Lese-Ansicht

H2C4TW

H2C4TW

About 10 months ago I splurged and ordered the Bambulab H2C 3D printer, and for 9 months it's steadily chugging along here. It's not printing non-stop, but it feels pretty close to that sometimes.

I've printed mostly PLA, but also TPU, ASA, PETG, PVA and Bambu's "Support for PLA/PETG"

And apart from one issue where a sensor was misbehaving and needed replacement, the machine is just ..

.. working. It is not foolproof, nor has every print been a success, but the vast majority of them. The machine spat out miniatures, terrain pieces, cosplay stuff, plastic toys for my nieces and nephews, functional and decorative prints for the household, cat toys, foam dart blasters, props for games, and so on.

But why did I upgrade from the X1C that I had until then?

  1. FOMO. yeah, sometimes that gets me too.
  2. The tool change functionality. Since I have that, I actually do multicolour prints, because they are a lot faster this way, but mostly because there is so much less plastic waste this way.
  3. The bigger build plate. It's "just" about 8cm more for each side, but those do make a notable difference in what I can print, or how many parts I can put into one print job.

I do acknowledge that Bambu is not a particularly FLOSS-friendly company, and that its products are decidedly less open than a home-built Voron printer. But...

...they do simply work. Again, they are not foolproof, this is after all a machine with high-speed moving parts that heat up to 300° and move molten plastic around based on user-generated software instructions. Of course something is bound to go wrong occasionally.

And despite all of this, most of the time whenever something goes wrong, the machine fails gracefully. It stops before things get worse, it asks the operator to check, it spits out messages that include a link to a friendly wiki with further information.

This has gotten to the point where the machine is extra busy now, because the girlfriend has spent one afternoon learning the basics from me and is now competing with me for machine time.

So, I am not saying that this is the perfect 3D printer. But it is gosh darn good and near perfect for how I use this. I can see the upside of a toolchanger that doesn't need to retract and reinsert filament all the time. But I do think that the advantage of being able to ad hoc combine different nozzle sizes with different filaments just in software outweighs that completely.

  •  

Ein gescheiterter Heist

Ein gescheiterter Heist

Ich habe eine tiefe Liebe zu dem Leverage RPG. Zum einen weil sich das "Heist" Genre schon seit "Der Clou" einen Platz in meinem Herzen ergaunert hat.

Zum anderen weil das Regelsystem der gleichnamigen TV-Serie auf den Leib geschrieben wurde, und dabei eben nicht nur auf Standbilder und Namen zugegriffen hat, sondern vor allem die Tropes verstanden hat. Die Regeln bauen also auf genau diesen Klischees und Versatzstücken auf und sorgen dafür, dass man sie gewinnbringend einbaut.

Das Würfelsystem ist eher grobschlächtig und führt Rolle (z.B. Dieb oder Hackerin), Attribut (z.B. Intelligenz oder Gewandheit) und dann eben auch noch Eigenschaften (z.B. "trockener Alkoholiker", "liebt Lüftungsschächte") zusammen und hat zusätzlich einen "Einsatz erhöhen"-Mechanismus.

Dazu kommen Mechaniken für Rückblenden, auf die Archetypen zugeschnittene Sonderfertigkeiten und die ständige Regieanweisung von "lass alle cool aussehen".

Mit diesem System habe ich so einige sehr, sehr geile Spielrunden geleitet, und hoffte letzten Mittwoch auf ebenso eine.

Dabei waren fünf Leute, von denen nur eine Person das System schonmal bespielt hatte. Ich teilte die Session in zwei Teile: Einen kurzen Einführungsjob um Charaktere zu erstellen und die Regeln kennenzulernen, und dann das Main Event nach der Essenspause.

Der Einführungsjob lief phä-no-me-nal. Alle hatten Spotlight, Rückblenden und Fähigkeiten wurden gut verstanden, und die Gruppe legte sich auf Schmalspurganovenniveau mit den Elektro-Tretrollerfahrenden Harburg Hools an, die gerade Nachbarin Elfriede mit dem Enkeltrick um die Ersparnisse gebracht hat.

So beflügelt ging es dann an den Hauptjob: Der vom freundlichen Punker Jörg betriebene Abenteuerspielplatz wurde von einem Immobilienhai bedroht.

Und ab da ging es dann abwärts. Das Mastermind versuchte den Plot über das Vereinsrecht zu lösen, der Schläger bekam nix zu tun, der Grifter bekam keine Ziele, die Diebin und der Hacker hatten kleine Aufgaben, aber agierten auch eher wahllos.

