Things I build, break, fix, and write about

17 September 2026
Require a BitLocker pre-boot PIN

TPM-only BitLocker is tidy until you remember what is left exposed when the machine can unlock itself. BitLocker PINs are the small, awkward step that makes a stolen laptop less cooperative, and I trust that far more than wishful thinking about physical security.

17 September 2026
Secure connectivity principles in water sector OT

Secure connectivity principles only work when the boundary is real, not decorative. I’ve seen too many remote paths that looked neat on paper and fell...

16 September 2026
Monitoring radio, transport and core faults

Private 5G resilience does not come from a cheerful dashboard or a nice radio map. I want to see where the attach failed, which path dropped, and...

16 September 2026
Pre-boot authentication for BitLocker

TPM-only BitLocker is convenient, but convenience is not the same as a proper boundary. BitLocker PINs push that line back to pre-boot, which is where...

Latest blog posts you might like

29 August 2026
Trusted proxies and interface binding in Home Assistant

Home Assistant OS web server settings matter more than they used to, because the port, bind and trusted proxy choices now decide how the box is reached. Get them wrong and I have seen proxy setups...

29 August 2026
controller-runtime cache: stale reads and conflicts

controller-runtime cache makes reads look easy until you trust them too much. I have chased stale objects and pointless conflicts through more than one controller, and the fix was never magic, just...

28 August 2026
Static Pod config breaks without API access

Kubernetes static pods are unforgiving when kubelet cannot satisfy a reference locally. I have seen a tidy manifest fail because it quietly leaned on the API server, and the fix was not clever, just...

28 August 2026
Gateway API TCPRoute for raw L4 routing

Gateway API TCPRoute finally gives raw L4 routing a proper shape, without the usual controller-specific nonsense. I like it because it stays plain, listener attachment is explicit, and you are not...

27 August 2026
Clipboard hijacking in cryptocurrency transfers

clipboard hijacking works because the address still looks right, until it does not. I prefer to treat the clipboard as hostile, especially with cryptocurrency transfers, where one careless paste is...

27 August 2026
Device encryption limits corporate data theft

Device encryption is useful, but it will not save you from corporate endpoint data theft once a session is live. I have seen the mess that comes from cached files, browser stores, and synced folders;...

26 August 2026
Retaining access logs for healthcare breach notifications

Healthcare breach notifications are only as solid as the logs behind them. I have seen enough broken audits to know that dashboards are no substitute for raw access records, especially when the notice...

26 August 2026
Self-hosted Metabase exposure from unauthenticated SQL

I’ve seen enough self-hosted tools turn into soft centres, and Metabase SQL injection is another reminder. If your analytics box holds credentials, exports and admin access in one place, one bad...

25 August 2026
Patching TrueConf Server 5.3.x before 5.3.9

An exposed TrueConf server is not just a nuisance, it can become a delivery point for poisoned client installers. I would patch first, then check every file it has been serving, because TrueConf...

25 August 2026
Sandboxing agentic AI to block unsafe web actions

Sandboxing agentic AI is less about the model than the exits. If frontier AI evaluations can browse, submit or copy data, the only thing between a test run and a mess is the permission boundary, and I...