I build tools and educational resources that help people inspect software behavior, examine privacy risks and make informed security decisions. My work includes browser release review, automated privacy analysis, local forensic tools and contributions to existing open-source projects.
Browser tooling · Local analysis tools · Open-source contributions · Guides and resources
Brave Nightly Change Tracker#
My work at Brave includes developing tooling for reviewing Brave Nightly changes. The public tracker organizes merged pull requests from brave/brave-core into a searchable review queue, with filters for separating relevant changes from routine maintenance.
Public review interface
Site Behavior Lab#
An open-source project for inspecting what a website does during an automated browser visit: network requests, third-party connections, cookies, storage, browser API use, and consent behavior.
Reports connect findings to recorded evidence and disclose the browser and scan conditions. This makes the observation available for inspection alongside its interpretation. A scan describes one visit under particular conditions; findings need to be interpreted within the project’s published coverage and limitations.
Project and methodology · Website
Trace#
A Rust and WebAssembly tool for checking iPhone sysdiagnose archives against known spyware indicators in the browser. Archive parsing, indicator matching and report assembly run locally in the browser tab. The reports distinguish findings from incomplete coverage.
Trace is an initial triage tool with limited coverage. A scan cannot establish that a device is free of compromise or replace expert mobile forensics.
Project and limitations · Browser application
A browser-based tool for inspecting and removing structural metadata from supported images, documents, audio, and video. Processing uses WebAssembly in a browser worker; cleaned files are checked again before download.
It does not remove sensitive information visible in the content itself. Format support and retained metadata need to be considered when sharing the result.
Project and supported formats · Browser application
QRWarden#
A pre-release QR inspector that shows decoded content and observable URL properties before the user acts on them. Inspection runs in the browser without visiting the decoded destination. It does not certify that a link is safe, and the project is not yet supported for production use.
Project and release status
Open-source contributions#
The records below document accepted code contributions, release verification and project acknowledgements.
Ente PrivacyPack contributions#
I contributed support for selecting multiple privacy alternatives per category and improvements to the mobile builder and export layout. These code changes were integrated into the project in April–May 2026.
Multiple alternatives · Mobile builder and export layout
I also contributed response-header hardening, Next.js and OpenNext runtime updates, catalog validation, and browser checks.
Response headers and runtime updates · Catalog validation and browser checks
SimpleX server release v6.3.1#
I independently reproduced the build for SimpleX server release v6.3.1. The official release, published March 22, 2025, acknowledges my contribution and includes my checksum signature.
Official release acknowledgement · Published checksum signature
Bitwarden security guide#
A practical guide to securing a Bitwarden account. Bitwarden linked to the guide and named me in its February 2025 community spotlight.
Bitwarden spotlight and guide link
Hush Line#
I contributed DevSecOps work to Hush Line, an open-source whistleblowing platform. The project’s draft whitepaper includes an acknowledgement of my contribution.
Project · Acknowledgements, page 39
Guides and resources#
The collection below includes system-hardening guides, security checklists, and curated privacy resources. Start with the GitHub hardening guide, iOS hardening guide, or penetration-testing checklist.
See my research publications for scholarly work, and About page for professional background and independent coverage.
A Beginner’s Guide to Monero Project Overview This guide provides a complete introduction to Monero (XMR), a privacy-focused cryptocurrency that enables secure, untraceable transactions. We cover everything from basic setup to advanced features, helping newcomers understand and effectively use Monero’s privacy-preserving technology.
Why This Matters In an era of increasing surveillance and data collection, Monero offers essential financial privacy through advanced cryptographic techniques. Understanding how to properly use Monero helps protect your financial privacy while participating in the digital economy securely and anonymously.
...
Comprehensive Cryptocurrency Wallet OpSec Guide Project Overview This guide provides detailed operational security practices for protecting cryptocurrency wallets and assets. From basic wallet security to advanced protection strategies, we cover essential measures for safeguarding your digital assets through proper OpSec procedures.
Why This Matters Cryptocurrency wallets are prime targets for attackers, and a single security mistake can lead to permanent loss of funds. Proper operational security is crucial for protecting your digital assets from theft, ensuring safe transactions, and maintaining long-term access to your cryptocurrency investments.
