# security engineering

Published articles for security engineering.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## How Two Small Bugs Led to a Critical Vulnerability and a Cryptography Audit of Go's SSH Library

DevFeed: [How Two Small Bugs Led to a Critical Vulnerability and a Cryptography Audit of Go's SSH Library](<https://devfeed.tech/articles/how-two-small-bugs-led-to-a-critical-vulnerability-and-a-cryptography-audit-of-go-s-ssh-library-29769.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/ncc-cryptography-audit-go-ssh/>)

Author: info@goteleport.com (Rob Picard)

Published: 2026-08-10T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [cryptographic audit](<https://devfeed.tech/topics/cryptographic-audit.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [audit](<https://devfeed.tech/tags/audit.md>), [bugs](<https://devfeed.tech/tags/bugs.md>), [cryptographic-audit](<https://devfeed.tech/tags/cryptographic-audit.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [go](<https://devfeed.tech/tags/go.md>), [security](<https://devfeed.tech/tags/security.md>), [security-engineering](<https://devfeed.tech/tags/security-engineering.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Teleport describes a critical vulnerability caused by two interacting bugs in its SSH certificate validation logic and reports that NCC Group conducted a cryptographic audit of Go's SSH package. The audit resulted in nine CVEs and identified subtle issues requiring expert review.

### Source excerpt

Learn about NCC Group's cryptographic audit of Go's SSH package.

## Visibility at scale: How Figma detects sensitive data exposure

DevFeed: [Visibility at scale: How Figma detects sensitive data exposure](<https://devfeed.tech/articles/visibility-at-scale-how-figma-detects-sensitive-data-exposure-10192.md>)

Original publisher: [Read original article](<https://www.figma.com/blog/visibility-at-scale-how-figma-detects-sensitive-data-exposure/>)

Author: Dave Martin

Published: 2025-10-23T00:00:00Z

Content type: article

Language: en

Sources: [Figma Blog](<https://devfeed.tech/sources/figma-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [distributed-systems](<https://devfeed.tech/topics/distributed-systems.md>), [Figma](<https://devfeed.tech/topics/figma.md>)

Tags: [authorization](<https://devfeed.tech/tags/authorization.md>), [distributed-systems](<https://devfeed.tech/tags/distributed-systems.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [scale](<https://devfeed.tech/tags/scale.md>), [security](<https://devfeed.tech/tags/security.md>), [security-engineering](<https://devfeed.tech/tags/security-engineering.md>), [validation](<https://devfeed.tech/tags/validation.md>)

### AI overview

Figma describes Response Sampling, a lightweight real-time control that monitors outbound responses, validates access, and provides early warning of potential sensitive data exposure. The system is designed to detect authorization flaws and unexpected data leaks across distributed application services, both before production and after deployment.

### Source excerpt

Solving security challenges at scale requires creativity as much as rigor. To reduce the risk of sensitive data exposure, we built Response Sampling: a lightweight, real-time control that watches outbound responses, validates access, and provides an early warning system across our products.

## This Shit is Hard: SLSA L3 and Beyond

DevFeed: [This Shit is Hard: SLSA L3 and Beyond](<https://devfeed.tech/articles/this-shit-is-hard-slsa-l3-and-beyond-13288.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/this-shit-is-hard-slsa-l3-and-beyond>)

Published: 2025-07-31T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [containers](<https://devfeed.tech/tags/containers.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [security](<https://devfeed.tech/tags/security.md>), [security-engineering](<https://devfeed.tech/tags/security-engineering.md>), [signing](<https://devfeed.tech/tags/signing.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>)

### AI overview

Chainguard explains how it uses SLSA to strengthen software supply chain security, support customer compliance, and build trust in hardened container images. The article focuses on SLSA Build Level 3, especially isolated build execution and tamper-resistant provenance attestations with signing secrets separated from build and test processes.

### Source excerpt

Chainguard goes through all the necessary steps to make things SLSA 3 compliant. Get the details on how we do it.

## Day in the life of a food giant CISO

DevFeed: [Day in the life of a food giant CISO](<https://devfeed.tech/articles/day-in-the-life-of-a-food-giant-ciso-7882.md>)

Original publisher: [Read original article](<https://snyk.io/blog/day-in-the-life-food-giant-ciso/>)

Author: Vandana Verma Sehgal

Published: 2024-04-18T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [engineering-culture](<https://devfeed.tech/topics/engineering-culture.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [ciso](<https://devfeed.tech/tags/ciso.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [governance](<https://devfeed.tech/tags/governance.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [management](<https://devfeed.tech/tags/management.md>), [organizational](<https://devfeed.tech/tags/organizational.md>), [product-security](<https://devfeed.tech/tags/product-security.md>), [security](<https://devfeed.tech/tags/security.md>), [security-engineering](<https://devfeed.tech/tags/security-engineering.md>), [strategy](<https://devfeed.tech/tags/strategy.md>)

### AI overview

This developer-focused interview profiles Sherif Mansour, Just Eat's Director of Information Security, and discusses his career, Just Eat's three-line information security model, and his responsibilities across platform security, cloud and infrastructure, product security, application security, security engineering, culture, and awareness. It also describes organizational leadership principles and a themed weekly schedule for managing priorities.

