
PagerDuty’s Security Training for Engineers, Penultimate
Coding Blocks
00:00
Getting Cryptographicly Strong Random Values for Tokens
The idea is to make it easy for web crawlers to change a state of the site. The tokens should be cryptographically strong random values, so that they can't be guessed. There are libraries in most major platforms for getting a truly Cryptographic Strong Random value. A lot of these frameworks and engines already have anti-forgery settings built in.
Transcript
Play full episode