We talk with Michael Lubas about steps we can take to protect our Phoenix applications from common automated bot attacks. We cover API abuse to send email spam, carding attacks, and credential stuffing. We learn how Michael started paraxial.io which aims to specifically serve the Elixir community and more!
Show Notes online - http://podcast.thinkingelixir.com/93
https://erlef.org/blog/eef/election-2022-results – Erlang Ecosystem Foundation board election voting resultshttps://erlef.org/blog/eef/election-2022 – Previous election notice and explanationshttps://hexdocs.pm/ex_doc/changelog.html – ExDoc v0.28.3 was releasedhttps://twitter.com/josevalim/status/1508528099973120004 – Call to help move ExDoc away from webpack to esbuildhttps://twitter.com/dominicletz/status/1506675402059792388 – iOS app store now has an Elixir application deployed in it!https://podcast.thinkingelixir.com/69 – Previous interview with Dominic Letz about doing Elixir on the desktop and mobile.https://www.erlang.org/news/155 – Erlang 25.0 rc-2 was released and requesting feedbackhttps://twitter.com/josevalim/status/1507443537851392007 – Jose Valim's experience compiling Elixir from scratch on Apple's new MacStudio M1 MaxConference remindershttps://www.empex.co/mtn – Empex MTN in Salt Lake City on May 6https://codesync.global/conferences/code-beam-sto-2022/ – CodeBEAM in Stockholm on May 19-20https://www.elixirconf.eu/ – ElixirConf EU in London on June 9-10https://elixirconf.com/events – ElixirConf US in Colorado on August 30-Sep2https://github.com/lucasvegi/Elixir-Code-Smells – Elixir Code Smells - public projecthttps://fly.io/phoenix-files/safe-ecto-migrations/ – Safe Ecto Migrationshttps://twitter.com/TylerAYoung/status/1508413319178297352 – Today I Learned about doctests and importingDo you have some Elixir news to share? Tell us at @ThinkingElixir or email at [email protected]
https://www.paraxial.io/blog/throttle-requestshttps://github.com/michalmuskala/plug_attackhttps://owasp.org/Top10/https://github.com/magento/magento2/issues/28614 – What is a carding attack?https://owasp.org/www-project-automated-threats-to-web-applications/http://paraxial.io/https://frame.io/https://news.adobe.com/news/news-details/2021/Adobe-Completes-Acquisition-of-Frame.io/default.aspxhttps://www.metasploit.com/https://www.crunchbase.com/https://owasp.org/www-community/attacks/Credential_stuffinghttps://en.wikipedia.org/wiki/Web_application_firewallhttps://twitter.com/paraxialio – on Twitterhttps://github.com/paraxialio/ – on Githubhttps://paraxial.io/ – WebsiteMessage the show - @ThinkingElixirEmail the show - [email protected] Mark Ericksen - @brainlidDavid Bernheisel - @bernheiselCade Ward - @cadebwardSponsored By:
- Fly.io: Fly.io is a great place to deploy your next Phoenix application! Check them out!