Articles
Guides, tutorials, and deep-dives on the tools we build at Toolhub.
APR vs APY: the compounding gap that quietly costs you
APR and APY measure the same thing β an annual interest rate β but one includes compounding and the other doesnβt. The gap between them grows with the rate and compounding frequency, and banks consistently advertise whichever number looks better for their side of the transaction. This article breaks down the formula, shows real dollar differences, and explains how to compare offers on equal footing.
Dice probability: why 2d6 isn't the same as 1d12
1d12 and 2d6 both average 6.5 and 7 respectively in their common uses, but the probability distributions are fundamentally different. 1d12 is uniform (equal chance of every outcome), while 2d6 produces a bell curve centred on 7. This article maps the full distributions, calculates variance and standard deviation, works through expected damage per round for D&D weapons, and explains how game designers use these properties to create different gameplay feels.
Grading on a curve: the math, and when it backfires
Grading on a curve adjusts raw scores so the distribution matches a target β usually a bell curve or a fixed class average. There are at least four common methods (bell curve, linear scaling, square root, flat bonus), each with different mathematical properties and different effects on the grade distribution. This article works through the actual formulas with real numbers, then examines when curving helps students and when it creates perverse incentives.
Image compression: lossy vs lossless, and when each one wins
Lossy compression (JPEG, WebP lossy, AVIF) discards visual information that human perception is least sensitive to, achieving dramatic file size reductions at the cost of irreversible quality loss. Lossless compression (PNG, WebP lossless, AVIF lossless) preserves every pixel perfectly but compresses less aggressively. This article explains the mechanics behind each approach, shows real file size comparisons, debunks the 'quality 80' myth, and provides a practical decision tree for choosing the right compression for each use case.
Reading an invoice like an accountant: the line items that matter
An invoice is a structured document with specific fields that each serve a legal or accounting purpose. Most recipients look at the total and pay it, but the line items, tax calculations, payment terms, and reference numbers are where errors, overcharges, and disputes hide. This article walks through the anatomy of a proper invoice, explains what each section should contain, and identifies the red flags that indicate something needs a closer look.
Regex lookarounds: the lookahead/lookbehind parts people avoid
Regex lookaheads and lookbehinds let you match text based on what surrounds it without including the surrounding context in the match. This makes them essential for password validation, log parsing, find-and-replace in IDEs, and scraping. This article covers the four lookaround types with practical patterns for each, explains the engine-specific limitations that trip people up, and shows when alternatives (capture groups, \ K) are simpler.
Rental yield vs cap rate vs cash-on-cash: three numbers, one property
Rental yield, capitalization rate, and cash-on-cash return are the three most common metrics for evaluating rental property investments. Each answers a different question: yield measures gross income relative to property value, cap rate measures operating income independent of financing, and cash-on-cash measures actual cash flow relative to the cash you invested. This article defines each metric, works through a consistent example showing how they diverge, and explains when to use which.
Placeholder images: when lorem-picsum isn't enough
Services like lorem-picsum hand you a random remote photo, which is perfect for a quick mockup and wrong for almost everything after that. This walks through where random image placeholders fail β non-deterministic layouts, external requests, offline builds, exact dimensions β and why a labelled inline-SVG placeholder is the better default for real prototyping.
Token counting: why your prompt costs more than the word count suggests
The gap between word count and token count is real, measurable, and predictable. BPE tokenizers split text into subword units based on training-corpus frequency β not linguistic boundaries. Code identifiers, non-English scripts, repeated JSON field names, and invisible overhead like tool schemas all push the real cost above the "roughly one token per word" estimate.
SQL formatting: why your team's queries are unreadable
Correct SQL isn't always readable SQL. This piece covers the five habits that silently make queries unmaintainable: SELECT *, cryptic table aliases, magic constants in WHERE clauses, compressing logic onto single lines, and nested subqueries where CTEs belong.
Currency conversion fees: 5 indie payment platforms compared
Payment platforms bury currency conversion costs in the exchange rate spread, not the headline percentage. This compares how Stripe, PayPal, Wise, Paddle, and Lemon Squeezy handle FX markup as of September 2026, explains the mid-market rate and the double-conversion trap, and shows how to check what a cross-currency sale really costs you.
