A PDF signature ByteRange must exclude its own Contents
A PDF signature ByteRange must exclude its own Contents An older PDF signature is not automaticall…
AI tools, cybersecurity and development news aggregated from top sources — saved permanently with unique URLs.
A PDF signature ByteRange must exclude its own Contents
A PDF signature ByteRange must exclude its own Contents An older PDF signature is not automaticall…
Understanding Platform Security - A StashPatrick Case Study
As developers, we often build platforms without thinking about what users actually want from a secur…
How to Build a Log Parser That Detects Brute Force Attacks
Brute force attacks against SSH, web logins, and APIs are constant background noise on any public-fa…
A graduated response ladder where every rung is invisible
Detection produces a number. Something has to turn that number into a response, and the response has…
Honeytokens that recognise themselves: stateless decoys with automatic attribution
Every signal in the previous articles is statistical. They weigh evidence, they have thresholds, the…
Four ways a baseline quietly destroys the anomaly detector built on it
Every anomaly detector answers one question: compared to what? That comparison, the baseline, is wh…
Three detection layers that disagree usefully and why they combine by max, not sum
Features get you a vector per window. Turning that into a decision is where the design choices are. …
The most obvious signals for detecting enumeration don't work
Every window of traffic, per credential, this system computes about twenty features. Six of them dri…
Simulating attackers is easy. Simulating legitimate users is the hard part
In part 1 I argued that enumeration from a valid credential can only be caught from the shape of the…
Your API is being enumerated by a client with a perfectly valid token
Here is a request: GET /users/4821 Authorization: Bearer eyJhbGciOiJSUzI1NiIs... The token …
How to Capture Consent-Timing Evidence in Browser Network Logs
A website request sent before consent and the same request sent after acceptance may look identical …
One maker fixed every security header on his launch in 24 hours — here's the before/after
A week ago I started leaving findings-first comments on launch posts here: I run a passive scan of t…