Hi, my name Gon. I'm from Indonesia. I've been trying to build some web app and I'm almost finished. But, I worrying about the security of my web app. I'm curious how you guys, every indiehacker, prevents your web app from hackers? Thanks
Host with a cloud host, like Heroku, to avoid having to constantly monitor/patch your system for 0day vulnerabilities
Subscribe to 0day mailing lists for your tech stack of choice. e.g. google "python flask 0day mailing list" and subscribe the Google groups.
Backup all your user data offsite.
If you don't know what you're doing, delegate payments to someone who does, like Stripe.
Use CloudFlare for an easy and free SSL certificate. Force HTTPS.
Read up on SQL injections. Avoid those.
Read up on XSS. Sanitize user input before displaying on screen.
Use middleware to rate limit the number of login attempts per hour.
Thanks, very useful
Thanks for your feedback. Wow i gain a lot knowledge just ask in indiehackers comunity. Thanks guys
A checklist to not get lost:
https://git.io/security
Thankyou
Hi Gon,
That's a good thing to worry about!
What you can do will depend on the tech you use to build your site, but here is what I do (mine is made with ruby on rails):
be aware of the main attack vectors: http://guides.rubyonrails.org/security.html It may seem a tad boring to read through, but is very well explained. You should be able to find a similar page for your own stack. Rails cast also has an old but good 'n short video on this: http://railscasts.com/episodes/178-seven-security-tips
use tools that scan your app for potential vulnerabilities: https://brakemanscanner.org or https://hakiri.io/
have your app hosted in a platform that doesn't require work from me such as Heroku. I wouldn't yet host it on aws yet for instance, as I wouldn't be sure that my instance can't be hacked.
There are surely many other things that needs to be done, but that's a good start.
All in all, it is definitely good to do that as you build the app, not as an afterthought once it is done. But "the second best time to plant a tree is now", right?
Can you maybe share your app here, or your tech stack?
Youre right. Thankyou gui. My app not finished yet,i planning build simple crm,based my background around 3 year as hustle. My stack is python+flask framework. I been learning python for 1 year. Thank you for your feedback😄
Great comments from other contributors here.
It's good that you're worrying about this; a CRM system definitely classifies as containing Personally Identifiable Information so depending on your market, there are some relatively hefty downsides to losing the data.
I'd add to what CodeForCash said - there's literally no reason to handle credit card data yourself unless you have insanely high transaction volumes. Use Stripe (or an equivalent, depending on geography).
Oh and encrypt your backups - they're just as valuable as the running system (then test them and make sure you can restore from them!)
Yes,i think in crm app,i will managing less sensitive data but valuable data. So backup is important. Thanks
What does your application do? If you're not dealing with sensitive customer data, then I would recommend ignoring security for now, so you have more time to focus on finding customers.
In past i'm planning build password manager web app,but i fell afraid managing sensitive data as single founder. Now i'm build simple crm,and i think will manage less sensitive data. Thankyou for your feedback