Web Security
Security reads as intimidating until you see how each attack actually works. These articles walk through the common ones — what the attacker sends, why the naive code accepts it, and the specific change that closes the hole.
Common attacks
- OWASP Top 10 Explained: Ten Categories, Ten Fixes Most people memorise the ten names and still ship broken access control. The list names categories of failure, not specific bugs, and that gap is where projects get hit. Tutorial · 12 min read · August 6, 2026
- SQL Injection Explained: The Fix Is Not Escaping Quotes Two dashes typed into a login box can delete the password check from your own query. The fix is not smarter escaping, and most beginners reach for escaping first. Tutorial · 12 min read · August 6, 2026
- XSS Explained: Why innerHTML Is a Security Bug Paste a script tag into innerHTML and nothing happens, so people conclude it is safe. An img tag with an onerror handler tells a very different story. Tutorial · 12 min read · August 6, 2026
- CSRF Explained: Why Your Own Cookie Attacks You The attacker never reads a single byte of the response, and the transfer still goes through. That is the part people misjudge about CSRF. Tutorial · 12 min read · August 6, 2026
Identity and secrets
- API Authentication: Sessions, Tokens and Where to Store Them Every tutorial teaches JWTs and very few mention that you cannot easily log someone out. Choosing between sessions and tokens is a trade-off, and knowing which way it runs is the interesting part. Tutorial · 9 min read · August 21, 2026
- Hashing vs Encryption vs Encoding: Three Things People Confuse Base64 is not encryption. A hash is not reversible. Encrypting a password is a mistake. These three confusions cause a large share of real security failures. Tutorial · 9 min read · August 18, 2026
- Two-Factor Authentication: Which Second Factor Actually Helps Two-factor authentication is the single highest-value security step most people can take. The factors are not equivalent, and the most common one is the weakest. Tutorial · 8 min read · August 18, 2026
- OAuth Explained: What 'Sign in with Google' Is Actually Doing OAuth exists to answer one question: how do you let an app act on your behalf without handing it your password? The answer is a redirect dance that looks confusing and is genuinely elegant. Tutorial · 9 min read · August 13, 2026
- Password Hashing Explained: Why SHA-256 Is Wrong Here SHA-256 is a good hash. That is exactly the problem: it is fast, and speed is the one property you do not want when someone is guessing your users' passwords. Tutorial · 12 min read · August 6, 2026
- SSH Permission Denied (publickey): Fixing Git Auth The server did not reject your password. It never asked for one. Understanding that single sentence is most of the fix. Tutorial · 12 min read · August 6, 2026
- JWT Authentication Explained (and Where It Goes Wrong) A JWT is signed, not encrypted. Anyone holding one can read it — and confusing verify with decode is a complete authentication bypass. Tutorial · 11 min read · August 5, 2026
- Cookies vs Sessions vs Tokens: What Is the Difference? These three get compared as if they were competing options. They are not — a cookie is a delivery mechanism, and it can carry either of the other two. Comparison · 10 min read · August 5, 2026
Transport and headers
- HTTP vs HTTPS: What the Padlock Actually Guarantees The padlock means the connection is private and the server is who it claims to be. It does not mean the site is honest — a fact that phishing sites rely on entirely. Comparison · 8 min read · August 19, 2026
- TLS Certificates: What the Browser Is Actually Checking A certificate does not make a site trustworthy. It proves you are talking to whoever controls that domain, and nothing more — which is exactly why the padlock is not a safety signal. Tutorial · 8 min read · August 18, 2026
- HTTPS and TLS Explained: What the Padlock Really Means The padlock does not mean the site is safe. It means the connection is private with whoever controls that domain, and a phishing site can get one for free in minutes. Tutorial · 12 min read · August 6, 2026
- What Is CORS and How to Fix the Error The request worked in Postman and fails in the browser. Nothing is broken — you are meeting a rule that only browsers enforce. Tutorial · 10 min read · August 5, 2026
More on Web Security
- RBAC vs ABAC: Two Ways to Model Permissions Roles are easy to reason about until you need "editors can only edit their own drafts." That single requirement is where RBAC ends and attribute-based rules begin. Comparison · 8 min read · September 3, 2026
- .gitignore: What Should Never Be in Your Repository A repository containing node_modules, a virtual environment and someone's editor settings is the most visible sign of an inexperienced project — and the .env file in there is a genuine problem. Tutorial · 8 min read · August 20, 2026
- Secrets Management: Keeping Keys Out of Your Repository A committed API key is found by automated scanners within minutes of reaching a public repository. Deleting it in the next commit does not help, because git remembers everything. Tutorial · 8 min read · August 19, 2026
- Auditing Dependencies: Reading a Vulnerability Report Properly An audit reporting eight high-severity vulnerabilities sounds alarming. Whether any of them can affect your project is a completely separate question, and answering it is the actual skill. Tutorial · 9 min read · August 19, 2026
- Firewalls: Deciding What Is Allowed to Reach Your Server A firewall does one simple thing: decide which connections are allowed. Getting it right is mostly about starting from 'nothing' rather than starting from 'everything'. Tutorial · 8 min read · August 19, 2026
- VPNs: What They Actually Hide, and From Whom A VPN moves the point at which your traffic enters the internet. That is genuinely useful for some things and completely irrelevant for others, and the marketing rarely distinguishes. Tutorial · 8 min read · August 19, 2026
- SSH: Keys, Config and Not Typing Passwords Into Servers SSH is how you reach every server you will ever work on. Learning keys and one config file removes almost all the friction, and removes passwords from the process entirely. Tutorial · 8 min read · August 18, 2026
- Setting Up a Linux Server: The First Hour A fresh server is scanned for weak SSH logins within minutes of getting a public IP. The first hour of setup is mostly about closing doors that are open by default. Tutorial · 9 min read · August 17, 2026
- localStorage, sessionStorage and Cookies: Which One to Use Browser storage looks like three interchangeable options. They differ in lifetime, size and — most importantly — in whether JavaScript on your page can read them, which is a security question. Tutorial · 8 min read · August 14, 2026
- Rate Limiting: Stopping One Client Taking Down Your API Without a rate limit, one buggy client in a retry loop can consume everything your API has. The algorithms are simple; choosing the right one depends on whether bursts are acceptable. Tutorial · 8 min read · August 13, 2026
- localStorage vs sessionStorage: What Actually Differs You save a user object, read it back, and get the string [object Object]. Web Storage stores nothing but strings, and that one fact explains most of the bugs people hit with it. Comparison · 11 min read · August 6, 2026
- Environment Variables Explained: Config Without Secrets in Code The first real security lesson most developers learn, usually the hard way — after committing an API key to a public repository. Tutorial · 10 min read · August 6, 2026
