4 ms·
If this is the "minimum", I'd love to see what they left off the list. My minimum for a public-facing MVP: - All services use HTTPS to talk to users and each
by lexandstuff 3y ago
If this is the "minimum", I'd love to see what they left off the list.
My minimum for a public-facing MVP:
- All services use HTTPS to talk to users and each other.
- High standard of password encryption (or prefer to use something like Cognito or Firebase).
- Plan for GDPR compliance (not exactly security related, but in the wheelhouse. The GDPR grifters come out of the woodwork quickly, so you need all the popups and account deletion stuff from day 1 if you are releasing to the EU).
- QA specifically for security: users can't access each other files, authentication controls work, etc.
- Don't store or handle credit cards - use a vendor like Stripe.
- Ensure all dev tools enforce 2FA where possible (GitHub, AWS, etc.).
- A basic backup system.
Then post-MVP, start working on the following:
- centralised logging.
- dependency patching plan.
- etc
- seabass-labrax 3y ago> Don't store or handle credit cards - use a vendor like Stripe. Alternatively, if your customers will make one-off or infrequent payments, you might want to consider accepting cheques, which can be made electronically through a system like BACS (note that every country has different systems available). Cheques (checks) are a 'customer pushes' method as opposed to cards, which are a 'seller pulls' method. Accepting international payments makes transfers somewhat more difficult, and cheques always assume a higher level of competence on the part of the customer than cards do; however, neither are likely to be a problem for B2B products. > Ensure all dev tools enforce 2FA where possible (GitHub, AWS, etc.). Two things that are critical to remember are that 1: most forms of 2FA don't improve security and 2: many services will refuse to restore accounts based on trust or some other form of evidence if 2FA was enabled, where they would otherwise. Challenge-based forms of 2FA such as TOTP or FIDO are better than SMS, as latter can be intercepted in transit. Calculating the response to a challenge on a separate physical device to the one being authenticated is additional benefit that FIDO2 usually has. Side-note: if you need to authenticate customers, allow them to choose at least TOTP; try not to even provide SMS 2FA. As for the lack of account recovery, this can be a benefit, but only if you have robust procedures to make sure employees' credentials (like TOTP codes) are copied to sites accessible by other employees; this effectively means things like buying fireproof safes if you are doing it properly. Revocation of credentials by other employees is just as important as recovery. All this is to say that 2FA is not something that you can just toggle a switch for to make your company secure; it is worthy of a company-wide strategy.