# Protection

Published articles for Protection.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## aulumu Introduces Nine iPhone 18 Pro Cases with Aramid-TPU Protection and Glow-in-the-Dark Designs

DevFeed: [aulumu Introduces Nine iPhone 18 Pro Cases with Aramid-TPU Protection and Glow-in-the-Dark Designs](<https://devfeed.tech/articles/aulumu-s-iphone-18-pro-cases-survive-drops-glow-in-the-dark-and-auto-cool-your-phone-26987.md>)

Original publisher: [Read original article](<https://www.yankodesign.com/2026/09/15/aulumus-iphone-18-pro-cases-survive-drops-glow-in-the-dark-and-auto-cool-your-phone/>)

Author: Sarang Sheth

Published: 2026-09-15T23:30:05Z

Content type: article

Language: en

Sources: [Yanko Design](<https://devfeed.tech/sources/yanko-design.md>)

Topics: [iphone](<https://devfeed.tech/topics/iphone.md>)

Tags: [accessories](<https://devfeed.tech/tags/accessories.md>), [accessories-deals-product-design-aulumu-smartphone-case](<https://devfeed.tech/tags/accessories-deals-product-design-aulumu-smartphone-case.md>), [aulumu](<https://devfeed.tech/tags/aulumu.md>), [consumer](<https://devfeed.tech/tags/consumer.md>), [deals](<https://devfeed.tech/tags/deals.md>), [design](<https://devfeed.tech/tags/design.md>), [iphone](<https://devfeed.tech/tags/iphone.md>), [product-design](<https://devfeed.tech/tags/product-design.md>), [products](<https://devfeed.tech/tags/products.md>), [protection](<https://devfeed.tech/tags/protection.md>), [smartphone-case](<https://devfeed.tech/tags/smartphone-case.md>), [tech](<https://devfeed.tech/tags/tech.md>)

### AI overview

The article examines aulumu's A18 collection of nine iPhone 18 Pro cases, highlighting different materials and design approaches. It focuses on the A18 Armor Shockproof Case, which combines 1500D aramid fiber with TPU for a lightweight build with added flexibility and cushioning.

### Source excerpt

aulumu's iPhone 18 Pro Cases Survive Drops, Glow In The Dark, And Auto Cool Your Phone Picking a phone case is one of the most low-stakes high-stakes decisions in consumer tech. The stakes are low because it's a $40 purchase. The...

## The only perfect Endpoint Prevention and Response (EPR) score in 2026 belongs to Elastic

DevFeed: [The only perfect Endpoint Prevention and Response (EPR) score in 2026 belongs to Elastic](<https://devfeed.tech/articles/the-only-perfect-endpoint-prevention-and-response-epr-score-in-2026-belongs-to-elastic-26916.md>)

Original publisher: [Read original article](<https://www.elastic.co/blog/av-comparatives-epr-test-2026>)

Author: Mia LaVada

Published: 2026-09-15T00:00:00Z

Content type: article

Language: en

Sources: [Elastic Blog - Elasticsearch, Kibana, and ELK Stack](<https://devfeed.tech/sources/elastic-blog-elasticsearch-kibana-and-elk-stack.md>)

Topics: [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Security](<https://devfeed.tech/topics/security.md>), [SOC](<https://devfeed.tech/topics/soc.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [alert-fatigue](<https://devfeed.tech/tags/alert-fatigue.md>), [analysts](<https://devfeed.tech/tags/analysts.md>), [investigation-incident-response-security-compliance-security-analytics-xdr](<https://devfeed.tech/tags/investigation-incident-response-security-compliance-security-analytics-xdr.md>), [obfuscation](<https://devfeed.tech/tags/obfuscation.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [protection](<https://devfeed.tech/tags/protection.md>), [security](<https://devfeed.tech/tags/security.md>), [security-endpoint-security](<https://devfeed.tech/tags/security-endpoint-security.md>), [soc](<https://devfeed.tech/tags/soc.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [testing](<https://devfeed.tech/tags/testing.md>), [tooling](<https://devfeed.tech/tags/tooling.md>), [usb](<https://devfeed.tech/tags/usb.md>)

### AI overview

Elastic describes its results in the 2026 AV-Comparatives Endpoint Prevention and Response test, reporting 100% protection scores, zero false alerts, and the lowest modeled operational footprint among tested products. The article explains that Elastic stopped all 50 attack scenarios at the initial phase.

### Source excerpt

Elastic sits at the very top of this year's AV-Comparatives' CyberRisk Quadrant within the 2026 Endpoint Prevention and Response (EPR) test with the highest protection scores at 100%. Learn more.

## PayZephyr: One Payment API for Stripe, Paystack, and PayPal

DevFeed: [PayZephyr: One Payment API for Stripe, Paystack, and PayPal](<https://devfeed.tech/articles/payzephyr-one-payment-api-for-stripe-paystack-and-paypal-22288.md>)

Original publisher: [Read original article](<https://laravel-news.com/payzephyr>)

Author: Paul Redmond

Published: 2026-09-11T01:46:25Z

Content type: tutorial

Language: en

Sources: [Laravel](<https://devfeed.tech/sources/laravel.md>)

Topics: [Laravel](<https://devfeed.tech/topics/laravel.md>), [API](<https://devfeed.tech/topics/api.md>), [stripe](<https://devfeed.tech/topics/stripe.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [checkout](<https://devfeed.tech/tags/checkout.md>), [failover](<https://devfeed.tech/tags/failover.md>), [installation](<https://devfeed.tech/tags/installation.md>), [integration](<https://devfeed.tech/tags/integration.md>), [laravel](<https://devfeed.tech/tags/laravel.md>), [laravel-packages](<https://devfeed.tech/tags/laravel-packages.md>), [payment](<https://devfeed.tech/tags/payment.md>), [payments](<https://devfeed.tech/tags/payments.md>), [production](<https://devfeed.tech/tags/production.md>), [protection](<https://devfeed.tech/tags/protection.md>), [providers](<https://devfeed.tech/tags/providers.md>), [stripe](<https://devfeed.tech/tags/stripe.md>), [subscription](<https://devfeed.tech/tags/subscription.md>), [webhooks](<https://devfeed.tech/tags/webhooks.md>)

### AI overview

PayZephyr is a Laravel payments package that provides one API for eight payment providers. It supports automatic failover, double-charge protection, signed webhooks, subscriptions, refunds, Composer installation, custom drivers, queue integration, and a playground.

### Source excerpt

PayZephyr gives Laravel one payment API across Stripe, PayPal, Paystack, Flutterwave, and four more, with failover and double-charge protection. The post PayZephyr: One Payment API for Stripe, Paystack, and PayPal appeared first on Laravel News. Join the Laravel Newsletter to get Laravel articles like this directly in your inbox.

