Snyk
Snyk
  • 189
  • 245 332
How to Secure a REST API
This video explores the best practices for securing REST APIs, essential tools for developers, and common security threats to watch out for.
Use Snyk for free to find and fix security issues in your applications today! snyk.co/ugLYn
✍️ Resources ✍️
- Snyk Blog Post: snyk.co/uhHum
⏲️ Chapters ⏲️
00:00 - Intro
00:12 - Authentication and Authorization
01:04 - How to set up HTTPS in a Project
01:20 - Input Validation and Sanitization
02:32 - Rate Limiting and Throttling
03:17 - Project Example Using CSP and CORS
03:53 - API Logging and Monitoring
04:09 - Using Secure Dependencies
04:42 - More Information
⚒️ About Snyk ⚒️
Snyk helps you find and fix vulnerabilities in your code, open-source dependencies, containers, infrastructure-as-code, software pipelines, IDEs, and more! Move fast, stay secure.
Learn more about Snyk: snyk.co/ugLYl
📱 Connect with Us 📱
🖥️ Website: snyk.co/ugLYl
🐦 X: snyksec
💼 LinkedIn: www.linkedin.com/company/snyk
💬 Discord: discord.gg/devsecops-community-918181751526948884
▶️ Subscribe: th-cam.com/users/SnykSec
🔥 We're hiring! Check our open roles: snyk.co/ugLYp
🔗 Hashtags 🔗
#DevSecOps #rest #api
มุมมอง: 621

วีดีโอ

Understanding CSRF and SSRF Attacks (Demo and Examples)
มุมมอง 68914 วันที่ผ่านมา
In this video, we examine two critical web security vulnerabilities: CSRF (Cross-Site Request Forgery) and SSRF (Server-Side Request Forgery). Learn about each attack, how it differs, and why it poses serious risks to web applications. Use Snyk for free to find and fix security issues in your applications today! snyk.co/ugLYn ✍️ Resources ✍️ - CSRF blog: snyk.co/csrf-blog - SSRF blog: snyk.co/s...
How Secure is this NEW AI Coding Tool? Bolt by Stackblitz
มุมมอง 1K21 วันที่ผ่านมา
How Secure is this NEW AI Coding Tool? Bolt by Stackblitz
Security Terms You Need to Know | XSS, CSRF, VPN, Malware, CVE
มุมมอง 473หลายเดือนก่อน
Security Terms You Need to Know | XSS, CSRF, VPN, Malware, CVE
Exploiting Vulnerabilities in Cursor AI Code
มุมมอง 392หลายเดือนก่อน
Exploiting Vulnerabilities in Cursor AI Code
Cursor AI: The VS Code Competitor
มุมมอง 1.2Kหลายเดือนก่อน
Cursor AI: The VS Code Competitor
Exploiting AI Generated Code
มุมมอง 1.3Kหลายเดือนก่อน
Exploiting AI Generated Code
How AI Almost Got Me FIRED: Part 4
มุมมอง 516หลายเดือนก่อน
How AI Almost Got Me FIRED: Part 4
Why ASPM is the Future of AppSec
มุมมอง 3772 หลายเดือนก่อน
Why ASPM is the Future of AppSec
How AI Impacts Reconnaissance and Bug Bounties
มุมมอง 4282 หลายเดือนก่อน
How AI Impacts Reconnaissance and Bug Bounties
How AI Almost Got Me FIRED: Part 3
มุมมอง 2602 หลายเดือนก่อน
How AI Almost Got Me FIRED: Part 3
How AI Almost Got Me FIRED: Part 2
มุมมอง 2392 หลายเดือนก่อน
How AI Almost Got Me FIRED: Part 2
How AI Almost Got Me FIRED: Part 1
มุมมอง 6283 หลายเดือนก่อน
How AI Almost Got Me FIRED: Part 1
More Ways GitHub Copilot Makes You Vulnerable
มุมมอง 9093 หลายเดือนก่อน
More Ways GitHub Copilot Makes You Vulnerable
GitHub Copilot Makes You Vulnerable
มุมมอง 1.5K3 หลายเดือนก่อน
GitHub Copilot Makes You Vulnerable
4 Hidden AI Coding Risks and How to Address Them
มุมมอง 7433 หลายเดือนก่อน
4 Hidden AI Coding Risks and How to Address Them
The Ultimate Guide to Choose the Best Open Source Packages
มุมมอง 3114 หลายเดือนก่อน
The Ultimate Guide to Choose the Best Open Source Packages
Uncovering the Polyfill.io Supply Chain Attack
มุมมอง 6794 หลายเดือนก่อน
Uncovering the Polyfill.io Supply Chain Attack
10 BEST Practices for Securely Developing with AI
มุมมอง 1884 หลายเดือนก่อน
10 BEST Practices for Securely Developing with AI
How to Create YOUR OWN (Secure) VS Code Color Theme!
มุมมอง 1.1K4 หลายเดือนก่อน
How to Create YOUR OWN (Secure) VS Code Color Theme!
9 Docker Pro Tips that will LEVEL UP your Skills
มุมมอง 3194 หลายเดือนก่อน
9 Docker Pro Tips that will LEVEL UP your Skills
Why You Should be AFRAID of PDF Files - PDF.js CVE-2024-4367
มุมมอง 3.8K5 หลายเดือนก่อน
Why You Should be AFRAID of PDF Files - PDF.js CVE-2024-4367
How to Securely Publish a VS Code Extension
มุมมอง 3595 หลายเดือนก่อน
How to Securely Publish a VS Code Extension
How to prevent SSRF Attacks in Node.js
มุมมอง 2.4K5 หลายเดือนก่อน
How to prevent SSRF Attacks in Node.js
How to Build a Secure NPM Package for ESM and CJS
มุมมอง 5785 หลายเดือนก่อน
How to Build a Secure NPM Package for ESM and CJS
Top 5 VS Code SECURITY Extensions
มุมมอง 1K6 หลายเดือนก่อน
Top 5 VS Code SECURITY Extensions
10 Node.js runtime features you SHOULD be using in 2024
มุมมอง 9556 หลายเดือนก่อน
10 Node.js runtime features you SHOULD be using in 2024
How to Use GitHub Actions Environment Variables and Secrets
มุมมอง 4.3K6 หลายเดือนก่อน
How to Use GitHub Actions Environment Variables and Secrets
Why you NEED an Open Source Vulnerability Scanner
มุมมอง 9286 หลายเดือนก่อน
Why you NEED an Open Source Vulnerability Scanner
How to Choose the Best and Secure Node.js Docker Image
มุมมอง 5757 หลายเดือนก่อน
How to Choose the Best and Secure Node.js Docker Image

ความคิดเห็น

  • @Wayk123
    @Wayk123 2 วันที่ผ่านมา

    Very very very shallow coverage. If you mention role based authentication, cover it and how should it be structured, what roles should do, how to connect them with user tokens, also signing request and best practices. Probably would be good to mention/cover jwt. what is CSP, CORS and other dangers and how are they executed / how to defend from them. These are only thing on top of my head someone should know and I came in here to see what I don't know, instead i got information I could easily ask chatgpt if I was just learning.

    • @clarkio
      @clarkio วันที่ผ่านมา

      Thanks for the feedback and you're absolutely right. The intention of this video is to be an introduction to the topic and lead to further potential videos based on feedback/questions that come up in response. I'm glad to hear you're already very knowledgeable on the topic 👍

    • @Wayk123
      @Wayk123 ชั่วโมงที่ผ่านมา

      @@clarkio Hi, thanks for the response. I didn't mean to be rude and I am not very well knowledgeable, but it would be nice to have more hints to advanced topics and where to learn more etc. I guess its a hard line to walk on between not being boring and being too shallow. Anyway this video made me watch some of your others vids which are a bit more in depth and they helped me a ton, thanks!

