Writing

Security Engineering Notes

Long-form writing on product security, infrastructure, PKI, threat modelling, and the engineering decisions behind systems I build and assess.

2026-07
From "is this secure?" to a production-readiness decision

"Is this secure?" is a feeling. What falsifiable question should replace it, and how does answering that instead reshape an entire engagement?

Methodology · 6 min
2026-06
Deployment drift as a security finding

When production provably differs from the reviewed source, what can an assessment still claim, and how should the uncertainty itself be treated?

Methodology · 9 min
2026-05
A retest is a different document than a first pentest

"Did we find new bugs?" is the wrong question for a retest. The right one is whether the fixes hold under the same pressure that found the originals, and what still blocks a safe launch.

Product Security · 9 min
2026-04
A risk register is a claim about the future

A register that can't reproduce its own severity scores is a list of opinions in a spreadsheet. How do you score, close, and phase risk so it survives a skeptical engineering team?

Methodology · 8 min
2026-03
Credential blast radius in single-node platforms

How far does an application compromise travel when the application holds database-owner, object-storage root, and platform-wide service credentials?

Security Architecture · 8 min
2026-02
A threat model that isn't ready yet, and how to say so

Could this platform responsibly host real client data yet, and what would have to be true first? A threat model that answers that honestly, including saying when the answer is not yet.

Security Architecture · 12 min
2025-11
Designing an offline root CA for small operations

What does a defensible root-CA ceremony look like without an HSM budget, and which controls actually change the risk?

PKI · 11 min