--- title: "Andrew Van Der Stock -- The New OWASP Top Ten" url: https://appsecpodcast.com/andrew-van-der-stock-the-new-owasp-top-ten/ date: 2024-07-23 duration_seconds: 3111 season: 11 episode: 19 guests: ["Andrew van der Stock"] topics: ["OWASP Top 10", "API Security", "Vulnerabilities and Exploits"] audio: https://www.buzzsprout.com/1730684/episodes/15457153-andrew-van-der-stock-the-new-owasp-top-ten.mp3 video: https://www.youtube.com/watch?v=99nnp1CjFQs transcript: true --- # Andrew Van Der Stock -- The New OWASP Top Ten *July 23, 2024 · 52 min · Season 11, episode 19* with [Andrew van der Stock](https://appsecpodcast.com/guests/andrew-van-der-stock/) on [OWASP Top 10](https://appsecpodcast.com/topics/owasp-top-10/), [API Security](https://appsecpodcast.com/topics/api-security/), [Vulnerabilities and Exploits](https://appsecpodcast.com/topics/vulnerabilities/) [Audio](https://www.buzzsprout.com/1730684/episodes/15457153-andrew-van-der-stock-the-new-owasp-top-ten.mp3) · [Video](https://www.youtube.com/watch?v=99nnp1CjFQs) ## Show notes Andrew Van Der Stok, a leading web application security specialist and executive director at OWASP joins us for this episode. We discuss the latest with the OWASP Top 10 Project, the importance of data collection, and the need for developer engagement. Andrew gives us the methodology behind building the OWASP Top 10, the significance of framework security, and much more. Andrew Vanderstock is a seasoned web application security specialist and enterprise security architect. He's the executive director at OWASP, taking the foundation through organizational change and taking OWASP's mission to the next level. Andrew has worked in the IT industry for over 25 years, has researched and developed the web application security and architecture fields since 1998. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Our training includes theory and immersive learning that teaches the skills and knowledge needed to create a security-first mindset across your organization. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Andrew van der Stock: → [The Crown Road by Iain Banks](https://www.amazon.com/Crow-Road-Iain-M-Banks/dp/0349103232) → [Edward Tufte](https://www.edwardtufte.com/tufte/books_be) Mentioned in this episode: → [The Crown Road by Iain Banks](https://www.amazon.com/Crow-Road-Iain-M-Banks/dp/0349103232) → [Edward Tufte](https://www.edwardtufte.com/tufte/books_be) → [OWASP Top Ten Project](https://owasp.org/www-project-top-ten/) → [OWASP Developer Guide](https://owasp.org/www-project-developer-guide/) → [PCI DSS](https://www.pcisecuritystandards.org/standards/pci-dss/) → [OWASP Top Ten for LLM Applications project homepage](https://owasp.org/www-project-top-10-for-large-language-model-applications/) → [RSA Conference](https://www.rsaconference.com/) Chapters: 00:00 Meet Andrew van der Stock: The New OWASP Top Ten 01:41 We are about to go on a journey into the topic 04:10 Phone goes with you probably just for emergency purposes, but so 07:27 Probably get ways to deal with it, right 13:08 Help me, help me remember what, what, what is the connection 15:29 On the topic of OWASP Top 10, give us an update 17:16 We talk about data and the need for data, I don't 20:58 Then if— so the, the request for data is really more 21:56 Now I'm curious. I want to dig a little deeper on 26:00 Are the downsides of, potential downsides of this data collection approach 30:23 That data weighted different in the model if it comes from 33:33 Wrapping all of this kind of together, we've got the data 35:14 I mean, or it used to be. Yeah. Or it used 36:24 I can, I mean, just to second something you said a 40:38 Yeah. So you already jumped ahead to controversial opinion, but before 42:23 All right. Yes, we already talked about the controversial opinions. So 45:59 Great. Last question is, what's your top book recommendation and why 50:12 Andrew, what's, how about a key takeaway then ## Transcript *8,156 words · assemblyai* **0:00 Chris Romeo:** Andrew Vanderstock is a seasoned web application security specialist and enterprise security architect. He's the executive director at OWASP, taking the foundation through organizational change and taking OWASP's mission to the next level. Andrew has worked in the IT industry for over 25 years, has researched and developed the web application security and architecture fields since 1998. He's a lifetime member of OWASP, A former director and co-leads the OWASP Top 10 projects. An Australian expat of Melbourne and Sydney, he currently lives in the USA with his family. Andrew joined us to catch up on the happenings of the OWASP Top 10 project. We discuss how the project is going, data collection, and the methodology for building the Top 10. We even asked Andrew for one thing that he wishes he could change About the top 10. The Application Security Podcast is brought to you by Security Journey. Our training includes theory and immersive learning that teaches the skills and knowledge needed to create a security-first mindset across your organization. **1:07 Andrew van der Stock:** Learn more at securityjourney.com. **1:08 Chris Romeo:** Hey folks, welcome to another episode of the Application Security Podcast. This is Chris Romeo. I'm the CEO of DaVinci and a general partner at Curve Ventures. And as always, happy to be joined by my good friend Robert. Hey, Robert. **1:32 Robert Hurlbut:** Hey, Chris. Yeah, Robert Hurlbut. I'm a principal application security architect and threat modeling lead at Acquia. And as you mentioned, always glad to be here. **1:41 Chris Romeo:** We are about to go on a journey into the topic Or at least the group is the topic that we've spent the most time on this podcast talking about, and that is OWASP. And so we're excited to have Andrew Vanderstock joining us for his third appearance, which by current calculations puts him into the top ten for number of number of visits to the podcast. There's a few people with five, maybe one or two with four, but you're. definitely in rare air with the group of people that have made a lot of appearances. And so, in case you want to catch Andrew's previous episodes, in January 2021, he did an episode with us called Taking Application Security to the Masses. And then in September 2017, I remember doing this interview live in Orlando, of all places. We had Andrew and Brian Glass talking about