Sunday, August 23, 2026

The Infrastructure Disappears. The Relationship Remains.

My kids play video games.  Sometimes too much. It used to be Roblox and Minecraft and then Fortnite and who knows what else as they gravitated from PlayStation and Xbox to basic mobile games and then eventually PC games.  The console vs PC philosophy I guess. 

What I noticed over the years is how much has changed since I was younger and had my Ultima and Star Control and Diablo 2 and Fable and then Elder Scrolls and NHL and Madden experiences is that everything is in app purchases and subscriptions now.  Buy an Xbox game and have to update and subscribe and take an hour to set it up. No more throw in the dvd or cartridge and start playing. Different times.  

Thinking on all these payment layers and back to some Pagarba VR and AR and decentraland and blockchain crypto tokenization and gamification angles and projects we did , it's fascinating how far the spaces have come, but how far they still need to go for a broader audience reach.  

The web3 gaming, prediction markets and digital wallets have adapted and are now  converging on the same problem; who owns the customer relationship when payments, digital assets and commerce become part of the product.

The answer is becoming less about blockchain and crypto tokens itself and more about who controls the layer between the customer and the transaction.

Web3 gaming did not struggle because blockchain stopped working. It struggled because blockchain became the user's burden.  And a lot of web3 games were awful.  And the virtual land and decentraland variations were just worse versions of second life honestly.  

And blockchain and crypto have had that UX and UI challenges for a decade now.  Users or players are expected to create wallets, protect seed phrases, understand gas fees, approve transactions and think about tokens before they could simply play a game or use the application.  

That is a product problem, it's a user experience problem and not a cryptography problem. The technology became visible at exactly the point where it needed to disappear.  And then you has the typical tech bro response of calling users too dumb to use it. That never goes well and never works. 

The numbers reflect the problem. Web3 gaming funding fell sharply in 2025, while daily active wallets declined to roughly 4.8 million in the second quarter, the lowest level since early 2023.

The underlying technology continued to operate. The user experience did not create enough value to justify the additional complexity.

The Ronin bridge exploit showed what happens when infrastructure becomes part of the trust relationship.

In March 2022, attackers compromised validator keys associated with the Ronin Network and used them to authorize fraudulent withdrawals totaling roughly $625 million.  Think about that. $625 million.   

The technical details were sophisticated, but the customer experience was simple as the assets were no longer safe.  Reputation for financial and gaming are huge.  Don't trust any of it and nobody wants to use it. And it's not as simple as a master card fraud charges where there are processes in place to cancel those transactions and get your money back. Cancel the card and so on.  Blockchain and crypto seemed to forget hackers exist, people forget passwords all the time and bad things can happen.  Nobody wants to think they're just screwed.

Users do not care whether the failure happened in a validator set, bridge contract, custody system or payment processor.

They care whether their money, assets and account are still there. 

The next generation of Web3 products is therefore taking the opposite approach.  So there is progress and hope. 


Make the infrastructure disappear.


If you're familiar with gaming and payments, Xsolla is one of the bigger players. There are many companies like them who do well , have many paying customers, many employees globally yet if you know you know and if you don't, you never heard of them but maybe saw them somewhere.  

I used to work at a company called ESET. Great efficient and cost effective anti virus software company. Nobody heard of them but a few people.  Yet I worked for them like 16 years ago and they still are around and have their products on display at Microcenter now.    

Which brings me back to Xsolla and their plans for blockchain and backpacks and wallets and payments and zero knowledge proof.   Xsolla has started implementing their Xsolla ZK and maybe it's part of the wave of the future for web3 products and features.  It's not tech trying to find a problem.  It's a problem being solved by technology. 

Xsolla originally positioned ZK as ZKsync-based infrastructure for managing digital assets and verifiable ownership. Its broader Web3 strategy has increasingly focused on ownership, programmable value exchange, interoperability and player participation without requiring the player to understand the underlying blockchain infrastructure.   Nobody cares about a wallet or token.  They just want things to work and work fast and be tustworthy.

That direction makes considerably more sense than asking every gamer to become a crypto user.

The best blockchain product may eventually be the one where the customer never knows blockchain was involved.  

But that creates a much bigger competitive problem for Xsolla.

Because the financial industry is moving in the same direction.

