Evidence outranks claims. That single rule shapes every decision I make about how to review a protocol: what to read first, what to test, what to write down, and what to keep private.
Most security work is a tight loop: understand the system, trace the risky paths, test what can actually break, and write down what a developer can act on. The order is deliberate. Reading for bugs before understanding intent produces noise; knowing the threat model first produces findings that survive being questioned.