Writing
Stories from real systems
Outages, breaches, weird bugs, and what they taught me.
- security2026 · 2 min
One Million Combinations, 50 Guesses a Day
A 6-digit OTP has a million combinations. Three stacked rate limits cap an attacker at 50 guesses a day, about a 0.005% chance. The math and the layers.
- payments2026 · 3 min
Chargeback Evidence in One Lookup
Fighting a chargeback meant hours of copy-paste per dispute. Built a tool that fills a 10-section evidence packet from one lookup, with card scheme liability rules coded in because the gateway API does not tell you.
- →Packet build: hours of copy-paste down to one lookup plus review
- →10 evidence sections filled automatically from order data and 3 gateway calls
- →Card scheme liability-shift rules coded in, not guessed per case
- security2026 · 3 min
Fraud Detection System: A Live Risk Engine for Checkout
Digital goods checkout is a fraud magnet. Every rule change needed an engineer and a deploy. Built a rule engine with a live expression builder. Risky orders now get declined, ID-verified with liveness or held automatically.
- →New fraud rule live in minutes, no engineer, no deploy
- →High-risk orders auto-route to ID verification with liveness
- →Every decision logged with matched rules, reused as chargeback evidence
- databases2026 · 4 min
1-Minute Timeouts to 5 Seconds: Moving Reports Off MariaDB
2020. Reports on a 4 GB MariaDB hit 1-minute timeouts. Years of indexing tricks and forum advice before moving analytics to ClickHouse. Reports came back in 5 seconds.
- →Reports: 1-minute timeouts down to 5-10 seconds on ClickHouse
- →Load on the primary OLTP database dropped at the same time
- →Storage cost growth decoupled from data growth via S3 and Glacier tiering
- security2026 · 4 min
A Hack, 15 Sleepless Nights and the Biggest Lesson of My Career
January 2020. Exposed PHPMyAdmin on a live server. An attacker pulled £5,000 of stock and would not leave. Fifteen days of cat-and-mouse to find the door and shut it.
- →£5,000 of stock pulled before lockout
- →15 days to find the attack vector: exposed PHPMyAdmin
- →Server hardened, attacker locked out for good
- database2026 · 3 min
Normal Forms in Four Moves
1NF to BCNF with one tiny table at each step. Each form fixes one kind of repeated data: crowded cells, half-key columns, tag-along columns and non-key deciders.