I am Daniel Alfocea, known for years as cr0hn
I find where a system breaks before someone else does. Especially when AI is involved.
I have spent twenty years doing it inside banks and large companies. Now I give training and consulting on secure development and AI security. And every day I send one email, Vamos al lío, about one thing I saw break that week. It takes three minutes to read.
As soon as you sign up you get the audio on why your AI turns dumb by the sixth message. Tomorrow at 15:17 the first email lands. Unsubscribe with one click.

So you know who you are talking to
I started by breaking systems. Then I wrote tools so I would not have to break them by hand every time. Some ship by default in the system security professionals use all over the world. Others are used by teams that will never know my name.
Once I found the medical records of millions of people sitting open on the internet. The owner believed it was closed. I wrote to them. They avoided a fine of the kind that hurts. They did not thank me, and that is not why I did it.
A process that took eight hours dropped to a tenth of a second. Same machine, same code. I only looked at where the time went. It is what I always do: find where time goes, where it will break under pressure, and where someone will get in.
I gave a talk and several companies checked their systems the next day. Some found open doors that had been there for months. That is what I want to happen to you. Before anyone gets in.
I have been inside BBVA, across much of Spain's IBEX 35, and with companies in the US, India and the UK. Not as a visitor: inside, with the system running. At Banco Santander I was the technical lead of the AI team while they built the new area. The bank has 185,000 employees and OpenAI as a partner; my job was making it work on the inside.
I founded Navaja Negra and OWASP Madrid because Spain needed places to talk about security without the posture. I have spoken at RootedCON, RSA and Codemotion. With Alfonso Muñoz I wrote a book on AI security that is on Amazon.
Now I work on my own. I train teams and step in when the problem will not die in another meeting. And every day I send one email about one thing I saw break, so it does not break on you.
The long version is on About. If you would rather see how I think, join the newsletter: tomorrow at 15:17 I send you the first one.
Where else to find me
- Services I give training and consulting on secure development, AI security and how to use AI for real.
- The podcast I make short episodes and each one covers a single idea.
- The blog I write long technical articles, in Spanish and English.
- cr0hn I explain why I changed my name and what stayed the same.
- Email me Write to me with a concrete problem.