As pen-testers we spend all our time finding bugs. This leads us to focus on the negative side of the software we review, and see everything in terms of problems. However, at least in web app land, things are actually getting better. The classic security bugs are becoming increasingly rare over time (except in the odd app where you can play bingo), while the focus moves to business logic and access control. This talk covers a range of trends and techniques, which each chip away at the attack surface of an application. Used where possible, we can move web applications to a better place.