# Scanned_20260730-1958 > [!privacy] Privacy-redacted working copy > Private-person names approved by the vault owner are replaced with `[PERSON REDACTED]`. The private source PDF and pre-redaction backup preserve the original wording. This notice governs over any general statement below describing transcription as exact or unchanged. > [!abstract] Executive archival statement > **Scanned_20260730-1958** is a sixty-page pocket notebook functioning simultaneously as an address book, password-and-recovery ledger, device inventory, Linux troubleshooting log, cloud-administration notebook, civic-technology research pad, and short-term relocation planner. Its strongest explicit dates cluster around **8–12 February 2022**, with earlier references to **2016, 2017, 2020, and 2021**. The notebook’s organizing principle is not alphabetical consistency so much as **[[Continuity Architecture|continuity under fragmentation]]**: identities, devices, domains, cloud systems, residences, contacts, and recovery pathways are written down wherever space is available so that access can be reconstructed after loss, confusion, device replacement, or account failure. The source does **not by itself prove unauthorized access, compromise, surveillance, or external coordination**; it does provide direct evidence of intensive account recovery, device attribution, infrastructure administration, and attempts to reconcile mismatched software and hardware identities. ## Archival Method, Evidentiary Discipline, and Privacy Every PDF page was inspected visually, including the front cover, printed ownership matter, crossed-out credentials, sticky notes, bleed-through, sparse pages, and the printed publisher colophon. Except for explicit privacy redactions, quoted blocks preserve visible spelling, capitalization, lineation, abbreviations, and uncertainty as closely as the scan permits. `"[uncertain: …]"` marks a constrained reading; `"[illegible]"` marks text that cannot responsibly be recovered. Meaningful cancellation is represented with `~~strike-through~~` where the underlying text remains safely legible. All personal telephone numbers are rendered as **`xxx-xxx-xxxx (see Scanned_20260730-1958.pdf, page N)`**. Passwords, PINs, recovery codes, backup codes, API-like secrets, vault phrases, wireless passphrases, and security-answer equivalents are rendered as **`[REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page N]`**. Device identifiers, account identifiers, domains, usernames, addresses, email addresses, and model numbers are retained unless their role is credential-equivalent. No credential was tested, validated, or used. The notebook’s factual substrate is separated into four layers: - **Visible evidence** — material directly present on the scanned page. - **Verified context** — independently researched history or technical function, cited through source notes. - **Strong inference** — an interpretation tightly constrained by page structure and surrounding notebook evidence. - **Unresolved ambiguity** — a reading or relationship that remains uncertain and is preserved rather than normalized into false certainty. --- ## Page-by-Page Archival Reconstruction ### Scanned_20260730-1958.pdf — PDF page 1 **Visible page.** A dark charcoal-black, lightly mottled front cover fills the frame. The surface shows abrasion, pale speckling, and edge wear but no label, handwriting, sticker, embossing, or title. The page establishes a small commercially manufactured notebook whose contents were not externally categorized. **Faithful transcription.** > "No visible text." **Entities and material reconstruction.** The cover itself has no identifying brand. Identification becomes possible only from the printed colophon on page 60, which names [[Flame Tree Publishing]] and describes the object as a Flame Tree Notebook. **Page-level interpretation.** The absence of an exterior title is materially significant: this was a **private utility notebook**, not a deliberately presented journal. Its later alphabetical headings and dense credentials suggest it was meant for rapid personal retrieval rather than narrative reading. **Evidentiary status.** Visible evidence only. #### Missed Signals and Open Leads The exterior provides no original owner name or topical label. The handwritten “[PERSON REDACTED]” on page 60 may be an ownership mark, a contact, or a later annotation; the cover does not resolve that ambiguity. --- ### Scanned_20260730-1958.pdf — PDF page 2 **Visible page.** The first written leaf is densely filled in black ink. Address and room information occupy the upper half; a long horizontal divider separates it from a contact/location note. “[PERSON REDACTED]” is circled at left. Several numbers and address fragments are grouped by underlining and arrows. The page has the character of a **temporary-residence and REDACTED-location index**. **Faithful transcription.** > "Uptown Suites > 7812 Clock Tower Drive > Austin 78753 > xxx-xxx-xxxx (see Scanned_20260730-1958.pdf, page 2) > # 233 > > [PERSON REDACTED] said meet him at; > his other office > 1801 N. Lamar St > xxx-xxx-xxxx (see Scanned_20260730-1958.pdf, page 2) > 75202 > Dallas > not Victor place > Car Max; 2244? > 1108!" **Entities and technical-historical reconstruction.** [[Uptown Suites Austin|Uptown Suites]] operates an extended-stay property at **7812 Clock Tower Drive, Austin, Texas 78753**, matching the notebook exactly.[^uptown] The room marker “# 233” is therefore strongly interpretable as a hotel room or internal unit number. “1801 N. Lamar St” is less certain because “75202” is a Dallas ZIP code while North Lamar addresses more naturally evoke Austin; the page may combine an Austin hotel address, a Dallas REDACTED instruction, and a separate automobile note. [[CarMax]] is explicitly named, but the adjacent numerals are too ambiguous to classify as an address, stock number, unit number, or price. **Page-level interpretation.** This page records **mobility logistics** rather than abstract research: where the writer was staying, whom to meet, which office to use, and which location not to confuse with another. Its structure resembles a field operator’s continuity page—minimal prose, enough landmarks to reconstitute a route or contact chain. **Cross-notebook connection.** [[Scanned_20260730-1719]] page 2 also names Uptown Suites and mixes hotel occupancy with cloud, device, and contact notes. Taken together, the notebooks suggest that temporary lodging served as a practical command center for account recovery and technical work, not merely as travel accommodation. **Evidentiary status.** The Uptown Suites address is verified. The room number and REDACTED instructions are visible evidence. The interpretation of “Car Max; 2244? / 1108!” remains unresolved. #### Missed Signals and Open Leads The identity of “[PERSON REDACTED],” the referent of “Victor place,” and the exact city associated with “1801 N. Lamar St” remain unresolved. A future cross-notebook match on “[PERSON REDACTED],” “Victor,” or room “233” could determine whether this page describes one itinerary or several compressed into the same space. --- ### Scanned_20260730-1958.pdf — PDF page 3 **Visible page.** Handwriting fills the upper two-thirds of a printed ownership page. A time and name appear at top, followed by the explicit date “Feb 8th 2022.” The central note is written as a discovery statement and names three Linux/KDE components. “Intertek PSI” is circled above the printed “THIS NOTEBOOK BELONGS TO” line. **Faithful transcription.** > "11:54 [PERSON REDACTED] > Feb 8th 2022 > discovered > computer > is running > on pixel phone? > something > using > called > ‘akonadi’ > and Kio Client > Intertek PSI" **Entities and technical-historical reconstruction.** [[Akonadi]] is the data and caching service used by the [[KDE]] personal-information-management stack; it centralizes mail, contacts, calendars, notes, and related resources for applications such as Kontact.[^akonadi] [[KIO]] is KDE’s network-transparent input/output framework, allowing applications to treat local files and remote resources—such as HTTP, FTP, SFTP, WebDAV, and other protocol-backed locations—through a common interface.[^kio] A “KIO Client” reference could therefore denote a KDE process, helper, library consumer, or visible component name rather than a standalone consumer application. The phrase “on pixel phone?” is technically anomalous. Akonadi is conventionally associated with Linux desktop environments, not stock [[Google Pixel]] Android. Plausible explanations include a Linux container or remote desktop session, a device list that misattributed a host, a process viewed through another machine, or a conceptual association rather than literal execution. The page does not establish which. [[Intertek PSI]] refers most plausibly to Professional Service Industries, acquired by Intertek in 2015 and integrated into Intertek’s building-and-construction testing, engineering, inspection, geotechnical, and environmental services.[^intertek] Its appearance beneath the software note may mark a location, employer/client context, contact, building project, or a separate reminder; no visible connector proves the relationship. **Page-level interpretation.** This is one of the notebook’s most important technical pages because it records an **unexpected system-identity observation**: software associated with a KDE/Linux PIM environment seemed to be present in a context the writer associated with a Pixel phone. The writer did not merely copy product names; the verbs “discovered” and “is running” show active attribution and anomaly detection. **Cross-notebook connection.** [[Scanned_20260730-1720]] page 2 records non-present device discovery, integrated MMC/SD controllers, Microsoft Storage Spaces, and Device Manager environment variables. [[Scanned_20260730-1235]] is explicitly labeled “Commands / Features / Obscure / Facts / ACCESS.” This page belongs to the same investigative trajectory: **enumerate hidden components, identify software lineage, and reconcile visible devices with subsystems that do not appear to fit them**. **Evidentiary status.** The named components and date are visible evidence; their technical functions are verified. Any claim that Akonadi literally executed natively on a Pixel remains unverified. #### Missed Signals and Open Leads The name at top may read “[PERSON REDACTED],” “[PERSON REDACTED],” or another close form; page 60 clearly reads “[PERSON REDACTED],” creating a possible but unconfirmed recurrence. The precise screen, log, process list, or device-management interface from which “Kio Client” was copied remains unknown. Locating a screenshot or terminal record from 8 February 2022 would be decisive. --- ### Scanned_20260730-1958.pdf — PDF page 4 **Visible page.** A short list of software names occupies the upper half, bracketed by a large descending line. A lower section contains Facebook and email recovery material, with “New” written beside one account and older entries crossed out. The lower edge is crowded and partly cut by the scan. **Faithful transcription.** > "[uncertain: Investigate]; 2/8/22 > xfdashboard > cockpit > Kio > akonadi > fb > [email protected] > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 4] > xxx-xxx-xxxx (see Scanned_20260730-1958.pdf, page 4) > ~~[old account entries, partly illegible]~~ > New > Facebook @21" **Entities and technical-historical reconstruction.** [[xfdashboard]] is an Xfce-oriented application launcher and workspace overview modeled after GNOME Shell’s overview and macOS Mission Control.[^xfdashboard] [[Cockpit]] is a web-based Linux server administration interface, conventionally served on TCP port 9090, that exposes services, logs, storage, networking, accounts, virtual machines, and terminal access through a browser.[^cockpit] Together with [[KIO]] and [[Akonadi]], these terms span **desktop shell, remote administration, filesystem/network abstraction, and PIM data services**. That combination matters. It suggests the writer was not observing a single application but trying to infer the architecture of a Linux environment from several visible components. Cockpit points toward a managed host or server; xfdashboard points toward a graphical desktop; KIO and Akonadi point toward KDE services. A machine could contain all four, but the mix may also reflect several systems or search results accumulated on one page. **Page-level interpretation.** The upper page is a compact **software-attribution stack**. The lower page switches to Facebook recovery, email identity, and a “new” account state. This juxtaposition makes the notebook’s governing concern explicit: system inspection and account continuity were treated as one problem because devices, identity providers, and application data were mutually dependent. **Evidentiary status.** Software names and date are visible. The interpretation that they belong to one machine is only plausible, not proven. #### Missed Signals and Open Leads The first word may be “Investigate,” “Investigation,” or an abbreviated variant. “Facebook @21” could mean a password epoch, account created/changed in 2021, or a recovery mnemonic. Because it functions like a secret marker, any adjoining value has been redacted. --- ### Scanned_20260730-1958.pdf — PDF page 5 **Visible page.** Sparse ruled page. “band 0102” appears at top. A large looping symbol or “OMG” occupies the center. Below a divider, a sentence about Konqueror is written with “Boxes VM” emphasized. **Faithful transcription.** > "band 0102 > [uncertain: OMG] > > Konqueror > is Boxes VM > and more!" **Entities and technical-historical reconstruction.** [[Konqueror]] is KDE’s long-running web browser and file manager. Through KIO it can browse local and remote resources using multiple protocols.[^konqueror] [[GNOME Boxes]] is a separate GNOME application designed to create and operate virtual machines with a simplified interface.[^gnome-boxes] The two are not the same product and do not share the same primary function. **Page-level interpretation.** The statement “Konqueror is Boxes VM and more!” is best preserved as a **working hypothesis**, not silently corrected. It may express functional analogy—Konqueror as a generalized container for remote and local resources—rather than literal product identity. More likely, the writer was trying to understand a Linux GUI in which files, remote hosts, and virtualized systems appeared through overlapping shells. The phrase “and more!” signals recognition that Konqueror’s role exceeded ordinary web browsing, which is technically correct even though it is not GNOME Boxes. **Evidentiary status.** Visible evidence and verified product distinction. #### Missed Signals and Open Leads “band 0102” could refer to a radio/cellular band, wearable device, account grouping, or a numerical category. No later page conclusively resolves it. The large central mark may be “OMG,” initials, or a diagrammatic loop. --- ### Scanned_20260730-1958.pdf — PDF page 6 **Visible page.** Large isolated model notes written in the upper half. Three small ink dots appear near the lower middle. **Faithful transcription.** > "Ms Air > Late 2020 > ‘13’ > A2337" **Entities and technical-historical reconstruction.** The note identifies a [[MacBook Air]] introduced in late 2020, with a 13.3-inch display and model number **A2337**.[^macbook-air] “Ms Air” is almost certainly a handwriting/transcription shorthand for “Mac Air.” **Page-level interpretation.** This is a **device-provenance page**: generation, form factor, and regulatory model are sufficient to distinguish the first Apple-silicon MacBook Air from neighboring Intel-era machines. The notebook repeatedly uses this minimal identification style—model, date, platform—because such facts are critical when restoring backups, choosing firmware, matching chargers, or interpreting account device lists. **Cross-notebook connection.** [[Scanned_20260730-1230]] begins with paired Mac Pro labels and hardware identifiers; [[Scanned_20260730-1650]] preserves Sony PSP labels and power-supply details. Page 6 is the same archival behavior in compressed form: **the physical device is treated as an identity-bearing object**. **Evidentiary status.** Verified model correspondence. #### Missed Signals and Open Leads No serial number, storage capacity, memory size, or ownership assignment appears. A future device-inventory note containing A2337 could connect this entry to a particular MacBook Air. --- ### Scanned_20260730-1958.pdf — PDF page 7 **Visible page.** Alphabetical heading “A.” The page contains web services, usernames, dates, phone/recovery material, and Apple business-management notes. Several fields are labeled “pw,” “Pin,” and “other,” requiring credential redaction. **Faithful transcription.** > "A > afternic.com > bryant19 > [uncertain email or username] > xxx-xxx-xxxx (see Scanned_20260730-1958.pdf, page 7) > apple business id (12/22/17) > apple business mgr. > [uncertain: service.ringcentral.com] > xxx-xxx-xxxx (see Scanned_20260730-1958.pdf, page 7) > username > pw: [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 7] > Pin: [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 7] > other: [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 7]" **Entities and technical-historical reconstruction.** [[Afternic]] is a domain aftermarket owned by [[GoDaddy]], used to list, distribute, and sell registered domain names through a reseller network.[^afternic] [[Apple Business Manager]] historically combined organizational device enrollment, app/content purchasing, managed accounts, and deployment workflows; its ancestry includes Apple’s Device Enrollment Program and Volume Purchase Program.[^apple-business] Apple began using the consumer-facing term **Apple Account** in place of Apple ID in 2024, while preserving the underlying credentials and services.