Tagged security
4 write-ups.
An Open Redirect Guard That Rebuilt What It Rejected
isSafeReturnTo("//bad.example.com") returns false, and the fallback for that rejection handed the browser the same string back, rebuilt from the request path. 0.3.0 closed one open redirect and shipped a second one for eight more days; both had been there since the first publish in 2019.
What Maintaining a Forked npm Package Actually Buys
I would have said "eighteen releases of upkeep". What npm audit can see is one digit in a dependency range: a caret below 1.0.0 walls off the published fix, so it reports "No fix available". What it could not see is the open redirect my fork shipped for seven years while auditing clean.
An AI Capture-the-Flag Tournament: What the Scoreboard Counted
A preliminary report concluded that models under 3B parameters cannot chain exploits. A later tournament with much larger models put an 8B model last: the engine credited 2 of its 279 logged captures, because a per-turn marker had counted each of the 232 times it read bonus flags off its own machine.
How a Dedup Pass Deleted My Training Curriculum
A fine-tuning pipeline that weighted its best examples 6x by duplicating them to 94,022 lines, followed by a dedup pass that handed the trainer 50,145, each exactly once. Two retrains were rolled back for regressing before I found that the graded curriculum had never reached the trainer at all.