Serverless security modeling in Firebase
Using secure design principles as our guide, we cover the default security of Firebase services and what developers need to do to configure and secure their applications. Walking through a simple serverless application built with Firebase backend products, we discuss different security threats, from malicious actors to user error. As we go, we build a checklist that you can use to audit your own app's security and protect yourself and your users. 00:00 Intro 02:39 Open source SDKs 03:35 DOS protection 06:39 API key management 08:11 Security Rules 12:23 Firebase Authentication 14:54 Anonymous Authentication 16:12 Limiting Team Access 17:27 Open source dependencies 18:58 Function Safety 20:34 Wrap up Resources: Pre-defined Firebase IAM roles: https://goo.gle/340cGPQ Attributes of Auth Tokens: https://goo.gle/2H25pGb Setting up Custom Auth with Okta: https://goo.gle/33VMbL6 Snyk: https://snyk.io/ and their NPM module: https://goo.gle/351N58a Cloud functions configuration options: https://goo.gle/2GRZPXc New features in Firebase Security Rules: https://goo.gle/2SQPE7A Upgrading to GCIP for MFA: https://goo.gle/3jZUWtk Authentication Limits: https://goo.gle/2TwDWPE Debug JWTs with https://jwt.io/ Firebase Security Checklist: https://goo.gle/3lQBekl Codelab: Local development with the Firebase Emulator Suite: https://goo.gle/2TsOzTK How to set up CI using the Firebase Emulator Suite: https://goo.gle/3otcnVJ Firebase Authentication: from fully managed to fully customizable: https://goo.gle/3kJpjEV How to turn on Billing and still sleep at night: https://goo.gle/2HEjYQC Speakers: Jon Skrip, Rachel Myers Watch more: Firebase Summit 2020 playlist → http://goo.gle/firebasesummit2020 Subscribe to the Firebase channel → https://goo.gle/Firebase #FirebaseSummit event: Firebase Summit 2020; re_ty: Publish; product: Firebase - General; fullname: Jon Skrip, Rachel Myers;

Intermediate topics in Firebase Security Rules - Firecasts

Cloud Firestore Data Modeling (Google I/O'19)

What's new in Firebase 2020 (Opening Keynote)

Three New Ways to Secure Your App with Firebase Authentication (Google I/O'19)

Five tips to secure your app (Firebase Summit 2018)

Introducing Nextcloud Hub 26 Spring: Built together, designed for the future 🚀

What's new in Firebase

AWS Explained: The Most Important AWS Services To Know

Adding on-device recommendations to your app using TensorFlow and Firebase

System Design Explained: APIs, Databases, Caching, CDNs, Load Balancing & Production Infra

Getting started with Firebase on Flutter - Firecasts

Go serverless: manage payments in your apps (Firebase Summit 2018)

The Unity Tutorial For Complete Beginners

How to Design APIs Like a Senior Engineer (REST, GraphQL, Auth, Security)

What do tech pioneers think about the AI revolution? - The Engineers, BBC World Service

Model Relational Data in Firestore NoSQL

Firebase - Ultimate Beginner's Guide

Something is jamming GPS over Europe. Here's what we found

Security Rules! 🔑 | Get to know Cloud Firestore #6

