Alikhan Uzakov @alikhan_uzakov

Executing arbitrary JavaScript from third-party origin when processing HTTP Basic Auth in Firefox, the story behind Bugzilla 1944926 and no CVE.

All opinions in this post are my own (and my colleague’s), and do not represent any employer, organization, or institution with which we are or have been affiliated.

Read more

Why every Security Engineer needs to know UX, program management and be imperfect.

In the past decade, the landscape of technical roles has transformed dramatically. Where once software engineers, ops, and sysadmins had distinct skill sets, the advent of DevOps has blurred these lines, creating an expectation for multifaceted expertise.

Read more

The Inconvenience of 2FA Convenience

Why your 2FA might not be an actual 2FA: the story of how I broke my phone screen

A common piece advice in the security world for securing your accounts/services is to use 2-Factor Authentication (2FA). “Use 2FA to be safe!” slogan often fails to take into account that many/most people have the second factor authentication on the same device that houses the first factor authentication.

Read more

Cost-effective means of combating domain phishing.

If you ever needed a solution to find and monitor phishing domains related to your company, but didn’t have a budget (or didn’t want to spend too much money) for a full scale solution – you are in the right place. The goal of this post is to talk about combating phishing domains, what actionable and measurable steps you can take, advantages and disadvantages of this setup.

Read more

Efficiency in personal finance

Working in the software engineering field one of the concepts we often speak about is efficiency. It would be no surprise to many that we can apply efficiency to our personal finance as well. Signal Credits by Eva K, CC BY-SA 2.5

Read more