Ask HN:全栈开发者应该了解哪些安全知识?

1 分•作者: ah1508•大约 1 个月前
大家好, 我被要求帮助一个全栈开发团队(Spring+Angular)提升安全技能。 我对全栈开发者的能力持怀疑态度,有多少全栈开发者能同时深入理解 `display: flex` 和事务隔离级别? 因此,虽然全栈开发者不应该成为公司里的网络安全专家,但由于公司没有网络安全专家,他们必须提升技能,以免公司面临风险。即使公司聘请了网络安全专家,他们也必须了解所有与开发相关的基础知识,以便能够遵循网络安全专家的建议。他们不是新手,例如,他们了解 SQL 注入。 这是我的培训清单(我将帮助他们学习所有这些内容),你们觉得怎么样?培训将包含一半理论和一半实践。 **引言** * 密码学与安全:两个不同的领域。 * 术语:哈希、加密、密钥、证书、签名、前向保密、CVC、零信任。 * OWASP Top Ten 2025 和 CWC Top 25 2025。 * 网络层安全,应用层安全; * 漏洞检测工具:SAST、DAST 和 IAST; * 一些算法:SHA、AES、RSA、椭圆曲线加密。用例和性能; * “像黑客一样思考”,案例研究:Spring4Shell (CVE-2022-22965)。 **保护 REST API** * 嵌入式 Web 服务器配置: * TLS 激活(密钥生成、证书、服务器配置、握手步骤) * HTTP 请求限制(请求头大小、参数、请求体大小、分块) * 不公平使用缓解(速率限制、超时、虚拟线程使用); * 日志管理 * 身份验证: * 密码保护:哈希、加盐、成本、算法(Bcrypt、Scrypt、Argon、Pbkdf2) * Cookie 身份验证 * Token 身份验证(生成、签名、验证、撤销); * 混合身份验证(Cookie + JWT)及 Token 中继; * 攻击(XSS、CSRF、日志注入、SQL 注入、授权绕过…)及如何缓解; * CORS 策略定义; * API 之间内部调用(东西向流量)的 mTLS 介绍。 **加密数据** * 加密术语:机密性、真实性、完整性、不可否认性; * 公钥基础设施的描述,有或无 KMS,有或无 HSM。 * 鸡生蛋蛋生鸡问题,使用 Diffie Hellman 进行密钥交换; * 使用 CMS(加密消息语法)交换加密数据; * 数据库加密:文件加密或行级加密。 **应用 CI/CD 最佳实践** * SBOM 生成并上传至 DependencyTrack; * 将扫描作为 CI 流水线的一个步骤; * 生产环境中的密钥管理 * Vault (Hashicorp Vault) 和/或 Spring Cloud Config 服务器; * 在应用程序启动时使用 Jasypt 进行解密; * Kubernetes 密钥管理介绍。 **保护 Angular SPA** * 脚本包含的 SRI 哈希和内容安全策略 (CSP); * 严格的模板检查; * 数据清理; * CSRF 缓解(涉及 API 和 Angular 客户端); * 守卫(Guards)配置; * JWT 的保护、使用和续订。 * 确保 HTTP Client 的完整性。 我还考虑了一些不会导致系统崩溃但会增加后端负载的微妙攻击。例如:如果 SQL 分页是使用 `offset` 和 `limit`(而不是基于键的分页)完成的,那么一个有效的 HTTP 请求 `GET /items?offset=100000000&limit=10`,如果频繁重复,将给数据库服务器带来意想不到的负载。此外,还会浪费时间去理解这种高负载的原因。这个例子中重要的是:1)使用基于键的分页,2)检测可疑活动(多个具有非常高 `offset` 的 HTTP 请求是可疑的)。 你们觉得我还有什么遗漏的吗?感谢您的反馈!
查看原文
Hi all,<p>I am asked to help a fullstack dev team (Spring+Angular) to skill up in term of security.<p>I am skeptical about fullstack profiles, how many fullstack devs knows in depth display:flex and in the same time transaction isolation level ?<p>So as fullstack devs they are not supposed to become cyber-security experts in their company but since they don&#x27;t have a cyber-security expert they must level up so they don&#x27;t put their company at risk. Even if they hire one they must know all the basics that are related to development so they will be able to follow their cyber-security expert recommendations. They are not newbies, for instance they know about sql injection.<p>Here is my checklist (I&#x27;ll help them to learn all of that), what to you think ? There will be half theory and half practice.<p>Introduction<p><pre><code> - Cryptography and security: two distinct domains. - Wording: hashing, encryption, key, certificate, signature, foward secrecy, CVC, zero thrust. - OWASP Top Ten 2025 and CWC Top 25 2025. - Security at the network level, security at the application level; - Tools to detect vulnerabilities: SAST, DAST et IAST ; - A few algorithms: SHA, AES, RSA, Elliptic curve encryption. Use cases and performances; - « Think like a hacker », case study: Spring4Shell (CVE-2022-22965). </code></pre> Secure a REST API:<p><pre><code> - embedded webserver configuration: - TLS activation (key generation, certificate, server configuration, handshake steps) - limits on HTTP requests (headers size, parameters, body size, parts) - unfair use mitigation (rate limiting, timeouts, virtual threads usage); - log management - Authentication : - password protection: hashing, salt, cost, algorithms (Bcrypt, Scrypt, Argon, Pbkdf2) - cookie authentication - token authentication (generation, signature, validation, revocations); - hybrid authentication (Cookie + JWT) with token relay; - Attacks (XSS, CRSF, log injection, sql injection, authorization bypass...) and how to mitigate them; - Definition of a CORS policy; - Introduction to mutual TLS for internal calls between API (est-west traffic). </code></pre> Encrypt data:<p><pre><code> * Keywords of encryption: confidentiality, authenticity, integrity, non-repudiation; * Description of a public key infrastructure, with or without KMS, with or without HSM. * Chicken and egg problem, key exchange with Diffie Hellman ; * Exchange of encrypted data with CMS (Cryptographic Message Syntax) ; * database encryption: file encryption or row level encryption. </code></pre> Apply CI&#x2F;CD best practices:<p><pre><code> * SBOM generation and upload on DependencyTrack; * scan as a step in the CI pipeline; * secrets management in production ◦ vault (Hashicorp vault) and&#x2F;or Spring Cloud Config server ; ◦ decryption on application startup with Jasypt ; ◦ introduction to secret management with Kubernetes. </code></pre> Secure an Angular SPA<p><pre><code> * hash SRI and content security policy (CSP) for script inclusion; * strict template checking; * data sanitization; * CSRF mitigation (involves the API and the Angular client); * guards configuration; * protection, usage and renewal of JWT. * ensure integrity of the HTTP Client. </code></pre> I also think about subtle attacks that don&#x27;t put a system down but can add load on the backend. Example: if sql pagination is done with offset and limit (rather than key based pagination) a HTTP request GET &#x2F;items?offset=100000000&amp;limit=10 (which is valid) will bring unexpected load on the database server if repeated often. Plus all the time lost in understanding the cause of this higher load. What is important in this example is: 1) use key based pagination, 2) detect suspicious activity (multiple http requests with very high offset is suspicious).<p>Do you think I forget something ? Thanks for your feedback !