Sign in

rmhrisk

@rmhrisk.bsky.social
420 followers 148 following 179 posts

Dropout. Father. I build things. Security, Cryptography, Engineering, Entrepreneurship. @peculiarventure + x-MSFT + x-GOOG ++. Also on @rmhrisk@infosec.exchange and twitter.com/rmhrisk

PostsRepliesMedia
rmhrisk @rmhrisk.bsky.social · 18/09/2026
There are now 370+ posts on the site across security, PKI, identity, cryptography, AI, compliance, and the occasional topic well outside those boundaries.
000
rmhrisk @rmhrisk.bsky.social · 18/09/2026
There is also a recent piece, The Amnesia Cycle and Why AI Is Turning Developers Back Into Testers, about how AI is shifting software development from producing code toward judging generated output, and bringing some old testing disciplines back into focus.
110
rmhrisk @rmhrisk.bsky.social · 18/09/2026
One recent example is The Verifier Never Showed Up, a long-form look at thirty years of digital identity programs, how they actually failed, and why adoption is usually decided by the part of the system nobody funds.
100
rmhrisk @rmhrisk.bsky.social · 18/09/2026
I’ve made a few updates to unmitigatedrisk.com. I’ve added RSS, and I’ve started bringing my longer-form writing onto the site so it is easier to discover alongside the shorter posts.
100
rmhrisk @rmhrisk.bsky.social · 26/08/2026
Think of this one as a field guide for all those countries and organizations making another run at these problems today: rmhrisk.github.io/verifier-nev...
rmhrisk.github.io
The Verifier Never Showed Up
Three decades of digital identity systems, sorted by how they actually failed, and why the half of the system that decides adoption is the half nobody funds.
011
rmhrisk @rmhrisk.bsky.social · 26/08/2026
Germany built a technically sound card and got none of the three, and the holder paid, in money and friction, for a credential whose benefits went to somebody else. Enrollment is not adoption.
rmhrisk.github.io
The Verifier Never Showed Up
Three decades of digital identity systems, sorted by how they actually failed, and why the half of the system that decides adoption is the half nobody funds.
121
rmhrisk @rmhrisk.bsky.social · 26/08/2026
Estonia got all three. It didn't build an identity system and go looking for uses. It built tax filing, prescriptions, and business registration, and made identity the way you reached them.
131
rmhrisk @rmhrisk.bsky.social · 26/08/2026
Something the credential unlocked that people actually wanted. And a use frequent enough to become a habit, because a credential somebody was issued and a credential somebody carries are different things.
120
rmhrisk @rmhrisk.bsky.social · 26/08/2026
Not one program in the set failed because the math was weak. What the failures were missing wasn't technical. It was three things, all outside the issuer's control. A verifier that already had a reason to verify.
120
rmhrisk @rmhrisk.bsky.social · 26/08/2026
Thirty years of digital identity post-mortems and the cryptography was almost never the problem. I went back through the record. Germany put the eID function on 97% of cards and got 22% usage. The UK spent £233 million on Verify and shut it down.
132
rmhrisk @rmhrisk.bsky.social · 19/08/2026
I started working in technology around 1993, in QA. More than thirty years later, AI is doing something I did not quite expect. It is turning software developers back into testers. unmitigatedrisk.com?p=1326
unmitigatedrisk.com
The Amnesia Cycle and Why AI Is Turning Developers Back Into Testers | UNMITIGATED RISK
000
rmhrisk @rmhrisk.bsky.social · 17/08/2026
The graduate is not the person with all the answers. It is the person who has become difficult to make helpless. unmitigatedrisk.com?p=1323
unmitigatedrisk.com
Hurst University | UNMITIGATED RISK
030
rmhrisk @rmhrisk.bsky.social · 17/08/2026
I was dyslexic and dysgraphic. My parents were told to prepare for the possibility I would never support myself. That prediction did not age well. The schools were not the education. The family was.
unmitigatedrisk.com
Hurst University | UNMITIGATED RISK
110
rmhrisk @rmhrisk.bsky.social · 17/08/2026
For as long as my kids can remember, I told them they are students at Hurst University. No campus. No accreditation. Enrollment is automatic when you join the family. Graduation is harder. There is one requirement. By the time you leave the house, you should be able to build a future for yourself.
100
Reposted by rmhrisk
rmhrisk @rmhrisk.bsky.social · 09/04/2026
If that's your kind of thing, check it out. Everything runs client-side, no data leaves your browser. peculiarventures.github.io/cardforensics/
peculiarventures.github.io
CardForensics
001
rmhrisk @rmhrisk.bsky.social · 14/08/2026
rmhrisk.github.io/security-des...
rmhrisk.github.io
Security Design Never Scaled
Two services, one bug, every instrument calling them identical. We scaled security's answers but never the reasoning behind them, and machine reasoning may finally change that.
