SECOND MEASUREMENTS

Track record

Every public claim we’ve checked, whether it held, and what happened after. And, at the bottom, every mistake of our own we’ve had to correct, because a scorecard that only lists other people’s errors isn’t one.

The score so far

Round trips

The clock runs on everyone we write to. These are the ones who answered, fixed it, and said so. The times are theirs to keep.

PaperWhoReplied inFixed inWhat they didSeal
SM-004Kaveh Ranjbar, whisper.online82 min4 hRepublished the missing log head the same night, found a second, worse bug himself while fixing it and disclosed that too, then ran our test suite and reproduced every check before we published.Second Measurement seal, SM-004, fixed in 4 hours badge
SM-001Billy Lau, Google Pixel binary transparency7 days7 daysConfirmed both findings, backfilled the 29 missing January images, fixed the cache eviction and the filing bug, and answered the witnessing question in full.Second Measurement seal, SM-001, fixed in 7 days badge

A round trip is counted when the operator replies, changes what we measured, and the recheck confirms it. The seal is theirs to keep and embed; it carries the paper, the fix date and the log leaf, and links back to the paper. The badge is the one-line version.

Papers

IDThe claimHeld?What we foundWhat happened next
SM-015Chrome CT policy: logs include within the MMD, RFC 6962 MMD at most 4 h, shard windows at most a year; Apple: “usable” logs can be relied onLogs held; the lists didn’t64 of 64 logs inside their MMD, tiled ones under 6 s; Chrome’s list declares 24 h against a 4 h policy, admits four 380-day shards; Apple’s list marks 12 closed shards usable, untouched since MarchSent to Apple and Chrome 3 Oct 2026
SM-012CCADB: CAs upload audit statements within 92 days; Microsoft: audits “on an annual basis”Didn’t hold11 of 119 statements past the deadline, 7 with nothing on file; 24 Microsoft-trusted roots with audits over 15 months old, one from 2019Sent to CCADB and Microsoft 3 Oct 2026
SM-011Mozilla: CRLite’s builder has “total knowledge” of the public Web PKI; uncovered certificates are “likely new certificates and private CAs”Didn’t holdThree of the largest logs read to June, June and August; 68 of 726 top-site certificates not covered, up to 50 days old, from Google, DigiCert and Microsoft; 57 of the 68 were issued by Google Trust ServicesSent to Mozilla 2 Oct 2026
SM-010Hugging Face: every file in every repository goes through a malware scanner at each commitDidn’t holdEvery file under 2 GiB scanned (2,539 of 2,551); none at 2 GiB or more (0 of 487); 476 of them badged “safe”Sent to Hugging Face 2 Oct 2026
SM-009Mozilla: CRLite stores all certificate revocations locally; Firefox enforces it and skips the online check for what it doesn’t coverDidn’t hold38 of 465 current revocations missing; 37 of 108 among certificates revoked within a day of issuance, for up to 28 daysSent to Mozilla 2 Oct 2026
SM-001Google: the Pixel log covers every factory image from Pixel 6 onDidn’t holdJanuary 2026 (29 images) missing for eight monthsGoogle confirmed and fixed it within a week
SM-002AIDev captures each coding agent’s pull requestsDidn’t holdIts Claude Code search catches about 1 in 11No reply yet; two other teams have since reached the same result
SM-003Wild SBOMs are written by many practitionersDidn’t holdNearly half came from one automated runOne author replied; no correction yet
SM-004whisper.online’s ledger proves nothing was changedHeldEvery proof checked; we found a duplicate-update bugOperator confirmed and fixed the bug
SM-005Meta: the pulled-software list is published every 3 hoursDidn’t holdEvery 6 hours since January; whitepaper unchangedNo reply yet
SM-006x402 payment counts on BaseNot testedOur count reproduced; traffic fell three-quartersNo reply yet
SM-007Docker: signed attestations for all Official ImagesDidn’t holdAttestations on 99.9% of Linux images; none signedSent 2 October; seven questions open
SM-008CISA: SSVC answers for every CVE IDDidn’t hold for the Linux kernel1 of 158 kernel CVEs since MarchSent 2 October; six questions open

Held, by this much

Claims that held are not all equal. Some had room to spare; some passed by a hair, and a hair is where the next finding comes from. The bar is how close the measurement came to the line: a full bar is a claim that held by a rounding error. The rechecks watch these first.

