37C3 - Writing secure software

Title:
37C3 - Writing secure software
Description:

https://media.ccc.de/v/37c3-11811-writing_secure_software

using my blog as example

I have previously given talks about security principles and approaches like Least Privilege, TCB Minimization, and Self Sandboxing. The most frequent feedback has been "I don't know how to apply this in practice". So, in this talk, I will show how I applied those principles in a real-world software project: a CRUD web app. My blog.

I introduced dangerous attack surface on purpose so I could some day give a talk about how to apply these techniques to reduce risk. This is that talk.

I will also introduce the concept of append-only data storage.

The end goal of this talk is to show how much more security you can achieve if you don't take an existing architecture and try to sprinkle security over it, but you make architectural decisions with security in mind.

This is rarely done in practice because there is a fundamental disagreement between security and software engineering. Security is about limiting what can be done with the software, while software engineering is about not limiting what can be done with the software.

My goal with this talk is to show what kind of security gains are possible architecturally. You, too, can sleep soundly at night. Even if the software is written in C. Even if you have bad ACLs or a buffer overflow in the software.

Fefe

https://events.ccc.de/congress/2023/hub/event/writing_secure_software/

#37c3 #Security

more » « less
Video Language:
English
Duration:
46:39
C3Subtitles edited English subtitles for 37C3 - Writing secure software
C3Subtitles added new URL for 37C3 - Writing secure software
C3Subtitles added new URL for 37C3 - Writing secure software
C3Subtitles changed primary url from http://www.youtube.com/watch?v=TaE28fJVPTk to http://www.youtube.com/watch?v=TaE28fJVPTk
C3Subtitles added a video: 37C3 - Writing secure software
http://www.youtube.com/watch?v=TaE28fJVPTk
Format: Youtube
Primary
Original
Added   by C3Subtitles
Format: Youtube
Primary
Original
http://www.youtube.com/watch?v=2MXo95pBFkw
Format: Youtube
Added   by C3Subtitles
Format: Youtube
http://www.youtube.com/watch?v=6ve_uMzETsY
Format: Youtube
Added   by C3Subtitles
Format: Youtube
This video is part of Amara Public.

Subtitles download

Incomplete subtitles (1)