#security-critical-infrastructureView all tags
Hybrid Schemes and Protocol Agility
· 10 min — #research-notes#post-quantum-cryptography#cryptography#protocol-design#security-critical-infrastructure#devsecops#distributed-systems#TLS
The Leaf Is the Hot Path: Signature Placement in Post-Quantum TLS (ML-DSA vs SLH-DSA)
· 9 min — #research-notes#post-quantum-cryptography#cryptography#protocol-design#security-critical-infrastructure#devsecops#distributed-systems#TLS#PKI
Stateful Signatures Are a Distributed Systems Problem: XMSS/LMS Without Index Reuse
· 10 min — #research-notes#post-quantum-cryptography#cryptography#security-critical-infrastructure#devsecops#iiot-platforms#distributed-systems#formal-methods
Research Frontiers: Composability, Proofs, and Future Primitives
· 3 min — #research-notes#post-quantum-cryptography#security-critical-infrastructure#protocol-design#cryptography
Long-Lived Secrets: Forward Secrecy, KEMs, and Key Erasure
· 3 min — #research-notes#post-quantum-cryptography#security-critical-infrastructure#protocol-design#cryptography
Post-Quantum DoS Surfaces: Handshakes, Amplification, and Mitigations
· 3 min — #research-notes#post-quantum-cryptography#security-critical-infrastructure#protocol-design#cryptography
Operationalizing PQC: Monitoring, Rollback, and Incident Response
· 3 min — #research-notes#post-quantum-cryptography#security-critical-infrastructure#protocol-design#cryptography
Quantum-Safe VPN Design: Lessons from Implementing a PQ IPSec Stack
· 3 min — #research-notes#post-quantum-cryptography#security-critical-infrastructure#protocol-design#cryptography
no_std Crypto in Rust: Determinism, Side Channels, and Constraints
· 3 min — #research-notes#post-quantum-cryptography#security-critical-infrastructure#protocol-design#cryptography
BFT with PQ Primitives: When Crypto Costs Dominate
· 3 min — #research-notes#post-quantum-cryptography#security-critical-infrastructure#protocol-design#cryptography
Quantum-Resilient Identity: Device + Human, Online + Offline
· 3 min — #research-notes#post-quantum-cryptography#security-critical-infrastructure#protocol-design#cryptography
PQC for Blockchain Signatures: Wallet UX, Size, and Verification Cost
· 3 min — #research-notes#post-quantum-cryptography#security-critical-infrastructure#protocol-design#cryptography
Quantum-Safe Secure Boot: Firmware Roots and PQ Signatures
· 3 min — #research-notes#post-quantum-cryptography#security-critical-infrastructure#protocol-design#cryptography
Hybrid Key Management: Rotations Across Algorithm Families
· 3 min — #research-notes#post-quantum-cryptography#security-critical-infrastructure#protocol-design#cryptography
Quantum Threat Modeling for Infrastructure: What Changes, What Doesn’t
· 3 min — #research-notes#post-quantum-cryptography#security-critical-infrastructure#protocol-design#cryptography
Red Teaming Infrastructure: Turning Attacks into Regression Tests
· 3 min — #research-notes#DevSecOps#security#resilience#security-critical-infrastructure
Rust/Go Secure Coding Patterns: The Bugs That Still Happen
· 3 min — #research-notes#DevSecOps#security#resilience#security-critical-infrastructure
Secure Configuration: Policy-as-Code and Guardrails
· 3 min — #research-notes#DevSecOps#security#resilience#security-critical-infrastructure
Backup/Restore as a Protocol: RPO/RTO with Adversaries
· 3 min — #research-notes#DevSecOps#security#resilience#security-critical-infrastructure
Observability at Scale: Traces, Cardinality, and Cost
· 3 min — #research-notes#DevSecOps#security#resilience#security-critical-infrastructure
Rate Limiting & Load Shedding: Protecting Reliability SLOs
· 3 min — #research-notes#DevSecOps#security#resilience#security-critical-infrastructure
Multi-Region Design: Failover That You Can Actually Test
· 4 min — #research-notes#DevSecOps#security#resilience#security-critical-infrastructure
Kubernetes Hardening: RBAC, NetworkPolicy, and Pod Security
· 4 min — #research-notes#DevSecOps#security#resilience#security-critical-infrastructure
Runtime Security: eBPF, Policy, and Drift Detection
· 3 min — #research-notes#DevSecOps#security#resilience#security-critical-infrastructure
