Blog
Notes on secure code.
Practical write-ups on the vulnerabilities we keep finding during reviews, and how to fix them. Examples are synthetic — never taken from client code.
-
Your webhook signature check is probably comparing strings wrong
Why == leaks timing information when you verify HMAC signatures, and how to fix it in Python, Node.js, Go and PHP.
-
Pin the algorithm: JWT confusion bugs that still ship
How trusting the alg header lets attackers forge tokens, and the few lines of configuration that prevent it.
-
Parameterized queries don't cover ORDER BY
Placeholders bind values, not identifiers. Where SQL injection still hides in codebases that 'always use prepared statements'.
-
A secret got committed. Here's the order of operations
Rotate, check usage, find every copy, then rewrite history. A short runbook for leaked credentials in git.
Shipping something important soon?
Tell us what you're building. We reply within two business days.