Least privilege, actually applied
Everyone agrees with the principle. Almost nobody has checked what their service can actually reach.
tech, developers, and the code underneath
22 pieces tagged security,
from February 7, 2025 to September 25, 2026.
Everyone agrees with the principle. Almost nobody has checked what their service can actually reach.
From today, actively exploited vulnerabilities in products sold into the EU must be reported within 24 hours. Here's what that requires.
Not a survey of vaults. The specific practices that actually reduce risk, in order of what to do first.
Europe is about to regulate software security across the whole product lifecycle. Open source is mostly carved out, and mostly is doing a lot of work.
Phishing-resistant authentication is now the default on major platforms. The remaining problem is account recovery.
The analogy is exact except for the part that matters: there is no parameterized query for natural language.
Treat added dependencies like added latency: a number you spend deliberately, with a ceiling nobody may exceed quietly.
WebAssembly's most important feature isn't running fast in a browser. It's letting you run someone else's code safely.
Harvest-now-decrypt-later makes this urgent for anything with a long confidentiality horizon. The tooling is finally ready.
The year in one page: what happened, what mattered, and the three things that will still matter in 2030.
The industry built SBOM tooling, VEX, and a lot of dashboards. Here's what actually changed and what didn't.
OpenAI ships a Chromium-based browser with an agent that can act on pages. The prompt injection surface is now your whole session.