[^apple-account] [[RingCentral]] is a cloud communications provider centered on voice over IP, messaging, REDACTED, and business telephony.[^ringcentral] **Page-level interpretation.** The date “12/22/17” anchors an **organizational Apple identity** predating the 2018 Apple Business Manager launch, making it plausible that the account began under an earlier Apple deployment program and was later migrated. The page links domain commerce, corporate device administration, and cloud telephony—three control planes needed to keep an online business reachable. **Evidentiary status.** Service names and date are visible; the migration lineage is historically verified but not account-specifically proven. #### Missed Signals and Open Leads The ambiguous RingCentral line should be compared with other notebooks for the same service hostname. The unlabeled email/username beside Afternic may identify the controlling domain-marketplace account, but the scan is insufficient for a confident reading. --- ### Scanned_20260730-1958.pdf — PDF page 8 **Visible page.** Very sparse contact/device page. A name or label appears at top, followed by a telephone number and a long digit string labeled “m.mel,” likely “IMEI.” **Faithful transcription.** > "[PERSON REDACTED] Car > xxx-xxx-xxxx (see Scanned_20260730-1958.pdf, page 8) > [uncertain: IMEI] 115818088945212[uncertain final digit]" **Entities and technical-historical reconstruction.** [[International Mobile Equipment Identity|IMEI]] numbers are identifiers assigned to cellular equipment rather than subscriber accounts. The string’s length and placement make IMEI the strongest reading, though the handwritten label is imperfect. “[PERSON REDACTED] Car” may name a vehicle-associated phone, a contact entry, a Bluetooth/cellular device used in a car, or a person-plus-context label. **Page-level interpretation.** This page extends the notebook’s identity map from accounts to **radio hardware**. Pairing a contact label with an IMEI is a practical way to distinguish a handset even when its phone number, SIM, or user account changes. **Evidentiary status.** The phone number is redacted. The device identifier is visible but the final digit remains uncertain. No ownership conclusion is made. #### Missed Signals and Open Leads The device make/model cannot be derived from the handwritten IMEI without querying proprietary equipment databases, which was neither necessary nor appropriate. A model number elsewhere in the notebooks may supply the missing link. --- ### Scanned_20260730-1958.pdf — PDF page 9 **Visible page.** Alphabetical heading “B.” Beneath it are an email address and a credential-like phrase. The rest of the page is blank. **Faithful transcription.** > "B > [email protected] > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 9]" **Entities and technical-historical reconstruction.** The page associates the writer’s primary-name domain with a secret. [[BryantMcGill.com]] functions here as an identity root rather than merely a public website: the domain-backed email appears throughout the notebook as a recovery address for Google, Apple, social platforms, and hosting systems. **Page-level interpretation.** This is a compact **root-identity record**. In an account graph, control of a primary domain and its mailboxes can become a recovery authority over many downstream services. The notebook repeatedly returns to this address because continuity of the domain may determine continuity of the broader digital estate. **Evidentiary status.** Visible evidence; secret redacted. #### Missed Signals and Open Leads The page does not identify which service the credential belonged to. Treating it as a universal password would be unsafe and unsupported; it may instead have been a mnemonic, historical password epoch, or recovery phrase. --- ### Scanned_20260730-1958.pdf — PDF page 10 **Visible page.** Alphabetical heading “C.” A CVS address and phone number occupy the upper area. A large central word or phrase is difficult to decipher. A small lower annotation begins with “same.” **Faithful transcription.** > "C > CVS > 213 East San Patricio Ave > xxx-xxx-xxxx (see Scanned_20260730-1958.pdf, page 10) > [uncertain: Maths?] > [uncertain: same …]" **Entities and technical-historical reconstruction.** [[CVS Pharmacy|CVS]] is the only securely identifiable entity. “213 East San Patricio Ave” points to a physical retail/pharmacy location, but the city is not written on the page. The large central word is too ambiguous to normalize. **Page-level interpretation.** This page is a conventional **local-services address-book entry** embedded inside a primarily technical notebook. It demonstrates that the object was used as a general continuity instrument: health/retail access, residences, contacts, and systems administration were not separated into different notebooks. **Evidentiary status.** Address and brand are visible; the uncertain text remains unresolved. #### Missed Signals and Open Leads A location match for the CVS address may reveal the writer’s route or temporary residence at the time, but resolving it would add little without corroborating notebook context. The central word should be revisited if a repeated term appears in another scan. --- ### Scanned_20260730-1958.pdf — PDF page 11 **Visible page.** Alphabetical heading “D,” with the word “outer” written at upper right. Two cloud providers are listed, followed by two labeled password fields. **Faithful transcription.** > "D > outer > digital ocean > vultr > RtPw: [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 11] > AuPw: [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 11]" **Entities and technical-historical reconstruction.** [[DigitalOcean]] provides virtual machines called Droplets, networking, storage, managed databases, Kubernetes, and related developer cloud infrastructure.[^digitalocean] [[Vultr]] offers globally distributed cloud compute instances, bare metal, storage, and networking.[^vultr] The abbreviations “RtPw” and “AuPw” plausibly mean root password and authorization/authentication password, although that expansion is inferential. **Page-level interpretation.** This page is the clearest **infrastructure-root page** in the notebook. DigitalOcean and Vultr are substitutable infrastructure providers; listing them together suggests redundancy, migration, comparison, or parallel server estates. The presence of privileged-password labels indicates concern with administrative access rather than ordinary consumer login. **Cross-notebook connection.** [[Scanned_20260730-1719]] page 2 names cloud/data-center concepts, AMD, EPYC, ARM, and cloud providers. [[Scanned_20260730-1706]] contains Linux desktop and hardware notes. Page 11 is the operational account layer beneath those broader architectural interests. **Evidentiary status.** Providers are visible; credential expansions are strong but unconfirmed inference. #### Missed Signals and Open Leads “outer” may be a server name, conceptual category, or fragment from a neighboring entry. Provider dashboards, IP ranges, or domain mappings are absent, so no specific server can be reconstructed from this page alone. --- ### Scanned_20260730-1958.pdf — PDF page 12 **Visible page.** Several service domains and email addresses are arranged as account pairs. The lower half contains Facebook-related material, old/new distinctions, and credentials. Some entries are squeezed into margins or partially crossed. **Faithful transcription.** > "ifttt.com > [uncertain email address] > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 12] > reportingthings.com > [email protected] > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 12] > > [uncertain: MaybeOldFb@21] > Acct > [uncertain: bcb.m] > bryant@bryantmcgill[uncertain domain ending].com > Facebook @21 > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 12]" **Entities and technical-historical reconstruction.** [[IFTTT]]—“If This Then That”—connects services through trigger-and-action automations called Applets.[^ifttt] [[ReportingThings.com]] and [[Simple Reminders]] appear to be project or business domains under the writer’s control or administration. The repeated `info@` mailboxes indicate role-based identities rather than personal-only accounts. **Page-level interpretation.** The page maps **automation infrastructure to branded properties**. IFTTT would have been a plausible glue layer for syndication, notification, social publishing, logging, or cross-service continuity. The Facebook material below suggests the same projects were bound to social identities whose ownership or password epochs had to be reconstructed. **Evidentiary status.** Domains and email are visible. No conclusion is made about what automations existed or whether they remained active. #### Missed Signals and Open Leads The first email beneath IFTTT is not safely legible. DNS records, archived IFTTT Applet descriptions, or email receipts could determine whether `reportingthings.com` and `simplereminders.com` were connected by automated publishing or data collection. --- ### Scanned_20260730-1958.pdf — PDF page 13 **Visible page.** Alphabetical heading “F.” The upper section contains multiple heavily crossed-out Facebook/Meta credentials and numeric codes. The lower section is a cleaner GoDaddy account block with an email-like username, PIN/customer fields, and secret material. **Faithful transcription.** > "F > ~~Facebook / Meta account entries~~ > ~~[REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 13]~~ > FB Pay Mom Last4 > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 13] > > New GoDaddy > godaddy.gomcgill@ > gomcgill > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 13]" **Entities and technical-historical reconstruction.** [[Meta Platforms|Facebook/Meta]] and [[GoDaddy]] represent two different identity layers: social presence and domain/DNS/hosting control. GoDaddy’s account structure often includes customer identifiers and support PINs in addition to login credentials; all such values have been treated as secrets. “FB Pay Mom Last4” appears to be a mnemonic linking a payment method or card ending to account verification; its value is credential-equivalent and redacted. **Page-level interpretation.** The crossing-out is evidentially important. It shows **account-state transition**: obsolete, rejected, or superseded recovery data was not erased but visibly invalidated. This is consistent with a manual recovery ledger built while access conditions were changing. **Evidentiary status.** Service labels and cancellation structure are visible. The reasons for invalidation are unknown. #### Missed Signals and Open Leads The exact relationship between `godaddy.gomcgill@` and the `gomcgill` domain is incomplete because the address is truncated. Archived GoDaddy receipts or account-recovery emails could establish whether this was a username, alias, or incomplete note. --- ### Scanned_20260730-1958.pdf — PDF page 14 **Visible page.** A February 2022 date marker appears near the top. Google Workspace and several domain email addresses are written in a structured cluster. Instagram appears near the bottom with a username and credential. **Faithful transcription.** > "[uncertain: new Disc… 2022/02] > [email protected] > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 14] > workspaces.google.com > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 14] > phone ends with 14 > [email protected] or gomcgill.com > [email protected] > [email protected] > instagram.com/mysimplereminders > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 14]" **Entities and technical-historical reconstruction.** [[Google Workspace]] is the name Google introduced in October 2020 for the suite previously branded G Suite, itself renamed from Google Apps in 2016.[^google-workspace] It supplies organizational Gmail, Drive, Calendar, identity, and administrative controls. The notebook’s `workspaces.google.com` spelling is not the standard administrative hostname; [[Google Admin Console]] is conventionally accessed through `admin.google.com`, which appears later on page 38.[^google-admin] [[Instagram]] is tied specifically to the `mysimplereminders` project identity. **Page-level interpretation.** This page reconstructs a **domain-to-mailbox-to-social-account dependency graph**. Personal Gmail, domain mailboxes, phone-tail verification, and an Instagram property are recorded together because each could serve as the recovery path for another. The writer was approaching what would now be modeled as an identity graph or credential dependency graph. **Evidentiary status.** Visible evidence and verified product history. The first line remains uncertain. #### Missed Signals and Open Leads The phrase “phone ends with 14” is a recovery clue rather than a full number; it is retained because it cannot be used independently as a telephone contact. The exact Google Workspace tenant domain and super-administrator account remain unresolved. --- ### Scanned_20260730-1958.pdf — PDF page 15 **Visible page.** Alphabetical heading “G.” The page begins with GoDaddy entries, including a named VIP representative and contact details, then moves through Google and PayPal to a Simple Reminders URL and an account associated with “[PRIVATE NAME REDACTED]” Arrows and underlines connect sections. **Faithful transcription.** > "G > GoDaddy > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 15] > vip rep > [PERSON REDACTED] > xxx-xxx-xxxx (see Scanned_20260730-1958.pdf, page 15) > [PRIVATE EMAIL REDACTED] > [uncertain: His city black] > accounts.google[uncertain ending] > [email protected] > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 15] > PayPal > info@simplereminders[uncertain domain ending] > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 15] > http://simplereminders.com/ > [PRIVATE NAME REDACTED] > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 15]" **Entities and technical-historical reconstruction.** [[GoDaddy]], [[Google Account]], [[PayPal]], and [[Simple Reminders]] form a business continuity chain: domain registrar, identity/email provider, payment processor, and public-facing property. The named “VIP rep” is a human escalation path, which can be crucial when automated recovery fails. **Page-level interpretation.** This page shows that the notebook was not merely storing passwords. It recorded **institutional routes of appeal**—a named representative, role mailboxes, provider portals, and brand accounts. That is a more advanced continuity strategy than keeping isolated credentials because it preserves the social and organizational mechanisms needed to recover control. **Evidentiary status.** The page verifies the written relationship only as a notebook assertion. No claim is made about the current employment or identity of the named person. #### Missed Signals and Open Leads “His city black” may instead read “His city block,” “His CITI…,” or another phrase. The truncated PayPal email should not be silently completed. Cross-notebook appearances of [PERSON REDACTED] or `[PRIVATE NAME REDACTED]` may clarify account ownership and chronology. --- ### Scanned_20260730-1958.pdf — PDF page 16 **Visible page.** Apple, Facebook, Google, and Twitter account notes are separated by whitespace and a horizontal divider. Several entries explicitly say “no username” or use role-based emails. **Faithful transcription.** > "apple.com > idmsa.apple.com > [email protected] > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 16] > facebook no username > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 16] > accounts.google.com > [PERSON REDACTED]@gomcgill.com > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 16] > > twitter: > @SimpleReminders > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 16]" **Entities and technical-historical reconstruction.** `idmsa.apple.com` is associated with Apple identity sign-in and account-management flows. `accounts.google.com` is Google’s identity endpoint. [[Twitter]]—now branded [[Twitter|X]]—is represented by the project handle `@SimpleReminders`. The page distinguishes service identity from public username: “facebook no username” is a recovery observation, not a missing transcription. **Page-level interpretation.** This is a cross-platform **brand identity matrix**. `[email protected]`, `[PERSON REDACTED]@gomcgill.com`, and `@SimpleReminders` connect a project to Apple, Facebook, Google, and Twitter. The page therefore records not one account but an ecosystem whose consistency depended on email aliases and public handles. **Evidentiary status.** Visible account labels; all secret values redacted. The current branding of Twitter/X is later context, not a correction of the 2022 notebook wording. #### Missed Signals and Open Leads “facebook no username” may mean the account was accessible only by email/phone, that the public vanity URL had been removed, or that the writer could not determine it. Platform export data could distinguish these possibilities. --- ### Scanned_20260730-1958.pdf — PDF page 17 **Visible page.** Alphabetical heading “H.” Google account information is written directly on the ruled page. A blue sticky note overlays the lower area with another account fragment and `myaccount.google.com`. **Faithful transcription.** > "H > accounts.google.com > [email protected] > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 17] > > [blue sticky note] > [uncertain: b@bmccom4mom] > myaccount.google.com > [email protected]" **Entities and technical-historical reconstruction.** [[Google Account]] uses `myaccount.google.com` for consumer account settings and `accounts.google.com` for authentication. The repeated domain email shows the same identity being approached through both sign-in and account-management surfaces. **Page-level interpretation.