Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Code Insecurity or Code in Security - Mano Paul

via YouTube

Overview

Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Explore a comprehensive conference talk on code security and insecurity, delving into the INSECURE framework. Learn about non-repudiation, error handling, cryptographic weaknesses, unsafe functions, and privilege elevation in code. Discover defensive strategies against various security threats, including injection attacks, spoofing, and reversible code. Gain insights into best practices for secure coding, such as implementing proper authorization checks and using non-admin accounts for code execution. Enhance your understanding of code security principles and practical defense mechanisms to improve your software development practices.

Syllabus

whoami
What is this talk about?
More than what meets the Eye
Code Insecurity (INSECURE Framework)
N - Non-repudiation non-existent
E - Errors & Exceptions Mis-/Un-handled
C-Cryptographically Weak Code
U - Unsafe / Unused Functions in Code Banned Ansecure Ale Unknown APIs and Interfaces Vestigial Functions (Crl+C. Ctrl+X, Ctrl+V)
E - Elevated in Privileges
Defense against Injection
Defense against Non-repudiation
Defense against Spoofing
Defense against Errors & Exception Mis-/Un-handling Laconic error messages
Defense against Cryptographically Weak Code
Defense against Unsafe / Unused Functions
Defenses against Reversible Code
Defenses against Elevated Privileges Check authorization before allowing privileged operations Non-admin accounts used for code execution
Conclusion

Reviews

Start your review of Code Insecurity or Code in Security - Mano Paul

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.