Research
The work starts at the point where the record stops.
Open problems
A problem is listed here when the literature and the products in the market both stop short of it, and when there is a way for somebody outside to tell whether that has changed.
The list is short. It is a record of what is actually being worked on, not a survey of what would be interesting, and a laboratory that publishes a long list of open problems is describing the field rather than its own work.
-
Telling a person from an automated client
Nobody has solved this. Every defence in production today either lets competent automation through or makes real people prove themselves over and over, and the second failure is invisible in the metrics because the people who give up are not counted.
Solved when the false-positive cost to a person approaches zero while the cost to the operator of the automation stays high enough to matter.
-
Proving a defence did not damage what it defends
A filter that blocks an attack and also blocks legitimate work has moved the cost, not removed it. The damage lands on the people using the system, which is exactly where nobody is measuring.
Solved when a defence ships with its own regression on utility, and that number is published next to the one about attacks.
-
Making a fix verifiable before it ships
A patch that cannot be shown to hold, against the project's own tests, an adversarial probe and its performance baseline, is a guess with good intentions behind it.
Solved when the evidence travels with the patch and can be re-run by whoever receives it.
What came out
Work that holds leaves the laboratory as something usable, and until it does there is nothing here to name. What follows is what has actually come out so far, which is infrastructure rather than a product, and every line of it can be checked from outside.
A database that survived its own leader being killed mid-write, on purpose, over the application’s own connection: 323 writes acknowledged, 323 alive. An identity system built rather than rented, for the same reason. A site that contacts no host it does not run, which takes about ten seconds to verify.
This panel is short, and that is the honest state of it. A laboratory four months old with a long list of finished work would be describing something other than its own.
How results are published
The method goes out with the result. A number without the procedure that produced it cannot be argued with, and a claim that cannot be argued with is not worth publishing.
What did not hold goes out too, in the same entry rather than in a quieter one later. An incident is written up in full, including the part that is still wrong on the day it is published.
There is no publishing calendar. Entries appear when there is something to put on the record, which is why the gaps between them are visible and are left that way.
On the record
- Five days of alarms that fired correctly and reached nobody.
- The conditions under which the work stops.
- Why the defences that matter are for attacks that have no name yet.
- Every third-party host removed, and how to check it.
- 323 writes acknowledged, 323 alive, after the leader was killed on purpose.