Greg talking about OWSAP - Top 10 for Rails Developers
@gregmolnar at #friendlyrb
Greg @gregmolnar about how @rails has settings to help with security
#friendlyrb
Think about Insecure Design and about what could go wrong
@gregmolnar
#friendlyrb

Example of a code that allows SQL injection as second order SQL injection - @gregmolnar

#friendlyrb

Methods that when used wrong can allow SQL injection
@gregmolnar
#friendlyrb
"Broken Access Control is the most common security problem" - @gregmolnar

- Strong Authorization
- Whitelist approach
- UUIDs are not equal to authorization (UUIDs can be leaked for example)
- Foreign keys (eg. Allow user to set the foreign key for an association
#friendlyrb
@gregmolnar inviting us to subscribe to This Week in Rails
#friendlyrb