# Security Resources in Every Programmer Should Know: A Complete Guide

> Discover essential security resources every programmer needs. This guide covers secure coding crypto web vulnerabilities and exploitation labs from mtdvio/every-programmer-should-know.

- Repository: [MTDV/every-programmer-should-know](https://github.com/mtdvio/every-programmer-should-know)
- Tags: tutorial
- Published: 2026-02-26

---

**The mtdvio/every-programmer-should-know repository curates nine essential security resources in its README.md file, covering secure coding practices, cryptographic fundamentals, web application vulnerabilities, and hands-on exploitation labs.**

The `mtdvio/every-programmer-should-know` repository serves as a comprehensive knowledge base for software engineers seeking to expand their technical expertise. Within its extensive [`README.md`](https://github.com/mtdvio/every-programmer-should-know/blob/main/README.md) file, a dedicated **Security** section (lines 104-114) aggregates high-quality security resources that provide actionable guidance for developers. These curated materials span from theoretical foundations to practical vulnerability exploitation exercises.

## Overview of the Security Resources Collection

The nine security resources listed in the repository cover four critical domains of software security. The collection balances **foundational theory** with **practical application**, offering everything from free online books to interactive hacking labs. Each resource targets developers at different skill levels, from beginners learning basic secure coding principles to experienced engineers implementing cryptographic solutions.

## Complete List of Security Resources

### Foundational Books and Guides

Two comprehensive books anchor the security fundamentals in this collection:

- **Security Programming** by David A. Wheeler — A complete guide to secure software design and implementation available at `https://www.dwheeler.com/secure-programs/`
- **Foundations of Security: What Every Programmer Needs to Know** — A practical introduction covering authentication, authorization, and secure coding patterns on Goodreads

### Cryptography Resources

Four resources specifically address cryptographic implementation and common pitfalls:

- **Rolling Your Own Crypto** — An article explaining why developers should avoid implementing custom cryptographic solutions
- **Cryptographic Right Answers** — A GitHub Gist providing consensus recommendations for modern cryptographic algorithm selection
- **An Open Letter to Developers Everywhere (About Cryptography)** — A position paper emphasizing proper crypto usage patterns
- **Hashing, Encryption and Encoding** — A blog post clarifying the critical differences between these often-confused operations

### Web Application Security

The repository includes the industry-standard reference for web vulnerabilities:

- **OWASP Top 10** — The Open Web Application Security Project's definitive guide to the most critical web application security risks

### Practical Training and Labs

Two hands-on platforms allow developers to practice exploitation techniques:

- **PortSwigger Academy** — Interactive labs and learning materials for web security testing from the creators of Burp Suite
- **Web Application Exploits and Defenses (Google Gruyère)** — A codelab environment where developers can find and fix vulnerabilities in a real application

## How to Use These Resources in Your Projects

When implementing security measures in your codebase, reference these resources systematically. Start with the foundational books to establish secure coding patterns, verify cryptographic implementations against the **Cryptographic Right Answers** gist, and audit web applications using the **OWASP Top 10** framework.

You can integrate these resources into your project documentation using a security checklist:

```markdown

## Security Checklist for New Projects

- [ ] Review **Security Programming** concepts
- [ ] Verify cryptographic usage against **Rolling Your Own Crypto**
- [ ] Cross‑check implementations with **Cryptographic Right Answers**
- [ ] Read the **Open Letter** for modern crypto best practices
- [ ] Ensure coverage of all **OWASP Top 10** items
- [ ] Complete at least one **PortSwigger Academy** lab
- [ ] Run the **Google Gruyère** tutorial to spot common flaws
- [ ] Apply hashing best‑practices from **Hashing, Encryption and Encoding**

```

## Locating the Security Section in the Source Code

The security resources reside in the repository's central documentation file. In [`README.md`](https://github.com/mtdvio/every-programmer-should-know/blob/main/README.md), navigate to the section titled `### Security` (approximately lines 104-114) to view the original curation. This section maintains the canonical list of links and brief descriptions that the repository maintainers have vetted for quality and relevance.

## Summary

- The `mtdvio/every-programmer-should-know` repository curates **nine essential security resources** in its [`README.md`](https://github.com/mtdvio/every-programmer-should-know/blob/main/README.md) file under the `### Security` section.

- The collection spans **foundational books**, **cryptographic guidance**, **web application security standards**, and **hands-on training labs**.
- Key references include the **OWASP Top 10** for web vulnerabilities and **PortSwigger Academy** for practical exploitation skills.
- Developers should cross-reference cryptographic implementations with the **Cryptographic Right Answers** gist to avoid common implementation flaws.

## Frequently Asked Questions

### Where are the security resources located in the Every Programmer Should Know repository?

The security resources are located in the [`README.md`](https://github.com/mtdvio/every-programmer-should-know/blob/main/README.md) file within the `### Security` section, approximately at lines 104-114. This section contains a curated list of nine links covering books, articles, and interactive labs essential for developer security education.

### Does the repository include hands-on security training materials?

Yes, the repository includes two practical training platforms: **PortSwigger Academy**, which offers interactive web security labs, and **Google Gruyère**, a codelab environment where developers can practice finding and fixing vulnerabilities in a real application.

### What cryptographic resources does Every Programmer Should Know recommend?

The repository recommends four cryptography-specific resources: **Rolling Your Own Crypto** (explaining why custom crypto is dangerous), **Cryptographic Right Answers** (a gist with algorithm recommendations), **An Open Letter to Developers Everywhere** (best practices), and **Hashing, Encryption and Encoding** (clarifying terminology differences).

### Is the OWASP Top 10 included in the security section?

Yes, the **OWASP Top 10** is included as the primary resource for web application security. It represents the industry-standard reference for understanding the most critical web application security risks and is listed alongside practical training resources like PortSwigger Academy.