TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: Best (practical) books on web security?

10 点作者 ingvul将近 4 年前
I would like to learn more about topics like:<p>- DMZ<p>- bastion hosts (should we use them? Why or why not)<p>- ssh<p>- best practices<p>in the context of web development on the cloud. I&#x27;ve found a lot of material but they are very cloud-focused (aws&#x2F;gcp security, for example) or rely a lot on Kubernetes (which I&#x27;m not using). I&#x27;m a solo-developer maintaining a simple Saas and I would like to keep it (more) secure than it is right now.

2 条评论

ivanr将近 4 年前
You mention web security in the title and that normally means web application security, but the body of your question talks about network security. Which of the two do you care about more? There won&#x27;t be a book that covers both.<p>For network security—which is what I think you&#x27;re asking for—I think you will enjoy Practical Cloud Security, by Chris Dotson: <a href="https:&#x2F;&#x2F;www.amazon.com&#x2F;Practical-Cloud-Security-Secure-Deployment&#x2F;dp&#x2F;1492037516&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.amazon.com&#x2F;Practical-Cloud-Security-Secure-Deplo...</a>
mophose超过 3 年前
OWASP is a good place to start for Web application security