Chris Chia's Blog - Posts Tagged "the-apex-code"

System Online: Welcome to the Blog

Hi — I'm Chris, and if you've found your way here, thank you. Genuinely.

The Apex Code has been out in the world since December, and every rating, review, and "want to read" add has meant more than you probably realize. Writing a first novel is a strange, solitary thing — you spend years with characters no one else has met yet, and then one day strangers start meeting them too. That's still the part I haven't gotten used to. This has literally been a boyhood ambition turned into a new skill I am learning decades later.

A little about what to expect here: I'll be posting weekly — useful, topical stuff rather than just promotional blah. That means real discussion of what's actually happening in the world of AI right now, and the hopes and fears that come with it; behind-the-scenes notes on the tech and research behind The Apex Code (some of it is uncomfortably close to real-world headlines lately); updates on The Axion Code (working title), the sequel currently in progress; and the occasional detour into whatever's caught my attention that week.

Before fiction, I spent years as a maritime navigator and later in the energy industry — which is a roundabout way of saying the technical world in The Apex Code isn't just imagined. A fair amount of it is drawn from things I've actually seen up close. I'll get into some of that here over time.

If you've read The Apex Code, I'd love to hear what you thought — the "Ask the Author" feature on my profile is open, and I try to answer everything. If you haven't yet, no pressure, but hello anyway.

Thanks for following along. More soon.

— Chris
 •  0 comments  •  flag
Share on Twitter
Published on July 19, 2026 08:20 Tags: introductions, the-apex-code, welcome

When Fiction Borrows From Real Headlines: The Hardware Backdoor Nobody Could Explain

Most of the technologies and events in The Apex Code are loosely based on real capabilities and real headlines — dramatized in places to help the story along, but rarely invented from nothing. I've come to call these details "Easter eggs": things a more discerning reader might recognize once they make the connection. One of the earliest and most central is a hardware backdoor — the idea of an unexplained chip buried on a motherboard, quietly doing something nobody outside its makers understood.

The real story behind the hardware backdoor:

In October 2018, Bloomberg Businessweek published "The Big Hack," an investigation claiming that Chinese state actors had covertly implanted tiny chips — some no bigger than a grain of rice — onto server motherboards built by Supermicro, a major US hardware supplier. The chips were allegedly discovered during a security audit by Amazon, and reportedly gave attackers a hardware backdoor into the servers by manipulating the Baseboard Management Controller: the component that controls a server remotely, below and before the operating system ever loads. In theory, that's an ideal hiding spot. The BMC has its own processor and its own memory, largely separate from the operating system it's meant to be managing, so it's invisible to normal security software because it operates before any of that software even starts running.
It's worth being straight about where this story actually stands. Apple, Amazon, and Supermicro all issued strong, repeated denials, an independent audit reportedly found nothing, and to this day no hard technical proof has been made public. It remains one of the most disputed stories in cybersecurity journalism — impossible to fully confirm, and impossible to fully dismiss.

Proof the concept is real, even if the allegation isn't:

What isn't disputed is that the underlying attack is genuinely buildable. In 2016, University of Michigan researchers — Kaiyuan Yang, Matthew Hicks, Todd Austin, Dennis Sylvester, and Qing Dong — built and demonstrated exactly this kind of hardware backdoor, nicknamed "A2," using a handful of analog components small enough to hide inside a single logic gate on a chip. It gave an attacker the ability to remotely seize full control of a machine, and by design, it was nearly invisible to every standard security check available at the time, including the kind of visual chip-level inspection that would normally catch an obviously foreign component. They built it specifically to prove the danger was real, not theoretical — a working demonstration, not a thought experiment, published openly for the research community to study.
That's the part that stuck with me. Somewhere between a disputed allegation nobody could fully prove and a peer-reviewed demonstration nobody could dismiss, there was a real gap: a vulnerability that was plausible, technically sound, and still largely unknown outside security research circles.

