--- title: "Chris and Robert -- Introductions and why #AppSec?" url: https://appsecpodcast.com/chris-and-robert-introductions-and-why-appsec/ date: 2016-09-13 duration_seconds: 1882 guests: ["Chris Romeo", "Robert Hurlbut"] topics: ["OWASP Top 10", "Secure Development"] audio: https://www.buzzsprout.com/1730684/episodes/8122739-chris-and-robert-introductions-and-why-appsec.mp3 transcript: true --- # Chris and Robert -- Introductions and why #AppSec? *September 13, 2016 · 31 min* with [Chris Romeo](https://appsecpodcast.com/guests/chris-romeo/), [Robert Hurlbut](https://appsecpodcast.com/guests/robert-hurlbut/) on [OWASP Top 10](https://appsecpodcast.com/topics/owasp-top-10/), [Secure Development](https://appsecpodcast.com/topics/secure-development/) [Audio](https://www.buzzsprout.com/1730684/episodes/8122739-chris-and-robert-introductions-and-why-appsec.mp3) ## Show notes In the inaugural episode of the Application Security Podcast, Chris Romeo and Robert Hurlbut introduce themselves, trace the experiences that brought them into security, and establish the question the show will keep answering: what is application security, and why should builders care? They walk through security requirements, threat modeling, secure development, testing, and release as connected parts of the software lifecycle. The conversation distinguishes application security from information security and the broader cybersecurity label, then makes the business case for treating AppSec as foundational work—a customer expectation and a worthwhile investment rather than optional overhead, driven by people and supported by tools. Connect with Chris and Robert: → [Chris Romeo on LinkedIn](https://www.linkedin.com/in/chrisromeo-appsec) → [Robert Hurlbut on LinkedIn](https://www.linkedin.com/in/roberthurlbut) Mentioned in this episode: → [Software Security: Building Security In](https://www.informit.com/store/software-security-building-security-in-9780321356703) → [OWASP Top 10](https://owasp.org/www-project-top-ten/) → [Gary McGraw](https://www.garymcgraw.com/) → [Robert Hurlbut](https://twitter.com/RobertHurlbut) Chapters: 00:00 Welcome to the Application Security Podcast 02:21 Chris and Robert’s security origin stories 06:31 Defining application security 09:05 Security requirements in the development lifecycle 10:25 Design and threat modeling 11:17 Secure development and testing 13:35 Release and operational feedback 15:53 Building security in 16:56 Application security vs. information security 20:31 What does cybersecurity mean? 22:59 Why organizations need application security 24:53 Applications as the path to valuable data 27:24 The OWASP Top 10 as a starting point 28:23 Final thoughts and the future of the field ## Transcript *5,539 words · assemblyai* **0:06 Chris Romeo:** The Application Security Podcast. Here we go. Welcome to the Application Security Podcast. I am one of your hosts, Chris Romeo, and I want to welcome you to our inaugural episode of this new podcast. And we are about reaching new people, explaining the details, and leaving the echo chamber in the dust. And our focus is application security. We want to educate people about what these— what application security is. We want to reach new people, those that don't necessarily have a background in it, and we want to teach them the details and, you know, kind of get out of that echo chamber. So, you know, our concept for the show is we want this to be security for developers, for testers, for managers, for product people, salespeople, even marketing people that are out there that want to have more of an understanding about this idea of application security. And so we'll do that by explaining the details and breaking them down in a way that anybody can understand. So you don't have to be part of the security elite to be a consumer of this podcast. You just have to have an interest in security, and we'll help bring you along the way. We also want to get outside of the security echo chamber. So, the echo chamber, this is the idea that security people just get together and talk to each other and constantly say the same things over and over again. So, we want to break out of that. We want to reach those developers and testers and people that build stuff and help them understand application security. And one of the other things that we'll do is, you know, we'll talk to interesting people that are out there in the world of application security. We'll deconstruct what makes them successful and the tools that they build and the processes and the things that they know about, and we'll ask them to share those insights and that knowledge that they have with you, our audience. And so I am with Robert Hurlbut, who is the co-host of the Application Security Podcast. And Robert, how are you doing today? **2:19 Robert Hurlbut:** Great. Chris, how about yourself? **2:21 Chris Romeo:** Oh, I can't complain. And I think our audience would be very well served if we started out here by sharing our superhero origin stories. So every comic book starts in episode 1 with the origin story. How did the hero— where did they come from? How'd they get into this? So Robert, tell us a little bit about how you got into application security. **2:41 Robert Hurlbut:** Sure. Well, actually, I originally am a developer and I still do some development occasionally. I've been doing that for probably 20 to 30 years now. About 12 years ago though, I was really interested— I was already interested in security in terms of some infrastructure, some IT security, and all those kinds of things. I knew that was there, firewalls, all that stuff, when I was building applications, but I came across a book that happened to come out about that time by Gary McGraw on Building Security In. I read that and it was such an eye-opening