** The sticky note is a material revision layer. Rather than replacing the underlying entry, the writer added a **temporary recovery hypothesis** over it. This is how paper becomes a versioned interface: base record, overlay, correction, and new access route coexist spatially. **Evidentiary status.** Visible evidence. The sticky-note shorthand is unresolved. #### Missed Signals and Open Leads The phrase ending “4mom” may be a mnemonic or account alias and has been left uncertain rather than treated as a credential. If it encoded a security answer, it should be reclassified and redacted in any future clearer scan. --- ### Scanned_20260730-1958.pdf — PDF page 18 **Visible page.** A contact named “[PERSON REDACTED]” with email and street address appears at top. Below is “[PERSON REDACTED],” a redacted phone number, the date “Sat Feb 12th 2022,” and an emotionally toned fragment. **Faithful transcription.** > "[PERSON REDACTED] > [uncertain: [email protected]] > 2212 Mountain View Road > Austin 78703 > [PERSON REDACTED] > xxx-xxx-xxxx (see Scanned_20260730-1958.pdf, page 18) > Sat Feb 12th 2022 > [uncertain: Sad … day evn]" **Entities and technical-historical reconstruction.** The page contains private contacts rather than safely identifiable public figures. The Austin address places the contact in the same geographic frame as Uptown Suites on page 2. “[PERSON REDACTED]” recurs from page 2, strengthening the probability that these are connected logistics or social-contact notes. **Page-level interpretation.** This is a **human continuity page**: names, addresses, and date anchors coexist with technical records because people were part of the recovery and relocation network. The fragment after the date may register an event or mood, but it cannot be responsibly reconstructed. **Evidentiary status.** Visible evidence; identities remain private/unverified. #### Missed Signals and Open Leads The email surname is uncertain and should be compared with contacts, calendar entries, or other notebooks. The date may anchor the surrounding pages chronologically, implying pages 14–20 were written in the same February 2022 recovery period. --- ### Scanned_20260730-1958.pdf — PDF page 19 **Visible page.** Alphabetical heading “I.” A named contact and phone number appear above an Instagram notation. A username and credential occupy the lower area. **Faithful transcription.** > "I > [PERSON REDACTED] > xxx-xxx-xxxx (see Scanned_20260730-1958.pdf, page 19) > Instagram ↑ > bryantmcgill > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 19]" **Entities and technical-historical reconstruction.** [[Instagram]] is linked to the `bryantmcgill` identity. “[PERSON REDACTED]” may be a private contact or could share a name with public individuals; the notebook provides insufficient disambiguation, so no external identity is assigned. **Page-level interpretation.** The upward arrow likely connects the contact to Instagram, but the direction is ambiguous: it may mean the phone number belongs to the Instagram recovery contact, that the contact assisted with the account, or simply that the next entry concerns Instagram. **Evidentiary status.** Visible evidence; contact identity unresolved. #### Missed Signals and Open Leads Page 40 repeats “[PERSON REDACTED]” in a list with [PERSON REDACTED] and FBI Austin. That recurrence is important but still does not establish role or institution. Cross-referencing both pages with contemporaneous phone records could clarify whether one person or two same-name contacts are involved. --- ### Scanned_20260730-1958.pdf — PDF page 20 **Visible page.** Heading “IG.” The page contains several Instagram/account clusters, a project name, explicit uncertainty about a password, crossed-out material, and family-name mnemonics. It is one of the densest credential pages. **Faithful transcription.** > "IG > gomcgill > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 20] > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 20] > Simplethingsbrand > same as above > except I dont know Pw. > ~~[crossed account strings involving bryantmcgill / mysimplereminders]~~ > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 20] > [family-name recovery mnemonic redacted as credential-equivalent]" **Entities and technical-historical reconstruction.** [[Instagram]] account names `gomcgill`, `Simplethingsbrand`, `bryantmcgill`, and `mysimplereminders` appear to form a portfolio of personal and project identities. The sentence “except I dont know Pw.” is direct evidence that the page was being used during **incomplete account recovery**, not merely as a static password list. **Page-level interpretation.** The page captures an identity estate in which several public-facing brands may share emails, passwords, phone recovery routes, or family mnemonics. The crossings and “same as above” notation reveal the danger of credential reuse and alias ambiguity: recovery becomes difficult when the remembered schema is relational rather than service-specific. **Cross-notebook connection.** [[Scanned_20260730-1305]] is marked “Pw” and contains sticky notes for cloud, scanning, buffers, and PDF encryption; [[Scanned_20260730-1734]] is likewise labeled “PW.” This page belongs to a larger paper-based credential corpus rather than an isolated notebook. **Evidentiary status.** Visible evidence. Family-name strings that function as password material are redacted even where individual names may be otherwise public. #### Missed Signals and Open Leads “Simplethingsbrand” may be a username, project label, or Instagram account display name. Platform account exports and archived profile URLs would be needed to reconstruct the exact portfolio without guessing. --- ### Scanned_20260730-1958.pdf — PDF page 21 **Visible page.** Alphabetical heading “J.” The page begins with “old 11 pro?” and “iphone encrypt pw,” then records [PERSON REDACTED]-related and iMazing material. The lower half contains Instagram identities and a family-name mnemonic. Several strings function as passwords. **Faithful transcription.** > "J > old 11 pro? > iphone encrypt pw > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 21] > [PERSON REDACTED]: ~~[crossed out]~~ 9? > iMazing > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 21] > IG > bryantmcgill > [email protected] > [family-name mnemonic redacted as credential-equivalent] > mysimplereminders > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 21] > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 21]" **Entities and technical-historical reconstruction.** “old 11 pro?” most plausibly refers to an [[iPhone 11 Pro]]. [[iMazing]] is third-party software for managing, transferring, and backing up iPhone and iPad data. Its encrypted-backup workflow relies on the iOS backup password: the password is supplied to Apple’s backup subsystem and is needed to decrypt protected backup contents.[^imazing] This distinction matters because an iPhone backup password is not necessarily the same as an Apple Account password, device passcode, or iMazing application credential. **Page-level interpretation.** The page is a **backup-chain reconstruction**. It links an old phone, the encryption password governing its backup, iMazing, a legacy Comcast email, and social identities. The writer appears to be trying to recover not just an account but the historical data state from which other credentials, messages, and evidence might be restored. **Cross-notebook connection.** [[Scanned_20260730-1806]] page 2 records “Update Roms,” “Dialer – Phones/Tablets,” “Lineage Info,” “Gadgets,” and “App Manager Activity.” Both notebooks treat mobile devices as historical containers whose software lineage and backup state must be preserved. **Evidentiary status.** Visible evidence; exact passwords redacted. “11 pro” remains a strong but not absolute model identification. #### Missed Signals and Open Leads The crossed [PERSON REDACTED] entry may record an attempted password, device count, or backup version. The notebook does not state whether the encrypted backup was successfully opened. iMazing logs or backup manifests could establish the relevant device UDID, backup date, encryption state, and completion status without exposing the password. --- ### Scanned_20260730-1958.pdf — PDF page 22 **Visible page.** The page contains a short heading or phrase at top and several clusters of eight-digit numbers. One cluster is crossed out. There is little explanatory prose. **Faithful transcription.** > "[uncertain: Ig go mcgill backy cdm] > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 22] > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 22] > ~~[REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 22]~~ > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 22]" **Entities and technical-historical reconstruction.** The uniform eight-digit formatting is consistent with backup codes, one-time recovery codes, PINs, or provider-generated verification identifiers. Because their function cannot be determined safely, every value is treated as a credential-equivalent secret. **Page-level interpretation.** This is a **code bank without service labels**. Its archival importance lies in the crossing-out pattern: at least one code was consumed, rejected, or invalidated. The page therefore records state change, even though the underlying values cannot be published. **Evidentiary status.** Visible pattern; exact values redacted. The heading is uncertain. #### Missed Signals and Open Leads The missing service association is the critical gap. Page adjacency suggests Instagram or GoMcGill recovery, but adjacency alone is insufficient. A contemporaneous SMS, email, or authenticator export could identify the issuing platform. --- ### Scanned_20260730-1958.pdf — PDF page 23 **Visible page.** Alphabetical heading “K.” Four short lines appear in the upper half; a divider separates them from a Facebook profile-and-credential entry. **Faithful transcription.** > "K > Kdp business > [uncertain: Austin A2D1] > dl. > Voter > > Fb > bryantmcgill (profile) > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 23]" **Entities and technical-historical reconstruction.** [[Kindle Direct Publishing|KDP]] is Amazon’s self-publishing system for Kindle ebooks, paperbacks, and hardcovers, with account-level control over titles, metadata, pricing, and distribution.[^kdp] “Kdp business” may therefore designate a publishing account or business-registration task. “Voter” could refer to voter registration, a project title, or a classification; no election procedure is stated. **Page-level interpretation.** The page couples **publishing authority and public identity**. KDP controls books and author metadata, while Facebook controls a public profile. In the notebook’s broader logic, both are publishing systems requiring durable account recovery. **Evidentiary status.** KDP and Facebook are securely read. The middle two lines remain uncertain and are not expanded beyond the scan. #### Missed Signals and Open Leads “Austin A2D1” may encode a district, address, Amazon account, or device label. “dl.” could mean download, driver’s license, or a person’s initials. No responsible resolution is possible without a repeated occurrence. --- ### Scanned_20260730-1958.pdf — PDF page 24 **Visible page.** A simple service, email, and credential triplet occupies the upper third. The remaining page is blank. **Faithful transcription.** > "Mail.com > [email protected] > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 24]" **Entities and technical-historical reconstruction.** [[mail.com]] is a hosted email service offering addresses under multiple domains. The address preserves a name-based mailbox independent of the writer’s owned domains. **Page-level interpretation.** This is a **fallback identity endpoint**. A mailbox outside `bryantmcgill.com`, `gomcgill.com`, Gmail, iCloud, or Comcast could serve as an independent recovery channel if domain DNS or a primary provider became inaccessible. **Evidentiary status.** Visible evidence; secret redacted. #### Missed Signals and Open Leads The page does not indicate whether the account remained active or whether it was configured as a recovery address elsewhere. Mail headers or account-security exports would be necessary to place it in the dependency graph. --- ### Scanned_20260730-1958.pdf — PDF page 25 **Visible page.** Alphabetical heading “M.” Three short lines combine “M1,” “mac,” “mcgill,” and number-like fragments. Their structure resembles device/account mnemonics. **Faithful transcription.** > "M > M1 mcgill [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 25] > [uncertain: occ mac mcgill mcgill] > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 25]" **Entities and technical-historical reconstruction.** “M1” may refer to the [[Apple M1]] MacBook Air identified on page 6, while “mac” and “mcgill” appear in secret-like combinations. Because the page does not distinguish username, computer name, local account, FileVault password, or Apple identity, the sensitive fragments are redacted. **Page-level interpretation.** The page likely records a **local-device access layer**—machine name, local user, or password mnemonic—rather than a web service. This distinction is important: a Mac can have separate firmware, FileVault, login, backup, iCloud, and administrator credentials, which are often conflated during recovery. **Evidentiary status.** “M1” is visible; its tie to page 6 is a strong inference, not proof. #### Missed Signals and Open Leads The ambiguous second line may contain “old mac,” “occ mac,” or a username. A photograph of the Mac login screen or `scutil --get ComputerName` output could resolve whether “mcgill” was a host name or account. --- ### Scanned_20260730-1958.pdf — PDF page 26 **Visible page.** A dense networking page headed “Netgear 22.” SSID/password-like lines, a gateway address, encryption mode, and Wi-Fi mode strings are written in groups. Some router text is crossed out. **Faithful transcription.** > "Netgear 22 > admin > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 26] > ~~[crossed router / network text]~~ > [REDACTED WIRELESS CREDENTIAL — see Scanned_20260730-1958.pdf, page 26] > 192.168.22.22 gateway > M22 > [REDACTED WIRELESS CREDENTIAL — see Scanned_20260730-1958.pdf, page 26] > cell ID: 429 496 7295 > Encrypt WPA-WPA2 > modus > MB02-11-BGN 2.4 > MB02-11-ANAC" **Entities and technical-historical reconstruction.** The page most likely concerns a [[NETGEAR Nighthawk M1]] mobile router. NETGEAR documentation for the MR1100 distinguishes **802.11 b/g/n on 2.4 GHz** and **802.11 a/n/ac on 5 GHz**, matching the handwritten “BGN 2.4” and “ANAC” strings.[^mr1100] [[Wi-Fi Protected Access|WPA/WPA2]] identifies the wireless security mode. The value **4,294,967,295** equals \(2^{32}-1\), the maximum unsigned 32-bit integer. In many systems it functions as an all-bits-set sentinel, “unknown,” invalid value, broadcast-like placeholder, or parsing default. It is therefore more likely to represent a failed or unavailable cell identifier than a real radio cell ID. `192.168.22.22` is a private IPv4 address. Calling it “gateway” may reflect a custom LAN, a host manually assigned as router, or a mistaken label; many consumer routers default to `.1`, but no universal rule requires that. **Page-level interpretation.** This is a **portable-network provenance page**. It records administrative access, SSIDs, radio bands, encryption, and a suspicious cell-ID value. The writer was not merely connecting to Wi-Fi; the notes suggest inspection of the router’s internal status and an attempt to understand how the cellular and WLAN layers were being represented. **Cross-notebook connection.** [[Scanned_20260730-1251]] page 2 also lists NETGEAR 90, hotspot credentials, CenturyLink, and Wi-Fi names. The repeated pattern reveals a larger device-network inventory spanning mobile hotspots, home routers, and ISP equipment. **Evidentiary status.** Wireless modes and number are visible. The identification as MR1100 is strong but should remain linked to the Nighthawk M1 family rather than asserted from a missing model label. #### Missed Signals and Open Leads “MB02” may be the router’s SSID prefix, a device alias, or a handwritten reading of a model field. The crossed network text may preserve an earlier SSID. A router configuration export or screenshot could establish firmware version, carrier, IMEI, APN, actual cell identifiers, and DHCP gateway. --- ### Scanned_20260730-1958.pdf — PDF page 27 **Visible page.** Alphabetical heading “N.” The page contains a short secret-like fragment, an email address, the word “Vault,” then “Norton” and another secret. **Faithful transcription.** > "N > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 27] > [email protected] > Vault > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 27] > Norton > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 27]" **Entities and technical-historical reconstruction.** [[Norton Password Manager]] uses a cloud vault associated with a Norton account and protected by a vault password; Norton documentation distinguishes the account sign-in from the password used to unlock stored vault data.[^norton-vault] **Page-level interpretation.** This page records a **credential manager inside a credential notebook**. That apparent redundancy is historically meaningful. When access to a digital vault is uncertain, its account identity and vault password must themselves be recovered through an external medium. The paper notebook therefore acts as a root-of-recovery beyond the password manager. **Evidentiary status.** Visible evidence; secret values redacted. #### Missed Signals and Open Leads The page may contain two distinct secrets—Norton account and vault—or a local mnemonic plus a vault password. Norton exports or account receipts could identify the historical product generation, including whether it originated as Norton Identity Safe. --- ### Scanned_20260730-1958.pdf — PDF page 28 **Visible page.