<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>@jonydevcode</title><description>My space on the internet.</description><link>https://jonybase.com/</link><item><title>The Problem with Withheld Wonder</title><link>https://jonybase.com/writing/problem-with-withheld-wonder/</link><guid isPermaLink="true">https://jonybase.com/writing/problem-with-withheld-wonder/</guid><pubDate>Wed, 17 Jun 2026 15:30:00 GMT</pubDate><content:encoded>&lt;p&gt;Months ago, I came across a trailer for &lt;a href=&quot;https://www.youtube.com/watch?v=UFe6NRgoXCM&quot;&gt;Disclosure Day&lt;/a&gt;. The trailer had all the ingredients for a movie that I would enjoy, including Spielberg as the director, John Williams as the composer, starring Emily Blunt, aliens, intrigue, and science fiction. I tremendously enjoy the work of Spielberg (Raiders of the Lost Ark, Minority Report). When tickets became available, I told myself, say no more, take my money, and I quickly booked a seat at the nearest IMAX theatre. I had high hopes and expectations.&lt;/p&gt;
&lt;p&gt;The trailer genuinely filled me with wonder. In the early version of the trailer, aliens were not even mentioned. That brief scene with Emily Blunt making the strange noises stirred up great intrigue in me. I wanted to see the movie because I wanted to be filled with a sense of discovery. Having finally watched it, the film simply does not deliver. I felt like everything in the movie was pointing towards something much more profound, but never fully bringing the viewer to that destination.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Warning: Major spoilers ahead. &lt;strong&gt;DO NOT&lt;/strong&gt; continue if you want to avoid spoilers.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The movie started strong. I was immediately thrown into a tense scene between Daniel vs Noah and his goons. There were multiple points of intrigue. What was that small cylindrical piece that Daniel held that struck such fear into everyone? What was the “truth” that was being hidden? I felt like I hit the ground running. The movie does a good job of moving the plot along without wasting time on exposition. I quickly learnt that there are good guys (the ones who wanted disclosure), and bad guys (the ones who wanted the secrets kept hidden). The film was setting up for a satisfying pay off at the end.&lt;/p&gt;
&lt;p&gt;However, as the plot marched on, the movie started to feel less like a display of intrigue and wonder, and more like a frustrating list of weak points and unanswered questions.&lt;/p&gt;
&lt;p&gt;For starters, the antagonist (CEO Noah and Wardex) is annoyingly weak. His men in black are super incompetent. They failed to notice Daniel sneaking around a board fence and let him steal one of their cars. They saw that same car drive into the river, and never considered that Daniel and Jane (who were simply hiding behind a rock nearby) could have jumped out before the cliff. For the final 15 mins of the movie, Noah just gave up, sat on the chair, and watched Margaret and Daniel release everything to the news networks.&lt;/p&gt;
&lt;p&gt;The motivations behind the major plot reveals are not clearly explained. Why did the aliens want to imbue Margaret and Daniel with those powers? Why did it take so long for the powers to manifest? What was the endgame? And let’s talk about Margaret. Her superpower is… weird. She seems to be able to control people, but the mechanism is not clear. In fact, the way she uses her power is borderline goofy. She rocks up to an army base, rattles off the guard’s name and personal PIN, and the guard lets her through. Shouldn’t you be extra doubtful of this civilian, who almost crashed into the barrier, and does not state her purpose in the military base, even though she knows something secret? Margaret then appears to Noah as his deceased wife, and suddenly Noah folds to her. What does appearing as a person’s deceased wife have to do with their free will? It doesn’t make sense.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;Emily Blunt holds a glowing alien artefact in her hand&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2200&quot; height=&quot;1467&quot; src=&quot;https://jonybase.com/_astro/disclosure_day_screengrab.D0Wg94nB_ZM4dgS.webp&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Source: Universal Pictures.&lt;/p&gt;