thing to say, oh, we really need to think about the security in the application. Now, it wasn't that we never thought about putting a password on a webpage or anything like that, but his book was interesting in terms of talking about the full picture of how does application security or thinking about security as you're developing software come into play throughout the entire lifecycle of developing the software and testing it and all those things. And so it was good. And then from there, I just continued to be more and more interested in it and talk about it at conferences, user groups, things like that, and helping clients more and more with thinking about application security. **4:00 Chris Romeo:** Yeah, and I love the fact that you made the transition from developer to security person because I think that's such a crucial path for people. A lot of times people come from the— they get into security, they come from the system administration world or something like that, and they don't have that development background. That's great that you have that as a foundation of what you do. **4:23 Robert Hurlbut:** Yeah, I agree. In fact, that's one thing I think has really helped a lot, especially when I'm talking to developers, is because I've been there. I know what they're experiencing. I know the the ins and outs, and so I can talk about that as well as how do I think about security if I'm a developer, and I can relate. **4:43 Chris Romeo:** Yeah, you speak their language, so that's definitely a very cool thing. And, you know, I kind of got into the world of security on accident in that right out of college, I left my first job and went down to Washington, D.C. to look for a new job, and I was at a job fair, and I'm standing in line with about 100 behind about 100 people thinking this is going to take hundreds of hours for me to actually talk to anybody. And I look over to the left and I see a guy sitting in a room all by himself typing on his laptop. And he's got this— his company name's on the door, so I thought, you know what? I'm just going to go over here and talk to this guy and see what— just kill some time here because I'm going to be here all day waiting to talk to the recruiters at the front of this event. And he and I, we got talking and he said they had a boutique security consulting firm, you know, before security was very cool. This is going back, you know, almost 20 years. And he said, you know, we're looking for a system administrator. Maybe we could have you come in and, you know, take care of our computers and networks, and we'll see if we can grow you into something else. And so I had the opportunity to begin as a system administrator, but then also grow into, you know, a security professional because I had a lot of great people that were mentoring me and were teaching me. And that company was such a great experience because everybody was about mentoring and teaching other people, and there was There was no real kind of attitude or anything that went with it. It was just about how do we bring everybody forward. **6:08 Robert Hurlbut:** Great. Wow. That's a really nice story. I like that. **6:11 Chris Romeo:** Yeah, thanks. It's been a great path for me to kind of get through that. I think you and I, we have a unique perspective here because I'm coming from the world of system administration, you're coming from the world of development, and we both have our own perspectives that we can share with our audience. I think that's going to be It should lead to some interesting dialogue as we get further down the road. **6:31 Robert Hurlbut:** Absolutely, definitely. **6:32 Chris Romeo:** So, a couple of things about the Application Security Podcast. We're not people that think that podcasts should run on for 6 hours at a time, so we're going to keep this short. We're going to try to keep each episode to 30 minutes or less. This is going to be family/corporate friendly, so we want you to be able to play this in the car while your kids are riding with you. not have to worry about something inappropriate that we might say. We're not using any scripts here. This is live without a net, which is the most fun type of content to create, but we might stutter and stammer now and again, and that's okay too. We're not really big fans of the news breakdown, so you're not going to get a news breakdown in the world of application security episode from us. We know a lot of other people are doing that. That's okay. That works for them, but for us, we want to focus in on a specific topic and really dive very deeply into it. So Robert, that takes us to our first foundational topic, and we can kind of transition here because if we're going to be the Application Security Podcast, we really need to explain what is application security to our audience. **7:39 Robert Hurlbut:** Yeah, absolutely. So let's talk about that. So when we're thinking about application security, there are several pieces of it, if you will. There's the processes that we talk about, the different things that we do to put in place policies and so forth. Then we also talk about the tools that we may use as well and the techniques in order to write secure software. That's one big aspect of all those kinds of things, policies and tools and techniques. Another is the people. You can't do this in a vacuum. You have to have the people who are involved and understanding from a security perspective what they're doing, the work they're doing and thinking about. You know, that's always important as well. **8:25 Chris Romeo:** Yeah, I see, I see, you know, application security is much more about the people than it is about the, the technology because, you know, you can, you can have the best tools on earth that are supposed to enable people to do things and make better decisions, but if the people don't have the right mindset and the right idea Then, you know, it's almost a losing battle at that point. You've got to start with focusing on the people. **8:50 Robert Hurlbut:** Right, because they're the ones who make the decisions, you know, determining if I have a tool, great, but I need to know how to use the tool. And that's, again, a person doing that, making those decisions and picking the right techniques. Again, that's people doing that. **9:05 Chris Romeo:** Yeah, and you hit on a couple of points there. You know, when I think about the world of application security, I'm very program-driven. That's just kind of my background. I'm very program and process driven, not process to the point of, you know, I don't do process just because, just for the sake of doing process, but, you know, I've seen the benefits, and I think process is so closely tied to the world of application security through this thing that we call secure development lifecycle. And secure development lifecycle is the idea that you want to ship a product that has the best security embedded within it as possible. But to do that, you have to, you have to do different security activities throughout the lifecycle of that product. So when you first start to think about a new product, the average company, what they're going to do is they're going to look at a series of requirements and say, you know, what is the problem we're trying to solve? And then how are we going to write a list of requirements to solve that problem? And so that's the first phase of the secure development lifecycle is how do we add security requirements into that? Robert, I know you're a big fan of the second phase, the design phase. What do you see as the piece of that second phase in design that really ties application security together? **10:25 Robert Hurlbut:** Right. Once you have requirements and you're thinking about, okay, these are features, these are things that we need, how do I put it together? That's, again, where design comes in. I'm a big fan, as you mentioned, of threat modeling, where I'm thinking about the kinds of problems potentially the ways attackers might look at the system and then building accordingly, putting in the controls appropriately and designing that way from the beginning, not later when, oh, okay, we found a problem, we better put it back in, but instead try to think through those things, the security issues and so forth. That's again what threat modeling is doing so that we have a blueprint. Essentially, we're creating a blueprint for what our application is going to be. We haven't written a line of code yet. We're just trying to think about what is the design from a secure perspective of the features I want to put in place and how do we go about that. **11:17 Chris Romeo:** Yeah, and then that takes us into the development phase where, you know, you've gone through the requirements, you've gone through the threat modeling, the secure design, and now you got to start— you got to sit at the keyboard and write some code. And so application security is also You know, the secure coding angle of application security is very important. And when we say secure coding, we're talking about, you know, depending on the language that you're using, there are some things that you do or do not want to do. You know, for example, in the C programming language, you have to be very careful that you don't use the wrong type of routines that don't, you know, properly check the input that's coming into them. You know, with other languages, you might have, you know, frameworks or something that's helping you do that. But the point is you have to be deliberate to ensure that you have a secure coding approach and so that you ensure that you have the best code that comes out of there. I think that's a— the secure coding is a big part of application security as well. Then next, Robert, is the whole idea of testing. How does testing come together in application security? **12:23 Robert Hurlbut:** Right. Once you have your product, you've developed it, you don't want to just ship it out and say, hey, let's just find out what happens. You want to know. beforehand, and you want to be able to do that through testing. That may involve your QA staff or other staff that may try— basically, most testers are going to go through and do your regular business process and flows and so forth, but when you're doing security testing, you're also thinking about some of the misuse cases. You're thinking about, well, what happens if I try to bypass this page? What happens? On a website, for example. Or if I try to change a password. How does that work? So you're basically testing some of these security controls that you designed, that you now developed, and verify, are these doing what we expect? What happens during failure? Did it react the way I expect? Does it give more information than it should? Things like that. That's what you're doing, at least for security testing, is verifying that all the things that we planned, all the things that we developed, are working correctly as best we know in terms of security. **13:35 Chris Romeo:** Yeah, and that takes us to our kind of our final phase of the secure development lifecycle, and that's the release phase where we, you know, we're going to release whatever it is that we, you know, whatever it is that we've been working on here in this process. And, you know, the thing that I think is so important from a release perspective in relation to application security is once we've released the product or the web application or whatever it is we're putting out there, We have to have a capability for if someone finds a problem with the software that we've created, they have to have an interface or a way to