Jim Manico

Results 64 issues of Jim Manico

We're not discussing login throttling as a way to stop detected automated login attacks, and yet, tbis is the most important dedense.

ACK_OBTAINED
UPDATE_CS
HELP_WANTED

We should create a function to safely embed JSON on a webpage simular to to what https://github.com/yahoo/serialize-javascript accomplishes.

enhancement

2.4.4 recommends bcrypt wf 10 (thats ok) but does not mention the 72 byte limit

Discussion ongoing
Needs wider input

2.3.3 is not clear in terms of what we need to review for it. Please add more clarify to this requirement!!

help wanted
Discussion ongoing
5.0
owasp_class_hel
Needs wider input

Discussion ongoing
5.0
owasp_class_hel

10.1.1 | Verify that a code analysis tool is in use that can detect potentially malicious code, such as time functions, unsafe file operations and network connections. -- | --

owasp_class_hel

13.2.6 | Verify that the message headers and payload are trustworthy and not modified in transit. Requiring strong encryption for transport (TLS only) may be sufficient in many cases as...

owasp_class_hel

I think the following objectives are too role-centric, Roles are just one paradigm. Change: * Users are associated with a well-defined set of roles and privileges. * Role and permission...

owasp_class_hel

I suggest we have a CSP requirement that moves folks away from allow-lists to a nonce or hash strict-dynamic policy (CSP3 stuff) which is much easier to deploy and more...

1) Discussion ongoing
_5.0 - prep
Community wanted
V50

8.3.6 | Verify that sensitive information contained in memory is overwritten as soon as it is no longer required to mitigate memory dumping attacks, using zeroes or random data. --...

5.0