Skip to content
Security

Security articles

Headers, injection, auth, dependencies, attacks.

4 articles

Ten lines of code that stop 90% of automated abuse — credential stuffing, brute force, scraping, API abuse. Here's how to actually do it.

Feb 23, 2025Read

They're not the same attack, and they don't have the same defense. Here's the difference — and the interview-ready way to explain it.

Feb 19, 2025Read

CSP, HSTS, X-Frame-Options and the rest. A plain-English reference for every HTTP security header your web app should set before launch.

Jan 22, 2025Read

A 42 KB file that expands to 4.5 petabytes. Here's how zip-bomb denial-of-service attacks work, the real numbers behind the famous 42.zip, and how to defend against them.

Jan 12, 2025Read