#securityView all tags
The KelpDAO Exploit Was Not a Bug
· 22 min — #incident-analysis#security#DeFi#cross-chain#distributed-infrastructure#formal-methods#protocol-design#Ethereum#LayerZero
Termination Is a Security Boundary: HotStuff Under UC, Delay Attacks, and the Uncomfortable Gap to Rust
· 13 min — #research-notes#distributed-systems#consensus#BFT#formal-methods#cryptography#Rust#security
Secure Distributed Storage: Erasure Coding Under Adversaries
· 3 min — #research-notes#distributed-systems#cryptography#formal-methods#security
Verifiable Computation as Infrastructure: Proof Systems at Scale
· 3 min — #research-notes#distributed-systems#cryptography#formal-methods#security
Composable Security: Where Proofs Break in Real Systems
· 3 min — #research-notes#distributed-systems#cryptography#formal-methods#security
CPZKp - Building Practical Zero-Knowledge Proofs in Rust from Scratch
· 3 min — #Rust#cryptography#zero-knowledge#chaum-pedersen#ecc#curve25519#security#portfolio
Designing for Catastrophic Failure: Compartmentalization and Recovery
· 4 min — #research-notes#security#distributed-infrastructure#threat-modeling#resilience
ZKP Systems Engineering: Provers, Verifiers, and Operational Cost
· 4 min — #research-notes#security#distributed-infrastructure#threat-modeling#resilience
Formal Verification of Crypto Protocols: Models, Gaps, and Pain
· 4 min — #research-notes#security#distributed-infrastructure#threat-modeling#resilience
Secure Enclaves in Distributed Systems: Remote Attestation and Trust
· 4 min — #research-notes#security#distributed-infrastructure#threat-modeling#resilience
Metadata and Privacy: The Hard Part Isn’t Encryption
· 4 min — #research-notes#security#distributed-infrastructure#threat-modeling#resilience
Byzantine Fault Injection: Testing Protocols Like an Attacker
· 4 min — #research-notes#security#distributed-infrastructure#threat-modeling#resilience
Consensus Under Attack: Adaptive Adversaries and Network Control
· 4 min — #research-notes#security#distributed-infrastructure#threat-modeling#resilience
Time-Based Attacks: NTP Manipulation, Expiration, and Replay
· 4 min — #research-notes#security#distributed-infrastructure#threat-modeling#resilience
Sandbox Escapes: Isolation Boundaries as a Design Input
· 4 min — #research-notes#security#distributed-infrastructure#threat-modeling#resilience
Supply Chain Attacks: Dependency Poisoning and Maintainer Compromise
· 4 min — #research-notes#security#distributed-infrastructure#threat-modeling#resilience
DDoS at Scale: Adaptive Defense and Cost Asymmetry
· 4 min — #research-notes#security#distributed-infrastructure#threat-modeling#resilience
BGP and Routing Attacks: Engineering for the Internet We Have
· 4 min — #research-notes#security#distributed-infrastructure#threat-modeling#resilience
Compliance & Standards: Translating NIST to Engineering Action
· 3 min — #research-notes#post-quantum-cryptography#cryptography#security#protocol-design
Migration Risk Management: Inventory, Prioritization, and Cutover
· 4 min — #research-notes#post-quantum-cryptography#cryptography#security#protocol-design
Side Channels in PQC Implementations: Where Theory Meets Cache
· 3 min — #research-notes#post-quantum-cryptography#cryptography#security#protocol-design
Benchmarking PQC: What to Measure (and What Not To)
· 4 min — #research-notes#post-quantum-cryptography#cryptography#security#protocol-design
Crypto Agility Tooling: Feature Flags, Policy, and Rollback
· 4 min — #research-notes#post-quantum-cryptography#cryptography#security#protocol-design
PQC for IoT: Memory, CPU, and Timing Side Channels
· 3 min — #research-notes#post-quantum-cryptography#cryptography#security#protocol-design
PQC in VPN/IPsec: IKEv2 Revisited Under PQ Constraints
· 3 min — #research-notes#post-quantum-cryptography#cryptography#security#protocol-design
PQC in TLS: Negotiation, Downgrade, and Interop
· 4 min — #research-notes#post-quantum-cryptography#cryptography#security#protocol-design
Hybrid Key Exchange: Binding Classical and PQ Secrets Correctly
· 3 min — #research-notes#post-quantum-cryptography#cryptography#security#protocol-design
Signatures in Practice: Dilithium/Falcon and Deployment Constraints
· 4 min — #research-notes#post-quantum-cryptography#cryptography#security#protocol-design
KEMs in Practice: Kyber Handshakes and Failure Surfaces
· 4 min — #research-notes#post-quantum-cryptography#cryptography#security#protocol-design
PQC Threat Models: 'Harvest Now, Decrypt Later' in Real Systems
· 4 min — #research-notes#post-quantum-cryptography#cryptography#security#protocol-design
Red Teaming Infrastructure: Turning Attacks into Regression Tests
· 3 min — #research-notes#DevSecOps#security#resilience#security-critical-infrastructure
Rust/Go Secure Coding Patterns: The Bugs That Still Happen
· 3 min — #research-notes#DevSecOps#security#resilience#security-critical-infrastructure
Secure Configuration: Policy-as-Code and Guardrails
· 3 min — #research-notes#DevSecOps#security#resilience#security-critical-infrastructure
Backup/Restore as a Protocol: RPO/RTO with Adversaries
· 3 min — #research-notes#DevSecOps#security#resilience#security-critical-infrastructure
Observability at Scale: Traces, Cardinality, and Cost
· 3 min — #research-notes#DevSecOps#security#resilience#security-critical-infrastructure
Rate Limiting & Load Shedding: Protecting Reliability SLOs
· 3 min — #research-notes#DevSecOps#security#resilience#security-critical-infrastructure
Multi-Region Design: Failover That You Can Actually Test
· 4 min — #research-notes#DevSecOps#security#resilience#security-critical-infrastructure
Kubernetes Hardening: RBAC, NetworkPolicy, and Pod Security
· 4 min — #research-notes#DevSecOps#security#resilience#security-critical-infrastructure
Runtime Security: eBPF, Policy, and Drift Detection
· 3 min — #research-notes#DevSecOps#security#resilience#security-critical-infrastructure
Secrets Hygiene: Rotation, Scoping, and Runtime Delivery
· 3 min — #research-notes#DevSecOps#security#resilience#security-critical-infrastructure
Reproducible CI/CD: Determinism as Defense
· 3 min — #research-notes#DevSecOps#security#resilience#security-critical-infrastructure
Supply Chain Security: SLSA, SBOM, and Build Provenance
· 3 min — #research-notes#DevSecOps#security#resilience#security-critical-infrastructure
Incident Response for Crypto Systems: Key Compromise Playbooks
· 4 min — #research-notes#cryptography#security#security-critical-infrastructure#DevSecOps
KMS/HSM Threat Models: When 'Managed' Doesn't Mean 'Safe'
· 4 min — #research-notes#cryptography#security#security-critical-infrastructure#DevSecOps
Multi-Tenant Isolation: Crypto Boundaries vs Kernel Boundaries
· 4 min — #research-notes#cryptography#security#security-critical-infrastructure#DevSecOps
Cryptographic Agility: Designing for the Algorithm You Haven't Met Yet
· 4 min — #research-notes#cryptography#security#security-critical-infrastructure#DevSecOps
Logging for Forensics: Tamper Evident Event Pipelines
· 4 min — #research-notes#cryptography#security#security-critical-infrastructure#DevSecOps
TLS Beyond Defaults: Ciphersuites, ALPN, and Operational Reality
· 4 min — #research-notes#cryptography#security#security-critical-infrastructure#DevSecOps
Secure Firmware Updates: Signed Manifests and Rollback Protection
· 4 min — #research-notes#cryptography#security#security-critical-infrastructure#DevSecOps
Side Channels: Constant-Time, Cache Attacks, and Real Threat Models
· 4 min — #research-notes#cryptography#security#security-critical-infrastructure#DevSecOps
Hardware Roots of Trust: TPM, Secure Boot, and Attestation
· 4 min — #research-notes#cryptography#security#security-critical-infrastructure#DevSecOps
Secrets vs Capabilities: Token Design in Microservices
· 4 min — #research-notes#cryptography#security#security-critical-infrastructure#DevSecOps
Key Management at Scale: Rotation, Audit, and Blast Radius
· 4 min — #research-notes#cryptography#security#security-critical-infrastructure#DevSecOps
PKI as an Operating System: Certificates, Policies, and Expiration
· 4 min — #research-notes#cryptography#security#security-critical-infrastructure#DevSecOps