A practical security guide for web developers
Summary
Fallible collects concrete rules for input validation, authentication, sessions, cryptography, dependencies and secure delivery. The guide is maintained publicly on GitHub. It covers backend, frontend and infrastructure.
Ideas
- Input is validated on the server against the expected structure.
- Passwords need slow, specialised hash functions.
- Session cookies need Secure, HttpOnly and suitable SameSite rules.
- Dependencies must be inventoried and updated promptly.
Insights
- Security arises from many consistent small decisions.
- Framework protection only works with correct configuration and use.
- Checklists complement threat models but do not replace them.
Facts
- Contributions and corrections are welcome.
Recommendations
- Automate dependency and configuration checks.
- Test abuse cases alongside normal user flows.
References
Links to the original source and the Web Archive open in a new tab.