Im Nachhinein war uns allen klar, dass die Person hinter dem Mastermind zwar Spiel und Genre kannte, super eloquent und dominant war, aber nicht über den Tellerrand der jeweiligen Szene schauen konnte und sich daher komplett und dauernd verrannte.

Zwischendurch winkte ich mit diversen Zaunpfählen, aber immer wenn ich die Leute so halbwegs in die richtige Richtung geschubst hatte, übernahm das Mastermind wieder: "Und dann schenke ich ihm Chruschtchows Schuh!"

Geile Idee, großartiges Bild, aber was das jetzt beim Bösewicht auslösen sollte, wusste das Mastermind dann nicht mehr so richtig zu sagen.

Dass ich auch nicht einfach Schienen verlegen wollte hat natürlich auch nicht geholfen. Natürlich muss man als Fixer bei Leverage immer wieder mal hart Szenen schneiden, aber zumindest der grobe Plan sollte schon von der Gruppe kommen...

Wir haben dann mit Hängen und Würgen den Plot irgendwie zuende bekommen, aber nicht ohne den Schläger verloren zu haben - die Person war sich permanent unsicher, ob sie nicht irgendwas falsch mache, ob sie vielleicht lauter sein solle, oder ob das nicht vielleicht doch das falsche Spiel für sie sei.

Meine Lektionen für die Zukunft:

  1. Die Mastermind Rolle nicht einfach nach Gutdünken vergeben, sondern die Person ein wenig auf "Du bist für den Plan zuständig, und der soll die anderen beinhalten" einschwören
  2. Klarere Ansagen machen, wenn ein Ansatz nicht zum Genre oder System passt. Und das dann auch so formulieren. Ich hatte versucht, zu erklären, warum der Vereinsrecht-Vorstoß juristisch nicht klappen kann, anstelle zu sagen "nee, das passt nicht zum Genre, denk Dir was passenderes aus - wie wäre es mit..."

Abgesehen davon hoffe ich, dass bei den Leuten die erste Hälfte deutlich mehr in Erinnerung bleibt, denn die Sache mit der Magic-Karte, dem Pfandleiher und den Elektrotretrollern war einfach super!

  •  

How to handle a responsible disclosure you get from me?

How to handle a responsible disclosure you get from me?

(this is mostly cribbed and then adjusted to me and my style from https://blog.literarily-starved.com/2025/06/how-to-handle-a-responsible-disclosure-you-get-from-me/. Thank you Martin for giving me the go-ahead!)

Let’s assume you run an IT service or deliver some kind of device to customers, and you receive a report from me informing you about a security problem in your service or device. This can —and has—happened to some of the best in the industry. So, you’re not alone.

Now you’re wondering: What should you do with this disclosure?

Huzzah: This post is here to guide you through the process.

Let’s start with what’s bad about me reporting such a thing:

  1. Most importantly: There is a very high probability that you (or a close supplier) have a somewhat serious problem. I don't nitpick and I only act when I see something I deem serious in some way or another.
  2. I will have no hope, but also hold you to high standards. I’m investing my spare time because I believe the issue is serious enough to warrant it. I might stop interacting with you, but I will ring bells to get someone's attention — starting small, but escalating quickly if needed.
  3. It is very likely that relevant authorities will be informed in parallel. I believe authorities can only act if they are aware of problems. So, I inform them — even if they don’t act in most cases.

Let’s continue with what’s good about me reporting such a thing:

  1. Fixing the issue will most likely save you money and prevent far bigger trouble in the future.
  2. I don’t want any money. My motivation is civic responsibility, not income. So you don’t need to open your wallet.
  3. I didn’t “hack” your system. I won’t attempt to hack anything, I'm not even that technical anymore. Your problem is most likely an obvious and embarrassing one — which is good, because that usually means it’s easy to fix.
  4. I don’t want to hurt you. My goal is to fix the problem, not to damage your reputation. This might happen anyway if you don’t fix the problem on your side.

What you shouldn’t do?

Some actions will only cause you more pain in the long run:

  1. Ignore me: As mentioned above, I will use increasingly large and loud bells to get attention. This will draw more eyes to your problem, and probably not in a good way.
  2. Threaten me: Attempting to silence me with threats (typically from your lawyers) won’t improve my mood nor resolve anythig. It’s very unlikely I’ll feel seriously intimidated, mostly because I firmly know and can prove that it wasn't me who did something wrong.
  3. Ask me to sign an NDA: I report what I report. I won’t sign an NDA. There’s no upside for me — it only restricts my ability to push for a fix.
  4. Refer me to a bug bounty platform: These often require signing NDAs (see above), and I have no interest in joining yet another platform. I don't want your money. Bug bounty programs don’t help my mission — unless they work via something as simple as sending an email to a listed address.

