Security
Topic, then cluster, then study. Recently added is the short list at the top.
Recently added
Show more- 6.Engineering Compliance into Systems - Data Classification, Audit Logs, Retention, JIT Access, Policy-as-Code & Continuous EvidenceBuilding compliance into the platform: data classification tags and lineage, key ownership, tamper-evident WORM audit logs, retention with legal hold, access reviews vs JIT access, policy-as-code gates, continuous evidence (how to evaluate Vanta, Drata and Secureframe), vendor risk, a breach notification runbook across GDPR 72h, HIPAA 60d, state laws, SEC 8-K and PCI, and compliance in CI/CD. Includes a runnable hash-chain audit log, retention engine and policy gate.
- 5.GDPR & CCPA Privacy Engineering - Lawful Bases, DSARs, Erasure in Practice, Data Transfers, DPIAs & ConsentGDPR vs CCPA/CPRA in practice: controller vs processor, the six lawful bases, DSAR workflows and deadlines, erasure in backups, event logs, search indexes, warehouses and processors (with crypto-shredding), international transfers (EU-US DPF, SCCs, TIAs), DPIAs, consent and Global Privacy Control, and the 2026 CPPA regulations. Includes a runnable crypto-shredding demo and a DSAR orchestrator with legal holds.
- 2.HIPAA & PHI - Covered Entities, Business Associates, BAAs, Security Rule Safeguards, Breach Notification & De-identificationHIPAA for builders: PHI vs health data that is not PHI, covered entities vs business associates, BAAs (including cloud and no-view providers), the Privacy Rule's minimum necessary standard, Security Rule safeguards and the status of the 2025 proposal, and breach notification (60 days, the 500 thresholds, the encryption safe harbor). Also covers Safe Harbor vs Expert Determination de-identification, tracking-technology guidance and enforcement cases, with a runnable de-identifier and PHI-safe logger.
- 4.PCI DSS v4.0.1 - Cardholder Data, CDE Scoping, Segmentation, Tokenization, SAQ Types & Payment Page ScriptsPCI DSS v4.0.1: cardholder data vs sensitive authentication data, CDE and connected-to scoping, segmentation and its testing, tokenization vs encryption, and how iframes, your own JS fields or a direct post lead to SAQ A, A-EP or D (including the January 2025 SAQ A change). Covers payment page script controls 6.4.3 and 11.6.1 and the future-dated requirements that are now mandatory, with a runnable token vault and scope calculator.
- 1.Security & Data-Protection Compliance - Why Frameworks Exist, the Shared Control Set & Choosing HIPAA, SOC 2, ISO 27001, PCI DSS, GDPR or CCPAHub: why compliance frameworks exist (law vs contract vs market), the shared control set every framework asks for, and HIPAA vs SOC 2 vs ISO 27001 vs PCI DSS vs GDPR/CCPA (plus HITRUST, FedRAMP 20x, NIST CSF) compared by trigger, assessor, artifact and cadence. Includes a runnable control-mapping matrix and framework triage in Python and TypeScript, and an engineering-guidance, not legal-advice note.
- 3.SOC 2 & ISO 27001 - Trust Services Criteria, Type I vs Type II, ISMS, Annex A, Statement of Applicability & Which to ChooseSOC 2 (an AICPA attestation against the Trust Services Criteria, Type I vs Type II, observation windows, CUECs and bridge letters) vs ISO/IEC 27001:2022 (a certifiable ISMS with clauses 4 to 10, 93 Annex A controls, the Statement of Applicability and a surveillance cycle). Covers which to choose by market and how engineers produce evidence, with a runnable Type II sampling simulation and SoA builder.
Security
AuthN, AuthZ, OAuth/OIDC, OWASP web attacks (injection, XSS, CSRF, SSRF, CORS), secrets/KMS, tokens, and service identity you can defend in interviews.
Authorization
6 studies- 1.Authorization — RBAC, ABAC, ReBAC & Policy EnginesHub decision tree for AuthZ models and PEP/PDP placement; AuthN left to OAuth & OIDC cluster.
- 2.RBAC — Roles, Permissions & Role ExplosionRoles, permissions, and how role explosion pushes teams toward ABAC/ReBAC.
- 3.ABAC — Attributes, Policies, PDP & PEPAttribute-based policies with PDP/PEP separation for env and resource attributes.
- 4.ReBAC & Zanzibar — Relationship Tuples & ConsistencyRelationship-based auth with Zanzibar-style tuples and consistency tradeoffs for sharing graphs.
- 5.Policy Engines — OPA/Rego vs Cedar vs CustomComparative OPA/Rego vs Cedar vs custom if/else; treat policies as audited code.
- 6.AuthZ Enforcement — Gateway, Service & Data FiltersEnforce at gateway + service + data filters; fail closed; defense in depth for AuthZ.
OAuth & OIDC
7 studies- 1.OAuth 2.1 & OIDC — Authorization Code + PKCEOAuth 2.1 makes Authorization Code + PKCE the default for public clients and retires implicit and password grants. Authentication (who) and authorization (what) are different questions: OIDC identity is the next lesson, JWT is only a token format, and the decision matrix picks session, BFF, PKCE, client credentials, device code, or mTLS. Interviews expect the redirect sequence, S256, exact redirect URIs, and state versus nonce.
- 2.OpenID Connect — ID Tokens, UserInfo, Discovery & NonceOpenID Connect is the identity layer on OAuth 2. The client asks for scope openid, validates an ID token aimed at itself (iss, aud, exp, nonce), and may call UserInfo. Discovery publishes the endpoints. Never send the ID token to your API as a bearer.
- 3.JWT vs Opaque Tokens — Validation, JWKS & RevocationJWTs validate locally via JWKS (iss/aud/exp/kid) and scale reads; opaque tokens make revocation trivial via introspection or a store. Choosing wrong means day-long stolen JWTs or introspection bottlenecks at the edge. Pair short AT TTL with refresh rotation and never skip audience checks.
- 4.Refresh Token Rotation & Reuse DetectionRefresh token rotation issues a new RT on every refresh and invalidates the old one; reuse detection treats a replayed ancestor as theft and revokes the whole token family. This is OAuth 2.1 / BCP guidance for public clients and pairs with short-lived access tokens and BFF storage.
- 5.BFF Cookie Sessions vs SPA Bearer TokensA BFF keeps access and refresh tokens on the server and gives the browser only an HttpOnly Secure SameSite session cookie. SPA bearer puts tokens in the browser, so XSS means token theft. BFF needs CSRF defenses; bearer needs extreme XSS hygiene. Prefer BFF for first-party SPAs.
- 6.Service-to-Service Auth — mTLS, Client Credentials & Workload IdentityService-to-service auth uses Client Credentials, mTLS/SPIFFE, or cloud Workload Identity federation instead of user OAuth dances. Narrow audiences, short-lived creds, and no long-lived JSON keys. Interviews probe blast radius, metadata SSRF, and token exchange.
- 7.OAuth Threat Model — CSRF, Token Leakage, Confused Deputy & Common PitfallsOAuth security is a threat model: login CSRF (state), code interception (PKCE), token leakage, confused deputy (aud), refresh theft (rotation), and mix-up attacks. Map each attack to controls across this cluster rather than treating OAuth as a grant-type checklist.
Secrets & KMS
6 studies- 1.Secrets & KMS — Envelope Encryption, Rotation & Blast RadiusCredentials, API keys, and data-encryption keys are high-blast-radius assets. This hub is the senior-SWE decision map for where secrets live, how KMS wraps data keys (envelope encryption), how you rotate without downtime, and how apps fetch secrets at runtime — without re-teaching OAuth/OIDC token flows or RBAC/ABAC policy engines. Focus: Vault, cloud Secrets Manager, and Kubernetes Secrets tradeoffs, the DEK/KEK/CMK hierarchy, dual-read rotation, injection paths, and leakage threat models.
- 2.Envelope Encryption — DEK, KEK & CMK HierarchyEnvelope encryption separates bulk data crypto (fast local AES with a DEK) from key protection (a KMS-held CMK or KEK wraps the DEK). This lesson is the DEK, KEK, and CMK hierarchy, the encrypt and decrypt paths, AAD, key policies, and rotation by re-wrap versus re-encrypt.
- 3.Secret Stores Compared — Vault, Cloud Secrets Manager & Kubernetes SecretsPicking a secret store is an architecture choice: dynamic leases in Vault, a managed cloud Secrets Manager, or Kubernetes-native Secrets plus CSI. This lesson compares trust boundaries, auth to the store, encryption at rest, HA, and anti-patterns — without rehashing OAuth grant types or full RBAC engines.
- 4.Credential Rotation — Dual-Read, Overlap Windows & Break-GlassRotation without downtime needs a dual-read overlap, version stages, and a rehearsed break-glass path. This lesson covers overlap windows, consumer lag, database password patterns, API key versioning, and what fails when only half the fleet has the new secret.
- 5.App Secret Injection — Env, Sidecar/Agent, CSI Drivers & Runtime FetchHow an app obtains a secret matters as much as where it is stored. This lesson compares environment variables, file mounts, Vault Agent and cloud sidecars, the Secrets Store CSI driver, and runtime SDK fetch — with blast radius and operational tradeoffs for Kubernetes and VMs.
- 6.Secrets Threat Model — Leakage Paths, Side Channels & Audit TrailsEven perfect KMS math fails if secrets leak through logs, CI, cores, tickets, or over-broad IAM. This lesson catalogs leakage paths, side channels, detection via audit trails, and incident response for credential exposure — closing the Secrets and KMS cluster.
- 1.Security & Data-Protection Compliance - Why Frameworks Exist, the Shared Control Set & Choosing HIPAA, SOC 2, ISO 27001, PCI DSS, GDPR or CCPAHub: why compliance frameworks exist (law vs contract vs market), the shared control set every framework asks for, and HIPAA vs SOC 2 vs ISO 27001 vs PCI DSS vs GDPR/CCPA (plus HITRUST, FedRAMP 20x, NIST CSF) compared by trigger, assessor, artifact and cadence. Includes a runnable control-mapping matrix and framework triage in Python and TypeScript, and an engineering-guidance, not legal-advice note.
