Your Server Doesn't Know What Random Means (And That's a Problem)
Linux entropy pools decide how fast a box generates SSH keys and TLS certs. What haveged, virtio-rng, and hardware RNG fix on a freshly booted VM.
All the articles with the tag "security".
Linux entropy pools decide how fast a box generates SSH keys and TLS certs. What haveged, virtio-rng, and hardware RNG fix on a freshly booted VM.
Advanced Caddy server configuration: wildcard certs, Caddyfile matchers, Docker label integration, rate limiting, forward auth with Authelia, and the JSON API.
Set up auditd to log every sudo command and file change on Linux: auditctl rules, ausearch, aureport, and shipping logs to Loki or Elasticsearch for compliance.
HashiCorp Vault tutorial: KV v2 secrets, AppRole auth, dynamic database credentials that auto-expire, a PKI certificate authority, and auto-unseal with cloud KMS.
Set up a WireGuard VPN kill switch and prevent DNS leaks on Linux. Practical iptables rules, resolv.conf locking, and systemd-resolved config.
Suricata beats Snort on multi-threading and EVE JSON logging. Side-by-side IDS/IPS breakdown with Suricata install, suricata.yaml config, and OPNsense setup for home labs.
nmap isn't just for pen testers. Learn what's actually worth scanning on your home network and what those open ports really mean.
Stop texting passwords. Set up Vaultwarden organizations to share credentials with family or your team: collections, member roles, the bw CLI, and backups.
Learn Linux capabilities to drop root privileges without breaking your apps. Master cap_drop, cap_add in Docker, and setcap for fine-grained privilege control.
Stop running Docker containers like it's the Wild West. Learn 15 critical Docker security mistakes and practical fixes to harden your containers today.
Go beyond ufw allow/deny: rate limiting with ufw limit, logging levels, before.rules for iptables, IPv6 handling, Docker bypass fixes, and fail2ban integration.
Scan your containers and dependency trees with trivy, grype, syft, and osv-scanner. Generate SBOMs and catch CVEs before a supply chain attack catches you.