TopicsSecurity
Security
AuthN, AuthZ, OAuth/OIDC, OWASP web attacks (injection, XSS, CSRF, SSRF, CORS), secrets/KMS, tokens, and service identity you can defend in interviews.
Common tags: oauth, oidc, jwt, mtls, authz, secrets, kms
- Security
SOC 2 & ISO 27001 - Trust Services Criteria, Type I vs Type II, ISMS, Annex A, Statement of Applicability & Which to Choose
Cluster · Security & Data-Protection Compliance
SOC 2 (an AICPA attestation against the Trust Services Criteria, Type I vs Type II, observation windows, CUECs and bridge letters) vs ISO/IEC 27001:2022 (a certifiable ISMS with clauses 4 to 10, 93 Annex A controls, the Statement of Applicability and a surveillance cycle). Covers which to choose by market and how engineers produce evidence, with a runnable Type II sampling simulation and SoA builder.
Open study →- security
- compliance
- data-protection
- hipaa
- phi
- soc2
- iso27001
- pci-dss
- gdpr
- ccpa
- privacy-engineering
- audit-logs
- policy-as-code
- breach-notification
- interview
- Security
Security & Data-Protection Compliance - Why Frameworks Exist, the Shared Control Set & Choosing HIPAA, SOC 2, ISO 27001, PCI DSS, GDPR or CCPA
Cluster · Security & Data-Protection Compliance
Hub: why compliance frameworks exist (law vs contract vs market), the shared control set every framework asks for, and HIPAA vs SOC 2 vs ISO 27001 vs PCI DSS vs GDPR/CCPA (plus HITRUST, FedRAMP 20x, NIST CSF) compared by trigger, assessor, artifact and cadence. Includes a runnable control-mapping matrix and framework triage in Python and TypeScript, and an engineering-guidance, not legal-advice note.
Open study →- security
- compliance
- data-protection
- hipaa
- phi
- soc2
- iso27001
- pci-dss
- gdpr
- ccpa
- privacy-engineering
- audit-logs
- policy-as-code
- breach-notification
- interview
- Security
PCI DSS v4.0.1 - Cardholder Data, CDE Scoping, Segmentation, Tokenization, SAQ Types & Payment Page Scripts
Cluster · Security & Data-Protection Compliance
PCI DSS v4.0.1: cardholder data vs sensitive authentication data, CDE and connected-to scoping, segmentation and its testing, tokenization vs encryption, and how iframes, your own JS fields or a direct post lead to SAQ A, A-EP or D (including the January 2025 SAQ A change). Covers payment page script controls 6.4.3 and 11.6.1 and the future-dated requirements that are now mandatory, with a runnable token vault and scope calculator.
Open study →- security
- compliance
- data-protection
- hipaa
- phi
- soc2
- iso27001
- pci-dss
- gdpr
- ccpa
- privacy-engineering
- audit-logs
- policy-as-code
- breach-notification
- interview
- Security
HIPAA & PHI - Covered Entities, Business Associates, BAAs, Security Rule Safeguards, Breach Notification & De-identification
Cluster · Security & Data-Protection Compliance
HIPAA for builders: PHI vs health data that is not PHI, covered entities vs business associates, BAAs (including cloud and no-view providers), the Privacy Rule's minimum necessary standard, Security Rule safeguards and the status of the 2025 proposal, and breach notification (60 days, the 500 thresholds, the encryption safe harbor). Also covers Safe Harbor vs Expert Determination de-identification, tracking-technology guidance and enforcement cases, with a runnable de-identifier and PHI-safe logger.
Open study →- security
- compliance
- data-protection
- hipaa
- phi
- soc2
- iso27001
- pci-dss
- gdpr
- ccpa
- privacy-engineering
- audit-logs
- policy-as-code
- breach-notification
- interview
- Security
GDPR & CCPA Privacy Engineering - Lawful Bases, DSARs, Erasure in Practice, Data Transfers, DPIAs & Consent
Cluster · Security & Data-Protection Compliance
GDPR vs CCPA/CPRA in practice: controller vs processor, the six lawful bases, DSAR workflows and deadlines, erasure in backups, event logs, search indexes, warehouses and processors (with crypto-shredding), international transfers (EU-US DPF, SCCs, TIAs), DPIAs, consent and Global Privacy Control, and the 2026 CPPA regulations. Includes a runnable crypto-shredding demo and a DSAR orchestrator with legal holds.
Open study →- security
- compliance
- data-protection
- hipaa
- phi
- soc2
- iso27001
- pci-dss
- gdpr
- ccpa
- privacy-engineering
- audit-logs
- policy-as-code
- breach-notification
- interview
- Security
Engineering Compliance into Systems - Data Classification, Audit Logs, Retention, JIT Access, Policy-as-Code & Continuous Evidence
Cluster · Security & Data-Protection Compliance
Building compliance into the platform: data classification tags and lineage, key ownership, tamper-evident WORM audit logs, retention with legal hold, access reviews vs JIT access, policy-as-code gates, continuous evidence (how to evaluate Vanta, Drata and Secureframe), vendor risk, a breach notification runbook across GDPR 72h, HIPAA 60d, state laws, SEC 8-K and PCI, and compliance in CI/CD. Includes a runnable hash-chain audit log, retention engine and policy gate.
Open study →- security
- compliance
- data-protection
- hipaa
- phi
- soc2
- iso27001
- pci-dss
- gdpr
- ccpa
- privacy-engineering
- audit-logs
- policy-as-code
- breach-notification
- interview
- Security
Cross-Site Scripting (XSS) - Contextual Encoding, Strict CSP Nonces & Trusted Types
Cluster · Web Application Security
XSS is attacker JavaScript running in your origin. Reflected, stored, and DOM XSS are three delivery routes. Contextual encoding is the fix. A strict nonce CSP and Trusted Types are the layer that still blocks the script when someone uses an escape hatch.
Open study →- security
- owasp
- web-security
- injection
- xss
- csrf
- ssrf
- cors
- interview
- Security
Web Application Security - OWASP Top 10, Injection, XSS, CSRF & SSRF
Cluster · Web Application Security
Almost every web bug on the OWASP Top 10 is untrusted data parsed as code or as authority at a sink. Fix that sink with an API that keeps code and data apart, then add a second platform layer for the day the first control is skipped.
Open study →- security
- owasp
- web-security
- injection
- xss
- csrf
- ssrf
- cors
- interview
- Security
SSRF - Cloud Metadata, DNS Rebinding, Redirects & Egress Allowlists
Cluster · Web Application Security
SSRF is your server fetching a URL the attacker chose. The request leaves from inside your network, often with the host's cloud role. Metadata at 169.254.169.254 is the famous target. Pin the resolved IP, re-check every redirect, allowlist egress, require IMDSv2 with hop limit 1, and keep that role small.
Open study →- security
- owasp
- web-security
- injection
- xss
- csrf
- ssrf
- cors
- interview
- Security
Injection Attacks - SQLi, Command & Template Injection, Parameterized Queries
Cluster · Web Application Security
Injection is string-built commands: SQL, a shell, a template, LDAP, or a NoSQL query. The attacker's bytes close your literal and open theirs. Bind values, pass argv, and allowlist identifiers. Escaping is the fallback you will get wrong.
Open study →- security
- owasp
- web-security
- injection
- xss
- csrf
- ssrf
- cors
- interview
- Security
CSRF - SameSite Cookies, Anti-CSRF Tokens & Fetch Metadata
Cluster · Web Application Security
CSRF works because the browser attaches cookies by itself. A page on another site can submit a form to yours, and the session rides along. SameSite, a CSRF token, and Origin or Sec-Fetch-Site each prove the request came from your pages. Bearer headers set by your own script are a different trade.
Open study →- security
- owasp
- web-security
- injection
- xss
- csrf
- ssrf
- cors
- interview
- Security
CORS & Security Headers - Same-Origin Policy, Misconfigurations, HSTS & CSP
Cluster · Web Application Security
The same-origin policy stops a script on another site from reading your responses. CORS is the opt-in that relaxes that rule. It never adds protection. Reflecting any Origin together with credentials lets any site read a logged-in user's data. A short header baseline closes clickjacking, MIME sniffing, and SSL stripping beside that.
