Security

  • From Defense AI Drift to Policy Enforcement: Why I Built Firebreak

    ·

    I wrote earlier about why defense AI companies drift toward offensive applications. Today for a hackathon I built the engineering solution I wish had existed when I was inside that world. Firebreak is a policy-as-code enforcement proxy that makes pre-negotiated AI boundaries hold — automatically, at machine speed, with full audit trails.

    Read More

  • Bounties and Risk

    ·

    I reflect on my experiences in cybersecurity, emphasizing the challenges and risks involved in reporting security issues. I’ve had positive experiences, such as receiving a bug bounty from Dropbox, and negative ones, like a legal threat from a university. Despite occasional hostilities, I strongly believe in responsibly reporting security problems and advocate for compensating security…

    Read More

  • Password Security

    ·

    How do you address password security? What controls do you put in place? Do they matter? What does a strong password look like? Learn how to protect your users in 2024 and beyond!

    Read More

  • Adversarial mindsets

    ·

    What’s the absolute worst thing that could happen with your application? How could an adversary leverage that mistake to their advantage?

    Read More

  • Basic firewall usage

    ·

    If you run a server in the cloud, you need to use a firewall to protect it. Let’s look at the most basic settings of Ubuntu’s ufw system.

    Read More