Talking Drupal

Talking Drupal #396 - Drupal Security


Listen Later

Today we are talking about Drupal Security with Mark Shropshire & Benji Fisher.

For show notes visit: www.talkingDrupal.com/396

Topics
  • Why do you care about security
  • Best tips for securing Drupal
  • Common Security Issues people have with Drupal
  • Convincing module maintainers to do full releases
  • Testing to ensure security
  • Guardr Drupal security distribution
  • What does the Drupal Security team do
  • Finding issues
  • Review compromised sites
  • Becoming a member
  • Process for writing security notices
  • Helping the security team
Resources
  • How to Join the Drupal Security Team
  • How to get involved
  • Passwords:
    • xkcd
    • Spaceballs
  • Discussed at this BadCamp talk - Sleep Better at Night with a Secure Drupal Site
  • OWASP
  • OWASP Zap baseline
  • Benji’s talk introducing the OWASP Top Ten
    • Current
    • Other versions
    • Source code (markdown)
  • Github repo building and testing guardr
  • Sam Mortenson talk
    • https://drupal.slack.com/archives/C1DD80ZKM/p1550697032017600
    • https://drupal.tv/external-video/2018-02-06/how-write-insecure-drupal-8-code
  • Guardr core
Guests

Benji Fisher - tag1consulting.com @benji17fisher Mark Shropshire - shrop.dev @shrop

Hosts

Nic Laflin - www.nLighteneddevelopment.com @nicxvan John Picozzi - www.epam.com @johnpicozzi Jordan Graham - @jordanlgraham

MOTW Correspondent

Martin Anderson-Clutz - @mandclu CrowdSec Integrates your Drupal site with the open source CrowdSec Security Engine, a collaborative malicious activity detection and remediation tool.

...more
View all episodesView all episodes
Download on the App Store

Talking DrupalBy Talking Drupal Hosts

  • 4.9
  • 4.9
  • 4.9
  • 4.9
  • 4.9

4.9

28 ratings


More shows like Talking Drupal

View all
Radiolab by WNYC Studios

Radiolab

43,789 Listeners

Marketplace by Marketplace

Marketplace

8,625 Listeners

Planet Money by NPR

Planet Money

30,725 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

284 Listeners

Freakonomics Radio by Freakonomics Radio + Stitcher

Freakonomics Radio

32,073 Listeners

99% Invisible by Roman Mars

99% Invisible

26,145 Listeners

Late Night Linux by The Late Night Linux Family

Late Night Linux

162 Listeners

Syntax - Tasty Web Development Treats by Wes Bos & Scott Tolinski - Full Stack JavaScript Web Developers

Syntax - Tasty Web Development Treats

990 Listeners

The Indicator from Planet Money by NPR

The Indicator from Planet Money

9,502 Listeners

2.5 Admins by The Late Night Linux Family

2.5 Admins

91 Listeners

Hard Fork by The New York Times

Hard Fork

5,437 Listeners

The Ezra Klein Show by New York Times Opinion

The Ezra Klein Show

15,363 Listeners

The Weekly Show with Jon Stewart by Comedy Central

The Weekly Show with Jon Stewart

10,299 Listeners

The AI Daily Brief (Formerly The AI Breakdown): Artificial Intelligence News and Analysis by Nathaniel Whittemore

The AI Daily Brief (Formerly The AI Breakdown): Artificial Intelligence News and Analysis

496 Listeners

Risky Business with Nate Silver and Maria Konnikova by Pushkin Industries

Risky Business with Nate Silver and Maria Konnikova

255 Listeners