Day 3 Lightning Talks

This video features Adrienne Lowe, Andrew Sauber, Dan Davis, Dan Dietz, Ethan McCreadie, Haris Ibrahim K.V., Justin Caratzas, Kevin Daum and Philip James at DjangoCon US 2016 in Philadelphia, Pennsylvania, USA.

Day 3 Lightning Talks
0:36:41
Published August 12, 2016
429 views

00:15 - Andrew Sauber

05:04 - Justin Caratzas

09:21 - Dan Davis

14:02 - Adrienne Lowe

17:10 - Kevin Daum

20:52 - Ethan McCreadie

25:02 - Dan Dietz

29:56 - Phillip James

32:56 - Haris Ibrahim K.V.

This talk was presented at: https://2016.djangocon.us/schedule/general-sessions/

LINKS:
Follow DjangCon US 👇
https://twitter.com/djangocon

Follow DEFNA 👇
https://twitter.com/defnado
https://www.defna.org/

Summary

The speakers present a series of practical Django and Python community topics. Andrew Sauber introduces Session Armor, a proposed protocol that adds encrypted tokens, HMAC request authentication, and optional timestamp- or counter-based replay prevention on top of Django sessions; Justin Karatzas shows an idempotent Ansible role for compiling and deploying Nginx with PageSpeed; and Dan Davis explains using Django CAS NG to integrate NIH single sign-on while keeping URL protection and development behavior under application control. Other speakers invite women who use Python or Django to share their stories with Django Girls, propose a Django implementation of Callisto’s encrypted, user-controlled sexual-assault reporting system, and demonstrate generating deployment files from Django settings with Makeconf. Dan Dietz outlines learning techniques such as retrieval practice, spacing, interleaving, and staying just outside the comfort zone; another speaker warns that exposing Django’s SECRET_KEY can compromise signed cookies, sessions, and password-reset tokens, and recommends environment variables and key rotation. Haris Ibrahim K.V. closes by promoting PyCon India, its volunteer community, Django Girls workshops, and Python Express outreach.

Key takeaways

  • Session Armor aims to strengthen cookie-based Django sessions with HMAC authentication and replay prevention without requiring application-code changes.
  • Ansible can make compiling and deploying Nginx with PageSpeed repeatable and idempotent across many servers.
  • Django CAS NG provides application-controlled NIH single sign-on, URL protection, decorators, and additional subnet-based admin restrictions.
  • Django Girls is collecting weekly stories from women who use Python or Django, while a sprint will adapt Callisto’s encrypted reporting model into a reusable Django app.
  • Makeconf generates Docker, Elastic Beanstalk, and other configuration files from Django settings and environment variables.
  • Learning improves through effortful retrieval, spaced and interleaved practice, while exposed Django SECRET_KEY values should be replaced and managed outside source control.

Summarised automatically from the transcript.

Transcript

6,446 words · auto-generated Show

Automatically transcribed, so expect mistakes in names and technical terms.

0:00

Speaker 1: Come on, no. Hi

0:15

Speaker 2: everyone, my name is Andrew Sauber. I'm sure that if we all woke up tomorrow and our bank account was at a zero balance, we'd be surprised to say the least. If you use online banking, this is a very real possibility. Banks, retailers, and healthcare use the same cookie-back sessions that our web applications use to authenticate user requests. Today I'd like to present Session Armor, a protocol that I'm developing as part of my graduate studies that aims to protect against session hijacking and provide robust replay prevention. So, first, let's review the vulnerabilities of cookie-based sessions. One thing to note is that sessions are bearer tokens, which means they're static for the duration of a session and they bear the burden of authenticating all requests. There's a number of opportunities to steal this token. First, if the client connection isn't encrypted when um

1:00

Speaker 2: during authentication, then all bets are off. This is why our login endpoints at least use HTTPS. If there's a cross-site scripting vulnerability on our site and we haven't set the HTTP only flag, then any injected JavaScript or third-party JavaScript library could ship off session cookies to an attacker. Also, packet sniffing during a session if traffic is unencrypted also provides an opportunity for the session token to be stolen. This is called sidejacking. And lastly, something that I haven't seen really mentioned before is rogue browser extensions. So you download a screenshot browser extension. It could be in the background if it's given permission. Um shipping all of your session tokens off to an attacker. So I was curious as to how many sites actually use these protections. So I developed a browser extension called Session Jack.

