Michael Lubas is the founder of Paraxial.io, the only application security company with full Elixir support. He is also a member of the Erlang Ecosystem Foundation Security Working Group, an open source software developer, and frequent contributor to the Elixir community on security related topics.
Every Elixir developer uses the Hex package manager to ship their project. Businesses, universities, and even governments all rely on this critical infrastructure to adopt Elixir and deliver high quality software that drives billions of dollars in economic activity and growth. Given Hex is a load bearing pillar of Elixir, have you ever asked yourself: Is it secure?
Thanks to the Ægis Initiative, two real world penetration tests of Hex were funded, successfully completed, and directly resulted in serious security vulnerabilities being blocked from release. This work confirmed the design decisions made by the Hex core team laid an incredibly secure foundation, and led to improvements that have made Hex more secure than ever before. This presentation will cover the results of both tests (which are public for full transparency), and the remediation efforts that prove the core infrastructure of Elixir is safe in the hands of a world class team.
Key takeaways:
Target audience: