Skip to content
tinywifi_
security researchtrust boundaries, auth, and failure modes
CanvasGLSLan in-game shader IDE for Minecraft
grain-clfcomputer vision for corn grading
helium-syncprivate bookmark sync for Windows
CanvasGLSL shader editor preview
CanvasGLSLcustom menu shaders with a live in-game editor.view the project →
writingsecurity notes and technical writeups
security glossaryplain-language definitions used in the writeups
useshardware, software, and tools
PGP keyencrypt a message or verify a signature
local redactionmask sensitive report text in your browser
Annotated computer-vision sample
latest field notethe same red-team mistakes keep showing up.read the writing →
Commands · /
Type to search
↑↓Navigate↵SelectEscClose
Color mode: system

writing

security research, computer-vision systems, and implementation notes from whatever i'm currently poking at.
4 published notes
  • authorization without a principal
    authorizationtenant-isolationidordata-integrity
    an authorized review of a multi-tenant education platform where tenant IDs, unsigned cookies, and unauthenticated service APIs were treated as identity. the result was cross-tenant data exposure, exam-integrity failures, and a potential physical-safety risk.
    Jun 10, 20268 min read1417 words
  • corn kernel grading with computer vision
    computer-visionagricultureyoloobject-detection
    a technical writeup on building a computer-vision pipeline for grading corn kernels by damage type, size consistency, and quality thresholds.
    Apr 29, 20264 min read625 words
  • the same red-team mistakes keep showing up
    red-teamobservationssecuritypatterns
    a short field note on the same broken trust boundaries that keep showing up in real systems: weak reset flows, bad CORS, exposed admin panels, and callback bugs.
    Apr 29, 20266 min read1166 words
  • how i could reset anyone's password on a school management platform
    auth-bypasspassword-resetaccount-takeoverdisclosure
    unauthenticated account takeover on a platform serving international schools. forgot-password endpoint returns the reset token directly in the http response body — four requests, zero prior access, complete staff admin takeover. bonus: open redirect via unvalidated callbackUrl and potential ssrf vector.
    Apr 18, 20265 min read855 words
tinywifisecurity research, computer vision, and useful little tools.
writingglossaryrsspgpsecurity.txt