{"repo":"FallibleInc/security-guide-for-developers","free":true,"listed":false,"github":"https://github.com/FallibleInc/security-guide-for-developers","clone":"git clone https://github.com/FallibleInc/security-guide-for-developers.git","description":"Security Guide for Developers","language":null,"stars":21094,"topics":["security-checklist","security-book","security","books","api"],"license":null,"category":"security-tools","readme_excerpt":"A practical security guide for web developers (Work in progress) The intended audience Security issues happen for two reasons - 1. Developers who have just started and cannot really tell a difference between using MD5 or bcrypt. 2. Developers who know stuff but forget/ignore them. Our detailed explanations should help the first type while we hope our checklist helps the second one create more secure systems. This is by no means a comprehensive guide, it just covers stuff based on the most common issues we have discovered in the past. Contents 1. The Security Checklist 2. What can go wrong? 3. Securely transporting stuff: HTTPS explained 4. Authentication: I am who I say I am 4.1 Form based authentication 4.2 Basic authentication 4.3 One is not enough, 2 factor, 3 factor, .... 4.4 Why use insecure text messages? Introducing HOTP & TOTP 4.5 Handling password resets 5. Authorization: What am I allowed to do? 5.1 Token based Authorization 5.2 OAuth & OAuth2 5.3 JWT 6. Data Validation and Sanitation: Never trust user input 6.1 Validating and Sanitizing Inputs 6.2 Sanitizing Outputs 6.3 Cross Site Scripting 6.4 Injection Attacks 6.5 User uploads 6.6 Tamper-proof user inputs 7. Plaintext != Encoding != Encryption != Hashing 7.1 Common encoding schemes 7.2 Encryption 7.3 Hashing & One way functions 7.4 Hashing speeds cheatsheet 8. Passwords: dadada, 123456 and cute@123 8.1 Password policies 8.2 Storing passwords 8.3 Life without passwords 9. Public Key Cryptography 10. Sessions: Reme","default_branch":null,"files":null,"tree":[],"storefront":"/r/FallibleInc","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/FallibleInc/security-guide-for-developers/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}