# fip (blogs) — RSS Amplifier

Recent posts from the 1 feeds in the RSS Amplifier directory that cover fip.

Page: <https://rssamplifier.com/topics/fip/blogs>  
Feed: <https://rssamplifier.com/topics/fip/blogs.md>

---

## [The Amnesia Cycle and Why AI Is Turning Developers Back Into Testers](https://unmitigatedrisk.com/?p=1326)

_2026-08-19 · rmhrisk · UNMITIGATED RISK_

I started working in technology around 1993. One of my first jobs was in quality assurance, partly because there was no security profession to join yet. There were people doing the work, but few companies were hiring for it. That changed within a decade. Until it did, people with the instincts that would later define \[…\]

## [Hurst University](https://unmitigatedrisk.com/?p=1323)

_2026-08-17 · rmhrisk · UNMITIGATED RISK_

For as long as my children can remember, I have told them that they are students at Hurst University. It has no campus, no accreditation, and no admissions process. Joining the family is enough to get you enrolled. Graduation is another matter. There is only one requirement. By the time you leave the house, you \[…\]

## [From Periodic Audit to Continuous Assurance](https://unmitigatedrisk.com/?p=1318)

_2026-08-06 · rmhrisk · UNMITIGATED RISK_

I have been writing about the limitations of audits and compliance systems for several years. In Accountability and Transparency in Modern Systems, I wrote about systems producing evidence continuously rather than assembling it periodically for an auditor. In First Principles for Root Store Management, I looked back at the decision to require WebTrust for publicly \[…\]

## [From Chains to Trees](https://unmitigatedrisk.com/?p=1314)

_2026-08-04 · rmhrisk · UNMITIGATED RISK_

The WebPKI has two structures that are not the same shape. One is a cryptographic graph of signed bindings. Public keys, names, entitlements, and the keys that authorized them. The other is a governance hierarchy of accountability. It explains why a relying party accepts that authority at all, and when it stops accepting it. Nearly \[…\]

## [The Status Quo Outlived Its Status](https://unmitigatedrisk.com/?p=1307)

_2026-07-17 · rmhrisk · UNMITIGATED RISK_

In security we like to say that the problems live in the gaps between systems. Each system, on its own, is usually coherent. It has a threat model, invariants, and someone who owns it. The seam between two systems is owned by nobody, and each side quietly assumes the other is handling the thing that \[…\]

## [Why FIPS 140 Means Running Old Code](https://unmitigatedrisk.com/?p=1293)

_2026-07-13 · rmhrisk · UNMITIGATED RISK_

You need to use FIPS 140 because of compliance, but have you ever asked what that requirement is actually for? What security properties are the authors of these policies trying to achieve? In high-assurance deployments, the practical goal is usually to establish a meaningful security boundary around cryptographic keys. Organizations want explicit controls over who \[…\]

## [The Certification Ends Where the Code Begins](https://unmitigatedrisk.com/?p=1291)

_2026-07-10 · rmhrisk · UNMITIGATED RISK_

Disclosure: I am an advisor to Binarly. I recently built the FIPS 140-3 Corpus, a dataset that pulls together the public record of FIPS validations. It combines CMVP certificate records, Security Policies, implementation details, operational environments, firmware versions, algorithm claims, and lifecycle data into something you can actually query and analyze rather than read one \[…\]

## [Steve Jobs, AI, and the Problem of Analysis Without Ownership](https://unmitigatedrisk.com/?p=1280)

_2026-07-09 · rmhrisk · UNMITIGATED RISK_

There is an old Steve Jobs clip from a 1992 MIT Sloan talk that feels newly relevant in the age of AI. In the talk, available here as Steve Jobs MIT 1992 Lecture, Jobs is asked about consultants. His answer is not that consultants are unintelligent or useless. His criticism is more subtle. He says \[…\]

## [The Breaker, the Priest, and the Philosopher](https://unmitigatedrisk.com/?p=1268)

_2026-06-18 · rmhrisk · UNMITIGATED RISK_

Spend enough years in security and you notice that the people whose judgment you actually trust are rarely the ones with the cleanest credentials. They are the ones who have been wrong in public often enough to develop taste. Their authority is earned backward, from scars rather than definitions. When they look at a scheme \[…\]

## [The Prompt Is an Argument](https://unmitigatedrisk.com/?p=1270)

_2026-06-18 · rmhrisk · UNMITIGATED RISK_

The prior piece made a narrow claim. The prompt is the record, because a system can only act on what reaches it. Intent that stays in your head does not govern anything. Context that never reaches the model does not constrain anything. Purpose that is not in the prompt, the retrieved material, the tools, the \[…\]

## [Crush Every Threat in Real Time (Sponsored)](https://crawlproof.com/a/yEjYkKdLLaWE)

_2026-06-18 · **Sponsored**_

One agent for real-time detection, exposure tracking, and active defense.

## [The Prompt Is the Meaning](https://unmitigatedrisk.com/?p=1266)

_2026-06-02 · rmhrisk · UNMITIGATED RISK_

Why textualism, original public meaning, and AI governance all turn on the same uncomfortable fact: intent does not travel unless it becomes part of the record. There is an old fight in legal interpretation about where meaning lives. Intentionalists look for purpose. They ask what Congress meant to do, what the drafters were trying to \[…\]

## [A CA That Produces Evidence, Not Promises](https://unmitigatedrisk.com/?p=1247)

_2026-05-23 · rmhrisk · UNMITIGATED RISK_

In my last post I argued that high-assurance systems should stop asking to be trusted on the basis of institutional promises and start producing verifiable runtime evidence about what actually happened. This post is the worked example. A certificate authority built that way, what choices it forced, and what is and is not done yet. \[…\]