&lt;p&gt;In many articles about the movie, a screengrab shows Emily Blunt’s character Margaret holding a strange object that glows. This is one of three alien artefacts that appear throughout the movie. The movie never explains what they are, what they can do, or how to use them. They seem capable of anything, from “diving” into people’s minds, to performing a &lt;a href=&quot;https://iantsybulkin.medium.com/the-optical-illusion-from-mission-impossible-iv-how-it-might-work-62fb83bf2427&quot;&gt;Mission Impossible IV invisibility illusion&lt;/a&gt;, to turning the power back on.&lt;/p&gt;
&lt;p&gt;Several scenes also seemed loaded with significance, but there was no pay off later. One of the men in black grabbed the artefact, vanished in a puff of black smoke, and reappeared on the ground moments later. What happened? What was the crop circle generation scene around Daniel for? What was that moment in the train when Margaret was having a panic attack all about? For a moment, I thought Daniel was going to play the piano to calm her down.&lt;/p&gt;
&lt;p&gt;All these flaws would have been redeemed if the ending had been great with a fantastic pay off. But the ending left me feeling empty and underwhelmed. Margaret looked into the camera and said “Listen”. There was no satisfying conclusion, no explanation, and I left the cinema with more questions than answers. Sometimes, that’s a good thing. With Inception, my friends would discuss for weeks whether they were in a dream or not. But this time, I just felt that the whole film was evasive about what it was really trying to reveal, rather than being something profound.&lt;/p&gt;
&lt;p&gt;After the movie, I jotted down my thoughts. Then, I went to &lt;a href=&quot;http://imdb.com&quot;&gt;imdb.com&lt;/a&gt;’s user reviews section to see what others were saying. I saw two titles that resonated strongly with me: “Disclosure: nothing is disclosed” and “I wanted to be awestruck by Spielberg but instead I was dumbstruck”. Those couldn’t have more perfectly captured how I felt about the movie.&lt;/p&gt;
</content:encoded></item><item><title>Compatibility vs Containment</title><link>https://jonybase.com/writing/compatibility-vs-containment/</link><guid isPermaLink="true">https://jonybase.com/writing/compatibility-vs-containment/</guid><pubDate>Tue, 16 Jun 2026 13:00:00 GMT</pubDate><content:encoded>&lt;h1&gt;Compatibility vs Containment&lt;/h1&gt;
&lt;p&gt;Proton is a compatibility layer that allows games to run on Linux. Proton is built by Valve, the company behind Steam, which is the world’s largest gaming platform by far. By making games playable on Linux, Valve has done unimaginable good for Linux adoption. I run Fedora on my gaming desktop. Proton is what has allowed me to enjoy so many games for the past several years.&lt;/p&gt;
&lt;p&gt;With the magic required to get games to run well on Linux, I imagined that Proton forms a sort of containment layer around the Windows application. However, this couldn’t be further from the truth. In fact, Proton is based on Wine, which literally stands for Wine Is Not an Emulator. What security boundary did I then wrongly assume that Proton (or Wine) provides?&lt;/p&gt;
&lt;p&gt;I encountered this lack of a security boundary firsthand while I was tinkering around with running games and other Windows applications on Linux. I ran &lt;code&gt;7zFM.exe&lt;/code&gt; (the File Manager binary for &lt;a href=&quot;https://www.7-zip.org/&quot;&gt;7-Zip&lt;/a&gt;) and noticed that Proton maps Windows drives to various paths on my Linux system. For example:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;Z:&lt;/code&gt; is mapped to &lt;code&gt;/&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;X:&lt;/code&gt; is mapped to my home directory&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This gave me pause for concern. My initial reaction was, why does a game need so much access to run? I briefly considered the risk of compromised developer accounts used to distribute malware via legitimate game updates. Access to my entire disk would give them the ability to harvest my personal data.&lt;/p&gt;