## Harness Named a Leader in SecureIQLab's August 2026 Cloud WAAP v5.0 Validation Report

DevFeed: [Harness Named a Leader in SecureIQLab's August 2026 Cloud WAAP v5.0 Validation Report](<https://devfeed.tech/articles/harness-is-a-leader-in-waap-evaluation-13411.md>)

Original publisher: [Read original article](<https://www.harness.io/blog/harness-named-a-leader-in-secureiqlabs-cloud-waap-v5-0-cyberrisk-validation-report>)

Author: Christine Ferrusi Ross

Published: 2026-09-11T00:00:00Z

Content type: news

Language: en

Sources: [Harness Blog](<https://devfeed.tech/sources/harness-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [API](<https://devfeed.tech/topics/api.md>), [Web](<https://devfeed.tech/topics/web.md>), [Testing](<https://devfeed.tech/topics/testing.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [api](<https://devfeed.tech/tags/api.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [harness](<https://devfeed.tech/tags/harness.md>), [protection](<https://devfeed.tech/tags/protection.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [v5](<https://devfeed.tech/tags/v5.md>), [validation](<https://devfeed.tech/tags/validation.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

Harness Web Application & API Protection was named a Leader in SecureIQLab's August 2026 Cloud WAAP v5.0 CyberRisk Validation Comparative Report. The article highlights reported scores for API protection, advanced-threat coverage, deployment and management, false-positive avoidance, and GenAI and LLM operational efficiency.

### Source excerpt

In the August 2026 SecureIQLab Cloud WAAP v5.0 CyberRisk Validation Comparative Report, Harness Web Application & API Protection (WAAP) was named a Leader. | Blog

## \[Crypto\] Time-based one-time password (TOTP) for 2FA, part I

DevFeed: [\[Crypto\] Time-based one-time password (TOTP) for 2FA, part I](<https://devfeed.tech/articles/crypto-time-based-one-time-password-totp-for-2fa-part-i-20550.md>)

Original publisher: [Read original article](<https://yurichev.com/blog/TOTP1/>)

Published: 2026-09-09T22:00:00Z

Content type: tutorial

Language: en

Sources: [Dennis Yurichev](<https://devfeed.tech/sources/dennis-yurichev.md>)

Topics: [passwords](<https://devfeed.tech/topics/passwords.md>), [QR Code](<https://devfeed.tech/topics/qrcode.md>), [Google](<https://devfeed.tech/topics/google.md>), [Python](<https://devfeed.tech/topics/python.md>), [Unix](<https://devfeed.tech/topics/unix.md>), [App](<https://devfeed.tech/topics/app.md>), [email](<https://devfeed.tech/topics/email.md>), [Code](<https://devfeed.tech/topics/code.md>)

Tags: [account](<https://devfeed.tech/tags/account.md>), [app](<https://devfeed.tech/tags/app.md>), [argument](<https://devfeed.tech/tags/argument.md>), [backup](<https://devfeed.tech/tags/backup.md>), [code](<https://devfeed.tech/tags/code.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [env-file-security](<https://devfeed.tech/tags/env-file-security.md>), [github](<https://devfeed.tech/tags/github.md>), [google](<https://devfeed.tech/tags/google.md>), [password](<https://devfeed.tech/tags/password.md>), [protection](<https://devfeed.tech/tags/protection.md>), [python](<https://devfeed.tech/tags/python.md>), [run](<https://devfeed.tech/tags/run.md>), [server](<https://devfeed.tech/tags/server.md>), [smartphone](<https://devfeed.tech/tags/smartphone.md>), [unix](<https://devfeed.tech/tags/unix.md>)

### AI overview

This tutorial explains how time-based one-time passwords work for two-factor authentication. It covers importing a base32-encoded secret from a QR code into Google Authenticator, generating 6-digit login codes, and calculating them with HMAC-SHA-1 from the secret and Unix time. It also discusses backup codes and securely storing TOTP secrets separately from passwords.

### Source excerpt

[Crypto] Time-based one-time password (TOTP) for 2FA, part I

## Negative caching protects databases from repeated lookups for nonexistent keys

DevFeed: [Negative caching protects databases from repeated lookups for nonexistent keys](<https://devfeed.tech/articles/negative-caching-the-misses-cost-more-than-the-hits-39602.md>)

Original publisher: [Read original article](<https://ankit-rana.com/logs/50-negative-caching-misses-cost-more/>)

Author: hello@ankit-rana.com

Published: 2026-09-09T00:00:00Z

Content type: tutorial

Language: en

Sources: [Ankit Rana | Mechanical Sympathy](<https://devfeed.tech/sources/ankit-rana-mechanical-sympathy.md>)

Topics: [Caching](<https://devfeed.tech/topics/caching.md>), [Cache](<https://devfeed.tech/topics/cache.md>), [Database](<https://devfeed.tech/topics/database.md>), [Security](<https://devfeed.tech/topics/security.md>), [Latency](<https://devfeed.tech/topics/latency.md>)

Tags: [cache](<https://devfeed.tech/tags/cache.md>), [cache-penetration](<https://devfeed.tech/tags/cache-penetration.md>), [caching](<https://devfeed.tech/tags/caching.md>), [database](<https://devfeed.tech/tags/database.md>), [negative-caching](<https://devfeed.tech/tags/negative-caching.md>), [protection](<https://devfeed.tech/tags/protection.md>), [redis](<https://devfeed.tech/tags/redis.md>), [reliability](<https://devfeed.tech/tags/reliability.md>), [security](<https://devfeed.tech/tags/security.md>), [ttl](<https://devfeed.tech/tags/ttl.md>)

### AI overview

Negative caching prevents repeated database queries for nonexistent keys by storing a distinguishable marker for negative results. The article explains how partner integrations, scrapers, stale clients, migrations, or attackers can exploit this gap and recommends using a shorter TTL for negative entries.

### Source excerpt

A cache that stores only found values gives you no protection against lookups for things that do not exist, and a miss on a nonexistent key costs the full origin query every single time. If the key is user supplied, an attacker can generate unlimited unique misses and bypass the cache entirely, which is cache penetration. Caching the negative result fixes it, with a shorter TTL than positive entries because a value appearing is a much more likely event than one disappearing.

## Introducing IP Allowlisting

DevFeed: [Introducing IP Allowlisting](<https://devfeed.tech/articles/introducing-ip-allowlisting-16082.md>)

Original publisher: [Read original article](<https://postmarkapp.com/blog/restrict-email-sending-api-with-ip-allowlisting>)

Author: Postmark team (fdossetto+postmark@activecampaign.com)

Published: 2026-09-08T17:37:00Z

Content type: release

Language: en

Sources: [Postmark (en-US)](<https://devfeed.tech/sources/postmark-en-us.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [API](<https://devfeed.tech/topics/api.md>), [Network](<https://devfeed.tech/topics/network.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [ip](<https://devfeed.tech/tags/ip.md>), [nat](<https://devfeed.tech/tags/nat.md>), [network](<https://devfeed.tech/tags/network.md>), [product-news](<https://devfeed.tech/tags/product-news.md>), [protection](<https://devfeed.tech/tags/protection.md>), [range](<https://devfeed.tech/tags/range.md>), [request](<https://devfeed.tech/tags/request.md>), [security](<https://devfeed.tech/tags/security.md>), [token](<https://devfeed.tech/tags/token.md>)

### AI overview

Postmark introduces IP Allowlisting, a security feature that restricts email sending through the Postmark API to up to 10 configured IP ranges in CIDR format. Requests from outside the allowed ranges are rejected with a 403 response. The ranges can be configured at the Server or account level, with Server settings overriding account settings.