### Source excerpt

Snyk's Vandana Verma Sehgal sat down with Sherif Mansour, the Director of InfoSec at JustEat, for a "Day in the life of a CISO" session to learn more about his day-to-day experience as a security leader.

## Enforcing device trust on code changes

DevFeed: [Enforcing device trust on code changes](<https://devfeed.tech/articles/enforcing-device-trust-on-code-changes-9810.md>)

Original publisher: [Read original article](<https://www.figma.com/blog/how-we-enforce-device-trust-on-code-changes/>)

Author: Griffin Choe

Published: 2023-12-08T00:00:00Z

Content type: article

Language: en

Sources: [Figma Blog](<https://devfeed.tech/sources/figma-blog.md>)

Topics: [Device Trust](<https://devfeed.tech/topics/device-trust.md>), [Figma](<https://devfeed.tech/topics/figma.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Security](<https://devfeed.tech/topics/security.md>), [pull-requests](<https://devfeed.tech/topics/pull-requests.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [WebAuthn](<https://devfeed.tech/topics/webauthn.md>), [OAuth](<https://devfeed.tech/topics/oauth.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>)

Tags: [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [device-trust](<https://devfeed.tech/tags/device-trust.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [figma](<https://devfeed.tech/tags/figma.md>), [git](<https://devfeed.tech/tags/git.md>), [github](<https://devfeed.tech/tags/github.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [okta](<https://devfeed.tech/tags/okta.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [security](<https://devfeed.tech/tags/security.md>), [security-engineering](<https://devfeed.tech/tags/security-engineering.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [sso](<https://devfeed.tech/tags/sso.md>), [verification](<https://devfeed.tech/tags/verification.md>)

### AI overview

Figma's security engineering team describes enforcing device trust for code changes merged into GitHub release branches. The approach combines commit signature verification with Okta Device Trust certificates to ensure changes originate from trusted, company-managed devices, while addressing risks from leaked credentials, tokens, and SSH keys.

### Source excerpt

Here's how the Figma security engineering team leveraged commit signatures and Okta Device Trust certificates to protect GitHub release branches.

## Security Principles in 2023

DevFeed: [Security Principles in 2023](<https://devfeed.tech/articles/security-principles-in-2023-36970.md>)

Original publisher: [Read original article](<https://shostack.org/blog/security-principles-in-2023/>)

Author: Adam

Published: 2023-10-27T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [design](<https://devfeed.tech/tags/design.md>), [developer](<https://devfeed.tech/tags/developer.md>), [security](<https://devfeed.tech/tags/security.md>), [security-engineering](<https://devfeed.tech/tags/security-engineering.md>)

### AI overview

The author reflects on how their view of security design principles has changed. Although many principles remain valid, they are harder to learn, apply, teach, and assess consistently than threat modeling techniques because they require abstraction, careful analysis, and comparison of possible designs.

### Source excerpt

Principles are lovely, but do they lead us to actionable results?

## Server-side sandboxing: An introduction

DevFeed: [Server-side sandboxing: An introduction](<https://devfeed.tech/articles/server-side-sandboxing-an-introduction-10037.md>)

Original publisher: [Read original article](<https://www.figma.com/blog/server-side-sandboxing-an-introduction/>)

Author: Hongyi Hu; Max Serrano

Published: 2023-10-24T00:00:00Z

Content type: article

Language: en

Sources: [Figma Blog](<https://devfeed.tech/sources/figma-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Image processing](<https://devfeed.tech/topics/image-processing.md>), [C++](<https://devfeed.tech/topics/c-plus-plus.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [architecture](<https://devfeed.tech/tags/architecture.md>), [article](<https://devfeed.tech/tags/article.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [defense-in-depth](<https://devfeed.tech/tags/defense-in-depth.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [image-processing](<https://devfeed.tech/tags/image-processing.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [security](<https://devfeed.tech/tags/security.md>), [security-engineering](<https://devfeed.tech/tags/security-engineering.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This introduction to server-side sandboxing explains why image processing, parsing, compression, and thumbnailing workloads can create security risks, especially when they depend on memory-unsafe software such as C++ libraries. It presents application-level sandboxing, or workload isolation, as a defense against vulnerabilities and outlines the challenge of choosing among available isolation techniques and balancing their trade-offs.

### Source excerpt

In this three-part series, our security engineering team shares practical tips for deploying and operating application sandboxing techniques. First up: evaluating the many sandboxing options, and how to think about the trade-offs between them.