&lt;p&gt;I then realised that I was implicitly treating Proton as a sort of security boundary, when this was entirely the wrong mental model to have.&lt;/p&gt;
&lt;p&gt;On &lt;a href=&quot;https://github.com/valvesoftware/proton&quot;&gt;its GitHub page&lt;/a&gt;, Proton very clearly states its intent:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Proton is a tool for use with the Steam client which allows games which are exclusive to Windows to run on the Linux operating system. It uses Wine to facilitate this.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;The goal has always been to run games. As many games as possible. In other words, the goal is widespread compatibility, not application isolation. This principle is also inherited from Wine, which clearly states in its FAQ that it &lt;a href=&quot;https://gitlab.winehq.org/wine/wine/-/wikis/FAQ#how-good-is-wine-at-sandboxing-windows-apps&quot;&gt;does not do any sandboxing whatsoever&lt;/a&gt;. Therefore, to desire or assume any form of isolation via Proton is a mistake.&lt;/p&gt;
&lt;p&gt;I started reflecting seriously about this because of how frequently supply chain attacks are used to distribute malware. Of all the malware, infostealers really scare me. But you know what’s worse than an infostealer? An infostealer masquerading as a game, available on Steam for anyone including myself to purchase and play.&lt;/p&gt;
&lt;p&gt;There are already several examples of games that were hijacked with infostealers. One example is &lt;a href=&quot;https://blog.gdatasoftware.com/2025/09/38265-steam-blockblasters-game-downloads-malware&quot;&gt;BlockBlasters&lt;/a&gt;. You can see an example of a batch script collecting browser profiles and crypto wallet data and sending it to a C2 server.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;Malware payload showing a batch script that collects crypto wallet and browser data.&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;862&quot; height=&quot;550&quot; src=&quot;https://jonybase.com/_astro/GDATA-BlockBlasters-Figure4.CFC7_qNW_Z10GFKv.webp&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Figure 1: Malware payload showing a batch script that collects crypto wallet and browser data. (&lt;a href=&quot;https://blog.gdatasoftware.com/2025/09/38265-steam-blockblasters-game-downloads-malware&quot;&gt;Source&lt;/a&gt;)&lt;/p&gt;
&lt;p&gt;I wondered, why doesn’t Valve do something about it with Proton? Then, I stumbled across &lt;a href=&quot;https://github.com/ValveSoftware/Proton/issues/3979&quot;&gt;this heated discussion on GitHub&lt;/a&gt; from 6 years ago discussing this very issue. I found the discussion fascinating, agreeing with arguments from both sides. The issue author questioned why Proton couldn’t just symlink to the directories it needs, like &lt;code&gt;~/.steam&lt;/code&gt; and the game’s install directory. Proton contributors responded that this is behaviour inherited from Wine, emphasising that Wine’s job is not isolation of applications from the host. The issue is marked as Closed, indicating that Valve likely does not see this as a problem to be fixed.&lt;/p&gt;
&lt;p&gt;It turns out that my question had been answered half a decade ago. The mapping of host directories, and a Wine executable having the ability to do anything a host user executable can do, is behaviour that should be expected from Proton.&lt;/p&gt;
&lt;p&gt;I did tinker further. In a WINE prefix, there is a &lt;code&gt;drive_c&lt;/code&gt; which serves as &lt;code&gt;C:&lt;/code&gt; for the Windows applications. If you place your binaries within &lt;code&gt;drive_c&lt;/code&gt;, you can minimise any need to read/write outside &lt;code&gt;C:&lt;/code&gt;. This means that entire games or applications can be run without Proton (or WINE) needing to map host directories.&lt;/p&gt;
&lt;p&gt;Assuming you are using that approach, there is a way to prevent this mounting by modifying a few lines inside &lt;a href=&quot;https://github.com/ValveSoftware/Proton/tree/proton_11.0&quot;&gt;Proton&lt;/a&gt; (and &lt;a href=&quot;https://github.com/Open-Wine-Components/umu-protonfixes/tree/b2e3bbc45dd74fa0ae60c93287e6de96a83fc8d3&quot;&gt;Protonfixes&lt;/a&gt; if you use that). Firstly, I must reiterate the point I already established earlier, which is that Proton is &lt;strong&gt;not&lt;/strong&gt; a true sandbox. Secondly, this an incredibly fragile solution.&lt;/p&gt;
