Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
••
IT NachrichtenMicrosoft puts Brad Smith in charge of communications(25.09.2026 um 00:08 Uhr)
••
IT Nachrichten25. September(25.09.2026 um 00:05 Uhr)
•
IT NachrichtenCI-Solution GmbH von Crossware übernommen(25.09.2026 um 00:01 Uhr)
•
IT NachrichtenInsta360 GO Ultra erhält KI-Sprachassistenten mit Gemini(24.09.2026 um 21:30 Uhr)
••
AI & KI NachrichtenMaryland Governor Draws New Boundaries for Data Centers(25.09.2026 um 00:04 Uhr)
••••
IT NachrichtenMicrosoft puts Brad Smith in charge of communications(25.09.2026 um 00:08 Uhr)
••
IT Nachrichten25. September(25.09.2026 um 00:05 Uhr)
•
IT NachrichtenCI-Solution GmbH von Crossware übernommen(25.09.2026 um 00:01 Uhr)
•
IT NachrichtenInsta360 GO Ultra erhält KI-Sprachassistenten mit Gemini(24.09.2026 um 21:30 Uhr)
••
AI & KI NachrichtenMaryland Governor Draws New Boundaries for Data Centers(25.09.2026 um 00:04 Uhr)
••
Intelligence View
⚡ tsecurity.de Intelligence

Building Secure Systems for Modern Applications

The importance of secure authentication in modern applications has grown exponentially in the last decade and continues to rise. The security of your personal information, private messages, photos, contacts, bank transactions, and much…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

The importance of secure authentication in modern applications has grown exponentially in the last decade and continues to rise. The security of your personal information, private messages, photos, contacts, bank transactions, and much more is at stake whenever you use any online service. While some corporations build their income on top of security, the vast majority of companies, regardless of size, are susceptible to cyber threats, as demonstrated by the recent increase in data breaches.



In this series of articles, I will cover various approaches to storing users' credentials and create a small, yet secure, application to demonstrate them. Rather than targeting a general audience, these articles are aimed at architects and developers, for whom they will be exceptionally useful.



The technology stack I've chosen is fairly standard – PostgreSQL, Java with Spring, and Angular. While these technologies are popular, the concepts and approaches discussed in the series can apply to any modern stack.






Key Concepts



Before we move on, let's refresh some key knowledge:



Authentication is the process of verifying the identity of a user or system. For example, when a user signs in, the system checks if the credentials are correct.



Authorization, on the other hand, is the process of determining the user's or system's permissions. For example, a signed-in user might be able to view and edit their own data if they're a "regular" user, or edit anyone's data if they have "elevated" permissions.



While these processes are often discussed together, they're distinct and entirely different, although interconnected. To use an analogy, if this were a concert, authentication would be the validation of your ticket, and authorization would be moving to your assigned seating zone.






The Role of Authentication & Authorization



Setting aside intentional data leaks, where someone with access to user data "dumps" or exports it, the majority of breaches occur due to poor authentication or authorization practices, whether it's weak password policies, outdated cryptographic algorithms, or what's commonly called "Broken Access Control" [link to OWASP].



To mitigate some of these vulnerabilities, weak passwords can be addressed by implementing Multi-Factor Authentication (MFA), also known as the "six-digit code from an email or app," which can be easily integrated into systems of any size.



Commonly used authorization models include:





  • Role-Based Access Control (RBAC): Pre-defined user roles and their access scope.


  • Attribute-Based Access Control (ABAC): Access is granted based on various attributes such as device type, user group, or file type.


  • Discretionary Access Control (DAC): Provides granular permissions with flexibility in exchange for increased complexity.






Modern Approaches



One of today's techniques to secure authentication and minimize data leakages is using advanced hashing algorithms like bcrypt and Argon2 for secure password storage and to prevent brute force attacks. These algorithms are computationally intensive, requiring a substantial amount of power to encrypt passwords, but also making brute force attacks against the resulting hashes extremely difficult – potentially taking days or even years to decrypt a single password with cutting-edge technologies.



As mentioned earlier, MFA mitigates the risks of weak cryptography by requiring users to provide a "second factor" for signing in. The first factor is something the user knows – their password. The second factor is something they possess, such as a trusted device, a smartphone with an app, or a secure token. But we'll get to that later in the series.






Improved Approach



Server-side password hashing is good enough to protect user accounts in case the database gets leaked, but we can enhance security tenfold by implementing the zero-knowledge approach. This improvement is why our app will be called "Knox."






Series Roadmap



In the following articles, I will describe in detail and implement:





  • Database design to store and manage user accounts


  • Classic approach to password storage


  • Frontend application (because an API alone won't cut it)


  • RBAC with Spring


  • Improved approach to password storage



After we've laid the groundwork, we'll dive into more advanced topics like:





  • MFA, with proper time-based implementation


  • WebAuthn, for a cutting-edge authentication flow


  • OAuth2, to implicitly sign users up



By following the series, you'll not only gain a fully functional backend with a GitHub repository included but also priceless knowledge. As a bonus, you'll have a neatly designed frontend with a wonderful user experience, crafted especially for this series by a friend of mine Andrii.

CTI Threat Relationship Graph2 Knoten / 1 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
SOC Incident Playbook: Remote Code Execution (RCE) Defense
Syntax validiert (0 Fehler)
title: Detect Exploitation - Building Secure Systems for Modern Applications
id: 454c4078-73b0-4144-8447-9b807b178f71
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
  - https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-25
logsource:
  category: network_connection
  product: any
detection:
  selection:
      CommandLine|contains:
        - 'exploit'
  condition: selection
falsepositives:
  - Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
  - attack.initial_access
Syntax validiert (0 Fehler)
rule CTI_Threat_Indicator {
    meta:
        author = "iShareStuff CTI Automated Detection Engine"
        date = "2026-09-25"
        description = "YARA Signature for "
    strings:
        $str = "Building Secure Systems for Mo" ascii wide
    condition:
        any of them
}
Syntax validiert (0 Fehler)
index=security sourcetype IN ("cisco:asa", "pan:traffic", "zeek_conn", "suricata", "WinEventLog:Security")
("Building Secure Systems for Modern Appli")
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip, dest_ip, dest_host, signature
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
| sort - count
Syntax validiert (0 Fehler)
message: "*Building Secure Systems for Modern Appli*"
Syntax validiert (0 Fehler)
CommonSecurityLog
| where Message has "Building Secure Systems for Modern Appli"
| summarize EventCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by SourceIP, DestinationIP, DestinationPort, Activity
| extend DetectionRule = "iShareStuff-CTI-Compiled"
| sort by EventCount desc
🎯
MITRE ATT&CK Matrix Navigator 14 Taktiken
Reconnaissance
-
Resource Development
-
Initial Access
Execution
Persistence
-
Privilege Escalation
Defense Evasion
Credential Access
-
Discovery
-
Lateral Movement
-
Collection
-
Command and Control
Exfiltration
-
Impact
tsecurity.de Cognitive Threat RAG
Fokus-Vektor:

Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich Building Secure Systems for Modern Appli.... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.

🛡️ Angriffsfläche & Exposure

Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.

⚡ Empfohlene Sofortmaßnahmen
  • 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
  • 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
  • 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
🔗 Semantisch verwandte Zero-Days MariaDB 11.7 VEC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Building Secure Systems for Modern Applications

Thematisch verwandte Begriffe: Building, Secure, Systems, Modern · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-82585 | The Botslab G980H dash camera firmware transmits sensitive information o…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel • Rechts: nächster Artikel • unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel TTP ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...
↗ Original-Quelle