Practice · 4 min read
Threat modelling a payments flow in ninety minutes
Threat modelling gets skipped because it sounds like a two-day workshop. Here is the ninety-minute version, run on the flow that carries your money.
Blog
About this blog
This blog covers application security as it turns up in real assessments: mobile app hardening, API authorisation, web access control, cloud blast radius, secure coding practice and the compliance questions Indian product teams get asked. 18 posts, each dated and revised when the advice changes.
Practice · 4 min read
Threat modelling gets skipped because it sounds like a two-day workshop. Here is the ninety-minute version, run on the flow that carries your money.
API security · 3 min read
A four-digit OTP with a per-IP limit is not protected. It is protected against one attacker on one connection, which is not the attacker you have.
Mobile security · 3 min read
A mobile scanner report reads alarmingly and usually contains nothing severe. Everything severe requires a second account, a device and a person.
Practice · 3 min read
They answer different questions. Which one to buy depends on whether you need to know what an attacker can do today, or why it was possible in the first place.
Web security · 3 min read
Nobody attacks your login form. They attack the flow that issues credentials to whoever holds an email address — which is usually written once and never reviewed.
Secure coding · 3 min read
A forty-item security checklist gets ticked without being read. Seven questions, asked only when they apply, get answered honestly.
Scope and a fixed quote within two working days. First consultation is free.