logo

Jesse's Blog

Change Other People's Avatars on a Retail Website

Why you should ensure your endpoints' authorization and authentication have been thoroughly tested. Read more...

Your Order History: For All the World to See

When buggy access controls can leak your personal information. Read more...

Encryption, Stacktraces, and Name Suppression

What laws could be broken when best practices aren't followed? Read more...

A Pure JS Space Game

Learning me some modern JavaScript without a compilation step. Read more...

Lifting PII from a News Website's Comment Section

How a poorly implemented 3rd-party commenting system can leak your personal data. Read more...