Security and Serverless

It’s just a different set of issues — but I prefer the security problems I have with serverless than the old ways

The intent is to start discussion, so comment/reply as I’m interested to see the opinions of others

Bad code is still bad code

There’s still a server (but it’s ok!)

Use an API Gateway

SQL injection is still a problem

Learn how to use the permissions (properly!)

Permissions for users/roles

Data, Keys and Secrets


What has this got to do with serverless?

This article is not definitive



