01 · whoami 🧑💻
Every system that runs on trust eventually meets someone testing where that trust ends.
I'm Trimphus, and that boundary is where I work. My field is trust and safety on a large online marketplace: fraud analysis, account integrity, message abuse, and the detection systems sitting in front of all three. Adversarial pattern recognition, essentially — reading a signal not for what it is, but for what someone meant it to look like.
Away from that: a homelab, bug bounty programmes, and as much of the year underwater as I can arrange. This site is mu-labs.dev introducing itself — there is nothing for sale here.
02 · cat domain.md 🌐
mu-labs.dev isn't a company and never has been. It's a private domain that a friend and I use for our own mail — mostly masked, one-off addresses, so that whichever shop leaks its database next doesn't get anything useful out of it. The homelab, this page, and a handful of small services live on the same domain because it was already there.
Everything here is under a handle rather than a name, and it'll stay that way. Not out of paranoia — I'd just rather keep the day job, the hobby, and the internet in separate drawers.
- domain
- mu-labs.dev
- purpose
- private — mail, homelab, notes
- commercial
- no
- people
- two, both pseudonymous
- tracking
- none — no analytics, no third-party requests
03 · tree ~/practice 🛡️
A marketplace attracts abuse in proportion to the money moving across it, and the abuse organises itself into a handful of recurring domains. These are the ones I work in.
fraud analysis
Listings constructed to take payment and disappear; organised activity visible only across many accounts at once.
account integrity
Establishing takeover and when it happened; recovery and identity checks where too strict and too permissive fail in opposite directions.
message abuse
Phishing and credential harvesting; impersonation, spoofing and bulk spam — each needing its own answer.
detection quality
Reviewing what automated classification got wrong, in both directions, and feeding that back in.
data protection
Access, erasure and lawful disclosure under GDPR — low volume, high cost of error.
Automated systems absorb the volume, which means what reaches a person is precisely what the model found ambiguous. The interesting work lives in that ambiguity: judgement at speed, on incomplete information, against someone who is actively trying not to be understood.
Which platform, and how any of it is detected, stays with me. That part isn't mine to publish.
04 · cat bug-bounty.md 🐛
Five years of working bug bounty programmes in my own time — on and off, but never really stopping. Reports go in, some get triaged, some get paid, plenty are closed as informative, and that is part of the exercise too.
It is the same instinct as the day work, turned around: instead of establishing that a flow has been abused, you establish that it can be — then write it up precisely and wait.
Where the interest sits — access control, and anything that decides who may do what
How I work — by hand and slowly, reading flows rather than pointing scanners at them
What I publish — nothing a programme has not cleared, which so far is nothing
05 · ls ~/lab 🖥️
Hardware I own, running things I'm allowed to break. It exists so I can try something stupid on a Sunday without it mattering.
06 · cat offline.md 🌤️
Not everything is screens. Most of what I look forward to happens away from one.
🤿 Diving — flooded quarries near Leipzig, all year, including the cold half.
🐾 The dog — the reason I'm outside twice a day whether I planned to be or not.
🚴 Cycling — replaced the car, one of the better decisions.
🎮 Games — the usual suspects, usually later than intended.
07 · contact --pgp 📮
Always glad to talk about abuse and detection work, the lab, or diving. Rather less glad to talk about SEO. If it should stay private, use the key.