# Insecure Design — OWASP Top 10

Source: https://www.skillbyai.com/en/owasp-top-10/d-design

> Flaws no amount of perfect code fixes.

## Business logic and abuse cases

**Insecure design** means missing or ineffective security controls in the design: password reset codes that can be guessed without rate limits, a checkout that trusts a client-supplied price, unlimited free-trial sign-ups, or workflows that skip a verification step. Prevent it with threat modelling, **abuse cases** ("how would a fraudster use this?"), secure design patterns, rate limits and quotas, server-side recalculation of prices and totals, and security requirements reviewed alongside features.

## Secure by design, hardened by default

Some flaws are in the design itself; others come from insecure defaults and configuration.

![Three ideas: insecure design, misconfiguration, security headers and error handling.](assets/figures/owasp-top-10/section-5-map.svg) — Figure 5.1 — Design flaws, configuration and headers.

## Recomputing totals on the server

Python sketch for a checkout endpoint.

```python
# VULNERABLE DESIGN: trusts the price sent by the browser
total = sum(item["price"] * item["qty"] for item in request.json["items"])

# SECURE DESIGN: prices come from the catalogue; quantities are validated
total = 0
for item in request.json["items"]:
    product = catalogue.get(item["product_id"]) or abort(400)
    qty = int(item["qty"])
    if not 1 <= qty <= 20:
        abort(400)
    total += product.price * qty
```

## Write abuse cases next to user stories

"As an attacker, I want to reuse a discount code 1,000 times" leads directly to the needed control.

**Quiz:** Which is an insecure design flaw rather than a coding bug?

- [ ] A typo in a variable name
- [x] No rate limit on guessing six-digit password reset codes
- [ ] A missing semicolon
- [ ] A slow database index

*Answer:* No rate limit on guessing six-digit password reset codes. The control is missing from the design.
