Search a title or topic

Over 20 million podcasts, powered by 

Player FM logo
Artwork

Content provided by SmartLogic LLC. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by SmartLogic LLC or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Michael Lubas on the Future of Elixir Security

40:30
 
Share
 

Fetch error

Hmmm there seems to be a problem fetching this series right now. Last successful fetch was on December 26, 2024 11:48 (4M ago)

What now? This series will be checked again in the next day. If you believe it should be working, please verify the publisher's feed link below is valid and includes actual episode links. You can contact support to request the feed be immediately fetched.

Manage episode 359982723 series 2493466
Content provided by SmartLogic LLC. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by SmartLogic LLC or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

In today's episode of Elixir Wizards, Michael Lubas, founder of Paraxial.io, joins hosts Owen Bickford and Bilal Hankins to discuss security in the Elixir and Phoenix ecosystem. Lubas shares his insights on the most common security risks developers face, recent threats, and how Elixir developers can prepare for the future.

  • Common security risks, including SQL injection and cross-site scripting, and how to mitigate these threats
  • The importance of rate limiting and bot detection to prevent spam SMS messages
  • Continuous security testing to maintain a secure application and avoid breaches
  • Tools and resources available in the Elixir and Phoenix ecosystem to enhance security
  • The Guardian library for authentication and authorization
  • Take a drink every time someone says "bot"
  • The difference between "bots" and AI language models
  • The potential for evolving authentication, such as Passkeys over WebSocket
  • How Elixir compares to other languages due to its immutability and the ability to trace user input
  • Potion Shop, a vulnerable Phoenix application designed to test security
  • Talking Tom, Sneaker Bots, and teenage hackers!
  • The importance of security awareness and early planning in application development
  • The impact of open-source software on application security
  • How to address vulnerabilities in third-party libraries
  • Conducting security audits and implementing security measures

Links in this episode:

Michael Lubas
Email - [email protected]
LinkedIn - https://www.linkedin.com/in/michaellubas/

Paraxial.io - https://paraxial.io/
Blog/Mailing List - https://paraxial.io/blog/index
Potion Shop - https://paraxial.io/blog/potion-shop
Elixir/Phoenix Security Live Coding: Preventing SQL Injection in Ecto

Twitter - https://twitter.com/paraxialio
LinkedIn - https://www.linkedin.com/company/paraxial-io/
GenServer Social - https://genserver.social/paraxial
YouTube - https://www.youtube.com/@paraxial5874

Griffin Byatt on Sobelow: ElixirConf 2017 - Plugging the Security Holes in Your Phoenix Application
Erlang Ecosystem Foundation: Security Working Group - https://erlef.org/wg/security
Article by Bram - Client-Side Enforcement of LiveView Security

Special Guest: Michael Lubas.

  continue reading

190 episodes

Artwork
iconShare
 

Fetch error

Hmmm there seems to be a problem fetching this series right now. Last successful fetch was on December 26, 2024 11:48 (4M ago)

What now? This series will be checked again in the next day. If you believe it should be working, please verify the publisher's feed link below is valid and includes actual episode links. You can contact support to request the feed be immediately fetched.

Manage episode 359982723 series 2493466
Content provided by SmartLogic LLC. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by SmartLogic LLC or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

In today's episode of Elixir Wizards, Michael Lubas, founder of Paraxial.io, joins hosts Owen Bickford and Bilal Hankins to discuss security in the Elixir and Phoenix ecosystem. Lubas shares his insights on the most common security risks developers face, recent threats, and how Elixir developers can prepare for the future.

  • Common security risks, including SQL injection and cross-site scripting, and how to mitigate these threats
  • The importance of rate limiting and bot detection to prevent spam SMS messages
  • Continuous security testing to maintain a secure application and avoid breaches
  • Tools and resources available in the Elixir and Phoenix ecosystem to enhance security
  • The Guardian library for authentication and authorization
  • Take a drink every time someone says "bot"
  • The difference between "bots" and AI language models
  • The potential for evolving authentication, such as Passkeys over WebSocket
  • How Elixir compares to other languages due to its immutability and the ability to trace user input
  • Potion Shop, a vulnerable Phoenix application designed to test security
  • Talking Tom, Sneaker Bots, and teenage hackers!
  • The importance of security awareness and early planning in application development
  • The impact of open-source software on application security
  • How to address vulnerabilities in third-party libraries
  • Conducting security audits and implementing security measures

Links in this episode:

Michael Lubas
Email - [email protected]
LinkedIn - https://www.linkedin.com/in/michaellubas/

Paraxial.io - https://paraxial.io/
Blog/Mailing List - https://paraxial.io/blog/index
Potion Shop - https://paraxial.io/blog/potion-shop
Elixir/Phoenix Security Live Coding: Preventing SQL Injection in Ecto

Twitter - https://twitter.com/paraxialio
LinkedIn - https://www.linkedin.com/company/paraxial-io/
GenServer Social - https://genserver.social/paraxial
YouTube - https://www.youtube.com/@paraxial5874

Griffin Byatt on Sobelow: ElixirConf 2017 - Plugging the Security Holes in Your Phoenix Application
Erlang Ecosystem Foundation: Security Working Group - https://erlef.org/wg/security
Article by Bram - Client-Side Enforcement of LiveView Security

Special Guest: Michael Lubas.

  continue reading

190 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Listen to this show while you explore
Play