1:47

Speaker 2: that um deactivates a cookie uh the cookies for each do for a given domain one at a time based on the protections that are being used. And if I was still logged in, it meant that the protection wasn't being used. And what I found was that about 30% of sites, um, their session tokens are potentially vulnerable to cross-site scripting. 50% of sites, their session tokens are potentially vulnerable to sidekacking, and 99% of sites use cookies for their session tokens. I think that we can do better than cookies. Um, this is why I'm developing the session armor armor protocol. Um the specification is still in flux. So I'm not going to go through it in complete detail. First of all, the server creates an opaque token which includes the real session ID.

2:33

Speaker 2: So this is a layer on top of our existing session token. It's symmetrically encrypted and sent to the client, including an HMAC key that the client uses to authenticate subsequent requests. Requests. HMAC is a way to prove ownership of a key without revealing the key itself and can also authenticate some associated data in the process. Your clients will use HMAC to authenticate their requests to the server. Once you have an HMAC , you can implement two types of replay prevention. If there's a timestamp in the HMAC, when the server verifies the HMAC, it can reject stale requests. So this is time-based replay prevention. You can also have counter-based replay prevention, which

3:18

Speaker 2: incurs some additional server-side storage because the server has to maintain the current count. in it and I'd recommend in a bit vector so that you can have some out of order um you can you won't reject requests even if they're out of order and um this is absolute replay Prevention, but requires you to have an additional cache of basically the counter that each of your clients are using. I'd recommend something like Redis or whatever underlies your Django cache. in order to implement that. So some of you may know that um HMAC is nothing new. Um having this kind of opaque token is nothing new, but I believe that my protocol has a few First of all, there's a setup phase to choose the HMAC algorithm in case there's a vulnerability found. For example, SHA

4:03

Speaker 2: -1 is not allowed. It's only SHA-256 and above. You can configure the headers that are authenticated, like for example, if you have some um cache control headers that um the server the your your intermediate proxy might not be able to to might not have the HMAC key in order to authenticate to your backend. There's optional custom header authentication, counter-based replay prevention is optional, and it leverages an existing session infrastructure rather than replaces. It. So it's a layer on top of your existing existing session tokens. Once the server um authenticates the request, it decrypts the opaque token and then just passes your session cookie down to Django. So Um you don't have to modify your application code if you're using this. Um

4:49

Speaker 2: I have a very early proof-of-concept implementation as a Django middleware and as a Google Chrome extension. up on my GitHub if you click repositories. And you can reach me on Twitter. I accept DMs at WK3AS. Thank you.

5:05

Speaker 3: I'm new to this, sorry. Uh my name is Justin Karatzis. I'm the director of technology at Narrative Content Group. Uh with the tech department of narrative content group, please stand up. Where are you? It's two people. We have a family of content sites such as MN. com, Mother Nature News Network, something like that, and we have treehugger. com as well Uh hopefully nobody at my job will see this video. But anyway, um we uh in front of our uh content Django-based content server We run page speed over Nginx, which is fun, until you have to upgrade it. And then it's terrible because you have to compile it. We have about 20 servers, give or take,

5:52

Speaker 3: across all the sites. And recently there was a security update for page speed. I think it was back in February. At least that's when I caught wind of it. I was not going to log into 20 servers. I'm way too lazy for that. Uh we use Ansible heavily to deploy our application. Um so we wrote an Ansible module for it. That is the readme for it, which is probably the best documentation for it now. The actual role is only about a hundred lines of code. How many people use Ansible? I might be talking to Ansible. And do those other people also use uh PageFeed? Alright, so nobody's gonna use this role. That's fantastic. But maybe somebody watching the video. This will help one person, I swear. Um so anyway, the problem with uh Nginx page speed, if you're unaware, is that you have to compile it, which is

6:39

Speaker 3: Hopefully in the future they'll have uh uh dynamic modules like Apache does. So anyway, uh we're able to so the the aginex world does Some cool stuff. If you're interested in Ansible at all, there's some cool features with this role, uh, which is a reason. We have about 25 rolls. I chose this one to talk about, not the Django one, which is a complete mess. Um This one has some cool features which I'm gonna try to review. So again, when you're compiling uh Nginx, you have to give it a bunch of build options Which you can specify with this Ansible dictionary that the cursor's kind of near right now. These are all configurable. You can extend it, you can change it, do whatever you need to do. And you'll be able to install Nginx just by specifying the version you want