Procedural level design: the math behind βrandomβ that feels right
Pure coin-flip randomness produces ugly, unplayable levels. This piece unpacks the layered techniques β Perlin noise, BSP trees, weighted tables, critical-path guarantees β that make procedural generation feel authored. Concrete examples from Spelunky, Minecraft, and The Binding of Isaac.
CSV edge cases: the commas, quotes, and newlines that break your parser
"Split on commas" is where most CSV bugs are born. This walks through the three edge cases that break naive parsers β commas inside fields, embedded quotes, and newlines inside a value β explains what RFC 4180 actually specifies for quoting and escaping, and shows how to round-trip data safely instead of silently shifting columns.
Temperature and top-p: what the sampling knobs actually do
Temperature and top-p both control how random an LLM's output is, but they do it differently β one reshapes the whole probability distribution, the other trims its tail. This explains what a model is really doing at each step, what each knob changes, why you usually tune one and leave the other alone, and how to test the effect instead of guessing.
The invisible ASCII control characters still haunting your data
ASCII's first 32 positions are non-printing control characters, and a few of them still cause real bugs today. This covers what control characters are, the carriage-return/line-feed split that breaks cross-platform files, the null and tab traps in data, and how to find invisible characters when text misbehaves.
BMI: what it actually measures, what it misses, and when to use something else
BMI was designed to describe populations, not diagnose individuals. This covers what it was built for, where it genuinely holds up, where it consistently fails (athletes, older adults, ethnic variation), why waist circumference belongs alongside it, and the body-composition alternatives worth knowing.
Cap rate: what it actually measures, what it misses, and when to stop trusting it
Cap rate is a relative benchmark, not an absolute verdict. This covers what it genuinely tells you, what it deliberately ignores (leverage, appreciation, capex), the compression trap that makes a falling cap rate look like a bad deal, and the hold periods where IRR is the number you actually need.
Color contrast for accessibility: the WCAG rules that actually matter
A focused guide to WCAG's contrast-ratio rules: the three thresholds (and why designers only remember the first), what counts as a UI component, the hover/focus state that quietly fails, the logo exemption people misread, and where APCA and WCAG 3.0 are heading.
Cron syntax: the guide you actually need (not another "five fields" rehash)
A working developer's guide to the cron edge cases that actually cause incidents: why 0 and 7 both mean Sunday, why */5 and 0/5 aren't always the same, how DST breaks a 02:30 job, why server timezone is the silent default, and the AND-not-OR trap in the day-of-month/day-of-week intersection.
CSS gradients that don't look cheap
A default two-colour CSS gradient often looks cheap for a specific, fixable reason: the colours pass through a dead grey midpoint. This covers why that happens, how multi-stop gradients and thoughtful hue paths avoid it, and how pairing a gradient with a matching shadow reads as polished.
The discount math that quietly kills your profit
Discounts come off the price, but they come straight out of the margin β and the margin is a much smaller number, so the damage is nonlinear. This covers why a discount hits profit far harder than it looks, the extra volume needed to break even, and when discounting is still the right call.
MB vs MiB: why your new drive is smaller than the box says
The gap between a drive's advertised size and what your OS reports is the 1000-vs-1024 problem. This explains the two definitions of kilo/mega/giga, why storage makers use one and operating systems the other, where the missing ~7% goes, and the MiB units that were invented to end the confusion.
Gross rent multiplier: the fast filter serious investors use before cap rate
Gross rent multiplier is the screening tool that comes before cap rate: purchase price over annual gross rent, one division, no expenses. This covers how to read it, why market baselines vary enormously, using it as a filter, what it safely ignores, and how it bridges to cap rate.
HTTP status codes that actually matter (and the ones people misuse)
A working guide to the HTTP status codes that matter in practice: how the five classes work, the 401-vs-403 distinction that leaks information when confused, the redirect codes that silently change your HTTP method, why 429 deserves more use, and why returning 200 for an error is a real bug.
