Long-form
Longer essays and research on security, identity, cryptography, compliance, and AI. Each piece develops an argument beyond the limits of a post.
- The Verifier Never Showed Up
Thirty years of digital identity programs, sorted by how they actually failed, and why the half of the system that decides adoption is the half nobody funds.
- Security Design Never Scaled
Two services, one bug, every instrument calling them identical. We scaled security’s answers but never the reasoning behind them, and machine reasoning may finally change that.
- How Audits Work, from Management Assertions to Control Matrices
How attestation audits actually function, using the WebPKI as a worked example, from management assertions and control matrices to evidence and auditor conclusions.
- Containing the Optimizer
A field guide to what containers, VMs, confidential VMs, and enclaves actually protect, and what it costs when each one fails.
- The Assurance Model Was Built for a World That No Longer Exists
How periodic audit came to be, why its epistemic reach is shrinking, and what AI does to the mismatch.
- Why Continuous Assurance Did Not Happen Until Now
The economics of cognition, the limits of GRC software, and what AI actually changes.
- The Post-Quantum WebPKI
How the Internet will decide which public keys to trust once signatures no longer fit on the wire.
- A Deep Dive on the Classical WebPKI
How the Internet decides which public keys to trust.
- FIPS 140-3 Validation, in Practice
What the US and Canadian standard for validating cryptographic modules actually covers, with data from the validation corpus.
- Power Wagon: The Whole Story
The story of the Dodge Power Wagon, from its wartime origins and working life to the modern truck that still carries its name.