Insights

Security intelligence archive

Deep technical analysis, threat research, and applied security engineering — from DEF CON 22 to the frontier of autonomous defense.

148
Posts published
3
Deep-dive series
39
Series episodes
14+
Years publishing
Security

Part XII & Conclusion — What you can price and what you can't

Four of this season's tensions are not trade-offs. In each, the beneficial property and the security exposure are one property under two descriptions. You cannot engineer those away. You can only know, for each increm...

September 1, 2026

Deep-dive series

Recent writing

Jump to archive ↓
Security

Part X — The assurance ledger

The practical security of a cryptographic primitive is not a theorem. It is a function of accumulated public expert-years of failed cryptanalysis. That makes it a quantity — and unlike a theorem, a...

August 29, 2026 · 9-minute read
Security

Part IX — Long dwell

Your organization can correlate cause and effect over some interval. Past that interval, log rotation, platform migration, and staff turnover destroy the forensic state — and your own operational h...

August 28, 2026 · 8-minute read
Security

Part VIII — The explanation layer is the attack surface

Human oversight depends on a reviewer knowing when they do not understand. Fluent explanation produces the feeling of understanding. That control can be disabled silently, and the failure leaves a ...

August 27, 2026 · 9-minute read
Security

Part VII — Your four controls are one control

Nuclear safety engineering has been quantifying common-cause failure since the 1970s. If your classifier, judge, monitor and reviewer share a base model, that literature already has a number for wh...

August 26, 2026 · 9-minute read
Security

Part VI — The certificate that means nothing

Verification transfers residual risk onto the least-defended artifact in the pipeline: the specification. Hardware verification has had detection for the classic failure mode since the late ninetie...

August 25, 2026 · 8-minute read
Security

Part V — Root over the logical namespace

An optimizer rewarded on theorem yield has a strategy that makes every subsequent theorem provable, passes every kernel check, and presents as a spectacular productivity improvement. Consistency is...

August 24, 2026 · 8-minute read
Security

Part IV — Your benchmark is a build dependency

Under verifiable-reward training the evaluation artifact and the training environment are the same object. That makes a benchmark a build dependency — and the artifacts that shape model behaviour h...

August 23, 2026 · 8-minute read
Security

Part III — The reward that points at the wall

Reward faster solutions. Penalize memory use. Both are standard, both are reasonable, and both create a gradient that points at the isolation boundary. Escape-adjacency is a static property of a re...