020
rmhrisk @rmhrisk.bsky.social · 14/08/2026
Take two systems with the exact same vulnerabilities. One loses its identity keys, the other doesn't. Yet every scanner, compliance checklist, and CVSS score will rate them exactly the same. We learned to scale security answers, but we never learned to scale the reasoning that produced them. 👇
120
Reposted by rmhrisk
Sophie Schmieg @sophieschmieg.infosec.exchange.ap.brid.gy · 10/08/2026
New blog post about cryptanalysis and AI bughunters.google.com/blog/more-cry…
22811
rmhrisk @rmhrisk.bsky.social · 10/08/2026
So I decided to do another long-form technical field guide, this time on isolation and containment. I specifically talk what the different kinds of sandboxes actually protect, how they fail, and what it really takes to contain an "optimizer" like an AI agent. rmhrisk.github.io/containing-t...
rmhrisk.github.io
Containing the Optimizer
One word, “sandbox,” has erased the distinctions between container, VM, confidential VM, and enclave — which is exactly how AI gets sold as secure and private. A field guide to what each primitive pro...
063
rmhrisk @rmhrisk.bsky.social · 10/08/2026
We use sandbox as though it describes a security property. But a container, a VM, a confidential VM, and a enclave are very different things. They expose different surfaces, were designed for different adversaries, and make very different promises when something inside is actively trying to get out.
131
rmhrisk @rmhrisk.bsky.social · 10/08/2026
Some of my more popular posts have focused on confidential computing, explaining TPMs, TEEs, secure enclaves, AI, and everything in between. With all the recent discussion about AI agents escaping "sandboxes," I realized there is a similar vocabulary problem here.
110
rmhrisk @rmhrisk.bsky.social · 07/08/2026
Why Continuous Assurance Did Not Happen Until Now rmhrisk.github.io/continuous-a...
rmhrisk.github.io
Why Continuous Assurance Did Not Happen Until Now
The economics of cognition, the limits of GRC software, and what AI actually changes
000
rmhrisk @rmhrisk.bsky.social · 07/08/2026
The Assurance Model Was Built for a World That No Longer Exists rmhrisk.github.io/assurance-mo...
rmhrisk.github.io
The Assurance Model Was Built for a World That No Longer Exists
How periodic audit came to be, why its epistemic reach is shrinking, and what AI does to the mismatch
100
rmhrisk @rmhrisk.bsky.social · 07/08/2026
We expanded the obligations, but the underlying assurance model remained largely the same. I’ve spent much of the last year thinking about why that is, where the model is beginning to fail, and what a different one might look like. I finally pulled that thinking together into two long-form pieces.
100
rmhrisk @rmhrisk.bsky.social · 07/08/2026
For fifty years, systems became faster, larger, more interconnected, and harder for any one person to understand. Our response was to add audits, frameworks, controls, evidence, reports, certifications, regulators, and penalties.
100
rmhrisk @rmhrisk.bsky.social · 05/08/2026
This is not just a crypto migration. It finally closes a decade-old compromise in Certificate Transparency, turning transparency from a post-issuance verification method into a verifiable issuance mechanism. rmhrisk.github.io/pq-webpki/
rmhrisk.github.io
The Post-Quantum WebPKI
How the Internet will decide which public keys to trust once signatures no longer fit on the wire
011
rmhrisk @rmhrisk.bsky.social · 05/08/2026
The response is Merkle Tree Certificates. A CA logs certificates into its own Merkle tree and signs the tree head. Each certificate carries a short inclusion proof. One signature covers the batch; the proof is the path.
100
rmhrisk @rmhrisk.bsky.social · 05/08/2026
Post-quantum signatures are too large for the classical model at web scale. A few hundred bytes of authentication material becomes many kilobytes, colliding with TCP congestion windows and other protocol limits. On many real connections the extra round trip costs more than the crypto itself.
100
rmhrisk @rmhrisk.bsky.social · 05/08/2026
Yesterday I wrote about the classical WebPKI, the certificate chains, CAs, and governance we’ve used for three decades. Today’s piece is about what ultimately replaces it.
100
rmhrisk @rmhrisk.bsky.social · 04/08/2026
what a certificate actually is, how trust is delegated, and why the governance layer matters more than most people realize.
rmhrisk.github.io
A Deep Dive on the Classical WebPKI
011
rmhrisk @rmhrisk.bsky.social · 04/08/2026
I found myself explaining the WebPKI a lot recently, so I decided to put together a long-form deep dive on what I have been calling the “classical WebPKI”, more on that in the post where I also explore things like...
101
rmhrisk @rmhrisk.bsky.social · 04/08/2026
The WebPKI has two core structures that are not the same shape. One is essentially a cryptographic graph of signed delegations. The other is a governance framework of accountability. Almost every major failure in its history sits in the gap between them.
