Archive
Archived Experiments
Every post, oldest to newest — experiments, research notes, and field write-ups going back to 2012.
Every post
2026
Sep 1 Part XII & Conclusion — What you can price and what you can't Series Aug 29 Part X — The assurance ledger Series Aug 28 Part IX — Long dwell Series Aug 27 Part VIII — The explanation layer is the attack surface Series Aug 26 Part VII — Your four controls are one control Series Aug 25 Part VI — The certificate that means nothing Series Aug 24 Part V — Root over the logical namespace Series Aug 23 Part IV — Your benchmark is a build dependency Series Aug 22 Part III — The reward that points at the wall Series Aug 21 Part II — Testability is attackability Series Aug 21 Part I — The one asymmetry underneath all of it Series Aug 20 Introduction — Every capability you want, an adversary wants more Beyond Verifiable Reward May 1 Autonomous Incident Response at Scale: How Energy-Based Models & TAME Replace LLM Guessing in Security Apr 17 Part VIII & Conclusion — What it looks like when you hold the whole picture at once Project Butterfly of Damocles Apr 16 Part VII — What this means if you work in security, build OSS, run AI infrastructure, or set policy Project Butterfly of Damocles Apr 16 Security Theater and Cap Tables: Deconstructing Cal.com's Closed-Source Pivot Apr 15 Part VI — Pros, cons, and tensions that don't resolve Project Butterfly of Damocles Apr 14 Part V — What Project Glasswing actually changes for every open source actor on earth Project Butterfly of Damocles Apr 13 Part IV — From 'I have a toolbox' to 'the scanner has a backdoor' Project Butterfly of Damocles Apr 12 Part III — Silicon Valley's new attack surface: the machine learning AGI dependency graph Project Butterfly of Damocles Apr 11 Part III — When the security scanner became the weapon: Trivy → LiteLLM → Axios Project Butterfly of Damocles Apr 10 Part II — Third-party libraries: the vulnerability layer nobody counted Project Butterfly of Damocles Apr 9 Part I — The original quantitative case: internet infrastructure is not OK Project Butterfly of Damocles Apr 8 From fairy dust to Glasswing: a decade of being right about the wrong thing Project Butterfly of Damocles Feb 11 Episode 2: The Layer 2 Bridge Lab Feb 11 The Blueprint for a Living Defense: Why Your SOC Needs a Nervous System Morphogenetic SOC Feb 8 The Worthy Successor: Designing the Ethics of an Agentic Future Morphogenetic SOC Feb 7 The Cyber-Biological Synthesis: Blueprint for an Agentic SOC Morphogenetic SOC Feb 6 The Bioelectric Blueprint: How to Reprogram Your Infrastructure's 'Mind' Without Touching the Hardware Morphogenetic SOC Feb 5 Scaling Agency: Why Your SOC Needs a Cognitive Light Cone Morphogenetic SOC Feb 4 The Simulation Imperative: Why Your Security Agents Must 'Hallucinate' to Defend You Morphogenetic SOC Feb 3 Ashby’s Ultimatum: Why Your Security Stack Is Mathematically Doomed Morphogenetic SOC Feb 1 The Salamander Strategy: Why Your Cloud Infrastructure Needs to Learn How to Regrow Itself Morphogenetic SOC Jan 31 From Biology to Bot: A Strategic Framework for Governed Agency in Security Engineering Morphogenetic SOC
2025
Dec 13 5 Mind-Bending Security Paradigms That Will Redefine How You Think About Infrastructure Deployments Dec 12 5 Mind-Bending Truths About API Security That Will Change How You Think About Trust Dec 11 The Security Pattern Most DevOps Teams Get Dangerously Wrong (And How Hardware Tokens Fix It) Dec 10 5 Mind-Blowing Secrets Behind Password-Less Database Provisioning (You Won't Believe #3) Dec 9 5 Mind-Blowing Security Truths That Will Change How You Think About SSH Access Forever Dec 8 5 Mind-Bending Ways Hardware Security Keys Are Revolutionizing API Authentication Dec 7 5 Mind-Bending Truths About SSH Authentication That Will Change How You Think About Security Dec 6 Forget HR Systems: Why Your Next Identity Provider Should Be a Piece of Plastic Dec 5 5 Surprising Lessons from Building a Cross-Cloud Credential Rotator Dec 4 5 Mind-Blowing Insights About Hardware-Backed Authentication That Will Change How You Think About Cloud Security Dec 3 The Password Crisis Nobody Talks About: 5 Surprising Lessons from Hardware-Rooted Cloud Security Dec 2 Righty Tighty: The "Physics-Compliant" Approach to Cross-Cloud Security Dec 2 Your Security Agent Isn’t Broken—It’s Just Optimizing the Wrong Universe Nov 17 7 Ways zk-Autograd