Loren Kohnfelder, Designing Secure Software: A Guide for Developers (Book Review)

This is a great read for software developers that want to write more secure code. Above all, there is one central principle: Trust your framework (Rails, Django, .NET). If you are building your CSRF controls yourself, for instance, you're probably doing it wrong. You should get a lot of controls right out of the box (unless you're failing to upgrade the version of your framework . . .).

One thing I especially liked was Chapter 12, which provides guidance for automated security tests. Basically, your test-driven-development practices should also create tests for security.

The book is quite good on what constitutes a security design review (SDR) document, and also goes over some of the tone a good security engineer should use when communicating with development teams: The author says that you should provide options. Exactly so.

The book goes into some detail for problems like XSS and CSRF, but I think the book is going to be updated periodically to provide insights into the problems du jour. For instance, just in the last couple of years, CSPs have become more important, as well as the whole process of ensuring secure authentication and authorization (e.g., how to use your JWTs properly).

Another thing missing here is the whole ecosystem of tooling. It's pretty clear that the author didn't want to mention specific vendors, but in this book you'd never know that a lot of automation exists (e.g., dependency checkers like Dependabot; SAST tools like Semgrep; etc.).

Originally reviewed on Goodreads on 17 December 2023.

Comments