Coinbase is moving deeper into regulated financial infrastructure. The OCC conditionally approved Coinbase's national trust bank charter application in 2026.

The OCC also conditionally approved five national trust bank applications in December 2025. First National Digital Currency Bank and Ripple National Trust Bank received conditional approvals for new national trust bank charters, while BitGo, Fidelity Digital Assets and Paxos received conditional approvals to convert existing trust companies into national trust banks.


The distinction matters.


These companies are not simply trying to become traditional retail banks. They are moving pieces of custody, settlement, fiduciary services and digital asset infrastructure closer to the regulated financial system.

PayPal is pursuing a different version of the same strategic direction. It has applied to establish an industrial bank in Utah, seeking greater control over parts of its financial infrastructure and the services it provides to businesses. That is another example of a platform trying to bring more of the financial relationship under its own control rather than depending entirely on external institutions.

Robinhood is doing something similar from the consumer finance side. It has expanded from brokerage into crypto, prediction markets, futures and derivatives. In late 2025, Robinhood announced a joint venture with Susquehanna International Group, with Robinhood as the controlling partner, to acquire MIAXdx and build an independent CFTC-licensed exchange and clearinghouse. The acquisition closed in January 2026. Robinhood reported more than 12 billion event contracts traded in 2025.

That is important because Robinhood is not simply adding another feature to its app. It is investing in the infrastructure underneath the feature.

MetaMask is moving in the opposite direction from a traditional financial institution. 

It starts with the wallet.

Then it adds the payment layer.

MetaMask has launched its own stablecoin and connected its wallet to a Mastercard payment product, allowing users to spend assets held through the wallet.

Kraken has similarly moved from exchange infrastructure into consumer payments with its Kraken Card, bringing crypto balances into a conventional card experience.


The strategic pattern is difficult to miss.


Financial companies are moving toward wallets.

Wallet companies are moving toward payments.

Payment companies are moving toward stablecoins.

Stablecoin companies are moving toward regulated financial infrastructure.

And gaming companies are trying to make digital ownership and value exchange part of the commerce experience.


The boundaries are collapsing.


Traditional payment networks are not standing still either.


Mastercard has been building stablecoin and wallet capabilities with companies including MetaMask and Kraken.


The important point is that Web3 payment products are not necessarily replacing traditional payment networks.


In many cases, they are using them.


The blockchain may provide the asset layer.

The wallet may provide the customer relationship.

The stablecoin may provide the settlement asset.

The card network may provide the merchant acceptance layer.


The customer simply taps a card.


That is the real convergence.  It's not what the original Bitcoin and cryptocurrency and blockchain world dreamed of and it's certainly far from Decentralization, but maybe that's just how it stays relavent and changes things in its own way. 


Visa's own analysis estimated that adjusted stablecoin transaction volume was on track to exceed $10 trillion in 2025 after removing high frequency trading wallets, smart contract addresses and bot activity.


The precise number depends on methodology, but the strategic signal is difficult to ignore.


Stablecoins are no longer simply a crypto trading instrument.

They are becoming financial infrastructure.

And that changes the competitive landscape.


The real competition is not blockchain versus Visa.


It is control of the customer relationship.


Who owns the wallet?


Who controls the payment experience?


Who owns the rewards layer?


Who controls identity and attribution?


Who gets the next transaction?


The company controlling those relationships can increasingly capture value across multiple layers of the transaction.


That is why Xsolla's position is interesting.


Xsolla already sits inside the commerce relationship between game developers, publishers and players.


It does not need to convince a player to download a cryptocurrency application simply to establish a financial relationship.


The commerce relationship already exists.


That gives Xsolla a potential advantage.


But it also creates a much larger competitive field.


Xsolla is not simply competing with other merchant of record providers. It is competing with platforms that already control enormous customer relationships.


Coinbase has the financial account.

MetaMask has the wallet.

PayPal has merchant relationships and consumer payments.

Robinhood has the retail financial customer and the exchange infrastructure underneath it.

Visa and Mastercard control enormous payment acceptance networks.


The strategic question is therefore not whether Xsolla can build blockchain infrastructure.


It can.


The question is whether it can use that infrastructure to strengthen the relationship it already has with the gaming ecosystem.


That is a much more interesting product question.


