# Simon Wijckmans — full content > Simon Wijckmans is Founder & CEO at cside, writing on browser security, developer experience, books, and travel. ## Entity Summary Simon Wijckmans is the Founder & CEO at cside, based in San Francisco. cside builds browser-first security for client-side attacks, fraud, privacy, and compliance gaps. The company focuses on visibility and protection for third-party scripts and browser-side behavior that traditional server-side tools cannot see. cside is backed by Uncork Capital, Mantis VC, Scribble Ventures, Roar Ventures, PrimeSet, and strategic angels. ## Press Highlights - 2026-07-26 — [Security Boulevard: BSidesSF 2026: Web Standard Consortiums Are a Game With Chrome as the Monopoly Man](https://securityboulevard.com/2026/07/bsidessf-2026-web-standard-consortiums-are-a-game-with-chrome-as-the-monopoly-man/) - 2026-02-19 — [NewsBytes: cside Privacy Watch: Script Monitoring](https://www.newsbytesapp.com/news/science/5-ai-tools-for-enhancing-online-privacy/story#:~:text=Cside%20Privacy%20Watch%3A%20Script%20monitoring) - 2026-02-12 — [Practical Ecommerce: New Ecommerce Tools](https://www.practicalecommerce.com/new-ecommerce-tools-feb-11-2026) - 2026-02-10 — [Security IT News: AI Agent Detection: cside Targets Emerging Bot Threats from AI Browsers](https://digitalitnews.com/ai-agent-detection-cside-targets-emerging-bot-threats-from-ai-browsers/) - 2026-01-30 — [Retail Tech Podcast: Interview with cside CEO Simon Wijckmans on Client Side Security for Ecommerce and Retail](https://retailtechpodcast.com/podcast/interview-with-cside-ceo-simon-wijckmans-on-client-side-security-for-ecommerce-and-retail) - 2026-01-29 — [Help Net Security: cside VPN Detection Enables Control of VPN Traffic to Prevent Fraud and Legal Exposure](https://www.helpnetsecurity.com/2026/01/29/cside-vpn-detection-enables-control-of-vpn-traffic-to-prevent-fraud-and-legal-exposure/) - 2026-01-21 — [Help Net Security: cside Targets Hidden Website Privacy Violations with Privacy Watch](https://www.helpnetsecurity.com/2026/01/21/cside-privacy-watch/) - 2026-01-07 — [BetaNews: How Attackers Are Weaponizing Open-Source Package Managers [Q&A]](https://betanews.com/2026/01/07/how-attackers-are-weaponizing-open-source-package-managers-qa/) - 2025-12-22 — [Help Net Security: Session Tokens Give Attackers a Shortcut Around MFA](https://www.helpnetsecurity.com/2025/12/22/session-token-theft-video/) - 2025-11-13 — [CRN: Stellar Startup Security Technology Vendors to Know in 2025](https://www.crn.com/news/security/2025/stellar-startup-security-technology-vendors-to-know-in-2025?page=12) - 2025-10-28 — [Cybersecurity Insiders: How the npm Trojan Horse Enables Undetectable Client-Side Attacks](https://www.cybersecurity-insiders.com/how-the-npm-trojan-horse-enables-undetectable-client-side-attacks/) - 2025-08-06 — [HackerNoon: c/side CEO and Co-founder Simon Wijckmans on The Importance of Browser-side Security](https://hackernoon.com/cside-ceo-and-co-founder-simon-wijckmans-on-the-importance-of-browser-side-security) - 2025-07-21 — [The Hacker News: 3,500 Websites Hijacked to Secretly Mine Crypto Using Stealth JavaScript and WebSocket Tactics](https://thehackernews.com/2025/07/3500-websites-hijacked-to-secretly-mine.html) - 2025-06-22 — [Bleeping Computer: CoinMarketCap Briefly Hacked to Drain Crypto Wallets via Fake Web3 Popup](https://www.bleepingcomputer.com/news/security/coinmarketcap-briefly-hacked-to-drain-crypto-wallets-via-fake-web3-popup/) - 2025-05-01 — [WIRED: North Korea Stole Your Job](https://www.wired.com/story/north-korea-stole-your-tech-job-ai-interviews/) - 2025-04-15 — [Forbes: Europe 30 Under 30](https://www.forbes.com/profile/simon-wijckmans/?list=30under30-europe-technology/) - 2025-01-29 — [TechCrunch: Hackers Are Hijacking WordPress Sites to Push Windows and Mac Malware](https://techcrunch.com/2025/01/29/hackers-are-hijacking-wordpress-sites-to-push-windows-and-mac-malware) - 2024-11-13 — [Software Engineering Radio: Simon Wijckmans on Third-Party Browser Script Security](https://se-radio.net/2024/11/se-radio-642-simon-wijckmans-on-third-party-browser-script-security/) - 2024-09-17 — [SecurityWeek: C/side Raises $6 Million to Secure the Browser Supply Chain](https://www.securityweek.com/c-side-raises-6-million-to-secure-the-browser-supply-chain/) - 2024-09-05 — [TechCrunch: Startup Battlefield](https://techcrunch.com/startup-battlefield/company/c-side/) - 2024-06-25 — [The Register: If You're Using Polyfill Code on Your Site, Remove it Immediately](https://www.theregister.com/2024/06/25/polyfillio_china_crisis/) --- ## Why didn't you do it? URL: https://simonwijckmans.com/writing/why-didnt-you-do-it Published: 2026-08-18 I left Belgium for San Francisco, and the move reset how old I was allowed to be. In Belgium, where I'm from, you're not taken seriously until you're 30. In San Francisco, by 30, you're already a little old. I'd moved from a country that thought I was too young to one that thought I was slightly past it. There's real power in accepting that the choices you make now are the ones you'll answer for later. I don't mean that as a threat. I mean it as permission. ## The question Say you died tomorrow. Nothing dramatic, no story to it, just gone. What would you be sad you never got to do? It sounds morbid. It's the fastest way I know to find out what you care about, because it burns off everything you were only doing to look busy and leaves the few things you'd genuinely grieve. Most of the noise doesn't survive the question. Whatever does is worth looking at properly. We avoid asking it because it's uncomfortable, and because as long as you never ask, every path stays open in theory. The moment you answer it honestly, a few doors close and a few others start to matter enormously. That's just finding out where you stand. ## The map check When I talk to people my own age in Europe, the difference in mentality is substantial, and I end up asking the same two things every time. What's your long-term goal. And how does the job you're in now, or the decision you're about to make, get you closer to it. Most people go quiet. Not because they've got no answer, but because they've never had to say it out loud, and the question lands like an accusation. It's a map check. You're allowed to stop, look at where you're standing, and ask whether this road goes where you once said you wanted to go. Part of it is that Europe is very good at offering a safe path, and a safe path is a genuinely nice thing to be handed. There's a sensible sequence, and if you follow it, nobody will ever be able to say you did anything wrong. The trouble with a route built so you can't be blamed is that it's optimised for not being blamed, which is not the same thing as the life you actually wanted. You can do everything right by that standard and still end up somewhere you never chose. So the question spooks people. Someone will be halfway through explaining a promotion, or a move, or a course they're thinking of signing up for, and you ask how it connects to where they actually want to end up, and the whole thing stalls. The honest answer is often that it doesn't connect to anything in particular. It's just the next available step. And the next available step is not a plan. It's drift with good posture. ## Phases The uncomfortable thing underneath all of this is that life runs in phases, and the phases don't wait for you to feel ready. The window for the kind of progression that compounds, the moves that set up the next 10 years, is a lot narrower than it looks from inside it. There's a stretch where you can take a real risk because you've got almost nothing to lose. Then