...
Comprehensive Guide to Rust for Security and Privacy Researchers Project Overview A comprehensive educational resource focusing on Rust’s security and privacy features, designed for researchers and developers working in security-critical domains. This guide covers everything from fundamental concepts to advanced security implementations.
Why This Matters In an era where software security is paramount, Rust offers unique advantages for building secure systems. This guide helps security and privacy researchers leverage Rust’s powerful features effectively, ensuring robust and secure implementations.
...
Comprehensive Guide to Safe and Privacy-Respecting AI Usage Project Overview This guide aims to help users of all backgrounds understand and use AI technologies in a safe and privacy-respecting manner. We cover self-hosted AI solutions, privacy concerns with popular AI services, best practices for safe AI usage, and practical setup instructions for running your own AI models.
Why This Matters As AI becomes increasingly integrated into our daily lives, it’s crucial to be aware of the potential risks and take steps to protect our personal information. This guide provides a comprehensive overview of safe and privacy-respecting AI usage, with a focus on self-hosted solutions and practical advice for users of all levels.
...
Comprehensive Penetration Testing Checklist Project Overview A comprehensive guide for ethical penetration testing, meticulously designed to cover all phases of a penetration test. This step-by-step checklist ensures thorough coverage from preparation to reporting, ideal for both novice and experienced testers.
Why This Matters Thorough penetration testing is crucial for identifying and addressing security vulnerabilities before they can be exploited by malicious actors. A structured approach ensures consistent, comprehensive assessments while maintaining compliance and professionalism.
...
Contributing to Open-Source Projects Project Overview A comprehensive guide for contributing to open-source projects, designed to help both newcomers and experienced developers make meaningful contributions to the open-source community. This step-by-step guide covers everything from basic concepts to advanced collaboration techniques.
Why This Matters Contributing to open-source projects is a rewarding way to learn, share knowledge, and collaborate with developers worldwide. Whether you’re new to programming or an experienced developer, this guide will help you make impactful contributions to open-source projects.
...
De-Google Your Life: Top Alternatives Project Overview Welcome to the ultimate guide for reducing your dependence on Google while maintaining productivity and functionality. This carefully curated collection of 62+ privacy-respecting alternatives helps users transition away from Google services without sacrificing essential features or convenience.
Why This Matters In today’s digital landscape, Google’s services are deeply integrated into our daily lives. However, this convenience often comes at the cost of privacy and data autonomy. This project helps users reclaim their digital independence by providing carefully vetted alternatives to Google’s ecosystem.
...
Donation-Worthy Privacy Projects Project Overview A carefully curated collection of open-source applications and services that are making significant contributions to digital privacy and security. This project highlights initiatives that deserve community support and recognition for their commitment to user freedom and privacy.
Why This Matters In a digital landscape dominated by commercial interests, these open-source projects represent the backbone of internet freedom and privacy. While many of these tools are free to use, they rely on community support to maintain their independence, continue development, and ensure long-term sustainability.
...
GitHub Security Hardening Guide Project Overview This guide provides comprehensive security recommendations for protecting GitHub repositories and organizations. From basic security measures to advanced features, we cover essential steps for securing your codebase, preventing unauthorized access, and maintaining development workflow integrity.
Why This Matters GitHub repositories often contain sensitive code, credentials, and intellectual property. A security breach can lead to data theft, unauthorized access, and compromise of entire development pipelines. Implementing proper security measures protects your assets and ensures safe collaboration.
...
GrapheneOS AppVerse Project Overview A comprehensive collection of 78+ privacy-respecting applications specifically curated for GrapheneOS users. This project aims to help new users transition smoothly to GrapheneOS by providing them with trusted, privacy-focused alternatives to common applications.
Why This Matters Moving to a privacy-focused mobile OS like GrapheneOS can be daunting, especially when looking for secure app alternatives. GrapheneOS AppVerse bridges this gap by providing a carefully vetted collection of privacy-respecting applications that maintain functionality without compromising security.
...