  • @JimmyS2
    @JimmyS2 4 วันที่ผ่านมา

    Short but covered all the points with examples 👍

    • @clarkio
      @clarkio วันที่ผ่านมา

      Are you interested in seeing something that goes more in-depth on the topic?

    • @JimmyS2
      @JimmyS2 วันที่ผ่านมา

      @clarkio of course, each of the methods you mentioned could have it's video were your start building an app with python or js add the code, run the app to see for example how to using Oauth2 works, next time add CORS until we have a full app with all features implemented and running.

  • @HhddGufif
    @HhddGufif 9 วันที่ผ่านมา

    AI is not relevant to this problem. Would have written the same issue either way

  • @petrlaskevic1948
    @petrlaskevic1948 11 วันที่ผ่านมา

    Could you please put the link of Cody's video you're referring to somewhere?

    • @clarkio
      @clarkio 10 วันที่ผ่านมา

      Yes it's been added in the description here now and is in the original main video this clip is from. Here is the direct link so you don't have to dig for it further: th-cam.com/video/QZWPdJUwxls/w-d-xo.html

    • @petrlaskevic1948
      @petrlaskevic1948 10 วันที่ผ่านมา

      @@clarkio Thanks!

  • @JonathanDavidLewis
    @JonathanDavidLewis 11 วันที่ผ่านมา

    The evident problem is that the hostname can come from the client, right?

    • @ZeruelB
      @ZeruelB 11 วันที่ผ่านมา

      no, the URL may ALWAYS come from the client, thats how the internet works (just put it into the address line, you're done). The issue is that the Serverside accepts it without checking if it was generated and its likely there is no appropriate Authorization used for a specific sideproject (or maybe even the same authorization codes over multiple projects), and most likely the projectId is just some numerically increasing code. you can figure out easily (project 1, project 2 etc). So you can steal the token you generate from project 1 and use it to access project 2.

    • @JonathanDavidLewis
      @JonathanDavidLewis 11 วันที่ผ่านมา

      ​@@ZeruelBWelp, clearly what I said was ambiguous. Thanks, that is what I meant. Thanks for expanding.

  • @felicitatumfortunae
    @felicitatumfortunae 11 วันที่ผ่านมา

    That is an easy fix and he should never be passing in inputs like that.

    • @jobjobbington6884
      @jobjobbington6884 11 วันที่ผ่านมา

      I think the point is that AI be passing inputs like that all the time… so imagine all the “devs” that are just using AI to fake skills, not knowing why what AI is doing is wrong.

    • @clarkio
      @clarkio 10 วันที่ผ่านมา

      @@jobjobbington6884 Yes that code was generated by AI. You can see more context about how it came to be from Web Dev Cody's video here: th-cam.com/video/QZWPdJUwxls/w-d-xo.html

  • @NotBJosh
    @NotBJosh 13 วันที่ผ่านมา

    In the real world, one solution would be to have an external script that links to a user controlled page on the site. `<script src="/uploads/user-controlled.js"></script>`

  • @Trosshack
    @Trosshack 14 วันที่ผ่านมา

    If you made more videos like this, I'd watch all of them. Cybersecurity is challenging to learn mostly because of lack of experience and lack of real world examples breaking down why the area is vulnerable and how it was exploited and reported. You should make video examples of disclosed vulnerabilities and break them down, xss, xxe, ssrf, csrf, sqli, lfi, etc.

