I specialize in software supply chain security, platform and code integrity,
confidential computing, provenance and transparency systems, and key
management across hosts, containers, and scale-out cloud platforms.
I maintain
Awesome Agent Runtime Security,
a Linux-focused curation of long-form writing, specifications, and technologies
at varying levels of maturity. It collects approaches to kernel- and
hypervisor-enforced agent isolation, secrets injection, and deriving
credentials from an agent’s measured state.
I maintain Awesome Software Supply Chain Security, a popular and
comprehensive reference of tools, trends, and challenges in the software supply chain security.
I’ve built Linux distributions of various sizes, from a consumer-focused one
that has millions of end users
to custom-built Linux desktop distributions for the enterprise. From there, I transitioned to
researching how distribution package management, release cadence, and
security are relevant to the open source software supply chain problem.
Most of my writing lives in GitHub Gists or
LinkedIn Articles. I have presented at several conferences from Argentina to
Tunisia, with slides often available on
Speaker Deck. Here are some selected earlier
works: