Take the opportunity to pilfer a goat.
— The 36 Stratagems, Take the Opportunity to Pilfer a Goat
Previously on this series:
#5: Leo Walked I...
For further actions, you may consider blocking this person and/or reporting abuse
Appreciate it! "Learned something without feeling like I was in class" is exactly what I'm going for with this series — glad this one landed. :)
Also, you still owe me that #13 reply 🤣 No rush though.
Oh, I see—but why did you ask a lazy girl? Anyway, it doesn't matter; I was reading that very post of yours regardless.
Because the laziest reader is the one who'll tell you the truth — no energy to be polite. 🤣
I'm actually feeling proud, by the way. That chinese dish was really good - I forgot its name, but the tast was amazing
There's so much good Chinese food out there — you've only tasted a single drop from the entire ocean. Keep eating, and when you get back, step on the scale. You might be in for a surprise. 😄
The ending is the part that stayed with me. "He thought he was the first. He wasn't" quietly turns the whole thing from a clever-revenge story into something colder: theft and counter-theft running as parallel silent systems, where disclosure is the exception and everyone just patches and stays quiet. And the detail I keep circling back to is the fifteen lines nobody deleted the next quarter. That is the truest note in it. A defensive hack written in one tense night outlives the threat, outlives the memory of why it is there, and quietly becomes load-bearing infrastructure no one owns. You wrote a revenge story and smuggled in how real systems actually accrete. The series keeps doing that, which is why I keep reading.
"Theft and counter-theft running as parallel silent systems" — you just named the series' whole architecture in one phrase. I've been calling it "stratagems," but yours might be more accurate.
Have you ever been on the disclosure side of one of these, or the quiet-patch side?
Disclosure side, and mostly by discipline rather than instinct, because the quiet-patch path in the story is the more tempting one. It is faster, it settles the score, and nobody audits you for taking it. The reason I still report is the thing your ending names: a fix that stays private only protects the system that already knows, and everyone standing on the same bug stays exposed. That is how you get the parallel silent systems in the first place. And "he wasn't the first" is the realest beat for me. On the disclosure side you regularly find something genuine and learn it was already reported, or already quietly fixed months back. The finding was real, you just were not first, and you make peace with the work mattering even when the credit and the surprise are both gone. Leo got the counter-move and the sting of not being first in the same night, and that part is not fiction.
"Disclosure by discipline, not instinct" — damn, that's the line right there.
Honestly that part was what made me nervous writing it. The quiet-patch route had to feel tempting, because in real life it is. Anyone who's kept a production system alive at 2 AM knows which path is easier.
But the thing you added — "everyone standing on the same bug stays exposed" — that completes it better than I did. Leo's fix only saved his pipe. The system was still leaky. A countermove isn't a fix, and I don't think I fully landed that part.
How do you keep choosing disclosure? Personal rule, or is it just how your team works?
Personal rule, and solo, so there is no team process to hide behind, which is exactly why it has to be a rule. Left to instinct I would lose some of the time, because the countermove tempts you at 2 AM when you are tired and feel wronged, which is the worst possible moment to be making an ethics call. So I do not make it then. I decided the disclosure question once, in the calm, and I do not reopen it per finding. The finding does not get a vote on whether I report it. That is the only version of discipline I trust, the one that does not depend on me being my best self at the exact moment I am least likely to be. And the duplicate reinforces it rather than undoing it: "you were not first" means the bug is bigger than you, so keeping it private is a bet that you are the only one who found it, and your own ending is the proof that bet loses. Report it and you are right whether or not anyone else was standing on it. Sit on it and you are only right if you were alone, which you rarely are.
The leak angle is strongest when you treat discovery time as part of the incident, not just the bug. If an outsider can find the leak before the owning team can explain when it started, what touched it, and who had access, the technical fix is only half the work. The other half is rebuilding the evidence trail.
This is exactly it. "Rebuilding the evidence trail" isn't about data recovery — it's about proving you were right after the fix is done. Most people fix the bug and call it done. They don't fix the trust fracture that made nobody believe them in the first place.
One of the later stories in this series sits right on that gap: the person who finds the leak knows exactly what happened, but nobody trusts him, because he didn't pull the logs before he got let go.
That is a brutal but important distinction. Fixing the leak repairs the system; rebuilding the evidence trail repairs the ability to be believed. In incident work, the logs are not just technical artifacts. They decide whether the person who saw the truth early can prove it before the organization edits the story around them.
I enjoyed the story, but what stayed with me wasn’t the drift or the countermeasure. It was the distinction between fixing your own system and fixing the ecosystem. Leo protected CoreStack, but the leak itself still existed until others addressed it. That’s a subtle but important difference, and probably the most realistic part of the story. The best technical stories are the ones that spark discussions about engineering judgment rather than just technology—and this one certainly did. 👍
You caught something I left unspoken. Leo fixed CoreStack's pipe, but he didn't knock on the neighbor's door. ACL found it themselves, fixed it themselves — no notification. The title already told you: he wasn't the first.
What stayed with me isn't what he did — it's what he didn't do. The evidence sat in _misc/ for three months. He didn't report it, didn't warn anyone, didn't use it for anything. Those fifteen lines were his only response to the whole incident. Enough for FinOptima. But for the next company whose training data gets reverse-cached?
You put your finger on the most honest part of this story. I'd love to hear your take on other stories from the series that resonate with you the same way. That kind of read doesn't come around every post
That’s exactly what made the story stick with me. Once I stopped thinking about the code, it became a story about engineering responsibility. For me, the hardest question isn’t whether Leo’s countermeasure was clever. It’s whether fixing only your own boundary is ever enough when you know others may still be exposed. In production, we’re often rewarded for protecting our own systems, not the ecosystem. But those aren’t always the same thing.
That’s why the _misc/ folder mattered more to me than the fifteen lines of code. It became a reminder that sometimes the most important engineering decision is the one you choose not to make—or the conversation you choose not to have.
Looking forward to reading the rest of the series.
Version bumps are always a mixed blessing.
Will read when I'm back from cycling (again) ;-)
Stratagems #16: Pick your line before the descent. 🚵😄
Pick your line before the descent - are you clairvoyant? :D
Yesterday I failed to do exactly that, and then I tumbled LOL - it was a harmless little tumble, not serious at all, but dumb and quite unnecessary - never mind, can happen, better next time!
Haha glad it was harmless! 🙌 And no, not clairvoyant — just a universal cyclist truth. We've all picked the wrong line at speed and thought "well, this is happening now" halfway through.
Nice twist plot, that the other 'party' found it before he did ... looking forward to the next episode, and I've jotted in my "notebook" (not a real one, just virtual) that I'm gonna do a "re-read" at some point of the whole series - see if I can find stuff that I missed on first read!
A re-read might catch a few things even I forgot I left there 😅 #15's almost ready — good timing for the refresh.
Hello, I am a senior developer with 9 years of experience.
Now I am looking for a friend to work with me.
If you're interested, send me a message.
Good Luck!
That's the question that keeps this series going, honestly. Not just "who found it first," but "who decided it should stay quiet." The patch isn't the scary part. The decision is.
Nice one
Thanks for the comment — things only get more interesting from here. Stay tuned!