Specific recommendations, grounded in the original conversation. Start with what’s newest or choose one lens.
Choose one filter
Showing the four newest recommendations
practitionerSecure Development
Set firm security boundaries with self-service paths
Said by Jeevan Singh ·
“We have to start saying, no, these are the lines in the sand that you cannot cross at all, and building our programs that way so that they know that this is the line that they can't cross, but they can self-help themselves to get to the place that they need to be without crossing that line.”
Transcript evidence from Vulnerability Jail and the AI-Era AppSec Engineer.
“Our proposal here is to build a champions community so that we're not overly relying on like a central security team, which is probably like a lot less people.”
Transcript evidence from Your AppSec Bottleneck Is a People Problem.
Protect psychological safety by not recording meetings
Said by Lisi Hocke ·
“Now what we have as a working agreement is we don't even record meetings because to set the ground for people being free to speak up and not fear that recording gets out of hand and somehow someone else, their manager, finds it and then they get the retribution.”
Transcript evidence from Your AppSec Bottleneck Is a People Problem.
“I do think there is still like a strength to being like an AI-native, either AI SaaS company or AI pen testing company, because you 've built so much harness and IP around like deduplication of results, how to build like a pipeline to go and do these things, how to do false positive analysis,”
Transcript evidence from AI Pen Testing Killed Traditional DAST.
“When you come up with an idea, you need to do an impact assessment and talk about, okay, who's going to be personally affected? What can be the risks? How can we protect against that? Are there any relevant regulations that we need to look into?”
Transcript evidence from AI Security: OWASP Meets Global Standards.
“If you use LLMs in red teaming, that includes a white box approach, that includes code, you will find the big leap will be in finding vulnerabilities that are hidden and found by looking at the code.”
Transcript evidence from AI Security: OWASP Meets Global Standards.
“I think the security engineer becomes the same thing, right? Like, hey, like, I'm going to manage a fleet of virtual security agents. They're going to do most of the toil work, right?”
Transcript evidence from Isaac Evans - AppSec in the Age of AI.
“I think that the advice to optimize for agility when it comes to security knowledge is important, right? Like you want to be on top of like, well, what is the latest trend here? Like what's going on? Like who are the security teams that have figured out how to get some good leverage in this new era and what are they doing? So I think that the importance of socializing with the security community, going to conferences, understanding how the teams that are effectively leveraging virtual agents is greater and greater.”
Transcript evidence from Isaac Evans - AppSec in the Age of AI.
“Then my second piece of advice is, be hands-on with the technology. Like there's never been a better time to be an IC, and the leverage that you can get as a solo IC is insane.”
Transcript evidence from Isaac Evans - AppSec in the Age of AI.
“What we've talked about so far is, hey, like if we provide plugins to the models that essentially are like additional security tests, I think you can start to get some good properties that are like, okay, like, we can trust that The model did not generate code that had any SQL injection possibilities.”
Transcript evidence from Isaac Evans - AppSec in the Age of AI.
“Because one of the main goals of observability is to be able to react. And then to react, you need to make sense out of the data, right? And then convert this data into information and that information into action.”
Transcript evidence from José Carlos Chávez - When Museums Get Hacked: OWASP Top 10 Lessons from Heists.
“You have to implement the controls, but then monitor Um, how is it working? Like how many denials did you have? How many, um, permission grants did you have? And then what is the baseline? What are the deviations? who are the outliers?”
Transcript evidence from José Carlos Chávez - When Museums Get Hacked: OWASP Top 10 Lessons from Heists.
“Things, easy things like Dockerfiles, you might see Dockerfiles, plenty of Wget or curl where they are pulling down artifacts directly from GitHub host. And then with no integrity check, no checksum, Nothing, curl and then directly execute the bash script or unzipping the content and then dumping into the Dockerfile, into the Docker image.”
Transcript evidence from José Carlos Chávez - When Museums Get Hacked: OWASP Top 10 Lessons from Heists.
“For that, you need to take the same warranties as you will do with any database, for example, like encryption at transport, encryption at rest, and then permissions for writing, or even better, like immutability.”
Transcript evidence from José Carlos Chávez - When Museums Get Hacked: OWASP Top 10 Lessons from Heists.
“Security needs you. And ownership or security, for security being a thing, for security being effective, for security being tangible and possible to roll out across an organization, you need a strong sense of ownership.”
Transcript evidence from José Carlos Chávez - When Museums Get Hacked: OWASP Top 10 Lessons from Heists.
“But that means you have to keep an eye on certain things and make sure that it's not gonna end up doing things that you don't wanna do, or pushing code you don't wanna do, or suddenly changing major settings.”
Transcript evidence from Josh Grossman--AI & SAST: Is it a match?.
Validate tool compatibility before static discovery
Said by Josh Grossman ·
“If you want to do the static discovery, you have to make sure the static discovery is going to be compatible with your, with the tool you're using to discover.”
Transcript evidence from Josh Grossman--AI & SAST: Is it a match?.
“Build agents that both ensure that those patterns are in use everywhere they're supposed to be, as well as finds areas where it's different and fixes it.”
Transcript evidence from Caroline Wong--The AI Cybersecurity Handbook.
“To your point, AI to get funding, but I think that there's reality, there's quality within the hype that gets drowned out.”
Transcript evidence from Brad Geesaman - Redefining AppSec with AI: Shrinking Toil, Expanding Impact - How LLMs are able to reduce toil in triage-heavy AppSec workflows.
“For you to trust the finding, you have to validate it so that you can broker your trust to the devs and not look like a silly fool when they go, hey, that's not an issue.”
Transcript evidence from Brad Geesaman - Redefining AppSec with AI: Shrinking Toil, Expanding Impact - How LLMs are able to reduce toil in triage-heavy AppSec workflows.
“There's a middleware library, or there's another capability, or there's something that is unique to your coding style that you can have a conversation with the developers and say, folks, we have 50 BOLAs.”
Transcript evidence from Brad Geesaman - Redefining AppSec with AI: Shrinking Toil, Expanding Impact - How LLMs are able to reduce toil in triage-heavy AppSec workflows.
“I think we need to train the next generation of developers to use this technology securely rather than saying you're never going to have a job or you're going to be replaced.”
Transcript evidence from Francesco Cipollone - Agentic AI Manifesto.
“Now, through their sister brand, CyberSec Games, they're helping thousands of people learn threat modeling and security concepts through engaging, hands-on gameplay.”
Transcript evidence from Simon Gibbs & Devika Gibbs -- Building Bridges with Games.
“It helps you that what all APIs you have in your organization, like depending on the classification, specification, functionality, all these will help.”
Transcript evidence from Akansha Shukla - Modern AppSec: Securing APIs with Threat Modeling and DevSecOps.
“BSIM is a maturity framework with like 110, 115 different questions you ask to development teams and you try to find the gaps and what's missing and you plan some improvement.”
Transcript evidence from Getting Ready for the EU CRA.
“Make it something that people can be motivated by proactively because they have seen it and they understand, oh, if I do this, then this will happen.”
Transcript evidence from Marisa Fagan - Measuring Security Culture.
“I don't think you need to get your security champions program ratified by legal, but the mindset that it should be a trustworthy agreement between 2 sides resonates.”
Transcript evidence from Marisa Fagan - Measuring Security Culture.
“If you can tell the story that teams that have champions show faster participation in our vulnerability management process, that is a great story to tell that comes from a metric that you need to start tracking first.”
Transcript evidence from Marisa Fagan - Measuring Security Culture.
“Then once we have these goals, the next level is formulating questions to measure progress towards that goal, to measure, to see how well we are doing in terms of a specific goal and to measure the progress towards that goal. And only then we pick metrics to answer these questions in a quantitative way.”
Transcript evidence from Aram Hovsepyan -- Your Security Dashboard is Lying to You: The Science of Metrics.
Test metrics for reliability, precision, and validity
Said by Aram Hovsepyan ·
“When you pick your metrics, you will eventually be facing the questions of how reliable is this metric, how precise is this metric, and what is the validity of this metric when we want to go back and answer the question that to support this is a certain decision-making, which comes from the goal.”
Transcript evidence from Aram Hovsepyan -- Your Security Dashboard is Lying to You: The Science of Metrics.
“You could go a step further and ask teams to write unit and integration tests for those requirements, which are then automated in your CI/CD pipelines.”
Transcript evidence from Aram Hovsepyan -- Your Security Dashboard is Lying to You: The Science of Metrics.
Balance dashboards across people, processes, and tools
Said by Aram Hovsepyan ·
“Your dashboard should reveal the truth of what's going on in terms, in terms of your process perhaps, rather than your output and these scanners that look into your code, because that's one side of the story. And a typical AppSec program is about people, processes, and tools.”
Transcript evidence from Aram Hovsepyan -- Your Security Dashboard is Lying to You: The Science of Metrics.
“Even if you have only 15 minutes, if you keep it into like a systematic small steps of improvements, but keep track that everything else isn't drifting away.”
Transcript evidence from Dag Flachet -- Kaizen for your Appsec Program.
“That's why a maturity model like OWASP SAM is good because it keeps track of everything, the state of everything, and then you try to move the lever somewhere a little bit.”
Transcript evidence from Dag Flachet -- Kaizen for your Appsec Program.
“Don't be afraid of little steps as long as you have the map well laid out and the little steps may seem Quite insignificant in the big picture, but if you're consistent with little steps, you can have pristine quality and security on the long run.”
Transcript evidence from Dag Flachet -- Kaizen for your Appsec Program.
“There needs to be something new because you need to separate the prompt, the command from the input and have some type of a solution that lets you, the im— that lets the model treat the input as only input and never commands that could cause it to go in a different route.”
Transcript evidence from Javan Rasokat and Andra Lezza -- When Chatbots Go Rogue - Lessons Learned from Building and Defending LLM Applications.
“If your, if your company policy tells you to not share sensitive company information with ChatGPT, then you should listen to that, especially if you work in a government intelligence agency.”
Transcript evidence from Javan Rasokat and Andra Lezza -- When Chatbots Go Rogue - Lessons Learned from Building and Defending LLM Applications.
“We need to build awareness and knowledge about those type of attacks because as you can't do a good threat model if you don't know those type of attacks.”
Transcript evidence from Javan Rasokat and Andra Lezza -- When Chatbots Go Rogue - Lessons Learned from Building and Defending LLM Applications.
Adapt security requirements to the operating environment
Said by Mehran Koushkebaghi ·
“If you're dealing like a 3-tier web application in some environment, it's going to be having a completely different completely different resilience and security requirement if you change that environment.”
Transcript evidence from Mehran Koushkebaghi -- Security as a Systemic Concern: How to develop Anti-Requirements.
Define trust boundaries before applying input validation
Said by Mehran Koushkebaghi ·
“Whether you need the input validation Depends on the the nature of application that you're building, how you define the trust boundaries, where the data is coming from.”
Transcript evidence from Mehran Koushkebaghi -- Security as a Systemic Concern: How to develop Anti-Requirements.
Explain security risks in terms of business impact
Said by Kalyani Pawar ·
“If in terms of, say, if I can say in a finance software, if I was able to say that if we were able to push this feature, we're gonna print out all the SSNs, I don't think anybody wants that, right? I think at that point, people are willing to work with you on this.”
Transcript evidence from Kalyani Pawar -- Shaping AppSec at Startups.
“First of all, you cannot secure what you cannot see. So, try to see everything that you have. Try talking to as many, say, if it was my day one at a certain startup as an AppSec engineer, my first line of action would be to talk to all the developers and ask them about an architecture diagram for whatever has been built.”
Transcript evidence from Kalyani Pawar -- Shaping AppSec at Startups.
“When we're talking about third-party tools, we often overlook the aspect of vendor security when I feel like every time we onboard new tools, there has to be some security vetting process in place.”
