Michal Špaček

Michal Špaček Email and Phone Number

Security engineer & hacker, web developer, speaker and consultant @ Shoptet
hlavní město praha, praha, czechia
Michal Špaček's Location
Prague, Czechia, Czech Republic
Michal Špaček's Contact Details

Michal Špaček personal email

n/a
About Michal Špaček

Hack the planet.Specialties: HTTP, HTML, XML, SSL, PHP, FPD, RFC, JPEG, URL, SMTP, WSDL, TCP, IMAP, SVN, F2F, XSLT, CIDR, QR, SQLIA, MVC, INI, CSP, UDP, RFI, BCP, POP, XSS, SSH, CVS, HSTS, XKCD, SQL, MC, PEAR, DNB, WAN, MIVEC, ASM, TLS, SFPD, MIC, CT, RFC, PGP, ATM, JSON, DNS, FTP, SJFC, CSRF, ICQ, MTA-STS, P2P, XMPP, TLSRPT, MIME, VISA, DMARC, API, PIC, GPG, LAN, UTF, PGSQL, BASH, SW, RPM, C, PNG, IIN, LFI, SOAP. OMG, WTF, BBQ.

Michal Špaček's Current Company Details
Shoptet

Shoptet

View
Security engineer & hacker, web developer, speaker and consultant
hlavní město praha, praha, czechia
Website:
shoptet.cz
Employees:
71
Michal Špaček Work Experience Details
  • Shoptet
    Head Of Security
    Shoptet Jan 2023 - Present
    I'm the security team in Shoptet, the Central European Shopify alternative. It's a technical role, mostly. I've known Shoptet since at least 2012, I know many Shoptet people, present or past, and I love e-commerce, in my own way, so the decision wasn't that difficult.My Shoptet security team is the smallest and the largest at the same time - because everyone in the company is my team member, some just don't know it yet. It would be very boring without them, and I couldn't do it without them either.We run tens of thousands eshops so there's a chance to influcence and motivate quite a large part of the market, and to royally mess it up, too. I've always loved it, both ways.My mission is to do it like I've always done, be transparent and don't require passwords to be changed every 91.5 days. Yes, we've already rolled out 1Password company-wide, why are you asking?
  • Web Security & Php Consultancy, Trainings, Speaking, Bug Hunting
    Hacker
    Web Security & Php Consultancy, Trainings, Speaking, Bug Hunting Dec 2011 - Present
    Helping companies figure out web security, performance, and architecture in general.My goal is to teach web developers (and managers!) how to build secure and fast web applications, that's why I also do some speaking. I've done 100 talks and counting, including 4 times in a row at BSides/Passwords in Las Vegas. My talks are available at https://www.michalspacek.com/talks, though most of them are in Czech.I also run my own public and in-house trainings, using my experience gained during my professional career, be it thinking as a hacker or designing applications as an experienced developer. See https://www.michalspacek.com/trainings for details.I look for and report security bugs, from Atlassian to T-Mobile CZ, was introduced to their Hall of Fames, from Alza to T.S.Bohemia. If you live in the Czech Republic, then my reports prevented leaking your personal data, even more than once. You're welcome :-) I'm a fan and an advocate for security.txt because trying to figure out where to report things shouldn't take this long.
  • Report Uri
    Software Developer
    Report Uri Jun 2017 - Dec 2022
    I build report-uri.com, a real-time security reporting tool for both browser reports (CSP, NEL, ...) and email reports (DMARC, TLS-RPT), with Scott Helme and Troy Hunt, both award-winning security researchers and bloggers.We've processed 1.3T reports so far (in Dec 2022, up from 1.2T reports in June 2022 and 1T in Feb 2022, see report-uri.com and scroll down for the current number) currently doing 5k+ requests per second every day – that's some 100k requests before I've even managed to write this sentence. Subscriptions & payments powered by Stripe, report processing uses Cloudflare Workers & Digital Ocean Droplets, PHP 8 & Microsoft Azure Storage.I contribute regularly to the Microsoft Azure Storage SDK. We rely on testing and static analysis to prevent most bugs reaching the production environment. We automate all the things and update our dependencies regularly. We have our vendor directory versioned in Git and for a really good reason, ask me. I've built the initial Stripe payments integration and then switched to Stripe-hosted payment pages few years later. I generally do most of the development nowadays.I know how to build a secure web app, check out our penetration testing reports https://scotthelme.co.uk/tag/penetration-test/We deploy on Fridays, and if you ask I'll tell you how we've managed to do that. We've even upgraded to PHP 8.0 on Friday 13th 👻