7:27

Speaker 3: and the Nginx version. So it'll compile Nginx and the page speed module and this other thing called PSAL, which you need to get uh page speed to work. What it does is it's actually going to build out using the version numbers, it's going to look to see if you have it already uh downloaded and then if you have it downloaded, it'll try to install it. So Uh with Ansible roles, I'm not sure if you all know, item potency is a very important thing. If you run a role twice, it shouldn't really do anything the second time. Everything's already configured. It shouldn't be re-downloading, it shouldn't be resetting uh configuration files or restarting servers. This role, thankfully, is idempotent. So we have a lot of checks and stuff. I'm gonna try to navigate. Do the task file

8:13

Speaker 3: main. Hopefully it'll just yes. So this is the actual Ansible role itself. Uh you can tell it's uh I don't know, this could look Greek to people that don't uh use I'm actually Greek, so that's a little bit meta. This could look a little weird to people that uh but anyway, it's basically the each uh I guess little tick mark on the left indicates a step in the in the build process. So you can see we download Nginx, we unpack it, we configure it, and we do source stuff, we set variables, and then we finally create the directory that you can actually put your Nginx site configuration in. That's really cool. Um one cool feature that I'm gonna do before I get out of here is what's known as the custom Ginja filter plugin. So Ansible uses Ginja for

8:59

Speaker 3: as its templating engine. I wrote a custom filter that turns those build that build dictionary that I pointed out to you before, the build options dictionary, into the actual command line that the uh compilation step is gonna take. So that's how we make it extensible and easy to use. And I'm done. That's it.

9:22

Speaker 4: This is about anti-social authentication. So I'm Dan Davis. I'm from the National Library of Medicine. There are a number of us here, and we're switching from Django to Django from a number of other languages, especially Cold Fusion. So oops. So what's the problem? I want to tell you how we integrate Django with NIH login, our corporate identity provider. Most of the Auth tutorials we see online are about user registration on the web, but most of the apps we implement only allow logins

10:08

Speaker 4: for corporate users. even if their public side is available on the web. Now so we want to implement single sign-on with this badge Um and we want to do it in with common code that can be used by multiple internal apps. So why is this hard? I mean, we may think that, you know, we can use, well, remote user middleware with some sort of Apache module. We may think that, oh, we'll just use um the LDAP authentication. Well, we're supposed to use NIH login because you know we don't want our applications handling passwords even if they are SSL. Um and NIH login is anti-social auth, not only in the sense that we don't want to authenticate Google, even though it does technically support that.

10:54

Speaker 4: But because it's based on CA SiteMinder, which means it is also based on SAML, that would mean every application needs a certificate and key tied to that application. Getting the certificate and key can take like a month for totally non-technical reasons. Finally, we also want to see the same auth in our development environment. So that our Selenium integration tests can handle pages that require authentication. So our systems guys will want us to do this by installing CA SiteMinder And that makes controlling particular paths outside of slash admin something we have to do by committee. And our application may have REST paths and be we may

11:40

Speaker 4: Want only to protect updates to our REST applic endpoints. Fortunately, our tooling team has already implemented a CAS server and they protect the login on that server with CA SiteMinder causing CAS to be what we need to integrate to And CAS is friendly to developers. You don't need a certificate for each app. It um authenticates the Earl. It's not quite as secure though. I mean it's really authenticating just the URL. But that does mean that localhost 8000 can be okay because the regex says localhost is okay. So our system guys are used to this and they would still like us to use an Apache module, this time

12:25

Speaker 4: mod of cass. We don't want to go this way. We still want to customize what earls are protected ourselves, and we still want to see the same thing in the development environment as in production. So we found that Django Cass NG, the NG stands for next generation, supports all this. It can integrate with the central authentication. service. It supports protecting an URL range such as slash admin through settings. It supports decorators such as login required. And we've also enhanced Django Cas NG by to add some extra security. We want some functions to work only within our some

13:12

Speaker 4: subnet. We want to deploy our apps so that the admin side and the public side can be deployed together on the same application servers. This is not what we've done with ColdFusion, and there was some pushback on this. But we want to make sure that admin users are only coming from our own subnet. So that includes a decorator, a middleware, and a context processor. And the context processor helps us to have our admin navigation in our web apps. So we can show that link only to users who should be allowed to use it. Thank you. I'm going to hang out up there on Floor G

13:57

Speaker 4: if there are any questions. Thanks. Thank you, Dan.

