4 ms·
If you’re doing a new startup, and have aggressive timelines, what security measures would you implement to protect PII from day 1? I’m an experienced dev but n
by embwbam 8y ago
If you’re doing a new startup, and have aggressive timelines, what security measures would you implement to protect PII from day 1? I’m an experienced dev but not a security expert.
- thinkingemote 8y agoI'd suggest hiring an expert, assuming the startup is funded
- ummonk 8y agoTwo factor authentication for all developer accounts, require TLS 1.2 to access the website and add HSTS, have some system for ensuring all SQL queries are sanitized, use bcrypt or scrypt with recommended settings to hash user passwords, add a content-security policy, enable secure and same-site attributes for cookies, as well as http-only, and add a double-submit csrf token. That should cover the basics to start with, in rough order of priority, assuming you're building a web app. Also, in general, be conservative about what PII you collect; hackers can't steal information you don't have.