Transcript evidence from Kalyani Pawar -- Shaping AppSec at Startups.
“To update the diagram or the model with the new threats for the new developments that you're planning, because it should be done before you implement, ideally, so that you can correct the design before you start implementing.”
Transcript evidence from Brett Crawley -- Threat Modeling Gameplay with EoP.
“I took those and I put those into the board, and then I added Post-its for pink ones for the threats, orange ones for proposed mitigations, and green ones for mitigations that are already existing in the design or in the implementation.”
Transcript evidence from Brett Crawley -- Threat Modeling Gameplay with EoP.
“They tell you if you accept pull requests, you need to treat it like untrusted input and you need to use the workflows to segment them and use the right type of events like Pull request, there are 2 types of events trigger the workflow.”
Transcript evidence from François Proulx - Arbitrary Code Execution 0-day in Build Pipeline of Popular Open Source Packages.
Understand before you can start doing a threat model, before you can start doing a pen test
Said by Jeff Williams ·
“There's like all this information about how the application works that you need to understand before you can start doing a threat model, before you can start doing a pen test.”
Transcript evidence from Jeff Williams -- Application Detection & Response (ADR).
“I think before introducing any new control on an enterprise level for your organization, take a step back and say, is this something that's going to scale?”
Transcript evidence from Irfaan Santoe -- The Power of Strategy in AppSec.
Design applications for secure-by-default frameworks
Said by Andrew van der Stock ·
“I think developer education is overrated. And I think what we need to do is get to the frameworks and say to the frameworks, you need to fix these things based around the ASVS.”
Transcript evidence from Andrew Van Der Stock -- The New OWASP Top Ten.
“If you have a collection of CWE data that is easily extractable, doesn't matter the size of the contribution. If you've got 10 apps, if you've got 100,000 apps, we'd love to talk to you.”
Transcript evidence from Andrew Van Der Stock -- The New OWASP Top Ten.
“You have to take more entry-level people and you have to provide them a pathway to grow them, to mentor them so that they could become those mid to high-level roles.”
Transcript evidence from Derek Fisher -- Hiring in Cyber/AppSec.
“To me, a secure guardrail is some technical implementation that tries to get you— it tells you, hey, you're not doing what you should do from a security perspective.”
Transcript evidence from Tanya Janca -- Secure Guardrails.
“Find out who needs what, who needs our help, and who these developers are, where they are located in the organization, what is the level of awareness when it comes to security”
Transcript evidence from Jahanzeb Farooq -- Launching and executing an AppSec program.
“With application security, starting with something like a BSIM framework, where you're looking across the different domains and take, take the existing— because every company, regardless of whether they have a dedicated security program or not, or a very well-built-out one, like, they're going to have some of the practices.”
Transcript evidence from David Quisenberry -- Building Security, People, and Programs.
“If you want to manage infrastructure in the cloud, if you start managing like Terraform deployments, you are one step away from like Python scripts to start doing things.”
Transcript evidence from James Berthoty -- Is DAST Dead? And the future of API security.
“Let's keep the people making money out of it, figure out how to go support it because they should be held, let's hold them accountable for going and doing it.”
Transcript evidence from Mark Curphey and Simon Bennetts -- Riding the Coat Tails of ZAP, without Open Source Funding.
“First off, I built a roadmap that I could use to socialize my vision for the program and communicate with the key stakeholders what would be needed from them.”
Transcript evidence from Devin Rudnicki -- Expanding AppSec.
“We did try to show the value as far as showing the vulnerability closure rates and showing the trends and vulnerabilities from quarter to quarter or month to month, depending on what level of reporting you were doing.”
Transcript evidence from Devin Rudnicki -- Expanding AppSec.
“You have to build a strong, uh, team that can drive this thing, because you want that champions program to exist years into the future, not be, so many champions programs are a flash in the pan.”
Transcript evidence from Dustin Lehr -- Culture Change through Champions and Gamification.
“Um, and so like how a threat actor could gain access and they've done a breach, um, if you're doing an assumed breach activity, you are given access.”
Transcript evidence from Meghan Jacquot -- Assumed Breach Red Team Engagements for AppSec.
“We want you to test if you have no login, we want you to test if you have a lower level login, we want you to test if you have super admin, and so you could set up a variety of different scenarios.”
Transcript evidence from Meghan Jacquot -- Assumed Breach Red Team Engagements for AppSec.
“It's, I continued when the software development side for a long time, but I was always the security guy on the dev team and eventually, um, I got off on a long, tiring project and went looking for something else to do and vulnerability assessment was one of the options.”
Transcript evidence from Bill Sempf -- Development, Security, and Teaching the Next Generation.
“Um, so it's, it's, it went fairly well, but, um, I more or less walked through the, what I used in, not only with these two, um, but, with, um, Scouts, working with Scouts for years and years, and working with KidsMatch, um, and being the advice giver in the family for people who, have”
Transcript evidence from Bill Sempf -- Development, Security, and Teaching the Next Generation.
“Um, and, um, I think that, yeah, people who are in application security with a primarily network background should go to developer conferences and see what the developers are dealing with.”
Transcript evidence from Bill Sempf -- Development, Security, and Teaching the Next Generation.
“Once you get to scale and you have tens of thousands of applications and on a ton of infrastructure, you have to define your scope of what you can cover.”
Transcript evidence from Jason Nelson -- Three Pillars of Threat Modeling Success: Consistency, Repeatability, and Efficacy.
Transcript evidence from Erik Cabetas -- Cracking Codes on Screen and in Contests: An Expert's View on Hacking, Vulnerabilities, and the Evolution of Cybersecurity Language.
“Talk to any of them, but please don't like go get somebody that doesn't know what they're doing.”
Transcript evidence from Erik Cabetas -- Cracking Codes on Screen and in Contests: An Expert's View on Hacking, Vulnerabilities, and the Evolution of Cybersecurity Language.
“Figure that out, and we have to use these more modern languages that are fully featured, but yet manage the memory for you a bit.”
Transcript evidence from Erik Cabetas -- Cracking Codes on Screen and in Contests: An Expert's View on Hacking, Vulnerabilities, and the Evolution of Cybersecurity Language.
“You have to get out of the idea of, let me, like, show you how cool I am with finding vulns and let me affect positively the way this business is run.”
Transcript evidence from Erik Cabetas -- Cracking Codes on Screen and in Contests: An Expert's View on Hacking, Vulnerabilities, and the Evolution of Cybersecurity Language.
“What's reasonable telling someone that you can't have critical vulnerabilities in your project or in your product? it's not reasonable because back on the software supply chain they take in a They use a component that's critical to the functionality of whatever it is that they're selling whatever their products”
Transcript evidence from Kyle Kelly -- The Dumpster Fire of Software Supply Chain Security.
“I think of that as a best practice as well and I'll even genericize it a little bit more and say Proxy, a third party dependency proxy is the capability.”
Transcript evidence from Kyle Kelly -- The Dumpster Fire of Software Supply Chain Security.
“This one, I'd say, one piece of advice I often give security peers is be empathetic, go out and try to understand the incentives and things that people are doing and why they're doing them, what things are driving them to do what they're doing, because often it's, it's simple for us to say,”
Transcript evidence from Chris Hughes -- Software Transparency.
“But if we want to get something that is valuable, For, uh, us, then we need to move away from this black box, gray box testing, and we need to get into something where opening stuff up and starting to get into some of the business logic issues.”
Transcript evidence from Jay Bobo & Darylynn Ross -- App Sec Is Dead. Product Security Is the Future..
“My, the practice that I've adopted is, uh, for my previous startup and for my existing startup is, I have a wide group of people interview any candidate, and anybody can be thumbs down.”
Transcript evidence from Arshan Dabirsiaghi -- Security Startups, AI Influencing AppSec, and Pixee/Codemodder.io.
“We were both uh, we were leaving at the same time and, uh, we got to talking about the different problems, uh, that AppSec, that there weren't AppSec left to solve.”
Transcript evidence from Arshan Dabirsiaghi -- Security Startups, AI Influencing AppSec, and Pixee/Codemodder.io.
“Uh, we're still pretty early, so we don't, unfortunately we don't have time for everything yet, but we absolutely, they know that's one of the reasons we, it's primary reason we made it open source is we want people to be able to build codemods and do whatever you want with them.”
Transcript evidence from Arshan Dabirsiaghi -- Security Startups, AI Influencing AppSec, and Pixee/Codemodder.io.
“I think it could vary a lot because I suppose there's no reason why a startup or any other company couldn't offer some rudimentary bug bounty type, program or something, but in general, I would agree, if you haven't done the fundamental, especially if you have a, if you're an older company”
Transcript evidence from Dr. Jared Demott -- Cloud Security & Bug Bounty.
“But for example, you could either use whitelists or blacklists and allow lists or deny lists as far as like, there should never be a, internal address in those parameters.”
Transcript evidence from Dr. Jared Demott -- Cloud Security & Bug Bounty.
“All the things that are in the SDLC, like security training and code reviews and automating and CICD and, security champions, like I feel like on any level, whether a company is small or large, you can find a way to do that in a way that makes sense to you.”
Transcript evidence from Dr. Jared Demott -- Cloud Security & Bug Bounty.
“Protecting personal data is one of the things that we protect with security, but it's so hard to stay updated on those various threats and defenses, um, related to machine learning systems.”
Transcript evidence from Katharina Koerner -- Security as Responsible AI.
“We're using it as an underpinning for our new vendor assessment processes to be able to improve those, speed them up, and make sure that things coming into our process are a lot better quality.”
Transcript evidence from Chris John Riley -- MVSP: Minimum Viable Secure Product.
“If there's an issue, you need to have identified the logs you require up front, because if you're trying to change your logging when an incident happens, you've already lost.”
Transcript evidence from Chris John Riley -- MVSP: Minimum Viable Secure Product.
“Our goal with MVSP is can you build that solid foundation and then if you want more from a product, it's easier to build that on top of a strong foundation and a good understanding of how things fit together.”
Transcript evidence from Chris John Riley -- MVSP: Minimum Viable Secure Product.
“What we are after is shifting that whole thing all the way left to the point in time when the developer says, I want to use a new open source project.”
Transcript evidence from Varun Badhwar -- The Developer Productivity Tax.
“First of all, get a list. Understand how many secrets you have, where are they, then enrich them, classify them, understand their blast radius, and then monitor them for any anomaly.”
Transcript evidence from Itzik Alvas -- Secrets Security and Management.
“If you make it easy for developers to fix and remediate those risks, that's going to be the single most impactful thing in, uh, in mitigation, right?”
Transcript evidence from Harshil Parikh -- Deep Environmental and Organizational Context in Application Security.
“By improving the developer experience, giving them context about why they should pay attention to certain things and being cognizant of the organizational decision making”
Transcript evidence from Harshil Parikh -- Deep Environmental and Organizational Context in Application Security.
Use automation to focus manual effort on high-impact work
Said by Maril Vernon ·
“Automate as much as possible so you can spend, that 20% of your precious manual time on the things that matter, the big impact items, the blast radius items.”
Transcript evidence from Maril Vernon -- You Get What You Inspect, Not What You Expect.
“I think that a lot more people should get on collab calls and see what happens, see what products emerge as a result, see who starts collabing on stuff.”
Transcript evidence from Maril Vernon -- You Get What You Inspect, Not What You Expect.
“If you don't understand the limitations of a given tool, if you don't understand its strengths and weaknesses and understand its both of those, you're not gonna pick the right tools.”
Transcript evidence from Dan Küykendall -- Why All Application Security Products Suck.
“I would probably grab an SCA product so that I could make sure that the packages that that we're pulling in, That we have some understanding of what's coming into our project. So I would probably look at an SCA tool off the bat and um, generally, again, this depends on what language you're using and all that stuff, but I would probably, the next thing would probably be a SAST is I would probably, especially if I'm that early, I would want to be making sure we're monitoring the code as closely as possible.”
Transcript evidence from Dan Küykendall -- Why All Application Security Products Suck.
“Um, but there has been a push for the last, I don't know, year that OWASP has to figure out how to help fund chapters and projects and promote itself to the community.”
Transcript evidence from Kevin Johnson -- Samurai Swords and Zap's Departure.
Prepare developers for unfamiliar component threats
Said by Chris Romeo ·
“Developers should understand because they may encounter threats and different components here that we as security people haven't even thought about yet.”
Transcript evidence from Paul McCarty -- The Burrito Analogy of the Software Supply Chain.
“The third model is the champion or deputy model where the AppSec team deputizes developers to do the bulk of the application security work, and the AppSec team becomes a resource and escalation point for more complex problems.”
Transcript evidence from Farshad Abasi -- Three Models for Deploying AppSec Resources.
“Then we would set up these weekly sessions where we would work at a mentorship capacity, where they would bring that filtered list of user stories, not all of them.”
Transcript evidence from Farshad Abasi -- Three Models for Deploying AppSec Resources.
“It can definitely be done together, but you need to like change heads going because you have different viewpoints to tackle that. But it can definitely be done and it should be done.”
Transcript evidence from Kim Wuyts -- The Future of Privacy Threat Modeling.
“The sooner you start with that, ideally at ideation already, the sooner you can start thinking of, well, okay, this is the end goal. This is the thing we want to achieve. Now, do we need to do that in that way that we think we, I don't know, need to have our users have their location data shared with us 24/7?”
Transcript evidence from Kim Wuyts -- The Future of Privacy Threat Modeling.
Use privacy patterns and tactics to address threats
Said by Kim Wuyts ·
“You have a set of strategies and tactics created by Jaap-Henk Hoekman, who is a Dutch professor, and his PhD student, former PhD student, Michael Kolesky, and the tactics there, they have They call it Little Blue Book, I think, with a lot of privacy strategies that say like, you need to minimize, you need to hide, you need to enforce.”
Transcript evidence from Kim Wuyts -- The Future of Privacy Threat Modeling.
“People will make layered architectures where they create very specific models that are only worried about screening for things like prompt injection.”
Transcript evidence from Steve Wilson -- OWASP Top Ten for LLMs.
Secure applications deployed in cloud environments
Said by Joshua Wells ·
“If you're a DevOps guy and you're working in, let's say, AWS, you're working in GCP, you're managing some type of application that's embedded on a container, you have to make sure that application is secure.”
Transcript evidence from Joshua Wells -- Application Security in the Age of Zero Trust.
“Directing that influence at the leadership level, making sure that you're focusing on, um, engineering leadership or the execs and making sure that they understand why it's important to do whatever you need to do.”
Transcript evidence from Jeevan Singh -- The Future of Application Security Engineers.
“You shouldn't be fixing vulnerabilities yourself. You should be guiding the business to fix vulnerabilities and being able to influence the, uh, business to fix vulnerabilities at scale.”
Transcript evidence from Jeevan Singh -- The Future of Application Security Engineers.
“It's like a specification to define somewhat programmatically a threat model and then some tooling to turn that into a human-readable file that in theory can live inside of the software repo along with the software and it can be managed with GitHub.”
Transcript evidence from Christian Frichot -- Threat Modeling with hcltm.
“If you've worked at a handful of places and in particular organizations that have these various levels of maturity with threat modeling, no one does it the same.”
Transcript evidence from Christian Frichot -- Threat Modeling with hcltm.
Avoid treating one perspective as the full picture
Said by Zohar Shachar ·
“Getting a perspective that is only one perspective and it's partial, but turning it into the full picture is a danger that you should avoid if you run a program.”
Transcript evidence from Zohar Shachar -- Bug Bounty from Both Sides.
“That's— and that helped me identify teams that were ripe for threat modeling because I was able to say, hey, in the past 6 months you've had this this, and this all after production, and they— that pain was always fresh with them then.”
Transcript evidence from Sarah-jane Madden -- Threat Modeling to established teams.
“But what that showed that I think we could bring forward, pandemic aside, because remote teams have huge advantages, but was that you do need to get together for threat modeling to address creator blindness.”
Transcript evidence from Sarah-jane Madden -- Threat Modeling to established teams.
“In order for address, for us to continue doing the job, we have to address it in a risk-based approach, identifying what should we be working on because we probably can't work on everything.”
Transcript evidence from Jet Anderson -- The AppSec Code Doctor.
“That's why I've spent the last 5 years or so focusing on how do I engage developers to make sure that they have this information on day one and give them a direction that they can use to go and learn more.”
Transcript evidence from Jet Anderson -- The AppSec Code Doctor.
“Then, but the last two-thirds was what are the best practices, proactive controls, like what are the things that you guys can do to make sure to do it right from the first time, from the start.”
Transcript evidence from Jet Anderson -- The AppSec Code Doctor.
“We as information security professionals have to get better about pulling out the pieces of information that are right, that are important, and put the why behind it. Right. And that's the key in that space is if we can get to the why and simplify the why, the details make sense.”
Transcript evidence from James Mckee -- Developer Security.
“Taking, let's take some of the projects that have gone through and figure out how to create a training set specifically saying, here is a bad code, based off of a security bug, and here's how it was fixed.”
Transcript evidence from James Mckee -- Developer Security.
“But what I would love to see more than that is pick one item off the OWASP Top 10 and do a deep dive. Like, if you want to, if you want to speak at a security conference, I say this as a— I'm one of the organizers of BSides Boulder, right? Like, if you want to do this, take one of those topics, dive deep, give them enough that they can take back. That's more than a blurb.”
Transcript evidence from James Mckee -- Developer Security.
“If you are, a developer in your IDE, if you can integrate open source tools to try to detect, whether it's, whether you're running a SAST or you're running some type of open-source scanner like DependencyCheck or something like that, and if you have the ability to run some container image”
Transcript evidence from Derek Fisher -- The Application Security Handbook.
“It's not about the beauty or the excellence of technical fixes or issues or architectures, I have to measure that against or weigh that against the business and say, sometimes I have to say, I'm going to have to accept that risk for a period of time, right?”
Transcript evidence from Derek Fisher -- The Application Security Handbook.
“Spend time thinking through what am I trying to get out of this penetration test and how can I set up the people that are conducting this test for success?”
Transcript evidence from Robyn Lundin -- Planning & organizing a penetration test as an AppSec team.
Replace personal connections in shared applications
Said by Michael Bargury ·
“You need to make sure when there's an application that is being used by an organization, by the organization, to make sure that the underlying connections are not somebody's personal connections.”
Transcript evidence from Michael Bargury -- Low Code / No Code Security and an OWASP Top Ten.
Consider harmful uses of legitimate application features
Said by Wolfgang Goerlich ·
“We need to think about how the applications we're creating and the functionality we're enabling can be with legitimate functions and no use of exploits, can be used in harmful ways.”
Transcript evidence from Wolfgang Goerlich -- Security beyond vulnerabilities.
“Of course, another thing about NetTacker is you can control the speed, because the way how the scans work, it's all multi-threaded, and the user is in control of how many threads per scan you wish to use.”
Transcript evidence from Sam Stepanyan -- OWASP Nettacker Project.
“If you do have the problem in your organization that you don't know your assets, you have an asset inventory issue, all right, I would invite everyone to use NetHacker to find out the assets.”
Transcript evidence from Sam Stepanyan -- OWASP Nettacker Project.
“Denial of service is one of the main pain points of GraphQL because the client is in control of what the response format is going to be, which is quite unique as well.”
Transcript evidence from Nick Aleks and Dolev Farhi -- GraphQL Security.
“Make sure that you have the necessary tools from rate limiting perspective, from log analysis perspective, from alerting perspective that can help you get your GraphQL APIs to the level of your REST APIs.”
Transcript evidence from Nick Aleks and Dolev Farhi -- GraphQL Security.
“Most of the appliances or systems that you're running in your business, in your enterprise, that use Log4j don't have a software bill of materials, SBOM, to tell you, this is the things that we are using, and Log4j is one of them.”
Transcript evidence from Guy Barhart-Magen -- Log4j and Incident Response.
“Pull request runs, we get an event, the event triggers the scans, right? The scans go, and if you've got newer scanner engines, they can talk back to the pull request, and they update the pull request with the results.”
Transcript evidence from Brett Smith -- Security is a Necessary Evil.
Get our database encrypted, or we need to encrypt our file system
Said by Hillel Solow ·
“I had the opportunity to do that a couple of times, whether it was on the cutting edge of things, so things that didn't necessarily exist and we were trying to create, Or it was, yeah, we need to encrypt our data, or we need to transmit our data encrypted, or we need to get our database encrypted, or we need to encrypt our file system.”
Transcript evidence from Hillel Solow -- How to do AppSec without a security team.
“But what you need is a good idea. You need, you need something that you stand behind, you think is going to, is going to work and is going to solve a customer's problem.”
Transcript evidence from Chris Romeo -- The Security Journey Story.
“Then once we had this list of tools together, we had to put together a list of evaluation criteria to understand whether they were applicable for our use case And I'll highlight now, I guess, that we were looking at our use case of having this idea of putting together a privacy threat modeling”
Transcript evidence from Kristen Tan and Vaibhav Garg -- Machine Assisted Threat Modeling.
Protect sensitive branches and repositories consistently
Said by Speaker not identified ·
“You need to make sure that you have this practice in place on all of your sensitive branches, in all of your sensitive repositories in your organisation.”
Transcript evidence from Omer Gil and Daniel Krivelevich -- Top 10 CI/CD Security Risks.
“We have 4 or 5 new fields that would help us classify the risk and would help us prioritize application security engineer activities to better protect the business, to better be prepared for the attackers to come.”
Transcript evidence from Alex Mor -- Application Risk Profiling at Scale.
“We go over those risk profiles, we go over the data, and when we prioritize what application should we pentest next, we take that list, but we don't only look at the high ones.”
Transcript evidence from Alex Mor -- Application Risk Profiling at Scale.
“The way that I explained the role, I have a cool PowerPoint slide that shows the liaison role of product security leads being the connection between the central product security office and our 150 to 200 security champions that we have, because we do have a security champion in each product team.”
Transcript evidence from Brenna Leath -- Product Security Leads: A different way of approaching Security Champions.
“Different skills, which is great to see how these— we currently have 8, so how these 8 people who all have the same role, they all have to do it slightly differently because they're all in different divisions.”
Transcript evidence from Brenna Leath -- Product Security Leads: A different way of approaching Security Champions.
“A PMP, a project management background, but it is important to know how to prioritize, how to figure out what it is you should be working on versus what people are telling you to do.”
Transcript evidence from Brenna Leath -- Product Security Leads: A different way of approaching Security Champions.
Document patterns for developers at every skill level
Said by Joern Freydank ·
“Now, the one thing though that's relatively important is that when those things are documented, those patterns, that is that you have to create an easy entry for the developers that don't have that abstraction-level knowledge.”
Transcript evidence from Joern Freydank -- Security Design Anti Patterns Limit Security Debt.
Threat-model the whole blockchain application stack
Said by Ken Toler ·
“Because blockchain is a part of the tech stack doesn't mean that it's all of the tech stack. And so there are still areas where applications are being used, APIs are being used, third-party integrations are being used, cloud infrastructure is being used, all of your containerization, all the things that we typically think of.”
Transcript evidence from Ken Toler -- Blockchain, Cloud, and #AppSec.
Apply standard authorization controls to smart contracts
Said by Ken Toler ·
“These are all authorization vulnerabilities and weaknesses that happen that we would, we would consider very similar to an unprotected or unauthorized API, right? If it was a public API, we had no authorization structure, like we'd have a very similar attack.”
Transcript evidence from Ken Toler -- Blockchain, Cloud, and #AppSec.
