I study application internals, review code, and trace requests across authentication, data, and privilege boundaries. My work turns unsafe behavior into practical fixes: tighter capabilities, explicit authorization, atomic updates, and verified transport.
Here I share what I learn from systems I operate, with source-level explanations, working examples, and patch patterns other developers can use.
Research repositories: Homelab security · Application security · Desktop security.
Found an error in an article or a vulnerability in my code? Report it privately through GitHub security advisories.