Sign in

rmhrisk

@rmhrisk.bsky.social
420 followers 148 following 179 posts

Dropout. Father. I build things. Security, Cryptography, Engineering, Entrepreneurship. @peculiarventure + x-MSFT + x-GOOG ++. Also on @rmhrisk@infosec.exchange and twitter.com/rmhrisk

PostsRepliesMedia
rmhrisk @rmhrisk.bsky.social · 18/09/2026
I’ve made a few updates to unmitigatedrisk.com. I’ve added RSS, and I’ve started bringing my longer-form writing onto the site so it is easier to discover alongside the shorter posts.
100
rmhrisk @rmhrisk.bsky.social · 26/08/2026
Thirty years of digital identity post-mortems and the cryptography was almost never the problem. I went back through the record. Germany put the eID function on 97% of cards and got 22% usage. The UK spent £233 million on Verify and shut it down.
132
rmhrisk @rmhrisk.bsky.social · 19/08/2026
I started working in technology around 1993, in QA. More than thirty years later, AI is doing something I did not quite expect. It is turning software developers back into testers. unmitigatedrisk.com?p=1326
unmitigatedrisk.com
The Amnesia Cycle and Why AI Is Turning Developers Back Into Testers | UNMITIGATED RISK
000
rmhrisk @rmhrisk.bsky.social · 17/08/2026
For as long as my kids can remember, I told them they are students at Hurst University. No campus. No accreditation. Enrollment is automatic when you join the family. Graduation is harder. There is one requirement. By the time you leave the house, you should be able to build a future for yourself.
100
Reposted by rmhrisk
rmhrisk @rmhrisk.bsky.social · 09/04/2026
If that's your kind of thing, check it out. Everything runs client-side, no data leaves your browser. peculiarventures.github.io/cardforensics/
peculiarventures.github.io
CardForensics
001
rmhrisk @rmhrisk.bsky.social · 14/08/2026
Take two systems with the exact same vulnerabilities. One loses its identity keys, the other doesn't. Yet every scanner, compliance checklist, and CVSS score will rate them exactly the same. We learned to scale security answers, but we never learned to scale the reasoning that produced them. 👇
120
Reposted by rmhrisk
Sophie Schmieg @sophieschmieg.infosec.exchange.ap.brid.gy · 10/08/2026
New blog post about cryptanalysis and AI bughunters.google.com/blog/more-cry…
22811
rmhrisk @rmhrisk.bsky.social · 10/08/2026
Some of my more popular posts have focused on confidential computing, explaining TPMs, TEEs, secure enclaves, AI, and everything in between. With all the recent discussion about AI agents escaping "sandboxes," I realized there is a similar vocabulary problem here.
110
rmhrisk @rmhrisk.bsky.social · 07/08/2026
For fifty years, systems became faster, larger, more interconnected, and harder for any one person to understand. Our response was to add audits, frameworks, controls, evidence, reports, certifications, regulators, and penalties.
100
rmhrisk @rmhrisk.bsky.social · 05/08/2026
Yesterday I wrote about the classical WebPKI, the certificate chains, CAs, and governance we’ve used for three decades. Today’s piece is about what ultimately replaces it.
100
rmhrisk @rmhrisk.bsky.social · 04/08/2026
The WebPKI has two core structures that are not the same shape. One is essentially a cryptographic graph of signed delegations. The other is a governance framework of accountability. Almost every major failure in its history sits in the gap between them.
101
rmhrisk @rmhrisk.bsky.social · 11/07/2026
FIPS 140-3 validations give you a narrow, well-defined assurance boundary. But the real security story often lives in the code and dependencies just outside that boundary - bootloaders, firmware parsers, and the plumbing that actually feeds the crypto.👇
110
rmhrisk @rmhrisk.bsky.social · 02/06/2026
Why textualism, original public meaning, and AI governance all turn on the same uncomfortable fact: intent does not travel unless it becomes part of the record. unmitigatedrisk.com?p=1266
unmitigatedrisk.com
The Prompt Is the Meaning | UNMITIGATED RISK
010
rmhrisk @rmhrisk.bsky.social · 26/05/2026
We built the WebPKI around buildings, cages, ceremonies, HSMs, and audits. Most of the compromises we worry about now don't live in any of those places. 👇
121
rmhrisk @rmhrisk.bsky.social · 09/04/2026
One of the developers at Peculiar Ventures needed to debug some smart card APDU traces recently. I have enough trauma from the 90s and 2000s that I felt compelled to build an AI-annotated APDU trace analyzer.
