sethserver.com

Security

Security

Seth's Opinionated Security Best Practices

Updated: September 17, 2026

AI makes it easy to ship code fast-and to paste secrets into the wrong place even faster. This post is a blunt tour of the boring security habits that keep working: password managers and MFA, real secret handling (not "temporary" hardcodes), least-privilege access, and a simple rule for LLMs: treat prompts like support tickets and sanitize before you paste. read on »

Security

Securing Dev‑Facing AI: Code Assistants, MCP Devtools, and CI Bots

Updated: September 17, 2026

Dev-facing AI tools don't need to be "evil" to be dangerous. The real risk is the plumbing: plugins, MCP servers, and CI bots wired to powerful tokens that nobody audits. This post lays out the boring rules that actually prevent leaks-read-only by default, tight scopes, dev/prod separation, human review for writes, and short policies engineers will follow. One pasted config or one sloppy token is all it takes. read on »

Newsletter

One email, once a week.

Notes on databases, systems, and the occasional strong opinion about Python. No spam, unsubscribe anytime.