there's a stretch where there's a mortgage, or a kid, or a title you don't want to hand back, and the exact same risk costs 10 times as much. The window never announces that it's closing. It just gets more expensive to do the thing, a little at a time, until one day the thing is something you talk about at dinner instead of something you do. Belgium and San Francisco just draw those lines in different places. One tells you you're too young to matter until 30. The other tells you you're already late by 30. Both are partly wrong. Both are load-bearing anyway, because the story a place tells you about your own timeline changes what you'll let yourself attempt inside it. I felt more permission to move fast the week I landed than I had in years, and nothing about me had changed except the map I was standing on. ## Luck Don't leave it up to luck. Luck is real, and it's a bigger factor in all of this than any of us likes to admit. Plenty of what happens to you was never yours to control. But leaving it up to luck is itself a decision. It's just the one you make by not making one. You can't control the roll. You can control whether you turned up to the table with a plan or a shrug, and over enough rolls that difference is most of the game. The people I know who look lucky, up close, mostly aren't. They decided what they were aiming at early, and then kept putting themselves in the rooms where the good kind of luck was even possible. ## The plan Making the plan is the boring part, which is exactly why people skip it. Find out what you actually find important. Not what you're supposed to find important, not the version that sounds good said out loud to other people. Then find out how you want to be remembered, and be specific about it. Not the job title. You, as a person. Your values. What you did for the people around you. The mark you left on the world, however small it turns out to be. Then take that whole picture, the person you're trying to have been, and make it the thing that drives the decisions. Not the logo on the badge. Not what your peer group will make of it at the next dinner. The real question is who you're trying to become, and once that's fixed, most of the things you were agonising over turn out to be negotiable around it. I should be honest that I'm not writing this from the far side of it. I forget it constantly. The grind is very good at dressing the next available step up as a strategy, and I've taken plenty of steps that were really just motion. Motion feels like progress right up until you look up and notice you've been busy in a direction you never chose. The plan almost never fails because it was wrong. It fails because you stopped looking at it. ## Where I landed None of this is special and none of it is new. Every generation hears some version of it from someone slightly older who wishes they'd listened sooner, and I'm aware I've become that person now, saying a thing that's halfway to a cliché. But a cliché is just a true thing that got tired from being repeated, and this one is true. In the grind, we all forget it. So I'll leave you with the version that still makes me move, the question I try to picture being asked right at the end, about every risk I talked myself out of and every plan I never sat down to make. Why didn't you do it? --- ## What I learnt at EMF Camp 2026 URL: https://simonwijckmans.com/writing/what-i-learnt-at-emf-camp-2026 Published: 2026-08-13 At 4 on the Friday afternoon, a man towed a flamethrower organ across a field in Herefordshire behind a road legal ride on lawnmower. Almost nobody looked up. A couple of people took photos, someone made an appreciative remark about the lawnmower being road legal rather than about the flamethrower, and the field went back to what it was doing. I've been trying to explain [Electromagnetic Field](https://www.emfcamp.org/) to people since I got back, and I keep failing the same way. The problem isn't that remarkable things happen there. It's that they happen constantly, in parallel, in front of a crowd that has calibrated its sense of remarkable somewhere well past yours. I had a talk on the Friday, which turned out to be the least interesting reason to be there. This is my attempt at writing down the rest. ## What it actually is EMF runs every 2 years at Eastnor Castle Deer Park in Herefordshire. This year it ran the 17th to the 19th of July, though you could turn up on the Thursday to get your village built and stay until Monday lunchtime. Around 3,000 people camp there. Calling it a festival undersells the infrastructure. There's a power grid. There's high-speed internet, run to your tent, by volunteers, across a field that spends the rest of its life as a deer park. There's a DECT phone network, with extension numbers. It all goes up in a few days, works for a weekend, and comes back down. Hold onto the phone network, it matters later. The schedule had 550 things on it across 66 venues: 157 talks, 175 workshops, 71 performances, 69 meetups, 28 DJ sets, 26 music acts, 13 family workshops and 11 films. You can't see it. That isn't a complaint, it's the design, and you make peace with missing almost all of it by about Friday teatime. Most of it isn't programmed centrally either. You bring a village, which is a camp within the camp, and you run your own programme out of it. Which is how the official schedule ends up with a venue called the Flame village. ## Fire The Flame village is down by the lake. It's what it sounds like. The flamethrower organ from the top of this post belongs to [Look Mum No Computer](https://www.lookmumnocomputer.com/), and the listing describes it as mk3, so there were 2 earlier ones. Dimitri, who goes by Hobbybob, fired 10 liquid flame units he'd built himself, at 10 at night, on the Friday and again on the Saturday. He burnt through 100 litres of isopropanol a night doing it. You feel it on your face from a lot further back than you'd think. The part I liked more came on the Saturday afternoon, in a session listed as "Flamers of the world Unite!". He opened one of the units up and talked through everything that had gone wrong while he built it. He'd sourced 16 controllers from a company in China. The manual specified a maximum of 8 seconds of fire time. He found out the hard way. Then he stood in a field and explained it to strangers, holding the evidence. You don't often get to watch someone open up the thing that nearly hurt them. On the Sunday night they burnt an effigy. Protest Props had been building it all weekend with whoever wandered past and felt like helping. It went up next to Null Sector at 10, with pyro, and a laser installation called Laser Lake throwing light across the field behind it. It's the closest thing EMF has to a closing ceremony. Nobody calls it that. ## Lasers Lasertag ran on all 3 evenings. Free, no booking, ages 7 and up, 10 players a game, on gear the organiser had 3D printed himself. There was a queue every night, and you stood in it behind children and people in their 40s in roughly equal number. That's a fair description of the whole event. Elsewhere, Karina Townsend performed on a set of DIY modular bagpipes with a laser show wired to respond to the sound. The bagpipes were built from rubber gloves, domestic water piping, bin bag material and a spread of tapes from self-amalgamating to insulating. The listing promised wobbly oscillations. It delivered. ## Rockets On the Sunday at 9 in the evening, a man called James test fired a small hybrid rocket motor named Banshee in the Flame village. It runs on oxygen with an acrylic fuel grain, which means the fuel is transparent. You can watch the flame front move