rssed

a collection of dev rss feeds - blogroll

Add a new feed

+

323 feeds


text/plain

Posts

โ€œTheโ€ IP Address ๐Ÿ”—

As elaborated in a prior post, sites and services often try to use an IP address as an input into protection (e.g. blocking a spammer) or customizatio [...]

Experimentation: Just Try It! ๐Ÿ”—

Iโ€™ve now been working in tech for 25 years, and in that time Iโ€™ve developed some wisdom. One theme Iโ€™ve discovered and blogged about repeatedly over t [...]

Simple Browser Security Improvements ๐Ÿ”—

Security Engineering is all about tradeoffs: Web Browsers attempt to achieve an absolutely bananas goal: Allow safe execution of untrusted content on [...]

The Windows Security App ๐Ÿ”—

Going back as far as the 2004 release of Windows XP SP2, Windows has offered various GUIs to help users understand the security state of their PC. In [...]

Attack Technique: AI Clones ๐Ÿ”—

Attackers are adept at using new technologies to enhance their attacks. Earlier this afternoon, for example, I got call from โ€œAmerican Expressโ€ sugges [...]

Fiddler in 2026 ๐Ÿ”—

Iโ€™ve shared the stories behind the Fiddler Web Debugger a fair bit over the years, in the Fiddler Book, in a talk at the CodeMash conference in 2015, [...]

Web Security is Too Hard ๐Ÿ”—

It started innocently enough. I saw a tweet about a new product offering from one of my favorite companies, Cloudflare. Neat! I clicked through to the [...]

Authenticode and UAC ๐Ÿ”—

When a user attempts to run a file with elevated privilege, Windows will show a User Account Control elevation prompt that asks whether the user trust [...]

Attack Techniques: Fake Captive Portals ๐Ÿ”—

When a device first joins a network, the upstream network hardware has full control over its traffic and can allow/block any packets sent from the dev [...]

Offboarding from Microsoft Defender for Endpoint ๐Ÿ”—

Microsoft Defender for Endpoint is a paid security product that extends Microsoft Defender Antivirus (included for free in Windows) with enterprise ca [...]