Application Security Learning Center

As a developer, you can prevent a data breach. Not by hoping you got security right, but by proving it: writing a failing test before the fix, writing abuser stories alongside user stories, and treating every security requirement the same way you’d treat any other one, as something that either passes or fails.

This track holds that idea in a lot of different shapes: a 60-second explainer, a full hour-long class, and conference talks recorded across the better part of a decade, on everything from patching a critical CVE under pressure to designing for GDPR to growing a real, policy-driven security program. Start wherever fits the five minutes you actually have.

Want more of this in your inbox instead of just on video? Subscribe to Rietta on Security, a low-volume newsletter on policy and technical trends in web application security.

Start Here

The Full Lecture

Quick Takes

Public Presentations

Frank Rietta presenting on a dark stage at a podium, with a projected slide reading "All security depends on software security."

Patch Production Now!

A conference talk on why timely patching of production systems is a non-negotiable part of application security, recorded at BSides Jackson.

Title slide reading "Securing the Open Source Software Supply Chain: Trusting third party code, CVEs, common attacks, and keeping up-to-date safely," with the HellaConf 2020 logo and Frank Rietta presenting in a webcam window.

Securing the Open Source Software Supply Chain

How malicious actors use open source libraries to attack applications, and a proactive approach to dependency management. Recorded at HellaConf 2020.

Presentation slide quoting Steve Blank, "A Startup is Not a Small Version of a Big Company," with Frank Rietta presenting at BSides Nashville in a corner video window.

Growing Up to Be an Infosec Policy-Driven Organization

How an organization matures from ad hoc security practices into a real, policy-driven information security program. Recorded at BSides Nashville 2018.

Slide titled "User Stories & Abuser Stories" with two stick figures, one wanting an easy login experience and one wanting to steal credentials, next to the Rocky Mountain Ruby logo and a photo of Frank Rietta speaking at the podium.

Defending Against Data Breaches, as a Practicing Ruby Developer

A 20 minute conference talk given at Rocky Mountain Ruby 2015 on defending against data breaches from the perspective of a practicing Ruby developer.

Frank Rietta presenting to colleagues around a conference table, with a screen behind him showing a "Commercial Information Classifications" slide listing five sensitivity levels.

What Information Do I Need to Secure?

An exercise in commercial information classification: figuring out which information actually needs to be kept secure, and why.

Frank Rietta standing beside a projector screen reading "Is XYZ secure? Ask three questions: secure against what, what's the worst thing that can happen, compared to what alternative."

Is Ruby on Rails Secure?

Security is not an on/off switch. Three questions to ask whenever you're evaluating the security of any framework or application.

Frank Rietta presenting beside a slide titled "Reducing Surface Area while Protecting Usability," listing bullet points on changing the business process, countermeasures, and limiting access.

Reducing an App's Vulnerability Surface Area While Maintaining Usability

How to eliminate vulnerability surface area at multiple levels while balancing the need for security against the need for usability.

Slide showing a UUID being stripped of dashes and combined with a long randomly generated password, with a photo of Frank Rietta presenting.

Does a UUID Make a Secure API Token?

Whether a UUID is a good, secure choice for a mobile app's API token, and how to build a secure token system if not.

Code editor showing a Rails configuration excluding sensitive fields like password and email from logs, under the heading "Step 1: Exclude new PII from Logs," with the Nash.rb logo.

GDPR on Rails: Designing for Security, Privacy, and Consent

A working Rubyist's briefing on designing Ruby on Rails applications for GDPR: security, privacy, and consent.

Screen recording of a browser showing a GitHub gist on converting serialized YAML to JSON in Rails models, alongside a code editor with related patch files, watermarked with the ATLRUG logo.

How to Efficiently Patch a Ruby on Rails Application When a Critical CVE Drops

A walkthrough of efficiently patching a Ruby on Rails application when a critical CVE drops, using a real ActiveRecord CVE as the working example.

A Eurasian eagle-owl in flight, wings fully spread, photographed head-on against a grassy background.

Breach Prevention for Developers

A guest lecture at Kennesaw State University on building security into web application development, for infosec students and professionals.

Title slide reading "How a Ruby/Rails developer can help prevent a Data Breach," by Frank S. Rietta, M.S. Information Security, with links to rietta.com/blog and @frankrietta on Twitter.

How a Ruby/Rails Developer Can Help Prevent a Data Breach

A full-length talk on how a Ruby on Rails developer can help prevent a data breach, recorded at the Atlanta Ruby Users' Group in 2014.