Writing on the agentic web.
Cryptography, local inference, and what it actually takes to build a browser from first principles. Written by the people doing the work.
Everything we’ve published.
Why harvest-now-decrypt-later makes post-quantum urgent today
Nation-state adversaries are collecting encrypted traffic now, planning to decrypt it once quantum computers arrive. For anything sensitive, the window to act is shorter than most teams think.
Read →The browser telemetry audit: what Chrome, Firefox, and Edge actually send
We ran a 30-day network trace on the three major browsers at default settings. The results were worse than we expected, and clarifying about what “opt-out” means in practice.
Read →Running Llama 3.3 70B in your browser agent on consumer hardware
We benchmarked local inference for the Dart Agent on M3, M4, and AMD AI-MAX hardware. Here is what is actually usable for agentic workloads today.
Read →The BYOM architecture: why we will never sell tokens
Every browser that proxies AI inference has a structural conflict between its margin and your wallet. Here is why BYOM is the only honest pricing model for a browser with an AI layer.
Read →Hardware-attested identity: a browser engineer’s guide to TPM 2.0
How we use TPM 2.0 and the Apple Secure Enclave to generate non-exportable identity keys — and why that changes the threat model for browser-based authentication.
Read →What we stripped out of Chromium, and why
A walkthrough of the patches we apply to the Chromium tree: what stays, what goes, and the engineering trade-offs in removing tightly-coupled Google services.
Read →New writing, roughly once a month.
Engineering notes, benchmarks, and the occasional argument. No product announcements dressed up as insight.