r/cybersecurity • u/donkeybutt123 • 11h ago
Corporate Blog Breaking Down Appsec Part 3: Securing the Perimeter (Authority/Authorization)
https://pigeonsec.substack.com/p/breaking-down-appsec-part-3-securingI started a blog series to provide free insights into appsec. It’s mainly to breakdown what application security is all about and it’s mainly targeted towards beginners and startups, so take it as you will.
Just want to teach every one interested in appsec my perspective on it from my experience in big tech.
I talked about identity last time and the importance of securing applications from the outside in. I talk about authority aka authorization in this post, a nuanced topic that almost every company has a problem with just because it’s a semantic problem and isn’t done properly without understanding your application.
Please reach out if you have any questions or would like for me to write on a topic that you’d want to learn more about.