Skip to content
Security Notes

Security Notes

Practical write-ups on application security, threat modelling and defensive engineering, for people who ship software.

All posts

Device code phishing against Microsoft 365

12 min read

All images verified. I have enough from primary sources Microsoft, Volexity, RFC 8628, Microsoft Learn, Huntress/Unit 42 reporting . Writing the post now. A…

What a bug bounty actually pays per hour

12 min read

The Write tool is disabled, and the task is to return the post itself. Here it is: The headline number, and the number underneath it In March 2019, a 19 year…

NIS2 and DORA in practice for EU companies

11 min read

The morning the four hour clock started At 17:00 on a Tuesday, a payments processor serving several mid sized European banks notices that transactions are…

Breaking into security without a degree

10 min read

The paradox at the front door In the summer of 2025, a mid sized managed security provider posted an opening for an "entry level SOC analyst." The listing…

Timing side channels explained in fifty lines

13 min read

The sixteen cycles that broke TLS In early 2013, Adam Langley measured how long OpenSSL took to reject a corrupted TLS record. When the record claimed a large…

How ransomware negotiation actually works

11 min read

The eight hour conversation nobody wants to have Somewhere right now, in a chat window that looks a lot like a retail help desk, a stranger is typing to a…