inside the motor while it burns. The schedule entry had a one word warning at the end: noisy. That was the demo. The talk that stuck with me was Danny Roberts on high-power rocketry done cheaply, which was really a talk about running an under-funded university rocketry society against teams with more than 10 times the budget. Materials, makerspaces, DIY altimeters, and the very specific anxiety of waiting to see whether your ejection charge fires at apogee. Emily Selwood also gave a funny one on the ways humans have proposed getting to space, including the ones that only work if you ignore safety. Or the rest of humanity. ## Satellites [AMSAT-UK](https://amsat-uk.org/), the British Amateur Television Club and the UK Microwave Group ran a joint village. They did live demonstrations of tracking and working an amateur radio cubesat as it went over. They also worked a pass of the International Space Station, using the amateur radio voice repeater on board. I watched that from a folding chair. Andrew Lindsay gave a talk about assembling and testing LoRa payloads for satellites. He's built and tested 10 of them. 6 are in orbit. Jeffrey Roe ran a workshop where you build your own ground station on [TinyGS](https://tinygs.com/), a community-run mesh of receivers around the world picking up LoRa satellites and weather probes on cheap modules. You can go from never having thought about it to receiving data from space in an afternoon, in a tent, for the price of the parts. That's the actual point of the village. ## Locks [TOOOL](https://toool.nl/) and friends ran a Lock Picking Village with no set times at all. You drop in, someone hands you a lock and a pick, and someone else teaches you. Beginners and experts, the listing said. In practice you watch a lot of people find out, for the first time, that a lock is a mechanism. Not a fact. The best thing I saw on the subject was Etienne Naude's talk on his open source lock picking robot, which he built to make locks more secure rather than less. His argument is about master keys. They're used almost everywhere, including on nearly every suitcase, and they carry real structural weaknesses. His machine pushes a series of wires through a custom 3D printed steel key blank to spoof whatever bitting the lock wants. [The build is open](https://github.com/etinaude/Lock-Picking-Robot). ## Cars [Hacky Racers](https://hackyracers.co.uk/) have a track in front of Null Sector. They race on it most of the weekend. The series started in 2018, after some of the founders saw the Power Racing Series in the US and decided the UK needed its own. It's a genuinely registered Motorsport UK club, non-contact, running cheap DIY electric vehicles that people build over the winter. There were races most hours across all 3 days, then the final and the medals on the Sunday at 5, with the audience voting for a favourite. The listing calls the entrants bonkers DIY karts and the track a DIY track. That's the right amount of self-awareness. Somewhere in the same family of object there was a small pink Lamborghini, which I [filmed](https://www.instagram.com/reel/DbGwiv_vGtl/), because of course I did. It ended up parked at the Brighton Consulate, where Jim Purbrick played a set from it as the sun went down. Generative ambient soundscapes underneath recordings of the last generations of people who'll remember glaciers. Performed from a tiny pink supercar. I can't describe that in a way that makes it sound less strange. I don't think it should. For contrast, James Hervey-Bathurst, who owns Eastnor, drove his 1928 Foden 6 ton steam wagon onto the site on the Saturday morning and talked about restoring it. So the range ran from a kart made of scrap and a battery to a 98 year old steam lorry. With a pink Lamborghini playing ambient music in the middle. ## The thing they left behind At the 2024 edition, which I was also at, somebody left 2 radioactive sources in the swap shop. The swap shop is what it sounds like. You leave things you don't want and you take things you do. These were Danish measuring ionisation chambers, built by a company called Elektronikcentralen, and their job was calibrating smoke detectors. A technician fed sample smoke through a port in the middle and checked the detector noticed. They contain Americium-241, the same alpha emitter as the detector in your hallway, but substantially more of it. Someone called Tryst, who works in civil nuclear and happened to be on site, worked out what they were. He sealed them in plastic bags and locked them in the back of his truck. Then he posted an appeal, asking whether anyone else had taken one from the swap shop, and offering 3 ways to reach him. https://meow.social/@tryst/112546598851850261 That's the campsite phone network from earlier, being used to trace radioactive material across a field. It resolved within the day. The person who'd brought them confirmed there had only ever been 2, and both were accounted for. What I keep thinking about is the gap before that, because he couldn't prove it at the time and said so publicly. Someone pointed out there might be more than 2. He didn't sleep well. He came back this year with a talk called "The Orphan Source Incident". An orphan source is what the name implies: radioactive material that's fallen out of the chain of custody meant to account for it. Intact, these ones aren't especially dangerous. The problem is they're easy to take apart, and an ingested alpha emitter is a completely different problem from one sitting inside a sealed housing. So they have to be kept safe. They have to be accounted for. The ending is the part that stayed with me. Normally they'd have gone back to their Danish manufacturer for disposal. Post-Brexit regulatory changes meant that route no longer worked cleanly, so they ended up in a grey area where nobody can straightforwardly take them. He finished a talk about a radiological incident by asking the room whether anyone had ideas. I don't think he was joking. He also built the whole thing so that no blame attaches to anyone involved. Nobody's named except the manufacturer and the regulators, and the route the sources took from industry to a field in Herefordshire is deliberately left vague. That isn't squeamishness. The reasoning is explicit: identify and punish the person who did this, and the next person in that position doesn't come forward. Then the next set of sources goes somewhere far worse than a campsite that happens to have a nuclear engineer standing in it. You can watch it. It's worth 30 minutes: [The Orphan Source Incident](https://media.ccc.de/v/emf2026-46-1-the-orphan-source-incident). Hackaday [wrote up the follow-up](https://hackaday.com/2026/07/28/the-orphaned-sources-at-the-hacker-camp-what-happened-next/) too. ## The bit I was there for, allegedly I was on Stage A on the Friday at 17:40, for 22 minutes, on how North Korean IT workers try to get themselves hired into your company. The short version: some time ago I opened a few remote roles and was buried in applications. Thousands of them. After a while I noticed how many looked like each other, so I stopped hiring for an afternoon and started digging. Greenscreen setups and computer vision to get through identity verification. Laptop mules on US soil, so the machine you shipped sits exactly where you expect it to sit while somebody else drives it. VPNs and KVMs of varying quality doing the driving. The investigation this fed into ended up contributing to 29 property searches and 5 arrests. It's here if you want it. https://www.youtube.com/watch?v=QAJt7uoKhQw We also had a village. There was a venue on the official EMF schedule called the cside