14:03

Speaker 5: I want to talk to you about Django Girls and uh in particular uh something that we do. Um every week we publish a story from a woman who uses Python and Django. So if you are a woman who uses Python and or Django at well You you know what I mean. Um, or if you know a woman who does that. So I'm hoping that covers everyone in the room. Um if you are or no, this talk is for you. I want to hear your story. I want you to email me at story at Djangogirls. org. So what is your Django Story? Your Django Story is an interview that's published weekly to our official Django Girls

14:49

Speaker 5: blog. It's blog. jjangogirls. org. We try to publish a news story every week. I'm the one who publishes them. It's really exciting. All experience levels are welcome. It doesn't matter if you're new to Python or you've been doing it for years. We still want to hear your story And it is a great way to share what you're working on or care about with the community. So Anna Schneider talked about what time here. I interviewed her a couple months ago, and now she's a DjangoCon. So It's great if you're trying to like build your brand or you want to share your story or what you care about. There are lots of opportunities to do that So I just want to go ahead and put out these are the questions that you would be asked. All the questions are optional. They're the questions that we came up with and that we think work, but you don't have to answer every one of them if you don't find it relevant or if you don't like it

15:40

Speaker 5: How did your story with code start? Tell us about that. What did you do before becoming a programmer? What do you love the most about coding? Why do you love Django? What cool projects are you working on? So pretty pretty easy. This slide is not in the right place, but this is an example of a recent story we had. We share an image if you're cool with that. I love this story. You should check it out, Anna's story. Here are the other questions. What in your life are you most proud of? You could say your kids, you could say your family, you could say your partner, you could say something you built. What are you curious about? What do you like doing in your free time? One of my favorite parts about this interview series is this question. What advice do you have for newbies?

16:27

Speaker 5: I care a lot about code newbies. I care a lot about folks who are new to programming. And if you read our blogs and these interviews, this is where some of the best material comes from. It's usually what I use for our tweets. So love to hear that. And if it applies to you, if you attended a Django Girls event, what did you get out of it? How did it change your life? And that's You can come at that angle either as an attendee, a participant, or as a coach. So it doesn't matter. So I hope I have convinced you or made you think of somebody who you could talk to about sharing their story Please email me story at DjangoGirls. org. We'd love to feature you. Um get you queued up to be published. Thanks so much

17:12

Speaker 6: Um I'm gonna give a content warning at the start. Um I'm gonna mention sexual assault, but um just kind of in the reporting of it. So last year, uh Kelsey Gilmar Innes gave a talk, I think it was called, at DjangoCon, I think it was called making Django really, really ridiculously secure or something like that. And she mentioned uh it was about a project called Callisto. Um who here knows what Callisto is? Okay, good. So for those of you who don't, um Callisto is a tool right now that's used for um college for reporting sexual assault on college campuses. Um it's designed to be kind of a more empowering um reporting experience and it's trauma-informed.

17:59

Speaker 6: And it's also designed to kind of facilitate the identification of repeat assailants. And so the w it it's based on this information escrow concept. So you can report Something happens to you, you can report the details of of what happened to you, um, like when it's still fresh in your mind, um, but then decide on your own time when and if You're gonna do anything with that report. So it belongs to you, it's encrypted, it's stored in this third-party place where no one really other than you has any legal authority to access it. Even if they're subpoenaed by a court, it's all encrypted and you can only decrypt it. So they can't even get it that way.

18:45

Speaker 6: But the really great thing is it has a matching feature where you can um identify your assailant. Um right now it's via a Facebook URL since almost everyone has Facebook. Um and then and say if anyone else reports this same assailant then audit you know automatically report. So both of your reports at that moment will get reported to the proper authorities wherever it is. So it's used on college campuses, but it's kinda and it's a it's a it's a general um you know the the the kind of the system and the core reporting uh machinery could be used in a variety of situations. It could be used um in the workplace or in the military or um any kind of place where that we're kind of reporting confidential information

