Commons

Work made public so other people can inspect it, use it, alter it, and carry it further.

Some of these resources began as answers to practical problems. Others are working methods, public-interest research, or small tools that seemed worth making.

They are here because useful work should not always require permission to travel.

Unless noted otherwise, everything is licensed under CC BY 4.0. Use it. Change it. Teach with it. Build on it. Give credit. Commercial use is welcome.

Materials are provided as-is. Nothing here is legal advice. Different licences and draft conditions are stated beside the relevant work.

Current work

The 2036–2038 timestamp rollovers

Three widely used ways of representing computer time reach their limits within less than three years of one another.

The Network Time Protocol era rolls over in February 2036. Signed 32-bit Unix time reaches its limit in January 2038. The next GPS week-number rollover follows in November 2038.

The individual technical failures are known. The harder problem is coordination. Affected systems are distributed across software, devices, suppliers, operators, sectors, countries, and long-lived infrastructure. No single institution can see or repair the whole.

XSTP.epoch is an ITU-T Technical Paper making the case for a coordinated international response. It surveys exposure across thirty sectors and sets out the work required across suppliers, operators, regulators, governments, and standards bodies.

Read the public background and current status →

Status: Revision 1 was agreed by ITU-T Study Group 17 in June 2026 and transmitted to the ITU Telecommunication Standardization Bureau for publication. Earlier drafts circulated under the identifier XSTR.epoch.

The linked background is cleared for unrestricted sharing (TLP:CLEAR). Circulated drafts remain limited to the communities in which they were shared (TLP:GREEN) until publication. Substantive review is welcome before Revision 2, planned for December 2026.

Things you can use

These are finished enough to pick up, adapt, teach with, or try.

The Hippocratic Oath of the Cybersecurity Practitioner

Cybersecurity work is full of decisions made under uncertainty, with consequences that may outlast the engagement, the system, or the people who made them.

The oath is a compact statement of duties concerning honesty, restraint, uncertainty, stewardship, and the obligation to avoid causing harm while trying to prevent it.

It is offered as a tool for reflection, discussion, teaching, or adoption—not as a badge of moral standing.

Read or adapt the oath →

The Friend Protocol

Difficult conversations often begin to fail before anyone can agree on what is going wrong.

The Friend Protocol is a small set of principles that friends or collaborators can adopt before the conversation becomes difficult. It gives everyone a shared place to return to without requiring one person to diagnose the room correctly in real time.

Its annexes address conditions such as unequal status, limited capacity, time pressure, identity, conflict, and difficult seasons that are larger than any single day.

Read, adapt, or adopt the protocol →

Companion pieces: When Minds Become the Problem and The Cafe Between Watches .

Knights Chess

What does responsible action look like when the ordinary rules have stopped describing the situation?

Knights Chess is a playable thought experiment. Both kings begin in check, the board violates normal chess geometry, and the usual rules return in full after the first capture.

It gives a group a concrete way to discuss decisions made under unstable conditions before the conversation disappears into abstractions about crisis, uncertainty, or polycrisis.

The exercise was first used at ITU-T Study Group 17 in December 2025.

Read the rules →

2038-Class Risk Exposure Matrix

Organisations often know that a risk matters without having a shared way to ask where it can travel, what depends on it, or who would need to act.

The matrix is an open framework for examining exposure across systems, suppliers, operations, governance, and infrastructure. It was developed for timestamp risk, but the method can be adapted to other distributed technical problems.

The accompanying workshop kit is designed so teams can run the exercise themselves.

Explore the matrix and workshop kit →

A thirty-minute executive briefing, with slides and a facilitation plan, is in development. Experienced government and corporate facilitators interested in testing it can get in touch.

proper-css

This site does not use a frontend framework or build system. Its visual foundation is a single static stylesheet.

proper-css publishes that foundation: Fibonacci spacing, a golden-ratio type scale, typography defaults, brand colours, and a small set of reusable components. There are no dependencies and no build step.

The name means “the CSS used by Proper Tools,” not “the correct way to write CSS.” It is one opinion among many.

View proper-css on GitHub →

MIT licensed.

Things you can help build

These are working drafts. Their incompleteness is part of the invitation.

The Meridian Protocol

Websites disappear. When they do, their URLs, authorship, links, and surrounding context often disappear with them.

Meridian is a proposed Internet protocol through which an author can authorise preservation in advance. Approved mirrors could keep a site available at its original URLs, with cryptographic evidence that the preservation was permitted.

The aim is prospective preservation rather than rescue after the fact: decide who may carry the work before the original site goes dark.

Read the draft on GitHub →

Early draft. Co-authors, implementers, archivists, and mirror operators are welcome. Get in touch with the part of the problem you are interested in.

Proof-sketches seeking collaborators

Two working arguments are circulating for criticism and development.

One concerns the undecidability of instruction boundaries. The other concerns the modelling limits of systems that must describe themselves using the same machinery they are trying to model.

They are upstream of the citable bar set by the rest of the Commons. That status is stated plainly so that the uncertainty travels with the work.

Read the proof-sketches and open questions →

Drafts, not results. Co-authors, critics, and reviewers welcome.

What belongs here

These resources do different jobs. The common principle is that a useful structure should be inspectable, contestable, and available to the people expected to rely on it.

Some are finished enough to use. Some are invitations to continue the work. Their status is stated beside them because uncertainty should travel with the thing itself.

Questions, corrections, adaptations, and reports from use are welcome. Tell me what you tried, what changed, and what broke.

Contact Proper Tools →