Security
Keeping the wrong people out, the right people in, and the data safe in between.
Security is not a separate phase you add at the end. Most of it is ordinary engineering done carefully: storing passwords properly, checking permissions on every request, not logging secrets. The advanced material (threat modeling, zero trust, compliance) builds on those habits rather than replacing them.
Topics
- Authentication & Authorization
Proving who someone is, then deciding what they're allowed to do.
49 concepts
- Web Application Security
The vulnerabilities attackers actually exploit in web apps, and how to prevent them.
36 concepts
- Cryptography Basics
Hashing, encryption and signatures: what to use, and never building your own.
18 concepts
- Secure Development
Building security into how software is written, built and shipped.
26 concepts
- Privacy & Compliance
Personal data, regulations, audits and licenses.
16 concepts