Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Security First
Search
Adam Baldwin
September 15, 2013
Technology
0
75
Security First
JSConfEU 2013
Adam Baldwin
September 15, 2013
Tweet
Share
Other Decks in Technology
See All in Technology
~Everything as Codeを諦めない~ 後からCDK
mu7889yoon
3
270
SREが向き合う大規模リアーキテクチャ 〜信頼性とアジリティの両立〜
zepprix
0
400
制約が導く迷わない設計 〜 信頼性と運用性を両立するマイナンバー管理システムの実践 〜
bwkw
3
860
使いにくいの壁を突破する
sansantech
PRO
1
120
All About Sansan – for New Global Engineers
sansan33
PRO
1
1.3k
入社1ヶ月でデータパイプライン講座を作った話
waiwai2111
1
240
usermode linux without MMU - fosdem2026 kernel devroom
thehajime
0
210
Introduction to Sansan, inc / Sansan Global Development Center, Inc.
sansan33
PRO
0
3k
セキュリティについて学ぶ会 / 2026 01 25 Takamatsu WordPress Meetup
rocketmartue
1
290
会社紹介資料 / Sansan Company Profile
sansan33
PRO
15
400k
GitHub Issue Templates + Coding Agentで簡単みんなでIaC/Easy IaC for Everyone with GitHub Issue Templates + Coding Agent
aeonpeople
1
180
オープンウェイトのLLMリランカーを契約書で評価する / searchtechjp
sansan_randd
3
650
Featured
See All Featured
Documentation Writing (for coders)
carmenintech
77
5.2k
AI in Enterprises - Java and Open Source to the Rescue
ivargrimstad
0
1.1k
Mind Mapping
helmedeiros
PRO
0
77
Balancing Empowerment & Direction
lara
5
880
The Cult of Friendly URLs
andyhume
79
6.8k
The Mindset for Success: Future Career Progression
greggifford
PRO
0
230
Git: the NoSQL Database
bkeepers
PRO
432
66k
Noah Learner - AI + Me: how we built a GSC Bulk Export data pipeline
techseoconnect
PRO
0
100
30 Presentation Tips
portentint
PRO
1
210
A Guide to Academic Writing Using Generative AI - A Workshop
ks91
PRO
0
190
Java REST API Framework Comparison - PWX 2021
mraible
34
9.1k
Producing Creativity
orderedlist
PRO
348
40k
Transcript
Security First
None
None
Thanks First
Hi, I’m Adam
Hi, I’m Adam @adam_baldwin @liftsecurity @nodesecurity
Hi, I’m Adam @evilpacket
None
andbang.com
andbang.com
None
None
Node Security Project nodesecurity.io
Security First
We’re Fucked
Nothing is 100% Secure.
None
None
Defender Attacker
Defender Attacker
None
Attacker Defender
Software is Hard
Software is full of opinions
None
Mobile First
Mobile First Content First
Mobile First Content First Offline First
Mobile First Content First Offline First SECURITY
Software is full of constraints
Security is one of those
Who’s responsible for security?
Who’s responsible for security? You are.
Why?
None
NSA Spent $25 million on ‘software vulnerabilities’ in 2013
Stay off the menu.
Litigation is coming.
Litigation is coming.
Enough Doom & Gloom already!
Enough Doom & Gloom already!
Something has to change
Let’s build a Security First culture
None
Why do we avoid security?
- Ignorance - Procrastination - Not Exciting work - Not
Rewarded
Education Understand Vulnerabilities
The simple stuff still works.
None
Validation / Sanitization Crypto http://www.matasano.com/articles/crypto-challenges/ http://owasp.org
npm install all the things™
npm install coffeescript
so..ahhh. what else?
Process It’s not immutable
Community Bridge all the worlds http://blog.andyet.com/2013/09/11/shame-and-security
security.md
Homework. - Learn about 1 vuln - Audit some code
- Teach a Friend
confwork? Talk to each other about security...
</PRESENTATION> @adam_baldwin | @LiftSecurity