Skip to main content

About

The way of seeing.

Bio

I started on the wrong side of the authentication arms race. I reverse engineered browser security, TLS fingerprinting, and anti-fraud systems — and for a while, I broke them for money. I don’t hide that. It ultimately led to a conviction in 2024, an outcome I take full responsibility for.

What I kept was the way of seeing. Once you’ve taken authentication apart for a living, you can’t un-see how fragile most of it is — and you get tired of watching the same systems get picked apart in the same ways. So now I point the same skills the other direction: I research how identity protocols and browser defenses fail (FIDO2 / WebAuthn, eIDAS, Smart-ID, anti-fraud VMs), disclose what I find responsibly, and design systems that are secure-by-design rather than secure-by-hope.

These days I’m Lead Systems Architect and CTO at MATx (matx.ee), a maths-learning platform that spots students’ learning gaps early. There I build production platforms under the threat models I write — zero-trust architecture, phishing-resistant authentication, and GDPR/NIS2 compliance treated as engineering, not paperwork. I work in English and Estonian, and most of my research orbits Estonia’s authentication and anti-fraud landscape, because it’s one of the most digitized in the world and therefore one of the most interesting to defend.

Kratt

In Estonian folklore a kratt is a servant assembled from spare parts that works tirelessly for its maker — and turns on you the moment you leave it idle. That’s offensive capability in one image. It’s only useful pointed in the right direction, so I do that pointing in public, and I stand behind my work and my opinions personally.

Find me

PGP

Download Public Key

Key ID: 0x0C2A0C6F110AABC5

Fingerprint: 03DA 4E96 931B B2DC 095A 2109 0C2A 0C6F 110A ABC5

SHA-256: a63667ca9b1729e02b24c19cf2441953b76b934417a17b042fd1eeab68d8530a