SCaLE

Room 105 Sunday Mar. 08 - SCaLE 23x

3:42:40 · 05 Mar 2026 – 08 Mar 2026 · YouTube

About this talk

In this talk, Kevin Perty discusses strategies for navigating network firewalls without compromising security, focusing on methods that enable seamless access to computing resources while maintaining strong security practices. He shares his experiences and technical expertise working with home labs and tools like Tailscale to create secure connectivity. The speaker elaborates on concepts such as STUN (Session Traversal Utilities for NAT) and ICE (Interactive Connectivity Establishment), which are essential for traversing NAT (Network Address Translation) and establishing peer-to-peer connections. Perty highlights the importance of understanding firewall configurations and the techniques to determine accessible ports, all while emphasizing the challenges posed by the increasing complexity of internet connectivity. The session concludes with a look at innovative solutions that can enhance personal network setups for everyday users.

Full transcript

microphone. microphone. Hello everybody. While we're waiting for the proctor to show up and make >> You're the proctor. Hi. >> The screen uh looks like this. >> Okay, that's I I plugged in my USBC thing. It seems to be a version of it. You know, a box of it is showing up. And then I have my mic working as you can see. >> So I just need

the slides to be big on this screen. >> That's correct. >> Okay. While we're calling the AV people, let's say you're from Washington DC and your flight is tonight at 9:30 p.m. You're in Pasadena, California. Your talk ends at 12:30 p.m. So, you have to get to LAX for a 9:30 flight. What do you do in Pasadena or between here in LAX with math is hard? Seven

hours. I'm a real neurotic airport person. So, like I'm a two hours, hour and 30 minute guy. What? Raise your hand if you have a do something in Pasadena this Sunday afternoon idea. Anybody? >> Anybody? Yes. >> Okay. Shopping on Colorado and movie theaters. See, I'm already following the instructions to repeat questions that I'm asked. Okay, good. Off to a good start. >> What What about the

Huntington? >> Do the Huntington. The whole thing. It's like botanical gardens and also kind of a museum and there's peacocks. Okay. >> Okay. Two hours, three hour like what what should I budget? >> Yeah. Yeah. Like Okay. >> Oh, yeah. I'm I'm a sicko and I was going to do the A-line to the Union Station and then do the flyaway bus that takes you from Union to

LAX. Okay. Got getting a lot of the most positive response to that out of anything I've said. So, okay. Everybody's like don't don't get in a car, which does like I don't want to be like an East Coast stereotype, but that's what I thought too. Don't I understand the the intricacies of California car culture, but like I also just don't want to be in a vehicle with

anybody for 90 minutes. Like >> like my wife and I get angry at each other after 90 minutes in a car together. So all rightology. >> Okay. Is that also a great idea? >> I was supposed to get tickets ahead of time also. And I don't think I >> this is my understanding like the museum that refuses to explain itself to you. >> Okay. I like that

the guy in the AEX twin t-shirt was like go to the Museum of Jurassic Technology. Absolutely. Endorsement. >> Can I Can I boost the treble on this? They're They're like diagnosing one I could also hold it closer to my face. >> I'm gonna be gated. I will move it in. Hello, my name is Kevin Perie. Social Security number one. Okay, this is just me speaking or more

bassy. Oh, boost. Put me in TV mode. >> Yeah, do do some enhanced dialogue. Okay. We got slides on the thing. I am speaking. People are liking the travel. Are we all good for tech stuff? Gotta take that as a yes. Okay. I always wanted to say this, but we'll give folks just like one more minute. I think our entire I think everyone who lived through 2020

is whenever they hear the phrase we'll give folks just one more minute. It's going to have like a tra traumatic effect on them at some point. Like just an endless series of video calls where we're giving folks one more minute. Like I think about that all the time. Okay. Hello everybody. Thanks for attending this talk. Um, I, you know, I hope you've all had a good time

this weekend and it's time to talk about punching through firewalls without punching holes. Um, as I said to some folks who got here early, I didn't name this talk. I'm I'm the fill-in for another speaker here. I would not have created a slide talk that has a metaphysical question in the in the title. But, um, here we go. Like I we're going to talk a little bit

about getting from one computer to another for fun reasons. Um, I am not Alex Crutchar. So that I just want to get that out of the way in case some of you are looking at me. You're like, "Oh, he doesn't sound as British." Like maybe he just got, you know, doesn't have as much beard. I am not that man. Yes. Can I put the what? Oh, no.

That's true. This would be quite a pen test. Um, no. I'm I'm not Alex Crutchar. Um, I am Kevin Perty. Um, this is my dog Howard. Um, so I I'm glad to hear to talk about natural uh and other such things as home labs and you know things like that. Uh, so I am I have been writing on the internet for a very long time. I used

to work for Lifehacker back in the pre-childhood wrestling star ruining my business days. Um, yep. Uh, I wrote 5,883 posts for Lifehacker back then, which was uh something I did. And um I also have worked for Wire Cutter. I've um I've reviewed lots of stuff. Feel free to grab me after the talk and we can talk about cutting boards or recycled toilet paper or toilet brushes or

ebikes or antivirus software or other stuff I just had to research and and write about for them. Um I've also written for fast company. Um I had a few pieces in wired and more before tail scale uh which I work at because of the t-shirt. Um, I worked for RS Technica. Also, when people look at me with a blank look, I'm like Wired's nerdy cousin. Like Wyard's

cousin who went all the way through grad school. Um, so I I wrote for them for about three years and uh maybe my favorite beat there was the Linux kernel mailing list where I would read just 9,000 words that were about something and I would try to translate it to a general audience like what's going on inside the LKML. And sometimes it would be great like sometimes

be like like there's a lot of stuff about Rust. I know a lot about Rust now without wanting to or actually intending to because of how much went on there. So, you know, as you can see, I've just been a professional kind of dilotant for a long time. Um, and then I arrived at Tailscale and they hired me to write some stuff for them. And so, that's

what I've been doing for Tailscale. I've been trying to cords. Um, I write about things that I think will get people interested in checking it out. This is the nature of marketing. But also, um, they seem to have forgotten they hired me sometimes and they don't really tell me what to do. So, I'm like, well, did you see that you can put tail scale on a jailbroken

Kindle? Uh, did you know that you can like obiate the need for a Rustes server if you just use tail scale to connect the two ends of the Rustes? Um, did you know that you don't have to ever remember your SSH keys anymore if you use tail scale for that? Um, things like this. This talk is not about tail scale, but I just want to let you

know what I've been up to. um how to create an exit node for you know helping your parents for being able to you know get around international kind of like you know bad government restrictions or in my case watching Buffalo Bills games from Washington DC by putting one in your house and uh I also am maybe the biggest proponent of Chromebooks at my company. Um they're I

always feel they get a bad rap. They are the most popular Linux laptop and we should all respect All right. Um, but what I what I started at Tailscale, I didn't have a home lab and now I have a Sony's my first home lab. Um, this is Alex's home lab on the left. Um, he sent me this picture and between the projector and me not actually knowing

what these things are. Um, I'll maybe I can provide a better version of it somewhere. But, um, as you can see, it's just a corner of a basement. Or in my case, it is the shelves behind me. I should stay in one place while I'm talking for the video. Um, that is a UG green nause with like three M2 drives loaded into it to create like a

RAID kind of thing. This is pre- AI memory prices. Just so you all know, I'm not that I'm not that well paid. Um, this is a Synology BS station backup. Basically, it's just taking backups from the NAS and throwing the most important stuff into S3 storage somewhere or like deep storage. Um, that is a nook from like a dentist office or something that is running Home Assistant.