Prediction markets provide another example of financial infrastructure becoming embedded in consumer platforms.


Robinhood's prediction market strategy is not simply about putting event contracts in an app. It is increasingly about the infrastructure underneath them: exchange access, clearing, liquidity, distribution and the customer relationship.


That distinction matters.


The market is moving away from standalone products toward integrated financial ecosystems.


A user does not necessarily care whether the company behind the experience is technically an exchange, wallet provider, payment company, bank or gaming commerce platform.


They care that the account works.

They care that the money moves.

They care that their assets are available.

They care that rewards arrive.

They care that checkout is fast.

They care that someone is accountable when something goes wrong.


The distinction between a wallet and a bank may become increasingly irrelevant from the customer's perspective.


What matters is who owns the relationship.


That is also why the competitive advantage will increasingly migrate away from blockchain mechanics.


The first generation of Web3 asked users to enter the blockchain.


The next generation is trying to put blockchain behind the experience.


That is a much better product strategy.


But it also changes what companies are actually competing for.


Wallets, payments, rewards, identity, commerce and settlement are converging into a single customer relationship.


The companies that control that relationship will have the strongest position.


Xsolla has a legitimate opportunity because it already controls an important piece of the gaming commerce relationship.


But Coinbase, MetaMask, Kraken, PayPal, Robinhood, Visa and Mastercard are all moving toward adjacent pieces of the same territory.


The question was never who has the best blockchain.


The question is who can make the entire financial and commerce experience feel invisible.


The infrastructure disappears.

The relationship remains.


And eventually, when the infrastructure is badly designed, the customer finds it anyway.

Friday, August 21, 2026

ZKP for medtech and medical devices?

 

The medtech space is fascinating.  It used to be bolt on security and worry about it later. Some of that philosophy has changed , the FDA made regulations and compliance more mandatory and less checkbox assessments and governance non technical advice, but still , many challenges remain.  

What about trying to implement ZKP or homomorphic encryption into medical devices or embedded instruments?   Even Post Quantum security techniques merging techniques that crypto and blockchain have researched, Google has written some white papers on and cryptographers are testing ?

Looking more into medtech and how a lot of medical devices generate far more sensitive data now , and across a system of parties with different trust relationships is a growing concern. Think about what a medical device actually is now vs just some pacemaker.  They are a medical device, gateways,  hospital network, patient phone and network, cloud infrastructure, analytics platforms, providers, payers, and regulators. 

The problem is not simply protecting the device. It is deciding what each party can see, what each party can verify, and what happens when those trust assumptions change.  And devices may send electrical or other signals now not just Bluetooth connectivity. 

Conventional controls handle much of the foundation. Secure boot, signed firmware, hardware roots of trust, device identity, attestation, and authenticated communications establish device and software integrity. That trust chain begins long before deployment.  You have  factory provisioning of device credentials and keys, boot ROM and hardware root of trust integrity, and contract manufacturing custody that  determine whether the root of trust is valid from the moment the device is powered on. 

If the requirement is simply proving that a device is running approved firmware, a signed measurement is generally more appropriate than a zero knowledge proof.  We do assume manufacturing is trustworthy and not installing software or hardware backdoors. Should we though ?

Once deployed, a gateway may act as a transparent relay or, if local protocol translation or edge processing is required, as a plaintext trust boundary. The security problems diverge once data leaves the device. Homomorphic encryption can allow certain cloud computations without exposing the underlying plaintext to the compute environment, but its practical use remains limited to workloads where the performance and complexity are justified. 

It is not a solution for most real time physiological telemetry. Zero knowledge proofs address a different problem entirely.  Proving a defined claim about private data without disclosing the data itself. Neither technology establishes that a sensor measurement reflects physical reality. An attack against an analog sensor interface can alter a measurement before software or cryptographic controls ever see it.

That distinction matters because medical device security has different consequences. A confidentiality failure can expose protected health information and create regulatory and legal risk. An integrity or availability failure can affect a clinical decision or interrupt therapy. The controls, threat models, and acceptable failure modes are not the same.

The fifteen-year lifecycle compounds these risks. Cryptographic algorithms can be deprecated, keys can be compromised, standards can change and regulatory requirements can evolve. But the hardware ages too. Memory retention, component degradation, sensor drift, clock accuracy, physical tampering, side channel attacks, and limited processing, storage, and battery capacity can constrain what security changes are actually possible.  And who knows the more AI is pushed what else becomes a vulnerability.  

