Review cards · 17 cards
Security
Authentication and authorization, tokens and cookies, TLS between services, secrets, encryption and abuse.
Cards
- Checking who is calling is _____; checking what that caller is allowed to do is _____.
- Anyone holding a signed JWT can read its claims: the payload is only _____-encoded, not encrypted. The signature proves the claims were not _____.
- A thumbnail worker reads uploaded images and writes thumbnails to the same bucket. Which permissions follow least privilege?
- Why is an app that authenticates with a session cookie exposed to CSRF, while one that sends a bearer token in the Authorization header is not?
- The cloud database encrypts its disks at rest with a managed key. Which attack does that stop?
- Private files are shared through signed download URLs. A link gets posted publicly. What limits the damage best?
- Logins are limited to 5 attempts a minute per account. How long would one attacker need to try 1 million passwords against a single account?
- What does mutual TLS between internal services add over ordinary TLS, and what does it cost?
- Why does a mobile app or single-page app use the OAuth authorization code flow with PKCE?
- How should a service get its database password, and how do you rotate it without downtime?
- Where should a browser app keep its session token, and with which cookie flags?
- A login endpoint limits each IP address to 10 attempts a minute. A botnet with 10,000 IP addresses runs a credential-stuffing attack. How many attempts an hour can it make?
- What is envelope encryption with a KMS, and why not send all the data to the KMS to encrypt?
- An API already requires idempotency keys. Does that protect it against an attacker replaying a captured request?
- A service receives a JWT whose header says "alg": "none". What should it do?
- A user logs out or is banned, but their JWT access token is still valid for an hour. Why can't you just revoke it, and what are the options?
- A "link preview" feature makes the server fetch any URL a user pastes. What is the main risk?
More topics
- Estimation 21 cards
- Networking 16 cards
- API design 17 cards
- Caching 21 cards
- Databases 22 cards
- Replication 15 cards
- Sharding 18 cards
- Consistency 19 cards
- Queues 18 cards
- Streaming 18 cards
- Availability 14 cards
- Resilience 16 cards
- Storage 14 cards
- Realtime 15 cards
- Data structures 16 cards
- Observability 18 cards
- Coordination 16 cards