Security
14 posts in this domain.
- Hardening a cloud server Spin up a fresh VPS, wait an hour, and the auth log already has thousands of brute-force attempts from across the internet. Every server-hardening guide says roughly the same things — here's what each one actually stops, and where the rules are theater. May 25, 2026 · intro
- How end-to-end encryption works Open WhatsApp and a banner tells you Meta can't read your messages. That claim sits on a specific protocol — Diffie–Hellman key agreement plus a 'double ratchet' that changes the key on every message. Here's the shape of it. May 24, 2026 · intermediate
- Why Spectre still isn't fully patched Eight years after disclosure, new Spectre-class vulnerabilities keep landing. The reason isn't sloppy patching — the speculation being exploited is what makes modern CPUs fast, and the list of channels it leaks through has no end. May 4, 2026 · intermediate
- Why ECDSA nonce reuse leaks the private key ECDSA needs a fresh random number for every signature. Use the same one twice and anyone watching can recover the private key with two lines of algebra — which is exactly how the PS3's master key fell out. May 2, 2026 · intermediate
- Why 'harvest now, decrypt later' is driving post-quantum crypto adoption A sufficiently large quantum computer doesn't exist yet. Encrypted traffic from 2018 might already be sitting on a tape, waiting for one. That asymmetry — encrypt now, decrypt later — means the damage starts when the recording happens, not when the machine arrives. May 2, 2026 · intermediate
- Why supply-chain attacks dominate the JavaScript ecosystem A small npm install pulls in a thousand-odd packages from hundreds of strangers, and some of that code runs before you type anything. JavaScript's deep, trusting dependency graph is the attack surface, and every step of the attack is a feature someone shipped on purpose. May 2, 2026 · intermediate
- What is public-key cryptography? Until 1976, published cryptography required both sides to already share a secret. Public-key crypto broke that chicken-and-egg problem and quietly became the substrate of the modern internet. Apr 30, 2026 · intro
- ASLR: why we shuffle memory before every run Attackers used to know exactly where your code lived in memory. ASLR reshuffles it every run, so an exploit has to learn the layout before it can use it — which is why modern exploit chains start by leaking a pointer. Apr 29, 2026 · intermediate
- Why JWTs are controversial JWTs solve a real problem — stateless auth across services — and then keep solving it past the point where the cure is worse than the disease. Here's where the seams are. Apr 29, 2026 · intermediate
- Passkeys: why the password is finally being replaced Passwords are a shared secret you keep retyping into whatever site asked. Passkeys replace it with a key pair whose private half never reaches the site at all. Apr 29, 2026 · intro
- Why password hashing is deliberately slow SHA-256 is fast and that's exactly why you must not use it for passwords. Password storage is the rare corner of computing where being slow — and greedy with memory — is the feature. Apr 29, 2026 · intermediate
- Why prompt injection isn't a bug to be patched SQL, XSS, and command injection are all fought the same way: separate the code channel from the data channel. An LLM has labels for that boundary and nothing that enforces them, so the move that works everywhere else has nowhere to land. The vulnerability is the architecture. Apr 29, 2026 · intermediate
- Why constant-time comparison is a thing An ordinary equality check leaks the secret it's supposed to protect — one byte at a time, through the clock. Constant-time comparison exists because == is faster than it should be. Apr 29, 2026 · intermediate
- Why public-key signatures are not just 'encryption in reverse' They look symmetric — encrypt with one key, decrypt with the other — but signatures and encryption answer different questions, and conflating them is how real cryptosystems get broken. Apr 29, 2026 · intermediate