July 07, 2026
Explained: Kerberos
It is 9 a.m. on a Monday. You type your password once to log into your work laptop. Then the day just happens: the shared drive opens, the intranet loads, Outlook connects, you print to the machine down the hall, you SSH into a build server. Not one of those systems asked for your password. Somehow, they all know who you are. That quiet magic is, in most corporate networks, Kerberos . It has been running underneath Windows Active Directory since 2… Read More
by Phee Jay
July 07, 2026
Explained: SASL
You're wiring up a new mail server. You reach the part where clients log in, and you open the SMTP docs to find not one login method but a menu of them: PLAIN , LOGIN , CRAM-MD5 , SCRAM-SHA-256 , OAUTHBEARER , GSSAPI . Then you open the IMAP docs for the same server, and it's the same menu again. Then LDAP. Then XMPP. The same names, the same handshakes, described separately in four different specifications. That repetition is exactly the probl… Read More
by Phee Jay
June 30, 2026
Explained: Honeypots
Information in this post reflects publicly available knowledge on honeypot techniques as of June 2026. The trap that nobody walks into by accident A small SaaS company spins up a new database server on a Tuesday afternoon. Nobody has announced it, no DNS record points to it yet, and no employee has the credentials. By Wednesday morning, the logs show seventeen login attempts from six different countries. Nothing about that server was advertised. Th… Read More
by Phee Jay
June 26, 2026
Explained: Model Distillation Attacks
You spend eighteen months and several million dollars training a model. It is good. It is your competitive edge. You wrap it in a clean API, set a price per thousand calls, and open it to the world. Six weeks later a competitor launches a near-identical service at half your price. Their model behaves almost exactly like yours: same quirks, same edge-case answers, even the same odd mistakes on the same odd inputs. They never breached your servers.… Read More
by Phee Jay
June 08, 2026
Explained: SMF Records
A batch job ran overnight and consumed three times its usual CPU. A CICS transaction that normally completes in 12 milliseconds is suddenly taking 200. A user account was used to access a sensitive dataset at 3am. A DB2 tablespace is approaching its storage limit. None of these events sent an alert. Nobody was watching at the time. But every one of them left a record. Because on z/OS, almost everything that happens is written down. That writing-do… Read More
by Phee Jay