// blog
notes & write-ups
Security research, CTF solutions, music production breakdowns, and whatever else is worth writing down.
2025-05-12
8 min
Breaking JWT Auth Misconfigurations in the Wild
securityA deep-dive into the most common JWT implementation mistakes I encounter during engagements — algorithm confusion attacks, weak secrets, and missing validation.
2025-04-28
12 min
Reverse Engineering a Proprietary IoT Protocol
reHow I dissected an undocumented binary protocol from a smart home device using Ghidra and Wireshark, ultimately finding an unauthenticated RCE.
2025-04-03
6 min
The Science of 808 Tuning (and Why Most Producers Get It Wrong)
musicBreaking down the physics of sub-bass, why key detection matters, and the workflow I use to tune 808s so they sit perfectly in a mix.
2025-03-19
15 min
CTF Write-up: HTB CyberMonster (Pwn + Crypto Chain)
ctfFull write-up for the HackTheBox CyberMonster challenge — format string exploitation chained with a weak ECDSA nonce to achieve full system compromise.
2025-02-27
7 min
Threat Modeling for Indie Developers Who Ship Fast
securityYou don't need a CISO or a threat model doc the size of a novel. Here's a practical, lightweight approach for small teams that actually want to ship securely.
2025-01-14
9 min
Sound Design Deep Dive: Granular Synthesis for Dark Atmospheres
musicHow I use granular synthesis to build the kind of unsettling, textured pads that underpin most of my darker productions — tools, techniques, and examples.
more posts coming soon — subscribe via RSS