2025
- The Impossible Equation
From the Eurodollar to the Splinternet: How the Race to Regulate the World Broke It
- Attestation, What It Really Proves and Why Everyone Is About to Care
Attestation has become one of the most important yet misunderstood concepts in modern security. It now shows up in hardware tokens, mobile devices, cloud HSMs, TPMs, confidential computing platforms, and operating…
- The Vanishing On-Ramp
This past week I spent more concentrated time with the newest generation of AI models than I have in months. What struck me was not just that they are better, but where they are better. They now handle routine…
- Beyond Gutenberg: How AI Is Teaching Us to Think About Thinking
At breakfast the other day, I was thinking about those old analogy questions: "Hot is to cold as light is to \\\?" My kids would roll their eyes. They feel like relics from standardized tests.
- Compliance at the Speed of Code
Compliance is a vital sign of organizational health. When it trends the wrong way, it signals deeper problems: processes that can't be reproduced, controls that exist only on paper, drift accumulating quietly until trust…
- Gradually, Then Suddenly: Compliance as a Vital Sign of Organizational Decay
"How did you go bankrupt?" a character asks in Hemingway's The Sun Also Rises. "Two ways," comes the reply. "Gradually, then suddenly."
- Beyond the Mathematics, Deploying Advanced Crypto Successfully
Advanced cryptographic systems like Multi-Party Computation (MPC) promise elegant solutions to complex security problems. Cryptography is essential. Every modern system already relies on it through authentication…
- Another Sleeping Giant: Microsoft’s Root Program and the 1.1.1.1 Certificate Slip
This morning (September 3, 2025), someone posted an incident to the Mozilla dev-security-policy list that exposed a serious incident: “Incident Report: Mis-issued Certificates for SAN iPAddress: 1.1.1.1 by Fina RDC…
- How Microsoft Code Signing Became Part of a Trust Subversion Toolchain
Code signing was supposed to tell you who published a piece of software and ultimately decide if you can trust the software and install it.. For nearly three decades, cryptographic signatures have bound a binary to a…
- From Persistent to Ephemeral: Why AI Agents Need Fresh Identity for Every Mission
My wife and I went on a date night the other day and saw a movie, in the previews, I saw they're making a new Tron. It got me thinking about one of my favorite analogies, we recognized early that browsers are agents of…
- Talent Isn't a Security Strategy
One of the best parts of Black Hat is the hallway track. Catching up with friends you've known for years, swapping war stories, and pointing each other toward the talks worth seeing. This year I met up with a friend who,…
- History Doesn't Repeat, But It Rhymes: The AI Panic Edition
When my parents were young, the message was simple. Do not have too many kids. By the 1980s, they were told, the world would be out of food. The oceans would be empty, the fields barren, and billions would starve.
- When Automation Becomes Bureaucracy
My wife is from Belarus. On one of my first visits there, I had my first real exposure to what extreme bureaucracy looked like.
- How a $135 Billion Fraud Bootstrapped America's Digital Identity System
I was doing some work on readying a launch for our integration with mDL authentication into one of our products when I realized I finally had to deal with the patchwork of state support. California? Full program,…
- The AI Paradox: Why Building Software is Both Easier and Riskier Than Ever
I've been building with computer vision and ML since before it was cool, and I use these tools daily. When my middle child announced they were majoring in computer engineering, I didn't panic about automation taking…
- Lawyers Think Like Security Engineers. AI Treats Them Like Secretaries
Part of the "AI Skill Liquidity" series
- How Let's Encrypt Changed Everything
I advised Let's Encrypt from its early days, watching it transform the security foundation of the web. Most think it won by offering free certificates. That's dead wrong.
- WebPKI Market Analysis: Mozilla Telemetry vs Certificate Transparency Data
In the past, I've written about how to measure the WebPKI, and from time to time I post brief updates on how the market is evolving.
- Conway's Law Is Dying
I've been thinking about Conway's Law, the idea that organizations "ship their org chart." The seams are most visible in big tech. Google, for example, once offered nearly a dozen messaging apps instead of a single…
- What Does CPA Canada Have to Do With the WebPKI Anyway?
