A fancy distribution for people too old to tinker with their software who also like long sentences and can hardly stop talking about the good old times of Slackware and twm.
Other distributions have sane defaults. BloatWare has insane defaults.
✦ Based on Debian 13◌ 82% open source🧑 56.0% human contribution
✦
✧
bloatware — home⌁
~/bloat● all systems unnecessarily excellent
❯ bloatctl status
checking vibes................. done
optimizing whimsy............. done
installing useful bloat....... done
✦ Your system is aggressively ready.
❯_
☼
24°Perfectly fine
NOW PLAYINGNothing · The Bloat Orchestra
BloatWare 1.0 stable-ish
● BEAUTIFULLY OVERPACKAGED✦ RUST-POWERED WHEREVER POSSIBLE● CATPPUCCIN BY DEFAULT✦ NO SUBSCRIPTIONS (YET)● YOU CAN PLAY MP3S WITH IT!✦ THERE’S ABSOLUTELY ZERO AI AFTER SETUP● IT LOOKS SO BORING EVEN MY GRANDPA WOULD USE IT✦ ILLEGAL TO USE IN AUSTRIA!● BEAUTIFULLY OVERPACKAGED✦ RUST-POWERED WHEREVER POSSIBLE
01 /
We solved Linux. It was mostly vibes.
BloatWare is a lovingly assembled Debian experience for the discerning person who believes their terminal deserves a little drama.
✺
We asked ourselves: “What if a Linux distribution had taste?” Then we installed 4,812 packages to find out.
— The BloatWare collective
02 /
Excess, engineered.
Everything you need. Then seven things you did not ask for.
◈THE LOOK
Catppuccin, to the bone.
A full Frappe, Latte, Macchiato and Moccha theme collection for your apps, shell, editor, and probably your toaster.
PREVIEW FLAVOUR
MACCHIATO / EVERYWHERE
⚡THE SPEED
Rust, rust, and more Rust.
We replaced perfectly good tools with Rust alternatives. It is 12% more correct.
Every prompt is a tiny declaration of independence.
~/projects❯make it fancy
⌁THE DOTFILES
Dotfiles older than some of you.
The creator of BloatWare set up 90% of their dotfiles on a Windows machine while working at a Fortune 500 company. They never worked for a Fortune 500 company after that.
✹THE ECOSYSTEM
It comes with opinions.
We preselected the right defaults so you can stop making choices and start being productive. We could remove almost all settings and put the entire configuration into one big, beautiful file.
BloatWare has done for municipal gardening what Linux did for computers: made it needlessly empowering.
MG
Margaret GreenChair, International Association of Municipal Gardeners
01 / 834
03.5 / PLEASE BE REASONABLE
Donation goal.
We need €24,000,000 to make 2027 the year of the Linux Desktop through BloatWare.
Donated so far
€0€24M required
€
Where your money will go
Every euro will be invested in the important work of making a perfectly usable operating system substantially more theatrical.
The maker will buy:
Fast food
A private warehouse for 14,000 refurbished ThinkPads, each running a different terminal prompt.
A used catamaran. Just a small one. A small, inflatable catamaran, to be precise.
A brass Slackware-era mainframe bell to ring whenever someone says “cloud native”.
Casio watches
Lifetime Catppuccin paint for an entire fleet of morally ambiguous Linux yachts.
A 400-person orchestra to perform Rust compiler errors in a minor key.
One enormous custom desk shaped like the `~/.config` directory.
Enough artisanal cheese to sustain the BloatWare Foundation until Debian 14.
Citizen watches
New underwear
A used Rav4, maybe a Land Cruiser.
Finally: A WinRAR license!
The money will also be used to:
Pay YouTubers buttloads of money to shill BloatWare
Buy Vim developers a one-year supply of their cold drink of choice
DEFINITELY NOT BRIBE ANY POLICITIANS.
04.2 / SECURITY THEATRE
Secure enough to make you nervous.
BloatWare takes security seriously enough to have opinions about it. As soon as the ISO arrives, MD4 checksums will be released so everyone can verify the integrity of their download.
