We just sent you a verification email. Please verify your account to gain access to
Node Summit 2017 | San Francisco. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Register For Node Summit 2017 | San Francisco
Please fill out the information below. You will recieve an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for Node Summit 2017 | San Francisco.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
Node Summit 2017 | San Francisco. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Sign in to gain access to Node Summit 2017 | San Francisco
Please sign in with LinkedIn to continue to Node Summit 2017 | San Francisco. Signing in with LinkedIn ensures a professional environment.
Are you sure you want to remove access rights for this user?
Details
Manage Access
email address
Community Invitation
Guy Podjarny, Snyk | Node Summit 2017
Guy Podjarny, Snyk, sits down with Jeff Frick at Node Summit 2017 in San Francisco, CA
Snyk tackles security risk in open-sourced Node.js libraries
https://siliconangle.com/2017/08/01/snyk-tackles-security-risk-open-sourced-node-js-libraries-nodesummit/
In modern web applications based on open-sourced libraries, often times developers are not aware of just how much dependency there is on risky third-party software packages. Guy Podjarny (pictured), co-founder and chief executive officer at Snyk Ltd., explained how his company is ensuring developers are working with Node.js packages free from security flaws. Node.js is an open-source JavaScript runtime based on Chrome’s V8 engine.
“Snyk deals with open-source security, specifically in Node.js in the world of NPM [Node Package Manager]. NPM is amazing and allows us to build on the shoulders of giants. But there are some inherent security risks with just pulling code off the internet and running it in your application,” Podjarny said.
Snyk spoke with Jeff Frick (@JeffFrick), host of theCUBE, SiliconANGLE Media’s mobile livestreaming studio, during Node Summit in San Francisco.
Dependency on risky code
Podjarny provided an extreme example of how one simple application can be exposed to a potentially large number of security threats.
“It has 19 lines of code, which uses two packages, which in turn uses 19 packages, which bring in 190,000 lines of code.… The majority of code in your application, especially with Node, is not first-party; it’s third-party code. And that means most of your security risk crops up there,” Podjarny said.
The trend toward server-less computing is driving more risk up the stack into the application space where developers spend more of their time implementing custom code based on NPM packages, Podjarny explained.
“A lot of the lower levels get abstracted away. You don’t need to manage servers or operating systems. With that, a lot of security concerns go away which focuses the attackers on the application.… So platform as a service really increases the importance of dealing with application security well,” Podjarny concluded.
@Snyk #Snyk @guypod @snyksec #NodeSummit @SiliconANGLE theCUBE @theCUBE #theCUBE