The Surface Landscape
ATG does not operate from a single place. An ATG operation can start in any language the runtime executes, on any platform that runs one, through any provider that delivers content into one, and from any supply-chain position that touches those three.
Languages and Runtimes (Chapter 4): what running code is permitted to do, and how the powers a language grants decide what an adversary gains by taking a position that ships that code.
The Platform Landscape (Chapter 5): where the runtime lives, the device-scale picture, and the ten platform categories that span the deployed Client Runtime landscape.
The Provider Landscape (Chapter 6): who delivers content into the runtime, the five ways an adversary gets in, and the cross-provider patterns that recur across the deployed landscape.
Content Delivery Networks are where the most sites depend on the fewest providers, and buying one of those providers turns that concentration into a working attack.
Third-party script loading is the trust problem in its most direct form: a site tells the browser to run whatever a third party sends it, and Runtime Anarchy is what that looks like one script at a time.
Open source reaches the Client Runtime through the Open-Source Open Door, the acquisition route with the lowest barrier, and through Origin Laundering.
AI in the Client Runtime makes every one of these properties worse at the same time, and Tailored Deception is the result.
Placement and Access (P&A), the APA Vector Landscape, the seven acquisition pathways, and the attack model run across all of these surfaces.
Ownership Opacity and Adversarial Asset Cycling name the four things a defender would need to know about who owns a provider and currently cannot find out.