the future of the OWASP Top 10. And so that seems like it was many, many years ago, but only a few years ago. So, Andrew, instead of an origin story, because you've been with us as a guest a number of times before, this is my, what I'm affectionately referring to as Go Outside Initiative. And so I'm curious, what do you like to do that takes you away from computers and technology? **3:04 Andrew van der Stock:** Well, honestly, I love going on cruises. Like, the thing that I do the most is actually I play Elite Dangerous, which is a computer game, but that's the exact opposite of what you just asked. The game actually has tools, it has all sorts of things that you just need to use to be able to play it properly. But what I like to do is cruising because you are literally forced to be apart from your computer. **3:30 Robert Hurlbut:** Yeah. **3:31 Andrew van der Stock:** People can't contact you. They can't call you. If you don't have a copy of your favorite book or your Kindle with you, the chances are that you're going to have to rely upon shipboard entertainment. Recently though, all of the cruise lines have actually started to adopt Starlink. So you could theoretically go on a cruise and do work, which is not the point of a cruise. The point of a cruise is to get norovirus. **4:02 Chris Romeo:** So, okay. So you're, you're going on a cruise and you're leaving computer behind at home. **4:09 Andrew van der Stock:** Yes. **4:10 Chris Romeo:** Phone goes with you probably just for emergency purposes, but so you're trying to stay off your phone and just, you're trying to have like a digital-free experience for the most part? **4:19 Andrew van der Stock:** Yeah. Most modern cruise lines actually use apps on the phone to do your ordering of ship excursions and things like that. So you can't, get away from just leaving the phone at home. You do need to have it with you. They generally don't have a piece of paper that comes to your room every morning saying, you know, what are the excursions and what's the events happening on board today. You actually do need to use your phone for that. That's just modern cruising. So realistically, you do need your phone with you, but you don't have to use it all the time. In fact, I'm pretty bad at using my phone. As I mentioned when we were doing, before the introductions, I missed an important call today because I just wasn't looking at it. **5:04 Chris Romeo:** That's a good problem to have though, because you weren't spending every second picking up your phone and looking at it and seeing what was happening. **5:15 Andrew van der Stock:** So yeah, that's cool. I gave up doom scrolling a couple of years ago. I actually stopped playing I stopped using Facebook pretty much about 2 years ago. It's been fantastic for my mental health. I do recommend it. **5:29 Chris Romeo:** Yeah, it is. It does seem like all of those apps are, their sole purpose is to try to get us to scroll, scroll. And if you look in public, like in airports, I love to do this and you just kind of walk down the terminal row and You just kind of look off to the side and you can see people, everybody just mindlessly. It's like a, you know, a commercial from 1984 by George Orwell or something like with people just engrossed into their technology devices. So, but that's great to hear, Andrew, that you have, you like to get out onto the cruise ships and that's a way that you get away from this world of technology that it seems like it's so engrossing to us. **6:18 Andrew van der Stock:** Yeah, absolutely. That's also a great chance to reconnect with your family because, you know, you often feel like you neglect them during work times because, you know, I don't know about you guys, but we do work long hours and I must admit I don't really share a lot of TV shows and like my wife loves those life after lockup type TV shows and I, I can't stand them. Um, so because we both love cruising, uh, it's a chance for us to reconnect and it's fantastic. **6:52 Robert Hurlbut:** Yeah. Excellent. **6:54 Chris Romeo:** So, so, so, uh, people should not get you a DVD set of Life After Lockup. Yeah. And send it to you for Christmas. That would be a terrible Christmas gift for Andrew Vanderstock. **7:07 Andrew van der Stock:** Yeah, but it'd be a fantastic regift for my wife. **7:11 Robert Hurlbut:** Very good. **7:11 Chris Romeo:** So you might, you might take people up on it because you're like, oh, quickly, let me just change the name here, scratch it off. Your wife's like, why is your name scratched off on this tag here? **7:21 Robert Hurlbut:** Oh, it's okay. **7:22 Chris Romeo:** It's fine. I wrote my name instead of yours. That's what I was trying to do. **7:26 Robert Hurlbut:** Probably get ways to deal with it, right? Yeah. So, uh, so Andrew, as we, uh, jump into our topic today, uh, I was wondering if you could remind us about the cinema booking system, which influenced the early top 10. **7:42 Andrew van der Stock:** Yeah. So back in the— just to give people some history, the OWASP Top 10 is actually 21 years old. The first version came out in January 2003. The first version that most people are aware of actually came out in April of 2024— sorry, 2004. So the reality is that we're in the 20th to 21st anniversary of the OWASP Top 10. Dave Wickers and Jeff Williams created the first versions, but a lot of the work that we did on the developer guide was influenced with this particular gig that I did back then. And it's so long ago that that system doesn't exist anymore, but it was a fantastic system. It basically had one of everything in terms of application security. It had access control problems. It had, you know, direct object reference problems. It actually had mathematical problems. It had business logic problems. It was fantastic. So I love these sorts of apps because back in those days, you would run a scanner or something over it, and you'd find yourself looking for SQL injections and cross-site scripting manually. And of course it had those because, well, why wouldn't you back in the early days of application security have cross-site scripting and whatnot? But I loved looking deeper into apps and how they're built. And so that developed my love of application security. So in particular, this particular booking system was, it was a really interesting system. It was a very early online cinema booking