<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Secrets and Credentials on I am Lino</title><link>https://iamlino.net/en/tags/secrets-and-credentials/</link><description>Recent content in Secrets and Credentials on I am Lino</description><generator>Hugo</generator><language>en</language><lastBuildDate>Fri, 29 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://iamlino.net/en/tags/secrets-and-credentials/index.xml" rel="self" type="application/rss+xml"/><item><title>Security by design: stop patching holes you dug yourself</title><link>https://iamlino.net/en/blog/security-by-design-stop-patching-holes-you-dug-yourself/</link><pubDate>Fri, 29 May 2026 00:00:00 +0000</pubDate><guid>https://iamlino.net/en/blog/security-by-design-stop-patching-holes-you-dug-yourself/</guid><description>&lt;p&gt;Most of the &amp;ldquo;security problems&amp;rdquo; you end up patching at 3 a.m. aren&amp;rsquo;t accidents.&lt;/p&gt;
&lt;p&gt;They&amp;rsquo;re decisions made months earlier under pressure, over a cup of coffee, with the unshakeable conviction that &amp;ldquo;we&amp;rsquo;ll fix it later.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.checkpoint.com/cyber-hub/cloud-security/what-is-developer-security/secure-by-design-the-complete-guide/" target="_blank" rel="noopener"&gt;Security by design&lt;/a&gt;
 is exactly about that: building security into the development cycle from the start, instead of relying on the &lt;em&gt;holy trinity of scanner + pentest + blind faith&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;Let&amp;rsquo;s get concrete: threat modeling, core principles, mistakes we&amp;rsquo;ve been repeating since 2010, and how to stop shooting yourself in the foot with your own code.&lt;/p&gt;</description></item></channel></rss>