

Secure By Design
S**D
I honestly didn't expect to learn as much as I did
This book overdelivered.I didn't realize that logging required UX design just as much as front-end applications.Read-once objects will definitely be in my arsenal for protecting passwords and secrets.I never considered logging to include semantic versioning, service ids, and trace ids.The types of invariant validations were also interesting as well as how they should be staged.I highly recommend this book.
A**Z
Great Book to read for those looking to improve their programming skills
The Author focuses on things that should be second nature to all developers but they are not. If the techniques presented in this book are considered from the initial design of any software we would all end up with secure easy to understand code. I am almost done reading the book and I have loved it so far.. Most likely I will re read some of the chapters again so I can engraved their content on my mind.
D**Y
Love this book!
This book is a must read for any computer science student who wants to design secure code.
A**A
Not just security, but one of the best books on Domain Driven Design
I've read many books on Domain Driven Design, but this one is by far second only to the original by Eric Evans. When I purchased this book, back in 2019, I purchased it with the goal of learning about writing secure code, never once thinking it had anything to do with DD and that it would change the way I code forever. Unfortunately the book sat on my shelf for years, but I'm glad I picked it up and started reading it. It's great.
P**T
Good lessons in writing decent code
Really solid set of principles to help reduce bugs in code, and thus reduce security concerns overall. Don’t get this expecting to deep dive into methodologies used to _exploit_ insecure code, rather more a compendium of patterns and strategies software engineers should _already be using_ that lead to a more reliable code base. The book leans fairly heavily on domain drive design concepts, but includes enough of a basic background to not require much, if any, pre-existing subject knowledge of the reader. It has a habit of, in my opinion, relying too heavily on Java-flavored example code to showcase some of its patterns, rather than forming a more complete conceptual model - but pragmatically this approach is likely to be more effective at point making than a more CS focused one. Overall a good read with valuable lessons, especially for engineers not already prone to doing “the right thing.”
T**M
Yeah 🙌
Like it
Trustpilot
5 days ago
2 weeks ago
1 week ago
1 day ago