Talking Drupal

Talking Drupal #396 - Drupal Security


Listen Later

Today we are talking about Drupal Security with Mark Shropshire & Benji Fisher.

For show notes visit: www.talkingDrupal.com/396

Topics
  • Why do you care about security
  • Best tips for securing Drupal
  • Common Security Issues people have with Drupal
  • Convincing module maintainers to do full releases
  • Testing to ensure security
  • Guardr Drupal security distribution
  • What does the Drupal Security team do
  • Finding issues
  • Review compromised sites
  • Becoming a member
  • Process for writing security notices
  • Helping the security team
Resources
  • How to Join the Drupal Security Team
  • How to get involved
  • Passwords:
    • xkcd
    • Spaceballs
  • Discussed at this BadCamp talk - Sleep Better at Night with a Secure Drupal Site
  • OWASP
  • OWASP Zap baseline
  • Benji's talk introducing the OWASP Top Ten
    • Current
    • Other versions
    • Source code (markdown)
  • Github repo building and testing guardr
  • Sam Mortenson talk
    • https://drupal.slack.com/archives/C1DD80ZKM/p1550697032017600
    • https://drupal.tv/external-video/2018-02-06/how-write-insecure-drupal-8-code
  • Guardr core
Guests

Benji Fisher - tag1consulting.com @benji17fisher Mark Shropshire - shrop.dev @shrop

Hosts

Nic Laflin - www.nLighteneddevelopment.com @nicxvan John Picozzi - www.epam.com @johnpicozzi Jordan Graham - @jordanlgraham

MOTW Correspondent

Martin Anderson-Clutz - @mandclu CrowdSec Integrates your Drupal site with the open source CrowdSec Security Engine, a collaborative malicious activity detection and remediation tool.

...more
View all episodesView all episodes
Download on the App Store

Talking DrupalBy Talking Drupal Hosts

  • 4.9
  • 4.9
  • 4.9
  • 4.9
  • 4.9

4.9

28 ratings


More shows like Talking Drupal

View all
This American Life by This American Life

This American Life

90,931 Listeners

Marketplace by Marketplace

Marketplace

8,762 Listeners

On the Media by WNYC Studios

On the Media

9,181 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

289 Listeners

Pivot by New York Magazine

Pivot

9,538 Listeners

The Daily by The New York Times

The Daily

112,360 Listeners

Up First from NPR by NPR

Up First from NPR

56,503 Listeners

Syntax - Tasty Web Development Treats by Wes Bos & Scott Tolinski - Full Stack JavaScript Web Developers

Syntax - Tasty Web Development Treats

987 Listeners

Behind the Bastards by Cool Zone Media and iHeartPodcasts

Behind the Bastards

15,566 Listeners

Interesting Times with Ross Douthat by New York Times Opinion

Interesting Times with Ross Douthat

7,227 Listeners

SmartLess by Jason Bateman, Sean Hayes, Will Arnett

SmartLess

57,845 Listeners

Hard Fork by The New York Times

Hard Fork

5,507 Listeners

Volts by David Roberts

Volts

632 Listeners

Prof G Markets by Vox Media Podcast Network

Prof G Markets

1,425 Listeners

Fest & Flauschig by Jan Böhmermann & Olli Schulz

Fest & Flauschig

22 Listeners