Representative Foreword

After the Code, the Structure Remains

The representative foreword of this blog: security now fails less at finding issues than at absorbing, sustaining, and acting on what has already been found.

This essay frames the entire site first. The posts on technical analysis, method, and governance all start from this same problem statement.

After the Code, the Structure Remains

Detection, Method, Governance

šŸ”„ A Mind That Dissects Systems

šŸ”„ Trust and Culture Beyond Technology

šŸ”„ Code That Fixes, Not Just Runs

There’s No Such Thing as a Free Lunch, But Security Was Free

The CVE system nearly collapsed in 2025. Who should fund public cybersecurity infrastructure when free-riding is no longer sustainable?

April 17, 2025 Ā· 3 min Ā· 478 words

In the AI Era, Employees Are Isolated and Organizations Thrive

A satirical critique of how AI-era organizations isolate employees through async workflows and data-driven control to suppress solidarity.

April 7, 2025 Ā· 2 min Ā· 317 words

The Place of Humans: Declaring the Creator’s Rights in the Age of AI

A philosophical essay on human authorship and creativity in the AI era, declaring the creator’s rights over machine-generated output.

April 3, 2025 Ā· 3 min Ā· 454 words Ā· windshock

Common Security Myths Developers Tell Themselves

Debunking developer security myths around responsibility deflection, tech overconfidence, and risk underestimation with real-world examples.

April 1, 2025 Ā· 3 min Ā· 507 words

How to Block ECH and Mitigate DoH in Enterprise Networks

A hands-on guide using dnsmasq to filter SVCB and HTTPS records for disabling ECH and enforcing central DNS policies. Notes that DoH requires separate network-layer policies.

March 31, 2025 Ā· 3 min Ā· 468 words

XML-RPC Security Vulnerabilities Analysis and Mitigation Strategies

Comprehensive analysis of XML-RPC security flaws including RCE, XXE, and DDoS, with mitigation strategies and a Python PoC exploit.

March 28, 2025 Ā· 4 min Ā· 692 words

Review of Citrix Security Policy Effectiveness

Citrix administrators apply security policies to each user’s VDI (Virtual Desktop Infrastructure) through Citrix Group Policy. However, certain structural vulnerabilities in Citrix CSE (Citrix Service Engine) and the Citrix VDI Agent allow for potential bypassing of these security policies.

November 5, 2024 Ā· 3 min Ā· 469 words

KPIs Can Cause Incidents!!!

Real cases where manipulated KPI metrics led to cybersecurity incidents, exposing the dangers of metric-driven security management.

June 20, 2024 Ā· 2 min Ā· 402 words

Common Misconceptions of Security Assessors

Three common misconceptions that weaken security assessments and strategies to build repeatable, effective vulnerability evaluation.

June 16, 2024 Ā· 3 min Ā· 550 words

Can Development Culture Influence Security Levels?

Exploring how development culture shapes code security, with practical examples using static analysis tools like Joern.

May 22, 2024 Ā· 5 min Ā· 952 words