



Complete with Te Reo intro!
#OWASPNZ



#OWASPNZ
Basically ends up DoSing the machine he's presenting on. Genius!
#OWASPNZ


Who has one of those @LastWeekTonight NZ map stickers?
#OWASPNZ

🎶 Definitely not doing anything dodgy just uploading an innocent file! 🎶
#OWASPNZ
Just because you're using NoSQL database doesn't mean you have No SQL injection...
#OWASPNZ

What are you building?
What can go wrong?
What are you going to do about it?
#OWASPNZ

More entropy (randomness) makes the math harder/longer to calculate.
#OWASPNZ


Can anyone see it in plaintext?
No - excellent!
Yes - this is bad, very bad.
#OWASPNZ

Simple patterns.
Password reuse.
#OWASPNZ


- use longer passwords
- use a password manager
- use Multi-Factor authentication
Talk about this stuff!
#OWASPNZ

Not just other peoples' computers - its a whole platform that enables unparalleled flexibility & scalability.
@petrajane #OWASPNZ

@petrajane #OWASPNZ

It depends on the security of the provider but also how well you've secured your OWN side of the environment
@petrajane #OWASPNZ

All of us! We're all responsible for different aspects of security.
@petrajane #OWASPNZ

Orange might be the service provider responsibility in the IaaS model.
@petrajane #OWASPNZ

But there are always parts you're responsible for.
@petrajane #OWASPNZ

Its up to you. It's your responsibility to make the right decisions to choose the correct provider.
@petrajane #OWASPNZ

- a shared responsibility
- about trust, not control
- an ongoing commitment
- easier with a good plan
Awesome talk @petrajane!
#OWASPNZ

Not everything needs to be automated.
Not everything needs to be DevOps.
#OWASPNZ

#OWASPNZ

Special shout out to Agile Application Security by @lady_nerd (and others)! ❤️
#OWASPNZ

No photos! I'll tweets the bits I can. 😊
#OWASPNZ
She's pretty awesome!
#OWASPNZ
@judyofcare #OWASPNZ
