Category

Security

All posts in this stream, newest first.

CSRF: The Attack That Rides Your Login Session

Cross-site request forgery tricks your browser into spending your login session on the attacker's behalf. Here's how it works, how WordPress's nonce system helps, and what to check when a plugin's defenses are not enough.

by Robbie·Jun 5, 2026·5 min read

TOTP, Passkeys, SMS: Two-Factor Methods Ranked

Not all second factors are created equal. Here is how SMS, authenticator apps, and passkeys actually hold up against phishing and SIM swaps, and how to get a reluctant team to turn any of them on.

by Robbie·May 16, 2026·5 min read