** A heterogeneous research page. “Next Party,” “Latin America,” and “Argentina” appear at top. The middle names a “Female judge,” “XRP Ripple,” and a possible Florida/2017 note. A boxed “June 13th / XRP Letter” anchors the center. Lower fragments mention resignation/security/listing and Coinbase, though several words are uncertain. **Faithful transcription.** > "Next Party > Latin America > Argentina > [uncertain marginal note: money gram] > Female judge > XRP Ripple > See Florida 2017? > June 13th > XRP Letter > [uncertain: current resignation] > [uncertain: not security] > [uncertain: lists?] > Coinbase" **Entities and technical-historical reconstruction.** [[XRP]] is the native digital asset of the [[XRP Ledger]], a public distributed ledger launched in 2012; [[Ripple]] is a separate company that developed products around payments and received a large allocation of XRP from the ledger’s founders.[^xrpl] [[Coinbase]] is a digital-asset exchange. “not security” may refer to the long-running legal classification debate around XRP, but the page does not identify a case, ruling, or speaker. “Next Party,” “Female judge,” “Florida 2017,” and “June 13th XRP Letter” are too underspecified to map reliably to one political or legal event. They may be separate lines of inquiry rather than a single theory. **Page-level interpretation.** The page records **financial-regulatory pattern searching**: jurisdiction, political organization, judicial authority, exchange listing, and token classification are being placed in proximity. The notebook does not supply enough connective language to establish a causal claim. **Evidentiary status.** XRP, Ripple, Coinbase, Argentina, and the date phrase are visible. Any linkage among them is interpretive and unresolved. #### Missed Signals and Open Leads “Next Party” may denote a named political party, a sequence marker, or “new party.” The “June 13th XRP Letter” is the strongest research lead because a dated document may be discoverable in correspondence or public filings. “Female judge” should not be assigned to a specific jurist without another identifier. --- ### Scanned_20260730-1958.pdf — PDF page 29 **Visible page.** Alphabetical heading “O.” The page lists civic-technology and democracy entities. `coe.int-world` is boxed. “World Justice Party” is written in the notebook, along with Emmanuel Macron and `democracyos.org`. **Faithful transcription.** > "O > Open Collective > DemocracyOS > coe.int-world > forum for Democracy > World Justice Party > emmanuel Macron > democracyos.org" **Entities and technical-historical reconstruction.** [[Open Collective]] provides transparent budgets, fiscal hosting, and ledger-based financial administration for communities and open-source projects.[^open-collective] [[DemocracyOS]] is an open-source participatory-democracy platform developed by a Buenos Aires organization and distributed under GPL licensing.[^democracyos] The `coe.int-world / forum for Democracy` notation points to the [[Council of Europe World Forum for Democracy]], launched as an annual forum connecting public authorities, civil society, and democratic innovation.[^world-forum-democracy] The notebook phrase “World Justice Party” most likely conflates or misremembers the [[World Justice Project]], an independent organization focused on advancing the rule of law.[^world-justice-project] That correction is analytically useful but must not replace the exact transcription. [[Index - People#Emmanuel Macron|Emmanuel Macron]] is separately named; no visible arrow proves that he controlled or founded any of the other entities. **Page-level interpretation.** This page is a compact map of **democracy as software, institution, finance, and legitimacy**. DemocracyOS supplies participatory code; Open Collective supplies transparent organizational funding; the Council of Europe forum supplies transnational deliberative infrastructure; the World Justice Project supplies rule-of-law measurement. The page anticipates contemporary civic stacks in which governance is not one institution but an interoperable architecture. **Cross-notebook connection.** [[Scanned_20260730-1830]] pages 1–2 maps intelligence alliances, Crossfire Hurricane, Echelon, Five Eyes, and international state relations. Page 29 represents the complementary civic side of the same systems instinct: institutions are studied as networks of protocols, jurisdictions, and information flows. **Evidentiary status.** Entity identification is strong, except “World Justice Party,” which is normalized only in analysis as a probable reference to World Justice Project. #### Missed Signals and Open Leads The exact Council of Europe URL fragment may have been copied from a World Forum for Democracy page. A browser-history or bookmark export from 2022 could reveal the specific article and why Macron was placed beside the civic-technology cluster. --- ### Scanned_20260730-1958.pdf — PDF page 30 **Visible page.** Alphabetical heading “R.” A single contact name and phone number appear near the top; the rest of the page is blank. **Faithful transcription.** > "R > [PERSON REDACTED] > xxx-xxx-xxxx (see Scanned_20260730-1958.pdf, page 30)" **Entities and technical-historical reconstruction.** “[PERSON REDACTED]” is not disambiguated. It should be treated as a private contact unless another notebook supplies organization, location, or role. **Page-level interpretation.** This is a conventional address-book entry. Its value to the archive is relational: the name may later connect to housing, technical support, business, or civic research recorded elsewhere. **Evidentiary status.** Visible evidence only. #### Missed Signals and Open Leads Search the cumulative people index for [PERSON REDACTED] variants, phone-tail matches, or shared addresses. No public identity should be assigned from name alone. --- ### Scanned_20260730-1958.pdf — PDF page 31 **Visible page.** “Servers” is written at top, followed by GoDaddy, “WHMCS Admin,” `gomcgill`, and a credential. The page is otherwise blank. **Faithful transcription.** > "Servers > Godaddy > WHMCS Admin > gomcgill > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 31]" **Entities and technical-historical reconstruction.** [[WHMCS]] is a hosting-business automation platform that integrates customer signup, service provisioning, recurring billing, support, domain registration, and account management.[^whmcs] GoDaddy may have supplied domains, DNS, certificates, or hosting, while WHMCS administered customer-facing service operations. **Page-level interpretation.** This is a **hosting control-plane page**. The word “Servers” gives the account context that was missing from many credential-only entries. `gomcgill` likely served as tenant, username, brand, or administrative identity across registrar and billing systems. **Cross-notebook connection.** [[Scanned_20260730-1719]] page 2 names cloud and data-center systems; page 31 identifies the commercial orchestration layer needed to turn infrastructure into managed services. **Evidentiary status.** Visible evidence; exact service topology unresolved. #### Missed Signals and Open Leads No WHMCS hostname, version, license key, cPanel/WHM endpoint, or server IP is recorded. Archived DNS, invoices, or application backups could reveal whether WHMCS was actively deployed or merely evaluated. --- ### Scanned_20260730-1958.pdf — PDF page 32 **Visible page.** Alphabetical heading “S.” Samsung account/contact material appears above a list of consumer devices. Device names are written with varying capitalization; the last line resembles a Bluetooth identifier or MAC-like string. **Faithful transcription.** > "S > Samsung > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 32] > [email protected] > xxx-xxx-xxxx (see Scanned_20260730-1958.pdf, page 32) > Facebook: Facebook > Mi Smart Band 5 > LE Bose Color II SoundLink > AmazFit GTS 2e > [uncertain: EOPing] 0021F8090C3A" **Entities and technical-historical reconstruction.** [[Mi Smart Band 5]] is a Xiaomi fitness tracker.[^mi-band] [[Bose SoundLink Color II]] is a portable Bluetooth speaker introduced in 2016.[^bose-color] [[Amazfit GTS 2e]] is a smartwatch introduced around CES 2021.[^amazfit] The prefix “LE” before the Bose name likely denotes [[Bluetooth Low Energy]], a label commonly exposed in discovery lists, though the speaker’s exact advertising behavior cannot be inferred from the notebook alone. `0021F8090C3A` has the twelve-hexadecimal-character shape of a 48-bit hardware address, but without separators or a label it could also be a serial or application-generated identifier. It is retained as a device identifier. **Page-level interpretation.** The page inventories **wearables and ambient Bluetooth devices** alongside a Samsung account and phone. This is important in device attribution because account dashboards, Bluetooth scans, and mobile logs may show these devices under inconsistent names. The writer appears to be building a translation table between commercial product names and machine-visible identifiers. **Evidentiary status.** Product names are visible and historically verified. The final identifier’s type remains uncertain. #### Missed Signals and Open Leads “Facebook: Facebook” may be an autofill username/password mnemonic, an application label, or a note that Samsung’s Facebook field used the literal word. It is not treated as a valid credential. A Bluetooth scan export could map the hexadecimal identifier to one of the listed devices. --- ### Scanned_20260730-1958.pdf — PDF page 33 **Visible page.** Alphabetical heading “T.” A single name and phone number appear near the top. **Faithful transcription.** > "T > [PERSON REDACTED] > xxx-xxx-xxxx (see Scanned_20260730-1958.pdf, page 33)" **Entities and technical-historical reconstruction.** “[PERSON REDACTED]” is an unresolved private contact. **Page-level interpretation.** Like pages 30 and 33, this leaf preserves the notebook’s address-book substrate beneath its technical use. **Evidentiary status.** Visible evidence only. #### Missed Signals and Open Leads The absence of surname, organization, and location prevents disambiguation. Phone-tail matching across the private archive would be the appropriate future method. --- ### Scanned_20260730-1958.pdf — PDF page 34 **Visible page.** The upper half is a keyboard-command and virtualization/network note. Commands are separated by semicolons and letters. A link-local IP address is centered. The lower section contains “advocacy / wells” and a phone number. **Faithful transcription.** > "Alt F4 close win > then ctrl+F4 for KVM > q,c,r,s,e > 169.254.217.237 > [uncertain: Xep NG] > [uncertain: proxd my/] > > advocacy > wells > xxx-xxx-xxxx (see Scanned_20260730-1958.pdf, page 34)" **Entities and technical-historical reconstruction.** `Alt+F4` is the standard window-close shortcut in many desktop environments. [[Kernel-based Virtual Machine|KVM]] is the Linux kernel virtualization subsystem, but “ctrl+F4 for KVM” may instead refer to switching or closing a console/tab in a particular KVM application or physical keyboard-video-mouse interface. `169.254.217.237` lies inside **169.254.0.0/16**, reserved for IPv4 link-local addressing when a host cannot obtain or is not configured with a routable address.[^rfc3927] “Xep NG” may read [[EVE-NG]]—a network-emulation platform—or another virtualization term, but the handwriting is insufficient for normalization. “proxd my/” could be Proxmox, proxy, or a URL fragment. **Page-level interpretation.** The page records a **console-access problem**: window-management shortcuts, virtualization controls, and a self-assigned link-local address. A 169.254 address commonly indicates that two endpoints can see a local link but lack DHCP or broader network configuration. The writer may have been attempting to reach a virtual appliance, KVM console, or directly connected host. **Evidentiary status.** The IP range interpretation is verified. Product identifications beyond KVM remain uncertain. #### Missed Signals and Open Leads The sequence `q,c,r,s,e` may be single-key console commands. If “Xep NG” is actually EVE-NG or Xen, the page could document a specific hypervisor. The adjacent “advocacy / wells” entry may be unrelated and should not be folded into the technical interpretation. --- ### Scanned_20260730-1958.pdf — PDF page 35 **Visible page.** Alphabetical heading “W.” The upper section contains Wells-related login material, then two Dell Latitude models with boot and management shortcuts. A lower divider introduces a “special number” for credit-card/Wells support. **Faithful transcription.** > "W > wells > bbmcgill7 > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 35] > Lat E7450 > Intel mgmt engine Bios Ext > ctrl+P / F12 > Raid > ctrl+I > > Lat E6420 > special number > For CC @ wells > xxx-xxx-xxxx (see Scanned_20260730-1958.pdf, page 35)" **Entities and technical-historical reconstruction.** [[Dell Latitude E7450]] and [[Dell Latitude E6420]] are business-class Dell laptops from different generations. [[Intel Management Engine BIOS Extension|Intel MEBx]] is entered on supported systems with `Ctrl+P` during startup, while `F12` commonly invokes Dell’s one-time boot menu.[^intel-mebx] Intel’s legacy RAID option ROM uses `Ctrl+I` to enter the Intel Rapid Storage Technology configuration utility on supported systems.[^intel-rst] [[Wells Fargo]] appears as a banking/credit-card contact context. The page does not establish that the bank and laptop notes are technically related; they are simply adjacent under “W.” **Page-level interpretation.** This page is a **firmware-level access map**. The writer knew that operating-system access was not the only control plane: Intel AMT/Management Engine, boot selection, and RAID metadata persist below the desktop. This is a more sophisticated device-recovery posture than ordinary password notes. **Cross-notebook connection.** [[Scanned_20260730-1230]] page 2 also records Wells Fargo access material and device/account identities. The recurrence suggests an ongoing effort to align financial access with known machines, rather than a one-time login note. **Evidentiary status.** Keyboard shortcuts and device families are technically verified. No claim is made that Intel AMT was provisioned or remotely managed. #### Missed Signals and Open Leads The notebook does not record BIOS versions, service tags, AMT provisioning state, RAID volume names, or storage serials. Those details would determine whether `Ctrl+P` and `Ctrl+I` were actually available on the specific machines. --- ### Scanned_20260730-1958.pdf — PDF page 36 **Visible page.** An email-like string appears at top, followed by a four-digit code, `g.co/recover`, and an address fragment. **Faithful transcription.** > "bryantmcgill.com@gmail > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 36] > g.co/recover > 9663 Santa Monica" **Entities and technical-historical reconstruction.** `g.co/recover` is Google’s shortened route to the official [[Google Account Recovery]] process, used when a user cannot sign in or needs to verify identity.[^google-recovery] The first line may be a malformed or mnemonic email rather than a syntactically complete address. “9663 Santa Monica” could be an address fragment used for location, billing, or account verification. **Page-level interpretation.** This is a **recovery challenge page**: remembered identity, verification code, official recovery URL, and address clue. The coexistence of a physical address and digital recovery endpoint shows how platform identity can depend on historical biographical data. **Evidentiary status.** The URL and text are visible; the role of the address is unresolved. #### Missed Signals and Open Leads The city/state for “9663 Santa Monica” is absent. The first line should not be silently corrected to a valid Gmail address. A clearer occurrence elsewhere may show whether `.com@gmail` was shorthand for an account name or an accidental transposition. --- ### Scanned_20260730-1958.pdf — PDF page 37 **Visible page.** Very sparse page with two account lines at the top. Strong mirrored bleed-through from the reverse page is visible across the sheet. **Faithful transcription.** > "accounts.google.com > [email protected]" **Entities and technical-historical reconstruction.** The page associates a role mailbox with Google’s sign-in domain. The absence of a written secret may mean the page was a heading for the next leaf, a reminder to attempt recovery, or a clean account locator after earlier password revisions. **Page-level interpretation.** The blank space is meaningful: unlike credential-dense pages, this one preserves only the **identity endpoint**. It may mark a transition from remembering passwords to using formal account recovery. **Evidentiary status.** Visible evidence only. #### Missed Signals and Open Leads Bleed-through should not be transcribed as page-37 writing. The account’s Workspace tenant, recovery phone, and administrator role remain unknown. --- ### Scanned_20260730-1958.pdf — PDF page 38 **Visible page.** The same Google account pair appears at top. A blue sticky note overlays the center with an admin email/domain and a credential. `admin.google.com` is crossed or underlined beneath it. The bottom contains a difficult domain-verification-like string. **Faithful transcription.** > "accounts.google.com > [email protected] > [blue sticky note] > [uncertain: [email protected]] > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 38] > ~~admin.google.com~~ > [uncertain: www.arlsj.com.test-google-a.com]" **Entities and technical-historical reconstruction.** [[Google Admin Console]] at `admin.google.com` is the administrative surface for Google Workspace organizations, where administrators create users, configure services, domains, security, and organizational settings.[^google-admin] The bottom string resembles either a copied DNS/domain-verification token, an intentionally constructed test hostname, or several domains run together. It should not be normalized into a live domain without corroboration. **Page-level interpretation.** This page captures a **tenant-administration hypothesis**. The writer was distinguishing ordinary Google account sign-in from organizational administration and experimenting with an admin identity or domain verification route. The sticky note again functions as a revision layer. **Evidentiary status.** Google Admin identification is verified. The `arlsj.com` reading and test string are uncertain. #### Missed Signals and Open Leads A Google Workspace domain-verification record normally appears in DNS as a TXT or CNAME token. DNS-history archives for the uncertain domain might establish whether the bottom text copied such a record. Because the domain reading is uncertain, no live lookup should be treated as dispositive. --- ### Scanned_20260730-1958.pdf — PDF page 39 **Visible page.** Multiple Google/Gmail identity variants, numeric codes, “was” notations, and phone recovery material fill the page. Several entries are crossed or superseded. A family-based mnemonic appears at bottom and functions as a secret; it is not reproduced. **Faithful transcription.** > "[REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 39] > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 39] > [email protected] > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 39] > was [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 39] > bryantmcgill@gmail > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 39] > xxx-xxx-xxxx (see Scanned_20260730-1958.pdf, page 39) > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 39]" **Entities and technical-historical reconstruction.** The written `[email protected]` is syntactically possible as a Gmail local part containing a period before `com`, but it may also be a mistaken fusion of a domain and Gmail address. The repeated “was” notation indicates password or PIN versioning. **Page-level interpretation.** This is a **manual credential history**, not a clean current-state record. It preserves prior values, variants, and recovery contacts, likely because the writer was testing which identity formulation a provider recognized. The page demonstrates the limits of paper recovery: without timestamps and service labels, remembered variants can become indistinguishable. **Evidentiary status.** Visible account variants; all codes, phone numbers, and mnemonic secrets redacted. #### Missed Signals and Open Leads The exact service attached to each code is unclear. Email-header evidence, Google security-event exports, and browser autofill databases could reconstruct the chronology more reliably than the page alone. --- ### Scanned_20260730-1958.pdf — PDF page 40 **Visible page.** A short list of names/institutions with phone numbers appears at top: [PERSON REDACTED], and FBI Austin. Below are “Fi,” an account number, and a PIN field. **Faithful transcription.** > "[PERSON REDACTED] > xxx-xxx-xxxx (see Scanned_20260730-1958.pdf, page 40) > [PERSON REDACTED] > xxx-xxx-xxxx (see Scanned_20260730-1958.pdf, page 40) > [PERSON REDACTED] > xxx-xxx-xxxx (see Scanned_20260730-1958.pdf, page 40) > FBI Austin > xxx-xxx-xxxx (see Scanned_20260730-1958.pdf, page 40) > Fi > account 82908 > pin [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 40]" **Entities and technical-historical reconstruction.** [[Federal Bureau of Investigation|FBI Austin]] is written as a contact label, but the notebook does not show whether the number was a public field office, an individual, a tip line, or a personally supplied contact. “[PERSON REDACTED]” and “[PERSON REDACTED]” are not disambiguated. “Fi” may refer to [[Google Fi]], a financial institution, a device/service abbreviation, or a truncated word. **Page-level interpretation.** This page is a **contact escalation ladder**: personal names, a federal office label, and an account/PIN block. The material does not prove an active case, communication, or institutional relationship; it proves only that these contacts were important enough to preserve together. **Cross-notebook connection.** Other notebooks combine named contacts with systems, intelligence, and infrastructure notes. This recurrent pattern should be treated as a personal operational index, not as evidence that every adjacent entity participated in one coordinated event. **Evidentiary status.** Visible labels; all phone numbers and PIN redacted. Institutional relationship unresolved. #### Missed Signals and Open Leads The recurrence of [PERSON REDACTED] from page 19 is the primary lead. “[PERSON REDACTED]” might be a person, project, company, or product. The account number `82908` is retained because it is not independently usable as a credential, but its issuing institution is unknown. --- ### Scanned_20260730-1958.pdf — PDF page 41 **Visible page.** A compact account block occupies the upper-left. “TLS School” is followed by a role-like educational email, a credential, and a phone number. **Faithful transcription.** > "TLS School > [email protected] > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 41] > xxx-xxx-xxxx (see Scanned_20260730-1958.pdf, page 41)" **Entities and technical-historical reconstruction.** `edu.gomcgill.com` appears to be a subdomain used for an educational project or organizational mailbox. “TLS” could mean a school name or project acronym. Although [[Transport Layer Security|TLS]] is a standard networking acronym, the explicit word “School” makes automatic expansion technically unjustified. **Page-level interpretation.** The page preserves an **education-branded identity** within the broader GoMcGill domain estate. A subdomain-based mailbox would allow project separation while remaining dependent on the parent domain’s DNS and mail administration. **Evidentiary status.** Visible evidence. Acronym unresolved. #### Missed Signals and Open Leads DNS history, archived webpages, or email headers for `edu.gomcgill.com` could identify the project and mail provider. “TLS School” should remain a provisional canonical note until another occurrence supplies the full name. --- ### Scanned_20260730-1958.pdf — PDF page 42 **Visible page.** A green sticky note covers much of the page. Two email identities and credential blocks are separated by the word “today.” **Faithful transcription.** > "[green sticky note] > [email protected] > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 42] > today > [uncertain: [PRIVATE NAME REDACTED]] > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 42]" **Entities and technical-historical reconstruction.** `@me.com` and `@icloud.com` are Apple-hosted email identities associated historically with MobileMe and iCloud. The two addresses appear to belong to different personal identities but may have participated in the same recovery or device-sharing event. **Page-level interpretation.** The word “today” gives the page the character of a **live credential-change note**. Sticky paper was used to overlay a current state on top of the permanent notebook, implying the values were expected to change again. **Evidentiary status.** Visible email identities; secrets redacted. The second address remains uncertain. #### Missed Signals and Open Leads The page lacks an explicit date. Its position among February 2022 notes makes that period plausible but not certain. Apple account-security emails could date the change precisely. --- ### Scanned_20260730-1958.pdf — PDF page 43 **Visible page.** “One of the iPads” appears at top with a credential. A torn green sticky note below contains an email at the legacy `tx.rr.com` domain and repeated secret material. Small lower fragments are difficult to classify. **Faithful transcription.** > "One of the iPads > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 43] > [green torn sticky note] > [email protected] > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 43] > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 43] > [small lower account fragments, partly illegible]" **Entities and technical-historical reconstruction.** [[iPad]] identifies a device class but not a generation. `tx.rr.com` is a legacy Road Runner/Time Warner Cable regional email domain, indicating an older ISP-based identity that may predate current provider branding. **Page-level interpretation.** The phrase “One of the iPads” signals **device multiplicity without unique naming**. That is a recurrent source of attribution failure: backups, Apple device lists, and browser sessions may show several iPads with similar names. The sticky note links one of them to an external email identity, but the role—owner, recovery contact, app account, or device setup address—is not stated. **Evidentiary status.** Visible evidence; credentials redacted. #### Missed Signals and Open Leads The iPad’s model, serial, Apple Account, and backup identifier are missing. The email surname could connect to a person index, but no identity should be inferred from an address alone. --- ### Scanned_20260730-1958.pdf — PDF page 44 **Visible page.** A dense boot/configuration page. The upper section records boot behavior and a password. The middle lists a “monthly Pin calculator,” seed/test values, and an instruction to enable “fastload” and a splash image. A domain-like string and a March 2016 expiration note appear at bottom. **Faithful transcription.** > "boot with > cap lock on > pass word easy2boot > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 44] > monthly Pin calculator > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 44] > [seed / attempts / test PIN values redacted] > enable fastload & use splashimg for master password > [uncertain: rmpreuse.com] > 14 day expire > from 20 march 2016" **Entities and technical-historical reconstruction.** [[Easy2Boot]] is a USB multiboot environment built around grub4dos and later related boot technologies, designed to launch multiple ISO and image payloads from one drive. “fastload,” “splashimg,” hotkeys, and master-password behavior are consistent with a customized boot menu rather than a conventional operating-system login. The page’s PIN-calculator language could describe a personal rotating-code scheme, a software license mechanism, or a configuration experiment; no algorithm is visible. **Page-level interpretation.** This is a **portable boot-environment security design**. The writer was experimenting with boot gating, menu concealment, timed expiration, and visual customization. The page does not establish malicious intent; multiboot media is routinely used for installation, diagnostics, recovery, and forensics. **Cross-notebook connection.** [[Scanned_20260730-1235]] explicitly catalogs obscure commands and access methods. Page 44 is a concrete implementation of that interest at pre-OS boot level. **Evidentiary status.** Visible configuration notes. All generated or password-like values redacted. The uncertain domain was not tested. #### Missed Signals and Open Leads The meaning of Caps Lock at boot, the PIN calculation formula, and the “14 day expire” mechanism are not documented. A surviving Easy2Boot USB image, `menu.lst`, `grub.cfg`, or custom batch file would allow exact reconstruction. --- ### Scanned_20260730-1958.pdf — PDF page 45 **Visible page.** A continuation of the Easy2Boot page. Function keys and control-key combinations are mapped to actions. The final line appears to describe an Fn/Escape lock function. **Faithful transcription.** > "ctrl+F8 grub hotkey > F11 boot to ISO > F9 clear grub hot key > F6 utilities > ctrl+F9 hide menu pw=[REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 45] > ctrl+F10 reset pw > ctrl+R reload refresh > [uncertain: Fn + esc … lock]" **Entities and technical-historical reconstruction.** Easy2Boot documentation confirms that `Ctrl+F8` can reload grub4dos/E2B, and its global-hotkey framework supports custom key mappings that launch ISO files or menu actions.[^easy2boot] The exact `F11`, `F9`, `F6`, and `Ctrl+F10` meanings may therefore be personal customizations rather than universal defaults. **Page-level interpretation.** The page is effectively a **human-readable control schema** for a customized recovery drive. It preserves the interface contract needed to operate an otherwise opaque boot environment: launch payloads, clear or hide menus, reset access, and reload configuration. **Evidentiary status.** Visible evidence plus verified Easy2Boot hotkey capability. Only `Ctrl+F8` is confidently matched to official behavior; other mappings remain configuration-specific. #### Missed Signals and Open Leads The referenced ISO image names are absent. A future device inventory should search for Easy2Boot partitions, `_ISO` directories, custom `menu.lst` files, and dated March 2016 payloads. --- ### Scanned_20260730-1958.pdf — PDF page 46 **Visible page.** A short ownership/provenance note occupies the upper half. A person’s name, “free chromebook,” and “managed by chisd.net” are written on separate lines. **Faithful transcription.** > "[uncertain: [PERSON REDACTED] Neem / [PERSON REDACTED] Neam] > free chromebook > from [PERSON REDACTED] > ‘managed by chisd.net’" **Entities and technical-historical reconstruction.** `chisd.net` corresponds to [[Cedar Hill Independent School District|Cedar Hill ISD]], which operates a Chromebook program and publishes student Chromebook resources.[^chisd] A Chromebook displaying “managed by chisd.net” would ordinarily indicate enterprise enrollment under the district’s Google administrative domain. **Page-level interpretation.** This is a **device-custody and management-state note**. The important fact is not merely that the Chromebook was free; it remained organizationally managed. That state can constrain extensions, accounts, updates, certificates, network settings, powerwashing, and re-enrollment. **Evidentiary status.** The management banner is a notebook transcription, not independently inspected hardware. The giver’s name remains uncertain. #### Missed Signals and Open Leads The device may have been legitimately decommissioned without being removed from enterprise enrollment, loaned, transferred improperly, or simply still displaying stale management metadata. Serial number, asset tag, and district disposition records would be needed before drawing conclusions. --- ### Scanned_20260730-1958.pdf — PDF page 47 **Visible page.** A password label and several standalone alphanumeric or numeric strings occupy the upper half. No service names are present. **Faithful transcription.** > "PW: [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 47] > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 47] > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 47] > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 47]" **Entities and technical-historical reconstruction.** No service, device, or account can be identified from the visible page. The values are credential-equivalent and therefore fully redacted. **Page-level interpretation.** The page demonstrates a recurring weakness in the notebook’s recovery method: **secrets without scope**. A value is not recoverable knowledge unless its service, account, date, and state are also known. **Evidentiary status.** Visible secret structure; values redacted. #### Missed Signals and Open Leads Page position suggests proximity to the managed Chromebook and Google accounts, but adjacency is not enough to assign the passwords. Handwriting comparison may reveal whether different values were added at different times. --- ### Scanned_20260730-1958.pdf — PDF page 48 **Visible page.** Sparse page with a short date/database notation and a solitary “W.” **Faithful transcription.** > "S: Data base 3 2020 > W" **Entities and technical-historical reconstruction.** “Data base 3 2020” may denote a database version, a March 2020 date, a notebook category, or a dataset label. No product or schema is named. **Page-level interpretation.** This may be an **index stub** for content that was never completed. The isolated “W” could be an alphabetical marker, status, initial, or continuation from another page. **Evidentiary status.** Visible evidence only. #### Missed Signals and Open Leads The spacing does not resolve whether “3 2020” means “March 2020.” Search the cumulative project index for “Database 3,” “S database,” and similar handwriting. --- ### Scanned_20260730-1958.pdf — PDF page 49 **Visible page.** Four lines describe Gmail, Google Workspace, “SMB Gate,” a phone appearing as a Nexus 5, and then “LaunchTime” and “blueline Console.” “Nice” is crossed out. **Faithful transcription.** > "Gmail seems to be > currents & Google Workspace > SMB Gate uses Gmail! > and thinks phone is a > Nexus 5 > ~~Nice~~ > LaunchTime > blueline Console" **Entities and technical-historical reconstruction.** [[Google Workspace]] provides organizational Gmail, making the first lines consistent with account/tenant investigation. “SMB Gate” is unresolved: it could be a small-business gateway, a Server Message Block gateway, a product name, or a personal label. The device-identity line is technically significant. Google’s Android source documentation identifies **`blueline` as the codename for Pixel 3**, whereas [[Nexus 5]] is an older LG-built Google phone with different codenames and hardware lineage.[^android-codenames] Thus “thinks phone is a Nexus 5” and “blueline Console” describe a mismatch if copied from the same interface. “LaunchTime” may be a timestamp field, application, or console metric. **Page-level interpretation.