Home Assistant is my favorite self-hosted thing. I give it its own bare metal because it deserves it. And then, uh, over in the corner there is a 02W whose whole job is to make the Brother Wireless printer accessible. It's all it does. It's It has It has the worst existence out of anything in my life. I I like all you do is wait for my wife to

send you a 30-page PDF. That's your whole job. You can sleep as much as you want. you have to print things. Um, anything can be a home lab though, you know, like it like pretty much anything you can still afford or find or scavenge, especially these days, can be a home lab, a Raspberry Pi, uh, a Mac Mini that you're repurposing, uh, like I said, you know,

a little HP or Lenovo, whatever, that you find on eBay for 150 bucks, or a laptop without a screen. Over on the left is a laptop framework, the original version, like the V1 or whatever. and um I just didn't need that laptop anymore. Um and so I basically took it and put it inside this cool shell from Cooler Master. Uh Framework is here and I don't work

for them or anything, but like more laptops should be able to be turned into home servers. That's my stated opinion. Um so once you have your little device and you can put stuff on it, you can do all kinds of self-hosting. Um I started at Tailscale with zero containers June 2nd. Uh March 4th, 33 containers. people like it's it's really addictive and like once you kind of

it just grows in your brain like the idea that you can do things. I'm just going to do a quick rundown starting clockwise from the upper left. Uh who here has heard of Dumbware? Yeah, Dumbware is they literally just make like single purpose uh apps like uh dumb assets which is like here's the manual for your fridge. Here's when you here's a reminder to change the water

filter in your fridge. here is like the model number of your fridge and like just real dad stuff. Dad non-gendered. I'm just saying like as a like genderneutral dad brain stuff where you're like what is the name of the lawn mower? What kind of what kind of oil does it take? Love it. Uh on the upper right is rally with three L's. That is a what time

are we meeting for movie night app or what time could everyone come for our birthday celebration thing. Um, I think like it's like some amount of money for up to five users and each user can create an infinite amount of like these things. And I just like giving money to open source developers for their cool projects. Uh, bottom right is Sterling PDF. It's just a PDF toolkit

without having to uh upload PDFs to random sites on the internet because you're running out of time. Um, or use other PDF tools. Uh, on the bottom left, this is the one that everyone knows according to my time at scale. Image. Um, image replaces essentially Google Photos. It allows you to securely back up your photos to a server. Uh you can do AI scans on it so

it can find dog, bread, etc. Whatever you want to do or even people you can tag and say here's all my photos of of my friend Raj. Um on the middle left is fresh RSS. I as noted I worked for Lifehacker in 2008ish. So of course like I Google Reader being canceled was the biggest crime any company's ever committed in my time. No, I'm not standing by

that statement. Uh, Google reader being killed was one of the worst things that I saw happen on the internet and so I have my own RSS reader that I'm self-hosting. I love it. And uh, yeah, we're back to Dumbware. Okay. Um, I thought this talk was about firewalls and parts. Me, too. So, I'm here in um, beautiful Pasadena, California. I want to access my dumb assets. I

want to access my PDF tool. How do I get back to it? What's the best way to get back to it? It's on it's in my house and I have to go through all these hops to get there. Um so apologies to those of you who know a little bit about this but before we can get to how do we get to computer we must ask ourselves

what is computer computer do thing computer have app computer be in room you're in the room that's great like this is a great system right here this is one of the most secure systems we've ever had computer do thing in room with you now there's a few computer uh now we have to now we can connect them uh I can send files to other computer. Computer can

send a few files to me. We're all on the same university campus or DARPA research lab. This is fine. There's no reason anyone would do something other than April Fools to do something to my computer on this network. Cool. Uhoh. Now there are many computer and some of them are in different rooms and different states. this is problem but there's not so many computer that is pro.

We can still give them addresses and connect to each other. seems okay so far. Uh oh. Now there's lots of computer in lots of states. Uh maybe different internet providers. Maybe it's not just a wire put out by the DoD anymore. Maybe there's actually lots of them. Okay. Well, we've got 4.2 billion addresses. So that's good. We we should be able to give each one of these

computers 100 something. That should be good. 4.2 billion computer. Oops, skipped one. Okay. Um, some of these computers should not be talking to Azure. It turned out uh there's a young man from Massachusetts who proved to all of us that we should not have computer open. We need to make sure that the right computers are talking to the right computers. We're going to start putting up firewalls.

Um, we don't really have a term for what we need exactly, but when a fire starts in a building and we want to make sure it spreads from one room to the other, we put in a firewall. So, that's what we're doing. Uh, you can't talk to this computer unless this computer has talked to you essentially like or there's rules. We're just going to create a bunch

of rules. That's enough computer. Should be good. Oh no. Oh god. Everyone got computer. There are lots and lots of computers. There might even be more than 4.2 billion computers now. I don't know how this happened. I thought people like being outside, but now we have more than 4.2 billion computer. What are we going to do? I can't just guess the address for that computer in England

I want to get to. I need Oh. Oh, yeah. Okay. Lots of computers in one space. I need to get that computer. Maybe those computers don't even have room for each of them to have an address. So, they're going to have uh that this little blue part at the front. Maybe that can just be the address and they have like a sub address so I can get

to them some way. Okay. Right. Good. IPv4. We've run out of addresses. But the good news is is that we can figure out a way to say, "Okay, you're trying to reach this computer. Um, I know how to get to it. Just ask me. I'm the concierge. Thank you for coming to the Ritz Carlton. I will show you to the computer you would like to get to.

Um, this will work out great. You know, you're trying to reach, you have 192 1681.2. You want to go to 10 uh 400 point whatever. I will figure out a way to make sure that your address is translated to them and back to you." This should work out. Okay. Um, but mostly you're just like pulling web pages, right? Like you don't need to come back and open

up a port or do any good. Okay. Got it. Got it. Got it. Got it. Right. Right. So you're in in you're here in Pasadena. You need to get back to 22 the SSH port on your computer at home. The standard SSH port. Thank you. And I Okay. Um, I guess you could just like open the port, right? Like we can just open the port because like

who knows how to get to my home? Like who's guessing where Washington DC computer is? like should be fine. Um, uh, last week before I came to this conference, a a writer on the XDA developers website, uh, set up an SSH honeypot. So, this is the most recent data I could get for you. Um, he does an SSH honeypot is for those who don't know, it's like

like just an SSH instance you open up to the public internet with a port forward and say like it's just like decent security, maybe like a bad password, not even a good password, just like okay. Um in about seven days time they saw 29,282 interactions uh with that port from 447 unique IP addresses and they were just smashing every password that is out in the in the

dark web everything that you could possibly have like there's just like password one password Raspberry Pi Pokemon 2 like just smashing and smashing and um some of them were known addresses and techniques that were connected with Noabot which is essentially like a traversal virus and then IRC worms which like break in and then they say, "Hey, I got in. I'm going to let an IRC channel in

somewhere else in the world know that I got in." So, we can communicate what happens next. What happens next? It'll be great. And Telegram grabs where like it gets in through the SSH. It immediately starts looking for the known folders that host Telegram data because they're like, "Well, people put all kinds of fun stuff in Telegram, so let's go grab that." So, we don't open the port.

It turns out opening port bad. Uh should should not do it. It seems like there's people scanning all the time to find port. Okay. So I'll close my ports. Awesome. All right. However, now I have opposite problem. Now I can't get into my port. Uh but also the you know the the bots can't get in. I can't get in. I guess we're back to man in in

room with computer by himself. Okay. Well, that's not what we wanted to get to, but that kind of feels like where we're at. Uh so what are we going to do now? Well, if you are try, let's say you were starting a new company today and you were going to figure out a way to fix this. Um, you want people to connect to their stuff, but you

don't want them to open ports and you need to figure out a way to deal with the fact that there's a lot there's more computers than their IP addresses. So, and I I promise I will talk about IPv6 at some point. Um, I know I know. But like for now, we live in the world we we we know person, same river. What are we going to do?

