Error handling should fail predictably
What an application does when something goes wrong is a security decision.
Returning a stack trace hands out internals. Failing in a way that skips the check is worse. Differing responses for a wrong password and an unknown user leak which accounts exist. The rule is to fail closed, consistently, and say as little as the situation allows without making it impossible to debug.
More on Secure development
- Threat modelling asks how a design can fail before code existsBreak it on paper first
- Input validation defines what the application acceptsOne shape fits
- Security requirements are product requirementsThey go on the same sheet
- Code review and automated scanning see different risksThe magnet and the eye
- Security tests should exercise abuse casesThe load nobody specified
- Feature flags can become security statesSomebody left it up
