“Shift left” is the concept of implementing security from the very beginning and continuously validating that the product is secure. This article is about how to shift security left, based on my experience with very large commercial payment applications and how I helped secure them.
Tag Archive: Security
I have been asked multiple time about how to go about starting a security program. This is a short primer that lists some of the things you should do to jump start a security program.
If you are trying to find out how to handle a ransom attack after you have been attacked, you are already way too late. Your options are very limited. Either pay or pray that the attackers were really stupid and try to recover the data by engaging a specialized consulting company. What you need to do is plan for this before you are attacked.
Should you implement HTTP Public Key Pinning (HPKP) for your site? Some reasons I don’t like it in its present form and when it can be acceptable.
Who is responsible for payment fraud? Why customers also need to get involved and cannot just depend on service providers to protect them.