### Source excerpt

Good security is layered and each layer does a job the others can't. Scoping a token to a Server limits what it reaches. Rotating a token limits how long it lasts. Neither can say anything about where a request came from. We've been hard at work to ship a new layer of protection that can. IP Allowlisting is a new Postmark security feature that lets you name the infrastructure your email should come from. It's available now on all Postmark plans at no extra cost. It's off until you turn it on. How IP Allowlisting works You add up to 10 IP ranges, in CIDR format, that are allowed to send email using the Postmark API. Send requests from outside those ranges are rejected with a 403 status code that includes the IP the request came from. You can set your ranges in two places: On a Server. The ranges apply to that Server, covering every Message Stream on it. This is where we'd suggest starting. On your account. The ranges apply to every Server you have. When a Server has ranges of its own they will override account level settings. That's it! A straightforward security control to protect your API sending. Protect individual Servers or across your account. Set your Allowlist ranges on the account or Server. If you don't write CIDR blocks often, it's a quick 30 seconds to get familiar with them and the correct notation. CIDR blocks allow you to enable a grouped collection of IP addresses (aka ranges.) A CIDR block is an IP address followed by a suffix that says how many addresses it covers. The smaller the suffix, the wider the range: 198.51.100.24/32 one address, and only that address 203.0.113.0/24 256 addresses: 203.0.113.0 through 203.0.113.255 203.0.0.0/16 65,536 addresses: 203.0.0.0 through 203.0.255.255 So a /32 pins the allowlist to a single machine, and a /24 covers a subnet. Most teams end up somewhere in that span. Where you find your own ranges depends on how you send. A single VM has a static public IP you can read off your provider's dashboard. Cloud workloads

## Tapjacking Protection: Rejecting Android Touches Behind an Overlay

DevFeed: [Tapjacking Protection: Rejecting Android Touches Behind an Overlay](<https://devfeed.tech/articles/tapjacking-protection-rejecting-android-touches-behind-an-overlay-19544.md>)

Original publisher: [Read original article](<https://www.codenameone.com/blog/tapjacking-protection/>)

Author: Shai Almog

Published: 2026-08-25T00:00:00Z

Content type: release

Language: en

Sources: [CodeName One](<https://devfeed.tech/sources/codename-one.md>)

Topics: [Android](<https://devfeed.tech/topics/android.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [android-12](<https://devfeed.tech/tags/android-12.md>), [false-positive](<https://devfeed.tech/tags/false-positive.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [protection](<https://devfeed.tech/tags/protection.md>), [report](<https://devfeed.tech/tags/report.md>)

### AI overview

Codename One adds Android tapjacking and screen-overlay protection. The feature can report or block gestures that begin behind another application's overlay and can ask Android 12 or newer to prevent overlays on sensitive screens.

### Source excerpt

Codename One can now report or block Android gestures that begin behind another application's overlay, and can ask Android 12 or newer to hide overlay windows on sensitive screens.

## Modern App Protection Requires Polymorphism | Guardsquare

DevFeed: [Modern App Protection Requires Polymorphism | Guardsquare](<https://devfeed.tech/articles/modern-app-protection-requires-polymorphism-guardsquare-26311.md>)

Original publisher: [Read original article](<https://www.guardsquare.com/blog/polymorphic-mobile-app-protection>)

Author: Jason Cortlund - Technical Marketing Writer

Published: 2026-08-18T13:45:43Z

Content type: article

Language: en

Sources: [Guardsquare Blog](<https://devfeed.tech/sources/guardsquare-blog.md>)

Topics: [Mobile](<https://devfeed.tech/topics/mobile.md>), [Mobile Security](<https://devfeed.tech/topics/mobile-security.md>), [Polymorphism](<https://devfeed.tech/topics/polymorphism.md>), [Security](<https://devfeed.tech/topics/security.md>), [Development](<https://devfeed.tech/topics/development.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>)

Tags: [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [ai](<https://devfeed.tech/tags/ai.md>), [development](<https://devfeed.tech/tags/development.md>), [dexguard](<https://devfeed.tech/tags/dexguard.md>), [ixguard](<https://devfeed.tech/tags/ixguard.md>), [large-language-models-llms](<https://devfeed.tech/tags/large-language-models-llms.md>), [mobile](<https://devfeed.tech/tags/mobile.md>), [polymorphism](<https://devfeed.tech/tags/polymorphism.md>), [protection](<https://devfeed.tech/tags/protection.md>), [reverse-engineering](<https://devfeed.tech/tags/reverse-engineering.md>), [security](<https://devfeed.tech/tags/security.md>), [security-research](<https://devfeed.tech/tags/security-research.md>), [thought-leadership](<https://devfeed.tech/tags/thought-leadership.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article argues that mobile app protection should use polymorphism, with protections changing for each application build. It links this approach to the risks created by development speed, AI-generated code, and scalable reverse-engineering attacks.

### Source excerpt

According to credit reporting agency Equifax, "...mobile app security is often neglected by developers -- making apps more vulnerable to fraud." The reason for this is quite simple for most organizations: development speed is the dominant priority. In fact, 79% of mobile developers cite time-to-market pressure as the top barrier to stronger protection.

## How Mobile App Security from Guardsquare Addresses Gaps in Framework Compliance

DevFeed: [How Mobile App Security from Guardsquare Addresses Gaps in Framework Compliance](<https://devfeed.tech/articles/how-mobile-app-security-from-guardsquare-addresses-gaps-in-framework-compliance-26306.md>)

Original publisher: [Read original article](<https://www.guardsquare.com/blog/how-mobile-app-security-from-guardsquare-addresses-gaps-in-framework-compliance>)

Author: Guest post by Dr. Edward Amoroso, CEO, TAG Infosphere Inc. and former AT&T Chief Security Officer

Published: 2026-08-11T14:00:31Z

Content type: opinion

Language: en

Sources: [Guardsquare Blog](<https://devfeed.tech/sources/guardsquare-blog.md>)

Topics: [Mobile Security](<https://devfeed.tech/topics/mobile-security.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [frameworks](<https://devfeed.tech/tags/frameworks.md>), [governance](<https://devfeed.tech/tags/governance.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [mobile](<https://devfeed.tech/tags/mobile.md>), [protection](<https://devfeed.tech/tags/protection.md>), [regulatory](<https://devfeed.tech/tags/regulatory.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [standards](<https://devfeed.tech/tags/standards.md>)

### AI overview

A featured guest post examines how mobile application security, including Guardsquare's hardening, runtime protection, and anti-tampering capabilities, can help enterprises address gaps in compliance frameworks. It also argues that frameworks such as NIST CSF 2.0 should more explicitly account for mobile app risk.

### Source excerpt

Former AT&T Chief Security Officer and TAG Infosphere founder Dr. Edward Amoroso shares his perspective on the state of mobile application security in a featured guest post for Guardsquare. Enterprise compliance is evolving as organizations face mounting regulatory pressure and more capable threat actors. Regulators now expect alignment to frameworks such as National Institute of Standards and Technology Cybersecurity Framework (CSF) 2.0 and sector-specific mandates. Yet, while governance has matured around cloud, endpoint, and networks, mobile app risk remains underrepresented in compliance frameworks and control processes.

## Rethinking Mobile App Security | Guardsquare

DevFeed: [Rethinking Mobile App Security | Guardsquare](<https://devfeed.tech/articles/rethinking-mobile-app-security-guardsquare-26312.md>)

Original publisher: [Read original article](<https://www.guardsquare.com/blog/rethinking-mobile-app-security>)

Author: Guardsquare

Published: 2026-08-04T13:02:55Z

Content type: article

Language: en

Sources: [Guardsquare Blog](<https://devfeed.tech/sources/guardsquare-blog.md>)

Topics: [Mobile Security](<https://devfeed.tech/topics/mobile-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [development](<https://devfeed.tech/tags/development.md>), [ios](<https://devfeed.tech/tags/ios.md>), [mobile](<https://devfeed.tech/tags/mobile.md>), [mobile-security](<https://devfeed.tech/tags/mobile-security.md>), [process](<https://devfeed.tech/tags/process.md>), [protection](<https://devfeed.tech/tags/protection.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [thought-leadership](<https://devfeed.tech/tags/thought-leadership.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article argues that mobile app security failures span code, development, testing, APIs, and production rather than occurring in one isolated place. It recommends integrating continuous security testing into the development lifecycle and protecting application logic such as payment flows, authentication mechanisms, and proprietary algorithms.

### Source excerpt

Mobile app security rarely breaks in a single place. Instead, it fails across layers that were never designed to work together.

## The Hidden Costs of DIY Android App Security | Guardsquare

DevFeed: [The Hidden Costs of DIY Android App Security | Guardsquare](<https://devfeed.tech/articles/the-hidden-costs-of-diy-android-app-security-guardsquare-26305.md>)

Original publisher: [Read original article](<https://www.guardsquare.com/blog/diy-android-app-security-hidden-costs>)

Author: Michael Olechna - Product Marketing Manager

Published: 2026-07-28T13:00:55Z

Content type: opinion

Language: en

Sources: [Guardsquare Blog](<https://devfeed.tech/sources/guardsquare-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Android](<https://devfeed.tech/topics/android.md>), [Mobile](<https://devfeed.tech/topics/mobile.md>), [obfuscation](<https://devfeed.tech/topics/obfuscation.md>), [R8](<https://devfeed.tech/topics/r8.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [dexguard](<https://devfeed.tech/tags/dexguard.md>), [mobile](<https://devfeed.tech/tags/mobile.md>), [obfuscation](<https://devfeed.tech/tags/obfuscation.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [protection](<https://devfeed.tech/tags/protection.md>), [r8](<https://devfeed.tech/tags/r8.md>), [security](<https://devfeed.tech/tags/security.md>), [thought-leadership](<https://devfeed.tech/tags/thought-leadership.md>), [threat-monitoring](<https://devfeed.tech/tags/threat-monitoring.md>)

### AI overview

The article argues that DIY Android app security built around open-source tools can leave important protection gaps. It explains that R8 helps compile and optimize Android applications but is not a complete security solution, lacking capabilities such as string encryption, API endpoint security, and control-flow obfuscation.

### Source excerpt

The DIY temptation to build with open-source is strong for mobile app developers. After all, their job is to build, secure, and design new applications, features, and architectures that benefit the users of their apps.

## Mobile App Security in the Age of SoftPOS | Guardsquare

DevFeed: [Mobile App Security in the Age of SoftPOS | Guardsquare](<https://devfeed.tech/articles/mobile-app-security-in-the-age-of-softpos-guardsquare-26314.md>)

Original publisher: [Read original article](<https://www.guardsquare.com/blog/softpos-mobile-app-security>)

Author: Guardsquare

Published: 2026-07-07T11:42:02Z

Content type: article

Language: en

Sources: [Guardsquare Blog](<https://devfeed.tech/sources/guardsquare-blog.md>)

Topics: [Mobile](<https://devfeed.tech/topics/mobile.md>), [Mobile Security](<https://devfeed.tech/topics/mobile-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [App](<https://devfeed.tech/topics/app.md>), [API](<https://devfeed.tech/topics/api.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [SDKs](<https://devfeed.tech/topics/sdks.md>), [Malware](<https://devfeed.tech/topics/malware.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [api](<https://devfeed.tech/tags/api.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [devices](<https://devfeed.tech/tags/devices.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [financial-services](<https://devfeed.tech/tags/financial-services.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [ios](<https://devfeed.tech/tags/ios.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mobile](<https://devfeed.tech/tags/mobile.md>), [payment](<https://devfeed.tech/tags/payment.md>), [payments](<https://devfeed.tech/tags/payments.md>), [pos](<https://devfeed.tech/tags/pos.md>), [protection](<https://devfeed.tech/tags/protection.md>), [sdks](<https://devfeed.tech/tags/sdks.md>), [security](<https://devfeed.tech/tags/security.md>), [smartphone](<https://devfeed.tech/tags/smartphone.md>), [thought-leadership](<https://devfeed.tech/tags/thought-leadership.md>)

### AI overview

This article examines the security implications of SoftPOS, which turns smartphones into card-present payment terminals. It explains that moving payment functions to mobile devices shifts responsibility to the device, operating system, application integrity, APIs, and runtime environment, and discusses threats including app tampering, reverse engineering, API abuse, credential theft, malware, and bypassed environment checks.

### Source excerpt

As retailers look for faster, more flexible ways to accept payments, SoftPOS is becoming a cornerstone of modern payment strategies. It's expected that by 2027, more than 34.5 million merchants will accept payments through SoftPOS technology. The ability to turn any smartphone into a card-present terminal reduces hardware costs, simplifies onboarding, and supports new use cases like curbside, pop-up stores, and in-aisle checkout.

