Kirk Abbott
Cloud, AI, and security: research, projects, and notes.
Per-user encryption keys: a length-extension trap and the HKDF fix
The 'obvious' way to derive per-user encryption keys from a master secret is SHA256(master || user_id). It's wrong in a specific and exploitable way. Here's the attack, and how HKDF fixes it.
Packet to Prompt
One request traced end to end, from a laptop’s network card to a model’s response: the header values before and after every hop, the log record each sensor emits, what that sensor cannot see, and the ATT&CK and ATLAS techniques that abuse each step.
Scam-Call Detector
An LLM security pipeline on AWS. I wrote “prompt injection: mitigated” in its threat model, then built the thing that could prove me wrong.
About
U.S. Air Force cyber defense operator with a web and cloud development background, working on cloud security, architecture, and AI/ML.
Started in web development, moved into cyber defense, now pointing at the place where cloud architecture, security, and AI/ML overlap.
Read full about →