&lt;p&gt;&lt;code&gt;./proton&lt;/code&gt;&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;&lt;span&gt;&lt;span&gt;# Line 998-1000: comment out these 3 lines&lt;/span&gt;&lt;/span&gt;
&lt;span&gt;&lt;span&gt;if&lt;/span&gt;&lt;span&gt; not&lt;/span&gt;&lt;span&gt; file_exists&lt;/span&gt;&lt;span&gt;(&lt;/span&gt;&lt;span&gt;self&lt;/span&gt;&lt;span&gt;.prefix_dir &lt;/span&gt;&lt;span&gt;+&lt;/span&gt;&lt;span&gt; &quot;&lt;/span&gt;&lt;span&gt;/dosdevices/z:&lt;/span&gt;&lt;span&gt;&quot;&lt;/span&gt;&lt;span&gt;,&lt;/span&gt;&lt;span&gt; follow_symlinks&lt;/span&gt;&lt;span&gt;=&lt;/span&gt;&lt;span&gt;False&lt;/span&gt;&lt;span&gt;):&lt;/span&gt;&lt;/span&gt;
&lt;span&gt;&lt;span&gt;    os&lt;/span&gt;&lt;span&gt;.&lt;/span&gt;&lt;span&gt;makedirs&lt;/span&gt;&lt;span&gt;(&lt;/span&gt;&lt;span&gt;f&lt;/span&gt;&lt;span&gt;&quot;&lt;/span&gt;&lt;span&gt;{&lt;/span&gt;&lt;span&gt;self&lt;/span&gt;&lt;span&gt;.prefix_dir&lt;/span&gt;&lt;span&gt;}&lt;/span&gt;&lt;span&gt;/dosdevices&quot;&lt;/span&gt;&lt;span&gt;,&lt;/span&gt;&lt;span&gt; exist_ok&lt;/span&gt;&lt;span&gt;=&lt;/span&gt;&lt;span&gt;True&lt;/span&gt;&lt;span&gt;)&lt;/span&gt;&lt;/span&gt;
&lt;span&gt;&lt;span&gt;    os&lt;/span&gt;&lt;span&gt;.&lt;/span&gt;&lt;span&gt;symlink&lt;/span&gt;&lt;span&gt;(&lt;/span&gt;&lt;span&gt;&quot;&lt;/span&gt;&lt;span&gt;/&lt;/span&gt;&lt;span&gt;&quot;&lt;/span&gt;&lt;span&gt;,&lt;/span&gt;&lt;span&gt; self&lt;/span&gt;&lt;span&gt;.prefix_dir &lt;/span&gt;&lt;span&gt;+&lt;/span&gt;&lt;span&gt; &quot;&lt;/span&gt;&lt;span&gt;/dosdevices/z:&lt;/span&gt;&lt;span&gt;&quot;&lt;/span&gt;&lt;span&gt;)&lt;/span&gt;&lt;/span&gt;
&lt;span&gt;&lt;/span&gt;
&lt;span&gt;&lt;span&gt;# Line 314: shortcircuit these two functions with return&lt;/span&gt;&lt;/span&gt;
&lt;span&gt;&lt;span&gt;def&lt;/span&gt;&lt;span&gt; setup_game_dir_drive&lt;/span&gt;&lt;span&gt;()&lt;/span&gt;&lt;span&gt;:&lt;/span&gt;&lt;/span&gt;
&lt;span&gt;&lt;span&gt;    return&lt;/span&gt;&lt;/span&gt;
&lt;span&gt;&lt;span&gt;    setup_dir_drive&lt;/span&gt;&lt;span&gt;(&lt;/span&gt;&lt;span&gt;&quot;&lt;/span&gt;&lt;span&gt;gamedrive&lt;/span&gt;&lt;span&gt;&quot;&lt;/span&gt;&lt;span&gt;,&lt;/span&gt;&lt;span&gt; &quot;&lt;/span&gt;&lt;span&gt;s:&lt;/span&gt;&lt;span&gt;&quot;&lt;/span&gt;&lt;span&gt;,&lt;/span&gt;&lt;span&gt; try_get_game_library_dir&lt;/span&gt;&lt;span&gt;())&lt;/span&gt;&lt;/span&gt;
&lt;span&gt;&lt;/span&gt;
&lt;span&gt;&lt;span&gt;def&lt;/span&gt;&lt;span&gt; setup_steam_dir_drive&lt;/span&gt;&lt;span&gt;()&lt;/span&gt;&lt;span&gt;:&lt;/span&gt;&lt;/span&gt;
&lt;span&gt;&lt;span&gt;    return&lt;/span&gt;&lt;/span&gt;
&lt;span&gt;&lt;span&gt;    setup_dir_drive&lt;/span&gt;&lt;span&gt;(&lt;/span&gt;&lt;span&gt;&quot;&lt;/span&gt;&lt;span&gt;steamdrive&lt;/span&gt;&lt;span&gt;&quot;&lt;/span&gt;&lt;span&gt;,&lt;/span&gt;&lt;span&gt; &quot;&lt;/span&gt;&lt;span&gt;t:&lt;/span&gt;&lt;span&gt;&quot;&lt;/span&gt;&lt;span&gt;,&lt;/span&gt;&lt;span&gt; try_get_steam_dir&lt;/span&gt;&lt;span&gt;())&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;code&gt;./protonfixes/utilities.py&lt;/code&gt;&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;&lt;span&gt;&lt;span&gt;# Insert a return to shortcircuit setup_mount_drives(), removing u, v, w, x&lt;/span&gt;&lt;/span&gt;
&lt;span&gt;&lt;span&gt;def&lt;/span&gt;&lt;span&gt; setup_mount_drives&lt;/span&gt;&lt;span&gt;(&lt;/span&gt;&lt;span&gt;func&lt;/span&gt;&lt;span&gt;:&lt;/span&gt;&lt;span&gt; Callable&lt;/span&gt;&lt;span&gt;[&lt;/span&gt;&lt;span&gt;[&lt;/span&gt;&lt;span&gt;str&lt;/span&gt;&lt;span&gt;,&lt;/span&gt;&lt;span&gt; str&lt;/span&gt;&lt;span&gt;,&lt;/span&gt;&lt;span&gt; str&lt;/span&gt;&lt;span&gt;]&lt;/span&gt;&lt;span&gt;,&lt;/span&gt;&lt;span&gt; None&lt;/span&gt;&lt;span&gt;]&lt;/span&gt;&lt;span&gt;)&lt;/span&gt;&lt;span&gt; -&amp;gt;&lt;/span&gt;&lt;span&gt; None&lt;/span&gt;&lt;span&gt;:&lt;/span&gt;&lt;/span&gt;
&lt;span&gt;&lt;span&gt;    &quot;&quot;&quot;&lt;/span&gt;&lt;span&gt;Set up mount point drives for proton.&lt;/span&gt;&lt;span&gt;&quot;&quot;&quot;&lt;/span&gt;&lt;/span&gt;
&lt;span&gt;&lt;span&gt;    return&lt;/span&gt;&lt;/span&gt;
&lt;span&gt;&lt;span&gt;    if&lt;/span&gt;&lt;span&gt; os&lt;/span&gt;&lt;span&gt;.&lt;/span&gt;&lt;span&gt;environ&lt;/span&gt;&lt;span&gt;.&lt;/span&gt;&lt;span&gt;get&lt;/span&gt;&lt;span&gt;(&lt;/span&gt;&lt;span&gt;&apos;&lt;/span&gt;&lt;span&gt;UMU_ID&lt;/span&gt;&lt;span&gt;&apos;&lt;/span&gt;&lt;span&gt;,&lt;/span&gt;&lt;span&gt; &apos;&apos;&lt;/span&gt;&lt;span&gt;):&lt;/span&gt;&lt;/span&gt;
&lt;span&gt;&lt;span&gt;        drive_map &lt;/span&gt;&lt;span&gt;=&lt;/span&gt;&lt;span&gt; {&lt;/span&gt;&lt;/span&gt;
&lt;span&gt;&lt;span&gt;            &apos;&lt;/span&gt;&lt;span&gt;/media&lt;/span&gt;&lt;span&gt;&apos;&lt;/span&gt;&lt;span&gt;:&lt;/span&gt;&lt;span&gt; &apos;&lt;/span&gt;&lt;span&gt;u:&lt;/span&gt;&lt;span&gt;&apos;&lt;/span&gt;&lt;span&gt;,&lt;/span&gt;&lt;/span&gt;
&lt;span&gt;&lt;span&gt;            &apos;&lt;/span&gt;&lt;span&gt;/run/media&lt;/span&gt;&lt;span&gt;&apos;&lt;/span&gt;&lt;span&gt;:&lt;/span&gt;&lt;span&gt; &apos;&lt;/span&gt;&lt;span&gt;v:&lt;/span&gt;&lt;span&gt;&apos;&lt;/span&gt;&lt;span&gt;,&lt;/span&gt;&lt;/span&gt;
&lt;span&gt;&lt;span&gt;            &apos;&lt;/span&gt;&lt;span&gt;/mnt&lt;/span&gt;&lt;span&gt;&apos;&lt;/span&gt;&lt;span&gt;:&lt;/span&gt;&lt;span&gt; &apos;&lt;/span&gt;&lt;span&gt;w:&lt;/span&gt;&lt;span&gt;&apos;&lt;/span&gt;&lt;span&gt;,&lt;/span&gt;&lt;/span&gt;
&lt;span&gt;&lt;span&gt;            os&lt;/span&gt;&lt;span&gt;.&lt;/span&gt;&lt;span&gt;path&lt;/span&gt;&lt;span&gt;.&lt;/span&gt;&lt;span&gt;expanduser&lt;/span&gt;&lt;span&gt;(&lt;/span&gt;&lt;span&gt;&apos;&lt;/span&gt;&lt;span&gt;~&lt;/span&gt;&lt;span&gt;&apos;&lt;/span&gt;&lt;span&gt;):&lt;/span&gt;&lt;span&gt; &apos;&lt;/span&gt;&lt;span&gt;x:&lt;/span&gt;&lt;span&gt;&apos;&lt;/span&gt;&lt;span&gt;,&lt;/span&gt;&lt;span&gt;  # Current user&apos;s home directory&lt;/span&gt;&lt;/span&gt;
&lt;span&gt;&lt;span&gt;        }&lt;/span&gt;&lt;/span&gt;
&lt;span&gt;&lt;/span&gt;
&lt;span&gt;&lt;span&gt;        for&lt;/span&gt;&lt;span&gt; directory &lt;/span&gt;&lt;span&gt;in&lt;/span&gt;&lt;span&gt; drive_map&lt;/span&gt;&lt;span&gt;.&lt;/span&gt;&lt;span&gt;keys&lt;/span&gt;&lt;span&gt;():&lt;/span&gt;&lt;/span&gt;
&lt;span&gt;&lt;span&gt;            if&lt;/span&gt;&lt;span&gt; os&lt;/span&gt;&lt;span&gt;.&lt;/span&gt;&lt;span&gt;access&lt;/span&gt;&lt;span&gt;(&lt;/span&gt;&lt;span&gt;directory&lt;/span&gt;&lt;span&gt;,&lt;/span&gt;&lt;span&gt; os.R_OK&lt;/span&gt;&lt;span&gt;)&lt;/span&gt;&lt;span&gt; and&lt;/span&gt;&lt;span&gt; not&lt;/span&gt;&lt;span&gt; _is_directory_empty&lt;/span&gt;&lt;span&gt;(&lt;/span&gt;&lt;span&gt;directory&lt;/span&gt;&lt;span&gt;):&lt;/span&gt;&lt;/span&gt;
&lt;span&gt;&lt;span&gt;                func&lt;/span&gt;&lt;span&gt;(&lt;/span&gt;&lt;span&gt;&apos;&lt;/span&gt;&lt;span&gt;gamedrive&lt;/span&gt;&lt;span&gt;&apos;&lt;/span&gt;&lt;span&gt;,&lt;/span&gt;&lt;span&gt; drive_map&lt;/span&gt;&lt;span&gt;[&lt;/span&gt;&lt;span&gt;directory&lt;/span&gt;&lt;span&gt;]&lt;/span&gt;&lt;span&gt;,&lt;/span&gt;&lt;span&gt; directory&lt;/span&gt;&lt;span&gt;)&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The changes above will &lt;strong&gt;not&lt;/strong&gt; persist across runner updates. Applications that rely on host directory access (e.g. if you need to browse for a file exposed over the &lt;code&gt;/run/media&lt;/code&gt; virtualised directories) will also not work correctly. I do not recommend this unless you can tolerate the trade-offs.&lt;/p&gt;
&lt;p&gt;At the end of the day, Proton provides compatibility, not a trust boundary. On Linux, I am certainly safer in some ways. But the real wake up call for me was realising that running untrusted software through a compatibility layer is ultimately still running untrusted software. If I wanted isolation, I’d reach for a VM.&lt;/p&gt;