experience. You know, this is 20-plus years ago. You would, I don't often think about, well, I just slap my $5 on the table and away I go and see a film. No, this was basically to allow you, like in Australia, we had this thing, or it's still a thing called Gold Class Cinemas. It's, they're fantastic. They, um, have lie-flat seats. They bring you alcohol and food during the actual movie. Uh, it's definitely a really wonderful way of actually seeing a film. Um, and so what they would do is they would sell you gift cards and, um, uh, packages and whatnot. And, uh, They were losing a little bit of money on this system and they didn't understand how that was even possible. So, well, there I go. I start looking into it and all of a sudden I see a pull-down menu with the quantity of tickets that you want to buy or whatever the case may be. And all of a sudden I realize I could just get rid of that as a pull-down and I could type a number in. So I typed in 0 and sure enough, it became 0. And I go, I wonder what happens if I put a negative number in? And sure enough, the price went down below zero. So what I had to do was play around with what I wanted in the basket until I got to about $2 for about $100 worth of stuff. Clicked, you know, update, and sure enough, it allowed me to actually check it out. So I did. 2 weeks later, I get in the mail, you know, the little coupons saying, you know, 2 cinema tickets and a complimentary food and drink thing for a certain value. And I just go, no way it worked. Anyway, the firm had actually implemented, they thought the problem was in the warehouse. They thought there's something in the warehouse. People were just taking these cards and giving them away to their friends. What was happening was people were doing exactly what I was doing. And it was such a simple fix. And it just simply came down to the fact that Java doesn't have unsigned integers. It has only signed integers. And so when I put in negative numbers, it just multiplied them through thinking there was no way you could possibly change anything because, you know, if you've got a pull-down menu. Well, yeah, that was fun. was eye-opening to the actual people that I was working for. And they were very nice. They actually let me keep the actual tickets and I had a really wonderful evening on them. So I really appreciate them. But you know what? Most of that ended up in the original developer guide. It was a fantastic experience, a wonderful client to work with. They fixed it really rapidly, which is something you don't always see. when you're in consulting. I think we've all been consultants over the time and sometimes clients are not always accepting of your findings, but they had a problem. I found their problems. And yeah, we went on to actually, some of my very first developer education came in as a result of that as well. Back in those days, you didn't need a computer science degree to become a web developer. In fact, most people were self-taught. And, um, I, uh, I, I might save that, uh, controversial topic for the controversial topic topic later. Don't burn it. **12:51 Chris Romeo:** Don't burn it too early here because we'll ask you for another one. **12:54 Robert Hurlbut:** Yeah. **12:55 Chris Romeo:** If you use it now. **12:56 Andrew van der Stock:** But no, that was a wonderful experience. And, uh, many of the lessons that we learned during that particular, um, that engagement ended up in the Developer Guide. **13:07 Chris Romeo:** So help me, help me remember what, what, what is the connection between the Developer Guide and the OWASP Top 10? Is there kind of connective tissue between those things or has it been lost over time? **13:21 Andrew van der Stock:** No, the Developer Guide was the thing that got going with OWASP in the very first thing. It was actually OWASP's first document that was ever published. Version 1.0 came out like 3 months after OWASP was formed. But I knew there was things that I knew that weren't in the developer guide. So I started helping out. So by the time that I was helping out on the developer guide, it was version 1.1, and I was responsible for version 2.0. That was a lot of work. I do not recommend having a full-time day job and then going home and then doing a full-time author job. I, if you've ever written a book, it's incredibly valuable experience, but it's also incredibly tiring. A lot of the things that were in the developer guide that I ended up documenting were things that ended up in the OWASP Top 10 and vice versa. So we didn't really have, like, today we've got access control, authentication, session management, input validation, these major topic headings, they weren't very well organized back then. It was literally a list of, here are some things you should try. So collecting them together and actually putting them into some sort of order actually helped both the top 10, and it also helped the developer guide. Because the OWASP Top 10 2020— 2004 came out, and it obviously had SQL injection at the top and, you know, worked its way down. It was really important to make sure the developer guide Had agreement, rough agreement with what the top 10 was saying. So, you know, we worked with Jeff and Dave to make sure that what they were saying was in the developer guide and vice versa. If we had some interesting things that maybe belong in the top 10 that there wasn't a lot of data for, that's one of the things that we'll talk about when we come to the construction of the top 10. The top 10's always had things that have been inserted that there isn't a lot of data for. Um, we had lots of discussions along those lines, but yeah, the first couple of versions, um, of the OWASP Top 10 were Dave and Jeff. **15:29 Chris Romeo:** So on the topic of OWASP Top 10, give us an update on the project, where it is, what's happening right now. I know it's, it's from a public perspective, it's been quiet since October, uh, 2021, right? I don't remember what month it came out in, but it's been, you know, there just, there hasn't been a lot of public kind of things happening. So give us an update on what's been happening behind the scenes. **15:55 Andrew van der Stock:** Okay. So the leaders have been meeting on and off. We are stuck. We need data. And that's my main purpose today is actually I'm begging folks for data. We had 550,000 apps worth of data then. We now have