[{"data":1,"prerenderedAt":30},["ShallowReactive",2],{"writing-index":3},[4,13,22],{"_path":5,"title":6,"description":7,"date":8,"updated":8,"tags":9},"/writing/what-tls-actually-protects","What TLS actually protects, and what it doesn't","The padlock means less than people assume. What TLS guarantees, what it never covered, and the misconfigurations that quietly remove those guarantees.","2026-06-23",[10,11,12],"tls","cryptography","secure-design",{"_path":14,"title":15,"description":16,"date":17,"updated":17,"tags":18},"/writing/sso-oauth-jwt-what-each-one-does","SSO, OAuth, and JWT: what each one actually does","These three get used interchangeably and they are not the same thing. What each layer is responsible for, and the mistakes that follow from confusing them.","2026-05-12",[19,20,21],"authentication","oauth","identity",{"_path":23,"title":24,"description":25,"date":26,"updated":26,"tags":27},"/writing/threat-modeling-that-people-use","How to run a threat model people actually use","Threat modeling fails when it produces a document instead of decisions. A practical walkthrough of scope, trust boundaries, STRIDE, and useful output.","2026-03-17",[28,29,12],"threat-modeling","security-architecture",1785577357038]