Open study →- security
- owasp
- web-security
- injection
- xss
- csrf
- ssrf
- cors
- interview
- Security
Secrets Threat Model — Leakage Paths, Side Channels & Audit Trails
Cluster · Secrets & KMS
Even perfect KMS math fails if secrets leak through logs, CI, cores, tickets, or over-broad IAM. This lesson catalogs leakage paths, side channels, detection via audit trails, and incident response for credential exposure — closing the Secrets and KMS cluster.
Open study →- secrets
- kms
- secret-leakage
- audit-trail
- crypto-shredding
- security
- interview
- Security
Secrets & KMS — Envelope Encryption, Rotation & Blast Radius
Cluster · Secrets & KMS
Credentials, API keys, and data-encryption keys are high-blast-radius assets. This hub is the senior-SWE decision map for where secrets live, how KMS wraps data keys (envelope encryption), how you rotate without downtime, and how apps fetch secrets at runtime — without re-teaching OAuth/OIDC token flows or RBAC/ABAC policy engines. Focus: Vault, cloud Secrets Manager, and Kubernetes Secrets tradeoffs, the DEK/KEK/CMK hierarchy, dual-read rotation, injection paths, and leakage threat models.
Open study →- secrets
- kms
- envelope-encryption
- secret-stores
- credential-rotation
- blast-radius
- security
- interview
- Security
Secret Stores Compared — Vault, Cloud Secrets Manager & Kubernetes Secrets
Cluster · Secrets & KMS
Picking a secret store is an architecture choice: dynamic leases in Vault, a managed cloud Secrets Manager, or Kubernetes-native Secrets plus CSI. This lesson compares trust boundaries, auth to the store, encryption at rest, HA, and anti-patterns — without rehashing OAuth grant types or full RBAC engines.
Open study →- secrets
- kms
- vault
- secret-stores
- kubernetes-secrets
- security
- interview
- Security
Envelope Encryption — DEK, KEK & CMK Hierarchy
Cluster · Secrets & KMS
Envelope encryption separates bulk data crypto (fast local AES with a DEK) from key protection (a KMS-held CMK or KEK wraps the DEK). This lesson is the DEK, KEK, and CMK hierarchy, the encrypt and decrypt paths, AAD, key policies, and rotation by re-wrap versus re-encrypt.
Open study →- secrets
- kms
- envelope-encryption
- dek
- kek
- cmk
- aad
- security
- interview
- Security
Credential Rotation — Dual-Read, Overlap Windows & Break-Glass
Cluster · Secrets & KMS
Rotation without downtime needs a dual-read overlap, version stages, and a rehearsed break-glass path. This lesson covers overlap windows, consumer lag, database password patterns, API key versioning, and what fails when only half the fleet has the new secret.
Open study →- secrets
- kms
- credential-rotation
- dual-accept
- break-glass
- security
- interview
- Security
App Secret Injection — Env, Sidecar/Agent, CSI Drivers & Runtime Fetch
Cluster · Secrets & KMS
How an app obtains a secret matters as much as where it is stored. This lesson compares environment variables, file mounts, Vault Agent and cloud sidecars, the Secrets Store CSI driver, and runtime SDK fetch — with blast radius and operational tradeoffs for Kubernetes and VMs.
Open study →- secrets
- kms
- secret-injection
- csi-driver
- workload-identity
- security
- interview
- Security
ReBAC & Zanzibar — Relationship Tuples & Consistency
Cluster · Authorization
Relationship-based auth with Zanzibar-style tuples and consistency tradeoffs for sharing graphs.
Open study →- security
- authz
- rebac
- zanzibar
- relationship-tuples
- consistency
- interview
- Security
RBAC — Roles, Permissions & Role Explosion
Cluster · Authorization
Roles, permissions, and how role explosion pushes teams toward ABAC/ReBAC.
Open study →- security
- authz
- rbac
- roles
- permissions
- role-explosion
- interview
- Security
Policy Engines — OPA/Rego vs Cedar vs Custom
Cluster · Authorization
Comparative OPA/Rego vs Cedar vs custom if/else; treat policies as audited code.
Open study →- security
- authz
- opa
- rego
- cedar
- policy-engine
- interview
- Security
AuthZ Enforcement — Gateway, Service & Data Filters
Cluster · Authorization
Enforce at gateway + service + data filters; fail closed; defense in depth for AuthZ.