## Seamless Crash Protection That Symbolicates Native Crashes

DevFeed: [Seamless Crash Protection That Symbolicates Native Crashes](<https://devfeed.tech/articles/seamless-crash-protection-that-symbolicates-native-crashes-19506.md>)

Original publisher: [Read original article](<https://www.codenameone.com/blog/seamless-crash-protection/>)

Author: Shai Almog

Published: 2026-06-22T00:00:00Z

Content type: article

Language: en

Sources: [CodeName One](<https://devfeed.tech/sources/codename-one.md>)

Topics: [App](<https://devfeed.tech/topics/app.md>), [GitHub Issues](<https://devfeed.tech/topics/github-issues.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Disk image](<https://devfeed.tech/topics/disk-image.md>), [Android](<https://devfeed.tech/topics/android.md>), [iOS](<https://devfeed.tech/topics/ios.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [tvOS](<https://devfeed.tech/topics/tvos.md>), [watchOS](<https://devfeed.tech/topics/watchos.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [crash](<https://devfeed.tech/tags/crash.md>), [data](<https://devfeed.tech/tags/data.md>), [github-issues](<https://devfeed.tech/tags/github-issues.md>), [ios](<https://devfeed.tech/tags/ios.md>), [linux](<https://devfeed.tech/tags/linux.md>), [macos](<https://devfeed.tech/tags/macos.md>), [native](<https://devfeed.tech/tags/native.md>), [protection](<https://devfeed.tech/tags/protection.md>), [retry](<https://devfeed.tech/tags/retry.md>), [storage](<https://devfeed.tech/tags/storage.md>), [watchos](<https://devfeed.tech/tags/watchos.md>), [win32](<https://devfeed.tech/tags/win32.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

The article describes the new com.codename1.crash client, which captures crashes on devices, removes personal data before transmission, stores reports until upload succeeds, retries failed uploads, and uses cloud-side symbolication to file deduplicated reports as GitHub issues. It covers native crash support across multiple platforms and deobfuscation of Android exceptions.

### Source excerpt

The new com.codename1.crash client captures crashes on device, scrubs personal data before anything is sent, retries reliably through a storage-first queue, and lets the build cloud symbolicate native crashes and file them as GitHub issues instead of emails.

## OpenAI Style Usage Limits: Implementing Customer Quotas in Your Product

DevFeed: [OpenAI Style Usage Limits: Implementing Customer Quotas in Your Product](<https://devfeed.tech/articles/openai-style-usage-limits-implementing-customer-quotas-in-your-product-10190.md>)

Original publisher: [Read original article](<https://dodopayments.com/blogs/openai-usage-limits-customer-quotas/>)

Author: Ayush Agarwal

Published: 2026-05-20T00:00:00Z

Content type: tutorial

Language: en

Sources: [Dodo Payments Blog](<https://devfeed.tech/sources/dodo-payments-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [OpenAI](<https://devfeed.tech/topics/openai.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [bug](<https://devfeed.tech/tags/bug.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [implement](<https://devfeed.tech/tags/implement.md>), [openai](<https://devfeed.tech/tags/openai.md>), [protection](<https://devfeed.tech/tags/protection.md>), [quotas](<https://devfeed.tech/tags/quotas.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [retry](<https://devfeed.tech/tags/retry.md>), [trust](<https://devfeed.tech/tags/trust.md>), [usage-based-billing](<https://devfeed.tech/tags/usage-based-billing.md>)

### AI overview

A tutorial on implementing customer-facing usage limits for AI and SaaS products. It explains soft limits with email alerts, hard limits that stop billable work, real-time usage aggregation, clear limit messaging, and the protection these controls provide to customers and sellers.

### Source excerpt

How to implement customer facing usage limits and quotas in your AI product. Soft caps, hard caps, alerts, and the OpenAI style limit experience.

## How to Handle Refunds and Chargebacks as a Solo Founder

DevFeed: [How to Handle Refunds and Chargebacks as a Solo Founder](<https://devfeed.tech/articles/how-to-handle-refunds-and-chargebacks-as-a-solo-founder-9895.md>)

Original publisher: [Read original article](<https://dodopayments.com/blogs/handle-refunds-chargebacks-solo-founder/>)

Author: Ayush Agarwal

Published: 2026-03-31T00:00:00Z

Content type: tutorial

Language: en

Sources: [Dodo Payments Blog](<https://devfeed.tech/sources/dodo-payments-blog.md>)

Topics: [Software as a service](<https://devfeed.tech/topics/saas.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [chargebacks](<https://devfeed.tech/tags/chargebacks.md>), [guide](<https://devfeed.tech/tags/guide.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [merchant-of-record](<https://devfeed.tech/tags/merchant-of-record.md>), [payments](<https://devfeed.tech/tags/payments.md>), [protection](<https://devfeed.tech/tags/protection.md>), [revenue](<https://devfeed.tech/tags/revenue.md>), [saas](<https://devfeed.tech/tags/saas.md>), [time](<https://devfeed.tech/tags/time.md>)

### AI overview

A guide for solo founders on distinguishing refunds from chargebacks, preventing payment disputes, and using a Merchant of Record for SaaS to reduce administrative work and protect revenue.

### Source excerpt

A comprehensive guide for solo founders on preventing disputes, managing refunds, and leveraging Merchant of Record protection to save time and revenue.

## Android expands AI-powered scam detection to Samsung devices and more regions

DevFeed: [Android expands AI-powered scam detection to Samsung devices and more regions](<https://devfeed.tech/articles/staying-one-step-ahead-strengthening-android-s-lead-in-scam-protection-19814.md>)

Original publisher: [Read original article](<http://security.googleblog.com/2026/02/strengthening-android-lead-in-scam-protection.html>)

Author: Edward Fernandez (noreply@blogger.com)

Published: 2026-02-25T15:17:00Z

Content type: release

Language: en

Sources: [Google Online Security](<https://devfeed.tech/sources/google-online-security.md>)

Topics: [Android](<https://devfeed.tech/topics/android.md>), [Google AI](<https://devfeed.tech/topics/google-ai.md>), [Google](<https://devfeed.tech/topics/google.md>), [Mobile](<https://devfeed.tech/topics/mobile.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [android](<https://devfeed.tech/tags/android.md>), [android-security](<https://devfeed.tech/tags/android-security.md>), [devices](<https://devfeed.tech/tags/devices.md>), [google](<https://devfeed.tech/tags/google.md>), [mobile](<https://devfeed.tech/tags/mobile.md>), [none](<https://devfeed.tech/tags/none.md>), [on-device-ai](<https://devfeed.tech/tags/on-device-ai.md>), [protection](<https://devfeed.tech/tags/protection.md>), [scams](<https://devfeed.tech/tags/scams.md>), [smartphones](<https://devfeed.tech/tags/smartphones.md>)

### AI overview

Google describes Android's AI-powered scam protections, including Scam Detection warnings for suspicious calls. The article announces expansion of call Scam Detection to Samsung devices and additional regions, while noting existing availability on Google Pixel devices in several countries.

