August 03, 2026
Architecture: Zero Trust
A contractor joins for two weeks to fix a reporting dashboard. Someone in IT provisions a VPN account, the contractor connects, and the laptop picks up an address inside the corporate range. The dashboard loads. So does everything else. From that laptop the build servers answer. So does the internal wiki, the file share holding three years of payroll exports nobody archived, the printer management console, and a Jenkins instance last patched in 2… Read More
by Phee Jay
July 07, 2026
Explained: Kerberos
It is 9 a.m. on a Monday. You type your password once to log into your work laptop. Then the day just happens: the shared drive opens, the intranet loads, Outlook connects, you print to the machine down the hall, you SSH into a build server. Not one of those systems asked for your password. Somehow, they all know who you are. That quiet magic is, in most corporate networks, Kerberos . It has been running underneath Windows Active Directory since 2… Read More
by Phee Jay
July 07, 2026
Explained: SASL
You're wiring up a new mail server. You reach the part where clients log in, and you open the SMTP docs to find not one login method but a menu of them: PLAIN , LOGIN , CRAM-MD5 , SCRAM-SHA-256 , OAUTHBEARER , GSSAPI . Then you open the IMAP docs for the same server, and it's the same menu again. Then LDAP. Then XMPP. The same names, the same handshakes, described separately in four different specifications. That repetition is exactly the probl… Read More
by Phee Jay