So here's the basic problem. Um a standard firewall, you know, like the most basic version of it, the Windows, the whatever UFW is, um you from computer A or 222 say I want a website from the verge.com and for some reason the Verge is at 7777. Um you try or you want something back from my home lab over there, if that's a better example. Um it will

not let you through because it hasn't seen you ask for that port. You send a packet out, you try to get something back, it doesn't know that because you haven't reached out to it. Um, firewalls will only accept traffic back on the same port that it went out through. So, if you're at 2222 and you send out a thing from port 20, um, you can only get

it back on that. But how does, but again, you are not actually at just um Kevin's address in the world. You are behind, in my case, Verizon's ISP router. I'm behind my home router and I'm not actually that address when I go out into the internet. So, what are we going to do? I I have to be able to convince my home lab to send something back

to me, but I can't get through it. I don't want to open the port. So, how are we going to find each other? Uh, the first layer of tricks is called stun, which stands for standard. Oh, crud. I made a flash card. Raj stun. >> I know. It stands for standard session traversal utilities for nap. Thank you. Thank you. Uh cosmic text editor. Sorry about that. There's

a lot of acronyms. All right. So, basically stun is a server that exists out there and they're public ones and you can run your own or you can do whatever. And it says like, okay, uh Kevin's server is 1921 1681.50 and it reached out on port 1 2 3 4 5. But when it came out of the pipeline, when it got past my home router and when

it got out through Verizon, you know, uh, Northeast Hub, whatever. Here's what it actually looked like. It came from 203.0.113.7.45123. Cool. Okay. Well, I don't know how that happened to you, man. Like, hope hope you're feeling okay, but okay. So, that's your new IP address from your home router. Same thing here in Pasadena. I'm going to reach out from my laptop over the hotel Wi-Fi. I go

out. I make it through Hyatt's router and uh through whatever our regional hub is here and it's like here's what that looks like. You're actually at blah blah blah 46759. And so stun just literally says to each other, okay, you you both have arrived here. Here's what your IP addresses actually look like if you're going the other way. All right, so that's and then I explained this

all before I gave you the diagram. Sorry. But that's what it looks like when you run a stun server. You basically are just saying like who am I? it responds back with this is who you are. It's very metaphysical if you think about it. Don't think about it. Um so, so here's what you do. So, um you can't necessarily set that up perfectly. Like, okay, you'll both

see each other at the same time and you'll go back through those addresses and it'll be great. What what you have to do sometimes you have to do is you have to set up a coordination server and you grab a UDP packet and you say okay on three we're both going to launch a UDP UDP packet from our from either end and roughly in the same 30

secondond window and we're going to launch them at each other and then they'll both go through and then both firewalls will be like ah I recognize that packet from that address ready one two three woof and you like both chuck them out there and if you feel bad about like data conservancy that those packets might not land. You actually are going to like drill a bunch of

them out there, but eventually both of them will kind of get through in the similar timing and the firewalls will be like these two guys, they're crazy, but we're going to let them hang out. Cool. We're through. Uh that was easy. Like that was the that's the easiest version of this is that like we're out of IPv IPv4 addresses. We need to know who people are when

they finally arrive at the party. Here's who they are. Connect. Good to go. All right. And again, you do not have to actually make the connection. you just have to put some traffic through. You just have to put it through enough so that the two firewalls see each other. Uh, now there's a problem. Um, not everyone is cool with that level of security. Some people are like

that's a you could do some bad stuff in there. A worm could get in there and say like, "Hey, open up one 2 3 4. I got some cool ideas." And the you're like, "I need a better firewall than that. I want that every time the data goes out, I want you to randomize the port it goes back uh goes out through." So, you are trying to

reach 777. It says, "Okay, uh, here's who you are. You're 621234." And then you want to go to a slightly different thing and it's like, well, this time you're 6789. You reach out, you reached out to a different thing. You got a different port and so God bless you if you want to get back through here and get through this firewall because I'm just changing it up

every time you go out. Uh, so there's the that's happening on the bottom. That's a nice uhnat uh allowing things to kind of go through and see each other, send back and forth. At the top is what it looks like when the server doesn't like who you are because you sent out through that way. It you you thought you were coming back this way and the server

is like, I don't recognize this other number. I don't understand what's going on there. Um that's one bad version. Another version is if any of you have ever looked in the docs for why something doesn't connect, every company on Earth has told you not to doubleat. I spent my entire career not really knowing what this meant. I was like, "Okay, why would I buy two routers?" Like,

I don't Verizon gave me one. I'm not going to set up a second one. Um, you can accidentally do it to yourself. That's why they're always telling you not to doubat yourself. Um, you this can happen to you without your knowledge of it. Um, because you can be inside what they call cgnat, which is carrier grade, which is we are so out of addresses that actually we

can't even really give every household an IP address. We just have to give like your block in Virginia an IP address or something like that. Like we're going to we're going to bundle people together. They can all have one IP address and then you can have a port for each one that like needs its own little port, but we we are going to send them all out

through the internet. We thank for using T-Mobile. We are completely out of room. Um what that looks like. So, like that would be okay if everything you were doing went out through the internet and went out to that and you could do that kind of standard stun trick where you like observe what the IP address is, inform each other, do the UDP uh trick back and forth.

But like sometimes you might literally just be in the same T-Mobile block as someone else and the routers and sometimes CGNet is not set up to handle that. They're like, "Well, what do you mean you're inside the network?" Like what is is that bad? like are you are you supposed to be inside that network? And so you try to send a packet out, go back around and

like if maybe my neighbor and I are on the same CGNAT, um the the packet may not route correctly through the CGT because it's actually trying to go out through the internet and back through and it doesn't work very well. Um you can solve this, but it's it's not always going to work. All right, so now we've arrived at the hard part, which is that um they

have made things so hard for us that we are going to have to trick them. We are going to have to trick the T-Mobile and the Verizons and the Hyatt uh regencies of the world by figuring out how what the ports are despite them refusing to tell us what they are. So, who here has heard of the birthday paradox? Great. I'm you're going to know it more

than I am, but essentially um I failed out of computer science in college because I hit CS250, which was advanced databru advanced database structures. And I was really good at the lower level stuff, like make JavaScript look cool. But then I got to CS250 and they're like, "How good are you at math?" I'm like, "I'm great." And they're like, and then I did a test, they're like,

"You're not very good at math." Um, so essentially the birthday paradox, the the layman's version I can give of it. And raise your hand if you would like to clarify what I'm saying more than I'm doing it. Um, you you know, if we just open up every port we think could possibly be the connection to our home lab and we hit it on that firewall, the firewall

is like, "Awesome. I have found the port scanner. You are blocked forever. Can't do that. You don't want to scan every single port. Um, how are we going to figure out what port possibly could be the way back through here if you don't have to actually do every single port on both sides? If each of you can kind of do some of the ports, you can use

math and you can kind of square root the amount of problems, the amount of time tries that you have to do. If you have a certain number of random probes on each side, by kind of following that progression, you can actually reduce the number of time uh ports you actually have to probe and you can arrive at a gentlemanly number of probe scans you have to do

before you get to it. Okay, whatever. We're not here to talk about math. Uh we you can do the birthday paradox. This is really well documented. Check it out after the talk if you want to. um we wrote about a little bit on our blog, but um you can do what we call the I call the halo and zoom set, which is um there's always a UPN

toggle on consumer grade hardware and it is almost never explained to you by the router maker and you're like, what is up UPN? Universal plug-andplay. Um and then there's better versions of it down the road like NATP and PCP where essentially you say, okay, I need to open a port, but I am inside the firewall and I'm asking to open the port. I'm only going to do

it while the connection is alive so that I can play Halo against my buddy Timbo. Okay, just open the Halo port. Do it from in here. If you stop getting packets from me showing that I'm absolutely owning him with a scorpion tank, you can close the connection. But then like and then now the port was only open for that one purpose for that one time. Thank you

so much that I'm UPN P&P or I'm not PNP or PCP. Um, so those work like you can actually kind of use them if the if you have software that that knows how to like access it and can and request it from the router. The problem is is that lots of folks are like don't turn on UPN. It's a terrible idea. And they're not empirically wrong. There

were security vulnerabilities for UPN back in the 2000s or 90 1990s. Like it's not perfect at all, but like it is a tool box that you can use, you can access and pull things from. And then there are side channels which are a little bit outside the scope of this talk, but like you can your software could say, "Okay, I'm going to run a server that is

just for computers to talk to each other about how they're going to meet up later. I'm going to run a dating service for UDP ports. You can contact me and say, "Hey, I'm trying to reach Pasadena. I think that I would be able I think that this is what my IP address looks like. Do you know how to like can you figure out how to get to

me? Here's all the ways I've seen along the trace route to Pasadena. What do you think? What's the way in? What IP address should I try to hit? So, you can actually just kind of instead of dumbly throwing ports out or or or hoping that things are going to go well, you just kind of toss them out. I did not start a timer. I'm so sorry. Um,

so then what? So, those are all tricks you could do. What if how do you know which one to do? This is what ICE is. ICE stands for anybody interactive. Oh, wow. 100%. Congrats. That was really good. Um, so ICE is like this is a series of protocols where you try every trick in your bag. You're like, are you both on IPv6? No, absolutely not. Almost never.

But sometimes some like sometimes actually things are set up with IPv6. Uh, IPv6 the really short version is much longer number. Not just four segments, not just 4.2 billion. I don't remember the number of IPv6 addresses. It might just be the heat death of the universe, but it's like a lot a lot a lot of addresses that are very complicated. But each one is just its thing.