Cryptographic agility therefore cannot mean simply having the ability to install a new algorithm. The device has to have enough hardware capacity to support the migration, enough storage for recovery mechanisms and alternative trust material, and an update architecture capable of delivering the change. 

Maybe we need to look at how the Voyager spaceships still operate and can be updated and fixed after 40+ years.  And nobody can actually go land on the ship and change or fix it. Different use case but learning from that engineering philosophy may go a long way for medical devices and AI. 

 A medical device without reliable access to its trust infrastructure creates another problem.  A revocation and key replacement may not be available when needed. When trust anchors fail, the system requires defined safety-state policies such as graceful degradation to standalone operation. A security mechanism that bricks a safety-critical device is an unacceptable failure mode.

Regulation adds another constraint. A manufacturer can engineer for change, but a cryptographic modification can affect verification, validation, documentation, and the approved configuration of the device. Meanwhile, the manufacturer does not control every trust boundary. Cloud providers, EHR vendors, certificate authorities, network operators, and other third parties can change infrastructure and trust relationships independently.

The real design question is therefore not which cryptographic primitive to choose. It is which security assumptions are controlled by the manufacturer, which are delegated to third parties, how those assumptions can change over the device lifecycle, and what happens when they fail.

Which parties are trusted with plaintext? Which only need a verifiable claim? Which computations must remain confidential even from the infrastructure executing them? What happens when a key is compromised, a device is offline, hardware degrades, or a security update conflicts with clinical safety?

A long-lived medical device needs more than cryptographic agility. It needs a security architecture that can evolve without turning a change in the security environment into a change in patient safety.

The future is bright. It's also challenging. 

Thursday, August 20, 2026

Supply chain attacks and genAI

Many executives and leaders still treat AI tools as plug-and-play; buy it , trust it, install it, connect it, use it , automate it, scale it. 

That assumption is becoming a liability. A huge one.

The LiteLLM supply chain attack in March of this year (2026), exposed exactly this philosophy. Attackers didn't need to breach their targets directly. They compromised a trusted security scanner inside a development pipeline, used stolen credentials to distribute poisoned software updates, and gained access to cloud keys, Kubernetes secrets, and live AI provider credentials across corporate environments. The front door was never touched. It wasn't even knocked on in a sense. 

The same principle applies to attacks on municipal water systems. You don't have to breach the facility itself when you can compromise a trusted management interface and control what sits behind it. And some of these city and county water and wastewater management systems have old PLC and other technology that was never supposed to be connected. Never designed for it.  

AI platforms create a similar choke point. They connect companies to dozens of services, so compromising one trusted dependency can provide access far beyond that single system.

Yet many organizations still rely on periodic audits, vendor trust, and reactive credential rotation. They rely on MVP products sold as GA v1 enterprise ready and aren't even close. But not everybody vettes these or vendor politics at play so forced onto teams and employees. That security model was built for a threat environment that no longer exists.

Every external software update should be treated as an unverified artifact until its provenance is established. Zero trust to the extreme. Supply chain attacks, at scale, should be a priority.  

Every centralized access layer should be treated as an elevated-risk target requiring continuous logging and monitoring.

The executives and leaders who understand this aren't treating cybersecurity as an IT cost center. They're treating digital infrastructure like any critical supply chain; with verified provenance, real-time visibility and zero assumption that something is safe simply because the package carries a familiar name.

This blog and description has more details about that liteLLM hack back in March.

liteLLM Hack March 2026



Saturday, August 8, 2026

The amateur was bad

 The Amateur movie review on medium


I watched the movie , 'the Amateur' last night. Saw the trailer before, poking through Amazon prime and it was free, so figured why not. 

The premise was interesting even though it's been done a thousand times over.  Revenge. Fish out of water. Conspiracy. Second guessing.   Why not give it a shot. I remember thinking the trailer looked promising and some big names in the movie.  A few actors who have shown they make movies better than they should have been in the past.  Worth it. 

What a bad movie though.  The premise, again, interesting enough with a catch,  as the guy isnt Jason Bourne or some MMA ex military tough guy. A lot of the Mr. nice guy but was a former seal or secret agent troupe is overdone and kind of annoying. So at least it wasn't that. 

But it was like they took some of those movie ideas Jason Bourne like premise and then thought hey let's get the guy who played Mr Robot as a hacker to be this bored analyst with a revenge plot.  And it started early. Demands. Weird situations. World travel. Unlimited money. Random secret hacker like friends. It was like they had a room full of writers using chatgpt and throwing anything and everything and why not. Let's do that. 

It was slow. But no real build up to care. That's the worse for a show or movie. Slow buildup but too quick where you have no connection to any of these people or story. It's like some bad Saturday night live satire sketch that wasn't funny or dramatic or serious and the comedians just going through the motions. Or they brought in some big name who isn't exactly a great actor and it falls flat. 

The common Hollywood troupe of computer geeks and hackers is always annoying.  The Amateur though, he wasn't even a hacker. CIA threat intelligence analyst who seemed to have certain clearances and relationships, but macgyver like traits, breaking bad Walter chemistry knowledge, Jason Bourne like revenge and connections, Mr Robot like hacker skills and it was just ridiculous and annoying. 

  I wonder if it even gets made or winds up lost and hardly watcher if they casted someone else to be the lead. Casting directors probably thought, "hey he was a hacker in Mr Robot" let's get Rami. it was good casting to get the guy who played an intelligent hacker in a somewhat successful show to play the lead. 

So let's go with the CIA like threat intelligence analyst in the basement who is somewhat of a hacker.  Somehow all that intelligent mindset was lost as he's using credit cards , IDs given to him by the CIA,  knows they can track him, knows he's basically committing treason and being targeted and his boss director  will have it out for him.  It was really like chatgpt wrote the movie with no context and everybody thought, hey this sounds cool.   I understand the nature of stress , fish out of water, and he's in over his head but all the build up was too slow but too quick and the overall revenge played out more ridiculous than the next. 

Jason Bourne has many plot holes and points but at least the idea he was getting revenge, figuring stuff out and one bad mofo was legitimate. Even in Mr Robot , he was a hacker out to get shady bad guys and then conspiracy to the extreme, there was still some semblance of suspension of belief where some of to makes sense and you understand.  

The Amateur. It was so bad. 

Saturday, August 1, 2026

Flock needs a VP

 

Interesting after all the uproar and media buzz , flock has a VP of Product opening. Wonder if someone had enough and quit or the environment and culture is playing out in different circles and is at an inflection point.    It'll be interesting to follow and see what leader they wind up hiring for this and how things change or stays the same .



The posted job JD


"

VP Product

The Problem

As Flock expands into new markets and use cases, scaling our portfolio across hardware-enabled infrastructure, firmware, and cloud software requires dedicated executive product leadership. Maintaining product differentiation and earned trust across complex technology layers demands a strategic leader who can align engineering execution with long-term business goals. You will lead end-to-end product strategy across core product lines, mentor product managers, and represent our technology with clarity to cross-functional partners and external stakeholders.


What You'll Own

Lead end-to-end product strategy and execution for a multi-layered portfolio spanning cloud software, firmware, and hardware systems.


Direct and develop a team of Product Managers responsible for driving core product areas from initial roadmap conceptualization to market execution.


Partner with Engineering leadership to align product roadmaps with technical architecture, platform evolution, and delivery capabilities.


Translate customer needs, competitive dynamics, and market signals into prioritized product roadmaps that balance innovation, system reliability, and speed to market.


Represent Flock's product portfolio and guiding development principles in high-stakes external conversations with customers, partners, and public stakeholders.


What This Role is Not

This isn't a hands-off corporate strategy position, you will actively engage with engineering teams on technical tradeoffs and dive deep into product architecture.


This is not a single-product or software-only role, you will oversee an integrated portfolio combining hardware devices, firmware, and cloud platforms.


This isn't an isolated internal management function, you will serve as an external product spokesperson who can explain technical systems clearly to diverse audiences.


What You Bring

Proven track record leading and growing complex, multi-layered technology products across software platforms and hardware-adjacent systems.


Strong product judgment with the ability to prioritize effectively across competing demands and incomplete market information.


Demonstrated experience developing and managing product managers to drive cohesive execution across distinct product lines.


