<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security on Yeah, I Made a Website</title><link>https://site.aaronhsyong.com/categories/security/</link><description>Recent content in Security on Yeah, I Made a Website</description><generator>Hugo -- gohugo.io</generator><language>en</language><managingEditor>aaronhsyong2@gmail.com (Aaron Yong)</managingEditor><webMaster>aaronhsyong2@gmail.com (Aaron Yong)</webMaster><copyright>© 2026 Aaron Yong</copyright><lastBuildDate>Fri, 17 Apr 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://site.aaronhsyong.com/categories/security/index.xml" rel="self" type="application/rss+xml"/><item><title>Why Postman Works But Your Browser Doesn't</title><link>https://site.aaronhsyong.com/posts/why-postman-works-but-your-browser-doesnt/</link><pubDate>Fri, 17 Apr 2026 00:00:00 +0000</pubDate><author>aaronhsyong2@gmail.com (Aaron Yong)</author><guid>https://site.aaronhsyong.com/posts/why-postman-works-but-your-browser-doesnt/</guid><description>CORS isn&amp;rsquo;t your server blocking requests — it&amp;rsquo;s your browser protecting users. Here&amp;rsquo;s what&amp;rsquo;s actually happening.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://site.aaronhsyong.com/posts/why-postman-works-but-your-browser-doesnt/featured.jpg"/></item><item><title>Top 10 Greatest Hits of 2025</title><link>https://site.aaronhsyong.com/posts/top-10-greatest-hits-of-2025/</link><pubDate>Sun, 11 Jan 2026 00:00:00 +0000</pubDate><author>aaronhsyong2@gmail.com (Aaron Yong)</author><guid>https://site.aaronhsyong.com/posts/top-10-greatest-hits-of-2025/</guid><description>The OWASP Top 10 for 2025, explained with code examples and practical fixes</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://site.aaronhsyong.com/posts/top-10-greatest-hits-of-2025/featured.jpg"/></item><item><title>Who Goes There</title><link>https://site.aaronhsyong.com/posts/who-goes-there/</link><pubDate>Sun, 14 Dec 2025 00:00:00 +0000</pubDate><author>aaronhsyong2@gmail.com (Aaron Yong)</author><guid>https://site.aaronhsyong.com/posts/who-goes-there/</guid><description>Sessions, JWTs, OAuth, and SSO — what they are and when to use each</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://site.aaronhsyong.com/posts/who-goes-there/featured.jpg"/></item></channel></rss>