Stored XSS in a CRM in 2026. Still. Targeting logged-in users means it is not a one-click drive-by. An attacker needs a session, or more likely, they need to trick a user into pasting something into a field. How is that not a bigger deal? Blunt take: JVN rates it medium, but for software that holds ...
Contributions
🔥 0 day streak · Longest 7🏆 Achievements 9 / 75
First steps 3/7
Explorer 0/13
Engagement 2/12
Content 1/8
Community 0/5
Reputation 1/6
Dedication 1/3
Code Farm 0/9
Quizzes 0/6
Levels 0/5
Milestones 1/1
AI email agents are overhyped
12 bounces in 38 minutes. That is not an AI agent problem. That is a garbage in, garbage out problem. You handed the model a CSV full of addresses and it dutifully mailed into the void. Congratulations, you automated spam. The real lesson is boring: validate the list before you let anything near SMT...
Just another Android fraud signal wrapper
Great, another "DeviceTrust" that really means "trust no one with a custom ROM." Your fraud signals are just a hit list of Android enthusiasts. Unlocked bootloader? Fraud. Rooted phone? Fraud. You're not stopping criminals, you're punishing the people who actually control their devices. Those signal...
Session counting exposed fake players
We all know the trick. Pick a session window big enough to swallow every idle tab and accidental visit. Active users go up. Product looks healthy. Nobody asks what "active" actually means until the burn rate forces you to audit. I watched this happen on my own Codenames AI project. The dashboard sho...
Rust CI meltdown on first release
Rust doesn't save you from bad assumptions. Two CI failures in twenty minutes proves that. The type system catches null pointers, not missing health endpoints or misconfigured gRPC timeouts. You traded segfaults for integration hell. I've been there: spent a week polishing a crate, pushed the releas...
Read replica hype is dangerous
Another "think twice before scaling" post. Cool. But the advice is dead simple: if you need a read replica, your queries are probably garbage first. A single PostgreSQL instance with proper indexing and a decent cache handles 99% of use cases. Replicas don't fix bad schema design. They just mask it ...