19:32

Speaker 6: um about something that's happened to you um where that would be important like this could be used and so The reason I'm talking about this is I'm gonna there's gonna be a sprint. Um I'm gonna organize a sprint um on Thursday and Friday to make a um they they Callisto recently open sourced the kind of underlying escrow code and the encryption of reports and all that. And we're gonna work on making a generic um Django app that kind of provides an example of how you could um implement that stuff in kind of a generic way, hopefully that other other places could then use in their own kind of organizations. So if you're interested in working on that, then find me tomorrow morning. There's a um a channel in the

20:18

Speaker 6: DjangoCon Slack called Sprint Callisto. Um so you can find us in there and once we figure out where we are tomorrow. Um and I we could use basically I can't imagine the skill that we couldn't use like Um where there's gonna be documentation writing, um, front and back end development, um, design work. Um if anyone has like any kind of experience with like trauma-informed design, like that would be super useful. Um but really Uh I think whatever you wanna however you want to help, I'm sure we can find a way for that to work. So thank you.

20:51

Speaker 4: Thank you, brother.

21:01

Speaker 6: Nobody's heard of this. It is uh it's a library, it makes conferences. Um no wait. It generates configuration files. Um So why would you want to generate a configuration file?

21:17

Speaker 7: Some of you guys probably use Ansible and Chef, you have this whole ecosystem made there. And it's always right the first time. I'm sure anybody who's used Chef, you you get it right Um but I've been using a lot of platform as a service stuff. It's really simple and I need to get like one setting into my application. Who uses Heroku? Elastic Beanstalk? Okay. Um I use Elastic Beanstalk, but I think all this stuff would work for Heroku too. And if anybody wants to help me make it work for Heroku. I'll cover that in the last slide. Um but basically I wanted to use my Django settings file that I already have to just generate other files like a Docker file or something like that. Um rather than having some whole other ecosystem.

22:03

Speaker 7: So I made this really complicated system that uses Django templates, which we already know and love, and Django settings, which we already know and love, to create Other files. So I'm using like PyDani 's configuration. I use different settings files based on the tier I'm using. And I just include a couple of extra settings in these files or use settings I've already got to make my templates work. So You might end up including AWS bucket names for deployment or role names or resource locations. And you might put these things in any files, cron files, Docker files, whatever. This is an example of generating

22:49

Speaker 7: um is a template you would use to generate from your settings. And you can see it's taking like your credentials location, which is going to be a link to AWS, and like an elastic beanstalk role name in this case. Don't use the bottom of this. I shortened it a lot. This isn't actually how AWS works But but it fits on one slide now. Anyway, but you just got a couple of things that are coming from your settings. And you know, you could use that to deploy different credentials based on the tier you're in. If I hopefully you're not using the same credentials in prod and dev But who knows? Um I also made a little helper to get uh settings from the environment into the template and it ends up working like a filter, so you have to you have to load makeconf to get environment, but you can then

23:36

Speaker 7: Like these this is uh Mikey built this, he's in the audience, and this uses Jenkins environment variables to put a little footer in uh in his site so he knows which like Did my did my uh code deploy? Is this the release I thought it was? And that's just getting in environment variables. And to set it up, you use a map. There's two ways to do it, but this is sort of you can just make a map and you're saying I want to make a file called Dockerfile and I want to make it from this template. And it will have access to your settings and your environment. And that's just going to generate a Docker file in the current directory. The other way to do it is with uh Elastic BeanSuck modules, and I can imagine having Heroku modules also. This

24:21

Speaker 7: in you know I have a I have uh they're not published because they're all secret, top secret. Um and I made them at my job But you can have modules for like different things, New Relic or HipChat, or if you use SAS and you need certain dependencies, I just have little modules that drop in. And this I this lets you put them kind of in order in case one is needed before another one And you just run it with a management command. So I do this in my Jenkins build. Using the cur the settings you want to use, run makeconf generates files. It's magic.

24:56

Speaker 6: And I'm accepting pull requests. Um, thank you.

