10 of 10 published
New instalments appear here as they are released.
Where cryptography replaces institutional assurance with independently checkable constraints, and where its guarantees stop.
New instalments appear here as they are released.
This series examines the difference between a claim that must be trusted and a property that can be checked. It follows that distinction through encryption, key custody, hardware security, software provenance, and the practical assessment of vendor claims.
Most organisational trust rests on promises: contracts, certifications, and terms of service. Cryptography offers something different — guarantees that hold regardless of whether anyone keeps their word.
Read articleEnd-to-end encryption has become a marketing checkbox. A careful look at what the term means, the conditions under which the guarantee holds, and the considerable territory it leaves uncovered.
Read articleEncryption at rest, encryption in transit, customer-managed keys, HSMs, BYOK — the terminology multiplies, but a single question cuts through all of it: who can use the keys without your participation?
Read articleThe quantum threat to today's encryption is real, slow-moving, and unusually well signposted. A sober account of harvest-now-decrypt-later, the new NIST standards, and what actually to do this year.
Read articleZero-knowledge proofs let one party prove a statement is true without revealing why. The mathematics is sound, the applications are real, and the marketing has rather got ahead of both.
Read articleSecure enclaves, TEEs, StrongBox, TPMs, HSMs – the vocabulary of hardware security is everywhere, and the differences between the things it names are material. So what does hardware-backed key storage really provide, and where are its limits?
Read articleEncrypt every message perfectly and an observer still learns who talks to whom, when, how often, and from where. Why metadata is frequently the more valuable intelligence, and what can and cannot be done about it.
Read articleSoftware supply chain security has run for decades on vendor assurance — questionnaires, attestations, and hope. A quieter movement is replacing assertion with cryptographic verification: signing, transparency logs, SBOMs, and reproducible builds.
Read articleSoftware agents now research suppliers, compare products, and execute transactions on their principals' behalf. The trust infrastructure of the web was built for humans reading pages. What replaces it is being decided now — and it is cryptographic.
Read articleSecurity marketing has a dialect, and learning to read it is a procurement skill. A field guide to vendor cryptography claims: which phrases carry information, which carry none, and the questions that sort one from the other.
Read article