I started the year with a reading goal of 12 books because I was trying to become a person who reads again. One a month felt realistic. It was a way to commit without pretending I knew exactly how it would fit into real life. Once it was obvious I was going to clear 12, I escalated the goal to 26. One every two weeks felt like a useful constraint, the kind that nudges you forward without turning a…
Over the past few years, I have given a talk on Cryptography Pitfalls at a variety of conferences. One section of the talk covers the evolution of password storage and the various data breaches the last few years . In addition to covering the ways password storage has been done wrong, I also present the best solutions. Instead of recapping it again, take a look at Coda Hale’s blog post on…
We’ve all seen the tense scene in a war movie where the order has come down to launch the nuclear missiles. The captain and his first officer each take out a special key they’ve had around their neck the whole time. Then they both insert their individual keys into the weapons computer and turn simultaneously. Despite being a popular motif, this is a real policy implemented by many…
Bio I’m the Chief Information Security Officer at GoFundMe , where we help people help each other. I work in security and still write a lot of code, mostly cryptography and infrastructure tooling. I’m also on the Gleam core team. What I build: 🔒 Cryptography libraries for Gleam: kryptos , gose (JOSE/COSE), and glasskey (Passkey/WebAuthn) 📡 tsbridge , for running…
Cryptography Pitfalls Slides Debugging TLS/SSL Slides Devops for the Rubyist Soul Slides Non-recorded I love UNIX and so can you! Basic iOS Security Analysis - OWASP Chicago