WritingLabProjectsAbout

Kirk Abbott

Cloud, AI, and security: research, projects, and notes.

Latest article
cryptographysecuritykdfhkdf

Per-user encryption keys: a length-extension trap and the HKDF fix

The 'obvious' way to derive per-user encryption keys from a master secret is SHA256(master || user_id). It's wrong in a specific and exploitable way. Here's the attack, and how HKDF fixes it.

2026-08-07 · 8 min readRead article →
All writing →
From the lab

MITRE ATT&CK 3D Explorer

An interactive 3D graph of MITRE ATT&CK Enterprise: techniques, threat groups, and malware with multi-dimensional filtering and search.

Open project →
More from the lab →
Featured project

Stratbeacon

A SaaS trading signals platform for retail traders. Live at stratbeacon.com, real users, real payments.

Open project →
All projects →

About

U.S. Air Force cyber defense operator with a web and cloud development background, working on cloud security, architecture, and AI/ML.

Started in web development, moved into cyber defense, now pointing at the place where cloud architecture, security, and AI/ML overlap.

Read full about →
WritingLabProjectsAbout
GitHubLinkedInRSS
© 2026 Kirk Abbott
Views and opinions are my own and do not reflect those of the U.S. Air Force or Department of Defense.