I break into things for a living.
More specifically, I’ve spent the last decade finding out how organizations fail at security and helping them do something about it. The technical work is interesting, but it’s the harder questions underneath that keep me here: how people build trust in systems, where that trust breaks down, and what it costs when it does.
I run Empiric Security (opens in new tab), my independent offensive security consultancy. My CV has all the details: experience, credentials, speaking history, etc.
Outside of work I shoot film (opens in new tab) and ride motorcycles.
Recent Writing
- You Can’t Just Publish Partial Exploits Anymore Taking a ‘safely’ disclosed WordPress RCE most of the way to a full unauthenticated exploit chain with public research, a patch diff, and an LLM, and the rest with a public PoC.
- One Home for Everything I Write Consolidating my scattered writing under one roof, without giving up digital ownership.
- What To Do With Bad Ideas From People Who Also Have Good Ideas On consuming valuable ideas from people whose other beliefs you find repugnant, and why avoidance is the choice to be passive.
New writing lands here first. Follow along with RSS or Atom to catch it as it goes up.