Categories
Editorial Programming

DHH’s keynote at Rails World 2026: “The most confusing funeral I’ve ever experienced”

The best one-line summary of David Heinemeier Hansson’s (DHH) keynote at Rails World 2026 was Stefan Lindbohm’s comment on its YouTube video:

“This is the most confusing funeral I’ve ever experienced”

This was the flagship keynote for the framework’s premier gathering, and it felt less like an affirmation of Rails’ future and more like an intellectual abandonment of its foundational craft, delivered by a creator increasingly insulated from the core community that used, supported, and helped build Rails alongside him.

(And DHH also did it so LOUDLY. I can’t be the only one who’s noticed that late-career DHH is a lot like late-career Al Pacino, who seems to think that the most effective way to get a message across is by YELLING.)

The keynote cannot be understood as an isolated technology talk. It set up a lawnchair right on the crossroads of two growing crises:

  1. The existential disruption of generative AI on software as craft, and
  2. A deep, multi-year revolt within the Ruby ecosystem against DHH’s personal politics, power concentration, cultural alienation, and let’s face it: he’s become yet another techno-dick.

Abandoned by its own creator

In his hour on stage, DHH barely mentioned the technology the audience had gathered to celebrate. In fact, an AI transcript analysis by a commenter revealed  that the word “Ruby” was spoken just 11 times throughout the entire presentation.

Instead, DHH unveiled a series of radical repudiations of the doctrines he spent two decades embedding into software canon:

“Pencils Down” on manual code. DHH announced that 37signals has banned hand-written code as standard operating procedure. Hand-writing code is now treated as a failure state. He also declared, “I have retired from being a professional programmer,” and that English is now his favorite programming language. He said that in the past year, only ~3% of the code he produced was Ruby. This. could be a hard pill to swallow for a community that had a tenet called “Exalt beautiful code”.

Ditching the web app. For 20 years, DHH championed server-rendered web applications, HTML over the wire, and the “Majestic Monolith”. At the keynote, he announced that 37signals’ flagship email client, HEY, is abandoning the web app model entirely. Armed with agentic code generators, a small team was tasked with pumping out six native desktop and mobile applications simultaneously.

Black-box Rust backends. Admitting he despises Rust (“like pouring acid in my eyes”, “inhumane to ask people of flesh and blood to subject their eyeballs to”), DHH celebrated outsourcing the entire HEY backend to AI agents writing Rust. His justification was rooted in total detachment: he never has to read or maintain it. It functions purely as an opaque black box.

The “loser” ultimatum. Dismissing concerns over job displacement, intellectual property theft, or code maintainability, DHH commanded the room to “take the white pill” and embrace extreme acceleration (the 2026 version of “move fast and break things”). His parting assessment for anyone feeling cautious or skeptical about turning software development into black-box agent orchestration: “The black pill is for fucking losers. Don’t be a loser.”

(The most extreme example: that two-hour unedited Primeagen interview with DHH from 2024. Caffeinated baboons would’ve been less noisy.)

Alienating the audience

To understand why this keynote felt less like bold leadership and more like a betrayal, you have to look at the cultural fracture that preceded it.

In a poignant, widely read November 2025 reflection, In Praise of DHH, long-time developer (and my friend) Fil MV captured the tragic arc of DHH’s relationship with the community:

“Prologue. I never met him, but I liked him. He was cool. He could be arrogant, and brash. He was maybe a little too self-satisfied. But on the whole I would say he was someone I admired, someone I looked up to. He was a role model. David Heinemeier Hansson (aka dhh), indirectly, through the creation of Ruby on Rails and the community that sprung up around it, had a big impact on my life… Rails was the connective tissue that threaded together many meaningful friendships of mine.”

As Fil noted, many in the community historically tolerated DHH’s arrogance because of his undeniable taste and track record: “I have always liked David’s technical leadership! I have historically thought that he’s right more often than he’s wrong!”

Yet, as documented across the ecosystem, from Fil’s essay to David Celis’s The DHH Problem, to Tekin Süleyman’s The Ruby Community Has a DHH Problem, DHH made a JK Rowling-like slide from a brash, opinionated visionary into a reactionary figure engaged in institutional power games:

The culture war shift. In recent years, DHH turned his public channels toward culture-war grievances: railing against DEI, adopting anti-trans talking points, praising far-right British agitators like Tommy Robinson, and describing London’s multicultural demographics as a “nightmare.” For a global community founded on the Ruby ethos of MINASWAN (“Matz is nice and so we are nice“), watching the titular figurehead of Rails embrace xenophobic tropes and exclusion felt like an assault on the community’s foundational spirit.

Power and institutional captivity. When community members and contributors pushed back, they discovered that DHH had architected a structure where he could not be held accountable. Between controlling the Rails trademarks, chairing the Rails Foundation, dominating Rails Core alongside Basecamp and Shopify (who also have a problematic leader), and exerting leverage over events (such as the contentious Ruby Central and RubyGems funding dramas of 2025), DHH built, as Fil MV observed, “a world where people can’t say no to him.”

The Eeection of the community. When DHH told his Rails World audience not to be “losers,” it confirmed what critics had warned: the empathy was gone. To quote Fil MV: “He has great technical taste but he is not a good leader… To have him keynote and hold a veto over the community is to say to people like me, and brown-skinned people everywhere, ‘you don’t belong here.’”

“Feel the fucking room, ffs” and the revolt in the comments section

DHH probably intended his keynote to be an exhilarating, Steve Ballmer-style “Oh, what a time to be alive!” rally. The public reception in the conference hall and across the YouTube comment section was characterized by shock, grief, and exhaustion.

The “conference tax” vs. the pitch. Attendees and remote viewers quickly noted the absurdity of paying premium ticket, travel, and lodging fees for a Rails conference only to be told that Rails is an afterthought and programming is dead:

“I attended Euruko a few days ago… Matz talked about tech. I feel sorry for everyone who bought a ticket and ‘has’ to be there to endure the rest of what’s coming.”

“Came here for Rails, got told I’m a loser in the shadows lol.”

“Imagine being a speaker following this talk and having to talk about Rails after DHH dumped it for Rust.”

Wealthy techie vs working techie. Commenters drove home the stark class divide between a multi-millionaire founder playing with unlimited API tokens and everyday developers navigating a brutal tech market and a rising cost of living:

“He’s a multimillionaire talking to a room of people who still need a paycheck for the next 30 years. He has his bag, of course he’s excited. He’s got nothing to lose like the rest of us.”

“The problem is not really that AI will end careers, the problem is that the people who will end it are trying to convince you to be happy about it… Feel the fucking room, ffs.”

The knowledge freeze and architectural decay. For years, DHH and 37signals marketed themselves as the ultimate defenders of digital sovereignty. They led the charge on leaving the public cloud (“Cloud Exit”), crusaded against Apple’s App Store tax, championed self-hosted SQLite, and preached independence from Silicon Valley oligarchs.

Yet at Rails World 2026, that posture inverted entirely:

  • From sovereignty to model rent-seeking: The software pipeline was surrendered to centralized model providers like Anthropic and OpenAI. As one commenter observed: “Rails World 2025: End to end freedom. Rails World 2026: Just depend on other companies.”
  • From craft to disposable slop: Software is no longer a well-tended garden engineered for human delight and maintainability. It’s now an unread, disposable byproduct generated in mass volume. To cite the work of another techno-dick: We are now the pointy-haired bosses from Dilbert.
  • Cannibalizing his own moat: If an email client, a desktop utility, or a SaaS backend can be vibecoded in 20 minutes from plain English prompts, the economic justification for 37signals vanishes. Why pay a monthly SaaS subscription to HEY or Basecamp when an agent can compile a custom personal client directly to native bytecode?

The end of an era

Programming languages and frameworks are like Freddy Kruger or Jason Voorhees; they’re hard to kill and live longer than expected.

Ruby on Rails won’t vanish overnight. Thousands of monoliths power the backbone of global businesses, and Ruby’s and Rails’ expressive designs will always offer genuine joy to developers who care about the craft of programming.

But something did die on the keynote stage in Austin: the social contract between the framework and its creator. For years, developers looked the other way during DHH’s controversies because he remained the ultimate champion of developer ergonomics, craftsmanship, and the indie hacker’s right to build elegant software.

By taking the stage at Rails World to declare coding obsolete, dismiss Ruby as a relic, flaunt unreadable Rust generated by third-party black boxes, and label his own audience “losers” for caring about their craft, DHH finalized a break that had been brewing for years.

Rails may endure, but its original architect has officially left the building. It’s now up to the community to decide whether it continues to chain itself to an alienated founder, or finally gather the courage to build a post-DHH future.

Postscript

why the lucky stiff, where are you when we need you?

Categories
Picdump

Saturday picdump for Saturday, September 26

Happy Saturday, everyone! Here on Global Nerdy, Saturday means that it’s time for another “picdump” — the weekly assortment of amusing or interesting pictures, comics, and memes I found over the past week. Share and enjoy!


