Stuart Thomas
01
A Commodore PET 2001 Series computer, its screen showing the Commodore BASIC ready prompt.
Plate I · Commodore PET 2001 SeriesAI-rendered to a written brief

stuart thomas

whitby north yorkshire

It started on a machine like this one. His father’s PET — dual disk drive and a printer — at a time when school meant a room full of BBC Micros. By five he was repairing one for a retired teacher.

Forty years on, the work is the same shape at a different scale: the cryptographic standards protecting sixty million NHS patient records, co-authored; the key architecture behind eight million contactless journeys a day on Transport for London; and still the bench work — fixes landed in OpenBSD, two CVEs credited by Apple in 2026. Standards authors don’t usually still find kernel bugs.

He works in writing, at his own pace, from the town at the bottom of the page.

02 Whitby harbour at night, lit windows above the water

information security practice

whitby north yorkshire

The lit windows are the point. Cryptographic systems and smart cards — the NHS national cryptographic standards, co-authored; the key architecture behind TfL contactless. Data protection — DPIAs, LIAs, ROPAs and breach response across clinical trials, retail and law firms. Vulnerability research — macOS, Darwin/XNU and OpenBSD, with fixes credited upstream in OpenBSD −current and three Apple disclosures published in 2026. Also penetration testing and incident response, network and protocol engineering, application security, and compiler and JIT analysis. Forty years of it. Commissioned work runs through TriageForge; the record is here.

Whitby, after dark — AI-rendered to a written brief, and labelled as such.

03
Stuart Thomas
Plate I · the surveyorWhitby, 2026

forty years

1986 – 2026

Started on a Commodore PET at five, for a retired teacher who wanted her machine back. Has since written cryptographic standards read by a national health service, designed the key management behind eight million daily journeys, and spent thirteen years’ worth of other people’s latent bugs finding them before somebody worse did. Neurodivergent, plain-spoken about it, and — for the last stretch — working in writing, at his own pace.

04

forty-year highlights

60MNHS patient records protected by standards he co-authored
8Mdaily contactless journeys on the key architecture he designed
22,000readers under one cryptographic key-management scheme
13years a relayd request-smuggling bug lay latent before he found it

Delivered for NHSTransport for LondonPwCDeloitteLondon Stock ExchangeHarrodsBootsSony PlayStationOraclePAREXELHome Office · DWP · DfT

05

record of delivery

2000 – 2023

Interim Data Protection Officer

DPO Interim Ltd

Practical DPO work — DPIAs, LIAs, ROPAs, breach response, vendor schedules, training. Not slide decks.

Cyber security & data protection consulting

PwC · Deloitte · Harrods · Boots · London Stock Exchange

GDPR implementation, security architecture, penetration testing and incident response across financial services, retail and critical national infrastructure.

Contactless travel security

Transport for London

Designed the cryptographic key-management architecture for London’s contactless payment network — ISO 27001 and PCI DSS compliant, 22,000 readers, 8 million transactions a day.

National cryptographic standards

NHS Connecting for Health

Co-authored the cryptographic security standards for the NHS national programme: smart-card infrastructure, key-derivation protocols, 60 million patient records.

PlayStation 2 UK network

Sony

Designed the online infrastructure for the PlayStation 2 UK launch. The technology was sound.

Ethical hacking

Oracle

The thing IBM was putting on the wanted list in 1999.

06

research & disclosure

independent 2026

libslirp

Two libslirp CVEs, credited

CVE-2026-95507 · CVE-2026-95508 · assigned 22 September 2026

Two guest→host memory-safety defects in libslirp, the user-mode network stack behind QEMU’s default VM networking. An NC-SI OEM handler reads up to four bytes past the supplied packet and reflects them into the guest’s reply — information disclosure, CWE-125, rated Moderate by Red Hat at CVSS 3.1 4.3. The DHCPv6 and TFTP response builders overflow the reply buffer where if_mtu is configured small — memory corruption, CWE-787, rated Important at CVSS 3.1 7.4.

Found by source audit and confirmed with minimised reproducers under a guard-page allocator. Patches written here and applied upstream by the maintainer; fixed in libslirp 4.9.5. Coordinated through Red Hat Product Security, which records: “Red Hat would like to thank Stuart Thomas for reporting this issue.” Credited, not a paid bounty.