“One is if you're taking, if you're taking input into a contract, you should be validating it. You have similar protections around, static typing or, um, or some built-in validations in some of these languages. But you may not be able to cover all cases unless you, unless you understand your own business logic and validate what's expected.”
Transcript evidence from Ken Toler -- Blockchain, Cloud, and #AppSec.
“Use a specialized tool for the job, any secrets manager, even a password manager if it's for your personal secrets, for example, use something like 1Password, LastPass, whatnot, KeePass.”
Transcript evidence from Jeroen Willemsen and Ben de Haan -- Dirty little secrets.
“There's nothing— there's no better future that I can think of than the threat modeling process doesn't even exist anymore because it's ingrained in how we build software.”
Transcript evidence from Adam Shostack -- Fast, cheap and good threat models.
“Translating the ASVS requirement into a threat and saying, for those people that are new to this and they don't have the mental models of all the things that we've done where we've seen different threats, and so we can see them jump off the page.”
Transcript evidence from Adam Shostack -- Fast, cheap and good threat models.
“But then I flip that back around and see that security measures can often get in the way or they can complicate it or they can make the user experience miserable.”
Transcript evidence from Loren Kohnfelder -- Designing Secure Software.
“Fairly short, gives you a broad overview of the field, because we want to get a lot of, uh, people connected to software, working on it, not developers, but all the people around them, user interface managers, We want them to have some intuition about what these problems are and what— how we have to deal with them”
Transcript evidence from Loren Kohnfelder -- Designing Secure Software.
“The whole point of being able to have the configuration files to spin up and build the infrastructure in the first place is so that you can delete it, you can tear down, you modify it and have a centralized location and know what and know how it, what it, how it connects to other resource cloud resources.”
Transcript evidence from Ochaun Marshall -- IaC and SAST.
“The SAST is a starting point in which you can make some initial investigation because any static analysis tool will need multiple runs and will need configuration changes as well.”
Transcript evidence from Ochaun Marshall -- IaC and SAST.
“It's a good idea because ZAP is free It means you can use ZAP as you're developing your application, and you can use ZAP to find vulnerabilities before you get the pen testers involved.”
Transcript evidence from Simon Bennetts -- Using OWASP Zap across an Enterprise.
“But the reality is it's a lot of the things, there are a lot of things that you would have to manage and secure and scan, monitor, and configure to be in a typical secure environment, not the highest security.”
Transcript evidence from Mazin Ahmed -- Terraform Security.
“The first thing to start with is learning about all of the attacks and all of the vectors. all of the threats that using Terraform can bring to the organization.”
Transcript evidence from Mazin Ahmed -- Terraform Security.
“That's what we talk about because ultimately these folks that are in these teams should strive to be— that should be their pipeline to be architects over time.”
Transcript evidence from James Ransome and Brook Schoenfield -- trust and verify: Building in Security at Agile Speed.
“With that, it takes us to A4 for 2021, insecure design, the one that causes all of us threat modeling people to run around and dance and jump up and down and be so happy and excited because If you have a flaw of insecure design, you're going to have to have a preventative measure of threat modeling.”
Transcript evidence from OWASP Top 10 2021 Peer Review.
“It's important that application encrypts the data before it sends through the network, through the servers, and the backend doesn't have decryption keys.”
Transcript evidence from Anastasiia Voitova -- Encryption is easy, key management is hard.
“The trade-off is to build a system that gives good enough security guarantees, but it's not catastrophic in terms of all these additional layers we need to build to make key management secure.”
Transcript evidence from Anastasiia Voitova -- Encryption is easy, key management is hard.
“We've been stepping through this with some of the other sub-departments, like say the compliance people, they have to do evaluations of a product that we're bringing in, like, well, let's threat model that.”
Transcript evidence from Mark Loveless -- Threat modeling in a DevSecOps environment..
“Now it's mostly been engineering-led because we're trying to make sure that they are trained in the right fashion for doing the threat models themselves.”
Transcript evidence from Jeevan Singh -- Threat modeling based in democracy.
“One of the big things that I did as an architect was, frankly, trying to document and capture the tech debt that we had for particular systems and start to pick those off, even so far as working with the business to try to allocate some time every single sprint to work on the technical debt.”
Transcript evidence from Dustin Lehr -- Advocating and being on the side of developers.
“I would say that, let's, call to action would be work hard, make sure that you are being an advocate for your developers and you're evaluating tools, that are going to work best for them.”
Transcript evidence from Dustin Lehr -- Advocating and being on the side of developers.
“The people who have to have the basic learning and understanding of what threat modeling is, what it represents, and what it can give you, must be the developer.”
Transcript evidence from Izar Tarandach and Matt Coles-- Threat Modeling: A Practical Guide for Development Teams.
“The key is how you approach it. Because again, you still got to face the problem, but do you want to face it in a negative attitude or do you want to keep it in a positive light? That's the choice that you control.”
Transcript evidence from Charles Shirer -- The most positive person in security.
“If you're feeling burned out, take a break. It could be your favorite television show. Take like 30 minutes if you need to, or if you want to go see something outside, take a walk outside, but fixate your mind on something that you enjoy for like, for like 30 minutes.”
Transcript evidence from Charles Shirer -- The most positive person in security.
Keep building skills instead of comparing yourself
Said by Charles Shirer ·
“I may not do— I may not be able to do what you can do right now, but I guarantee you, if I, if I stick around and keep working at it, I will get there.”
Transcript evidence from Charles Shirer -- The most positive person in security.
“Even if it's taking the first step of asking the question. That's a step towards the right direction. Hey, how do I do this? I guarantee you, there's someone out there that's willing to help you.”
Transcript evidence from Charles Shirer -- The most positive person in security.
“If security is bought into what engineering is doing and understands how engineers build stuff, when you as a security person are reviewing something or providing feedback, you're gonna be much more likely to be able to provide feedback that makes sense.”
Transcript evidence from Leif Dreizler -- Tactical tips to shift engineering right.
“That naturally makes security something that you need to invest in more heavily because otherwise, your big customers are going to be like, we don't trust you, so we're not going to give you millions of dollars.”
Transcript evidence from Leif Dreizler -- Tactical tips to shift engineering right.
“The first thing I did was made a list of different projects which are part of OWA's flagship projects, lab projects, and then picked up from the incubator projects which are active at the moment.”
Transcript evidence from Vandana Verma -- OWASP Spotlight Series.
“DevOps is about a culture where everybody has a shared responsibility for ensuring that the software that gets deployed is stable, it's deployed efficiently, and it's secure.”
Transcript evidence from Alyssa Miller -- Bringing security to DevOps and the CI/CD pipeline.
Use managed identity services instead of building auth
Said by Liran Tal ·
“You offload it to Okta, Auth0, whatever, all of those things that help you do it because you understand they have solved the problem and you need to get your app working in that function.”
Transcript evidence from Liran Tal — Cloud native application security, what’s a developer to do?.
“Work with the team to get the pipeline set up to the point where you've got the security tools you need to gain the assurance about the build, so then you can move at DevOps speed.”
Transcript evidence from Chris Romeo — DevSecOps Fails.
“The answer to your question is the one aspect of a software security transformation that's often ignored— there's people involved and people have to change behavior, and those softer skills in terms of behavior change are essential to any software security program success.”
Transcript evidence from Jim Routh — Secure software pipelines.
“If you're highly skilled as a software developer, you have to learn additive skills to configure the packaging of the build, where all of that is provided for you in the on-prem world.”
Transcript evidence from Jim Routh — Secure software pipelines.
Assess the maintenance and security of dependencies
Said by Speaker not identified ·
“If we are serious about supply chain, which is in the news and an issue for all kinds of reasons related to telecommunications and other things, we need to start to understand the quality and the maintenance histories of what we're using and whether those things are defective or whether they're vulnerable or whether they're actively maintained.”
Transcript evidence from JC Herz and Steve Springett — SBOMs and software supply chain assurance.
“Without the full SBOM, and we're looking for that full, not only my direct dependencies, but my, all of my transitive dependencies and all of my runtime and environmental dependencies as well.”
Transcript evidence from JC Herz and Steve Springett — SBOMs and software supply chain assurance.
“At the highest levels, when we threat model, we ask 4 key questions. 1, what are we working on? 2, what can go wrong? 3, what are we going to do about it? And 4, did we do a good enough job?”
Transcript evidence from The Threat Modeling Manifesto – Part 2.
“We wanted to have the Threat Modeling Manifesto be something that could be printed on a poster, a one-page poster, and hung up on the wall inside of a company somewhere, because here's what we're gonna drive towards as we're doing threat modeling.”
Transcript evidence from The Threat Modeling Manifesto – Part 2.
“Threat modeling must align with an organization's development practices and follow design changes in iterations that are each scoped to manageable portions of the system.”
Transcript evidence from The Threat Modeling Manifesto – Part 2.
“If some of those applications are not using frameworks, probably you should put them on top of your list, and you should have monitoring or protections on top of that.”
Transcript evidence from Aviat Jean-Baptiste — The AppSec report.
“I think having a data-driven decision model to help a given team implement CI, to put more runtime protections on your applications, to build your security strategy JB, thanks for taking the time to share this report with us and explain many of the different pieces of the report.”
Transcript evidence from Aviat Jean-Baptiste — The AppSec report.
“I had a basic understanding that you should obviously, like, your cloud environment should be secured, you should have the lowest possible permissions everywhere, you don't store your keys where they can be grasped, don't put them in code.”
Transcript evidence from Dmitry Sotnikov – REST API Security – there is no silver bullet.
“I think number one thing is to make sure that all the APIs that get spun up are controlled, whatever you have, your CI/CD process or some other process that would discover all the APIs and you have a good grasp of the APIs that you have.”
Transcript evidence from Dmitry Sotnikov – REST API Security – there is no silver bullet.
“Then, not only might you incorporate some automated testing into a regression test to try and eliminate that from coming up in future iterations, but putting a step earlier in the process to try and prevent it from being created in the first place.”
Transcript evidence from Caroline Wong — The state of Penetration Testing.
“One of them, which we talked about a little bit, but I want to go into a nuance of it, is that identifying a vulnerability is not the same as assessing the risk that it presents.”
Transcript evidence from Caroline Wong — The state of Penetration Testing.
“The best part is if the security guarantees, espousing LavaMoat provides, even if there was a flaw found that tears away all the security, you're back to where you are today.”
Transcript evidence from Aaron Davis — LavaMoat — solving JavaScript software supply chain.
“Once you've disabled that, on your build server or on your personal development machine, then you want to move on to moving your builds, your build server, or a server if you're running Node stuff, in Lava Mode Node.”
Transcript evidence from Aaron Davis — LavaMoat — solving JavaScript software supply chain.
“What those potential product managers don't know is about technical data, which needs to be protected. All these accesses, keys, logs, all the things, right?”
Transcript evidence from Anastasiia Voitova — Use Cryptography; Don’t Learn It.
“Key generation, key rotation, key revocation, key expiration, key sharing. All these things you kinda need to think about in your system and build in from day zero Or at least think about it, how you will handle it.”
Transcript evidence from Anastasiia Voitova — Use Cryptography; Don’t Learn It.
“First of all, I would say that take a look on this native platform libraries available for your language or for your technical stack and look on which ciphers this library provides. And if it provides old ciphers, that's like a question mark, right?”
Transcript evidence from Anastasiia Voitova — Use Cryptography; Don’t Learn It.
Prefer cryptographic tools that are hard to misuse
Said by Anastasiia Voitova ·
“I would say try to use boring tools, right? Instead of spending time on learning cryptography or figuring out how to use, like, how to do your things with normal, I don't know, cryptographic tools, or like usual, better spend this time trying to find the boring tool because this will save your time later during implementation, during testing, or even save you from security mistakes and potential vulnerabilities.”
