vault backup: 2022-07-29 13:43:29

This commit is contained in:
Jet Hughes 2022-07-29 13:43:29 +12:00
parent 7b7a456921
commit ed73da6ca6

View File

@ -41,4 +41,12 @@ tags:
- one is useless without the other - one is useless without the other
- many security vulnerabilities are caused by inexperienced/incompetent programmer creating systems that only have one or the other - many security vulnerabilities are caused by inexperienced/incompetent programmer creating systems that only have one or the other
- authenticaion without authorisation can lead to *path traversal* flaws - authenticaion without authorisation can lead to *path traversal* flaws
- authorisation without authenticaion is the equivalent of blindly trusting your users. - changing the url path to find admin sites
- authorisation without authenticaion is the equivalent of blindly trusting your users.
# Passwords
- not good
- lots of bad advice
- we are lazy
- "safe" passwords are difficult to enter on touch screen devies
- to many accouts