• NeilBrü@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    20 hours ago

    As I mentioned in other comments, I am a noob when it comes to web-sec; please forgive what may be dumb questions.

    Is it really just permission rights “over-exposure” issue? Or does one need to also encrypt and then decrypt the data itself that must be sent to a database?

    Also, if you have time, recommend any links to web/cloud/SaaS security best practices “for dummies”?