Open study →- security
- authz
- enforcement
- gateway
- pep
- data-filters
- fail-closed
- interview
- Security
Authorization — RBAC, ABAC, ReBAC & Policy Engines
Cluster · Authorization
Hub decision tree for AuthZ models and PEP/PDP placement; AuthN left to OAuth & OIDC cluster.
Open study →- security
- authz
- authorization
- rbac
- abac
- rebac
- zanzibar
- opa
- rego
- cedar
- pdp
- pep
- policy-engine
- interview
- Security
ABAC — Attributes, Policies, PDP & PEP
Cluster · Authorization
Attribute-based policies with PDP/PEP separation for env and resource attributes.
Open study →- security
- authz
- abac
- attributes
- pdp
- pep
- policies
- interview
- Security
OpenID Connect — ID Tokens, UserInfo, Discovery & Nonce
Cluster · OAuth & OIDC
OpenID Connect is the identity layer on OAuth 2. The client asks for scope openid, validates an ID token aimed at itself (iss, aud, exp, nonce), and may call UserInfo. Discovery publishes the endpoints. Never send the ID token to your API as a bearer.
Open study →- oidc
- openid
- id-token
- userinfo
- discovery
- nonce
- oauth
- authn
- security
- interview
- Security
Service-to-Service Auth — mTLS, Client Credentials & Workload Identity
Cluster · OAuth & OIDC
Service-to-service auth uses Client Credentials, mTLS/SPIFFE, or cloud Workload Identity federation instead of user OAuth dances. Narrow audiences, short-lived creds, and no long-lived JSON keys. Interviews probe blast radius, metadata SSRF, and token exchange.
Open study →- mTLS
- client-credentials
- workload-identity
- s2s
- spiffe
- security
- auth
- interview
- Security
Refresh Token Rotation & Reuse Detection
Cluster · OAuth & OIDC
Refresh token rotation issues a new RT on every refresh and invalidates the old one; reuse detection treats a replayed ancestor as theft and revokes the whole token family. This is OAuth 2.1 / BCP guidance for public clients and pairs with short-lived access tokens and BFF storage.
Open study →- refresh-tokens
- rotation
- reuse-detection
- oauth
- security
- auth
- interview
- Security
OAuth Threat Model — CSRF, Token Leakage, Confused Deputy & Common Pitfalls
Cluster · OAuth & OIDC
OAuth security is a threat model: login CSRF (state), code interception (PKCE), token leakage, confused deputy (aud), refresh theft (rotation), and mix-up attacks. Map each attack to controls across this cluster rather than treating OAuth as a grant-type checklist.
Open study →- oauth
- threat-model
- csrf
- confused-deputy
- token-leakage
- security
- auth
- interview
- Security
OAuth 2.1 & OIDC — Authorization Code + PKCE
Cluster · OAuth & OIDC
OAuth 2.1 makes Authorization Code + PKCE the default for public clients and retires implicit and password grants. Authentication (who) and authorization (what) are different questions: OIDC identity is the next lesson, JWT is only a token format, and the decision matrix picks session, BFF, PKCE, client credentials, device code, or mTLS. Interviews expect the redirect sequence, S256, exact redirect URIs, and state versus nonce.
Open study →- oauth
- oauth2
- oauth2.1
- oidc
- pkce
- authorization-code
- authn
- security
- auth
- interview
- Security
JWT vs Opaque Tokens — Validation, JWKS & Revocation
Cluster · OAuth & OIDC
JWTs validate locally via JWKS (iss/aud/exp/kid) and scale reads; opaque tokens make revocation trivial via introspection or a store. Choosing wrong means day-long stolen JWTs or introspection bottlenecks at the edge. Pair short AT TTL with refresh rotation and never skip audience checks.
Open study →- jwt
- opaque-tokens
- jwks
- introspection
- revocation
- security
- auth
- interview
- Security
BFF Cookie Sessions vs SPA Bearer Tokens
Cluster · OAuth & OIDC
A BFF keeps access and refresh tokens on the server and gives the browser only an HttpOnly Secure SameSite session cookie. SPA bearer puts tokens in the browser, so XSS means token theft. BFF needs CSRF defenses; bearer needs extreme XSS hygiene. Prefer BFF for first-party SPAs.
Open study →- bff
- cookies
- spa
- bearer
- csrf
- samesite
- security
- auth
- interview