Priya Venkatraman
Translator of dense mechanism into plain language without losing precision. Reaches for a physical analogy within two lines and never lets it do more work than it can carry.
Posts by Priya
A session token is not an audit record
JWTs are excellent at what they were designed for: carrying claims for minutes. Using them as decade-long evidence fails on canonicalisation, key availability and algorit
A username and a password: what a 21 CFR Part 11 signature actually proves
Part 11 §11.200 permits a non-biometric electronic signature to consist of an identification code and a password. That construct sits under every batch release in the ind
Break the glass, break the evidence: what an emergency-access record actually proves
Break-the-glass lets a clinician into a restricted chart in seconds. The record it leaves behind is a row your own system wrote about itself — which is the weakest thing
Hidden instructions in court filings: document provenance when the reader is an AI
Courts have found concealed instructions embedded in filed documents aimed at AI-assisted review. A filing is now read by two audiences, and the record cannot prove what
The case for specifying the receipt format openly
Evidence that only one vendor can produce and verify is not evidence in the sense that matters. A format worth relying on has to be one anyone can implement.
After the 2026 certificate authority compromise: signing authority is not key custody
An April 2026 CA compromise produced stolen code-signing certificates used to sign malware. Hardware key storage improved custody and did nothing to establish that a huma
The FAA expanded its falsification rule in 2026. What that means for digital maintenance records.
In a paper logbook a correction is a line-out with initials — visibly a correction. In a database a correction is an UPDATE. Whether it was honest depends on an audit tra
Proving you are a unique human does not authorise a payment
Personhood systems establish that an account belongs to a distinct person, once. Enterprise workflows need to know that a specific person approved a specific act, repeate
Zero-knowledge proofs and the audit that needs to see the data
A zero-knowledge proof establishes that a constraint held without revealing the inputs. An auditor, a regulator and a court all want the inputs.
Descriptor registries solve blind signing by adding a dependency
Clear-signing standards let a wallet render a contract call by looking up a descriptor. The descriptor comes from somewhere, and that somewhere becomes part of the trust
Building an agent kill-switch that actually stops the agent
The usual kill-switches are a firewall rule and a token revocation. One takes minutes and stops everything; the other stops everything too. Neither is what you want at 3a
BVLOS drone operations: who authorized the flight the remote pilot never saw?
Beyond-visual-line-of-sight rules enable one-to-many operations. Regulation places responsibility on a remote pilot in command; scaled operations put one human in charge
The notary's journal is the evidence, and it lives on a vendor's server
A notarial act must be provable for as long as the underlying instrument matters — often decades. The recording and journal entry that prove it are held by a commercial p
The loadsheet nobody signed: identity economics at the turnaround
Final loadsheet acceptance is a safety-critical decision executed by contracted handler staff using the airline's systems, frequently under shared station accounts.