Transcript evidence from Anastasiia Voitova — Use Cryptography; Don’t Learn It.
“I would ensure that you are dialed in with the providers of your infrastructure and that, if there is a vulnerability that exists in one of those things, you are taking advantage of the information feeds that those companies provide.”
Transcript evidence from Chris Romeo — The State of Security and the Importance of Empathy.
“Its primary purpose is to govern what resources can load on a given page or what content can execute in the context of a given page load inside of a browser.”
Transcript evidence from Neil Matatall — Content Security Policy.
“If this is— and this is a true story— one of the first ones I did had one page that had a WYSIWYG editor that needed unsafe-inline and unsafe-eval, but enabling that for the entire application was wrong because it didn't need that anywhere else.”
Transcript evidence from Neil Matatall — Content Security Policy.
Keep this very quiet, close— closely held until the solution was out there so that we could…
Said by Graham Holmes ·
“My role was to, during this transition period of building these things secretly, was to compel developers to make changes in their code base that they didn't understand why we were doing it and what the outcome was and convince them that we need to keep this very quiet, close— closely held until the solution was out there so that we could then announce to our customers what we had done to mitigate the problem.”
Transcript evidence from Graham Holmes — Adversarial Machine Learning.
Start with a data training set, say, you know, here's how to classify good data and here's how…
Said by Graham Holmes ·
“As the machine learning system is trained, that's— you have to start with a data training set, say, here's how to classify good data and here's how to classify bad data.”
Transcript evidence from Graham Holmes — Adversarial Machine Learning.
Think about business systems that you might have in your network that require a lot of…
Said by Graham Holmes ·
“Think about business systems that you might have in your network that require a lot of interaction with humans to look at the data, to take an action, and to make a decision.”
Transcript evidence from Graham Holmes — Adversarial Machine Learning.
“We have to build from scratch, simply for not for billing reasons, but to understand, to understand the risks and the complications in an AWS environment.”
Transcript evidence from Ochaun Marshall — Securing Web applications in AWS.
“I think the use case that we've been using internally is either as a pre-commit hook, which has worked quite well, or a GitHub Action, or a CircleCI, where you're like, hey, as long as it finishes in less than 3 or 4 minutes, totally fine.”
Transcript evidence from Drew Dennison – Security should make the computer sweat more.
Show developers only findings introduced by their change
Said by Drew Dennison ·
“It is going to show you the findings that are in that 15 lines of code or whatever you submitted as part of that pull request, which I think is nice because then you're like, oh, yeah, or I disagree with the tool and I want to archive it and be like, add that to the whitelist file.”
Transcript evidence from Drew Dennison – Security should make the computer sweat more.
Inventory authorization coverage across repositories
Said by Drew Dennison ·
“Show me across all my codebases, what are the routes that have any authorization, or more interestingly, which ones don't have any authorization at all?”
Transcript evidence from Drew Dennison – Security should make the computer sweat more.
“Let the computer do that work, find the hotspots, and then, you tell the developer directly, you send a Slack notification or open a Jira issue to the security team, and then they're going to go through and apply their intelligence.”
Transcript evidence from Drew Dennison – Security should make the computer sweat more.
“2 is if you want to statically analyze the firmware, you can download the Raspberry Pi, use something like binwalk to extract the firmware file system, And from there analyze the file system contents for vulnerabilities, look at the configurations, check for, any web pages that let's say aren't”
“One way would be to download the VirtualBox or virtual VMware version of the image, run that, set up a virtual machine on my computer, start it, and then effectively that virtual machine is emulating what an IoT device would look like. if it was sitting on the network.”
“IoT Goat is one tool or platform to accomplish that goal, in addition to, the test— the firmware security testing guide and the Security Verification Center we're working on.”
“If I don't have the building block of I'm going to draw the system in some way, or even I'm going to draw the system with a data flow diagram, then what can happen is different people have different mental models of the system.”
Transcript evidence from Adam Shostack — The Jenga View of Threat Modeling.
Define responsibilities and support for the rollout
Said by Adam Shostack ·
“There's roles and responsibilities, right? Who does what? Okay, so I'm raising my hand here. I'm a software engineer working on the mobile app. What does it mean for me to do my job once we've made this change to the way we deliver things? What exactly am I supposed to deliver Who do I deliver it to? What does goodness look like? How do I get help?”
Transcript evidence from Adam Shostack — The Jenga View of Threat Modeling.
“In fact, we've had DevOps groups that have gone off and purchased GitLab, including our— and used our security capabilities and said, okay, now we're going to unplug Fortify.”
Transcript evidence from Cindy Blake — Aligning security testing with Agile development.
“But you don't often— the day-to-day pictures that you want to capture is part of your living experience and you want to share it with your friends and family, you don't use a camera for that anymore because it's not integrated.”
Transcript evidence from Cindy Blake — Aligning security testing with Agile development.
“, if you're a company who is using Multijuicer and I don't know about yet, we should start something like a, like a section in the README of companies who are already using it and can provide some feedback on how they're using it.”
Transcript evidence from Jannik Hollenbach — Multijuicer: JuiceShop with a side of Kubernetes.
“First of all, I think from a content perspective, I think it's, it's important that we are in line with modern development practices in an organization.”
Transcript evidence from Sebastien Deleersnyder and Bart De Win — OWASP SAMM.
“If you think about what a CISO— the breadth of what a CISO needs to understand, you've got to start positioning yourself and put a plan together to say, all right, I'm in this space.”
Transcript evidence from Marc French, Steve Lipner, Maya Kaczorowski, DJ Schleen, Kim Wuyts — Season Six Wrap up.
“If we know how long average time it takes to remediate cross-site scripting, then we have a much better way of knowing what we can expect when we come across these kinds of vulnerabilities.”
Transcript evidence from Mark Merkow — Secure, Resilient, and Agile Software Development.
“I think the takeaway there for our listeners that might be trying to do this is, it will be wise of you to have a template/sample threat model like Adam had here as a place to start.”
Transcript evidence from Adam Shostack — Remote Threat Modeling.
“I think the thing to think about as your listeners are asking, what tool do I want, is do I want a drawing tool like Miro that allows me to create these diagrams, get consensus around what we're working on, where the trust boundaries are, how it's put together, what the components are so that we can be”
Transcript evidence from Adam Shostack — Remote Threat Modeling.
“But secondly, working remotely, of course, you need to make sure you have good remote tools in place, whether that be tools that, like we've been looking at here, that naturally allow good collaboration inside the tool, or you use other video screen sharing tools that allows multiple folks to see a screen or see”
Transcript evidence from Adam Shostack — Remote Threat Modeling.
Use one data-flow diagram for security and privacy
Said by Kim Wuyts ·
“We have the data flow diagram for which you make a mapping table for each of the landing categories and then you systematically go over each of the cells of the table and look at the Linden knowledge, Linden threat trees, to determine whether for that specific DFD element, a privacy threat occurs.”
Transcript evidence from Kim Wuyts — Privacy Threat Modeling.
“The logical extension of that is leading different organizations, leading different companies to build software smarter, better, and faster, including securing it better, including building software right the first time.”
Transcript evidence from John Martin — Preventing a Cyberpocalypse.
“I think if I had to solve this problem and I only had 1 or 2 minutes to describe my explanation, which I'm sure we'd have weeks, if not months, to formulate this, but I'm almost thinking about the secure development lifecycle as your building code.”
Transcript evidence from John Martin — Preventing a Cyberpocalypse.
Use automated pull requests for dependency updates
Said by Jeremy Long ·
“But, what Dependabot does is if a new version of a library comes out, you get a pull request, your CI kicks off, light is green, you can merge the pull request.”
Transcript evidence from Jeremy Long — It’s dependency check, not checker.
“He's built some tools to do, sandboxing of your build system, sandbox your, your Jenkins and monitor what files have changed, monitor what URLs people have been connecting out to.”
Transcript evidence from Jeremy Long — It’s dependency check, not checker.
“But if you plan out your implementation correctly, when you're putting this into your pipeline, don't throw the data directory away or use an internal— we support internal, databases.”
Transcript evidence from Jeremy Long — It’s dependency check, not checker.
“If you build your threat model as part of documenting your user story before it goes into the backlog, now you don't have to worry about slowing down the development cycle anymore.”
Transcript evidence from Alyssa Miller — Experiences with DevOps + Automation and beyond.
Ask about critical data and functions in each user story
Said by Alyssa Miller ·
“Initially, you can simplify it literally to a couple of simple questions about what critical data Is there any critical data being collected as a part of this? Is there critical functionality?”
Transcript evidence from Alyssa Miller — Experiences with DevOps + Automation and beyond.
“You have to continuously be trying to improve your processes, continuously deploying updates to that process that introduce those improvements so that not only is your end product getting better, but the way that you're developing it is getting better, which of course then feeds into the end product getting better.”
Transcript evidence from Alyssa Miller — Experiences with DevOps + Automation and beyond.
“It's got to be something carefully planned that you're looking at over— my recommendation honestly is planning it out over at least a 3-year period where you're taking it in bite-sized chunks.”
Transcript evidence from Alyssa Miller — Experiences with DevOps + Automation and beyond.
“Automate the exception creation and the remediation plan and have this load lifted off of the developers and off the GRC, the other folks in the security organization.”
Transcript evidence from DJ Schleen — DevOps: The Sec is Silent.
“Instead of SSHing in and making a change, you patch You apply a patch to an existing application, you rebuild that as a new image, and you roll out that image.”
Transcript evidence from Maya Kaczorowski — Container and Orchestration Security.
“Setting up role-based access control, setting up network policies, namespaces, etc., for them to work in your environment are some of the decisions you have to make on the first day.”
Transcript evidence from Maya Kaczorowski — Container and Orchestration Security.
“If you think of it, the most basic form is that you want to have security introspection at each stage of the development and release journey, as it were.”
Transcript evidence from Geoff Hill — AppSec, DevSecOps, and Diplomacy.
“The security champion is going to help you during these activities because the security champion will bring forth, will be leading the charge there, and will have a knowledge of what the security backlog is and will have knowledge of what the current threat model looks like and introduce that to the team and will help the team to t-shirt size any issues that come along that have a whiff of security to them.”
Transcript evidence from Geoff Hill — AppSec, DevSecOps, and Diplomacy.
“The security person should be up front and center and figuring out the security attributes of each one of those epics and/or business requirements and attaching them as part of the story or attachment as part of the epic, because then they will float down and they will make the life of the security champion a lot easier when they go through because they will see this metadata there and they will say, oh, well, the SME has already looked over this, and has figured this out that there's going to be a huge element of access control here.”
Transcript evidence from Geoff Hill — AppSec, DevSecOps, and Diplomacy.
“A lot of users, a lot of developers, and even architects are not aware of the problems, and you cannot fix anything or remediate anything until you're aware of the situation.”
Transcript evidence from Erez Yalon — The OWASP API Security Project.
“If you used to have a version 1 or version 2 of the API and now you move to version 3, please make sure that version 1 and 2 are either monitored or deprecated because if they are still exposed, it might be very risky, especially if you combine them and they are undocumented.”
Transcript evidence from Erez Yalon — The OWASP API Security Project.
“Start with the basics, make sure you have a security response process, and that you are capable of dealing with discovered vulnerabilities in the software you ship.”
Transcript evidence from Steve Lipner — The Past, Present, and Future of SDL.
“Managing third-party components for security so that if there's a vulnerability discovered in some component you're using, about it and you're able to respond to it.”
Transcript evidence from Steve Lipner — The Past, Present, and Future of SDL.
“Take the tools and take the steps that are part, that have to be done, and then overlay them so they're integrated into the way that the developers do development.”
Transcript evidence from Steve Lipner — The Past, Present, and Future of SDL.
“You first of all have to create partnerships with the development teams in order to fully understand what's being required of them, what are the details they're being asked to do.”
