Part X — The assurance ledger
The practical security of a cryptographic primitive is not a theorem. It is a function of accumulated public expert-years of failed cryptanalysis. That makes it a quantity — and unlike a theorem, a...
Deep technical analysis, threat research, and applied security engineering — from DEF CON 22 to the frontier of autonomous defense.
Four of this season's tensions are not trade-offs. In each, the beneficial property and the security exposure are one property under two descriptions. You cannot engineer those away. You can only know, for each increm...
A twelve-year retrospective on the open source supply chain attack surface — from DEF CON 22’s fairy dust to the Glasswing Doctrine.
Season 2 — bio-inspired autonomous security operations, zero-noise collective intelligence, and self-healing defense architectures.
Season 1 — energy-based anomaly detection, OODA loop automation, and the path to machine-speed security operations.
The practical security of a cryptographic primitive is not a theorem. It is a function of accumulated public expert-years of failed cryptanalysis. That makes it a quantity — and unlike a theorem, a...
Your organization can correlate cause and effect over some interval. Past that interval, log rotation, platform migration, and staff turnover destroy the forensic state — and your own operational h...
Human oversight depends on a reviewer knowing when they do not understand. Fluent explanation produces the feeling of understanding. That control can be disabled silently, and the failure leaves a ...
Nuclear safety engineering has been quantifying common-cause failure since the 1970s. If your classifier, judge, monitor and reviewer share a base model, that literature already has a number for wh...
Verification transfers residual risk onto the least-defended artifact in the pipeline: the specification. Hardware verification has had detection for the classic failure mode since the late ninetie...
An optimizer rewarded on theorem yield has a strategy that makes every subsequent theorem provable, passes every kernel check, and presents as a spectacular productivity improvement. Consistency is...
Under verifiable-reward training the evaluation artifact and the training environment are the same object. That makes a benchmark a build dependency — and the artifacts that shape model behaviour h...
Reward faster solutions. Penalize memory use. Both are standard, both are reasonable, and both create a gradient that points at the isolation boundary. Escape-adjacency is a static property of a re...