25:04

Speaker 7: Well my name is Dan Dietz. I'm one of the partners at Bolt Effect, a Django Web Development Agency in Greenville, South Carolina. Last year I gave a lightning talk on Fabric Bolt, which is a Django project We support that allows you to run fabric deployments right from your browser. So you could be a project manager, click a button, and it goes. So it's really cool. Uh and so that's up there for uh SEO reasons. Uh we just added channels to that project, so Jared uh has a pending pull request. He's shaking his head right now, he had no idea what it is. uh mugshot in there. So anyway, uh we're gonna get that pushed out. So if you want to see channels running a real project, there you go. What I'm gonna talk about today though is things that I share with my students at the Iron Yard. I'm a

25:49

Speaker 7: uh uh an instructor uh for the ironyard we help people move into programming careers that are fulfilling. Uh so non-programmers, we turn them into programmers, it's really awesome. So there's research that suggests teaching the mechanism of how the brain grows when it's challenged increases performance. So you learn better if I tell you a little bit about how your brain works. One thing we need to know is learning is kind of like uh trekking across the Appalachian Trail, not climbing Mount Everest. So we're talking about uh learning complex skills like programming, you're gonna do this over a lifetime. It's gonna take a long time There are two things I want to talk about real quick before we dive in.

26:34

Speaker 7: Cut the comfort zone and the panic zone. Kind of uh look like this. Where you basically have the comfort zone, no learning's happening. We have the learning zone where you're pushing yourself to learn something new, and then you have the panic zone where you're freaking out. Okay, what we want to try to do is get as close to the panic zone as possible while staying in that learning zone to maximize what's happening. Now the reason for that is effortful learning is longer lasting and more versatile. Learning is built on the shoulders of habits. So things that you do on a regular basis is how you're gonna learn. Be aware of cognitive bias. So we oftentimes think we know stuff when we don't, so test yourself. Be aware of falsely perceived fluency.

27:19

Speaker 7: You could read something ten times and that doesn't mean you actually know something, right? So just rereading things a bunch of times maybe not be so helpful. Retrieval interrupts forgetting and strengthens retrieval pathways. So the way your brain works is you're connecting these neurons in your brain together through these pathways. And as you try to retrieve information from your brain, whether or not you get the right answer, it turns out that actually helps your learning. Now if you come up with the wrong answer, hopefully You've got the right answer close at hand. You don't want to just have the wrong answer. That doesn't help. But just the act of trying to retrieve helps you learn. Uh make retrieval harder with spaced repetition and interleaving. Interleaving is this idea of having multiple topics.

28:06

Speaker 7: So I would suggest if you're trying to learn a little bit of advanced CSS , you go ahead and sprinkle in some SQL query stuff. So you're going to interleave topics, which helps you forget the CSS that you were just working on, and then you come back and you retrieve that information, and that'll actually increase your learning. Try to solve problems before you're taught how. Learning styles are overrated. Always aim to extract principles and rules So you want to pull concepts out of things that you're learning so that you can apply them in a different context. Elaborate on newly gained knowledge. So as you're bringing in new knowledge, you want to kind of beef it up a little bit. This is a lot to read, so I will post these slides.

28:54

Speaker 7: We'll have them write a blog post on boltifact. com, get those out to you. So if you want to read all that. Uh build a mind palace. Sounds completely weird, but totally works. There's people that have memorized thousands of digits of pi. There's no limit to what your brain can actually store. We haven't at least found what that limit is So uh you need to kind of work to store things in there in creative ways. Uh it turns out that intellectual ability isn't fixed. It's not like you're born with some amount of information that you can store and that's it. So mindset and learning actually changes your brain. And uh let you soak some stuff in. Uh stay calm. So if you get into that panic zone, so you try and bite off a little bit more than you can chew,

29:39

Speaker 7: it actually causes your brain to uh lose some of the plasticity there. And uh so you want to even if you're doing some challenging learning, stay calm. In review, here's all the things that we just learned about learning. Uh nice, huh? And uh that's it. Thanks, thanks very much. Okay, cool. Oops, I committed my secret key. I'm gonna talk really fast. So let's say you have an idea for the best thing ever. You do Django M and Py start project best thing ever because of course you're gonna build the best thing ever in Django. You do get init because you are a responsible developer, you want to put this in source control. Git add dot, git commit m initial commit, git push origin master. This is not something you should do because what have you just done? You have just committed your secret key to a probably open repository because you're probably using GitHub like most of the room.

