8 ms·
Security 101 for SaaS startups
- koolba 10y ago> Open an email group and name it seurity@mycompany.com and add a page on your website to report security incidents to this email You know a company takes security seriously when they have a typo in the word "security".
- itaifrenkel 10y agoHa ha. That's my typo. I'll fix it. Thanks
- koolba 10y agoFunny thing is I've seen this same typo (security spelled with a missing "c") first hand when reporting a security incident. What made it particularly bad was that it was a mailto:// link that was also spelled wrong so clicking it would send the email to the wrong address with no bounce reply (I'm guessing they had a catch all inbox rather than bouncing bad addresses). Might want to throw in there a suggestion to generate a security@example.com GPG key and instructions to use it if the submitter feels it warrants it. Also, the usual note of not losing the private half of the GPG key so you don't look like an ass when someone emails you an encrypted security incident that you cannot decrypt!
- itaifrenkel 10y agoThanks. I will
- itaifrenkel 10y agoPlease comment on https://github.com/forter/security-101-for-saas-startups/pull/36 https://github.com/forter/security-101-for-saas-startups/pul...
- sokoloff 10y agoIt's on github and you can submit a pull request in not much more time than it took to snark here. (I submitted one for some of the other grammar/spelling issues in the file. [sorry for using the online editor-that authored a poor diff])
- anotherturn 10y agoTypos happen all the time - I was going to suggest that it was a bit of an unfair comment. Then I opened up their website [0] and their strapline is "In fraud prevention Accuracy Matters"... None the less it is a useful document for those not versed in the basics of opsec and there's likely more value in insightful comments on the content... [0]:https://www.forter.com https://www.forter.com
- itaifrenkel 10y agoMmm. I'm sure our marketing would like to know why it feels strange. Would you care to state it even if it feels obvious to you?
- anotherturn 10y agoaccurate ˈakjʊrət/ adjective 1. (especially of information, measurements, or predictions) correct in all details; exact. "accurate information about the illness is essential" synonyms: correct, precise, exact, right, errorless, error-free, A typo is the antithesis of this. However, as I mentioned in my previous comment the content is of value and to find fault in the guise of typos is absurd.
- itaifrenkel 10y agoAhhh - now I get it. Well our marketing staff are mostly native English speakers. I'm not :)
- itaifrenkel 10y agoOriginal Author here. If you have questions or comments I would love hearing them.
- sneak 10y agoSome of it seems like overkill. Now that Google Cloud Shell is a thing, the correct answer for small teams of people who are not security engineers is usually just "chromebook".
- itaifrenkel 10y agoI'm not familiar with it. How many startups that you know actually use it? Was it released only recently? Also, do you know of startups that use chrome books or toshiba zero client? Also keep in mind that laptops are used by data scientists and management
- eranid 10y agoAs a founder of a company I would gladly buy chromebooks for all employees if it would solve my security problems. Sadly, I don't think today there's one solution that addresses everyone's needs, balancing dev requirements with security (and I don't think here will be one so soon): 1. We are a company that develops for iOS, so we have Apple computers and laptops... Nothing to be done about that. 2. We are on AWS, switching to Google Cloud is definitely not for everyone, definitely not just for this feature. 3. Even if we had not been developing for iOS, some developers really value working on a MacBook, and in a highly competitive recruiting market, that's a factor, and not an insignificant one.
- sneak 10y agoI run 100% in AWS too and still use the (free) Google Cloud Shell for doing dev and orchestration and running terraform and docker-machine and whatnot.
- itaifrenkel 10y ago
- simplehuman 10y agoGood advice but this is a little dubious "For other internal communication use Slack". Use slack because it is beautiful and free, not because of security
- itaifrenkel 10y agoOlder employees, and some managers, I found prefer email in many cases. I still request them to use slack
- thedevil 10y agoCall me an old fart but I much prefer email. Email gives me a reminder to keep me organized. And the two teams I worked on that use slack killed productivity by chatting all day and sending animated gifs. Plus, people expect email to be asynchronous. With slack, I get a mixture of immediate and asynchronous requests. So every message breaks my flow while I determine the priority level.