### Source excerpt

Posted by Lyubov Farafonova, Product Manager, Phone by Google; Alberto Pastor Nieto, Sr. Product Manager Google Messages and RCS Spam and Abuse We've shared how Android's proactive, multi-layered scam defenses utilize Google AI to protect users around the world from over 10 billion suspected malicious calls and messages every month1. While that scale is significant, the true impact of these protections is best understood through the stories of the individuals they help keep safe every day. This includes people like Majik B., an IT professional in Sunnyvale, California. Despite his technical background, Majik recently found himself on a call that felt dangerously legitimate. While using his Pixel, he received a call that appeared to be from his bank. The number looked correct, the caller knew his name and his address, and the story about a "suspicious charge" made perfect sense. "I'm usually pretty careful about this stuff," Majik recalled, "but I stayed on the line longer than I normally would. Even knowing how these scams work, it was convincing in the moment." The turning point came when his phone displayed a Scam Detection warning during the call, which provided a critical moment to pause and reflect. Majik hung up, checked his bank app directly, and confirmed there was no fraudulent charge. For Majik, Scam Detection was the intervention he needed: "The warning is what made me pause and avoid a bad situation". While stories like Majik's show how our existing protections provide a robust shield against scams, our work isn't done. As scammers evolve their tactics and create more convincing and personalized threats, we're using the best of Google AI to stay one step ahead. A recent evaluation by Counterpoint Research found that Android smartphones provide the most comprehensive AI-powered protections of any mobile platform. We are committed to building on this foundation by expanding our AI-powered protections to more users and devices, while rolling out new feature

## \[Pentesting\] HTTP auth, part II: digest

DevFeed: [\[Pentesting\] HTTP auth, part II: digest](<https://devfeed.tech/articles/pentesting-http-auth-part-ii-digest-20540.md>)

Original publisher: [Read original article](<https://yurichev.com/blog/HTTP_auth_2/>)

Published: 2025-11-20T23:00:00Z

Content type: article

Language: en

Sources: [Dennis Yurichev](<https://devfeed.tech/sources/dennis-yurichev.md>)

Topics: [HTTP](<https://devfeed.tech/topics/http.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [web browser](<https://devfeed.tech/topics/web-browser.md>)

Tags: [apache](<https://devfeed.tech/tags/apache.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [browser](<https://devfeed.tech/tags/browser.md>), [code](<https://devfeed.tech/tags/code.md>), [compatibility](<https://devfeed.tech/tags/compatibility.md>), [crack](<https://devfeed.tech/tags/crack.md>), [http](<https://devfeed.tech/tags/http.md>), [legacy](<https://devfeed.tech/tags/legacy.md>), [mitm](<https://devfeed.tech/tags/mitm.md>), [password](<https://devfeed.tech/tags/password.md>), [protection](<https://devfeed.tech/tags/protection.md>), [protocol](<https://devfeed.tech/tags/protocol.md>), [server](<https://devfeed.tech/tags/server.md>), [tls](<https://devfeed.tech/tags/tls.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>)

### AI overview

The article examines HTTP Digest Authentication, including how the server and browser exchange hashed credentials, how the exchange resists password interception and replay attacks, and how attackers can attempt to crack MD5-based exchanges with hashcat. It notes that Apache 2.4.63 still uses MD5 and recommends upgrading HTTP authentication to TLS.

### Source excerpt

[Pentesting] HTTP auth, part II: digest

## How Android and Google Messages protect users from mobile scams

DevFeed: [How Android and Google Messages protect users from mobile scams](<https://devfeed.tech/articles/how-android-provides-the-most-effective-protection-to-keep-you-safe-from-mobile-scams-19803.md>)

Original publisher: [Read original article](<http://security.googleblog.com/2025/10/how-android-protects-you-from-scams.html>)

Author: Edward Fernandez (noreply@blogger.com)

Published: 2025-10-30T16:59:00Z

Content type: article

Language: en

Sources: [Google Online Security](<https://devfeed.tech/sources/google-online-security.md>)

Topics: [Android](<https://devfeed.tech/topics/android.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [Mobile](<https://devfeed.tech/topics/mobile.md>), [Google AI](<https://devfeed.tech/topics/google-ai.md>), [iOS](<https://devfeed.tech/topics/ios.md>), [Google](<https://devfeed.tech/topics/google.md>), [iphone](<https://devfeed.tech/topics/iphone.md>), [Messaging](<https://devfeed.tech/topics/messaging.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [android](<https://devfeed.tech/tags/android.md>), [android-security](<https://devfeed.tech/tags/android-security.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [google](<https://devfeed.tech/tags/google.md>), [google-ai](<https://devfeed.tech/tags/google-ai.md>), [ios](<https://devfeed.tech/tags/ios.md>), [iphone](<https://devfeed.tech/tags/iphone.md>), [messaging](<https://devfeed.tech/tags/messaging.md>), [mobile](<https://devfeed.tech/tags/mobile.md>), [none](<https://devfeed.tech/tags/none.md>), [pixel](<https://devfeed.tech/tags/pixel.md>), [protection](<https://devfeed.tech/tags/protection.md>), [report](<https://devfeed.tech/tags/report.md>), [scams](<https://devfeed.tech/tags/scams.md>), [security](<https://devfeed.tech/tags/security.md>), [smartphone](<https://devfeed.tech/tags/smartphone.md>), [survey](<https://devfeed.tech/tags/survey.md>)

### AI overview

This article describes Android's layered protections against mobile scams, including defenses for malicious calls and messages and safety checks for RCS. It also presents a Google and YouGov survey comparing reported scam experiences and confidence among Android and iOS users in the U.S., India, and Brazil.

### Source excerpt

Posted by Lyubov Farafonova, Product Manager, Phone by Google; Alberto Pastor Nieto, Sr. Product Manager Google Messages and RCS Spam and Abuse; Vijay Pareek, Manager, Android Messaging Trust and Safety As Cybersecurity Awareness Month wraps up, we're focusing on one of today's most pervasive digital threats: mobile scams. In the last 12 months, fraudsters have used advanced AI tools to create more convincing schemes, resulting in over $400 billion in stolen funds globally.¹ For years, Android has been on the frontlines in the battle against scammers, using the best of Google AI to build proactive, multi-layered protections that can anticipate and block scams before they reach you. Android's scam defenses protect users around the world from over 10 billion suspected malicious calls and messages every month2. In addition, Google continuously performs safety checks to maintain the integrity of the RCS service. In the past month alone, this ongoing process blocked over 100 million suspicious numbers from using RCS, stopping potential scams before they could even be sent. To show how our scam protections work in the real world, we asked users and independent security experts to compare how well Android and iOS protect you from these threats. We're also releasing a new report that explains how modern text scams are orchestrated, helping you understand the tactics fraudsters use and how to spot them. Survey shows Android users' confidence in scam protections Google and YouGov3 surveyed 5,000 smartphone users across the U.S., India, and Brazil about their scam experiences. The findings were clear: Android users reported receiving fewer scam texts and felt more confident that their device was keeping them safe. Android users were 58% more likely than iOS users to say they had not received any scam texts in the week prior to the survey. The advantage was even stronger on Pixel, where users were 96% more likely than iPhone owners to report zero scam texts4. At the other end o