120
rmhrisk @rmhrisk.bsky.social · 30/03/2026
My father learned rocket chemistry on a subsistence farm using stump remover and sugar. No kits. No experts. Just trial, error, and the stubborn belief that if it's broken, you fix it with what you have. He went on to have his name engraved on hardware that flew in orbit.
unmitigatedrisk.com
We Built It With Slide Rules. Then We Forgot How. | UNMITIGATED RISK
140
rmhrisk @rmhrisk.bsky.social · 17/03/2026
The WebPKI is something we all rely on every day, and most people do not even know it exists. What is interesting is that even those who do often do not understand it as well as they think they do. To help more people understand how it works, I put together the WebPKI Observatory.
webpki.systematicreasoning.com
WebPKI Observatory — Certificate Authority Trust Ecosystem Analysis
Quantitative analysis of 96 trusted CAs: market share, concentration risk, compliance incidents, distrust history, and root program governance. Updated daily.
132
rmhrisk @rmhrisk.bsky.social · 14/03/2026
Been thinking about PQC signatures in QR codes and started playing with what an MTC-like approach might look like. Demo URL: mta-qr.peculiarventures.com Repo URL: github.com/PeculiarVent... Includes Go and TypeScript implementations. Still just an experiment. Context: unmitigatedrisk.com?p=933
mta-qr.peculiarventures.com
MTA-QR · In-Browser Demo
210
rmhrisk @rmhrisk.bsky.social · 12/02/2026
There's a pattern that plays out across every regulated industry. Requirements increase. Complexity compounds. And instead of building capacity to meet the rising bar, organizations quietly lower the specificity of their commitments. ⬇️
120
Reposted by rmhrisk
Natalie Silvanovich @natashenka.bsky.social · 15/01/2026
Today, Project Zero released a 0-click exploit chain for the Pixel 9. While it targets the Pixel, the 0-click bug and exploit techniques we used apply to most other Android devices. projectzero.google/2026/01/pixe...
projectzero.google
A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby - Project Zero
Over the past few years, several AI-powered features have been added to mobile phones that allow users to better search and understand their messages. One ef...
15733
rmhrisk @rmhrisk.bsky.social · 16/01/2026
Short-lived and IP address certificates are now generally available from Let’s Encrypt. Modern infrastructure no longer has stable hostnames, static IPs, or long-lived trust anchors. Workloads spin up before DNS exists, live briefly, and disappear. Trust has to keep up. 👇
110
rmhrisk @rmhrisk.bsky.social · 24/12/2025
Enron passed their audits. Wirecard passed their audits. Every distrusted CA passed their audits. Auditors are paid to confirm compliance, not to find problems. When the measure becomes the target - and the measurer is incentivized to pass you - it stops measuring anything.
170
Reposted by rmhrisk
Filippo Valsorda @filippo.abyssdomain.expert · 24/12/2025
Really big age release coming tomorrow! 🎅🏻 - native post-quantum keys - built-in recipients for hw plugins - age-inspect tool - plugin framework - batchpass plugin - many improved error messages
age-encryption.org
GitHub - FiloSottile/age: A simple, modern and secure encryption tool (and Go library) with small explicit keys, no config options, and UNIX-style composability.
A simple, modern and secure encryption tool (and Go library) with small explicit keys, no config options, and UNIX-style composability. - FiloSottile/age
011723
rmhrisk @rmhrisk.bsky.social · 23/12/2025
PLCs on the internet -> MCP servers on the internet. Evolution happened. Learning didn’t. We’re rebuilding ICS - this time with agency!
