Nadia Ferreira-Strand
Writes the procedure someone will run at 2am. Lists prerequisites first, names the step where most people fail, and gives the verification that proves it worked.
Posts by Nadia
The payload flip: signing what you did not see
The largest digital asset thefts did not involve stolen keys. Signers held their hardware, reviewed a transaction in a web interface, and signed a different transaction.
Designing a benchmark that is not a vendor opinion poll
Most security surveys are sponsored, sampled opaquely, and ask respondents to self-assess. A benchmark worth citing has to be designed against those failure modes deliber
625 stolen engine parts and a paper tag: binding release certificates to a named human
A part's airworthiness rests on a release certificate that is, physically, a document with a signature block. Verification means telephoning the issuer. EASA warned
Fictitious pickup: designing a dock release gate that assumes every document is forged
A driver arrives with a rate confirmation, a bill of lading number and a licence. Every one of those is a document, and document matching is exactly what the thief prepar
Seventy-two spoofed sites, one phone call: which MFA factors survive a real-time proxy
In 2026 attackers telephoned staff at large private equity firms and funnelled them into dozens of spoofed authentication sites where codes were captured in real time. Ev
Who told 40,000 inverters to curtail? Authorization in aggregated DER
A single API call can curtail tens of megawatts across thousands of privately owned assets. The call is authenticated by a platform credential. Nothing names the human wh
Segregation of duties exceptions: the compensating control that compensates for nothing
An SoD conflict is accepted because the business needs it. The register records an approver, a date and a free-text compensating control, and whether that control was eve
What California's automated decision rules ask of human review
California's ADMT framework gives consumers rights around automated decision-making. Answering a consumer's request about human review requires records most bus
Self-authenticating records: why some logs are admitted and others are not
Evidence rules provide a route for electronic records to authenticate themselves. A plain application log does not qualify; a record with a verifiable digital identificat
The bribed rep problem: a taxonomy of insider-completable operations
Retail and care staff need broad account authority to do their jobs. That authority includes exactly the operations an attacker wants. Monitoring detects the pattern afte
The second signer: elder financial protection that does not strip autonomy
Firms can delay a transaction and notify a trusted contact, or a court can remove a client's authority entirely. There is nothing in between that a client can choose
AAGUID attestation: restricting which authenticators count
WebAuthn accepts any conforming authenticator by default. If your policy says corporate hardware keys only, you need attestation — and most deployments never request it.
Putting wire confirmation inside the closing platform
Escrow officers spend most of an hour per file chasing buyers by phone to confirm instructions. The call is expensive, unreliable, and produces no record.
A verifier small enough that someone can read all of it
Verification is the point where trust is established. A verifier pulling hundreds of transitive dependencies has a trust base nobody has examined.
Payroll diversion: when the session is stolen, the HR portal cannot tell
Infostealers harvest employee SSO sessions and change direct deposit details in the HR system. Detection sees a legitimate session from a plausible location and allows th
Fund administrator instruction authority: subscriptions, redemptions and the NAV nobody signed
Subscriptions, redemptions, NAV adjustments and expense approvals are executed by an administrator on instructions from named individuals at the manager. Authority is a s
Break-glass in the enterprise: the account that defeats every other control
Every organisation keeps emergency accounts exempt from conditional access, MFA policies and monitoring, because those controls can fail. The exemption is necessary; its
An agent payment rail cannot also be the accountability layer
Platforms built to let agents transact without human involvement are solving a real problem. The thing they remove by design is the thing accountability requires.
Where decentralised identity's generality becomes a cost
Verifiable credentials are designed to work without any shared infrastructure between issuer and verifier. That generality has a price, and most enterprise deployments do
IoT SIM fleets: who authorized a profile change on 200,000 devices?
Remote SIM provisioning made connectivity a software property of very large device fleets. One console action can suspend or re-provision an entire estate, authorised by
Agent of record changes: moving a book of business with a signature nobody verifies
An AOR letter on client letterhead redirects the commission on a commercial policy. Carriers process it because the client is presumed to have signed it, and incumbent br
The economics of review: how much attestation can an organisation afford?
Organisations run certification campaigns against everything they can connect, allocating scarce human review uniformly across entitlements whose risk differs by orders o
Pilot qualification records: the training entry that makes a crew legal
Crew legality depends on recency, checkrides and line checks. Each is a row created by a training system, approved by an instructor's login, and rarely questioned un