A strong password breached. Multi-factor authentication saved the day. So many passwords to check. Why can each site not use OpenID Connect single identity?
Happy Eyeballs? Mime-Type-Sniffing? Security wins, don't infer content type from file name.
Take Wordpress. Modernise it. Make it cloud-native. Add tidb cloud-native database. Add stateless storage.
Do what I say. The central tennet of security. In web application security, this translates to a set of headers. Learn how to use Content Security Policy, XSS, CORS, etc.
Digitally Disconnected. The 2nd class citizens of the 21st Century. Unable to access data due to identity or VPN. NO MORE! Zero Trust.
Risk versus Reach. A false choice. We should not materially compromise security to reach more users.
The humble cookie. So controversial. So complex to secure. If your web app must have them, you must secure them.
You and your browser run inside a nice safe firewall. A firewall which doesn't do what you think. Explore how the browser is the accomplice to the crime.
The Content-Security-Policy headers exists to protect the users of your web site from the content they themselves might create.
Web applications may not be inherently secure. But we want them Internet available anyway. How can we reconcile these two? Let's see!.
VPN slow? It might be your friends using YouTube and Spotify. Ration bandwidth? Split Horizon? We recommend door #3: Zero Trust, Internet Exposed, Direct.
A sudden influx of remote workers is stressing the VPN. That stateful device struggles. Consider a future switch to Zero-Trust, secure remote access with it.
Agilicus. Its a compass on a shield, reminding us of the need to protect from the east-west traffic. But what about the name? The icus part invokes Spartacus (from which… Read More »The Philosophy Behind The Name