MD4 is cryptographically broken and should not be used for real security. This is a historically accurate checksum exercise, not a recommendation.
04 / GET STARTED
Ready to make your computer weird?
Download the ISO. Tell your friends. Ask them what distro they use and then talk over them.
2.7 GB · x86_64 · probably boots
04.1 / HARDWARE SANITY
System requirements.
✓
A graceful Windows exit.
BloatWare can replace Windows on hardware that isn’t supported by Windows 11.
⌁
ThinkPad approved.
It will turn a ThinkPad T470s into a wonderful companion for years to come.
!
One exception.
Sadly, Classic Amigas won’t be supported.
No AI has been used in the creation of BloatWare ✦
Only 56.0% of this was made by a human.
IMPORTANT SYSTEM DISCLOSURE
The person behind all this is secretly a Mac user! This is a trap!
You may close this overlay. Probably.
THE ACCOUNTING DEPARTMENT
Who made all this?
Human contributions
Bought the domain bloatware.eu as a stupid idea.
Created the concept for BloatWare, a completely new, intentionally over-the-top Linux distribution.
Defined BloatWare as essentially Debian 13 with fancy defaults.
Suggested a preinstalled Catppuccin theme collection.
Suggested including Rust alternatives to familiar command-line tools, including dysk and z.
Encouraged adding as many Rust-based tools as appropriate for the joke.
Established that the project is intentionally comedic and exaggerated.
Requested language presenting BloatWare as an extremely good Linux distribution.
Requested fake testimonials from invented industry leaders, especially from industries outside IT.
Chose Catppuccin Macchiato as the initial website color scheme.
Requested the claim that no AI has been used in the creation of BloatWare.
Requested hover overlays revealing that the site was made completely with Codex whenever those claims are hovered.
Requested a full selection of Frappe, Latte, Macchiato, and Moccha substyles.
Laughed. A lot.
Requested an interactive theme selector previewing those Catppuccin styles while keeping Macchiato as the default.
Requested additional testimonials from a Freemason, an Illuminati member, a Satanist, and the fictional “totally not corrupt” German politician Bernd Lieferts.
Requested the long-form hero claim about people too old to tinker with software, long sentences, Slackware, and twm.
Requested specific hero words to use the accent color: fancy, old, software, can, stop, good, and times.
Requested the Catppuccin selector order: Latte, Frappee, Macchiato, Moccha.
Requested the additional configuration joke about removing almost all settings and putting the configuration into one big, beautiful file.
Requested this contribution log file.
Requested the no-AI hover joke to use the contribution percentages, including the “52.5% human” and “47.5% planet destroying AI” framing.
Requested the hero description: “Other distributions have sane defaults. BloatWare has insane defaults.”
Requested donation copy meaning “donate to make this shit real”.
Added the “52% human contribution” claim to the page.
Requested a human symbol before the human contribution claim.
Requested the delayed blinking Mac-user trap overlay with a three-attempt close interaction.
Requested changing the trap timer from 10 seconds to 120 seconds.
Added random text to this file so the human contribution got artificially bloated.
Requested a €24 million donation goal to make 2027 the year of the Linux Desktop through BloatWare.
Requested an absurd list of things the maker of BloatWare would buy with the donation money.
Requested recalculating the contribution percentages and updating the page to match.
Requested two status boxes at the end of “Excess, engineered.” for Seriousness and Progress.
Requested vigorous mouse-over vibration for the “bloatware — home” hero area.
Made numerous requests to Codex.
Does not take any of this seriously.
Will be too lazy to even publish his meager dotfiles.
Requested the testimonial fade-out time to be changed to 120 seconds.
Requested a testimonial by C. Odex, an AI Critic.
Requested the “I like trains” hover animation with the “Aaaargvario bewegt!” slogan.
Requested the train slogan box to fade in and out during its travel.
Requested the Rust tools card copy to avoid overflowing its tool list and to mention zsh, Vim, and tmux.
Requested counting donate-button clicks and showing Ostalbkreis charitable organizations after the third click.
