ANTITREE

/dev/loop3 ro squashfs ---------------------------------------------------------~inode 0x4e21c8

uts:ns 4026532198 ----------------------------------------------------------#cap_sys_admin -eff

seccomp filt 0x1f ---------------------------------------------------------#rtt 12.4ms mtu 1500

::fe80::4a2c/64 ::::::::::::::::::::::::::::::::::::::::::::::::::::::::[vmalloc 0xffffc90000]

antiTree

Containers, kubernetes, AI, sandboxes, security, Linux isolation

and whatever else looks interesting enough to take apart.

[SANDBOXES]
[RUNTIME]GVISORID: RTM-49GVISOR / SYSCALL 0x2A / 11:16:45
Syscalls & sandboxes
[CONTAINERS]
[CLUSTER]CONTAINERDNODE: K8S-17CGROUP V2 / CAP_SYS_ADMIN / 04:22:09
Containers
[AI AGENTS]
[INFERENCE]TOOL-CALLCTX: 128KMCP / TOKENS 4096 / 19:41:02
AI & agents

About

Career

Working in isolation. The through-line of my career has been security through process isolation — sandboxes, containers, build systems, mobile apps. Wherever we confine resources to prevent further privilege escalation, that is where I have spent my time. From containers running on firewalls to build systems running gVisor, seccomp filters blocking system calls to microVMs with hypervisor boundaries, securing LLM agents to breaking out of containers — I've found allowing untrusted things to execute to be an interesting problem space.

At Intrepidus Group that meant mobile application security. At NCC Group I started and led the container practice, working on containers and Kubernetes. At Snowflake I helped build remote code execution as-a-Service and, eventually, their fully managed Kubernetes cluster service. Chainguard was a chance to sharpen the same skills in build environments and agentic workloads, alongside some of the best people in the world on software supply chain security.

My talks live in this space too, from Docker to seccomp to microVMs, and now agentic isolation.

Consulting

IOIOIO Security. My consulting practice is an opportunity to work with people building things and facing genuinely interesting problems. Usually that is sandbox or container work, or both at once — gVisor, or microVM runtimes for Kubernetes pods.

I'm always happy to meet and talk through the challenges you're facing, whether or not we end up working together on an engagement.

www.ioioiosecurity.com

Community

Building a Rochester Security Community. Spending time in Chicago's security community and attending conferences like DEF CON, I wanted the same thing closer to home. What started as a few people looking for each other turned into three organizations — and a lot of the people who came through them have gone on to do remarkable things, using Rochester as the jumping-off point.

Security B-Sides Rochester

With a small group of friends we started Security B-Sides Rochester, watched it grow, and it is still running today. It began the year after BSidesLV — which makes it the second longest-running Security B-Sides in the world.

www.bsidesroc.com

Interlock Rochester Hackerspace

Before BSidesROC there was the hackerspace. We ran it out of a warehouse in the Hungerford Building in downtown Rochester, and a lot of people passed through it. The events we held there produced some genuinely strange stories.

Rochester 2600

The 2600 chapter was my first step into a local hacker community. The meetup had been running for decades across various locations; I picked up the mantle and kept regular meetings going. It was never a formally organized event — just an opportunity for nerds to hang out with other nerds.

www.rochester2600.com