a lot more to give. So recoiling into the safety of my home is no longer a stance I&#8217;m taking because time will out me.</p><div><hr></div><p>What&#8217;s something you built, wrote, or made that you didn&#8217;t really trust was good enough? Not until someone picked it up on their own and got it, without you there to explain it?</p><p>&#8212;Kevin</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://theweeklytinkerer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Weekly Tinkerer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Who Decides You're the Problem?]]></title><description><![CDATA[A Waymo called the cops on two teenagers. The privacy question turned out to be the wrong one.]]></description><link>https://theweeklytinkerer.com/p/who-decides-youre-the-problem</link><guid isPermaLink="false">https://theweeklytinkerer.com/p/who-decides-youre-the-problem</guid><dc:creator><![CDATA[Kevin Ebert]]></dc:creator><pubDate>Sat, 22 Aug 2026 13:02:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/EPxy-25Lefc" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Who is really behind the curtain when an autonomous vehicle decides to pull over under the guise of a &#8220;technical issue?&#8221; But, that &#8220;technical issue&#8221;, may indeed be a ruse set off by an alert and provide the the cover and time for the authorities to arrive on the scene and investigate.</p><p>I had my assumptions, but decided it was worth looking into further.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://theweeklytinkerer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Weekly Tinkerer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>My first instinct told me this was a privacy nightmare, a case of false pretense, deceit, lies, or worse entrapment. I was having a visceral reaction of hell no, I&#8217;ll never set foot in a Waymo vehicle. I will not surrender any more of my privacy rights in the name of convenience in the surveillance economy.</p><p>I&#8217;m, of course, talking about the recent incident where Waymo stopped a vehicle and alerted local police because two teenage riders were acting suspiciously in the vehicle during their ride. The passengers were allegedly drinking and waving guns (that turned out to be toys). <sup>[1]</sup></p><p>The story goes that suspicious activity was detected, alerted a Waymo employee who intervened telling the the passengers there was a &#8220;technical issue&#8221; with the car, advising that it was pulling over and that they should remain in the vehicle. Simultaneously, Waymo contacted the police, gave them the vehicle&#8217;s location, and kept it there until they arrived.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zuAt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f5098b2-f538-4129-9a07-1632dd775b96_1080x300.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zuAt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f5098b2-f538-4129-9a07-1632dd775b96_1080x300.png 424w, https://substackcdn.com/image/fetch/$s_!zuAt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f5098b2-f538-4129-9a07-1632dd775b96_1080x300.png 848w, https://substackcdn.com/image/fetch/$s_!zuAt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f5098b2-f538-4129-9a07-1632dd775b96_1080x300.png 1272w, https://substackcdn.com/image/fetch/$s_!zuAt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f5098b2-f538-4129-9a07-1632dd775b96_1080x300.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zuAt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f5098b2-f538-4129-9a07-1632dd775b96_1080x300.png" width="1080" height="300" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1f5098b2-f538-4129-9a07-1632dd775b96_1080x300.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:300,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:43699,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://theweeklytinkerer.com/i/212173830?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f5098b2-f538-4129-9a07-1632dd775b96_1080x300.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zuAt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f5098b2-f538-4129-9a07-1632dd775b96_1080x300.png 424w, https://substackcdn.com/image/fetch/$s_!zuAt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f5098b2-f538-4129-9a07-1632dd775b96_1080x300.png 848w, https://substackcdn.com/image/fetch/$s_!zuAt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f5098b2-f538-4129-9a07-1632dd775b96_1080x300.png 1272w, https://substackcdn.com/image/fetch/$s_!zuAt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f5098b2-f538-4129-9a07-1632dd775b96_1080x300.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The police officers arrived on the scene and treated it like a high-risk traffic stop and proceeded to remove the passengers from the vehicle and ultimately took them home and didn&#8217;t arrest them.</p><p>After reading the article, I had questions and needed to research this further.</p><h3><strong>Did Waymo play judge, jury, and executioner?</strong></h3><p>Reading the article, that&#8217;s what every fiber in my body was screaming. But I&#8217;ve been known to overreact a time or two, and this was no exception.</p><p>As it turns out, no, not really.</p><p>Nearly a few dozen sensors are installed on each vehicle, both internally and externally. There are the obvious ones you&#8217;d expect any autonomous vehicle to have to drive safely, and there are the internal ones you might think about, but there are a few you may not consider. <sup>[2]</sup></p><p>Internally, there are obviously the cabin cameras, seatbelt, door, and window sensors. Not so obvious are the weight sensors, smoke detectors, and microphones.</p><p>What is missing, though, is facial and voice recognition systems. <sup>[3]</sup></p><p>And, according to the Waymo privacy statement and terms of service, the data collected is used to enhance the rider experience, improve vehicle operations, respond to emergency situations, and protect Waymo&#8217;s property. <sup>[4]</sup></p><p>This data is not shared with law enforcement agencies unless requested through the normal judicial warrant process. They regularly receive and respond to these requests and assert that they follow the relevant laws of the jurisdictions in which they operate. No different of a stance than most technology companies take.</p><p>In the case of the two teenagers, the vehicle&#8217;s machine learning detected an issue from the data collected, involved a Waymo operator who decided there was enough concern to alert local police and suspend the ride so they could investigate.</p><p>So yes, Waymo alerted police, but they didn&#8217;t act as the judge, jury, and executioner. That was left to law enforcement and the district attorney.</p><h3><strong>What about privacy? Isn&#8217;t there a level of privacy you expect when riding in a taxi, ride-share, or autonomous vehicle?</strong></h3><p>At first glance, this screams of a privacy violation of sorts. People&#8217;s behaviors were monitored, someone was alerted, and action was taken.</p><p>But, as I thought through the situation, I found myself asking, what level of privacy do we expect when taking public transportation? Traditional taxi services? Or ride-share services?</p><p>In all of those cases, there is some level of human and autonomous observation, i.e., video recording, a driver, a conductor, an operator, and other safety sensors. So, you shouldn&#8217;t expect any specific level of privacy when using them.</p><p>Thus, I couldn&#8217;t see anything Waymo was doing that isn&#8217;t already being done through other modes of transportation. The primary difference is that the person isn&#8217;t in the same vehicle as you are; they are remote and interact with you in real time when required. But, they aren&#8217;t constantly monitoring the situation, AI is.</p><p>Take, for example, you jump into a cab and light up a cigarette; the cab driver is likely to turn around and tell you to put it out. Is that necessarily any different than an autonomous vehicle detecting the same behavior and asking you to refrain from smoking in the vehicle?</p><p>The more I thought about it, the more I couldn&#8217;t see any difference between the autonomous vehicle experience and other public transportation and taxi services when it comes to the level of privacy you should expect.</p><p>But, you have to admit the obvious, there is the layer of abstraction, filled by AI, that exists between the passenger and the Waymo employee that&#8217;s different.</p><h3><strong>When in a Waymo, are you aware that you are being monitored and recorded?</strong></h3><p>Yes-ish.