security village, which is a sentence I enjoyed reading more than I expected to. We ran a scavenger hunt across the site, "Find the Creatures Attacking the Web": 4 mythical creatures, each standing in for a different client-side attack. Find all 4 and you went into a raffle for a retro handheld running Linux. Marc, Jovian and Aarnav did most of the actual work. That's about 22 minutes of stage time and a tent. I spent the other 3 days walking around, which is the part I'd go back for. ## Where I landed I went in expecting to enjoy the spectacle. I came out thinking about the norms underneath it. The through line at EMF is that you open the broken thing and show people the inside. Dimitri opens up a flame unit that failed and walks a crowd through his own mistakes. Tryst gives a talk about a radiological incident on a campsite and builds it so that nobody involved gets identified. The whole schedule is people describing, in detail, the parts that didn't work. That's the same norm the security industry claims to run on and mostly doesn't. Disclosure only works if reporting isn't punished. Everyone agrees with that as a principle. Then a company finds something embarrassing about itself, and the incentive is to say nothing, ever, to anyone. Which is how the next 50 companies get to learn the same lesson individually and expensively. I don't think you get a culture like that from a code of conduct. You get it from 3,000 people who have all built something that didn't work the first time, standing in the same field, with nothing much to prove to each other. The talk was my excuse to go. Being there was the point. See you in 2028. --- ## How Minecraft raised a generation of engineers URL: https://simonwijckmans.com/writing/how-minecraft-raised-a-generation-of-engineers Published: 2026-08-09 I was 14 when I first watched a machine I was responsible for fall over in front of an audience. The console was printing the same line over and over, "Can't keep up! Is the server overloaded?", and about 30 people were standing frozen in a world I'd promised them would work. It was a school night. Nobody was going to fix it except me. I've been noticing something for a few years now, and it has become impossible to unsee. The people I meet who are genuinely good at infrastructure and security, the ones born somewhere after 1995, almost all did some version of this as teenagers. Minecraft servers, mostly. Sometimes Garry's Mod, sometimes a Teamspeak box, sometimes a private server for a game they couldn't afford to play properly. I don't think that's a coincidence and I don't think it's nostalgia either. What happened is that a block game accidentally became the most effective infrastructure and security curriculum a generation ever had, and it was free, and nobody designed it. ## The box It starts under a desk. You run the jar on the family laptop, your friends connect over the local network, and for about a week that's enough. Then someone's friend wants in, then someone posts it somewhere, and suddenly the laptop is a production system with an uptime expectation. So you rent a machine. And the machine arrives as an IP address, a root password, and nothing else. No interface, no wizard, no support engineer. I learned Linux because there was a black rectangle between me and the thing I wanted, and the only way through it was to type. I learned what a process was because one kept dying. I learned about screen and later tmux because closing the terminal killed the server, which took me an embarrassingly long time to work out. Then DNS, because typing an IP address is not a brand. Then the SRV record, because Minecraft ran on port 25565 and nobody was going to remember a port number. Then firewalls, because you eventually notice things knocking on ports you never opened. And backups. Everyone learns backups the same way, which is afterwards. I lost a world once, a real one, months of things people had built, and I remember the specific feeling of telling them. It wasn't a technical feeling. That's the part that stays with you: the outage has faces. ## 20 ticks The server tries to run 20 ticks a second. That number was my first service level objective, years before I knew the term, and I could feel a drop below it in my hands before any tool told me. The Java Virtual Machine was my first performance teacher, and it was a harsh one. You start by giving the heap more memory, because more is better. Then you give it all the system memory and discover the machine starts swapping and everything gets worse, which is the first time most of us learn that a system has parts that need room to breathe. Then the server freezes for 3 seconds at a time, on a rhythm, and you find out about garbage collection, and that a pause is not a crash but your players cannot tell the difference. Half of us ran the same long string of JVM flags, passed around forums, tuning the garbage collector for pause time over throughput. I copy-pasted it. I did not understand a single flag in it. What I did understand, eventually, was the shape of the thing: a runtime with knobs, tradeoffs between them, and no setting that's correct for everyone. Then you learn to profile, because guessing stops working. You generate a timings report and get a tree of where the tick actually went, and you find out that the lag everyone is complaining about is one plugin doing something expensive on an event that fires constantly. That's a debugging skill with a shelf life measured in decades. Measure, don't assume. It's the same lesson at every scale I've worked at since. ## The first time you get hit Everything is fine, and then nothing is. Players drop all at once. You can't reach the machine. And after a while your host emails you to say they've null-routed your IP address to protect everyone else on the rack, which is a polite way of saying the attack won. The thing that makes this different from every other outage is that this one has an author. It's a person. Usually it's someone you banned, or the owner of a competing server who wants your players to have a bad evening. I remember the shift in how I thought about systems after that. Up to that point failures were accidents, gravity, entropy. Now there was somebody on the other end who wanted this, and who would adapt. So you learn. Layer 4 against layer 7, because they don't feel the same and don't get solved the same. Putting a proxy in front so your real machine's address isn't the one in everyone's server list. Discovering that your origin leaked months ago through some old DNS record you forgot about, which is a lesson people are still learning at companies with security teams. It's worth being honest about how dark this got, because it isn't a fun anecdote. The Mirai botnet, the one that knocked a chunk of the internet offline in 2016, came out of exactly this scene. Paras Jha and Josiah White ran a company called ProTraf Solutions that sold DDoS mitigation, and part of the point of the botnet was knocking over rivals in the Minecraft server hosting market. They and Dalton Norman [pleaded guilty in December 2017](https://www.justice.gov/usao-ak/pr/justice-department-announces-charges-and-guilty-pleas-three-computer-crime-cases). Same curiosity, same skills, same market, pointed somewhere terrible. That branch was always available and some people took it. Years later I worked at a company that sells the mitigation. I won't claim that was a plan, because it wasn't. I do think that when you've been on the receiving end at 15, the product explains itself. ## Java, because there was no choice Nobody in that scene chose Java. Java was simply the language the plugin API was written in, so it was the language you wrote, and I think there's something underrated about learning your first language under duress rather than from a syllabus. You didn't start with a hello world. You started because a specific thing annoyed you and no existing plugin did it. So you learned what an event listener was, because someone placing a block had to be something your code could hear. You learned about the lifecycle because your plugin needed to load in the right order. You learned that the game's internals had version-specific names, and that every Minecraft update broke your code in a way that had nothing to do with you being wrong. Documentation barely existed, so you read other people's code, which is still the fastest way I know to learn anything. And you learned SQL the moment you realised player data has to survive a restart, which is the same moment everyone discovers that state is the hard part. None of this was structured. All of it stuck. ## META-INF I have to be honest about being on both sides of this one. There was a real economy in plugins. People sold them, for actual money, to teenagers running servers. And a jar file is just a zip file, which means anyone can open it and look, and once you've discovered that you cannot un-discover it. Point a decompiler at the classes inside and you get something close enough to the original source to read. So the sellers defended. Some phoned home to a licence server, keyed to your server's IP address, refusing to load if the answer came back wrong. And some signed their jars. That last one is where I learned the single most useful security lesson of my life. Inside a jar there's a directory called META-INF, and for a signed jar it holds the manifest plus the signature files. The JVM checks them, and if a class doesn't match its recorded digest, it refuses to load the thing. Which sounds airtight, until you notice the obvious. You delete the signature files. The jar is now simply an unsigned jar, and it loads perfectly happily. A signature proves a file wasn't modified. It doesn't stop anyone from removing the signature. The check and the thing being checked were both in my hands, and I got to decide which one survived. After that the arms race just escalates, in both directions, and I was on both. Obfuscation, so the decompiled output is a soup of single-letter names. Encrypted strings, so you can't grep for the licence URL. Checks scattered through the code rather than one honest boolean called something like isLicensed, because a single boolean is a single edit. Self-integrity checks, where the code hashes itself. And on the other side: patch the boolean anyway, point the licence domain at 127.0.0.1 in your hosts file, attach an agent that hooks the method, let the thing decrypt itself at runtime and then dump what it produced. I cracked plugins I couldn't afford. I also sold plugins and tried to stop other people doing to me exactly what I'd been doing to everyone else. That symmetry is the whole education. Sitting on the defending side, losing, over and over, teaches you something that no amount of reading gets across: any check that runs on hardware you don't control is not a control, it's a suggestion. You can raise the cost. You cannot win. I now run a company built entirely on that idea, that the code executing on someone else's machine is the part you can't take on trust. I didn't learn it from a book. ## Moderating The part that took the most out of me was the part nobody counts as engineering. A public server is a community, and a community of mostly teenagers is a moderation problem you did not sign up for. There's griefing, which is the easy version and the reason half of us learned what an audit log is. Then there's chat. People say things to each other in a text box at 2 in the morning, and some of it is nasty, and occasionally something appears that genuinely frightens a 15-year-old with no adult anywhere in the chain. So you write rules, and then you discover rules get lawyered, because someone will always argue that what they did was technically permitted. You build an appeals process, badly. You recruit staff, and you learn that a permission system is a trust system: give someone the ability to ban and some of them will ban their friends' enemies. Given the whole thing ran on volunteers with no way to fire anyone properly, you also learn how to have hard conversations early. And there was money. Donations, ranks, a store, chargebacks from a parent who saw a PayPal charge and had no idea what it was. That's fraud, disputes, refunds and customer support, at an age where I could not legally have a job. We were doing trust and safety before I'd ever heard the phrase. Badly, mostly, and entirely alone. ## When the platform changes its mind Then twice in one summer, the ground moved. In June 2014, Mojang enforced its end user licence agreement and gave servers until the 1st of August to stop selling anything that affected gameplay. Cosmetics were fine, advantages were not. A large part of how the whole server economy funded itself became non-compliant on a deadline, and people who'd built something real spent that summer rebuilding their revenue model or shutting down. Then in September, [a DMCA notice landed on CraftBukkit](https://github.com/github/dmca/blob/master/2014/2014-09-05-CraftBukkit.md). Wesley Wolfe had contributed something like 23,000 lines to the project under the GPL, Mojang's quiet ownership of the project had just surfaced, and he took the position that the licence terms hadn't been honoured. Whatever you think of the merits, the effect was that the foundation nearly every server in the world was built on went dark in a weekend. I was 17. The lesson arrived fully formed: everything I'd built sat on top of somebody else's platform, and their licence terms were load-bearing. Not their servers, not their API, their terms. Most people get taught that at 30 with a company and a payroll attached to it. ## Why any of this worked It was never really about Minecraft. It's about the shape of the thing. You had a real system with real users, and those users complained within seconds rather than in a quarterly survey. You had genuine adversaries who adapted to whatever you did. You had no budget, so every solution had to be understood rather than purchased. You had no mentor and no escalation path, so the only way out was through. And the consequences were social instead of financial, which is a strange kind of gift: enough pressure to make you care, not enough to ruin you. Most of all, you owned the entire stack. The kernel, the runtime, the application code, the database, the DNS, the payments, the community, the moral calls. I don't know where a 19-year-old gets that today in a job. Junior roles hand you one layer and a paved road across it, and the paved road is a good thing for shipping and a bad thing for learning what's underneath. While I believe this pattern is real, I want to be careful with it, because it describes a starting line and not a ceiling. It needed a computer at home, a decent connection, unstructured hours, and parents who tolerated a teenager on a server at midnight. Those spaces were also frequently hostile, and pushed out plenty of people who would have been brilliant at all of it. Some of the best engineers I've worked with never touched any of this. Every cohort had its own version anyway: BBSes, IRC bots, phpBB forums, private game servers, and today it's Roblox, FiveM and Discord bots. The sandbox changes. The shape doesn't. ## Where I landed If I want to know whether someone can actually operate a system, I've stopped asking