Inflation and real returns: the number your savings account hides
The gap between the interest rate you're quoted and what your money can actually buy is the difference between nominal and real returns. This covers how inflation erodes purchasing power, the simple real-return subtraction, why cash 'safety' can be a slow loss, and how it compounds over a retirement horizon.
JSON Schema in production: validation that actually catches bugs
The gap between a documentation schema and a validation schema is where bugs live. This covers what a production-grade schema enforces, why additionalProperties:false turns silent acceptance into useful errors, the surprise that format is advisory by default, composing schemas with $ref and $defs, and generating typed models from a schema.
JWTs are not sessions: the security mistake that's everywhere
A JWT is a signed claim, not a session. This draws the line: what JWTs are genuinely for, why they can't be revoked before expiry without giving up their only advantage, why the payload is readable by anyone, why long expiries are a trap, and the cases where a JWT really is the right tool.
The Luhn algorithm: how a 1954 checksum still guards every card number
The Luhn algorithm is the check-digit formula behind card numbers, IMEIs, and more. This explains what it does, the simple doubling-and-summing math, exactly which errors it catches (and the one it misses), and the crucial distinction between 'passes Luhn' and 'is a valid, real card'.
MIME types: the header that decides whether your file downloads or executes
MIME types tell a browser what a byte stream actually is, and getting them wrong ranges from annoying to a security hole. This covers what a media type is, why the browser trusts the header over the file extension, the XSS risk of a mislabelled upload, and what nosniff does.
Settling group debts with the fewest payments
Splitting a shared cost fairly is one problem; settling the resulting web of who-owes-whom with the fewest transfers is a different one. This covers why naive settlement creates too many payments, the netting idea that collapses them, a worked four-person example, and where the math gets genuinely hard.
The minimum payment trap: how revolving debt keeps you paying for decades
Paying the minimum on a credit card isn't a modest version of paying it off β it's a mechanism that can stretch a balance across decades and multiply what you repay. This covers how the minimum is calculated, why it shrinks as you pay, the decades-long payoff it produces, and how to escape it.
What mortgage affordability calculators won't tell you
Affordability calculators measure PITI and stop there. This walks through the six ownership costs they leave out, the income-stability haircut that hits self-employed and variable-income buyers, how to build a corrected affordability number from the calculator's output, and when the rent-vs-buy math actually favours renting.
camelCase, snake_case, kebab-case: naming conventions and why they matter
The major casing conventions map to specific ecosystems and rules, not personal taste. This covers where each convention belongs (and why), the case-sensitivity bugs that bite when they're mixed, and why consistency inside a boundary matters more than which style you pick.
Hex, binary, and why developers still count in base 16
Base 16 and base 2 are everywhere in computing for one good reason: they line up with how bytes work. This explains what a base actually is, why one hex digit equals exactly four bits, why colours and addresses use hex, and how to read between the bases without memorising tables.
Open Graph tags: why your links look broken when shared
When a shared link renders as a rich card β image, title, description β that's Open Graph doing its job. This covers what the protocol is, the four tags you actually need, why the image so often fails (dimensions and caching), and how to debug a broken preview.
OpenAI vs Anthropic API: what developers actually need to know when switching
A practical map of the gaps that cause breakages when moving between the OpenAI and Anthropic APIs: where the request shapes diverge, why a system message can silently disappear, the different streaming event formats, tool-use naming, and why token counts (and therefore cost) aren't equivalent for the same text.
Passkeys vs passwords: what actually changes
Passkeys replace the shared-secret model of passwords with public-key cryptography. This explains what a passkey actually is, why there's no secret for a server to leak or an attacker to phish, how the sign-in flow works, the honest trade-offs around device loss and sync, and where passwords still hang on.
QR codes in 2026: what actually works, what's spam, and when they're the right tool
A practical guide to QR codes that respects your reader's intelligence: the density/error-correction trade-off, where physical-to-digital bridging genuinely works, where QR codes are pure friction, the static-vs-dynamic decision, and the encoding types beyond plain URLs.
RAG quality problems that aren't chunk size
Once your chunking is sane, the next RAG failures hide in the rest of the retrieval path: the query/document phrasing mismatch, pure vector search missing exact terms, no reranking of top results, and answers that aren't grounded in what was retrieved. This maps those failure modes and the fixes.
