What Is Digital Privacy?
Privacy (and Digital Privacy) is one of those terms that I’ve thrown around a lot in the last few years. However, I never took the time to define it.
Application Front-Ends Must Not Make Authorization Decisions
First, let’s get the usual introductions out of the way. For an in-depth discussion of what Authorization is, check out this post. For a complete introduction to Authorization concepts see my Authorization Series. This post continues my long-running Authorization Series. In this post, we’re going…
Application Security Models
I like to start system design (at the application level) with the security model that will be used to protect the system. Application security models have several attributes that need to be addressed at each layer of the application.
OpenID Connect Logout
The OpenID Connect (OIDC) family of specs supports logout (from a single application) and global (or single) logout (from all applications that the user has logged into through the OpenID Provider, OP), but these features are optional or in draft status (as of Q2, 2017). So, these spec features may…
API Security vs. Web Application Security: Part 2
This post was originally published as “API Security vs. Web Application Security: Part 2” on the Levvel Blog.
API Security vs. Web Application Security Part 1: A Brief History of Web Application Architecture
This post was originally published as “API Security vs. Web Application Security Part 1: A Brief History of Web Application Architecture” on the Levvel Blog.





