Ruby Rogues

219 RR Brakeman and Rails Security with Justin Collins


Listen Later

02:40 - Justin Collins Introduction
  • Twitter 
  • GitHub 
  • Blog
  • Brakeman
    • @brakeman
  • SurveyMonkey
  • Brakeman Pro
    • @brakemanpro
03:40 - Brakeman & Static Analysis 04:02 - Common Security Vulnerabilities (and Definitions)
  • Cross-site Scripting
  • SQL Injection    
    • rails-sqli.org
  • Mass Assignment
  • Open Redirects
08:57 - The Inspiration for Brakeman09:47 - Getting Brakeman Working (Process)10:41 - Learning About Security
  • The Rails Cheat Sheets
  • The Open Web Application Security Project (OWASP)
    • The OWASP Top Ten    
13:01 - Security and The Rails Core Team
  • Justin Collins: The World of Ruby on Rails Security @ RailsConf 2015 
15:19 - Should Brakeman be integrated into Rails?16:29 - Running Brakeman On Your CI Machine
  • guard-brakeman
17:43 - Are there specific types of vulnerabilities that are hard to find with static analysis?19:18 - Rails Engines20:56 - When building an app, is security something you should focus on from the get-go?
  • Where should you get started?
    • The OWASP Top Ten
25:32 - Code Schools Teaching Security26:17 - Translating Lessons Learned Into Brakeman27:24 - Handling Security and Data Breaches
  • Charlie Miller
32:28 - Crowdsourcing Security (Security in Open Source)
  • Terri Oda: Bringing Security to Your Open Source Project 
34:54 - The Technical Side of Brakeman and Static Analysis Tools
  • Identifying a Dangerous Value
37:34 - Data Tracing, Limited Data Flow Analysis 40:52 - Future Brakeman Features43:29 - Supporting and Contributing to Brakeman48:23 - PhDsPicks "Why didn't you [just]..." and "Did you consider..." Parley Thread (Avdi)
Object Thinking (Developer Reference) by David West (Avdi)
Web Design - The First 100 Years (Avdi)
Brighton Ruby Conference (Avdi)
Email (Avdi)
The Twitter Mute Button (Avdi)
git - the simple guide (Saron)
I Love My Campus (Saron)
LoneStarRuby (Saron)
React Rally (Jessica)
Livecoding.tv (Jessica)
Remembering the Apollo 11 Moon Landing With the Woman Who Made It Happen (Coraline)
Showgoers (Coraline)
AngularJS Kurs (Chuck)
Hire Thom Parkin! (Chuck)
RethinkDB (Justin)
Dealers of Lightning: Xerox PARC and the Dawn of the Computer Age by Michael A. Hiltzik (Justin)
The Search for General Tso (Justin)Special Guest: Justin Collins.

Advertising Inquiries: https://redcircle.com/brands

Privacy & Opt-Out: https://redcircle.com/privacy

Become a supporter of this podcast: https://www.spreaker.com/podcast/ruby-rogues--6102073/support.
...more
View all episodesView all episodes
Download on the App Store

Ruby RoguesBy Charles M Wood

  • 4.5
  • 4.5
  • 4.5
  • 4.5
  • 4.5

4.5

45 ratings


More shows like Ruby Rogues

View all
The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

290 Listeners

The Ruby on Rails Podcast by Elise Shaffer

The Ruby on Rails Podcast

53 Listeners

Adventures in Angular by Charles M Wood

Adventures in Angular

33 Listeners

JavaScript Jabber by Charles M Wood

JavaScript Jabber

236 Listeners

iPhreaks by Charles M Wood

iPhreaks

17 Listeners

React Native Radio by Jamon Holmgren, Robin Heinze, Mazen Chami

React Native Radio

67 Listeners

Nerdland Podcast by Lieven Scheire

Nerdland Podcast

54 Listeners

Adventures in Angular by Charles M Wood

Adventures in Angular

15 Listeners

JavaScript Jabber by Charles M Wood

JavaScript Jabber

62 Listeners

Ruby Rogues by Charles M Wood

Ruby Rogues

21 Listeners

My Angular Story by Charles M Wood

My Angular Story

0 Listeners

My Ruby Story by Charles M Wood

My Ruby Story

0 Listeners

The Diary Of A CEO with Steven Bartlett by DOAC

The Diary Of A CEO with Steven Bartlett

8,361 Listeners

Remote Ruby by Chris Oliver, Andrew Mason

Remote Ruby

34 Listeners

Code with Jason by Jason Swett

Code with Jason

15 Listeners

Cautionary Tales with Tim Harford by Pushkin Industries

Cautionary Tales with Tim Harford

5,150 Listeners

The Rest Is History by Goalhanger

The Rest Is History

15,271 Listeners

The Ezra Klein Show by New York Times Opinion

The Ezra Klein Show

15,853 Listeners

The Rest Is Politics: Leading by Goalhanger

The Rest Is Politics: Leading

781 Listeners