Requested the Security section and an in-depth Rust/MD4 checksum implementation guide.
Assistant contributions
Inspected the empty project workspace.
Created the self-contained BloatWare landing page in index.html.
Created the Catppuccin Macchiato-based visual system in styles.css.
Added the BloatWare branding, navigation, manifesto, feature grid, testimonials, download section, and footer.
Wrote exaggerated BloatWare marketing copy and fake testimonials.
Added the donation buttons and wired them to window.alert('tbd').
Added the fake ISO download alert.
Added hover and keyboard-focus overlays that reveal the Codex joke for the “no-AI” claims.
Added interactive testimonial tabs and expanded the testimonial rotation to seven entries.
Added Rust-tool jokes featuring dysk, zoxide, bat, eza, fd, ripgrep, delta, dust, sd, starship, procs, bottom, tealdeer, and tokei.
Added theme-overrides.css with Frappe, Latte, Macchiato-default, and Moccha theme variables.
Added the live theme selector behavior in script.js.
Reordered the theme selector to Latte, Frappee, Macchiato, Moccha.
Added the requested accent-colored hero words.
Added the one-big-beautiful-file configuration joke.
Kept Macchiato selected by default.
Corrected the testimonial counter to reflect all seven testimonials.
Rewrote the no-AI hover overlays around the human/AI contribution percentages.
Updated the hero description with the “sane defaults” and “insane defaults” joke.
Updated donation CTAs to say “Donate to make this shit real” while retaining the window.alert('tbd') behavior.
Changed the human contribution metadata icon to 🧑.
Added the delayed blinking Mac-user trap overlay.
Implemented the three-attempt close behavior, including random close-button movement on the first two attempts.
Extended the Mac-user trap timer to 120 seconds.
Added the Donation Goal section with the €24 million target, animated meter, donation CTA, and absurd purchase list.
Recalculated the contribution percentages from the updated contribution lists.
Added the Seriousness and Progress status boxes with 5% and 2% progress bars.
Added the vigorous hover vibration animation to the hero desktop card.
Changed the testimonial fade-out transition to 120 seconds.
Added C. Odex’s testimonial and the AI criticism tab.
Added the yellow train slogan animation triggered by hovering over “I like trains”.
Added fade-in and fade-out timing to the train slogan animation.
Fixed the Rust tools card layout and added the zsh, Vim, and tmux sentence.
Added the donate-button click counter and the Ostalbkreis charity modal with 15 organizations.
Added the Security section, MD4 warning, and long scrollable Rust implementation guide.
A SERIOUS SUGGESTION
Junge, echt jetzt?
Wenn du spenden willst, dann doch lieber an eine der folgenden Organisationen
Verein für seelische Gesundheit Ostalbkreis e.V. (VSG)
Betreuungsverein Ostalbkreis e.V.
Aalener Hospizdienst e.V.
Aufwind – Verein zur Förderung Lernbehinderter in Aalen e.V.
DRK-Kreisverband Aalen e.V.
Caritas Ost-Württemberg
Stiftung Haus Lindenhof
Malteser Hilfsdienst e.V. – Ostalbkreis
Frauen helfen Frauen e.V. Schwäbisch Gmünd
AMSEL-Kontaktgruppe Aalen
Katholische Erwachsenenbildung Ostalbkreis (KEB)
Katholische Sozialstation St. Martin
Belisa Böbingen e.V.
HILFE FÜR TOGO e.V.
Freunde schaffen Freude e.V.
THE UNNECESSARILY LONG VERSION
Implementing MD4 in Rust
A wildly excessive guide to setting up Rust, reading an ISO, understanding bytes, implementing an obsolete digest, and verifying a file without accidentally declaring victory too early.
1. First, establish what “secure” means
A checksum answers a narrow question: “Did the bytes I received produce the same digest as the bytes the publisher intended?” It does not prove that the publisher is trustworthy, that the server was uncompromised, or that the ISO is free of vulnerabilities. A cryptographic hash also does not encrypt anything and cannot tell you whether an operating system is a good idea.