CVE-2026-95507 · CVE-2026-95508

Apple

Two Apple CVEs, credited

CVE-2026-84538 · CVE-2026-84553 · shipped 14 September 2026

A kernel NFS-server denial of service and an SMB resource-exhaustion flaw, both fixed across macOS Golden Gate 27, Tahoe 26.7 and Sequoia 15.8. A third report is acknowledged under Terminal in the iOS 27 and macOS Golden Gate 27 advisories.

Disclosure

RELAYD-001 — OpenBSD relayd request smuggling

CWE-444 · fixed 2026-06-03 · commit e8e5aa2db9c

Thirteen years latent. A single crafted request made proxy and backend disagree on the message boundary. Found by a source-review pass against the RFC 9112 framing rules; fixed in −current.

Apple

Three macOS disclosures, published

13 May 2026 · bounty consideration forfeited by design

PING-01 (out-of-bounds write in /sbin/ping), SMB-01A (smbd copy-chunk DoS) and MAILDROP-01 (unsigned parameters on icloud.com) — each with vendor references and status notes. Apple fixed the first two on 14 September 2026; MAILDROP-01 remains under review.

Book

macOS Security Research: A Complete Framework

Free · CC BY-SA 4.0 · DOI 10.5281/zenodo.19855016

A six-phase methodology from 35 years of structured practice — scope, recon, research tracks, red-team, submission, archive. Eleven chapters.

Paper

The Calculator Discipline

DOI 10.5281/zenodo.20393083 · CC BY 4.0

A four-class taxonomy of how AI-assisted disclosures go wrong, a pre-send filter that catches the mechanical two, and two real withdrawals from the author’s own OpenBSD work.

07

now, in whitby

pro bono no fee

Provenance

Whitby Jet Provenance Platform

An NFC tag in every genuine piece carries an unforgeable AES-128 signature. Tap with any phone — no app required.

authenticwhitbyjet.co.uk
Maritime

Cyber security for Whitby’s harbour

A plain-English guide for fishing operators, quayside businesses and maritime families: GPS spoofing, onboard networks, invoice fraud, insurance gaps.

Read the guide
Data protection

Pro bono help for small organisations

Community groups, charities and small research teams with a genuine data-protection question. A record of what I know, not a services page.

What I can help with
08
Robert Dixon, Whitby jet worker

jet

whitby 1911

Robert Dixon, four-times great-grandfather, worked Whitby jet in the heart of the trade. Standing on the same streets, using cryptography to protect what he helped create felt inevitable.
William (Bill) Steele, Merchant Navy radio officer, c.1940

signals

scarborough c.1940

Bill Steele, grandfather, Marconi-trained radio officer on wartime convoys, then a Cold War listening post at Scarborough, copying Russian Navy Morse. The thread between his radio set and AES-128 is there.
09

To whoever is reading

a note on working with me

Being honest upfront saves everyone time. I’m neurodivergent — ADHD, autism, RSD. Over 35 years I’ve had more than 75 jobs. I do my best work on things that genuinely interest me, on my own terms, at my own pace.

This site is a record, not a shop window. It is what I’ve done, what I know, and what interests me. Commissioned data-protection and security work runs through TriageForge. I also share knowledge pro bono when health and energy allow, for community, charity or research purposes.

Written communication only. No phone calls, no video meetings, no real-time chat. Async, at my pace. I may not respond quickly. I may not respond at all. That isn’t rudeness — it’s capacity.

Stuart ThomasWhitby, September 2026

10

six I don’t bend on

checked against every job

Provenance
Where it came from is most of the question. Jet, NHS data sets, audit findings — same rule.
Heritage
Some skills, places and objects only happen once. Make sure they survive the next bit.
Honesty
What it is. What it isn’t. What I’m still not sure about — all three on the page, labelled.
Craft
Build it well enough that you’d be glad to find your own work twenty years on, with the lid off.
Accessibility
If it only works for some of us, it doesn’t really work.
Independence
No investors, no retainers, no conflict I have to work around. Work is taken on its merits, one piece at a time. The simplest of the six; probably the most expensive.
11

credentials

held not claimed

CIPP/ECertified GDPR PractitionerCiSMP · DistinctionGIAC GSECISO 27001 · implementation

Not a Lead Auditor, and I don’t claim to be: ISO 27001 experience is implementation, pre-audit preparation and post-certification management — not leading audits.

12

Correspondence

if it fits the note above, write.

stuartpaulthomas@gmail.com

Based in Whitby. Genuine pro bono questions from community, charity, research or family contexts are welcome here. For commissioned data-protection or security work, write to TriageForge. If it is urgent, or needs legal advice, I’m not the right person.

This site uses no cookies or tracking. Server logs only. Privacy notice