Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Rationales #8

Open
erlkonig opened this issue Jul 9, 2017 · 6 comments
Open

Rationales #8

erlkonig opened this issue Jul 9, 2017 · 6 comments

Comments

@erlkonig
Copy link

erlkonig commented Jul 9, 2017

Each thing in the list deserves a file on the rationale behind it, even if those are largely URLs.

@alexchamberlain
Copy link

I agree that seeing the rationale would be great, but please don't do this within the checklist, as you probably don't want to read it every time you read the checklist.

@netcode
Copy link
Member

netcode commented Jul 9, 2017

A very good idea . May be we can start to make a seperate files as a reference to every check point.

@StillLearnin
Copy link

How about wiki pages that are linked to from the list?

@darioseidl
Copy link

Without a rational for each recommendation, the checklist is not very useful (to me at least).

Security is never perfect or absolute, so whether and how to secure something depends on how sensitive the data is and who you are protecting it from. And while some practices are widely accepted, there are disagreements about others. Take for example the discussions on Basic Auth and JWT in the issues on this repo. A rational for why the author(s) of this checklist recommend to use JWT Bearer Auth over Basic Auth would be good. (IMO, neither is perfect, but both can be good enough for some APIs)

@montchr
Copy link

montchr commented Jun 14, 2022

I agree that this list does not come across as useful to me. A security checklist asking its users to follow its advice without question paradoxically undermines the security-conscious process and mindset the checklist appears to support.

@Maikuolan
Copy link
Collaborator

Anyone want to try having a go at this, make some PRs, etc?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

7 participants