--- title: "Andrew van der Stock — Taking Application Security to the Masses" url: https://appsecpodcast.com/andrew-van-der-stock-taking-application-security-to-the-masses/ date: 2021-01-20 duration_seconds: 1841 guests: ["Andrew van der Stock"] topics: ["Conferences and Community"] audio: https://www.buzzsprout.com/1730684/episodes/8122581-andrew-van-der-stock-taking-application-security-to-the-masses.mp3 transcript: true --- # Andrew van der Stock — Taking Application Security to the Masses *January 20, 2021 · 31 min* with [Andrew van der Stock](https://appsecpodcast.com/guests/andrew-van-der-stock/) on [Conferences and Community](https://appsecpodcast.com/topics/conferences-and-community/) [Audio](https://www.buzzsprout.com/1730684/episodes/8122581-andrew-van-der-stock-taking-application-security-to-the-masses.mp3) ## Show notes How does a volunteer security community reach the millions of people who build software? Andrew van der Stock reflects on that challenge after becoming OWASP’s executive director in 2020. He traces his early application security work and contributions to OWASP projects, then explains the foundation’s purpose and the organizational work behind its public resources. Chris and Robert ask about membership, support from companies that use those resources, and ways to welcome people who are new to security. Andrew also discusses the disruption of 2020 and plans for OWASP’s twentieth anniversary. This archive conversation captures his ambitions for making practical application security knowledge more accessible while building a stronger, more sustainable community around it. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Security Journey provides application security education for developers and everyone in the software development lifecycle. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Andrew van der Stock: → [Andrew van der Stock at OWASP](https://owasp.org/corporate/) Mentioned in this episode: → [OWASP Foundation](https://owasp.org/) → [OWASP Developer Guide](https://owasp.github.io/www-project-developer-guide/) → [OWASP Proactive Controls](https://top10proactive.owasp.org/) → [ZAP](https://www.zaproxy.org/) Chapters: 00:00 Taking application security to the masses 02:42 Andrew’s early AppSec and OWASP work 06:17 Becoming OWASP’s executive director 10:35 OWASP’s mission and community 12:19 Application security beyond the web 13:47 Why individuals and companies join OWASP 18:07 Welcoming newcomers into security 20:32 How OWASP navigated 2020 23:25 A longer-term vision for the foundation 26:23 Planning OWASP’s twentieth anniversary 28:20 How listeners can participate ## Transcript *5,524 words · assemblyai* **0:00 Chris Romeo:** Andrew Vanderstock has been around the world of application security for quite a long time. In 2020, he took over as the executive director of OWASP, and he's working from within the organization to further the mission of taking application security to the masses. We discuss Andrew's OWASP origin story. He defines OWASP and the OWASP core mission, and we talk about membership, the future, and we even drop some details about the upcoming 20th anniversary of OWASP. We hope you enjoy this conversation with Andrew Vanderstock. You cannot hack yourself secure. Everyone wants to focus on the offensive side of the equation. The challenge is that developers get bored with hacking broken pieces of code after a while. Sure, it's a shiny, cool new thing in the beginning, but how about one year later? At Security Journey, we focus on long-term sustainable security culture with the developers as defenders. Our approach integrates experimentation together with learning. We believe that developers need hands-on experience, but not at the expense of fundamental knowledge. Visit www.securityjourney.com to sign up for a free trial of the Security Dojo or schedule a demo. Hey folks, welcome to this episode of the Application Security Podcast. This is Chris Romeo, CEO of Security Journey, and I'm also joined by my good friend, Robert Hurlbut. Hey, Robert, how's it going? **1:34 Robert Hurlbut:** Hey, Chris. Yeah, good to be here. Threat modeling architect, really excited about our topic today. **1:38 Chris Romeo:** Yeah, and we are going to talk about something that if we had to, if we had to total things up, like how much coverage did different topics get on the Application Security Podcast, I would say OWASP is pretty high up there in total, probably second to threat modeling. But shame, you know, that's just, Robert, that's just you and me kind of talking about what we love from that perspective. We're excited to have Andrew Vanderstock joining us today for his second visit to the Application Security Podcast. We were reminiscing about his first visit. We did an interview with he and Brian and Neil when they were working on the OWASP Top 10 2017 edition in a giant room in Orlando, Florida, which we're just reminiscing about how it seems like yesterday, but yet it was many years ago. So Andrew, I want to jump right in. We already heard your security origin story. Folks can go back and hear that from the past. I want to hear your OWASP origin story. I'd even like to know before you took on the new role that you're in now. Give us the— give us a little bit of a history lesson about Andrew Vanderstock and your interactions with OWASP all the way up to today. **2:42 Andrew van der Stock:** Yeah, sure. Hi guys. So back in 1998, I got into application security. I did my first code review for a bank. They called essentially websites at that point that had ActiveXs, they called them mobile applications because