    • @comosaycomosah
      @comosaycomosah 14 วันที่ผ่านมา

      2nd this

    • @Trosshack
      @Trosshack 14 วันที่ผ่านมา

      @comosaycomosah are you having this same issue? What resources have you found (youtube channels, blogs, reports, websites, etc.) that helped you out the most? My major issue is that I can read 500 page cybersecurity/bug hunting/hacking/pentesting books day after day but unless I can see an example or do it physically (follow along), it just seems to be forgotten. There is so much information needed for any part of cybersecurity. I could spend years on just xss or xxe or ssrf... it's just a lot. So how did you manage this? (If any of this applies to you that is)

    • @comosaycomosah
      @comosaycomosah 14 วันที่ผ่านมา

      @@Trosshack I'm like this too I have to to do the problems myself to actually learn, watching yt channels is almost pointless I try and do things like try hackme and hackthebox another thing you can do is set up your own servers amd pentest on them

    • @comosaycomosah
      @comosaycomosah 14 วันที่ผ่านมา

      @@Trosshack I think my subscriber list is public I cant really think of many good ones right off but I've noticed a trend even good channels like loi llang yang has been shit lately. Zsecurity is good yt channel

    • @Trosshack
      @Trosshack 14 วันที่ผ่านมา

      @@comosaycomosah I 100% agree.. I really like zsecurity and also that yang hasn't made content like he used to because he taught me a lot in his early stuff... I'll just keep practicing.. in cybersecurity it seems that practice practice practice is key to understand it fully. Books are good for refreshing your knowledge or reference the information... otherwise I seem to forget 80% of the details.

  • @Danilyn_Livao
    @Danilyn_Livao 15 วันที่ผ่านมา

    This is such valuable information for anyone looking to strengthen their cybersecurity knowledge. Big thanks for sharing!❤

    • @clarkio
      @clarkio 15 วันที่ผ่านมา

      Thank you so much for the comment! I'm glad to hear you found this valuable 👍

    • @Danilyn_Livao
      @Danilyn_Livao 15 วันที่ผ่านมา

      ​@@clarkio You're very welcome! I'm always excited to support your great content. Keep up the fantastic work! 👍

  • @jesperhustad
    @jesperhustad 15 วันที่ผ่านมา

    He explains how to set a secret at 15:55

  • @JuanJoseSierraOrtega
    @JuanJoseSierraOrtega 16 วันที่ผ่านมา

    If a transaction is validated by a code sent to the email or phone before being carried out, would this prevent the transaction from being carried out using only cookies?

    • @clarkio
      @clarkio 15 วันที่ผ่านมา

      Hmm without further context it's hard to definitively say yes or no but it sounds like yes that would help ensure the request is being done intentionally by someone and not maliciously by a bad actor. Essentially, when it comes to CSRF, having a way to validate the source of the request is key to mitigating the vulnerability. One common way to mitigate CSRF is using what's called the Synchronizer Token Pattern. That involves create a unique and random token that is included in the request and the server validates it before handling the request further.

  • @chuckcrizer
    @chuckcrizer 16 วันที่ผ่านมา

    Whenever I see a ridiculous "open mouth" thumbnail. I immediately hit "do not recommend channel."

    • @clarkio
      @clarkio 15 วันที่ผ่านมา

      Appreciate the feedback Chuck and I definitely understand disliking that sort of thing. What are the types of thumbnails that you prefer or find yourself clicking on more then? I'm continuously learning how things work on YT and lean on a partner of ours to help with the thumbnails so it'd be super helpful to hear your suggestions and discuss this further with them.

  • @AmyUcef
    @AmyUcef 17 วันที่ผ่านมา

    where to find that scripts.js ?

    • @clarkio
      @clarkio 15 วันที่ผ่านมา

      I didn't have it available before but you can now check it out under my repo here: github.com/clarkio/ai-code-security/blob/main/cursor/public/script.js

  • @mako13937a
    @mako13937a 17 วันที่ผ่านมา

    Thanks for uploading a video on this topic.

    • @clarkio
      @clarkio 15 วันที่ผ่านมา

      Thank you too for the question that inspired this video 👍

    • @clarkio
      @clarkio 15 วันที่ผ่านมา

      Also did this help answer your question? Do you have any further questions that come to mind? Hope it helped

    • @mako13937a
      @mako13937a 15 วันที่ผ่านมา

      @@clarkio Thanks. It did help. I will let you know if I have any further questions .