talk back into our organization. A lot of times that's referred to as a PSIRT function. Product Security Incident Response Team is what a lot of big companies use these days. But I think that it's crucial to have that piece at the end as well where you are dealing with the release and you're giving people a way to let you know about security problems they might find. And so I think all of those things go together, you know, from the requirements to the design to development to testing to release. All of those things go together to make up that lifecycle of security. But I think of application security as being an umbrella that captures all of those pieces underneath it. **14:53 Robert Hurlbut:** Right, that makes sense to me. I mean, that's what we're trying to do is understand and think about all the potential security issues here and how can we Yeah, how can we capture? And so, you know, the whole lifecycle is all about that. And, you know, I like it. I think it makes sense, especially, like I said, if you're doing all these things focusing on how can we make this product secure all the way through, not at the end. And that's what sometimes happens is that, okay, well, you know, now we built everything, now let's go and run a penetration test or something like that. **15:29 Chris Romeo:** Right. **15:30 Robert Hurlbut:** And if you haven't thought about security from the beginning, then you may find more problems than it's going to be worth trying to go fix. I mean, the resources and all that increase, obviously, as you go further down and haven't addressed these issues. So the whole lifecycle and the whole, you know, looking at application security from the beginning is really important, and just like what you were talking about. **15:53 Chris Romeo:** And that's the idea of building security in. You know, there's a couple different places that that idea has been publicized on the internet over the last decade or even more. But the idea with building security in is that you've got this lifecycle that you're going to go through to create your products. And so it's just going to be cheaper in the long run to build that security, to do those security activities earlier in the process than to wait until after you ship the product out. And then you've discovered there's all these different security problems that exist in it, and now you have to go back to the requirements phase, and you have to go back to design, and you have to fix the problems that exist, but you have to do it at every phase along the way. Whereas if you apply the principles of building security in, you're looking for those security problems during requirements, during design, during the time that you're developing, writing code, and then test is just confirming all the other work that you've done and put forward, you know, into doing that process. **16:55 Robert Hurlbut:** Absolutely, yeah. **16:56 Chris Romeo:** So one of the other things I think we can think about that, you know, those people that are new to application security, they may be confused as to, you know, we have application security, we have information security, we have cybersecurity, that word that everybody in the security profession loves so much. So Robert, from your perspective then, let's start by talking about application security versus information security. And it's not like we're having a football game or soccer match or something. But what is the difference between application security and information security from your perspective? **17:30 Robert Hurlbut:** Well, to me, I think of application security as we've been talking about that product lifecycle where you're building software, you're building a service, you're building something that people are going to be using, and it involves, again, development and things like that. Information security, on the other hand, to me usually relates to IT security, infrastructure security. That may involve what do you have on the outside, the peripheral for your network, for example, appliances, routers, firewalls, things like that. That's what I think of most people when they're thinking about information security. They're thinking about how do I protect the network. When I'm thinking about application security, we're talking about how do I protect my applications or my software and products that I'm delivering. **18:19 Chris Romeo:** Yeah, and one of the distinctions that I make between that is, you know, I used to work at a big tech company for 10 years, and I was part of the application security team there. And at that company, we had a very specific separate information security department. And so I always thought of it like this: the information security department was responsible for protecting the networks and the infrastructure of the company. So they were the guardians of the gate. They watched all the, you know, entry points into the network. They managed the firewalls. They did the incident response, you know, as it related to people trying to attack and, you know, compromise different, you know, services or, you know, servers or workstations or things within the network. But the application security side, our focus was watching over and ensuring that those things that the company built and sold to our customers had security built into them. So we were almost an inward-facing group that was focused on our end customer being those people that are the recipients of the products that our company built. And the information security department was focused on watching that, you know, the overall network. And like you said, all the infrastructure that goes into running the business or running the company, and they're responsible for reducing the risk of those type of networks. **19:42 Robert Hurlbut:** Right, exactly. Just like you said, they're the ones who are focused on information security, protecting the network, making sure that we know what's going across packets, things like that, getting from one place to the other versus the products that are actually running. In fact, we talk about a very good distinction is if you think about a website, I may have a way to get to the website, but then once you're in that website, you're running an application. So to get there and to send my messages and so forth, that's going over the network. 