The Changelog   /     Securing ecommerce: "It's complicated" (Interview)

Description

Ilya Grigorik and his team at Shopify has been hard at work securing ecommerce checkouts from sophisticated news attacks (such as digital skimming) and he's here to share all the technical intricacies and far-reaching implications of this work.

Subtitle
Duration
1:05:09
Publishing date
2025-03-20 14:00
Link
https://changelog.com/podcast/633
Contributors
Enclosures
https://op3.dev/e/https://cdn.changelog.com/uploads/podcast/633/the-changelog-633.mp3
audio/mpeg

Shownotes

Ilya Grigorik and his team at Shopify has been hard at work securing ecommerce checkouts from sophisticated news attacks (such as digital skimming) and he’s here to share all the technical intricacies and far-reaching implications of this work.

Join the discussion

Changelog++ members save 7 minutes on this episode because they made the ads disappear. Join today!

Sponsors:

  • RetoolThe low-code platform for developers to build internal tools — Some of the best teams out there trust Retool…Brex, Coinbase, Plaid, Doordash, LegalGenius, Amazon, Allbirds, Peloton, and so many more – the developers at these teams trust Retool as the platform to build their internal tools. Try it free at retool.com/changelog
  • Augment Code – Developer AI that uses deep understanding of your large codebase and how you build software to deliver personalized code suggestions and insights. Augment provides relevant, contextualized code right in your IDE or Slack. It transforms scattered knowledge into code or answers, eliminating time spent searching docs or interrupting teammates.

Featuring:

Show Notes:

Something missing or broken? PRs welcome!

Deeplinks to Chapters

0 Welcome to The Changelog
255
1035 PCI shortcomings
255
1115 PCI v4
255
1228 1st-party scripts
255
1278 3rd-party scripts
255
1412 Sounds not possible
255
1470 Sponsor: Augment Code
255
1659 Shopify's approach
255
1942 Compromises
255
2192 A long journey
255
2290 Is compliance enough?
255
244 Welcoming Ilya back
255
2528 Improving the web platform
255
2797 CSP / SRI reporting details
255
3088 Shopify's SRI setup
255
3241 Key takeaways
255
3424 AI shopping agents
255
343 Ilya's career path
255
3533 Human out of the loop?
255
3660 Wrapping up
255
3785 Closing thoughts
255
619 Core Web Vitals
255
63 Sponsor: Retool
255
816 Unpacking PCI
255