Browse

Security

BMAD and Micrantha: Workflow Discipline on a Governed Substrate

Oct 1, 2026 12:00AM
9 min read
1895 words
BMAD and Micrantha: Workflow Discipline on a Governed Substrate
BMAD and Micrantha converge on several autonomous-development mechanics, but differ in where context, identity, authority, durable state, repository truth, and evidence live.

From AI-Native SDLC to Governed Software Delivery

Oct 1, 2026 12:00AM
10 min read
2006 words
From AI-Native SDLC to Governed Software Delivery
The AI-native SDLC gets the bottleneck shift right. My own architecture pushes the idea further: generated artifacts are cheap, but trusted acceptance and authorized effects must remain explicit.

Git Is Becoming an Execution Surface

Apr 3, 2026 12:00AM
6 min read
1273 words
Git Is Becoming an Execution Surface
Git metadata now crosses execution boundaries in CI and agentic systems, turning familiar repository fields into potential code execution inputs.

Mobuild Envuscator and Digitalis

Mar 30, 2026 12:00PM
6 min read
1149 words
Mobuild Envuscator and Digitalis
Two beerware-minded tools for reducing mobile configuration risk: one by hardening what ships in the client, the other by hardening what the backend is willing to deliver.

Threat Modeling AI as an Engineering Coprocessor

Mar 8, 2026 3:56PM
10 min read
2103 words
Threat Modeling AI as an Engineering Coprocessor
A practical threat model for AI-assisted and agentic software development across requirements, architecture, implementation, testing, and operations.

Friday Frida Hacking Without the Why

Sep 6, 2022 12:00AM
7 min read
1285 words
A practical Frida walkthrough showing how Android runtime instrumentation changes client behavior and what that means for trust boundaries.

Man-in-the-Middle

Feb 18, 2021 11:18AM
6 min read
1105 words
A practical overview of MITM attacks, how they work on real networks, and the mitigations that actually matter.