2 different things. And so that's what we're trying to talk about is how do you protect both? One's not more important than the other, but they certainly are both important and we need to focus on both. Yeah. **20:31 Chris Romeo:** And then we have this idea of cybersecurity, right, as this word that gets thrown around all over the place. So when you hear cybersecurity, what do you think of? **20:41 Robert Hurlbut:** Well, I think of marketing. It's a great term, and, you know, everybody thinks about that. At least I think what most people think about is, you know, the attacker out there somewhere in a, you know, some country who's trying to get at everybody, and he's attacking not through, you know, weapons, you know, bullets and so forth, but instead through computers, because that's where we're connected. Everyone's connected by computers, and so they understand Most people understand that that's a new way of attacking, is by using a computer. That's typically related to cybersecurity. **21:19 Chris Romeo:** I think cybersecurity is the word that you hear a lot on television, and you hear a lot of it coming out of Washington, D.C. here in the United States. It's the word that they use to describe nation-states attacking us. Like you said, a lot of it is a marketing kind of term, but we just have to realize it's a term that's here to stay. We're not going to get rid of it. So, I think of cybersecurity as— well, I used to use the word security by itself to mean everything that existed within application security, information security. And I think that given the way that our culture is using this word now, that cybersecurity is now the umbrella that every other, you know, security-related function or job type or, you know, project, they kind of all fit underneath that cybersecurity moniker. **22:14 Robert Hurlbut:** Well, yeah, in fact, this is a funny thing. I've said before, I work in security, and they look at me and say, are you a guard somewhere? So I think that's another part of why we say cybersecurity, because instantly Maybe not everyone would know what information security means, application security means, but cyber, again, they think about computers. They think, oh, okay, or the internet. Is that what you're talking about? Yes. **22:38 Chris Romeo:** Yeah, it's a good point. It's a good way to connect with those people that really don't necessarily understand what it is that we do, but it's okay. It gives them a term in their vocabulary that allows them to understand and define what we do as professionals. So, I'm okay with it. **22:59 Robert Hurlbut:** Right. **22:59 Chris Romeo:** So another question that always comes up when people are talking about application security is, why do I even need to care about this whole application security thing? You know, I mean, we've got firewalls, we've got SSL/TLS, we've got encryption protecting our traffic as it flows back and forth between our users and our servers. You know, why do we need to care about application security? **23:23 Robert Hurlbut:** Well, I think the number one reason why is it's in the news. I think almost every day these days we're hearing something, one more story about a breach of some sort, some kind of data breach, credit cards stolen, personal information stolen or accessed, information about our passwords and our other health information, for example. All kinds of stories like that keep coming out in the news almost to the point where we're almost numb to it because, oh, it's another one, here's another company. But really all of that has to do with typically is application security because again application security is relating to the software that was written and the applications that were written. It also relates to how that software was configured perhaps, or maybe it was a misconfiguration, which happens often. It also relates to the data. All these bits of software, all the applications we use, the websites, the applications we use on our phone, They're collecting data and it's stored somewhere. Anything we put in there into an app is stored somewhere. So there's that data protection issue and privacy about what is it we're doing on the internet or what is it we're doing with our applications. All those things relate to application security. And so that's why it's so important is that we want to be thinking about this and come up with good solutions and ways to try to minimize the problems that we're seeing in the news about security. **24:53 Chris Romeo:** Yeah, and you mentioned data breaches there, and you can't think about a data breach without tying that back to application security because let's face it, data breaches happen for one of two primary reasons. The first primary reason is somebody left a laptop USB drive, external hard drive, printout, you know, something that has data contained within it. They left it in an insecure area like the trunk of their car, the back seat of their car, the hood of their car, wherever they put it, right? So that's one place where it's easy to understand how that data was breached and lost. The other primary reason why data is breached and stolen from databases is because of application security vulnerabilities. You know, you don't really go after a given application. You