DEV Community

Security

Hopefully not just an afterthought!

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Stuck on Casbin's model.conf? 5 mistakes beginners hit most

Stuck on Casbin's model.conf? 5 mistakes beginners hit most

Comments
3 min read
I DNA-encode my encrypted database before writing it to disk - here's why (and why it's not "quantum" anything)

I DNA-encode my encrypted database before writing it to disk - here's why (and why it's not "quantum" anything)

Comments 1
2 min read
Chống DDoS Layer 7 Với Cloudflare Workers & KV

Chống DDoS Layer 7 Với Cloudflare Workers & KV

Comments
4 min read
"Pinned to a SHA" is a lie your coding agent told you. Here's the Git trick behind Plugin4Shell.

"Pinned to a SHA" is a lie your coding agent told you. Here's the Git trick behind Plugin4Shell.

6
Comments 19
3 min read
I tested my sandbox against Deno and plain Python on 63 AI-written scripts

I tested my sandbox against Deno and plain Python on 63 AI-written scripts

1
Comments 4
3 min read
Your AI agent's audit log is signed by the thing it's auditing

Your AI agent's audit log is signed by the thing it's auditing

Comments 2
4 min read
The nginx misconfigurations that fail silently

The nginx misconfigurations that fail silently

Comments
5 min read
I DNA-encode my encrypted database before writing it to disk - here's why (and why it's not "quantum" anything)

I DNA-encode my encrypted database before writing it to disk - here's why (and why it's not "quantum" anything)

Comments
2 min read
Infisical vs 1Password for homelab machine secrets: why I self-host

Infisical vs 1Password for homelab machine secrets: why I self-host

3
Comments 5
7 min read
Claude Code's Read deny rules let 4 of 11 routes through: grep -r, a Python one-liner and two CLAUDE.md @imports

Claude Code's Read deny rules let 4 of 11 routes through: grep -r, a Python one-liner and two CLAUDE.md @imports

2
Comments 7
15 min read
MCP security: what to log when an AI agent calls tools, and what the log can prove

MCP security: what to log when an AI agent calls tools, and what the log can prove

1
Comments 2
7 min read
Designing an eval harness for prompt-injection detection: what measuring my defenses actually taught me

Designing an eval harness for prompt-injection detection: what measuring my defenses actually taught me

Comments 1
6 min read
Mask PII in Grafana Alloy logs without a stage.replace pattern list

Mask PII in Grafana Alloy logs without a stage.replace pattern list

1
Comments 1
8 min read
Before Sovereign AI, You Need Sovereign IT

Before Sovereign AI, You Need Sovereign IT

Comments
5 min read
Your Supabase anon key can probably read your whole users table

Your Supabase anon key can probably read your whole users table

Comments
5 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.