Skip to content

Writing

All writing

Long-form essays on identity, AI security, CIAM, Generative Engine Optimization, and the practice of building software. 584 pieces, newest first.

Latest essay

Mobile Security

eSIM vs iSIM vs SIM: Which Is Actually More Secure?

"Is eSIM safer than a physical SIM?" has a more interesting answer than most articles give. Each SIM type, physical, eSIM, and iSIM, has a different architecture and a different attack surface. Here is how they actually work and which is genuinely more secure.

Read the article
AI (Artificial Intelligence)

LLM vs SLM: What They Are, How They Work, and When to Use Each

Large language models get the headlines, but small language models are quietly winning most real enterprise workloads on cost, speed, and privacy. Here is what SLMs actually are, how they work, and a clear framework for choosing between an SLM and an LLM.

Cybersecurity

What to Do When You Receive a Bug Bounty Email

A stranger emails saying they found a security hole in your site and would like a reward. Is it a genuine researcher, a low-effort "beg bounty," or extortion? Here is how to tell the difference and exactly what to do and not do.

Cybersecurity

How You Actually Secure Systems: Using OWASP and NIST Together

OWASP and NIST get mentioned in the same breath, but they answer different questions. One tells you what to fix in your code; the other tells you how to run a security program. Here is what each framework actually does and how to use them together.

Cybersecurity

How to Prevent a Data Breach: A Practical Playbook

Most data breaches don't come from sophisticated zero-day attacks. They come from stolen credentials, misconfigurations, and unpatched systems. Here is a practical, prioritized playbook for preventing the breaches that actually happen.