I build software, then I try to break it before anyone else does.
Self-taught since age 10. Full-stack development, cybersecurity, and hardware design. I run Kjern, my own electronics company where I design circuit boards and ship real products, solo, from my room in Bergen.
I've spent the last couple of years doing practical security work: penetration testing, source review, and responsible disclosure to both private companies and public sector organizations. I find vulnerabilities, report them quietly, and move on. Several fixes I suggested are running in production today.
I also care about building things people actually use. Not demos, not concepts. Stuff that runs, stays up, and does what it says.
| Project | What it is | Stack |
|---|---|---|
| Messages Never Seen | Anonymous platform for unsent messages. Grew into a large community on self-hosted infra. | Flask SQL JS |
| Kjern | My hardware company. Custom PCB design, MCU/MPU dev boards, shipped products. | KiCad Firmware C++ |
| Anonymyze.Me | Write a problem anonymously, get real answers. No accounts, no names. | Flask SQL JS |
| VolaryDDNS | Free, fast, privacy-first dynamic DNS service. | Flask SQLite Tailwind |
| VisualMETAR | Desktop app for live aviation weather. 5,000+ downloads. | Python |
| p1h.me | Dead simple URL shortener. Paste, shorten, share. | Flask Supabase Tailwind |
There's more that isn't listed here, plus things still being built.
STATUS: Active researcher · ~2 years practical experience
FOCUS: Auth/token validation, CSRF, credential hygiene, API hardening
METHOD: Find it, write it up, hand it over privately, stay quiet until patched.
POLICY: Responsible disclosure only. No proof-of-concept dumps, no drama.
"Minify your JavaScript all you want. I'll still un-minify it, find the keys you left in there, and email you about it like a disappointed parent."