Transcript evidence from David Kosorok — The Three Pillars of an AppSec Program: Prevent, Detect, and React.
“Using this benevolent society, that means that we're all working together to create something that is much better than we could have done individually.”
Transcript evidence from David Kosorok — The Three Pillars of an AppSec Program: Prevent, Detect, and React.
“He had an interesting point about automation here in that he says, common in DevOps is a myth that everything, including all security, can be automated.”
Transcript evidence from Chris and Robert: A Taste of Hi-5.
“When any interactions that we're able to have, we should all be looking for those opportunities to say, Hey, how can we help educate each other about things that we may not have as much perspective on?”
Transcript evidence from Chris and Robert: A Taste of Hi-5.
“I think it, what you said, points to If you ran a bounty program before you even started all the other stuff that you need to start, and somebody found some extreme issues, what are you going to do then?”
Transcript evidence from Chris and Robert: A Taste of Hi-5.
“That then, as you start digging into, yes, we need this, and yes, we have controls, you can then as a modeler say, I'm not sure those controls are sufficient.”
Transcript evidence from Bill Dougherty — INCLUDES NO DIRT, practical threat modeling for healthcare and beyond.
“I'd create a diagram that shows a user with a browser on their laptop and they're connecting to a web interface with a backend, and then there's an administrative interface for the, the legal person to go evaluate it, and there's trust boundaries, there's firewalls and things, and then I'd start looking at,”
Transcript evidence from Bill Dougherty — INCLUDES NO DIRT, practical threat modeling for healthcare and beyond.
“People have been telling me all sorts of wonderful little stories of like, now I have 2 mentors, or, this person introduced me to someone important and then I ended up getting a job because of it, or I'm reading all these books thanks to the people you introduced me to.”
Transcript evidence from Season 5 Finale — A cross section of #AppSec.
“You can't start it by having some exec saying, now we're going to have secure software and writing a bunch of policies and handing them to everybody and saying, see, now we're secure.”
Transcript evidence from Season 5 Finale — A cross section of #AppSec.
“You can't start it by having some exec saying, now we're going to have secure software, and writing a bunch of policies and handing them to everybody and saying, see, now we're secure.”
Transcript evidence from Brook Schoenfield — Security is a messy problem.
“If you reduce to start off, your baseline is your suite of high confidence checkers, and you hand those to developers— I've done this a bunch of times now and it works— hand those to developers and say, here, especially if you can get that on their desktop so while they're coding they can check, then you're using the tool in the way the developer wants to see, like a compiler.”
Transcript evidence from Brook Schoenfield — Security is a messy problem.
Choose vendors by supply-chain capabilities and roadmap
Said by Steve Springett ·
“You need to choose that vendor, that solution that you're going to partner with that knows supply chain and has a roadmap item to address all your capability concerns.”
Transcript evidence from Steve Springett — An insiders checklist for Software Composition Analysis.
“If you have tens of thousands of applications in your environment and you are producing software bill of materials in a CI/CD pipeline, DependencyTrack can automatically ingest, automatically analyze, and automatically alert you of any vulnerability or other types of risk.”
Transcript evidence from Steve Springett — OWASP Dependency Track — 5 Minute AppSec.
“In some cases, they're almost certainly vulnerabilities, but in all cases, you need a developer to look at the error messages that are generated and determine if a fix is necessary.”
Transcript evidence from Elissa Shevinsky — Static Analysis early and often.
“One thing that I've been encouraging is for people who are junior developers to learn static analysis, because that's a space that I know, but there's probably a lot of other things like this as a way for them to level up, as a way for them to stand out and become better developers and, like, get interesting jobs.”
Transcript evidence from Elissa Shevinsky — Static Analysis early and often.
“We do think that there is a need for the framework to be universal, to be adaptable to different technologies, different development processes, different coding languages.”
Transcript evidence from Tommy Ross — The BSA Framework for Secure Software.
“Development of software should begin beyond the idea for the software, should begin with an assessment of the potential risks or the potential threats.”
Transcript evidence from Tommy Ross — The BSA Framework for Secure Software.
Use best-practice literature to build your program
Said by Tommy Ross ·
“We began by looking through what we identified as commonly used or widely recognized literature, including best practice literature, NIST publications, internationally recognized standards, OWASP, of course, the Common Weakness Enumerators that we reference throughout the framework.”
Transcript evidence from Tommy Ross — The BSA Framework for Secure Software.
“I'm thinking about threats that provoke people. I'm thinking about things that happen at that human layer and how we engineer to maximize the value and minimize the problems.”
Transcript evidence from Adam Shostack — Threat modeling layer 8 and conflict modeling.
“When we engineer things, instead of waiting until the system has shipped to figure out what's going to go wrong, We anticipate it in some way and we start to plan for it.”
Transcript evidence from Adam Shostack — Threat modeling layer 8 and conflict modeling.
“My goal is first to catalog, and then when we have catalogs of both the threats and the controls, we can start to build out threat modeling processes, methodologies that help you take this from here's a list of problems to here's the way to think about this as you're building what you're working on.”
Transcript evidence from Adam Shostack — Threat modeling layer 8 and conflict modeling.
“The people building a photo upload and display filter feature need to think about how can that feature be abused in ways that will threaten the human users of the system or act as a threat to other users of the system.”
Transcript evidence from Adam Shostack — Threat modeling layer 8 and conflict modeling.
“This requires collaboration. It requires people from diverse backgrounds, diverse perspectives, different skill sets coming together to figure this out.”
Transcript evidence from Adam Shostack — Threat modeling layer 8 and conflict modeling.
“By using a structured approach to asking what can go wrong, like STRIDE or attack trees or a kill chain, you can systematically go through each of the elements of your system to make sure that you've thought about security. And that can inform the entire remainder of your AppSec program and activities.”
Transcript evidence from Adam Shostack – Threat Modeling – 5 Minute AppSec.
“One of the things that I've tried to learn how to do throughout my career is I've tried to learn how to prioritize and how to get on the same page as my manager with regards to my priorities and how to, understand the linkage between the organization's priorities, the security team's priorities, and”
Transcript evidence from Caroline Wong — Self-care and self-aware for security people.
“I think that one thing that hiring managers can do, and this takes time, valuable time away from all the firefighting that you're doing while you're still trying to keep things running and get some of your projects done, is to think about what are the specific skills and tasks that I need this”
Transcript evidence from Caroline Wong — Self-care and self-aware for security people.
Remove obsolete training challenges instead of faking vulnerabilities
Said by Björn Kimminich ·
“Um, we— I decided to take out that challenge then because, uh, building your way around that and faking the vulnerability, that's nothing that we are so happy doing because then it gets unrealistic and very expensive to maintain at some point.”
Transcript evidence from Björn Kimminich — The new JuiceShop, GSOC, and Open Security Summit.
“You can switch the color theme, you can change the project or the application title, you can change all logos, you can completely rewrite the entire product list to fit whatever business you want to represent.”
Transcript evidence from Björn Kimminich — The new JuiceShop, GSOC, and Open Security Summit.
“As a developer, you want the Juice Shop because I think you can learn almost every existing known security vulnerability in web applications from it, and not in a boring way, but by trying out attacks and practicing.”
Transcript evidence from Björn Kimminich — JuiceShop — 5 minute AppSec.
“That's, that's a little side project that allows you to quickly set up a CTF server in 5 minutes with the Juice Shop challenges with no manual data entry, a simple import feature.”
Transcript evidence from Björn Kimminich — JuiceShop — 5 minute AppSec.
“I encourage people on Mondays or whenever, search the hashtag #MentoringMonday and respond to people, even if it's to suggest like, this is the best book I've ever read on this topic.”
Account for healthcare systems in your threat model
Said by Matt Clapham ·
“Think of the electronic medical records systems or the imaging archive systems, the IT, the operational IT that makes a healthcare delivery organization or a hospital more efficient in providing care.”
Transcript evidence from Matt Clapham — A perspective on appsec from the world of medical software.
“I had heard all the stories about what you need to do in terms of bringing a burner phone, not turning on your phone, certainly not turning on Wi-Fi, Bluetooth, all those kinds of things.”
Transcript evidence from Jon McCoy — Hacker outreach.
“I had heard all the stories about what you need to do in terms of bringing a burner phone, not turning on your phone, certainly not turning on Wi-Fi, Bluetooth, all those kinds of things.”
Transcript evidence from Jon McCoy — Hacker outreach.
“I would suggest to clone it from GitHub and start tweaking it and seeing See if you can come up with a data flow diagram that looks like your system.”
Transcript evidence from Izar Tarandach — Command line threat modeling with pytm.
“I thought even then it would be— wouldn't it be a good idea to have something which would automatically test my software for the most common security vulnerabilities?”
Transcript evidence from Simon Bennetts — OWASP ZAP: past, present, and future.
“Um, I talk about them and then I talk about what skills people need to have and then how to get those skills into your, uh, into your development group, um, and and start isolating folks that might be good candidates to be an AppSec person even though they don't know it themselves.”
Transcript evidence from Bill Sempf — Growing AppSec People and KidzMash.
“I don't have all the answers yet, but it's unquestionable that So the main crux of the lessons that I learned from cultivating an individual in your group is what I've been doing, and I've done it successfully now at 5 different companies, a couple of them big, is you hold a training and instead of giving them”
Transcript evidence from Bill Sempf — Growing AppSec People and KidzMash.
“10 to 15-year-olds and walked them through a couple of capture-the-flag-style challenges in web application security using an OWASP tool called Security Shepherd.”
Transcript evidence from Bill Sempf — Growing AppSec People and KidzMash.
“Mobile app security, but what's being missed, I think, and perhaps is making a resurgence with things like mobile threat defense, is that, it's a whole device.”
Transcript evidence from Georgia Weidman — Mobile, IoT, and Pen Testing.
“We can get into it at some point in the discussion about what some of the differences between security practices like red teaming, purple teaming, and chaos engineering, and there are major differences.”
Transcript evidence from Conclusion: Season 4 Finale.
“What we have is a central repository a set of JavaScript libraries that we're monitoring, where we have a list of vulnerabilities connected to them, and we have some ways of identifying each library and each version.”
Transcript evidence from Conclusion: Season 4 Finale.
“The philosophy around the project overall is help as many people as possible with a single list, with very concise, very clear description of what to avoid.”
Transcript evidence from Conclusion: Season 4 Finale.
“Then if you start building out too many attack trees, then about a month later you find out that things have changed and you have to build a whole new set of attack trees.”
Transcript evidence from Geoff Hill -- Rapid Threat Model Prototyping Process.
“They've spent like a day doing model storming and in sprint zero and they're off to the races and you're already behind the times because you're already telling them, well, guys, you have to put in the mitigation that we described here.”
Transcript evidence from Geoff Hill -- Rapid Threat Model Prototyping Process.
Take into account that every inbound from other systems, whether they're inside the company or…
Said by Geoff Hill ·
“In order to make your system resilient, you have to take into account that every inbound from other systems, whether they're inside the company or not, are potentially inbound attack vectors, and therefore they're outside of your control.”
Transcript evidence from Geoff Hill -- Rapid Threat Model Prototyping Process.
“Some of the things that the cloud helps you do better than you might've had traditional access to is access to a more complete toolset So the uh, I can— I know Azure best, but this would apply to most clouds.”
Transcript evidence from Bill Wilder -- Running Azure Securely.
“Like in the on-prem world, if you have a machine in the cloud, you may want to remotely access it for management and diagnostic reasons, normal stuff.”
Transcript evidence from Bill Wilder -- Running Azure Securely.
“I mentioned before that you need to authenticate to Azure Key Vault in order to access, secrets within it or to use the secrets within it that are— that it won't give you to, like, exercise the use of private key to sign something or to decrypt a value.”
Transcript evidence from Bill Wilder -- Running Azure Securely.
