#security
4 items tagged with "security"
AuthenticationAuthorizationBackendCareer GrowthClean CodeCleanArchitectureCloudCommand LineCommunicationConcurrencyDDDDatabasesDevOpsDockerJWTKubernetesLeadershipLearningLinuxMental HealthMicroservicesNetworkingOAuth2RefactoringSecuritySenior EngineerSoft SkillsSoftware EngineeringSoftwareArchitectureSysadminSystem DesignSystemDesignTDDTeamworkTerminalTestingZeroTrustab-testingaccessibilityagileaialgorithmsanalyticsanthropicappsecarchitectureasync-communicationauthenticationautomationawsbackendbehavioralbuild-vs-buyburnoutbusiness-acumenbusiness-impactcareercareer-growthci-cdclaudeclean-architectureclean-codecode-reviewcollaborationcommunicationcontainerscontext-switchingdatabasesdecision-makingdeep-workdesigndesign-patternsdesign-systemdeveloper-experiencedevopsdistributed-systemsdockerengineering-cultureengineering-leadershipengineering-managementengineering-qualityengineering-strategyexperimentationfeature-flagsfinance-for-engineersflow-statefrontendhexagonal-architectureinfrastructure-as-codeinterviewjob-searchkanbankotlinkubernetesleadershiplean-methodologylearningllmmental-modelsmessagingmetricsmicroservicesmtlsnetworkingnorth-star-metricnote-takingooporchestrationoutcome-drivenowaspperformance-reviewpersonal-brandingports-and-adaptersprdprobabilistic-data-structuresproduct-discoveryproduct-mindsetproduct-thinkingproductivityprogressive-deliveryprotocolqareactredisreliabilityremote-workrequirementssalary-negotiationscrumsenior-engineerssoft-skillssoftware-designsoftware-engineeringstaff-engineersupply-chainsystem-designtailwindtddtechnical-debttechnical-decisionstechnical-leadershiptechnical-writingterraformtestingtheory-of-constraintsuser-researchuxwcagweb-security
Series
Software Testing: From Fundamentals to Modern Practice
A practical, engineer-focused guide to software testing — the testing pyramid, TDD/BDD, automation strategy, CI/CD integration, security testing, and modern AI-assisted practices.
7 chapters
testingqatddautomation
Start readingPosts
Martin Fowler on LLMs: Six Things Worth Taking Seriously
A synthesis of Martin Fowler's August 2025 essay on LLMs and software development — covering workflow gaps, hallucinations as a feature, the Lethal Trifecta security risk, and why non-determinism changes everything.
May 19, 2026aillmsoftware-engineering
The OWASP Top 10:2025 Update: What Changed and Why It Matters
OWASP quietly replaced the 2021 Top 10 in November 2025. SSRF disappeared, misconfiguration jumped to #2, and supply chain got its own top-3 slot — here's the diff.
Jul 2, 2026securityowaspappsec
Service-to-Service Authentication: The Threat Model You're Ignoring
Most microservices deployments skip internal auth entirely. Here's what that costs you, and the three patterns that fix it.
Jun 24, 2026microservicessecurityauthentication