020
rmhrisk @rmhrisk.bsky.social · 19/12/2025
Key Transparency is the unsung hero of E2E encryption, the essential but often overlooked until you're deep in implementation. @FiloSottile's been working on a transparency-log-based approach that's worth your attention: blog.transparency.dev/building-a-t...
blog.transparency.dev
Building a Transparent Keyserver
Today, we are going to build a keyserver to lookup age public keys. That part is boring. What’s interesting is that we’ll apply the same transparency log technology as the Go Checksum Database to keep the keyserver operator honest and unable to surre...
041
rmhrisk @rmhrisk.bsky.social · 05/12/2025
The GRANITE Act, which tries to rein in extraterritorial overreach in tech regulation, got me thinking.👇
100
rmhrisk @rmhrisk.bsky.social · 03/12/2025
Attestation, What It Really Proves and Why Everyone Is About to Care unmitigatedrisk.com?p=1114
unmitigatedrisk.com
Attestation, What It Really Proves and Why Everyone Is About to Care | UNMITIGATED RISK
042
Reposted by rmhrisk
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 07/11/2025
NEW: The U.S. Congressional Budget Office was hacked. @doublepulsar.com found that the cause may be an unpatched Cisco ASA firewall. I asked CBO about that but it did not respond to the question. techcrunch.com/2025/11/07/c...
techcrunch.com
Congressional Budget Office confirms it was hacked | TechCrunch
The congressional research office confirmed a breach, but did not comment on the cause. A security researcher suggested the hack may have originated because CBO failed to patch a firewall for more tha...
8192105
Reposted by rmhrisk
Lea Kissner @leak.bsky.social · 07/11/2025
I hired a director recently and this was my screening question: can you please explain the difference between public-key and symmetric-key cryptography. Virtually all the candidates, who universally claimed security engineering expertise of some kind (some cryptography-related) could not. At all.
15838
rmhrisk @rmhrisk.bsky.social · 26/10/2025
AI can lift human dignity by opening doors to more people and adapting to how we think, letting us focus on what matters. But only if we design it right and keep monitoring its work. 👇
100
Reposted by rmhrisk
Andy Greenberg @agreenberg.bsky.social · 14/10/2025
Researchers pointed a satellite dish at the sky for 3 years and monitored what unencrypted data it picked up. The results were shocking: They obtained thousands of T-Mobile users' phone calls and texts, military and law enforcement secrets, much more: www.wired.com/story/satell... 🧵👇
wired.com
Satellites Are Leaking the World’s Secrets: Calls, Texts, Military and Corporate Data
With just $800 in basic equipment, researchers found a stunning variety of data—including thousands of T-Mobile users’ calls and texts and even US military communications—sent by satellites unencrypte...
20884453
rmhrisk @rmhrisk.bsky.social · 03/09/2025
This morning, a serious WebPKI incident surfaced: a tiny CA misissued certificates for 1.1.1.1 - Cloudflare’s DNS service. With BGP hijacks happening regularly, those certs could enable full man-in-the-middle attacks. 👇
130
rmhrisk @rmhrisk.bsky.social · 03/09/2025
Looks like something is up in Whoville. It seems an obscure CA trusted by Microsoft has issued a certificate for 1.1.1.1. groups.google.com/a/mozilla.or...
groups.google.com
Incident Report: Mis-issued Certificates for SAN iPAddress:1.1.1.1 by Fina RDC 2020
020
Reposted by rmhrisk
Matt Blaze @mattblaze.org · 21/08/2025
Prof. Michael Specter on practical vulnerabilities in deployed mobile voting systems. www.youtube.com/watch?v=_BgA... #VotingVillage
youtube.com
17 Specter -- It's Not Safe Yet; Online Voting in Practice vv25 d2s8
YouTube video by Voting Village @ DEF CON
1164
rmhrisk @rmhrisk.bsky.social · 22/08/2025
Big milestone for email security. CA/Browser Forum just published S/MIME BR v1.0.11. Now with NIST-approved post-quantum algorithms (ML-DSA & ML-KEM). Quantum-resistant S/MIME is here. 👇
131
rmhrisk @rmhrisk.bsky.social · 22/08/2025
Building on the great research by Cem Paya and Matthew Ludwigs at River Financial, my new post details how attackers are exploiting fundamental assumptions in Microsoft's code signing. 👇
100
rmhrisk @rmhrisk.bsky.social · 15/08/2025
With Authenticode & CA/B Forum–compliant code signing, intent ≠ immunity. The Baseline Requirements define revocation conditions based on use in the wild, not the developer’s intent. Ship signed code? Design it to resist abuse — attackers can weaponize your trust, and your cert can be pulled.
