Things I build, break, fix, and write about

17 September 2026
Require a BitLocker pre-boot PIN

TPM-only BitLocker is tidy until you remember what is left exposed when the machine can unlock itself. BitLocker PINs are the small, awkward step that makes a stolen laptop less cooperative, and I trust that far more than wishful thinking about physical security.

17 September 2026
Secure connectivity principles in water sector OT

Secure connectivity principles only work when the boundary is real, not decorative. I’ve seen too many remote paths that looked neat on paper and fell...

16 September 2026
Monitoring radio, transport and core faults

Private 5G resilience does not come from a cheerful dashboard or a nice radio map. I want to see where the attach failed, which path dropped, and...

16 September 2026
Pre-boot authentication for BitLocker

TPM-only BitLocker is convenient, but convenience is not the same as a proper boundary. BitLocker PINs push that line back to pre-boot, which is where...

Latest blog posts you might like

24 August 2026
Testing frontier AI for sensitive data handling

frontier AI evaluations are easy to get wrong when the model only sees tidy prompts and harmless files. I care more about where the data ends up, in logs, caches, memory, or a tool call, because that...

23 August 2026
Testing agent boundaries before tool access widens

Frontier AI evaluations are only useful if they fail in the right places. If a model can keep itself safe until the last gate, then the gate is doing the work, not the model, and I would rather find...

22 August 2026
Skia integration for Rust image decoding

Chromium image codecs are where browser safety gets real, because malformed images arrive before anything else useful has happened. I like the Skia route for that reason; it keeps the ugly parsing...

22 August 2026
Styled output in macOS Terminal can leak data over DNS

macOS Terminal ANSI escape codes are one of those details I keep tripping over, because the wrong sequence can do more than colour text. I like this kind of bug precisely because it is small, ugly,...

21 August 2026
Tool boundaries in incident response for AI agents

When an autonomous AI intrusion lands, I care less about the model’s output and more about whether my tools still work. If a hosted service refuses the forensic workload, your response path is already...

21 August 2026
Flatpak pipewire escape through module loading

Flatpak PipeWire sandbox escape sounds tidy until you look at the PulseAudio path properly, where a length check passes for authentication and module loading stays open. Give a Flatpak...

20 August 2026
Founder-led startups and the cost of replacing generalists

AI can make founder-led startups look busier than they are, which is exactly why I distrust it when the team is already thin. The easy wins are real, but once you remove the generalist, you often...

20 August 2026
RCU and refcount faults in Linux kernel net/sched

RCU and refcount faults in the Linux kernel net/sched path are the sort of bug I like least, because the refcount check arrives after the damage is already done. On a busy CentOS 9 box, the race is...

19 August 2026
Simple Caddy access rules for cgit

I keep cgit behind Caddy access rules because the decision belongs at the front door, not buried in the app. It is a blunt setup, but it keeps browser noise out, leaves Git clients alone, and avoids...

19 August 2026
Skipping fenced code blocks in Neovim Markdown outline

Neovim Markdown outline navigation gets ugly fast if you let fenced examples count as headings. I fixed that with a small state flag, a blunt scan, and no ceremony; the sort of change that quietly...