Security Notes
Analyses on product security.
Technical analyses, practical engineering insights and regulatory context for teams developing security-critical products.
Redlings’ own investigations and research findings are published under Research.
Engineering Note
Featured
Mar 12, 2026
8 min read
Secure Boot: What Signature Verification Protects, and What It Doesn’t
FirmwareSecure BootTesting
Read note →
Current Note
Aug 27, 2026
7 min read
CRA Vulnerability Reporting: The Technical Reality of the 24-Hour Window
RegulationVulnerability
Current Note
Aug 13, 2026
6 min read
EN 18031 and the CRA: What Security Testing Can Show, and What It Can’t
RegulationTesting
Engineering Note
Jul 23, 2026
8 min read
“Does This CVE Affect Our Product?”. A Practical Triage Workflow
FirmwareRegulationVulnerability
Field Note
Jul 9, 2026
5 min read
Field Note: “The Key Is in a Secure Element”. What We Check Next
CryptographyDevice Identity
Engineering Note
Jun 25, 2026
7 min read
Embedded Device Penetration Testing: Why a Web Pentest Isn’t Enough
FirmwareTestingWireless
Engineering Note
Jun 11, 2026
7 min read
Firmware Extraction: Why Readable Flash Changes Your Threat Model
FirmwareTesting
Engineering Note
May 28, 2026
7 min read
Device Identity: Why Shared Credentials Put the Fleet at Risk
CryptographyDevice Identity
Engineering Note
May 14, 2026
8 min read
BLE Pairing Security: Encryption Doesn’t Tell You Who You’re Talking To
CryptographyWireless
Engineering Note
Apr 30, 2026
8 min read
Secure Element vs. Secure Storage vs. TPM: Where Device Keys Belong
CryptographyDevice IdentityTesting
Engineering Note
Apr 16, 2026
8 min read
Firmware Anti-Rollback: Why Signed Firmware Can Still Be Downgraded
FirmwareSecure BootVulnerability
Engineering Note
Mar 26, 2026
7 min read
Secure Boot vs. Firmware Signing vs. Code Signing: The Differences Explained
CryptographyFirmwareSecure Boot