the application itself was being transported to this browser and executed over there. That was amusing, but the reality is I had to more or less discover and document the things that I was interested in from first principles. And so once I saw OWASP start, I thought that's a really great idea. And so about 3 or 4 months after it got going and they put out the first, you know, initial version of the developer guide, I realized that it had all these gaps and there was a lot of things that they missed. And I felt that it could be improved. So I started contributing and in the process I wrote down everything I knew and it turned out to be quite a lot. I might've accidentally discovered things that other people hadn't discovered to that point, but we stood on the shoulders of giants and it's very, very hard to say who discovered what at that point, 'Cause it was such a rush. Everyone was learning from each other, posting new techniques all the time. It was great. It was a very exciting time to be in the industry. Every app had SQL injection. Every app had it. So back in late 2001, I don't know exactly when, my first post is December of 2001 on the archives. So I thought I was there a little bit earlier, but I was not there at the beginning. There were a few people who were there at the beginning. There's a whole bunch of people who claim they were there. Mark Kerfe actually has a blog post about that. Sort of interesting. But I think it shows the success of an organization when so many people claim to have started it. So I did the Developer Guide 2.0. Took 18 months of working out of hours. I was pulling 18-hour days doing it. I got my first real experience of a proper group project that was pretty much not a group project, it was me. There were contributors, I won't lie. I had some really good reviewers, like Michael LeBlanc from Microsoft reviewed the buffer overflow chapter because that wasn't a specialty of mine. And he gave us a lot of really good advice, including like 3 hours before I had to leave to go to Black Hat to release it. So I was editing it. So if you ever wondered why it was, It's called 201 or something because I edited the final version and then re-released it for the Black Hat edition. And yeah, basically went and had a shower and got into a taxi and went to the airport and went to Vegas. So that's how close it was to the final edits for some of the things. And the rest is history. I've just, I got involved in the OWASP Top 10, realized during the OWASP Top 10 that it's exactly the wrong approach, says the person who's the current co-lead of the OWASP Top 10. The reality is it's an education piece and it makes people aware of the issues, but it's not actually meant be a standard. People were using it as a standard. PCI DSS chose it as a standard, even though I wrote in the foreword, please don't use this as a standard. It's an education piece. So I'm really going to be focusing this year's, or the 2021's, OWASP Top 10 on making sure the developers and the others who use it are aware that there are proper standards. And that they should look over here if they want a short one like the proactive controls. That's a better choice. That's how the top 10 should have been written in the first place, not like the way it's written at the moment. **6:17 Chris Romeo:** So then how did you get to where you sit today as the executive director of OWASP? Now I'm curious as to, as to how you got there. **6:27 Andrew van der Stock:** So I went to— I was a senior principal consultant at Synopsys, a large consulting firm. I was the head of managed services. from a technical point of view. And so I was basically leading a team of penetration testers and I was trying to take them to the next level. I got a new boss and that new boss decided that he had his own team that he wanted to bring along. He may not have been very happy with the direction I was going, which is essentially working towards quality. That's by the by, that's past history. So I had a conversation with Sharif Mansour, one of the board members, and we talked about the vision for the future because he really wanted me to get back involved in the more of the, the back end of it more than anything else. Um, We had a really great executive director who is fantastic at the administrative side of running a nonprofit, but he really wasn't able to connect with the community. And I think the community was getting very restless. And, you know, we talked about ways that we could make that better. Where do we need to go? What is— what needs to happen over the next 4 to 5 years? And over time that got shaped and after a fair amount of immigration to and fro, because I live in America, but I'm obviously an Australian expat, I was able to accept the position of executive director. And since June '29, I've been acting as that role, and I hope I'm making an impact. I think I am. Things have certainly improved from the community's point of view. From my perspective, there's ways to go, and, you know, nothing changes overnight. But I, I think by getting back into the, um, the community leading the organization, I think we're going to be in the right spot. **8:04 Chris Romeo:** Yeah, I know, uh, I was excited when I saw the announcement because I realized, okay, now we have Andrew, who's someone who is an AppSec person, has lived and breathed this, knows the technology and stuff behind it, but also is so well respected in the community. And so I was excited when, when, when that was announced, because I'm like, this is going to be great. Certainly people from a not-for-profit perspective, we've had good leaders in the past, but like you said, they just weren't, they weren't connected to the community. And a lot of it was, this is, this is a complicated world that we've all chosen and we love it, right? Like we wouldn't trade it for anything, but somebody doesn't just come in as a business person and in 3 months say, I'm going to learn everything about AppSec, right? Like we've got, we've got SOCs that are older than that or whatever, you know, when we think about it. **8:51 Andrew van der Stock:** Well, to be fair, Mike actually knew how to develop. I just don't think he actually understood the way our community worked. We're a membership organization that doesn't require membership. We're we're organization with a long and I think interesting vendor versus community relationship that's always been very tense. I've actually got a blog post that's about to go live on vendor neutrality tomorrow because I think people misunderstand what vendor neutrality is about. It's essentially, in my view, it's a fair and equitable access to OAS on equal terms. Not no vendors, not no advertising, but our corporate supporters and sponsors actually help us achieve our mission. And without them, we've got nothing. And so we need to have a healthy relationship in both directions. And I think by resetting expectations and taking the community for the journey, I'm really, really hopeful that we'll actually get to a nicer place where people will be understanding at the very least and actually actively helpful and recruiting more corporate members. 'Cause we've got finance reform coming up, and we want to do grants. Grants are going to be funded by corporate sponsorship. I expect the corporate sponsors to basically say, I need this feature in XAP, I need it to happen. How do we get that happening? You can fund that feature. That's exactly where we need to go. That means that in some cases, some organizations will have quite a lot of say in the way OS works, and that's different. But that doesn't mean that that's vendor exclusive. It doesn't mean we should never do that. It means that we need to make sure that everybody has the same opportunity to do that. **10:35 Robert Hurlbut:** So you mentioned OWASP Top 10, and I think that's sometimes the first introduction for developers when they're hearing about OWASP. But that term OWASP has been around for a while, obviously, and what is it? You know, I know what it stands for, but, you know, maybe we don't talk about that as much, but what is it? And what's its mission? **10:56 Andrew van der Stock:** So OWASP is originally the Open Web Application Security Project. As I've got into application security more, to me it's about protecting the data of humans. Our mission really should be making sure that transactions are safe, privacy is maintained, and that applications are designed and built by default to be secure and safe. We should be encouraging frameworks and developers to choose safer practices at all times. You know, certain languages and frameworks don't have that safety, and they should be discouraged unless you know what you're doing. And if, you know, it's sort of like having a very sharp knife. As long as you know what you're doing and you understand the pitfalls, then it's okay. So to my mind, the mission that we've had has been around for some time, and I think we need to reshape it. And so I, I've got some ideas, but it's really the board's point of view, and the board owns the strategy. So I'm going to be guiding them on the 13th and 14th through a 2-day strategy meeting. And I've got them to read a strategy book for nonprofits to create impact. It's not enough to basically say, I want to run 3 conferences this year. I want to have 150 chapters. I want to have 200 projects. That's irrelevant. We want to make impact with the developer community. I think our mission statement needs to be updated to reflect that. **12:19 Robert Hurlbut:** Sort of a follow-on on that, I know you mentioned the open web application. Is it exclusively web application focused? I know it isn't, but it's interesting that that was originally in the title. Of course, we still keep it. I've seen mobile guides, I've seen a bunch of other stuff, of course, in just general application security. **12:39 Andrew van der Stock:** Interestingly, the answer to that is I think we do need to focus on Code and you know configuration as code, applications that are building on cloud platforms as code. That is interesting, and I think it's probably the lowest layer that we should go to. I think we should not focus on infrastructure. We should not focus on networking. They are important, but there are other foundations like the Linux Foundation actually has a subsidiary that deals with network security. I think it would be a mistake for OS to get unfocused about what we're actually trying to achieve. I think you know we definitely have. Have a role in the IoT world, embedded operational technology, APIs, mobile, because they are applications at heart. Now, I think we should also probably get into operating systems and systems languages as well, which has not been a strong focus for the organization. But now that we're seeing APIs built in Go and Rust and things like that, which are essentially system languages, I think we probably do need to widen it a little bit. I don't think we should go much further than that, though. **13:47 Chris Romeo:** So when you think about membership, you said, when you were describing membership, you said we're a membership organization run by non-members. And so when you think about the value proposition for individuals