Cyber Security Engineer ยท MorphOS Developer ยท Open Source

Pawel Stefanski Security Infrastructure & Retro Computing

Building zero-trust authentication systems by day, creating MorphOS applications and demoscene productions by night. CyberArk / PaloAlto engineer with 20+ years in IT.

0
Years in IT
0
Released Projects
0
Technologies
0
LinkedIn Connections

From Amiga to Cyber Security

My adventure with computers started in 1990 when I saw an Amiga 500 for the first time. The graphics, the sound โ€” I was hooked. My parents bought me an Amiga 1200 around 1992/1993 and I've been coding ever since.

📱

Early Years

In 1996 I co-founded the Ostroleka Amiga User Group. We developed games and tools. In 1998 my demoscene career began with Nah-Kolor, creating disk magazines, music disks, videos and demos.

💡

MorphOS Era

In 2000 I joined the #Amigazeux developer group and started developing MorphOS applications. I was invited to join the MorphOS Team, creating Paint, Sketch, Transfer, Titler, and many more applications.

🛡

Professional Career

From PTC, Schneider Electric, and Airbus through ING, GE, and Friend Software Labs โ€” to CyberArk / PaloAlto today. Building security infrastructure across Windows, Linux, Android, and embedded systems.

$ cat ABOUT.md
Company: Transition Technologies PSC / CyberArk / PaloAlto
Role: Cyber Security Engineer
Location: Warszawa, Poland
Specialty: Zero-trust security, cryptography, cross-platform systems
Hobby: Amiga, MorphOS, Demoscene, Retro computing
Motto: "Build things that matter. Have fun doing it."
[OK] Profile complete โ€” 25+ projects released
"Strongly motivated and focused on the target. Great programmer and skilled analyst. I like to work with Pawel each time."
โ€” Rafal J., former colleague at LinkedIn recommendation

Career milestones

1990

First contact with Amiga 500

The spark that started a lifelong passion for computing.

1996

Ostroleka Amiga User Group co-founder

Local Amiga user group. Game and tool development. Demoscene beginnings.

1998

Demoscene โ€” Nah-Kolor

Disk magazines, music disks, videos, and demos. Met incredible people across Europe.

2000

MorphOS developer, joined MorphOS Team

#Amigazeux developer group. System and application development. First Genesi hardware.

2005

First full-time job โ€” PTC, Schneider Electric, Airbus

Trained across Europe (Lyon, Munich, Stuttgart, Toulouse). Contributed to A380 and Beluga programs.

2008โ€”2015

ING / Nationale Nederlanden

Programmer/Senior IT Analyst. Cobol, Java, WebSphere, JBoss, Tibco, Crystal Reports.

2016

General Electric + Friend Software Labs

Source migration systems at GE Aviation Institute. "Operating System for Cloud" at Friend Software Labs.

Present

Cyber Security Engineer at CyberArk / PaloAlto

Zero-trust security infrastructure. ECC P-384 cryptography. Bluetooth authentication. MobileProvider project.

Professional & Open Source Work

From enterprise security systems to MorphOS applications โ€” spanning two decades of software engineering across Windows, Linux, Android, and Amiga platforms.


MobileProvider โ€” Zero-Trust Authentication

My flagship open-source security project. Turn any mobile device into a hardware-backed authentication token with ECC P-384 cryptography and Bluetooth transport. No cloud dependency. Available for Windows, Linux, and macOS.

📺

Windows Service

Native SCM service with Bluetooth RFCOMM, named pipe IPC, and Credential Provider integration.

v2.4.1x64
Download .msi
🐧

Linux Daemon

systemd service with BlueZ RFCOMM, PAM authentication, logind session management.

v2.4.1amd64/arm64deb/rpm
Download .deb Download .rpm
📱

Android App

Encrypted vault with biometric confirmation. API 29+. No key material stored on device.

v2.4.1APK
Download .apk
🌐

Browser Extensions

Chrome, Firefox, Edge. Native messaging bridge to local service. MV3.

v2.4.1MV3
Chrome (.zip) Firefox (.xpi) Edge (.zip)
🪄

Windows SDK

MobileProviderSDK.dll with C API header. Integrate apps with the service.

v2.4.1
Download SDK .zip
🪄

Linux SDK

libmobileprovidersdk.so.1 with header. Available in deb/rpm repositories.

v2.4.1
Download dev .deb
📷

macOS Service

launchd daemon with IOBluetooth RFCOMM, os_log, Unix domain socket IPC. macOS 13+.

v2.4.1universal
Download .pkg Install via Homebrew
🪄

macOS SDK

libmobileprovidersdk.dylib with header. Integrate with any macOS app via C API.

v2.4.1
Download SDK .zip

Enterprise & commercial work

🏦

ING Bank & ING Insurance Poland

Designed and programmed HR forms, OFE website, COP application features, and Crystal Reports. Full-stack development with Cobol, Java, WebSphere, JBoss, and Tibco (2008โ€”2015).

✈️

Airbus โ€” PTC / Schneider Electric

Worked on the A380 and Beluga programs as part of the PTC and Schneider Electric projects. Trained across Europe.

⚙️

General Electric โ€” Aviation Institute

Developed a source migration system for the Aviation Institute, modernizing legacy codebases (2016).

☁️

Friend Software Labs

Core developer on the "Operating System for the Cloud" โ€” a decentralized cloud platform (2016โ€”present).

🎨

Cadalog INC โ€” SketchUp Plugin

Developed a SketchUp plugin for Kray raytracing integration.

🏛️

M4B โ€” Museum Applications

Full server and client stack for the Museum of Solidarity in Gdansk.

