search

Web applications have proven to be vulnerable to attacks from different sources, though, and it is our responsibility to safeguard our data. This article will help you develop a secure ASP.NET Core MVC web application.

Bharat Dwarkani shared on Dec 17, 2019
image
syncfusion.com
bookmarks
share
favorite_border0 visibility31
favorite_border0 visibility31 share bookmarks

In this article, we are going to learn about the ASP.NET Core built-in data protection mechanism, IDataProtector, which we can use to encrypt and decrypt our sensitive data.

Bharat Dwarkani shared on Nov 25, 2019
image
code-maze.com
bookmarks
share
favorite_border0 visibility47
favorite_border0 visibility47 share bookmarks

An Open Redirection is when a web application or server uses a user-submitted link to redirect the user to a given website or page.

Bharat Dwarkani shared on Nov 24, 2019
image
sagarjaybhay.com
bookmarks
share
favorite_border0 visibility0
favorite_border0 visibility0 share bookmarks

Learn how to build Web APIs with the new ASP.NET Core 3.0 and how to secure them with Auth0 authentication and authorization features.

Bharat Dwarkani shared on Oct 19, 2019
image
auth0.com
bookmarks
share
favorite_border0 visibility25
favorite_border0 visibility25 share bookmarks

You might have noticed the recent public discussions around how to securely build SPAs – and especially about the “weak security properties” of the OAuth 2.0 Implicit Flow.

Bharat Dwarkani shared on Oct 10, 2019
image
leastprivilege.com
bookmarks
share
favorite_border0 visibility23
favorite_border0 visibility23 share bookmarks

This article shows how Vue.js can be used together with ASP.NET Core 3 in a single project. The Vue.js application is built using the Vue.js CLI and built to the wwwroot of the ASP.NET Core application. The ASP.NET Core application is used to implement the APIs consumed by the Vue.js UI. The application is secured using a separate secure token server, implemented using IdentityServer4 hosted in an ASP.NET Core 3 application.

Bharat Dwarkani shared on Oct 07, 2019
image
damienbod.com
bookmarks
share
favorite_border0 visibility13
favorite_border0 visibility13 share bookmarks

In this article, you will learn about ASP.NET Core security headers.

Bharat Dwarkani shared on Sep 25, 2019
image
c-sharpcorner.com
bookmarks
share
favorite_border0 visibility6
favorite_border0 visibility6 share bookmarks

In the IdentityServer world authorization code with PKCE now replaces OpenID Connect's (OIDC) hybrid flow as our most secure authorization method; however, not all client libraries or even OpenID Providers support PKCE yet. An alternative approach that gives a comparatively high level of assurance is to use the OIDC hybrid flow in combination with encrypted identity tokens via JSON Web Encryption (JWE).

Bharat Dwarkani shared on Sep 15, 2019
image
scottbrady91.com
bookmarks
share
favorite_border0 visibility8
favorite_border0 visibility8 share bookmarks

assword Authenticated Key Exchange (PAKE) is one of those odd protocols that sounds like a great idea, but one that no one seems to be using. Even then, it seems no one can agree upon a good implementation. Secure Remote Password (SRP) is the most common implementation, found in use by Apple and 1Password; however, it is far from perfect.

Bharat Dwarkani shared on Sep 15, 2019
image
scottbrady91.com
bookmarks
share
favorite_border0 visibility4
favorite_border0 visibility4 share bookmarks

Quick basic .NET security tips for developers.

Bharat Dwarkani shared on Sep 05, 2019
image
github.com
bookmarks
share
favorite_border0 visibility6
favorite_border0 visibility6 share bookmarks
add