Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Frank Rietta — The convergence of Ruby on Rails and #AppSec

50 min6 oktober 2020

Om avsnittet

Ruby on Rails can provide strong security defaults, but a framework cannot make every design decision for its developers. Frank Rietta, a security-focused Rails developer and business owner, explains where the framework helps and where teams still need to think carefully. He traces his path into application security, describes Rails beyond its startup reputation, and discusses testing, secure coding guidance, and the familiar threats facing web applications. Frank also shares his work on RubyGems typosquatting and the risks introduced through dependencies. The practical discussion turns to Brakeman, Bundler Audit, and building checks into everyday development. His recurring advice is to combine useful tooling with deliberate design, maintained dependencies, and an understanding of how attackers can misuse ordinary features.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Frank Rietta:
Frank Rietta’s website

Mentioned in this episode:
Rails security guide
Brakeman
Bundler Audit

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Ruby on Rails and AppSec with Frank Rietta
01:14 Frank’s path into application security
07:13 Helping developers build security skills
11:00 What Ruby on Rails provides
14:01 Rails beyond early-stage startups
17:15 Security defaults and their limits
22:23 Secure coding guidance for Rails developers
25:20 Testing culture and security checks
29:13 The main threats facing Rails applications
32:14 Typosquatting and the RubyGems supply chain
38:32 Brakeman, Bundler Audit, and the security toolkit
45:11 Key takeaways for secure Rails development

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.