|
Message-ID: <CABeokRdp3LAkfrHhbDfQeGdLgiMEqu8DXrMn1o6b2nneyfqyZQ@mail.gmail.com> Date: Thu, 18 Aug 2011 10:15:08 -0400 From: Sergey Chernyshev <sergey.chernyshev@...il.com> To: oss-security@...ts.openwall.com Subject: Start(up) API project security Hello from fellow Open Sourcerer. I'm working on a project to help people build web apps, called Startup API (thinking of renaming it to Start API to make it less cool, but more useful). Having seen too many startups keeping the passwords in clear and committing many similar security "crimes", I'm very much concerned about it and want to establish some security process around building the apps. I've started gathering information about security-related issues on the project's wiki (not only for Startup API software itself, but for best practice collection in general): http://startupapi.org/Security Right now, I'm trying to understand what are the most common and / or most dangerous security issues surrounding web apps. I feel that this group should have a pretty good experience tracking those down and I'd love any thoughts you might want to share. If you have any links to good articles or videos about web app security, I'd really appreciate that too. Thank you, Sergey -- Sergey Chernyshev http://www.sergeychernyshev.com/ http://www.meetup.com/Web-Performance-NY/ http://www.showslow.com/
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.