Very good info and concise example code. Could have been better if the discussion was geared around some (simple) real-life examples.
Really interesting concepts, lots to think about. Mic would have been really nice
great talk
Well-delivered overview of important security concepts. The visualizations were entertaining and helpful, driving home the real-world effects of the vulnerabilities. They underscore the point that it's not just about throwing up an alert box and giggling.
Could have used a little more explanation about using CSRF tokens.
Also, I was shocked I didn't see reference to the iconic Bobby Tables.
https://xkcd.com/327/
Thanks for putting together this presentation.
Good refresher on simple things we can do to be more secure! Great speaker and talk.
Great high-energy speaker with fun examples. Highly recommended. This talk peels back some layers of abstractions the frameworks give you (filtering, escaping) and reminds you of everything you should be thinking about!
Very knowledgeable, you know your stuff.
Consider revising talk for 50 min session, consider screen shots in presentation rather than live demonstration. Consider larger text so the audience can see what is on the screen
Excellent topic and really good delivery. We all need to be reminded about basic security concerns when dealing with web apps. I would have enjoyed a few more code samples that highlight the best practices that were mentioned.
I was already familiar with the OWASP Top 10, but this talk really made it so much clearer, with the understandable explanations and real-world examples. Entertaining, too. Thank you!
Ecxellent talk! I would like to hear a little about persistent cache engines