Turn on ye ole Javascript to add ratings in this low-budg app.

Title:

Hackproofing Ruby-on-Rails Web Applications

Your vote:
Yes No
Organizer:
Mike Subelsky, OtherInbox.com
Description:
Ruby-on-Rails makes building web applications deceptively simple, and for most Rails startups, security is usually an afterthought. Through a live coding demonstration, I will demonstrate how thinking from the attacker's perspective can help you protect sensitive data and avoid the pain of a hacking incident.
Questions
Answered:
  1. What are common hacker tactics?
  2. How do I defend my web app from hackers?
  3. What security features does Ruby on Rails come with?
  4. What are the biggest security sins in web development?
  5. How can I write code quickly while being safe?
  6. How do I prevent Cross Site Request Forgery?
  7. How do I prevent Cross Site Scripting attacks?
  8. How do I layer my defenses to guard against hacking?
  9. What can I do today to make my site safer?
  10. How can I detect hacker activity on my site?
Level:
Advanced
Category:
Type:
Solo
Event:
SXSW Interactive 2009
on 8/8/08
I worked for the Department of Defense as a cyber security analyst and in private industry as a security consultant for eight years before becoming a full-time Rails developer, which I've been doing for two years. I'm going to combine both sides of my background and make this a really fun, interesting presentation!
on 12/8/08
Live hacking fun! I hope you don't divulge any national security secrets.
on 12/8/08
Does anyone know of any RoR sites getting hacked for real? If so, please email sxsw-ror-hacks@joshuabaer.com
Joleen Sanborn
on 18/8/08
Cyber security, DOD, and hacking....my interested in piqued.
on 18/8/08
I think this is vital information for Rails Developers, with so much conforming going on in the framework, a single exploit could affect a ton of sites. I'd like to stay ahead of the curve here and would love to listen.
soph que
on 20/8/08
sounds like a great session
on 10/12/08
What do you think
on 13/11/09
I'd be super into learning from Kris. Dig it!
Developed for SXSW by Lindsey Simon