THE TEXTS
The API key that sat exposed for three years (and the four places yours are sitting now)
It was committed on a Friday in a busy sprint. Removed the following Monday, everyone assumed. Three years later a security review found it in four places nobody had thought about.
S2Nº 01
Security findings need more than a debt label
Security findings need an assessment of exposure and impact, an owner and a deadline. The label ‘technical debt’ doesn’t give us that assessment.
S2Nº 02
400 Dependabot alerts. Where do you start?
An example with 400 alerts: assess exploitation, exposure and impact to find what needs urgent action and give the rest a reasoned plan.
S2Nº 03
‘It’s just an internal system’ – the sentence that takes down the most teams
No input validation, no logging, a shared admin password. It’s only internal, after all. The sentence gets used as an exemption from everything we know about security, and it rests on an assumption that stopped being true a long time ago: that the inside is safe.
S2Nº 04COMING TUE 13/10
Threat modeling for teams that have never done it
The word scares people: threat modeling sounds like something for specialists with certifications and frameworks. In practice it’s four questions and a whiteboard, an hour-long exercise any team can run on its own, and one that changes how you look at your own architecture.
S2Nº 05COMING THU 15/10
Security in code review: The five questions that catch the most
Security bugs are cheapest to catch in review, and review is where they most often slip past: the reviewer reads for correctness and style, not for attackability. Five concrete questions that change what you see, without turning every PR into an audit.
S2Nº 06COMING TUE 20/10
+ 14 more this season