Security - go do this.
Video at https://www.youtube.com/watch?v=8GMIm_Pcxuw
I have a version with notes, which may or may not be more useful. Email/message me if you want them!
Security: I Have 5 minutes,You Have a LifetimeBen Hughes, Etsy, obviously,just look at this slide.
View Slide
These are real graphs of *something*
Mean Time to PasteBin™
`photo by https://secure.flickr.com/photos/asjaboros/
https://secure.flickr.com/photos/izik/SSL**(TLS really)
https://secure.flickr.com/photos/refractedmoments/
https://secure.flickr.com/photos/gaby1
https://isTLSfastyet.com/Ummm, yeah, fast enough.big shout out to the design of this slide.
Password hashing: Just use bcrypt.
BUT WHAT ABOUT scrypt/PBKDF2/SpecialThing?
Cross Site Request Forgery
And you were worried HTTPS would slow things down…
Multi factorauthenticationAwesome taken apart SecureID token by https://www.flickr.com/photos/travisgoodspeed
Responsibledisclosure ispretty cool!
The winner takes it all!
Bounty HuntersYou may want to considertheir kind of scum.
https://github.com/etsyhttp://codeascraft.com/@benjammingh[email protected]