  • @comosaycomosah
    @comosaycomosah 21 วันที่ผ่านมา

    0:23 "..and whatever other extremities you want to use metaphorically" lol but no this was good i been trying to use actions way more

    • @clarkio
      @clarkio 15 วันที่ผ่านมา

      🤣🤣🤣

  • @GhostBoy-iy9tv
    @GhostBoy-iy9tv 22 วันที่ผ่านมา

    omg i love it!!!!!! it's amazing

    • @clarkio
      @clarkio 15 วันที่ผ่านมา

      Glad to hear that!

    • @GhostBoy-iy9tv
      @GhostBoy-iy9tv 15 วันที่ผ่านมา

      @@clarkio only thing i dislike is how fast tokens go away

  • @notleeland
    @notleeland 29 วันที่ผ่านมา

    Great video, thanks for this

  • @Trosshack
    @Trosshack หลายเดือนก่อน

    Can i ask you something? When searching for XSS injection areas, what JS code is most vulnerable? Is there anything specifically that stands out as vulnerable to you?

    • @clarkio
      @clarkio หลายเดือนก่อน

      Questions are definitely welcomed. The short answer is any time there is data that is not validated for the context in which it's intended to be used. Essentially, always question those areas and assume it *could* be vulnerable to XSS. I hope that helps and feel free to share any further questions you have.

    • @Trosshack
      @Trosshack หลายเดือนก่อน

      @@clarkio thank you. Fantastic advice. I also had a question about the software you use.. how accurate is it opposed to other automated tools?

    • @clarkio
      @clarkio 15 วันที่ผ่านมา

      @@Trosshack hmm that's a tough question for me to answer because I'm not as experienced with other tools and therefore don't want to comment without having given them a fair review first. What I can confidently say is Snyk continuously works hard on being accurate while also limiting noise for developers and security teams.

  • @mako13937a
    @mako13937a หลายเดือนก่อน

    What are the main differences between SSRF and CSRF?

    • @clarkio
      @clarkio หลายเดือนก่อน

      That's a great question and I can look into going deeper on the topic in a follow-up video if you'd like. However the quick/short answer is that CSRF happens due to trust from the client (for example your browser) to the server and SSRF happens due to trust from the server to another server/API. So for CSRF an attacker forges requests from the client to the server whereas for SSRF an attacker forges requests from the server to another dependent server or service/API. Hope that helps and let me know if you have further questions.

    • @mako13937a
      @mako13937a หลายเดือนก่อน

      I would really appreciate more detailed video of this topic from you. Thanks.

    • @clarkio
      @clarkio 27 วันที่ผ่านมา

      @@mako13937a hey heads up that a video on this is in progress. It'll likely be published on Monday October 28

    • @mako13937a
      @mako13937a 27 วันที่ผ่านมา

      @@clarkio Thanks.

  • @mako13937a
    @mako13937a หลายเดือนก่อน

    SSRF.

  • @MonsTVUB
    @MonsTVUB หลายเดือนก่อน

    No available destinations to fork this repository.

  • @patrickgronemeyer3375
    @patrickgronemeyer3375 หลายเดือนก่อน

    That is pretty cool

    • @clarkio
      @clarkio หลายเดือนก่อน

      Glad to hear that

  • @smcmayi162
    @smcmayi162 หลายเดือนก่อน

    "Look at me! Smarter than AI"

    • @clarkio
      @clarkio หลายเดือนก่อน

      🤣🤣🤣

  • @suckahugeduck
    @suckahugeduck หลายเดือนก่อน

    please get a fucking life

  • @robertpurpose
    @robertpurpose หลายเดือนก่อน

    I am having trouble replicating the results you have using your project. Would I need to reduce a version of something for this to work?

  • @jim-i-am
    @jim-i-am หลายเดือนก่อน

    If you use the 'apply' button instead of using copy/paste, then you can review the diff and accept/decline each row or set of rows. I find it much more convenient that way. I resort to copy/paste when cursor fails to apply (which occasionally happens....it's a bit "beta" sometimes).

