Evidence-Driven Security Analysis
I examine attacks, authentication mechanisms, interfaces, and user behavior to identify where risk appears and where security can be improved.
Digital identity security, made clearer and stronger
I work to make digital identity systems safer, clearer, and easier to use.
I combine cybersecurity research, system analysis, and human-centered thinking to understand how authentication and identity systems fail in real-world use—and how they can be designed to better resist attacks while supporting better security decisions.
Insights & Analysis
Research-informed articles that explain security technologies, risks, and design choices for professionals, decision-makers, students, and anyone responsible for protecting digital identities.
Explore all articles →
Follow an SMS code from server to phone, understand channel and phishing risks, and compare SMS-based verification with independent TOTP and HOTP devices.
Read article
A practical threat analysis of endpoint attacks, synchronized vaults, phishing, and malicious extensions, together with ways to reduce risk.
Read article
Compare traditional local and synchronized password vaults with approaches that generate site-specific credentials without conventional password storage.
Read articleWhat I Bring
My work connects technical security analysis with real-world system behavior, user experience, and the decisions organizations and individuals must make about digital identity.
I examine attacks, authentication mechanisms, interfaces, and user behavior to identify where risk appears and where security can be improved.
I translate technical research and security problems into clear explanations that can support technical teams, decision-makers, students, and wider audiences.
I look at technical protection and usability as parts of the same security system—because security must work when real people use it.
Areas of Expertise
My work focuses on systems that establish and protect digital identity, especially where strong technical security must also support clear and reliable human decisions.
How identity and authentication systems can resist compromise while remaining practical and understandable in real-world environments.
02The security, usability, and decision-making challenges behind second-factor and push-based authentication systems.
03Authentication and password-management approaches designed to reduce exposure to phishing, credential theft, and weak or reused secrets.
Problems I Work On
I am particularly interested in what happens when security mechanisms meet real interfaces, real users, and real attackers.
I study how authentication systems can present enough context for people to distinguish legitimate requests from fraudulent or unexpected ones.
I investigate how security mechanisms can provide strong protection without creating unnecessary friction, confusion, or cognitive burden.
I explore designs that make systems themselves more resistant to phishing and misuse rather than depending entirely on perfect user vigilance.
Research Evidence
Peer-reviewed work spanning password managers, push-based authentication, two-factor authentication, and human-centered security.
Article
IEEE Internet Computing
Article
ACM Computing Surveys
Let's Work Together
I welcome conversations with organizations, technical teams, researchers, and professionals working on digital identity, authentication, phishing-resistant systems, password security, and security usability.
I am also open to research collaborations, expert discussions, invited talks, educational initiatives, and projects that connect cybersecurity research with practical challenges.