BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//pycones-2026//talk//YMQXEH
BEGIN:VTIMEZONE
TZID:Europe/Madrid
BEGIN:STANDARD
DTSTART:20251108T000000
TZNAME:CET
TZOFFSETFROM:+0100
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T030000
RDATE:20270328T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20261025T030000
RDATE:20271031T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Securing High-Risk Django Applications: Lessons from the Payment D
 omain - Dmytro Khmelenko
DTSTART;TZID=Europe/Madrid:20261108T112000
DTEND;TZID=Europe/Madrid:20261108T120000
DTSTAMP:20260726T231356Z
UID:pretalx-pycones-2026-YMQXEH@pretalx.com
DESCRIPTION:Applications that process money operate under numerous securit
 y constraints and require particular attention. Even small issues\, such a
 s an insecure endpoint or an inconsistent workflow\, can lead to fraud or 
 financial loss. Yet many Django applications rely on the default setups th
 at are not always suitable for high-risk domains.\n\nIn this talk\, I will
  share practical lessons from securing a real-world Django payment system.
  We will explore how to design reliable transaction flows\, enforce data i
 ntegrity across distributed components\, and prevent various attacks. The 
 session covers common blind spots such as race conditions\, fraud attacks\
 , unsafe admin usage\, as well as the architectural patterns that prevent 
 them.\n\nWe will also discuss proper error handling\, secrets management\,
  monitoring strategies for abusive behaviour\, and how to think like an at
 tacker when evaluating your own code.\n\nAttendees will learn concrete tec
 hniques and pragmatic security recommendations to build modern application
 s that remain secure under high load.
LOCATION:Track 05
URL:https://pretalx.com/pycones-2026/talk/YMQXEH/
END:VEVENT
END:VCALENDAR