“It's, when you have developers or architects or anybody who is involved in software development start to think about that and start to integrate it in, we always talk about trying to get security in early.”
Transcript evidence from Matt Konda -- OWASP Glue.
“Glue originated when we were working with companies that wanted to do— originally they wanted to do static analysis, on languages that didn't have good coverage in commercial tools, and they wanted them to integrate into their developer's toolset.”
Transcript evidence from Matt Konda -- OWASP Glue.
“But I think one of the One of the main points that I see is that most companies, their primary control at the moment is the application security testing, as in application penetration testing, getting someone to come in and test their applications.”
Transcript evidence from Josh Grossman, Avi Douglen, and Ofer Maor -- AppSec in Israel and Three Talks to watch from AppSec USA.
“What I've had my talk about today is how do we build a way to do test automation, security test automation, as part of this workflow of continuous delivery where we get organizations pushing hundreds of updates every day into production?”
Transcript evidence from Josh Grossman, Avi Douglen, and Ofer Maor -- AppSec in Israel and Three Talks to watch from AppSec USA.
“But I do feel like manufacturers need a different project because I'm looking to launch a number of projects around this, but they will be independent rather than making this one larger.”
Transcript evidence from Daniel Miessler -- OWASP IoT Top 10.
“It's in the OWASP IoT security channel, so people show up, they give feedback, but there was a core of about 10 people and we would go through all that data and we would then use our judgment, right?”
Transcript evidence from Daniel Miessler -- OWASP IoT Top 10.
“As security people, we gotta be more open. We can't be so afraid to share our information and share our experiences with the people that we're working with.”
Transcript evidence from Chris Romeo -- Security Culture Hacking: Disrupting the Security Status Quo.
“You have to, this assessment has to become a strategy, and so I'm gonna share with you 15 different hacks that I've experienced in different companies.”
Transcript evidence from Chris Romeo -- Security Culture Hacking: Disrupting the Security Status Quo.
“We should be protecting our applications against the threats that are 5 or 10 years out because our applications that we're building today are probably going to still be in service in 5 to 10 years.”
Transcript evidence from Jeff Williams -- The History of OWASP.
“I bet you don't know very much about who wrote that code, how they tested it, what tools they used, were the developers trained, what open source components are they using, what other AppSec processes do they use to make sure that thing is secure?”
Transcript evidence from Jeff Williams -- The History of OWASP.
“If they choose to register with their Google account, there's a little bit more technical way to be that, but that's something that managers can understand if you show them because the Juice Shop behaves silly after doing a proper OAuth 2 authentication with Google.”
Transcript evidence from Bjorn Kimminich -- The Joy of the Vulnerable Web: JuiceShop.
“But what we did, which is the real benefit coming from our side, we created a little side project which is a command line tool which you run and then you answer a couple of questions like, hey, what CTF framework do you want to use?”
Transcript evidence from Bjorn Kimminich -- The Joy of the Vulnerable Web: JuiceShop.
“I'm not— because I think if the developers should learn how the vulnerabilities work, they should concentrate on that and use tools they know and not try to learn tools at the same time.”
Transcript evidence from Bjorn Kimminich -- The Joy of the Vulnerable Web: JuiceShop.
“We have some organizations that are dipping their toes into working with the external hacking community And they'll start their program in what's called private mode.”
Transcript evidence from Adam Bacchus and Jon Bottarini -- Two Sides to a Bug Bounty: The Researcher and The Program.
“In additional to— or excuse me, in addition to the tactical benefit of finding and squashing those individual bugs, you can perform some root cause analysis of the bugs flowing through your program and identify and implement systematic improvements to your overall security posture.”
Transcript evidence from Adam Bacchus and Jon Bottarini -- Two Sides to a Bug Bounty: The Researcher and The Program.
“If you want to learn how to perform a cross-site scripting attack, Going through the training modules on that site will give you all the information that you need to know, and then you can take that information and apply it to the different types of bug bounties on the platform.”
Transcript evidence from Adam Bacchus and Jon Bottarini -- Two Sides to a Bug Bounty: The Researcher and The Program.
“On the DevOps side, I do believe that if you provide a way to capture this information in an easy, more code-like way with YAML, especially YAML being a very popular way of doing things with most DevOps implementations, I felt that it would become a lot more user-friendly for an engineering team or a DevOps team to”
Transcript evidence from Abhay Bhargav -- Threat Modeling as Code.
“The tools we'll be using in this workshop are going to be OWASP ZAP, which is my number one favorite for testing applications, and it's probably got the best API in the business.”
Transcript evidence from Abhay Bhargav -- Threat Modeling as Code.
“Uh, so I'll lead it with, uh, if you go to principlesofchaos.org, it's the marquee seminal, uh, doctrine when it comes to chaos engineering that everyone sticks to.”
Transcript evidence from Aaron Rinehart -- Chaos Engineering and #AppSec.
“What Chaos Monkey does is during business hours, that's a key part, during business hours, it will, it will randomly bring down a VM on one of Netflix's production systems.”
Transcript evidence from Aaron Rinehart -- Chaos Engineering and #AppSec.
“That's what the focus is of chaos engineering, is to sit down with your product team, your app team, and say, okay, hey, we think we're seeing these failures happening.”
Transcript evidence from Aaron Rinehart -- Chaos Engineering and #AppSec.
“The next thing that I would say is that as much as possible, start— get— because we do have monthly meetings, there should be a representative from your chapter on these monthly calls.”
Transcript evidence from Jessica Robinson and Vandana Verma-- WIA: Women in #AppSec.
“The other thing is because men many times at conferences are leading these conferences, they're the presidents of the chapter, there's more men on boards even here at OWASP, that when we have conferences like this and we're thinking, okay, we want to have speakers, how can we make sure that we have women speakers?”
Transcript evidence from Jessica Robinson and Vandana Verma-- WIA: Women in #AppSec.
“If you're, if you're involved and you're someone who uses OWASP and attends chapter meetings and does those type of things and you're not a member, you should consider because 40% of the membership goes to the local chapter.”
Transcript evidence from Karen Staley -- A Conversation with Karen.
Run security checks in the IDE and after integration
Said by Ofer Maor ·
“We need to get as much as we can early on in the IDE, but we need to do things that can happen later in the build as you integrate all the pieces together.”
Transcript evidence from Ofer Maor -- A Pen Testers Transition to #AppSec: #VoteForOfer.
“Now it allowed me to have sane conversations about resource allocation on my team because, everyone's agile and things are switching around quickly and you have to shift work, but I didn't understand the cost of that shifting until I had it managed with something like DefectDojo.”
Transcript evidence from Matt Tesauro -- #AppSec Pipeline as Toolbox.
“It's— fundamentally, it's a way to — well, the best use of it in my mind is to have an automated way to do baseline testing across the suite of applications that your program has.”
Transcript evidence from Matt Tesauro -- #AppSec Pipeline as Toolbox.
“Then the final phase is what we call delivery, and that's putting stuff into a vulnerability repository like DefectDojo and then pushing out metrics and reports and bugs into bug trackers.”
Transcript evidence from Matt Tesauro -- #AppSec Pipeline as Toolbox.
“If you have X number of security engineers in your team, make sure they are embedded with product teams, that they are part of these engineering discussions very early on so that they can advocate for specific security controls.”
Transcript evidence from Julien Vehent -- Securing DevOps.
“They are very tactical items, very short documents that we put in GitHub issues as markdown with checkboxes and whatnot, and developers and operators can go through them very quickly and make sure they're compliant with our security principles.”
Transcript evidence from Julien Vehent -- Securing DevOps.
Automate repeatable checks and retain manual testing
Said by Julien Vehent ·
“To me, the real value of security in DevOps is automating everything that can be automated, the low-hanging fruits, so you can free up time to go manually test or implement the complex stuff.”
Transcript evidence from Julien Vehent -- Securing DevOps.
“You make it repeatable. You take those tests, you script them, you automate them. Some of it is not scriptable at all, but a lot of it is, so that even if your engineers rotate, you have a turnover, then your tests continue to run the same way.”
Transcript evidence from Julien Vehent -- Securing DevOps.
“What you want to do is add a new test. every time you do a loop over this cycle and make sure that everything goes green so you can flag it for regression if it ever goes back to red.”
Transcript evidence from Julien Vehent -- Securing DevOps.
“We need to get closer to the developers and the toolset is all there, the toolchain is there, it's open source, you can very easily integrate it into your process in your company, how you do how you do software.”
Transcript evidence from Christian Folini -- CRS and an Abstraction Layer.
“Think small businesses who do not, who do not have the technical expertise I can see that argument, but at the same time, there's a lot been done over the years to make HTTPS simple.”
Transcript evidence from Sean Wright -- Google Chrome and the Case of the Disappearing HTTP.
“When I think of usable security, usable security should be built in and it should be— you should have to make an active decision to disable it, and it should ultimately make the world a better place.”
Transcript evidence from Sean Wright -- Google Chrome and the Case of the Disappearing HTTP.
“When we build requirements, we have to, we have to have security in the conversation so we're building good security requirements so that we can build good design, so that now we can take the design and implement it correctly in software and then code.”
Transcript evidence from Conclusion: All the Pieces You Need for an #AppSec Program.
“If you're not constantly updating your code to use new and newer versions of those components as a best practice, it's very hard for organizations to respond when they absolutely have to do a 24-hour turnaround to mitigate something.”
Transcript evidence from Conclusion: All the Pieces You Need for an #AppSec Program.
Show developers how OWASP tools fit their delivery practices
Said by Martin Knobloch ·
“When you tell them what is there, how you can use it, how you can use it in your environment, be it DevOps, DevSecOps, continuous delivery, continuous integration”
Transcript evidence from Martin Knobloch -- OWASP, Reach Out; We Are Known and Misunderstood.
“Go have a strong sense of empathy towards the other people you're working with, the security researchers and hackers, and try to understand your business engagement with them from their point of view.”
Transcript evidence from Devin McMasters -- Bug Bounty with a Side of Empathy.
“It allows business owners who don't know how to write code to write these user stories and use cases and then hand that off to the security team and say, okay, here's what we want to test for.”
Transcript evidence from Apollo Clark -- Malicious User Stories.
“Anyway, a potential attacker that would be set up in a man-in-the-middle position during a firmware update would be able to unpack that firmware, make modifications, add their own password hash, or turn on SSH, etc., and then, repackage that firmware and then make sure that it got down to you.”
Transcript evidence from Chase Schultz -- AppSec and Hardware.
“It being able to access the kernel space and, being able to read out the entire— the entirety of the kernel space where, you might have very sensitive cryptographic operations like you said, that thing.”
Transcript evidence from Chase Schultz -- AppSec and Hardware.
“People should start looking at using safe components, using the latest version of these components, using components that have a low number of vulnerabilities.”
Transcript evidence from David Habusha -- Third Party Software is not a Cathedral, It’s a Bazaar.
“Once you build on top of existing components, those vulnerabilities, those properties of those components become an inherent property of the overall application.”
Transcript evidence from Steve Springett -- Dependency Check and Dependency Track.
“If you're not constantly updating your code to use new and newer versions of those components as a best practice, it's very hard for organizations to respond when they absolutely have to do a 24-hour turnaround to mitigate something.”
Transcript evidence from Steve Springett -- Dependency Check and Dependency Track.
“If you do try to do a forklift-style upgrade where you're taking an old version of software that is vulnerable and replacing it with a more modern version, it's going to break all the API connections and other things that were happening there.”
Transcript evidence from Steve Springett -- Dependency Check and Dependency Track.
“If you were to create some very good threat models on that, then an organization that is new to threat modeling could take the reference threat model, see how their applications differ from that one, and then you need to do the threat modeling on the small differences.”
Transcript evidence from Steven Wierckx -- The #OWASP Threat Modeling Project.
