Security practice
Security Practice
Real-world security for engineers.
- •200 XPPassword StorageNever plaintext. Never unsalted. Never fast.
- •200 XPPassword Hash CrackerDictionary attacks, crack rates, and why argon2id exists.
- •200 XP2FA and TOTPWhy SMS is the floor, hardware keys are the ceiling, and recovery is the weakest link.
- •200 XPCredential StuffingWhy password reuse is catastrophic — and the four defenses that actually move the needle.
- •200 XPSession ManagementTokens, JWTs, refresh, revocation — and why 'JWTs can't be revoked' is a half-truth.
- •200 XPSecrets in ConfigEnv vars, secret managers, the .env-leak problem, and the 12-factor compromise.
- •250 XPSupply ChainDependency confusion, typosquatting, malicious post-installs, SBOMs, sigstore.
- •250 XPDefense in DepthLayered controls, least privilege, network segmentation, and the honeypot in your VPC.
- •250 XPIncident ResponseDetect → contain → eradicate → recover → learn. Don't power-off the box.