Skip to content
AppSec PodcastThe Application Security Podcast — home
29 min

Chris and Robert -- #AppSec Recommendations

With Chris Romeo and Robert Hurlbut

Threat Modeling

Which books, sites, conferences, and communities are genuinely useful for learning application security? Chris and Robert compare their personal recommendations and explain what each resource offers.

Listen

Audio hosted by Buzzsprout. Nothing loads until you press play.

Episode chapters · 15 chapters
  1. 00:00Chris and Robert’s AppSec recommendationsAudio
  2. 01:25Building a balanced learning listAudio
  3. 02:47Foundational design and architecture booksAudio
  4. 04:36Secure development booksAudio
  5. 06:03Core software securityAudio

About this episode

Which books, sites, conferences, and communities are genuinely useful for learning application security? Chris and Robert compare their personal recommendations and explain what each resource offers. Their list moves from foundational software design and architecture books to secure development, threat modeling, web security, DevOps, checklists, blogs, recorded talks, and local conferences. They discuss learning from Irongeek and YouTube, following practitioners such as Troy Hunt, and using gatherings like BSides, SOURCE, and Black Hat to build relationships as well as technical knowledge. The episode is not a ranked shopping list; it is a guide to assembling a balanced learning practice from books, current writing, hands-on material, video, and community participation.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Chris Romeo and Robert Hurlbut:
Chris Romeo on LinkedIn
Robert Hurlbut on LinkedIn

Resources
Agile Application Security: Enabling Security in a Continuous Delivery Pipeline
Iron Geek
The DevOps Handbook
Threat Modeling: Designing for Security
The Tangled Web: A Guide to Securing Modern Web Applications
Start with Why: How Great Leaders Inspire Everyone to Take Action
Books by Martin Fowler
Troy Hunt
Have I Been Pwned
Google Alerts
The Checklist Manifesto: How to Get Things Right
BSides
Black Hat

Actionable

From this conversation

  1. Build a foundation in software architecture

    Anything that's related to the Martin Fowler series is good to get a good foundation on architecture in general.

    1:49
  2. Watch recorded security conference talks

    YouTube has a lot of security content, some from the Iron Geek site, but even beyond that, some of the conferences do their own recordings.

    7:35
  3. Learn DevOps fundamentals

    If you're a security professional and/or you're a developer who's new to security and you somehow at this stage don't have a good grasp of DevOps, this is a real nice book to take you through what is DevOps.

    8:30
  4. Network at security conferences

    Go to the social events, hang out, walk up to somebody.

    17:35
  5. Set alerts for security topics

    You set up alerts on keywords.

    20:29
Transcript · 29 min conversation

0:00Chris RomeoHey folks, on this episode of the Application Security Podcast, Robert and I talk about our favorite recommendations for application security. They could be books, they could be conferences, they could be websites. We throw all our best recommendations for resources at you, so we hope you enjoy. The Application Security Podcast. Here we go. Hey folks, welcome to the Application Security Podcast. This is season 3, episode 8, and on today's podcast, Robert and I are joined by— Nobody. It's just us today, and we're going to talk about our favorite application security recommendations. So, Robert, probably like me, you probably get asked for recommendations all the time, right?

1:14Robert HurlbutYeah, occasionally I do. Somebody wants to know, you know, what's, what's a good account to follow? What's, what's a good resource out there? So yeah, it comes in occasionally.

1:25Chris RomeoYeah, so we thought what we'd do today is we each made a list of some of our top recommendations, and we're just going to go back and forth down this list and explain each of these items. And if the other person hasn't heard about it, maybe we'll argue about it a little bit, who knows. But with that, I'd say, Robert, let's dive in. So, what is your first— the first item on your recommendation list for folks?

1:49Robert HurlbutWell, you know, I'm coming from a development background in architecture and so on. So, in terms of what I like to recommend for people if they're, if they're wanting to get into application security in particular is that, uh, first of all, they, you know, look at some, some good books out there or good resources out there on either application development and architecture as well as application security. And so in terms of books or resources that I still like to follow, for example, is maybe Martin Fowler He wrote quite a few books on architecture in general. Just getting a good foundation in architecture is one I still recommend. Anything that's related to the Martin Fowler series is really good to get a good foundation on architecture in general.

2:47Chris RomeoThat's not a security— these aren't security-specific books, though. These are foundational books on how to do design and how to do architecture. From a software perspective in general?

