Ask HN: Handling Security as a Solo Dev?
There’s so many different ways to screw up, depending on how the app is developed and deployed (an old style VPS deployment is a very different beast than something e.g. deployed on Vercel using S3 and Supabase), and I’m most experienced in mobile client dev (haven’t touched back end since ~2012) which makes for considerable blind spots. I’m aware of basics like not checking in API keys and secrets, but I’m sure there’s a laundry list of things I’m not considering.
What’s the best way to make sure my bases are covered here? It used to be that using well vetted, battle tested tools like up to date Rails w/Devise would take you a long way, is that still true?
Thanks, and apologies if the question is too vague.