THE ARCADE
ArcadePathsBuildPrep
  1. Home
  2. /Security Practice
Security practice

Security Practice

Real-world security for engineers.

← Back to all areas
  • 01·200 XP
    Password Storage
    Never plaintext. Never unsalted. Never fast.
    •
  • 02·200 XP
    Password Hash Cracker
    Dictionary attacks, crack rates, and why argon2id exists.
    •
  • 03·200 XP
    2FA and TOTP
    Why SMS is the floor, hardware keys are the ceiling, and recovery is the weakest link.
    •
  • 04·200 XP
    Credential Stuffing
    Why password reuse is catastrophic — and the four defenses that actually move the needle.
    •
  • 05·200 XP
    Session Management
    Tokens, JWTs, refresh, revocation — and why 'JWTs can't be revoked' is a half-truth.
    •
  • 06·200 XP
    Secrets in Config
    Env vars, secret managers, the .env-leak problem, and the 12-factor compromise.
    •
  • 07·250 XP
    Supply Chain
    Dependency confusion, typosquatting, malicious post-installs, SBOMs, sigstore.
    •
  • 08·250 XP
    Defense in Depth
    Layered controls, least privilege, network segmentation, and the honeypot in your VPC.
    •
  • 09·250 XP
    Incident Response
    Detect → contain → eradicate → recover → learn. Don't power-off the box.
    •
arcade.