Security
Practical controls for secrets, dependencies, authentication, and data handling inside everyday engineering workflows.
Checksums, Signatures, and Provenance Solve Different Problems
A threat-based guide to release checksums, digital signatures, and build provenance, including trust distribution, verification policy, and residual risks.
Read field noteApply Least Privilege to CI Credentials
A threat-based CI credential design covering token scope, untrusted code, short-lived identity, protected environments, third-party actions, logs, and recovery.
Read field noteDesign Application Logs Without Leaking Sensitive Data
A secure logging workflow for selecting events, minimizing data, preventing injection, protecting transport and storage, controlling access, and testing failures.
Read field noteThreat-Model a Small Feature Before It Ships
A lightweight threat-modeling method for mapping assets, actors, data flow, trust boundaries, abuse cases, controls, residual risk, and verification evidence.
Read field noteSecret Scanning Before a Git Commit: A Practical Defense
How to prevent credentials from entering Git with staged-content scanning, entropy and format checks, allowlists, secure storage, and an incident response plan.
Read field noteSecure Token Storage in React and Tauri Desktop Applications
A practical architecture for short-lived access tokens, rotating refresh tokens, OS credential vaults, IPC validation, logout, and offline entitlements in Tauri.
Read field note