what they studied. I ask what they ran before anyone was paying them to run it, and then I ask what broke, because that answer is never rehearsed and it tells you everything about how the person thinks when the thing is on fire and it's theirs. What we were really being taught, for 4 or 5 years, on machines nobody was paying for, is that no help was coming. Nobody was coming to fix it. That was the education. --- ## How to handle hair loss as a male in 2026 URL: https://simonwijckmans.com/writing/how-to-handle-hair-loss-as-a-male-in-2026 Published: 2026-08-01 A while back I went down the hair loss rabbit hole properly. Spend an hour online and you'll find shampoos, serums, rollers, supplements, oils, peptides, laser caps, influencers, and clinics all telling you they have the answer. They don't. There's no silver bullet here, and a lot of what's on offer is solving for the wrong problem entirely. Disclaimer: I'm not a doctor and this isn't medical advice. It's what I learned reading, and I've tried to be honest about where the evidence is strong and where it isn't. Anything below that needs a prescription needs a real doctor. If you want to do something useful about hair loss, start by working out what type you have. ## It isn't one thing People talk about balding like it's one condition. Genetics and androgenetic alopecia is one category. Stress-induced shedding, telogen effluvium, is another. Autoimmune attacks on the follicle, alopecia areata, is a third. Iron deficiency and other boring nutritional problems sit somewhere else again. Every cause requires a different treatment. In many cases, the best you can do is slow the process down. ## Genetics An enzyme converts testosterone into DHT, DHT binds receptors in susceptible follicles, and each hair cycle comes back a little finer and shorter until it stops being a real hair. That shrinking is called miniaturisation. How susceptible you are is mostly inherited, somewhere between 60 and 80 percent by most estimates. There's an old rule of thumb about looking at your mother's father. The androgen receptor gene, the biggest single genetic player here, sits on the X chromosome. You have one X and you got it from your mother, who got one of hers from her father. Your own father, by definition, handed you a Y and no X at all. That's where the folklore comes from. But treat it as a signal, not a prophecy. Your mother's two X chromosomes shuffle before she passes one on, so the X you ended up with is only about half your grandfather's. And of the 600-odd genetic locations mapped so far, only 26 sit on the X. Your father's hairline matters too, and the number of bald relatives on both sides predicts better than any single designated ancestor. ## Stress Telogen effluvium is usually triggered by a big physiological hit: a high fever, surgery, a rapid drop in weight, a new medication, a thyroid problem, low iron… Severe psychological stress is on every list too, though the evidence there is softer than most people assume. The annoying part is the delay. It shows up months after the event, so people miss the connection and go looking in the wrong place. A very 2026 version of this: GLP-1 drugs. There's now decent evidence linking semaglutide and tirzepatide to shedding, mostly through the rapid weight loss rather than the drug itself. If you started one and your hair began coming out four months later, that's probably not pattern baldness announcing itself. A shed usually settles once the trigger is gone. The catch is that it often exposes pattern loss that was already underway, and that part doesn't recover by waiting. ## Autoimmune In alopecia areata, a type of white blood cell attacks the follicle directly. It usually shows up as discrete round patches rather than general thinning, and it's diagnosed by a dermatologist looking at your scalp, not by you squinting at the bathroom floor. This is also the one area where the last few years genuinely changed things. There are now 3 approved oral drugs for severe alopecia areata, all JAK inhibitors, and a meaningful share of people get most of their hair back on them. The headlines confuse this constantly: they do nothing for pattern baldness. When you see "FDA approves new hair loss drug" in a news alert, this is almost always what it's about, and it almost certainly isn't about you. ## Iron Iron comes up constantly in hair forums, and it is worth ruling out, because it's cheap to check and easy to fix. Just don't try to diagnose it from how you feel. The symptoms that actually point at low iron are unrelenting fatigue, getting winded on stairs you used to manage, restless legs at night, and, oddly specific but a real tell, craving and crunching ice. Feeling lightheaded or seeing black spots when you stand up too fast is usually a blood pressure dip, not iron. Worth knowing that nearly all of the iron and hair research is in women, where deficiency is genuinely common. In men it's much rarer, and the evidence that topping up regrows anything is thin even in women. So don't take iron on spec. Get ferritin measured instead, and if a man does turn out to be deficient with no obvious explanation, that's worth chasing down well beyond your hairline. I think the reason this whole category gets skipped is simple: checking your health is less marketable than buying a branded bottle with the word 'advanced' on it. ## DHT and why it's so confusing DHT doesn't treat all hair the same way. If you're genetically predisposed, the hair on the top and front of your scalp gets punished by it. The rim around the back and sides doesn't. Those follicles are androgen resistant, and they keep that resistance even after a surgeon moves them to the top of your head, which is the entire reason transplants work at all. Meanwhile beard and chest hair respond to the same hormone by getting thicker and darker. So the hormone grows hair in places you may not care about while taking it off the place you do. ![A side profile marking the 3 zones: the top and front punished by DHT, the back and sides resistant even after a surgeon moves them, and the jaw where the same hormone thickens hair](/images/hair-loss-dht-map-figure.svg) This one took me a while to get. The obvious explanation, that a balding scalp has more DHT machinery, is wrong: beard follicles have more enzyme activity and more receptors, and they thrive. The difference is in what each follicle does with the signal. There's no line across your face separating the two behaviours, it's a property baked into each follicle. DHT matters from puberty onward, which is why this almost never starts in children. But later-age hair loss can still absolutely be DHT-related. Genetics and follicle sensitivity matter far more than calendar age. ## What actually has evidence The FDA hasn't approved a new drug for pattern hair loss since finasteride in 1997. Everything else you're being sold sits in one of three other buckets, and I think this distinction is the most useful thing a non-doctor can hand you. Approved means a regulator reviewed it for this specific use. Cleared, which is what laser caps are, is a much lower bar. Off-label means the drug is approved, just not for your hair. Compounded means a pharmacy mixed it and nobody reviewed it at all. You'll be sold products from all four categories in the same afternoon, usually without being told which is which. ### Minoxidil If your follicles are still there but cycling out of the growth phase too early, minoxidil can help hold them in it. The blood flow explanation you hear everywhere is mostly folklore. It's a prodrug, meaning an enzyme in the follicle has to convert it before it does anything. That's part of why some people simply don't respond, and never find out why. The liquid is the drug dissolved in alcohol and propylene glycol, which is why some people end up with an itchy, flaking scalp and blame the drug itself. The foam drops the propylene glycol and is usually the answer there. The bigger mistake is application: it has to land on the scalp, not on your hair. A lot of people think they're using it correctly when they're mostly conditioning their hair with it. That's part of why low-dose oral minoxidil has taken off, and it's the biggest practical change in this field since 2023. One pill instead of a twice-daily ritual, and there's now a proper international expert consensus behind it. While that's a real shift, it's still a blood pressure drug used off-label, and no regulator has approved it for hair. That's a conversation to have with a doctor. Set your expectations either way. Roughly a third of men get regrowth they'd notice in a mirror, and a larger group just gets a slowdown. It's a tap, not a cure. Stop, and the benefit goes within months. ### Finasteride and dutasteride If your loss follows the male pattern, receding temples and a thinning crown over years, then by definition it's androgen driven, and this is where finasteride and dutasteride make sense. They work by reducing the hormonal pressure that's shrinking the follicle. They're mostly a hold rather than a restoration, and the trial numbers are good on exactly that: 83% of men on finasteride had no further loss at 2 years, against 28% on placebo. Give it 6 to 12 months before you judge anything, and expect a temporary increase in shedding early on. Dutasteride is the stronger of the two and now tops the 2025 comparative analyses, though in the West it's used off-label. Topical finasteride is what people reach for when they're nervous about systemic side effects. Be careful with that reasoning. In its own trial it still cut circulating DHT by about 35%, against roughly 56% for the tablet. That's reduced exposure, not zero. And in the US there's no approved topical finasteride at all. Everything sold is compounded, and the FDA issued a specific alert about that in April 2025 after a run of adverse event reports. That's mostly what the subscription telehealth companies are selling you. They're convenient and they do prescribe real approved drugs, but they make their margin on the compounded ones. In July 2026 the FTC and 2 states sued the biggest of them. In 2025 European regulators finished a formal safety review and added suicidal ideation as a recognised side effect of finasteride, and the UK strengthened its warnings again in May 2026 with mandatory patient alert cards. Most reported cases involved the 1mg hair loss dose specifically, not the higher prostate dose. This is not a withdrawal and the drug is still first-line. But any doctor putting you on it should raise it with you, and if your mood changes you stop and you call them. The sexual side effects are what everyone asks about. In the registration trials around 3.8% of men reported one, against 2.1% on placebo, so the drug-attributable excess is somewhere around 1 or 2 men in 100. You'll also run into "post-finasteride syndrome" within about one search. My honest read is that the evidence is poor in both directions, and I wouldn't let either camp settle it for you. Finasteride roughly halves your PSA reading. If you ever get a prostate check your doctor needs to know you're on it, because a normal-looking number can be a genuinely abnormal one. And both drugs can harm a male fetus, so broken tablets and topical residue on pillowcases and towels matter if there's any chance of a pregnancy in the house. None of this is universal. If your issue is autoimmune, stress-related or nutritional, a DHT blocker isn't an all-purpose answer. It's aimed at a mechanism you don't have. ### The maybe pile PRP, or platelet-rich plasma, is used to improve the environment around the follicle, and some people clearly benefit. If you're going to do it, my view is that you don't do it casually: 3 or 4 sessions about a month apart, then top-ups every 3 to 6 months, indefinitely. The effect fades when you stop. It's an ongoing cost, not a course you finish. Copper peptides probably do something small for some people, but I won't pretend the proof is solid. Microneedling turned out more interesting than I expected. The channels dramatically increase how much topical minoxidil gets absorbed, and that's the real reason to bother. But this is also a category where the internet has convinced people that if a little is good, more must be better. That's how people make things worse. Done badly it causes tram-track scarring and pigment changes that don't undo themselves, and going deeper than about a millimetre doesn't help. Laser caps are the one I feel bad about lumping in with the junk earlier. Several double-blind sham-controlled trials show a real improvement in density. It's a genuine result, but they're cleared rather than approved, the trials are short and mostly manufacturer funded, and nothing tells you which of the 30-odd devices is worth buying. Rosemary oil deserves a mention because everyone brings it up. The viral evidence is a single 2015 trial that found no difference between it and 2% minoxidil. That's weaker than it sounds: there was no placebo group, so nothing proves either arm beat doing nothing. ## When you get to a transplant, treat it seriously Once follicles have properly given up, no drug brings them back, and surgery is the only way to put hair where there is none. But thinning isn't gone. Miniaturised follicles are still alive and are exactly what finasteride and minoxidil act on, so drugs first and surgery later is almost always the right order. You'll be sold method names: FUE, DHI, sapphire, robotic. Most are the same operation with a different instrument at one step. What actually decides your result isn't on the brochure: how many follicles get damaged during extraction, and who is physically holding the tools. Start with the punch, because that's the number I'd actually ask about. It's the cylindrical blade that cores each follicular unit out of the back of your head. It runs somewhere between 0.7 and 1.2mm across, with 0.9mm the usual workhorse for scalp hair. Every tenth of a millimetre is a trade. Go wider and you cut fewer follicles in half, but you take more tissue and leave more scar: a punch 10% narrower removes about 19% less skin per graft. Go narrower and the donor area heals close to invisibly, while the margin for error shrinks and a mediocre operator starts slicing through the things they're trying to harvest. ![Three punches drawn to scale, 0.7mm, 0.9mm and 1.2mm, each around the same follicular unit](/images/hair-loss-punch-sizes-diagram.svg) Diameter isn't the whole story either. In one small study using the same 0.9mm punch with 3 different tips, transection ran at 23.9% sharp, 18.8% serrated and 14.5% blunt. The shape of the cutting edge moved the damage rate by nearly 10 points, before anyone's skill entered into it. At the other end of the operation, the recipient sites should be cut to fit the graft going into them. That's roughly 0.6 to 0.8mm for a single hair, and wider for 3 and 4 hair units. Sites that are too big for their grafts damage the blood supply the graft has to survive on. Who's holding the tools is where this market gets ugly. A lot of people fly to Turkey, get pushed through a clinic as fast as possible, and are back out the same day. I understand why, it's cheaper and heavily marketed. I still think it's often a bad setup, and in 2026 that's no longer just an opinion about aesthetics. 