Who are you, and are you allowed? SPIFFE, OPA and OpenFGA

Two questions sit underneath almost every distributed system, and most of the security work anyone does is really about answering them well. Who is calling me. And are they allowed to do what they are asking for. The first is authentication, the second is authorization, and the reason they are worth keeping apart is that the good answers to them look nothing alike.

Read more about Who are you, and are you allowed? SPIFFE, OPA and OpenFGA

Java vulnerabilities of the week: 4 to 10 September 2026

I keep this series going because most security news is useless to me as a developer. You get a CVE number, a CVSS score, a one line summary that says “an attacker may be able to execute arbitrary code”, and then nothing. You close the tab having learned that a thing is bad, which you already assumed, and not one word about why the thing happened or whether the same mistake is sitting in your own code.

Read more about Java vulnerabilities of the week: 4 to 10 September 2026