30:26

Speaker 7: Uh so you have made a huge mistake. Wait, have I made a huge mistake? What does the secret key actually get used for? The answer is yes, you have made a huge mistake. There should be no doubt about this. Here is what I here is a list of what the secret key is used for. Signed cookies. Secure sessions. Password reset tokens. Shout out to Russell who pointed this one out to me yesterday. And then I went and looked in the source code. And yes

30:48

Speaker 1: The password reset tokens are generated from the secret key. So that means if your secret key is public, someone can impersonate your users and potentially change their passwords. This is bad. What do you do? I'm about to show a big block of code. It's for one reason. The slides will be posted. There's a link at the end, so you don't need to understand this. Just a kind of an uh uh Point of view, you should be putting secret things in environment variables. Those environment variables can actually live in the environment or they can live in a separate file that you import, but they should not live in source control. This big old block of code is so that you can do this And this is how you should be accessing secret keys. If you have a stat a static secret key in production, please use environment variables Okay, so you've made this huge mistake. How do you get a new key so you can put it in an environment variable and not have your users be hacked?

31:34

Speaker 1: Uh two really easy ways One is use this web tool. Um if you it will generate a 50-character Django secret key. If you are super paranoid and don't want your secret key to ever even touch the internet. You could do this. Uh this will prove a kind of alpha moneric-ish, but it's included in the standard library in Django, very easy to use. Um you might be asking yourself, okay, well if I change my secret key What about my users? Will anything bad happen to them if I rotate my secret key? The worst that will happen is that they will have to log in again because the session cookies will no longer be valid. However, them having to log in in again is way better than their account getting hacked and them calling you in the middle of the night There's an optional step, which is you could not have a permanent key. If you have an auth mechanism like some of the ones that have been discussed earlier that doesn't rely on session keys and session cookies, then you don't need to have a permanent secret key and it doesn't matter if you store it.

32:23

Speaker 1: So think about this, but really investigate whether this is going to work for you. Uh that is it. Uh so I am giving a talk Uh at 130 about more Django security issues. Um at 115 in here, I'm going to try to run. uh a very large game of cat on your head. It is a game that you can play sitting down in a conference center and is better with large groups of people. So 115 come back here and play some cat on your head. That's the link to these slides if you want my Block of how to get environment variables and I'm giving a talk at one thirty, I already said that and I'm done.

32:57

Speaker 4: Thank you

32:58

Speaker 7: I am Haris Abraham KV and that's where I am from at a Paul Kerala and I've flown like what twenty-three hours in a flight to get to the Justice Conference So I'll be here for just this week. So thank you so much for having me. Yeah, as I was telling everyone, the sun sets at like 8 30 p. m. over here. What's up with that? Cool. So I'm here to talk about PyCon India, which is happening on September 24 and 25. Um uh last year we had it in Bangalore, which is like the tech capital of India, as some people refer to it. Right. This year we have shifted it towards the north. Which is the actual capital of India, New Delhi. And just to give you a few stats, the number of attendants for PyCon India last year was 1137 Uh thus many people actually attend the conference

33:43

Speaker 7: and the ticket price for the conference is $25, which it gives you like two days of conference, three times of food, and like to meet like thousand people in like two days Which if you think it's cheap, people still bicker about it over in India when we actually try to decide the price. So um yeah, there you go. That's how we name our tickets like late Python and regular Python and stuff Just to share a few photos and stuff which you have done. I was actually the registration lead last year, so that's our registration booth. I am there at the left if you can see me. So this is like what the registration happens over there. And if you notice, we have a different cue for just the letter names that start with the letter S Out of 1100 people, we have 346 people just starting with the letter S.

34:29

Speaker 7: So we have a different cue for that altogether. So yeah, that's a swag packing s session. All of us are there. It's it's like really funny times. Um and oh what is this? Okay, there's a couple of photos and stuff. Oh yeah, that's the entire volunteering. That's the there I am, there I am. That's one that one Whoa! That's the entire volunteer team. We are like fifty plus volunteers running this conference and it's been amazing so far. And I also am on a secret mission from Paikan India this year over here, which you might know in a little bit. I'll tweet about it later. I think I've accomplished it, but I'll let you know later And yeah, a couple of photos again. That's the networking thing setting things up. That's the sprints that we had on the first day. And yeah, that's literally how the conference looks like.

35:14

Speaker 7: It's full when you don't have a session going on Yeah, and uh cool, that's like the picture from last year. And also we this year we had like 165 uh proposals submitted. The reviews are going on The talks haven't been finalized yet. We also had like the Django Girls workshop over there in Bangalore. I was one of the coaches, so the community is pretty interesting. There are Python local meetup groups in almost every state. Yeah, that's the Python Software Society of India, which actually runs all these things together. It's like an umbrella over all of that. And we also have this interesting thing called the Python Express. Which is like if you are an organization or a institution and want to contact Python workshops, you just sign up over there. And the community people actually say we volunteer to come and teach over there.

