Velocity Conference Santa Clara 2014 Ignite

Security - go do this.

Video at https://www.youtube.com/watch?v=8GMIm_Pcxuw

Bea Hughes

June 24, 2014


  1. Security: I Have 5 minutes, You Have a Lifetime Ben

    Ben Hughes, Etsy
  3. Mean Time to PasteBin™

  SSL* *(TLS really)

  https://isTLSfastyet.com/

  10. Password hashing: Just use bcrypt.

  11. BUT WHAT ABOUT scrypt/ PBKDF2/SpecialThing?

  12. Cross Site Request Forgery

  13. And you were worried HTTPS would slow things down…

  Multi factor authentication

  16. Responsible disclosure is pretty cool!

  17. The winner takes it all!

  Bounty Hunters

  20. https://github.com/etsy http://codeascraft.com/ @benjammingh ben@etsy.com