Field Notes.
What actually happens.
From the trenches
Real problems. Real solutions. No theory, no fluff. These are tactical notes from actual client work and implementation projects – the stuff that breaks, the approaches that work, and the conventional wisdom that needs challenging. If you want thought leadership, look elsewhere. If you want solutions that actually ship, you're in the right place.
CSS Evolved. Your Sticky Nav Didn't.
Position:sticky and position:fixed haven't changed. Safari 26 just reads them differently now. Adapt your sticky CSS, don't wait for Apple to file this as a bug.
Read field noteThe demo was great. That's the problem.
Demos are built to be watched, not to fit your workflow. The tools that get the loudest launch are rarely the ones that actually solve your specific gap.
Read field noteKill the Banner
Two-thirds of German visitors reject marketing cookies. So why block 100% of them to protect a feature only a third will ever use? Cookieless isn’t consent-free. GA4 isn’t required for Ads. The banner was never for your visitors — it was for the agency’s invoice.
Read field noteWhy We're Not Rolling Out S/MIME
The premise S/MIME is an open standard. It shouldn't cost anything beyond the certificate itself, and a handful of CAs — Actalis, HARICA — offer free tiers for individuals. On paper, "secure, signed, encrypted email for anyone" looks achievable without an enterprise budget. What actually holds up The standard is sound. S/MIME certs carry the…
Read field noteYour SSO Rollout Will Break in Ways the Documentation Never Mentions
Should You Centralize Login Across Twenty Sites? Most agencies running more than a handful of WordPress installs eventually ask this question, then answer it wrong in both directions. Either they never centralize, and every client site has its own forgotten admin password rotting in a spreadsheet, or they centralize without thinking through what happens when…
Read field noteTLS-RPT Reports Cost Nothing to Receive. So Why Are You Paying?
TLS-RPT tells you when your mail encryption is failing. Receiving the reports costs nothing technically — yet every hosted service charges enterprise prices. Here's a free Cloudflare Worker that does the whole job.
Read field noteNo, We Are Not Cooked. But You Might Be Doing It Wrong.
Six months of actual changes to my stack, my workflow, and my reasoning — not a hot take, not a panic, not a victory lap. What shifted between WordPress and static, what AI integration looks like when it compounds rather than just assists, and why the “we are cooked” narrative is the laziest read on what is actually happening.
Read field noteYour Self-Hosted DNS Is Probably Open to the World and You Don’t Know It
You set up AdGuard Home on a VPS. You configure DNS-over-TLS on port 853. You point your router at it. It works. You feel good about it. What you probably did not do: restrict who can actually reach port 853. If your cloud firewall has port 853 open to the world, your private DNS resolver is a public DNS resolver — and services like mirrordns.xyz are actively advertising it as one.
Read field noteEra 4. Sure.
I cannot output JSON-LD in Etch. The security layer strips it. JSON-LD is Schema.org structured data — by definition, a web standard. Etch’s own documentation promises “Web Standards” and “Full Empowerment — complete control over your code without limitations.” Except, apparently, that one. Meanwhile, AI that can copy a stranger’s layout for $0.07 just became the top priority on the roadmap. It wasn’t on the list at all in January.
Read field noteTwo bugs, one silent canvas: how Etch, ACSS, and Yabe Webfont break each other
A client's Etch builder canvas looked nothing like the frontend. The page was usable, but all AutomaticCSS styles were unavailable, custom properties, tokens, utility classes, gone.
Read field note