Skip to content

Category

Security

Security 5 min read

Secrets Management: Life Beyond the .env File

The real leak vectors ranked, the non-negotiables at any size, a three-rung maturity ladder that mostly stops at rung two, and rotation as a rehearsed muscle with two-key overlap.

Security 5 min read

OAuth2 and OIDC in Plain Words

The founding delegation story, the cast renamed into English, the one flow that survived (auth code + PKCE) with every step's attack labeled, ID vs access tokens untangled, and the do-you-even-need-this triage.

Security 4 min read

JWTs vs Sessions: The Debate, Settled-ish

Why revocation is where stateless goes to die, the XSS blast-radius problem, the specific habitats where JWTs genuinely shine, and the sessions-at-the-edge / tokens-between-machines architecture.