Skip to main content

532 posts tagged with "Security"

Cybersecurity, smart contract audits, and best practices

View all tags

Read the Platform security guide

Daytona's Repo Is Frozen — Will the Fork Survive? What Three Open-Source Relicenses Teach About Betting on Nightona
·Dora Noda·10 min

Daytona's Repo Is Frozen — Will the Fork Survive? What Three Open-Source Relicenses Teach About Betting on Nightona

Daytona froze its public repo at v0.190.0 in June 2026 and moved development private. Community fork Nightona carries the AGPL tree forward, but the HashiCorp, Redis, and Elasticsearch precedents say forks survive only with funded maintainers, neutral governance, and API compat — Nightona scores half a point out of three.

AI agents
self-hosting
infrastructure
security
Humans Missed 1 in 3 Threats Approving AI Agent Commands: What 409,000 Decisions Say About Human-in-the-Loop Deploy Guardrails
·Dora Noda·9 min

Humans Missed 1 in 3 Threats Approving AI Agent Commands: What 409,000 Decisions Say About Human-in-the-Loop Deploy Guardrails

Across 409,000 approve-or-deny decisions, human reviewers missed a third of malicious AI agent commands — and the credential-stealing ones slipped through three times as often as the obviously destructive ones. The numbers argue for sandboxes, scoped credentials, and policy engines ahead of the approve button.

AI agents
security
developer tools
engineering
TLS for a Bare IP: What Let's Encrypt's Free IP-Address Certificates Change for Self-Hosted Deploys
·Dora Noda·10 min

TLS for a Bare IP: What Let's Encrypt's Free IP-Address Certificates Change for Self-Hosted Deploys

Let's Encrypt's free IP-address certificates went generally available in January 2026: six-day, ACME-automated TLS for a bare IPv4 or IPv6 address. Where they fit in a self-hosted PaaS — node bootstrap before DNS, fallback vhosts, IP-addressed infrastructure — the exact recipe for getting one, and the limits that keep tenant traffic on real domains.

self-hosting
security
infrastructure
engineering
Lint the Dockerfile Before You Build It: What hadolint, dockle, and Docker Scout Catch That a Green Build Never Will
·Dora Noda·8 min

Lint the Dockerfile Before You Build It: What hadolint, dockle, and Docker Scout Catch That a Green Build Never Will

A green docker build waves through unpinned base tags, root users, baked-in secrets, and known CVEs. How hadolint at PR time, dockle at build time, and Docker Scout at deploy time each catch a failure class the others cannot see — with gate configs you can copy.

security
self-hosting
PaaS
developer tools
15 Clean Releases, Then One Exfiltration Line: Lessons from the First Malicious MCP Server in the Wild
·Dora Noda·11 min

15 Clean Releases, Then One Exfiltration Line: Lessons from the First Malicious MCP Server in the Wild

In September 2025 the npm package postmark-mcp shipped fifteen clean releases, then added a one-line BCC backdoor in v1.0.16 — the first malicious MCP server caught in the wild. What the incident proves about version-history trust, plus a concrete checklist for teams installing third-party MCP servers and platforms distributing their own.

Model Context Protocol
AI agents
security
cybersecurity
MCP Won the Protocol War — the Lock-In Just Moved Up a Layer: A Self-Hoster's Field Test
·Dora Noda·10 min

MCP Won the Protocol War — the Lock-In Just Moved Up a Layer: A Self-Hoster's Field Test

MCP became the universal agent interface — and the lock-in moved into security policies, drift detection, and Skills libraries. A hands-on field test shows which moats self-hosting defeats and which one follows you home.

Model Context Protocol
AI agents
self-hosting
security
+1
10,000 MCP Servers Later: What Pinterest's Central Registry Teaches About Running Your Own Deploy Tools
·Dora Noda·12 min

10,000 MCP Servers Later: What Pinterest's Central Registry Teaches About Running Your Own Deploy Tools

Pinterest runs 66,000+ MCP tool calls a month through domain-specific servers behind a central registry. How the registry-plus-fleet pattern solves discovery and access control — and what it means for the deploy tools agents drive.

Model Context Protocol
AI agents
engineering
infrastructure
+1
The Worst Three Months in npm History: What Your Build Layer Needs When the Registry Can't Be Trusted
·Dora Noda·11 min

The Worst Three Months in npm History: What Your Build Layer Needs When the Registry Can't Be Trusted

Between March and June 2026, Axios, node-ipc, Red Hat's npm namespace, and the Mastra framework were all compromised — each defeating a different defense. A concrete accounting of all four attacks and the five build-layer controls that survive them: frozen lockfiles, disabled install scripts, DNS-aware egress sandboxing, honest provenance, and per-build SBOMs.

security
cybersecurity
developer tools
self-hosting
+1
Nvidia Runs OpenBao in Production: The Vault Fork's Enterprise Moment, and How to Wire It Into Kubernetes
·Dora Noda·9 min

Nvidia Runs OpenBao in Production: The Vault Fork's Enterprise Moment, and How to Wire It Into Kubernetes

NVIDIA runs its serverless GPU platform's secrets on OpenBao, eight vendors now sell commercial support, and v2.6 added per-namespace sealing — why the Vault fork is now safe to bet a self-hosted platform on, and how to wire it into Kubernetes with the External Secrets Operator.

self-hosting
PaaS
security
Kubernetes
Showing 172–180 of 532 posts