You don't need ports. You don't need to segment them into, you know, uh into NATS. You can just say this is computer named this. This is computer named this. Connect each other. Like, and if you don't like each other, that's fine. But like that's where you're going to reach each other. or there's no need to do kind of weird tricks. So, that could work. Um, it could

turn out that it's just on the same lawn and your software could be like, "You're so lazy. Why did you even call me? Like, you can just reach each other on the same subnet. This is so stupid." Um, you can try stun as we talked about. You can do one mapped by like UPN or PMP2 or PCP, those other kind of like open a port for Halo

uh tricks. And you can also just do static port forwards. Sometimes this is totally okay. Um I will talk about one that we kind of lightly recommend later. Um but yeah so you can this is the system by running through everything to see like can we make these packets talk and then sometimes you got to do a relay you know you got to say okay I sometimes

hum like networks like humans they're just jerks like you're just never going to get around them. Um there's enterprise firewall symmetric nat carrier grade carrier grade net that explicitly allows hairpinning. hair pinning is coming back inside and trying to avoid going out to the internet again. Hotel conference Wi-Fi, it just hates you sometimes. Sometimes some networks just block UDP because they think it's like I don't know,

they're kind of like a weird like border state or something. And then certain cloud gateways and certain default configurations are like absolutely no no you can't get through our natural. Everything going out is going to be randomized completely like within like 30 second windows. You'll never get out. Um so that's what natural is. It is a optimistic packet scam combined with careful observation of which packets make

it through. Chad GPT said that if I said this at the scale conference, everyone would laugh. Awesome. So, I rewrote it, which is what you should do. And I call it genally FA and responsibly FO. like you just send stuff out, you see what's going to happen and you try your best and um you learn lessons from it and occasionally like build it into your software. Uh

there are other tricks. there is um you as an organization contacting FreeBSD and saying could we please make pfSense not do like hard symmetricNNAT on UDP by default and and FreeBSD is like that's a pretty good idea actually okay like that could be a default setting and you're like great we will patch it we'll sponsor the patch we can code it thank you so much and so

that will trickle in eventually and now everyone who's behind a pfSense router unless they explicitly say no I I really hate UDP you can't have a st you know, solid address. Uh, that's one way you could have a pandemic. Um, everyone everyone in everyone in the world is suddenly trying to make peer-to-peer connections between uh Zoom and they're playing Among Us on their Switch and they're everyone

is remember Among Us, remember the little blobs? So everyone in the world could start trying to make peer-to-peer connections and you could get that QA feedback to device makers and router makers and hardware and be like actually maybe these super hard tricks that people are constantly hitting our support tickets about are a bad idea. Um uh corporate talk you could like if you were a company that

was putting together all this stuff you could just make a peer relay that people can put together themselves. Um, you could make one of your, in our case, like a node on your tail net. You could say, I designate you as the pure relay. Um, you are the MAC Mini sitting at the front of my network. You will have UDP port whatever like 40,000 or something. You'll

have that one open because the only thing that port does is listen for me to get back to my home lab. And uh, you know, if that works, like you let's let's set it up. Um Raj who is in the back there he wrote a post for our blog about being in India and trying to reach back to a home lab in Minnesota. Minnesota that's a lot

of hops and um there was a weird there's weird things about like the way that a lot of uh the country of India's the nation of India's networks are set up that make that even trickier. So that's a good post. Um and so yeah that is natural. That is what we're trying to do. That is what anyone's trying to do when they're trying to connect you to

Among Us, Zoom, your TailNet, things like that. And that is how I'm able to from this conference access my stuff. I can my wife can ask me when is the next bus coming and I can show her the app that I built that like uh taps into the WA API and tells her when the next bus is coming better than Google Maps does. Um so that's how

I'm able to have 33 containers running uh on my home and I can reach all of them. um, Home Labs Rock and and then I'm gonna open up for questions while I take a glass of water. with the caveat that I am an English major. So, you know, I can answer questions. I have some back up in the in the back. I I I pulled in a

ringer. Um, but if you have any questions about natural or anything I spoke about, hit me up. Yes. >> Is that pure relay feature you mentioned? >> It is. Um you are setting up one specific node on your tailet with a UDP port and saying you know you are the you're for the purposes of net traversal you're the way in. Subnet routing uh in tail scale is

like saying okay um you've accessed me and now you can access everything on 192 168 slash how however you want to divide that up like everything from 0 to 100 or something. Um yeah that it is different in terms of like scope and scale. You are specifically creating one node that is for the purposes of making the connection versus putting one node in there that can connect

you to other stuff that's not running stuff like that. Yeah, good question though. Thank you. Anyone else with a question? Otherwise, you're gonna get some time back. I don't want like I don't threaten you with a good time here, but um anybody else have any questions about home lab stuff or want to recommend anything? Tell a natural story. Tell a I opened a port on my computer

story. >> Well, now I'm not gonna repeat that. Here you go. >> Oh, sorry. I was running like a test application to proof of concept something for work basically and I had opened a port to like an internal machine that was running the application and and it wasn't really secure but it was only temporary and of course I forgot about it and I left it there and

somehow it wasn't wasn't I wasn't running the application anymore. I was running just a web server and it was browsing like a network volume on my local network that I was using internally and somehow Google crawled it and basically I got I got an email from somebody who basically was like, "Hey, can you put this file back up? It's it's not there anymore. I I was trying

to download this thing and I'm like, "Dude, how did you get in here?" Like, how like and essentially Google it was a non-standard port. It was like I don't know how Google crawled it, but I was searchable. And yeah, anyways, >> don't do that. >> That that is amazing. Uh the the the real life equivalent is like your neighbor texting you and be like, "How are you

enjoying Stranger Things?" >> That's that's really good. Um anybody else have a question or a open port story or anything like that? Okay. Uh thank you all so much for coming and I really appreciate your Hello everyone. Welcome to the last So, please join me in giving him a hand. >> Thank you. Thank you for that. This is a little hot impromptu uh introduction. Yeah. So, I

built a AI running coach and I'm gonna tell you about the process. It's it's kind of interesting. Um, but I think there's also some lessons that apply to just in general building software like specifically for your own use case. Um, and what can be learned from that. So, this is um Lake Masinoff this is Lake Masinoff and it is a couple hours uh away from where I

live. I'm having an issue here. Let's try this. And apparently it is besides the Great Lakes one of the deepest lakes in um Canada where I live. Uh and it's beautiful. And they they used to think that there was a monster that lived in it or so they made up and it turned out to be a rock pike which is just like a very big eel looking

fish. But so then a race started there called the monsters of Masna named after it. And the monsters of Masna is a ultramarathon. It is the um their their tagline is Canada's shortest ultramarathon because it is exactly one kilometer longer than a marathon. But it looks like this. It's on the Canadian Shield. There's no real dirt. It's just like rocks and tree roots and whatever. And it's

a it's a single track race. And I have been going in it for a couple years now. And um every year my friend here, Malcolm, convinces me to sign up for it. He's very outdoorsy and you know, he's like, "Hey, let's do this." And you know, it's it's springtime and I'm like, "Yeah, I could sign up for this race and I can spend the spring and the

summer getting in shape. Stop spending all my time sitting around the computer." Um, this will be my forcing function will be to race with Malcolm. And so every year I do this, I don't get as much exercising done as I think. Sometimes I really, you know, the last couple months put in a lot of effort, try to build my speed up and every year Malcolm beats me.

