Cybersecurity

Security threats, vulnerabilities, privacy, identity, compliance, threat intelligence, and security tools.

Create Post

Ask a question, share your experience, or learning

Log in to post
Prasad
Prasad

Aug 9, 2026

CybersecurityTechdiscussion

How are you handling secrets rotation without a paid vault?

Small team, Postgres + a Node API, everything on a single cloud provider. Right now our database password and third-party API keys live in environment variables and have not been rotated since we set them up. Managed vaults are the obvious answer but the pricing starts above what this project can justify. What I am considering: 1. The cloud provider's own secret manager — cheap, but ties us to them harder than I would like. 2. SOPS with age keys committed to the repo, decrypted at deploy. 3. Just rotating manually on a calendar reminder and accepting the risk. For those of you running small production systems: what actually works in practice, not in theory? I would rather hear "we do option 3 and it is fine" than a best-practice answer nobody follows.

Indian Tech Community
Indian Tech Community

Aug 4, 2026

CybersecuritySecurityLoggingCompliance

How long should a small startup keep security logs before it becomes pointless overhead?

We're logging auth events, API access, and admin actions but retention is unbounded right now and storage costs are creeping up. What's a sensible default retention window for a 15-person startup without dedicated security staff?

Indian Tech Community
Indian Tech Community

Jun 3, 2026

CybersecurityExchange ServerSysadminSecurity

Two Exchange 2019 servers coexisting in one domain (temporarily), no DAG — has anyone actually done this?

Can two Exchange servers coexist in the same domain and send/receive mail without a DAG configured, even temporarily during a migration? If yes, how? Looking for anyone who has tested this in a lab or done it in production.

Indian Tech Community
Indian Tech Community

May 26, 2026

CybersecurityIncident ResponseSecurityDevOps

Our first real security incident and what our runbook got wrong

A leaked API key led to unexpected usage charges before we caught it. Our incident runbook assumed we'd notice from monitoring alerts — we actually noticed from a billing anomaly two days later. Rewrote the runbook to include billing alerts as a first-class detection signal, not just an afterthought.

Indian Tech Community
Indian Tech Community

May 12, 2026

CybersecurityPasskeysAuthenticationSecurity

Rolling out passkeys for our internal tools — adoption was higher than expected

Assumed passkeys would be a hard sell internally given how new the UX still feels to a lot of non-technical staff. Rolled it out as an option alongside password+2FA rather than a mandate, and within a month over 60% of the team had switched voluntarily once they saw how much faster login was.

Indian Tech Community
Indian Tech Community

Apr 30, 2026

CybersecuritySecurityGroup PolicyIT Admin

What's the best way to block application/web browser downloads through Group Policy?

Trying to restrict browser-based downloads for a subset of machines on our domain without breaking legitimate business use. Group Policy Objects seem like the right tool but the exact settings for modern Chrome/Edge policies aren't well documented anywhere I've found.

Haven’t Added a Project Yet?

Show real work, get validated by industry experts, and get discovered.

Add Project
DeAI Hackathon 2024