** This page documents **identity inconsistency across management surfaces**. A console may have shown one marketing model, another hardware codename, and a Google Workspace/Gmail context. Such mismatches can arise from stale device records, user-agent spoofing, restored backups, custom ROMs, emulator profiles, mislabeled management data, or simple conflation of separate entries. The page records the anomaly but does not choose among causes. **Cross-notebook connection.** Page 3 similarly records desktop Linux components in a Pixel-associated context. Together they show a recurring effort to reconcile **what a device claims to be, what software lineage it exposes, and what account console calls it**. **Evidentiary status.** The codename-to-device mapping is verified. The underlying console and phone are not identified. #### Missed Signals and Open Leads A screenshot of the “blueline Console” would determine whether this was Google Admin, Android Debug Bridge, a custom ROM dashboard, Firebase, or another system. Device serial, Android ID, build fingerprint, and user agent would resolve whether the mismatch was superficial or architectural. --- ### Scanned_20260730-1958.pdf — PDF page 50 **Visible page.** Alphabetical heading “P.” A crossed identifier and a phone-like number appear above a possible automobile-business name. Below a divider are two domains and the years 1996 and 2006. **Faithful transcription.** > "P > ~~[crossed numeric/string identifier]~~ > xxx-xxx-xxxx (see Scanned_20260730-1958.pdf, page 50) > [uncertain: Carway auto] > > Lionheart.net > ChangeUpdate.com > 1996: > 2006:" **Entities and technical-historical reconstruction.** [[Lionheart.net]] and [[ChangeUpdate.com]] are domain names or remembered domain-like strings. The years may indicate registration, use, project launch, or historical comparison. No ownership claim should be inferred solely from handwriting. **Page-level interpretation.** The lower block resembles **domain chronology reconstruction**—an attempt to remember which digital property existed in 1996 versus 2006. This is consistent with the notebook’s wider concern with long-lived online identity. **Evidentiary status.** Visible evidence; no live-domain or ownership conclusion. #### Missed Signals and Open Leads Historical WHOIS, Internet Archive captures, registrar receipts, and old email headers could determine whether the years correspond to creation, acquisition, expiration, or project milestones. The automobile-related name is too uncertain for normalization. --- ### Scanned_20260730-1958.pdf — PDF page 51 **Visible page.** The scanned page is upside down relative to the rest of the PDF. When mentally rotated 180 degrees, it shows GoDaddy, two number/name blocks, a phrase involving [PERSON REDACTED], several long identifiers, and a circled year sequence “2006” and “2005 → April.” **Faithful transcription.** > "godaddy > #1716642 [uncertain: web…ss] > [REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 51] > #1545530 [PERSON REDACTED] > [PERSON REDACTED] 2 acts > 12203544 > 27142000 > 2006 > 2005 → > april" **Entities and technical-historical reconstruction.** [[GoDaddy]] is the only certain service. The hash-prefixed values may be customer IDs, support tickets, account numbers, order numbers, or project references. The two eight-digit values are retained as identifiers because the page does not label them as passwords; the separate secret-like string near the first GoDaddy block is redacted. **Page-level interpretation.** This appears to be a **registrar history page** connecting account identifiers, people, and dates. The upside-down scan is a capture artifact, not evidence that the notebook was written inverted. **Evidentiary status.** Visible identifiers and names; roles unresolved. #### Missed Signals and Open Leads “[PERSON REDACTED]” may be a GoDaddy representative, customer, domain contact, or unrelated person. “[PERSON REDACTED] 2 acts” may read “[PERSON REDACTED] 2 accts,” which would fit account reconstruction, but the scan is insufficient to silently normalize it. GoDaddy support archives keyed by the visible IDs could resolve the page. --- ### Scanned_20260730-1958.pdf — PDF page 52 **Visible page.** Two clusters of numbers are arranged like categories or mappings. The left begins with a circled `1001`, then `1002`, `3001`, `3002`, `3003`, and `3005`. The right has a short heading and circled `2010`. **Faithful transcription.** > "[uncertain heading: Last] > 1001 > 1002 > 3001 > 3002 > 3003 > 3005 > [uncertain heading: new] > 2010" **Entities and technical-historical reconstruction.** These values could be extension numbers, account classes, ports, room/unit codes, model families, status codes, or chronological labels. No accompanying noun constrains them. **Page-level interpretation.** The spatial grouping suggests a **mapping from an old series to a new series**, but the domain of that mapping is unknown. **Evidentiary status.** Visible numbers; interpretation unresolved. #### Missed Signals and Open Leads Search neighboring notebooks for the same number set. Their regular four-digit form makes exact-match retrieval across OCR or manual indexes especially valuable. --- ### Scanned_20260730-1958.pdf — PDF page 53 **Visible page.** The top contains a short uncertain word/name and a crossed or circled acronym. Below a divider are “white house,” “camala harris,” a White House phone number, and an uncertain “Swifty” phrase. **Faithful transcription.** > "[uncertain: Seu] > ~~[uncertain: PSA / Ki]~~ > > white house > camala harris > xxx-xxx-xxxx (see Scanned_20260730-1958.pdf, page 53) > [uncertain: W4 SWIFTY / WY Swifty]" **Entities and technical-historical reconstruction.** [[The White House]] and [[Index - People#Kamala Harris|Kamala Harris]] are clearly intended, although the notebook spells the first name “camala.” The phone number is redacted under the project’s universal phone rule, regardless of whether it may have been publicly listed. **Page-level interpretation.** This is a **political contact/reference page**, not a developed political argument. The uncertain “Swifty” phrase may name a person, organization, campaign shorthand, or unrelated note. **Evidentiary status.** Visible names; no claim of direct contact or relationship. #### Missed Signals and Open Leads The crossed acronym at top may be a person or organization that explains the political references. A clearer scan or repeated note is needed before expanding it. --- ### Scanned_20260730-1958.pdf — PDF page 54 **Visible page.** Two political/media clusters are separated by a horizontal divider. The upper group names Shaun King, Real Justice, PAC, BLM, and North Star. The lower group names [PERSON REDACTED], a science film festival, an email, phone number, and “(Can trust).” **Faithful transcription.** > "Shaun King > Real Justice! > PAC > BLM > North Star > > [PERSON REDACTED] > Founder of Pow Science Film Festival > [PRIVATE EMAIL REDACTED] > xxx-xxx-xxxx (see Scanned_20260730-1958.pdf, page 54) > (Can trust)" **Entities and technical-historical reconstruction.** [[Index - People#Shaun King|Shaun King]] co-founded [[Real Justice PAC]], a political action committee focused on local criminal-justice elections, and relaunched [[The North Star]] as a media platform.[^real-justice][^north-star] [[Black Lives Matter|BLM]] is written as part of that topical cluster, but the page does not specify an organizational chapter or formal relationship. The lower festival name is almost certainly a handwriting error for the [[Raw Science Film Festival]]. [PERSON REDACTED] is identified by the festival’s own site as its founder/president.[^raw-science] The phrase “(Can trust)” is the writer’s personal assessment and should be preserved as such, not converted into an external endorsement. **Page-level interpretation.** The page is a **trust-and-influence map**. The upper half tracks activist media, electoral intervention, and movement branding. The lower half records a specific person, role, contact route, and explicit trust judgment. This shows the notebook being used to distinguish institutional affinity from interpersonal reliability. **Evidentiary status.** Public organizational relationships are independently verified. The trust assessment is subjective notebook evidence. #### Missed Signals and Open Leads “Pow Science” should remain in transcription even though “Raw Science” is the verified referent. The reason these two clusters share a page is not stated; they may have been written at different times. --- ### Scanned_20260730-1958.pdf — PDF page 55 **Visible page.** A single seven-digit number is written near the top. No label or surrounding text is present. **Faithful transcription.** > "[REDACTED CREDENTIAL — see Scanned_20260730-1958.pdf, page 55]" **Entities and technical-historical reconstruction.** The number could be an account, ticket, PIN, recovery code, extension, or reference. With no context, publication would create unnecessary credential risk, so it is conservatively redacted. **Page-level interpretation.** The page is an **orphan identifier** whose informational value depends entirely on future linkage. **Evidentiary status.** Visible numeric string; redacted by precaution. #### Missed Signals and Open Leads A private archival version could retain the exact value for exact-match searching across email, banking, support tickets, or device records. In the public reconstruction, the page reference preserves retrievability without disclosure. --- ### Scanned_20260730-1958.pdf — PDF page 56 **Visible page.** A rent-like numeric range appears at top. “MANOR” is partly crossed or rewritten as “MANOR House.” The address is written across several lines, followed by a phone number. **Faithful transcription.** > "$1250-800 > ~~[uncertain: MANOR H…]~~ > MANOR House > [uncertain: Heller] > 1222 Commerce > ST Dallas TX > 75202 > xxx-xxx-xxxx (see Scanned_20260730-1958.pdf, page 56)" **Entities and technical-historical reconstruction.** [[Manor House Dallas|Manor House]] is a residential high-rise at **1222 Commerce Street, Dallas, Texas 75202**, matching the notebook.[^manor-house] The numeric range likely represents monthly rent or target pricing, although the descending order `$1250-800` may reflect two quoted figures rather than a formal range. **Page-level interpretation.** This begins a three-page **Dallas housing comparison**. Address, price, and phone are sufficient for a rapid screening list. The writer was likely evaluating downtown residences near contacts or work. **Evidentiary status.** Property/address verified. Price interpretation is strong but not explicit. #### Missed Signals and Open Leads “Heller” may be a leasing contact, nearby property, or misread word. Historical 2022 listings could test whether the written price range matched Manor House availability at that time. --- ### Scanned_20260730-1958.pdf — PDF page 57 **Visible page.** `$1500` appears at top, followed by “ARRIVE Apt,” a complete Dallas address, weekday hours, phone number, and “NEAR [PERSON REDACTED].” **Faithful transcription.** > "$1500 > ARRIVE Apt > 800 Ross Ave > Dallas TX > 75202 > Mon-Fri > 8:30am-5:30pm > xxx-xxx-xxxx (see Scanned_20260730-1958.pdf, page 57) > NEAR [PERSON REDACTED]" **Entities and technical-historical reconstruction.** [[Arrive West End]] is located at **800 Ross Avenue, Dallas, Texas 75202**, exactly matching the notebook.[^arrive-west-end] Current posted office hours differ from the handwritten 8:30–5:30, which is expected because management schedules can change; the notebook should be read as a 2022-era contact record. **Page-level interpretation.** “NEAR [PERSON REDACTED]” connects housing search to the recurring contact from pages 2 and 18. This is strong evidence that at least part of the Dallas search was organized around **proximity to a person or REDACTED location**, not price alone. **Evidentiary status.** Property/address verified. The identity and location of [PERSON REDACTED] remain unresolved. #### Missed Signals and Open Leads A map of the written Dallas addresses against the page-2 “other office” may reconstruct the intended neighborhood and route. Historical lease quotes could explain the `$1500` figure. --- ### Scanned_20260730-1958.pdf — PDF page 58 **Visible page.** `$1000-1100` is written at top. “Deep Ellum / Lofts” forms one property block. A divider separates it from “The Wilson / Building” and a Main Street address. **Faithful transcription.** > "$1000-1100 > Deep Ellum > Lofts > > The Wilson > Building > 1623 Main St. > Dallas TX 75201" **Entities and technical-historical reconstruction.** [[Deep Ellum Lofts]] is a Dallas apartment community associated with the Deep Ellum district.[^deep-ellum-lofts] The [[Wilson Building (Dallas)|Wilson Building]] stands at **1621–1623 Main Street** and is a historic downtown structure later adapted to residential lofts.[^wilson-building] The notebook’s “1623 Main St.” is therefore precise. **Page-level interpretation.** The page compares **neighborhood identity and historic adaptive reuse**: Deep Ellum’s cultural district against a landmark downtown building. Price bands are lower than the preceding Arrive entry, suggesting budget and location tradeoffs. **Evidentiary status.** Both property references are verified. The dollar figure is assumed to be rent only because of the surrounding housing pages. #### Missed Signals and Open Leads The page does not specify whether “Deep Ellum Lofts” refers to the named management portfolio or lofts generically in the district. Historical unit availability would clarify which property was actually contacted. --- ### Scanned_20260730-1958.pdf — PDF page 59 **Visible page.** Two phone-like numeric strings are written at the upper left, one split across two lines. A long swooping underline or flourish extends across the page. The lower two-thirds are blank. **Faithful transcription.** > "xxx-xxx-xxxx (see Scanned_20260730-1958.pdf, page 59) > xxx-xxx-xxxx (see Scanned_20260730-1958.pdf, page 59)" **Entities and technical-historical reconstruction.** No name, organization, property, or service is attached. Because both strings are phone-like, they are redacted even though one lacks a clearly written area code. **Page-level interpretation.** Given the immediately preceding housing pages, these may be leasing contacts; that remains only a positional inference. **Evidentiary status.** Visible phone-like strings; redacted. #### Missed Signals and Open Leads Private exact-number matching against call logs or property websites could identify the contacts. The public archive preserves only the page location. --- ### Scanned_20260730-1958.pdf — PDF page 60 **Visible page.** The final page contains “[PERSON REDACTED]” handwritten at top. The rest is a printed publisher colophon identifying the notebook, publisher, ISBN, designers, copyright year, address, and manufacturing location. **Faithful transcription.** > "[PERSON REDACTED] > > See our range of fine, illustrated books, ebooks, notebooks and art calendars: > www.flametreepublishing.com > > This is a FLAME TREE NOTEBOOK > > Published and © copyright 2020 Flame Tree Publishing Ltd > > FTPF03 • 978-1-78755-873-1 > > Edge detail is created by Flame Tree Studio and based on artwork by Knopazyzy, Anastasia Zenina-Lembrik and Uncleaux/Shutterstock. > > FLAME TREE PUBLISHING | The Art of Fine Gifts > > 6 Melbray Mews, London SW6 3NS, United Kingdom > > All rights reserved. Printed in China. Created in the UK." **Entities and technical-historical reconstruction.** [[Flame Tree Publishing]] produces illustrated and art-oriented notebooks, often with decorated page edges and gift-format binding.[^flame-tree] The printed copyright date establishes **2020 as the earliest possible notebook manufacture**, not necessarily the date the handwritten content began. The ISBN-like identifier `978-1-78755-873-1` and product code `FTPF03` provide stable bibliographic identifiers for the physical object. “[PERSON REDACTED]” may be an ownership inscription, a contact, or a reminder. Its possible relationship to the page-3 name is notable but unresolved. **Page-level interpretation.** The colophon closes the evidentiary loop by identifying the physical artifact and providing a terminus post quem. Since explicit writing dates reach February 2022, the notebook was used within roughly two years of manufacture. **Evidentiary status.** Printed matter and handwritten name are directly visible. #### Missed Signals and Open Leads The precise commercial design corresponding to ISBN `978-1-78755-873-1` should be added to the object catalog if a reliable publisher or library record is found. “[PERSON REDACTED]” warrants cross-notebook comparison with page 3’s uncertain “Gray/[PERSON REDACTED].” --- # Notebook-Level Synthesis ## Probable Date Range **Explicit temporal evidence.** The notebook itself supplies the following anchors: | PDF page | Visible date or year | Evidentiary meaning | |---:|---|---| | 3 | “Feb 8th 2022” | Direct date attached to the Akonadi/KIO discovery note. | | 4 | “2/8/22” | Direct or near-direct date attached to the Linux component list. | | 14 | “[uncertain: … 2022/02]” | Probable February 2022 account-recovery note. | | 18 | “Sat Feb 12th 2022” | Direct date attached to Austin contacts. | | 6 | “Late 2020” | Device-generation note for MacBook Air A2337. | | 7 | “12/22/17” | Historical Apple business identity date. | | 44 | “20 march 2016” | Historical Easy2Boot/PIN-expiration note. | | 48 | “3 2020” | Ambiguous database/date notation. | | 50–51 | “1996,” “2006,” “2005,” “april” | Historical domain/registrar chronology fragments. | | 60 | Printed copyright 2020 | Manufacturing terminus post quem for the physical notebook. | **Probable active-use range.** The physical notebook cannot predate its printed 2020 copyright. The densest coherent writing episode falls in **February 2022**, with older information copied forward from 2016–2021. The best reconstruction is therefore: **manufactured in or after 2020; used intermittently from late 2020 through February 2022; carrying historical account and project information reaching back to at least 1996.