And it's gotten frustrating for me. Malcolm's not even that fast. U we're both just like mediocre runners, but I'd really like to beat him. So I just finished in this last September. I did the 10k version of the race along with Malcolm and I I trained pretty hard in the two months before the race, which is not sufficient apparently, and I twisted my ankle. But um he

still beat me. He beat me by like seven minutes in the 10k And I said to myself, listen, I need to come up with a way to to crush him, right? I need I know it's great to think about health goals and you know getting active and whatever, but the thing that is motivating me is I want to see him behind me, right? I want to be

at the finish line while he's running. It's just going to make me feel better about So, I came up with a plan. All I really need to do is run more. Like, not do it in the two months before the race, but do it continuously throughout the year. I had just finished the race. So if I start from that September, we're signing up next year for the

30K. And if I can just keep running, then I can beat them. This is my theory, right? So there's a lot of running software that exists in the world. Um, serious runners uh will often have very complicated running plans, right? some my friend has a a professional running coach that he pays several hundred dollars a month to like review his runs and give him plans or there

is SAS software you can use that will look at your Garmin data and suggest plans for you. Um is anyone in the room like really into running? Like they Yeah. Do you do you what's your do you have like a target marathon time that you're training for right now? Yeah. So the running plan that he might want would be very different than mine, right? He has gone

on a vacation centered around running and I am trying to get myself away from the computer uh and get out and and exercise. So this tool wasn't for me, right? There's also this um there's also this uh couch to 5K is another uh running plan for for a different set of people. You know, people who are they just want to start running and so the plan is

based around like oh I'm going to start walking and then gradually build up to running. So the two approaches basically neither one is a fit for me. So also I I just wanted to build my own. So I had this idea build my own running app. All it needs to do is keep me consistently running and then I'll beat Malcolm and then I'll feel better about the

world. But the cool thing that happened is I built this that I'm going to share is just like building personal software is is really easy now. Like I was using cloud code for a lot of this and I always like to build side projects but like I rarely would ever get them complete before I started like a new one. But now in this new world of agentic

coding like it was actually pretty attainable. So this is my veg plan for my AI running coach uh just in some Python pseudo code, right? So every morning at 6 a.m. it will get my training plan, check out my runs this week, and then it will send me a Slack message saying like, hey, according to your plan, you know, you should be running today. So this kind

of keep me on track, right? Today, this is the run you should be doing. And then on the other side of it, um I have a Strava web hook, right? So, I have a running watch here. I'm sure that you do because going on running vacations >> right after this. Yeah. See, he's better than me. I Anyways, Straa, uh, if you're not familiar, it's like a backend.

It's it's a social network, but it's also for these purposes like a backend for all my running data that comes from my watch or from whatever runs I take. So I can register uh a web hook with it have it call my running coach so that whenever I do a run the my running coach the AI will get my running run that I just did and it

can evaluate it as per my plan right basically the most important thing it does is kind of say like you know adab boy good job right you you completed a run or if I if I didn't follow the plan maybe it can offer me some correction so that's the plan right the architecture is kind of like We have Straa and it's going to call a lambda. Uh

the lambda is going to store some of my data in Dynamob and then it's going to post a message to Slack. The message will be written using an LLM. Um and then I use Event Bridge as like a cron for that early morning uh reminder. So I was being asked before if this is like a self-hosted project. I I really actually did not want to have the

operational burden of keeping something running on on a server I managed. So, this is all on AWS and it's running in a lambda and it runs so infrequently that it costs me like I get the bill every month from AWS that's like 0.01 which is nice. I I'm also cheap I guess is is one of my themes here. A lot of people are building these like um

open cloud instances and they're buying a MacBook or a Mac Mini to run this on and I'm you know just living on the free tier of AWS and it's really nice. Okay, but first thing I do is I set up some infrastructure. So this is um just some Palumi code in Python. So I set up a AWS um Dynamob table. I use paper request. I would love

to store this information uh in Postgress, but DynamoB has this paper request instance that has like a very generous free tier and so I can use it without having to pay them anything. Uh then I just have my Python code sort of like the pseudo code I showed you earlier and it's going to run inside of a lambda. Uh so that's this second part and then I

just have a function URL on my lambda. Right? So, it's just a URL that I can call and will call my Python code that runs. And because it's a lambda, it just spins up at that point, does whatever sends the message to Slack. And so, it's never running except when it's processing runs. So, it's very like uh computationally efficient. Um, yeah, and I also set up this

cron AWS. Apologize for breathing on this but but the beautiful part is it cost me almost nothing uh for the LLM I'm using uh grock where I can host an open source uh sorry open weight API and so my main cost for running this is uh here so this is actually my trying to see this it's a bit small so for January my cost of running this

is 40 cents um and that's about the range sometimes gets higher depending on how many runs I do but the the token cost is pretty low. And this is like something I kind of like to do, which is have a side project that I can host somewhere. I don't have to worry about the um operational overhead because I just have it running in one of these cloud

accounts. But I try to size it so that it runs within their free tier. So you can do this on most cloud accounts, right? You can use Google Cloud Run, you can do Azure functions. If you manage to keep the compute small, if your storage is using some of the cheaper services, like you're totally in the free tier, you know, because they're hoping, you know, that you

will grow into a bigger thing. It's kind of like free riding off of a corporation spending millions on AWS and you're just there with my little running So, the next problem is how to train, right? What will my coach tell me? So there's a lot of different approaches. Um the one that I find simplest is just working by heart rate zones. So if you're familiar, you have

a max heart rate and you can kind of subdivide from your max heart rate down based on certain um physiological dividing lines and uh you can split into these five zones. And then uh my approach is a polarized training approach, right? Which is basically you want to spend 80% of your time in zone two, which is like an easy run pace. It's like at the pace of

which you're you're still running, but you can talk. And then you you know the other 20% is at a very high uh heart rate. This is like occasionally running as hard as you can, but mainly just doing easy runs. This is like evidence-based very basic training plan. that you get the most benefit from a lot of time in this zone 2 area with occasional, you know, really

going hard. The next problem though I have is is a data problem because there's two types of runs I do. One is right. I I go out running with my friend Malcolm or I run with this uh Peter Bro trail running club, which you can see here in this picture. And that works great. I just use my watch and then it sinks and everything's happy. But I'm

in Canada. It's currently freezing and I don't really like running in the winter. So a lot of my running actually takes place on my Pelaton tread that you can see right here. So, this is me in the basement on the Pelon tread. I try to do this after work. Get me away from the computer. Uh, Pelaton has a lot of great classes, but what I tend to

do is watch Stranger Things and then run on the treadmill, which is awesome. You can see I've also got this pedestal where I put my laptop. And a lot of the development of this running coach has been me dictating, fixing things um to cloud code as I'm jogging along, which I think is really just time So, one of the principles I had to learn as I was

building this is when to lean on an LLM that's very good at uh kind of generic thinking tasks and and when to like actually write specific code. So I came up with this principle to guide me that I called cognitive delegation which I think I got from somebody else online but adapted which is if you're doing something very specific you know where it's easy to write ifs

I just write code right but if I'm doing something very soft like providing coaching advice um then I lean on the LM right if I need to decide based on the notes if this was a good effort or a bad effort you use the LM but if I need to do something more specific like figure out how many minutes were in this run. Like I just parse

the running file. That led me to this problem. The Pelaton does not have an API. So my Pelaton tread that there's no way to get the data out. I can sync it to Strava, but they only send basically the timing data. They don't send the incline. The heart rate comes from my watch and it's hard to sync. So this is a problem that maybe an LLM could

solve, but I just solved with code things can't really not have an API, right? When I log in and I see my Pelaton data, you know, it's clearly And if if you dig a little deeper in theory, I guess one thing to say before this is that um Pelon is a great product. And if they're watching this, um, I think this is still in the spirit of

the terms and conditions, if not, you know, properly allowed by it. If you go to your Pelaton app and you log in, you could see it's a Ozero request and that they give you back some JWT token. Technically, once you have a JWT token, I mean, you you do have an API, right? because you can take that JWT token, you can write it out, save it in

S3, and then your app, you know, your LLM can use that to access the site. in theory, I take the refresh token, I save it to S3, I make my running Lambda able to take down that JWT, hit the Ozero endpoint, refresh the credentials, uh, and now it can act as me and retrieve my data. So now this is my new process, right? I do a run,

it goes to Strava. Straa calls my Lambda. Lambda will check is this an indoor run or an outdoor run. If it's an outdoor run, it goes or sorry, if it's an indoor run, it goes to Pelaton. It impersonates me, grabs that data. Then we need to form this into something useful for the coach to understand. So I have like a columner based format for the stream of

data that you can get from a watch or from a treadmill. So at 1 second sample intervals I just have all the data that the various devices I use are providing right. So I have a every second I have a heart rate I have a speed and meters per second uh foot cadence power etc. as well as the sources right and then um I roll this up

breaking it down into zones. So, how much time did I spend in each heart rate zone? How long am I working at things? This is just another example of this cognitive delegation uh concept that I found really helpful. Like I could give the raw run information to the LLM to analyze, but I found it actually a lot better to provide my own summarization and rollups and provide

the LLM like a a summary view that actually a running coach might want. Right? Right. So what the coach uh the LLM ends up seeing is something more um summarized like the following. Right? It can see here that right I've done three activities this week. Total running time 4 hours 15 minutes. And then it has the zone breakdowns and then it kind of will break down each

of the activities as well as recent history. So the LM gets this as input. breathing on this with my nose. And then in its prompt, it also gets um an information about my training plan. Right? So I put together a training plan. It tracks through the whole year up until the coming race with varying stages. Right? In the fall, it was just building up the amount of

time. In the winter, where I now am, it was increasing the length of my long runs and so on and so forth. So the each time I run and it's providing me feedback, it gets my running plan, it gets what I'm doing and then it acts uh as a coach providing me and then what it generates is each morning it gives me an updated plan. Here's what

you should be doing, right? And this is the format I kind of came up with that I like in the out column here. So I have uh MVW which I call like the minimum viable week. So each week I want to do three runs plus one long run plus a strength session. And so it will map out the week and suggest what I should do each day.

