Skip to content
View tomkabel's full-sized avatar

Highlights

  • Pro

Block or report tomkabel

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
tomkabel/README.md

Tom Kristian Abel

Authentication security researcher. I analyze how authentication systems fail at the client and protocol level, and I build specifications for systems that survive what I find.

Based in Estonia. I write in English and Estonian. Most of my work sits on one fault line: the gap between what a system claims to verify and what it actually verifies.

Selected work

  • google-botguard-security-research — SoK: Client-Side Anti-Automation Under VLM-Based Attack. A systematization of five paradigms of client-side anti-fraud, from VM attestation to hardware-anchored determinism, with a cost model for VLM-based operator synthesis attacks. Companion opcode-level teardown of Google's BotGuard VM at tomabel.ee/disclosures/botguard-disassembled.
  • smart-id-security-research — Independent protocol-level research on Smart-ID and cross-device eID flows: why MITM and endpoint replacement fail by design, how the approval layer fails instead, and what cryptographic origin binding and a FIDO2 migration path would change. Disclosed to the vendor before publication.
  • zero-trust-octagon — Zero-trust architecture from first principles: eight irreducible axioms, a nine-dimension morphological matrix, four archetypal breach analyses, and 24-month implementation roadmaps.
  • fingerprintproxy — A standalone TLS fingerprinting forward proxy in Go. Applies real browser TLS fingerprints (JA3/JA4, 65+ profiles) to outbound requests so you can test what your anti-bot layer actually sees.
  • ee-eudiw — Estonian EUDI Wallet: an independent technical specification with a zero-knowledge proof-of-age profile, plus a working ZK age-proof demo over ISO 18013-5 mdoc. Currently private while the demo is finished; public soon.

Currently working on

  • ZK age-proof demo over ISO 18013-5 mdoc for the Estonian EUDI Wallet
  • Server-side companion analysis to the BotGuard SoK
  • Smart-ID protocol analysis and coordinated disclosure

Find me

Previously

I was previously active as M41KL-N41TT (archived). That account holds earlier work from a different period of my life. My current research and published work lives here.

Pinned Loading

  1. fingerprintproxy fingerprintproxy Public

    Standalone TLS fingerprinting forward proxy that applies browser TLS fingerprints to outbound requests

    Go 2

  2. google-botguard-security-research google-botguard-security-research Public

    SoK: Client-Side Anti-Automation Under VLM-Based Attack – an analytical systematization of client-side anti-fraud defenses

    Python 104 19

  3. eudi-wallet-poc eudi-wallet-poc Public

    Forked from open-eid/eudi-wallet-poc

    Independent fork of RIA's EE EUDI Wallet PoC for Android: PID and mDL via OpenID4VCI/OpenID4VP, plus a zero-knowledge proof-of-age (mso_mdoc_zk) presentation

    Kotlin

  4. zero-trust-octagon zero-trust-octagon Public

    Zero-trust architecture from first principles: eight irreducible axioms, a nine-dimension morphological matrix, archetypal breach analysis and reference implementations

    TypeScript