Security-Centered Design: Exploring the Impact of Human Behavior

Chris Shiflett (Jun 12, 2010 at 09:30)
Keynote at Dutch PHP Conference 2010 (English - UK)

Rating: 5 of 5

Security is more than filtering input and escaping output (FIEO), and it's more than cross-site scripting (XSS) and cross-site request forgeries (CSRF). Security isn't even always black and white. In order to create a more secure user experience, we need to understand how people think. Perception is as important as reality, and meeting user expectations is a fundamental of good security. In this multifarious talk, I'll explore topics such as change blindness and ambient signifiers, and I'll show some real-world examples that demonstrate the profound impact human behavior can have on security.

Comments

Rating: 5 of 5

Jun 12, 2010, 08:42 by marcelvanveelen

GREAT!

Rating: 5 of 5

Jun 12, 2010, 08:44 by koku

Great keynote!

Rating: 5 of 5

Jun 12, 2010, 08:45 by Gerb

I liked how Chris pointed out the various pitfalls of commonly accepted uxp principles, and how you need to come up with creative solutions to these challenges. Not unimportant: the talk was very entertaining.

Rating: 5 of 5

Jun 12, 2010, 08:48 by Smithy

Just as good as PHP London 09! Although I didn't see the change this time! Brilliant speaker and interesting points!

Rating: 5 of 5

Jun 12, 2010, 09:02 by orlissenberg

OMG I'm blind O_o

Rating: 5 of 5

Jun 12, 2010, 09:06 by TrafeX

Great talk, a real eye-opener

Rating: 5 of 5

Jun 12, 2010, 09:40 by jach

Great talk. Good introduction to some new stuff. Very interesting.

Rating: 5 of 5

Jun 12, 2010, 09:45 by kanenas.net

I wouldn't expect anything less! Great talk!

Rating: 5 of 5

Jun 12, 2010, 09:47 by ThijsFeryn

Second time I see this talk and I still absolutely love it. Is it about PHP? No ! Is it important for people involved with PHP? Yes !

I like the very relaxed, confident, but humble style Chris brings to the stage. The slides look good , but even cooler: they allow crowd interaction and there even some videos involved.

My favorite talk so far because it also deals with people rather than just technology.

Rating: 5 of 5

Jun 12, 2010, 09:55 by Jkeppens

Super talk! Informative, funny, natural born speaker.

Rating: 5 of 5

Jun 12, 2010, 10:09 by akrabat

I can only second everyone else. Excellent keynote providing food for thought.

Rating: 5 of 5

Jun 12, 2010, 12:53 by relaxnownl

Chris didn't dissapoint, very interesting and entertaining talk.

Rating: 4 of 5

Jun 12, 2010, 17:09 by richardhinkamp

Really entertaining keynote, fun way to bring a less fun (imho) topic.

Rating: 5 of 5

Jun 12, 2010, 18:56 by Marsman

Great and entertaining presentation which my coworkers should have seen. Nice to let the audience participate.

The only minor downside for me personally was I already knew the Amazing Color Changing Card trick and had already thought about this clip during the presentation before it was mentioned. Always a pleasure to see it again though.

Rating: 5 of 5

Jun 12, 2010, 19:58 by nuqqsa

Refreshing!

Rating: 5 of 5

Jun 12, 2010, 21:46 by esnoeijs

great keynote about the social side of security.

Rating: 5 of 5

Jun 12, 2010, 22:32 by brro

Saw the Amazing Color Changing Card trick before as well.
Still great presentation and worthy of being a keynote.

Rating: 5 of 5

Jun 13, 2010, 00:32 by Anonymous

Nothing much to add, except: great presentation, and glad i'm not clearly visible on the photo of the attendants.

Rating: 5 of 5

Jun 13, 2010, 20:52 by mcleod@spaceweb.nl

The best talk I ever attended so far. I liked many things about it. To point out just a few: Chris has a very calm and clear voice that makes it very easy to stay focussed. He not just made his points but also proved them in a strong way. The selection of images and examples was engaging. When I look back at it I still smile.

Rating: 5 of 5

Jun 14, 2010, 08:29 by arnolambert

wonderfull and entertaining view on human behaviour focussed on the web solutions. Loved it.

Rating: 5 of 5

Jun 14, 2010, 14:50 by stephane_wis

There is a lot of information I can use here ;-) I hope to find the video about the card deck trick.

Rating: 5 of 5

Jun 14, 2010, 18:18 by Martin1982

This was the best keynote I have ever seen. Although it wasn't technical at all, it showed us all something that we surely need to know but just don't come up with between the UML'ing and programming.
Although I was working on my own presentation I listened carefully and sometimes even looked up because I actually didn't want to miss this one.

Rating: 5 of 5

Jun 16, 2010, 15:57 by tswann

There's a reason this was a keynote talk - it was EXCELLENT.
It's not often you get to be so involved with a talk. Highlight of the event for me.

Speaker comment:

Jun 16, 2010, 16:57 by shiflett

Thank you all very much for the feedback! I really appreciate you taking the time to say such nice things, and I'm so happy you enjoyed it. :-)

Is Spam

Want to comment on this talk? Log in or create a new account or comment anonymously

Write a comment

 
Please note: you are not logged in and will be posting anonymously!
© Joind.in 2010