Learning path · Beginner
Security essentials
Logins, secrets, the attacks everyone should know, and how to stop them.
Who a user is and what they may do, how secrets are kept, the classic attacks on web apps, and the habits that defend a whole system.
40 pages4 chaptersabout 1.5 hours of reading
- Security
Not started yet0/40 read
Start with AuthenticationProgress comes from your reading history, kept only in this browser.
Chapter 1Who are you, and what may you do?
- 1AuthenticationSecurity, p. 2Authentication is the process of verifying that a user, device, or service really is who it claims to be, for example by checking a password or passkey.
- 2AuthorizationSecurity, p. 3Authorization is the process of deciding what an authenticated user or service is allowed to do, such as which data it can read, change, or delete.
- 3Two-Factor AuthenticationSecurity, p. 46Two-factor authentication is a login method that requires two different kinds of proof, such as a password plus a code or security key, to confirm identity.
- 4PasskeySecurity, p. 25A passkey is a passwordless sign-in credential based on public-key cryptography, unlocked with a fingerprint, face scan, or device PIN, that resists phishing.
- 5OAuthSecurity, p. 22OAuth is an open standard for authorization that lets an app access a user's data on another service without ever seeing the user's password.
- 6OpenID ConnectSecurity, p. 23OpenID Connect (OIDC) is an identity layer on OAuth 2.0 that lets an app sign users in via an identity provider and get a signed token saying who they are.
- 7SSOSecurity, p. 41SSO lets a user sign in once with a central identity provider and then access many separate applications without entering credentials again.
- 8SAMLSecurity, p. 36SAML is an XML-based single sign-on standard: an identity provider authenticates the user and sends the application a signed assertion that logs them in.
- 9RBACSecurity, p. 32RBAC is an authorization model that grants permissions to roles, such as admin or editor, and then gives users access by assigning them those roles.
- 10Principle of Least PrivilegeSecurity, p. 28The principle of least privilege is a security rule that every user, program, and service gets only the minimum access it needs to do its job, and no more.
Chapter 2Keeping secrets
- 11HashingSecurity, p. 14Hashing is the process of turning any input into a fixed-length value with a one-way function, used to verify data integrity and store passwords safely.
- 12SaltingSecurity, p. 34Salting is the practice of adding a unique random value to each password before hashing it, so identical passwords produce different hashes and resist cracking.
- 13HMACSecurity, p. 15HMAC combines a secret key with a hash function to produce a tag that proves a message came from someone who knows the key and wasn't changed on the way.
- 14EncryptionSecurity, p. 12Encryption is the process of scrambling data with a key so that only someone holding the correct key can turn it back into its original, readable form.
- 15Symmetric EncryptionSecurity, p. 44Symmetric encryption uses the same secret key to encrypt and decrypt data; it is fast, so it protects most stored and transmitted data, usually with AES.
- 16Public-Key CryptographySecurity, p. 30Public-key cryptography is a method that uses a pair of linked keys, a public key anyone can see and a private key kept secret, to encrypt and sign data.
- 17TLSSecurity, p. 45TLS is the cryptographic protocol that encrypts data sent over a network and verifies the server's identity, securing HTTPS, email, and many other connections.
- 18HTTPSSecurity, p. 17HTTPS is the secure version of HTTP that encrypts traffic between a browser and a website with TLS, protecting data from eavesdropping and tampering.
- 19End-to-End EncryptionSecurity, p. 13End-to-end encryption (E2EE) encrypts messages on the sender's device so only the intended recipients can decrypt them, not even the service carrying them.
- 20Certificate AuthoritySecurity, p. 5A certificate authority is a trusted organization that issues digital certificates confirming a public key belongs to a specific website, company, or person.
- 21Secrets ManagementSecurity, p. 37Secrets management is the practice of securely storing, distributing, rotating, and auditing sensitive credentials such as passwords, API keys, and tokens.
Chapter 3Common attacks
- 22OWASP Top 10Security, p. 24The OWASP Top 10 is a widely used list of the ten most critical security risks to web applications, published by the nonprofit OWASP and updated regularly.
- 23XSSSecurity, p. 48XSS is a vulnerability that lets an attacker inject malicious JavaScript into a trusted website so that it runs in other users' browsers.
- 24CSRFSecurity, p. 8CSRF is an attack that tricks a logged-in user's browser into sending an unwanted request to a trusted site, which treats it as a genuine user action.
- 25SQL InjectionSecurity, p. 40SQL injection is an attack where user input is treated as part of a database query, letting an attacker read, change, or delete data they should not reach.
- 26ClickjackingSecurity, p. 6Clickjacking is an attack that hides a legitimate website inside an invisible frame on a malicious page, tricking users into clicking buttons they cannot see.
- 27SSRFSecurity, p. 42SSRF is a vulnerability where an attacker makes a server send requests to a destination of their choice, often reaching internal systems they can't access.
- 28PhishingSecurity, p. 27Phishing is a social engineering attack in which criminals pose as a trusted company or person to trick people into revealing passwords, codes, or money.
- 29Social EngineeringSecurity, p. 39Social engineering is manipulating people, not breaking technology, to get information, access or money, often by posing as someone the victim trusts.
- 30MalwareSecurity, p. 20Malware (malicious software) is any program designed to harm a computer or its user by stealing data, spying, damaging files or taking control of the system.
- 31RansomwareSecurity, p. 31Ransomware is malware that encrypts an organization's files or systems and demands a ransom for the key, often also threatening to leak stolen data.
- 32Brute-Force AttackSecurity, p. 4A brute-force attack is an attempt to break into an account or decrypt data by systematically trying huge numbers of possible passwords or keys until one works.
Chapter 4Defending the whole system
- 33Input ValidationSecurity, p. 18Input validation is the practice of checking that data entering a program has the expected type, format and range before it is used, and rejecting the rest.
- 34Content Security PolicySecurity, p. 7A Content Security Policy is an HTTP response header that tells the browser which scripts, styles, and other resources a page may load, blocking injected code.
- 35Web Application FirewallSecurity, p. 47A web application firewall (WAF) inspects HTTP requests before they reach a web application and blocks malicious ones, such as SQL injection, based on rules.
- 36Same-Origin PolicySecurity, p. 35The same-origin policy is a browser security rule that stops scripts on one website from reading data from another site unless that site explicitly allows it.
- 37Zero TrustSecurity, p. 49Zero trust is a security model that trusts no user, device, or network by default and verifies every request based on identity, device health, and context.
- 38Supply Chain AttackSecurity, p. 43A supply chain attack compromises software through something it relies on, like an open-source package, a build tool or an update server, not the app itself.
- 39Zero-DaySecurity, p. 50A zero-day is a software vulnerability that the vendor doesn't know about or hasn't fixed yet, so attackers can exploit it before any patch exists.
- 40Penetration TestingSecurity, p. 26Penetration testing is an authorized, simulated attack on a system that helps an organization find and fix security weaknesses before real attackers do.
Along the way, compare
Pairs on this path that are easy to mix up, side by side.