EPISODE · Oct 6, 2020 · 49 MIN
Frank Rietta — The convergence of Ruby on Rails and #AppSec
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Ruby on Rails can provide strong security defaults, but a framework cannot make every design decision for its developers. Frank Rietta, a security-focused Rails developer and business owner, explains where the framework helps and where teams still need to think carefully. He traces his path into application security, describes Rails beyond its startup reputation, and discusses testing, secure coding guidance, and the familiar threats facing web applications. Frank also shares his work on RubyGems typosquatting and the risks introduced through dependencies. The practical discussion turns to Brakeman, Bundler Audit, and building checks into everyday development. His recurring advice is to combine useful tooling with deliberate design, maintained dependencies, and an understanding of how attackers can misuse ordinary features.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Frank Rietta:→ Frank Rietta’s websiteMentioned in this episode:→ Rails security guide→ Brakeman→ Bundler AuditFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Ruby on Rails and AppSec with Frank Rietta01:14 Frank’s path into application security07:13 Helping developers build security skills11:00 What Ruby on Rails provides14:01 Rails beyond early-stage startups17:15 Security defaults and their limits22:23 Secure coding guidance for Rails developers25:20 Testing culture and security checks29:13 The main threats facing Rails applications32:14 Typosquatting and the RubyGems supply chain38:32 Brakeman, Bundler Audit, and the security toolkit45:11 Key takeaways for secure Rails development
Embed this episode
What this episode covers
Ruby on Rails can provide strong security defaults, but a framework cannot make every design decision for its developers. Frank Rietta, a security-focused Rails developer and business owner, explains where the framework helps and where teams still need to think carefully. He traces his path into application security, describes Rails beyond its startup reputation, and discusses testing, secure coding guidance, and the familiar threats facing web applications. Frank also shares his work on Ruby...
Ready to play
Frank Rietta — The convergence of Ruby on Rails and #AppSec
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.