Group 4 Created with Sketch.

JSJ 294: Node Security with Adam Baldwin

01:08:31
Play Audio
Add to Playlist
Share Report
Snippets are a new way to share audio!
You can clip a small part of any file to share, add to playlist, and transcribe automatically. Just click the to create your snippet!
Top Snippets - JSJ 294: Node Security with Adam Baldwin
Found on these Playlists
Add to Playlist
Full Description
Back to Top
Panel: 

Charles Max Wood

AJ O’Neal

Joe Eames

Special Guests: Adam Baldwin

In this episode, JavaScript Jabber panelist speak with Adam Baldwin. Adam is a return guest and has many years of application security experience. Currently, Adam runs the Node Security Project/Node Security Platform, and Lift Security. Adam discusses the latest of security of Node Security with Charles and AJ. Discussion topics cover security in other platforms, dependencies, security habits, breaches, tokens, bit rot or digital atrophy, and adding security to your development.

In particular, we dive pretty deep on:


What is  the Node Security Project/Node Security Platform
Dependency trees
NPM
Tokens and internal data
What does Node Security do for me?
NPX and NSP
Command Line CIL
Bit Rot or Digital Atrophy
How often should you check repos.
Advisories
If I NPM install?
Circle CI or Travis
NSP Check
What else could I add to the securities?
Incorporate security as you build things
How do you find the vulnerabilities in the NPM packages
Two Factor authentication for NPM
Weak Passwords
OL Dash?
Install Scripts
Favorite Security Story?
And much more!


Links:


Node Security 
Lift Security
https://github.com/evilpacket
@nodesecurity
@liftsecurity
@adam_baldwin


Picks:

Adam


Key Base
Have I been Pwned?


Charles


Nettie Pot 
convo.com


AJ


This Episode with Adam Baldwin
Free the Future of Radical Price
Made In America Sam Walton
Sonic - VGM Album


Joe


Pych - Movie
NG Conf
Why We Don’t Suck