Главная
Study mode:
on
1
Intro
2
What is Startup Security
3
The Problem with Security
4
Meet the Team
5
What is Exfil
6
Challenges
7
Application Security
8
Host Security
9
Technologies
10
Languages
11
Security Challenges
12
Security Tools
13
CI Pipeline
14
linting downsides
15
fuzzing
16
password hashing
17
fuzz
18
Security reviews
19
Choosing dependencies
20
Automating dependencies
21
Express vulnerability
22
Amazon EC2
23
Things to do right away
24
Amazon Checklist
25
Console Axis
26
Policy Conditions
27
Jumpboxes
28
Duo PAM
29
Network Structure
30
AWS Alerts
31
Logs
32
Infrastructure
33
Packer
34
JSON
35
Security Groups
36
Terraform
37
Managing Secrets
38
Code Ship
39
Parameter Store
40
Next Steps
Description:
Explore startup security strategies in this 47-minute LASCON conference talk. Learn how to integrate security measures without impeding progress or increasing developer workload. Discover open-source tools and automated processes for dependency, code, and infrastructure security. Gain insights into building security into the pipeline, approaching new technologies, and implementing proactive controls. Examine application and host security challenges, various technologies and languages, and security tools like CI pipeline, linting, fuzzing, and password hashing. Understand how to conduct security reviews, choose dependencies, and automate vulnerability checks. Dive into Amazon EC2 security best practices, including console access, policy conditions, and jumpboxes. Explore network structure, AWS alerts, logs, and infrastructure management using Packer, JSON, and Terraform. Learn about managing secrets and leveraging AWS Parameter Store for code deployment.

Startup Security - Making Everyone Happy

LASCON
Add to list