Readability scores for content and AI: the metric most teams ignore
Readability scores have found two modern uses their inventors never imagined: matching content to an audience's reading level for SEO, and filtering low-quality text out of LLM training corpora. This covers what the scores actually measure, their real limitations, and how both new contexts use them.
Regex: the 20% that handles 80% of real problems
A practical guide to the regex that actually appears in real code: the handful of characters you use constantly, the right level of precision for email and phone validation, why URL 'validation' is usually a false goal, named capture groups, and the one lookahead pattern worth learning.
Salting and peppering: why hashing passwords isn't enough
Hashing a password is step one, not the finish line. This explains why an unsalted hash database falls to precomputed rainbow tables, what a per-user salt actually changes, why identical passwords should never share a hash, and where a pepper adds a further layer.
Subnetting without the headache: CIDR notation explained
CIDR notation looks like magic until you see it in binary. This explains what the slash number actually counts, how to read the address range from it, why /24 and /16 are so common, and the off-by-one traps (network and broadcast addresses) that catch people setting up a VPC.
SVG vs PNG: the decision most people make backwards
The SVG-vs-PNG choice is usually framed as vector-vs-raster, but the decision that actually matters is rendering context. This covers when SVG wins cleanly, when PNG is the right call (email, especially), the three SVG embedding contexts that each break something different, and why exported SVGs are bloated.
Unix timestamps vs ISO 8601: the practical guide for developers who keep getting them mixed up
The two dominant time formats and where converting between them goes wrong: what a Unix timestamp really is, the ISO 8601 variants that are safe versus ambiguous, the JavaScript date-parsing gotcha, the milliseconds-vs-seconds factor-of-1000 bug, and the Y2K38 overflow.
Timezone management for global teams: the errors that kill async
A team-process guide to the timezone errors that sabotage distributed work: the store-UTC rule and its one real exception, the weeks-long DST gap between regions, why ISO 8601 without an offset is a bug, the "noon everywhere" fallacy, and specifying timezone in scheduled jobs.
Unicode for developers: why your string length function is lying to you
The distinction between code points, code units, and grapheme clusters explains a whole family of string bugs: why JavaScript counts emoji as length 2, why two identical-looking strings can be unequal, why combining characters break naive truncation, and what to count when a limit actually matters.
URL anatomy: the parts most developers get wrong
A tour of the URL parts that actually trip people: the full anatomy including the dangerous bits people skip, origin versus authority and why CORS cares, when percent-encoding is required versus optional, why the fragment never reaches your server, and why you should never assume query-string order.
UUID versions: which one to use and when (it actually matters)
A map of UUID versions to real use cases: why v4 random keys fragment database indexes at scale, why v7 is the right default for new projects, the privacy problem baked into v1, and when deterministic v3/v5 hashes are exactly what you want.
YAML: the config format that will surprise you eventually
Five YAML behaviours that are consistent with the spec, absent from onboarding, and responsible for a disproportionate share of config bugs: the Norway problem, implicit number typing, the two-flavour multiline strings, anchors as shared mutable state, and why a single tab breaks everything.
Avalanche vs snowball: settling the debt-payoff debate
The avalanche method attacks the highest-APR debt first and pays the least total interest. The snowball method clears the smallest balance first and delivers early wins that keep people motivated. This article works through a concrete example of both, looks at the behavioural-finance case for snowball, and explains how to decide β because the mathematically optimal plan only helps if you finish it.
Critical hit math: when crit chance lies to you
Crit chance and crit multiplier combine into a single expected-value multiplier that tells you the real damage gain from a build. But expected value hides variance, and variance is what makes a 25% crit build 'feel' unreliable. This article covers the EV formula, the gambler's-fallacy trap around streaks, how 'pity'/pseudo-random systems smooth those streaks, and how crit interacts with attack speed and multi-hit β with a worked DPS table.
Splitting expenses with co-founders: 6 honest methods
Equal split, income-proportional, usage-based, equity-weighted, itemised, and running-tally settle-up are the six honest ways to divide shared costs among co-founders, partners, or housemates. Each has a situation where it's clearly fair and a situation where it breeds resentment. This article covers the math behind all six and shows how a single $600 bill splits differently depending on which one you pick.
Readability scores: what Flesch-Kincaid actually tells you
Flesch Reading Ease and Flesch-Kincaid Grade Level are the two most-cited readability formulas. Both are computed from just two surface features: average words per sentence and average syllables per word. This article states the real formulas, explains what they do and don't measure, shows how they're gamed, and maps out when a readability score is a legitimate tool versus a misleading one.
JWT decoding for non-cryptographers
A JWT is three base64url-encoded parts β header, payload, and signature β joined by dots. The header and payload are encoded, not encrypted, so anyone can decode and read them. Only the signature tells you whether the token is genuine. This article explains the structure, the standard claims, how HS256 and RS256 signatures work conceptually, and the mistakes that turn a token into a security hole.
Password length vs complexity: which actually wins
Password strength comes from entropy β the number of guesses an attacker must make. Entropy grows with length far faster than with character-class complexity, which is why a long passphrase beats a short scrambled string. Forced complexity rules backfire by producing predictable patterns, and NIST's modern guidance now favours length, drops mandatory rotation, and screens against breached-password lists. This article walks through the math and how hashing protects stored passwords.
Diffing prompts at scale: when small changes flip behavior
Large language models are sensitive to tiny prompt changes: a stray "always," a reordered few-shot example, or trailing whitespace can flip behavior in ways that are hard to trace. This article explains why prompts are brittle, makes the case for version-controlling them like source code, and lays out a controlled A/B process β fixed eval set, temperature 0, one variable at a time β plus a regression-testing workflow so teams know exactly which edit caused a change.
When to refinance: the breakeven math
Refinancing replaces one loan with another, and it is not free. The breakeven point β closing costs divided by monthly saving β tells you how many months you must keep the new loan before it pays for itself. This article covers the core formula, why resetting the amortization clock can raise your total interest even at a lower rate, cash-out versus rate-and-term, and a worked example. It is honest about when refinancing is the wrong move.
RPG growth curves: linear, exponential, and the math behind 'one more level'
An RPG's levelling curve is a design decision disguised as a number. Linear curves feel steady but flatten out; exponential curves create the 'one more level' pull but risk grind; quadratic sits in the middle. This article walks through the three main curve shapes, how they interact with damage scaling and enemy HP, and a worked example table so hobbyist designers can pick a curve on purpose instead of by accident.
Building rubrics that catch AI-written essays
Most essay rubrics grade fluency, structure, and grammar β precisely the traits an LLM produces effortlessly. This article explains why generic rubrics reward AI-written work, how to reweight criteria toward process and specificity (real citations, local examples, in-class drafts, oral defence), and why AI-text detectors are too unreliable to grade on. It includes a sample criterion-by-criterion reweighting table teachers can adapt.
SVG optimization: how small you can go without breaking the icon
Hand-authored and editor-exported SVGs are full of metadata, over-precise path data, unused defs, and inline cruft that adds no visible value. Removing it is safe and routine. But a few popular optimizations β flattening transforms, merging paths, and especially dropping the viewBox β can break the icon. This article separates the safe wins from the risky ones, explains where the decimal-precision floor actually sits, and covers why gzip on top of minification changes the whole calculation.
System prompts: 10 patterns that quietly hurt your LLM
System prompts accumulate cruft the same way codebases do: contradictory rules, negative-only instructions, buried directives, and stale text left over from an older model. This article walks through ten concrete anti-patterns that silently degrade LLM output quality, with the symptom each one produces and a practical fix, aimed at people shipping real LLM applications.
Third-party cookies are dying β what fills the gap
Safari and Firefox already block third-party cookies by default, and Chrome's Privacy Sandbox has been reshaping the plan for years. This article explains what third-party cookies did, where each browser actually stands today, and the realistic replacements: first-party data, server-side tagging, the Privacy Sandbox APIs, contextual advertising, and clean first-party campaign URLs.
