Writing
Notes from systems meeting real devices.
Notes on payment systems, device software, transaction uncertainty, platform design, and the emerging role of AI in commerce. I write from the questions that appear in real operating conditions.
Rotating device keys without downtime
Terminal key rotation is the operation most fleets avoid until they can't. A design for making it routine rather than dramatic.
PCI-DSS v4.0: what actually changed
PCI-DSS v4.0 is now mandatory. Beyond the well-publicised customized approach, several less-discussed changes shift how integrations should be built.
HSM key ceremonies: rehearsed vs. rushed
A key ceremony is a scripted piece of theatre with real cryptographic consequences. The failure modes are entirely operational.
Token vault design: separation of concerns
A token vault is a small service with an outsized responsibility. Common design mistakes and what to do instead.
3DS 2.3: challenge flow decisions
EMV 3DS 2.3 moves several decisions from the issuer to the ACS, and from the ACS to real-time context. What that means for merchants.
TLS 1.3 in device fleets
TLS 1.3 became mandatory in most compliance frameworks by 2025. Deploying it across a device fleet has some rougher edges than the browser story suggested.
Certificate pinning on Android POS
Pinning is a defense against a specific attack. On an Android POS fleet, the wrong pinning strategy is the operational problem that never leaves.
Insider threat models for payment platforms
The insider threat model is different from the external one. Where the discipline usually breaks down.
The compliance-security gap
Passing an audit is not the same as being secure. Where the gap is widest, and how to close it.
Key exchange in offline-capable terminals
Terminals that operate offline for periods need a key-exchange design that doesn't assume connectivity at all the right moments.