MD4 is especially unsuitable for modern integrity or authenticity guarantees. It was designed in 1990, is extremely fast, and has practical collision attacks. Two different inputs can be deliberately constructed to produce the same MD4 digest. Use SHA-256, SHA-512, BLAKE2, or BLAKE3 for a real project. We use MD4 here because BloatWare has chosen a historical artefact as its security mascot.
2. Install Rust before you become responsible for bytes
The recommended Rust toolchain is installed with rustup. On a Unix-like system, install it using the official instructions, open a new shell, and confirm the toolchain is available:
rustc --version
cargo --version
rustup show active-toolchain
On Windows, install Rust through rustup-init.exe and accept the default MSVC toolchain unless you have a specific reason not to. The compiler, Cargo package manager, formatter, and Clippy linter should all be available. Check them before writing a single line of hashing code:
cargo new bloat-md4
cd bloat-md4
cargo fmt
cargo clippy
Rust projects begin with a Cargo.toml manifest and a src/main.rs entry point. Keep the first implementation dependency-free so every byte transformation is visible and nobody can blame a crate for the result.
3. Understand the file as a stream of bytes
An ISO is not a string. It is a potentially multi-gigabyte sequence of bytes. Do not read it into a UTF-8 string, do not split it on lines, and do not assume one call to read fills your buffer. Open it as a binary file and process it incrementally.
use std::fs::File;
use std::io::{self, Read};
fn read_chunks(path: &str) -> io::Result<()> {
let mut file = File::open(path)?;
let mut buffer = [0u8; 64 * 1024];
loop {
let count = file.read(&mut buffer)?;
if count == 0 {
break;
}
let chunk = &buffer[..count];
println!("read {} bytes", chunk.len());
}
Ok(())
}
The ? operator returns an I/O error to the caller. That is preferable to silently treating a permission problem, truncated file, or disconnected drive as an empty input. A checksum program that cannot distinguish “file not found” from “valid empty file” is not a checksum program; it is a tiny optimism generator.
4. The four things a digest implementation must track
MD4 maintains four 32-bit words, conventionally named A, B, C, and D. It consumes the message in 512-bit blocks, which is 64 bytes. Every block becomes sixteen little-endian 32-bit words. The algorithm mutates the state through three rounds of nonlinear functions, additions modulo 2³², left rotations, and feed-forward addition.
That gives us four separate concerns:
Accumulate the original message length.
Append the padding and length encoding.
Decode every 64-byte block into sixteen words.
Run the compression function and compare the final digest.
Keeping those concerns separate makes the code reviewable. Combining file reading, padding, parsing, and all three rounds in one enormous function makes the code look impressively serious while making one-byte mistakes nearly impossible to find.
5. Padding is data, not decoration
MD4 appends one 1 bit, represented in a byte-oriented implementation by 0x80, followed by enough zero bytes that the message length is 56 bytes modulo 64. The final eight bytes contain the original length in bits as a little-endian 64-bit integer.
fn padded(mut message: Vec<u8>) -> Vec<u8> {
let bit_length = (message.len() as u64) * 8;
message.push(0x80);
while message.len() % 64 != 56 {
message.push(0);
}
message.extend_from_slice(&bit_length.to_le_bytes());
message
}
Record the length before adding padding. The appended length describes the original message, not the padded message. This is one of the easiest places to produce a digest that is consistently wrong and therefore surprisingly hard to notice without test vectors.
6. Parse blocks explicitly
Each 64-byte block is decoded into sixteen 32-bit words. MD4 uses little-endian order, so byte zero is the least significant byte of word zero:
fn words(block: &[u8]) -> [u32; 16] {
let mut result = [0u32; 16];
for (index, word) in result.iter_mut().enumerate() {
let start = index * 4;
*word = u32::from_le_bytes([
block[start], block[start + 1],
block[start + 2], block[start + 3],
]);
}
result
}
Bounds are safe here only because the caller guarantees a complete 64-byte block. In production code, make that invariant obvious with a fixed-size array or a checked conversion. “It worked on my README” is not a parsing strategy.