Timezone bugs: 7 gotchas everyone misses
Most datetime bugs trace back to a handful of wrong assumptions: that local time is enough, that offsets are fixed, that every clock hour exists exactly once. This article walks through seven concrete timezone gotchas β from storing local time instead of UTC to DST gaps, moving offsets, and naive-versus-aware datetimes β and gives the same three fixes for all of them: store UTC, use timezone-aware libraries, and name zones with the IANA database instead of raw offsets.
YouTube thumbnails: the click-through math
YouTube recommends thumbnails at 1280Γ720 in a 16:9 ratio, under about 2MB, at least 640px wide. But that image is downscaled to a few hundred pixels in feeds and to a strip in the sidebar. This article covers the canonical dimensions, why elements have to be large and high-contrast to survive downscaling, and the file-size versus quality trade-off of staying under the upload limit.
Lesson planning: the 5-part template that works K-12
Most lesson plan formats reduce to five elements: a clear objective, a hook, direct instruction, guided-to-independent practice, and a closing check. This article walks through each part, what it's actually doing, and where teachers consistently go wrong with all five.
Markup vs margin: the math indie sellers get wrong
Markup and margin use the same inputs but different denominators β and confusing them leads to systematic underpricing. This article shows the two formulas side by side, the classic mistake that inflates apparent profit, and the conversion between them.
Hash functions: MD5, SHA, BLAKE3 β which to use when
MD5 and SHA-1 are broken for security purposes but still fine for non-security checksums. SHA-256 is the right default for signatures, HMAC, and integrity checks. BLAKE3 is faster and modern but not NIST-approved. Passwords need Argon2id, bcrypt, or scrypt β not any of these.
Rent vs buy: when ownership stops winning
The conventional wisdom that buying always beats renting is wrong in specific, calculable ways. This article walks through the break-even timeline, the price-to-rent ratio, opportunity cost of the down payment, and the three conditions that actually flip the math toward buying.
Designing for color blindness: what 8% of users see
Color blindness affects roughly 8% of men and 0.5% of women. Most design failures aren't contrast failures β they're cases where color is the only signal. This piece covers the most common types, the most common UI mistakes, and the concrete fixes that work without sacrificing aesthetics.
5 free citation generators compared (and which actually follow the spec)
ZoteroBib, EasyBib, Citation Machine, Cite This For Me, and MyBib tested on a single journal-article source against APA 7, MLA 9, and Chicago 17th. The Chegg-owned tools still output the old APA 6 DOI prefix. ZoteroBib wins because it uses the same Citation Style Language engine that academic publishers use.
Stripping EXIF GPS from mobile photos before sharing
Modern smartphone GPS is accurate to 3β5 metres and embedded in every photo by default. This guide covers iOS and Android native controls, which sharing platforms strip GPS (and which don't), the WhatsApp document-mode trap, and how to verify a strip worked β including the embedded thumbnail that survives most naive attempts.
Pre-tax vs post-tax math for indie founders
Self-employment tax adds 15.3% on top of income tax, and most indie founders don't model it. This piece covers the SE tax deduction, solo 401(k) and SEP-IRA contribution limits, traditional vs Roth break-even math, the health insurance above-the-line deduction, and how tax drag compounds β with concrete numbers throughout.
RNG seeding: why your "random" feels rigged
Games use seeded pseudo-random number generators, not true randomness. The same seed always produces the same sequence, which explains loot streaks, speedrun exploits, and why Minecraft's world generation is reproducible. This piece unpacks how seeds work, what can go wrong, and how game designers use (and abuse) determinism.
VAT MOSS for digital sellers: rules, pitfalls, and exemptions
VAT MOSS became OSS in July 2021, but the underlying obligations for digital sellers remain. This article covers what changed (and what didn't), the two-evidence location rule most sellers get wrong, the β¬10k threshold exemption, B2B reverse charge, the UK's separate post-Brexit scheme, and the currency conversion trap in quarterly filings.
Detecting prompt injection in your own bots
Prompt injection attacks manipulate LLMs into ignoring your system prompt or leaking sensitive data. This guide covers direct vs indirect injection, input-layer and output-layer detection patterns, structural defenses in system prompts, and how to red-team your own bot before attackers do.