819123990_10236535965762634_839005063707742698_n

817831117_10165972886049245_936869335309238950_n

821523291_2012316232758510_5436807527487761980_n

821468804_1399077276611291_627463316009069794_n

821719054_3017410615267738_8822214565721925121_n

781276143_28512912551675822_3214346372768849899_n

795583341_1400717178850980_6034966861494757642_n-1

765573514_28062462673391276_5447584912699396840_n

818353565_29392562780331200_2865061696133224172_n

807750445_1075806855314871_312632806793250003_n-1

811664966_17961311169214435_4406041307379425325_n

790300987_1103784965488153_7612477104259454303_n

800842036_10241889398443418_2540616191841927210_n-1

795776044_2899924997008456_4117364202908216564_n

821523269_1120588610861956_2997761412033852744_n

822392533_1673323817555109_1297673069104558205_n

820280052_2163408007936031_3215531174780482003_n

Screenshot
Screenshot

821523298_4562720477383931_4921608207141091127_n

770774414_28128765213427688_7294827002387899016_n

819811994_974061969072371_843845983623869956_n

817651420_1086360570790970_2195224854121587070_n

1790105530134

825279844_10163332925676088_7862478935603936766_n

821638562_4379982442252051_8382640005318710333_n

703222535_27166524742985078_5511981231123969596_n

bzd6buus1oqh1

824930706_1065392243076678_4337297296192714912_n

819882522_3427111597469721_4404105749018785850_n

815866680_1989604028400682_8782547871267993814_n

667046726_26651814321122792_3572431210722142030_n

808431080_17986415292116671_4173388024493428004_n

814393626_1719975096799343_5609793324376510888_n-1

813421482_10165044397661131_2000127176188460321_n

818365676_4561175260871786_6389646558407277954_n

819219111_4364652843751639_4665925582074286210_n

825351363_10238791062373398_1039418349437025379_n

824352674_17991197160104396_6719057387967304188_n

818365280_10175393632070117_9080107879800925728_n

IMG_2997

819470291_2119221958987933_4607706961654203776_n

698505114_27059485940355626_1602761737624178341_n

800239300_10232020826454927_3821409630873980910_n

817706491_122135360955239157_8738235513031948708_n

822440704_10244383677627812_7196772067552703572_n

689491418_26989484570689097_8294107568853208737_n

795661506_2965146087156347_3729225186282856420_n

Screenshot
Screenshot

1790042119610

795431324_10165972892419245_6892780507710282937_n

815890867_10240726202306748_1003209096411808053_n

796608721_10163828794629482_7460493462888896546_n

823990436_29258542310410542_5322306005867559951_n

683823908_26882178914752997_5381462264704167087_n

815921291_10163869755183878_8655780198632243409_n

820064606_1082459451162525_9088291104520209111_n

819987691_1100289355917620_3962930397938907371_n

795298249_1473825134604788_7707630137040565014_n

no-laptops-classroom

818936764_28832590033041570_8968305787016464630_n

Screenshot
Screenshot

can-confirm-v0-1i9tj5utooqh1

rotate-pdf-1

818936756_1097977319235811_4544152903222660300_n

817519490_10163619253171025_9021595426012613840_n

815866687_10163869755213878_5059647885669113747_n

819684225_28253414347633335_5626905095733349357_n

Screenshot
Screenshot

818936777_913902011523941_2489938017797496961_n

819329296_1434793618558948_8682122606413750556_n

1790096506111

809812445_3345452275843812_5349324263263627463_n

800220527_1818313039363097_25108154847674253_n

818392555_1099901915818082_5551010988054174279_n-1

819068731_1609414317585281_8438080335033500800_n

813137183_1611026600417201_1004288666964600976_n

774362105_28190125277291681_4195995548351623676_n

meta-tamagotchi

793000788_28433193772984829_1158743573489202084_n

pbbsul1wseqh1

794994768_10175705397830192_5974788287806404475_n

796958385_28466730849631121_5178993453632692991_n

1790256918893

699650831_27079340128370207_4345560452102787519_n

818686448_1878770086427917_6135522337493841089_n

IMG_2992

810051567_10243479485432953_9146853808146118849_n

820336365_1772232014908628_447014945898113209_n

818865580_2815953092101377_4058392984447855941_n

1790050682381

818819570_10165096699387020_2043423111382152949_n

818926167_1521090850039255_6449735724423477104_n

IMG_3382

IMG_3436

IMG_3415

IMG_3371

IMG_3410

IMG_3420

IMG_3409

IMG_3435

IMG_3405

IMG_3498

IMG_3499

Screenshot
Screenshot

IMG_3524

IMG_3521

IMG_3475

Screenshot
Screenshot

IMG_3379

IMG_3446

IMG_3515

IMG_3376

IMG_3370

IMG_3375

IMG_3380

IMG_3377

Screenshot

IMG_3372

IMG_3383

Screenshot

IMG_3378

IMG_3523

IMG_3489

Screenshot

IMG_3452

IMG_3374

IMG_3381

Screenshot
Categories
Current Events Meetups Tampa Bay

Tampa Bay tech, entrepreneur, and nerd events list (Monday, September 28 – Sunday, October 4)

Here’s what’s happening in the thriving tech scene in Tampa Bay and surrounding areas for the week of Monday, September 28 through Sunday, October 4!

This list includes both in-person and online events. Note that each item in the list includes:

✅ When the event will take place

✅ What the event is

✅ Where the event will take place

✅ Who is holding the event

This week’s events

Monday, September 28

Event name and location Group Time
Venice Area Toastmasters Club #5486
Online event
Toastmasters District 48 7:30 AM to 9:00 AM EDT
Beach Networking at DoubleTree North Redington
DoubleTree by Hilton Beach Resort Tampa Bay/North Redington Beach
Beach Bar Backers Group -Professional Networking & Social 4:30 PM to 6:30 PM EDT
Speakeasy Toastmasters #4698
Online event
Toastmasters District 48 6:00 PM to 8:00 PM EDT
Sarasota Blood on the Clocktower
Clocktower meetup
Board Games and Card Games in Sarasota & Bradenton 6:00 PM to 10:00 PM EDT
MTG: Commander Night
Critical Hit Games
Critical Hit Games 6:00 PM to 11:00 PM EDT
Games at Barriehaus Trinity
Barriehaus Beer Company, Trinity
Advance 3 Spaces Neurodivergent Social Gaming 6:00 PM to 8:00 PM EDT
Toast of Lakewood Ranch Toastmasters Club
Lakewood Ranch Town Hall
Toastmasters District 48 6:30 PM to 7:30 PM EDT
North Port Toastmasters Meets Online!!
Online event
Toastmasters District 48 6:30 PM to 8:00 PM EDT
Mythic Bastionland: Session 3 of 6
Kitchen Table Games (New Location)
St Pete and Pinellas Tabletop RPG Group 6:30 PM to 9:30 PM EDT
Finding Your Voice
Online event
Tampa Bay – Pinellas County Black Business Meetup Group 7:00 PM to 8:00 PM EDT
Let’s Talk Toastmasters
Online event
Toastmasters Divisions C & D 7:00 PM to 8:30 PM EDT
Hidden Gems Night, Presented by A Duck!
Online event
Nerdbrew Events 7:00 PM to 10:00 PM EDT
Monday New Port Richey Games!
Old Tavern Games
Blood on the Clocktower Tampa Bay 7:00 PM to 10:00 PM EDT
On Desire: Why We Want What We Want
Online event
Orlando Stoics 7:00 PM to 8:30 PM EDT
DigiMondays
Sunshine Games | Magic the Gathering, Pokémon, Yu-Gi-Oh!
Sunshine Games 7:30 PM to 9:30 PM EDT
Weekly General Meetup
Online event
Beginning Web Development 8:00 PM to 9:00 PM EDT
Where is Bitcoin Going?
Online event
Bitcoiners of Southwest Florida 9:00 PM to 10:00 PM EDT
Return to the top of the list

