Security Fundamentals: Building Secure Foundations
Security isn't something you add later—it's a foundation you build from day one. Every product needs basic security practices, regardless of size.
The Security Mindset
Security is about:
Protecting user data : Their information is your responsibilityPreventing breaches : One breach can destroy trustCompliance : Many industries have legal requirementsBusiness continuity : Security incidents disrupt operations
Authentication and Authorization
Authentication (Who Are You?)
Verify users are who they claim to be:
**Best Practices**:
Strong passwords : Enforce complexity requirementsPassword hashing : Use bcrypt, Argon2, or similar (never plain text)Multi-factor authentication (MFA) : Add second factor for sensitive operationsSession management : Secure session tokens, proper expiration
**Common Mistakes**:
Storing passwords in plain text Weak password requirements No rate limiting on login attempts Session tokens that never expire
Authorization (What Can You Do?)
Control what authenticated users can access:
**Principles**:
Least privilege : Users get minimum access neededRole-based access control (RBAC) : Assign permissions by roleResource-level permissions : Check permissions for each resource
**Implementation**:
```
// Bad: Trust client
if (user.isAdmin) {
deleteUser(userId);
}
// Good: Verify on server
if (user.isAdmin && canUserDelete(user, userId)) {
deleteUser(userId);
}
```
Input Validation and Sanitization
Never trust user input:
Validation
Check that input meets requirements:
Type checking : Ensure strings are strings, numbers are numbersLength limits : Prevent buffer overflowsFormat validation : Email addresses, phone numbers, etc.Business rules : Values make sense in context
Sanitization
Clean input to prevent injection attacks:
SQL injection : Use parameterized queriesXSS (Cross-Site Scripting) : Escape HTML, use CSP headersCommand injection : Don't execute user input as commands
**Example**:
```
// Bad: SQL injection risk
query = "SELECT * FROM users WHERE id = " + userId;
// Good: Parameterized query
query = "SELECT * FROM users WHERE id = ?";
db.query(query, [userId]);
```
Data Protection
Encryption
**At Rest**: Encrypt data in databases, file storage
Use database encryption features Encrypt sensitive files Protect backup data
**In Transit**: Use HTTPS/TLS
Always use HTTPS in production Enforce HTTPS (redirect HTTP) Use strong TLS versions (1.2+)
Secrets Management
Never hardcode secrets:
Environment variables : For configurationSecret managers : AWS Secrets Manager, HashiCorp VaultRotate regularly : Change secrets periodically
**What to protect**:
API keys Database passwords Private keys OAuth secrets
API Security
Rate Limiting
Prevent abuse and DoS attacks:
Limit requests per IP/user Different limits for different endpoints Return 429 (Too Many Requests) when exceeded
API Keys and Tokens
**API Keys**: For server-to-server communication
Store securely Rotate regularly Scope to specific permissions
**JWT Tokens**: For user authentication
Use short expiration times Include user ID and permissions Sign with strong secret Validate on every request
CORS (Cross-Origin Resource Sharing)
Control which domains can access your API:
Restrictive : Only allow your frontend domainNo wildcards : Don't use `*` in productionCredentials : Only allow when necessary
Dependency Security
Keep Dependencies Updated
**Why**: Vulnerabilities are discovered regularly
**How**:
Use dependency scanning tools Update regularly (monthly) Test updates before deploying Monitor security advisories
**Tools**:
npm audit : Built into npmSnyk : Comprehensive vulnerability scanningDependabot : Automated dependency updates
Minimize Attack Surface
Only install what you need : Fewer dependencies = fewer vulnerabilitiesRemove unused dependencies : Regular cleanupUse trusted sources : Official packages, verified publishers
Infrastructure Security
Network Security
Firewalls : Restrict access to necessary portsVPC : Isolate resources in private networksWAF : Web Application Firewall for HTTP traffic
Access Control
SSH keys : Use keys, not passwordsIAM : Principle of least privilegeMFA : Require for admin accessAudit logs : Track who accessed what
Monitoring and Alerting
Log security events : Failed logins, permission denialsAlert on anomalies : Unusual patterns, spikes in errorsIncident response plan : Know what to do when something happens
Compliance Basics
GDPR (EU)
If you handle EU user data:
Right to access : Users can request their dataRight to deletion : Users can request data removalData portability : Users can export their dataPrivacy policy : Clear, understandable
SOC 2
For B2B SaaS:
Security controls : Documented and testedAccess controls : Who can access whatMonitoring : Logging and alertingIncident response : Plan and procedures
HIPAA (Healthcare)
If you handle healthcare data:
Encryption : Required for PHIAccess controls : Strict authenticationAudit logs : Track all accessBusiness Associate Agreements : With vendors
Security Checklist
Development
Input validation on all user inputs
Parameterized queries (no SQL injection)
Output encoding (prevent XSS)
Authentication on all protected routes
Authorization checks for all operations
HTTPS in production
Secrets in environment variables
Dependencies updated and scanned
Infrastructure
Firewall rules configured
Database encrypted at rest
Backups encrypted
Access logs enabled
Monitoring and alerting set up
Incident response plan documented
Operations
Security updates applied regularly
Access reviewed periodically
Secrets rotated regularly
Security incidents documented
Team trained on security practices
Common Vulnerabilities
OWASP Top 10
Injection : SQL, NoSQL, OS command injectionBroken Authentication : Weak passwords, session managementSensitive Data Exposure : Unencrypted data, weak encryptionXML External Entities : XXE attacksBroken Access Control : Missing authorization checksSecurity Misconfiguration : Default settings, exposed servicesXSS : Cross-site scriptingInsecure Deserialization : Remote code executionUsing Components with Known Vulnerabilities : Outdated dependenciesInsufficient Logging : Can't detect or investigate attacks
Incident Response
When something goes wrong:
Contain : Stop the attack, isolate affected systemsAssess : Understand what happened, what data was accessedNotify : Inform affected users, authorities if requiredRemediate : Fix vulnerabilities, restore systemsLearn : Post-mortem, improve processes
Conclusion
Security is a foundation, not a feature:
Build it in from day one Keep dependencies updated Monitor and alert Have an incident response plan
At Fundare, we help teams build secure foundations from the start. The goal isn't perfect security—it's good enough security that protects users and your business without slowing development.
Remember: Security is everyone's responsibility, not just the security team's.