May 2026
- A CA That Produces Evidence, Not Promises
In my last post I argued that high-assurance systems should stop asking to be trusted on the basis of institutional promises and start producing verifiable runtime evidence about what actually happened. This post is the…
- A CA Built for the Threat Model We Actually Have
This builds on earlier posts on what attestation actually proves, what confidential computing is and isn't, and an honest accounting of the problems with the current generation of TEEs. None of those problems go away…
- The First AI-Built Zero-Day Is Not the Interesting Part
In the mid 90s I worked at a company called Cybersafe. Today it would get labeled an IAM/SSO vendor. What we actually built was a first-generation security platform: Kerberos, password management, PKI-based MFA, key…
- AI Is Not Why They Are Cutting (Yet)
Back in 2000, the rule of thumb at Microsoft was that each employee needed to average roughly \$600K in top-line revenue. Inflation adjusted, that is about \$1.1M to \$1.2M today. Microsoft was a high-margin software…
- Smaller, Provable, and on Hardware You Own and Operate
Dino Dai Zovi made an argument recently that I want to build on.