From the walls.
Working notes on operational security, written for people who will check them. Where a claim is measured we name the command; where it is an opinion we say so in the sentence.
6 min read
Post-block alerting is a receipt, not a defence
It tells you precisely how much you lost and exactly when you lost it. Both facts arrive too late to be worth anything.
There is a moment in every on-chain incident where the outcome is still undecided. It is one block wide, and it is the only moment in which a defensive system can change the number at the bottom of the report.
Read itYour audit certified the code. The attacker is signing in as you.
Four incidents, four different mechanisms, and not one of them was a Solidity bug the auditors were asked to look for.
Why the model is never the first line of defence
Software that guesses does not get to declare an emergency. The layer order is a commitment, not a preference.
Read and attest: capping the blast radius of your own vendor
The question nobody asks their monitoring vendor: what happens on the day the vendor is the one that gets breached?
Measured, not asserted: how a number earns its place
A false-positive rate without a denominator is a marketing figure wearing a lab coat. Here is how ours is produced.
How we write about measurement.
Three rules, and they are the reason these notes are worth the time it takes to check them.
- NAME THE MEASUREMENT. Where a claim is measured, the note says how the number was produced. A figure you cannot reproduce is an assertion wearing a lab coat
- NAME THE OPINION. Where a claim is a judgement rather than a measurement, the sentence says so. Not the footnote, not the appendix: the sentence, in the same type as the claim
- NAME THE TRADE. Every architectural decision costs something. A note that describes only the upside is marketing; these describe what the choice gave up and why it was worth it
The next breach is already being dug.
Every engagement is scoped to your protocol by the team, and pricing follows that scope.