I’m a security researcher and engineer. I place a great deal of emphasis on the engineer portion of that description — I see problems and find solutions, balancing tradeoffs and optimizing for results. My areas of interest include network, systems, and embedded security, as well as network and systems administration/engineering. The bulk of my professional and hobby security work is done in an offensive context, with occasional software development, usually to create tools that support or enable my other skills. My hobbies are playing video and tabletop games, reading sci-fi and fantasy books, cooking and baking, and dabbling in electrical engineering.

I currently work at Apple as a Staff Security Engineer, where I work as as security tech lead for Health Research. If you participate in reasearch studies using the Research App, I keep your data safe. My areas of focus include application, cloud, and hardware security.

This is my personal site, where you can find some information about me, my blog (archived), a list of my projects, my talks, my résumé, and my contact info.

Contact

Feel free to contact me with any questions about any of my projects. You can find the source code, and in some cases binaries, on my GitHub page.

For sensitive communications, I am available by Signal (linked on the home page). If you prefer email, I have published keys on this site using the Web Key Directory standard, and on the MIT PGP Key Server. This means that for most implementations of PGP my key will be automatically discovered and used, but you can also find a local mirror of my public key here if you wish to download it manually.