** ## Executive Reconstruction This notebook records a period in which **digital identity, physical devices, cloud infrastructure, and geographic mobility had become one entangled recovery problem**. The writer was simultaneously trying to remember or regain control of email identities, social accounts, Apple and Google organizational systems, domain registrars, cloud servers, hosting automation, encrypted iPhone backups, mobile routers, laptops, managed Chromebooks, and residences in Austin and Dallas. The notebook is not well described as a password book, because passwords are only one layer. It is better understood as a manual [[Identity Dependency Graph|identity and continuity graph]] whose nodes include: **identity roots** — owned domains, role mailboxes, Gmail, iCloud, legacy ISP email; **platform identities** — Facebook, Instagram, Twitter, PayPal, Samsung, Apple, Google; **infrastructure control planes** — GoDaddy, Afternic, DigitalOcean, Vultr, WHMCS, Google Admin; **device roots** — MacBook Air A2337, Dell Latitudes, iPhone 11 Pro, iPads, Chromebook, Nighthawk hotspot; **data-recovery mechanisms** — encrypted iOS backups, iMazing, password vaults, backup codes, Easy2Boot; **human escalation paths** — named representatives, contacts, [PERSON REDACTED], FBI Austin; **physical continuity** — Uptown Suites, Austin contacts, and Dallas apartment candidates. The notebook’s apparent disorder is therefore functional. It mirrors the actual architecture of modern identity, where one lost phone can interrupt two-factor authentication; one inaccessible mailbox can block domain recovery; one expired registrar account can disrupt mail; one encrypted backup can contain the only surviving record of historical credentials; and one organizational management profile can make a device appear to belong to someone else’s administrative domain. ## Chronological and Conceptual Trajectory The notebook opens with **residence and REDACTED logistics** (pages 2–3), immediately followed by a dated software anomaly involving Akonadi, KIO, Pixel, xfdashboard, and Cockpit (pages 3–5). It then identifies a MacBook Air by model and generation (page 6) before entering an alphabetized—but only loosely ordered—account corpus (pages 7–43). That corpus moves from Afternic and Apple Business Manager through cloud providers, social platforms, Google Workspace, GoDaddy, PayPal, Instagram, iPhone backups, Amazon KDP, mail.com, NETGEAR, Norton, civic-technology research, WHMCS, wearables, virtualization, Dell firmware, Google recovery, and organizational administration. Pages 44–49 deepen from account recovery into **pre-boot and device-attribution mechanisms**: Easy2Boot hotkeys, a managed Chromebook, unlabeled passwords, a database fragment, and a Google/Android identity mismatch involving Nexus 5 and `blueline`. Pages 50–55 return to domains, GoDaddy account history, numerical mappings, national political contacts, activist/media networks, trust notation, and an orphan code. Pages 56–59 become a concise Dallas housing survey, and page 60 identifies the physical notebook while leaving the handwritten name “[PERSON REDACTED]” as an unresolved ownership/contact marker. Conceptually, the notebook travels from **“Where am I and whom do I meet?”** to **“What is this machine actually running?”**, then to **“Which identity controls which service?”**, then to **“How can the system be booted, decrypted, administered, or recovered below the ordinary interface?”**, and finally to **“Where can I live near the human network supporting this work?”** This is a coherent trajectory from physical location to digital attribution to continuity architecture. ## Technology and Systems Map ```text PHYSICAL PERSON / BUSINESS IDENTITY │ ├── Owned domains │ ├── bryantmcgill.com │ ├── gomcgill.com │ ├── simplereminders.com │ ├── reportingthings.com │ ├── Lionheart.net │ └── ChangeUpdate.com │ ├── Registrar / domain commerce │ ├── GoDaddy │ └── Afternic │ ├── Organizational identity and mail │ ├── Google Workspace / Google Admin │ ├── Apple Business Manager / Apple Account │ ├── Gmail │ ├── iCloud / me.com │ ├── mail.com │ ├── Comcast │ └── tx.rr.com │ ├── Public and transactional platforms │ ├── Facebook / Meta │ ├── Instagram │ ├── Twitter / X │ ├── PayPal │ ├── Samsung │ └── Amazon KDP │ ├── Infrastructure │ ├── DigitalOcean │ ├── Vultr │ ├── WHMCS │ ├── Cockpit │ └── IFTTT │ ├── Desktop / data middleware │ ├── KDE │ │ ├── Akonadi │ │ ├── KIO │ │ └── Konqueror │ ├── Xfce / xfdashboard │ └── GNOME Boxes │ ├── Recovery and pre-OS access │ ├── iMazing encrypted iOS backups │ ├── Norton Password Manager vault │ ├── Google Account Recovery │ ├── Easy2Boot / grub4dos hotkeys │ ├── Intel MEBx │ ├── Intel RST RAID option ROM │ └── KVM / virtual console │ ├── Network and device identity │ ├── NETGEAR Nighthawk mobile router │ ├── WPA/WPA2 │ ├── 2.4 GHz 802.11 b/g/n │ ├── 5 GHz 802.11 a/n/ac │ ├── IPv4 link-local 169.254/16 │ ├── Pixel 3 codename blueline │ ├── Nexus 5 mismatch │ └── IMEI / Bluetooth-like identifiers │ └── Physical endpoints ├── MacBook Air M1 A2337 ├── Dell Latitude E7450 ├── Dell Latitude E6420 ├── iPhone 11 Pro ├── iPads ├── CHISD-managed Chromebook ├── Mi Smart Band 5 ├── Bose SoundLink Color II └── Amazfit GTS 2e ``` The map reveals a crucial architecture: the notebook was preserving **multiple mutually dependent roots of trust**. The owned domain depended on registrar control; mail depended on DNS and Workspace; social accounts depended on mail and phones; cloud servers depended on privileged credentials; backups depended on device-specific encryption; and devices could remain subject to firmware or enterprise-management layers beneath the visible operating system. ## People, Companies, Institutions, and Relationship Map | Entity | PDF page(s) | Notebook relationship | Confidence | |---|---:|---|---| | [PERSON REDACTED] | 2, 18, 57 | REDACTED/location contact; Dallas housing evaluated “NEAR [PERSON REDACTED].” | High recurrence; identity unresolved. | | [PERSON REDACTED] | 18 | Austin contact with email and street address. | Visible; identity unresolved. | | [PERSON REDACTED] | 19, 40 | Contact associated once with Instagram-adjacent note and later with escalation contacts. | High recurrence; role unresolved. | | [PERSON REDACTED] | 15 | Written as “vip rep” at GoDaddy. | Visible notebook assertion; current status not claimed. | | [PERSON REDACTED] | 8, 16, 20–21, 42, 51 | Appears in device, Google, Instagram, Apple/iCloud, and registrar/account contexts. | Strong cross-system recurrence. | | [PERSON REDACTED] | 60; possible page 3 | Handwritten on colophon; possible owner/contact recurrence. | Name clear on page 60, relationship unresolved. | | [PERSON REDACTED] | 30 | Private contact. | Visible; no role. | | [PERSON REDACTED] | 33 | Private contact. | Visible; no role. | | [PERSON REDACTED] [uncertain surname] | 46 | Source of a free Chromebook still marked managed by CHISD. | Visible claim; surname uncertain. | | [PERSON REDACTED] | 51 | Associated with a GoDaddy-like identifier. | Visible; role unresolved. | | [PERSON REDACTED] | 40 | Contact in escalation list. | Visible; could be person/project. | | [PERSON REDACTED] | 40 | Contact in escalation list. | Visible; identity unresolved. | | Shaun King | 54 | Reference node connecting Real Justice PAC, BLM, and North Star. | Public entity cluster. | | [PERSON REDACTED] | 54 | Festival founder and explicitly trusted contact. | Role independently verified. | | Emmanuel Macron | 29 | Named beside civic-democracy entities. | Visible; relation not specified. | | Kamala Harris | 53 | Political reference with White House contact. | Visible; no direct relationship claimed. | | FBI Austin | 40 | Institutional contact label. | Visible; type of number/communication unresolved. | | Intertek PSI | 3 | Circled organization beneath Linux discovery note. | Entity verified; page-level relationship unclear. | | Cedar Hill ISD | 46 | Administrative domain controlling Chromebook. | Strong domain match. | | Council of Europe | 29 | World Forum for Democracy reference. | Strong URL/title match. | | World Justice Project | 29 | Probable correction of written “World Justice Party.” | Strong contextual match, transcription preserved. | | Flame Tree Publishing | 60 | Manufacturer/publisher of the physical notebook. | Printed evidence. | ## Master Entity Index ### Accounts, Domains, and Online Properties | Canonical entity | Notebook wording or identifier | PDF page(s) | |---|---|---:| | [[Afternic]] | “afternic.com” | 7 | | [[Apple Account]] | `apple.com`, `idmsa.apple.com`, Apple identity notes | 7, 16, 42 | | [[Apple Business Manager]] | “apple business id,” “apple business mgr.” | 7 | | [[BryantMcGill.com]] | domain and role mailboxes | 9, 12, 14, 17, 32 | | [[ChangeUpdate.com]] | “ChangeUpdate.com” | 50 | | [[Facebook]] | “fb,” “Facebook,” profile/account entries | 4, 12–13, 16, 23, 32 | | [[GoMcGill.com]] | domain, usernames, mailboxes | 13–17, 20, 31, 41 | | [[Google Account]] | `accounts.google.com`, `myaccount.google.com`, recovery notes | 15, 17, 36–39 | | [[Google Admin Console]] | `admin.google.com` | 38 | | [[Google Workspace]] | “workspaces.google.com,” “Google Workspace” | 14, 49 | | [[Instagram]] | `bryantmcgill`, `gomcgill`, `mysimplereminders`, `Simplethingsbrand` | 14, 19–21 | | [[Lionheart.net]] | “Lionheart.net” | 50 | | [[mail.com]] | `[email protected]` | 24 | | [[PayPal]] | PayPal + Simple Reminders email | 15 | | [[ReportingThings.com]] | “reportingthings.com” | 12 | | [[Simple Reminders]] | domain, social handles, email | 12, 14–16, 20–21 | | [[Twitter]] / [[Twitter\|X]] | `@SimpleReminders` | 16 | | [[Road Runner Email]] | `tx.rr.com` address | 43 | | [[Comcast Email]] | `[email protected]` | 21 | | [[iCloud Mail]] | `@me.com`, `@icloud.com` | 4, 42 | | [[TLS School]] | `[email protected]` | 41 | | [[arlsj.com]] | uncertain admin/test domain | 38 | ### Software, Services, Protocols, and Standards | Canonical entity | PDF page(s) | Function in notebook | |---|---:|---| | [[Akonadi]] | 3–4 | KDE PIM data service unexpectedly observed. | | [[KIO]] | 3–5 | KDE network-transparent data and filesystem layer. | | [[Konqueror]] | 5 | KDE browser/file manager compared with Boxes VM. | | [[xfdashboard]] | 4 | Xfce overview/dashboard component. | | [[Cockpit]] | 4 | Browser-based Linux server administration. | | [[GNOME Boxes]] | 5 | Virtual-machine interface used as analogy/comparison. | | [[DigitalOcean]] | 11 | Cloud server provider. | | [[Vultr]] | 11 | Cloud server provider. | | [[IFTTT]] | 12 | Cross-service automation. | | [[WHMCS]] | 31 | Hosting billing/provisioning/support automation. | | [[iMazing]] | 21 | iPhone/iPad backup and data management. | | [[Norton Password Manager]] | 27 | Digital vault whose own access needed recovery. | | [[Kindle Direct Publishing]] | 23 | Publishing-business account. | | [[Easy2Boot]] | 44–45 | Customized multiboot and recovery environment. | | [[grub4dos]] | 44–45 | Bootloader/hotkey substrate. | | [[Kernel-based Virtual Machine]] | 34 | Virtualization/console reference. | | [[Intel Management Engine BIOS Extension]] | 35 | Pre-OS management configuration. | | [[Intel Rapid Storage Technology]] | 35 | RAID configuration via `Ctrl+I`. | | [[Wi-Fi Protected Access\|WPA]] / [[Wi-Fi Protected Access\|WPA2]] | 26 | Wi-Fi encryption. | | [[Link-local Address\|IPv4 Link-Local Addressing]] | 34 | `169.254.217.237` self/local-link address. | | [[Bluetooth Low Energy]] | 32 | Probable “LE” device-discovery label. | | [[International Mobile Equipment Identity]] | 8 | Cellular hardware identifier. | | [[XRP Ledger]] | 28 | Distributed ledger/financial-regulatory research. | | [[Coinbase]] | 28 | Digital-asset exchange reference. | | [[Open Collective]] | 29 | Transparent fiscal hosting and collective finance. | | [[DemocracyOS]] | 29 | Open-source participatory-democracy software. | ### Hardware and Device Models | Canonical device | Notebook wording | PDF page(s) | |---|---|---:| | [[MacBook Air\|MacBook Air (M1, 2020)]] | “Ms Air / Late 2020 / ‘13’ / A2337” | 6 | | [[iPhone 11 Pro]] | “old 11 pro?” | 21 | | [[iPad]] | “One of the iPads” | 43 | | [[NETGEAR Nighthawk M1]] | “Netgear 22,” BGN/ANAC wireless modes | 26 | | [[Dell Latitude E7450]] | “Lat E7450” | 35 | | [[Dell Latitude E6420]] | “Lat E6420” | 35 | | [[Chromebook]] | “free chromebook,” managed by `chisd.net` | 46 | | [[Google Pixel]] | “pixel phone?” | 3 | | [[Google Pixel\|Google Pixel 3]] | `blueline` | 49 | | [[Nexus 5]] | “thinks phone is a Nexus 5” | 49 | | [[Mi Smart Band 5]] | exact product name | 32 | | [[Bose SoundLink Color II]] | “LE Bose Color II SoundLink” | 32 | | [[Amazfit GTS 2e]] | exact/near-exact product name | 32 | ### Companies, Institutions, Platforms, and Projects | Canonical entity | PDF page(s) | |---|---:| | [[GoDaddy]] | 13, 15, 31, 51 | | [[RingCentral]] | 7 | | [[Intertek PSI]] | 3 | | [[Apple]] | 6–7, 16, 21, 42–43 | | [[Google]] | 14–17, 36–39, 46, 49 | | [[Meta Platforms]] | 4, 12–13, 16, 20, 23, 32 | | [[Samsung Electronics\|Samsung]] | 32 | | [[Wells Fargo]] | 34–35 | | [[CVS Pharmacy]] | 10 | | [[CarMax]] | 2 | | [[Cedar Hill Independent School District]] | 46 | | [[Council of Europe World Forum for Democracy]] | 29 | | [[World Justice Project]] | 29 | | [[Real Justice PAC]] | 54 | | [[The North Star]] | 54 | | [[Black Lives Matter]] | 54 | | [[Raw Science Film Festival]] | 54 | | [[The White House]] | 53 | | [[Federal Bureau of Investigation]] | 40 | | [[Flame Tree Publishing]] | 60 | ### Places and Physical Addresses | Place | PDF page(s) | Archival role | |---|---:|---| | [[Uptown Suites Austin]] — 7812 Clock Tower Drive, Austin 78753 | 2 | Temporary residence / room 233. | | 2212 Mountain View Road, Austin 78703 | 18 | Contact address. | | 213 East San Patricio Avenue | 10 | CVS location; city omitted. | | 9663 Santa Monica | 36 | Address fragment used in recovery context. | | [[Manor House Dallas]] — 1222 Commerce Street, Dallas 75202 | 56 | Housing candidate. | | [[Arrive West End]] — 800 Ross Avenue, Dallas 75202 | 57 | Housing candidate near [PERSON REDACTED]. | | [[Deep Ellum Lofts]] | 58 | Housing candidate/neighborhood. | | [[Wilson Building (Dallas)]] — 1623 Main Street, Dallas 75201 | 58 | Housing candidate/historic building. | | Austin, Texas | 2, 18, 40 | Primary location frame. | | Dallas, Texas | 2, 56–58 | Relocation/housing frame. | | Argentina / Latin America | 28 | Political/financial research frame. | ## Cross-Notebook Pattern Analysis ### 1. The notebooks form a distributed continuity system [[Scanned_20260730-1305]] and [[Scanned_20260730-1734]] are overtly marked as password notebooks; [[Scanned_20260730-1230]] begins with Mac Pro labels and account data; [[Scanned_20260730-1650]] catalogs certificates and hardware labels; [[Scanned_20260730-1958]] integrates those functions into a single portable graph. The repetition is not mere duplication. Each notebook preserves a different recovery stratum—**credentials, hardware identity, software behavior, institutional contacts, and physical location**—so later reconstruction can triangulate across partial records. ### 2. Hidden or non-obvious interfaces are a recurrent investigative object The project repeatedly records components that ordinary users rarely name: Akonadi, KIO, xfdashboard, Cockpit, Microsoft non-present devices, Storage Spaces, Intel MEBx, RAID option ROMs, grub hotkeys, Android codenames, management banners, and link-local addressing. [[Scanned_20260730-1720]] page 2 is especially close: it lists an integrated MMC/SD controller, McAfee integration drivers, Microsoft Storage Spaces, and command-line methods for exposing non-present devices. Across notebooks, the writer is consistently asking: **What control plane exists beneath the one the interface admits?** ### 3. Device identity is treated as a contested translation problem Page 3’s Pixel/Akonadi tension and page 49’s Nexus 5/`blueline` mismatch recur in a corpus containing model labels, MAC addresses, Bluetooth names, firmware shortcuts, and serial stickers. The central concern is not simply “which device is this?” but **which layer is naming it**—retail model, hardware codename, account dashboard, restored backup, virtual machine, enterprise manager, or network advertisement. ### 4. Temporary housing and technical recovery are intertwined [[Scanned_20260730-1719]] page 2 and this notebook page 2 both reference Uptown Suites. The Dallas apartment pages then orient explicitly toward “[PERSON REDACTED].” This suggests that relocation and technical recovery were coupled: lodging determined network environment, device custody, proximity to trusted contacts, and access to offices or support. ### 5. Civic systems are approached architecturally [[Scanned_20260730-1830]] maps intelligence alliances and transnational surveillance structures; page 29 of this notebook maps DemocracyOS, Open Collective, the Council of Europe, and the World Justice Project. These are not random political names. They reveal a stable cognitive pattern: **institutions are understood as interoperating systems of information, finance, legitimacy, and control**. ### 6. Early recognition of identity dependency graphs The notebook never uses the modern phrases “identity graph,” “zero trust,” “recovery graph,” “digital twin,” or “continuity architecture,” yet its layout repeatedly instantiates them. Emails point to platforms; phones point to recovery; domains point to mail; mail points to Google Workspace; registrars point to DNS; devices point to backups; boot media point below the OS. This was an early, practical recognition that **identity is not an account but a topology**. ## What I Was on the Trail Of The notebook shows a search for the **actual substrate of personal digital sovereignty**. The visible user interface was being treated as an unreliable summary of deeper systems. Beneath a social profile lay a recovery mailbox; beneath the mailbox lay a managed domain; beneath the domain lay a registrar and DNS; beneath the computer lay firmware, RAID, virtual machines, and bootloaders; beneath the phone’s marketing name lay a codename, IMEI, backup identity, and management console; beneath public civic institutions lay software platforms, fiscal hosts, forums, and measurement organizations. The strongest latent insight was that continuity requires preserving **relationships among identifiers**, not merely identifiers themselves. A password list can restore one session. A relationship graph can restore an ecosystem. The notebook was approaching a personal [[Configuration Management Database|configuration-management database]], a [[Asset Management|digital-asset inventory]], an [[Identity Dependency Graph|identity and access map]], and a provenance ledger—all in handwritten form. ## What I Missed or Could Not Yet See The notebook’s method captured high-value fragments but lacked the metadata needed to make them computationally reliable. It rarely recorded **service name + account + device + date + status + source** together. As a result, old passwords, current passwords, recovery codes, phone tails, account IDs, and model labels sometimes became orphaned. The missing concept was not more secrecy but **structured provenance**. Several technical anomalies were noticed but not fully resolved: **Akonadi/KIO on a Pixel context.