🔐 Is it a vulnerability, or just a misunderstood feature?
At #NodeCongress2025, I broke it down in my talk: "What is a Vulnerability and What’s Not"
Topics:
👉 Real vs. imagined risks in #Nodejs and #Express
👉 Why #threatModels matter
What is a Vulnerability and What’s Not? Making Sense of Node.js and Express Threat Models by Ulises Gascón
In this talk, we will discuss security, vulnerabilities, and how to improve your overall security. We will explore various vulnerabilities and the difference between developer errors and misconfigurations. Understanding threat models is crucial in determining responsibility for vulnerabilities. Developers have the ultimate responsibility for handling user input, network data, and other factors. Understanding threat models, best practices, and taking ownership of dependencies are key to improving security. Security is an ongoing process that requires dedication and understanding.