2:57Robert HurlbutExactly, exactly. Now, that's if somebody is looking to that slant, so they may be coming from a development background or architecture background, and so I recommend that as at least something to ground them, to get a good foundation to start with.

3:14Chris RomeoI have never seen that book series, so I'm gonna go take a look at it as well here. Maybe I need to learn a little bit about architecture.

3:22Robert HurlbutYou know, again, if you're a developer and you want to continue to develop and continue to think about architecture, security architecture in particular, I think it's a good foundation.

3:33Chris RomeoOkay. So, my first recommendation, number 1 on my list, is also a book. And this is a book called Agile Application Security: Enabling Security in a Continuous Delivery Pipeline. So, this book is by Laura Bell, Michael Brunton-Spall, Rich Smith, Jim Byrdes, kind of a team effort to put this book together. And Laura Bell's going to be on the podcast here in a few months. And this is a relatively new book. It just came out, I believe it came out later in 2017. It is spectacular in describing how do you take agile and people that are writing software in an agile perspective, and how do you, how do you connect application security both from an agile perspective And it even kind of brushes up against the edge of DevOps as well because there's a lot of crossover there. But really good stuff. They talk about all kinds of things like security testing and secure coding and how do all these things fit in nicely into the whole idea of agile sprint. So that's my number one go-to, Robert.

4:36Robert HurlbutExcellent. I do like that book as well. I remember seeing Laura and others who were working on that and was so eager to get a copy when it came out. It kind of reminds me of another couple of books that I like to recommend as well. Of course, if you go back to my origin story way, way back when in the early days of our podcast, I mentioned that the first book I ever read was— that got me into application security in general was Building Security In by Gary McGraw.

5:06Chris RomeoYep.

5:06Robert HurlbutI still like that book. I still recommend it. I think it's a great starter place, but, you know, there's some things that have been more current, more recent. One I also like to recommend is another book called Core Software Security: Security at the Source, and James Ransom, Anmol Mehta, I think I said it right.

5:29Chris RomeoMisra, yeah.

5:30Robert HurlbutMisra, thank you. Excellent book. Like the one by Laura Bell and others, it also covers a lot of areas about application security, security and building it into the software development lifecycle. I know there's also a great chapter in there on Agile and application security by Brooke Schoenfeld, who we've had on the program as well. But anyway, in general, I really like this book and I recommended this even recently. I was at a conference recently and mentioned this book to someone to take a look at as well.

6:03Chris RomeoYeah, I definitely— I'd forgotten about that book. You kind of reminded me of it. So I used to work with Jim Ransom back many, many years ago at a company called Exodus. I actually saw him at an event a couple years ago right when that book was coming out, and they were actually talking about it. So yeah, great recommendation there on that, the Jim Ransom and Mr. Misra's book there. So number 2 on my list, I'm gonna switch gears, and I'm not gonna, I'm not gonna talk about a book now. I'm gonna talk about a website. And this website is called Iron Geek, and it belongs to a gentleman by the name of Adrian Crenshaw. And what Adrian does is he travels around the United States and he goes to various BSides conferences and He goes to a lot of the more open security conferences and he records all the different sessions there. Sometimes they record multi-track, so there's 2 recordings happening at the same time. And then he posts all those talks on YouTube. And so I love this website because I hear from people all the time. They say, hey, I wanna go to an application security conference. I wanna go to some type of security conference. We don't have budget. Nobody will send me. They won't pay for travel. What Adrian's website here, this Iron Geek website, brings a lot of the big security conferences directly to you, and it's all free. He posts this all on YouTube. He does this all out of, uh, all out of his desire to improve the community, so he doesn't charge anything for it. So it's a great resource to be able to listen and hear a lot of the talks that are happening at conferences without actually doing any of the travel involved as well. So, so that's my number 2, Robert.

7:35Robert HurlbutOkay, great. I like that as well. I like that source. I've used it. I'll go a little further than that though, just YouTube in general. YouTube has a lot of security content, some from the Iron Geek site, but also even beyond that, some of the conferences do their own recordings.

7:53Chris RomeoYeah, like OWASP. So OWASP, great. I just— you just made me think of the OWASP AppSec USA postings on the OWASP channel on YouTube.

