Skip to main content
thoughtbot thoughtbot
  • Live on Twitch!

    thoughtbot is livestreaming

    Work alongside the thoughtbot team as we collaborate with each other and our clients, live. Ask us anything, we're live right now!

  • Case Studies
  • Blog
  • Let’s Talk
Live on Twitch!

thoughtbot is livestreaming

Work alongside the thoughtbot team as we collaborate with each other and our clients, live. Ask us anything, we're live right now!

Let’s get started!
View all Services
Development
  • Ruby on Rails
  • Hotwire
  • AI and Machine Learning
  • Maintenance
  • Mobile
Design
  • Discovery Sprints
  • UX, UI, and Product Design
  • Design Systems
Product
  • MVP
  • Product Management
  • Accessibility
Team and Processes
  • Team Augmentation
  • Fractional Leadership
View all Services
View all Resources
Development
  • Tech Leadership Resources
  • Open Source
  • Books
  • The Bike Shed Podcast
  • Live Streaming on YouTube
  • Conference Talks
The business of great software
  • Playbook
  • Purpose Built
  • Giant Robots Smashing Into Other Giant Robots Podcast
  • Design Sprint Guide
  • Live Streaming on LinkedIn
View all Resources

Security Articles

Written by thoughtbot, your expert partner for design and development.

    • All Topics
    • Design
    • Development
    • Product
    • More topics
  1. New online workshop: Protect your Rails app against security threats during COVID-19

    Join us as we discuss the rise of security threats during COVID-19, and how upgrading your Rails application can protect your business and users.

    Daniel Colson
    May 7, 2020
    • Security
    • Rails Upgrade
    • Remote
    • Workshops
    • Code Audit
    • Web
    • Ruby
    • Rails
  2. Web Security During the COVID-19 Pandemic

    The COVID-19 pandemic has brought with it an increase in cyber threats, but we can fight back by being more thoughtful about web security.

    Daniel Colson
    April 20, 2020
    • Security
    • Web
    • Ruby
    • Rails
    • Rails Upgrade
    • Code Audit
  3. Protecting User Data in HIPAA Compliant Staging Environments

    How to populate your staging environment with data while keeping user data secure.

    Sweta Sanghavi
    March 6, 2020
    • Health Tech
    • Security
    • Data
    • Web
  4. Health Tech, HIPAA, and Humans

    A brief introduction to HIPAA compliance for developers in health technology.

    Mike Wenger and Sarah Cassidy
    October 25, 2019
    • Health Tech
    • Security
    • Compliance
    • Design
    • Consulting
    • Accessibility
  5. Is Your Site Leaking Password Reset Links?

    Emailed password reset links are a common part of web applications. Is your site leaking these confidential links to third party sites?

    Derek Prior
    October 24, 2016
    • Web
    • Security
  6. Paperclip IS vulnerable to ImageTragick

    Paperclip is affected by CVE-2016–3714 if used with ImageMagick 7.0.1-0 or earlier.

    Tute Costa
    May 6, 2016
    • Security
    • Open Source
    • Paperclip
    • Ruby
  7. ImageMagick vulnerability does not affect Paperclip

    There is no need to upgrade Paperclip in light of CVE-2016–3714. You may choose to upgrade ImageMagick regardless.

    Tute Costa
    May 4, 2016
    • Security
    • Open Source
    • Paperclip
    • Ruby
  8. Paperclip Security Release

    We released Paperclip v4.2.2 with a security fix.

    Tute Costa
    June 5, 2015
    • News
    • Web
    • Open Source
    • Security
    • Ruby
    • Paperclip
  9. Building secure web applications with Ruby on Rails

    Ruby on Rails makes it easy to build web apps with security in mind.

    Murtaza Gulamali
    March 2, 2015
    • Rails
    • Ruby
    • Security
    • New Bamboo
    • Web
  10. Who's responsible for web application security?

    In short, we’re all responsible. And this is why.

    Alexis Ternoy
    February 12, 2015
    • Security
    • New Bamboo
    • Web
  11. Sign up to receive a weekly recap from thoughtbot

    Looking for even more ways to stay connected?
    RSS feed icon Check out our feeds
« First ‹ Prev 1 2 3 Next › Last »

Footer

thoughtbot
  • Services
  • Case Studies
  • Resources
  • Let's Talk
  • Our Company
  • Careers
  • Purpose
  • Blog
  • Sponsor
  • Mastodon
  • Bluesky
  • GitHub
  • YouTube
  • Twitch
  • Feeds
© 2025 thoughtbot, inc.

The design of a robot and thoughtbot are registered trademarks of thoughtbot, inc.

  • US: +1 (877) 9-ROBOTS
  • UK: +44 (0)20 3807 0560
  • Beware of fraudulent thoughtbot job listings Learn more
  • Code of Conduct
  • Accessibility Statement
  • Privacy Policy