Loading...

Tag trends are in beta. Feedback? Thoughts? Email me at [email protected]

Accelerating The Adoption of Post-Quantum Cryptography with PHP

Solving Open Source Supply Chain Security for the PHP Ecosystem

Preventing Timing Attacks on String Comparison with Double HMAC Strategy (2015)

PASETO is an Even More Secure Alternative to the JOSE Standards

JWT Is a Bad Standard That Everyone Should Avoid

JOSE Is a Bad Standard That Everyone Should Avoid (2017)

Improving the Cryptography of the JavaScript Ecosystem

WordPress 5.2: Mitigating Supply-Chain Attacks Against 33% of the Internet

2019 Guide to Cryptographic Key Sizes and Algorithm Recommendations

CipherSweet: Searchable Encryption Doesn't Have to be Bitter

Security Concerns Surrounding WebAuthn: Don't Implement ECDAA (Yet)

Paseto is a Secure Alternative to the JOSE Standards (JWT, etc.)

Our Ambitious Plan to Make Insecure PHP Software a Thing of the Past

The 2018 Guide to Building Secure PHP Software - Paragon Initiative Enterprises Blog

Certainty: Automated CACert.pem Management for PHP Software

It Turns Out, 2017 is the Year of Simply Secure PHP Cryptography

Guide to Automatic Security Updates For PHP Developers

Libsodium Quick Reference: Similarly-Named Functions and Their Use-Cases

Building Searchable Encrypted Databases with PHP and SQL

Checklist-Driven Security Considered Harmful

How We Engineered CMS Airship to Be Simply Secure

Avoid Encrypting URL Parameters (2015)

JWT (JSON Web Tokens) Is a Bad Standard That Everyone Should Avoid

Cryptographically Secure PHP Development

Split Tokens: Token-Based Authentication Protocols Without Side-Channels

Everything You Know About Public-Key Encryption in PHP Is Wrong

Automatic Security Updates for Developers

Implementing Secure “Password Reset” Features in Web Applications

How to Generate Secure Random Numbers (in Various Programming Languages)

CMS Airship - Simply Secure Content Management

More →