- 2.HIPAA & PHI - Covered Entities, Business Associates, BAAs, Security Rule Safeguards, Breach Notification & De-identificationHIPAA for builders: PHI vs health data that is not PHI, covered entities vs business associates, BAAs (including cloud and no-view providers), the Privacy Rule's minimum necessary standard, Security Rule safeguards and the status of the 2025 proposal, and breach notification (60 days, the 500 thresholds, the encryption safe harbor). Also covers Safe Harbor vs Expert Determination de-identification, tracking-technology guidance and enforcement cases, with a runnable de-identifier and PHI-safe logger.
- 3.SOC 2 & ISO 27001 - Trust Services Criteria, Type I vs Type II, ISMS, Annex A, Statement of Applicability & Which to ChooseSOC 2 (an AICPA attestation against the Trust Services Criteria, Type I vs Type II, observation windows, CUECs and bridge letters) vs ISO/IEC 27001:2022 (a certifiable ISMS with clauses 4 to 10, 93 Annex A controls, the Statement of Applicability and a surveillance cycle). Covers which to choose by market and how engineers produce evidence, with a runnable Type II sampling simulation and SoA builder.
- 4.PCI DSS v4.0.1 - Cardholder Data, CDE Scoping, Segmentation, Tokenization, SAQ Types & Payment Page ScriptsPCI DSS v4.0.1: cardholder data vs sensitive authentication data, CDE and connected-to scoping, segmentation and its testing, tokenization vs encryption, and how iframes, your own JS fields or a direct post lead to SAQ A, A-EP or D (including the January 2025 SAQ A change). Covers payment page script controls 6.4.3 and 11.6.1 and the future-dated requirements that are now mandatory, with a runnable token vault and scope calculator.
- 5.GDPR & CCPA Privacy Engineering - Lawful Bases, DSARs, Erasure in Practice, Data Transfers, DPIAs & ConsentGDPR vs CCPA/CPRA in practice: controller vs processor, the six lawful bases, DSAR workflows and deadlines, erasure in backups, event logs, search indexes, warehouses and processors (with crypto-shredding), international transfers (EU-US DPF, SCCs, TIAs), DPIAs, consent and Global Privacy Control, and the 2026 CPPA regulations. Includes a runnable crypto-shredding demo and a DSAR orchestrator with legal holds.
- 6.Engineering Compliance into Systems - Data Classification, Audit Logs, Retention, JIT Access, Policy-as-Code & Continuous EvidenceBuilding compliance into the platform: data classification tags and lineage, key ownership, tamper-evident WORM audit logs, retention with legal hold, access reviews vs JIT access, policy-as-code gates, continuous evidence (how to evaluate Vanta, Drata and Secureframe), vendor risk, a breach notification runbook across GDPR 72h, HIPAA 60d, state laws, SEC 8-K and PCI, and compliance in CI/CD. Includes a runnable hash-chain audit log, retention engine and policy gate.
Web Application Security
6 studies- 1.Web Application Security - OWASP Top 10, Injection, XSS, CSRF & SSRFAlmost every web bug on the OWASP Top 10 is untrusted data parsed as code or as authority at a sink. Fix that sink with an API that keeps code and data apart, then add a second platform layer for the day the first control is skipped.
- 2.Injection Attacks - SQLi, Command & Template Injection, Parameterized QueriesInjection is string-built commands: SQL, a shell, a template, LDAP, or a NoSQL query. The attacker's bytes close your literal and open theirs. Bind values, pass argv, and allowlist identifiers. Escaping is the fallback you will get wrong.
- 3.Cross-Site Scripting (XSS) - Contextual Encoding, Strict CSP Nonces & Trusted TypesXSS is attacker JavaScript running in your origin. Reflected, stored, and DOM XSS are three delivery routes. Contextual encoding is the fix. A strict nonce CSP and Trusted Types are the layer that still blocks the script when someone uses an escape hatch.
- 4.CSRF - SameSite Cookies, Anti-CSRF Tokens & Fetch MetadataCSRF works because the browser attaches cookies by itself. A page on another site can submit a form to yours, and the session rides along. SameSite, a CSRF token, and Origin or Sec-Fetch-Site each prove the request came from your pages. Bearer headers set by your own script are a different trade.
- 5.SSRF - Cloud Metadata, DNS Rebinding, Redirects & Egress AllowlistsSSRF is your server fetching a URL the attacker chose. The request leaves from inside your network, often with the host's cloud role. Metadata at 169.254.169.254 is the famous target. Pin the resolved IP, re-check every redirect, allowlist egress, require IMDSv2 with hop limit 1, and keep that role small.
- 6.CORS & Security Headers - Same-Origin Policy, Misconfigurations, HSTS & CSPThe same-origin policy stops a script on another site from reading your responses. CORS is the opt-in that relaxes that rule. It never adds protection. Reflecting any Origin together with credentials lets any site read a logged-in user's data. A short header baseline closes clickjacking, MIME sniffing, and SSL stripping beside that.