<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>#security · Faiz Ahmed Farooqui</title><description>Posts tagged security.</description><link>https://faizahmed.in/</link><item><title>Loading Secrets at Runtime Without Leaking Them: config(), the Keystore, and run</title><link>https://faizahmed.in/secret-keystore-runtime-config-loader-nodejs/</link><guid isPermaLink="true">https://faizahmed.in/secret-keystore-runtime-config-loader-nodejs/</guid><pubDate>Fri, 12 Jun 2026 13:17:21 GMT</pubDate><category>aws</category><category>nodejs</category><category>security</category><category>devops</category><category>backend</category></item><item><title>Encrypt Your .env with One Command: The secret-keystore CLI</title><link>https://faizahmed.in/secret-keystore-cli-encrypt-env-aws-kms/</link><guid isPermaLink="true">https://faizahmed.in/secret-keystore-cli-encrypt-env-aws-kms/</guid><pubDate>Fri, 12 Jun 2026 12:59:34 GMT</pubDate><category>aws</category><category>security</category><category>nodejs</category><category>backend</category><category>devops</category></item><item><title>Your .env Is a Loaded Gun: A Saner Threat Model for Node.js Secrets</title><link>https://faizahmed.in/nodejs-secrets-threat-model-aws-kms/</link><guid isPermaLink="true">https://faizahmed.in/nodejs-secrets-threat-model-aws-kms/</guid><pubDate>Fri, 12 Jun 2026 11:31:09 GMT</pubDate><category>security</category><category>aws</category><category>nodejs</category><category>backend</category><category>devops</category></item><item><title>Encrypted .env for Node.js with AWS KMS: The Complete Guide</title><link>https://faizahmed.in/encrypted-env-aws-kms-nodejs-complete-guide/</link><guid isPermaLink="true">https://faizahmed.in/encrypted-env-aws-kms-nodejs-complete-guide/</guid><pubDate>Fri, 12 Jun 2026 11:24:08 GMT</pubDate><category>security</category><category>aws</category><category>nodejs</category><category>devops</category><category>backend</category></item><item><title>Stop Putting Secrets in process.env: Encrypt Env Vars with AWS KMS</title><link>https://faizahmed.in/secret-keystore/</link><guid isPermaLink="true">https://faizahmed.in/secret-keystore/</guid><pubDate>Sat, 21 Feb 2026 19:30:57 GMT</pubDate><category>security</category><category>aws</category><category>attestation</category><category>nodejs</category><category>nextjs</category><category>nestjs</category><category>devops</category><category>cloud</category><category>backend</category></item><item><title>How to Prevent Replay Attacks with JWTs: JWS vs JWE and Fingerprint Validation in Node.js</title><link>https://faizahmed.in/how-to-prevent-replay-attacks-with-jwts-jws-vs-jwe-and-fingerprint-validation-in-nodejs/</link><guid isPermaLink="true">https://faizahmed.in/how-to-prevent-replay-attacks-with-jwts-jws-vs-jwe-and-fingerprint-validation-in-nodejs/</guid><pubDate>Fri, 06 Jun 2025 13:27:47 GMT</pubDate><category>nodejs</category><category>jwt</category><category>security</category><category>authentication</category><category>backend</category><category>backendengineering</category><category>websecurity</category><category>replay-attack</category><category>devtips</category><category>express</category></item><item><title>JWT, JWE, and JWKS Explained: A Developer’s Guide to Token-Based Security</title><link>https://faizahmed.in/jwt-jwe-and-jwks-explained-a-developers-guide-to-token-based-security/</link><guid isPermaLink="true">https://faizahmed.in/jwt-jwe-and-jwks-explained-a-developers-guide-to-token-based-security/</guid><pubDate>Thu, 27 Mar 2025 12:30:46 GMT</pubDate><category>jwt</category><category>jwe</category><category>jwks</category><category>token</category><category>security</category></item></channel></rss>