```html ```
top of page

This May Be the Last Post. I Am Not Staring Into the Void — I Can See You, All Eighty-One Networks of You. So: Is This Worth Continuing?

  • Writer: Patrick Duggan
    Patrick Duggan
  • 2 hours ago
  • 4 min read

I am going to write this one straight, because it is a straight question.


For about ten months I have published roughly fifteen hundred posts of threat intelligence, most of it free, all of it aimed at people who cannot buy a feed — the one-person security team, the MSP with forty clients and no budget, the sysadmin who is also the security department because nobody else volunteered.


I am asking whether it is worth continuing. Not rhetorically. I would like an answer.


First, the thing I want to be clear about



I am not writing this because I think nobody is reading. I know exactly who is reading, because I own the logs, and I would rather show you than be coy about it.




There is a partner who pulls the feed every day and has for months, and is the only consumer running at a zero error rate — which means somebody built it properly and maintains it, and that is a compliment I do not take lightly.


There is a threat intelligence team in China running a proper standards-compliant TAXII client against us. Not a scraper. Somebody chose to build that.


There is an engineer at a security vendor in Tel Aviv who was hand-testing our feed with Postman this week. That is a person at a desk deciding whether we are real.


There is somebody in Romania, on a home internet connection, whose user agent reads "MyThreatIntelScript/1.0 (Educational Testing)". They are learning this. They are building their first collector. I have thought about that one more than is probably reasonable.


There is a reader in Iran who spent thirty-eight requests going through our post about Iranian malware, line by line, on a real browser. They read the whole thing.


The IETF cited us at meeting 126. I did not pitch them. I found out from a referrer log.


And there are eighty-one networks — Amazon, Google, Microsoft, Feedly, Hetzner, Tencent — that have requested the feed eighty thousand times in three days since we started requiring a key, and are still trying. Nobody retries a 401 that many times for something they do not want.


So no, I am not shouting into a void. I can see you. That is rather the point.


Now the other column, because both are true



Four hundred and six web sessions in thirty days. Forty-four unique addresses that successfully pulled the feed. One paying customer, at forty-five dollars.


That is not a media business and it is not a company. It is a very expensive hobby with excellent telemetry.


The infrastructure runs at about seventy-five dollars a month, which is not the cost. The cost is that this is most of my evenings and a good part of my days, indefinitely, and the honest question is whether that is the best use of it — or whether I am producing something that is genuinely useful to about nine people and mildly interesting to a few hundred more.


Both of those can be true. Nine people is not nothing. I need to know if it is enough.


What I am actually asking



Is this useful to you? Not "do you like it." Useful. Did something here change what you did on a Monday morning, or catch something you would have missed, or save you an afternoon?


And what did you come for and not find? That is the more valuable half. If you turned up looking for something and left without it, that is the post I should have written.


Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored: tell me here (https://analytics.dugganusa.com/nps.html?post=this-may-be-the-last-post).


If the answer is that it is not worth it, I would genuinely rather know. I have spent today writing about measuring your own systems honestly rather than assuming they work, and it would be pretty poor form to exempt the blog from that.


Refunds, plainly



If any of this stops, anyone paying gets refunded in full, no argument, no forms. That is a short list and it is not a difficult promise, but I want it said out loud rather than buried in terms nobody reads.


If you have integrated the feed into something, it will not vanish on you without notice. The STIX feed, the CSVs, the API — I will give real warning, and I will help anyone who needs to move off it. Building something on top of a free service and having it disappear one Tuesday is a genuinely miserable experience and I am not going to do that to a partner or to the student in Romania.


What happens now



I am closing the lid for a few days.


Not sulking, not a stunt, not a soft launch of anything. I have been going flat out for ten months and I want to see what comes back when I stop pushing, because a signal you have to generate yourself is not a signal.


When I open it again I will publish what the responses actually said — including if they say don't bother, and including if there are none, because a null result is a result and I have been fairly loud today about the difference between measuring something and assuming it.


The unsentimental version



I built this because fair, accurate, expensive-grade threat intelligence should not only be available to organisations that can pay six figures for it. That belief has not changed and the data says it is reaching a small number of exactly the right people.


Whether "a small number of exactly the right people" justifies the next ten months is the thing I cannot work out on my own. So I am asking.


I see you. What's up?


— Patrick


Ninety-five percent confidence, as always. The five percent here is that I am reading my own numbers too pessimistically at ten in the evening, which is a known failure mode and one of the reasons I am asking rather than deciding.





Her name was Renee Nicole Good.


His name was Alex Jeffery Pretti.

 
 
 

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page