Written to support decisions, not just fill a blog
Attomus shares practical insight on resilience, technology delivery, specialist security, and operational risk.
Practical Attomus insight on cybersecurity, programme delivery, operational risk, and related issues in demanding environments.
Attomus shares practical insight on resilience, technology delivery, specialist security, and operational risk.
Every organisation runs on software it did not write, built by people it has never met, assembled from components those people did not write either. The traditional governance answer to this uncomfortable arrangement is the supplier-assurance process: questionnaires, certifications, contractual flow-downs, and an …
Read articleThreat modelling has a reputation problem. Ask a developer what a threat model is and you tend to get one of two answers. The first: an architectural diagram with threat labels, produced during design and never looked at again. The second: the section of a compliance document everyone writes carefully and nobody reads, …
Read articleMichael Hayden – the only person to have run both the NSA and the CIA – told a 2014 debate at Johns Hopkins, “We kill people based on metadata.” The line was not a boast about breaking encryption. It was the opposite point: for a great many purposes, nobody needs to. The earlier posts in this series looked at what …
Read articleThe backup format for an authenticator app looks like a solved problem. Encrypt the secrets with a passphrase, write the ciphertext to a file, done. It is not done. The naive version fails silently in several distinct ways, and the worst of them leaves a user holding a file that will never decrypt again, reporting an …
Read article“Hardware-backed” is among the most widely used and least interrogated phrases in security. At its best it names a specific and valuable protection: a small, deliberately limited piece of hardware that holds cryptographic keys and will not surrender them, even to software that has otherwise taken over the machine. At …
Read article