000
rmhrisk @rmhrisk.bsky.social · 15/08/2025
The "Invitation Is All You Need" attack: AI agent poisoned through calendar, executed malicious commands days later. AI agents persist memory across sessions, and static credentials become persistent threats. 👇
100
rmhrisk @rmhrisk.bsky.social · 10/08/2025
One of the best parts of Black Hat is the hallway track. This week, I got to watch some great talks with friends, and one reminded me of a common pattern, the innovation–security debt cycle: 1️⃣ Rush to ship 2️⃣ Debt builds 3️⃣ Incident forces change 4️⃣ Security becomes a differentiator 👇
110
rmhrisk @rmhrisk.bsky.social · 09/08/2025
In the 1960s: "Don't have kids, the world will starve." Today: "Don't learn to code, AI will do it all." Both predictions ignore the same truth, when there's money to be made, markets adapt faster than doomsday forecasters expect. 👇
100
rmhrisk @rmhrisk.bsky.social · 25/07/2025
We build systems to make things easier. But too often, what we call “automation” ends up feeling like digital red tape, frustrating, rigid, and impossible to reason with. 👇
110
rmhrisk @rmhrisk.bsky.social · 17/07/2025
From dropping tables to jailbreaking GPTs, some kids just never change. Meet Little Bobby Prompts. 😂
010
rmhrisk @rmhrisk.bsky.social · 17/07/2025
The biggest digital identity experiment in U.S. history wasn’t planned; it was a side effect of pandemic-era fraud. Now that Apple and Google are standardizing digital ID in wallets, we’re about to find out if market pressure can succeed where government urgency failed. 👇
100
rmhrisk @rmhrisk.bsky.social · 25/06/2025
As a recovering security engineer, I recognize threat modeling anywhere. Lawyers do it constantly - they're security engineers for text. So why does legal AI treat them like secretaries? 👇
100
rmhrisk @rmhrisk.bsky.social · 16/06/2025
450,000+ certificates are issued every hour across the WebPKI. But raw volume doesn't tell you which CAs actually matter. Matthew McPherrin recently shared Mozilla's Firefox telemetry data showing actual CA usage vs the Certificate Transparency issuance numbers I usually track. 👇
140
rmhrisk @rmhrisk.bsky.social · 16/06/2025
For decades, companies shipped their structure. Now a solo founder with AI agents for product, marketing, development and support can move faster than entire teams. No org chart means no internal drag. 👇
220
rmhrisk @rmhrisk.bsky.social · 15/06/2025
A WebTrust seal is often marketed by CAs as a gold star, but in reality, it simply confirms they’ve met the minimum bar. The accounting style audit model was never designed to surface hidden security gaps, and its incentives can even reward looking the other way. 👇
110
rmhrisk @rmhrisk.bsky.social · 13/06/2025
Classic moral hazard problem in internet infrastructure: Those making critical security decisions don't face the consequences when things go wrong. Meanwhile, 8 billion users bear all the risks. This misalignment creates predictable problems across any system at scale. 👇
141
rmhrisk @rmhrisk.bsky.social · 08/06/2025
The future of web trust isn't weaker enforcement. It's making the CPS the living, automated center of CA operations. Policy must drive practice, not just scramble to document it. The security of 8 billion people depends on it. #WebPKI groups.google.com/a/mozilla.or...
groups.google.com
Results of 2025 Roundtable Discussion
010
rmhrisk @rmhrisk.bsky.social · 05/06/2025
My kids are going to grow up thinking “Shit My Dad Says” was mostly just t-shirts about cryptography, root access, malware, and accountability in Git. And… they’ll be right.
020