Application security from start to finish - Michael Kaufmann - NDC Porto 2022

  Рет қаралды 10,548

NDC Conferences

NDC Conferences

Күн бұрын

In 2016, a dispute over the name Kik let to an outage that affected nearly the entire internet: an open-source package with 11 lines of code, that every developer could easily write themselves, was withdrawn from the package registry and caused thousands of websites to break. And, in 2020, SolarWinds caused a security leak that affected over 33,000 customers, amongst them the Department of Homeland Security and the Department of Treasury: an attack to the software supply chain of their software Orion was successful and let to malicious software to be distributed to many of their clients.
Incidents like this proof that application security is not just security testing before you ship your software or architecture reviews. Security must be baked into your development process and if must span the entire software supply chain.
In this talk you’ll learn how you can integrate security into your complete development process:
Secure development environments
Secret scanning and secret rotation
Dependency management and software composition analysis (SCA)
Manage your software supply chain with Dependabot
Find XSS, SQL injection, and memory leaks
Static and dynamic security testing (SAST and DAST)
Hunt for vulnerabilities writing your own CodeQL queries
The talk is for everyone that is interested in application security - developers as well as DevOps engineers.
Check out more of our featured speakers and talks at
www.ndcconfere...
ndcporto.com

Пікірлер: 4
@1695AB
@1695AB Ай бұрын
What are the benefits of commercial tools against OS ones?
@0oMindStormso0
@0oMindStormso0 2 жыл бұрын
Very informative, thank you!
@sergiocoder
@sergiocoder 9 ай бұрын
You should have mentioned the node-ipc incident
@Erril_Ferndal
@Erril_Ferndal 2 жыл бұрын
👍
Getting API security right - Philippe De Ryck - NDC London 2023
51:49
NDC Conferences
Рет қаралды 28 М.
IL'HAN - Qalqam | Official Music Video
03:17
Ilhan Ihsanov
Рет қаралды 700 М.
Enceinte et en Bazard: Les Chroniques du Nettoyage ! 🚽✨
00:21
Two More French
Рет қаралды 42 МЛН
Une nouvelle voiture pour Noël 🥹
00:28
Nicocapone
Рет қаралды 9 МЛН
Domain-Driven Refactoring - Jimmy Bogard - NDC London 2022
1:00:03
NDC Conferences
Рет қаралды 48 М.
OAuth - the good Parts - Dominick Baier - NDC Porto 2022
57:50
NDC Conferences
Рет қаралды 11 М.
Application Security:  The Six Figure Job Nobody Wants
13:31
StationX
Рет қаралды 2,7 М.
Linus Torvalds: Speaks on Hype and the Future of AI
9:02
SavvyNik
Рет қаралды 347 М.
What Is Dynamic Application Security Testing (DAST)? | AppSec 101
19:41
Fortify Unplugged
Рет қаралды 23 М.
SEVEN things about API security By Philippe De Ryck
53:30
Devoxx
Рет қаралды 2,4 М.
Back to Basics: Efficient Async and Await - Filip Ekberg - NDC London 2022
1:01:59