Writing
War Studies takes war itself as its object — not a single method for studying it. The field was given its modern shape by Sir Michael Howard, who built it at King’s College London on a deliberately plain premise: war is too large and too consequential to belong to any one discipline, so it is examined through all of them at once — history, strategy, politics, law, economics, psychology, technology. What holds the field together is a subject, not a method. Denial and deception is among its oldest problems, and the one I study.
Digital forensics is the practice of reconstructing what happened on a system from the evidence it leaves behind — reading a machine not as a diagram of how it should behave, but as a record of what was actually done to it. It carries a courtroom standard: every finding has to survive someone trying to break it. It is also where the teaching and the research meet the work, which is why I treat them as one subject rather than two.
The Second Circuit just held, for the first time, that the First Amendment protects filming a police station from a public sidewalk. The same opinion says the man who did it was lawfully arrested anyway, and that the officers who got the law wrong owe him nothing.
Greenville, NC officers investigating a real shooting handcuffed a woman who declined to show them her Ring footage, entered her home, and held her phone to her face to unlock it. Every lawful path to that footage was available. They used none of them.
The Supreme Court just ruled your location history is protected by the Fourth Amendment. The reasoning points straight at Flock's license-plate cameras — and that is a good thing.
Fraud is deception with a price tag — the same manipulation of belief studied in war, turned on money and identity. What earns it a heading of its own is scale and speed: tools that once took a state now cost a subscription, and the defender’s problem shifts from spotting the fake to hardening the process the fake is built to exploit.
A dark web storefront called Nexus offered searchable access to 153 million driver's license scans from the US and Canada, complete with the infrared and ultraviolet layers verification systems use to spot fakes. The breach came from an identity verification vendor, and that detail is the whole story.
How to read AI-generated images, why the visible tells have a shelf life, and what detection actually holds up when money is on the line.
Resiliency is the study of failure before it happens — not how to prevent it, which is often impossible, but how to know in advance, and in detail, the shape it will take, and to build so that recovery outruns collapse. The honest measure is not uptime; it is what a system does on its worst day.
Seven South Korean lenders were breached in four days, possibly with help from a two-month-old open-source AI pentesting tool. The regulator ordered the entire sector to fix the exposure class within a week — without waiting to find out who the attacker was. That ordering of priorities is the lesson.
Five federal agencies warned this week that attackers are using AI to write exploit code for Siemens controllers and scanning the internet for exposed ones. The advisory tells operators what to do. The harder question is what happens to everyone downstream of the operators who don't.
In July an OpenAI model escaped its sandbox and hacked Hugging Face — the first fully autonomous cyber attack on record. What saved the defenders was not prevention, and that is the whole lesson.
What resiliency actually is — not preventing failure, but knowing in advance and in detail the shape failure will take — and the craft that produces it.
Artificial intelligence appears here as both tool and threat: the thing that now manufactures deception at scale, and the thing increasingly asked to detect it. My interest is less in the models than in what they change — where they collapse the cost of an attack, and where a claim they produce can, or cannot, be trusted.