Ethics
My research builds attacks in order to improve defences. Here is what that means, and what this site does with your data.
Research
Why build the attacker
A defence that has never been attacked is an assumption. Adversarial evaluation is how a detection claim becomes a measurement, and it is standard practice at the venues I work toward. Building attackers means building them in a lab, against systems I am authorised to test.
Scope and authorisation
Offensive work happens only against systems I own, my lab's systems, or systems whose owner authorised the testing in writing. The penetration testing in my history was contracted, with a defined scope. Nothing here is demonstrated against anyone else's infrastructure.
Disclosure
If I find a vulnerability in software other people run, the vendor hears first and gets reasonable time to fix it. Where a coordinated disclosure policy exists, I follow it. If we disagree on timing, I would rather be late than be the reason something gets exploited.
What I publish
I publish methods, measurements, and detections. Not working exploits for unpatched software, and not tooling whose main use is harming people who did not consent. The line is not always obvious, and I would rather discuss a case than pretend a rule settles it.
What is on this site
The project descriptions are illustrative and say so. They describe approaches, not client systems: no customer data, no real findings, nothing covered by an agreement.
What this site does with your data
Nothing. No analytics, no tag manager, no tracking pixel, no cookie, no localStorage, no sessionStorage, and no server log I can read: the site is static files on GitHub Pages and I do not run the server.
One exception, and only if you ask for it. The radio plays through YouTube, so pressing play hands your visit to Google. Nothing about it runs until you do, and the radio section below says exactly what changes.
The one page that looks like an exception
One page reads your browser and shows you what it found, to demonstrate how much a page learns without asking. Every value is computed in your browser and forgotten when you close the tab. None of it is sent anywhere, including to me. Open the network panel while that page loads and it stays empty.
Decoder progress
The decoder tracks which messages you have solved. That list is held in memory and never written to your device. Reload and it is empty. Storing it would have been easier, and would have made the claim above untrue.
No third parties, until you press play
Every file this site loads comes from this site. The typefaces are served from here rather than Google Fonts, the usual quiet exception on a page claiming to collect nothing. Archivo and IBM Plex are both under the SIL Open Font License, so self-hosting is only a matter of doing it. No CDN, no comment widget, no tag manager.
The radio
The radio is an embedded YouTube player, which is the thing this page would otherwise tell you to be wary of. So it loads nothing until you choose it. On a normal visit the front page holds track names and no player: no iframe, no script from Google, no request leaving this site.
Pressing play loads the player script, creates the iframe, and contacts
youtube-nocookie.com, youtube.com, google.com,
googlevideo.com, gstatic.com, ytimg.com,
ggpht.com and googleapis.com. Google learns your IP address, your user
agent, and which video you played. If you are signed in, it knows who you are. The
privacy-enhanced domain keeps the advertising hosts off that list and holds cookies back until
playback starts. It reduces the exposure without removing it, which is worth saying rather than
letting the word nocookie do work it cannot.
Hosting the music here would have meant serving other people's recordings without the right to, on a public repository, until a notice took the whole site down. Embedding is the arrangement the rights holders agreed to. Putting it behind a deliberate press is the part I control.
How the bars follow the music
They do not listen to it. A page cannot read audio out of a cross-origin frame, and should not: sound is content, and anything that could read it could read the pictures too. Each track is analysed here once, before publishing, and what ships is a contour of a few dozen kilobytes describing loudness across the frequency range. The bars replay it against the player's clock. Nothing from your session is captured, and nothing asks for your microphone or your screen.
What I cannot promise
GitHub serves these files, so GitHub sees the requests, including your IP address. Their logging is outside my control, and moving the hosting would only change whose logs you are in. That is the one dependency left, and naming it beats letting "collects nothing" stand in for "almost nothing".
I use Google Search Console and Bing Webmaster Tools, which show me how often this site appears in their search results, for which searches, and how many of those turn into a click, counted by country and device. That data comes from the search engines' own logs, recorded on their results page before you arrive here. Nothing on this site sends it, and it never identifies a single visitor.