RR 328: Rails Security Beyond the Defaults with Matias Korhonen episode artwork

EPISODE · Sep 19, 2017 · 53 MIN

RR 328: Rails Security Beyond the Defaults with Matias Korhonen

from Ruby Rogues · host Charles M Wood

Tweet this EpisodeMatias Korhonen has been writing Rails apps professionally at Kisko Labs, a Rails-focused software consultancy in Finland, for almost a decade. In his spare time he works on too many side projects (including Piranhas.co), a book price comparison site, and TLS.care (an SSL certificate monitoring service). He also somehow manages to find time to homebrew beer.The Rogues talk to Matias about securing your Rails applications. Rails comes with a lot of security features built in, but you can still leave yourself open to exploitation if you're not careful. Most of these problems occur in the portion of the app your write as opposed to the parts of the app that Rails handles for you. We go over several tools and techniques for making sure your application, access, and data are all secure.In particular, we dive pretty deep on:Tools that you can use to scan for vulnerabilities or add more security checks to your applicationsAuthentication and authorization mistakesSecurely managing dataand much, much more...Links:secureheadersbrakemanCode ClimateCloudFlarezxcvbnTroy Hunt article on pwned passwordsDevise Security ExtensionpunditDrifting Ruby episode on Complex Strong Parametersgemnasiumbundler-auditOWASP Zed Attack Proxy Projectrack-attackPicks:Brian:Regex 101Give and Take by Adam GrantEric:Indie HackersDave:Sumo LogicChuck:Ready Player One Comic-Con trailer breakdownMattermostRuby Rogues ParleyRuby Dev Summit (FREE)Matias:Webpacker 3.0ActiveStorageHerokuSpecial Guest: Matias Korhonen. Advertising Inquiries: https://redcircle.com/brandsPrivacy & Opt-Out: https://redcircle.com/privacyBecome a supporter of this podcast: https://www.spreaker.com/podcast/ruby-rogues--6102073/support.

Tweet this EpisodeMatias Korhonen has been writing Rails apps professionally at Kisko Labs, a Rails-focused software consultancy in Finland, for almost a decade. In his spare time he works on too many side projects (including Piranhas.co), a book price comparison site, and TLS.care (an SSL certificate monitoring service). He also somehow manages to find time to homebrew beer.The Rogues talk to Matias about securing your Rails applications. Rails comes with a lot of security features built in, but you can still leave yourself open to exploitation if you're not careful. Most of these problems occur in the portion of the app your write as opposed to the parts of the app that Rails handles for you. We go over several tools and techniques for making sure your application, access, and data are all secure.In particular, we dive pretty deep on:Tools that you can use to scan for vulnerabilities or add more security checks to your applicationsAuthentication and authorization mistakesSecurely managing dataand much, much more...Links:secureheadersbrakemanCode ClimateCloudFlarezxcvbnTroy Hunt article on pwned passwordsDevise Security ExtensionpunditDrifting Ruby episode on Complex Strong Parametersgemnasiumbundler-auditOWASP Zed Attack Proxy Projectrack-attackPicks:Brian:Regex 101Give and Take by Adam GrantEric:Indie HackersDave:Sumo LogicChuck:Ready Player One Comic-Con trailer breakdownMattermostRuby Rogues ParleyRuby Dev Summit (FREE)Matias:<a href="https://github.com/rails/webpacker" target="_blank"...

NOW PLAYING

RR 328: Rails Security Beyond the Defaults with Matias Korhonen

0:00 53:21

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

JFK The Enduring Secret Jeff Crudele An in depth tutorial and discussion around the assassination of John F. Kennedy, (JFK) the country's 35th president who was brutally murdered in Dallas Texas on November 22, 1963. The series comprehensively explores the major facts, themes, and events leading up to the assassination in Dealey Plaza and the equally gripping stories surrounding the subsequent investigation. We review key elements of the Warren Commission Report , and the role of the CIA and FBI. We explore the possible involvement of the Mafia in the murder and the review of that topic by the government's House Select Committee on Assassinations in the 1970's. We explore the Jim Garrison investigation and the work of other key figures such as Mark Lane and others. Learn more about Lee Harvey Oswald the suspected killer and Jack Ruby the distraught Dallas night club owner with underworld ties and the man that killed Oswald as a national TV audience was watching. Stay with us as we take you through the facts and theorie Explicit 暗黑森林 The Dark Forest 榮忠豪/Ruby 盧春如/Joanna Wang 王若琳 社會總是希望人人都活在明亮。但一旦人的黑暗面露出的時候,社會會怎麼反應? 人性的黑暗總是被壓抑的而不被允許顯露, 但若這些邪惡的行為無法被壓下來 會有什麼事情發生? 本播客想透過真實殺人案件與其他暗黑的故事來探索人的黑暗面,但就像暗黑的森林,在黑暗的樹枝之中還是看得到光芒,提醒人們黑暗之處還是有希望的存在。 除了只關注故事的黑暗,『暗黑森林』也會專注在人們對於彼此的關懷,同情,與自我保護的重要性。來吧!跟著主持人 榮忠豪/Joanna 王若琳/Ruby 盧春如 一起走進 「暗黑森林」 Powered by Firstory Hosting Explicit Rogues Gallery 27th Letter Productions Kristen, M.J., and Chris investigate pop culture's most memorable villains, antiheroes, and misunderstood monsters to find out how they make being bad look so good. New episodes every other Thursday. Explicit Ruby Ryder – Pegging Paradise Ruby Ryder Your guide for pegging, anal sex, and bdsm Explicit

Frequently Asked Questions

How long is this episode of Ruby Rogues?

This episode is 53 minutes long.

When was this Ruby Rogues episode published?

This episode was published on September 19, 2017.

What is this episode about?

Tweet this EpisodeMatias Korhonen has been writing Rails apps professionally at Kisko Labs, a Rails-focused software consultancy in Finland, for almost a decade. In his spare time he works on too many side projects (including Piranhas.co), a book...

Can I download this Ruby Rogues episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!