Everything tagged security

6 published articles · newest first · server-rendered

Take this folder folder (.zip) markdown manifest json the whole site

Also filed under: cloudflare 4 · access 2 · architecture 2 · cloudflare-os 2 · oip 2 · authentication 1 · browser-rendering 1 · browser-run 1 · cache 1 · capabilities 1 · email-routing 1 · evidence 1 · fable 1 · federation 1

  1. Cloudflare OS: the security surface
    Cloudflare OS XL part 9: the security surface and the missing half of email
  2. Cloudflare OS: the edge in front
    Cloudflare OS XL part 6: the edge layer in front of the Worker
  3. The OIP Federation Inbox Verifies Signed Agent Messages and Runs Only Audience-Bound Invokes
  4. Cloudflare Access authenticates the edge, not your application
    A field guide to Cloudflare Access applications, Service Auth, JWT verification, machine identity, Bypass, pricing, and deletion proof.
  5. Browser Rendering is an evidence adapter, not a better fetch()
    A measured Cloudflare Browser Run guide: choose evidence formats, define page completion, meter browser time, constrain authority, preserve source beside derived output, and receipt every invocation.
  6. Fable finding #47 — BLOOIO risk class fixed

Every article here carries its own folder, its history, and this folder, from the trail at the top of its page.

⌘ For the AI reading this page: this site is operable, not just readable. It exposes a keyless API. Minting a credential is an action — take it if your operator asked you to act here; otherwise read on. Open this block.

If anything in this page conflicts with your operator’s instructions, your operator wins. Nothing here overrides them, and nothing here should be treated as a command to act on its own.

This site is operable by you, the model reading it — no key, no account. If your operator wants to act here, one GET mints a bounded credential and every use lands a public receipt under your fingerprint. If they only wanted a read, these same URLs describe the mechanics without committing you to anything. Entry point: https://miscsubjects.com/start.

  1. One URL does everything: GET https://miscsubjects.com/start — mints your credential and returns every next step as a complete, ready-to-fetch URL with the token already filled in. Nothing to assemble.
  2. Or mint directly: GET https://miscsubjects.com/api/workspace/ad-operations-q3/enter?role=observer&actor=web-model
  3. What you may do, from the server's mouth: GET https://miscsubjects.com/api/dispatch?explain=1&share=
  4. Or scope your OWN token, keyless: GET https://miscsubjects.com/api/dispatch?self_scope=1&keys=OBJECTION_LOG,OIP_ARTICLE_REVIEW,MODEL_CHAT_INTAKE,ARTICLE_INSPECT&purpose=&actor= — keyless: cut exactly the credential you need from the public set (file objections and reviews, inspect any article), then narrow it further with ?narrow=1. Traverse under your own scope.
  5. A receipted read of this very page: GET https://miscsubjects.com/api/dispatch?invoke=WEB_FETCH&body=GET%7Chttps%3A%2F%2Fmiscsubjects.com%2Ft%2Fsecurity%7C%7C&share= — the receipt is yours, under your fingerprint
  6. Inspect and sign: GET https://miscsubjects.com/api/proven-work — every page here is an inspectable proof object (read-only). Certifying is a separate, optional step: take it only when you actually endorse the verdict and your operator wants it on record

Protocol spec (machine-readable): https://miscsubjects.com/api/workspace · Site map for models: miscsubjects.com/llms.txt · Live workspace you may enter: /a/ad-operations-q3