Security Question of the Week, Websec Advice Edition

Jan 18, 2010

The question

Like last week’s question, this week’s is another “spot the bad advice” question — this time, ripped straight from the headlines.

“Security in Web Applications” are the slides from a presentation on web security given a couple weeks ago as part of MIT’s 6.470 Web Programming Competition. There is a lot of good advice in there — but unfortunately, there are also some reasonably significant problems. Spot them.

As always, the best answer(s) win the prize. Send them to me via email or on twitter — bonus points for impact, obscurity, irony, sangfroid, schadenfreude, and/or bonhomie. I’ll post the results here at the end of the week.