344 subscribers
¡Desconecta con la aplicación Player FM !
Securing ecommerce: "It's complicated" (Changelog Interviews #633)
Manage episode 472457048 series 1280399
Ilya Grigorik and his team at Shopify has been hard at work securing ecommerce checkouts from sophisticated news attacks (such as digital skimming) and he’s here to share all the technical intricacies and far-reaching implications of this work.
Changelog++ members save 7 minutes on this episode because they made the ads disappear. Join today!
Sponsors:
- Retool – The low-code platform for developers to build internal tools — Some of the best teams out there trust Retool…Brex, Coinbase, Plaid, Doordash, LegalGenius, Amazon, Allbirds, Peloton, and so many more – the developers at these teams trust Retool as the platform to build their internal tools. Try it free at retool.com/changelog
- Augment Code – Developer AI that uses deep understanding of your large codebase and how you build software to deliver personalized code suggestions and insights. Augment provides relevant, contextualized code right in your IDE or Slack. It transforms scattered knowledge into code or answers, eliminating time spent searching docs or interrupting teammates.
Featuring:
Show Notes:
- Powering Shopify’s High-Performance, PCI DSS v4 Compliant Checkout with Sandboxing
- PCI Compliance: What Is It and Everything Retailers Need to Know
- PCIv4: SRI gaps and opportunities - Google Docs
- Shopify/remote-dom
Something missing or broken? PRs welcome!
Capíttulos
1. Welcome to The Changelog (00:00:00)
2. Sponsor: Retool (00:01:03)
3. Welcoming Ilya back (00:04:04)
4. Ilya's career path (00:05:43)
5. Core Web Vitals (00:10:19)
6. Unpacking PCI (00:13:36)
7. PCI shortcomings (00:17:15)
8. PCI v4 (00:18:35)
9. 1st-party scripts (00:20:28)
10. 3rd-party scripts (00:21:18)
11. Sounds not possible (00:23:32)
12. Sponsor: Augment Code (00:24:30)
13. Shopify's approach (00:27:39)
14. Compromises (00:32:22)
15. A long journey (00:36:32)
16. Is compliance enough? (00:38:10)
17. Improving the web platform (00:42:08)
18. CSP / SRI reporting details (00:46:37)
19. Shopify's SRI setup (00:51:28)
20. Key takeaways (00:54:01)
21. AI shopping agents (00:57:04)
22. Human out of the loop? (00:58:53)
23. Wrapping up (01:01:00)
24. Closing thoughts (01:03:05)
2263 episodios
Manage episode 472457048 series 1280399
Ilya Grigorik and his team at Shopify has been hard at work securing ecommerce checkouts from sophisticated news attacks (such as digital skimming) and he’s here to share all the technical intricacies and far-reaching implications of this work.
Changelog++ members save 7 minutes on this episode because they made the ads disappear. Join today!
Sponsors:
- Retool – The low-code platform for developers to build internal tools — Some of the best teams out there trust Retool…Brex, Coinbase, Plaid, Doordash, LegalGenius, Amazon, Allbirds, Peloton, and so many more – the developers at these teams trust Retool as the platform to build their internal tools. Try it free at retool.com/changelog
- Augment Code – Developer AI that uses deep understanding of your large codebase and how you build software to deliver personalized code suggestions and insights. Augment provides relevant, contextualized code right in your IDE or Slack. It transforms scattered knowledge into code or answers, eliminating time spent searching docs or interrupting teammates.
Featuring:
Show Notes:
- Powering Shopify’s High-Performance, PCI DSS v4 Compliant Checkout with Sandboxing
- PCI Compliance: What Is It and Everything Retailers Need to Know
- PCIv4: SRI gaps and opportunities - Google Docs
- Shopify/remote-dom
Something missing or broken? PRs welcome!
Capíttulos
1. Welcome to The Changelog (00:00:00)
2. Sponsor: Retool (00:01:03)
3. Welcoming Ilya back (00:04:04)
4. Ilya's career path (00:05:43)
5. Core Web Vitals (00:10:19)
6. Unpacking PCI (00:13:36)
7. PCI shortcomings (00:17:15)
8. PCI v4 (00:18:35)
9. 1st-party scripts (00:20:28)
10. 3rd-party scripts (00:21:18)
11. Sounds not possible (00:23:32)
12. Sponsor: Augment Code (00:24:30)
13. Shopify's approach (00:27:39)
14. Compromises (00:32:22)
15. A long journey (00:36:32)
16. Is compliance enough? (00:38:10)
17. Improving the web platform (00:42:08)
18. CSP / SRI reporting details (00:46:37)
19. Shopify's SRI setup (00:51:28)
20. Key takeaways (00:54:01)
21. AI shopping agents (00:57:04)
22. Human out of the loop? (00:58:53)
23. Wrapping up (01:01:00)
24. Closing thoughts (01:03:05)
2263 episodios
All episodes
×

1 Hello, Matworld! (Changelog & Friends #90) 1:15:10


1 Make sales not features (Changelog Interviews #638) 1:08:10


1 Vibing into the vibe (Changelog & Friends #89) 1:31:28


1 Making DNSimple (Changelog Interviews #637) 1:46:43


1 Proud pod parents (Changelog & Friends #88) 1:39:53


1 The era of durable execution (Changelog Interviews #636) 1:40:03


1 Turn him into a walrus (Changelog & Friends #87) 1:10:08


1 The 1000x faster financial database (Changelog Interviews #635) 1:40:28


1 Of agents & agency (Changelog & Friends #86) 1:37:53


1 Leading leaders who lead engineers (remastered) (Changelog Interviews #634) 1:14:21
Bienvenido a Player FM!
Player FM está escaneando la web en busca de podcasts de alta calidad para que los disfrutes en este momento. Es la mejor aplicación de podcast y funciona en Android, iPhone y la web. Regístrate para sincronizar suscripciones a través de dispositivos.