Tuesday, September 29

Event name and location Group Time
CEO Toastmasters
Online event
Toastmasters Divisions C & D 8:00 AM to 9:00 AM EDT
Branding: The Secret Weapon In Your Job Search
Online event
Tech Success Network 10:00 AM to 11:00 AM EDT
Online: DaVinci Resolve – Edit Page
Online event
Orlando Video & Post Production Meetup 2:00 PM to 3:30 PM EDT
Online: DaVinci Resolve – Fusion FX
Online event
Orlando Video & Post Production Meetup 4:00 PM to 5:30 PM EDT
Weekly Open Make Night
4931 W Nassau St
Tampa Hackerspace 6:00 PM to 9:00 PM EDT
Disney Lorcana Night
Critical Hit Games
Critical Hit Games 6:00 PM to 11:00 PM EDT
Hobby Night
Critical Hit Games
Critical Hit Games 6:00 PM to 11:00 PM EDT
Free Thinkers: Exploring The Big Questions
President Barack Obama Main Library
Freethinker’s Workshop 6:15 PM to 8:00 PM EDT
Winter Haven Toastmasters
St Paul’s Episcopal Church
Toastmasters Division E 6:30 PM to 8:30 PM EDT
Loner Seekers Euchre – Tampa
Shamrocks Ale House
Loner Seekers Euchre – Tampa 6:30 PM to 9:30 PM EDT
D&D @ Critical Hit Games (Full)
Critical Hit Games
RPG-Pinellas 6:30 PM to 11:00 PM EDT
The Sarasota Creative Writers
Sarasota Alliance Church
The Sarasota Creative Writers Meetup Group 6:30 PM to 9:30 PM EDT
Find Your Voice: Dunedin Toastmasters
Unity Community Church
Dunedin Toastmasters 2166 7:00 PM to 8:30 PM EDT
Winter Springs Toastmasters Club
Online event
Toastmasters Divisions C & D 7:00 PM to 8:15 PM EDT
Boards & Bones Table Top RPGs
Gambit Games
Nerdbrew Events 7:00 PM to 10:00 PM EDT
St. Pete Beers ‘n Board Games Meetup for Young Adults
3 Daughters Brewing
St. Pete Beers ‘n Board Games for Young Adults 7:00 PM to 10:00 PM EDT
Yu-Gi-Oh Evening Tournament
Sunshine Games | Magic the Gathering, Pokémon, Yu-Gi-Oh!
Sunshine Games 7:00 PM to 11:00 PM EDT
Badass Babes – Weekly Movie Night
Online event
Nerdbrew Events 7:30 PM to 9:30 PM EDT
Trading Tuesday
Online event
Bitcoiners of Southwest Florida 8:00 PM to 9:00 PM EDT
Get The Most Out Of Your Photos: Lets Study FILE FORMATS: JPG, TIFF, RAW, MORE!
Online event
Tampa St Pete Photography Community 8:00 PM to 8:40 PM EDT
Return to the top of the list

Wednesday, September 30

Event name and location Group Time
World Toasters Toastmasters Club
Online event
Toastmasters Division E 7:05 AM to 8:00 AM EDT
Tampa Highrisers Toastmasters
Hyde Park United Methodist Church
Toastmasters District 48 7:45 AM to 8:45 AM EDT
Computer Repair Clinic
2079 Range Rd
Tampa Bay Technology Center 8:30 AM to 12:30 PM EDT
✨IndieGameBusiness® Sessions:The Path from Storefront to Success30.9/10AM ET
Online event
Orlando Unity Developers Group 10:00 AM to 6:00 PM EDT
Productivity Wednesday
300 E State Street
Kazba Cafe – Oldsmar FL 10:00 AM to 1:00 PM EDT
NotebookLM: Turn Your Documents into an AI Research Assistant
Online event
AI Tool of the Week 12:00 PM to 1:00 PM EDT
Lunch Hour Meetup
Online event
Sarasota Web Development Meetup Group 12:00 PM to 1:00 PM EDT
Online: DaVinci Resolve – Color Page
Online event
Orlando Video & Post Production Meetup 4:00 PM to 5:30 PM EDT
Wednesday Night Gaming
Nerdy Needs
Brandon Boardgamers 5:00 PM to 10:00 PM EDT
40k Escalation League
Battlebrush Games
Battlebrush Games: Paint Minis & Play Warhammer/Warmachine 5:00 PM to 9:00 PM EDT
CNC Wednesday’s
MakerSpace St. Petersburg
Makerspaces Pinellas Meetup Group 5:30 PM to 7:30 PM EDT
Orlando Chess Association
West Osceola Library
Greater Orlando Chess 5:30 PM to 8:30 PM EDT
Wednesday Board Game Night
Bridge Center
Tampa Gaming Guild 5:30 PM to 11:00 PM EDT
AWS Transform
Entrepreneur Collaborative Center (ECC)
Tampa Bay AWS User Group 6:00 PM to 7:30 PM EDT
Casual Commander Wednesdays
Sunshine Games | Magic the Gathering, Pokémon, Yu-Gi-Oh!
Sunshine Games 6:00 PM to 11:00 PM EDT
Board Game Night
Critical Hit Games
Critical Hit Games 6:00 PM to 11:00 PM EDT
ELKS Euchre Night
Elks Club Ladge
Greater Orlando Euchre Players [ UNKNOWN DISPLAY TIME ]
Board game night at CHG!
Critical Hit Games
Saint Pete Boardgamers 6:00 PM to 11:00 PM EDT
Magic Pioneer Event
Sunshine Games | Magic the Gathering, Pokémon, Yu-Gi-Oh!
Sunshine Games 6:45 PM
Sun Coast Euchre Club
The Hanger Restaurant & Flight Lounge
Suncoast Euchre Club -St Pete 6:50 PM to 8:50 PM EDT
Carrollwood Toastmasters Meetings meet In-Person and Online
Jimmie B. Keel Regional Library
Toastmasters District 48 7:00 PM to 8:30 PM EDT
Games & Grog! Board game night @ Peabodies
Peabodies
Nerdbrew Events 7:00 PM to 11:00 PM EDT
St Pete Wednesday Game Night
Right Around The Corner
St Pete Game Night 7:00 PM to 9:00 PM EDT
Cardfight Vanguard!! OverDress Weekly
Sunshine Games | Magic the Gathering, Pokémon, Yu-Gi-Oh!
Sunshine Games 7:30 PM to 9:30 PM EDT
Return to the top of the list