- itaifrenkel 10y agoI know. We use emails for some meeting summary. But you can't ignore the fact that many attacks start with phishing, and slack is free from that problem
- the_common_man 10y agoSlack is not free of the problem whatsoever: https://arstechnica.com/security/2016/04/hacking-slack-accounts-as-easy-as-searching-github/ https://arstechnica.com/security/2016/04/hacking-slack-accou... http://www.businessinsider.com/slacks-security-breach-may-be-worse-than-its-letting-on-2015-3 http://www.businessinsider.com/slacks-security-breach-may-be... http://www.networkworld.com/article/3123727/collaboration/the-next-target-for-phishing-and-fraud-chatops.html http://www.networkworld.com/article/3123727/collaboration/th...
- 10y ago
- mugsie 10y agoIf any developer says code review is too "corporate", I would suggest that they need to try a different profession. Code review is an industry practice these days, and that is a good thing. I would say even for POC / MVP development, CR is a must.
- itaifrenkel 10y agoI might need to find a better example.... Do you have an example of a process that is not needed in the beginning, and needed one year down the road that is less obvious?
- l_t 10y agoI think (good, thorough) documentation is probably a good example. Unnecessary early, when everything is in flux, but critical later, when there's too much for one person to know.
- mugsie 10y agoYeah, docs is a good one. Starting out a lot of people dump info in a wiki, but as they get bigger, proper docs (with actual doc writers) is a must.
- tarr11 10y agoDisabling email attachments from your email server is also a good idea.
- itaifrenkel 10y agoCan it be done with hosted mail solutions like most startups use? (Gmail/office365)
- tarr11 10y agoI know you can do it with Google Apps. Have not tried with Office365.
- itaifrenkel 10y agoAfter sleeping on it... I am not sure it would work with managers. They work with outside council on a day2day basis and they use attachments for that. I wonder why gmail hasn't made phishing attachments obsolete.
- Puts 10y ago> Remember that SSL encrypts network traffic, but does not supply authentication. SSL is also not a replacement for 2FA. False and false.
- jankedeen 10y agoAre you referring to something like SRP+DSS|RSA? Not widely supported but I've used it via gnutls as a custom auth proxy layer for various things. 1password uses something like this iirc. A really simple TFA pattern with SSL enabling is requiring a signed client cert with additional directory services auth (or even basic auth).
- cyberferret 10y agoA pretty useful, logical and sensible list. I'd be actually surprised if most SaaS startups were NOT doing this. As a one man show (recently doubled in size to TWO!), I've ticked off nearly everything on here. One question though - is on the multiple domains bit. Not sure how several separate domains is better than one domain utilising subdomains for API etc.? Intrigued about the 'secret' internal domain thing, and I guess it would apply to larger organisations. I'd be interested to hear how many startup founders here have a separate internal domain name for back office stuff related to their web offerings.
- _wmd 10y agoSPF and DKIM can be applied just fine to subdomains, I don't understand the suggestions made for email, yet there are good reasons to have a few extra domains, none which are actually mentioned: accidental cookie leakage and redundancy being obvious ones. The implication made for the API domain was that it should not be protected by SPF and DKIM I stopped reading there
- itaifrenkel 10y agohi. Here is my attempt to clarify this section. Could you please comment on PR https://github.com/forter/security-101-for-saas-startups/pull/35 https://github.com/forter/security-101-for-saas-startups/pul... ?
- itaifrenkel 10y agoMy understanding was that SPF and DKIM are only for sending emails. I need to rearrange that paragraph and add the 2 other reasons you mentioned, and you are right that outgoing emails are better sent from subdomains. I do wonder though if a spam filter blocks x.d.com would it also block emails from d.com?
