SabunMacTavish

security against real adversaries, not ceremony

Hello, world

Most of what gets written about security is ceremony. Frameworks, maturity models, dashboards that measure how much process exists rather than whether an attacker would get in. This blog is the other thing.

I write about three overlapping areas:

A quick sanity check that code blocks render properly:

def defend(system, adversary):
    # ponytail: the only metric that counts
    return adversary.cost_to_compromise(system) > adversary.budget

Subscribe via RSS if you want the posts and nothing else.