Talk in English - UK at phpDay 2016
Track Name:
Track 1
View Slides: http://www.slideshare.net/asgrim1/dip-your-toes-in-the-sea-of-security-phpday-2016
Short URL: https://joind.in/talk/fc2dc
(QR-Code (opens in new window))
Dip Your Toes in the Sea of Security
Comments
Comments are closed.
awesome talk to skratch the surface of security, and something more..
Security is a very wide and complex topic but this talk is a very comprehensive overview. Especially liked the real-world example and anecdotes.
Very nice and basic to little to medium talk, easy to comprehend and very useful
I'm not sure who was few parts of the talk intended for (not for beginners, but not for intermediate too). For example the CSRF vulnerability. I think it lacked the example what an attacker can do if you do not have your application secured. Somebody who knows how CSRF works usually knows how to implement CSRF tokens too. If you do not know what CSRF is, those tokens does not tell you much. I know you cannot squeeze everything in one hour. But the things you manage to squeeze into the talk should make sense too.
Nice talk! However, I'm not sure who were few parts of the talk intended for (not for beginners, but not for intermediate too). For example the CSRF vulnerability. I think it lacked the example what an attacker can do if you do not have your application secured. Somebody who knows how CSRF works usually knows how to implement CSRF tokens too. If you do not know what CSRF is, those tokens does not tell you much. I know you cannot squeeze everything in one hour. But the things you manage to squeeze into the talk should make sense too.
A good introduction to several attack vectors. Some explanations were not very clear, especially i the second part.
Great talk. Really valuable.
It was good, quite a lot of mistakes we have done in the past were covered but I didn't 100% understood the finalities of this talk: it was just a showcase or something else?
Still very good.
I liked this talk! informative enough for some security tips on php7.
I understand how you can't talk comprehensive about security in just 1 hour, so maybe it would worth to focus more on an objective (like talking exclusively on what changed on php7 best practices for handling security issues or talking a bit more in depth about the most common owasp vulnerabilities).
Very good anyway!
Nice talk about different vectors of security. May be it might be good to mention what is now trending (vulnerabilities) and how to protect yourself from them.
I just can't get enough... Security is crucial. Thanks for your advices!