36:00

Speaker 7: So it's like a middle middle layer between people who want to learn and people who want to teach. So that's also there. Yeah, that's one of the workshops that I did under Python Express. And that's a shameless plug. That's my blog, a psychopath , as long as whatever you can understand from that. And uh since I have like uh multiple entry visa now now that you guys have accepted me to the US. I'll be back. Thank you.

Questions this talk answers

How does the Session Armor protocol prevent session replay?

Session Armor wraps the existing session token in an encrypted opaque token and uses HMACs to authenticate requests. Replay can be limited with timestamps, or prevented more completely with server-tracked counters, though counters require additional storage such as Redis.

Discussed at 2:33

How can Ansible automate compiling and installing Nginx with PageSpeed?

The Ansible role accepts configurable build options and version numbers, downloads and compiles Nginx, PageSpeed, and PSOL, and installs them. It checks for existing downloads and is idempotent, so rerunning it does not unnecessarily reset configuration or restart servers.

Discussed at 5:39

How can Django integrate with an organization’s CAS single sign-on?

Dan Davis’s team uses Django CAS NG to connect applications to a central CAS service protected by NIH login. It supports URL-range protection and login-required decorators while allowing the same authentication behavior in development and production, without requiring a certificate for every application.

Discussed at 11:40

How do I submit my Django story to Django Girls?

Women who use Python or Django can email their story to [email protected] for a possible weekly feature on the Django Girls blog. All experience levels are welcome, and contributors can answer only the interview questions relevant to them.

Discussed at 14:03

What is Callisto and how does its information escrow system work?

Callisto is a trauma-informed tool for confidentially reporting sexual assault. Reports are encrypted and held until the person chooses what to do, while a matching feature can identify repeated reports about the same assailant and trigger reporting to the appropriate authorities.

Discussed at 17:12

How can I help build a generic Django app based on Callisto’s reporting and encryption code?

The speaker is organizing a sprint to turn Callisto’s open-sourced escrow and encrypted-report code into a reusable Django app. Contributors are needed for documentation, front-end and back-end development, design, and trauma-informed design work.

Discussed at 19:32

How can Django settings generate Docker, deployment, or other configuration files?

The makeconf library uses Django templates together with Django settings and environment variables to generate files such as Dockerfiles and deployment configuration. A map specifies each output filename and its template, and the process can be run through a management command or build system.

Discussed at 21:01

What are effective ways to learn programming and retain technical knowledge?

The talk recommends effortful learning near—but not inside—the panic zone, active retrieval, spaced repetition, interleaving topics, trying problems before being taught, and extracting general principles. It also advises staying calm and avoiding the false confidence that comes from simply rereading material.

Discussed at 25:49

What happens if I commit Django’s SECRET_KEY to a public repository?

A compromised secret key can invalidate signed cookies and secure sessions and can allow attackers to forge password-reset tokens, potentially taking over users’ accounts. Production secrets should be supplied through environment variables or another mechanism outside source control.

Discussed at 29:39

How do I rotate Django’s SECRET_KEY safely?

Generate a new key with a secure generator, such as Django’s standard-library-based approach, and store it outside source control. Existing users will generally just have to log in again because their session cookies become invalid; that is preferable to leaving accounts exposed.

Discussed at 31:34

What is PyCon India and what does its conference ticket include?

PyCon India is a two-day Python conference; the talk describes the 2016 event in New Delhi after the previous year’s conference in Bangalore. The ticket cost was $25 and included the conference, three meals, and access to a community of roughly a thousand attendees.

Discussed at 32:58

How does Python Express connect organizations with Python workshop instructors in India?

Organizations or institutions request a workshop through Python Express, and community volunteers sign up to teach it. The service acts as an intermediary between people who want to learn and people willing to teach.

Discussed at 35:59

Note: We understand that names change, people change, and bodies change. We respect each individual's journey and privacy. If you have any concerns about a video or need us to remove content, please don't hesitate to contact us. We will handle your request with care and promptly address any issues.

More videos by Adrienne Lowe, Andrew Sauber, Dan Davis, Dan Dietz, Ethan McCreadie, Haris Ibrahim K.V., Justin Caratzas, Kevin Daum and Philip James

More videos from DjangoCon US