The claimWhat we measuredThe marginHow close
PyPI: more than 20% of uploads via Trusted Publishing20.5% in our sample0.5 points above the line
PyPI: 17% of uploads carry an attestation17.9% measured0.9 points above
MCP registry: 4.2% of servers redirected4.02% measured0.18 points below the paper's figure
Homebrew attests every bottle599 of 600one bottle short, reported and fixed by them
Chrome CT policy: logs are “expected to accept” every root Chrome trustsCloudflare Nimbus2026 and Nimbus2027 accept 76 of 101; DigiCert’s Sphinx shards 95; 29 shards miss one; 31 miss nonean expectation, not a MUST; 25 CAs can’t log at Cloudflare (script, data)
Chrome CT policy: a shard’s expiry range “must be no longer than one calendar year”60 of 64 shards within a year on 2026-10-04; 4 over14 days over, and Chrome accepted them anyway
Apple: a log marked “usable” can be relied on for Apple’s CT policy12 usable shards with closed windows on Apple’s list as of 2026-10-04 (list last modified Tue, 31 Mar 2026)no deadline in Apple’s text; Chrome moved the same shards within 8 days
">
Baseline Requirements: a CRL’s nextUpdate at most 10 days after thisUpdate16,000 TLS CRLs: 90th percentile 9.96 days, 28% past 9 daysan hour inside the cap at the 90th percentile; CAs set it to the limit
RFC 9286: a new RPKI manifest “MUST be issued and published before the nextUpdate time”registro.br on 2026-10-04: 21 manifests past nextUpdate within the last seven days (170 in all, most abandoned years ago); RIPE hosted 0, ARIN hosted 1the registry’s own process allows five days; validators allow none
Armored Witness log names its source27 of 28one tag that doesn't exist
Debian blocks unreproducible migrations0 unexplained of 45712 binaries crossed only because a release manager overrode the gate by hand
Proton: an epoch every 4 h, never more than 72longest gap 38.1 hused 53% of the allowance
CT logs: merge within 24 h (classic) or 60 s (tiled)61 min; 6 sused 4% and 10% of the allowance
Firefox CRLite covers every log44 of 68 qualified logs in its coverage list0 of 465 certificates affected today; the margin is the CAs' choice of logs
GitHub: public attestations go to a public log161 of 161 Actions attestations on Rekor227 release attestations in the same sample have no log, by design

Green is comfortable, amber is within sight of the line, red is on it.

Checked, held

The claimHeld?Detail
Armored Witness firmware log names its sourceHeld, 27 of 28The recovery image names a tag that doesn’t exist
Cloudflare Plexi audits every WhatsApp key-transparency epochHeld150 of 150 sampled
MSR 2026 dataset describes real-world MCP serversHeldKeeps only repos with 50+ stars, unstated
PyPI: 17% of 2025 uploads carry an attestationHeld17.9% in our sample
4.2% of MCP registry servers redirected their endpointHeld4.02%
GitHub leaves reporter credit out of the CVEs it assignsHeld0 of 150 carry it
Homebrew attests every bottle its CI buildsHeld, 599 of 600One bottle reported: homebrew-core#314985
NIST enriches known-exploited CVEs within one business dayHeld163 of 163
Kubernetes signs all release binariesHeld408 of 408; 12 of 12 verified
Proton publishes a key-transparency epoch every 4 hours, never more than 72Held515 epochs; median 4.00 h, longest 38.1 h
Debian blocks unreproducible new packages and regressions from migratingHeld457 unreproducible binaries in testing, 0 unexplained; the one hard case was flagged and overridden on the record
Every Certificate Transparency log serves a new entry inside its promised merge delayHeld, 64 of 64Tiled logs within 6 s; classic logs 10 s to 61 min against a 24-hour promise

Scripts for every row are on the measurements index and on GitHub.

What a stranger could reproduce

On 3 October 2026 every paper’s “Run it yourself” block was executed from the public repository on a clean machine by an agent that had not seen the work, with the packages the README names and nothing else. Eleven of thirteen reached the headline number or a result that holds on fresh data; the rest need something a stranger doesn’t have, and the paper says what.

