EN
A security incident exposed the resumes of 460 job seekers. The surprising part? There was no single bug or obviously wrong decision to blame. Instead, a series of reasonable technical choices interacted in unexpected ways, creating a vulnerability that went unnoticed until it was too late. In this talk, I’ll share how the incident was discovered, investigated, and resolved, along with practical lessons on security, complexity, and hidden assumptions in Ruby on Rails applications.