Drupal - Melbourne cryptoparty

11

Click here to load reader

description

A small talk ab

Transcript of Drupal - Melbourne cryptoparty

Page 1: Drupal - Melbourne cryptoparty

Drupal

Cryptoparty, Melbourne 27th Oct

@chrischinch

Page 2: Drupal - Melbourne cryptoparty

Overview

‘Drupal’ is a Trademark

Released under GPL license, as are all modules and themes

Drupal distributions

A healthy consultant / developer ecosystem

Acquia and commercialisation

Page 3: Drupal - Melbourne cryptoparty

You’re in good company…

Page 4: Drupal - Melbourne cryptoparty

Why use an Open Source CMS?

Freedom

After a bit of work

Especially with Drupal

Page 5: Drupal - Melbourne cryptoparty

Data in

CSV, XML, RSS, JSON, KML, OPML, RDF, SQL, SSO, Oauth, OpenID, Social Logins, phpBB, Joomla, Wordpress, LiveJournal…

And more!

Page 6: Drupal - Melbourne cryptoparty

Data Out…

CSV, RSS, XML, JSON, TXT, Serialize, Node Code

MORE

Page 7: Drupal - Melbourne cryptoparty

Security process

Open source

Security Team

Most vulnerabilities, “Bad practice”

drupalsecurityreport.org

Page 8: Drupal - Melbourne cryptoparty

Security Features

Passwords

Private keys

Cookies / Sessions

Passwords never emailed

Cross-site forgery / Scripting

Data Sanitisation

Database Abstraction Layer

Page 9: Drupal - Melbourne cryptoparty

Securing

Disabling PHP Filters

Check HTML Filters

Captcha / Mollom

Status Report

Error Logs

Page 10: Drupal - Melbourne cryptoparty

Privacy

Basic user tracking by default

Many other initial flaws slowly resolved

Public & private fields

Highly configurable permissions

Cookies / EU compliance

Page 11: Drupal - Melbourne cryptoparty

More?

Drupal Melbourne

www.meetup.com/drupalmelbourne

Australia’s first ‘official’ Drupal Con

Sydney, 6th Feb 2013