Security & offense
Defensive mindset, attacker psychology, what the cert grind teaches, conference reflections, the gap between studying security and doing it.
I write to think — about security, systems, the people building them, and the parts of engineering nobody puts in the documentation. This isn't a blog. It's a notebook with the cover off.
The fastest way to find out you don't actually understand something is to try to write it down. The fastest way to figure it out is to keep writing until the sentences make sense. That's the loop.
Most of what I post here started as a Slack message I couldn't send in three lines, a journal entry I didn't want to lose, or a 2am realization that wouldn't let me sleep. If it survives the editing pass, it shows up here.
Five recurring obsessions. Most posts touch at least two of them.
Defensive mindset, attacker psychology, what the cert grind teaches, conference reflections, the gap between studying security and doing it.
How real infrastructure breaks. Cascading failures. Why incentives shape architecture more than architects do. The boring stuff that runs everything.
Code as communication. Working under real constraints. What MSP work, KARE, and AC4S taught me that no tutorial would. The unglamorous half of shipping.
Gym, sleep, focus, training as emotional regulation. How body work translates into work-work. The case for treating health as infrastructure.
Games as systems. Mentorship and the people who shaped me. Conference reflections. The reading list. The "why does this exist" of weird things on the internet.
The hardest part of becoming a serious engineer isn't the code. It's the patience to keep showing up when nothing's clicking yet.
Most recent first. Click any card to read.
A year ago, my life mostly consisted of solving tickets, studying for certifications, lifting weights, and trying to figure out where I actually fit into