Topic

#security

5 essays on security from the people writing in Remote Since Forever.

Essays
5
Contributors
1
First filed
Jul 2026
Latest
Sep 2026
Written by NH
  1. aws

    Closing the Rate-Limit Bypass: A CloudFront + ALB Case Study

    How we closed an `X-Forwarded-For` spoofing bypass on an AWS WAF rate-limit rule — CloudFront custom secret header, ALB origin verification, and a composite-key rate-based rule that actually counts real clients.

    10 min
  2. express

    Replacing a Wildcard CORS Policy: An Express Allowlist Case Study

    How we replaced a permissive Express `cors` regex with a strict allowlist — escaped-dot origin matching, `Vary: Origin` on every response, and no more CWE-942 finding on the pen-test report.

    8 min
  3. aws

    How a CloudFront Custom Error Page Leaked JWTs to S3: A Case Study

    A pen-test curl found CloudFront forwarding `Authorization` headers to the S3 error-page bucket, where S3 reflected every JWT back in its XML error response. Two lines of Terraform closed it across sixteen distributions.

    12 min
  4. jwt

    How a JWT Audience Map Saved a CORS Mistake: A Defense-in-Depth Case Study

    On a client's API, a CORS wildcard looked like a HIGH severity finding — until we tried to actually exploit it. A second, independent JWT audience check turned a trivially exploitable bug into one that required a much harder prerequisite.

    7 min
  5. devsecops

    From DevOps to DevSecOps: How I Became Clearview's In-House Pen-Tester

    How we built an in-sprint pen-tester role into every engagement — the DevSecOps handoff, the two decades of DevOps that led to it, and the OWASP Top 10 categories that show up first in real client APIs.

    11 min
Type to search. ↑↓ to navigate. Enter to open. Esc to close.