Complete with Te Reo intro!
#OWASPNZ
#OWASPNZ
Basically ends up DoSing the machine he's presenting on. Genius!
#OWASPNZ
Who has one of those @LastWeekTonight NZ map stickers?
#OWASPNZ
🎶 Definitely not doing anything dodgy just uploading an innocent file! 🎶
#OWASPNZ
Just because you're using NoSQL database doesn't mean you have No SQL injection...
#OWASPNZ
What are you building?
What can go wrong?
What are you going to do about it?
#OWASPNZ
More entropy (randomness) makes the math harder/longer to calculate.
#OWASPNZ
Can anyone see it in plaintext?
No - excellent!
Yes - this is bad, very bad.
#OWASPNZ
Simple patterns.
Password reuse.
#OWASPNZ
- use longer passwords
- use a password manager
- use Multi-Factor authentication
Talk about this stuff!
#OWASPNZ
Not just other peoples' computers - its a whole platform that enables unparalleled flexibility & scalability.
@petrajane #OWASPNZ
@petrajane #OWASPNZ
It depends on the security of the provider but also how well you've secured your OWN side of the environment
@petrajane #OWASPNZ
All of us! We're all responsible for different aspects of security.
@petrajane #OWASPNZ
Orange might be the service provider responsibility in the IaaS model.
@petrajane #OWASPNZ
But there are always parts you're responsible for.
@petrajane #OWASPNZ
Its up to you. It's your responsibility to make the right decisions to choose the correct provider.
@petrajane #OWASPNZ
- a shared responsibility
- about trust, not control
- an ongoing commitment
- easier with a good plan
Awesome talk @petrajane!
#OWASPNZ
Not everything needs to be automated.
Not everything needs to be DevOps.
#OWASPNZ
#OWASPNZ
Special shout out to Agile Application Security by @lady_nerd (and others)! ❤️
#OWASPNZ
No photos! I'll tweets the bits I can. 😊
#OWASPNZ
She's pretty awesome!
#OWASPNZ
@judyofcare #OWASPNZ