Thursday, October 1

Event name and location Group Time
Sarasota Speakers Exchange Toastmasters
Online event
Toastmasters District 48 12:00 PM to 1:00 PM EDT
Open Board Gaming Day at Dark Side
Dark Side Comics & Games
Board Games and Card Games in Sarasota & Bradenton 4:00 PM to 10:00 PM EDT
Omni Toastmasters Club 6861
Online event
Toastmasters Divisions C & D 5:45 PM to 7:00 PM EDT
[AL] Phandelver and Below: The Shattered Obelisk [APL 4 Tier 1]
Coliseum of Comics Kissimmee
Adventurers of Central Florida 6:00 PM to 9:00 PM EDT
Board Game Night
Unrefined Brewing
Tarpon Springs Community Fun & Games 6:00 PM to 9:00 PM EDT
Warhammer Night
Critical Hit Games
Critical Hit Games 6:00 PM to 11:00 PM EDT
Creative Writing club
Foxtail coffee
Cozy Club 6:30 PM to 8:00 PM EDT
What’s the Problem? Bitcoin for Beginners
Tampa Bay Innovation Center
Tampa Bay Bitcoin 7:00 PM to 9:00 PM EDT
New Website Announcement
Online event
Tampa AI Applications Meetup Group 7:00 PM to 8:00 PM EDT
Palm Harbor Toastmasters Club #8248
1500 16th St
Toastmasters District 48 7:00 PM to 8:30 PM EDT
FABulous Thursdays
Sunshine Games | Magic the Gathering, Pokémon, Yu-Gi-Oh!
Sunshine Games 7:00 PM to 11:00 PM EDT
One Piece Thursdays
Sunshine Games | Magic the Gathering, Pokémon, Yu-Gi-Oh!
Sunshine Games 7:00 PM to 10:00 PM EDT
Pathfinder Society
Critical Hit Games
Critical Hit Games 7:00 PM to 10:00 PM EDT
Let’s Talk About Social Media
Online event
So, How’s Social Media Going? 7:00 PM to 8:00 PM EDT
Digger
AMC Veterans 24
Tampa Movie Group 7:15 PM to 9:15 PM EDT
Thursday Tacos & Tax Write Offs
Online event
Nerdbrew Events 7:30 PM to 10:30 PM EDT
Return to the top of the list

Friday, October 2

Event name and location Group Time
Osceola Toastmasters Club
Kissimmee Utility Authority (KUA)
Toastmasters Division E 7:30 AM to 9:00 AM EDT
Computer Repair Clinic
2079 Range Rd
Tampa Bay Technology Center 8:30 AM to 12:30 PM EDT
Age of Sigmar: Escalation League
Battlebrush Games
Battlebrush Games: Paint Minis & Play Warhammer/Warmachine 5:00 PM to 9:00 PM EDT
MTG: Commander FNM
Critical Hit Games
Critical Hit Games 6:00 PM to 11:00 PM EDT
Book Club at Turmeric
Turmeric
Pages and Plates Book Club 6:30 PM to 8:30 PM EDT
Marcus Aurelius – Meditations, Part IV
The Skills Center
Tampa Stoics 6:30 PM to 8:30 PM EDT
Modern FNM
Sunshine Games | Magic the Gathering, Pokémon, Yu-Gi-Oh!
Sunshine Games 7:00 PM to 10:30 PM EDT
Friday Pokemon Tournament
Sunshine Games | Magic the Gathering, Pokémon, Yu-Gi-Oh!
Sunshine Games 7:30 PM to 11:30 PM EDT
Return to the top of the list

