Lesson 1.35mIntermediate11.9k students
Secure defaults and least privilege
Most breaches exploit something that was left open rather than something clever. Default deny, then grant the narrow thing that is needed.
This lesson sits in Thinking About Threats, part of Practical Web Security. It assumes what came before it and leads directly into the next lesson in the module.
In this lesson you will
- Default to deny and grant explicitly
- Scope credentials to the minimum they need
- Reduce attack surface by removing unused paths
Resources
Your notes for this lesson will appear here.