Where I put all the stuff I’ve been wanting to say about security and auth systems design for years, but have been to scared to say (because it’s mostly just co-opting the tone of everybody else who writes in the infosec space, with zero practical/firsthand experience or evidence to back it up).

Note that these files were never actually comitted to the stuartpb on Security repo, and as such may actually be incomplete in their currently comitted form (in fact, I’m sure that at least two of these have at least one incomplete sentence each):


These might be a little sloppier, they came via Messays from messier eras of these notes: