Show HN: Security Training for Developers
11–20 of 37 posts
Re: Show HN: Security Training for Developers
#12Blacklist input validation as defense against XSS? Are you kidding me? And then over to session fixation, where I see the exact same ?jessionid=blah example that has been in any Web Security book for the last 10-15 years? Come on!
Re: Show HN: Security Training for Developers
#13Re: Show HN: Security Training for Developers
#14Re: Show HN: Security Training for Developers
#15Any comments on who put this together, or their long term goals?
Not sure about the business model yet, though it's peaked some interest here and on /r/programming, so I figure there's an appetite for good training material.
Re: Show HN: Security Training for Developers
#16At a glance this seems to be aimed mostly at web developers. How much of this would be relevant for a native mobile developer like myself?
Re: Show HN: Security Training for Developers
#17This is so beautiful that I wish it was good advice, but it's not. Some of these examples actually introduce problems. SHA-256? Really?
Re: Show HN: Security Training for Developers
#18Re: Show HN: Security Training for Developers
#19Security is hard. XSS lol. http://i.imgur.com/3QJfsu7.png
Re: Show HN: Security Training for Developers
#20Security is hard. XSS lol. http://i.imgur.com/3QJfsu7.png