Saturday, October 3

Event name and location Group Time
Creative Writing In-Person Monthly Gathering for Aspiring Authors
16120 US Hwy 19 N
Pinellas Writers Group 9:00 AM to 12:00 PM EDT
Saturday Chess at Wholefoods in Midtown, Tampa
Whole Foods Market
Chess Republic 9:30 AM to 12:00 PM EDT
Saturday Morning ‘Toons & Tabletop
Conworlds Emporium
Tarpon Springs Community Fun & Games 10:00 AM to 1:00 PM EDT
Mutant Crawl Classics – a one-shot adventure
Emerald City Comics Games Toys
St Pete and Pinellas Tabletop RPG Group 1:00 PM to 4:00 PM EDT
FREE Fab Lab Orientation
Faulhaber Fab Lab
Suncoast Makers 1:30 PM to 2:30 PM EDT
D&D (5e) @ Game-o-Storus (FULL)
Game-o-Storus
St Pete and Pinellas Tabletop RPG Group 1:30 PM to 5:30 PM EDT
D&D @ Game-O-Storus (FULL)
Game-o-Storus
RPG-Pinellas 1:30 PM to 5:30 PM EDT
Tampa Fright Club Presents: Creature from the Black Lagoon in 3D (35mm)!
Sun-Ray Cinema
Tampa Fright Club 2:00 PM to 5:00 PM EDT
Saturday Afternoon Catan
Whole Foods Market
Tampa Bay Settlers of Catan 4:00 PM to 7:00 PM EDT
Board Brews
Zephyrhills Brewing Company
Nerdbrew Events 5:00 PM to 10:00 PM EDT
Warmachine Journeyman League
Battlebrush Games
Battlebrush Games: Paint Minis & Play Warhammer/Warmachine 5:00 PM to 9:00 PM EDT
Yu-Gi-Oh Evening Tournament
Sunshine Games | Magic the Gathering, Pokémon, Yu-Gi-Oh!
Sunshine Games 7:00 PM to 11:00 PM EDT
Things Fall Apart by Chinua Achebe Discussion Cybel in St. Pete (BYOB))
Cybel
Classic Book Club – Dinner Edition 7:00 PM to 9:00 PM EDT
Return to the top of the list

Sunday, October 4

Event name and location Group Time

Networking & Mastermind
Online event

Founders And Capital

2:00 PM to 3:00 PM EDT

Sunday Chess at Wholefoods in Midtown, Tampa
Whole Foods Market

Chess Republic 2:00 PM to 5:00 PM EDT
D&D Adventurers League
Critical Hit Games

Critical Hit Games 2:00 PM to 7:30 PM EDT
Saltmarsh and Beyond (5e 2024 D&D Campaign)
Cozy Dragon Games

Adventurers of Central Florida 3:00 PM to 7:00 PM EDT
Traveller – Science Fiction Adventure RPG
Black Harbor Gaming

St Pete and Pinellas Tabletop RPG Group 3:00 PM to 6:00 PM EDT
Sunday Pokemon League
Sunshine Games | Magic the Gathering, Pokémon, Yu-Gi-Oh!

Sunshine Games 4:00 PM to 8:00 PM EDT
Community Hang-out Night
Online event

Nerdbrew Events 6:00 PM to 9:00 PM EDT
A Duck Presents NB Movie Night
Discord.io/Nerdbrew

Nerd Night Out 7:00 PM to 11:30 PM EDT
Return to the top of the list

About this list

How do I put this list together?

It’s largely automated. I have a collection of Python scripts in a Jupyter Notebook that scrapes Meetup and Eventbrite for events in categories that I consider to be “tech,” “entrepreneur,” and “nerd.” The result is a checklist that I review. I make judgment calls and uncheck any items that I don’t think fit on this list.

In addition to events that my scripts find, I also manually add events when their organizers contact me with their details.

What goes into this list?

I prefer to cast a wide net, so the list includes events that would be of interest to techies, nerds, and entrepreneurs. It includes (but isn’t limited to) events that fall under any of these categories:

    • Programming, DevOps, systems administration, and testing
    • Tech project management / agile processes
    • Video, board, and role-playing games
    • Book, philosophy, and discussion clubs
    • Tech, business, and entrepreneur networking events
    • Toastmasters and other events related to improving your presentation and public speaking skills, because nerds really need to up their presentation game
    • Sci-fi, fantasy, and other genre fandoms
  • Self-improvement, especially of the sort that appeals to techies
  • Anything I deem geeky
Categories
Security

“You will never patch fast enough” (or: 5 days to exploit, 32 days to patch, and why better triage doesn’t close that)

There’s a six-part series on the NetFoundry blog with a title that’s becoming only more apparent as we move further into the Age of AI: You Will Never Patch Fast Enough. Here’s the Math.

It’s written by Jack Poller. Yes, his title says VP Product Marketing, but he has a long history as a developer, so he’s got first-hand experience with what fixing software used to be like, and an educated view into what it’s like now. So the “here’s the math,” part of the title makes it clear that this is an article written by someone who’d rather show you the arithmetic than the adjectives.

Jack kicked off the series on our blog yesterday, and here’s my summary:

The numbers

From Verizon’s 2025 DBIR and FIRST’s mid-year forecast:

  • Disclosures: 40,000+ CVEs in 2024, up 38% year over year. FIRST’s June revision puts 2026 near 66,000, which is considerably higher than the February projection of 59,427, and running about 46% above that baseline through April.
  • Remediation: for the edge and VPN device vulnerabilities DBIR studied, a median of 32 days to close, and only 54% fully closed at all. The average for that set was over half a year (209 days).
  • The median time from disclosure to exploitation was five days. Exploitation as a breach vector rose 34% year over year and factors into 20% of breaches. Edge and VPN devices went from 3% to 22% of studied breaches in a single year.

Five days versus 32 days, on the same population of assets. There are some levers available to you that can cut that time down to 25 days (more analysts, tighter change windows), but that reduced time is still five times as long as the disclosure-to-exploitation time.

FIRST attributes the climb to 66,000 CVEs to three structural drivers and not just one:

  • AI-assisted discovery
  • A 449% jump in GitHub Security Advisory volume
  • A 3,119% increase in VulnCheck acting as CNA of last resort

The VulnCheck figure is largely a backlog of already-existing vulnerabilities finally getting IDs assigned. FIRST’s interpretation is that this reflects better discovery and reporting rather than software getting worse. In my opinion, this emphasizes Jack’s point: Even flaws that don’t count as “new” are still going to end up in your queue.

Capacity and latency are different problems

A key part of Jack’s post is the section on volume versus risk. If you filter all those CVEs for things that are actually being exploited, such as CISA KEV entries or or EPSS above 10%, the actionable burden is fairly flat, and it’s a workload that’s manageable with some smart triage. If your team is well-run team, they can 66,000 disclosures without extra headcount, simply because most of them will never be weaponized against anyone.

But you’ll still be left with the set of vulnerabilities attackers have already decided are worth building for. That’s the slice with the shortest clock on it. Prioritizing well gives you a smaller list that burns faster.

So there are two different questions here, and they have different answers:

  1. Can my team absorb the workload? Sure, with good triage.
  2. On the items that survive triage, can I close before exploitation? Median five days against median 32.

Getting better at the first question doesn’t change the answer to the second one. In systems terms it’s problem of service-time rather than throughput. You can have a perfectly stable queue and still blow every deadline in it.

Where the series goes

Jack’s argument is that same as WOPR from the movie WarGames: Don’t play games you can’t win. In practical security terms, it’s better to make the asset unreachable, so an unpatched flaw has no network path to it. The CVE stays open in your scanner, but the exposure doesn’t exist.

NetFoundry calls this vulnerability cloaking, and parts 2 through 6 in Jack’s series will cover risk-acceptance waivers, the technical case, assets that can never be patched (EOL systems, plus everything not yet disclosed), the CFO math, and a vendor checklist.

The honest limit, because I’d rather say it than have it said at me: this helps for things that shouldn’t be broadly reachable in the first place. Your public web front end has to answer the internet and no overlay changes that. Where it bites is the large category of stuff that’s internet-reachable for reasons nobody can currently articulate: management interfaces, internal APIs, appliance admin panels, that one jump box. Which, per DBIR, is exactly the category that went from 3% to 22%.

Once again, here’s the article: You Will Never Patch Fast Enough. Here’s the Math.

Categories
Design Editorial

My systems design advice

Build your systems, workflows, and user interfaces with the mindset that people will walk up to this place and ask “What kind of food do you have?”

It’s not that they’re idiots, but that their attention is getting pulled in so many different directions at once these days.

Categories
Artificial Intelligence Security

“Reachability Watch” for September 11 – 17, 2026: 8 CVEs against Langflow in one week, and why “publicly shared” = “publicly ownable”

I’m a few days late on this one, but the content holds up: last week’s Reachability Watch, written by our Chief Strategy and Marketing Officer Mark Jaffe, covering September 11–17, is here:
https://netfoundry.io/ai/reachability-watch-cve-kev-tracker-2026-09-18/

(On the bright side, I had time to draw a “back of the envelope” comic that covers the big CVE!)

The CVE numbers

Here are the numbers:

  • 1,248 new network-exploitable CVEs
  • 117 of these CVEs are rated at 8.6 or higher
  • 12 of these CVEs are a perfect 10.0:
    • 9 of those twelve in vm2 alone

Worth reading

1. The Langflow flaw

CVE-2026-85025 (9.8) is unauthenticated RCE in IBM Langflow OSS 1.0.0–1.11.5. It’s reachable through publicly shared MCP project endpoints, with read and write access to chat sessions on top. Whatever context, credentials, or proprietary data flowed through those sessions comes along with it.

The mechanism is the interesting part. Langflow lets you share a flow via an MCP project endpoint so other tools and agents can call it programmatically. The code that’s supposed to enforce “this one flow is public, everything else isn’t” doesn’t hold that boundary. So “publicly shared” quietly generalizes from one flow to the host. This happens without a privilege escalation chain, user interaction, or even any waiting for someone to click anything.

All in all: 8 CVEs against Langflow in a single seven-day window, including the one above: code injection, OS command injection, path traversal, an incomplete scanner denylist, and this one.

2. The difference between CVE vs. KEV

  • CVE: Common Vulnerabilities and Exposures. These are publicly-disclosed security flaws, and may or may not have been used in an attack. These are weaknesses that have been announced.
  • KEV: Known Exploited Vulnerability. This is a CVE that CISA (Cybersecurity and Infrastructure Security Agency) has confirmed is being actively exploited against real targets. A KEV is a CVE that got a job.

Mark writes that he’d bet money that the Langflow flaw above becomes a KEV. Another Langflow CVE has already done that: CVE-2025-3248, a missing-authentication RCE, which went onto CISA’s KEV catalog on May 5, 2025, with a three-week federal remediation deadline and confirmed ransomware use. Sysdig later documented that same flaw on a server nobody had patched in over a year as the entry point for what they assessed as the first fully autonomous agentic ransomware operation.

The traits that move a CVE onto KEV are the traits this one has: no auth, trivially scannable, and sitting on infrastructure that isn’t in anyone’s asset inventory. Langflow has supplied both ends of that pipeline before.

3. Why AI agent platforms keep showing up in Reachability Watch

Because these tools are three things all at once:

  • New
  • Fast-moving
  • Production-critical

…and they’re shipped by teams optimizing for getting an AI capability out the door. As a result, exposure and hardening get less scrutiny than they’d get on a mature enterprise system.

The part that makes them worth an attacker’s time specifically: compromising one doesn’t get you a single host, it gets you the whole key ring. The same property that makes the platform useful is what makes the blast radius large, which is why “it’s just an internal tool on a dev box” ages so badly.

Categories
Security Tools

Can you use zrok’s Free hosted plan for your team’s internal tool? (or: 5 questions, answered)

We recently got a great set of questions from someone evaluating hosted zrok for a web-based e-commerce content tool.

Their situation: a small team of internal colleagues testing a tool for business work that might later become part of their daily workflow, and their budget was zero dollars.

Their main question: Could they use the Free hosted version of zrok?

The super-short answer

Yes!

The short (but with some details) answer

If you’re on a small internal team with zero budget, zrok’s Free hosted plan will cover your core needs:

  • A stable HTTPS address
  • Browser access with no install for users
  • Login-gated access for approved colleagues/users.

Watch the daily bandwidth (you’re limited to 5GB in any 24-hour period), make sure team knows about the interstitial page, and test from every region where you plan to use it.

Before the detailed 5 answers: What’s zrok?

zrok (pronounced “zee-rock”) is an open-source tool for sharing things running on your machine, such as…

  • A web app,
  • an API, or
  • a folder of files…

…without the need for you to open firewall ports or set up servers. You run one command on the machine where the service lives, and zrok gives you a way for other people to reach it. If you’ve used tunneling tools like ngrok, zrok covers similar ground, with private sharing and zero trust networking built in, and with a much bigger bandwidth allowance, too!

zrok can share in two ways:

  • Public shares give your service a regular HTTPS URL that anyone with a browser can open. zrok handles the TLS certificate. You can optionally require a Google or GitHub login so only approved people get in.
  • Private shares are reachable only by people who also run zrok and have been given access, so the service is never exposed to the open internet.

zrok is built on OpenZiti, the open-source zero trust networking platform created by NetFoundry. Your service makes outbound connections to the zrok network instead of listening for inbound ones, which means there are no inbound ports on your machine for scanners and attackers to find. As far as unauthorized parties are concerned, nothing’s happening on your machine, and there’s no way in.

You can use the hosted version at zrok.io, run by NetFoundry, or self-host it under the Apache 2.0 license. This article is about the hosted Free plan.

The 5 questions, answered

1. Is small-team, business-related use allowed on the Free plan?

Yes! Testing a business tool with a few colleagues, and using it internally afterward, is allowed on the hosted Free plan. You don’t need a paid tier for commercial use.

The terms that apply are in NetFoundry’s Self Service Subscriptions Agreement. As with any service agreement, have someone read it before you build a workflow on top of it.

2. Can I reserve a persistent, custom-named public HTTPS address without a payment method?

Yes! By default, zrok2 share gives you a random share token that disappears when the share ends. zrok 2.0 adds namespaces and names, which let you keep a stable address:

  • A namespace works like a DNS zone. The public namespace corresponds to share.zrok.io.
  • A name works like a DNS record inside that zone. A reserved name persists across runs of zrok2 share.

If you reserve the name contenttool in the public namespace, your app is available at https://contenttool.share.zrok.io. That address stays the same every time you restart the share, and it comes with a trusted TLS certificate automatically.

To see which namespaces you can use:

# bash
zrok2 list namespaces

For the details, see Reserved names and namespaces and Manage reserved names.

3. Can colleagues use the app in a normal browser without installing zrok? Can I limit who gets in?

Yes to both! A public share is a regular HTTPS URL, so your colleagues just open it in a browser. Only the machine running your app needs zrok installed.

To limit access to approved people, turn on OAuth for the share. zrok supports Google and GitHub login for public shares, and you can restrict access by email address pattern:

# bash
zrok2 share public --backend-mode proxy \
  --oauth-provider google \
  --oauth-email-address-pattern '*@yourcompany.com' \
  http://localhost:8080

Anyone who visits is sent to sign in first. Only accounts whose email matches the pattern get through. You can repeat --oauth-email-address-pattern to allow several domains or specific addresses.

There’s also a bonus for developers. Once someone is authenticated, zrok adds headers such as zrok-auth-email to every request it forwards to your app. That means your app can tell who’s using it without you building a login system. See OAuth public frontend for the full flow.

4. Are there mandatory charges, usage limits, or restrictions?

No mandatory charges. The Free plan costs $0 a month and doesn’t require a credit card. It does come with limits you should plan around:

  • 5 GB of bandwidth per day, measured over a rolling 24-hour window. If you go over, your running shares are disabled and you can’t create new ones until usage drops back under the limit. For a small team using a content tool this is usually plenty, but heavy media uploads could reach it.
  • 25 environments, 50 share backends, and 50 private access frontends. A small team won’t come close.
  • Rate limits on public shares: 2,000 requests per IP and 7,500 requests per share, each per 5-minute window.
  • An interstitial page. Accounts without a card on file show an anti-phishing page the first time someone visits a public share. It’s a one-time click-through for each visitor, but tell your colleagues about it so it doesn’t surprise them. Adding a card removes it, and you’re still on the Free plan.

In case you were wondering, here’s what the interstitial page looks like:

r/openziti - Can you use zrok's Free hosted plan for your team’s internal tool? (or: 5 questions, answered)

There’s also community support through the OpenZiti Discourse forum.

All the details are on the zrok pricing page and in the service limits docs. If you outgrow the Free plan, you can self-host zrok with no limits under the Apache 2.0 license, or talk to NetFoundry about commercial options.

5. Are there known restrictions on reaching hosted zrok shares from mainland China or other countries?

We don’t publish a list of country-by-country access guarantees. Whether a public URL is reachable from a given country depends partly on things outside our control, like local network policy.

Our advice is to review the terms of service linked above, then test your exact setup from the locations your users will be in before you roll it out. Stand up a throwaway share, have a colleague in each region load it and click around, and confirm it performs well enough for your needs.

Worth watching on Ziti TV

On the OpenZiti YouTube channel, there’s the Sharing Safely (and Rocking Out) with zrok episode, where hosts Clint and Joey explore zrok’s commands and talk zrok with its creator, NetFoundry developer Michael Quigley.