20 issues · 2025—2026

Archive.

Monthly field notes on product security, cloud infrastructure, identity, supply chains, and APIs.

API authorization: check permission on every object

API Security

Stop secrets before they reach Git

DevSecOps

OAuth 2.0 without the insecure legacy

Identity

A presigned URL is a temporary credential

Cloud

Kubernetes Restricted as the default

Cloud

Strict CSP: trust code, not a growing domain list

Web Security

GraphQL: limit request cost, not only depth

API Security

Webhooks without surprises: signatures, replay, and idempotency

Application Security

Passkeys: phishing-resistant sign-in without a shared secret

Identity

An SBOM is useful only when it answers an operational question

Supply Chain

Business logic needs adversarial stories

Product Security

SSRF is an egress-control problem

Cloud

JWT validation is a contract, not a decode operation

Identity

An API inventory must know how to retire things

API Security

Resource budgets are security controls

API Security

Threat modeling before the backlog hardens

Product Security

Vulnerability disclosure is a product interface

Security Operations

Security headers are a browser contract

Web Security

Review dependencies at the diff

Supply Chain

Zero trust is not a new network zone

Architecture