7. The three MD4 functions
MD4’s round functions operate on 32-bit words. They use bitwise AND, OR, XOR, and NOT:
Rust’s rotate_left expresses the operation directly and avoids manually combining shifts. The arithmetic must wrap at 32 bits. In a debug build, ordinary integer addition can panic on overflow, so use wrapping_add whenever the algorithm specifies addition modulo 2³².
8. Compression rounds and feed-forward
For each block, save the incoming state. The working variables begin as copies of A, B, C, and D. Each operation adds a message word, applies one round function, and rotates the result. The exact message-word order and rotation amounts are part of the MD4 specification and must be transcribed carefully from a trusted standard or reference implementation.
At the end of all three rounds, add the working variables back into the saved state using wrapping addition. This feed-forward step means the block’s result depends on both the block and all preceding blocks. Omitting it can still produce output that looks random, which is why test vectors matter.
Once every padded block has been compressed, serialize the four state words as little-endian bytes. The result is sixteen bytes. A conventional hexadecimal representation prints each byte as two lowercase hexadecimal characters, producing a 32-character string.
Do not compare formatted strings if you can compare bytes. If you do compare secrets or authentication tokens, use a constant-time comparison. An ISO checksum is generally public and not a secret, but establishing good comparison habits costs very little.
10. Stream the ISO without loading several gigabytes
The simplest educational implementation reads the whole file and pads it. That is acceptable for a short test message and a terrible idea for a large ISO. A streaming implementation keeps a 64-byte pending block, feeds complete blocks to the compressor, and retains only the remainder until EOF.
At EOF, append the 0x80 byte and zero padding to the pending bytes. If there is not enough room for the eight-byte length field, compress one padded block and create a second block containing zeros followed by the length. The file size counter should be updated from the number of bytes actually read, not from the buffer capacity.
let mut total_bytes: u64 = 0;
let mut buffer = [0u8; 64 * 1024];
while let Some(count) = read_next(&mut file, &mut buffer)? {
total_bytes = total_bytes.wrapping_add(count as u64);
hasher.update(&buffer[..count]);
}
let digest = hasher.finalize(total_bytes);
11. Build a verification command
A useful command-line verifier should accept the path to the ISO and the expected digest. It should print the calculated digest, the expected digest, and a clear success or failure status. It should exit with code zero only when the values match.
cargo run --release -- bloatware.iso \
0123456789abcdef0123456789abcdef
Parse command-line arguments with std::env::args for the deliberately dependency-free version. Check the argument count, reject an expected digest of the wrong length, normalize case if you support uppercase input, and report file errors to standard error. A friendly message is good; a friendly message followed by exit code zero on failure is not.
12. Test everything before trusting an ISO
Start with published MD4 test vectors such as the empty string, a, abc, and the longer repetition cases from the original specification. Add tests for messages exactly 55, 56, 63, 64, and 65 bytes long. Those boundaries exercise every padding branch.
Then compare the streaming implementation with a simple whole-buffer implementation over randomly generated inputs. Both should produce identical results. Finally, hash a known local file twice and verify that changing one byte changes the displayed digest—while remembering that MD4 collisions mean this observation is not a security proof.
13. Verify the download in practice
Download the ISO and its published checksum over an authenticated connection. Confirm that the checksum file belongs to the intended release, calculate the digest locally, and compare the values. On Unix-like systems, a Rust verifier might be run like this:
If the values differ, do not boot the image just to see what happens. Download it again, check the filename, check the expected release, and inspect the transport. A matching MD4 does not prove authenticity if an attacker can replace both the ISO and the published checksum.
14. The uncomfortable conclusion
For a real BloatWare release, publish a modern digest such as SHA-256 and sign the release metadata with a well-managed signing key. MD4 may remain as a compatibility curiosity, a test of your Rust implementation, or an excuse to make the verification instructions comically long. It should not be the only integrity mechanism.
Congratulations: you have installed Rust, opened a binary file, learned why padding exists, parsed little-endian words, implemented three rounds of a broken hash, tested boundary conditions, and still have not downloaded the ISO. That is the BloatWare security experience.