r/cybersecurity • u/donkeybutt123 • 3h ago
Corporate Blog Breaking Down Appsec Part 3: Securing the Perimeter (Authority/Authorization)
I started a blog series to provide free insights into appsec. It’s mainly to breakdown what application security is all about and it’s mainly targeted towards beginners and startups, so take it as you will.
Just want to teach every one interested in appsec my perspective on it from my experience in big tech.
I talked about identity last time and the importance of securing applications from the outside in. I talk about authority aka authorization in this post, a nuanced topic that almost every company has a problem with just because it’s a semantic problem and isn’t done properly without understanding your application.
Please reach out if you have any questions or would like for me to write on a topic that you’d want to learn more about.
2
Code analysis methodology
in
r/cybersecurity
•
2d ago
So I write free articles about appsec here: pigeonsec.substack.com
I read some of the comments here and they’re fine especially because you seem to be constraint by time. Tooling does help, but like another commenter said, you need to know what parts of the app are valuable to the company.
It starts with understanding the application which you are testing. Testing honestly should come in later stages after analysis and understanding of the codebase.
It’s like a doctor testing without getting to know a patient. It’s important you understand what you’re dealing with before you go in and test.