Posts
All the articles I've posted.
I put a signing key in the browser on purpose
What that buys, split by what the attacker can already do, and why the property that actually protects the user is not in my code at all.
We built a distributed page cache, then deleted it
Three rounds of tuning to cut the write bill, then removal. The same machinery stayed for images.
Your error handler is inside the cache
A container restart took thirty seconds. The site stayed broken for an hour after it came back.
A missing capability beats a threshold
A limit can be misconfigured, and mine throttled the one thing that was supposed to recover from the problem it was throttling.