<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>bordumb — writing</title><description>Notes on identity, bounded authority, verification, formal methods, and human trust.</description><link>https://bordumb.dev/</link><item><title>A proof should break when the program changes</title><link>https://bordumb.dev/blog/a-proof-should-break-when-the-program-changes/</link><guid isPermaLink="true">https://bordumb.dev/blog/a-proof-should-break-when-the-program-changes/</guid><description>How Auths Proof translates its production Rust authority kernel through Charon and Aeneas, refines it against a readable Lean specification, and makes semantic drift fail CI.</description><pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Why I built Auths</title><link>https://bordumb.dev/blog/why-i-built-auths/</link><guid isPermaLink="true">https://bordumb.dev/blog/why-i-built-auths/</guid><description>I built Auths to separate identity from authority and make exact, bounded authorization portable across systems that will inevitably change.</description><pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate></item><item><title>What Japanese taught me about what people leave unsaid</title><link>https://bordumb.dev/blog/what-japanese-taught-me-about-what-people-leave-unsaid/</link><guid isPermaLink="true">https://bordumb.dev/blog/what-japanese-taught-me-about-what-people-leave-unsaid/</guid><description>Japanese taught me that understanding depends not only on what a sentence contains, but on what two people can safely omit.</description><pubDate>Wed, 29 Jul 2026 14:28:00 GMT</pubDate></item><item><title>I learned Japanese by starting with kanji</title><link>https://bordumb.dev/blog/i-learned-japanese-by-starting-with-kanji/</link><guid isPermaLink="true">https://bordumb.dev/blog/i-learned-japanese-by-starting-with-kanji/</guid><description>Seventeen years of Japanese began with a year of kanji, followed by grammar dictionaries, half-understood podcasts, and comedy with captions.</description><pubDate>Wed, 29 Jul 2026 13:55:00 GMT</pubDate></item><item><title>A dependency update can change what your program is allowed to do</title><link>https://bordumb.dev/blog/a-dependency-update-can-change-what-your-program-is-allowed-to-do/</link><guid isPermaLink="true">https://bordumb.dev/blog/a-dependency-update-can-change-what-your-program-is-allowed-to-do/</guid><description>A capsec diff of two published Rust crate versions shows why dependency review should include newly reachable filesystem, network, process, and FFI behavior.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate></item><item><title>A function signature should say what the function can do</title><link>https://bordumb.dev/blog/a-function-signature-should-say-what-the-function-can-do/</link><guid isPermaLink="true">https://bordumb.dev/blog/a-function-signature-should-say-what-the-function-can-do/</guid><description>How capsec makes filesystem and network authority visible in Rust types, what the compiler rejects, and where audit must take over.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate></item><item><title>A probe that has never failed proves nothing</title><link>https://bordumb.dev/blog/a-probe-that-has-never-failed/</link><guid isPermaLink="true">https://bordumb.dev/blog/a-probe-that-has-never-failed/</guid><description>Why executable claims need retained counterexamples, distinct failure states, and a gate that distrusts the confidence of its operator.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Authority should only get smaller</title><link>https://bordumb.dev/blog/authority-should-only-get-smaller/</link><guid isPermaLink="true">https://bordumb.dev/blog/authority-should-only-get-smaller/</guid><description>Why auths-proof separates identity evidence, delegated authority, and application execution behind one offline verification contract.</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The repository rejects reverse dependencies</title><link>https://bordumb.dev/blog/the-repository-rejects-reverse-dependencies/</link><guid isPermaLink="true">https://bordumb.dev/blog/the-repository-rejects-reverse-dependencies/</guid><description>How auths-proof turns layer direction, offline verification, deterministic CBOR, and protocol bounds into executable repository checks.</description><pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate></item><item><title>One authority model, many identity and transport systems</title><link>https://bordumb.dev/blog/one-authority-model-many-systems/</link><guid isPermaLink="true">https://bordumb.dev/blog/one-authority-model-many-systems/</guid><description>How auths-proof admits KERI, raw keys, P-256, Iroh, HTTPS, and other systems without letting them redefine permission.</description><pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate></item><item><title>A machine-checked map is not a solution</title><link>https://bordumb.dev/blog/a-map-is-not-a-solution/</link><guid isPermaLink="true">https://bordumb.dev/blog/a-map-is-not-a-solution/</guid><description>What an honest formal map contributes to an open mathematical problem—and why preserving the red nodes is part of the result.</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate></item></channel></rss>