SShortSingh.
Back to feed

Your Database Will Leak Someday: Field-Level Encryption and Blind Indexes for PII with Python and PostgreSQL

0
·6 views

Tuần này HN đang bàn rất nhiều về vụ rò rỉ dữ liệu ở Đan Mạch: thông tin cá nhân của 8,8 triệu người bị lộ. Đọc qua các vụ breach lớn vài năm gần đây, mình thấy kịch bản gần như lặp lại: lộ một bản backup, một bucket S3 cấu hình sai, một lỗi SQL injection, hoặc một tài khoản read-only của bên analytics bị lấy mất. Điểm chung là kẻ tấn công đọc được database ở dạng plaintext. Lúc đó TLS hay disk encryption cũng không giúp được gì. Bài này chia sẻ cách mình làm field-level encryption cho dữ liệu PII (email, số điện thoại, CCCD...) bằng Python và PostgreSQL.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

I Built Vericore: A Verification Layer for AI Coding Agents

AI coding agents can make large changes to a repository very quickly. But an important question remains: Did the agent actually change only what it was supposed to change? I built Vericore to explore this problem. Vericore is an open-source verification layer for AI-assisted development. The workflow is: Understand → Prepare → Agent Changes → Verify Before the agent changes code, Vericore builds repository context and creates a Change Contract.

0
ProgrammingDEV Community ·

DeepSeek R1 vs. OpenAI o3-mini: Which API is Best?

Choosing between DeepSeek R1 vs OpenAI o3-mini is a critical decision for developers integrating reasoning APIs into software applications in 2026. When it comes to reasoning APIs, these are the two strongest candidates most teams end up weighing. Both models excel at complex tasks, code generation, mathematical analysis, and structured logic. However, they operate on different pricing structures, reasoning token methods, latency patterns, and structured data validation limits. This guide compares the two in detail to help you choose the best API for your developer workflows.

0
ProgrammingDEV Community ·

Scrape Etsy search results sorted by price: 10 rows for $0.065

Disclosure: I publish and maintain the Actor used here (publicrecords/etsy-search-scraper on Apify Store). This is the publisher account. You have an Etsy search query and you want the results as rows you can sort and filter, not a screenshot of page one. Here's the shortest route I know, with a real run as proof. Each Etsy search result comes back as one row with listing_id, title, price, currency, shop_name, shop_url, rating_value, review_count, badges (bestseller, star_seller, etsys_pick, popular_now, free_shipping), position and page.