enough data to be able to say with some certainty, if we have 100,000 apps worth of data, we can extrapolate what's real, what's not, what is an outlier and help us normalize 100,000 apps worth of data. The problem is right now we don't have 100,000 apps worth of data. One of the things that's been the hallmark of the top 10 post-2017 is it is data-driven. We deliberately make room for 2 injected items so that we can have an opinion and some subjective things that are included. But Yeah. The other 8, they're real, they're data. And, you know, you can argue about what order they belong in, but you can't argue about their inclusion. So right now we are a little bit stuck. We're well behind schedule. We should be writing the OWASP Top 10 2024 right now. We wanted to publish it in September. I don't think we're gonna make that. We're probably gonna be hitting the November timeframe again. **17:15 Chris Romeo:** So, when we talk about data and the need for data, I don't want to assume that everybody knows what that means. So, let's unpack this idea of data. Like, when you use the word, you say, hey, we need data, what does that actually mean? What do you need? **17:29 Andrew van der Stock:** Okay. So, we need people from consultancies, people who run tools, people who run bug bounty programs, those sorts of things, What they will generally do is they'll have an app, they've done an assessment, and they will actually have a list of findings. In the list of findings, they will categorize— generally, most people do this, not all— they will generally put a CWE, a Common Weakness Enumeration number against it. Not everybody agrees with that categorization. For example, many people put in category 200, which is a catch-all. for a bunch of CVEs. We don't like that. Generally, the, you know, there's 1,200+ CWEs. If you can't figure out which of the 1,200 a particular vulnerability is, you haven't searched hard enough. I think, you know, but the problem is we do get a lot of information from people that say it's CWE-200. Well, now we need to unpack it a bit more. But when you've got enough data, it doesn't really matter. You can actually say, well, I'm just going to ignore the 200 and just bucket it, you know, as a tiebreaker or something like that. What we need is for people who've got this information, we need an Excel spreadsheet that basically describes the number of times you found a particular CWE across the number of apps that you've actually found them in. We really love boutiques who may only have 20 or 30 apps worth of findings, but you know what? They're so high quality because these are literally people who've manually gone and tested the application. They've triaged it, they've presented it to a customer, and the customer's agreed. It's as good as bug bounty data. Bug bounty data is actually remarkably high quality because they don't pay out for like a lot of the configuration items that you know, a lot of tools find. It's all triaged, it's all real. They've got the t-shirt or the $25. In some cases, they've got $100,000, whatever the case may be. But most people don't make a living from bug bounties. But the data we receive from bug bounty programs is actually remarkably solid. So much so that it's actually one of the ways that we judge whether a piece of data coming in actually is an outlier or not. Now, the problem with bug bounties is that they don't accept every single type of bug. And boutiques, you will see a very wide variety of bugs. Tools, if we accepted just tool data, like scans from source code tools or something like a Nessus scan or something like that, We would be overwhelmed, and we were at one stage overwhelmed with the insert tool vendor name top 8, because the only thing they found was 8 things. They're really good at finding it, but we all know tools have false positives. Was that actually triaged? Was that actually made real before we actually got that data? Because, you know, if we get 40,000 findings, or 8 items, those 8 items are ending up in the top 10. So we need to find a way to weight that. So there's a data normalization process that we use. **20:57 Chris Romeo:** So then if— so the, the request for data is really more than I just package up all of the scans that I've ever done and send them to you to pour through. So you don't want data that identifies the destination, for example, right? Like, I don't have to worry about anonymization of my data in this process with you. **21:29 Andrew van der Stock:** Yeah, I mean, basically, if we get data that is overwhelmingly pointing towards a single tool, we'll do some work to, like, make it more anonymous. We're not interested in URLs. We are not interested in particular parameter names or anything like that. We're interested in the CWE number, the number of times you found it, and the number of apps you found it in. **21:52 Chris Romeo:** Okay. **21:54 Andrew van der Stock:** Got it. **21:56 Chris Romeo:** So now I'm curious. I want to dig a little deeper on this as far as you mentioned, there's some data normalization. There's some other things that are happening here. Maybe walk us through an example of the steps that a piece of data goes through. And are there endpoints, are there places where the journey ends for a piece of data? Like, is there a place where data gets thrown out? Is there a place where a decision point, like, I'd love to get just a little more perspective on the steps you're going through to normalize this stuff. **22:31 Andrew van der Stock:** Sure. So, One of the common complaints is that we don't get data from enough of different types of sources, but we have access to the same CISOs that everybody else has access to. One of the things that might start coming towards us is data that is, that maybe the people who gave us the data is only interested in 3 types of CWEs this year. I've actually worked for a client who was only interested in fixing cross-site scripting and SQL injection. And that gig was actually a really interesting gig because we were involved in fixing, not just finding, but fixing the SQL injections and cross-site scripting. And we found, you know, thousands of it. But if you asked, if the top 10 asked for data from that year from that client, they would have, you would have received 3 CWEs, like CWE-79, CWE-80, we would almost certainly have to throw that data away. There's just not enough variety in the data to say that, you know, that's real. It's not that there's no other vulnerabilities, it's just not normal compared to the other sorts of data that we receive. We do like to see a spread of CWEs over the data we receive. We're not interested, like, again, if we get a consultancy who gives us 40 results representing every single engagement that they've done this year, that is a fantastic piece of information and we'll see a variety of CWEs and we know it's real. We'll just bucket it with all the others. What we do internally though is we do actually have, we ask people to describe the way that they collected that data. So we actually, call it humans assisted by tools, tools assisted by humans, and manual. The worst type of data that we can receive is actually scan data that hasn't been triaged. We generally can't use it. **24:35 Robert Hurlbut:** Okay. **24:38 Andrew van der Stock:** It's the most voluminous, it's the hardest to normalize, and because we don't know if there's any false positives in there, it's the least valuable type of data. So the main data that we actually like is manual data, such as from bug bounty programs and boutiques. Humans assisted by tools. This is where a security program has a tool, like for example, Burp Suite, and you're manually driving the tool most of the time, but the tool is helping out in the background. They're doing passive scans, they're doing active scans of parameters and things like that. That's actually pretty high quality, especially if they've been triaged. The lesser quality tools are those that are generally like static code analysis tools, where, you know, it's part of a CI/CD process, and the code is run through the CI/CD process, the scan tool runs, thousands of results are generated, and then a human triages them. And because of the volume of findings, you generally find there's a lot of them, But you're starting to wonder just how many are real. And so we actually do have different weightings for those different buckets. And yeah, as I said, we tend to not use just scan data, raw scan data by itself. **26:00 Chris Romeo:** What are the downsides of, potential downsides of this data collection approach? **26:11 Andrew van der Stock:** The people who submit the data are self-selected. **26:12 Robert Hurlbut:** So. **26:15 Andrew van der Stock:** I'd be, I'd really love to see every single boutique and every single consultancy and every single, you know, bug bounty program, everybody who has a large AppSec program, I'd love to basically say it was a point of pride to submit your data to the OWASP Top 10. At the moment, because we have so few sources, that self-selection often comes from people who have very mature AppSec programs. And so maybe the things we're seeing are from people who have well-tuned, well-resourced programs, and the CWEs aren't representative of what you might necessarily see elsewhere. Yeah. **27:01 Chris Romeo:** And then I guess, The other challenge is that you don't, you only know, you're only analyzing the data for CWEs. And so if there is something new in our industry, you don't have a mechanism, like it's not going to be data-driven in the early days, at least because the tools won't know to find it. So most of the finding, And maybe some pen testers know about it, but, you know, that community tends to be, have people that are at different levels, different abilities. Um, so that seems like that is also, that's also a potential downside is that there could be, it could, there could be a lag while the industry catches up with stuff that's new to be able to get the data, to be able for you to be able to drive the data. **27:53 Robert Hurlbut:** Yeah. **27:54 Andrew van der Stock:** One of the biggest things we've definitely seen is that the SOF 10 can become self-referential because if people use it as their AppSec program, then people will find the things in the previous top 10. If they're doing PCI DSS and only PCI DSS, well, PCI DSS is based on the OWASP Top 10 2007. Now, I must admit, I haven't looked at the recent PCI DSS 4.0. I've heard that they've updated it quite considerably. I'm hopeful about that because quite frankly, the 2007 version of the OWASP Top 10 is considerably old. But if you're only looking for those things, well, it could become self-referential. And I think that's one of the reasons why we haven't seen a lot of change in the OWASP Top 10. Like, I was looking at the OWASP Top 10 2004 the other day. You know, we still have injections. We still have cross-site scripting and things like that. Dave and Jeff, with the information that they had at their firm at the time, which is Aspect Security, which has now been bought by a very large multinational, they had the data, but it was only their data. But it was interesting to see that that data has replicated itself throughout the history of the OS Top 10. And so one of the valid criticisms I think is the OS Top 10, and one of the reasons why we actually inject a couple of things into it, is it becomes very self-referential. **29:21 Robert Hurlbut:** Yeah, and that's what I was wondering about, you know, in terms of, you said you do want to see other data. You want to see not just the top organizations maturity-wise and so forth submitting data, but others as well. So you get that good cross-section. It's not just representative of a certain type of organization that's giving you that data. So that's— Yeah. **29:49 Andrew van der Stock:** So, I mean, the lower maturity programs would actually struggle to get the data that we need because it's going to be in PDFs rather than in a database. They're not going to have an application management platform. They're not going to have some form of, you know, the larger organizations are set up to give us this data. And that gives us a headline number of, oh, we've got 100,000 apps worth of data. That's fantastic. But as I said, I love hearing from boutiques who might give us 40 pieces of data. That data is gold. **30:22 Chris Romeo:** Is that data weighted different in the model if it comes from a boutique? **30:27 Andrew van der Stock:** A little bit. We use it to prove that because there are so many different findings in the boutique data, we have to be careful of overweighting them. Because we may get 2 people who are really good at finding like SSRF and tools are terrible