Skip to content

[Talk Proposal] Secure Rails Development with Local HTTPS #93

Description

@benburkert

Abstract:
Building secure web applications is hard. Rails has a bunch of built-in security features, but some security risks are outside of Rail's purview. HTTPS encryption is a big one. Often as developers, we skip HTTPS in development and only run it in production. But this can lead to problems with per-customer hostnames, secure cookies, and mixed-content issues. The talk will include an overview of these problems, how (local) HTTPS works, and how it helps with secure development.

Bio:
Ben Burkert is the CTO of Anchor (https://anchor.dev/), a security product that helps companies deploy internal TLS encryption. Ben has been a Ruby developer since 2006, and has worked at various bay area startups including Heroku, GitHub, and Engine Yard.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions