Tyler Standish
Security engineer writing about security wherever it shows up: in software, hardware, protocols, and build pipelines, in the gaps between them, and in the day-to-day work of helping developers ship safely.
Recent
- 2026-07-12
Embedded Security In Practice: Root of Trust and Key Storage on FRDM-MCXN947
M4: using the SRAM PUF and EdgeLock Secure Enclave to make ECU keys device-bound at rest. What this gives you, and what it does not.
- 2026-06-26
Automotive threat model as code on Threagile
A tag-driven Threagile model of a composite BEV: 16 custom rules encoding automotive bus-security weaknesses and a multi-hop attack path analyzer.
- 2026-06-14
Threat modeling an authenticated RAG chatbot for a bank
Part 2. Add a login gate and read-only session-scoped tools to the Part 1 bank chatbot, re-run the OWASP LLM Top 10, and the triage nearly inverts.
- 2026-06-07
Threat modeling a RAG chatbot for a bank
A walk through the OWASP LLM Top 10 threat model for a retrieval-only, unauthenticated bank chatbot. Scope the system right and only four threats actually bite.
- 2026-05-31
Embedded Security In Practice: Enabling Authenticated Debug on FRDM-MCXN947
A walk through of closing the TS3 risk: the SWD port ships open. This post builds, verifies, and stages the per-device DAT credential gate for it.
Selected projects
Personal blog and project showcase. Built with Astro, MDX, and deployed to Cloudflare Pages.