
Alice and Bob Learn Secure Coding
by Tanya Janca
1st Edition
Publisher: John Wiley & Sons P&T
Book Details
| Print ISBN | 9781394171705 |
| eText ISBN | 9781394171712 |
| Publisher | John Wiley & Sons P&T |
| Publishing Year | 2025 |
| Edition | 1st Edition |
| Language | English |
| Pages | 416 |
Alice and Bob Learn Secure Coding, 1st Edition, authored by Tanya Janca, is a 2025 textbook published by John Wiley & Sons P&T that introduces application security fundamentals and defensive software practices. The volume addresses the industry need for embedding security directly into development workflows across modern software teams.
The core coverage moves through the Secure System Development Life Cycle, guiding readers through threat modeling, security requirements, code reviews, and security testing. It provides concrete security patterns for programming languages including Python, Java, JavaScript, C/C++, SQL, C#, and PHP, as well as web frameworks like Angular, Express, React, .NET, and Spring.
To clarify core security concepts, the text utilizes character stories featuring Alice and Bob alongside diagrams, analogies, and real-life examples. This format supports software developers of all experience levels, software architects, project managers, and budding security engineers seeking practical application security knowledge.
Table of Contents
Chapter 1: Introductory Security Fundamentals
- • Assume All Other Systems and Data Are Insecure
- • The CIA Triad
- • Least Privilege
- • Secure Defaults/Paved Roads
- • Assume Breach / Plan For Failure
- • Zero Trust
- • Defense in Depth
- • Supply Chain Security
- • Security by Obscurity
- • Attack Surface Reduction
- • Usable Security
- • Fail Closed/Safe, Then Roll Back
- • Compliance, Laws, and Regulations
- • Security Frameworks
- • Learning from Mistakes and Sharing Those Lessons
- • Backward Compatibility (and Potential Risks It Introduces)
- • Threat Modeling
- • The Difficulty of Patching
- • Retesting Fixes for New Security Bugs
- • Chapter Exercises
Chapter 2: Beginning
- • Follow a Secure System Development Life Cycle
- • Use a Modern Framework and All Available Security Features Within
- • Input Validation
- • Output Encoding
- • Examples of Output Encoding
- • HTML Context
- • JavaScript Context
- • Parameterized Queries and ORMs
- • Authentication and Identity
- • Authorization and Access Control
- • Access Control Models
- • Logical Access Control Methods (Implementation)
- • Session Management
- • Secret Management
- • Password Management
- • Communication Security (Cryptography and HTTPS Only)
- • Protecting Sensitive Data
- • Security Headers
- • New Security Header Features
- • Fetch Metadata Request Headers
- • Content Security Policy Header
- • Strict-Dynamic
- • Trusted-Types
- • Security Headers Previously Covered
- • Content-Security-Policy Header
- • HTTP Strict-Transport-Security
- • X-Frame-Options
- • X-Content-Type-Options
- • Permissions Policy
- • Expect-CT
- • Referrer-Policy
- • Public Key Pinning Extension for HTTP (HPKP)
- • X-XSS-Protection
- • More New Headers
- • Same-Origin Policy
- • COEP: Cross-Origin Embedder Policy
- • COOP: Cross-Origin Opener Policy
- • CORP: Cross-Origin Resource Policy
- • CORS: Cross-Origin Resource Sharing
- • CORB: Cross-Origin Read Blocking
- • Secure Cookies
- • Error Handling
- • Chapter Exercises
Chapter 3: Improving
- • Database Security
- • Four Perspectives for Protecting Databases
- • File Management
- • File Uploads
- • Your Source Code
- • Memory Management (Buffer, Stack, String, and Integer Overflows)
- • How Do We Avoid Overflows?
- • (De)Serialization
- • Privacy (User/Citizen/Customer/Employee)
- • Errors
- • Logging, Monitoring, and Alerting
- • Fail Closed
- • Locking Resources
- • Enabling Password Managers
- • Cryptographic Practices
- • Strongly Typed Languages
- • Weakly Typed Programming Languages
- • Domain-Driven Development
- • Memory-Safe Languages
- • Chapter Exercises
Chapter 4: Achieving
- • Secure Design
- • How much is “enough” (design) security?
- • Dependency Management and Supply Chain Security
- • Dependency Security
- • Checking If Dependencies Are Safe to Use
- • Supply Chain Security
- • Secure Defaults
- • Secure Defaults for Users
- • Secure Defaults for Developers
- • Readable and Auditable Code
- • Important Functions Happen on Trusted Systems
- • What Is an “Untrusted” System?
- • What Are “Important Functions”?
- • Putting It Together
- • Allowlists versus Blocklists
- • Why Are Block Lists Bad?
- • How Do We Create an Allowlist?
- • Secure Configurations
- • Hostname Validation
- • Reusable Code
- • Safe System Calls
- • Mitigating Circumstances
- • Commenting and Other Documentation
- • Comments
- • Documentation
- • Verification of User Consent
- • Integrity Checks, Code Signing, and Immutable Builds
- • Immutable Builds
- • Avoiding Brute Force
- • Security Controls
- • Handling Elevated Privileges
- • Security Maintenance
- • Repaying Technical Debt
- • Chapter Exercises
Chapter 5: Technology-Specific
- • API Security Best Practices
- • Mobile Application Security Best Practices
- • WebSocket Security Best Practices
- • Serverless Security Best Practices
- • IoT Security Best Practices
- • Chapter Exercises
Chapter 6: Popular Programming Languages
- • JavaScript
- • Html/css
- • HTML5, Specifically
- • Python
- • Sql
- • Node.js
- • Java
- • Serialization in Java
- • TypeScript
- • C#
- • Php
- • C/c++
- • Conclusion
- • Chapter Exercises
Chapter 7: Popular Frameworks
- • Web and JavaScript
- • Express
- • React.js
- • Angular
- • jQuery
- • Vue.js
- • Other Frameworks and Libraries
- • .NET (Core)
- • Ruby on Rails
- • Spring and Spring Boot
- • Flask
- • Chapter Exercises
Chapter 8: Vulnerability Categories
- • Design Flaws / Logic Flaws
- • How Does This Happen?
- • The Risk
- • Prevention
- • Code Bugs / Implementation Errors
- • Overflows and Other Memory Issues
- • Overflows
- • Buffer Overreads
- • Invalid Page Faults
- • Use After Free
- • Uninitialized Variables
- • Memory Leaks
- • Injection: Interpreter and Compiler Issues
- • Input Issues
- • Authentication and Identity Issues
- • Authorization and Access Issues
- • Configuration and Implementation Issues
- • Fraudulent Transactions
- • Replay Attacks
- • Crossing Trust Boundaries
- • File Handling Issues
- • Object Handling Issues
- • Prominent Features of OOP
- • Deserialization and Other Object Handling Issues
- • Secrets Management Issues
- • Race Conditions and Timing Issues
- • Resource Issues
- • Falling into an Unknown State
- • Chapter Exercises
Chapter 9: Requirements
- • Project Kick-Off: Outline of Your Project’s Security Activities
- • Project Scheduling and Planning
- • Security Requirements
- • Chapter Exercises
Chapter 10: Design
- • Threat Modeling
- • Secure Design Patterns and Concepts
- • Architecture Whiteboarding
- • Examining Data Flows
- • Security User Stories
- • Chapter Exercises
Chapter 11: Coding
- • Training
- • Organizations
- • Individuals
- • Code Review
- • First- and Second-Generation Static Analysis Tools
- • Secure Guardrails
- • IDE Plugins and Other Guidance
- • Verifying That Your Dependencies Are Safe (SCA)
- • How Do You Decide Which Dependencies Are Worth Updating or Changing?
- • Finding and Managing Secrets
- • Dynamic Testing (DAST)
- • Chapter Exercises
Chapter 12: Testing
- • Test Coverage and Timing
- • Depth Versus Coverage
- • Scanning Your Infrastructure
- • Production or Lower-Level Environments
- • Scoping
- • Timing
- • Manual Testing
- • Automated Testing
- • Fuzzing
- • Interactive Application Security Testing (IAST)
- • Bug Bounty Programs
- • Test Results
- • Actioning Test Results
- • Final Thoughts
- • Chapter Exercises
Chapter 13: Release/Deployment
- • Security Events Within the CI/CD
- • Breaking the Build
- • Secret Scanning
- • Static Analysis
- • Dynamic Analysis
- • Software Composition Analysis
- • Linting
- • Infrastructure as Code scanners
- • Securing the CI/CD Pipeline Itself
- • Assuring the Integrity of Your Release
- • Security Release Approval
- • Chapter Exercises
Chapter 14: Maintenance
- • Monitoring, Alerting, and Observability
- • Blocking/Shielding
- • Web Application Firewalls (WAFs)
- • Content Delivery Networks (CDNs)
- • Runtime Application Self-Protection (RASP)
- • Virtual Patching
- • API Gateways
- • A Special Note for Data Scientists
- • Continuous Testing
- • Security Incidents
- • Business Continuity and Disaster Recovery Planning
- • Chapter Exercises
Chapter 15: Conclusion
- • Good Habits
- • Your Responsibility
- • How Much Is Enough?
- • Using Artificial Intelligence Safely
- • Continuous Learning
- • Becoming a Champion
- • Getting Others on Board
- • Transitioning ont
Customer Reviews
0.0
0 reviews
No reviews yet. Be the first to review this book!
Write a Review
Reviewed by GradeFocus Editorial Team
▶Research Sources (14)
- Alice and Bob Learn Secure Coding, eBook by Tanya Janca ...
- Perusall
- Alice and Bob Learn Secure Coding [1 ed.] 1394171706, 9781394171705
- https://lernerbooks.com/products/search_results?se...
- Search result for "learning" (154)
- Alice and Bob Learn Secure Coding - Porrúa
- Please verify you are human - Captcha
- Alice and Bob Learn Secure Coding - Tanya Janca - Perlego
- Alice & Bob Learn Secure Coding 9781394171705
- Alice and Bob Learn Secure Coding: Chapter 1
- Alice and Bob Learn Secure Coding
- Alice and Bob Learn Secure Coding
- My review of Tanya's Alice and Bob learn Secure Coding
- 'Alice and Bob Learn' Book Series





