December 19, 2019 — Malicious activity is an unfortunate reality when maintaining a web presence today. Most people involved in the web industry know someone who encountered the aftermath of a disruptive attack–if they haven’t themselves. Because of this, awareness of security best practices is at an all-time high. To many, though, it may not be clear exactly why these measures are important.
To remedy that, we’ll be taking a practical look at what’s actually happening when a website gets attacked, as well as discussing the hows and whys along the way. From understanding why small sites still get hacked, to why password reuse is really as bad as everyone says, we’ll explore the rationale behind the security principles you’re always being told to follow.
December 19, 2019 — As developers, we are capable of many amazing feats. We can create experiences that touch the lives of millions, brings aid to the corners of the world, empowers new businesses and bring a voice to the voiceless. WordPress powers over 30% of the entire web! However with this capability, we must also take on the responsibility for the people, and data, we interact with.
During this session, we’ll discuss how a culture of security can benefit not only your organization but also protect your end users and yes even the world. We’ll look at the ethics of privacy, secure web design and architecture, and the impact our decisions have on the community and our users. Mixed in will be best practices for secure coding, how to manage sensitive data from clients and users, compliance with various regulations and laws around privacy, and how to foster a culture of security even while you manage distributed teams. I’ll share my experiences from almost a decade in Open Source and some of the mistakes and successes I’ve had along the way.
Most of all, as WordPress continues to empower more and more of our digital world, it is up to us to decide as a community how we will use this influence and together we can work to make the world a better and safer place for people no matter where they come from.
December 10, 2019 — Why would a hacker hack YOUR website? For fun, for glory? Not anymore! Hacking websites is now a monetized criminal enterprise. They don’t care about your website, they care about your website computing resources.
An understanding of what the bad guys know (and how easy it is for them to operate) will motivate you to take a proactive approach to security prior to a hack – instead of spending tens of thousands to get your data back after the fact.
November 18, 2019 — WordPress è sicuro? Sì, certo! Tuttavia, un’installazione obsoleta di WordPress, con una password debole e plugin mal scelti, è decisamente vulnerabile.
Si dice spesso che “la sicurezza è un processo” e la sicurezza del proprio sito inizia con l’installazione di WordPress. Perché dovresti preoccuparti della sicurezza dal primo giorno, quando il tuo sito è nuovo di zecca e solo tua mamma lo legge? Cosa dovresti fare da solo, mentre il tuo sito cresce, quando non hai (ancora) il budget per assumere un esperto? Come puoi rendere più sicura la navigazione dei tuoi visitatori? Come puoi minimizzare il rischio di essere hackerato?
In questo talk, esaminerò alcune best practice che è possibile implementare per rendere il tuo sito più sicuro e perché dovresti averne cura. Nessuno di questi richiede una singola riga di codice. Tutto ciò di cui hai bisogno è buon senso e una buona comprensione di cosa fare e cosa non fare quando gestisci il tuo sito.
November 10, 2019 — Sometimes the bad guys get in, despite all the protections and precautions. If that happens, there are many techniques that can be used to stop further damage, track down what the intruder did and how they got in. Finally the site needs to be cleaned up and re-opened for visitors. In this talk the most important techniques are presented along with real-life examples when they were used.
October 29, 2019 — You installed a security plugin, and you don’t get much traffic anyway since your business is small…so you don’t need to worry about getting hacked, right?
While there are several good security plugins that are a useful part of a security plan, securing a WordPress site requires more than a plugin. Plugins are handy tools but can give a false sense of security if the entire security landscape is not considered.
You may not have a lot of money to invest, but you can learn a framework and some basic actions to help you get a better grasp on security for your website – and your business.
September 19, 2019 — Ο Νίκος έχει δει τον ιστοχώρο σου. Και σε έχουν χακάρει. Πάνω από μία φορές. Γιατί συμβαίνει αυτό; Δεν έχεις κανένα τεράστιο αποτύπωμα στο Internet. Είναι τα πάντα ανασφαλή; Είναι απάντηση ο μηδενισμός; Ή μήπως τα πράγματα είναι κάπως διαφορετικά και μπορείς κι εσύ να προστατέψεις τον ιστοχώρο σου και τον ιστοχώρο του πελάτη σου χωρίς να φας τα νιάτα σου και χωρίς να ξοδέψεις μια περιουσία;
August 11, 2019 — Everyone knows their site needs to be secure. But, just what does it take to make sure your site is optimally secure from compromise? In this workshop, whether you’re advanced or just starting out, we will help walk you through virtually every step it takes to make sure your WordPress environment is secure. We will start out with basics like what is security and general concepts about security. From there, we will walk you through selecting a secure hosting provider and choosing a secure password. Finally, we will go into more specific configuration details and the do’s and don’ts when securing your WordPress environment. By the time you walk out of this workshop you should feel like a WordPress security pro.
June 25, 2019 — You know security is important and want your site to be secure, but what will actually help? There’s so much information to be found on securing your site, but what are the myths and what actually helps? Find out how to avoid the myths and implement real security.
June 10, 2019 — Sometimes the bad guys get in, despite all the protections and precautions. If that happens, there are many techniques that can be used to stop further damage, track down what the intruder did and how they got in. Finally the site needs to be cleaned up and re-opened for visitors. In this talk the most important techniques are presented along with real-life examples when they were used.