## Announcing cost-efficient storage with usage-based backups, cold storage, and Network file storage

DevFeed: [Announcing cost-efficient storage with usage-based backups, cold storage, and Network file storage](<https://devfeed.tech/articles/announcing-cost-efficient-storage-with-usage-based-backups-cold-storage-and-network-file-storage-19916.md>)

Original publisher: [Read original article](<https://www.digitalocean.com/blog/nfs-cold-storage-backups>)

Author: Nihar Namjoshi

Published: 2025-10-02T08:05:09Z

Content type: release

Language: en

Sources: [DigitalOcean](<https://devfeed.tech/sources/digitalocean.md>)

Topics: [Digital Ocean](<https://devfeed.tech/topics/digital-ocean.md>), [Filesystems](<https://devfeed.tech/topics/filesystems.md>), [data](<https://devfeed.tech/topics/data.md>), [Data Management](<https://devfeed.tech/topics/data-management.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [datacenter](<https://devfeed.tech/topics/datacenter.md>)

Tags: [backups](<https://devfeed.tech/tags/backups.md>), [cost](<https://devfeed.tech/tags/cost.md>), [data](<https://devfeed.tech/tags/data.md>), [data-centers](<https://devfeed.tech/tags/data-centers.md>), [digitalocean](<https://devfeed.tech/tags/digitalocean.md>), [network](<https://devfeed.tech/tags/network.md>), [product-updates](<https://devfeed.tech/tags/product-updates.md>), [protection](<https://devfeed.tech/tags/protection.md>), [space-object-storage](<https://devfeed.tech/tags/space-object-storage.md>), [spaces](<https://devfeed.tech/tags/spaces.md>), [storage](<https://devfeed.tech/tags/storage.md>)

### AI overview

DigitalOcean announces generally available Network File Storage, usage-based backups, and Spaces cold storage. The release targets shared storage for AI and cloud workloads, infrequently accessed data, and stronger data protection policies.

### Source excerpt

As data footprints grow, businesses need cost-efficient storage for infrequently accessed data, high-performance file systems for collaborative work, and more aggressive data protection policies to meet strict recovery objectives. We're introducing several significant enhancements to our storage portfolio to help you manage the challenges of data management, protection, and scaling. TL;DR Network file storage solution for high-performance AI workloads and cloud applications, is now generally available. You can access it in the DigitalOcean console. To learn more visit the product documentation page. Usage-based backups are now generally available to meet aggressive rpos. Check out our documentation to learn more and head over to the DigitalOcean console to enable backups for your Droplets or GPUs. Spaces cold storage for infrequently accessed data is now generally available. Visit our documentation to learn more and and head over to the DigitalOcean console to set up Spaces cold storage. Network file storage (NFS) for high-performance AI workloads Data-intensive applications, particularly in AI and machine learning, require shared, high-performance file storage that is easy to provision and manage. Our Network file storage service is now generally available in our ATL1 , NYC2 and AMS3 data centers. We have also introduced a new Standard Tier designed for general-purpose cloud applications like App Platform workloads, web applications, CMS platforms, general compute tasks, and legacy applications requiring shared file systems. This tier provides predictable, cost-effective shared storage with ReadWriteMany semantics for cloud applications. Customers with high-throughput or data-intensive needs, such as AI/ML, GPU training, high-throughput analytics, or those requiring parallel multi-node access, should instead utilize the NFS High Performance Tier, which supports superior throughput scaling for multi-node environments and demanding data pipelines. NFS supports share

## Prevent Accidental Deletes with Database and Group Delete Protection

DevFeed: [Prevent Accidental Deletes with Database and Group Delete Protection](<https://devfeed.tech/articles/prevent-accidental-deletes-with-database-and-group-delete-protection-6022.md>)

Original publisher: [Read original article](<https://turso.tech/blog/prevent-accidental-deletes-with-database-and-group-delete-protection>)

Author: Jamie Barton

Published: 2025-04-02T00:00:00Z

Content type: release

Language: en

Sources: [Turso Blog](<https://devfeed.tech/sources/turso-blog.md>)

Topics: [Turso](<https://devfeed.tech/topics/turso.md>), [Platform API](<https://devfeed.tech/topics/platform-api.md>), [API](<https://devfeed.tech/topics/api.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [Database](<https://devfeed.tech/topics/database.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [cli](<https://devfeed.tech/tags/cli.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [database](<https://devfeed.tech/tags/database.md>), [databases](<https://devfeed.tech/tags/databases.md>), [new-feature](<https://devfeed.tech/tags/new-feature.md>), [platform-api](<https://devfeed.tech/tags/platform-api.md>), [production](<https://devfeed.tech/tags/production.md>), [protection](<https://devfeed.tech/tags/protection.md>), [turso](<https://devfeed.tech/tags/turso.md>)

### AI overview

Turso Cloud introduces Delete Protection for databases and groups. The feature is available through the Turso Dashboard, CLI, and Platform API, and blocks deletion attempts until protection is explicitly disabled.

### Source excerpt

Turso Cloud now supports Delete Protection on databases and groups from the dashboard, CLI, and Platform API, blocking accidental deletions of production data.

## ERR\_PROXY\_CONNECTION\_FAILED errors with HTTP proxies

DevFeed: [ERR\_PROXY\_CONNECTION\_FAILED errors with HTTP proxies](<https://devfeed.tech/articles/err-proxy-connection-failed-errors-with-http-proxies-19092.md>)

Original publisher: [Read original article](<https://httptoolkit.com/blog/proxy_connection_failed/>)

Author: HTTP Toolkit; Tim Perry

Published: 2024-12-11T17:00:00Z

Content type: tutorial

Language: en

Sources: [HTTP Toolkit](<https://devfeed.tech/sources/http-toolkit.md>)

Topics: [HTTP](<https://devfeed.tech/topics/http.md>), [browser](<https://devfeed.tech/topics/browser.md>), [Security](<https://devfeed.tech/topics/security.md>), [debug](<https://devfeed.tech/topics/debug.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [cURL](<https://devfeed.tech/topics/curl.md>), [Postman](<https://devfeed.tech/topics/postman.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [browser](<https://devfeed.tech/tags/browser.md>), [chrome](<https://devfeed.tech/tags/chrome.md>), [curl](<https://devfeed.tech/tags/curl.md>), [debugging](<https://devfeed.tech/tags/debugging.md>), [errors](<https://devfeed.tech/tags/errors.md>), [http](<https://devfeed.tech/tags/http.md>), [issue](<https://devfeed.tech/tags/issue.md>), [port](<https://devfeed.tech/tags/port.md>), [postman](<https://devfeed.tech/tags/postman.md>), [protection](<https://devfeed.tech/tags/protection.md>), [proxy](<https://devfeed.tech/tags/proxy.md>), [server](<https://devfeed.tech/tags/server.md>), [tcp](<https://devfeed.tech/tags/tcp.md>), [tls](<https://devfeed.tech/tags/tls.md>), [tools](<https://devfeed.tech/tags/tools.md>)

### AI overview

This tutorial explains how to diagnose ERR_PROXY_CONNECTION_FAILED when using a local debugging proxy with Chrome or similar applications. It covers incorrect connection details, unreachable proxies, and antivirus software that intercepts local proxy traffic and rejects the proxy's TLS certificate.