- deleted 10y ago[deleted]
- wink 10y agoA few remarks/questions > Stop using disk-on-keys never heard that phrase > Buy at least 2 or 3 domain names I don't really understand the whole paragraph - or fundamentally disagree with your reasoning. Of course there are some upsides (regarding security) of splitting stuff over a few domains but there's a lot of reason why you wouldn't do that. I think this is written too harshly as "Do as I say" without proper explanations and nuances of the details. > Monitor your endpoint's public certificate expiration date, to detect prevent certificate expiration. typo? missing "and"? remove "detect"? > By default AWS users choose Oregon (us-west-2). Highly misleading. Or is your advice only relevant for US companies? I'd also say this is false for many people who have an international market leaning towards Europe, not Asia - then us-east is often better. > Using git would allow you to add outsource/freelance developers for a limited time, by giving and then revoking commit permissions. Non-sequitur unless you insert "easily". Maybe. I don't disagree that git is the way to go, but your reasoning is nonsensical here. We did exactly that with CVS and SVN 15 years ago. > Every service you use requires a 2nd authentication factor (2FA). This is under "your first customer". Was this meant to be "should require"? Are you talking about the XaaS you (the company) are using? Are you advocating that your users use 2FA with your product? > Antivirus No, don't. All in all some good points, but could use some clean up. You're lumping things together from varying degrees of technical expertise - also some paragraphs are highly detailed (and thus, sometimes miss to convey the bigger point) and others are pretty sparse. Sorry if this sounded like complaining, there were (very) few points where I strongly disagree, but overall a good overview. I probably would've split it in at least 2 parts - e.g. for a CEO (overviews, less details, but more fields) and CTO level (technical stuff, with details).
- itaifrenkel 10y agoUSB flash drives is the term used in the US, right? us-west - perhaps I should change it to don't use us-east-1, since it fails much more often and is more crowded. I'll rephrase the git and 2fa. Endpoint Security - you gotta have it. I understand the natural objections, but there is no certification that doesn't ask about it. There are the more expensive ones like cyberreason or carbonblack. I need to research more the domains issue. I suppose it's more prevalent in Israel since some devops in Israel worked for gaming (gambling) companies where they definitely use multiple domains for multiple purposes. But I think the main reason is allowing devs more management access to internal subdomains and disallowing management access to the API endpoint domains that customers use, to reduce attack surface. Thanks for your comments. Keep them coming
- ecesena 10y ago> automation (for example a Jenkins task) I think there's value in this, but I want to point out that often time Jenkins becomes a collector of tech/security debt itself. It has very high privileges, and often time accesses/changes are not properly auth & audited.
- itaifrenkel 10y agoAre there any best practices you would recommend?
- joshvm 10y agoI would advise against Google Drive for document sharing. Recently I tried to share a trial build of an application (an exe I built) with a client. I zipped everything up and created a share link. Google auto-flagged it as a terms of service violation and blocked the file. No way of getting round it, and no way Google will bother to remedy the situation in time. There's also OneDrive for business which seems to work well for sharing, though syncing options are totally broken. There's no way to selectively sync a share folder, so either you have your entire filesystem downloaded or you go online to get files. That sucks when your backup is terabytes of data. I ended up sending a Dropbox link instead. So far it seems to be more or less foolproof.
- itaifrenkel 10y agoI am not sure that binaries are the use case for g-docs. I would have used s3 for that.
- joshvm 10y agoFor mass distribution, sure a solution like S3 is the way to go. However, this was more of a "The file is too large to email, I'll zip the build and send a shared link" occasion. Using S3 for that is a sledgehammer approach especially when you're working with people who aren't tech savvy. The concern is that G-Drive (not Docs) seems to arbitrarily decide what you can and can't share using it. In this case, it was a binary and associated files. I was able to share an earlier build without problems. Was it a DLL I'd bundled? VCpp redistributable? Was there some pattern of bits in the code that bothered the file checker? I don't know what triggered the violation and probably never will.
- nkkollaw 10y agoMight not contribute much to the discussion, but I found this pretty sad: - Mac users can encrypt their drive with 1 click. - Windows users would need the Pro version and prefer laptop hardware that supports TPM. - Linux users would require disk reformatting
- mi100hael 10y agoI believe that's slightly misleading. Enabling LUKS on Linux would require a re-format, but there are ways to encrypt only your home folder without a re-format, which is all macOS does.
- metafunctor 10y agoI think FileVault 2 [1] has been doing full-disk encryption, not just the home folder, since OS X Lion. [1]: https://support.apple.com/en-us/HT204837 https://support.apple.com/en-us/HT204837
- cottsak 10y agosubmit a PR
- nkkollaw 10y agoYeah, but I have a lot of stuff outside my home folder. Including /etc/passwd.