YoVDO

Engineering Better Security at Facebook

Offered By: nullcon via YouTube

Tags

nullcon Courses PHP Courses HTML Courses

Course Description

Overview

Explore a comprehensive conference talk from nullcon Goa 2017 on engineering better security practices at Facebook. Delve into real-world security issues, vulnerability prevention, and detection techniques. Learn how Facebook empowers engineers to write more secure code through innovative tooling. Discover insights on the software development lifecycle, PHP, Hack, asynchronous functions, cross-site scripting, code abuse prevention, and code review processes. Examine linting techniques, Harold Rules, and production security measures. Investigate TLS, Certificate Transparency, and its practical applications. Gain valuable knowledge on scaling security efforts, managing false positives, and implementing effective security programs in large-scale environments. Benefit from the expertise of Karen Sittig, a Software Engineer at Facebook with a strong background in applied machine learning for security applications.

Syllabus

Introduction
About Karen
Software Development Lifecycle
PHP
Hack
Asynchronous function
Asynchronous call
Crosssite scripting
XHT
HTML
Example
Code Abuse
Code Reviews
linting
subscribe
Harold Rules
stuffing in production
Buzzers
Spring Deserialization
Head
TLS
Certificate Transparency
Certificate Transparency Example
Recap
Writing your code
Code review
Certificate transparency program
How do you scale
Rate of false positives
How far do we go
Herald Rules


Taught by

nullcon

Related Courses

Unearthing Malicious and Risky OpenSource Packages Using Packj
nullcon via YouTube
Pushing Security Left by Mutating Byte Code
nullcon via YouTube
The Faces of MacOS Malware - Detecting Anomalies in a Poisoned Apple
nullcon via YouTube
Contextomy - Let's Debug Together
nullcon via YouTube
Mind The Gap - The Linux Ecosystem Kernel Patch Gap
nullcon via YouTube