Tag
Security
Every article tagged Security across the Atmosphere.
122articles
Articles
Publications
Self-hosting email the hard way from your own routable IPv4 block up
How we refreshed self-hosted Recoil email with our own RIPE-allocated IPv4 block, and deployed Postfix/rspamd/Dovecot to get full SPF/DKIM/DMARC deliverability.networkingselfhosting
Install-script allowlists
A survey of install-script allowlist mechanisms across package managers and language ecosystems.package-managerssecurity
gittuf - a signed log for git refs
Branch protection is a row in someone else's databasegitsecurity
Skills Registry Threat Models
How long until we see a CVE filed against a markdown file?securitypackage-managers
The agent control plane gets real
Two prompt-injection incidents show why agent security is about permission boundaries, not better instructions.daily-briefagents
Composer's dependency policies
uBlock Origin for composer installpackage-managerssecurity
Protestware for coding agents
printMessageForCodingAgents()supply-chainsecurity
Cloudflare for Families DNS resolver and miscategorisation
today iain learned: How to report a miscategorisation of a site/domain in the Cloudflare for Families DNS resolver service.webdevCloudflare
Android app WebView hijacking via MITM
Stealing user logins by hijacking a vulnerable webview implementation in a mobile appsecuritybug bounty
GitHub Actions security in Python packages
Thank you Dr. Zizmorsecuritysupply-chain
Signing is for the bad days
TUF, in-toto, and Sigstore only look pointless while nothing is on firesupply-chainsecurity
The trust boundary moves inward
GitHub's poisoned-extension breach, Railway's GCP account suspension, and SpaceX's AI-heavy S-1 all point to the same thing: the inside of infrastructure is now the story.daily-briefinfrastructure
Experimental DTLS Support in Node.js
An experimental implementation of the DTLS protocol is coming to Node.js, bringing TLS-equivalent security to datagram-based communication over UDP.javascriptnetworking
Language Registries Are Unstable by Default
apt install -t unstable, but make it your whole personalitypackage-managerssecurity
Not a Security Issue
How curl's disclosure policy filtered an AI scanner's findings at sourcesecurityopen-source
proxy
A lightweight multi-ecosystem caching package proxypackage-managerstools
The Mismeasure of Open Source
The streetlight effect in project-health scoringopen-sourcesecurity
Weekend at Bernie's
Which of your dependencies are wearing sunglassesopen-sourcesecurity
Free as in Tribbles
The next metaphor after free-as-in-puppyopen-sourcedependencies
Revisiting the 2015 Open Source Census
The riskiest projects in open source, scored a decade earlysecurityopen-source
Package Manager Threat Models
The non-CVE half of package manager securitypackage-managerssecurity
ECCL Login Refactor
eccrefactor