Tobias Lindqvist-Rao
Protocol-level engineer. Cites the RFC by number, states what the specification actually guarantees, and refuses to let a diagram stand in for a mechanism.
Posts by Tobias
Locked out of your own plant: what the July 2026 water attacks prove about OT authorization
Attackers reached internet-exposed controllers at water systems across a dozen states, changed passwords and IP addresses, and locked operators out. No exploit was requir
Unique to one individual: what AC 120-78B demands and what MRO systems deliver
FAA advisory material requires an electronic signature to be unique to one individual and under that individual's sole control. In production it is a login to a main
The four-eyes illusion: why ERP dual authorization does not stop push payment fraud
Maker-checker in an ERP records approvals as database rows. A stolen session, an insider with database access, or a post-approval field edit produces a payment that every
EU GMP Annex 22: when a model reviews the batch record, whose signature releases the product?
EU GMP is adding a dedicated artificial intelligence annex covering AI in visual inspection, deviation triage and batch record review. It will require provable human over
The capital call nobody can verify: making drawdown notices cryptographically real
A capital call arrives as a PDF attached to an email, instructing a limited partner to wire a very large sum by a deadline. Verification is comparing the wire instruction
A maturity model for human oversight of automated decisions
Generic maturity models do not ask the question that matters here: at what point, and with what evidence, does a human take responsibility for an automated action?
Why database pause states fail as human-in-the-loop evidence
Agent frameworks implement human-in-the-loop by pausing execution and writing state to a database. The resume is triggered by a row. The row is mutable and produced by th
Deemed export: proving who authorized a foreign national's access to technical data
Releasing controlled technical data to a foreign person in the United States is an export requiring authorization. In practice access is governed by directory groups, and
Who touched the CUI? Access evidence across prime and subcontractor boundaries
Safeguarding requirements flow down through multiple supplier tiers by contract clause, with compliance evidenced by supplier attestation rather than observation. Nobody
Gating payment orders at the API boundary: an API key is not an intent
Programmatic treasury platforms treat possession of an API key as proof of intent. There is no cryptographic distinction between a scheduled batch run and an attacker wit
Why MFA at login does not protect anything after login
Multi-factor authentication establishes who opened the session. Everything consequential happens later, to a session token that can be copied off the machine.
Why browser-based face liveness cannot be trusted
A liveness check that runs in the browser asks the client to report on itself. The client is the thing under attack, and the answer it returns is a boolean an attacker co
SMS and voice OTP: a postmortem on borrowed trust
One-time codes delivered by telephone inherit the security properties of the telephone network. Those properties were set in the 1970s for a network of trusted state carr
Why a hardware key will not work down a remote desktop tunnel
Remote access forwards input and screen. It cannot forward a physical touch on a device attached to the machine at the far end, and that limitation is a security property
Transaction confirmation in the browser: the extension that never shipped
WebAuthn signs a challenge. It has never signed the text a user was shown. An extension to do that has been discussed for a decade and is not deployed.
Four tiers of presence, matched to what an action can cost
Treating every approval the same produces either unbearable friction or a session click guarding a wire transfer. A tiered model matches the assurance to the consequence.
Chain of custody for electronic evidence: the declaration nobody can test
Federal Rules of Evidence 902(13) and 902(14) let electronic records self-authenticate through a certification by a qualified person. That certification is a declaration,
The vendor invoice scam: deconstructing account details substitution
Attackers compromise a vendor's email, send updated bank details on genuine letterhead, and slip the change into AP software where approvers do not notice the modifi
What external auditors actually require for electronic payment approvals
Companies submit chat screenshots and ticket exports to evidence payment approval controls. AS 2201 asks for evidence of operating effectiveness, and a screenshot is the
Container release PINs are passwords: terminal gate identity at scale
A container is released to whoever presents the correct PIN. The PIN travels by email, messaging app and phone call through forwarders, brokers and dispatchers. It is a b
The electronic bill of lading needs a signer, not a platform
An eBL is a title document whose validity currently depends on the platform that issued it. Verification means membership; endorsement means the platform's database
Emergency and disaster assistance: speed versus proof when both are mandatory
Disaster assistance must move within days to people who may have lost their documents, their devices and their homes. Fraudsters exploit precisely the flexibility that le
Marketplace seller payout redirection: the takeover that looks like an update
A compromised seller account's payout destination is changed. Sales continue normally, and the seller discovers the diversion at the next payout cycle — typically we
Reading draft agent legislation for architectural requirements
Draft bills on autonomous software converge on a small set of demands. Most are architectural, most survive redrafting, and most are cheaper to build now than to retrofit
Re-performing controls offline: what changes when evidence verifies
Auditors sample because reviewing evidence by hand is expensive. When evidence is machine-verifiable, the population becomes testable and the economics of the audit chang
Sponsor oversight across the CRO and CDMO boundary: delegation an inspector can verify
Regulators hold sponsors accountable for delegated GxP activities. The partner's audit trail names the partner's employees, is written by the partner's sof
The registrar's signature: credential issuance authority in an age of instant fakes
Credential verification is an institution-to-verifier lookup. It requires the institution to exist, to answer, and to be trusted. Nothing the graduate holds can be verifi
Procurement award authority: the contracting officer's warrant as a verifiable credential
Only a warranted contracting officer can bind the government, within a dollar ceiling. A vendor receiving a commitment has no way to verify the warrant, and an unauthoriz
Signing the deviation, not the dashboard: cold-chain and serialization exception disposition
A shipment logs a temperature excursion or arrives with a serialization mismatch. Somebody dispositions it as acceptable. Downstream trading partners inherit that decisio
Third-country repair stations: verifying a signature across a bilateral agreement
Heavy maintenance concentrates offshore while oversight relies on periodic audits. An airline accepts work on the strength of a certificate number and a signature it cann
Visitor access and insider threat programs: the escort who was never assigned
Visitor authorization, escort assignment and area access are recorded at check-in by reception staff. Escort reassignment happens verbally, and the escort of record may n