PaperResult on a clean machine
SM-001exact (tree size 1,163, 963 logged, 128 under the generic label).
SM-002the counts land within 0.1% (16,060 and 173,135 against 16,065 and 173,066; GitHub search moves daily). The union sample takes about 50 minutes of search calls.
SM-003the live GitHub check holds on a fresh repository set (80 of 86 exported SBOMs carry links). The corpus steps need the 12 GB Zenodo table and were not run in the window.
SM-004holds at tree size 402,935 (three inclusion proofs fold to the served root, consistency from 251,620 verifies, four malformed requests get 400, the log signature verifies).
SM-005exact (2,701 epochs, median gap 4.0 h, longest 19.2 h; 37 of 70 weeks with a server entry).
SM-006exact (234,490 and 63,003 settlements; the same 15 and 5 wallets at about 80%). The per-payment value scan runs longer than ten minutes.
SM-007the probe holds (attestations present, no signature media type). The full census takes about 25 minutes and the signing sample depends on it.
SM-008exact (kernel 0 of 53, others 335 of 335, 1 of 105 by month, 5,024 kernel CVEs since the directive). The known-exploited pass takes about 15 minutes.
SM-009the CRL sample and the Firefox query tool build and run (1,320 CRLs parsed, 255,797 revocations in the window, example.com Good against 63 filters). The crt.sh lookups for 1,691 certificates take about an hour.
SM-010Reproduced from the public repository on 3 October 2026 on a clean machine, on a fresh sample: holds (0 of 688 files of 2 GiB or more scanned; 2,502 of 2,801 smaller files safe; 519 unscanned files behind a safe badge).
SM-011exact (mozilla.org NotCovered; Xenon2026h2 read to 12 June, 1.66 billion entries unread).
SM-012exact (119 statements, 11 late, 90th percentile day 92; Mozilla 0 of 172, Chrome 0 of 101, Apple 6 of 144, Microsoft 24 of 331).
SM-015the root and list results are exact (30 logs accept all 101 roots, four 380-day shards, 12 closed shards usable on Apple's list). The merge-delay measurement needs a publicly trusted certificate chain of your own.

The fixes that run surfaced (inputs read from the exhibits folder, binary paths, runtimes) are in the repository as of that day. The pass is repeated when the scripts change.

Our own mistakes

WhenWhat we got wrong, and what we did
3 OctWe re-read all fifteen papers against their own exhibits, one adversarial pass per page, before anyone else did. It found errors on twelve of them, corrected the same day and listed here so the record is complete. The ones that changed a finding: SM-001 undercounted the missing Pixel images on 15 September (54 of 1,091, not 33 of 1,070; the 21 we left out were September builds we had filed as lag). SM-012 credited Thailand’s auditor letter to all three of its late statements when it covers one, so seven statements have nothing on file, not five. SM-011 said every one of the 68 uncovered certificates sat behind the lagging logs; five were simply under a day old. SM-007 said 50 repositories were checked for signatures; 45 were, and only 37 of them carried both an SBOM and provenance. SM-015 counted 64 Chrome logs timed; 61 were, plus three of Cloudflare’s from Apple’s list, and 30 logs accept every Chrome root, not 31. SM-006 called August’s payments “manufactured” where the study says operator-internal, and said the payers changed completely when a quarter of them stayed. Smaller slips on SM-002, SM-003, SM-004, SM-005, SM-008, SM-009, SM-010 and the October review (a table number, a date, a page reference, a rounding) are corrected in place; every corrected page is re-stamped, and the old bytes stay in the log.
3 OctThe round-trip seal we sent Kaveh Ranjbar printed its log leaf as plain text, and the number was already stale; SM-004 named the standard as RFC 6962 in one place and RFC 9162 in another. He pointed out both within the hour. The seal now links the leaf and follows every re-stamp; the page names one standard. The same night we found two pages carrying a third paper’s description tag, copied from a template; fixed and re-stamped.
2 OctBefore SM-009 went up, four bugs in our own pipeline each produced a wrong count: crt.sh timestamps shifted six hours by the database session’s timezone, millisecond rounding on embedded timestamps, crt.sh’s own log submissions counted as the certificate’s, and base64 line-wrapping corrupting certificate files. Each was caught by cross-checking against Mozilla’s query tool; none was published. Listed here because the first count would have said 7.9% instead of 8.2%, and been wrong about which certificates.
20 SepOur own witness cosigned a size-0 checkpoint with a made-up root. Found while building our witness test suite; fixed the same day.
23 SepWe said Google’s Pixel log had no witness cosignatures. It does, through a separate distributor. Corrected in the public thread.
SepWe said a log called apertrue was unwitnessed. It was on a list we hadn’t checked. Corrected.
30 SepSM-001’s first log stamp didn’t match the page readers got, because Cloudflare rewrote an email link. Re-stamped against the public bytes.
1 OctOur x402 script printed five facts about August as fixed text, so a rerun on another day would have shown August’s numbers. Fixed to measure them; four of the five held.
2 OctThe first edition of our October review understated what a co-authorship paper did about its own sample. Corrected the same day; the page says so.
2 OctFour cells in the review’s first AIDev table were filled from memory, not from the papers. Checked against the papers and corrected before the authors were written to.

Superseded versions of every paper stay in our public log, so a corrected page can always be compared with what it said before.