The Other Sean Byrne Doesn’t Exist
A fictitious employee of an Irish aircraft-parts company ended up on a U.S. government restricted-party list. Sixteen years later, companies keep mistaking me for him.
Security engineering leader. Building and scaling security programs at high-growth companies.
A fictitious employee of an Irish aircraft-parts company ended up on a U.S. government restricted-party list. Sixteen years later, companies keep mistaking me for him.
Slides and notes from my Cork|Sec talk on the evolution of end-to-end encryption key storage, and why the WebAuthn PRF extension may collapse authentication and encryption roots into a single primitive.
Anthropic pointed Claude at the Firefox codebase and found 22 zero-days in two weeks. The capability gap between AI and widespread exploitation won't last. The window to prepare is now.
A leaked iPhone exploit framework avoids devices with Lockdown Mode enabled. For anyone who tried the feature early and gave up, it may be worth revisiting.
Passkeys solve the authentication problem corporate IT has been fighting for decades. But the more interesting story is what happens when every employee has a hardware-backed key generation and storage facility in their pocket.
On AMD's insecure auto-updater, the responsible disclosure process, and why fixing the bug should be the beginning of accountability, not the end.
SMS 2FA won't be killed by SIM swapping or SS7. It will be killed by the paperwork now standing between you and a six digit code.
On Trevor Perrin's talk about the TextSecure (Signal) protocol, and why authentication is the harder half of end-to-end encryption.
On the AT&T Archives UNIX documentary, composition as a way to manage complexity, and why inspectable systems are easier to secure.