Go and tell your family and friends. Break out! #prism
Using itsdangerous (HMAC and SHA1 based signing utility lib) in another project. Thanks @mitsuhiko!
MACAuth
Online backups for the truly paranoid
(0.30$ / GB-month)
Tarsnap is a secure online backup service for BSD, Linux, OS X, Minix, Solaris, Cygwin, and probably many other UNIX-like operating systems. The Tarsnap client code provides a flexible and powerful command-line interface which can be used directly or via shell scripts.
@SlexAxton @rem definitely use pbkdf2. See for details and to s/bcrypt/pbkdf2. Sha-ing won’t do.
If your Python application has users, you should be worried about security. This talk will cover advanced material, highlighting common mistakes. Topics will include hashing and salts, timing attacks, serialization, and much more. Expect eye opening demos, and an urge to go fix your code right away.
security cheat sheets for developers #owasp
DOM Snitch is an experimental Chrome extension that enables developers and testers to identify insecure practices commonly found in client-side code.
HTTPS Everywhere is a Firefox extension that encrypts your communications with a number of major websites.
Useful + interesting technology behind the scenes.