February 2025
- Incident Response Done Right: A CA’s Guide to Resilience
Imagine yourself as a pilot at 30,000 feet when an engine begins to sputter. You don't panic—your training activates, you follow your checklist, and take control. For Certificate Authorities (CAs), incidents like…
- How Organizational Inertia Externalizes Risk in the WebPKI
I’ve been involved in the Web PKI since the mid-‘90s, when SSL certificates carried five- or ten-year lifetimes—long-lasting credentials for an internet still a wild west. Issuance was manual, threats were sparse, and…
- From Perimeter to Patterns: Envisioning Security a Decade from Now
I’ve been mulling over what security might look like ten years from now, especially as AI-based workloads and robotics take on bigger roles. Growing up, I’d hear my father talk about his work on communication satellites,…
- The Fallacy of Alignment: Why AI Safety Needs Structure, Not Hope
My grandfather’s love of science fiction was his portal to tomorrow’s world—and it became mine. Together we’d pore over books like Asimov’s I, Robot, imagining futures shaped by machines. In the 1940s, when Asimov…
- Educating the Champion, the Buyer, and the Market
Security used to be something we tried to bolt on to inherently insecure systems. In the 1990s, many believed that if we simply patched enough holes and set up enough firewalls, we could protect almost anything. Today,…
- The Account Recovery Problem and How Government Standards Might Actually Fix It
Account recovery is where authentication systems go to die. We build sophisticated authentication using FIDO2, WebAuthn, and passkeys, then use "click this email link to reset" when something goes wrong. Or if we are an…
- From the Morris Worm to Modern Agentic AI Threats
The year was 1988, and at age 13, I found myself glued to news and IRC channels buzzing with news of the Morris Worm. As reports poured in about thousands of computers grinding to a halt, I was captivated by how one…
- From Plato to AI: Why Understanding Matters More Than Information
Reading was a big deal when I was a kid, but it was also a challenge. I’m dyslexic, dysgraphic, and dysnumeric, which made traditional learning methods difficult—but that’s largely another story. My parents—determined,…
- Key Management: A Meme Retrospective
We all need a little laugh from time to time, especially when things get unexpectedly crazy. Well, yesterday was one of those days for me, so I decided to do a retrospective on what we call key management. I hope you…
- The Identity Paradox: If It’s an Identity, Why Is It in a Secret Manager?
Enterprises love to talk about identity-first security—until it comes to machines. Human users have IAM systems, SSO, MFA, and governance. But workloads? Their so-called identities are often just API keys and…
- AI Agent Security Needs Accountability and Control
This weekend I came across a LinkedIn article by Priscilla Russo about OpenAI agents and digital wallets. It connected with a problem I have been thinking about for some time. Who is liable when an AI agent changes a…
- How Washington State is Preparing to Undermine Parents and the Constitution
I am not a lawyer, but I love the law. I love the law because it increases the chances of predictable outcomes, aiming to provide a stable framework that protects our rights and creates a level playing field for all. The…