    • @clarkio
      @clarkio หลายเดือนก่อน

      Thanks for pointing that out. Missed it before

  • @timekeeper1656
    @timekeeper1656 หลายเดือนก่อน

    VS CODE KILLER!!! jk its just a fork of vs code with ai plugins

    • @clarkio
      @clarkio หลายเดือนก่อน

      Ha yea just messing around saying that. Good to have competition

  • @nixoncode
    @nixoncode หลายเดือนก่อน

    Can't switch, won't switch

    • @clarkio
      @clarkio หลายเดือนก่อน

      Fair enough. Personally idk that I will fully switch but I’m enjoying trying it out

  • @aculz
    @aculz หลายเดือนก่อน

    its not VSCode competitor if its source by forking VSCode itself

    • @clarkio
      @clarkio หลายเดือนก่อน

      You have a point. I think if it’s got features that pull people away from VS Code though then it’s a competitor

  • @Nooobbbyyy
    @Nooobbbyyy หลายเดือนก่อน

    PEAR AI PEAR AI PEAR AI PEAR AI PEAR AI PEAR AI PEAR AI PEAR AI PEAR AI

  • @mohamedesalem
    @mohamedesalem หลายเดือนก่อน

    Man you can just click apply on the cursor's suggested code instead of copy and pasting them

    • @clarkio
      @clarkio หลายเดือนก่อน

      Ah shoot yea thanks for pointing that out

  • @soundofsilence...
    @soundofsilence... หลายเดือนก่อน

    Hi, can Snyk be integrated with Azure Boards?

  • @Rajroyal384
    @Rajroyal384 หลายเดือนก่อน

    thanks for the info about cloak i needed that

  • @Noam-Bahar
    @Noam-Bahar หลายเดือนก่อน

    Cursor is so good for me it's almost a drop in replacement for vscode. I don't rely 100% on the AI but it's always there

  • @Entification
    @Entification หลายเดือนก่อน

    Sadly, people aren't stupid enough to add user generated content as HTML instead of a span or smth😔

    • @klh_io
      @klh_io หลายเดือนก่อน

      But, looking at the linked video title, AI is :)

    • @potatoes1549
      @potatoes1549 หลายเดือนก่อน

      you underestimate how stupid people can be

    • @Entification
      @Entification หลายเดือนก่อน

      @@potatoes1549 ye but, stupid people wouldnt even learn how the <head> tag works so i doubt they'll make somethinglike this anytime soon

    • @clarkio
      @clarkio หลายเดือนก่อน

      @@klh_io what's the AI trained on?

  • @OOB-0
    @OOB-0 หลายเดือนก่อน

    I never found this vulnerability in real life 😂😂😂

    • @clarkio
      @clarkio หลายเดือนก่อน

      Guess it should be removed from the OWASP top 10 then...

    • @OOB-0
      @OOB-0 หลายเดือนก่อน

      @@clarkio I dunno I never found a bug outside of labs 😔

  • @shiv_7989
    @shiv_7989 หลายเดือนก่อน

    what are your vs code color settings

    • @DexFlex_YT-
      @DexFlex_YT- หลายเดือนก่อน

      same question, looks beautiful

    • @clarkio
      @clarkio หลายเดือนก่อน

      @@DexFlex_YT- It's called Deep Purple: marketplace.visualstudio.com/items?itemName=mel-brown.deep-purple

  • @Krewer69
    @Krewer69 หลายเดือนก่อน

    Still learning programming but i hope one day i'll be able to understand this better lol

    • @clarkio
      @clarkio หลายเดือนก่อน

      Hey that's cool to hear you're learning programming. I'm sure you'll get there and I'm here if you have questions so don't hesitate to share them. Or if you'd like you could join our Discord community to learn more about security and programming: discord.com/invite/NXuz63GmUt

  • @pietraderdetective8953
    @pietraderdetective8953 หลายเดือนก่อน

    Great video but I dislike the code editor color theme. Still cool content!