Capability to partner deeply with Engineering on platform architecture, technical sequencing, and development tradeoffs.


Clear executive communication skills with the ability to represent complex product capabilities to non-technical external stakeholders.


Compensation

In this role, you'll receive a starting salary between $280,000 and $300,000 as well as Flock Stock Options. Base salary is determined by job-related experience, education/training, as well as market indicators. Your recruiter will discuss this in depth with you during our first chat.


Why Flock

Every community deserves to be safe. Flock builds the technology that makes that real: last year we supported over 1 million criminal investigations and helped locate more than 10,000 missing people. We're 1,700 people building the impossible with over $1B in funding, and the expectations are high on purpose. If you want a role where the stakes are real and the pace matches, this is it.


Some problems get solved faster in the same room, so we prioritize candidates in Atlanta and Boston. Hub-based roles mean real in-person time with your coworkers. Remote roles exist, and when a posting is open to remote work, it says so.


Building the impossible takes every kind of mind. Flock is an equal opportunity employer, and we know the best solutions come from diverse perspectives, experiences, and skills working together with mutual respect

"



Definitely will follow this.



Thursday, July 30, 2026

Water systems challenge in Minnesota

 Water supply systems Minnesota

US blaming Iran

"Officials are investigating after a cyber attack targeted water systems in several Minnesota cities, but they say there is no threat to the drinking water. FOX 9's Bill Keller reports."



These old public utilities, parks and everything government related have a lot of old tech, forgotten about tech and maintained by a few people overworked and overextended who aren't IT or cybersecurity or OT individuals. Nor should be but it's easy to just say system is flawed and blame certain folks.

Sunday, March 1, 2026

Ice Rinks: The Reality Behind the Surface

 Ice Rinks: 

The Reality Behind the Surface

Guides , manuals, blogs , video's , old heads will tell you ice should be perfect. Thin. Level. Precise. But made to last and think long term not just short term. Especially old barns. 

In reality, most rinks don’t get that luxury. There isn't the time , patience , experience or equipment for all that.  The ice needs to be 1.5 inches thick or more to survive a day of high school games, beer league, clinics, and youth camps and games and part time temporary zamboni drivers

The people maintaining it are often part-timers. Ten minutes to cut and flood. Not really flood. Temperatures fluctuate. Old compressors wheeze. Pipes leak. Water quality varies. HVAC systems are aging, sometimes broken. You learn quickly that “ideal” ice is a fantasy.  And many people don't even care unless it's really bad. Or the locker rooms and bathrooms are a mess , then they start chomping about ice quality too. 

Every day, someone adjusts on the fly: adding water, watching the cracks, watching the puck slide differently depending on the morning temperature, last night's usage and the days schedule. It’s improvisation, judgment, and experience. And yet, somehow, the ice holds. Mostly. Even when it doesn't and the paint starts peeling or looks too bright , deep, dark its more about flooding , light cutting and get it back to 1.5. Somehow, games are played, practices happen, kids learn, and adults compete. Day after day, night after night, week after week, month after month and year after year. Mostly. 

Ice maintenance isn’t glamorous. It’s sweaty, precise, repetitive, and unforgiving. Ice depths can be as simple as a drill , pen and paper and a metal depth ruler. It requires attention to detail, patience, and an understanding that conditions change with every hour. It’s like life; rarely perfect, often frustrating, but always moving forward.

Sports technology can help. Sensors, analytics, monitoring systems add visibility, consistency, and insight. But no tech replaces judgment. And a lot of the tech was built by people who never played or stepped on the ice or drove a zamboni.  But that's silicon valley and tech startup culture.  Many never actually care about the customer much less spent any time actually getting to know the day to day and week to week and pain points.  AI replaces experience, but it doesn't. The rink survives because people care, notice, and adapt. That grumpy old Zamboni and rink operator actually cares about the rink, the ice and hockey, figure skating, sled hockey , broom ball, skippyball, boot hockey, curling and more. 

So when you step onto the ice, remember: there’s a world beneath the surface. One layer of frost at a time. And sometimes, that’s enough.





The Infrastructure Disappears. The Relationship Remains.

My kids play video games.  Sometimes too much. It used to be Roblox and Minecraft and then Fortnite and who knows what else as they gravitat...