Blog
Notes on client-side security, mostly from incidents. We try to write the version we wanted to read beforehand.
- Card testing looks like a good day1 September 2026 · The first sign of a card-testing run is usually a metric going up.
- Your CSP is more permissive than you think5 August 2026 · Every entry was added deliberately, by a competent person, to fix a real breakage.
- Why we don't block7 July 2026 · The decision that most shapes the product, and the scenario that settled it.
- Code freeze is a security event, not just a release policy19 June 2026 · A freeze reduces the change you control and does nothing to the change you do not.
- What PCI DSS 4.0 actually asks about scripts2 May 2026 · The plain version, including the parts less dramatic than the marketing.
- The eleven scripts nobody remembered adding14 April 2026 · Eleven is our median surprise on a first inventory.