Brakeman And Rails Security: Mike Hall Interviews Justin Collins | RailsConf 2014
•
UGtastic Archive
Full Transcript Available
LIVE CC
UGtastic Archive
Press play or click any turn in the transcript to start real-time synchronized playback...
Mike Hall interviews Justin Collins, the creator of the Brakeman Gem, about the importance of static analysis security tools for Ruby on Rails applications. Learn about the challenges of creating a security tool and the importance of being a developer with security knowledge. Don't miss this talk at RailsConf 2014! #brakeman #railssecurity #rubyonrails #devsecurity #railsconf2014
The Interviewer
Mike Hall
Interviewer, UGtastic
The Guest
Justin Collins
Brakeman and Rails security
The Conversation
Mike Hall
Interviewer, UGtastic
▶ Speaking
Hi, it's Mike with UGtastic . I'm here again at RailsConf 2014 and I'm standing here with Justin Collins. Justin is going to be doing a talk tomorrow called "Tales from the Crypt" but he's also the creator of the Brakeman Gem. Well, thank you very much for taking the time to speak with me. First, can we start with the Brakeman Gem?
Justin Collins
Brakeman and Rails security
▶ Speaking
Because I'm a fan, but I'd like you to describe what it is.
Mike Hall
Interviewer, UGtastic
▶ Speaking
Sure.
Justin Collins
Brakeman and Rails security
▶ Speaking
So, the Brakeman Gem is a static analysis security tool for Ruby on Rails applications. So, it looks at your source code, finds potential vulnerabilities, and lets you know about them.
Mike Hall
Interviewer, UGtastic
▶ Speaking
Great.
Justin Collins
Brakeman and Rails security
▶ Speaking
But wait, it's a dynamic language.
Mike Hall
Interviewer, UGtastic
▶ Speaking
How can we do any kind of static analysis?
Justin Collins
Brakeman and Rails security
▶ Speaking
Oh, boy. So, I've talked about that quite a bit. You know, the important thing for a security tool is just finding stuff. And, yes, static analysis security purists may be upset because you can't prove certain things or you can't analyze certain things. But for a security tool, it's really not that important that it be perfect, but just that we're able to identify potential problems inside the source code. So, it's kind of like if you, just because you can't maybe identify everything, it doesn't mean that it's going to work.
Mike Hall
Interviewer, UGtastic
▶ Speaking
Yeah.
Justin Collins
Brakeman and Rails security
▶ Speaking
So, it's kind of like if you, just because you can't maybe identify everything, it doesn't mean that it's going to work.
Mike Hall
Interviewer, UGtastic
▶ Speaking
Yeah.
Justin Collins
Brakeman and Rails security
▶ Speaking
So, it's kind of like if you, just because you can't maybe identify everything, it doesn't mean that it's going to work.
Mike Hall
Interviewer, UGtastic
▶ Speaking
Yeah.
Justin Collins
Brakeman and Rails security
▶ Speaking
It doesn't mean you shouldn't identify problems statically just because you can't identify everything.
Mike Hall
Interviewer, UGtastic
▶ Speaking
Exactly. So what inspired you to create Brakeman?
Justin Collins
Brakeman and Rails security
▶ Speaking
It's kind of a long story, but I got an internship on a security team at AT&T Interactive. Knowing nothing about security or Rails, I proposed building a tool that finds vulnerabilities automatically. They let me open source it at the end of my internship, and then I worked for them later on it.
Mike Hall
Interviewer, UGtastic
▶ Speaking
So security is something you have a passion about?
Justin Collins
Brakeman and Rails security
▶ Speaking
I fell into it by accident! But creating a tool that helps people allowed me to get into the security community. As a developer, having security knowledge bridges the gap between developers trying to get work done and security teams.
Mike Hall
Interviewer, UGtastic
▶ Speaking
Anything that gives insight into what's going on in code is great. You said you can't cover everything—is there a common problem that's too hard to pin down statically that Rails developers should be thinking about?
Justin Collins
Brakeman and Rails security
▶ Speaking
Good question. Helper methods using `html_safe` are a big one. Developers trust helper methods, but if a helper sets `html_safe` while inserting user input, you get cross-site scripting. Check your gems and helpers to make sure they properly escape values.
Mike Hall
Interviewer, UGtastic
▶ Speaking
Which brings me to your talk, 'Tales from the Crypt'. I'm presuming encryption?
Justin Collins
Brakeman and Rails security
▶ Speaking
Good assumption, but we're not talking about encryption! To be honest, I didn't notice the pun until after the talk was accepted. We're presenting a developer's worst nightmare—one day in the life of developers facing security problem after security problem, with proactive steps to prevent bad days.
Mike Hall
Interviewer, UGtastic
▶ Speaking
I'm looking forward to your talk, and I really appreciate you taking the time to speak with me.
Justin Collins
Brakeman and Rails security
▶ Speaking
No problem, thank you very much!
Critical Insights
durable
"Brakeman is a static analysis security tool for Ruby on Rails applications."
durable
"Static analysis security tools are not perfect, but they are useful for identifying potential problems."
durable
"Security is something that developers can have a passion for, and it can help bridge the gap between developers and the security community."