Where Riley picked up the thread:

That gap — a contested real-world allegation, backed by published academic proof that the underlying attack is genuinely achievable — is exactly where The Apex Code climbs in. Riley's breakthrough in the novel is realizing the attack doesn't need to touch the operating system at all. Insert a control-code layer between the BIOS and the boot sequence, and you're operating in the one place virtually nothing is watching — before the machine has even finished waking up. It's the same fundamental idea as the Supermicro allegation and the A2 research, just given a name, a face, and a reason to matter to the people in the story.

I didn't invent this hardware backdoor. I just gave it somewhere to live — and once you know it's there, it's a little harder to look at a server rack, or a boot screen, the same way again.

If this is the kind of detail you enjoy spotting, keep it in mind for The Axion Code — a new version of this particular Easter egg doesn't stay buried in one book.

- Chris
 •  0 comments  •  flag
Share on Twitter
Published on August 01, 2026 07:41 Tags: behind-the-scenes, cybersecurity, easter-eggs, techno-thriller, the-apex-code, the-axion-code

Computer Hacking 101

Many of the hacking techniques used in The Apex Code — including a healthy dose of social engineering — are taken from the real thing. As basic as some of them seem, and for as long as they've been around, they're still in use today, and getting hacked has never carried more personal risk than it does now. We're all carrying the equivalent of a hand-held computer everywhere we go, in our pockets and bags, and that phone holds everything a hacker would need to take over your identity, drain your accounts, or run up your credit cards. It's not just personal risk either — companies face it just as much, made worse by the fact that lists of stolen login credentials get bought and sold on the dark web every single day.

It's close to true today that anyone can get hacked, and there's very little real defense if someone determined enough wants into your bank account or your entire social media footprint.

This Happened to Us Last Week

A friend of ours appeared to be selling a truck on their social media account, on behalf of another friend whose husband had recently passed away. It looked like a decent deal — not a steal, not "too good to be true," just something reasonably priced that we might genuinely want. So we asked about it. The "friend" answered our questions, gave details, and then suggested we send a deposit to hold the truck until we could come see it in person a couple of days later. All perfectly reasonable, for someone we knew, with mutual friends all over our social feeds. We passed for other reasons, and said we'd call ahead once we had time to actually go look at it.

The whole thing was bogus. Our friend's account had been hacked, and whoever was behind it had been running the same play on multiple people — a truck, an ATV, a car, a boat, golf clubs, whatever story fit the account they'd taken over. Nobody in that chain of victims did anything careless. They just answered a message from someone they already trusted.

The Social Engineering Problem

This is what social engineering looks like when it's actually good at its job — professional enough, and insidious enough, that you genuinely can't take anything you see or hear online at face value anymore. Even voice replication means the person calling you might not be who you think, especially if it's been a while since you last heard from them.

In The Apex Code, I kept things to well-known, conventional hacking methods — all real, all with a long history, all still very much in use. A few examples:

Credential mining — mining someone's social media and online presence for personal details, then using that information to make smart, targeted guesses at their login credentials.

Password reuse — taking one cracked password and reusing it across multiple accounts, since most people reuse the same passwords or close variations of them everywhere.

Malicious software — spyware quietly injected onto a device that mines every unprotected password and login it can find.

Email and messaging — straightforward fake messages designed to get you to hand over your login details to someone pretending to be someone else, which is really just social engineering wearing a different hat.

The Bottom Line

Use an encrypted password vault. Use the strong, random passwords a good password generator gives you — often built right into that same vault app. And stop reusing family names, pet names, birthdays, and the usual combinations of them, over and over, across everything.

This isn't exhaustive advice. Think of it more as a nudge to run a few checks and refresh your own security every so often — before someone else finds the reason to do it for you.

— Chris
 •  0 comments  •  flag
Share on Twitter
Published on August 08, 2026 10:37 Tags: behind-the-scenes, cybersecurity, hacking, social-engineering, techno-thriller, the-apex-code