Really great seeing how people like @ShahriyarRzayev take ideas, play around with them, and spin them in their own direction. “Read-Once Object in Python” - I would never have done it myself. Learned a lot from looking at it.
"We can't all be security experts. We *can* all be mindful of good Domain-Driven Design and its consequent impact on security." -- @tastapod, in the Foreword to the excellent book 'Secure by Design'.
#AppSec#DDD
https://t.co/3olCbmHpzG
The book 'Secure by Design' sparked real joy in me about writing good code 🥰 The combination of #DDD + #Security makes so much sense.
Wonderful book 📙 - thank you, @danbjson, @DanielDeogun, @DanielSawano
Just learned that #SecureByDesign has risen to 5th place on BookAuthority's list of Best Software Security Book. Humble thanks for all the good reviews, everybody!🙏 https://t.co/UWJTbfuU2F
@jacobian I am mostly interested in stuff at the intersection of software engineering and software security and I liked @SecuringDevOps and @SecByDesign a lot.
Reading „API Security in Action” by @neilmaddog and liking it so far.
Way to go @DanielSawano! We're delighted to inform you that "Secure By Design" made it to the list of best Software Security books of all time! https://t.co/ZMrdgsVW97
@danbjson @DanielDeogun @DanielSawano From the top of my mind ...
- The application of DDD feels very real
- The emphasis on shifting to Design to adress 'Security issues'. Although I believe it addresses many more issues
- How you can lean on static typing to leverage design
If you are processing untrusted data, you need to validate it at different levels (via @SecByDesign):
1. Origin
2. Size
3. Lexical correctness
4. Format
5. Semantics
The validation should be done in this order. Cheaper checks come first.
#appsec
.@DanielDeogun: "Security is a quality aspect of a system. If your system is insecure, your quality is low." #SecureByDesign#AppSec@danbjson@DanielSawano https://t.co/Hyu5l6fQqF
Being "Secure By Design" requires developers and engineers to understand failures and exceptions. @danbjson, @DanielDeogun and @DanielSawano have advice in their book on getting the job done. @ManningBooks#InfoSec#AppSec https://t.co/HGPv05uzbG
I recently finished reading Secure by Design by @danbjson, @DanielDeogun, and @DanielSawano. I learned a lot of new concepts for designing secure systems. Cheers to the book's authors!
⭐️⭐️⭐️⭐️⭐️ https://t.co/FPCsQNm2li #SecureByDesign#BookReview