When we discuss the WebPKI, we naturally focus on Certificate Authorities (CAs), browser root programs, and the standards established by the CA/Browser Forum. Yet for these standards to carry real weight, they must be…
- The WebPKI's Moral Hazard Problem: When Those Who Decide Don't Pay the Price
TL;DR: Root programs, facing user loss, prioritize safety, while major CAs, with browsers, shape WebPKI rules. Most CAs, risking distrust or customers, seek leniency, shifting risks to billions of voiceless relying…
- From Mandate to Maybe: The Quiet Unwinding of Federal Cybersecurity Policy
Why the 2025 Amendments to EO 14144 Walked Back Progress on PQC, SBOMs, and Enforcement, Even as the Products to Support Them Have Become Real.
- Why CP and CPSs Matter More Than You Think
I've been in the PKI space for a long time, and I'll be honest, digging through Certificate Policies (CPs) and Certification Practice Statements (CPSs) is far from my favorite task. But as tedious as they can be, these…
- Déjà Vu in the WebPKI
This morning, the Chrome Root Program dropped another announcement about Certificate Authority (CA) performance. Starting with Chrome 139, new TLS server certificates from specific Chunghwa Telecom \[TAIWAN\] and NetLock…
- Necessity is the Mother of Invention: Why Constraints Invite Innovation
Limitations often spark the most creative solutions in technology. Whether it's budget constraints, legal hurdles, or hardware restrictions, these boundaries don't just challenge innovation, they fuel it.
- Rethinking Compliance: AI, Skill Liquidity, and the Quest for Verifiable Truth
In an earlier piece, 'The Limitations of Audits,' we explored how traditional compliance frameworks often fall short, functioning as point-in-time assessments rather than drivers of continuous security practices.…
- When AI Injects Liquidity Into Skills: What Happens to the Middle Tier?
In financial markets, liquidity changes everything. Once-illiquid assets become tradable. New players flood in. Old hierarchies collapse. Value flows faster and differently.
- The Rise of the Accidental Insider and the AI Attacker
The cybersecurity world often operates in stark binaries, "secure" versus "vulnerable," "trusted" versus "untrusted." We've built entire security paradigms around these crisp distinctions. But what happens when the most…
- Agents, Not Browsers: Keeping Time with the Future
When the web first flickered to life in the mid-'90s, nobody could predict how quickly "click a link, buy a book" would feel ordinary. A decade later, the iPhone landed and almost overnight, thumb-sized apps replaced…
- Agents, Not Browsers: The Next Chapter of the Internet
Imagine how you interact with digital services today: open a browser, navigate menus, fill forms, manually connect the dots between services. It's remarkable how little this has changed since the 1990s. Despite this…
- Crypto agility isn’t a checkbox—it’s an operational mindset.
In the early 2000s, I was responsible for a number of core security technologies in Windows, including cryptography. As part of that role, we had an organizational push to support “vanity” national algorithms in SChannel…
- How ‘Sneakers’ Predicted Our Quantum Computing Future
I was 16 when I first watched Sneakers on a VHS tape rented from my local video store. Between the popcorn and plot twists, I couldn’t have known that this heist caper would one day seem less like Hollywood fantasy and…
- The Strategic Reality of Enterprise Deployment Options
Offering customers deployment flexibility from managed SaaS to complex on-premise installations often feels like essential table stakes in enterprise software. Vendors list options, sales teams confirm availability, and…
- Strategic Product End-of-Life Decisions
When a product reaches the end of its lifecycle, companies typically create simple tables mapping products to migration paths, target dates, and release milestones. While operationally necessary, these tables often fail…
- Decision-making as a Product Manager
We cannot do everything; the French have a saying, "To choose something is to renounce something." This also holds true for Product Managers. How we choose is important, especially in a startup where resources are…
- Cloud's Accelerated Evolution: Lessons from Telecom's Century of Change
What took the telecommunications industry a century to experience—the full evolution from groundbreaking innovation to commoditized utility status—cloud computing is witnessing in just 15 years. This unprecedented…
- Understanding Enterprise Security Buyer Dynamics
When selling security solutions to enterprises, understanding who makes purchasing decisions is critical to success. Too often, security vendors aim their messaging at the wrong audience or fail to recognize how budget…
- TPMs, TEEs, and Everything In Between: What You Actually Need to Know
Ever been in a meeting where someone drops terms like "TEE," "TPM," or "FIPS-certified" and everyone nods along, pretending they understand? Yeah, me too.
