Kirk Abbott
Cloud, AI, and security: research, projects, and notes.
Per-user encryption keys: a length-extension trap and the HKDF fix
The 'obvious' way to derive per-user encryption keys from a master secret is SHA256(master || user_id). It's wrong in a specific and exploitable way. Here's the attack, and how HKDF fixes it.
MITRE ATT&CK 3D Explorer
An interactive 3D graph of MITRE ATT&CK Enterprise: techniques, threat groups, and malware with multi-dimensional filtering and search.
Stratbeacon
A SaaS trading signals platform for retail traders. Live at stratbeacon.com, real users, real payments.
About
U.S. Air Force cyber defense operator with a web and cloud development background, working on cloud security, architecture, and AI/ML.
Started in web development, moved into cyber defense, now pointing at the place where cloud architecture, security, and AI/ML overlap.
Read full about →
