Cryptographic Infrastructure
Browse series · RSS · Atom
Start here: first entry.
PKI as an Operating System: Certificates, Policies, and Expiration
Correctness-focused deep dive (January 2018): PKI as an Operating System: Certificates, Policies, and Expiration.
Key Management at Scale: Rotation, Audit, and Blast Radius
Spec-driven research note (February 2018): Key Management at Scale: Rotation, Audit, and Blast Radius.
Secrets vs Capabilities: Token Design in Microservices
Design memo (March 2018): Secrets vs Capabilities: Token Design in Microservices.
Hardware Roots of Trust: TPM, Secure Boot, and Attestation
Correctness-focused deep dive (April 2018): Hardware Roots of Trust: TPM, Secure Boot, and Attestation.
Side Channels: Constant-Time, Cache Attacks, and Real Threat Models
Adversarial-first deep dive (May 2018): Side Channels: Constant-Time, Cache Attacks, and Real Threat Models.
Secure Firmware Updates: Signed Manifests and Rollback Protection
Spec-driven research note (June 2018): Secure Firmware Updates: Signed Manifests and Rollback Protection.
TLS Beyond Defaults: Ciphersuites, ALPN, and Operational Reality
Spec-driven research note (July 2018): TLS Beyond Defaults: Ciphersuites, ALPN, and Operational Reality.
Logging for Forensics: Tamper Evident Event Pipelines
Adversarial-first deep dive (August 2018): Logging for Forensics: Tamper Evident Event Pipelines.
Cryptographic Agility: Designing for the Algorithm You Haven't Met Yet
Threat-model-first analysis (September 2018): Cryptographic Agility: Designing for the Algorithm You Haven't Met Yet.
Multi-Tenant Isolation: Crypto Boundaries vs Kernel Boundaries
Spec-driven research note (October 2018): Multi-Tenant Isolation: Crypto Boundaries vs Kernel Boundaries.
KMS/HSM Threat Models: When 'Managed' Doesn't Mean 'Safe'
Correctness-focused deep dive (November 2018): KMS/HSM Threat Models: When 'Managed' Doesn't Mean 'Safe'.
Incident Response for Crypto Systems: Key Compromise Playbooks
Correctness-focused deep dive (December 2018): Incident Response for Crypto Systems: Key Compromise Playbooks.