- Operational Evolution Revisited: How AI-Native Systems Will Revolutionize Infrastructure
The evolution of technology operations has always been driven by necessity. From the early days of single system operators (sysops) managing physical servers through hands-on intervention, to today's complex landscape of…
- Incident Response Done Right: A CA’s Guide to Resilience
Imagine yourself as a pilot at 30,000 feet when an engine begins to sputter. You don't panic—your training activates, you follow your checklist, and take control. For Certificate Authorities (CAs), incidents like…
- How Organizational Inertia Externalizes Risk in the WebPKI
I’ve been involved in the Web PKI since the mid-‘90s, when SSL certificates carried five- or ten-year lifetimes—long-lasting credentials for an internet still a wild west. Issuance was manual, threats were sparse, and…
- From Perimeter to Patterns: Envisioning Security a Decade from Now
I’ve been mulling over what security might look like ten years from now, especially as AI-based workloads and robotics take on bigger roles. Growing up, I’d hear my father talk about his work on communication satellites,…
- The Fallacy of Alignment: Why AI Safety Needs Structure, Not Hope
My grandfather’s love of science fiction was his portal to tomorrow’s world—and it became mine. Together we’d pore over books like Asimov’s I, Robot, imagining futures shaped by machines. In the 1940s, when Asimov…
- Educating the Champion, the Buyer, and the Market
Security used to be something we tried to bolt on to inherently insecure systems. In the 1990s, many believed that if we simply patched enough holes and set up enough firewalls, we could protect almost anything. Today,…
- The Account Recovery Problem and How Government Standards Might Actually Fix It
Account recovery is where authentication systems go to die. We build sophisticated authentication using FIDO2, WebAuthn, and passkeys, then use "click this email link to reset" when something goes wrong. Or if we are an…
- From the Morris Worm to Modern Agentic AI Threats
The year was 1988, and at age 13, I found myself glued to news and IRC channels buzzing with news of the Morris Worm. As reports poured in about thousands of computers grinding to a halt, I was captivated by how one…
- From Plato to AI: Why Understanding Matters More Than Information
Reading was a big deal when I was a kid, but it was also a challenge. I’m dyslexic, dysgraphic, and dysnumeric, which made traditional learning methods difficult—but that’s largely another story. My parents—determined,…
- Key Management: A Meme Retrospective
We all need a little laugh from time to time, especially when things get unexpectedly crazy. Well, yesterday was one of those days for me, so I decided to do a retrospective on what we call key management. I hope you…
- The Identity Paradox: If It’s an Identity, Why Is It in a Secret Manager?
Enterprises love to talk about identity-first security—until it comes to machines. Human users have IAM systems, SSO, MFA, and governance. But workloads? Their so-called identities are often just API keys and…
- AI Agent Security Needs Accountability and Control
This weekend I came across a LinkedIn article by Priscilla Russo about OpenAI agents and digital wallets. It connected with a problem I have been thinking about for some time. Who is liable when an AI agent changes a…
- How Washington State is Preparing to Undermine Parents and the Constitution
I am not a lawyer, but I love the law. I love the law because it increases the chances of predictable outcomes, aiming to provide a stable framework that protects our rights and creates a level playing field for all. The…
- Why It’s Time to Rethink Machine and Workload Identity: Lessons from User Security
MFA slashed credential-based attacks. Passwordless authentication made phishing harder than ever. These breakthroughs transformed user security—so why are machines and workloads still stuck with static secrets and…
- What Makes a QR Code Verifiable?
QR codes are everywhere—tickets, ID cards, product packaging, menus, and even Wi-Fi setups. They’ve become a cornerstone of convenience, and most of us scan them without hesitation. But here’s the thing: most QR codes…
- How AI Can Transform Our Broken Healthcare System
Healthcare becomes deeply personal when the system’s fragmentation leads to life-altering outcomes. During COVID-19, my father’s doctor made what seemed like a prudent choice: postpone treatment for fluid retention to…
- The Laws of Stupidity and the Gaps in Your Security Posture
Carlo M. Cipolla, in his essay The Basic Laws of Human Stupidity, laid out a set of principles that are both hilarious and uncomfortably accurate when applied to everyday life. If you've ever watched a perfectly…