Settings

Theme

Ask HN: Resources about building secure websites and web services?

2 points by sunday_serif 2 years ago · 2 comments · 1 min read


Hi all,

Can anyone recommend any resources (books, websites, papers, lectures, etc.) about building secure websites and software services generally? I know this is a very broad topic, and so I understand that there won't be a one size fits all resource.

Topics that are of interest include: - considerations for building a secure login on a website - interfaces for authentication & authorization in web apis - considerations for storing customer / user information - considerations for communication between backend services and 3rd party services - probably lots of other things that I haven't even considered!

justinludwig 2 years ago

OWASP Cheat Sheet Series [1] is a great place to start (for websites or HTTP services generally). Also see their Web Security Testing Guide [2] for a comprehensive list of security issues to watch out for:

[1] https://cheatsheetseries.owasp.org/index.html

[2] https://owasp.org/www-project-web-security-testing-guide/lat...

LinuxBender 2 years ago

This may not be exactly what you are looking for but if you have specific topics you wish to learn more about then the Security [1] portion of StackExchange contains some decent questions and answers. ServerFault [2] also contains some server best practices. Stack Overflow [3] would have some of the coding best practices. Lurk on there for a while before asking questions as people expect a certain style of question formatting and some degree of research from someone in a related professional field prior to asking questions.

[1] - https://security.stackexchange.com/

[2] - https://serverfault.com/

[3] - https://stackoverflow.com/

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection