Write Python that keeps data safe
Secure coding, cryptography, and network fundamentals
Every Python developer handles passwords, tokens, user input, and network traffic. Real Python shows you how to do it safely: generate secrets properly, encrypt data, understand HTTPS and sockets, and avoid the injection bugs attackers look for.
from cryptography.fernet import Fernet key = Fernet.generate_key() token = Fernet(key).encrypt(b"db_password=hunter2") token[:32]
b'gAAAAABnQ2x0Vd3k8bJ1rWm0qZyT4cN9'
Fernet(key).decrypt(token) # Right key
b'db_password=hunter2'
Fernet(Fernet.generate_key()).decrypt(token) # Wrong key
Traceback (most recent call last):
...
cryptography.fernet.InvalidToken
The security skills every Python developer needs
You don’t need to become a full-time security engineer to write safer code. These are the fundamentals that protect your users, your data, and your servers.
Handle secrets
Generate tokens and passwords that can’t be guessed, hash data, and keep credentials out of your code.
Encrypt data
Understand symmetric and public-key cryptography, then encrypt and decrypt messages with real libraries.
Block injection
Recognize and fix the classic holes: SQL injection, unsafe eval(), untrusted pickles, and shell commands built from user input.
Understand the network
See how HTTPS protects traffic, work with IP addresses, and build clients and servers with sockets.
A clear path to writing secure Python
Not sure where to start? Work through these in order. Each step builds on the one before, and the Network Programming and Security learning path ties it all together with a final quiz.
-
1
Generating Random Data in Python
Learn why
randomisn’t safe for passwords and tokens, what “cryptographically secure” means, and how to use thesecretsmodule and hashing instead. -
2
Preventing SQL Injection Attacks With Python
Exploit a vulnerable query yourself, then fix it with query parameters and safe composition so user input can never rewrite your SQL.
-
3
Exploring HTTPS and Cryptography in Python
Sniff unencrypted traffic, then build up from ciphers to public-key cryptography and certificates until you understand how HTTPS keeps data private.
-
4
Network Programming and Security
Put it together: REST APIs, HTTPS, and socket programming, with quizzes along the way and a final knowledge check.
-
Securely Deploy a Django App With Gunicorn, Nginx, & HTTPS
Harden a real web app for production: turn on HTTPS, redirect insecure traffic, add a Content Security Policy, and test the result.
New to Python itself? Start with Python Basics first.
Encrypt a message with a Fernet cipher
This is a real exercise from the Exploring HTTPS and Cryptography in Python video course, using the same library as the example above. Write your functions in the editor and click Run Tests.
Running tests, hints, and solutions are included with a Real Python membership. Not a member yet? You can still read the task and write your solution before you join.
Read it, watch it, test it, practice it
Security concepts stick when you see them break and then fix them yourself. Mix the formats however you like.
Tutorials
In-depth guides to HTTPS, cryptography, sockets, secure randomness, and injection attacks.
Start with HTTPS →Video courses
Watch an instructor build and break real code, one bite-sized lesson at a time.
Programming Sockets in Python →Quizzes
Check what you’ve learned in a few minutes and see exactly which concepts to review.
Test your network security skills →Coding exercises
Write ciphers, key handling, and secure connections in your browser and get instant test feedback.
How exercises work →Not sure if your code is safe? Ask right where you are
Security bugs often look like perfectly working code: a token from random, an f-string inside a SQL query, a password committed to a settings file.
Mentor AI sees the tutorial, lesson, or exercise you’re on and your code, and asks the questions that help you spot the problem yourself, so you recognize it next time.
Meet Mentor AI →random.choices(string.ascii_letters, k=32). That’s long enough, right?Length helps, but there’s a catch. The random module is built for simulations, not secrets. Its output can be predicted by someone who sees enough of it.
Remember the section on “cryptographically secure” in the tutorial you just read? Which standard-library module did it recommend instead?
secrets module! So secrets.token_urlsafe(32)?Exactly. It uses your operating system’s secure random source. Next question: how will you store the token on the server so a leaked database doesn’t expose it?
Know the modules that keep your code safe
Much of what you need ships with Python itself. Learn what each tool is for and when to reach for it.
Python features that need a security mindset
Some of Python’s most convenient tools are also the easiest to misuse. These tutorials show you where the risks are and how to stay on the safe side.
Questions and answers
Do I need to know Python before I start?
You should be comfortable with Python basics like functions, strings, and working with files. If you’re not there yet, the Python Basics learning path gets you ready.
Is this an ethical hacking or penetration testing course?
No. Real Python focuses on the defensive side: writing secure code, understanding cryptography and HTTPS, and knowing how networks work. These are the foundations you’ll build on whatever direction you take in security.
Do I need a networking or math background?
No. The HTTPS and cryptography material starts from the basics and explains concepts like keys, ciphers, and certificates with working Python code rather than proofs.
Why not just use random for passwords and tokens?
Because its output is predictable to anyone who sees enough of it. Use the secrets module for anything security-related. Generating Random Data in Python explains why.
What’s included in a membership?
Every Real Python membership includes all video courses, quizzes, coding exercises, and learning paths for security and every other topic, along with Mentor AI as it rolls out.
Start writing code you can trust
Get your free learning plan and work through the full security roadmap, with courses, quizzes, coding exercises, and a mentor at your side.