RMRenukashree Muraliinquietbytes.hashnode.dev·Sep 22 · 7 min readVerifying Why zeroize Matters: Dead-Store Elimination and Memory Remanence in RustPart 2 of the "Building a Memory-Safe File Encryptor in Rust" series. Part 1 covered the encryptor's design decisions - Argon2id, AES-GCM, the file format, and a first pass at zeroizing secrets in mem00
RMRenukashree Muraliinquietbytes.hashnode.dev·Sep 20 · 6 min readWhat Building a File Encryptor in Rust Taught Me About Authenticated EncryptionWhat this does A command-line tool that encrypts a single file with a password. Under the hood: Argon2id turns your password into a 256-bit key, AES-256-GCM encrypts the file with that key, and everyt00
RMRenukashree Muraliinquietbytes.hashnode.dev·Sep 15 · 13 min readBuilding a Concurrent JWT Validator in Go - and What It Taught Me About Go's Concurrency ModelA companion build to JWT Attack Lab — eight parts spent breaking a Flask API's JWT verification six different ways. This one flips the direction: building a validator meant to reject every one of thos00
RMRenukashree Muraliinquietbytes.hashnode.dev·Jul 18 · 5 min readJWT Attack Lab — Part 8: Algorithm Confusion, and a Bug the Attack Uncovered By AccidentPart 8, the final stage in a series building a Flask API with JWT authentication, then deliberately exploiting six real vulnerabilities in it. Part 7 closed a gap in expiry enforcement. This last stag00
RMRenukashree Muraliinquietbytes.hashnode.dev·Jul 18 · 4 min readJWT Attack Lab — Part 7: When exp Isn't Actually Enforced EverywherePart 7 of a series building a Flask API with JWT authentication, then deliberately exploiting six real vulnerabilities in it. Part 6 spoofed a JWKS URL to bypass RS256 verification entirely. This part00