درباره این اپیزود
A file-upload vulnerability in Rails Active Storage just scored a 9.5 out of 10 on the severity scale, high enough that, as Justin Edwards puts it: "Everybody stop what you're working on and get this patched." In this episode of SaaS That App, Aaron Marchbanks and Justin break down what made this one so dangerous (anonymous, unprivileged file uploads were enough to compromise a server), why it took two separate patches to actually close the hole, and how they decided which client projects needed a full credential rotation and which didn't.
What You'll Learn:
- Why this CVE was "as bad as it gets;" vulnerable by default, exploitable by anyone with file upload access, and one step away from full remote code execution
- The real difference between patching a vulnerability and actually remediating it (hint: rolling every API key and secret your app touches)
- How Justin used two real client situations, a three-person beta test vs. a consumer app with thousands of users, to decide when "assume breach" is overkill and when it's non-negotiable
- The concentric circles (and Swiss cheese) framework for layering security so no single failure becomes catastrophic
- Why AI hasn't triggered the predicted vulnerability apocalypse, and might actually be helping more than hurting
- The homeownership metaphor for why "done building" doesn't mean "done maintaining"
This podcast is brought to you by Delta Systems, your one-stop shop for front-end, back-end, and full-stack software development. At Delta, Justin and Aaron share the same philosophy when it comes to clients: they treat people like colleagues, not just customers. Maybe that’s why Delta typically spends years working with the same companies: how many software engineering firms can you say that about? So, if you’ve got a big SaaS project in mind but have no idea where to start, come and get a free scope and estimate from Delta Systems at: https://deltasystems.com/
Got a burning idea for an episode, or a SaaS question you absolutely must know the answer to? Leave us a voice memo: https://www.speakpipe.com/SaasThatApp
Highlights:
- [01:28] What Is a CVE, Anyway?
- [03:19] The Rails Active Storage Vulnerability Explained
- [06:35] The Race Between Disclosure and Exploitation
- [09:43] When to Roll and When to Accept Risk
- [11:31] Why Environment Isolation Saves You in a Crisis
- [13:52] Is AI Going to Cause a Vulnerability Explosion?
- [14:35] Concentric Circles and Swiss Cheese
- [17:26] Why Every SaaS Founder Needs to Budget as Homeowners
- [19:29] The One Thing Every Team Should Automate
Episode Resources:
- Aaron Marchbanks on LinkedIn
- Justin Edwards on LinkedIn
- CVE Record
- Rails Security Advisory
- Delta Systems Website
Saas That App is handcrafted by our friends over at: fame.so
Check out our three most downloaded episodes:
- AI-Assisted Development: Expectations vs. Reality with Richardson Dackam
- How to Price SaaS for Maximum Growth with Dan Balcauski
- You're Shipping Constantly - So Why Aren't You Growing? With Daniel Layfield
We’d love your feedback. Please take a moment to fill out our audience questionnaire:
https://forms.gle/DN8hWFDcE9jwvNKo6
Your input helps us shape future episodes and continue bringing you practical, real-world insights into building B2B web applications.
انگلیسی
ایالات متحده آمریکا
رونوشت 🔗
Are you the producer of this podcast?
Add a podcast transcript
Need Audio-to-Text?
Transcribe with Listen411 in Just 60 Seconds
جستجوی اپیزودهای گذشته
اپیزودهای قبلی SaaS That App - Building Tech-Enabled Businesses را جستجو کن.
قسمت های دیگر در این پادکست
Claude Code nearly wiped out a production database while racking up an unexpected AWS bill overnight, and that’s just one of many stories from guest Daniel Cannon. As CIO at Delta Systems and CEO of StriveDB, Daniel joins hosts Aaron Marchbanks and Justin Edwards to share what AI-assisted developme…
Teams don't know their customer, and that gap, not a lack of features, is what quietly stalls SaaS growth. In this episode of SaaS That App, hosts Aaron Marchbanks and Justin Edwards sit down with Gia Laudi, a customer-led growth expert who's advised Postman, Bitly, Sprout Social, EverCommerce, and…
Delta Systems co-owner Steve Powell built a production-grade SaaS app in under 200 hours…. without actually knowing the stack.
Not a prototype. Not a demo. A real, deployed application: myeaglecoach.com, used by Scout leaders to manage documents, e-signatures, collaboration, and project workflows, …
AI in drug discovery, data-centric machine learning, precision medicine, and building SaaS for life sciences; this episode of SaaS That App covers it all with a founder who’s lived it for a decade. Aaron Marchbanks and Justin Edwards sit down with Dr. Abhishek Jha, Co-Founder and CEO of Elucidata, …
Most companies don't have a sales problem. They have a playbook problem. And it's costing them every deal that should've closed.
In this episode of SaaS That App: Building Tech-Enabled Businesses, Tom Stearns and Peter Cleary, co-authors of Graphic Sales, join Aaron Marchbanks and Justin Edwards to…
سلب مسئولیت: پادکست و آثار هنری تعبیه شده در این صفحه متعلق به Delta Systems است که متعلق به صاحب آن است و به Listen Notes، Inc وابسته یا تایید نشده است.
ویرایش
از کمک شما برای بروز نگهداشتن پایگاهدادههای پادکست سپاسگزاریم