#threat-modeling
A set of research notes and deep dives focused on correctness, security, and operational evidence.
Best starting points
PQC Research Series — Part 1
A formal adversary taxonomy for PQC deployments: classical vs quantum vs QROM, with explicit resource accounting (queries, memory, time) and system-boundary assumptions.
Designing for Catastrophic Failure: Compartmentalization and Recovery
Spec-driven research note (December 2024): Designing for Catastrophic Failure: Compartmentalization and Recovery.
ZKP Systems Engineering: Provers, Verifiers, and Operational Cost
Threat-model-first analysis (November 2024): ZKP Systems Engineering: Provers, Verifiers, and Operational Cost.
Formal Verification of Crypto Protocols: Models, Gaps, and Pain
Spec-driven research note (October 2024): Formal Verification of Crypto Protocols: Models, Gaps, and Pain.
Secure Enclaves in Distributed Systems: Remote Attestation and Trust
Spec-driven research note (September 2024): Secure Enclaves in Distributed Systems: Remote Attestation and Trust.
Roadmap
- Start with assumptions and invariants
- Enumerate failure modes and attack surfaces
- Define what to monitor and how to roll back