    • @clarkio
      @clarkio หลายเดือนก่อน

      Hey glad to hear you enjoyed the video and totally understand about the color theme. What's a color theme you really enjoy using? I can try it out in a future video.

    • @pietraderdetective8953
      @pietraderdetective8953 หลายเดือนก่อน

      @@clarkio nahh it's okay, I was bothered by some of the text color that's really hard to read in purple.. but if you really like purple, I saw an Evangelion theme but it was for neovim. I use the "Bamboo" color theme on my neovim. It's nature / forest based theme.

    • @fourone1254
      @fourone1254 หลายเดือนก่อน

      @@clarkioi actually really like it, but the theme is going to be a bit hard for some people to read

    • @clarkio
      @clarkio หลายเดือนก่อน

      @@pietraderdetective8953 I kinda like purple but mostly going for consistency with the branding in these videos. I'm assuming you mean this Bamboo color theme? github.com/ribru17/bamboo.nvim That looks kinda similar to the default theme in VS Code. I did find a more green theme called Dark Green Jungle I'm kinda liking: github.com/AaBbdev29/Dark-Green-Jungle

  • @JaniDinner
    @JaniDinner หลายเดือนก่อน

    actually enjoyed this video

    • @clarkio
      @clarkio หลายเดือนก่อน

      Thanks! Glad to hear that

  • @FreshForALifetime
    @FreshForALifetime หลายเดือนก่อน

    What theme are you using for pycharm? Cool vid!

    • @clarkio
      @clarkio หลายเดือนก่อน

      I'm using Visual Studio Code (VS Code) and the theme is called Deep Purple: marketplace.visualstudio.com/items?itemName=mel-brown.deep-purple

  • @Tim_We
    @Tim_We หลายเดือนก่อน

    Very Interesting video! Thanks, I’ve learned a lot.

    • @clarkio
      @clarkio หลายเดือนก่อน

      Awesome to hear and thanks for sharing

  • @kloudweb8427
    @kloudweb8427 หลายเดือนก่อน

    Do you have prompts for getting information

  • @afitnerd
    @afitnerd หลายเดือนก่อน

    How about "prompt kiddie"?

    • @clarkio
      @clarkio หลายเดือนก่อน

      Nice I like that one

  • @dupex69420
    @dupex69420 หลายเดือนก่อน

    love this series!!!

    • @clarkio
      @clarkio หลายเดือนก่อน

      Very glad to hear that!

  • @MeBadDev_
    @MeBadDev_ หลายเดือนก่อน

    Great content! I've looked into your channel and looks like all of your videos are well made. It's such a shame that they got so little views. Keep it up man!

    • @clarkio
      @clarkio หลายเดือนก่อน

      This comment made my day! Thanks so much for sharing. We'll definitely be keeping this up. Appreciate the encouragement👍

  • @sitdowndusty
    @sitdowndusty 2 หลายเดือนก่อน

    Work smarter not harder

    • @clarkio
      @clarkio 2 หลายเดือนก่อน

      100%

  • @deedee4531
    @deedee4531 2 หลายเดือนก่อน

    The promise of putting HR staff out of a job.jesus Christ I've had some issues with them shemumpets

  • @Frank00000
    @Frank00000 2 หลายเดือนก่อน

    How to fix security vulnerability: Download another 150kb+ package that increases the attack vector, while implementing very basic CSP.... Nah, I'm good.

    • @clarkio
      @clarkio 2 หลายเดือนก่อน

      I can understand not wanting to download yet another package. So yea if you want to roll out your own mitigation code to prevent CSRF attacks that works too. However, did you mean CSRF instead of CSP?

    • @Frank00000
      @Frank00000 2 หลายเดือนก่อน

      CSRF is only one area of content security. If you are worried about CSRF on a note taking app, then you might as well check for other browser side channel attacks. Can't wait to see this 'AI' figure out how to implement XSS vulnerabilities next.