
§03 Security & Privacy
Threat Modeling in an Afternoon: A Focussed Exercise for Small Teams
Threat modeling is an essential exercise that security teams use to identify security flaws before an application is released. Draw this on a…
Identity, trust and the plumbing of the web·on the home of the Yadis discovery protocol since 2005
Catalogue
Material written by the editorial team, and material placed on this domain by outside contributors. Both are listed; they are not mixed.

§03 Security & Privacy
Threat modeling is an essential exercise that security teams use to identify security flaws before an application is released. Draw this on a…

§01 Identity & Access
When account holders lose the things that authenticate them, the path to recovery is a security control, not a support convenience. Brute-forcing it…

§05 Gaming Tech
The line between valid gameplay and cheating is becoming increasingly hard to draw. Servers are now expected to police player actions, yet a strict…

§03 Security & Privacy
It was late on a Friday. Odds rolled in fast. Bets queued up. Then, bets froze. Payouts stalled. Support lines lit. The root cause was not epic. A…

§01 Identity & Access
Online gaming is not only about games, fun, and bright graphics. It is also about trust. When people play with real money, they share personal data…

§05 Gaming Tech
You tap Spin. The reels flash. Seven long seconds pass. Did the house nudge the odds, or did math and code pick the line? That doubt is normal. You…

§04 Dev & Infrastructure
Web caching slows down user experience under three conditions: – If previously caught content is cached, if the cache size exceeds the capacity of…

§04 Dev & Infrastructure
Ninety milliseconds can flip a match. A winger breaks free. The live price should swing. But your stream trails. Your odds API stalls at the worst…

§02 Web Standards
The Vary response header is the pivot point in HTTP content negotiation. Negotiated content can only be cached if the server explicitly directs…

§06 AI & Data
Here is a small story. A team shipped “smart offers” to help users save time. Clicks went up for two weeks. Then complaints grew. People felt…

§06 AI & Data
Every product team will use a third-party generated model at some point, whether you sell software, offer a content recommendation engine or focus on…

§03 Security & Privacy
Friday night. A big promo drops. Sign-ups jump. Deposits look clean. Support is quiet. By Monday, the bonus pool is gone, VIPs are upset, and a few…

§02 Web Standards
Web standards are the building blocks of the modern Internet, yet the path from a clever specification draft to widespread adoption is a complex…

§02 Web Standards
The process for modern web applications to discover each other and the services they offer on behalf of a user has evolved from specialized XRDS…

§05 Gaming Tech
We were scared to soften the streak. A growth PM said churn would spike if users could miss a day and keep their run. We did it anyway. We added a…

§02 Web Standards
Before diving into the text of an RFC, always check its status, updates, publication stream, and errata. The RFC Editor says these metadata inputs…

§01 Identity & Access
An OpenID Connect ID token is not a user-identity data blob. It's a compact cryptographic artifact that only speaks to authentication when the…

§04 Dev & Infrastructure
We launched in five new markets in one week. The copy was fine. The code passed tests. Yet checkout tanked. Prices showed in USD for users in Paris…

§05 Gaming Tech
In multiplayer games, matchmaking is an optimization problem. Studios can trade longer queue times for fairer skill-based games, yet latency is…

§01 Identity & Access
Designing OAuth scopes is a critical aspect of any modern application that relies on third-party integrations and user permissions. Poorly designed…

§01 Identity & Access
Device-bound passkeys are lost forever if the hardware storing them fails or is stolen. With a synced passkey, the private key is stored online. Once…

§05 Gaming Tech
We shipped a “provably fair” game. A week later, a player sent us a log. Two bets had the same nonce. The test suite was green. Our code was wrong…

§04 Dev & Infrastructure
You lead a mid-size sportsbook. Football season starts in ten weeks. Your team can ship a clean PWA in six weeks and test markets fast. Or you can…

§03 Security & Privacy
For most small projects, the biggest security concern is not having advanced defenses, but actively stopping the primary leaking points. From the…

§03 Security & Privacy
Web applications tend to use a defining function or routine called a session to keep a user logged in until:

§04 Dev & Infrastructure
What it really takes to keep glass‑to‑glass under a second when a million people tap “Vote now.”

§02 Web Standards
The .well-known directory is a fundamental but often misunderstood feature of web server configuration. It provides a standardized path for hosting…

§04 Dev & Infrastructure
It starts on a bus. Left hand on a pole. Right thumb on the screen. Signal drops to 3G. Odds move. A pop-up slides in. The bet slip jumps. The user…

§06 AI & Data
We once took out a “hurry up” timer on a deposit page. It looked urgent, but the time did not matter. It pushed people to act fast. We also made the…

§06 AI & Data
What can you still measure after a user says no to tracking? A surprising amount, but only if you rebuild the report around aggregates, operational…

§04 Dev & Infrastructure
A web request from a user action to a visible response time is a series of costs paid across the request path. And the useful question is not “what…

§01 Identity & Access
The current version of the Yadis specification is 1.0, released March 2006.
Articles placed on Yadis by outside contributors, in 10 languages. They are kept for the record at their original addresses and are not edited by us.
The working wiki of the Yadis protocol lives in its own section: the Yadis wiki, 2005–2006 →