This was a presentation at a security conference.
I like how you mentioned frameworks like RoR that have XSRF prevention built in. Not enough security talks mention things like that.