at it. **30:47 Robert Hurlbut:** Yeah. **30:49 Andrew van der Stock:** And so we might end up putting SSRF in, which was an injection. Like we literally, I probably should describe the way that we've always included something subjective in the OWASP Top 10. I mean, I think that's important as well. Back in 2007, I put cross-site I put cross-site request forgery in. There was no data for it, but every app suffered from it. And I'm glad to say that that actually made a change in the industry because, you know, I don't know if you remember Sammy Is My Friend, probably the worst CSRF attack of all time, but the funniest one as well. Well, you know, we do need that opportunity to inject things, to keep things fresh, to Like this year, I believe that we'll actually be injecting stuff about the European CRA that harmonizes the way that software needs to be developed and supported and kept secure for its lifetime in Europe. And that distinctly pushes the, you know, you have no warranty. Well, in Europe, you absolutely will have the requirement to look after your software. So I'm expecting us to inject some CRA items into the OWASP Top 10 2024. Will it happen? I don't know. We rely upon, we survey on social media to find out what the community thinks. What Andrew van der Stock thinks is not important. I might put a survey out that lists 10 or 15 things that I think are important, But the community may disagree with me. But if we have a lot of people from Europe, they'll say they will select the CRA items. So we'll see. But yeah, the OWASP Top 10 has always had injection of things that we think are important. And logging and monitoring was the controversial one in 2017. **32:49 Chris Romeo:** Mm-hmm. **32:49 Andrew van der Stock:** But if you've read the Verizon data breach reports ever since they started coming out 20-plus years ago, The idea that you can write an app that doesn't log is ridiculous. So everybody who gave us grief around logging and monitoring as being something, well, the people who definitely were upset by that were the people who couldn't scan for it. You actually had to ask the question, you had to ask the customer questions, and they don't like doing that. You have to deal with other humans. No, I don't want to deal with another human. Goodness gracious. Yeah. Um, yeah, I'm a hacker into my mom's basement. **33:30 Robert Hurlbut:** Okay. **33:32 Chris Romeo:** So wrapping all of this kind of together, we've got the data, you've done a bunch of analysis of it. What's the, what finally gets us to the order that we see? Okay. Like how do you pick the number one? **33:51 Andrew van der Stock:** It's a battle to the death over 4 and a half hours or so. We spend a very, I won't say it's an acrimonious meeting, but I would say that people have hills they're prepared to die upon. I was actually pushing for maybe not including injections into the 2021 version, but when we pushed all the data together, including cross-site scripting, including SQL injection, and for all of the forms of injection together, It did end up in there. It was top 10, 2021. And then the question became, does it belong as number 1? That order is actually one of those things where we know that people do pay attention to. But my message to everybody listening to this podcast is the order is unimportant. Do all of them because it's only 10 things. Do all of them. And if you find that like, Injections is a big problem for you and it's still number 7, it doesn't matter. Just do them. Just do your best. **34:53 Chris Romeo:** Unfortunately, I don't think people interpret it that way though, which I wish they do. And I agree with you. I agree with that. Like, these are the 10 most important things. Do them all. It doesn't matter what order they're in. But I think human nature says people are going to get caught up in, well, that's the number 1 thing on the list. And that's the most important thing. **35:14 Robert Hurlbut:** And I mean, or it used to be. Yeah. Or it used to be. So yeah, it used to be. So therefore it's not important anymore. You know? **35:21 Chris Romeo:** Yes. And that's what I would hate to see is like, oh, well, injections is number 7. Some percentage of the world will be like, that doesn't really matter that much anymore. When in fact, we know that if you don't practice input validation and output encoding and all these things, you're just going to keep building applications that suffer from injection attacks. **35:42 Andrew van der Stock:** Absolutely. And realistically, the injected items that we put into it never appear at number 1 or number 2. But considering the fines that will associate with the CRA, maybe they should. **35:56 Chris Romeo:** Could you take the numbers out? Could you just give us a top 10 list that doesn't have a, doesn't have a number 1, just has 10 things on a bullet list? **36:05 Andrew van der Stock:** Controversial. Um, many people, including the CWE, actually categorize by the actual number. So we sort of need it. **36:14 Chris Romeo:** Okay. I see. **36:17 Robert Hurlbut:** Yeah. And it's a way of identifying, but, um, yeah, I can see that. **36:23 Chris Romeo:** I can, I mean, just to second something you said a minute ago, I remember when, when CSRF went from 4, I believe you told me years ago, It actually went to number 13 when it moved off the list, but it still felt like a step forward. It felt like as an industry, we could say, hey, we did something, like something got better. The CSRF was, people understood what it was, people started to mitigate for it, and eventually the frameworks absorbed it. So, I mean, you really got to do something ridiculous to set up a CSRF in a framework-based application today. You gotta go turn a bunch of things off, man, you know, on purpose. And so that's really the ultimate goal. Like, is there another thing, Andrew, from your perspective? Like, what's the next one that we're closest to being able to celebrate victory on? **37:17 Andrew van der Stock:** Injections. My controversial take, I'm jumping forward one question. Okay. **37:26 Robert Hurlbut:** Sure. **37:26 Andrew van der Stock:** I actually think developer education is overrated. And I think what we need to do is actually get to the frameworks and say to the frameworks, you need to fix these things based around the ASVS. Um, make sure your framework actually covers off these things by secure by design. Do you know why CSRF and injections are falling off? It's because the frameworks don't let you do it. You can still shoot yourself in the foot if you do it the hard way. But I've never met a developer who really wants to do it the hard way. They rely upon their frameworks. **37:56 Chris Romeo:** Mm-hmm. **37:56 Andrew van der Stock:** I, my controversial opinion is we need to get the frameworks to really, and to be, to be fair to them, the major ones that are in use actually do a really good job of the vast majority of the OWASP Top 10. It's just, I'd really like to see the same sort of focus on access control and authentication now. Because we're starting to see that that's starting to become much more important than it used to be because the other things that were traditionally in the top 10, like injection, CSRF, and, you know, all of those wonderful things that were easy to find, like security misconfigurations, are starting to go away because the frameworks are doing the right thing. **38:40 Robert Hurlbut:** Yeah. **38:41 Chris Romeo:** I think access control and authentication are going to be a harder framework fix. Just because with most languages, there's other pieces. It's not the framework that you rely upon to implement access control. There's, there's a lot of moving open source pieces. You know, when I think about like a Node.js JavaScript application, there's, there's multiple pieces that I can, I can get. And so maybe it means you got to get to all those other pieces. You need to get to the open source package maintainers and try to get a cohesive story to be built there. But I think it's a good step forward. I mean, it seems like it's something that you could achieve in 5 years, that there would be a decent chunk of moving forward. Because if, I mean, it feels like it's something like, well, why don't we just fix it in a year? It feels like it's a multi-year engagement to try to fix things at the source, it's gonna take time for them to catch up. **39:43 Andrew van der Stock:** So access control is one of those functional business requirements that enterprise architects used to do, but people got rid of their enterprise architects. And so what happens is that people don't think about the negative access control consequences. And so they don't write user stories that incorporate them. And so the developers don't include them. The frameworks are absolutely like capable of implementing these negative access control stories. They just don't because nobody bothered to enumerate them. But I think that that's going to become like the business logic flaws of the future. People will be able to get in and do things they're not supposed to do. And because there's less surface area to attack, well, now people will spend more time looking at the access control and business logic. and see whether they can abuse that because people didn't, well, they didn't have enterprise architects anymore. **40:38 Chris Romeo:** Yeah. So you already jumped ahead to controversial opinion, but before we go to Robert's other, which will now be a 2-question segment, I gotta ask you this one. So what's one thing that you wish you could change about the Top 10? If you had a, if you had the ability to change something? **41:01 Andrew van der Stock:** I would like to see it to be a little bit more, I would like it to be shorter. I would like it to be no more than 15 pages long. I would like it to be more infographic heavy. The reality is, is that When we come to do translations of the OS Top 10, a lot of the things become very technical and there may not be words for what we're actually trying to describe. It'd be really good for us to be able to have a more visual approach to the Top 10. Dave tried to do that in 2013 with the PowerPoint version, but I thought it was a bit confusing in the iconography. And we never really kept it. And so the later versions didn't have, didn't continue with that at all. So yeah, I would like to see it shorter and I'd like to see it a little bit more visual. **42:02 Chris Romeo:** Yeah, that makes sense that, you know, when you start to think about all the languages that it's translated into and it's, it does make sense that simple is gonna be better and, and more visual is gonna be less translation. have to go into it. So, all right, with that, Robert, take us into the abridged lightning round. **42:23 Robert Hurlbut:** All right. Yes, we already talked about the controversial opinions. So let's go into— so what would it say if you could display a single message on a billboard at the RSA or Black Hat conference? **42:37 Andrew van der Stock:** I've been thinking about this since the beginning of the actual episode where you popped it out and I'm just going, wow. Okay. So honestly, when I went to RSA this year, it was my first time at RSA and it's overwhelming. I do think the best messages that got through were the simple ones. So a few years ago, we were working on our message of our mission and OWASP has had a few missions in its time, but I do think we needed a simple and short and sweet vision statement. And the current one we've got is, and I'm, you know, so help come up with it, is no more insecure software. It's a big, hairy, audacious goal, and it says where we should be going and how do we get there. I think one of the things OWASP has been very successful at is helping people to actually make their secure, their software more secure. there's a lot of criticism of, you know, the fact that some of OWASP's projects are getting a little bit stale, a little bit old, like WebGoat and whatnot. The reality is though, the bread and butter of the application security world is actually to do the things that are a little bit boring, but we need to keep up. You know, we need to make sure that we're agile. We need to make sure that our processes aren't falling back into the waterfall engineering process, you know, stage gates and things like that. We don't want to do that. We have to respect the fact that most firms don't have enterprise architects anymore. So developers have to do that role. So we need to provide easy-to-understand reasons why. But I think one of the gaps that we've got at OWASP, and I think where we need to go in the future, everybody at RSA was jumping on the AI bandwagon. **44:29 Robert Hurlbut:** Yeah. wagon. **44:31 Andrew van der