</p><p>After watching a few different riders&#8217; experiences on YouTube, you hear the car go through a series of instructions and disclosures when the passengers first enter the car and begin the ride.</p><p>The vehicles start with a confirmation of the destination, seat belt requirements, rider support button use, child seat safety, emergency protocol, no interference, and interior monitoring and microphones.</p><p>The announcement also covers the use of interior cameras to check on riders, analyze for product improvements, and <strong>more</strong> (see the next section). That&#8217;s the &#8216;ish&#8217; in yes-ish, b/c what is more? The weight sensors? Door sensors? Window sensors? Other sensors?</p><p>The microphones remain off unless you activate them via a support request or when a situation requires them for two-way dialog with a Waymo operator.</p><p>The disclosure doesn&#8217;t get into how your data is collected and managed, or what your rights are regarding data privacy. For that, you have to use the app or go to their website.</p><p>So technically, you may hear that you are being recorded and monitored, but most people who sit down believe there is a level of privacy because a human is not present. Which is obviously different than when taking a taxi or other ride share service who have humans operators in the vehicle with you.</p><h3><strong>Is it an algorithm or human making the decision on what is suspicious activity?</strong></h3><p>Both.</p><p>Business Insider reports that &#8220;...Waymo hasn&#8217;t publicly disclosed the full range of behaviors its systems can recognize or exactly what prompts an employee to access a live feed.&#8221; <sup>[5]</sup> Nor will they disclose a full list of sensors they have.</p><p>But, Waymo does disclose that they leverage machine learning from the behavior detecting sensors, which trigger alerts to employees.</p><p>Only after anomalous events are detected will the vehicle engage with human operators from Waymo. These operators have access to all the sensors and internal camera feeds and can engage with passengers using the microphones and the car&#8217;s sound system.</p><p>In other videos I&#8217;ve watched, though, it doesn&#8217;t appear that these operators can remotely operate the car per se, like with a remote control car. <sup>[6]</sup> From the video, you can see and hear the operator clearly explaining to the passenger that they are sending recommendations to the car on how to proceed when it became stuck in a parking area. And when finally faced with the fact the vehicle would not continue, the operator had to ask the passenger to exit the vehicle and look for alternative transportation.</p><p>This was a startling finding. So, not only is an algorithm making the initial decisions on anomalous behaviors its sensing inside the car. The remote operators have limited abilities to take control of the cars driving. But, they have every tool available to monitor, observe, and communicate with the passengers, up to suspending the service.</p><h3><strong>Where does this leave me with my thoughts on autonomous vehicles?</strong></h3><p>After looking through the Waymo website, it&#8217;s clear that safety is a top priority. And this makes sense: if the vehicles and service aren&#8217;t perceived as safe, there is no way people will set foot in the vehicle.</p><p>But, for me, this is just as much about trust as it is about safety. There is a level of trust that has to be developed. And feeling save requires trust.</p><p>A vehicle that is instructed to pull over under the pretense of a technical issue when, in fact, authorities are alerted and en route to investigate doesn&#8217;t build trust. Especially when Waymo doesn&#8217;t fully disclose what behaviors or actions will trigger such escalations.</p><p>While the algorithm engages a person, that person hasn&#8217;t been like a driver interacting with you. They step in and review the preponderance of evidence in near real time AND after the fact, making a quick decision without any obvious direct engagement with you about the circumstances.</p><p>I&#8217;ve read enough of Waymo&#8217;s policies and watched plenty of videos to feel they are working with positive intent to build a safe and reliable product. But they are falling short in building a brand you can trust.</p><p>It&#8217;s naive to expect there not to be incidents involving riders in their vehicles, no different from incidents we&#8217;ve heard about with taxi drivers and ride-share services. But the major difference is an algorithm and AI sitting between the passenger and the operators: no dialog or interaction, sensors and an AI model deciding how to proceed. Sure, a human is introduced in the middle. For now. Will that remain the case as the service scales to more markets and the number of daily trips increases? Only time will tell.</p><p>And that makes riding in a Waymo vehicle or other autonomous vehicle service a hard pass for me. What about you?</p><h4><strong>References</strong></h4><ol><li><p><strong>Original incident coverage</strong> &#8212; NPR, &#8220;Waymo called the cops on teen riders, raising privacy concerns&#8221; July 10, 2026: <a href="https://www.npr.org/2026/07/10/nx-s1-5886113/waymo-police-privacy-driverless-autonomous-vehicles">https://www.npr.org/2026/07/10/nx-s1-5886113/waymo-police-privacy-driverless-autonomous-vehicles</a></p></li><li><p><strong>Sensor/camera count</strong> &#8212; Waymo, &#8220;Self-Driving Car Technology for a Reliable Ride&#8221; (&#8221;There are 29 cameras on our Jaguar I-PACEs&#8221;): <a href="https://waymo.com/waymo-driver/">https://waymo.com/waymo-driver/</a></p></li><li><p><strong>No facial/voice recognition; interior camera/microphone policy</strong> &#8212; Waymo Help Center, &#8220;Cameras, microphones, and related data processing&#8221;: <a href="https://support.google.com/waymo/answer/9190819?hl=en">https://support.google.com/waymo/answer/9190819?hl=en</a></p></li><li><p><strong>Data use / privacy statement</strong> &#8212; Waymo Privacy Policy: <a href="https://waymo.com/privacy/">https://waymo.com/privacy/</a></p></li><li><p><strong>ML flagging + Waymo&#8217;s declined comment on full trigger list</strong> &#8212; Business Insider, Lloyd Lee, &#8220;Kids, rowdy riders, don&#8217;t forget: Waymo could be watching,&#8221; July 2026: <a href="https://www.businessinsider.com/waymo-cabin-cameras-monitor-teens-police-san-mateo-incident-2026-7">https://www.businessinsider.com/waymo-cabin-cameras-monitor-teens-police-san-mateo-incident-2026-7</a></p></li><li><p><strong>Sawyer Merritt</strong>, &#8220;I rode a Waymo robotaxi in Nashville. It didn&#8217;t go as planned...&#8221; July, 2026 &#8212; YouTube: </p></li></ol><div id="youtube2-EPxy-25Lefc" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;EPxy-25Lefc&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/EPxy-25Lefc?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://theweeklytinkerer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Weekly Tinkerer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Nobody Can Reliably Tell AI Writing From Human Writing]]></title><description><![CDATA[Your chances of getting it right are slightly better than a coin toss. Here's my disclosure anyway.]]></description><link>https://theweeklytinkerer.com/p/nobody-can-reliably-tell-ai-writing</link><guid isPermaLink="false">https://theweeklytinkerer.com/p/nobody-can-reliably-tell-ai-writing</guid><dc:creator><![CDATA[Kevin Ebert]]></dc:creator><pubDate>Sat, 15 Aug 2026 13:02:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ubT6!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F491f2404-dd18-4eeb-9093-fe9046b9dedf_256x256.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;m at a crossroads of sorts: should I or should I not disclose the usage of AI within my workflow as it relates to my newly minted The Weekly Tinkerer newsletter?</p><p>And before you start screaming at me, of course you need to disclose it; how can we trust anything you are writing if you are using generative AI for your writing?</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://theweeklytinkerer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Weekly Tinkerer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>I was right there with you 96 hours ago when I started this piece. It was going to be simple; yes, I use AI to help aggregate data on my tinkering. Yes, I fact-check everything I post. Yes, all the ideas I write about are my own. And finally, no, I don&#8217;t mindlessly post AI-generated text.</p><p>But as I researched the topic, I came to understand that this is not a binary conversation, and that the data and reasons behind disclosing the use of AI-generated text are more nuanced than they appear.