DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Per-user two-factor auth in CakePHP with CakeDC/Users (opt-in, one method)

Per-user two-factor auth in CakePHP with CakeDC/Users (opt-in, one method)

1
Comments
5 min read
Why We Ship Our Security Webhook Fail-Open

Why We Ship Our Security Webhook Fail-Open

Comments
2 min read
Deploying Logto as an AWS Cognito Alternative

Deploying Logto as an AWS Cognito Alternative

7
Comments
14 min read
Deploying Logto as a GCP Identity Platform Alternative

Deploying Logto as a GCP Identity Platform Alternative

6
Comments
14 min read
Free WAF for Self-Hosted Apps: Protect Your Stack Without the Bill

Free WAF for Self-Hosted Apps: Protect Your Stack Without the Bill

2
Comments 1
3 min read
Deploying Ory Hydra: An Open-Source OAuth 2.0 and OpenID Connect Server

Deploying Ory Hydra: An Open-Source OAuth 2.0 and OpenID Connect Server

6
Comments
11 min read
Magento 2.4.6 Lost Support in August: What Waiting Actually Costs

Magento 2.4.6 Lost Support in August: What Waiting Actually Costs

6
Comments 1
5 min read
Stop a Malicious postinstall Script Cold With One CircleCI Config Change

Stop a Malicious postinstall Script Cold With One CircleCI Config Change

Comments
3 min read
Governance Attack Surface Review: Gemini

Governance Attack Surface Review: Gemini

Comments
7 min read
7 Security Checks Before Installing a New Developer Tool

7 Security Checks Before Installing a New Developer Tool

Comments
4 min read
An injection that moved is not an injection that was fixed

An injection that moved is not an injection that was fixed

7
Comments 9
8 min read
A container per job, without a daemon

A container per job, without a daemon

Comments
3 min read
Claude Code's ultrareview vs Dromeas Code Review with LLM council

Claude Code's ultrareview vs Dromeas Code Review with LLM council

Comments
2 min read
We ran 15 prompt-injection attacks against a stock local LLM. It failed 3. Here's the free tool we built to check yours.

We ran 15 prompt-injection attacks against a stock local LLM. It failed 3. Here's the free tool we built to check yours.

Comments
3 min read
No accounts meant no license server — so my $19 one-time SaaS signs its keys with ECDSA P-256

No accounts meant no license server — so my $19 one-time SaaS signs its keys with ECDSA P-256

Comments
5 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.