Your Own .onion Site From Scratch: Vanity Addresses, Stealth Onions, and Real Hardening
Set up hardened Tor v3 onion services with vanity addresses, client authorization, and comprehensive security hardening techniques.
Explore threat detection, vulnerability management, and hardening strategies for Linux systems, cloud infrastructure, and software applications.
Set up hardened Tor v3 onion services with vanity addresses, client authorization, and comprehensive security hardening techniques.
Implement mutual TLS for service authentication in Go and Rust. Generate certificates, set up your CA, and secure internal services without service meshes.
OWASP Top 10 2025 explained with vulnerable code and real fixes. Understand broken access control, injection, and critical vulnerabilities.
Container image scanning at scale: compare Harbor, Quay, and ECR for registry scanning, CVE monitoring, and securing thousands of images in production.
Replace static database credentials with HashiCorp Vault dynamic secrets. Automatic rotation, bounded blast radius, and audit trails. Full production guide.
Learn SCIM provisioning with Authentik to automatically manage users across self-hosted apps. Covers architecture, working configurations, and failure modes.
Learn to centralize secrets with HashiCorp Vault. Cover KV storage, Transit encryption, and AppRole machine authentication for self-hosted setups.
Compare AES-GCM vs ChaCha20-Poly1305 AEAD ciphers. Understand performance tradeoffs, hardware compatibility, and when to use each cipher for your encryption.
Set up NSD for authoritative DNS with DNSSEC signing, zone transfers, and production-ready operations. A faster, more secure alternative to BIND.
Automate short-lived certificate rotation with Vault PKI and cert-manager. Reduce attack surface, force automation from day one, and monitor effectively.