Security and Identity
Authentication, authorization, threat thinking, and secure service design.
Lessons
- Threat Modelling for Backend Services
- OAuth 2.0, OIDC, and JWT — Delegation Without Sharing Passwords
- HTTPS — TLS for Confidentiality and Integrity on the Web
- Secrets and Key Management
- OWASP Top 10 — Practical Web Risk Map
- OAuth 2.0 Flows Overview — Delegated Authorization
- Multi-Tenant Isolation Patterns
- TLS, mTLS & PKI — Trust on the Wire
- Session Cookies vs JWT — Server State vs Bearer Tokens
- Privacy Engineering Basics
- Supply-Chain Security and SBOMs