What moved me
I’ve spent more than 25 years working in information security, risk, compliance, and security architecture, and I’ve gradually become more interested in the deeper question underneath all of them: how do humans and systems make trustworthy decisions when the available information is incomplete, contextual, and sometimes adversarial?
That question has led me from conventional security and compliance work into threat modeling, knowledge management, provenance, privacy, AI, and eventually LORE, a project I’m developing around trustworthy context for humans and machines. LORE grew out of a frustration with how easily important context gets lost when people, organizations, and AI systems move information between boundaries. I’m interested in infrastructure that makes the trustworthy path easier without requiring everyone to surrender control to a central authority.
I’ve also been influenced by people who take both technical rigor and human consequences seriously. Grace Hopper is particularly important to me, as are W. Richard Stevens, Bruce Schneier, Adam Shostack, and others who have demonstrated that good engineering is often less about cleverness than about making the important things explicit.
What didn’t hold
I’ve become increasingly skeptical of the idea that compliance is synonymous with security. Compliance can be useful evidence that certain controls exist, but optimizing for the audit rather than the underlying risk can produce systems that are technically compliant and still poorly understood or poorly defended.
I’m similarly skeptical of treating authentication as equivalent to knowing who someone actually is. A password, device, biometric, location, secret, or credential can provide useful evidence, but each answers a different question and each can be compromised or coerced. Identity is contextual and should be treated as a collection of evidence rather than a magical boolean.
My experience has also made me wary of systems that silently discard context. A piece of information can be perfectly accurate in isolation and still become misleading when detached from its provenance, time, purpose, or surrounding circumstances.
Where I stand
Security and privacy: I favor systems that make secure and privacy-preserving behavior the easy path while retaining meaningful human control. I don’t think privacy should be treated merely as a subset of security. They overlap heavily, but they have different questions, risks, and failure modes.
AI and knowledge: I’m interested in AI as a reasoning partner, but I don’t want important context trapped inside a proprietary model or platform. Humans should be able to understand, preserve, move, inspect, and revoke the context on which machine reasoning depends.
Trust: I don’t think trust should be reduced to a single reputation score. Trust is contextual. I can trust someone’s judgment about one subject without trusting their judgment about another, and evidence should matter more than authority alone.
Technology and governance: I prefer small, understandable mechanisms over enormous systems that claim to solve everything. I’m particularly interested in capability-based security, provenance, explicit authorization, negotiated boundaries, and systems that fail visibly rather than silently improvising.
Disagreement: I think disagreement is useful when people are actually trying to understand one another. I’m much more interested in finding the exact point where two apparently incompatible positions diverge than in deciding which tribe is correct.
What would change my mind? Good evidence, a better model, or a demonstration that a supposedly necessary distinction doesn’t survive contact with reality. I’m quite comfortable abandoning an idea I can no longer defend.
When I’m not doing that
I love fast things. Fast cars, fast machines, fast ideas. I have a somewhat opinionated relationship with sports: soccer, winter biathlon, and HEMA are the only ones I consider worthy of watching. The combination of speed, tactics, precision, endurance, and sheer physicality appeals to much the same part of my brain that enjoys security engineering.
I’m also an AFOL, an Adult Fan of LEGO. I enjoy building LEGO Technic and other complicated sets, but probably enjoy the engineering and problem-solving as much as the finished models. There is something deeply satisfying about turning a pile of small, standardized pieces into a machine or structure that actually works.
A lot of my free time involves tinkering. Home networking, self-hosted services, Linux, Docker, smart-home projects, local AI, and whatever technical rabbit hole has most recently caught my attention. I have a tendency to look at something that is annoying, opaque, or unnecessarily complicated and think, “I wonder how that actually works?”
I read widely, especially science fiction, technology, computing, and history. Science fiction has probably had an outsized influence on how I think about technology and society. I particularly like stories that take an apparently impossible premise and use it to expose assumptions we didn’t realize we were making.
And I like conversations that wander. Some of my favorite conversations start with a seemingly simple question and end three hours later somewhere completely unexpected.
How I like to engage
I like deep, exploratory conversations that start with a concrete problem and follow the implications wherever they lead. I enjoy sparring with ideas, but not with people. The most productive conversations for me are collaborative: challenge an assumption, find the corner case, test the model, and improve it.
I tend toward breadth first and depth when something turns out to be interesting. I particularly enjoy connecting ideas that normally live in different disciplines: security architecture with linguistics, knowledge management with distributed systems, human factors with formal models, or old engineering ideas with problems created by new technology.
I’m a security architect and lifelong systems thinker trying to figure out how we can build technology that deserves to be trusted without requiring people to surrender their agency.