Category
Security
Secrets, exposure and the defensive posture of the things you run for clients.
Secrets, exposure and the defensive posture of the things you run for clients.
A monitoring tool holding readable credentials is a breach waiting to happen. Ours can’t.
HSTS, CSP, nosniff, framing, Referrer-Policy, Permissions-Policy. What each one stops, and the exact lines to add for nginx, Apache and Node.
A session cookie without the right flags is a session waiting to be stolen. What Secure, HttpOnly and SameSite do — and how to set them on any stack.