  • Apiary
    Security Engineer
    Apiary Apr 2015 - Sep 2015
    Prague, The Capital, Czech Republic
    I was in charge of all things security: handling our penetration testing response as well as doing testing on my own, handling security incident responses, helping with security measures and design of secure storages and procedures. Also, raising team security awareness and introducing best practices to keep Apiary people safe and secure.
  • Slevomat
    Lead Web Developer
    Slevomat Sep 2013 - Jun 2014
    Hlavní Město Praha, Česká Republika
    Introduced up-to-date web security concepts and helped build payment and order pickup integrations. Discovered several security issues, introduced better protection for user passwords (no more SHA-1), initiated the move to HTTPS everywhere. Introduced Content Security Policy for resources loaded into our HTML.
  • Skype
    Lead Software Engineer & Scrum Master, Secure Web
    Skype Jul 2007 - Nov 2012
    Prague, The Capital, Czech Republic
    Building web applications in PHP (mainly Account https://secure.skype.com/account, Skype Manager https://manager.skype.com and various PCI-DSS certified payment systems 💳, integrations and APIs) and writing backend PostgreSQL functions and scripts in Python.
  • It Systems A.S.
    Developer/Analyst
    It Systems A.S. Jan 2007 - Jun 2007
    Infrastructure support, bugtracking software management, knowledge basemanagement, learning- and document management systems analysis & tweaking.
  • Webmade, Spol. S R.O.
    Web Developer, System Operator
    Webmade, Spol. S R.O. Sep 2005 - Dec 2006
    Web sites and on-line applications development, co-founder of www.tojeono.cz webhosting service.
  • Biology Centre Ascr, V.V.I., Institute Of Plant Molecular Biology
    Network Administration
    Biology Centre Ascr, V.V.I., Institute Of Plant Molecular Biology Sep 2005 - Dec 2006
    Network, server, workstation administration, user support.
  • My Own One Man Show Company
    Freelancer
    My Own One Man Show Company Nov 2002 - Sep 2005
    Internet websites and applications, network and server administration(cooperation with WEBMADE, spol. s r.o. on www.tojeono.cz web hostingstart-up; cooperation with Institute of Plant Molecular Biology ASCR,administration of network, servers and workstations).
  • Calvo, Spol. S R.O.
    Web Developer
    Calvo, Spol. S R.O. Aug 2000 - Nov 2002
    Internet presentations, websites, graphic designs.

Michal Špaček Skills

Php Web Development Internet Security Web Application Security Postgresql Sql Mysql Scrum Xml Software Development Technical Presentations Web Services Mvc Network Security Screwdriver Web Applications

Frequently Asked Questions about Michal Špaček

What company does Michal Špaček work for?

Michal Špaček works for Shoptet

What is Michal Špaček's role at the current company?

Michal Špaček's current role is Security engineer & hacker, web developer, speaker and consultant.

What is Michal Špaček's email address?

Michal Špaček's email address is ma****@****acek.cz

What skills is Michal Špaček known for?

Michal Špaček has skills like Php, Web Development, Internet Security, Web Application Security, Postgresql, Sql, Mysql, Scrum, Xml, Software Development, Technical Presentations, Web Services.

Who are Michal Špaček's colleagues?

Michal Špaček's colleagues are Rosalie Ovesná, Pavel Husa, Jana Šumberová, Gabriela Paurová, Natália Majer, Jitka Šišperová, Andrea Bradáčová.

Not the Michal Špaček you were looking for?

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.