March 30, 2026 6 min read
The Self-Signed Permission Slip
JWTs feel like magic until you realize nobody's checking the signature.
appsecidentityauthentication
March 26, 2026 5 min read
The Flimsy Wristband
Why the thing that keeps you logged in is the thing attackers want most
appsecidentitysession security
March 5, 2026 3 min read
Turns Out I've Been Taking Notes
How a pile of scratch notes became whatever this is