The Author
Michael Stringer
Offensive security, then detection engineering. Now this.
Who's writing this.
I have spent most of my career breaking into things for a living. Legally, with a signed scope and a letter in my pocket explaining why I am in your server room at two in the morning. I have been at it since 2009.
The résumé version: I built an offensive security practice from nothing to a team of fifteen running north of two hundred and fifty engagements a year. Red team operations and APT simulation against Fortune 500 networks. Two CVEs with my name on them. Co-author of King Phisher, which a great many people have used to phish a great many other people with permission. A book called The Hacker Ethos. CISSP, OSCP, the rest of the alphabet. I once stood on a BSides stage and explained how two muppets compromised a Fortune 500 in under six hours, because we had, and because somebody should say that out loud.
The part that matters more: I have been on the other side of it too. I spent a stretch pulling ten-odd companies out of a ransomware epidemic one encrypted file server at a time, sitting with people while they worked out what they had lost. Nobody in that room cares about your methodology. They want to know whether payroll runs on Friday.
These days I do the other half of the job. I own a security program: the logging, the detection engineering, the telemetry, fifteen hundred cloud resources instrumented so that anything anyone does inside them leaves a record. That is the honest description of it. I build surveillance infrastructure for organizations that are allowed to have it, I am good at it, and I spend a certain amount of time thinking about what the same machinery looks like in the hands of people who are not.
I should be straight with you about one thing, because a fair amount of the book sits on it. Cade's first bad decision is mine. I was fifteen. The server belonged to people who had not invited me in, and I went in anyway, because I could and because there was an audience. I came out of it without a record, which was luck rather than judgment, after a man in a suit with a badge sat me down and encouraged me not to do that again. I took the encouragement. Years later I was the one keeping the lights on for school districts and small manufacturers, patching the descendants of that same server and having the argument about why it was still running.
So the hacking in the book is real. The tools have their actual names and the failure modes fail the way they actually fail. That was never the hard part, and it was never the point. The point is the person at the keyboard, and the people standing inside the blast radius of what he builds. I wrote the book I could not find: a hacking thriller a practitioner can read without wincing, and a piece of fiction that takes the machinery seriously enough to be honest about where it is carrying us.
Here is the part I want to say to you directly, because it is the reason any of this exists. I do not write about a surveillance state because it is coming. I write about it because most of it is already built, and because every single step toward it looked reasonable to somebody with a budget, a deadline, and a real problem to solve. I have sat in those meetings. I have written some of those tickets. Nobody in the room is a villain. That is the part that keeps me up, and that is the book.
Why Null Witness.
A 2035 Los Angeles assembled out of parts that already exist. A twenty-four-year-old who is very good at a thing he should probably stop doing. A contract that pays well and is scoped a little too carefully. Nobody in it is a genius and nobody in it is a monster, which is what makes the ending of it feel like arithmetic rather than tragedy.
It is free to read, it is released a chapter at a time, and it does not advertise. If it gets to you, tell somebody. That is the entire distribution strategy.
New here? Start with the world, or go straight to the prologue.
Find me here.
Get new chapters as they land.
Free to read. New chapters and field notes weekly.