101
rmhrisk @rmhrisk.bsky.social · 11/07/2026
Read the post: unmitigatedrisk.com?p=1291 FIPS 140-3 Corpus: rmhrisk.github.io/fips-140-3-c... #FIPS140 #FirmwareSecurity #PKI
unmitigatedrisk.com
The Certification Ends Where the Code Begins | UNMITIGATED RISK
000
rmhrisk @rmhrisk.bsky.social · 11/07/2026
The public record shows recurring patterns and gaps. Procurement and architecture teams should be pressing vendors hard on evidence, not just paper. 👇
100
rmhrisk @rmhrisk.bsky.social · 11/07/2026
AI is accelerating discovery of these issues at scale, and the last decade of supply chain incidents has made one thing clear, third-party firmware risk is among the largest unaddressed threats in high-trust systems. 👇
100
rmhrisk @rmhrisk.bsky.social · 11/07/2026
FIPS 140-3 validations give you a narrow, well-defined assurance boundary. But the real security story often lives in the code and dependencies just outside that boundary - bootloaders, firmware parsers, and the plumbing that actually feeds the crypto.👇
110
rmhrisk @rmhrisk.bsky.social · 02/06/2026
Why textualism, original public meaning, and AI governance all turn on the same uncomfortable fact: intent does not travel unless it becomes part of the record. unmitigatedrisk.com?p=1266
unmitigatedrisk.com
The Prompt Is the Meaning | UNMITIGATED RISK
010
rmhrisk @rmhrisk.bsky.social · 26/05/2026
unmitigatedrisk.com?p=1247
unmitigatedrisk.com
A CA That Produces Evidence, Not Promises | UNMITIGATED RISK
020
rmhrisk @rmhrisk.bsky.social · 26/05/2026
PQ is forcing every CA into a rebuild before 2029. The cheap version swaps the algorithms. The version worth doing fixes what audits and physical controls can't reach. unmitigatedrisk.com?p=1245 👇
unmitigatedrisk.com
A CA Built for the Threat Model We Actually Have | UNMITIGATED RISK
130
rmhrisk @rmhrisk.bsky.social · 26/05/2026
We built the WebPKI around buildings, cages, ceremonies, HSMs, and audits. Most of the compromises we worry about now don't live in any of those places. 👇
121
rmhrisk @rmhrisk.bsky.social · 09/04/2026
If that's your kind of thing, check it out. Everything runs client-side, no data leaves your browser. peculiarventures.github.io/cardforensics/
peculiarventures.github.io
CardForensics
001
rmhrisk @rmhrisk.bsky.social · 09/04/2026
One of the developers at Peculiar Ventures needed to debug some smart card APDU traces recently. I have enough trauma from the 90s and 2000s that I felt compelled to build an AI-annotated APDU trace analyzer.
120
rmhrisk @rmhrisk.bsky.social · 30/03/2026
He was right. And we're doing it again. unmitigatedrisk.com?p=1227
unmitigatedrisk.com
We Built It With Slide Rules. Then We Forgot How. | UNMITIGATED RISK
020
rmhrisk @rmhrisk.bsky.social · 30/03/2026
Then he spent decades in our garage with a green chalkboard and his slide rule, trying to make sure I understood concepts like orbital decay, thrust, specific impulse, the rocket equation, and more, because he was convinced we were forgetting how to go to the moon.
unmitigatedrisk.com
We Built It With Slide Rules. Then We Forgot How. | UNMITIGATED RISK
120
rmhrisk @rmhrisk.bsky.social · 30/03/2026
My father learned rocket chemistry on a subsistence farm using stump remover and sugar. No kits. No experts. Just trial, error, and the stubborn belief that if it's broken, you fix it with what you have. He went on to have his name engraved on hardware that flew in orbit.
unmitigatedrisk.com
We Built It With Slide Rules. Then We Forgot How. | UNMITIGATED RISK
140
rmhrisk @rmhrisk.bsky.social · 23/03/2026
Found issue. Should be fixed in the AM. Thanks.
010
rmhrisk @rmhrisk.bsky.social · 23/03/2026
I’ll double check the numbers, right now it’s enumerating all CCADB json populated CRLs. Could be a bug though.
100
rmhrisk @rmhrisk.bsky.social · 22/03/2026
The first version of the revocation analysis is now live on the site FWIW
100
rmhrisk @rmhrisk.bsky.social · 21/03/2026
I have announced it on LinkedIn, Twitter, X, BlueSky, and noted it in my CA/Browser Forum presentation last week, but I do intend to announce on mdsp and the other public lists, but wanted to finish a few things, like that auditor page (now live) and the CRL checking (mostly done), before I do.
100
rmhrisk @rmhrisk.bsky.social · 17/03/2026
The WebPKI is something we all rely on every day, and most people do not even know it exists. What is interesting is that even those who do often do not understand it as well as they think they do. To help more people understand how it works, I put together the WebPKI Observatory.
webpki.systematicreasoning.com
WebPKI Observatory — Certificate Authority Trust Ecosystem Analysis
Quantitative analysis of 96 trusted CAs: market share, concentration risk, compliance incidents, distrust history, and root program governance. Updated daily.
132