Security·18 min read·
Ninety-Two Posts as a Test Corpus
Auditing the archive produced something more useful than corrections: a labelled corpus of known-false claims. What we are building against it, what works, and what does not.
Vol. MMXXVINo. 92
Field reports from cloud-security engineering,AI experiments, and a homelab that keeps getting bigger.
Security·18 min read·
Auditing the archive produced something more useful than corrections: a labelled corpus of known-false claims. What we are building against it, what works, and what does not.
Security·8 min read·
A proved gate is only as good as the policy it enforces, and the policy is the part that changes while the agent is running. What OSCAL and the agent-authorization drafts both assume, and what breaks.
Security·14 min read·
npm's own replication database says 4,288,093 packages. The aggregator most supply-chain research runs on says 5,732,659. The gap is retained unpublish tombstones, and sampling from the wrong side moves a headline number by sixteen points.
Security·7 min read·
Formal verification for AI-agent security. You can't prove a probabilistic model does the right thing — but the deterministic gate in front of it is small enough to prove outright. Dafny proofs, a Rego twin, and differential testing, following the method AWS used for Cedar.
Security·7 min read·
Rewriting security controls for probabilistic agents. Static control catalogs assume systems that do what they're told; AI agents don't — so here's how to express agent guardrails (tool allowlists, secret-egress denial, audit) as machine-checkable OSCAL component definitions.
Design·10 min read·
A dataset of 545 terminal color schemes, converted to OKLCH and republished as an npm package — and the theme picker in this site's own header that quietly runs on it.