Writing
Security Engineering Notes
Long-form writing on product security, infrastructure, PKI, threat modelling, and the engineering decisions behind systems I build and assess.
"Is this secure?" is a feeling. What falsifiable question should replace it, and how does answering that instead reshape an entire engagement?
When production provably differs from the reviewed source, what can an assessment still claim, and how should the uncertainty itself be treated?
"Did we find new bugs?" is the wrong question for a retest. The right one is whether the fixes hold under the same pressure that found the originals, and what still blocks a safe launch.
A register that can't reproduce its own severity scores is a list of opinions in a spreadsheet. How do you score, close, and phase risk so it survives a skeptical engineering team?
How far does an application compromise travel when the application holds database-owner, object-storage root, and platform-wide service credentials?
Could this platform responsibly host real client data yet, and what would have to be true first? A threat model that answers that honestly, including saying when the answer is not yet.
What does a defensible root-CA ceremony look like without an HSM budget, and which controls actually change the risk?