SAAS Security Blog

News and resources for development, web application security and cryptography.

Fortifying Your Digital Storefront: Essential Bot Mitigation Strategies for E-commerce

So you're making an RSA key for an HTTPS certificate. What key size do you use?

What web developers should know about HTTPS but probably don't.

What Is Certificate Pinning?

How To Setup Your Development Environment for Ruby on Rails in 2026

Ultimate Guide to Rack::Attack

Product Development for Non Us Markets

Single Multi Domain Https Certificates Are the Same Thing

'You can't use Brotli for dynamic content'

5700 upvotes later: be careful about crypto advice from Reddit.

Break the web.

CERT COMMON NAME INVALID doesn't mean what you think it does

ES2017's async/await is the best thing to ever happen to JavaScript

HAProxy for Modern Load Balancing

How to diagnose and troubleshoot JavaScript async/await issues

How to flatten an existing JavaScript codebase

HTTPS provides more than just privacy

It's happened: current Chrome is warning users about insecure pages

Modern nginx Configuration for HTTP/2 Load Balancing

Onion TLS/SSL certificate updates

Practical Prevention of Web Shenanigans With Content Security Policy

Safe ECC curves for HTTPS are coming sooner than you think

SSL 'site seals' are even worse than you thought

Strange things are afoot with Symantec's search results injection

The ultimate guide to deploying your node app on Linux

Unix things web developers often struggle with - and how to fix them

We recreated the Unix Rosetta Stone

Why can't I get a wildcard EV certificate?

Why people who know better still say 'SSL'. And 'hoverboard'.

Why there's junk in your whois results, and how you can get rid of it

Why you're always at least two steps down your HTTPS certificate chain

Wireshark is the simplest way to inspect HTTPS on your Mac

You won't remember the options for OpenSSL, so here's bash shortcuts for everything.

Your OpenSSL CSR command is out of date