DEV Community

Security

Hopefully not just an afterthought!

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
What a Website Can Learn From Your Browser: IP, WebRTC, and IPv6

What a Website Can Learn From Your Browser: IP, WebRTC, and IPv6

2
Comments 1
2 min read
Don't trust my "client-side only" claim. Open DevTools and check.

Don't trust my "client-side only" claim. Open DevTools and check.

7
Comments 1
3 min read
My repository health tool gave Chromium a score. It had only seen part of it.

My repository health tool gave Chromium a score. It had only seen part of it.

Comments
5 min read
Linux Kernel CVEs: What to Patch by Device (2 – 8 Aug 2026)

Linux Kernel CVEs: What to Patch by Device (2 – 8 Aug 2026)

1
Comments
7 min read
Week 6: Signing the State, and Closing My Own Pull Requests

Week 6: Signing the State, and Closing My Own Pull Requests

Comments
4 min read
Put SSH Behind Tailscale and Close Port 22

Put SSH Behind Tailscale and Close Port 22

2
Comments 1
6 min read
Hardware Backdoors in x86 CPUs: The 2026 Hacker News Wake-Up Call

Hardware Backdoors in x86 CPUs: The 2026 Hacker News Wake-Up Call

Comments
4 min read
Three AI Agents Walk Into a Codebase, and Only One Walks Out

Three AI Agents Walk Into a Codebase, and Only One Walks Out

6
Comments 1
3 min read
Beyond the Password: How Passkeys Work Under the Hood

Beyond the Password: How Passkeys Work Under the Hood

1
Comments
3 min read
Read-only by construction: why instructions aren't a security boundary for an AI agent in a Kubernetes cluster

Read-only by construction: why instructions aren't a security boundary for an AI agent in a Kubernetes cluster

1
Comments 1
6 min read
Setting Up Your Own VPS: A Secure Starting Point

Setting Up Your Own VPS: A Secure Starting Point

1
Comments 1
7 min read
What Is CSRF (Cross-Site Request Forgery)?

What Is CSRF (Cross-Site Request Forgery)?

Comments
3 min read
Metabase Unauthenticated SQL Injection: From Admin Privilege Heist to Connected DB Data Theft

Metabase Unauthenticated SQL Injection: From Admin Privilege Heist to Connected DB Data Theft

Comments
7 min read
VMware ESX Shell Obfuscation: 21 Techniques Work with BusyBox and Bypass Plaintext Keyword Detection

VMware ESX Shell Obfuscation: 21 Techniques Work with BusyBox and Bypass Plaintext Keyword Detection

Comments
7 min read
Scrubbing secrets from logs: patterns catch what you didn't issue, literals catch the rest

Scrubbing secrets from logs: patterns catch what you didn't issue, literals catch the rest

Comments
5 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.