And you can see here, right, I'm on Friday and I've just finished one 49m minute run. And it's suggesting like, okay, here's what you should do Saturday and Sunday in order to hit your plan. So it looks like this in Slack, right? I have just completed a run and then I get a Slack message coming in and the Slack message kind of summarizes the run and it

says like here's where you are on the plan right you can see the line that says just now uh if this isn't too small to read right just now this happened and then here's the plan for the rest of the week and then the most important part is kind of the coaching feedback it provides me at the bottom so that's postron and I just found this very

motivating to tell me after I've done something good. Like, hey buddy, good job. Like, here's your plan and you've worked towards it. I actually played around a lot um with the best way to get the LM to respond to me that it would be motivational. Like, I tried this kind of um like David Gogggins approach where it was like, "You got to be hardcore, like go buddy."

I didn't really enjoy being yelled at in caps from a Slackbot. I tried like very overly positive like, "Look at you. You're succeeding." uh that I didn't like either. What I found was most motivational for me was just very factual information about like, hey, here's your plan and you're working towards it and you're a little bit faster now than you were before or a little bit slower

from a month ago. That actually I found quite motivational. The other important thing was just that the LM can adjust the plan on the fly. Like I I kind of think of this like a GPS, right? when you're driving in a GPS and you make a wrong turn. It doesn't like criticize you for having made a mistake, it just like adjusts and give you a new plan

right away. So on Monday, right, it will post me a message um and say like, "Hey, here's your plan. You're going to do this Monday, this Tuesday, this Thursday, etc." But then on Tuesday, after I've done nothing on Monday, it just gives me a new plan. It doesn't criticize me for not doing Monday. Like here's the new plan. And then after not doing a run for several

days, which does happen, then it stops saying like, "Hey, here's your plan. There's no way you can complete it this week." Instead, it says like, "Hey, how's it going? You haven't run in 3 days. Maybe do that." And the way I do this is I have in the prompt some information about kind of establishing my motivations. So, I just have this, hey, note, you know, this is

literally from the prompt I use. you note if the motivation is considered fragile, right? So, if I'm in a fragile motivation state, then it has a different tone that it replies with and it doesn't include the progress and it doesn't include all these preamles. It just says like, "Hey, you haven't run in a while. What's up with that?" And then I have a further stage which is

low motivation where I haven't run in a week, like five plus days. And in that case, it just comes up with um what's the term? It won't even say that, hey, you should go for a run. It'll say like, hey, you like watching shows on your treadmill. I mean, what shows might be interesting for you? Like, it's like kind of backing off. And it's it's fun to

write prompts that are kind of trying to motivate yourself, right? Because it's a little bit like trying to psych yourself out. But the secret ingredient that actually made this work um and I think works for all these kind of personal projects is intention stacking. Uh which is this idea from psychology research that if you want to do something you can combine it with something you really like

to do. And if you kind of glue those two together then you're more likely to do them. So in my case that's just like I like to build weird things as like side projects, right? I'm always building some little thing on my computer. And by making that little thing I was building um actually a running coach, it made me more motivated to run because I would be

like, "Oh, you know, I did a run and something failed and then I fix it and I I want to do another run to see what happens when I go back through that pipeline or it has a problem, you know, handling the heart rate um at a certain level." And so, you know, hey, I want to do another long run. see if it gives proper feedback on

that. Now, so the the next thing that I added because the interesting part about a personal project is like you can just keep adding features, right? There is no um project manager telling me, you know, whether something should be a priority or not. It's just everything that I want gets in this. So, I did in fact add chat, right? So, it's posting a message saying like, hey,

your run did good. And then in Slack on my phone, you know, while I'm catching my breath after, I will often just like voice dictate how things went, especially if things didn't go well. Um, I tried to include a screenshot, but my Slack is the free version, and after 90 days, it gets rid of the history. So, I've recreated it here. Um, a couple weeks ago, it

was a Sunday. I had lots of free time, and I also had neither completed my long run uh nor my strength session. And so I thought, hey, let's do those both at once. Um, so I did my long run and then I did my strength session, which as planned was this kind of metcon activity involving uh like dumbbell squats and then a lot of lunges. And afterwards,

I was like, "Oh my god, that was super hard. My legs are struggling." So I put that as a message. And then the next day when I woke up, I almost fell down the stairs because my quads were so bad that like I could barely go downhill. And so I put another message in and I said like I'm having trouble walking. But the cool feature I added

was when we have this chat back and forth with my coach, which I'll demonstrate to you, uh it will store things that uh it finds out about my training into a S3 document. And then that S3 document will end up in the context when it prompts. So once I had this conversation, it added to its S3 prompt that you should not do a leg strength day on

the same day as your longest run. Like that's just a bad idea. And that meant, right, it kind of works like this. So I have the chat in Slack. The Lambda adds that to this context which is then used by the LLM. But the cool thing was just having that conversation meant now every time it's generating a plan, it will never tell me to do those two

things on the same day. In fact, it often tells me not to do them on the same day, like even if it's not relevant, which is another problem. But the customization was super cool. Like this was a this was a cool moment for me where I'm like, this software is so simple. It's like not the smartest LM in the world. It's just a bunch of Python code

calling various things. And here it is learning my training plan, learning what I need to happen. Um, and every time I'm providing a feedback, it's learning more about me and customizing things more. The other thing I learned um was something I call intentguided prompting. So once I started to add all these logs about what worked well for me, the LLM just started getting very verbose, right? because

it went from having a simple prompt to having a prompt that has like 800 words of things about what Adam should do. And so it started thinking like I need to provide him, you know, a small essay every day about how he should do his running. So I started with just adding rules like respond in two sentences or less and um you know, don't ask questions unless

whatever. And it it was a battle that I couldn't win. Like every time you add a like do or do not rule, I don't know if you've had this problem with like your cloud MD, every do and do not rule like the more you add the less likely it is to follow them all or that they disagree with each other. So the thing that I found that

worked really well is what I call intentguided prompting. So instead of giving specific rules, I try to write down the principles. The same way like if you're trying to assign give somebody a task to complete, it makes sense to tell them like what's the goal here? Instead of giving them like do this, do that, don't do that, what what are they trying to accomplish? So instead of

all these rules, I would just say be concise and encouraging and honest. When uncertain, ask one focus question. And then I can get rid of a lot of rules and it's using its own guidance to decide The next part of that is giving examples. So if I can provide like hey under this circumstance here's a good response it can learn and pattern itself off that LMS are

really great at copying you know a writing style. Here's the actual uh prompt. Um so it's a little bit abbreviated but it just says you're an encouraging and phase running coach. The phase aware is because I have a plan with like multimonths and then it has the principles and then it has just some examples of responses and I actually have some where I say don't like a

negative example as well if it's too verbose I can put an example and say like don't do that and then I also have this function so when I'm chatting with it it will save these reflections But the time that this really time when I really was like this is cool was you know it it pings me in the morning it's like you got to do a run.

I didn't really want to and then I I did and I was watching Stranger Things which I had never watched before and there's like five seasons of it and it was just my favorite thing. Once I would get on the treadmill and I'd start watching Stranger Things, I just wanted to keep running because I wanted to see what was happening. And so I put that in my

notes. I was like, I didn't want to run, but now I just want to keep running because I want to find out what happens in Stranger Things. And then the next day the coach pings me in the morning and it's like, hey, today after work, jump on the treadmill and remember to keep watching Stranger Things. And I was like, yeah, no, I I do want I want

to find out what's happening with those demogorgans. And this was like watching a fun TV show on the treadmill I think is my big unlock. But I only learned it because of the treadmill or sorry of the software taking my notes and feeding them back to me. Um, what else? I also added some health tracking. Oh, another problem I had was in Slack. So, this is all

working in Slack. If I send a message to my bot, it has 3 seconds to respond. Um, otherwise Slack considers it a timeout and they send the request again and they will just keep doing that, like hammering your Lambda with repeated requests. I could never figure out how to stream Lambda results back to Slack. So, I have to wait until the entire LM response is finished to

get it back, but in the meantime, it's timing out and it's sending off more requests. So, I came up with this strategy of just I can have the Lambda call itself. Uh, another option might be a Q, but basically if I send a message to my Slackbot, it will respond with like thinking dot dot dot and then it will call itself so that it has a longer

timeout period and when it gets its actual LM response, it will edit it and put it in place and that way I can sidestep the Slack timeout issue. The other issue I had uh also relates to time which is just LMS are slow, right? And if you're in chat and you're chatting and it streams the response, it might not be too bad, but you have a lambda

and you send a message to it and it needs to wake up and then it's doing this big response and sending you it all back. It just started to lose that feel of like, oh, I'm actually chatting with something. And so I started using this open weight model, GPT OSS 12B, which you can get from Grock and many other places. But the cool thing was Grock um

has a very fast endpoint where OpenAI will do like 50 to 100 tokens per second. On Grock you can get 500 tokens per second. And so the response that might take 3 minutes on GPT5 on this model I can get it in like a couple of seconds and it just really makes it feel that much more Uh some other things. Yeah, let me show you some of

this. um this is a Slack channel for my podcast and I'm in here all the time. That's why I was like, "Hey, I want to do this in Slack because I'm always in the Slack channel. Each message I'll see each day I'll see there's a new message and I'll want to read it." And so, this is my momentum bot. You can see um here. Wait, that's I

also have this Horizon bot that does things. But um a new problem I've just discovered since coming to California is it does not understand time zones. So my 6 a.m. message is currently coming in at 3:00 a.m. But here's an example of the message, right? So earlier this week it said, "Hey, your last run was 3 days ago. Um yeah, how's your back?" because my back was

hurting from the plane. And then I've moved on from watching uh Stranger Things. I finished season five. It was super good. I don't know if anybody else is into Stranger Things, but good stuff. So now I'm on to watching Dirk Gently. So it says like, "Hey, uh maybe do your long run and you can watch Derk Gentley." And it has some buttons here. So if I want

to see my plan, you can see it quickly puts working on plan and then that's how it avoids the timeout in the background. and it's doing the LLM request. I also have review. Yeah. So, here's my plan so far for this week, right? So, I did several long runs. I counted the hike I did with Enen as one of my runs and I just have this long

run left. And then it kind of says, "Oh, it's saying, oh, you should get on your treadmill and just watch a movie for your long run." That's not going to work because my treadmill does not come with me. So, I can say like I don't have my treadmill. I'm in Southern California. This is my other trick to just respond with an emoji, you know, so you get

a quick response before it times out and you can come back. Oh, it's like, oh, got it. Let's run outdoors. Okay. It's kind of a lame feedback that's not that helpful. We're doing a demo here, Uh, yeah. Any specific advice about for the run? It's probably going to be like just run, man. Let's see. It's great that you're ready to get out since you don't have a

treadmill. let's translate this into a solid outdoor session. Pre-run activity. Oh, my running coach really wants me to do ab exercises. Uh, because I have some issues with my back and apparently I never listen to this advice, by the way. It's always like, yeah, you need to do these dead bug exercises to to strengthen your core. I hate doing core. Like, that's not going to happen. Yeah.

So, here's this advice, right? So, this is the type of thing for helping plan my week and then when I actually do a run, um, it's a little bit harder to demo, but if you guys will give me an hour to run around the building and then I'll stop my watch. No, I can just, uh, I'll fake it. So, if I call the web hook um, that

Straa normally calls. >> Yeah. No, >> I was actually I was a little I I had this idea like, oh, I'll go for a run and then I'll just I'll turn the Bluetooth syncing off my watch so that I could sync it on here, but then like I wanted to listen to my headphones on my phone and I turned it on and I was like, damn, that

was part of my plan. Anyways, this is my new plan. So, this is basically the call that is made um by Strava when a new run comes in. So, I'm basically just uh telling it, hey, there's a new run in Straa. And so it gets this status. Okay. So this is like the function URL for my web hook, right? And then in the it should once it's

done responding come up with a response here. So or it may not and then it will be very anticlimactic. But yeah, adding these buttons was super helpful too because like uh I also added these graphs of you know what type of um how I'm building my base running ability. Let's see. Oh, here it is. 2:22 p.m. Yeah. So, this is kind of the feedback that I get

on each specific run. Nice job getting this done while traveling and without the treadmill. I It's It's clearly responding to our previous chat message. Uh, your effort drifted higher than usual. You quietly hit your five hour goal for the week and here's your Yeah. So, this is kind of how it works. Let's go back to my slides here. Um, but did it work, right? Like, did I

actually get better at running? I pulled some graphs. So, this is a graph of me historically, like the weekly training volume in minutes. And there is like a spike back in November 2024, but besides that, I'm a bit above that. But then I decided to graph it. Like the real problem I'm having is consistency. So when I graph based on consistency, the weeks where I never run

are are now virtually gone, right? Where in the past some weeks I would be really in and I would get running. Some weeks I wouldn't. Now I'm consistently running. And when I compare post um post app to pre-app right, the number of non-zero weeks is way better. The weeks with three plus activities is way better and my average minutes has climbed. But the cool thing I think

with all this is it's a personal app, right? Like everything is just specifically built for me. You know, Netflix is personalized. It will always put the Stranger Things up there and tell me to watch it. This is just actually just very specifically meant for my needs, right? I'm not going to open source it. It only does Atom things. It's only useful for people who, you know, have

a treadmill and a Strava watch and whatever. But it's so possible to build things like this now, right? You can have a specific use case and build software for yourself, right? Uh, the reason I was able to get this done is sort of just leaning into coding agents, leaning into my own passion and just not worrying about building something that could be used, you know, by lots

of people. It only talks in Slack because that's what I wanted to use, right? It only, you know, does Strava and Pelaton because that's all I cared about. It doesn't have complicated weightlifting stuff because I hate to do ab exercises or whatever. But I think it's cool that you can build this type of stuff, right? I actually don't chat to the app very much. It's actually consuming

data that I produce in the world, right? And providing feedback to me. And the the feedback is useful, but I don't actually have to talk to it that much. And there seems like there's so many cases like that where there's information out there that you're generating. And there used to be this big like quantified self movement where I could dig through all my data and and find

things. Um, but now you can actually use the, you know, intelligence on demand of an LM to do this type of analysis, right? I have this uh, aura ring that I don't use that much because I never found it super useful, but maybe I should throw an AI at it and see maybe there's useful information about my sleeping in there. Maybe the problem is that the UI

they have is very generic for everybody, right? And that the important metrics for myself are very specific. So that's kind of the cool thing I learned from this is like you can build something just for yourself, right? If it's like a meal planning app or music practice or sleep or journaling, like you can have things in your life where you want to accomplish something and lean on

coding agents, lean on, you know, some free cloud tier stuff and build the things that work for you. That's what I think is awesome. you can just, hey, what's something where if somebody was paying attention to it and giving me feedback on it, like it would improve my life and then can I just roll that myself? So, I I don't know if I'm going to beat Malcolm,

though. Like, it's still a little bit in the air, but definitely I'm running more. Uh, if that's sufficient or not enough to beat him, we won't know uh until Canada's shortest ultramarathon uh next September. But if you'd like to, you can come and join me and see. Otherwise, uh yeah, I'll report back. >> Yeah, we have some questions. >> Wow. Let me bring this to you so

we can get any questions on any recordings that we have. >> Sorry, I missed the start of your speech. Do you use a Garmin watch? >> Uh, it's a Choros. >> Choros. Okay. I I was trying to uh pull the Garmin API, but they're rather restrictive. I guess they only really let you sign up if you're a company is my understanding. >> Yeah. So, I actually get

the data from Strava. Like I have my watch app go to Strava. I think that would work for Garmin as well. But also, if you saw my Pelaton slide, it's very possible to reverse engineer these if you ignore the terms and conditions. >> Okay, so I actually have a question. Um, so being a selenial, I'm kind of at the intersection of being a Gen Z and a

