Responsible disclosures
Reports and postmortems after a fix or disclosure window. The useful part is not the screenshot; it is the trust assumption that failed.
hej hej — it’s benevolent
Most days I’m turning messy manufacturing and business processes into software: ERP workflows, internal tools, automations, and interfaces that people can use without fighting them. That is the builder half.
The other half notices when something does not add up - a portal trusting public information, a strange transaction trail, an internet puzzle, or a product decision that feels needlessly broken. I studied cybersecurity, but I care less about sounding like a “security person” than finding the actual failure mode and explaining it clearly.
This is where I publish vulnerability disclosures once they are safe to discuss, notes from things I build, investigations that consumed more time than intended, and the occasional rant.
Currently losing time to: ERPNext, public-facing portals, Bitcoin puzzles, and whatever looked harmless five minutes ago.
what I actually write about
Reports and postmortems after a fix or disclosure window. The useful part is not the screenshot; it is the trust assumption that failed.
ERP workflows, internal consoles, automation, product experiments, and the unglamorous machinery that makes operations work.
Strong opinions, half-resolved questions, internet oddities, and occasional essays written because keeping quiet felt less useful.
latest notes
I report before I publish. Vulnerability details go public after remediation or a reasonable disclosure window. Credentials, personal data, and details that create avoidable risk stay out.