I'm a security engineer who reports on critical infrastructure, surveillance, and digital rights. I read the advisories, the indictments, and the vendor write-ups the same way I read production systems — and I write about what they actually say.
Writing
All writing-
How to read a CISA advisory without overclaiming
An advisory tells you less than the coverage of it usually implies. A short guide to what these documents assert, what they only suggest, and where the seams are.
-
What this site is
A security engineer's notebook on critical infrastructure, attribution, and digital rights — and what I'm using it for.