Content Security Policy: Putting the Browser on a Security Diet
Web applications have become remarkably powerful.
Read article: Content Security Policy: Putting the Browser on a Security Diet21 articles tagged Application Security.
Web applications have become remarkably powerful.
Read article: Content Security Policy: Putting the Browser on a Security DietThere is a special kind of optimism that exists in software development.
Read article: Input Validation: Because Users Are Creative, and Attackers Are More CreativeFor most corporate IT workshops, we are often trying to abstract as many security details away from application code as possible. I understand things may work differently at Big Tech / shops-with-many-competent developer resources. I initially started jotting down notes for this blog post while I…
Read article: Secure Code Reviews: Finding Security Issues Before Attackers DoAuthentication is one of the most fundamental concepts in application security. Most developers spend considerable time designing how authenticated users are represented, authorized, and managed. Surprisingly, much less attention is given to the opposite state of users who have not authenticated at…
Read article: Understanding Unauthenticated Traffic: How Applications and APIs Represent The Unauthenticated UserThis is the fifth (and final) post in my “AI / LLM Software Security Series”.
Read article: AI / LLM Software Security: Part 5This is the forth post in my “AI / LLM Software Security Series”.
Read article: AI / LLM Software Security: Part 4This is the third post in my “AI / LLM Software Security Series”.
Read article: AI / LLM Software Security: Part 3This series explores the “OWASP Top 10 for LLM Applications 2025” issues.
Read article: AI / LLM Software Security SeriesThis is the second post in my “AI / LLM Software Security Series”.
Read article: AI / LLM Software Security: Part 2This is the first post in my “AI / LLM Software Security Series”.
Read article: AI / LLM Application Software Security: Part 1