Two encrypted emails in twenty years
One of them was from me, testing it. I'd still publish the key, and the reason isn't cryptographic.

One of them was from me, testing it. I'd still publish the key, and the reason isn't cryptographic.

Opening a public marketplace for agent workflows meant publishing an attack surface, and then having to defend it from my own convenience.

A secret scanner failed a merge request over a test key and a documentation PEM that the change did not contain. Scoping a scan properly.

The philosophical end of the signing series: a stolen key and a bought one produce the same signature, and trust has to survive both.

Generate an asymmetric RSA-4096 signing key inside AWS KMS with no export path, then sign releases by calling kms:Sign instead of holding the key.

A checksum proves the bytes match the manifest, but says nothing about who wrote the manifest. Why self-update needs a signature instead.

The national vulnerability database is buckling under defunding and volume, which changes what a severity score is actually worth.

Signed but poisoned packages show a signature proves who sent something, not what is in it. Nobody is coming to clean this up for you.
