3 ms·
My biggest worry with this checklist is that while it helps already security-minded people and web developer professionals remember what they should already be
by eggbrain 9y ago
My biggest worry with this checklist is that while it helps already security-minded people and web developer professionals remember what they should already be doing, it doesn't really help security novices (who may search for something like this) make their app more secure. Why?
1. The checklist tells me what I need to do, but not how to do it right.
I could imagine many security novices reading one of these items, implementing the first solution they find on StackOverflow, and checking it off in a "fixed it, boss" kind of manner. That may lead them to thinking their app is more secure than they should, and is then a detriment to the security of their app.
2. The checklist doesn't really help me decide in what order to do things, and what perceived increase in security I'll receive
Storing sensitive data in the database using bcrypt is pretty easy to implement (many times baked into web frameworks), and provides a good amount of security for the time it takes. Compare that to something like implementing CSP however, which may involve moving a ton of files around your app, adding nonces/hashes, etc, and it gets me an A+ on secureheaders.io, but I'm not sure if all the pain was worth it for my basic application.
3. The checklist makes things way harder for a developer to think about.
Anyone wanting to build a web app looking at this list would probably be too overloaded with information to want to implement much of this, when in reality, they could start off with something like Heroku where they just push it up and it works, and many of the security concerns have been taken care of for them.
- aeronautic 9y agoThanks for your well structured comments. The purpose of the checklist was to get people to think. It is really hard to do much more without going very long. A number of people have suggested that I link implementation background off each item. I think that can work and layer the info as well.
- eggbrain 9y agoI know your pain -- things like this get long fast, and it's hard to include everything all at once without going on forever. I would definitely appreciate implementing some background off of each item! Another thing that might help is knowing about services or open source solutions that can bundle a lot of the checklist together. Heroku might be a paid one, for example, but there might be things like ansible scripts out there that do a lot of this from security professionals, I'd love to know how to be able to package a lot of these checklist items together more easier.
- aeronautic 9y agoCoding is easy, writing is just darn hard!! Thanks for the ideas. I'll check those out.