DEV Community

Security

Hopefully not just an afterthought!

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Your Authz Checks the Caller. The Model Picked the Tenant.

Your Authz Checks the Caller. The Model Picked the Tenant.

3
Comments
14 min read
Why your Clio token stopped working

Why your Clio token stopped working

Comments
5 min read
Building a Secure Infrastructure Dashboard with React 18, Tailwind v4, and Local Sovereign LLMs

Building a Secure Infrastructure Dashboard with React 18, Tailwind v4, and Local Sovereign LLMs

Comments
2 min read
Why Do APIs Use Bearer <token>? A Beginner-Friendly Explanation 🐻

Why Do APIs Use Bearer <token>? A Beginner-Friendly Explanation 🐻

Comments
2 min read
First bug

First bug

Comments
1 min read
How Attackers Enumerate Your Laravel App — And What to Hide Before They Map Your Entire Backend

How Attackers Enumerate Your Laravel App — And What to Hide Before They Map Your Entire Backend

Comments
7 min read
"Private" wasn't private: a fresh Gitea auth bypass, reproduced on a live lab

"Private" wasn't private: a fresh Gitea auth bypass, reproduced on a live lab

Comments
5 min read
Your coding agent runs a shell on your machine. I audited mine.

Your coding agent runs a shell on your machine. I audited mine.

Comments 1
5 min read
XChaCha20-Poly1305 in a Mesh Network: A Practical Deep Dive

XChaCha20-Poly1305 in a Mesh Network: A Practical Deep Dive

Comments
3 min read
An Agent Harness Is Not a Security Boundary: Reading AgentSmith as a Workflow Layer

An Agent Harness Is Not a Security Boundary: Reading AgentSmith as a Workflow Layer

1
Comments 2
2 min read
Building a Decompiler Pipeline in Rust: Why Fission Separates NIR and HIR

Building a Decompiler Pipeline in Rust: Why Fission Separates NIR and HIR

Comments
7 min read
From Wordlists to Polynomials: Understanding BIP39 and Shamir's Secret Sharing

From Wordlists to Polynomials: Understanding BIP39 and Shamir's Secret Sharing

1
Comments
4 min read
I ran my Solidity scanner across the 10 most-audited codebases in web3. Here's every flag.

I ran my Solidity scanner across the 10 most-audited codebases in web3. Here's every flag.

Comments
3 min read
Auto-Renewal Wasn’t Enough for SSL Certificates — So I Built an Independent Monitoring Workflow

Auto-Renewal Wasn’t Enough for SSL Certificates — So I Built an Independent Monitoring Workflow

1
Comments
6 min read
Metadata-Only Tracing: Privacy-First Observability for AI Agents

Metadata-Only Tracing: Privacy-First Observability for AI Agents

2
Comments
6 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.