Tutorials, guides, comparisons and analysis on security, Linux, networking, development, cloud and the tooling that powers modern technology — written by practitioners, for practitioners.
Two S3 endpoints, two behaviours, and most guides pick one without saying which. One gives you working directory URLs and a public bucket; the other gives you a private bucket and a 403 on every folder path.
The parsing is the short part. What decides whether your collection is usable is which rung of the access ladder you took, what you did with personal data afterwards, and whether you can still say where each fact came from.
Passing tests, rising coverage and a green badge all measure the same thing — that the code ran. None of them tell you anything was checked. Here is how to find the tests that defend nothing.
The C is twenty lines. Getting it to load on a machine bought in the last few years is the hard part, and Secure Boot is the reason — an error that says nothing about signing.
Coverage says a line ran. Mutation testing says whether anything would notice if that line were wrong. The idea takes a sentence; making it finish before you lose interest takes a plan.
A VPN is excellent against two adversaries, barely useful against a third and irrelevant against the rest. Work out which row you are in, learn what a no-logs claim is worth without an audit, and test the result yourself in ten minutes.
Nobody is finding your camera by your IP address. They are finding it because UPnP opened a port, or because a password was reused. Turn off the first, fix the second, and put everything else on its own network.
CEH gets a CV past a filter. OSCP convinces the person running the technical interview. Which one is worth six months of your evenings depends entirely on which gate is actually in front of you.
CloudFront meters delivery and gives you free origin egress from AWS. Cloudflare does not meter delivery but your S3 bucket still bills you on every cache miss. Which one wins comes down to a number most people have never measured.
Middleware is not an authorisation boundary — CVE-2025-29927 proved it with one header. Where to put the check so a page, a route handler and a Server Action are all covered, what leaks into the RSC payload, and the CSP choice that costs you static rendering.
·8 min
Newsletter
Get smarter about security
Practical guides, tooling notes and the developments actually worth your attention — delivered when there is something worth saying.