8:01Robert HurlbutRight, right. So I could go to several of those. I've subscribed to several of those in the individual, like OWASP and so forth, so that I can get those that may not be covered by Iron Geek because unfortunately it doesn't get to every one of those conferences. And like I said, some of them record their own, manage their own, and push them out there on YouTube. So that's another one of my go-tos, is just see what's the latest on, on YouTube for some of these conferences as well.

8:27Chris RomeoYeah, so that was your number 3?

8:29Robert HurlbutThat's it.

8:30Chris RomeoAll right, I'll give you my number 3. I'm gonna go back to the library. Well, I don't think anybody actually goes to libraries anymore, but It kind of fit with the whole book theme. This book is called The DevOps Handbook: How to Create World-Class Agility, Reliability, and Security in Technology Organizations. It's by a couple of heavyweights in the world of DevOps: Gene Kim, Jez Humble, Patrick DeBois, John Willis. If you're a security professional and/or you're a developer who's new to security and you somehow at this stage don't have a good grasp of DevOps, this is a real nice book to take you through what is DevOps. It's not really a security book per se. They do spend a chapter talking about security and DevOps and how they— how those 2 things kind of fit together. But it's really more of a book about how do you do DevOps as a development organization. And so I think that's something that everybody's got to get an appreciation for here. So I really like this book and I recommend it. What do you got for number 4?

9:25Robert HurlbutWell, since my focus is on threat modeling, there are only a few books out there on threat modeling. Of course, we've had all of them essentially on the show. Adam Szostak has a book on threat modeling. Brooke Schoenfeld, as I mentioned a moment ago, he also has a book on threat modeling. We also have— we don't have— we've never had Marco Moreno, but Tony UV, the two of them wrote a book on threat modeling as well, Risk Modeling. And so, you know, those are the books I continue to advise and recommend for if you're wanting to get into threat modeling. There's not very much out there. But those are the ones you start with and take a look at. Yeah.

10:04Chris RomeoAnd that's Threat Modeling: Designing for Security by Mr. Adam Szostak, a previous podcast guest. That was on my list as well. It was coming up here pretty quick. So yeah, I definitely agree with those. I like what all of those guys have to say about threat modeling. And the nice thing is they don't all recommend threat modeling the same way. All 3 of those those individuals come at threat modeling from a slightly different perspective. So it's good to look at all those resources and try and figure out kind of which methodology really fits in with your organization and kind of the way you think. But just know there are some options out there.

10:42Robert HurlbutCorrect.

10:43Chris RomeoSo my number 4 is a website, and it's going to be kind of a crazy— this is kind of a crazy pick. You know, when you get to the number 4 spot in any type of a draft or anything, you get take kind of a crazy pick and, and take a little bit of a chance with a recommendation here. But of all places, one of my favorite websites for security news is a site called The Register. And so it's The Register. It's actually a UK, United Kingdom, uh, news publication. But I just love the fact that they— I guess I just like British humor. And they really have— they take security news and they provide some real cheeky humor to it. as well in their headlines and things, and they report the news as well. So for me, it's a good source to get news about vulnerabilities that have hit, big stories in the security world, but I know I'm gonna get it with a little bit of humor kind of mixed into it. And yeah, it makes me smile sometimes early in the morning. So I recommend The Register, which is a website in the UK that provides security news. What are you thinking for number 5?

11:44Robert HurlbutWell, if we talk about websites, I guess mine is partly because I know him personally and I've worked with him, but also just I like his detailed write-ups, and that's probably Troy Hunt. I really do enjoy some of the things he's written and some of— like I said, some of his deep dives. And so I like to see what he's doing and kind of keep up with that a little bit occasionally.

12:07Chris RomeoOkay, so his blog, you're talking about his blog specifically?

12:10Robert HurlbutHis blog. He also has a Twitter account, of course, but a lot of those Twitter posts point to his blog. So yeah, essentially his blog. Okay.

12:17Chris RomeoYeah. And he's the— Troy Hunt's the guy behind haveibeenpwned.com, which is a place where he captures and stores many of the different password-based data breaches and provides a search, the ability for you to search to see, is your account or web or email address going to show up in any of the major data breaches that happen? So that's a big thing he does for the community. And I guess I'll add that recommendation to know about that resource. I'll pile that right on top of yours just in recommending Troy in general, because that's a great site for security pros to understand. Because I've interacted with some folks who are non-security people who are like, what is this Have I Been PYNED site thing here that I'm supposed to look at? So more than just security people even know about Troy and his work.

