5 of 5 published
New instalments appear here as they are released.
The security decisions behind Signet: vault sessions, hardware boundaries, backup formats, threat modelling, and claims that can be checked.
New instalments appear here as they are released.
These notes document decisions made while building Signet, the Attomus authenticator for iOS and Android. They cover the points where security properties depend on precise boundaries rather than reassuring language.
The real trade-off between live TOTP lists, per-use authentication, and vault design.
Read articleAndroid can attest RSA and EC keys, but AES keys are different. Here is what the Keystore can prove, what it cannot, and how to design around that boundary.
Read articleA backup format is more than ciphertext. Signet's 28-byte header makes each backup self-describing, upgradeable, and tamper-evident without hiding the parameters needed to derive its key.
Read articleThreat modelling becomes useful when it challenges a design the team already believes in. What Signet's STRIDE review changed, what it left exposed, and why rejected controls belong in the record.
Read articleVague security language trains buyers to accept confidence instead of evidence. Why familiar claims fail, what precise product security communication looks like, and how vendors can make scrutiny possible.
Read article