5 ms·
Do you have any resources you'd recommend instead?
by sehr 11y ago
Do you have any resources you'd recommend instead?
- sarciszewski 11y agohttps://github.com/paragonie/awesome-appsec https://github.com/paragonie/awesome-appsec https://cryptocoding.net https://cryptocoding.net https://www.crypto101.io https://www.crypto101.io
- tptacek 11y agoYes: The Web App Hacker's Handbook is a better resource for building a checklist of app security concerns for your application, and remains the best resource on generic appsec.
- noir_lord 11y agoHad not seen this, thanks :). EDIT: This is absolutely the book I was looking for the other day and didn't know existed, most of this stuff I'm familiar with but this looks like an excellent refresher.
- briandh 11y agoThe Tangled Web: A Guide to Securing Modern Web Applications is a good complement.
- noir_lord 11y agoFantastic!, thank you.
- saturdayplace 11y agoDefinitely +1 on both of these. They're fantastic.
- nickpsecurity 11y agoThanks for the reference. That one is new to me, too.
- sarciszewski 11y agoYou're kidding, right?
- nickpsecurity 11y agoI don't really work on application side of web: handed that part off to others while I did client-server plumbing and endpoints. Web is simply too much risk for high-assurance security. Plus, a brain injury in an accident cost me most of my memory. I operate on fragments now while trying to reconnect stuff. I probably knew about the guide and forgot. Or I didn't but used something else. Usually remember a lot of INFOSEC stuff but this one is total blank. So, such resources are good for getting stuff back in my head. Here's last list I put up when my memory was working better than ATM that detailed what kinds approaches I recommended or used (often in combination): https://www.schneier.com/blog/archives/2014/04/the_security_of_8.html#c5626550 https://www.schneier.com/blog/archives/2014/04/the_security_... I know I used a SPECTRE clone in the past for at least one legacy app. Did high-assurance HTTP to prevent defacing. Did an application server on microkernel similar to Barracuda's nice architecture to keep TCB minimal. Outside SPECTRE, it's what we all did in high-assurance though: certain things everyone seems to build. The rest and all details are a blank. Sorry... Barracuda lightweight approach https://realtimelogic.com/products/lua-server-pages/ https://realtimelogic.com/products/lua-server-pages/
- sarciszewski 11y agoSorry to hear about your brain injury. If it's any consolation, I had no idea because your comments are consistently insightful and worth the time to stop and read.
- nickpsecurity 11y agoI appreciate the feedback and thank you. They said people are usually zombie-like in such a situation. I've seen it. It's quite the battle to maintain or deliver day-to-day functions much less top normal minds in insight. Nonetheless, I've been fighting for civil liberties and privacy a long time. Plus trying to do bulletproof systems. Even with gaps & lacking specialist skill, I'm closer now than ever mapping & semi-synthesizing systems from high-level specs all the way to transistors with reliability, security, & recovery via dozens of techniques. Dedicated endpoint mostly solved, client server too, Web is if you cheat (I did proxies), P2P still open-ended, and much more to do in decentralized. Plus my activity here and elsewhere of evangelizing strong methods & making sure old wisdom doesn't get lost. Got motivation & keep active so remaining synapses get reinforcement. So, a little brain injury and Memento-style moments ain't enough to totally knock me out of the game. Just gotta get it back piece by piece & be more mentally efficient than before. Wirth-style ultra-simplification & Dijkstra abstraction pays off there. Anyway, NSA gonna shit their pants when I go commercial again. Short-term rather than long-term goal hopefully. ;)