Explores vulnerabilities in web and software applications, discussing broken access control, injection flaws, and defense strategies like DEP and ASLR.
Analyzes Yubico's proposal for asynchronous remote key generation in WebAuthn, focusing on security, performance, and compatibility with public key protocols.