and for corporate folks, what is the value proposition? Like, why should somebody become a member of OWASP? **14:09 Andrew van der Stock:** Honestly, the reality is you can do everything you want to do without being a member of the organization. And the only thing you can't do is vote for the board. You can't stand for the board, you can't vote for the board. I am trying to improve the value of our membership. OWASP members can now access what we call a learning platform. And the first part of the learning platform, and I know Chris, we've talked about this as well, I want in that sort of vendor-neutral way, We've got SecureFlag at the moment. I'd love to see Security Journey there. I would love to see Secure Code Warrior there just on a fair and equitable basis. On the same terms that we actually did it with SecureFlag, I would like to see our own projects like SKF and other threat modeling tools and things like that available on the learning platform. It's early days. The reality is the membership is a way of saying thank you to the organization. For me, OWASP has actually, like, not only defined my career, it's enabled me to get to the peak of my career. And it's really been a very, very helpful organization to say that I'm a thought leader and, you know, I'm able to actually execute at this very high level. And to do that, I was actually doing a lot of research and work for OWASP over a long period of time. And my way of thanking the organization was to become a lifetime member. I think, you know, at the end of the day, if you think about, you know, my predecessor had a thing where he actually had us akin to other charities. If you volunteer at the local animal shelter, you're going to be walking dogs, you're going to be cleaning out the kennels. You get pats, you get licks, but there's also the downsides as well. The reality is, OWASP is sort of like that. You shouldn't expect too much. It's got to be a passion of yours, and I do encourage people who get value out of OWASP to become a member, become a corporate member. I am trying to improve the value. I won't lie, for the $50, which is extremely low compared to, say, most other professional organizations— if you're a CPA, wow, that's, that's quite expensive, and you need to be a CPA or a CA to actually do your job. We don't need to be an OWASP member to do your job. I do think we're priced at the right level for the amount you get out of us. But the reality is you're actually helping our mission. And that's where I think it actually comes from. It's a feel— it's to feel good about the fact that you're getting something out of it. It's probably not very easy to actually say exactly what you're going to get out of it. But I would certainly suggest that people do benefit from being around OWASP, even if you're not a member. But please, if you feel like you've got something out of us, please join. **16:55 Chris Romeo:** Yeah, because I mean, you think about all of the different things that are supported by membership. Like, I mean, you have events and things, and I know you try to get those to zero, you know, so that they pay for themselves. But I know not every event that OSF has ever done has paid for itself. I mean, that's just being a realist, right? And so some of that membership money is going towards helping to— I like how you said that— going to further the mission. **17:22 Andrew van der Stock:** That's right. **17:22 Chris Romeo:** And I think that's something that we all have to be able to grasp onto. Those of us, I mean, I've benefited hugely from OWASP, from both learning and being able to participate on some projects and getting to kind of mingle with some of the great minds of AppSec and watch them work and learn from them through the process, but also just the event perspective and stuff like that. Like, you know, it's a bit of a sales pitch for those people that are out there that are consumers of OWASP, right? If you're somebody who's used these things, become a member and help to further the mission because we all have the same mission. We all should have the same mission at the end of the day. Let's help more people to know about application security and let's build more people for our industry. That's what we need to do. **18:07 Robert Hurlbut:** Of course. **18:07 Chris Romeo:** If I hear one more discussion about a cybersecurity skills shortage, I'm going to fall out of my chair, right? Like, we all talk about it and we know there's some amount of skill shortage, But let's fix it. We fix it by bringing more people to OWASP, and we do that by becoming members so that OWASP has more resources to be able to help reach more people. You know, let's give Andrew some money here to go out and start marketing to— imagine if we went out and marketed to developers who have never heard of OWASP before. **18:33 Andrew van der Stock:** That's exactly who we're going to be reaching out to next year. No, I mean, absolutely. And I think, you know, for corporate members, there is actually a benefit that we're basically qualified and interested in the products and services for many of our corporate members. The reality is though, I am trying to do things so that every single part of the organization has an opportunity of earning money to fund what they're doing. In the past, we've run 2 or 3 very big events and that's paid for everything else. COVID has shown us that is not a good idea. It also means that we rely upon 2 or 3 regions exclusively, but that isn't our mission. Our mission is to be global. And so I've made some reforms recently to actually get regional pricing for everything. So