Skip to content

Details

We are pleased to announce our June 13, 2013 meetup. As always, we'll be meeting at LivingSocial in Reston and we'll provide good food and good drinks.

Our June presenters are traveling from the west coast to share some of the awesome work they're doing at Twitter. If you work in a fast-paced, large development shop, you need to hear what they have to say.

Abstract: Security Automation at Twitter

Despite the apparent simplicity of Twitter, a large quantity of code is shipped every day. Despite our best efforts, the product security team cannot effectively review that much code. Using Brakeman, a static analysis security scanner for Ruby on Rails, was the first step towards automating the review process. However, this quickly grew into a need for automating not just running Brakeman, but also other security tools and technologies. For example, our effort to apply security headers universally across our sites requires a central location for analyzing CSP reports.

While working on and thinking about security automation, we have come up with a set of philosophies to help guide our decisions which we would like to share with you. In this talk we will discuss Brakeman and security headers in depth, along with how we have integrated these tools and others into our security automation dashboard (SADB).

Bios:

Neil Matatall is a security engineer at Twitter. With a background in
development, he tries to spend as much time writing code as possible
in a security role. He spends most of his time integrating,
augmenting, or creating tools for automation or applying programmatic fixes for systematic code problems as well as day-to-day reviews of Twitter systems.

https://twitter.com/ndm

Justin Collins is a security engineer at Twitter and a PhD candidate at UCLA. He mostly works on static analysis for security tools.

https://twitter.com/presidentbeef
https://github.com/presidentbeef/brakeman

Related topics

You may also like