About
I'm a security and infrastructure engineer who writes about critical infrastructure, surveillance, and digital rights.
TODO: two or three paragraphs. What you've built and defended, how long you've done it, and what drew you to reporting. Be specific about the technical work — "I've run incident response for industrial control systems" lands very differently from "I'm passionate about security."
What I cover
- Attacks on critical infrastructure, and the gap between the advisory and what the operator can actually do about it.
- Attribution: who gets named, on what evidence, and how private-sector claims differ from government confirmation.
- Surveillance and censorship technology, and its use against journalists, activists, and civil society.
- Open-source investigation and the preservation of evidence of human rights abuses.
How I work
I go to the primary document — the advisory, the indictment, the designation, the filing — rather than to somebody else's summary of it. I say plainly when attribution is contested or unconfirmed, and I'd rather publish an honest uncertainty than a clean story that outruns the evidence.
Corrections
If something here is wrong, tell me and I'll fix it. Substantive corrections are noted on the piece itself with the date and what changed, not silently edited away. Reach me at the addresses on the contact page.
Conflicts of interest
TODO: state your day job and what you therefore won't write about — your employer, its customers, its vendors, and anything you learned through that work. Do this before you need it. Disclosing a conflict up front is routine; being found to have one you didn't mention is a career problem.
Funding
TODO: how this site is paid for, and whether any of the work here was grant-funded. If a piece came out of a fellowship or grant, say so on the piece.