student members in a regional, like a developing country— I'm not a huge fan of that term, but it is what it is— is now $8, right? If you want to become a startup member, we've got a startup option for $2,000. We want to make sure then the startups in the developing countries actually have access to that at a fair and equal basis. So the startup version of that is $400 in a developing country, because I know that it's difficult to come up with money during this time. But also, to a certain degree, we need to spread our wings. We need to address the Indian market. We need to address the African market. We need to address the Asia-Pacific area. Like, we've pretty much lost contact with the chapter in China, yet it's a huge area. Now, I'd like to re-establish relations with them, but I don't even know who leads it at the moment. Now, that is an area that we absolutely do need to concentrate on and be a global mission, and to focus our energies throughout 2021 and beyond by ensuring that there are events in every time zone. And we're going to do that. **20:32 Robert Hurlbut:** So you were mentioning a little bit about, you know, this year in 2020 and how we learned a lot more than we wanted to about different conferences and other meetings and so forth. But how has 2020 gone for OWASP in particular? **20:51 Andrew van der Stock:** Well, 2020 for everybody has been terrible. OWASP has had its own set of issues that are probably separate to COVID. I won't lie, it was a pretty rocky time when I first got in. I think the community was really at a crossroads, and I've been able to turn that around to a certain degree. I think there's more things coming that will actually turn it around even more. I've got a meeting on Monday with the Californian chapter leaders to hear what their issues are. and to come up with an action plan to address those issues, because I bet it's not just in California that we've got this issue, or whatever those issues might be. I know, for example, with the failure of the leaders policy to get through, the board literally did not vote for it. One board member voted against it. So we haven't had any other policy that was working that way. So we've got to go back to the drawing board for many of the policies and have a reset. And to a great degree, I am working on that reset. The leaders policy will probably die as it stands, and we'll probably just put it— sprinkle the things that we absolutely must have through the rest of the policies. I know the reason why it was constructed, to try to treat every leader the same, but at the same time, the settings in that policy just weren't right, not for the community, not for the way that we work. So, you know, things like complimentary membership. So leaders often had an expectation that they should be able to get honorary membership just because they're volunteering their time. That's in many ways a strange and unusual request, but that's an expectation that the majority of leaders had. 83% of the leaders weren't members, and yet the leaders were the people who were the next in line to become the board. And they couldn't set any policy by electing board members who thought like themselves because they weren't members. So complementary membership is now available to active leaders. I hope that that's taken up some more so we get more, you know, more candidates for the board. Fresh ideas all the time are really good. And more to the point, we have more people participating in the selection of the board. **23:10 Chris Romeo:** So when you think about the future then, so I know, you know, that I've heard you talk about, you know, kind of where your perspective on this job and the fact that, you know, you want to look to 2021 and beyond. I'm going to go a little further down the road first and then we'll come back to 2021. **23:25 Andrew van der Stock:** Okay. **23:25 Chris Romeo:** But I'm curious, for Andrew Vander Stock as the executive director, when you think 5 or 10 years into the future, let's pretend we've got the, you know, the DeLorean, we can jump in and 88 miles an hour and boom, we're there, right? Like, what do you think, what are you aiming at for 5 to 10 years from now for OWASP? **23:46 Andrew van der Stock:** I would like us to be universally known by the developer community and have a strong relationship with developers, developer conferences, and developer organizations. I really do think that, you know, furthering ties with people like the OpenSSL, which is a Linux Foundation initiative, is really important to us. That allows us to get in front of hundreds of thousands of developers, In particular, framework owners who actually help other developers, millions of other developers code securely by being involved in these key organizations. So I think there's some partnerships going there. We absolutely do need to work on bug classes. There's things like cross-site scripting which are going down rapidly because people are starting to use React and Next.js. These frameworks just don't have cross-site scripting. You can still shoot yourself in the foot, but it's harder. And if you use React or Next.js properly in the way it was designed, you don't have cross-site scripting. That's a bug class solver, and that's what we need to work with the developers of frameworks on. That's how we got rid of CSRF. That's how we're going to get rid of cross-site scripting. And in my view, that's how we're going to get rid of injections in general. Long-term, I would like to see the health of OWASP be an incredibly global organization. I think it's well known in Europe and America. It's sort