13:04Robert HurlbutAbsolutely.

13:05Chris RomeoSo in my number 5 spot, I've got a website that's kind of like a blog, but it's really more of a news source for all things technology. And disclaimer, cards on the table here, I do write some articles for this site. It's a site called TechBeacon. But I do enjoy consuming a lot of the stuff that gets written there that I have nothing to do with because they provide a nice breakdown of a number of cross-functional kind of areas. They focus on application security in some degrees. They do some things on DevOps. They do some things things on kind of general developer things. They have posts about what are the most— what are the best conferences for a developer to go to, for a security person to go to. So they have a lot of interesting kind of takes on the world of technology. And so I just enjoy— I enjoy both being able to write for them and also being able to read a lot of the stuff that other people are writing on that platform. So that's my number 5. What's your number 6, Robert?

13:58Robert HurlbutWell, I, I find that You know, conferences— you mentioned a little bit about conferences there and finding the right ones to go to, the best ones to go to for developer security or application security. I have a few that I can recommend, or at least that I like in particular. I definitely like, of course, the OWASP conferences, the AppSec USA, the various locations that they have those each year. I really enjoy that. My other go-to one is AppSec Cali. In California in January. It's perfect in, in nice weather and in the winter, in the middle of winter. It's great. And then also any of the BSides are pretty good. I like the local ones that are, you know, pretty, uh, pretty good to go to. And Source conferences, I enjoy those. Those are pretty intimate as well in terms of being able to have great discussions in the sessions as well as outside the sessions. So those are some of my, my go-to. Of course, also Security Summer Camp, I can't forget that. It's not for everybody, you know. Black Hat, for example, this year is having a new SDL track, which is a great addition. It's not always focused on application security per se, but I think they're starting to look at it a little bit more, that they really need to think about it.

15:19Chris RomeoYeah, and I'll provide a couple of conference recommendations on top of that. I second everything that you shared here as far as good places to check out. I'll second the recommendation for the Source Conference. I'm actually on my way out to the new— kind of Source is doing a Southwest conference in Mesa, Arizona next week. I'll actually be on my way out there to speak and hang out and meet a lot of new people who you might not meet in the kind of major conferences that are happening. I'll also add another one that happens in Detroit, Michigan, and this is not just because I'm from Michigan and I like to go back there. It's also— it's a conference called Converge, Robert. Actually, you and I, I think we met face-to-face, maybe.

16:03Robert HurlbutWe did.

16:03Chris RomeoWe met the first time at an OWASP conference, but then we got a chance to connect, and I think we actually talked about this, creating this podcast while we were at Converge. I believe it was, right? Watching a session, but The nice thing, and I'll say this about Converge, I love this conference, that Converge tailors to all of the different audiences that exist in the world of security, meaning they have kind of an information security focus, they have an application security focus, and a kind of a hacker track kind of focus. But then they're always thinking about how do we connect these groups together and get them to communicate. And so I'm a big fan of Converge. I'm bummed I'm gonna have to miss it this year because I'm doing something else during that time, but, but I highly recommend visiting Detroit and being a part of Converge, just a great overall conference.

16:44Robert HurlbutOne other thing I might wanna add about conferences, sometimes I hear, you know, why go to a conference? Why care? One of the things about some of these conferences, especially the local ones, they're not as expensive. That's one great thing. But secondly, it gets you in touch with other people that are in the community, and the community, I think, Even though there are more and more people that are being added, it's still relatively small, so it's intimate. You can talk to almost anyone, and most people are responsive. I think it's just a great way to network with people and find out what's going on. That's what I always recommend in terms of people saying, why should I go to a conference? Here's a great way to meet people face-to-face.

