Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <CABeokRdp3LAkfrHhbDfQeGdLgiMEqu8DXrMn1o6b2nneyfqyZQ@mail.gmail.com>
Date: Thu, 18 Aug 2011 10:15:08 -0400
From: Sergey Chernyshev <sergey.chernyshev@...il.com>
To: oss-security@...ts.openwall.com
Subject: Start(up) API project security

Hello from fellow Open Sourcerer.

I'm working on a project to help people build web apps, called Startup API
(thinking of renaming it to Start API to make it less cool, but more
useful).

Having seen too many startups keeping the passwords in clear
and committing many similar security "crimes", I'm very much concerned about
it and want to establish some security process around building the apps.
I've started gathering information about security-related issues on the
project's wiki (not only for Startup API software itself, but for best
practice collection in general):
http://startupapi.org/Security

Right now, I'm trying to understand what are the most common and / or most
dangerous security issues surrounding web apps.
I feel that this group should have a pretty good experience tracking those
down and I'd love any thoughts you might want to share.

If you have any links to good articles or videos about web app security, I'd
really appreciate that too.

Thank you,

         Sergey


--
Sergey Chernyshev
http://www.sergeychernyshev.com/
http://www.meetup.com/Web-Performance-NY/
http://www.showslow.com/

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.