Manuals / Security Testing Basics / Guide 1

Start · beginner · ~25 min · Guide 1 of 5

Security mindset for QA

You don’t need to hack banks. You need to ask “what if I’m not who I claim?” and “what if this input is hostile?”

Path progress
20%

Step 1 of 1

Draw the trust line

Client, server, third parties. Mark what you trust and why.

Draw the trust lineDrag stickies · tap for tips
Study mapDrag stickies · tap for tipsKeep it shortdrag · tap →Name the waitdrag · tap →Scope locatorsdrag · tap →Trace when stuckdrag · tap →One browser firstdrag · tap →Isolate statedrag · tap →Assert the UIdrag · tap →Retry wiselydrag · tap →Seed datadrag · tap →Close the loopdrag · tap →Keep it shortdrag · tap →Name the waitdrag · tap →Scope locatorsdrag · tap →Trace when stuckdrag · tap →One browser firstdrag · tap →Isolate statedrag · tap →Pathwise hackdrag · tap →Draw the trust lindrag · tap →Try thisdrag · tap →Follow the dashed drag · tap →

Do this now

Sketch a trust map for one feature.

Was this step clear?
Chapter learning outcomes
  • Trust boundaries
  • Threat vs vulnerability
  • Responsible reporting

Clear these before you leave