CEO of @InkbridgeNtwrks, leader and co-founder of the @freeradius Project, and leading expert on Authentication, Authorization, and Accounting (AAA) frameworks.
Some call RADIUS legacy technology. I'd argue the opposite - it's still here because it works.
Heading to @ietf 126 Vienna (18–24 July) for RADEXT sessions. Want to talk protocol? Find me there:
https://t.co/xSq7am4jVK
#IETF126#RADIUS#InternetStandards
The protocol does what it's supposed to do. The surrounding architecture undoes the work.
We see it constantly: EAP-TLS deployed with shared client certs, RADIUS servers not validating certificate content, flat networks behind a shiny new AAA stack.
https://t.co/SU7cnHE8rH
I keep watching ISPs spend months building custom REST APIs to answer one question: "Which customer has this IP right now?"
The data's already in your DHCP database. DNS has handled queries like this for decades. Integration in minutes, not months.
https://t.co/SUcF6QWgpO
The RADIUS Conference Virtual Speaker Series is tomorrow. You can find the agenda & registration link below.
Free, live talks with industry leaders. Register to hold your spot or to receive the recordings after.
https://t.co/IBQ1J9c57K
#RADIUS#NetworkSecurity#Cybersecurity
What do MS-CHAP and the floppy disk have in common? They're both relics from the 90s that have no place in modern tech. But unlike floppy disks, MS-CHAP can still cause real damage. Find out why we're declaring it officially dead here: https://t.co/CziBo9NcRV
#CyberSecurity
The engineering argument against AI-generated contributions is simple: bad code wastes maintainer time and erodes the signal-to-noise ratio that makes a healthy project function.
Thanks to Jana for drawing our attention to this telling incident:
https://t.co/NRejMZATbr
The in-person workshop in Helsinki is done, now it's time for our virtual speaker series on June 15th.
Live streamed with an interactive Q&A. Register and you'll get all the recordings even if you can't make the full day.
https://t.co/ugB8canPLT
@RadiatorAAA
I spent hours in a room with network operators telling them that the mental model most engineers have of RADIUS is wrong.
The server is not in charge. The NAS is.
Once you understand that, a ton of troubleshooting problems stops being mysterious.
https://t.co/LRiCf4k91u
Complexity as a security strategy: probably responsible for more outages, failed audits, and successful attacks than anything else I can think of.
The most resilient systems I've seen are simple enough for one person to understand and fast enough to recover from being wrong.
FreeRADIUS is 400,000 lines.
I use AI to flag inconsistencies across that codebase - the kind of cross-referencing humans are slow at.
We still manually review everything, because 5% wrong out of 10,000 items is a lot of wrong answers.
Use it. Don't trust it blindly.
I knew an engineer who went six layers deep fixing a bug-in-a-tool-in-a-tool instead of the actual task.
His curiosity was great. But he lost the thread.
Senior engineers obsess over the objective. Everything else is a detour.
Looking forward to being in Dallas for the Wireless Global Congress WBA Americas from the 18th to 21st this month.
Drop a comment or message me directly if you'll be around and want to meet!
Dallas hosts the Wireless Global Congress WBA Americas from May 18–21, and both Alan and Jana will be there.
Reply or message us to set up a meeting with one of them during the event.
#WGCAmericas
Back in February, thousands of enterprise users got locked out of Microsoft 365 - no attackers required, just the MFA infrastructure going down.
Zero Trust assumes the verification layer is reliable.
It's worth asking: what's your plan for when it isn't?
@sophos found that only 5% of IT leaders fully trust their cybersecurity vendors.
I've watched this for 25 years: vendors claim it works. Customers find out otherwise.
Open source fixes this. When the code is public, anyone can check. The internet always surfaces the truth.
The inevitable support call ... "I upgraded production at 2 a.m. and it's broken."
The answer is always the same: revert, and write the process down before you touch it again.
Good engineers make mistakes. Engineers who skip the process turn mistakes into disasters.
A CTO ran out of the room during a demo. Came back convinced we were hiding complexity. We weren't. The SQL query really is one line.
Open source POCs answer questions in hours. Vendor sales processes take weeks to tell you the same thing.
Full story: https://t.co/QBfOEYKczt
The CVE programme nearly went dark in 2025. It's funded again - but it still runs on a single government contract.
Worth watching.
https://t.co/5X37AJ6vGC
Companies that succeed maintain control over their infrastructure. I say this because I've watched the ones that didn't.
Flexibility vs convenience. Ownership vs managed service. These aren't abstract trade-offs.
They're what you live with at 2 a.m: https://t.co/2xFerFHqyS