What can you do beforehand?

There’s one thing you can do in advance that will make such events much less painful:

➡️ Publish a security.txt file compliant with RFC 9116 at all your services.

Having this file means:

  • I assume (initially) that you take security seriously.
  • I’ll use the contact you specified to alert you.

You save everyone time and effort — which I appreciate.

The other thing you can do is to prepare procedures to work with such disclosures. Make sure that any possible input channel of your organization knows how to proceed if such a disclosure arrives. It won’t do any good if you have a security.txt but the message gets ignored because one person is on vacation.

So how should you reply?

I recommend that your reply addresses the following points:

  1. Confirm receipt and establish a channel or contact for further communication.
  2. Reflect your view of the analysis: severity, impact, scope.
  3. Describe the next steps and a timeline.

Example of a near-perfect reply

Such a message would make me very happy:

Thank you for your disclosure. We have opened ticket #123456 to track this issue. You can contact us at incident@example.org for status updates or to provide new information.

We believe this vulnerability affects all customers using service X, especially group Y. We have identified the core problems as Z1 and Z2. We currently rate the severity as (your rating).

To address this, we need to resolve Z1 and Z2 by (your measures). This will take some time, and we can’t give a fixed timeline yet. However, we intend to implement a mitigation in service X within (number of days).

Unless you set an unreasonable timeline, I’ll leave you alone for that period.

My experience with such disclosures

Unless you’ve planned ahead, you very likely will fail to meet my expectations.

Footnotes

  • My disclosure may trigger other legal implications for you. You may need to inform customers, shareholders or other relevant groups. That is your task. I epxect you to know and follow your obligations.
  • You canot prevent me from writing a publicly available after action report. But you have great influence on how professional you look in it.
  • I deeply dislike organisations that fix the problem, but do not communicate (neither to me or the public).
  • My disclosures should be very easy to distinguish from the AI slob you get on other channels. I’ll try to make identifying the problem and severity as easy as possible.
  •  

Raiders of Arismyth - another year later...

Raiders of Arismyth - another year later...

Last year in August, I declared the rules of my new own RPG to be done.

Hah.

Turns out, I still had a few ideas and thoughts in me:

  • I tinkered with how Armour and Shields work
  • The whole system moved from "here's a skill list with lots of written dependencies" to having all the skills and spells arranged in hexmaps. If things are adjacent to each other on those hexmaps, you can learn them, done.
  • Incidentially, that makes for nicer looking character sheets too, as I found out even with my mediocre layouting skills
  • and as a result, I regrouped and removed a bunch of skills. Partially because I realised that there was an overlap, partially because I noticed that for some, I never asked for dice rolls anyway. It feels unfair to ask people to spend advancements for things they never use.

As there was a NordCon between the last blogpost and this one, where I met up with lovely people and talked at length at them about the game, I pressed two people with more design chops into service: Wiebke and Julie.

Julie is busy with creating illustrations for explaining rules and adding interesting views of the various bestiary entries.

And Wiebke has created very lovely character sheets for the game, that fully embrace the "medieval utilitarian" look I hope to go for, and also make the hexmaps pretty. Head over to the game page to check them out!

I am tempted to say now that I'm finished, but I'm probably not kidding anyone. There's at least a few more monsters to write about, I might also add to or revise the starting equipment table, and once I find a good and proper editor, I expect a lot of the text to undergo some changes too.

Nonetheless, the moments where playtesters ask me to change things after a session are definitely gone, so I do think that the bones of the game are there and set now.

And those bones... those bones are beautiful. At least to me.

  •  

Kinopolis? Lieber nicht mehr

Kinopolis? Lieber nicht mehr

Wir waren kürzlich im Kino, und weil das Savoy (unser Stammkino) schon recht ausgebucht war, versuchten wir mal das Kinopolis in der HafenCity. Die Buchungswebseite versprach zwar nicht wörtlich, aber schon vom Eindruck und den Schlagwörtern her (Bar, Relax-Sessel, etc.) ein Erlebnis wie das Odeon in London.

