Go offline with the Player FM app!
140: Web Application Security, Part 1 with Scott Arciszewski
Manage episode 214305874 series 2410493
In this weeks episode we chat with Scott Arciszewski about all things Security and Cryptography. We start off the show by explaining how he got interested in this field of work, correcting PHP security related answers on Stack Overflow and why he focuses on PHP security. From here, we move on to highlight what the OWASP Top Ten is, how you can distill many security principles into data/code seperation and what is involved in a software audit. This leads us on to discuss what HTTPS actually is, touching on TLS, PKI’s, Ciphersuites, and reported attacks against TLS and ECB. Finally, we highlight some important browser security features that can be used, pushing new software releases in a secure manor, thoughts on Cryptocurrencies and how everyone wants to solve their problem with a blockchain at this time.
Show Links
- Scott Arciszewski on Twitter
- Paragon Initiative Enterprises
- The 2018 Guide to Building Secure PHP Software
- RPG Maker
- Hack This Site!
- The Enigma Group
- PHP Password Hashing
- Problematic PHP Cryptography Advice in Popular Questions - Meta Stack Overflow
- Usage Statistics of Server-side Programming Languages for Websites
- Hardened-PHP Project
- The Month of PHP Security
- Psalm - a static analysis tool for PHP
- OWASP Top Ten Project
- Burp Suite Scanner
- OWASP Zed Attack Proxy Project
- On The Design and Implementation of a Stealth Backdoor for Web Applications
- Padding oracle attack
- Public key infrastructure
- PCI Council pushes back TLS 1.0 End of Life Date to June 2018
- The ECB Penguin
- Attacks against Transport Layer Security
- DigiNotar SSL certificate hack amounts to cyberwar, says expert
- Is TLS Fast Yet?
- Content Security Policy - An Introduction
- Subresource Integrity
- CMS Airship - Secure PHP CMS for the Modern Web
- paragonie/chronicle - Public append-only ledger microservice built with Slim Framework
- Zcash - All coins are created equal.
164 episodes
Manage episode 214305874 series 2410493
In this weeks episode we chat with Scott Arciszewski about all things Security and Cryptography. We start off the show by explaining how he got interested in this field of work, correcting PHP security related answers on Stack Overflow and why he focuses on PHP security. From here, we move on to highlight what the OWASP Top Ten is, how you can distill many security principles into data/code seperation and what is involved in a software audit. This leads us on to discuss what HTTPS actually is, touching on TLS, PKI’s, Ciphersuites, and reported attacks against TLS and ECB. Finally, we highlight some important browser security features that can be used, pushing new software releases in a secure manor, thoughts on Cryptocurrencies and how everyone wants to solve their problem with a blockchain at this time.
Show Links
- Scott Arciszewski on Twitter
- Paragon Initiative Enterprises
- The 2018 Guide to Building Secure PHP Software
- RPG Maker
- Hack This Site!
- The Enigma Group
- PHP Password Hashing
- Problematic PHP Cryptography Advice in Popular Questions - Meta Stack Overflow
- Usage Statistics of Server-side Programming Languages for Websites
- Hardened-PHP Project
- The Month of PHP Security
- Psalm - a static analysis tool for PHP
- OWASP Top Ten Project
- Burp Suite Scanner
- OWASP Zed Attack Proxy Project
- On The Design and Implementation of a Stealth Backdoor for Web Applications
- Padding oracle attack
- Public key infrastructure
- PCI Council pushes back TLS 1.0 End of Life Date to June 2018
- The ECB Penguin
- Attacks against Transport Layer Security
- DigiNotar SSL certificate hack amounts to cyberwar, says expert
- Is TLS Fast Yet?
- Content Security Policy - An Introduction
- Subresource Integrity
- CMS Airship - Secure PHP CMS for the Modern Web
- paragonie/chronicle - Public append-only ledger microservice built with Slim Framework
- Zcash - All coins are created equal.
164 episodes
All episodes
×
1 164: Delving into Elixir with Keyvan Akbary 1:07:07

1 163: Building SaaS Products with Simon Bennett 48:10

1 161: Exploring Bitcoin with Mattias Geniar 1:14:26

1 160: Serverless PHP using Bref with Matthieu Napoli and Neal Brooks 51:21

1 159: PHP Test Tooling and RFC Roundup with Joe Watkins 56:37

1 158: Hexagonal Architecture (Ports and Adapters) with Matthias Noback 1:01:16

1 157: The Symfony Ecosystem with Nicolas Grekas 49:55

1 156: Running Symfony on AWS Lambda with Neal Brooks 57:42

1 155: Bridging the Security Gap with Scott Arciszewski 1:12:30

1 154: Why all the Curly Braces? with Scott Wlaschin 1:10:08

1 151: AWS, Golang and iOS Development with Alex Bilbie 1:00:22

1 150: PHP was not designed for that?! with Joe Watkins 44:38
Welcome to Player FM!
Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.