“With all the cheat sheets and all the different topics, and of course over the years, I imagine some of them you have to keep them up to date, right?”
Transcript evidence from Jim Manico -- The #OWASP Cheat Sheet Project.
“If you're a security professional and/or you're a developer who's new to security and you somehow at this stage don't have a good grasp of DevOps, this is a real nice book to take you through what is DevOps.”
Transcript evidence from Chris and Robert -- #AppSec Recommendations.
“In my experience, that's something that I've, I've dealt with this burnout thing in the last, I don't know, in the last 6 months or so, leading right up until the first of this year.”
Transcript evidence from Magen Wu -- Hustle and Flow: Dealing With Burnout in Security.
“When it comes to JSON, the other thing that I usually say is to use to manipulate JSON objects to use a well-known library that hasn't any known vulnerabilities.”
Transcript evidence from Katy Anton -- OWASP Top 10 #4 XXE.
“You're gonna find a lot of stuff that you're not gonna like, and the fact that you found it is good, and you're gonna need to find some way to get after it.”
Transcript evidence from Pete Chestna -- SAST, DAST, and IAST. Oh My!.
“That's a interesting question, and I'm going to double back for a minute to a little bit more, a little bit, one other piece of my analysis is all the other weird deserialization pieces that I ran into.”
Transcript evidence from Bill Sempf -- Insecure Deserialization.
“It's even worse on the data deserialization side because, man, we've got so much old code out there that's dependent on the developers encoding a dataset in.NET and tossing it in a cookie or tossing it in a hidden input.”
Transcript evidence from Bill Sempf -- Insecure Deserialization.
“I guess the last part, what we wanted to enlighten our listeners on is if somebody happens to be listening here and they're thinking, hey, I want to set up a security champion program, where do they start?”
Transcript evidence from Chris and Robert -- Security Champions.
“Well, first of all, shifting left, in industries, you have to be somewhat think about things in a realistic way because a lot of buzzwords, a lot of different jargons are always thrown around and people don't quite understand it.”
Transcript evidence from Kevin Greene -- Shifting left.
“That's the whole notion of using CAPEC and ATT&CK to build good, misuse cases to see, to see if whatever is being offered up can be abused in a way that compromises security before it's designed, right?”
Transcript evidence from Kevin Greene -- Shifting left.
“The Threat Dragon approach is to boil that down to the fundamentals, so you have the straightforward types of elements, not enriched in any particular way, so it's simple to get you drawing your diagrams out, understanding the data flows quickly without having to try and figure out, well,”
Transcript evidence from Conclusion: OWASP is for everyone.
“But we want to make them more, like, app-focused things where it's, like, these little apps that you can test on, like, understand, all right, this is an HTTP/2.0 app.”
Transcript evidence from Conclusion: OWASP is for everyone.
“I learned quite a bit about containers that I didn't realize, and I'm going to go start telling anyone in the IoT space, Brian said you should look at this maturity model and you should build your software in containers so that it's signed and don't make it run as root and control your system calls.”
Transcript evidence from Brian Andrzejewski -- Containers Again.
“You've got like different things— hardware, embedded devices, radio communication, mobile app, web dashboard, all of that. So not a single developer can focus on all of those particular areas, right? So you have different teams working on different things, and if they don't coordinate properly, you'll end up having issues between the communication of 2 components.”
Transcript evidence from Aditya Gupta -- The Exploitation of IoT.
Design for secure firmware updates and credential changes
Said by Chris Romeo ·
“That is one of the things that comes in the design process, like how much flexibility do we have to give to the users in order to have them control the, the firmware upgrades or change the default creds on the device or those things.”
Transcript evidence from Aditya Gupta -- The Exploitation of IoT.
“We're going to be working in GitHub, so anyone who's truly interested in following us for whatever reason, like day by day, they can follow us at GitHub and see where we're at.”
Transcript evidence from Andrew van der Stock and Brian Glas -- The Future of the OWASP Top 10.
“Because essentially it's an awareness document, and it's treated as a baseline. It's that starting point, and we can't emphasize that enough. This is a starting point.”
Transcript evidence from Andrew van der Stock and Brian Glas -- The Future of the OWASP Top 10.
“The next thing along the lines of container breakout is, and this one's probably the absolute most important, is you have to use an unprivileged container.”
Transcript evidence from Jay Beale -- Docker Security and AppSec.
Start realizing, well, wait, am I also using a package manager for my web app framework, for…
Said by Jay Beale ·
“Even when you've got a package manager for the container, you have to start realizing, well, wait, am I using a package manager for my web app framework, for Ruby on Rails, or my package manager for Python, or my package manager, npm for JavaScript, and trying to track all of those?”
Transcript evidence from Jay Beale -- Docker Security and AppSec.
“Um, as I'm scanning down the list of the changes here and looking at the document, and so folks know, the Proactive Controls, they're making this update as a public Google Doc that anybody can add comments to and anybody can suggest changes to in real time.”
Transcript evidence from Chris and Robert -- Proactive Controls, AppSec USA, and Gartners MQ on AppSec Testing.
“Certainly, I went to one session, it was called Day Zero, which was all about— and that was the eve before Black Hat started— and that was all about trying to help people who are new to Black Hat, help them understand the history.”
Transcript evidence from Robert Hurlbut -- Blackhat Security Conference.
“It's a minimum set of hygiene that every team should think about as they're either working on a new development project or some added functionality to an existing product.”
Transcript evidence from Dave Ferguson -- The OWASP Top 10 Proactive Controls.
“The devil's in the details though because encoding the data is not as simple as it seems because sometimes you have to use HTML encoding, sometimes you have to use HTML attribute encoding, sometimes you have to use JavaScript escaping.”
Transcript evidence from Dave Ferguson -- The OWASP Top 10 Proactive Controls.
“If you have already invested in it, and are hesitant to rip it out, yeah, you can keep using the SAPI, get the latest updates that were pushed out a couple months ago.”
Transcript evidence from Jim Manico -- MORE OWASP!.
“If you can't write clean code that, passes the static analysis system, then it bumps back, kicks out your change, and you have to go back and fix it.”
Transcript evidence from Matt Clapham -- The Technical Debt Ceiling.
“You have to build an encryption capability or you have to build— and then you have the problem of what you do with the crypto keying materials, the things that make the encryption.”
Transcript evidence from Brook S.E. Schoenfield -- Security in the Design and Architecture.
Include leaders, architects, and builders in risk discovery
Said by Brook S.E. Schoenfield ·
“I want to talk to architects. I want to talk to people on the ground, who are building things to get a sense of what they think, where their frustrations—”
Transcript evidence from Brook S.E. Schoenfield -- Security in the Design and Architecture.
“Then afterwards, he politely came out and said, "Can I talk to you for a second?" And said, "I didn't appreciate when you said think like an attacker." Oh no!”
Transcript evidence from Conclusion: The End…of Season 1.
“You can integrate static analysis. build that in, you can do something else, and there's some engineering up front and there's some maintenance, but there's never enough time to do it all.”
Transcript evidence from Adam Shostack -- Think like an Attacker or Accountant?.
“I would bake it from the concept of the story level where you're doing a unit test for a SQL record push, but we can do a unit test for SQL injection.”
Transcript evidence from Jon McCoy -- The Mindset to Reverse Engineer.
Reverse-engineer software you are authorized to inspect
Said by Jon Mccoy ·
“Poke around your own system and find an app that you care about, something like your VPN, your communication software, your messaging software, and pull it apart and see what it does.”
Transcript evidence from Jon McCoy -- The Mindset to Reverse Engineer.
“What you can do is over a lunchtime session, which might even be easier for a small company because you can order a couple of pizzas and invite 20 people to come and listen and have a little conversation about security.”
Transcript evidence from Chris Romeo -- Security Community at Any Scale.
“Must expose the vision and the mission and the plans of the business To all technologists, such that— and to everybody in the company, quite frankly— such that there is harmony and people don't walk into boardrooms speaking a different language.”
Transcript evidence from Deidre Diamond -- The Soft Skills of AppSec.
“Go to an improv event where you can practice being uncomfortable because Until that uncomfortableness goes away, one's not gonna love, the art of communication.”
Transcript evidence from Deidre Diamond -- The Soft Skills of AppSec.
“Security professionals within organizations that are alongside these product managers and developers need to start to have their stethoscope to good, credible threat intel that is correlated to the application frameworks that their developers are using”
Transcript evidence from Tony UcedaVelez -- PASTA: Not Just for Breakfast Anymore.
“My job is to explain the vulnerability, explain the impact, provide some examples, And hopefully, if I'm good at my job, provide here's what the mitigation would be and here's how much mitigation would cost.”
Transcript evidence from Mike Landeck -- Security Must Meet the Needs of the Business.
“I always start out with trying to gather as much information as I can about the application and its immediate environment, any dependencies that it has or components that it interacts with on the backend.”
Transcript evidence from Daniel Ramsbrock -- Web Application Pen Testing – Part 2.
“Usually there's at least a regular user role Sometimes there's an admin role and, and if the application is more involved than that, there might be other in-between roles that have, more privileges than a regular user but not quite admin privileges.”
Transcript evidence from Daniel Ramsbrock -- Web Application Pen Testing – Part 2.
“They have an application called WebGoat, and it's, it's an application that you can, download and install in a VM, and you can start, and so you're not hitting anybody else's environment, you're, attacking it in your own your own localhost.”
Transcript evidence from Daniel Ramsbrock -- Web Application Pen Testing – Part 2.
“To me, the waterfall methodology lends itself most to the traditional approach to pen testing, which, most organizations will test their key apps, once a year or so.”
Transcript evidence from Daniel Ramsbrock -- Web Application Pen Testing – Part 1.
“I definitely think that there's pros and cons to both approaches, and I think that ultimately most organizations end up with some hybrid model because it makes the most sense.”
Transcript evidence from Daniel Ramsbrock -- Web Application Pen Testing – Part 1.
“They don't attack any systems, whether don't have explicit permission, and they always report their findings, to the vendor with plenty of lead time to have to perform a fix before they would publish their results to the wider community.”
Transcript evidence from Daniel Ramsbrock -- Web Application Pen Testing – Part 1.
“For example, very often, privacy law allows you to do many different things, but companies get in trouble how they describe to the customers or to the end users what they do with data.”
Transcript evidence from Elena Elkina -- Privacy and Data Protection.
“Developers play an instrumental role in this process because very often privacy and security controls to protect personal information required for a particular process or application or product are ignored or left to the end of the product development cycle.”
Transcript evidence from Elena Elkina -- Privacy and Data Protection.
“To summarize what I, what I took away from the description you provided of agile in general, some of the advantages to agile are that you can make changes.”
Transcript evidence from Chris and Robert -- Security in the Methodology.
“Yes, so I think that the important thing here Regardless of the methodology that you use, the important thing here is to understand what are the security activities that need to be done, what are the steps that exist in our methodology that our company is deciding to use or our team is deciding to use, and then”
Transcript evidence from Chris and Robert -- Security in the Methodology.
“You need to write something down, and I agree, and that's what I've seen as well, that it's important to have some concrete place or something, piece of paper, whatever it is, to keep track of those requirements that you've determined or the features of the system, if you will.”
Transcript evidence from Chris and Robert -- The Activities of the Secure Development Lifecycle.
“The threat modeling aspect of this is understanding your system, understanding the potential threats in that system, and then figuring out ways to mitigate those or create countermeasures, and then, plan out that as essentially your design of your system.”
Transcript evidence from Chris and Robert -- The Activities of the Secure Development Lifecycle.
“You need to invest the time and the resources in any tool that you're going to use to tune it, to make sure you provide the best possible output for the developers to focus their time and the information that you're putting in front of them so you're not wasting their time.”
Transcript evidence from Chris and Robert -- The Activities of the Secure Development Lifecycle.