Netflix Security
Netflix Security
  • 13
  • 43 982
Scaling Security - Appsec
Scaling Security: Appsec event that Netflix co-hosted with Twilio and GitHub on 28 April 2022. It is a series of lightning talks about how we each scale our approach to Application Security.
- "Engineering Fundamentals: How GitHub tracks security tech debt" - Phil Turnbull, Github
- "Democratizing Vulnerability Management: Making Risk everyone's responsibility" - Vlad Perelmuter and Ariel Shin, Twilio
- "Asset Inventory & Prism: a graph-based approach to Application Security" - Dave King and Dan Kohlbrenner, Netflix
Переглядів: 4 331

Відео

Risk-based Security Decision Making at Netflix
Переглядів 4 тис.2 роки тому
Netflix presentation on quantified risk by Prashanthi Koutha and Shannon Morrison at WiCys SV event - Oct 2021 This talk covers how we use risk to make informed decisions, and includes a deep dive into application risk quantification. We will describe our process to survey experts on application features to gather target variables of frequency and magnitude, and will describe how we use machine...
Product Security lessons from Incident Response
Переглядів 2,1 тис.3 роки тому
From the Loco Moco Security Conference on Nov 6, 2020. by Astha Singhal Traditional security teams have largely independent proactive and reactive security functions. This comes from organizational distance and vastly different charters and measures of success for these capabilities. Many modern product security teams now work a lot closer with incident response, in some cases even owning certa...
Communication Challenges in Information Security
Переглядів 7533 роки тому
A Panel Discussion hosted by the Netflix Security team in January 2021. An engaging & authentic conversation with three great security leaders (Jason Chan, Frederick Lee, Coleen Coolidge) about Communication Challenges in Information Security. We touch upon the power of storytelling in Information Security and how our communication styles are impacted by culture, background, and identity.
Netflix Product & Application Security Panel
Переглядів 2,1 тис.3 роки тому
Note: This is a recording of a virtual 'after hours' event that took place during USENIX Enigma 2021 on February 2, 2021. Panelists: Astha Singhal, Director of Application Security at Netflix, Nitzan Blouin, Product Security Manager at Spotify, Mike Shema, Product Security Lead at Square and Arkadiy Tetelman, Head of Application and Infrastructure Security at Chime Hosts: Julia Knecht & Patrick...
Securing the Studio: How Netflix Protects Productions from Pitch to Play
Переглядів 5 тис.4 роки тому
Note: This is a recording of an evening event that took place during USENIX Enigma 2020 on January 27, 2020. Speakers: Ben Lim, Manager of Studio Information Security; Patrick Thomas, Senior Security Partner in Application Security; and Stephanie Cheng, Studio Technology Product Manager Many thousands of people worldwide are working to make movies and shows for Netflix. They include writers, di...
FIRST Podcast 2018
Переглядів 7495 років тому
FIRST Podcast 2018
Defending Netflix from Abuse
Переглядів 1,7 тис.7 років тому
Netflix is the world’s leading Internet television network with over 83 million members in over 190 countries enjoying more than 125 million hours of TV shows and movies per day. We’ll discuss the range of unique abuse-related challenges we face, including techniques we’ve developed to detect and remediate specific issues such as account takeover and payments fraud. We’ll cover techniques for u...
User Focused Security at Netflix: Stethoscope
Переглядів 4,4 тис.7 років тому
User Focused Security is an approach we are using to address employee information security at Netflix. If we provide employees with the right information and low-friction tools, we believe they can get their devices into a more secure state without heavy-handed policy enforcement. Letting people retain control over their devices means that they can maintain flexibility and productivity and addr...
OSCON 2016: Netflix BLESS
Переглядів 15 тис.8 років тому
BLESS: How Netflix gives all its engineers SSH access to instances running in production.

КОМЕНТАРІ

  • @Wolfraise
    @Wolfraise 9 місяців тому

    Does anyone implemented this with new ssh key ed25519

  • @vpxc
    @vpxc Рік тому

    Hey! I saw a conference talk once about Netflix's original rollout of semgrep for AppSec, but I can't seem to find it now. :( Does anyone at Netflix have a copy or link?

  • @stackoverflow84
    @stackoverflow84 Рік тому

    Would be great if there's a quick link in the description or video chapters to get to content of interest. For i.e, I wanted to specifically get to Dan and Dave's content from the start of the video.

  • @FirehawkVFX
    @FirehawkVFX Рік тому

    I love this talk. One of the issues I have with validity windows in AWS is that web browser sessions will just force re-authentication after a short window like 10-30 mins, and then you have to just start over again. I'm yet to solve that neatly.

  • @RichBarilla
    @RichBarilla Рік тому

    A WAF is not overrated, so he's wrong. A WAF with exploit-specific detection is 100% necessary to BLOCK what is KNOWN in the wild. Secondly, the # of secure coding bugs continues to increase over the past 20 years, therefore the NEED for WAF is increasing since secure code bugs increases. The gentleman has no idea what he's talking about -- I'm tired of quasi-experienced ITSec folks forming opinions publicly to the masses without being checked for integrity, common sense, logic, knowledge, experience, and reality. IF secure coding was getting better (and NOT EXPANDING exponentially) then you can make the claim that a WAF is overrated or unnecessary. Also, for production code, fixing secure coding bugs is exponentially more expensive $$$$ than deploying a signature-OWASP-based WAF. An open source WAF which costs almost nothing is exponentially more valuable than secure coding. Web App developers are lucky and used to having a WAF protecting them. Hiding a vulnerability being a negative WAF attribute is just a silly statement... barilla.ink or menschrisk.com

  • @MarcVandenplas
    @MarcVandenplas 2 роки тому

    They did a good job presenting what most people don't readily grasp.

  • @ultimaz100
    @ultimaz100 2 роки тому

    This sounds like some high school academic project with almost no value add to Netflix.

    • @tolchelmikhail35
      @tolchelmikhail35 Рік тому

      How can enabling the cost effective decision making process add no value?

  • @aideenfay4744
    @aideenfay4744 3 роки тому

    Awesome storytelling and info sharing. In future, I'd definitely request for Netflix slide deck to have more color contrast so the slides are easy to read for everyone (grey can be hard to see against dark grey background)

  • @rjoshi298
    @rjoshi298 3 роки тому

    Thank you for sharing the information. This is extremely helpful.

    • @spindavidspin
      @spindavidspin Рік тому

      For the last time I was there to get 💯. I have a good mmm 😭♥️😭

  • @jasonfanclub4267
    @jasonfanclub4267 4 роки тому

    please provide a link to the slides

  • @mdjuniorful
    @mdjuniorful 4 роки тому

    02:00 - Building an Animation Studio 13:10 - Tackling Scale at Netflix with an Embedded Security Model 27:10 - Securing the Netflix Connected Studio 42:00 - Questions

  • @timleungck
    @timleungck 5 років тому

    how to securely collect the security config of a device? do you install an agent on their device? how do you prevent attacker from spoofing those traffic, can the user send green traffic even their device is not compliant?

  • @jasonfanclub4267
    @jasonfanclub4267 5 років тому

    nice work!

  • @valerievanbuskirk1318
    @valerievanbuskirk1318 7 років тому

    I called the first number that google gave for your help line.. turned out to be bogus number wanting me to pay 200 dollars to get rid of hackers.. leading me to believe my netflix had been hacked! I hung up feeling it was a scam, please look into this

  • @manishkochar
    @manishkochar 8 років тому

    Excellent Presentation, absolutely copy-book.