don't go after a website to try to attack it these days and focus on the infrastructure layer and, you know, are they leaving any ports open? You know, is there any chance that I can find a Telnet open and, you know, Telnet access or even SSH access from the outside to a server, you know, that's in their DMZ, for example? You know, that's not going to exist. The pathway to compromise a web application and to get to that data that is so valuable to the attacker is going to be through using an application layer attack. It's going to be profiling their web application and looking for a vulnerability that they have in that web application and using that to then dump data, you know, pull data out of their database and steal it. **26:28 Robert Hurlbut:** Right. Yeah, there are a lot of common vulnerabilities, as you mentioned, that are known. We've seen there's some lists out there that talk about various vulnerabilities, various problems that you might have. For example, if you're building a web application or a mobile application or any other kind of application, those are well known. And the interesting thing about it is, as well known as some of those are, we still see those problems. And in fact, a lot of the data breaches, as we mentioned, If you look at the root cause, you look at, you know, how did this happen, you'll find that many times it's those vulnerabilities that we already know about but somebody missed. And so the information is there, but we're still working on trying to make sure that everybody understands it's the basics that we need to cover and make sure that, you know, we're writing that secure software using those good principles. **27:24 Chris Romeo:** Yeah, and I'll mention one of those top 10 lists because it's the most famous one out there, right? And it's, you know, those people that are now looking around and thinking about the application security world that we've been talking about here, if you go and look up the OWASP, O-W-A-S-P, top 10, the OWASP top 10 has been in existence for more than a decade, and it's the 10 most prevalent vulnerabilities, web application vulnerabilities that can be found in, you know, the majority of web applications as they're deployed these days. So if you're interested in diving deeper, and we'll cover the details of the OWASP Top 10 on future episodes of the podcast here, but if you want to go dive deeper now because your interest has been piqued, I'd recommend that you go and check out the OWASP Top 10 and read that document in preparation for studying on with us further in the future. **28:20 Robert Hurlbut:** Definitely. **28:23 Chris Romeo:** So, a couple of key takeaways I just want to use to wrap us up here. The first one is when we're talking about application security, you know, I want our listeners to remember application security is foundational to what you're doing. And we talked about how application security works together with the secure development lifecycle as a process to be able to ensure that security is built into everything that you do. We talked about how requirements and design and development and testing and release, those things all come together. Application security is the foundation, though, that builds secure products for your— the things that you provide to your customers. I think you're going to find as you dive deeper into it that it is a worthy investment. It's something that your customer base wants you to do. And just remember that Application security, as you're beginning your journey into it here, it's a people issue and it's supported by the tools that we use along the way. So Robert, as we're wrapping up here, any last-minute thoughts you want to share with the audience about application security? **29:24 Robert Hurlbut:** Well, I was going to say, or thinking just a moment ago, you know, it's a great time to be in this field. It's a great time to be thinking about this because one, the opportunities. We need more people. to be thinking about this. We need developers, we need system administrators to be thinking about application security because it is so critical that we get this right. And so to me, it's just exciting on the one hand. It's also a little bit scary that, you know, there's so much data out there, there's so many opportunities potentially for attackers. So we've got a lot of work to do, but, you know, it's a, it's a great time to do it. So I'm really glad for this podcast to be able to reach out some more people get them interested, get them started, and start thinking about what can we do to build out some good applications that are secure. **30:15 Chris Romeo:** Yeah, that's a great way to end our first episode here, Robert, by letting the audience know that if you stick around with us, we're going to take you through the process of application security. We're going to take you through the details, and we're going to dive a lot deeper into this as we we go, and we just hope that you'll stick with us and, and learn along with us. We thank you for listening to the first episode of the Application Security Podcast. For Robert and myself, Chris Romeo, we want to thank you for listening, and we want to just let you know you can catch us on Twitter @AppSecPodcast. So if you have questions, comments, flames, anything you want to offer to us, we ask, hey, hit us up on Twitter. Twitter. We'll be happy to continue the dialogue there. Thank you very much. Thanks for listening to the Application Security Podcast. Our intro music is 8-Bit Kung Fu by Boring and TJ, and the outro is Southern Delight by Stefan Cartenberg. **31:12 Robert Hurlbut:** You can find us on Twitter @appsecpodcast or on the web at www.appsecpodcast.org. --- Source: https://appsecpodcast.com/chris-and-robert-introductions-and-why-appsec/