Security
The protocols, identity systems and secure architectures behind cloud, Agent and AI applications — cryptography and TLS, authentication and IAM, and application, network and AI/agent security, taught defensively throughout.
Every system you have built so far assumed a cooperative world. The user sends the request you designed the form for; the service on the other end of the connection is the one named in the URL; the document your retrieval layer pulls back contains information, not instructions. Security is the discipline of dropping that assumption and asking what happens when someone benefits from breaking it — and then building so that the answer is "not much". It is not a layer you add at the end. It is a set of decisions about trust that are already baked into the code you wrote this morning.
This discipline builds those decisions from the bottom up, and it builds them as things you make rather than things you are told. You will write a toy hash, a toy cipher and a toy Diffie-Hellman exchange, then watch a TLS handshake turn out to be exactly that exchange with a certificate attached. You will store a password the way a competent service does, then carry the resulting session across a browser, a token, a Kerberos ticket and an OAuth redirect. You will decide what an authenticated caller is allowed to do, harden an API that is currently wrong, shrink what a service can reach on the network, and finally put a boundary around an LLM agent that wants to call your tools. Attack material is here throughout, because you cannot defend a system whose failure you have never seen — but every attack in this discipline arrives with the defence that stops it, and the exercises grade the defence.
Cryptography & Secure Transport
Authentication & Identity
P54 · Authentication & Kerberos
passwords/MFA, sessions vs tokens, Kerberos tickets
4 live modules · 3 tracks
P55 · OAuth 2.0 / OIDC & Federated Identity
authorization-code + PKCE, OIDC, JWT, SAML
4 live modules · 3 tracks
P56 · IAM & Authorization
RBAC/ABAC, policy, least privilege, cloud IAM
4 live modules · 3 tracks