rmhrisk @rmhrisk.bsky.social · 18/09/2026There are now 370+ posts on the site across security, PKI, identity, cryptography, AI, compliance, and the occasional topic well outside those boundaries. 000
rmhrisk @rmhrisk.bsky.social · 18/09/2026There is also a recent piece, The Amnesia Cycle and Why AI Is Turning Developers Back Into Testers, about how AI is shifting software development from producing code toward judging generated output, and bringing some old testing disciplines back into focus. 110
rmhrisk @rmhrisk.bsky.social · 18/09/2026One recent example is The Verifier Never Showed Up, a long-form look at thirty years of digital identity programs, how they actually failed, and why adoption is usually decided by the part of the system nobody funds. 100
rmhrisk @rmhrisk.bsky.social · 18/09/2026I’ve made a few updates to unmitigatedrisk.com. I’ve added RSS, and I’ve started bringing my longer-form writing onto the site so it is easier to discover alongside the shorter posts. 100
rmhrisk @rmhrisk.bsky.social · 26/08/2026Think of this one as a field guide for all those countries and organizations making another run at these problems today: rmhrisk.github.io/verifier-nev...rmhrisk.github.ioThe Verifier Never Showed UpThree decades of digital identity systems, sorted by how they actually failed, and why the half of the system that decides adoption is the half nobody funds. 011
rmhrisk @rmhrisk.bsky.social · 26/08/2026Germany built a technically sound card and got none of the three, and the holder paid, in money and friction, for a credential whose benefits went to somebody else. Enrollment is not adoption.rmhrisk.github.ioThe Verifier Never Showed UpThree decades of digital identity systems, sorted by how they actually failed, and why the half of the system that decides adoption is the half nobody funds. 121
rmhrisk @rmhrisk.bsky.social · 26/08/2026Estonia got all three. It didn't build an identity system and go looking for uses. It built tax filing, prescriptions, and business registration, and made identity the way you reached them. 131
rmhrisk @rmhrisk.bsky.social · 26/08/2026Something the credential unlocked that people actually wanted. And a use frequent enough to become a habit, because a credential somebody was issued and a credential somebody carries are different things. 120
rmhrisk @rmhrisk.bsky.social · 26/08/2026Not one program in the set failed because the math was weak. What the failures were missing wasn't technical. It was three things, all outside the issuer's control. A verifier that already had a reason to verify. 120
rmhrisk @rmhrisk.bsky.social · 26/08/2026Thirty years of digital identity post-mortems and the cryptography was almost never the problem. I went back through the record. Germany put the eID function on 97% of cards and got 22% usage. The UK spent £233 million on Verify and shut it down. 132
rmhrisk @rmhrisk.bsky.social · 19/08/2026I started working in technology around 1993, in QA. More than thirty years later, AI is doing something I did not quite expect. It is turning software developers back into testers. unmitigatedrisk.com?p=1326unmitigatedrisk.comThe Amnesia Cycle and Why AI Is Turning Developers Back Into Testers | UNMITIGATED RISK 000
rmhrisk @rmhrisk.bsky.social · 17/08/2026The graduate is not the person with all the answers. It is the person who has become difficult to make helpless. unmitigatedrisk.com?p=1323unmitigatedrisk.comHurst University | UNMITIGATED RISK 030
rmhrisk @rmhrisk.bsky.social · 17/08/2026I was dyslexic and dysgraphic. My parents were told to prepare for the possibility I would never support myself. That prediction did not age well. The schools were not the education. The family was.unmitigatedrisk.comHurst University | UNMITIGATED RISK 110
rmhrisk @rmhrisk.bsky.social · 17/08/2026For as long as my kids can remember, I told them they are students at Hurst University. No campus. No accreditation. Enrollment is automatic when you join the family. Graduation is harder. There is one requirement. By the time you leave the house, you should be able to build a future for yourself. 100
Reposted by rmhriskrmhrisk @rmhrisk.bsky.social · 09/04/2026If that's your kind of thing, check it out. Everything runs client-side, no data leaves your browser. peculiarventures.github.io/cardforensics/peculiarventures.github.ioCardForensics 001
rmhrisk @rmhrisk.bsky.social · 14/08/2026rmhrisk.github.io/security-des...rmhrisk.github.ioSecurity Design Never ScaledTwo services, one bug, every instrument calling them identical. We scaled security's answers but never the reasoning behind them, and machine reasoning may finally change that. 020