</p><p>I hope this article helps you think about the topic in a different way.</p><p>You may have seen recent headlines.</p><p>LinkedIn introduces an &#8220;AI Slop&#8221; reporting tool to wage war against content quality on its platform.</p><p>Hank Green, a YouTube creator and educator, inadvertently admitted to using AI in his process during a video he recorded, prompting swift condemnation from many and bringing the generative AI disclosure debate into focus.</p><p>Anthropic is rolling out the ability to watermark AI-generated text in new models, to comply with EU regulation.</p><p>Substack partners with Pangram to provide an AI text scanner.</p><p>For this piece, I&#8217;m going to keep my argument and research centered on LinkedIn, Substack, and YouTube. These are my platforms of choice. I think much of what I&#8217;ll assert is valid in other platforms, but I&#8217;m not going to take the time here to make that point.</p><p>At the time of this writing, none of the platforms have taken a firm stance on outright requiring you to disclose the use of AI-generated content on their respective platforms, except for YouTube, but, as it turns out, their stance is limited to specific use and not necessarily far-reaching.</p><p>YouTube requires disclosure of AI-generated content when it results in realistic content that a viewer could mistake as being real. This includes synthetic voices, altered events, or fabricated photorealistic scenes.</p><p>This makes perfect sense; it&#8217;s a visual platform, and the disclosure focuses on the content displayed.</p><p>But what is exempt from their policy is the use of AI to create scripts, ideas, captions, animated content, or thumbnails. In other words, no need to disclose when using AI to help with structure and research, but required when dealing with voice and visuals.</p><p>LinkedIn and Substack do not have specific terms of use regarding generative AI on their platforms, but both have given readers tools to flag or check for it. LinkedIn gives you an &#8220;AI Slop&#8221; reporting button, and Substack lets you scan a piece using Pangram.</p><p>So, the case for disclosure is more of an ethical/moral/voluntary choice, not compulsory.</p><p>And to throw some fuel on the fire, a research article by Toff and Simon in The International Journal of Press/Politics<sup>[1]</sup> asserts that when it is disclosed that AI was used in the writing of articles, trust in the content drops significantly, even though the articles are factually correct. The research also showed that this drop in trust is reversed when specific sources outside AI are used.</p><p>So, where does this put creators?</p><p>If you disclose your usage of AI, you may be labeled as untrustworthy, even if still factually correct. The damage is mitigated somewhat if you cite sources outside the AI sphere. Creators are also benefiting from using AI in their content creation processes.</p><p>But, as the late-great Paul Harvey liked to say, now for the rest of the story (or something like that).</p><p>Here is an uncomfortable truth that I suspect will have you throwing your shoes at me. Humans are barely more able to reliably identify AI-generated text than using a simple coin toss.</p><p>Yup, your ability to detect AI-generated text is only slightly better than tossing a coin.<sup>[2]</sup></p><p>I know, you don&#8217;t believe me. There&#8217;s the em dashes, the sameness in sentence structure. Lack of rhythm in the work. It&#8217;s not X, it&#8217;s Y. Not an original thought, etc.</p><p>Just head to LinkedIn and ask anyone; they&#8217;ll gladly proclaim they can, without a doubt, identify AI-generated text.</p><p>The data shows otherwise. <strong>People are confident about the wrong signals.</strong></p><p>But there is actually one tell that is obvious and tips the scales in your favor: hallucinated facts and fabricated sources.</p><p>All at the same time now, &#8220;well no sh*t Sherlock.&#8221;</p><p><strong>And that&#8217;s the point: for most people, human detection is more performative art than fact unless the text in question is factually incorrect and the sources are invalid.</strong></p><p>It&#8217;s such a big point that the EU recently enacted the EU AI Act&#8217;s Transparency Code (Article 50(2)).<sup>[3]</sup> It says several things, but most notably as related to this article:</p><p>AI models need to produce a synthetic content marking when it&#8217;s generative AI. This includes having the software machine-mark text, image, audio, and video output so it&#8217;s detectable as AI-generated.</p><p>There&#8217;s one important limitation to this legislation worth noting.<sup>[4]</sup> The watermark ONLY proves the AI touched the content it&#8217;s producing, but doesn&#8217;t indicate who wrote it or how much of the text is generated; i.e., stuff heavily edited by a human after the fact will no longer necessarily bear the watermark. As such, the watermark isn&#8217;t enough to purely indicate that content is AI-generated, and thus any claims to be able to identify AI text are more performative than quantifiable.</p><p>So, this article is getting lengthy; let&#8217;s summarize quickly before moving on.</p><ul><li><p>We are more likely to distrust AI-generated content, even when factually correct.</p></li><li><p>AI is proving to be a very effective tool for generating content and researching topics.</p></li><li><p>People&#8217;s ability to identify AI-generated text is slightly better than a coin toss; the signals we rely on are unreliable. The ability to detect AI-generated text changes when it hallucinates or cites non-existent sources.</p></li><li><p>Disclosing AI usage is more a matter of principle than a compulsory rule.</p></li></ul><p>Where does this leave someone like me, someone without a well-known brand, but liked by my colleagues (for the most part), who is starting on a new journey to publish works in the public space? Should I or should I not disclose the use of AI as part of my workflow?</p><p>Interestingly, it was difficult to find straightforward examples of more well-known creators disclosing their use of AI. The few I found include Katie Harbath, Carlo V. Santiago, Hank Green&#8217;s personal policy, and Complexly&#8217;s institutional policy.<sup>[5]</sup> And that was it. It&#8217;s not to say others don&#8217;t disclose their use, nor does it imply people aren&#8217;t being honest about it, but what it does signal is that the topic, while hot, isn&#8217;t necessarily being addressed by widespread acceptance of disclosing AI use.</p><p>For me, I&#8217;m all for disclosure. I&#8217;m beginning my creator journey, and it&#8217;s not just about publishing my thoughts, but about building trust in what I&#8217;m doing so I can share what I&#8217;m creating with you, and you can see my process.</p><p>In 2025, I started posting on LinkedIn to build a personal brand. It was more of an experiment than driven by a specific cause, and it yielded modest results.</p><p>When I began the process, I was all in, leveraging Claude to help generate content. This included taking my ideal customer profile (which AI helped me create) and asking about the pain points people were experiencing in my areas of expertise. I&#8217;d find a pain point and write my own thoughts around it, more of a brain dump than a structured article.</p><p>I fed my brain dump into an AI process I created, which helped me write two versions of the same article. The first was a story-based arc and the second was a contrarian take on the original idea. A third process compared the dueling articles, scoring them against an opaque rubric (again created by AI) and recommending which version to publish.</p><p>Maybe not ironically, the scores were often 39 out of 50 vs. 37 out of 50. Read into this what you will, but I find it funny that the two different arcs converged into near sameness when quantified by AI. The humor lands hard when looking back on that time.</p><p>Not only was there the sameness, but the articles that were being produced were flat, uninteresting, and void of soul.</p><p>The output I was reading looked eerily similar to so much of what I was seeing on LinkedIn. As it turns out, a peer-reviewed study confirmed that people who frequently use AI for writing are better detectors of AI-generated content.<sup>[6]</sup></p><p>I was producing AI slop. The same slop I rolled my eyes at so often when scrolling.</p><p>What was produced was a sanitized, watered-down version of a brief I fed to the AI that looked like so many other posts.</p><p>I tried to rewrite them to follow the arc of the winning article. If the measure of success for the posting was engagement and views, I had a few land well, but most of the articles posted didn&#8217;t move the needle.</p><p>The frustration was mounting with the lack of results, especially as I started writing more about the business I was starting.</p><p>Thinking the problem was that the output was lacking my voice, I launched into a 100-question interview of me to generate a voice profile to give to AI to make it sound more like me, an idea I took from Ruben Hassid&#8217;s newsletter article titled &#8220;I can be you.&#8221;</p><p>I reworked my dueling agent process to leverage my newly minted voice profile, and while the quality of the drafts improved and sounded more like me, the output was still flat and lacked soul, so I was rewriting it before publishing.</p><p>So, I pivoted my process to where I&#8217;m at today. I trashed the dueling agents and replaced them with a muse process I created that takes the output of my weekly tinkering, considers a backlog of article ideas I&#8217;ve generated based on things I&#8217;m reading, and asks me one question.</p><p>&#8220;What&#8217;s on your mind &#8212; tell me the idea or the moment, like you&#8217;re talking it through.&#8221;</p><p>It takes my long-form brain dump of an idea, often transcribed, and helps identify the threads to pull on, the ones to leave alone, and the ones to cut out altogether. It asks clarifying questions, restates what it understands, and iterates to help fully develop the article&#8217;s scaffolding. Not prose, just a scaffolding that looks like:</p><div class="callout-block" data-callout="true"><ol><li><p><strong>The hot-topic hook</strong> &#8212; AI slop is a live topic right now: LinkedIn&#8217;s AI-slop-reporting tools (verified 2026-08-11, see Research below), the Hank Green LLM controversy and public outcry, and Kevin&#8217;s own read of LinkedIn feeds souring on AI slop and AI comments (this last part stays personal observation, not a cited fact).</p></li><li><p><strong>The turn to nuance</strong> &#8212; the subject is much more nuanced than a binary &#8220;I don&#8217;t use AI&#8221; vs. &#8220;I use AI&#8221; stance.</p></li><li><p><strong>The schism</strong> &#8212; creators find the tools valuable for assistance but shy away from disclosing actual AI-generated/published content, because consumers trust AI-assisted creators and content less. Real friction point that can push people toward silence. Backed by the&#8230;</p></li></ol><p><em>(scaffold continues through 7 points which are left off for brevity)</em></p></div><p>I use scaffolding to craft the article, and when satisfied with the content, I feed it into Grammarly to help with grammar, punctuation, and sentence structure.</p><p>The result of the process is the article you are reading now.</p><p>With the backstory out of the way, it&#8217;s time to formalize my disclosure statement:</p><div class="callout-block" data-callout="true"><ul><li><p>I use Claude AI to assist in the research and data aggregation for the content I produce.</p></li><li><p>I use Claude AI and Gemini to research questions I have related to the ideas I&#8217;m cultivating.</p></li><li><p>All research is validated and cited in my notes, and where appropriate in my finished articles. Nothing that at least three sources can&#8217;t verify is included in my research.</p></li><li><p>AI will never be cited as the sole source of information.</p></li><li><p>I use Claude AI to build the scaffolding for my articles.</p></li><li><p>The words you are reading are my own.</p></li><li><p>I use Grammarly to edit my content for grammar, spelling, and sentence structure.</p></li><li><p>I use Gemini to build infographic and cartoon-style images to accompany some of the articles I&#8217;m producing.</p></li></ul></div><p>What I have learned is that creating content is hard. The urge to find shortcuts in the process is real, and AI genuinely eases friction in it. This creator economy is always in flux, and the idea of AI disclosure, while not new, has taken on renewed vigor due to the proliferation of creators, pressures to produce, recent legal changes, and the high-profile case of Hank Green.</p><p>As I look at what happened with Hank Green, the court of public opinion hasn&#8217;t been kind to him for doing something he never fully explained. Clearly, I don&#8217;t know his intent or how widely AI was used in his process, but for me, I&#8217;m willing to give him the benefit of doubt. I&#8217;ve enjoyed the videos he&#8217;s produced over the years. What I&#8217;m taking away from his situation, disclosing how I use AI early in my creator journey is important to me. And how that disclosure looks includes what tools I use, how I use AI, and when I use AI.</p><h3>Sources</h3><ol><li><p>Toff, B., &amp; Simon, F. M. (2025). &#8220;Or They Could Just Not Use It?&#8221;: The Dilemma of AI Disclosure for Audience Trust in News. The International Journal of Press/Politics, 30(4), 881&#8211;903. <a href="https://doi.org/10.1177/19401612241308697">https://doi.org/10.1177/19401612241308697</a></p></li><li><p>Human detection of AI-generated text hovers near chance &#8212; or worse &#8212; across multiple independent studies:</p><p><br>Penn State News, &#8220;Q&amp;A: The Increasing Difficulty of Detecting AI vs. Human Text&#8221; (May 14, 2024): <a href="https://www.psu.edu/news/information-sciences-and-technology/story/qa-increasing-difficulty-detecting-ai-versus-human">https://www.psu.edu/news/information-sciences-and-technology/story/qa-increasing-difficulty-detecting-ai-versus-human</a></p><p><br>Yale Daily News, &#8220;Readers Can&#8217;t Accurately Distinguish Between AI and Human Essays, Researchers Find&#8221; (Nov. 18, 2024): <a href="https://yaledailynews.com/blog/2024/11/18/readers-cant-accurately-distinguish-between-ai-and-human-essays-researchers-find/">https://yaledailynews.com/blog/2024/11/18/readers-cant-accurately-distinguish-between-ai-and-human-essays-researchers-find/</a></p><p><br>Berber Sardinha, T. (2024). AI-Generated vs Human-Authored Texts: A Multidimensional Comparison. Applied Corpus Linguistics, 4(1). <a href="https://www.sciencedirect.com/science/article/abs/pii/S2666799123000436">https://www.sciencedirect.com/science/article/abs/pii/S2666799123000436</a></p><p><br>&#8220;Bot or Not: Can People Tell the Difference Between Stories Written by a Human or by an AI System?&#8221; Judgment and Decision Making (Cambridge Core): two studies, N=424 and N=481 adults &#8212; 39.39% and 51.97% correct respectively, both at or significantly below chance. <a href="https://www.cambridge.org/core/journals/judgment-and-decision-making/article/bot-or-not-can-people-tell-the-difference-between-stories-written-by-a-human-or-by-an-ai-system/45E6DC0BB90AA648654D5AE243F6C667">https://www.cambridge.org/core/journals/judgment-and-decision-making/article/bot-or-not-can-people-tell-the-difference-between-stories-written-by-a-human-or-by-an-ai-system/45E6DC0BB90AA648654D5AE243F6C667</a></p><p><br>Mili&#269;ka et al. (2025). Learning to Detect AI Texts and Learning the Limits. PLoS One. Baseline (untrained) accuracy 55.4% (N=254), rising to 65.1% with corrective feedback training &#8212; still short of reliable. <a href="https://pmc.ncbi.nlm.nih.gov/articles/PMC12527182/">https://pmc.ncbi.nlm.nih.gov/articles/PMC12527182/</a></p></li><li><p>The EU AI Act&#8217;s Transparency Code (Article 50) itself, effective Aug. 2, 2026:</p><p><br>European Commission, &#8220;Safer and More Transparent AI&#8221; (Aug. 2, 2026): <a href="https://commission.europa.eu/news-and-media/news/safer-and-more-transparent-ai-2026-08-02_en">https://commission.europa.eu/news-and-media/news/safer-and-more-transparent-ai-2026-08-02_en</a></p><p><br>EU Artificial Intelligence Act, Article 50 transparency obligations, explainer: <a href="https://artificialintelligenceact.eu/transparency-rules-article-50/">https://artificialintelligenceact.eu/transparency-rules-article-50/</a></p></li><li><p>Anthropic&#8217;s own published limitations on its text watermark:</p><p><br>Anthropic Support, &#8220;How Claude Marks AI-Generated Content&#8221;: <a href="https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content">https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content</a></p><p><br>TechCrunch, &#8220;Anthropic Says It Will Watermark Text Generated by Its AI Models&#8221; (Aug. 11, 2026): <a href="https://techcrunch.com/2026/08/11/anthropic-says-it-will-watermark-text-generated-by-its-ai-models/">https://techcrunch.com/2026/08/11/anthropic-says-it-will-watermark-text-generated-by-its-ai-models/</a></p></li><li><p>Named creators with published AI-disclosure policies:</p><p><br>Katie Harbath, &#8220;How I Use AI&#8221; (Anchor Change newsletter): <a href="https://anchorchange.substack.com/p/how-i-use-ai-newsletter-workflow">https://anchorchange.substack.com/p/how-i-use-ai-newsletter-workflow</a></p><p><br>Carlo V. Santiago, &#8220;Coming Out (AI Edition)&#8221;: <a href="https://carlovsantiago.substack.com/p/coming-out-ai-edition">https://carlovsantiago.substack.com/p/coming-out-ai-edition</a></p><p><br>Hank Green / Complexly AI policy (YouTube Community post, ~2026-08-09): https://www.youtube.com/post/UgkxbXRPEpONUqoIf0Zu2OPNaKBtd95IIgxU</p></li><li><p><strong>Complication &#8212; frequent AI-tool users are a real exception:<br><br></strong>Russell, J., Karpinska, M., &amp; Iyyer, M. (2025). &#8220;People Who Frequently Use ChatGPT for Writing Tasks Are Accurate and Robust Detectors of AI-Generated Text.&#8221; Accepted, ACL 2025. Five annotators who write with ChatGPT frequently reviewed 300 non-fiction articles against multiple frontier LLMs (GPT-4o, Claude, o1); majority vote misclassified only 1 of 300 &#8212; outperforming commercial detection tools, even against paraphrasing/evasion tactics. <a href="https://arxiv.org/abs/2501.15654">https://arxiv.org/abs/2501.15654</a></p></li></ol><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://theweeklytinkerer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Weekly Tinkerer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[How Email Terrorism Leads to Inbox Colonization]]></title><description><![CDATA[Six approvals for one company, a podcast rant that named the problem, and the domain-level fix that stops it.]]></description><link>https://theweeklytinkerer.com/p/how-email-terrorism-leads-to-inbox</link><guid isPermaLink="false">https://theweeklytinkerer.com/p/how-email-terrorism-leads-to-inbox</guid><dc:creator><![CDATA[Kevin Ebert]]></dc:creator><pubDate>Sat, 08 Aug 2026 13:03:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!O5LY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff49fa3bf-1192-4c74-9326-7a8ba0038df3_1408x470.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<blockquote><p>&#8220;...I&#8217;m in a long lifetime battle with email terrorism... it&#8217;s something that I battle every day, about three or four times a day.&#8221;</p></blockquote><p>I snort laugh when I hear the term <em>email terrorism</em>, but continue listening.</p><blockquote><p>&#8220;I purchased something for my new apartment... I know when I checked out it was like, &#8216;Sign up for our savings email blast.&#8217; And I was like, uncheck. Want no part of this.&#8221;</p><p>&#8220;I&#8217;m talking I&#8217;m like eight emails deep after I purchased like some towel hooks. Something incredibly pedestrian... something you would never write a review about unless you&#8217;re a complete whack job bored to tears.&#8221;</p><p>&#8220;So I unsubscribed. And then it pops up, &#8216;Thank you. We&#8217;re sorry to see you go. Thank you for unsubscribing. This will take 48 hours to update.&#8217; Which is total &#8212; and a pathological lie.&#8221;</p><p>&#8220;In those 48 hours after I declined the survey... I unsubscribe. And in the ensuing 48 hours, six emails per day, 12 additional nukes to my inbox.&#8221;</p><p>&#8220;Here&#8217;s what I hate &#8212; you put the unsubscribe when you&#8217;re checking out, but they have your email for billing. So then they keep emailing you. So you unsubscribe twice.&#8221;</p><p>&#8220;A lot of these retailers are abusive husbands. And the consumers are the battered wives... everything&#8217;s a hustle. Everything&#8217;s a shakedown. Everything&#8217;s a harassment.&#8221;</p><p>&#8221;Will you ever buy anything from that company again?&#8221;</p><p>&#8221;If I need it, I probably will... that&#8217;s the problem. I&#8217;m just being honest... the instant gratification person in me... I&#8217;ll be like, tap the vein, hit it... let&#8217;s go with the emails. I&#8217;m ready. I&#8217;m locked and loaded.&#8221;</p></blockquote><p>It&#8217;s too much. I stopped the lawnmower, turned it off, and then pulled my headphones off. I was belly laughing at what I just heard. I&#8217;d been mowing the yard listening to the podcast &#8220;<strong>I&#8217;ve Had It</strong>&#8221; for the first time, where the hosts Jennifer Welch and Angie Sullivan discuss all things political pop culture.</p><p>Buried in the podcast, the hosts described one of the problems that led me to build bwak email. There is real frustration when you opt out of receiving emails from a company. Most of the time, you opt out of receiving promotional or product updates, but you still receive emails asking you to &#8220;rate the product you bought&#8221; or to &#8220;tell them about your shopping experience.&#8221; And the colonization of your inbox happens as you receive these unwanted emails.</p><p>When it happens, you feel powerless and don&#8217;t know what else to do, nor do you have many good options today other than to write a rule in your inbox or mark the emails as spam.</p><p>And the scary part- not scary like The Amityville Horror kind of scary, but scary like What a coincidence, I was experiencing something similar with emails I was receiving from LinkedIn the other day.</p><p>Bwak email is one of the Tinkers I&#8217;m working on today. It is an email alias gateway that sits in front of my real email address and acts as a gate for emails I receive. The inbound emails require explicit human <strong>opt in</strong> approval before reaching my inbox. I can give anyone an alias that passes through the gate and gets delivered to my email if I&#8217;ve approved the sender.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OFUj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0853ed2c-b078-4328-8c5d-c28d6fa07e88_1408x293.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OFUj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0853ed2c-b078-4328-8c5d-c28d6fa07e88_1408x293.png 424w, https://substackcdn.com/image/fetch/$s_!OFUj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0853ed2c-b078-4328-8c5d-c28d6fa07e88_1408x293.png 848w, https://substackcdn.com/image/fetch/$s_!OFUj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0853ed2c-b078-4328-8c5d-c28d6fa07e88_1408x293.png 1272w, https://substackcdn.com/image/fetch/$s_!OFUj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0853ed2c-b078-4328-8c5d-c28d6fa07e88_1408x293.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OFUj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0853ed2c-b078-4328-8c5d-c28d6fa07e88_1408x293.png" width="1408" height="293" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0853ed2c-b078-4328-8c5d-c28d6fa07e88_1408x293.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:293,&quot;width&quot;:1408,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:551968,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://theweeklytinkerer.com/i/210216204?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0853ed2c-b078-4328-8c5d-c28d6fa07e88_1408x293.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OFUj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0853ed2c-b078-4328-8c5d-c28d6fa07e88_1408x293.png 424w, https://substackcdn.com/image/fetch/$s_!OFUj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0853ed2c-b078-4328-8c5d-c28d6fa07e88_1408x293.png 848w, https://substackcdn.com/image/fetch/$s_!OFUj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0853ed2c-b078-4328-8c5d-c28d6fa07e88_1408x293.png 1272w, https://substackcdn.com/image/fetch/$s_!OFUj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0853ed2c-b078-4328-8c5d-c28d6fa07e88_1408x293.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>Since I began tinkering with this idea, I&#8217;ve approved over 130 senders to different email aliases I&#8217;ve created for my <a href="http://k3bert.net/">k3bert.net</a> domain. And after several weeks, I started to feel like I was experiencing d&#233;j&#224; vu as I approved six different senders from LinkedIn.</p><p>It took the 6th approval to finally catch on to an issue I&#8217;m having with the user experience. Each time I received an email from LinkedIn, I approved it, and each time I thought to myself, I had already approved the sender on LinkedIn, not realizing each approval was for a different sender from LinkedIn. I was only keying on the domain LinkedIn, and that was the missing piece for the application.</p><p>The original design for the app included a per-sender (From) AND per-receiver (To) address approval process, which would mean if I received emails from different senders, albeit the same domain, I&#8217;d have to approve them all explicitly.