Security-Centered Design: Don't Just Plan for Security; Design For It

Chris Shiflett (13.Nov.2008 at 15:00)
Talk at php|works/PyWorks (English - US)

Rating: 5 of 5

Anyone who has ever disabled a certain proprietary software firewall because of its constant, irritating demands for approval knows that secure development practices are useless if you don't design your product so that the security solutions are usable. User perception is as important as reality, and meeting user expectations is a fundamental of good security. In this talk, I demonstrate both usable and unusable security solutions and give you practical techniques for creating a secure user experience.

Who are you?

Claim talk

By clicking this button you are declaring that you are the speaker responsible for it and a claim request will be sent to the administrator of the event.

If the claim is approved you will be able to edit the information for this talk.

Are you sure?

 
Comments closed.

Comments

Rating: 5 of 5

13.Nov.2008 at 20:53 by Cal Evans

Excellent session. Chris is obviously knowledgeable in the area of security but he's also a good speaker. Unlike some speakers I've seen at other conferences, his presentation style does not get in the way of his material.

Rating: 5 of 5

13.Nov.2008 at 21:22 by Ivo Jansch

Chris called his session 'weird'. I wouldn't say it was weird, but it was very refreshing; a totally different style than most conference talks (with social experiments with the audience).

Quite remarkable demonstration about how security is much more than just 'escape output, filter input'.

Rating: 5 of 5

16.Nov.2008 at 17:22 by

Very interesting talk on how security is more than just writing secure code. A good user interface allows end users to help protect their own security. Also a good comparison between the credit card industry and interactive web sites/services.

Cloud server hosting by Combell Combell      © Joind.in 2012