Notes about Security
A collection of articles about product security, software engineering, and building reliable products.
Hidden security costs when choosing API frameworks
When selecting an API framework, most startups focus on developer productivity, community size, and how quickly they can ship their MVP. I've witnessed firsthand how framework...
2025-05-21
Authentication strategies for scaling B2B products
According to recent surveys, nearly 68% of B2B SaaS startups adopt JWT (JSON Web Tokens) as their default authentication mechanism without considering alternatives. While JWT...
2025-05-14
Implementing OAuth2 for B2B SaaS: Why small teams struggle and how to succeed
Why do so many startups implement OAuth2 in ways that create more security problems than they solve?
2025-05-07
Security is done elsewhere
Security being implemented elsewhere is a common attitude amongst developers, at least in my experience. I've certainly fallen victim to this attitude myself, especially when...
2025-04-30
API security should be built into your product
I see many teams that have a laissez-faire attitude towards API security. They'll build their product, make sure all requested features are in, and one week before going live...
2025-04-23