Lessons from the trenches
Type safety alone is not security
Real security is more difficult than it sounds
It is impossible to separate implementation errors from design problems
New features introduce new security holes
New classes of attacks keep appearing
Humans are an essential element to consider