tag / ai
06 essays- The Agent Has Your Session Cookie · 10 min
Browser-resident AI agents inherit the human's authenticated session by design. The threat model that follows is not prompt injection. It's session theft with consent, against an identity stack that assumes the browser is the user. A short note on what DPoP, CAEP, and the still-unfinished sender-constraint story actually fix.
- The Password Replacement and Why Your Agent Needs One Too · 8 min
Passwordless authentication is finally landing across enterprise IAM programs. The same orgs are simultaneously onboarding AI agents that hold long-lived credentials and run inside the human's session. The two projects are colliding, and most identity programs aren't ready.
- RFC 8693 in Practice · 7 min
Token exchange is the cleanest pattern for delegating identity to an AI agent, and every major IdP implements it differently. Field notes from wiring it into Entra, Okta, and Auth0 — what the spec leaves to interpretation, what breaks first, and what to standardize before the second agent ships.
- The Agent Identity Front · 9 min
AI agents are the next vulnerability vector and we are not tackling it fast enough. A look at why the gap between AI adoption and AI governance is widening, what it looks like inside real orgs, and where identity programs should be aiming.
- Why I Started a Security Firm in the Age of Vibe Coding · 8 min
The orgs most exposed to AI-era security risk are the ones moving fastest to ship with AI. They are also the orgs least likely to have a CISO. I built Diallo Security Advisors for that gap.
- What a Decade in Infrastructure Taught Me About AI · 8 min
I came up through racking servers, hypervisor migrations, and identity provisioning. The lesson that work taught me, and that I keep applying to AI in 2026, is that you cannot make good security calls from one set of binoculars.