Wer das nicht kennt: Das Odeon ist ein, ahem, Luxus-Kino. Man sitzt in Sesseln, die sich quasi komplett in Liegen umwandeln lassen, angeordnet in Zweiergrüppchen mit viel Platz zur nächsten Gruppe, Tabletthaltern damit man die Snacks nicht auf dem Schoß balancieren muss. Vorne gibt es eine richtige Bar, eine Garderobe, und so weiter.

Das Kinopolis ist das... nicht so.

Die Relax-Sessel sind tatsächlich einfach nur die erste Reihe, die aus der Puren Not [tm] heraus als Liegen ausgeführt ist, damit man keinen steifen Hals bekommt. Konsequenterweise lassen sie sich auch nicht verstellen, sondern sind eben einfach nur Liegen.

Die Sicht auf die Leinwand ist dennoch eher bescheiden, man sitzt einfach zu nah dran, und alles ist irgendwie verzerrt. Dafür dann auch noch den "Relax-Sessel-Aufpreis" zu verlangen ist schon unverschämt.

Ton- und Bildqualität waren ansonsten 1a, da kann man nicht meckern.

Und der Rest vom Kino"erlebnis"?

Naja. Das geht damit los, dass das Kinopolis in der Westfield Mall der HafenCity ist. Das ist eines der seelenlosesten Konsumgebiete der Stadt, wenn Ihr mich fragt. Am Wochenende natürlich voll von Pinnebergern[^1] und Touristen.

Die Läden sind die bekannten Ketten, und man muss sich erst durch den Food Court quälen, bevor man am Kino selbst ist.

Das ist dann auch weniger "premium" und mehr "wir maximieren den Durchfluss mit minimalen Personaleinsatz": Bildschirmkioske überall, und die Snackbar hat quasi nur Popcorn und Nachos, weil das eben einfach en gros portionier- und verkaufbar ist.

Mittendrin wollte dann noch wer aufs Klo und hat den Notausgang statt den richtigen Ausgang genommen. (Dies Schilder sind an beiden die gleichen) Und damit den Türalarm ausgelöst, der dann so 5-10m vor sich hin piepte, bis mal wer vom Personal vorbeischaute..

Und jetzt der Kicker: Ich hab die Karten online gekauft. Und bei solchen Abschlüssen gebe ich NIE die Erlaubnis für Newsletter oder ähnliches. Ein Kundenkonto hab ich auch nicht angelegt.

Dennoch kam zwei Tage nach dem Kinobesuch erst mal eine "hey, kannst Du uns bewerten?" Email und heuer dann auch nochmal der allgemeine Filmempfehlungs-Newsletter.

Bei Betätigung des "Abbestellen"-Knopfs wird dann auch gezielt darauf hingewiesen, dass man damit genau nur diese Kategorie von Newsletter abbestellen würde. Welche es sonst noch gibt, und ob man die bekommen würde verrät das Tool einem nicht. Das Dark Pattern hier ist, dass die Firmen hier gefühlt drölfzig verschiedene obskure Kategorien haben, und auch gerne mal neue hinzuerfinden. Denkt an so Späße wie "Action-Filmempfehlungen" vs "Filmempfehlungen voller Dynamik".

Das formale DSGVO-Schreiben zwecks Datenauskunft und -löschung ist raus. Die sehen mich nie wieder.

[^1]: Die von eingeborenen Hamburgern abfällige Bezeichnung für das Landvolk aus dem Speckgürtel. Sorry Pinneberg! :)

  •  

Once more onto the breach!

Once more onto the breach!

I did like WriteFreely in general, but there were a few drawbacks:

  • Very limited layout
  • no comment functionality at all
  • not really a good support for displaying tags
  • and a some minor quibbles

Over the weekend, I finally got Ghost to work properly, and the Discourse integration to boot. There were a few things to sort out though:

  • contrary to instructions found at ghost.org/integrations/discour, Discourse does not provide a snippet of code. Well, I'll just copy that from the page there, eventually, it worked.
  • the trailing / in the URL for the discourseUrl super important and mandatory. That should be spelled out.
  • if you don't tell Discourse to really server everything over https, you'll get mixed-content-security errors instead of an integration
  • and of course, I had to add aliases for noreply etc. to my account at the mailserver, so it won't reject things.

So, in the end, this now works, and I can update the stacks through Portainer too. I had to throw away the Discourse install away though and recreate it because the Marius Hosting howto locks the version at 3.5.o instead of "latest", and I didn't realise that until it was too late.

Mostly, I am happy that there is a comment functionality again, and maybe I'll use the forum for some other things too in the future. I do guess that Raiders of Arismyth could use one - need to look at the Wiki functionality of Discourse.

  •  
❌