Session

Pentesting Hex: Real Findings from the Ægis Initiative

Every Elixir developer uses the Hex package manager to ship their project. Businesses, universities, and even governments all rely on this critical infrastructure to adopt Elixir and deliver high quality software that drives billions of dollars in economic activity and growth. Given Hex is a load bearing pillar of Elixir, have you ever asked yourself: Is it secure?

Thanks to the Ægis Initiative, two real world penetration tests of Hex were funded, successfully completed, and directly resulted in serious security vulnerabilities being blocked from release. This work confirmed the design decisions made by the Hex core team laid an incredibly secure foundation, and led to improvements that have made Hex more secure than ever before. This presentation will cover the results of both tests (which are public for full transparency), and the remediation efforts that prove the core infrastructure of Elixir is safe in the hands of a world class team.


Talk Recording: https://www.youtube.com/watch?v=_fER9bzlSOE
Slides: https://docs.google.com/presentation/d/1jEDeu2PR-IHsZGrhB8bX0QoC8A-KClxTEySqSsCTG7M/edit?usp=sharing

Jonatan Männchen

CISO @ Erlang Ecosystem Foundation

Winterthur, Switzerland

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top