## Server-side sandboxing: Virtual machines

DevFeed: [Server-side sandboxing: Virtual machines](<https://devfeed.tech/articles/server-side-sandboxing-virtual-machines-10040.md>)

Original publisher: [Read original article](<https://www.figma.com/blog/server-side-sandboxing-virtual-machines/>)

Author: Hongyi Hu; Max Serrano

Published: 2023-10-24T00:00:00Z

Content type: article

Language: en

Sources: [Figma Blog](<https://devfeed.tech/sources/figma-blog.md>)

Topics: [Figma](<https://devfeed.tech/topics/figma.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Operating system](<https://devfeed.tech/topics/operating-system.md>), [systems](<https://devfeed.tech/topics/systems.md>)

Tags: [containers](<https://devfeed.tech/tags/containers.md>), [cpu](<https://devfeed.tech/tags/cpu.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [figma](<https://devfeed.tech/tags/figma.md>), [os](<https://devfeed.tech/tags/os.md>), [security](<https://devfeed.tech/tags/security.md>), [security-engineering](<https://devfeed.tech/tags/security-engineering.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>)

### AI overview

This article explains how Figma uses server-side sandboxing with virtual machines to isolate workloads and reduce security risks. It examines the VM security model, including hypervisors, VM escape risks, permissions, and trade-offs compared with containers and seccomp.

### Source excerpt

With so many sandboxing options, it's daunting to choose the right one. Here, we dive into the virtual machine (VM) security model for sandboxing, including the engineering trade-offs to consider and how we use them at Figma to achieve security isolation.

## My Career Pivot: From IT recruiter to information security

DevFeed: [My Career Pivot: From IT recruiter to information security](<https://devfeed.tech/articles/my-career-pivot-from-it-recruiter-to-information-security-32387.md>)

Original publisher: [Read original article](<https://medium.com/@SkyscannerEng/my-career-pivot-from-it-recruiter-to-information-security-cf955ca39d24?source=rss-401f3b3c958f------2>)

Author: Skyscanner Engineering

Published: 2022-06-24T08:08:19Z

Content type: article

Language: en

Sources: [Stories by Skyscanner Engineering on Medium](<https://devfeed.tech/sources/stories-by-skyscanner-engineering-on-medium.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [career](<https://devfeed.tech/tags/career.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [female-engineers](<https://devfeed.tech/tags/female-engineers.md>), [information-security](<https://devfeed.tech/tags/information-security.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [security](<https://devfeed.tech/tags/security.md>), [security-engineering](<https://devfeed.tech/tags/security-engineering.md>), [women-in-tech](<https://devfeed.tech/tags/women-in-tech.md>)

### AI overview

This profile follows Maria Sepulveda's career transition from customer service and IT recruitment into information security. As a Senior Security Engineer at Skyscanner, she discusses her role, career development, and responsibility for leading the recertification of the company's PCI DSS compliance.

### Source excerpt

Senior Security Engineer Maria Sepulveda As we celebrate International Women in Engineering Day this week, we're profiling female-identifying engineers across our business. Maria Sepulveda is a Senior Security Engineer at Skyscanner. An expert within information security, Maria led the recertification of Skyscanner's PCI DSS (Payment Card Industry data Security Standard) compliance. Maria took an unconventional path to information security, starting her career in customer service and IT recruitment. Here, she discusses her journey, imposter syndrome and what her role looks like today. Maria, as a Senior Security Engineer, what does your role involve? Well, I only recently joined Skyscanner so a typical day for me today might look different to a typical day in a couple of months time! Having said that, I have already been given responsibility to lead the recertification of our PCI-DSS compliance. It's great that I can be trusted so early on in my Skyscanner journey. My day typically starts with following up on tasks that are due in the coming week. During the day I meet with people and various teams to understand what they do. I'll also attend internal events, often to better understand the Skyscanner culture and the way things work here -- as well as to make connections. Focus Time in the afternoon allows me to re-read my notes and absorb information I obtained during the day. The day might end with a recap of the day with my team, allowing me to ask questions I haven't already asked or just generally talk about how the day went. What was your career journey to this point? I took an unconventional path into information security. Originally from Australia, I worked in customer service roles and IT recruitment. I arrived in London and found a job working at an in-house recruitment team for an online betting company. I knew that I wanted to move into a more tech-focussed role but still interfacing with the business. My colleague who was recruiting for the security team

## Threat Modeling Thursday: 2018

DevFeed: [Threat Modeling Thursday: 2018](<https://devfeed.tech/articles/threat-modeling-thursday-2018-37065.md>)

Original publisher: [Read original article](<https://shostack.org/blog/tmt-2018/>)

