TrenchOps 🐎

Insights from the tech trenches

Security

Cover Image

Your AI Agent Reads 50,000 Tokens to Learn One Thing

Compression as via negativa: the cheapest token is the one you never send

Take any coding agent session and open the raw request log. Not the pretty transcript - the actual payload. What you find is a JSON search result with 100 hits where 3 mattered, a log file where the interesting line is buried in 800 lines of "INFO: still fine," and a directory listing of a repo the model already walked twice.

Then apply the uncomfortable ratio: cost of the finished output versus the raw inputs actually required to produce it. The model needed maybe 2,000 tokens of real signal. You paid for 55,000. In manufacturing terms, that is a part made of solid gold to hold a plastic clip in place.

I spent a few weeks running everything - coding, research, boring text work - through a compression proxy called Headroom, and the interesting part was not the money. It was watching exactly how much of what I "sent" to the model was never information in the first place.

What it actually does

It sits between your agent and the API and squeezes everything the model reads - tool outputs, logs, retrieved chunks, conversation history - before it goes upstream. Compression happens locally, nothing gets shipped off to a third party to be shrunk. The model can pull the original back if it needs it.

Read more
Cover Image

Many Eyes, Zero Readers

A hardware wallet built keys from a random number generator it never once called. For five years. The source code was public the entire time.

In a 25-minute window, someone swept roughly 594 bitcoin - about $38 million - out of some 500 unrelated wallets. No phishing. No malware. No supply chain tampering. No 5$ wrench.

Every one of those wallets was protected by a device sold on a single, admirable promise: keys generated offline, on isolated hardware, using a true hardware random number generator, Bitcoin-only to shrink the attack surface, no cloud, no companion app, and open-source firmware you can verify yourself.

The hardware RNG was on the board. Powered. Functional.

For roughly 1,900 days, the firmware never asked it for a number.

The bug is one character wide

The vendor did something entirely sensible: they switched off MicroPython's built-in random path with a build flag, because they had written their own wrapper around the microcontroller's true RNG. Textbook embedded hygiene.

Then a cryptographic support library checked that flag with #ifndef - which asks "does this macro exist?" rather than "is it set to something other than zero?"

The macro existed. Its value was zero. So the library concluded hardware entropy was available and happily bound itself to MicroPython's random function. MicroPython, having read the same macro correctly, had compiled a non-cryptographic software fallback instead of the hardware peripheral.

Read more
Cover Image

The 14 Demands Your European Tech Company Should Be Making of Every Vendor

(And Why Their Sales Team Will Say Yes)

If your European tech company is not making these demands of every vendor, you are subsidizing the offshoring of your own economy and gambling with your sovereignty. I once sat through a postmortem with a German SaaS company that had a Severity 1 outage lasting 38 hours. Their vendor had a platinum support contract with "30-minute first response" but the first response was from Bangalore, asking, "Have you tried restarting the service?" After escalating for 6 hours, they got someone who knew the product - but that someone was in the US and needed to wake up. The contract had no teeth, the data was on AWS us-east-1, and the vendor's escalations went through three continents before reaching someone with decision power.

This is not a support experience. It is a hostage situation.

If you are a larger European tech company, you are actually in a position to make demands. You have the leverage. Use it. Here is the minimum you should enforce with every vendor and service provider. Do not apologize. Do not negotiate on the top items.

Top Priority - Non-Negotiable Core

Data hosted exclusively in Europe

Your PII, your customer data, your telemetry, your configuration, your logs - everything must be stored and processed within the EU. That means no data replication to US regions, no backup in Israel, no disaster recovery in Singapore unless it meets the same standard. The US has the Cloud Act and the Patriot Act. Europe has GDPR, and it is the strongest data protection framework on earth, but it only works if your data never leaves. Include contractual language that forbids data transfer to any territory without adequate protection, with explicit penalties for violating data residency.

Read more
Cover Image

The Night the Kernel Bled

Why Smart Companies Are Mad to Trust Any Foreign Software With Their Crown Jewels

You know the date. A single file pushed by a high-profile cybersecurity vendor turned millions of computers into expensive paperweights. Airlines grounded flights. Hospitals stopped surgeries. Banks locked their vaults. It was the largest digital outage in history.

That file ran at the deepest level of the operating system. It could read every byte of memory, every keystroke, every piece of intellectual property on those machines. And it was delivered silently, automatically, without any human approval.

Now ask yourself: how many other files like that are already on your systems?

This isn't about one company or one country. It's about a structural vulnerability that every organization faces when it outsources its security and operational software to vendors with close ties to any foreign intelligence apparatus. Some of these vendors are based in democracies, which is no guarantee that they don't spy on you or aren't concerned about your sovereignty behind closed doors. Some are based in countries with documented programs to use commercial software as offensive tools. Some have even been caught using shell companies to corrupt the supply chain itself.

You don't need to know which ones. You only need to know that the risk exists, and the only safe move is to reduce your dependency.

Read more
Cover Image

The Employee You Cannot Sue

A friend told me this story about a Company that hired a remote support engineer from a country with beautiful beaches and terrible rule-of-law. They worked European hours, had full access to the CRM, and handled tickets for enterprise customers across Germany, France, and the UK. On paper, it was a perfect hire: talented, responsive, and cheap.

After a few months, they noticed an odd pattern. Customer churn was increasing in a way that correlated with this engineer's shift. No obvious cause in the tickets themselves. But an elaborate security audit revealed that a competitor had started approaching their customers with suspiciously accurate knowledge of their infrastructure, decision-makers, and contract terms.

That engineer had been quietly exporting customer data from the CRM during his shift for three months. He just looked into the account data, wrote it in a notepad, typed it back into his personal computer, and then sold it to a shady data broker who resold it to the competitor. The total payout to the engineer was probably a few thousand dollars (or the equivalent in Bitcoin). A fraction of their annual salary.

The company found out. They fired the engineer. They contacted local law enforcement. And then they hit a wall.

Read more