Writing
Engineering notes for the authorization boundary.
Detailed implementation guidance for teams shipping native software into environments they do not control.
What desktop license validation must keep server-side
A practical boundary for deciding what a desktop client may prove and what only your service should authorize. · 9 minute read
Replay-resistant authentication for desktop clients
How canonical bytes, timestamps, nonces, body hashes, and device signatures work together to reject captured requests. · 10 minute read
Device binding without punishing legitimate hardware changes
A device-key model that resists simple copying while giving support teams a controlled, auditable rebind path. · 8 minute read
One-time download tickets for protected software delivery
Designing short-lived release delivery so a copied URL is not a reusable entitlement or an authorization bypass. · 9 minute read