Many, many years ago Aaron Bedra did a talk at Clojure/conj highlighting the (at the time) poor default state of web app security in Clojure. Because the Clojure community is awesome, that quickly resulted in a lot of changes to the defaults in Ring, Compojure, etc and fixed many of the problems.
Several years later, Joy Clark did a talk called Simple AND Secure? at EuroClojure 2017. This talk goes through the OWASP Top 10 areas (for 2017) and looks at what Clojure provides for web apps in those areas. I think most of it is still relevant and worth watching (but keep in mind this is 4 years old).
I think now is a good time for an update, both on the threats and the state of Clojure with respect to them. If you’re pitching things to a Clojure conference in the next year, I think this would be a great topic!
0 Comments
Log in to join the conversation.No comments yet. Be the first to share your thoughts.