Profile    Mohammed Shiroz Status   Loading  
Logo
Share This

My web security
blog and Updates

It's my personal blog and my post about what was my interested in. Not regularly. If you have any questions any discussion, I'm happy you get in touch with me, and try to answer as many as possible!

Blog
Let's See
Back to blog
Filter by:
Tags
//Article

JWT Explained: What's Inside the Token and What Can Go Wrong

JWT Explained: What's Inside the Token and What Can Go Wrong

Blog Summary

Paste any JWT into a decoder and you can read it, no key needed. That surprises a lot of developers. Here's what's really inside a token, why base64 isn't encryption, and the mistakes that cause real breaches.

Read more
  • 67
  • 48
  • 10

Cookies vs Tokens: Where Should Your Web App Keep the Session?

Cookies vs Tokens: Where Should Your Web App Keep the Session?

Blog Summary

That login token in localStorage is readable by every script on your page. Here's the real trade-off between HttpOnly cookies and tokens, XSS vs CSRF, and how Laravel Sanctum handles SPAs and mobile apps.

Read more
  • 72
  • 78
  • 6

HTTPS in Plain English: Certificates, Keys and What the Padlock Really Means

HTTPS in Plain English: Certificates, Keys and What the Padlock Really Means

Blog Summary

The padlock doesn't mean a site is safe. Here's what HTTPS really does, in plain English: symmetric and asymmetric keys, the TLS handshake, what a certificate authority proves, and what HTTPS can't protect.

Read more
  • 18
  • 34
  • 21

01. About Shiroz

Mohammed Shiroz

Hi, I'm Mohammed Shiroz, a software engineer and AI enthusiast from Sri Lanka who turns ideas into intelligent, real-world solutions. With over 9 years of hands-on experience, I currently lead real estate ERP development at Kate Group, a...

03.My Projects

04. Categories

Ready To Start Your Project ?

Get in Touch
Close