17:35Chris RomeoYeah, you're going to have to step out of your comfort zone though. That's just something I learned a number of years ago is that people, we actually enjoy— I enjoy meeting people at conferences. I enjoy when somebody comes up and says, hey, I listen to the podcast and hey, I just wanted to say hi. I mean, that's really cool for me. I love to ask them questions about what things do you want to hear in future episodes and and really, you know, get a chance to connect with them and understand where they're coming from. So yeah, you have to— I mean, conferences— don't just go to a conference thinking, hey, I'm just here to see the talks. The talks can be good a lot of times, and they're a good place to really get some new ideas and things, but really go to conferences to meet people, to talk to people. Go to the social events, hang out, walk up to somebody. You know, one of my favorite things to do is I'll walk up to somebody who's kind of standing off to the side by themselves and just say hi. Hey, my name's Chris. What are you, what are you doing? You know, what are you doing here? What's, uh, what drew you to this conference? Um, and kind of try to, try to connect with people who are, you know, a little bit maybe off to the side and, and aren't fully connected with people yet. But totally agree with you, Robert, there on the, uh, the networking side. Um, I'm gonna go give you another one here. Here's another book. This is an oldie but a goodie. I don't know if you've read this one, Robert, but it's a book called The Tangled Web A Guide to Securing Modern Web Applications by Michael Zalewski. And this is, this is getting a little bit old. It's been, it's a little bit dated. But the thing I love about this book is it really explains to somebody like me when I first picked it up who didn't really have a great understanding a number of years ago about how web applications and how the web in general actually works behind the scenes. Not only do they cover things like cross-site scripting, SQL injection, and give you some breakdowns, but they start with laying the foundation of how do web applications work, what is HTML, what is CSS, what is JavaScript, what are all the things, what are the frameworks, what are all the things that fit together. So if you're not a developer, if you're coming at this web app security thing as someone who doesn't have a development background, I found this as a nice foundational resource to help me really gain an appreciation for how the web actually works.

19:45Robert HurlbutYeah, great resource. Actually, that's always on my list whenever I do any kind of web security talks. That's always on my list as well of references, even though, like I said, it's getting a little older. You know, there are some things that are new, but it's still relevant, I think. So yeah, great recommendation.

20:02Chris RomeoMichael Zalewski, if for some crazy reason you're listening to this, please update your book. We'd love to buy more copies. And I used to give this out when I had I worked in that large technology company. I used to have a stack of these I would hand out at different events and things because the information was so good. All right. What's your— I think we're up to— is this your 8th or your 7th? I don't know. I've lost count, but—

20:25Robert HurlbutI lost count.

20:26Chris RomeoDoesn't really matter. What's your next one you got here?

20:29Robert HurlbutOkay. Well, I'm going to do a little bit of a shift here. And in terms of thinking about current events, I know you mentioned the Register as one way to find out some information. One way that I do this, and it may or may not work for others, but what really works for me is to use what's called Google Alerts. There might be some other services that are similar, but this is the one I use, Google Alerts. Basically, you go to this site. It's essentially a sub-site of their— or subfolder of their domain. You set up alerts on keywords. And so I put in, for example, application security, threat modeling, data security, you know, artificial intelligence, whatever, any kinds of things that I am interested in learning about and finding out what is current. What are the current articles out there? What is happening? If somebody has written about it and it has been cataloged in some way, it is going to come across my email and I will take a look. And I sometimes will set up you know, once a day or a couple of them once a week or something like that, and just summarize a bunch of the findings so that I don't have to go out and try to find what's new. It actually comes to me.

21:40Chris RomeoHmm.

21:40Robert HurlbutAnd so that way, you know, I have the latest and see what's going on. And that's great for just, you know, finding out the latest papers, latest information. Now, it's not going to catch everything, but it does catch quite a bit. And so I'll know, you know, sometimes sooner than most about what's the latest so that I have, you know, at least an idea of what's going on. So that's one thing I've used. So what's—

22:03Chris RomeoI guess my thought on that is, is the noise level— is it real noisy? Like, how do you— do you turn it down somehow so that you don't get like thousands of entries a day? Or what's the— what is the noise level that you kind of are dealing with?

22:18Robert HurlbutIt can be. I mean, what you have to do is then determine if it says, say for example, artificial intelligence, there's potentially a lot of stuff in that. If there's some area in there that you want to focus more on, or if you want to, yeah, if you want to filter, you can go into the alerts setup and, and do a little bit of tweaking if you want. Or again, you can get the email and decide, hey, I don't want this, and, or, you know, I don't want anymore, I'm done, or something like that, and you can go tweak it as well. So, mileage may vary on that one, but that's one that's been useful for me. Okay.

