Writing

Notes from the field.

Posts and technotes, published here, on the IT Audit Labs blog, or wherever the audience lives. Mostly security and edge-native engineering.

01 · Posts

Latest

May 10, 2026
When the AI Bubble Deflates, What Survives

Every hype cycle leaves a wreckage and a residue. The wreckage is the companies that never had a real use case. The residue is the practitioners who used the cycle to build durable skill. AI will be no different, and the gap between adoption speed and governance maturity is where security and audit professionals get to plant a flag.

#ai #governance #audit #security
read post →
May 5, 2026
Vivecoding
Vibecoding vs Vivecoding: A Manifesto

For years I pronounced it wrong. Then I looked at what I actually do, and realized the mistake had a thesis behind it. This is the case for treating AI-assisted engineering as a campaign, not a roll of the dice.

#vivecoding #ai-engineering #sdd #methodology
read post →
May 5, 2026
Vivecoding
Field Notes from the Vivecoding Talk

I gave the Vivecoding talk live at IT Audit Labs. The manifesto post has the technical bones. This one has the moments the slides could not carry: the pronunciation that turned out to be a thesis, the night Bard refused to let me refactor, and the two production scars I can only laugh about now.

#vivecoding #talk #ai-engineering #field-notes
read post →
May 5, 2026
Building a Voice Agent on Cloudflare Workers

How I ended up running an end-to-end realtime phone agent on Workers + Twilio Media Streams + Workers AI, after trying two heavier stacks first. The architecture, the loop, and the gotchas no tutorial shows you.

#cloudflare #workers #voice-agents #twilio
read post →
Apr 13, 2026
IT Audit Labs
Browser Extensions Are the Quiet SSO Bypass

108 malicious Chrome extensions hit ~20,000 users by capturing OAuth2 tokens, opening backdoor URLs, and stripping security headers, bypassing MFA, EDR, and CSP. Here's what actually defends against this.

#security #browser #sso #oauth
read on IT Audit Labs →