</p><p>The answer: build a DOMAIN-level approval/denial mechanism.</p><p>In other words, give the user the option to <strong>Opt In</strong> to all emails from a specific domain (a.k.a. website) and forgo the explicit approval process for each sender.</p><p>And this is what I built in version v0.6.0 of bwak email. A unified 5-state approve/block model (sender/domain/alias scopes) replacing the previous asymmetric terminology I developed.</p><p>The five states?</p><ol><li><p>Let newsletters-noreply@linkedin.com through</p></li><li><p>Trust everyone from linkedin.com</p></li><li><p>Block just newsletters-noreply@linkedin.com</p></li><li><p>Block everyone from linkedin.com</p></li><li><p>Block anyone emailing linkedin@k3bert.net (To)</p></li></ol><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!O5LY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff49fa3bf-1192-4c74-9326-7a8ba0038df3_1408x470.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!O5LY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff49fa3bf-1192-4c74-9326-7a8ba0038df3_1408x470.png 424w, https://substackcdn.com/image/fetch/$s_!O5LY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff49fa3bf-1192-4c74-9326-7a8ba0038df3_1408x470.png 848w, https://substackcdn.com/image/fetch/$s_!O5LY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff49fa3bf-1192-4c74-9326-7a8ba0038df3_1408x470.png 1272w, https://substackcdn.com/image/fetch/$s_!O5LY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff49fa3bf-1192-4c74-9326-7a8ba0038df3_1408x470.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!O5LY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff49fa3bf-1192-4c74-9326-7a8ba0038df3_1408x470.png" width="1408" height="470" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f49fa3bf-1192-4c74-9326-7a8ba0038df3_1408x470.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:470,&quot;width&quot;:1408,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:845814,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://theweeklytinkerer.com/i/210216204?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff49fa3bf-1192-4c74-9326-7a8ba0038df3_1408x470.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!O5LY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff49fa3bf-1192-4c74-9326-7a8ba0038df3_1408x470.png 424w, https://substackcdn.com/image/fetch/$s_!O5LY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff49fa3bf-1192-4c74-9326-7a8ba0038df3_1408x470.png 848w, https://substackcdn.com/image/fetch/$s_!O5LY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff49fa3bf-1192-4c74-9326-7a8ba0038df3_1408x470.png 1272w, https://substackcdn.com/image/fetch/$s_!O5LY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff49fa3bf-1192-4c74-9326-7a8ba0038df3_1408x470.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>With this approach, a block action (domain or sender) ALWAYS overrides an approve. Domain-level actions override sender-level approvals.</p><p>This approach creates a streamlined user experience, giving them the control they need over their emails.</p><p>Looking back at the discussion between Jennifer and Angie, if they had bwak email, they wouldn&#8217;t have to worry about unsubscribing; they would potentially have the option to block the &#8220;review the product emails&#8221;, but approve &#8220;order update emails&#8221; because they come from different senders. And if they ever got annoyed to the point of no return, they could go nuclear and block ALL the emails from the sender.</p><p>I just rolled this out last week, and I&#8217;m testing it. I&#8217;ve tested with sample data, but I couldn&#8217;t test all the usage/approval/denial paths due to limitations in my ability to send emails from different senders, so I&#8217;m fishing with bait, waiting to see how the system performs in the real world.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://theweeklytinkerer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Weekly Tinkerer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[I've Been a Stubborn Donkey]]></title><description><![CDATA[Two decades on LinkedIn, and I finally figured out I wasn't reading the room.]]></description><link>https://theweeklytinkerer.com/p/ive-been-a-stubborn-donkey</link><guid isPermaLink="false">https://theweeklytinkerer.com/p/ive-been-a-stubborn-donkey</guid><dc:creator><![CDATA[Kevin Ebert]]></dc:creator><pubDate>Sun, 02 Aug 2026 17:00:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Z1Xm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff7d85e6-a35e-431a-abf8-e0d1f9f6504d_480x640.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>They drew the arrow back, took aim at the target, and released the arrow. Whoosh - thump, bullseye. They yelped in excitement and ran to the target to look closer at the arrow they just shot, sitting in the middle of the target.</p><p>Charlotte&#8217;s grandchildren hadn&#8217;t ever shot arrows before, but they instantly fell in love. After a few hours, they were drawing the arrow back and hitting the target like a pro. This is life on the farm. When you visit, we create an experience you take home with you. Charlotte&#8217;s grandchildren now have their own archery range back in Texas, set up by their parents.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Z1Xm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff7d85e6-a35e-431a-abf8-e0d1f9f6504d_480x640.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Z1Xm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff7d85e6-a35e-431a-abf8-e0d1f9f6504d_480x640.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Z1Xm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff7d85e6-a35e-431a-abf8-e0d1f9f6504d_480x640.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Z1Xm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff7d85e6-a35e-431a-abf8-e0d1f9f6504d_480x640.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Z1Xm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff7d85e6-a35e-431a-abf8-e0d1f9f6504d_480x640.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Z1Xm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff7d85e6-a35e-431a-abf8-e0d1f9f6504d_480x640.jpeg" width="480" height="640" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ff7d85e6-a35e-431a-abf8-e0d1f9f6504d_480x640.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:640,&quot;width&quot;:480,&quot;resizeWidth&quot;:480,&quot;bytes&quot;:678300,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://theweeklytinkerer.com/i/209375594?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff7d85e6-a35e-431a-abf8-e0d1f9f6504d_480x640.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Z1Xm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff7d85e6-a35e-431a-abf8-e0d1f9f6504d_480x640.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Z1Xm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff7d85e6-a35e-431a-abf8-e0d1f9f6504d_480x640.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Z1Xm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff7d85e6-a35e-431a-abf8-e0d1f9f6504d_480x640.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Z1Xm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff7d85e6-a35e-431a-abf8-e0d1f9f6504d_480x640.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Visits to our farm are not casual; they are experiences carefully planned, created, curated, and executed by us.</p><p>I&#8217;ve been on LinkedIn for two decades now, and I&#8217;ve been posting regularly for the past several years. More recently, I started posting with a purpose. After experiencing a career disruption, instead of jumping back into the familiar corporate life, I decided to bet on myself and post on LinkedIn with the purpose of promoting a business I started.</p><p>The performance of those posts has been lackluster, and it would be easy to blame the algorithm for killing my reach. I refuse to assert that my posts are flopping. No, I failed to realize the strength of the LinkedIn platform and how to succeed on it. I&#8217;ve been a stubborn donkey not reading the room.</p><p>With new resolve and a shift in focus, I&#8217;m going to refine the work I&#8217;m doing on LinkedIn AND extend my outreach to include Substack.</p><p>LinkedIn is the snack bag you get on a short airline flight. You open the bag and pick through the contents while reading the nutritional information on the back. It&#8217;s the platform you open up at work when you have a few minutes and scroll to kill time. You enjoy the saltiness of the posts; they are quick, tasty hits of time management, leadership development, and other career-growth flavors that reflect your interests.</p><p>Substack, on the other hand, is the dinner you sit down to once you arrive on the farm. It follows a day of activities like archery. It&#8217;s a time where you receive a multi-course meal with an appetizer, main course, dessert, and a relevant drink pairing. It&#8217;s a time to reflect on the day&#8217;s activities and wonder what tomorrow will bring.</p><p>We have a seat waiting for you. Subscribe to The Weekly Tinkerer.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://theweeklytinkerer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Weekly Tinkerer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[The Impotent Inbox]]></title><description><![CDATA[Three companies, one AI trend, and the experiment I'm running to stop giving my inbox away for free.]]></description><link>https://theweeklytinkerer.com/p/the-impotent-inbox</link><guid isPermaLink="false">https://theweeklytinkerer.com/p/the-impotent-inbox</guid><dc:creator><![CDATA[Kevin Ebert]]></dc:creator><pubDate>Wed, 29 Jul 2026 05:47:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ubT6!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F491f2404-dd18-4eeb-9093-fe9046b9dedf_256x256.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I have 1,390 unread messages in my inbox telling me that my inbox is impotent.</p><p>It&#8217;s time to turn the opt-out model of email on its head to fix it.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://theweeklytinkerer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Weekly Tinkerer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>I wanted another Apple HomePod speaker for our home. Found it online for in-store pickup at my local Electronic Express. I added it to the cart, checked out as a guest, and forgot about it.</p><p>A couple of years later, I received a spam message addressed to: electronicexpress-0921@k3bert.net. I was confused; I didn&#8217;t create an account with them. Why am I receiving spam?</p><p>I looked up the address on Have I Been Pwned and found out that in Feb of 2023, Eye4Fraud, an online fraud protection system used during payment transactions, was breached and the data made available to hackers.</p><p>The forgotten email came back to life until I created an inbox rule to delete any messages sent to electronicexpress-0921@k3bert.net permanently<a href="mailto:electronicexpress-0921@k3bert.net.">.</a> <strong>Opt-out</strong>.</p><p>And then there was the time I decided to sign up for updates to my Alma Mater, CU. I opted to receive alum emails at cualumni@k3bert.net related to the engineering school, from which I graduated.</p><p>I received my first few updates, but then there was a shift. It wasn&#8217;t just updates on the School of Engineering; the emails were now boosters for the Alumni Association and covered other clubs and associations within the university. And then, to make matters worse, someone from the Alumni Association started calling. Their whole job is traveling around meeting alumni to &#8220;catch up,&#8221; which I&#8217;m fairly sure means asking for money.</p><p>I tried to opt-out through my mail preferences, but the emails and calls kept coming in.</p><p>I created an inbox rule to delete any messages sent to cualumni@k3bert.net permanently. <strong>Opt-out</strong> and blocked the phone number.</p><p>And then there was Verizon and Heritage Bank and Trust. For a few years, we did business with these companies until we stopped and permanently closed our accounts. Or at least we thought.</p><p>But, for months after closing the accounts, we still received monthly statements of our accounts. Confused, I called several times, explaining the accounts were closed and that there was no need to send us statements anymore. They agreed. The emails kept coming.</p><p>I created an inbox rule to delete any message sent to their aliases permanently. <strong>Opt-out</strong>.</p><p>Today, AI agents are augmenting and supercharging inbox rules and, if you decide, will take over your entire inbox for you. But what&#8217;s the difference between an AI agent managing your inbox for you versus you manually managing the rules? Other than out of sight, out of mind, it&#8217;s still opt-out.</p><p>In the immortal words of Buzz Lightyear: &#8220;This isn&#8217;t flying, it&#8217;s falling with style.&#8221;</p><p>And personally, I&#8217;m not all that comfortable with an AI agent crawling through my inbox and noticing who I shop or bank with, what credit cards I have, when I received my tax return, or when I pay my utility bills. This is all personal information that I would like to keep personal.</p><p>For years, I&#8217;ve been trying to manage the 1,390 unread messages like most everyone else. Giving out my email, receiving unwanted messages, trying to opt-out, giving up, and waving the white flag.</p><p>And now, I&#8217;m tinkering. I&#8217;ve started an experiment with my personal k3bert.net domain that, if successful, I&#8217;ll transition the domain my wife and I share for all our household accounts.</p><p>The experiment started with a declaration of email bankruptcy, archiving off all my messages into cold storage. And a gate slotted in front of the domain that inspects all senders and aliases, comparing them to an allowed list. When a new email arrives and the sender is not in the allowed list, I have a choice to allow the email to land in my inbox; in other words, I <strong>opt-in</strong>.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://theweeklytinkerer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Weekly Tinkerer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[I thought color was taste. It's a number.]]></title><description><![CDATA[WCAG doesn't care about taste. It cares about a computable number, and mine wasn't hitting it.]]></description><link>https://theweeklytinkerer.com/p/i-thought-color-was-taste-its-a-number</link><guid isPermaLink="false">https://theweeklytinkerer.com/p/i-thought-color-was-taste-its-a-number</guid><dc:creator><![CDATA[Kevin Ebert]]></dc:creator><pubDate>Sun, 26 Jul 2026 00:50:28 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!DVP5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dfc536f-6960-4ed8-9336-58402f151589_979x781.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I was deep into the weeds trying to crack my onboarding dilemma. For a few weeks now, I&#8217;ve been trying to figure out why people are signing up for the Bwak News app, but not onboarding any newsletters.</p><p>And then something caught my attention. The green highlight text I chose for the site was difficult to read.</p><p>I have good color perception. In fact, Charlotte has crowned me the official paint color picker when it comes to decorating our house. So, I figured if the text was difficult for me to read, the roughly 8% of men with red-green color vision deficiency would struggle to read it also.</p><p>That wasn&#8217;t ok with me.</p><p>I was aware of the accessibility guidelines published by the Web Content Accessibility Guidelines (WCAG), but never had to worry about building with them. So I was surprised when I handed the problem off to my AI agent, and it threw up a sample page showing that indeed, the emerald-600 (hex #059669) green color I selected for the website failed the standard.</p><p>Standard? What standard? Up until now, my choice of colors was always based on taste and if it reads fine, ship it. I had no idea that the standard specified a way to calculate the contrast and grade it as a means to quantify accessibility usage of your application.</p><p>Every color has a computable relative luminance, which is a fancier and more accurate way of saying &#8220;how bright it actually reads to the eye.&#8221; Take two colors, compare their luminance, and you get a contrast ratio. Identical colors give you 1:1, invisible against themselves. Pure black on pure white gives you 21:1, the ceiling. Everything else falls somewhere in between, and the formula gives the same answer every time, for every viewer, regardless of taste.</p><p>My green, emerald-600, measured 3.77:1 against white. WCAG&#8217;s baseline standard for normal text is AA, and AA requires 4.5:1. My &#8220;fine, it&#8217;s just a light green&#8221; accent color was failing the accessibility standard I didn&#8217;t know existed.</p><p>There are two levels worth knowing; AA is the baseline most sites are expected to hit: 4.5:1 for normal text, 3:1 for large text (think 18-point-plus, or bold at 14-point-plus). AAA is the stricter tier, not usually a legal requirement but the one that gives you real margin instead of a bare pass: 7:1 for normal text, 4.5:1 for large. My original green wasn&#8217;t even clearing the low bar.</p><p>I went with the recommended emerald-800 (hex #065f46), a 7.68:1 ratio. Not a bare pass over the AA line, but clear of AAA too, with real margin to spare.</p><p>Because the color lived in one config token instead of being copy-pasted into forty places, changing it fixed the accent color across the entire app in one shot: CSS, every transactional email, account and billing pages, badges. All of it, except three admin-only internal tools I left alone on purpose, because nobody outside my team ever sees those.</p><p>The part I want to hand you isn&#8217;t the story. It&#8217;s that this is checkable, right now, on whatever you&#8217;re running, without asking anyone&#8217;s opinion:</p><p>1. <strong>Chrome DevTools</strong> &#8212; inspect any text, click the color swatch next to color in the styles panel, and it shows you the live ratio plus AA/AAA pass or fail, along with a suggested color that would pass. Fastest option, already installed.</p><p>2. <strong>WebAIM Contrast Checker</strong> (webaim.org/resources/contrastchecker) &#8212; paste in two hex codes, get the ratio and pass/fail for both normal and large text. It&#8217;s the tool most accessibility writeups point to first.</p><p>3. <strong>Lighthouse</strong> (also built into Chrome DevTools) &#8212; audits a whole page at once instead of one pair of colors at a time, so it&#8217;ll surface every low-contrast spot you didn&#8217;t think to check.</p><p>4. <strong>An AI coding assistant</strong> &#8212; ask it to build you a side-by-side comparison tool for your candidate colors, with real computed ratios. It&#8217;s not a shortcut around the standard; it&#8217;s a fast way to see the standard applied to your actual palette, which is exactly what got me here.</p><p>You already have a website, an app, a newsletter template, something with text on a background. Open DevTools, click your accent color, and read the number. If it says fail, you now know something concrete instead of something you assumed.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DVP5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dfc536f-6960-4ed8-9336-58402f151589_979x781.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DVP5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dfc536f-6960-4ed8-9336-58402f151589_979x781.png 424w, https://substackcdn.com/image/fetch/$s_!DVP5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dfc536f-6960-4ed8-9336-58402f151589_979x781.png 848w, https://substackcdn.com/image/fetch/$s_!DVP5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dfc536f-6960-4ed8-9336-58402f151589_979x781.png 1272w, https://substackcdn.com/image/fetch/$s_!DVP5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dfc536f-6960-4ed8-9336-58402f151589_979x781.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DVP5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dfc536f-6960-4ed8-9336-58402f151589_979x781.png" width="979" height="781" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0dfc536f-6960-4ed8-9336-58402f151589_979x781.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:781,&quot;width&quot;:979,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:105941,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://weeklytinkerer.substack.com/i/208508668?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dfc536f-6960-4ed8-9336-58402f151589_979x781.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DVP5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dfc536f-6960-4ed8-9336-58402f151589_979x781.png 424w, https://substackcdn.com/image/fetch/$s_!DVP5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dfc536f-6960-4ed8-9336-58402f151589_979x781.png 848w, https://substackcdn.com/image/fetch/$s_!DVP5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dfc536f-6960-4ed8-9336-58402f151589_979x781.png 1272w, https://substackcdn.com/image/fetch/$s_!DVP5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dfc536f-6960-4ed8-9336-58402f151589_979x781.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p>]]></content:encoded></item><item><title><![CDATA[A bot logged into my app before my friend could]]></title><description><![CDATA[Found it before an appointment. Fixed it on the drive. Shipped it in the waiting room.]]></description><link>https://theweeklytinkerer.com/p/a-bot-logged-into-my-app-before-my</link><guid isPermaLink="false">https://theweeklytinkerer.com/p/a-bot-logged-into-my-app-before-my</guid><dc:creator><![CDATA[Kevin Ebert]]></dc:creator><pubDate>Sat, 25 Jul 2026 02:21:48 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ubT6!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F491f2404-dd18-4eeb-9093-fe9046b9dedf_256x256.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Receiving a message from a friend (and former work colleague) telling you they can&#8217;t access the system you built sucks. The kind of suck that one wishes there was a rock I could crawl under. I might be milking the scene a bit for dramatic effect, but it still sucks, no one likes to hear they have a problem.</p><p>That&#8217;s what happened to me today.</p><blockquote><p>&#8220;Hey Kevin, I signed up for your service, but I can&#8217;t login. Here&#8217;s my email address I&#8217;m trying to log in with and the device/browser I&#8217;m using. Can you help?&#8221;</p></blockquote><p>I had 10 minutes before Charlotte and I were to head out for an appointment, so the pressure was on.</p><p>Check the logs, yep, there were the three login attempts made. But no indication of an error in the process nor that they received the message saying the magic link the app sent them to failed.</p><p>This was going to require intuition and an educated guess.</p><p>The difference in the time that the token was created and the time it was used was only a dozen seconds. That seems quick, too quick.</p><p>An AI prompt later, the working theory was developed. Somehow, the token for the magic link was already used before my friend could click the link in the email. But, why?</p><p>AI had an idea. I didn&#8217;t, this was outside of any experience level. I&#8217;ve been around a lot of systems in my career, but authentication and authorization mechanisms was an area I didn&#8217;t spend a lot of time in.</p><p>The most likely cause was that an email security scanner/pre-fetch was loading the link in the email and because the way the /auth end point was written, it was validating the token with the pre-fetch which in turn told the system that the token was valid, and no longer needed and discarded.</p><p>That all happened between the email being delivered and the time my friend clicked the link. When they clicked the link, they received the unfriendly message that they couldn&#8217;t login.</p><p>And to add insult to injury, there was no way in the app for them to reach out and ask for assistance. Luckily, they had my number.</p><p>This was the theory, it was easily tested and confirmed.</p><p>The fix is simple, don&#8217;t validate the token when the /auth end point is called. Instead, put an intermediary step requiring the user to click the link in the email, load a new page with another button to select to finish the login process.</p><p>Yes, the solution adds a bit of friction to the process, there&#8217;s an extra click now. But, it eliminates any pre-fetch or inadvertent previewing of the page assuring that the token will work when the user intends it to work.</p><p>So, the embarrassment is real, I have no way of knowing how many other people have had the issue, more than I&#8217;m willing to admit to b/c I can see the similar usage patterns.</p><p>The embarrassment was replaced with gratitude quickly b/c someone took the time to say, something wasn&#8217;t right and brought it to my attention.</p><p>This isn&#8217;t about not trusting what AI builds. That&#8217;s too easy, and it sidesteps the real responsibility. I understood the design. What I didn&#8217;t have was the experience to know there was a gap in it. And building alone means there&#8217;s no one else around to catch what you don&#8217;t know to look for.</p><p>The counter to that is building a system that expects surprises and handles them gracefully. For me, that means an easy way for someone to reach me when something breaks, and auditing every critical process that could stop a user dead and hardening those first.</p><p>What tips or techniques do you build with to handle the unexpected surprises that will inevitably hit your system?</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://theweeklytinkerer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Weekly Tinkerer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>