2 British medical tourists died in Istanbul in 2025, one of those cases investigated as possible reckless homicide. The international hair restoration society estimates that 15 to 20% of Istanbul clinics aren't properly licensed. While there are genuinely good surgeons in Turkey, you're shopping in a market where that is the failure mode. Your donor area is also finite, which is why treating the first transplant as a cheap experiment is shortsighted, and why surgeons want you past about 25 with stable loss. A Norwood 2 at 22 can be a Norwood 5 at 35, and you can't design a hairline for a pattern that hasn't finished declaring itself. ![The same head at Norwood 2 and at Norwood 5, 13 years apart](/images/hair-loss-norwood-figure.png) A transplant isn't an exit from the medication. Transplanted follicles are DHT resistant, the native hair around them isn't. Stop finasteride and the transplanted hairline stays while everything behind it keeps receding, and you end up with an island of hair and a gap behind it. So don't shop for this the way you'd shop for a budget airline ticket. What I'd want is a doctor with a real track record, using the thinnest instruments they can responsibly handle, who can tell you their own transection rate without going to check. Ask who physically does the extraction and cuts the sites. The same society that counted those unlicensed Istanbul clinics is explicit that harvesting, hairline design and site creation are the doctor's job. In the clinics it warns about, a technician does all 3. I'd also avoid clinics that lead with the machine. Being honest about the evidence, it doesn't back me up on the part you'd expect. In a small split-scalp trial the robot's transection rate was no worse than an experienced surgeon's on the other side of the same head. It did discard about twice as many follicles. My objection isn't that the robot cuts badly. It's that the more industrial the whole thing feels, the more of your result is being decided by whoever was cheapest to have in the room. ![Two hairlines: one a ruled straight line with identical 3-hair grafts on a grid, the other with no line at all, single hairs in front thinning forward](/images/hair-loss-hairline-diagram.svg) You also don't want a result that leaves you looking like a Playmobil character. If the hairline is a straight ruler edge instead of an irregular one, if there's no soft feathered transition, if there are multi-hair grafts sitting in the front row, then congratulations: you paid for permanence and got a costume. A good transplant shouldn't announce itself. ## What's coming Clascoterone, a topical that blocks the androgen receptor in the scalp directly, finished phase 3 trials in late 2025 and would be the first genuinely new mechanism in 30 years. It hasn't been filed with the FDA yet, so realistically it's 2027 or 2028 before you could buy it. Hair cloning, meanwhile, is further away than it was in 2023, not closer. Stemson shut down in December 2024, dNovo has gone quiet, RepliCel delisted, and the Japanese programme people keep citing has slipped to 2027 at the earliest for a first human trial. If someone tells you regenerative hair is 5 years out, hold on to the fact that they've been saying that for a decade. ## Where I landed If you're worried about hair loss, start by figuring out what's happening. If it's DHT, look at the treatments that address DHT. If it's a shed, treat whatever caused the shed. If it's autoimmune or nutritional, the answer sits somewhere else entirely and no serum is going to find it for you. And if the damage is already done, be honest about that too. Sometimes the only durable answer is a well-executed transplant by someone who knows exactly what they're doing. That's not a fun answer. It's just an honest one. --- ## How Peter R de Vries inspired me URL: https://simonwijckmans.com/writing/how-peter-r-de-vries-inspired-me Published: 2021-06-18 When doing things on my computer that don’t require my full attention I would usually play something in the background. Music, Netflix, sometimes YouTube. When I was 16, without knowing what to expect, I moved onto another series: ‘Peter R de Vries: Crime reporter’. Each of his episodes started with the following statement: ‘The program that investigates, exposes, indicts, defends and tonight…’. And while I agree with that statement I believe there is a significant bullet point he failed to mention. “Inspires”. - Solving cold cases. Picking up where others gave up and making the case/project feel like your own is a skill best mastered by a rare combination of driven and beyond loyal people. This is a rare skill and while some people have it in them, this mentality sits at the core essence of someone’s personality and can’t be easily taught at a later age. This is a superpower. - Looking for different angles. There are many different ways of looking at a situation, by only exploring one angle you miss out on a lot of information and opportunities. Look for other angles. - When exploring angles, you often end up having to make some level of assumptions. The data often doesn’t exist yet or would require a significant amount of time to gather. But be aware of your assumptions and don’t allow them to influence your way of reviewing that angle when you have exact data. - In a broken system hard work does not necessarily pay off. So be wary of what you are trying to achieve. If doing hard work satisfies you, then maybe you don’t need the system to recognize it. Sometimes your hard work is part of a bigger goal. - The personality trait of ‘bite and don’t let go’ can lead to some amazing successes. In school I was taught this is a bad personality trait… This proves how a small number of people are capable of making things happen for the better. - Peter didn’t solve every cold-case he ever investigated. In fact, only if he solved a small fraction of them. it was still worth it. If you aim high enough a partial success can still be of significant impact. Peter’s story came to a brutal end but hopefully his legacy will live on in the next generations. --- ## What I learnt from Stephen Hawking URL: https://simonwijckmans.com/writing/what-i-learnt-from-stephen-hawking Published: 2021-03-18 5 years + a few days ago, on the 14th of March 2018 the iconic Stephen Hawking died. Below are 5 life lessons I have learnt from him. - At the age of 21 he was diagnosed with a rare disease called ALS. Despite of the diagnose he went on to do what he loves. No bump in the road is big enough to stop you from your life goal. - Normally people with ALS have a lower life expectancy. Stephen lived with ALS for more than 50 years. He lived on till his last day doing amazing work. Being able to do what you love most likely has positive impact on your health. - In 1985 on a trip to Geneva he caught pneumonia and was put on life support. Doctors performed a tracheotomy. As a result he lost the ability to speak. Stephen got a voice from Intel allowing him to speak 15-20 words per minute. Communication is a powerful tool. Choose your words with care, keep it short. - In 2007 Stephen Hawking fulfilled a lifelong dream, to experience weightlessness. Don’t let your situation affect your dreams. - Finally. Stephen has published 15 books and 55 papers, he gave humanity a lot of wisdom in his lifetime. Even though he has faced so many odds in his life he didn’t give up. Next time you feel like you are being negatively impacted by anything think of Stephen. His drive and hunt for impact on society has always inspired me and will continue to motivate me for the rest of my life. If you can dream it, you can do it.