Douglas Crockford 'Principles of Security'

preview_player
Показать описание
The web turned from document retrieval system to application delivery system, but the web was not refactored. Not unusual for purpose of software to change over its life but this left open security holes in the web.

White hats vs black hats? Security is not about hats. Security specialization is a problem. Security cannot be delegated to someone in a hat. Security is everyone’s job, don’t leave it to specialists.

Deterrence is not effective. You can’t punish an invisible attacker. Making an attacker fearful does not work online. You cannot threaten a bot. Prevention is the only thing that works.
Рекомендации по теме
Комментарии
Автор

Is "the principles of least authority" even possible to implement? Can it be implemented without affecting the performance

varunshenoy
Автор

"go to yahoo and google for" 47:29

iamalsolegend
Автор

why is counter attacking never an option? lol seems if someone attacks you, u move out the way and strike back. I'm sure they'll land on this idea in another generation.

thehardworker