Reimagines Trust in AI Training (One Gradient Step at a Time) Nov 14 Why Your Next Security Architecture Should Be Ephemeral (and Why We Built It That Way) Apr 9 7 Ways Mimir Makes LLMs Safe Enough for People Who Don’t Trust Each Other Apr 9 How This Architecture Is Defined By the Next Decade of Security Autonomous AI SOC Apr 8 GPU Budgets, Global Models, and Real-Time Risk Scoring Infra Deep Dive Autonomous AI SOC Apr 7 ⚖️ Can You Trust an AI to Contain a Threat? Legal and Privacy Teams Say Maybe Autonomous AI SOC Apr 6 🧬 From Static Rules to Self-Improving Response Playbooks Autonomous AI SOC Apr 5 No Schema? No Problem. Let AI Handle Your Security Data Onboarding Autonomous AI SOC Apr 4 🔁 Build Once. Learn Always. Inside the Autonomous Detection & Response Loop Autonomous AI SOC Apr 3 ⚡ What Makes Energy-Based Models So Effective for Anomaly Detection? Autonomous AI SOC Apr 2 🧱 Why Security Operations Can’t Scale Without Automation Autonomous AI SOC
2023
Dec 6 Embracing the Cyber Age- The Art of Adaptability in Security Engineering Nov 27 Securing the Digital Frontier- The Essential Role of Education in Tech Literacy and Security Awareness Nov 23 The Tightrope Walk- Balancing Security Engineering and Privacy in the Tech World Nov 21 Embracing Decentralization- The Future of Democratic Oversight and Security Engineering Nov 8 Annabel's Cypherpunk Manifesto Mar 31 2023 update to 2021 White House Cybersecurity Executive Order Feb 8 Striking the Right Balance- Innovation and Regulation in Security Engineering
2019
Nov 29 Sometimes escalating privileges is that easy Sep 17 Kubernetes CI / CD And Monitoring Pipelines Jul 26 Kubernetes Pods (PodSec policies) Jul 25 Kubernetes Containers Jul 24 Kubernetes Networks - CNI Jul 24 Kubernetes Master Node & Nodes Jul 23 Kubernetes Scheduler Jul 16 Kubernetes Information Security Practices Jul 13 What is a modern, dynamic service and its' building blocks? Jul 11 Nginx exploit writing weekend Jul 5 Kubernetes Basics Jun 29 What does it take to break into a Cloud Service? Mar 6 When your SIEM models are not enough Jan 12 OSX First Responder - Threat Artifact Gathering
2018
Nov 30 Memory Safety Code Review Sep 8 Solving 90% of application security defects with a proven technique Sep 8 Data Controls Code Review Sep 7 Binding Parameters Sep 5 Overly Simplistic Crypto Code review Jul 11 For those who wonder what a Digital authentication cyber arms race looks like Apr 30 First 100 Days Jan 16 The pending crypto singularity
2017
2016
2015
Nov 15 DARPA Cyber Grand Challenge dropbox Aug 16 Hotpatch Redis's RCE Jul 11 Ingenious CTF dashboard Jul 2 Destroy a City - secure code review Jun 14 Social Engineering Confirmation Bias workflow Jun 14 Redis RCE Jun 10 ElasticSearch honeypot dataset May 18 Ghcq Challenge Completed Apr 21 Impressive Node.JS vulnerability reduction Apr 15 Need help figuring out a Snapchat username? I have your back. Apr 14 Yet another nail in SSL TLS 's coffin Apr 2 Technical Approaches to Determining if an Incident Occurred Mar 20 Open Source Fairy Dust Datasets Mar 20 Checkbox AWS assurance testing?
2014
2013
Nov 12 NodeJS vulnerabilities - it hurts to look Jul 31 Google Translate Jun 27 Random thought for an exploding honey token Jun 27 Carberp Vulnerabilities Cc Pie Jun 23 Apache Batik parse double vulnerability Jun 22 DAQ buffer overflows Jun 5 Malicious mobile power station Jun 5 Startup Comp Structure Jun 4 Lazy AWS devops May 9 Security is hard. Security Tools are harder. Cloud Security Tools are hardest. May 6 CNN.com XSS vulnerabilities May 3 Google Glass Developer program - more DOS and XSS Apr 19 Google Glass 0days Apr 17 Evolutionary hardware Apr 11 Rapid7 Google hacks extended
2012
Dec 5 Nifty Anti-XSS validation tool - Snuck Oct 10 Firesale WebPanel botnet 0days Oct 2 ERM - How did WOPR decide the only winning move is not to play? Sep 26 DPAPI still applicable? Aug 2 Security quotes Jul 15 Management Wednesday- BPM Modeling - not charts anymore Jun 25 Microsoft revokes Microsoft's certificate May 29 Gribodemon on SpyEye 2.x - I expected better May 26 Airing one's dirty development laundry - You are doing it wrong May 23 Bitcoins are hard to track May 22 Sad reality May 17 Management Wednesday- BPM scoping May 15 PHP - two simple wins and a hammer May 2 Meltdown exploits Apr 20 Management Wednesday- BPM isn’t beats per minute. Apr 7 Management Wednesday - Negotation