An appeal for security for the ordinary developer
erik.io
erik.io
I think a lot of the current approach to infosec and cryptography makes most rank-and-file programmers feel like they shouldn't bother because they'll get it wrong anyway. Unfortunately that just means more harebrained schemes, not less.
My own humble contribution to this cause looks more at the issue from a pure cryptographic point of view than a more general information security point of view. My PyCon 2013 talk is available for anyone to see (thanks, PyCon!), and is a very high level blitz through what it takes to get a TLS connection set up: http://pyvideo.org/video/1778/crypto-101. I'm currently trying to turn that into a book.
PS: Tweet word count is 140 ;)