-
Notifications
You must be signed in to change notification settings - Fork 12
Detailed notes on Security. #27
Conversation
kyoung
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
+1
README.md
Outdated
| * Use [two factor authentication](https://support.google.com/accounts/answer/1066447?hl=en). | ||
| * [Never commit secrets or keys](https://mobify.atlassian.net/wiki/display/SYS/Best+Practices+For+Keeping+Secrets+in+Applications). | ||
| * Apply the [principle of least privilege](https://en.wikipedia.org/wiki/Principle_of_least_privilege). | ||
| * When it doubt, ask! `#security` is always happy to help! |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
* Don't implement your own security scheme: libraries are your friend
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@kyoung 🤔 I really like this point... but I don't feel like this needs to be an exhaustive list – we're probably missing a link to a more detailed policy. I'm going to move ahead for now, and cycle back on that.
README.md
Outdated
| * Use [two factor authentication](https://support.google.com/accounts/answer/1066447?hl=en). | ||
| * [Never commit secrets or keys](https://mobify.atlassian.net/wiki/display/SYS/Best+Practices+For+Keeping+Secrets+in+Applications). | ||
| * Apply the [principle of least privilege](https://en.wikipedia.org/wiki/Principle_of_least_privilege). | ||
| * When it doubt, ask! `#security` is always happy to help! |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Can #security be a link?
| - Follow [Mobify's software security policy](https://mobify.atlassian.net/wiki/questions/60817443/what-is-mobifys-software-security-policy). | ||
| #### 🔒 Build Secure Software | ||
|
|
||
| > With great power comes great responsibility. – [Uncle Ben](https://en.wikipedia.org/wiki/Uncle_Ben) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
<3 my fav
* Reverse ordering of points. * Link #security channel. * Fix a typo.
Expand on the existing section on Security with a short checklist.