millennial. Um for those for just context um 97 through 99 is millennials. So um my question is all through Tik Tok. So I'm the Tik Tok generation. I look at Tik Tok for everything whether it's recipes or restaurants etc. Um even career advice I look at Tik Tok. Um so right now on Tik Tok what has been going crazy is as you mentioned the um the Apple

minis and going using Clawbot and as m people are giving money like they're giving credit cards to Clawbot and telling Cloudbot make my life better and just letting it have access to all the data. And so my question is kind of um what are your thoughts on that? I know it's a huge security risk, but um they're encouraging people people are buying the um Apple minis, going

out buying it, and then using Clawbot. I I do like large um learning models. I am I have Chat GPT Pro. I use Gemini and um Grock and I've utilized them and I like them but they're not always accurate. So I have some hesitations about Clawbot and the usability. I don't know anyone personally who uses Clawot. I've just seen people online. >> Yeah. Um my my colleague

here Enen is pretty hot on his Cloudbot playing around with it, but I don't think he's giving in his credit card. But um you know if I had built if id started building this right now maybe I would take a look at at cloudbot um it didn't when I started this project but the interesting thing about it is it seems to consume a lot of tokens um

yeah there's obvious security problems and I think that some of the way it's used kind of violates the thing I put about cognitive delegation like here I'm I'm very much doing the coding things just in good oldfashioned you know Python and So going out to the API and putting it in a file and then using the LLM for the judgment where I think uh you know Cloudbot

has layers of uh using agents to do things that that could be just written as a straightforward program. So that's like one of my objections just because like I actually do like code. I I don't think everything should be uh just like layers of LLMs trying to figure out how to do things. Um but yeah. Yeah. Don't give it your credit card. Also, >> you mentioned this

term called quantified self. >> I was wondering if that's an established, you know, concept and where it came from. And I I do see that uh a lot of things are made possible now with LLMs and it's not just because you're using them to in to read your data, but you're using them to maybe write the programs too. Um but uh you know like wearables for example,

a lot of promise before. Um maybe maybe we need to revisit things now because we have this glue that kind of can make the projects Yeah, the quant I don't know when quantified self started but it it's not an LLM thing. It was like people who were really into data and they would be like I'm going to track every meal I eat and oh look at that.

If I have artichokes then I have heartburn. Like gathering data about their lives and doing analysis on it. And it seemed really cool. Like it's cool to give a talk and you can show all the vegetables and artichoke looks bad, but like that analysis is is hard to do, right? But now we have an LLM and we can throw it at this information, right? Like I have

a scale um you know that measure I have a smart scale, you know, and it graphs my weight, but I don't really look at it. But it could be that my AI coach could be hooked up to that and could say like, "Hey buddy, easy on the potato chips or what whatever." >> So I have a two for one. One question is, have you published this on

any opensource platform for other people? And then the other question I have is let's say I don't want to pay a dollar for Slack and I want to be a little bit more scrappy. Um, can this also have could this also be utilized for like let's say WhatsApp or like a text-free app if that I'm more um of a texter? >> Yeah. So, um, in terms of

open sourcing it, yeah, I I struggle with that because it's so weirdly designed for my use case. Maybe there's reusable things in it that I haven't really figured out. And in terms of the cost, right, the the main cost is just the LM token usage. So, the $1 a month is basically going to the Grock for my token consumption, and I'm basically free riding just on the

free plan of a AWS account. Um, I don't think you can get cheaper than that unless you're going to just like sneak it on a USB drive and try to run it on some computer somewhere without them knowing. >> But even so, you'll need an LLM. So, yeah. I I don't know. >> All right. I have a question. >> Do you ever tell your coach that you

never do your core exercises? >> I don't. No, I don't. >> How can you trust them to do the right thing then? It's interesting. Like I could it would be useful to to say like hey yeah I don't want to like I wonder if it could re it could be like hey stop telling me this if I'm not doing it because yeah usually what I'm doing is

just consuming the suggestions that it gives. But yeah it's a valid point to be like hey you know what if you want me to do abs suggest one thing not like a 20 minute ab workout. So, uh, say say you don't work out for a while, right? And it's gone through that slew of of things, right? At at what point does it like start like being like,

well, you know, you're not going to you're not going to beat them if you don't come back, right? >> When does it kind of like kind of like trash talk a little bit to kind of get you motivated or try something different? It doesn't have to be trash talking because that sounds like you don't like that, but like you know what I mean? Like kind of like

trying to motivate you a little bit more than Netflix. it it so yeah I mentioned before I did have this like uh I don't know if any you guys are familiar with David Gogggins yeah so I did try like having that kind of personality that was like really uh talking down to me and like get out there what's wrong with you yeah I did not find it

motivational I didn't try like yeah leaning into the Malcolm thing too much >> other question was do you feel like you're improving. >> Yeah, I I do feel like I'm improving quite a bit and I I did spend a lot of time because I'm like now um like if you notice from my graph, I had all this old run data because once I started doing this, I

was like, oh, I can pull in all my old run data and start looking through it. And then I was like, well, can I find trends of where I'm improving and and not and I definitely feel like I'm improving. Um, but according to like me and Claude's skills at like machine learning, the the signal isn't clear. Like there's so much variety in my day-to-day running, I can't

really say like uh I'm an amount better, but I I do feel like I'm doing better. So maybe if I do like the fun run here or there, I can get a new baseline. >> So this is Thank you for the talk. Uh this is really meta and weird this approach you're taking and you know you spent the time and and engaged with with uh this all

to uh write yourself a program and then you're lying to it. You know um it's uh you could just adjust the prompt to say hey if I uh reject your suggestions uh go out and find some other way to motivate me. >> Yeah. But then you could al it's I just want to thank you for the talk. It's it's very interesting. I think it it kind of

reminds me of maybe uh like a body hacking community uh type of approach. Uh but uh it's made me think a lot. Thanks. >> Yeah, you're right. There's an interesting thing where I'm trying to write things to motivate me, but like I'm also aware that I'm writing them, right? So like tricks aren't really going to be the key because I'm the one receiving them. But yeah, thank

you. >> I I mean I Yeah, that got me through college just like Yeah. You lie like I want to sleep in 15 then move back 15. >> All right. I Oh, hey. Our vacation. Oh, >> you had a question. >> I did kind of want to know uh on September 20th, what public site can we go to to find out whether or not you beat Walcom?

>> Yeah. Yeah. Uh you're you're trying to keep me honest, right? Yeah. What's your name? I can add it to the bot to say like Dave is gonna check your speed. Um yeah, if you look for the Monsters of Masinau race, then uh they they will put out the public uh chip times and you'll be able to see, you know, how I did. >> Yeah, I think

I have it here. Whoa, lot of slides. Yeah. Yeah. M A Z I N A W. >> Yeah. Keep me honest, please. Come to the race. You can come run. >> So So >> So you spoke about latency being one of the major decisions in in choosing Grock as your your model? Like how about relevancy? Like you know, how do you measure the relevancy? Like did you

compare Grock to any of the models especially for plan generation? because it's like you're just letting it's like hey you're thinking Grock is the you know you're accepting what it is you know was it the best you know were there other options like so how do you re um measure relevancy for >> yeah it's interesting gro it's it's Grock with a Q by the way it's not

the Elon Musk gro it's like a different one it's confusing but they they host openweight models um and so the model I'm using is uh it's GPT OSS openweight model um I I have tried using various models and when I had specific rules like do this, don't do that. Um, I sometimes had trouble and I had to use a very, you know, like GPT5 with thinking to

figure things out. When I started putting in the intent, like, you know, here's your goal, here's some examples. Um, the the results were pretty consistent um, across models except when you get to one that's like just not smart enough. Like there is some complications where it's like yeah you shouldn't okay we're planning out your week and we you know you need to do the strength thing on

Tuesday because otherwise you'll like when there is complicated um constraints the smarter models are better but otherwise this is a much easier task than like the agentic coding right like it didn't take the smartest models to to help me out here actually >> mean for plant generation Yeah. Yeah. No, I mean I I found that it works fine, but you may have a much more complicated plan

with pacing targets and whatever than than I myself. Well, thank you everybody. This is uh yeah, thanks for watching my talk. >> Thank you, Adam.

From event

SCaLE

05 Mar 2026 – 08 Mar 2026

All event videos
Back to Watch