📋

Nanovo โ€” Queue Control

Raspberry Pi application for shop queue management and customer flow control.

🎮

Funtronic โ€” Interactive Floor & Games

Games for "Magiczny Dywan" interactive floor. Multiplatform engine & educational games "Bambikowe Logoprzygody" and "Akademia Bambika".


Open source, demoscene, retro computing

🎨

Paint

Image editor with layers, masks, plugins SDK. Ships with MorphOS.

📥

Transfer

FTP/SFTP client with 64-bit support, tabs, MUI GUI. Ships with MorphOS.

🖼️

Sketch

Lightweight image editor. Included in MorphOS system distribution.

📹

Titler

3D text animation with TinyGL. TrueType fonts, export via mencoder.

🎯

Teksturator

LightWave object texturing and conversion tool.

📝

Gallerius

HTML gallery generator with auto-thumbnails, drag-and-drop, captions.

💰

Miliarderzy

Quiz game based on "Milionerzy". AmigaOS 3.x, MorphOS, Windows.

🌍

Animator

3D object animation. Load LightWave, generate keyframes.

🎲

Arka3oid

Arkanoid in 3D. Level editor, multiple bonuses. In development.

📖

DJVUViewer

MorphOS DJVU document reader.

🖼️

MiniShowPicture

Fast image browser using datatypes.

✂️

ImageMapper

HTML image slicer with clickable maps.

📲

GLUI

C++ OpenGL GUI toolkit. XML skinning, multiplatform.

🎛️

AmiNetRadio plugins

3D visualizer plugins for AmiNetRadio.

🎬

Demoscene productions

Nah-Kolor demos, disk magazines, music disks.

MobileProvider SDK & API

Integrate any application with MobileProvider security infrastructure. C-compatible API, same interface on Windows, Linux, and macOS. Build third-party tools, automate workflows, extend the platform.


19 functions โ€” complete reference

1. Connection Management

FunctionSignatureDescription
IsMobileAvailablebool IsMobileAvailable()Returns true if the service pipe/socket can be opened.
SayHelloconst char* SayHello()Sends HELLO handshake. Returns service greeting with version info.
RequestConnectionconst char* RequestConnection(const char* deviceName)Initiate Bluetooth connection to a named device.
DisconnectDeviceconst char* DisconnectDevice()Disconnect the current Bluetooth device.
Repairconst char* Repair()Trigger Bluetooth repair sequence.

2. Status & Monitoring

FunctionSignatureDescription
GetMobileStatusconst char* GetMobileStatus()Returns connection, pairing, and device state as JSON.
SetAutoLogoutconst char* SetAutoLogout(int action, int intervalMs, int timeoutCount, int btDisconnectEnabled)Configure auto-logout: action, PING interval and timeout count.
SetInactivityConfigconst char* SetInactivityConfig(int enabled, int timeoutSec)Configure inactivity lock: enable/disable and timeout.
SetConfigStorageTypeconst char* SetConfigStorageType(const char* type)Switch config backend: "file" or "registry".

3. Credential Storage

FunctionSignatureDescription
CreateEntryconst char* CreateEntry(const char* key, const char* jsonData)Create encrypted entry with P-384 + AES-256-GCM.
GetEntryconst char* GetEntry(const char* key)Retrieve and decrypt entry by ID.
DeleteEntryconst char* DeleteEntry(const char* key)Delete entry by ID from both service and mobile.
ListEntriesconst char* ListEntries()List all stored entry metadata as JSON array.
StoreCredentialsconst char* StoreCredentials(const char* username, const char* password)Validate and store Windows credentials.
GenerateCredentialconst char* GenerateCredential(const char* requestJson)Ask the phone to complete a field set (each field prefilled, user-typed, or generated on-device); returns the completed set and stores a sealed copy.
FreeStringvoid FreeString(const char* s)Securely wipe the per-thread return buffer after copying a secret-bearing reply.

4. Authentication

FunctionSignatureDescription
RequestAutologinconst char* RequestAutologin(const char* key)Trigger browser autofill with mobile biometric confirmation.
RequestWindowsLoginconst char* RequestWindowsLogin()Trigger Windows login via mobile confirmation.

5. Bluetooth Device Management

FunctionSignatureDescription
ListDevicesconst char* ListDevices()List paired Bluetooth devices.
UnpairDeviceconst char* UnpairDevice(const char* address)Unpair specific device by Bluetooth address.
UnpairAllDevicesconst char* UnpairAllDevices()Unpair all Bluetooth devices.

Wire format

All SDK communication uses 4-byte little-endian length-prefixed JSON. Same format on Windows (named pipe), Linux, and macOS (Unix domain socket).

OffsetSizeFieldDescription
04 bytesLength (LE uint32)Payload size in bytes
4N bytesJSON payloadUTF-8 encoded JSON message

📖

Architecture Guide

Full system architecture, component interaction diagrams, data flow.

PDF
rorbit-architecture.pdf
📖

Deployment Guide

Installation for Windows, Linux, Android. systemd, SCM, packaging.

PDF
rorbit-deployment.pdf
📖

Security White Paper

Threat model, cryptographic design, FIPS 140-3 / GDPR compliance.

PDF
rorbit-security-whitepaper.pdf

Get in touch

Have a question, a project idea, or just want to say hello? Reach out via email or LinkedIn.

📧 Email: rorbitcompany@gmail.com

📍 Location: Warszawa, Poland

👤 LinkedIn: linkedin.com/in/pawel-stefanski

🌐 Website: stefkos.morphos.pl

Response: Usually within 24โ€”48 hours


Social & Professional

1,000+ followers on LinkedIn. 500+ connections. Let's connect and build something great.