Security·5 min read·
Your Backup Administrator Should Not Be Able to Delete Yesterday
Timelock Drive puts retention below a compromised host. An offline model shows why unfreezing a backup must start a countdown, not erase its protection.
Vol. MMXXVINo. 94
Field reports from cloud-security engineering, AI experiments, and a homelab that keeps getting bigger.
Start here: agentic security, tools, and homelab reading paths
Security·5 min read·
Timelock Drive puts retention below a compromised host. An offline model shows why unfreezing a backup must start a countdown, not erase its protection.
Security·6 min read·
A disposable PostgreSQL lab tests what an agent-facing database role can actually do, including the SELECT that writes through a privileged function.
Systems·3 min read·
Pilot Execution treats recovery as a state-changing program and previews its cross-component effects before committing the action.
Security·8 min read·
A proved gate is only as good as the policy it enforces, and the policy is the part that changes while the agent is running. What OSCAL and the agent-authorization drafts both assume, and what breaks.
Systems·4 min read·
SYSSPEC treats a filesystem specification as the thing an agent edits, then asks generated code to live up to the contract.
Security·7 min read·
Formal verification for AI-agent security. You can't prove a probabilistic model does the right thing — but the deterministic gate in front of it is small enough to prove outright. Dafny proofs, a Rego twin, and differential testing, following the method AWS used for Cedar.