DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
The Password Reset Flow: Where Good PHP & Laravel Developers Ship Bad Security

The Password Reset Flow: Where Good PHP & Laravel Developers Ship Bad Security

1
Comments 1
16 min read
I ran someone else's vibe-coded app through four AIs at once. Here's what they found in an hour

I ran someone else's vibe-coded app through four AIs at once. Here's what they found in an hour

Comments
4 min read
I Replaced a Gate That Accepted Everyone With a Gate That Accepted No One. My Tests Couldn't Tell the Difference.

Tests passing while security fails completely

I Replaced a Gate That Accepted Everyone With a Gate That Accepted No One. My Tests Couldn't Tell the Difference.

35
Comments 25
17 min read
The Finding That Hasn't Fired Yet

The Finding That Hasn't Fired Yet

1
Comments
8 min read
CRC32 vs SHA-256 vs XXHash: Which Checksum Should You Use?

CRC32 vs SHA-256 vs XXHash: Which Checksum Should You Use?

Comments
2 min read
NestJS Production Checklist: 17 Checks Before You Deploy

Includes strict Zod schema validation tips

NestJS Production Checklist: 17 Checks Before You Deploy

22
Comments 9
17 min read
Calling redirect() Inside a Suspense Boundary Doesn't Undo What Already Streamed to the Browser

Calling redirect() Inside a Suspense Boundary Doesn't Undo What Already Streamed to the Browser

1
Comments
3 min read
Build a PQC migration inventory that separates key exchange from certificate signatures

Build a PQC migration inventory that separates key exchange from certificate signatures

Comments
5 min read
My security test was green for six weeks because it could not turn red

My security test was green for six weeks because it could not turn red

Comments
3 min read
Harvest Now, Decrypt Later: Why Post-Quantum Cryptography Can't Wait

Harvest Now, Decrypt Later: Why Post-Quantum Cryptography Can't Wait

Comments
6 min read
AI in the SOC: The Seductive Trap of Automation Without Thinking

AI in the SOC: The Seductive Trap of Automation Without Thinking

Comments
7 min read
Building Your Own Sovereign CVE Watch: An OpenCVE Field Report

Building Your Own Sovereign CVE Watch: An OpenCVE Field Report

Comments
5 min read
Themes, slots and AI edits for untrusted components

Themes, slots and AI edits for untrusted components

1
Comments 2
7 min read
Die meisten Sicherheitsvorfälle sind langweilig

Die meisten Sicherheitsvorfälle sind langweilig

Comments
1 min read
Why SAST and DAST Aren't Enough for Secrets Security

Why SAST and DAST Aren't Enough for Secrets Security

Comments
10 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.