rmhrisk @rmhrisk.bsky.social · 14/08/2026Take two systems with the exact same vulnerabilities. One loses its identity keys, the other doesn't. Yet every scanner, compliance checklist, and CVSS score will rate them exactly the same. We learned to scale security answers, but we never learned to scale the reasoning that produced them. 👇 120
Reposted by rmhriskSophie Schmieg @sophieschmieg.infosec.exchange.ap.brid.gy · 10/08/2026New blog post about cryptanalysis and AI bughunters.google.com/blog/more-cry… 22811
rmhrisk @rmhrisk.bsky.social · 10/08/2026So I decided to do another long-form technical field guide, this time on isolation and containment. I specifically talk what the different kinds of sandboxes actually protect, how they fail, and what it really takes to contain an "optimizer" like an AI agent. rmhrisk.github.io/containing-t...rmhrisk.github.ioContaining the OptimizerOne word, “sandbox,” has erased the distinctions between container, VM, confidential VM, and enclave — which is exactly how AI gets sold as secure and private. A field guide to what each primitive pro... 063
rmhrisk @rmhrisk.bsky.social · 10/08/2026We use sandbox as though it describes a security property. But a container, a VM, a confidential VM, and a enclave are very different things. They expose different surfaces, were designed for different adversaries, and make very different promises when something inside is actively trying to get out. 131
rmhrisk @rmhrisk.bsky.social · 10/08/2026Some of my more popular posts have focused on confidential computing, explaining TPMs, TEEs, secure enclaves, AI, and everything in between. With all the recent discussion about AI agents escaping "sandboxes," I realized there is a similar vocabulary problem here. 110
rmhrisk @rmhrisk.bsky.social · 07/08/2026Why Continuous Assurance Did Not Happen Until Now rmhrisk.github.io/continuous-a...rmhrisk.github.ioWhy Continuous Assurance Did Not Happen Until NowThe economics of cognition, the limits of GRC software, and what AI actually changes 000
rmhrisk @rmhrisk.bsky.social · 07/08/2026The Assurance Model Was Built for a World That No Longer Exists rmhrisk.github.io/assurance-mo...rmhrisk.github.ioThe Assurance Model Was Built for a World That No Longer ExistsHow periodic audit came to be, why its epistemic reach is shrinking, and what AI does to the mismatch 100
rmhrisk @rmhrisk.bsky.social · 07/08/2026We expanded the obligations, but the underlying assurance model remained largely the same. I’ve spent much of the last year thinking about why that is, where the model is beginning to fail, and what a different one might look like. I finally pulled that thinking together into two long-form pieces. 100
rmhrisk @rmhrisk.bsky.social · 07/08/2026For fifty years, systems became faster, larger, more interconnected, and harder for any one person to understand. Our response was to add audits, frameworks, controls, evidence, reports, certifications, regulators, and penalties. 100
rmhrisk @rmhrisk.bsky.social · 05/08/2026This is not just a crypto migration. It finally closes a decade-old compromise in Certificate Transparency, turning transparency from a post-issuance verification method into a verifiable issuance mechanism. rmhrisk.github.io/pq-webpki/rmhrisk.github.ioThe Post-Quantum WebPKIHow the Internet will decide which public keys to trust once signatures no longer fit on the wire 011
rmhrisk @rmhrisk.bsky.social · 05/08/2026The response is Merkle Tree Certificates. A CA logs certificates into its own Merkle tree and signs the tree head. Each certificate carries a short inclusion proof. One signature covers the batch; the proof is the path. 100
rmhrisk @rmhrisk.bsky.social · 05/08/2026Post-quantum signatures are too large for the classical model at web scale. A few hundred bytes of authentication material becomes many kilobytes, colliding with TCP congestion windows and other protocol limits. On many real connections the extra round trip costs more than the crypto itself. 100
rmhrisk @rmhrisk.bsky.social · 05/08/2026Yesterday I wrote about the classical WebPKI, the certificate chains, CAs, and governance we’ve used for three decades. Today’s piece is about what ultimately replaces it. 100
rmhrisk @rmhrisk.bsky.social · 04/08/2026what a certificate actually is, how trust is delegated, and why the governance layer matters more than most people realize.rmhrisk.github.ioA Deep Dive on the Classical WebPKI 011
rmhrisk @rmhrisk.bsky.social · 04/08/2026I found myself explaining the WebPKI a lot recently, so I decided to put together a long-form deep dive on what I have been calling the “classical WebPKI”, more on that in the post where I also explore things like... 101
rmhrisk @rmhrisk.bsky.social · 04/08/2026The WebPKI has two core structures that are not the same shape. One is essentially a cryptographic graph of signed delegations. The other is a governance framework of accountability. Almost every major failure in its history sits in the gap between them. 101
