I was just reading an article this morning (see link below) that was geared around the Top Ten Security tips that every developer must know, as the title states.  I am not sure that these are the "TOP 10" or not, but I think that they are all pretty good (Especially #4, IMHO), so I am sharing.

image

(Example of #4...Bad Developer...bad developer)

If you want to add to this list, please feel free to post in the response section of this blog.

Subscribe to Sheltonblog.com

↑ Grab this Headline Animator

 

Here's the list:

  1. Trust User Input at Your Own Peril
  2. Protect Against Buffer Overruns
  3. Prevent Cross-site Scripting
  4. Don't Require sa Permissions
  5. Watch that Crypto Code!
  6. Reduce Your Attack Profile
  7. Employ the Principle of Least Privilege
  8. Pay Attention to Failure Modes
  9. Impersonation is Fragile
  10. Write Apps that Non-admins Can Actually Use!

To see the full article (Written by: Michael Howard and Keith Brown): Click here

~Robert Shelton

Technorati Tags: