<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>KitBoxDev Blog</title><description>Practical guides to developer, DevOps and electrical-engineering tasks — written around tools that run entirely in your browser.</description><link>https://blog.kitboxdev.com/</link><language>en</language><item><title>Your Google Authenticator export QR code is not encrypted</title><link>https://blog.kitboxdev.com/google-authenticator-export-qr-is-not-encrypted</link><guid isPermaLink="true">https://blog.kitboxdev.com/google-authenticator-export-qr-is-not-encrypted</guid><description>The &quot;Transfer accounts&quot; QR is base64 protobuf — every 2FA seed in plain sight. Here is the format, the risk, and a browser-only decoder that reads it.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>crypto</category><category>decoder</category><category>generator</category><category>reference</category><author>KitBoxDev</author></item><item><title>The real risk of online JWT decoders that log your secrets</title><link>https://blog.kitboxdev.com/online-jwt-decoders-that-log-your-secrets</link><guid isPermaLink="true">https://blog.kitboxdev.com/online-jwt-decoders-that-log-your-secrets</guid><description>A remote JWT decoder does not need to be malicious to leak your token. Here is what its log pipeline captures, what an attacker does with it, and how to test for it.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>crypto</category><category>decoder</category><category>reference</category><author>KitBoxDev</author></item><item><title>JWT vs OAuth2 tokens: why claims matter for backend security</title><link>https://blog.kitboxdev.com/jwt-vs-oauth2-claims-backend-security</link><guid isPermaLink="true">https://blog.kitboxdev.com/jwt-vs-oauth2-claims-backend-security</guid><description>OAuth2 is a flow, JWT is a format — and neither one authorises anything. The claims your backend verifies and validates are what actually decide access.</description><pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate><category>crypto</category><category>decoder</category><category>generator</category><author>KitBoxDev</author></item><item><title>Verify, don&apos;t just trust: checking AI-generated cron jobs and infrastructure</title><link>https://blog.kitboxdev.com/verify-ai-generated-cron-and-infrastructure</link><guid isPermaLink="true">https://blog.kitboxdev.com/verify-ai-generated-cron-and-infrastructure</guid><description>An LLM will hand you a cron expression and a manifest that look right and run wrong. Here is the verification pass that catches them before a scheduler does.</description><pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate><category>devops</category><category>config</category><category>reference</category><author>KitBoxDev</author></item><item><title>How to spot a misconfigured RS256 signature before deployment</title><link>https://blog.kitboxdev.com/spot-misconfigured-rs256-signature</link><guid isPermaLink="true">https://blog.kitboxdev.com/spot-misconfigured-rs256-signature</guid><description>RS256 fails quietly — the happy path verifies while the key, the PEM format or the algorithm allowlist is wrong. Here is how to catch it before it ships.</description><pubDate>Fri, 21 Aug 2026 00:00:00 GMT</pubDate><category>crypto</category><category>decoder</category><author>KitBoxDev</author></item><item><title>The KitBoxDev privacy-first manifesto: local processing, zero egress</title><link>https://blog.kitboxdev.com/privacy-first-manifesto-local-browser-processing</link><guid isPermaLink="true">https://blog.kitboxdev.com/privacy-first-manifesto-local-browser-processing</guid><description>Data-egress policy made third-party utility sites a compliance problem. Our answer is architectural — every tool runs in your browser, so credentials never leave the machine.</description><pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate><category>crypto</category><category>devops</category><category>reference</category><author>KitBoxDev</author></item><item><title>How to Use Browser-Private Tools for Cron, CIDR, YAML, JWT and Kubernetes</title><link>https://blog.kitboxdev.com/developers-devops-utility-guide</link><guid isPermaLink="true">https://blog.kitboxdev.com/developers-devops-utility-guide</guid><description>A step-by-step DevOps workflow built on client-side-only tools — cron parsing, CIDR maths, YAML and .env conversion, JWT debugging and Kubernetes resources.</description><pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate><category>devops</category><category>converter</category><category>network</category><category>crypto</category><author>KitBoxDev</author></item><item><title>KitBoxDev is live: 35 in-browser tools, built the way we wanted to use them</title><link>https://blog.kitboxdev.com/kitboxdev-launch-35-browser-tools</link><guid isPermaLink="true">https://blog.kitboxdev.com/kitboxdev-launch-35-browser-tools</guid><description>Why we built a tool platform with no backend, no accounts and no uploads — and what 35 finished tools, a 12 KB app shell and WCAG-audited contrast actually took.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate><category>announcement</category><category>performance</category><category>accessibility</category><category>devops</category><author>KitBoxDev</author></item></channel></rss>