In this presentation, Kevin Johnsonwill discuss how security works, why we do the things we do and where platforms and libraries can be both good and badwith a series of real world examples directly from his testing and assessment of modern applications and the SDLC.