I break into things for a living.
More specifically, I’ve spent the last decade finding out how organizations fail at security and helping them do something about it. The technical work is interesting, but it’s the harder questions underneath that keep me here: how people build trust in systems, where that trust breaks down, and what it costs when it does.
I do that work under my own name now, at Empiric Security (opens in new tab), my independent offensive security consultancy. Before it was mine it was other people’s: a red team seat at Bishop Fox, and five years at risk3sixty where I ended up running the penetration testing practice.
I turn up on conference stages now and then. If you’d rather watch than read: (Almost) Serverless Password Cracking (opens in new tab), Purple Teaming for ROI and Growth (opens in new tab), and Solving Dumb Hacker Problems with Nix (opens in new tab). My CV has all the details: experience, credentials, speaking history, etc.
Outside of work I shoot film (opens in new tab) and ride motorcycles.
Recent Writing
I’m an equal opportunity critic. The industry I work in gets the same treatment as everyone else, and so do my own past decisions.
- Everyone Has A Plan Until They Get Punched In The SonicWall Why any organization with a public IP has to plan for un-patchable zero-day exploitation, not just targeted attacks.
- You Can’t Just Publish Partial Exploits Anymore Taking a ‘safely’ disclosed WordPress RCE most of the way to a full unauthenticated exploit chain with public research, a patch diff, and an LLM, and the rest with a public PoC.
- One Home for Everything I Write Consolidating my scattered writing under one roof, without giving up digital ownership.
I post new writing here first. Follow a feed to catch it as it goes up. I ♥ RSS (opens in new tab)
Recent Frames
More of it over here (opens in new tab).