About this talk
This talk delves into the enhanced security features of Drupal 8 compared to its predecessors, building on insights shared in a prior blog post. The speaker examines the specific security improvements within the context of general PHP web application security, connecting them to relevant OWASP Top 10 vulnerabilities. By highlighting past vulnerabilities in Drupal 7 that Drupal 8 effectively mitigates, the session illustrates the advancements in design and architecture. The speaker also shares insights from their experience in driving key security issues and implementing changes in both Drupal and PHP, outlining the process of identifying weaknesses and determining effective solutions.