This is a personal blog about information security, GRC, the software development lifecycle, mentorship, community building, judgment calls that don't fit a checklist, and inconvenient truths whenever they cross a certain inconvenience threshold. Open-source security is a recurring focus -- project health, secure development in the commons, and related craft. I write through the path I actually walked: systems and networks administration, SRE, DevOps, software development, and cybersecurity. Some posts are hands-on -- how we design, build, and ship securely. Others are reflective notes on craft, mentoring, and teams under pressure, or notes from events I visit and talks I give. Sometimes I write to untangle something for myself until the problem has a clearer shape. Take what helps, leave the rest.
Personal opinions only#
Unless a post is clearly labeled as a guest post (or otherwise attributes another author), everything published on this site -- including articles, code samples, diagrams, opinions, recommendations, and commentary -- reflects my personal views as an individual.
Those views do not represent, and should not be attributed to:
- any current or former employer
- any client, customer, or contractor relationship
- any open source project, foundation, working group, or community I contribute to or maintain
- any professional association, standards body, conference, or other organization I participate in
- any colleagues, collaborators, or third parties mentioned in passing
Affiliation with an organization does not imply endorsement by that organization of anything written here, and nothing here should be read as an official statement by any of them.
Guest posts#
If this site publishes guest content, it will be identified as such (for example in the title, byline, or an explicit notice on the page). Guest posts reflect the guest author's views, not mine, unless I state otherwise. Likewise, my own posts remain mine alone even when they discuss work done with others.
No professional advice#
Content on this site is provided for general informational and educational purposes. It is not legal, security, financial, compliance, or other professional advice. You are responsible for evaluating fitness for your own situation, including testing, review, and applicable policies at your organization.
Accuracy and change#
I aim to be careful and correct, but posts may contain mistakes, incomplete context, or ideas that I later revise. Software and practices change; treat older posts accordingly. Corrections or updates may appear in later revisions or follow-up posts.
AI and LLM usage#
I use AI-based tools (including large language models) as part of how I write on this site. Typical uses include:
- brainstorming and narrowing post ideas
- drafting and refining content
- grammar and wording help -- English is not my native language
I remain responsible for what gets published: I review, edit, and decide what stays. The judgment, experience, and mistakes are still mine. AI assistance does not change the authorship or "personal opinions" points above. Treat posts with the same critical eye you would any technical writing -- verify claims, test code, and do not treat generated or assisted text as authoritative advice.
Trademarks#
Product, company, and project names used on this site are trademarks of their respective owners. Use of those names does not imply affiliation with or endorsement by the trademark holders.
Questions#
If you need clarification about authorship or attribution for a specific post, reach out via the social links on this site or the About me page.