bk99.de entertain the web since 1997

A practical security guide for web developers

Summary

Fallible collects concrete rules for input validation, authentication, sessions, cryptography, dependencies and secure delivery. The guide is maintained publicly on GitHub. It covers backend, frontend and infrastructure.

Ideas

  • Input is validated on the server against the expected structure.
  • Passwords need slow, specialised hash functions.
  • Session cookies need Secure, HttpOnly and suitable SameSite rules.
  • Dependencies must be inventoried and updated promptly.

Insights

  • Security arises from many consistent small decisions.
  • Framework protection only works with correct configuration and use.
  • Checklists complement threat models but do not replace them.

Facts

  • Contributions and corrections are welcome.

Recommendations

  • Automate dependency and configuration checks.
  • Test abuse cases alongside normal user flows.

References

Read the original article

Search the Web Archive