</content:encoded></item><item><title>I&apos;m Learning Neovim</title><link>https://jonybase.com/writing/learning-neovim/</link><guid isPermaLink="true">https://jonybase.com/writing/learning-neovim/</guid><pubDate>Sun, 14 Jun 2026 07:00:00 GMT</pubDate><content:encoded>&lt;p&gt;I use VSCode as my default editor. Honestly, I’m happy using it and have no pressing need to switch. However, very recently, curiosity got the better of me. I have decided to learn and use Neovim for a few weeks. At the end of the journey, I hope to report back on my experience, and whether I want to make the switch to Neovim permanent.&lt;/p&gt;
&lt;p&gt;I’m fairly proficient in VSCode’s keyboard shortcuts. Features like the file picker and command palette (&lt;code&gt;⌘+P/Ctrl+P&lt;/code&gt; and &lt;code&gt;⌘+Shift+P/Ctrl+Shift+P&lt;/code&gt;) help tremendously with feature discovery, particularly when I don’t know the exact keybind but I know that an action exists (like split right).&lt;/p&gt;
&lt;p&gt;My history with Vim dates back to my Computer Science undergrad days. Learning Vim and showing off rapid keyboard commands was very trendy among my classmates. At the time, I learnt the bare minimum, which allowed me to SSH into the school’s cluster, edit files, and most importantly, quit Vim. When I was much younger, I had learnt programming with IDEs like Visual Studio and IntelliJ. I was very used to feature discovery being part of the UI. For text editing, Sublime Text or gedit was my preferred tool. Vim, on the other hand, seemed like a path towards getting no work done at all.&lt;/p&gt;
&lt;p&gt;Lately, as I’ve become more interested in craftsmanship, I’ve seen people promote Neovim as a way to care about the tools one uses to write code. I’ve seen several online lists of benefits that Neovim has over UI-based editors. Here are some I would like to test or experience for myself:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Cool factor
&lt;ul&gt;
&lt;li&gt;Neovim is just cooler than VSCode. I previously worked at a company where the “elite” backend devs would stereotypically have beards and use Vim. There is nothing objective about how either attribute makes you a better programmer. Since my wife won’t let me grow a beard, I’ll have to settle for using Vim.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Consistency in keyboard shortcuts
&lt;ul&gt;
&lt;li&gt;I use macOS and Linux consistently. VSCode shortcuts are not universal. The modifier is ⌘ on macOS and Ctrl on Linux. Using Neovim on both OS helps build consistency, especially since Vim motions and commands are designed to be portable and avoid OS-specific requirements.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Ability to SSH into anywhere and have a powerful editor at my fingertips.
&lt;ul&gt;
&lt;li&gt;Generally, I’ve had no issues managing my servers effectively, relying on basic vim/nano. In rare instances, I’ve wished for a better editor setup. That’s where Neovim would have come in clutch.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Faster (?)
&lt;ul&gt;
&lt;li&gt;Vim motions and commands promise to make a proficient user much faster at editing text. Is this true? Vim/Neovim enthusiasts will tell you yes but I haven’t seen any empirical data.&lt;/li&gt;
&lt;li&gt;Lots of great discussion points in &lt;a href=&quot;https://news.ycombinator.com/item?id=34364336&quot;&gt;this Hacker News thread&lt;/a&gt;, but the one that stuck with me was the differentiation between those who “think then code” vs those who “think while coding”. I fall into the latter camp. I instinctively put my initial thoughts into code, despite knowing that my plan or direction could be off. Then, I iterate. I’m sure I spend equal if not more time refactoring and rewriting existing code than writing brand new lines. Vim/Neovim is supposed to help with the speed of that iteration.&lt;/li&gt;
&lt;li&gt;Launching and taking equivalent actions in Neovim feels faster than VSCode. I would guess that a lot of this stems from the Electron and JavaScript overheads. From my own experience, VSCode is so well optimised that it is already fast enough. Would this difference have any measurable impact on one’s experience using the editor, be it productivity or enjoyment? I’m not sure, but I would certainly like to test this with my own experience.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Avoid VSCode’s marketplace (?)