Secrets Hygiene: Rotation, Scoping, and Runtime Delivery
· 3 min — #research-notes#DevSecOps#security#resilience#security-critical-infrastructure
Reproducible CI/CD: Determinism as Defense
· 3 min — #research-notes#DevSecOps#security#resilience#security-critical-infrastructure
Supply Chain Security: SLSA, SBOM, and Build Provenance
· 3 min — #research-notes#DevSecOps#security#resilience#security-critical-infrastructure
Post-Quantum Readiness at the Edge: Constraints and Migration
· 4 min — #research-notes#IIoT#security-critical-infrastructure#distributed-systems#DevSecOps
Anomaly Detection: What 'Baseline' Means in Industrial Systems
· 4 min — #research-notes#IIoT#security-critical-infrastructure#distributed-systems#DevSecOps
Secure Remote Access: Bastions, Just-in-Time, and Audit
· 3 min — #research-notes#IIoT#security-critical-infrastructure#distributed-systems#DevSecOps
Offline-First Edge: Consistency During Intermittent Connectivity
· 3 min — #research-notes#IIoT#security-critical-infrastructure#distributed-systems#DevSecOps
Safety-Critical vs Security-Critical: Integrating Two Worlds
· 4 min — #research-notes#IIoT#security-critical-infrastructure#distributed-systems#DevSecOps
Gateway Architecture: Protocol Translation Without Becoming a Bottleneck
· 4 min — #research-notes#IIoT#security-critical-infrastructure#distributed-systems#DevSecOps
Time-Series at Scale: Ingestion, Downsampling, and Query Isolation
· 4 min — #research-notes#IIoT#security-critical-infrastructure#distributed-systems#DevSecOps
Zero Trust for IIoT: Network Segmentation and Policy Enforcement
· 4 min — #research-notes#IIoT#security-critical-infrastructure#distributed-systems#DevSecOps
Firmware Update Pipelines: Rollouts, Canary, and Recovery
· 4 min — #research-notes#IIoT#security-critical-infrastructure#distributed-systems#DevSecOps
Edge-to-Cloud Messaging: MQTT, OPC UA, and Threat Models
· 4 min — #research-notes#IIoT#security-critical-infrastructure#distributed-systems#DevSecOps
Secure Telemetry: Integrity, Nonce Discipline, and Replay Protection
· 3 min — #research-notes#IIoT#security-critical-infrastructure#distributed-systems#DevSecOps
Device Identity: Provisioning, Attestation, and Lifecycle
· 4 min — #research-notes#IIoT#security-critical-infrastructure#distributed-systems#DevSecOps
Incident Response for Crypto Systems: Key Compromise Playbooks
· 4 min — #research-notes#cryptography#security#security-critical-infrastructure#DevSecOps
KMS/HSM Threat Models: When 'Managed' Doesn't Mean 'Safe'
· 4 min — #research-notes#cryptography#security#security-critical-infrastructure#DevSecOps
Multi-Tenant Isolation: Crypto Boundaries vs Kernel Boundaries
· 4 min — #research-notes#cryptography#security#security-critical-infrastructure#DevSecOps
Cryptographic Agility: Designing for the Algorithm You Haven't Met Yet
· 4 min — #research-notes#cryptography#security#security-critical-infrastructure#DevSecOps
Logging for Forensics: Tamper Evident Event Pipelines
· 4 min — #research-notes#cryptography#security#security-critical-infrastructure#DevSecOps
TLS Beyond Defaults: Ciphersuites, ALPN, and Operational Reality
· 4 min — #research-notes#cryptography#security#security-critical-infrastructure#DevSecOps
Secure Firmware Updates: Signed Manifests and Rollback Protection
· 4 min — #research-notes#cryptography#security#security-critical-infrastructure#DevSecOps
Side Channels: Constant-Time, Cache Attacks, and Real Threat Models
· 4 min — #research-notes#cryptography#security#security-critical-infrastructure#DevSecOps
Hardware Roots of Trust: TPM, Secure Boot, and Attestation
· 4 min — #research-notes#cryptography#security#security-critical-infrastructure#DevSecOps
Secrets vs Capabilities: Token Design in Microservices
· 4 min — #research-notes#cryptography#security#security-critical-infrastructure#DevSecOps
Key Management at Scale: Rotation, Audit, and Blast Radius
· 4 min — #research-notes#cryptography#security#security-critical-infrastructure#DevSecOps
PKI as an Operating System: Certificates, Policies, and Expiration
· 4 min — #research-notes#cryptography#security#security-critical-infrastructure#DevSecOps