3 ms·
Check out OWASP’s cheat sheet: https://cheatsheetseries.owasp.org/cheatsheets/Authentication_Cheat_Sheet.html https://cheatsheetseries.owasp.org/cheatsheets/Aut
by bdibs 7y ago
Check out OWASP’s cheat sheet: https://cheatsheetseries.owasp.org/cheatsheets/Authentication_Cheat_Sheet.html https://cheatsheetseries.owasp.org/cheatsheets/Authenticatio...
- pier25 7y agoJesus this is a gold mine!
- thephyber 7y agoThere is really no reason any developer should try to roll their own auth these days. OWASP has identified and enumerated all of the relevant info. It seems like negligence when a teacher/professor talks about building a web app without referencing the project.
- ak39 7y agoWhen you say "roll their own auth", are you implying "designing from scratch their own method or idea of authentication"? Or are you implying using existing libraries or services instead of rolling out your own?
- anayar 7y agoBut even if you use a third party, tying identity in to your application almost always still has to be rolled on your own right? So no matter how bulletproof the 3rd party solution, it’s likely that a tremendous number of vulnerabilities on an application basis could come from faulty auth integrations as well
- anayar 7y agoPhenomenal, many thanks!