** The anomaly was real at the level of observation, but the notebook did not preserve the process path, package name, screenshot, host, or log source needed to distinguish native execution from remote display, containerization, virtualization, or management-console mislabeling. **Konqueror versus GNOME Boxes.** The writer recognized that Konqueror was more than a browser but conflated it with a virtual-machine manager. The deeper commonality was resource abstraction: both can present remote or virtual resources, but through different architectures. **4,294,967,295 as a cell ID.** The notebook preserved an important anomaly but did not identify it as the unsigned 32-bit sentinel value \(2^{32}-1\). That interpretation makes a missing/invalid telemetry field more likely than a meaningful cell identifier. **Nexus 5 versus `blueline`.** The codename mismatch was recognized, but the notebook lacked the build fingerprint and console source that would discriminate a stale label from spoofing, emulation, restore history, or simple cross-entry confusion. **Managed Chromebook.** The management domain was noticed, but provenance and deprovisioning state were not documented. A managed banner is evidence of administrative enrollment, not by itself evidence of malicious control. **Paper as root of trust.** Paper protected recovery information from device failure but introduced its own vulnerabilities: reuse, unlabeled secrets, loss, legibility, lack of timestamps, and exposure. The next evolutionary step would have been an encrypted, versioned, offline-first continuity database with printed emergency recovery summaries. ## Prioritized Unresolved Research Agenda 1. **Reconstruct the February 2022 timeline.** Correlate pages 2–20 with calendar events, hotel receipts, phone logs, photos, screenshots, browser history, and Google/Apple security notifications from 8–12 February 2022. 2. **Identify the software-observation source.** Locate any screenshot, process list, package inventory, `ps`, `systemctl`, Android management console, remote-desktop record, or browser history showing Akonadi, KIO Client, xfdashboard, and Cockpit. 3. **Build an account dependency graph.** For each retained email/domain/platform, record recovery email, recovery phone tail, registrar, DNS provider, tenant admin, device, two-factor method, and last verified date. Do not import notebook secrets into the graph; reference the exact page instead. 4. **Reconstruct device provenance.** Match A2337, Dell Latitude models, iPhone 11 Pro, iPads, Chromebook, router, wearables, IMEI, and Bluetooth-like identifiers to purchase records, serials, backups, and photographs. 5. **Recover Easy2Boot configuration non-destructively.** Image surviving USB media read-only and inspect configuration files, hotkey mappings, ISO names, timestamps, and hash values. Do not boot unknown payloads on a trusted machine. 6. **Resolve Google Workspace tenant history.** Determine which domains were verified, which accounts held super-admin roles, and whether `arlsj.com` or the test hostname was a real domain-verification artifact. 7. **Trace GoDaddy and Afternic account lineage.** Use receipts, support correspondence, customer IDs, and historical WHOIS to map domains, representatives, and 1996/2005/2006 chronology. 8. **Disambiguate recurring people.** Prioritize [PERSON REDACTED], Greg/[PERSON REDACTED] [surname uncertain], [PERSON REDACTED], and [PERSON REDACTED]. Use private records and exact phone matching rather than public-name guessing. 9. **Map Dallas housing to contact geography.** Plot pages 2 and 56–58, then compare with [PERSON REDACTED]’s known location and the “other office” notation. 10. **Investigate the June 13 XRP letter.** Search private correspondence and public regulatory archives for a dated document matching the wording, while keeping “female judge,” “Florida 2017,” and “Next Party” separate until evidence connects them. ## Self-Contained Archival Narrative In early February 2022, while associated with an extended-stay hotel in Austin and considering contacts or relocation in Dallas, the writer was actively trying to understand an anomalous computing environment. Akonadi, KIO, xfdashboard, Cockpit, Konqueror, and Boxes were copied into the notebook as clues. The working concern was not simply how to use Linux software, but why components associated with desktop and server environments appeared in a Pixel- or phone-related context. The notebook then became the recovery surface for an extensive digital estate: Apple business identity, Google Workspace, domain mailboxes, Facebook, Instagram, Twitter, PayPal, GoDaddy, Afternic, DigitalOcean, Vultr, WHMCS, IFTTT, Samsung, KDP, and project brands such as Simple Reminders. As recovery deepened, the writer moved below ordinary accounts into encrypted mobile backups, password vaults, router radio modes, link-local networks, Intel management firmware, RAID configuration, KVM, Easy2Boot, and enterprise Chromebook enrollment. The same pages preserved human escalation routes and trust judgments—GoDaddy representatives, Austin contacts, [PERSON REDACTED], FBI Austin—as well as civic-technology research into DemocracyOS, Open Collective, the Council of Europe’s World Forum for Democracy, and the World Justice Project. The notebook ended with Dallas housing options near the human network supporting the work. The resulting artifact is an analog precursor to a contemporary [[Continuity Architecture|continuity platform]]. It preserves not merely passwords but the **ontology of access**: who, what, where, through which provider, on which device, under which administrative layer, recoverable by which other identity. Its imperfections—crossed values, unlabeled codes, uncertain service boundaries—are precisely what make full archival reconstruction necessary. They show a person attempting to maintain sovereignty over an expanding digital organism before the available tools had caught up with the complexity of that organism. # Linked Notes Created or Referenced ## People [PERSON REDACTED], [[Index - People#Shaun King|Shaun King]], [PERSON REDACTED], [[Index - People#Emmanuel Macron|Emmanuel Macron]], [[Index - People#Kamala Harris|Kamala Harris]] ## Companies and Institutions [[Flame Tree Publishing]], [[Uptown Suites Austin|Uptown Suites]], [[Intertek PSI]], [[GoDaddy]], [[Afternic]], [[Apple]], [[Google]], [[Meta Platforms]], [[DigitalOcean]], [[Vultr]], [[RingCentral]], [[PayPal]], [[Samsung Electronics|Samsung]], [[Wells Fargo]], [[CVS Pharmacy]], [[CarMax]], [[Cedar Hill Independent School District]], [[Federal Bureau of Investigation]], [[The White House]], [[Council of Europe]], [[World Justice Project]], [[Real Justice PAC]], [[The North Star]], [[Black Lives Matter]], [[Raw Science Film Festival]] ## Software, Platforms, and Services [[Akonadi]], [[KIO]], [[Konqueror]], [[KDE]], [[xfdashboard]], [[Xfce]], [[Cockpit]], [[GNOME Boxes]], [[Google Workspace]], [[Google Admin Console]], [[Google Account Recovery]], [[Apple Business Manager]], [[Apple Account]], [[IFTTT]], [[WHMCS]], [[iMazing]], [[Norton Password Manager]], [[Kindle Direct Publishing]], [[Facebook]], [[Instagram]], [[Twitter]], [[Twitter|X]], [[Easy2Boot]], [[grub4dos]], [[Kernel-based Virtual Machine]], [[DemocracyOS]], [[Open Collective]], [[XRP Ledger]], [[Coinbase]] ## Hardware, Networking, and Standards [[MacBook Air|MacBook Air (M1, 2020)]], [[Apple M1]], [[iPhone 11 Pro]], [[iPad]], [[Google Pixel]], [[Google Pixel|Google Pixel 3]], [[Nexus 5]], [[Dell Latitude E7450]], [[Dell Latitude E6420]], [[NETGEAR Nighthawk M1]], [[Chromebook]], [[Mi Smart Band 5]], [[Bose SoundLink Color II]], [[Amazfit GTS 2e]], [[International Mobile Equipment Identity]], [[Bluetooth Low Energy]], [[Wi-Fi Protected Access|WPA]], [[Wi-Fi Protected Access|WPA2]], [[Link-local Address|IPv4 Link-Local Addressing]], [[Intel Management Engine BIOS Extension]], [[Intel Rapid Storage Technology]] ## Domains, Projects, and Properties [[BryantMcGill.com]], [[GoMcGill.com]], [[Simple Reminders]], [[ReportingThings.com]], [[Lionheart.net]], [[ChangeUpdate.com]], [[TLS School]], [[mail.com]], [[Road Runner Email]], [[Comcast Email]], [[Uptown Suites Austin]], [[Manor House Dallas]], [[Arrive West End]], [[Deep Ellum Lofts]], [[Wilson Building (Dallas)]] ## Cross-Notebook Sources [[Scanned_20260730-1230]], [[Scanned_20260730-1235]], [[Scanned_20260730-1251]], [[Scanned_20260730-1305]], [[Scanned_20260730-1650]], [[Scanned_20260730-1706]], [[Scanned_20260730-1719]], [[Scanned_20260730-1720]], [[Scanned_20260730-1734]], [[Scanned_20260730-1739]], [[Scanned_20260730-1806]], [[Scanned_20260730-1830]], [[Scanned_20260730-1845]] # Research Sources [^uptown]: Uptown Suites, “Extended Stay Hotel Austin, TX – Downtown,” confirming 7812 Clock Tower Drive, Austin, TX 78753. https://uptownsuites.com/extended-stay-hotels/extended-stay-austin-tx-downtown/ [^akonadi]: KDE, “Akonadi” developer and Kontact component documentation, describing the centralized PIM data service. https://develop.kde.org/docs/features/akonadi/ and https://kontact.kde.org/components/akonadi/ [^kio]: KDE API Documentation, “KIO,” describing network-transparent access to files and data. https://api.kde.org/kio-index.html [^intertek]: Intertek, “Intertek Acquires Professional Service Industries, Inc. (PSI)” and Intertek PSI service overview. https://www.intertek.com/news/2015/11-30-intertek-acquires-professional-service-industries-psi/ and https://www.intertek.com/building/psi/ [^xfdashboard]: Xfce Documentation, “xfdashboard,” describing the GNOME Shell/Mission Control-like overview for Xfce. https://docs.xfce.org/apps/xfdashboard/start [^cockpit]: Cockpit Project, official project and administrator guide. https://cockpit-project.org/ and https://cockpit-project.org/guide/latest/ [^konqueror]: KDE Apps, “Konqueror,” web browser and file manager. https://apps.kde.org/konqueror/ [^gnome-boxes]: GNOME Apps, “Boxes,” virtualization interface. https://apps.gnome.org/Boxes/ [^macbook-air]: Apple Support, “MacBook Air (M1, 2020) — Technical Specifications,” including 13.3-inch display and model generation. https://support.apple.com/en-us/111883 [^afternic]: GoDaddy, “What is List for Sale?” identifying Afternic as a GoDaddy company and domain marketplace. https://www.godaddy.com/en-ph/help/what-is-list-for-sale-27761 [^apple-business]: Apple, Apple Business Manager User Guide and deployment overview. https://support.apple.com/guide/apple-business-manager/welcome/web and https://www.apple.com/business/docs/site/iOS_and_iPadOS_Deployment_Overview.pdf [^apple-account]: Apple Newsroom, 2024 Apple-services announcement explaining the transition from “Apple ID” to “Apple Account.” https://www.apple.com/uk/newsroom/2024/06/new-features-come-to-apple-services-this-fall/ [^ringcentral]: RingCentral, official VoIP overview. https://www.ringcentral.com/office/features/voip/overview.html [^digitalocean]: DigitalOcean Documentation, Compute/Droplets overview. https://docs.digitalocean.com/products/compute/ [^vultr]: Vultr Documentation, Cloud Compute instances. https://docs.vultr.com/products/compute/instances/cloud-compute [^ifttt]: IFTTT, “What is IFTTT and how does it work?” and service integrations overview. https://ifttt.com/explore/what-is-ifttt [^google-workspace]: Google, “Introducing Google Workspace,” October 2020, and the earlier G Suite rebranding announcement. https://blog.google/products-and-platforms/products/workspace/introducing-google-workspace-help-you-get-more-done/ and https://blog.google/products-and-platforms/products/workspace/all-together-now-introducing-g-suite/ [^google-admin]: Google Workspace Admin Help, user-account and administration documentation. https://support.google.com/a/answer/33310 [^imazing]: iMazing, “Backup Encryption in iMazing.” https://imazing.com/guides/backup-encryption-in-imazing [^kdp]: Amazon Kindle Direct Publishing, official self-publishing overview and KDP help. https://kdp.amazon.com/ and https://kdp.amazon.com/help/topic/GHKDSCW2KQ3K4UU4 [^mr1100]: NETGEAR, Nighthawk M1 MR1100 Quick Start Guide and data sheet, documenting 2.4 GHz b/g/n and 5 GHz a/n/ac modes. https://www.netgear.com/images/datasheet/mobile/mr1100_qsg_en.pdf and https://www.downloads.netgear.com/files/GDC/MR1100/MR1100_DS.pdf [^norton-vault]: Norton Support, “Create Norton Password Manager cloud vault” and vault sign-in documentation. https://support.norton.com/sp/en/us/home/current/solutions/v54500320 and https://support.norton.com/sp/en/us/home/current/solutions/v6282380 [^xrpl]: XRP Ledger, official overview, history, and “What is XRP?” documentation. https://xrpl.org/ and https://xrpl.org/about/history and https://xrpl.org/docs/introduction/what-is-xrp [^open-collective]: Open Collective, official “About” page. https://opencollective.com/about [^democracyos]: DemocracyOS, official project site. https://democraciaos.org/en/ [^world-forum-democracy]: Council of Europe, World Forum for Democracy. https://www.coe.int/en/web/civil-society/world-forum-for-democracy [^world-justice-project]: World Justice Project, “About Us.” https://worldjusticeproject.org/about-us [^whmcs]: WHMCS, “What is WHMCS?” and developer overview. https://www.whmcs.com/what-is-whmcs/ and https://developers.whmcs.com/about/ [^mi-band]: Xiaomi, Mi Smart Band 5 specifications. https://www.mi.com/global/product/mi-smart-band-5/specs/ [^bose-color]: Bose, press information for SoundLink Color Bluetooth Speaker II. https://www.bose.com/pressroom/new-bose-soundlink-color-bluetooth-speaker-ii [^amazfit]: Amazfit, CES 2021 product announcement including GTS 2e. https://us.amazfit.com/blogs/news/amazfit-is-stronger-together-at-ces-2021 [^rfc3927]: Internet Engineering Task Force, RFC 3927, “Dynamic Configuration of IPv4 Link-Local Addresses.” https://datatracker.ietf.org/doc/html/rfc3927 [^intel-mebx]: Intel Support, Intel AMT/MEBx startup access using `Ctrl+P`. https://www.intel.com/content/www/us/en/support/articles/000091667/technologies/intel-active-management-technology-intel-amt.html [^intel-rst]: Intel, Rapid Storage Technology user guide documenting `Ctrl+I` option-ROM access. https://cdrdv2-public.intel.com/841982/irst_user_guide.pdf [^google-recovery]: Google Account Help, official account-recovery instructions. https://support.google.com/accounts/answer/7682439 [^easy2boot]: Easy2Boot, “Global Hotkeys” and official configuration documentation. https://easy2boot.xyz/create-your-website-with-blocks/configure-e2b/global-hotkeys/ [^chisd]: Cedar Hill Independent School District, official Chromebook resources and district site. https://www.chisd.net/services/academics/blended-learning/chisd-chromebook-connection and https://www.chisd.net/ [^android-codenames]: Android Open Source Project, build-number/device-codename reference identifying Pixel 3 as `blueline`; Google Nexus 5 support reference. https://source.android.com/docs/setup/reference/build-numbers and https://support.google.com/nexus/answer/6102470 [^real-justice]: Ballotpedia, “Real Justice PAC,” and public organizational descriptions linking Shaun King to the PAC. https://ballotpedia.org/Real_Justice_PAC [^north-star]: The North Star, official “About” page. https://www.thenorthstar.com/about [^raw-science]: Raw Science Film Festival, official team page identifying [PERSON REDACTED]. https://www.rawsciencefilmfestival.com/team [^manor-house]: Manor House property listings confirming 1222 Commerce Street, Dallas, Texas 75202. https://www.apartments.com/manor-house-dallas-tx/y8frjwv/ [^arrive-west-end]: Arrive West End, official property site confirming 800 Ross Avenue, Dallas, Texas 75202. https://arrivewestend.com/ [^deep-ellum-lofts]: Deep Ellum Lofts, official property site. https://www.deepellum-lofts.com/ [^wilson-building]: City of Dallas Office of Historic Preservation and Texas historic-property records for the Wilson Building at 1621–1623 Main Street. https://cityofdallaspreservation.wordpress.com/tag/wilson-building/ and https://atlas.thc.texas.gov/Details/2079002931 [^flame-tree]: Flame Tree Publishing, official Flame Tree Notebooks series description. https://www.flametreepublishing.com/flame-tree-notebooks-book-series-list.html