&lt;ul&gt;
&lt;li&gt;There have been past &lt;a href=&quot;https://www.techradar.com/pro/security/vscode-market-struck-by-huge-influx-of-malicious-whitecobra-extensions-so-be-warned&quot;&gt;examples&lt;/a&gt; &lt;a href=&quot;https://www.techradar.com/pro/security/malicious-ai-made-extension-with-ransomware-capabilities-sneaks-on-to-microsofts-official-vs-code-marketplace&quot;&gt;of&lt;/a&gt; &lt;a href=&quot;https://blog.checkpoint.com/securing-the-cloud/malicious-vscode-extensions-with-more-than-45k-downloads-steal-pii-and-enable-backdoors/&quot;&gt;malware&lt;/a&gt; on the VSCode Marketplace. Just last month, &lt;a href=&quot;https://x.com/github/status/2056884788179726685&quot;&gt;GitHub confirmed&lt;/a&gt; that a poisoned VSCode extension gave an attacker access to ~3,800 internal repos. Neither VSCode nor Neovim offer complete sandboxing, hence Neovim’s plugin security exposure is the same as VSCode’s, albeit with a much smaller ecosystem.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;I am also pre-empting some downsides:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Initial productivity decrease is very tangible and noticeable
&lt;ul&gt;
&lt;li&gt;I’m struggling to get started on fixing my broken Game Boy emulator timer implementation.&lt;/li&gt;
&lt;li&gt;I don’t know how long this period of low productivity will last.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Losing access to VSCode’s larger extension ecosystem
&lt;ul&gt;
&lt;li&gt;The larger ecosystem of VSCode marketplace means faster and widespread support. However, the impact to me is likely not going to be major since I haven’t encountered any language or feature that I use on VSCode but isn’t on Neovim.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;I enjoy learning something new. Getting started learning Vim motions and configuring &lt;code&gt;init.lua&lt;/code&gt; from scratch was very satisfying. Yet, I’m fully aware that configuring the editor and actually using it are two very separate experiences. I hope that as I continue this experiment, I will become better at motions. I hope that editing and refactoring code will become easier. I hope that I will generally enjoy the experience of using Neovim. The crucial tell at the end is whether I reach for VSCode or Neovim when I have to write code.&lt;/p&gt;
</content:encoded></item><item><title>Is How We Use AI Destroying Our Craft?</title><link>https://jonybase.com/writing/ai-destroying-craft/</link><guid isPermaLink="true">https://jonybase.com/writing/ai-destroying-craft/</guid><pubDate>Tue, 09 Jun 2026 14:00:00 GMT</pubDate><content:encoded>&lt;blockquote&gt;
&lt;p&gt;My opinion has always been that AI is a great tool, but it’s a tool.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;At the Open Source Summit North America 2026 in Minneapolis, Linus Torvalds said (&lt;a href=&quot;https://youtu.be/fi29pfLcW4I?t=1556&quot;&gt;25:57&lt;/a&gt;) the above. He noticed how people proudly declare that their code was 99% written by AI, but those same people would have never said that their code was 100% written by compilers.&lt;/p&gt;
&lt;p&gt;I love the tongue-in-cheek comparison that I had never thought of. But should we even consider AI to be a tool? In his series “Wading Through AI”, Casey Muratori contends (&lt;a href=&quot;https://youtu.be/4fxo6zuhP1c?t=100&quot;&gt;1:40&lt;/a&gt;) that AI shouldn’t be considered a tool because it is inherently non-deterministic. Historically, tools have been controllable devices that responded well to skill. A blacksmith’s hammer. A painter’s brush. A surgeon’s scalpel. A programmer’s keyboard. The predictable nature of tools, and the fact that you can receive clear and usually instant feedback, allowed people to master them. In fact, unpredictable tools are a major risk to the wielder. A chainsaw that cannot be used in a controlled way is capable of great destruction.&lt;/p&gt;
&lt;p&gt;Yet, that isn’t the right question. AI is undoubtedly a tool. Consider this Merriam-Webster definition of &lt;code&gt;tool&lt;/code&gt;:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;something (such as an instrument or apparatus) used in performing an operation or necessary in the practice of a vocation or profession&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Purely based on the definition, AI solutions are “tools”. People use them for information retrieval, summarisation, analysis, image generation, and role-playing. Arguably the biggest impact LLMs have had is in the arena of programming, where “agentic coders” are now writing significantly &lt;a href=&quot;https://www.anthropic.com/institute/recursive-self-improvement&quot;&gt;more&lt;/a&gt; &lt;a href=&quot;https://fortune.com/2026/01/29/100-percent-of-code-at-anthropic-and-openai-is-now-ai-written-boris-cherny-roon/&quot;&gt;code&lt;/a&gt; than before.&lt;/p&gt;
&lt;p&gt;Instead, I posit that the right question is this: does the way we use our tools destroy our craft?&lt;/p&gt;
&lt;p&gt;Craftsmanship is important. I believe that we should approach our skills, whether for our profession or for leisure, with the intent to practice a craft for enjoyment and fulfilment. We exert control over our tools to accomplish a task, and often in that process receive feedback about our skills. We learn and improve. When I started learning to type, the keyboard gave me consistent feedback about how slow or wrong I was. With practice over many years, I’ve grown to be proud of how quickly I can type. Using a tool more typically builds competency, which instils a sense of pride and accomplishment in the individual.&lt;/p&gt;
