2026
- Rejection Is Not a Verdict
Life offers an almost unlimited supply of chances to be rejected, and it is easy to take each one personally.
- The Amnesia Cycle and Why AI Is Turning Developers Back Into Testers
I started working in technology around 1993. One of my first jobs was in quality assurance, partly because there was no security profession to join yet.
- Hurst University
For as long as my children can remember, I have told them that they are students at Hurst University.
- From Periodic Audit to Continuous Assurance
I have been writing about the limitations of audits and compliance systems for several years.
- From Chains to Trees
The WebPKI has two structures that are not the same shape.
- The Status Quo Outlived Its Status
In security we like to say that the problems live in the gaps between systems. Each system, on its own, is usually coherent. It has a threat model, invariants, and someone who owns it. The seam between two systems is…
- Why FIPS 140 Means Running Old Code
You need to use FIPS 140 because of compliance, but have you ever asked what that requirement is actually for? What security properties are the authors of these policies trying to achieve?
- The Certification Ends Where the Code Begins
Disclosure: I am an advisor to Binarly.
- Steve Jobs, AI, and the Problem of Analysis Without Ownership
There is an old Steve Jobs clip from a 1992 MIT Sloan talk that feels newly relevant in the age of AI. In the talk, available here as Steve Jobs MIT 1992 Lecture, Jobs is asked about consultants. His answer is not that…
- The Breaker, the Priest, and the Philosopher
Spend enough years in security and you notice that the people whose judgment you actually trust are rarely the ones with the cleanest credentials.
- The Prompt Is an Argument
If you accept that, the next question is unavoidable. What kind of record should a good prompt be?
- The Prompt Is the Meaning
Why textualism, original public meaning, and AI governance all turn on the same uncomfortable fact: intent does not travel unless it becomes part of the record.
- A CA That Produces Evidence, Not Promises
In my last post I argued that high-assurance systems should stop asking to be trusted on the basis of institutional promises and start producing verifiable runtime evidence about what actually happened. This post is the…
- A CA Built for the Threat Model We Actually Have
This builds on earlier posts on what attestation actually proves, what confidential computing is and isn't, and an honest accounting of the problems with the current generation of TEEs. None of those problems go away…
- The First AI-Built Zero-Day Is Not the Interesting Part
In the mid 90s I worked at a company called Cybersafe. Today it would get labeled an IAM/SSO vendor. What we actually built was a first-generation security platform: Kerberos, password management, PKI-based MFA, key…
- AI Is Not Why They Are Cutting (Yet)
Back in 2000, the rule of thumb at Microsoft was that each employee needed to average roughly \$600K in top-line revenue. Inflation adjusted, that is about \$1.1M to \$1.2M today. Microsoft was a high-margin software…
- Smaller, Provable, and on Hardware You Own and Operate
Dino Dai Zovi made an argument recently that I want to build on.
- The Illusion of Constant Acceleration
Spend enough time around AI right now and you start to get the feeling that everything is speeding up, all the time.
- Confidential Computing's Inconvenient Truth
This is part of a series on confidential computing. See also: Confidential Computing: What It Is, What It Isn't, and How to Think About It for practical deployment guidance, and Why Nobody Can Verify What Booted Your…
- What Is Confidential Computing, What It Isn't, and How to Think About It
Confidential computing is the most important security technology that most organizations deploying it do not fully understand.
- Why Nobody Can Verify What Booted Your Server
There is no public database of known-good TPM measurements. There never has been.
- We Built It With Slide Rules. Then We Forgot How.
My father grew up on a subsistence farm, the kind that raised chickens and grew just enough to get by. Farmers were the original hackers. You couldn't wait for the right tool or the right expert. You fixed what was…
- The WebPKI and Client Authentication Are at a Crossroads
The CA/Browser Forum is having its first serious conversation about whether publicly trusted client authentication certificates deserve their own Baseline Requirements. Nick France kicked off the discussion on the public…
- Introducing the WebPKI Observatory
For as long as I have been in this industry, the WebPKI compliance conversation has run on impressions. People with long memories and regular conference attendance have built up a picture of which CAs are well-run, which…
- Signed, Auditable, Offline-Tolerant, PQ Secure QR Codes
Signed, Auditable, Offline-Tolerant, PQ Secure QR Codes
- When Compliance Records Become the Only Honest Signal
I've been spending a lot of time lately building Systematic Reasoning with my long-time friend Vishal. The core premise is straightforward. Organizations reveal their true operational character through how they design to…
- The Signal They Chose to Ignore
Two prior posts worked through the statistics of the SB 6346 sign-in data. In the first I established the methodology and the finding. After applying a birthday-corrected collision test to separate organic participation…
- Duplicates Are Not the Problem
The Washington House is now arguing that the sign-in dataset for SB 6346 is unreliable because it contains duplicate names. The claim is simple. If the same name appears more than once, you cannot trust the totals.
- Teach to the Median, Punish the Variance
Factories exist to produce consistent, cost-effective products. That is the point. The relentless optimization of cost of goods sold is not a side effect of industrial production. It is the mandate. And it works, until…
- The Data Doesn't Support the Narrative
SB 6346 would create Washington's first personal income tax in nearly a century. A 9.9% rate on income above \$1 million, projected at \$3.4 billion annually, it passed the Senate 27-22 on party lines and is now in the…
- When Building Gets Cheap, Distribution Becomes Destiny
"Distribution is the new moat." You can find some version of that sentence in almost any startup discussion from the last year. It circulates as a take, gets liked, gets reshared, and then gets reproduced by someone else…
- Domain Control Validation Grew Up. It Only Took Thirty Years.
Let's Encrypt announced <a href="https://letsencrypt.org/2026/02/18/dns-persist-01" data-type="link" data-id="https://letsencrypt.org/2026/02/18/dns-persist-01">DNS-PERSIST-01</a> support this week. That is worth noting…
- Disdain or Design?
Washington State is not in the middle of a single policy dispute.
- You're Not Outsourcing Infrastructure. You're Outsourcing Capability.
Chamath posted this week: "Is on-premise the new cloud? I'm beginning to think yes. It's the only way for companies to not blow themselves up and have some semblance of capability in an AI world." Jason Fried dropped a…
- Agents Are More Like Humans Than Workloads. Here's Why That Matters for Identity.
This is a long one. But as a great man once said, forgive the length, I didn't have time to write a short one.
- "A Few Hours" and the Slow Erosion of Auditable Commitments
There's a pattern that plays out across every regulated industry. Requirements increase. Complexity compounds. The people responsible for compliance realize they can't keep up with manual processes. So instead of…
- The Housing Affordability Crisis
Recently, I was talking to one of my kids, now in university, about why housing feels so out of reach here in Washington. He asked the simple question so many young people are asking: Why is it so expensive to just have…
- Intuition Comes Last
Early in my career, I was often told some version of the same advice: stop overthinking, trust your intuition, move faster.