HSTS in plain English
One response header ends the silent downgrade to plain HTTP. How HSTS works, the first-visit gap, the preload list, and the one way to brick your own subdomains.
Insights
Every new AI model ships with a chart where most bars go up. The bars that go down are the most useful pixels on it. How to adopt a new model without breaking what already works.
One response header ends the silent downgrade to plain HTTP. How HSTS works, the first-visit gap, the preload list, and the one way to brick your own subdomains.
Most failed security scans trace back to the same five missing response headers. Each one is a single line of server config. What they do, what to set, and the one that needs care.
Prompt injection is not hacking the model. It is the model doing exactly what it was built to do - follow instructions - with no reliable way to tell yours from an attacker’s. A field guide.
You did not get breached - your dependency did. How compromises actually travel through package managers, what history keeps teaching, and the unglamorous defenses that work.
When a researcher finds a hole in your site, the difference between a quiet heads-up and a public surprise is often whether they can find your inbox. RFC 9116, in practice.
The EU’s NIS2 directive stopped being a big-company topic. Who is actually in scope, what it genuinely requires, and the short list a small operator should do first - without the legal fog.