&lt;p&gt;However, I don’t feel that same degree of pride and accomplishment when I use agentic coding tools. Much has been said about AI coding. On one hand, language models today are incredibly capable. I have personally been astounded by how good OpenAI’s Codex is at creating desktop and web apps, some of which I use on a daily basis. On the other hand, many people online have bemoaned the issues of shifting coding to agents, including the loss of control, loss of understanding, and inconsistent quality across language models and harnesses. The issue that bothers me the most is the &lt;a href=&quot;https://www.anthropic.com/research/AI-assistance-coding-skills&quot;&gt;cognitive offloading&lt;/a&gt; that happens when a programmer substitutes their slow and often frustrating process of coding by hand with AI in the name of efficiency gains.&lt;/p&gt;
&lt;p&gt;Going back to Linus’ quote above, I get his point. But I worry about how Linus is open ended about the way people use AI as a tool. Using AI to write code for you has virtually no corresponding skill increase in the individual, compared to another who hand-writes, debugs, corrects, and improves their own code. Additionally, I can see how both compilers and AI form an abstraction above machine code. However, compilers are (mostly) deterministic. Given the same set of inputs (code), build environment, compiler version, compiler flags, and other config, a compiler should produce the same output. That predictability enables debugging and reproducible builds.&lt;/p&gt;
&lt;p&gt;Can the same be said about AI? I’ve recently warmed to the idea of calling AI a slot machine. Pull the lever, and wait for the spinning ASCII progress circle to complete. Fail, and you try again, without reasoning through the obstacle encountered. For common languages and frameworks, the probability of getting good, workable, maintainable code with AI is very high. If your encounters with AI are limited to those scenarios, you’re consistently hitting “jackpot” with each AI lever pull. But AI does much worse for languages, frameworks, or domains outside the popular. Recently, I’ve been learning Zig. I’d say about 50% of the time, I can’t get GPT 5.5 to generate idiomatic working Zig code. Initially, I couldn’t tell that the code was wrong. In fact, I only realised how wrong the generated code was after the compiler gave me the predictable, instant feedback of dozens of error messages. After hours of reading through the Zig docs, reading online discussions, and crucially, working through Zig programming exercises by hand, I finally started to build a sense of how to write better Zig code.&lt;/p&gt;
&lt;p&gt;Here’s what I’ve decided. For scenarios where I don’t care about the element of craftsmanship, I personally do use AI as a “tool” to aid me in accomplishing a task. Some examples include summarising product reviews on the internet, quickly generating throwaway web apps and utilities, and summarising transcripts of videos that I do not intend to watch closely.&lt;/p&gt;
&lt;p&gt;But in two areas, I will not use AI as a tool for output generation: programming and writing. As I write more code, I want to improve as a programmer. As I write and publish more posts, I want to improve as a writer. I acknowledge that my code and writing both will start out terrible. However, using AI to short circuit the process and achieve unearned output quality will only hurt me in achieving my desired improvement.&lt;/p&gt;
&lt;p&gt;Slow down and think about your use of AI. Are you overemphasising the output and inadvertently discounting how your skills are affected? I’m not against the use of AI. And I have no doubt that AI is capable of producing fantastic output. Rather, the question I need to ask is whether I still want to become the kind of person who could have produced it.&lt;/p&gt;
</content:encoded></item><item><title>Editorial House Rules v1.0</title><link>https://jonybase.com/writing/editorial-house-rules-1.0/</link><guid isPermaLink="true">https://jonybase.com/writing/editorial-house-rules-1.0/</guid><pubDate>Mon, 08 Jun 2026 14:50:00 GMT</pubDate><content:encoded>&lt;p&gt;To kick off my actual writing, I want to talk about some boundaries.&lt;/p&gt;
&lt;p&gt;I have a day job. As is typical for most organisations, there are clear rules about what I, as an employee, am allowed to say publicly. To ensure a clean separation between what is work and what is personal, I want to state clearly what I will write or will not write about.&lt;/p&gt;
&lt;p&gt;All my writing is done entirely in my personal capacity. My writing does not represent the views of my employer. I may write about my personal observations, books, movies, music, technology, programming, and AI. These are topics that interest me. If any are work-adjacent, they will be entirely based on public sources and personal interest.&lt;/p&gt;
&lt;p&gt;There are also topics I will not write about.&lt;/p&gt;
&lt;p&gt;For instance, I will not post about my work, or official, non-public, or work-derived information. I am also intentionally going to avoid topics that touch on sensitive public issues, which include matters about social cohesion, national security, or politics. I may state my views and preferences in my posts, but they should not be treated as official information, insider content, or professional or role-related advice. Essentially, if anything is connected to work, I will leave it out.&lt;/p&gt;
&lt;p&gt;I believe that for the most part, constraints are good, and spelling them out clearly here can help me write safely and sustainably. I can still write about plenty of other topics. I hope that my writing here will become my personal space for my interests, not a window into my work.&lt;/p&gt;
</content:encoded></item><item><title>Hello, world!</title><link>https://jonybase.com/writing/hello-world/</link><guid isPermaLink="true">https://jonybase.com/writing/hello-world/</guid><pubDate>Fri, 05 Jun 2026 07:00:00 GMT</pubDate><content:encoded>&lt;p&gt;It is always appropriate for the first post to be the customary greeting of programming.&lt;/p&gt;
&lt;p&gt;Hello, world!&lt;/p&gt;
</content:encoded></item></channel></rss>