Don’t let it crash - Security through Static Analysis by Melinda Tóth & Dániel Horpácsi | Code BEAM

  Рет қаралды 287

Code Sync

Code Sync

Күн бұрын

✨This talk was recorded at Code BEAM Europe 2023. If you're curious about our upcoming event, check codebeameurope... ✨
Abstract:
Something to love about the BEAM is the principle of ‘let it crash’: exceptions are isolated and handled by design. Indeed, various kinds of data checks can be mercifully omitted, but it would be rash to conclude that all input validation is redundant and unnecessary. In 2020, the Erlang Ecosystem Foundation curated an extensive list of secure coding principles to raise programmers’ awareness and assist them in creating secure Erlang systems. But the reality is always messy: Erlang/Elixir projects rarely follow these guidelines, and legacy have been running for years with well-known vulnerabilities. In this talk, we will explain how static analysis can be useful for detecting critical security issues in new or legacy Erlang code bases, mitigating and even eliminating them semi-automatically. In particular, we will present use cases of vulnerabilities found in open-source projects and demonstrate how techniques like data-flow analysis can reveal and cure them.
Let's keep in touch! Follow us on:
💥 Twitter: / codebeamio
💥 Facebook: / codesyncglobal
💥 Linkedin: / code-sync
💥 Mastodon: genserver.soci...

Пікірлер
Federal Trade Commission Chair Lina Khan: The 60 Minutes Interview
13:15
Do you choose Inside Out 2 or The Amazing World of Gumball? 🤔
00:19
POV: Your kids ask to play the claw machine
00:20
Hungry FAM
Рет қаралды 19 МЛН
Поветкин заставил себя уважать!
01:00
МИНУС БАЛЛ
Рет қаралды 6 МЛН
Шок. Никокадо Авокадо похудел на 110 кг
00:44
Why Isn't Functional Programming the Norm? - Richard Feldman
46:09
The Best Programmer I Know • Daniel Terhorst-North • GOTO 2024
48:33
GOTO Conferences
Рет қаралды 50 М.
Renaissance of Terminal User Interfaces with Rust - FrOSCon 2024
53:23
Orhun Parmaksız
Рет қаралды 2,8 М.
HTTP Polling vs SSE vs WebSocket vs WebHooks
22:22
ByteVigor
Рет қаралды 11 М.
New Ukrainian Weapons Hit Russia Where It Hurts || Peter Zeihan
7:32
Zeihan on Geopolitics
Рет қаралды 516 М.
JavaScript Security Vulnerabilities Tutorial  - With Code Examples
25:05
freeCodeCamp.org
Рет қаралды 76 М.
Don't Contribute to Open Source
9:55
Theo - t3․gg
Рет қаралды 233 М.
How AI 'Understands' Images (CLIP) - Computerphile
18:05
Computerphile
Рет қаралды 201 М.
Do you choose Inside Out 2 or The Amazing World of Gumball? 🤔
00:19