Writing
Write-ups on web application security and the infrastructure underneath it. Also available as RSS.
Why this site renders its own response headers in the hero, and what breaks if you try to serve a strict CSP from two different runtimes at once.