Ruby Rogues

RR 328: Rails Security Beyond the Defaults with Matias Korhonen


Listen Later

Tweet this EpisodeMatias Korhonen has been writing Rails apps professionally at Kisko Labs, a Rails-focused software consultancy in Finland, for almost a decade. In his spare time he works on too many side projects (including Piranhas.co), a book price comparison site, and TLS.care (an SSL certificate monitoring service). He also somehow manages to find time to homebrew beer.The Rogues talk to Matias about securing your Rails applications. Rails comes with a lot of security features built in, but you can still leave yourself open to exploitation if you're not careful. Most of these problems occur in the portion of the app your write as opposed to the parts of the app that Rails handles for you. We go over several tools and techniques for making sure your application, access, and data are all secure.In particular, we dive pretty deep on:
  • Tools that you can use to scan for vulnerabilities or add more security checks to your applications
  • Authentication and authorization mistakes
  • Securely managing data
  • and much, much more...
Links:
  • secureheaders
  • brakeman
  • Code Climate
  • CloudFlare
  • zxcvbn
  • Troy Hunt article on pwned passwords
  • Devise Security Extension
  • pundit
  • Drifting Ruby episode on Complex Strong Parameters
  • gemnasium
  • bundler-audit
  • OWASP Zed Attack Proxy Project
  • rack-attack
Picks:Brian:
  • Regex 101
  • Give and Take by Adam Grant
Eric:
  • Indie Hackers
Dave:
  • Sumo Logic
Chuck:
  • Ready Player One Comic-Con trailer breakdown
  • Mattermost
  • Ruby Rogues Parley
  • Ruby Dev Summit (FREE)
Matias:
  • Webpacker 3.0
  • ActiveStorage
  • Heroku
Special Guest: Matias Korhonen.

Advertising Inquiries: https://redcircle.com/brands

Privacy & Opt-Out: https://redcircle.com/privacy

Become a supporter of this podcast: https://www.spreaker.com/podcast/ruby-rogues--6102073/support.
...more
View all episodesView all episodes
Download on the App Store

Ruby RoguesBy Charles M Wood

  • 4.5
  • 4.5
  • 4.5
  • 4.5
  • 4.5

4.5

45 ratings


More shows like Ruby Rogues

View all
The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

290 Listeners

The Ruby on Rails Podcast by Elise Shaffer

The Ruby on Rails Podcast

53 Listeners

Adventures in Angular by Charles M Wood

Adventures in Angular

33 Listeners

JavaScript Jabber by Charles M Wood

JavaScript Jabber

236 Listeners

iPhreaks by Charles M Wood

iPhreaks

17 Listeners

React Native Radio by Jamon Holmgren, Robin Heinze, Mazen Chami

React Native Radio

67 Listeners

Nerdland Podcast by Lieven Scheire

Nerdland Podcast

54 Listeners

Adventures in Angular by Charles M Wood

Adventures in Angular

15 Listeners

JavaScript Jabber by Charles M Wood

JavaScript Jabber

62 Listeners

Ruby Rogues by Charles M Wood

Ruby Rogues

21 Listeners

My Angular Story by Charles M Wood

My Angular Story

0 Listeners

My Ruby Story by Charles M Wood

My Ruby Story

0 Listeners

The Diary Of A CEO with Steven Bartlett by DOAC

The Diary Of A CEO with Steven Bartlett

8,451 Listeners

Remote Ruby by Chris Oliver, Andrew Mason

Remote Ruby

34 Listeners

Code with Jason by Jason Swett

Code with Jason

15 Listeners

Cautionary Tales with Tim Harford by Pushkin Industries

Cautionary Tales with Tim Harford

5,154 Listeners

The Rest Is History by Goalhanger

The Rest Is History

15,285 Listeners

The Ezra Klein Show by New York Times Opinion

The Ezra Klein Show

15,855 Listeners

The Rest Is Politics: Leading by Goalhanger

The Rest Is Politics: Leading

795 Listeners