Frank Rietta — The convergence of Ruby on Rails and #AppSec episode artwork

EPISODE · Oct 6, 2020 · 49 MIN

Frank Rietta — The convergence of Ruby on Rails and #AppSec

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Ruby on Rails can provide strong security defaults, but a framework cannot make every design decision for its developers. Frank Rietta, a security-focused Rails developer and business owner, explains where the framework helps and where teams still need to think carefully. He traces his path into application security, describes Rails beyond its startup reputation, and discusses testing, secure coding guidance, and the familiar threats facing web applications. Frank also shares his work on RubyGems typosquatting and the risks introduced through dependencies. The practical discussion turns to Brakeman, Bundler Audit, and building checks into everyday development. His recurring advice is to combine useful tooling with deliberate design, maintained dependencies, and an understanding of how attackers can misuse ordinary features.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Frank Rietta:→ Frank Rietta’s websiteMentioned in this episode:→ Rails security guide→ Brakeman→ Bundler AuditFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Ruby on Rails and AppSec with Frank Rietta01:14 Frank’s path into application security07:13 Helping developers build security skills11:00 What Ruby on Rails provides14:01 Rails beyond early-stage startups17:15 Security defaults and their limits22:23 Secure coding guidance for Rails developers25:20 Testing culture and security checks29:13 The main threats facing Rails applications32:14 Typosquatting and the RubyGems supply chain38:32 Brakeman, Bundler Audit, and the security toolkit45:11 Key takeaways for secure Rails development

Episode metadata supplied by the publisher feed · Published Oct 6, 2020

Embed this episode

Ruby on Rails can provide strong security defaults, but a framework cannot make every design decision for its developers. Frank Rietta, a security-focused Rails developer and business owner, explains where the framework helps and where teams still need to think carefully. He traces his path into application security, describes Rails beyond its startup reputation, and discusses testing, secure coding guidance, and the familiar threats facing web applications. Frank also shares his work on Ruby...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Frank Rietta — The convergence of Ruby on Rails and #AppSec

0:00 49:33

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 49 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on October 6, 2020.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!