Interests and methodology
Research
My current security research examines how identity, authority, and trust move across software boundaries, alongside broader interests in cryptography and computer systems.
Research Interests
- Cryptography
- System Security
- Computer Systems
- Vulnerability Research
- Responsible Disclosure
Research Method
An evidence-first process for evaluating security boundaries. Operational heuristics and target-specific techniques are intentionally omitted.
-
Boundary Modeling
Define the identities, capabilities, data domains, and trust transitions that shape the system's expected security properties.
-
Authority-Aware Analysis
Follow how identity and scope propagate across components, focusing on places where authority may be weakened or reinterpreted.
-
Evidence and Falsification
Use bounded local validation and competing explanations to distinguish a real boundary failure from expected behavior or an artifact.
-
Conservative Triage
Separate technical impact from reportability, account for prior work, document limitations, and coordinate disclosure responsibly.