### Source excerpt

If you're using a local debugging proxy tool like HTTP Toolkit, you might run into the dreaded ERR_PROXY_CONNECTION_FAILED error in Chrome and other similar apps. This can be a very frustrating and unhelpful error! There's only a few possible causes though, and it's usually easy to fix. The Simple Case The simplest explanation is exactly what it says: the browser can't connect to your proxy. In the simple case this may be caused by a basic connection issue: you have the address, port or some authentication details wrong, or the details are correct but the proxy is just not reachable on your connection, and so the browser can't talk to it. The easiest way to confirm this is to try connecting to the details directly using an HTTP client tool like curl, Postman, or the HTTP Toolkit Send page, to manually check if the server is listening on the port you expect. If you see a TCP error then the details are wrong, but if you see any kind of HTTP error or similar then you know that the server does exist and it's reachable with the given details. If the failure comes from a browser intercepted by a tool like HTTP Toolkit though, where intercepted clients are preconfigured & launched for you, this is not what's happening - the server is definitely reachable (it's running locally) and the config is correct (it's been done automatically). Instead, this might be caused by something more complicated... Beyond the Simple Case If you know the settings are correct, and you know the proxy is reachable, what could cause this ERR_PROXY_CONNECTION_FAILED error? Once you're ruled out basic connection issues, the most likely cause is antivirus software on your computer that is intercepting your connections. This is becoming a common feature of some antivirus & security software, most notably ESET. It's not directly related to viruses at all, but is a separate security feature that's often enabled automatically for additional protection. What happens in this case is that your browser is tryi

## Meet Chainguard at Black Hat USA 2024 in Vegas!

DevFeed: [Meet Chainguard at Black Hat USA 2024 in Vegas!](<https://devfeed.tech/articles/meet-chainguard-at-black-hat-usa-2024-in-vegas-13150.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/meet-chainguard-at-black-hat-usa-2024-in-vegas>)

Published: 2024-07-19T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [black-hat](<https://devfeed.tech/tags/black-hat.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [charity](<https://devfeed.tech/tags/charity.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cves](<https://devfeed.tech/tags/cves.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [developers](<https://devfeed.tech/tags/developers.md>), [events](<https://devfeed.tech/tags/events.md>), [insights](<https://devfeed.tech/tags/insights.md>), [music](<https://devfeed.tech/tags/music.md>), [networking](<https://devfeed.tech/tags/networking.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [organization](<https://devfeed.tech/tags/organization.md>), [protection](<https://devfeed.tech/tags/protection.md>), [security](<https://devfeed.tech/tags/security.md>), [sponsor](<https://devfeed.tech/tags/sponsor.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [us](<https://devfeed.tech/tags/us.md>)

### AI overview

Chainguard announces its participation in Black Hat USA 2024 in Las Vegas, including a booth, a cybersecurity breakfast co-hosted with GitGuardian, social events, and a container security capture-the-flag challenge at DEF CON 32.

### Source excerpt

Join Chainguard at Black Hat USA 2024 for cybersecurity insights, networking, and fun in Las Vegas this August. Don't miss our exciting events and activities!

## Bunny.net CDN caching flaw exposed authenticated users' private HTTP responses

DevFeed: [Bunny.net CDN caching flaw exposed authenticated users' private HTTP responses](<https://devfeed.tech/articles/leaking-secrets-through-caching-with-bunny-cdn-19044.md>)

Original publisher: [Read original article](<https://httptoolkit.com/blog/bunny-cdn-caching-vulnerability/>)

Author: HTTP Toolkit; Tim Perry

Published: 2023-06-20T11:30:00Z

Content type: article

Language: en

Sources: [HTTP Toolkit](<https://devfeed.tech/sources/http-toolkit.md>)

Topics: [Caching](<https://devfeed.tech/topics/caching.md>), [HTTP](<https://devfeed.tech/topics/http.md>), [Cross-origin resource sharing (CORS)](<https://devfeed.tech/topics/cors.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [caching](<https://devfeed.tech/tags/caching.md>), [cdn](<https://devfeed.tech/tags/cdn.md>), [http](<https://devfeed.tech/tags/http.md>), [performance](<https://devfeed.tech/tags/performance.md>), [protection](<https://devfeed.tech/tags/protection.md>), [responses](<https://devfeed.tech/tags/responses.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article examines a Bunny.net CDN caching flaw that caused private HTTP responses intended for one authenticated user to be served to other users. It explains how CDN caching can diverge from HTTP standards and expose private data or authentication credentials, and notes that the issue has been fixed.

### Source excerpt

Caching is hard. Unfortunately though, caching is quite important. Hosted caching & CDNs offer incredible powers that can provide amazing performance boosts, cost savings & downtime protection, essential for most modern sites with any serious volume of users. Unfortunately, while there are strict standards for how caching is supposed to work with HTTP on the web, many cache providers do not quite follow these, instead giving their customers free reign over all kinds of invalid caching behaviour, and providing their own default configurations that often don't closely follow these standards to start with either. There are many good reasons for this, but the main one is that CDNs are now doing dual service: providing performance improvements, and actively protecting upstream sites from DoS attacks and traffic spikes (similar problems - the key difference between a DoS attack and hitting #1 on Hacker News etc is intent, not impact). This conflicts with many of the standards, which prioritize correctness and predictability over this use case and, for example, expect clients to be able to unilaterally request that the cache be ignored. Bunny.net provides one of these CDNs, and like most they aggressively cache content beyond the limits of the standards, both to help protect upstream servers and to support advanced user use cases. This has upsides, but in some edge cases can result in awkward bugs and break developer expectations. In some more dramatic cases though, it can expose private user data, break applications & even leak auth credentials, and that's where this story gets serious. A few months ago, I ran into exactly that issue while testing out deployment options with Bunny.net, where I discovered that private HTTP responses intended for one authenticated user could be served to other users instead. Spoiler: this is now fixed! That said, it's worth exploring where this went wrong, the many ways this can work right, and how CDNs solve issues like this in practice. C

[Next page](<https://devfeed.tech/tags/protection.md?cursor=WyIyMDIzLTA2LTIwVDExOjMwOjAwKzAwOjAwIiwgImI0NGQzOTQyLTI0NWMtNGE1ZS04OWQ2LTAwYzQzMTQ5ODZjZSJd>)