DEV Community

Security

Hopefully not just an afterthought!

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Rate Limiting Your API: Algorithms, Tradeoffs, and Implementation

Rate Limiting Your API: Algorithms, Tradeoffs, and Implementation

Comments
4 min read
ForgeRock AM Scripted Decision Node: Production Scripts & Debug Guide

ForgeRock AM Scripted Decision Node: Production Scripts & Debug Guide

Comments
4 min read
Google Cloud Next26:Securing AI

Google Cloud NEXT '26 Challenge Submission

Google Cloud Next26:Securing AI

1
Comments
3 min read
Securing AI Agent Workflows: Preventing Identity Collapse in Multi-Step Chains

Securing AI Agent Workflows: Preventing Identity Collapse in Multi-Step Chains

Comments
9 min read
The TLS Fingerprinting Hell: Why I Stopped Reverse-Engineering the Vinted App

The TLS Fingerprinting Hell: Why I Stopped Reverse-Engineering the Vinted App

Comments
5 min read
Your Agent's Reputation Doesn't Travel. Here's What Does.

Your Agent's Reputation Doesn't Travel. Here's What Does.

Comments
4 min read
Everyone's Sharing Claude Code Skills. Nobody's Checking What's Inside.

Everyone's Sharing Claude Code Skills. Nobody's Checking What's Inside.

Comments
5 min read
Your API Is Leaking Source Fingerprints. Here's How to Stop It.

Your API Is Leaking Source Fingerprints. Here's How to Stop It.

2
Comments
6 min read
How to Safely Allow Inline Scripts Without Breaking Security with CSP Nonce

How to Safely Allow Inline Scripts Without Breaking Security with CSP Nonce

1
Comments
4 min read
nginx-ui's MCP endpoint shipped with 'empty allowlist equals allow-all' — and that's the story worth sitting with

nginx-ui's MCP endpoint shipped with 'empty allowlist equals allow-all' — and that's the story worth sitting with

Comments 3
7 min read
Protecting Node.js APIs: Audiences, Scopes, and Bearer Tokens

Protecting Node.js APIs: Audiences, Scopes, and Bearer Tokens

Comments
5 min read
From Promises to Proof: Designing a Defensive Escrow Protocol

From Promises to Proof: Designing a Defensive Escrow Protocol

5
Comments
5 min read
How to cut your AWS bill by 20–45% without touching your architecture

How to cut your AWS bill by 20–45% without touching your architecture

Comments
2 min read
How Enterprise Wallet Infrastructure Actually Works: MPC, Custody Models, and Why MetaMask Was Never the Answer

How Enterprise Wallet Infrastructure Actually Works: MPC, Custody Models, and Why MetaMask Was Never the Answer

1
Comments
9 min read
AI-Generated Backends Almost Always Get CORS Wrong

AI-Generated Backends Almost Always Get CORS Wrong

Comments
3 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.