Ask HN: I'd like to learn more about programming secure websites
Thanks!
Thanks!
2. Pro PHP Security by Chris Synder and Michael Southwell: Covers most of what you are looking for, namely, perils of shared hosting, safe development practices, Encryption, SSL and SSH, HTTP and HTTPS, Access Control and Authentication. Of course the book is inclined towards PHP but most of the concepts are language neutral and you can easily extrapolate these concepts to another language of your choice.
3. Foundation of Security by Neil Daswani et al.: The blurb on the first page speaks for itself What every programmer needs to know about security with running examples of web applications and stories of what’s gone wrong in the past. Mostly language neutral but sample codes are implementation in Java. Comprehensive. Recommended.
4. A bunch of videos at http://code.google.com/edu/security/index.html helped too.
For protecting against attacks, the absolute rule is: Never trust anything that the user has provided. This includes form submission, URLs for requests (i.e. it could be a malformed URL), the HTTP headers, the cookies, etc. They are all vectors for an attack. The corollary to this is: validate everything. From here, you can start learning more about the creative ways your app can be exploited.
For securely transferring and storing information, you'll need to look at encryption strategies like SSL and hashes (for, e.g., passwords) and the like.
Of course we can only point you in the general direction. This is a very big topic!
getting my server hacked into is certainly on my mind as i set up the server myself only out of necessity and poverty (if not financial then creative and social). i really want the data to remain private.
i have form submission secured. not only does django escape input into sql, but i have a pre-save signal that removes html tags. once concern i do have is that when a form has an error in it, the page is reloaded with the previously entered form values. i believe django templates always escape variables, but i should try writing javascript there just to make sure.
django also stores salt + hashes of user passwords, rather than the passwords themselves. django also puts non-critial information in session cookies. the real data gets looked up in the view middleware.
Go to the library and pick up some network security books, and focus on the website security sections (sql injections, exploiting the parameters sent to a website, trying to learn the sites using their error messages to ssl to domain spoofing). For one, this is actually a lot of fun, but more importantly, now you'll always be thinking how to exploit the code you write, and doing so will allow you to realize mistakes very quickly.
You might want to serve some personally-identifiable or sensitive data via HTTPS if you have the the resources. At the very least, you should authenticate via HTTPS which is what a lot of services do.
Reason being, someone between the client and the server can sniff the traffic. If it is HTTPS it will be encrypted; if not, plain as day. Hence the reason why login pages usually redirect you over to a HTTPS login page, when you login you don't want to send your username and password pair to the server in plaintext!
What's funny is people often still send their email creds to their email server without being encrypted either...
Your whole site should not use HTTPS unless all of the data or functionality on that site were sensitive. Pretty simple rule of thumb: public facing pages use HTTP and login pages + anything behind use HTTPS.
Which brings me to your second subject: logic flaw. That is probably the most common security flaw than anything else. It is been made worse by the fact that most "web developers" don't actually understand logic nor the full implications of structured programming.
It is compounded by a lack of understanding system fundamentals too; it's quite common amongst developers I have met to not know why "0123" comes out as "83" in any scripting language built atop C (Python and PHP are popular examples). (Hint for those that don't know: C interprets integer literals with a leading zero as an Octal number).
we'll do the best we can to get both fronts up to snuff before the general public gets a stab at us.
I highly recommend the Slicehost articles. They've been indispensable for me and there are some good ones on SSL/HTTPS server setup:
i've chosen to make the entire site HTTPS and redirect HTTP to HTTPS. the reason being that performance doesn't seem to take a big hit, and while things like caching and moving to multiple servers will be harder, if we get to that point then re-writing some of this code will be fine (whereas it is not fine now when we just want to get some user testing done).
i'm using django. the move for some pages to be accessed via https means accounting for redirects more intelligently. eg, {% url login %} should produce https://... while {% url static_page %} should produce http://... there is a django snippet for middlewhere that allows one to provide a SSL flag.
still...if one is visiting https://mysite.com/A and then moves to https://mysite.com/B, then won't the browser alert them to the move? it should, but that provides the wrong viewing experience... i guess, once a user logs in, the rest of their visit to the site should be over https, even the static pages that non-logged in users view over http?
alternatively, i care less about the users that log in and more that the API used by my Firefox extension to communicate with my server is conducted over HTTPS. that's where i started, but once i made that https it was a slippery slope for the rest of the site :-)