AVIF vs WebP: when each is actually faster
AVIF usually produces smaller files than WebP, and the internet has decided that settles the speed question. It doesn't. Fewer bytes on the wire is only one of three clocks that matter β decode time in the browser and encode time in your build both push the other way. This is when each format is genuinely faster, and how to tell without trusting a single-number benchmark.
How to read a security advisory: CVE, CVSS, EPSS and KEV without the hype
Security advisories throw four different acronyms at you β CVE, CVSS, EPSS and KEV β and each answers a different question. This guide explains what every one actually measures, why the headline severity score is the least useful number on the page, and how to triage a vulnerability in five minutes instead of panicking over a colour.
Markdown across platforms: 7 differences that bite you
There's no single Markdown: CommonMark, GFM, Pandoc, Slack, Notion, and a dozen platform dialects are all subtly incompatible. These seven differences β line breaks, tables, strikethrough, code fences, inline HTML, autolinks, and list indentation β account for most formatting surprises when moving content between platforms.
Why your VPN doesn't hide you from browser fingerprinting
VPNs hide your IP. They don't hide your browser fingerprint β the dozens of low-entropy signals (screen, fonts, Canvas hash, audio context, timezone) that combine to identify you uniquely regardless of which IP you connect from. Here's what each tool actually defends against and what genuinely defeats fingerprinting.
ROI vs CAGR: which number you actually want
ROI is the headline finance number everyone quotes. CAGR is the one that survives scrutiny when investments have different durations. This article shows where ROI quietly misleads, what CAGR actually measures, when to use each, and three real-world traps the gap between them creates.
Prompt versioning: keep your iterations honest
Every team that ships LLM features eventually hits the same wall: a production prompt called v3-final-FIXED, no way to reproduce the eval from three weeks ago, and a slow drift toward worse output that nobody caught. This article lays out the minimum versioning discipline that prevents that β Git the prompts, couple them to evals, track cost-of-change, and chase clarity before cleverness.
Base64: when to use it, when it ruins your life
Base64 encodes binary as text β useful for email attachments, JWT payloads, and small inline assets. It's also routinely misused for fake encryption, oversized inline images, API payloads that should be multipart, and URL params past the 2KB limit. This article covers when Base64 is the right answer and when it's the source of your performance bug.
EXIF metadata: what your photos quietly leak about you
EXIF metadata embeds far more than GPS coordinates: device serial numbers, software-edit trails, sometimes the owner's name. This article walks through the four main categories of leak, where stripping fails, and which platforms preserve metadata when you upload (more than you'd guess).
RPG damage formulas explained: subtractive vs divisive vs percent-resist
Subtractive (D&D), divisive (Diablo), and percent-resist (MMO) β the three core damage formulas in RPG design, what each does to the player's experience, when each falls apart, and how to pick the right one for the game you're trying to build.
VAT for digital products: the 101 indie sellers actually need
EU VAT on digital products: the β¬10k threshold, OSS vs IOSS, when a Merchant of Record makes sense, country quirks, and the rules that change when a B2B buyer enters their VAT number. The decisions an indie seller actually has to make, plus the math at each scale.
Why browser-only tools matter for privacy (and why most "free online tools" sites aren't)
Most "free online utility" sites quietly upload your input to a server, log it, and sometimes archive it for training data or resale. Browser-only tools don't have a server to upload to. This article defines the difference precisely and shows you how to verify it yourself.
Citation styles cheat sheet: APA 7 vs MLA 9 vs Chicago vs Harvard (and when each is required)
APA 7, MLA 9, Chicago, and Harvard are the four citation styles most likely to be required by an instructor or journal. Each has a personality, each has a domain where it's standard, and each has the specific rules that consistently trip up students. This article covers all four at the level you need to actually finish the assignment.
JSON: 5 common errors devs hit and how to fix them
Trailing commas, single quotes, unquoted keys, comments, and unescaped characters cause the majority of "but it looks fine" JSON failures. Five concrete fixes, with code samples and a short RFC 8259 reference.