rmhrisk @rmhrisk.bsky.social · 11/07/2026Read the post: unmitigatedrisk.com?p=1291 FIPS 140-3 Corpus: rmhrisk.github.io/fips-140-3-c... #FIPS140 #FirmwareSecurity #PKIunmitigatedrisk.comThe Certification Ends Where the Code Begins | UNMITIGATED RISK 000
rmhrisk @rmhrisk.bsky.social · 11/07/2026The public record shows recurring patterns and gaps. Procurement and architecture teams should be pressing vendors hard on evidence, not just paper. 👇 100
rmhrisk @rmhrisk.bsky.social · 11/07/2026AI is accelerating discovery of these issues at scale, and the last decade of supply chain incidents has made one thing clear, third-party firmware risk is among the largest unaddressed threats in high-trust systems. 👇 100
rmhrisk @rmhrisk.bsky.social · 11/07/2026FIPS 140-3 validations give you a narrow, well-defined assurance boundary. But the real security story often lives in the code and dependencies just outside that boundary - bootloaders, firmware parsers, and the plumbing that actually feeds the crypto.👇 110
rmhrisk @rmhrisk.bsky.social · 02/06/2026Why textualism, original public meaning, and AI governance all turn on the same uncomfortable fact: intent does not travel unless it becomes part of the record. unmitigatedrisk.com?p=1266unmitigatedrisk.comThe Prompt Is the Meaning | UNMITIGATED RISK 010
rmhrisk @rmhrisk.bsky.social · 26/05/2026unmitigatedrisk.com?p=1247unmitigatedrisk.comA CA That Produces Evidence, Not Promises | UNMITIGATED RISK 020
rmhrisk @rmhrisk.bsky.social · 26/05/2026PQ is forcing every CA into a rebuild before 2029. The cheap version swaps the algorithms. The version worth doing fixes what audits and physical controls can't reach. unmitigatedrisk.com?p=1245 👇unmitigatedrisk.comA CA Built for the Threat Model We Actually Have | UNMITIGATED RISK 130
rmhrisk @rmhrisk.bsky.social · 26/05/2026We built the WebPKI around buildings, cages, ceremonies, HSMs, and audits. Most of the compromises we worry about now don't live in any of those places. 👇 121
rmhrisk @rmhrisk.bsky.social · 09/04/2026If that's your kind of thing, check it out. Everything runs client-side, no data leaves your browser. peculiarventures.github.io/cardforensics/peculiarventures.github.ioCardForensics 001
rmhrisk @rmhrisk.bsky.social · 09/04/2026One of the developers at Peculiar Ventures needed to debug some smart card APDU traces recently. I have enough trauma from the 90s and 2000s that I felt compelled to build an AI-annotated APDU trace analyzer. 120
rmhrisk @rmhrisk.bsky.social · 30/03/2026He was right. And we're doing it again. unmitigatedrisk.com?p=1227unmitigatedrisk.comWe Built It With Slide Rules. Then We Forgot How. | UNMITIGATED RISK 020
rmhrisk @rmhrisk.bsky.social · 30/03/2026Then he spent decades in our garage with a green chalkboard and his slide rule, trying to make sure I understood concepts like orbital decay, thrust, specific impulse, the rocket equation, and more, because he was convinced we were forgetting how to go to the moon.unmitigatedrisk.comWe Built It With Slide Rules. Then We Forgot How. | UNMITIGATED RISK 120
rmhrisk @rmhrisk.bsky.social · 30/03/2026My father learned rocket chemistry on a subsistence farm using stump remover and sugar. No kits. No experts. Just trial, error, and the stubborn belief that if it's broken, you fix it with what you have. He went on to have his name engraved on hardware that flew in orbit.unmitigatedrisk.comWe Built It With Slide Rules. Then We Forgot How. | UNMITIGATED RISK 140
rmhrisk @rmhrisk.bsky.social · 23/03/2026I’ll double check the numbers, right now it’s enumerating all CCADB json populated CRLs. Could be a bug though. 100
rmhrisk @rmhrisk.bsky.social · 22/03/2026The first version of the revocation analysis is now live on the site FWIW 100
rmhrisk @rmhrisk.bsky.social · 21/03/2026I have announced it on LinkedIn, Twitter, X, BlueSky, and noted it in my CA/Browser Forum presentation last week, but I do intend to announce on mdsp and the other public lists, but wanted to finish a few things, like that auditor page (now live) and the CRL checking (mostly done), before I do. 100
rmhrisk @rmhrisk.bsky.social · 17/03/2026The WebPKI is something we all rely on every day, and most people do not even know it exists. What is interesting is that even those who do often do not understand it as well as they think they do. To help more people understand how it works, I put together the WebPKI Observatory.webpki.systematicreasoning.comWebPKI Observatory — Certificate Authority Trust Ecosystem AnalysisQuantitative analysis of 96 trusted CAs: market share, concentration risk, compliance incidents, distrust history, and root program governance. Updated daily. 132