Library

Every Attack the Glass resource, in each published format: the technical whitepaper and primer, the executive summary, the remediation playbook, and the FAQ. Each one keeps its versioned filename at a stable path, because a citation has to still mean what it meant when it was made.

5 resources across 5 documents.

Attack the Glass: Executive Summary

Attack the Glass for a board, a general counsel and an executive team. The page you publish is not the page your reader sees, and neither of you can tell. What that means for an organization, why existing controls do not reach it, and the questions worth putting to your own people.

Start reading

Attack the Glass: Technical Whitepaper

The full technical treatment, in sixteen chapters across five parts: the architecture that produces Attack the Glass, the surface it covers, the mechanism by which it is exploited, the confirmed historical record, and the limits of existing defenses.

Start reading

Attack the Glass: Technical Primer

The short technical introduction. A journalist checking a source document, a grid operator reading a control display, and a finance officer approving a transfer all decide on what a screen shows them, and none of them can check whether it shows what the system actually sent. Twenty-two sections, about half an hour.

Start reading

Attack the Glass: Remediation Playbook

What to do about it, in three horizons: the first ninety days, months three to twelve, and beyond. No patch removes Attack the Glass, so an organization reduces it instead, and remediation sorts into three groups by what each change costs to make. Every measure ships today, and every one states plainly where it stops.

Start reading

Attack the Glass: Frequently Asked Questions

Thirty-two questions across six categories: what was found and what it means, the technical objections to it, what is known and what is not, the disclosure record, and what an organization can do in response. The sceptical questions are answered alongside the rest.

Start reading