Sep 09, 2024
219 words
Problematic Course Platform

Regarding the Educoder platform mentioned before, the platform is very problematic. It doesn't have any CSP policies, you can input markdown to it, and I discovered this when it rendered images directly from my CDN

Aug 12, 2023
627 words
Web Scraping and Security

I am obsessed with searching and browsing the Internet these days. However, it is kind of tiresome to browse everything myself. So I decided to try out scrapying information. When trying to scrape a website,

Enc keys are deterministic(Argon2, username and password), Sign with private key and store public sign key in keystore UUID is deterministc (Argon2, username and password) Since encryption protects the confidentiality, the attacker doesn't know the