Added by thopro, last edited by thopro on Sep 03, 2008  (view change)

Labels:

Enter labels to add to this page:
Wait Image 
Looking for a label? Just start typing.

Describe concepts like defence in depth, whitelisting, risk management, assurance etc.

Whitelisting versus blacklisting

You should always define what you will accept, not what you won't accept. The latter strategy can not be exhaustive and it is easy to make mistakes. Whitelisting on the other hand specifies exactly what you accept. This strategy can be found in input validation, web server hardening etc.

The security craftsman, interesting and readable blog series by Erlend Oftedal on several security/injection practices.

All content on this wiki is licensed under a Creative Commons Attribution 3.0 Unported License.