What hashing a password actually protects you from
Password hashing protects users after a database leak, but it does not stop phishing, credential stuffing, or bad session security.
8 results
Password hashing protects users after a database leak, but it does not stop phishing, credential stuffing, or bad session security.
HSTS is powerful and unforgiving. Roll it out in stages, audit subdomains first, and treat preload as a one-way door.
A practical guide to noopener, noreferrer and nofollow: what they change, when to use them, and what they do not fix.
Permissions-Policy can reduce browser feature access, especially in iframes. It is useful, but narrower than many teams assume.
Most organisations already have shadow AI. This 10-minute, 7-question audit shows you exactly where you stand — and what to do next.
Contact forms are the weakest link in most websites' spam defenses. Here's why they're so vulnerable and what to do about it.
Email authentication records look like gibberish until you need them. Here's a practical guide to MX, SPF, DKIM and DMARC that skips the theory and focuses on what works.
EXIF metadata embeds location, device info, and timestamps into every photo. Here's how to strip it reliably before sharing images online.