A practical walkthrough of threat modeling a retrieval-augmented generation pipeline — mapping STRIDE threats to OWASP LLM Top 10 risks with controls that actually ship.
Notes on security, code, and other things I find interesting.
Here you can find some of the things I find interesting and some of the things I've been working on.
Showing 5 posts tagged security
In 2018 I wrote a master's thesis on the state of post-quantum cryptography and built simulators for McEliece and Niederreiter. Here's what the field looks like now - and what actually changed.
I've had chances to fix real security issues - and been blocked by people who'd rather stay visible than stay safe. Quick wins beat beautiful frameworks.
A technical walkthrough of remote code execution, why rule engines are dangerous attack surfaces, and how a custom Drools rules menu became a Java code injection vector.
How structured threat modeling turns security standards into actionable design decisions - without slowing teams down.