Security
The security basics AI-built apps skip — secrets, logins, row-level security, bot abuse — and the isolation that keeps untrusted code contained.
78 posts · page 1 of 3
"Your Connection Is Not Private" on Your Own Site: Causes and Fixes
When visitors see NET::ERR_CERT_DATE_INVALID, ERR_CERT_COMMON_NAME_INVALID or ERR_CERT_AUTHORITY_INVALID on your site, the SSL certificate is expired, for the wrong name, or incomplete. How to tell which, and how to fix each one.
What Is Cloudflare? What It Does When You Put Your Site Behind It
Cloudflare sits between your visitors and your server: DNS, a CDN, free SSL, DDoS protection and a firewall. What changes when you turn on the orange cloud, what it costs, what it can break, and whether a small app needs it.
UFW Firewall Basics: Lock Down a Linux Server in Five Commands
A firewall decides which network traffic can reach your server. UFW makes Linux's firewall simple: allow SSH, HTTP and HTTPS, deny the rest. The commands, how not to lock yourself out, why your database port should never be open, and the Docker gotcha that bypasses UFW.
The TLS 1.3 Handshake Explained: What Happens Before the First Byte
What actually happens when a browser connects over HTTPS: ClientHello, key shares, the server's certificate and signature, Finished messages, one round trip instead of two, 0-RTT resumption and its replay risk, SNI and ECH, certificate chain validation, and how to inspect it all with openssl.
How to Secure a New VPS: The First 30 Minutes
A fresh server is scanned within minutes of going online. The essential hardening steps for a new Ubuntu VPS: updates, a non-root user, SSH keys only, firewall, automatic security patches, fail2ban, safe service binding, backups and monitoring — in order, with commands.
Postgres Roles and Permissions: CREATE USER, GRANT, and Least Privilege
Most apps connect to Postgres as a superuser, so one SQL injection or rogue AI command can drop everything. How Postgres roles, privileges, schemas and default privileges work, and a practical setup with separate owner, app and read-only roles.
localStorage vs sessionStorage vs Cookies: Where Should You Store It?
Three ways to store data in the browser, with different lifetimes, sizes and security properties. What each one is for, why login tokens shouldn't go in localStorage, the size limits, and a simple rule for choosing.
Hashing vs Encryption vs Encoding: What's the Difference?
Three ways to transform data that people mix up constantly — sometimes with security consequences. Encoding changes format (Base64), encryption hides data with a key you can reverse, hashing makes a one-way fingerprint. What each is for and the mistakes to avoid.
Do You Need a Cookie Banner? A Plain-English Guide for Small Apps
Cookie banners are required when you set non-essential cookies or trackers for EU and UK visitors — not for every cookie. What counts as essential, when you need consent, what a compliant banner must do, and how to avoid needing one at all.
API Authentication Methods: API Keys, Sessions, JWTs, OAuth and mTLS
How should clients prove who they are to your API? API keys for server-to-server, session cookies for your own web app, bearer tokens for mobile and SPAs, OAuth for third-party access, HMAC signatures for webhooks, mTLS for service meshes. When to use each and how to do it safely.
What Is an API Key? A Plain-English Guide (With Claude and ChatGPT Examples)
An API key is a password for software. What API keys are, how they're different from your login, how to get one for Claude or OpenAI, where to keep it, why it must never be in your frontend code, and what to do if one leaks.
What Is a DDoS Attack? A Plain-English Guide for Website Owners
A DDoS attack floods a website with traffic until real visitors can't get through. How DDoS attacks work, the main types, how likely a small site is to be hit, what DDoS protection actually does, and the cheap steps that protect a small app.
Two-Factor Authentication Explained (and How to Add It to Your App)
What two-factor authentication is, how authenticator-app codes (TOTP) work, why SMS codes are the weakest option, where passkeys fit, and how to add 2FA to your own app — including recovery codes and the mistakes to avoid.
Session Cookies vs JWTs: Which Should Your App Use for Authentication?
Server-side sessions and JWTs both keep users logged in, with very different trade-offs. How each works, revocation and logout, where to store tokens (cookies vs localStorage), the hybrid access/refresh pattern, and a clear default for web apps.
HTTP Security Headers Explained: HSTS, CSP, and the Rest (With a Copy-Paste Setup)
A practical guide to the HTTP security headers worth setting: Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, frame protection, Referrer-Policy and Permissions-Policy — what each prevents, safe values, a Next.js and Nginx config, and which old headers to drop.
Role-Based Access Control (RBAC) for Your App: A Practical Guide
How to add roles and permissions to a web app without making a mess: roles vs permissions, a simple database schema, checking permissions on the server, multi-tenant roles per organisation, enforcing in the UI and the API, and testing it.
Password Reset and Email Verification Flows Done Right
Password resets are one of the most attacked parts of any app. How to build reset and email-verification flows securely: token generation and hashing, expiry, account enumeration, host header poisoning, invalidating sessions, and the UX details that reduce support tickets.
The OWASP Top 10 (2025) Explained for Beginners and App Builders
The OWASP Top 10 is the most widely used list of web application security risks. All ten 2025 categories in plain English — from broken access control to supply chain failures — with what each looks like in an AI-built app and how to prevent it.
npm audit Explained: What the Warnings Mean and What to Actually Do
"found 14 vulnerabilities (3 moderate, 2 high)" — should you panic? How npm audit works, what the severity levels mean, why npm audit fix sometimes does nothing, why --force is risky, and how to tell real risks from noise.
Mixed Content Errors: Why Your HTTPS Site Loads Things Over HTTP (and How to Fix It)
"Mixed Content: The page was loaded over HTTPS, but requested an insecure resource." What mixed content is, why browsers block it, how to find every http:// URL, and the fixes — including apps behind a proxy that generate http links.
Magic Link Login: How Passwordless Email Sign-In Works (and Its Pitfalls)
Magic links let people log in by clicking a link in their email — no password. How they work, when they're a good fit, the security details that matter (expiry, single use, token hashing), and the real-world problems: spam filters, email scanners and phones vs laptops.
Linux File Permissions Explained: chmod 755, 644, and "Permission Denied"
What rwxr-xr-x means, how chmod numbers like 755, 644 and 600 work, chmod +x for scripts, chown, the correct permissions for SSH keys, and why chmod 777 is never the right fix for "Permission denied".
What Is IDOR? The Security Bug Where Users Can See Each Other's Data
IDOR (insecure direct object reference) is when changing an ID in a URL shows you someone else's data. How it happens, why it's the most common serious bug in AI-built apps, how to test for it in five minutes, and the one-line habit that prevents it.
Encryption at Rest vs in Transit: What's the Difference?
Encryption in transit protects data moving across a network; encryption at rest protects data stored on disk. What each one protects against, what it doesn't, how HTTPS, disk encryption and field-level encryption fit together, and what a small app actually needs.