<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Abhishek Reddy</title><description>Security engineer writing about platform security, cryptography, and building systems that fail safe.</description><link>https://abhishekreddy.com/</link><language>en-us</language><item><title>Fail closed: default-deny as a design discipline</title><link>https://abhishekreddy.com/blog/fail-closed-as-a-design-discipline/</link><guid isPermaLink="true">https://abhishekreddy.com/blog/fail-closed-as-a-design-discipline/</guid><description>A control that fails open is a control that isn&apos;t there when it matters. Notes on building systems where the error path is also the safe path.</description><pubDate>Sun, 14 Dec 2025 00:00:00 GMT</pubDate><category>design</category><category>authz</category><category>resilience</category></item><item><title>Certificate rotation that doesn&apos;t page you at 3am</title><link>https://abhishekreddy.com/blog/certificate-rotation-that-doesnt-page-you/</link><guid isPermaLink="true">https://abhishekreddy.com/blog/certificate-rotation-that-doesnt-page-you/</guid><description>Most mTLS outages aren&apos;t attacks — they&apos;re expiry. A few design choices turn rotation from a recurring incident into a non-event.</description><pubDate>Sun, 02 Nov 2025 00:00:00 GMT</pubDate><category>mtls</category><category>pki</category><category>reliability</category></item></channel></rss>