Stock:** I honestly, it could be a fad. It could be something that is transformative and changes the world. We do have a few OWASP projects that are dealing with generative AI, like the OWASP Top 10 LLM. You'd be surprised at the number of people at RSA that actually came to me and said, hey, that was a fantastic top 10. So great work to the guys who were involved with that. But no more insecure software is so audacious, and we need to actually make sure that we set ourselves up for the next 20 years. And if that involves AI, great. If that doesn't involve AI, well, we've still got these huge areas like architecture, building software securely, making sure that we're in front of the developers at all times. One of the things that I've been working on recently is actually trying to make sure that we're actually in front of the developer community. We're doing articles with dev.to. We're making sure that we reach out. We went to PyCon recently. We really need to get more developers involved. There are 100 developers for every application security developer. And so we don't know the correct answer to how to develop software correctly. What we do know is this is how you can actually break software. How do we help each other and have a really constructive conversation with developers? **45:59 Robert Hurlbut:** Great. Last question is, what's your top book recommendation and why do you find it valuable? **46:10 Andrew van der Stock:** I'm actually gonna go to a nonfiction book, The Crow Road by Iain Banks. is one of my favorite books. Um, I did, you can't see it. It's actually over there at the moment. Um, but it is a fantastic book that opens up. I'm not giving away the plot at all. Um, with his grandmother blowing up in a funeral home. Um, they forgot to take the pacemaker out. And it just gets better and better and better and better. The, the book is the most amazing book. It's a, it's a transformative book and it, it'll actually make you a fan of his writing. Unfortunately, he passed away way too early. And so he's only left us with about 25 books, but he's written award-winning literature, Crow Road is literature, and award-winning science fiction. I actually do think his literature is actually better than his science fiction. That's a controversial topic. But, you know, my favorite technical book would actually have to be the— have you ever seen the books by Edward Tufte? **47:29 Robert Hurlbut:** No. **47:31 Andrew van der Stock:** Oh my goodness. Wow. These are fantastic. This is a video podcast. This is just one of them. There's 5 books in total. And it's how to explain technical things in visual form. He's the person who created sparklines. He's the person who created Chart Junk, like literally get rid of 3D graphs in your Excel spreadsheets because they're garbage. like hot garbage and then explains exactly how that led to the Challenger disaster. So he has an entire chapter who's involved in the Challenger investigation, and it's because the information that was presented to NASA management was completely misleading, but absolutely 100% technically accurate. because the visual representation was just awful. And it killed people because, and, you know, set back a massive program because people were just misusing data. And back then you weren't doing it in computers, you were doing it with pencil and paper and whatnot. And he just showed that if Here is the simplest possible graph that says you should not have launched that day. And it's literally just, it's like, here's the launches and here's the number of failures that have been observed of O-ring seals. And here's where you are planning to launch. No, don't launch that day. It's literally one graph and it would've said to anybody who could actually have eyeballs, don't launch. So Edward Tufte. **49:28 Chris Romeo:** Edward Tufte. **49:29 Andrew van der Stock:** He is an amazing, amazing guy. Lots and lots of opinions, but they're valid opinions. And honestly, anybody who comes up with sparklines and has great ideas like that needs to be listened to. His books are amazing. They're They actually have foldouts. One of them is actually the Napoleon march to Moscow and back. And it shows how he lost his soldiers along the way from dysentery and disease and things like that. And the actual battle was inconsequential. He lost the battle because of the way that he had logistics. And it was so easily shown in this graph. **50:09 Chris Romeo:** Very cool. **50:11 Robert Hurlbut:** Yeah. **50:12 Chris Romeo:** Andrew, what's, how about a key takeaway then? or a call to action? I think I know where you're going to go with this, but I'll throw it out anyway. Like, what's, what's your call to action coming out of this conversation? **50:22 Andrew van der Stock:** I would entirely love for you to give us data. If you have a collection of CWE data that is easily extractable, doesn't matter the size of the contribution. If you've got 10 apps, if you've got 100,000 apps, we'd love to talk to you. I'll be in Lisbon next week for AppSecEU. Happy to talk to you at that point. I'm available on OWASP Slack and easily available through various means, including X, I believe it's called this week. Just look for Vander AJ. **51:02 Chris Romeo:** Very cool. Well, Andrew, thank you for all you do for the OWASP universe. Not only do you run various projects, but you're the executive director, which we didn't even really mention. We just thought people already knew it, but I'll say it anyway. So thank you for all you do for the community and for pushing things forward. We appreciate you and the rest of the team. I know there's a team behind the scenes at OWASP that's part of the foundation that makes it all come together. So thank you to them as well. **51:28 Robert Hurlbut:** Thank you. **51:29 Chris Romeo:** We look forward to seeing this 2024 edition, and I'm just hoping that there's a, there's a Chris Romeo Item on the list in the top 10. **51:36 Robert Hurlbut:** Yeah. **51:38 Andrew van der Stock:** Well, submit data. **51:39 Chris Romeo:** No, no. I just want you to name one after me. That's what I'm saying. I want to know. **51:43 Robert Hurlbut:** I want— The Chris Romeo number. **51:45 Chris Romeo:** Oh, thanks, Andrew. **51:49 Andrew van der Stock:** No worries. Thank you. --- Source: https://appsecpodcast.com/andrew-van-der-stock-the-new-owasp-top-ten/