How to create a Secure, Random Password with JavaScript

Please do not put IP addresses into DNS MX records

File Exfiltration via LibreOffice in BigBlueButton and JODConverter

Generating Crime Safe CSRF Tokens

Userdir URLs like https://example.org/~username/ are dangerous

#include </etc/shadow>

Security Issues with PGP Signatures and Linux Package Management

How my personal Bug Bounty Program turned into a Free Security Audit for the Serendipity Blog

Efail: HTML Mails have no Security Concept and are to blame

efail: Outdated Crypto Standards are to blame

Introducing Snallygaster - a Tool to Scan for Secrets on Web Servers

Some minor Security Quirks in Firefox

Abandoned Domain Takeover as a Web Security Risk

In Search of a Secure Time Source

How I Tricked Symantec with a Fake Private Key

Don't Leave Coredumps on Web Servers

The Problem with OCSP Stapling and Must Staple and why Certificate Revocation is still broken

Passwords in the Bug Reports (Owncloud/Nextcloud)

Pwncloud – Bad crypto in the Owncloud encryption module

A little POODLE left in GnuTLS (old versions)

About the supposed factoring of a 4096 bit RSA key

How Heartbleed could've been found

How Kaspersky makes you vulnerable to the FREAK attack and other ways Antivirus software lowers your HTTPS security

Comodo ships Adware Privdog worse than Superfish

Software Privdog worse than Superfish

LibreSSL on Gentoo