What are the security implications of storing a CA password for local development only in a repository?

During local development of our website we need some features that are restricted to secure contexts, meaning we need a self signed certificate for ‘localhost’ for some things to work.
To make things as easy as possible for new developers … Continue reading What are the security implications of storing a CA password for local development only in a repository?

A company is still leaking highly sensitive data well over 90 days after I have reported the issue, where to go from here?

Back in February, well over 90 days ago, I reported a vulnerability to a service that is leaking highly sensitive data, such as passport id, full name, date of birth and medical data. After that I have sent a few more reminders about the l… Continue reading A company is still leaking highly sensitive data well over 90 days after I have reported the issue, where to go from here?