Author: Adam

Published: 2018-07-12T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [blackhat](<https://devfeed.tech/tags/blackhat.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [framework](<https://devfeed.tech/tags/framework.md>), [platforms](<https://devfeed.tech/tags/platforms.md>), [practices](<https://devfeed.tech/tags/practices.md>), [security](<https://devfeed.tech/tags/security.md>), [security-engineering](<https://devfeed.tech/tags/security-engineering.md>), [series](<https://devfeed.tech/tags/series.md>), [social-media](<https://devfeed.tech/tags/social-media.md>), [talk](<https://devfeed.tech/tags/talk.md>), [techniques](<https://devfeed.tech/tags/techniques.md>)

### AI overview

The author asks readers what they want covered in the Threat Modeling Thursday series and in a Black Hat talk on threat modeling in 2018. The talk will address evolving attacks, system properties, attack techniques, social media threats, and keeping security engineering and threat modeling practices current.

### Source excerpt

Help me help you.

## Security Engineering: Computers versus Bridges

DevFeed: [Security Engineering: Computers versus Bridges](<https://devfeed.tech/articles/security-engineering-computers-versus-bridges-36969.md>)

Original publisher: [Read original article](<https://shostack.org/blog/security-engineering-computers-versus-bridges/>)

Author: Adam

Published: 2018-04-11T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [discussion](<https://devfeed.tech/tags/discussion.md>), [security](<https://devfeed.tech/tags/security.md>), [security-engineering](<https://devfeed.tech/tags/security-engineering.md>), [security-research](<https://devfeed.tech/tags/security-research.md>)

### AI overview

This commentary compares security engineering with bridge engineering, arguing that public criticism, questioning, and investigation of failures are essential to improving designs and advancing the field.

### Source excerpt

[no description provided]

## Reasonable Software Security Engineering Podcast

DevFeed: [Reasonable Software Security Engineering Podcast](<https://devfeed.tech/articles/reasonable-software-security-engineering-podcast-36949.md>)

Original publisher: [Read original article](<https://shostack.org/blog/reasonable-software-security-engineering-podcast/>)

Author: Adam

Published: 2018-04-02T00:00:00Z

Content type: release

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [engineering](<https://devfeed.tech/tags/engineering.md>), [podcast](<https://devfeed.tech/tags/podcast.md>), [security](<https://devfeed.tech/tags/security.md>), [security-engineering](<https://devfeed.tech/tags/security-engineering.md>), [software](<https://devfeed.tech/tags/software.md>)

### AI overview

ISACA released a podcast discussing the "Reasonable Software Security Engineering" perspectives article. The document says the podcast could be downloaded from ISACA, although the listed MP3 link no longer worked.

### Source excerpt

[no description provided]

## Humble Bundle

DevFeed: [Humble Bundle](<https://devfeed.tech/articles/humble-bundle-36834.md>)

Original publisher: [Read original article](<https://shostack.org/blog/humble-bundle-20170719/>)

Author: Adam

Published: 2017-07-19T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>)

Tags: [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [security](<https://devfeed.tech/tags/security.md>), [security-engineering](<https://devfeed.tech/tags/security-engineering.md>)

### AI overview

A Humble Bundle offers cybersecurity books, including works on threat modeling, security engineering, and cryptography. Proceeds support the Electronic Frontier Foundation and WaterAid America.

### Source excerpt

[no description provided]

## The View From here

DevFeed: [The View From here](<https://devfeed.tech/articles/the-view-from-here-1862.md>)

Original publisher: [Read original article](<https://signal.org/blog/the-view-from-here/>)

Published: 2015-01-18T00:00:00Z

Content type: opinion

Language: en

Sources: [Signal Blog](<https://devfeed.tech/sources/signal-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Messaging](<https://devfeed.tech/topics/messaging.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>), [Ratchet](<https://devfeed.tech/topics/ratchet.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [SSL](<https://devfeed.tech/topics/ssl.md>)

Tags: [app-development](<https://devfeed.tech/tags/app-development.md>), [auth](<https://devfeed.tech/tags/auth.md>), [blog](<https://devfeed.tech/tags/blog.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [development](<https://devfeed.tech/tags/development.md>), [security](<https://devfeed.tech/tags/security.md>), [security-engineering](<https://devfeed.tech/tags/security-engineering.md>)

### AI overview

The author describes helping develop TextSecure with Open Whisper Systems by applying the TripleDH idea, prekeys, and an improved OTR ratchet to asynchronous text messaging and email. The resulting core protocol was later refined for multiparty and multidevice use, with additional security features such as stronger authentication and metadata hiding. The article argues that text messaging is an important environment for rapidly deploying secure communication innovations and praises the team's combination of security engineering and user-friendly app development.

### Source excerpt

Winter Break Of Code, Day 6 I've been working with Open Whisper Systems on TextSecure for about a year and a half. I feel like I've earned better treatment than being forced to blog at knifepoint, but here we are, so I'll tell my story. Read more...