<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Zero Trust Machines</title>
    <link>https://zerotrustmachines.com/</link>
    <description>Essays on zero trust architecture: identity as the control plane, policy enforcement and decision points, microsegmentation in practice, device posture, workload identity and mutual TLS, and the honest limits of the model.</description>
    <language>en</language>
    <atom:link href="https://zerotrustmachines.com/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>What Zero Trust Does Not Fix</title>
      <link>https://zerotrustmachines.com/what-zero-trust-does-not-fix/</link>
      <guid isPermaLink="true">https://zerotrustmachines.com/what-zero-trust-does-not-fix/</guid>
      <pubDate>Thu, 30 Jul 2026 00:00:00 +0000</pubDate>
      <category>Limits</category>
      <description>The model relocates trust rather than eliminating it. Knowing precisely where it was relocated to — the issuer, the policy, the enforcement points, the administrators — is the difference between architecture and belief.</description>
    </item>
    <item>
      <title>Workload Identity Without Shared Secrets</title>
      <link>https://zerotrustmachines.com/workload-identity-without-shared-secrets/</link>
      <guid isPermaLink="true">https://zerotrustmachines.com/workload-identity-without-shared-secrets/</guid>
      <pubDate>Sat, 18 Jul 2026 00:00:00 +0000</pubDate>
      <category>Workloads</category>
      <description>Service-to-service authentication is where most estates still run on long-lived credentials that nobody can rotate. Replacing them means giving workloads identities they cannot copy and did not have to be told.</description>
    </item>
    <item>
      <title>Device Posture, and the Cost of Checking Again</title>
      <link>https://zerotrustmachines.com/device-posture-and-the-cost-of-checking-again/</link>
      <guid isPermaLink="true">https://zerotrustmachines.com/device-posture-and-the-cost-of-checking-again/</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <category>Device Signals</category>
      <description>Posture is a claim made by software running on the machine being assessed. Re-checking it continuously is the expensive part of zero trust, and the expense is where most implementations quietly compromise.</description>
    </item>
    <item>
      <title>Microsegmentation on the Diagram and in Production</title>
      <link>https://zerotrustmachines.com/microsegmentation-in-production/</link>
      <guid isPermaLink="true">https://zerotrustmachines.com/microsegmentation-in-production/</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <category>Segmentation</category>
      <description>Segmentation is easy to draw and hard to keep. The difficulty is never the enforcement technology — it is that nobody has an accurate description of which systems legitimately talk to which.</description>
    </item>
    <item>
      <title>Identity as the Control Plane</title>
      <link>https://zerotrustmachines.com/identity-as-the-control-plane/</link>
      <guid isPermaLink="true">https://zerotrustmachines.com/identity-as-the-control-plane/</guid>
      <pubDate>Thu, 11 Jun 2026 00:00:00 +0000</pubDate>
      <category>Identity</category>
      <description>If policy is written against identity, then the identity system is not one control among many — it is where authority is manufactured, and the estate inherits every weakness it has.</description>
    </item>
    <item>
      <title>What the Perimeter Was Actually For</title>
      <link>https://zerotrustmachines.com/what-the-perimeter-was-actually-for/</link>
      <guid isPermaLink="true">https://zerotrustmachines.com/what-the-perimeter-was-actually-for/</guid>
      <pubDate>Tue, 02 Jun 2026 00:00:00 +0000</pubDate>
      <category>Architecture</category>
      <description>The network perimeter was not a mistake. It was an amortisation strategy for the cost of authorisation, and it worked until network location stopped predicting anything useful about the requester.</description>
    </item>
  </channel>
</rss>