of well known in Australia and the Asia-Pacific area through the efforts of some of our amazing leaders like Ryo Taira. We need to make sure that we have healthy chapters because they spread the message. If a developer is interested in coming and talking to us, they'll probably come to a chapter meeting. I'd love to see healthy chapters all over the world. And that's why we've got a chapter initiative, like a chapter restart initiative running right now. I prefer to invest in chapters that are actually active, but I want as many of them as possible, and that's where we need to go. But lastly, I think, you know, one of the things that's really important to me is we need projects that are game changers. And for too long, OWASP policy settings were designed to pretty much stop project leaders do projects. It was very difficult for project leaders to spend money, and honestly, they accrued a fair amount of money, but they couldn't spend it. I want to fix that. I want to change it so that we can actually say, you know, Zap developers, break down about 8 or 9 packages you'd like to go to sponsors and get you some money to be able to work on these things. So not only do the sponsors get something, but the community gets something back as well. **26:23 Robert Hurlbut:** So OWASP has been around for a while, 20 years. Lots of interesting things have happened. But what are we planning for a celebration of that? **26:34 Andrew van der Stock:** Very good question. We are trying to organize a 20th anniversary special on the 24th of September, 2021. That is our 21st anniversary. I have had discussions with Mark Kerfee, one of our major founders and probably the driving force behind early OWASP. At the moment, he doesn't feel like he wants to participate in that, and I hope I can turn him around before then. But I do want to get together all the early folks and Have some panels, get some, you know, discussions of key projects like the OS Top 10, get Geoff and Jayve to discuss the early days of the OS Foundation and the OS Top 10 when it first got going. That'd be really cool. But I also want to talk about not only the present but also the future. And so in September, do look for a number of events all themed around the 20th anniversary, and some of them will be the next 20 years. Some of them will be celebrating our current chapters and our current projects and some of our other missions. Like for example, we've kicked off an education committee. I want them to come up with a curriculum. They are working on industry and tertiary curriculums, which is going to be fantastic. But I also want them to work on early start stuff. Like how do we get folks who want to get into application security? They might be a developer or they might be someone at university who's getting into it. How do you do it? How do you bootstrap yourself? This is something that I think OWASP has had a little bit missing for a while. And so the Education Committee are going to work on that through then. I'd love to see some promotion of that. And I'd certainly like to say that is the future. Bootstrapping the next generation is really important. The early pioneers of OWASP are getting like me into their late 40s, early 50s, and we've got to bootstrap that next generation before the next 20 years are up. **28:20 Chris Romeo:** Well, Andrew, when you think about key takeaway or call to action, What do you want our listeners to do in regards to OWASP? **28:29 Andrew van der Stock:** I'd really like people to come to meetings. If you're a chapter leader, please have virtual meetings. We've got the facilities to do so. I would love for chapters to promote getting involved in projects. Projects are a love that you, you have to have the itch. You can't just say, I want to help Project X and I'll do X, Y, and Z for them. You've really got to say, for example, there's a great threat modeling tool I want to do threat modeling, and you work on that specific tool. We get those volunteers from chapters, and so I think it's all integrated. I think the first and pretty much the major call to action is please go to a chapter meeting. If there's no chapters happening in your area, virtual makes it so easy to attend other people's chapter meetings. Come have a look at the next couple of chapter meetings that are available to you. Come to the chapter meetings, get involved with projects. the biggest call to action I have for you. **29:27 Chris Romeo:** Andrew, thank you for all that you do, all that you've done for the OWASP world, but all that you're doing today through your current role. We certainly appreciate it, and we see the value that's, that's being driven, and we look forward to the future. We look forward to where OWASP is going because we know that to achieve this mission of getting more people excited about and into application security, it's not going to happen by a bunch of individuals individuals doing things. Maybe we'll get a tiny percentage, but it's got to be a coordinated effort, and that's, that's the value that OWASP brings to the table. So thanks for being here, and thanks for what you do for OWASP. **30:03 Andrew van der Stock:** No worries. Thank you. Thank you for having me. **30:07 Chris Romeo:** Thanks for listening to the Application Security Podcast. You'll find the show on Twitter @AppSecPodcast or on the web at www.securityjourney.com/application-security. You can also find Chris on Twitter @edgeroute and Robert @roberthurlbut. Remember, security is a journey, not a destination. --- Source: https://appsecpodcast.com/andrew-van-der-stock-taking-application-security-to-the-masses/