<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Daniel Khrapko</title><link>https://danielkhrapko.com/</link><description>Recent content on Daniel Khrapko</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Sun, 08 Feb 2026 20:16:16 -0500</lastBuildDate><atom:link href="https://danielkhrapko.com/index.xml" rel="self" type="application/rss+xml"/><item><title>Sideloading Apps in Apple's Ecosystem.</title><link>https://danielkhrapko.com/posts/sideloading-apps-in-apples-ecosystem/</link><pubDate>Sun, 08 Feb 2026 20:16:16 -0500</pubDate><guid>https://danielkhrapko.com/posts/sideloading-apps-in-apples-ecosystem/</guid><description>&lt;h2 id="apple-tries-to-make-signing-ipa-files-complicated-to-stop-people-from-sideloading-this-post-will-demonstrate-how-to-sideload-in-a-simple-step-by-step-format"&gt;Apple tries to make signing IPA files complicated to stop people from sideloading. This post will demonstrate how to sideload in a simple step-by-step format.&lt;/h2&gt;
&lt;p&gt;&lt;img src="cover.jpg" alt=""&gt;&lt;/p&gt;</description></item><item><title>My First Post: Hello World!</title><link>https://danielkhrapko.com/posts/my-first-blog-post/</link><pubDate>Sat, 31 Jan 2026 02:29:13 -0500</pubDate><guid>https://danielkhrapko.com/posts/my-first-blog-post/</guid><description>&lt;p&gt;Hello there! This is my first blog post on my site. To be honest, I&amp;rsquo;m not too sure what I should write about for my first post, but that&amp;rsquo;s the whole reason I wanted to start a blog: to get better at writing and documenting!&lt;/p&gt;
&lt;p&gt;&lt;img src="Marktwainquote.jpg" alt="Mark Twain Quote: I notice that you use plain, simple language, short words and brief sentences. That is the way to write English - it is the modern way and the best way. Stick to it; don&amp;rsquo;t let fluff and flowers and verbosity creep in."&gt;&lt;/p&gt;</description></item><item><title/><link>https://danielkhrapko.com/about/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://danielkhrapko.com/about/</guid><description>Homelab notes, tech tinkering, and projects I’m building to learn in public.</description></item><item><title>Certifications</title><link>https://danielkhrapko.com/certifications/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://danielkhrapko.com/certifications/</guid><description>Verified certifications (IT + Design).</description></item><item><title>Contact</title><link>https://danielkhrapko.com/contact/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://danielkhrapko.com/contact/</guid><description>Contact Page</description></item><item><title>Security</title><link>https://danielkhrapko.com/security/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://danielkhrapko.com/security/</guid><description>&lt;p&gt;If you believe you’ve found a security vulnerability affecting &lt;strong&gt;danielkhrapko.com&lt;/strong&gt;, please report it responsibly.&lt;/p&gt;
&lt;h2 id="how-to-report"&gt;How to report&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Email: &lt;strong&gt;&lt;a href="mailto:daniel@danielkhrapko.com"&gt;daniel@danielkhrapko.com&lt;/a&gt;&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;You may encrypt your message using my PGP key: &lt;strong&gt;&lt;a href="https://danielkhrapko.com/pgp-key.txt"&gt;https://danielkhrapko.com/pgp-key.txt&lt;/a&gt;&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Please include:
&lt;ul&gt;
&lt;li&gt;A clear description of the issue&lt;/li&gt;
&lt;li&gt;Steps to reproduce / proof of concept&lt;/li&gt;
&lt;li&gt;Any relevant URLs, screenshots, or logs&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="scope-in-scope"&gt;Scope (in-scope)&lt;/h2&gt;
&lt;p&gt;This policy covers vulnerabilities that could impact:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;danielkhrapko.com and subdomains I control&lt;/li&gt;
&lt;li&gt;My deployments, DNS, CDN/WAF configuration, and CI/CD pipelines&lt;/li&gt;
&lt;li&gt;Misconfigurations or integration issues involving third-party services &lt;strong&gt;as they apply to my setup&lt;/strong&gt;
(e.g., Cloudflare/DNS issues, GitHub Pages/Actions misconfig, webhook leakage, token exposure)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="out-of-scope"&gt;Out of scope&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Vulnerabilities in third-party providers that are not specific to my account/configuration or do not impact my domain&lt;/li&gt;
&lt;li&gt;Attacks that require targeting third-party infrastructure directly (e.g., attacking Cloudflare/GitHub/etc systems)&lt;/li&gt;
&lt;li&gt;Social engineering, physical attacks, or denial-of-service (DoS) testing&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="what-to-expect"&gt;What to expect&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;I’ll try to acknowledge your report within &lt;strong&gt;7 days&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;If it’s a valid issue, I’ll work on a fix as time allows&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="safe-harbor"&gt;Safe harbor&lt;/h2&gt;
&lt;p&gt;I won’t pursue legal action against you for good-faith security research that:&lt;/p&gt;</description></item></channel></rss>