1 of 12

Security

2 of 12

Why is security important?

  • “Massive cyberattack hits Europe with widespread ransom demands”
    • Washington Post - June 27, 2017
  • “Chipotle says ‘most’ of its restaurants infected with credit card stealing malware”
    • The Verge - May 26, 2017
  • “Gamestop.com Investigating Possible Breach”
    • KrebsOnSecurity - April 17, 2017
  • “Several CNN Facebook accounts hacked by OurMine”
    • Mashable, January 29, 2017

3 of 12

It’s a scary Internet out there...

4 of 12

…but you can make it better!

5 of 12

What’s the core principle for security?

Code you write, and systems you use, should do what you want them to do, and nothing more or less.

If someone can log into your account without your permission, that’s probably the code doing something you don’t want.

6 of 12

How do I make my code more secure?

  • Test everything!
    • Make sure your code and your apps do what you want them to do.
  • Think like someone who is trying to break into your app
    • “What happens when I do this? What about this? What about this?”
  • If something happens that you weren’t expecting…
    • It’s probably a bug
    • Maybe even a security bug!
  • Fix things as you find them.

7 of 12

What do I need to be especially careful about?

  • Anywhere users give input
    • Answers to questions, usernames, passwords, bio sections, text for tweets, comments on photos, or uploading the photos themselves
  • Places where users give you input are the first places attackers are going to start trying to attack your app
  • When you’re accepting user input, you want to sanitize it.
    • Make sure the user input looks like you’re expecting it to look.
    • If you’re expecting email addresses, you should reject when a user gives you sentences

8 of 12

What should I try really hard NOT to do?

  • Writing your own code for creating, storing, or handling passwords
    • Use an existing library for this, like this one
  • Writing your own code for encrypting things
    • Use an existing library for this, like one of these
  • Blindly trusting input from your users.
    • Most of your users are going to be amazing people, but some of them are going to be attackers.
    • Instead of trusting everything, you should sanitize either when you accept it, or before you display it to other users, or both!

9 of 12

Whew!

That was a lot.

Let’s have a gif.

10 of 12

How can I protect myself online?

  • Use strong passwords
  • Don’t write those passwords down
    • A password manager helps with both of these
  • Don’t give out your password to anyone. Seriously, anyone.
  • Use two-factor authentication when you can.
    • That thing where they send you a text when you log in
  • Be vigilant, and trust your instincts.
    • If a site or email seems fishy, don’t trust it, and definitely don’t trust it with personal information
  • Be careful clicking links in email
    • There’s a lot of email-based attacks out there right now. Only click links from emails your trust.

11 of 12

What should I absolutely remember from this?

  • Secure software is software that does exactly what you want it to do, nothing more or less
  • The Internet can be scary, but it’s also wonderful and amazing
  • You can make the Internet better for everyone by being vigilant

12 of 12

Other resources!