LangSec for the Masses

No ratings

Presented at lascon 2016 by

In the last few years LangSec has finally gained widespread exposure as a methodology and technique for building applications in such a way that user input cannot be used to change the behavior of applications in unintended ways. LangSec for the Masses is a followup to Trials and Tribulations in Applying LagSec first present in 2014 at Toorcamp. It provides a brief introduction to LangSec, explains why the vulnerability classes exist that it solves, and explains why it is the correct solution to solve them. From there is expands to a survey of common tools and techniques used for implementation, problems likely to encounter while implementing, and provides solutions to them. It is intended to serve as a guiding resource for engineers interested in introducing LangSec into their applications' architecture and provide the necessary primer for those interested in a LangSec solution to truly understand what the benefits and limitations of it are.