About

About

I’m Filipe Paz Rodrigues. I write about security, smartcards, and embedded devices, and I use this blog to work through things in more depth than a thread or a set of notes allows.

Most of what ends up here starts the same way: I read about something that sparks my interest, then I start writing about it. I make an effort for all of my blog posts to be independently verifiable by providing source code and references.

Disclaimer: I use large language models as part of my writing process. I am the one that always starts the draft, while AI helps me with additional information, restructuring, and catching mistakes. The code, the commands, their output, and the sources are always independently verified before a post is published.

What’s here

Two series so far, both best read in order:

  • Container runtimes — what container runtimes actually do, starting from OCI and CRI fundamentals and working down through runc’s lifecycle: namespaces, the init process, the rootfs, capabilities, seccomp, and the OCI hooks.
  • CVE-2025-23266 — a two-part look at the NVIDIA Container Toolkit escape, including how to reproduce it and why createContainer hooks made it possible.

Everything is indexed under tags and archives.

Open source

Most of my open source work has been on the same problem from different angles: making USB smartcard readers work on embedded hardware. The CCID specification is how a host talks to a smartcard reader over USB, and it tends to be the missing piece in otherwise capable USB stacks.

Alongside those, a few smaller things of my own: a smartcard simulator on an ATtiny85, a smartcard built as a PCB, and tooling for the Neander educational processor.

Elsewhere

For anything sensitive, my PGP key is on Keybase and the proof is at /keybase.txt:

1
A0E3 5546 1DBD 974A 9D57  BFF6 09B5 836B F3FA F8B8

About the site

Static, built with Jekyll and the Chirpy theme, published to GitHub Pages and mirrored to S3. I wrote up the reasoning, and the move off WordPress that prompted it, in Moving to Jekyll.