6 ms·
I am just learning coding for the web. Security is something that is clearly important, but I am unsure on a lot of specifics. Do you have any suggestions for a
by impostir 8y ago
I am just learning coding for the web. Security is something that is clearly important, but I am unsure on a lot of specifics. Do you have any suggestions for a beginner?
- sansnomme 8y agoLearn how basic user registration to login workflow works. I.e. user sign-up -> password hashing -> confirmation email etc. There are also "alternative" methods such as medium-style "email a login link" style logins and also stuff like OAuth. Stick with large frameworks and libraries; Rails, Omniauth and Devise, Django comes with Auth built-in. Avoid Auth frameworks which doesn't build upon its built-in systems. Learn the difference between authorization and authentication. DO NOT ATTEMPT TO ROLL YOUR OWN AUTH FOR PRODUCTION. A lot of concepts regarding Auth are simple in theory but if you have a poor grasp of the implementation language or the authentication protocol, you are going to introduce vulnerabilities. Stick to boring battle-tested stuff. Yes that means you should avoid the latest-web-framework-of-the-week-that-doesn't-include-auth when it comes to anything you want to push into production. Keep everything behind TLS if possible (Let's Encrypt et al. are free) and if you don't understand something, don't use it. If JWTs doesn't make sense to you, avoid it and stick with traditional sessions. Your SPA works perfectly fine using traditional server-side sessions and encrypted cookies without the latest hip protocol implemented by a 3rd party API gateway. Don't trust security advice from random people over the internet without doing your own research. Here is some good reading material: https://latacora.micro.blog/2018/06/12/a-childs-garden.html https://latacora.micro.blog/2018/06/12/a-childs-garden.html https://latacora.micro.blog/2018/04/03/cryptographic-right-answers.html https://latacora.micro.blog/2018/04/03/cryptographic-right-a...
- sansnomme 8y ago*server-side sessions with CSRF