August 22, 2026 · 9-minute read

Full archive

148 posts
2026
Sep 1 Part XII & Conclusion — What you can price and what you can't Series Aug 29 Part X — The assurance ledger Series Aug 28 Part IX — Long dwell Series Aug 27 Part VIII — The explanation layer is the attack surface Series Aug 26 Part VII — Your four controls are one control Series Aug 25 Part VI — The certificate that means nothing Series Aug 24 Part V — Root over the logical namespace Series Aug 23 Part IV — Your benchmark is a build dependency Series Aug 22 Part III — The reward that points at the wall Series Aug 21 Part II — Testability is attackability Series Aug 21 Part I — The one asymmetry underneath all of it Series Aug 20 Introduction — Every capability you want, an adversary wants more Beyond Verifiable Reward May 1 Autonomous Incident Response at Scale: How Energy-Based Models & TAME Replace LLM Guessing in Security Apr 17 Part VIII & Conclusion — What it looks like when you hold the whole picture at once Project Butterfly of Damocles Apr 16 Part VII — What this means if you work in security, build OSS, run AI infrastructure, or set policy Project Butterfly of Damocles Apr 16 Security Theater and Cap Tables: Deconstructing Cal.com's Closed-Source Pivot Apr 15 Part VI — Pros, cons, and tensions that don't resolve Project Butterfly of Damocles Apr 14 Part V — What Project Glasswing actually changes for every open source actor on earth Project Butterfly of Damocles Apr 13 Part IV — From 'I have a toolbox' to 'the scanner has a backdoor' Project Butterfly of Damocles Apr 12 Part III — Silicon Valley's new attack surface: the machine learning AGI dependency graph Project Butterfly of Damocles Apr 11 Part III — When the security scanner became the weapon: Trivy → LiteLLM → Axios Project Butterfly of Damocles Apr 10 Part II — Third-party libraries: the vulnerability layer nobody counted Project Butterfly of Damocles Apr 9 Part I — The original quantitative case: internet infrastructure is not OK Project Butterfly of Damocles Apr 8 From fairy dust to Glasswing: a decade of being right about the wrong thing Project Butterfly of Damocles Feb 11 Episode 2: The Layer 2 Bridge Lab Feb 11 The Blueprint for a Living Defense: Why Your SOC Needs a Nervous System Morphogenetic SOC Feb 8 The Worthy Successor: Designing the Ethics of an Agentic Future Morphogenetic SOC Feb 7 The Cyber-Biological Synthesis: Blueprint for an Agentic SOC Morphogenetic SOC Feb 6 The Bioelectric Blueprint: How to Reprogram Your Infrastructure's 'Mind' Without Touching the Hardware Morphogenetic SOC Feb 5 Scaling Agency: Why Your SOC Needs a Cognitive Light Cone Morphogenetic SOC Feb 4 The Simulation Imperative: Why Your Security Agents Must 'Hallucinate' to Defend You Morphogenetic SOC Feb 3 Ashby’s Ultimatum: Why Your Security Stack Is Mathematically Doomed Morphogenetic SOC Feb 1 The Salamander Strategy: Why Your Cloud Infrastructure Needs to Learn How to Regrow Itself Morphogenetic SOC Jan 31 From Biology to Bot: A Strategic Framework for Governed Agency in Security Engineering Morphogenetic SOC
2025
Dec 13 5 Mind-Bending Security Paradigms That Will Redefine How You Think About Infrastructure Deployments Dec 12 5 Mind-Bending Truths About API Security That Will Change How You Think About Trust Dec 11 The Security Pattern Most DevOps Teams Get Dangerously Wrong (And How Hardware Tokens Fix It) Dec 10 5 Mind-Blowing Secrets Behind Password-Less Database Provisioning (You Won't Believe #3) Dec 9 5 Mind-Blowing Security Truths That Will Change How You Think About SSH Access Forever Dec 8 5 Mind-Bending Ways Hardware Security Keys Are Revolutionizing API Authentication Dec 7 5 Mind-Bending Truths About SSH Authentication That Will Change How You Think About Security Dec 6 Forget HR Systems: Why Your Next Identity Provider Should Be a Piece of Plastic Dec 5 5 Surprising Lessons from Building a Cross-Cloud Credential Rotator Dec 4 5 Mind-Blowing Insights About Hardware-Backed Authentication That Will Change How You Think About Cloud Security Dec 3 The Password Crisis Nobody Talks About: 5 Surprising Lessons from Hardware-Rooted Cloud Security Dec 2 Righty Tighty: The "Physics-Compliant" Approach to Cross-Cloud Security Dec 2 Your Security Agent Isn’t Broken—It’s Just Optimizing the Wrong Universe Nov 17 7 Ways zk-Autograd Reimagines Trust in AI Training (One Gradient Step at a Time) Nov 14 Why Your Next Security Architecture Should Be Ephemeral (and Why We Built It That Way) Apr 9 7 Ways Mimir Makes LLMs Safe Enough for People Who Don’t Trust Each Other Apr 9 How This Architecture Is Defined By the Next Decade of Security Autonomous AI SOC Apr 8 GPU Budgets, Global Models, and Real-Time Risk Scoring Infra Deep Dive Autonomous AI SOC Apr 7 ⚖️ Can You Trust an AI to Contain a Threat? Legal and Privacy Teams Say Maybe Autonomous AI SOC Apr 6 🧬 From Static Rules to Self-Improving Response Playbooks Autonomous AI SOC Apr 5 No Schema? No Problem. Let AI Handle Your Security Data Onboarding Autonomous AI SOC Apr 4 🔁 Build Once. Learn Always. Inside the Autonomous Detection & Response Loop Autonomous AI SOC Apr 3 ⚡ What Makes Energy-Based Models So Effective for Anomaly Detection? Autonomous AI SOC Apr 2 🧱 Why Security Operations Can’t Scale Without Automation Autonomous AI SOC