Goals
Where I am trying to get to
Written down and published, because a roadmap nobody can check is just a wish list. Completed goals stay on the page — the record is the point.
2026
Ship real things, and get through the door.
Grow Hackuten
In progressLearning paths, an open contribution format, and enough challenge coverage that someone can go from nothing to competent inside one domain.
Get Orbyte to a usable client
In progressWorking end-to-end encryption, verifiable identities, and a written threat model published alongside it.
Publish more write-ups
In progressOne properly written piece a month. Not solve logs — write-ups that explain the reasoning, including the paths that went nowhere.
Pass the OSCP
In progressPrepared through the labs, with a written report for every machine rather than a screenshot folder.
Find an apprenticeship
In progressIn application security, starting September 2026. This is the one everything else is pointed at.
2027 and beyond
Go deeper, and give something back.
Pass the OSWE
PlannedWhite-box web exploitation. Reading source and turning it into working exploits is the skill I want to be measured on.
Work as a security engineer
PlannedApplication security full time — reviewing designs, breaking implementations, and building the parts that need to hold.
Bug bounty, properly
PlannedConsistent scope-respecting research with reports good enough that triage is boring. Quality over volume.
Contribute to open source
PlannedSecurity tooling I already use. Fixing my own annoyances is the most reliable contribution pipeline there is.
Speak at a conference
PlannedPresent research — even a short talk at a local event. Writing it up for an audience is the fastest way to find the gaps in your own understanding.
For the shorter horizon, /now covers this month.

