Skip to main content
thoughtbot thoughtbot
  • Live on Twitch!

    thoughtbot is livestreaming

    Work alongside the thoughtbot team as we collaborate with each other and our clients, live. Ask us anything, we're live right now!

  • Case Studies
  • Blog
  • Let’s Talk
Live on Twitch!

thoughtbot is livestreaming

Work alongside the thoughtbot team as we collaborate with each other and our clients, live. Ask us anything, we're live right now!

Let’s get started!
View all Services
Web Development
  • Ruby on Rails
  • Hotwire
  • AI and Machine Learning
  • React
  • Maintenance
Mobile Development
  • React Native
  • iOS
  • Android
Design
  • UX, UI, and Product Design
  • Design Research
  • Design Systems
Product
  • Product Management
  • Product Design Sprint
  • Research and Strategic Insights
  • Accessibility
Team and Processes
  • Team Augmentation
  • Fractional Leadership
  • Level up your junior team
View all Services
View all Resources
Development
  • Tech Leadership Resources
  • Open Source
  • Books
  • The Bike Shed Podcast
  • Live Streaming on YouTube
The business of great software
  • Playbook
  • Startup Incubator
  • Giant Robots Smashing Into Other Giant Robots Podcast
  • Design Sprint Guide
  • Live Streaming on LinkedIn
View all Resources

Security Articles

Written by thoughtbot, your expert strategy, design, product management, and development partner.

    • All Topics
    • Design
    • Web
    • iOS
    • Android
    • More topics
  1. Protecting User Data in HIPAA Compliant Staging Environments

    How to populate your staging environment with data while keeping user data secure.

    Sweta Sanghavi
    March 6, 2020
    • Health Tech
    • Security
    • Data
    • Web
  2. Health Tech, HIPAA, and Humans

    A brief introduction to HIPAA compliance for developers in health technology.

    Mike Wenger and Sarah Cassidy
    October 25, 2019
    • Health Tech
    • Security
    • Compliance
    • Design
    • Consulting
    • Accessibility
  3. Is Your Site Leaking Password Reset Links?

    Emailed password reset links are a common part of web applications. Is your site leaking these confidential links to third party sites?

    Derek Prior
    October 24, 2016
    • Web
    • Security
  4. Paperclip IS vulnerable to ImageTragick

    Paperclip is affected by CVE-2016–3714 if used with ImageMagick 7.0.1-0 or earlier.

    Tute Costa
    May 6, 2016
    • Security
    • Open Source
    • Paperclip
    • Ruby
  5. ImageMagick vulnerability does not affect Paperclip

    There is no need to upgrade Paperclip in light of CVE-2016–3714. You may choose to upgrade ImageMagick regardless.

    Tute Costa
    May 4, 2016
    • Security
    • Open Source
    • Paperclip
    • Ruby
  6. Paperclip Security Release

    We released Paperclip v4.2.2 with a security fix.

    Tute Costa
    June 5, 2015
    • News
    • Web
    • Open Source
    • Security
    • Ruby
    • Paperclip
  7. Building secure web applications with Ruby on Rails

    Ruby on Rails makes it easy to build web apps with security in mind.

    Murtaza Gulamali
    March 2, 2015
    • Rails
    • Ruby
    • Security
    • New Bamboo
    • Web
  8. Who's responsible for web application security?

    In short, we’re all responsible. And this is why.

    Alexis Ternoy
    February 12, 2015
    • Security
    • New Bamboo
    • Web
  9. Handling Security Issues In Open Source Projects

    How to handle vulnerabilities in your open source project.

    Tute Costa
    December 24, 2014
    • Security
    • Open Source
  10. Sign up to receive a weekly recap from thoughtbot

« First ‹ Prev 1 2

Footer

thoughtbot
  • Services
  • Case Studies
  • Resources
  • Let's Talk
  • Our Company
  • Careers
  • Purpose
  • Blog
  • Sponsor
  • Mastodon
  • GitHub
  • Instagram
  • YouTube
  • Twitch
© 2024 thoughtbot, inc.

The design of a robot and thoughtbot are registered trademarks of thoughtbot, inc.

  • US: +1 (877) 9-ROBOTS
  • UK: +44 (0)20 3807 0560
  • Beware of fraudulent thoughtbot job listings Learn more
  • Code of Conduct
  • Accessibility Statement
  • Privacy Policy