22:52Chris RomeoYeah, no, I use that, I guess, from a vain perspective. I've got my name and I just want to know if somebody publishes something about me or says something about me, I want it to pop up and let me know so that I can potentially defend myself or send them a, hey, thanks for mentioning me on whatever that was. So, I'm going to come back to a book for— this is the final one I have on my list. This is a book, but this is a book outside the world of security. So this book is by a gentleman by Simon— named Simon Sinek, and his— this book is called Start with Why: How Great Leaders Inspire Everyone to Take Action. And so I, I found this concept a number of years ago, and I read the book, and I was like, this, this guy is really on to something here. And it's really more of a general book about how do you convince people to do something that they don't want to do, which is one of the problems that I was dealing with a few years ago in a big technology company, trying to get everybody excited about product security and secure development lifecycle and all these different types of things. And so, I learned a lot from this book. And in general, the concept is start with why. We always start with what whenever we go at developers and we tell them, hey, you need to do threat modeling. And then we start answering the what. We tell them what threat modeling is. they don't care what threat modeling is until they understand why they need to threat model. So Simon wrote a whole book about this, great resource. The other recommendation I'll make about books in general here, and this is an example of— listen, read and read outside of our discipline, folks. Don't, don't just live in the world of application security and read books that are security-focused. You got to have a broader perspective because there's much more to the world when you're managing a career than just the bits and bytes that happen in the world of security. So extend your reach, read things that are outside of your comfort zone, outside of your core disciplines, and you will really learn some new ideas that you can apply.

24:49Robert HurlbutYeah, with that in mind, there's another book, Checklist Manifesto, that is really interesting in terms of thinking through that. I've heard a few people that have recommended it. Just recently I heard somebody recommend it again. in an application security conference where they said, hey, you should look at this book, and it's something outside of what we do, but it's actually useful and interesting. And so that was one I've also been thinking about as well that would be a good recommendation for people.

25:21Chris RomeoYeah, that's a— that is another— I've heard that book recommended as well, and that's another good one. I haven't read it, so now I'm going to definitely go read it. Because this is multiple times people have recommended it to me. So Robert, you got anything else on your list or have we exhausted all of your recommendations?

25:39Robert HurlbutI think mostly exhausted my recommendations. I mean, I guess a general recommendation I have is I used to follow a lot more on blogs. I used to have a blog that I— I mean, I still do, but I don't really update it as much. And I find that a lot of people don't update theirs as much either. What I find more than anything else is that people are updating Twitter. They go out to Twitter and they write there. Now, of course, some accounts are more noise than signal, so you have to— your mileage may vary on some of those. But I find that certain people that I do like to follow are, I think, give some good information, and it helps me to kind of think about where they are. and what's going on. Of course, our friend Jim Manico, definitely follow what he's saying because I find that Jim, he's definitely great in OWASP for many years, but beyond that, he likes to point out other things that are going on. He's been a good resource for me and a few others. Twitter is where I, I guess, hang out a lot and see what's going on. Basically, following different security people that I want to see what they're doing in different areas that I'm interested in is one of my recommendations generally.

27:01Chris RomeoYeah, I think that's another recommendation I totally agree with. Unfortunately, I found nothing to argue with you about on this episode, but I totally agree with the Twitter thing. I fought Twitter for years because I didn't understand it, and then as soon as I figured it out, I was like, oh, now this is why everybody does this. So, yeah, you definitely have to have a Twitter account. Don't be afraid to message, to reach out to people on Twitter. I mean, half of the podcast interviews we do here start as open tweets to somebody saying, hey, want to be on the podcast to talk about something that you love? And then, we end up booking them as guests and bringing them on. So, with that, I think that's enough time today on our recommendations. offer this final recommendation, and that is please check the show notes for this episode because there are lots of different— we've got lots of links and lots of things we talked about. We'll have all the links to all these books and websites and everything in the show notes so that you can go ahead and take those and be able to kind of find these things and use them. So, we hope these recommendations are useful to you. Please hit us up on Twitter and let us know what you think or offer your recommendations back to us. We'll add your stuff to our list. We thank you for listening. Thanks for listening to the Application Security Podcast. If you enjoy the podcast, please do us a favor and visit the iTunes Store and give us a 5-star rating. Our intro music is 8-Bit Kung Fu by Born and TJ, and the outro is Southern Delight by Stefan Cartenberg. You can find us on Twitter @AppSecPodcast or on the web at www.appsecpodcast.org.

5,361 words · transcript by assemblyai

More on Threat Modeling

View all episodes →

Get Reasonable AppSec: new episodes and useful picks from the archive.