CODE-FIRST
CHROMIUM
Historical mapping · Normal · Mojo/IDL · Fixes
Large systems reveal different security questions through general code, interfaces and boundaries, or historical fixes.
A SELF-TAUGHT RESEARCH JOURNEY
No formal roadmap. No assumption that we knew what we were doing. We started with code, two AI systems, and a willingness to be wrong repeatedly.
OpenAI + Anthropic in parallel. Evidence as the referee.
WHY AI MATTERED
AI compressed the distance between a question and an understandable model of the problem. But the fastest lessons came from the moments when an idea looked convincing, reached real code, and failed.
OpenAI and Anthropic worked as parallel reasoning partners, not as competitors. One answer could challenge the other. Assumptions became easier to expose. Failed approaches could be re-evaluated. The human decision remained the final gate.
AI accelerated the learning curve; evidence decided what was true.
FROM EXPERIMENTS TO LENSES
Repeated experiments gradually became structured viewpoints. They are not products or autonomous engines; they are complementary lenses for asking better questions of code, devices, change and signals.
CODE-FIRST
Historical mapping · Normal · Mojo/IDL · Fixes
Large systems reveal different security questions through general code, interfaces and boundaries, or historical fixes.
DEVICE-FIRST
Real Pixel · Full-stack context
Begin with the real device, then work backward toward the relevant artifact and code—a second viewpoint that reduced false leads.
FRESHNESS
Z1-D · Official inventory · Git delta
Not “what was interesting before?” but “what code has actually changed now?” Freshness became its own research perspective.
SIGNALS
Event-driven · Manual · ESR · T0 · T1 · MDA
Watch signals around future code movement, then investigate only when something becomes materially interesting.
INTERACTIVE CENTERPIECE
A compact map of the viewpoints, memory and validation stages that emerged from the learning process.
INTENTIONALLY INCOMPLETE
The universe shows the lenses, the flow and the validation stages. It does not expose the selection logic, internal scoring, thresholds, prompts, datasets or operational rules behind them.
WHEN A SIGNAL STARTS TO LOOK REAL
01
Evidence and candidate state are frozen before directed validation, preventing drift through the pipeline.
02
One concrete causal path must lead to a material, observable consequence.
03
A technically valid issue is not automatically new. Public prior art and observable originality still matter.
04
A reproducible PoC, defensible root cause, material impact and clearly applicable scope.
RESULTS WITHOUT OVERCLAIMING
The system is small and imperfect, but the journey has already produced real outcomes: confirmed findings, closures, reports, technical results and cases that resulted in patches.
Just as important, many apparently promising ideas failed. False positives were eliminated. Methods were discarded when evidence did not support them. Those failures changed the system.
RESPONSIBLE RESEARCH
Our work has focused on the passive side of security research: source, deltas, architecture, boundaries, validation and reproducibility. The active, offensive side of the discipline is a different craft that we have not explored to the same depth.
THE MAP LEFT BEHIND
We started by trying to understand why we were wrong.
The methodology came later. Explore Google Scan UniverseThis universe is simply the map left behind by that learning process.