Skip to content
AppSec PodcastThe Application Security Podcast — home
19 min

Conclusion: The End…of Season 1

With Chris Romeo and Robert Hurlbut

Threat Modeling

What defined the first season of the Application Security Podcast? Chris and Robert revisit clips that established the show’s early themes: thinking like an attacker, building security community, practicing threat modeling, collaborating during penetration testing, learning reverse engineering, and finding a path into the profession.

Listen

Audio hosted by Buzzsprout. Nothing loads until you press play.

Episode chapters · 12 chapters
  1. 00:00Looking back at Season 1Audio
  2. 02:00Adam Shostack on thinking like an attackerAudio
  3. 04:45Why that phrase can exclude developersAudio
  4. 06:38Chris Romeo on security communityAudio
  5. 09:33Tony UcedaVélez on PASTA threat modelingAudio

About this episode

What defined the first season of the Application Security Podcast? Chris and Robert revisit clips that established the show’s early themes: thinking like an attacker, building security community, practicing threat modeling, collaborating during penetration testing, learning reverse engineering, and finding a path into the profession. Adam Shostack explains why “think like an attacker” can exclude developers, Chris describes internal security communities, Tony UcedaVélez introduces PASTA, and the hosts revisit lessons about testers working with development teams. Jon McCoy defines reverse engineering, while Tracy Maleeff shares career-transition advice and reading recommendations. The finale is both a retrospective and a statement of direction: application security improves when technical methods, empathy, learning, and community reinforce one another.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Chris Romeo and Robert Hurlbut:
Chris Romeo on LinkedIn
Robert Hurlbut on LinkedIn

Resources
PASTA Threat Modeling
Cybersecurity Canon
The Cuckoo’s Egg
Adam Shostack
Tony UcedaVelez
Jon McCoy
BSides

Actionable

From this conversation

  1. Think like an attacker

    When I say think like a hacker or think like an attacker, what I'm thinking about is how would I break this system, right?

    3:39
  2. Build a security community

    But one of the things that I did in my time there was I focused on building this thing that we call security community.

    6:38
  3. Test whether attacker framing engages people

    Then afterwards, he politely came out and said, "Can I talk to you for a second?" And said, "I didn't appreciate when you said think like an attacker." Oh no!

    4:45
Transcript · 19 min conversation

0:05Chris RomeoThe Application Security Podcast. Here we go. Good day, friends. The Application Security Podcast has reached the conclusion of our first season. With the help of many friends, we were able to record 18 episodes. We've done something a bit different for this final episode of season 1. Our producer, Daniel Romeo, has collected some of our favorite clips from this season. These are the things that really stood out to us as we were reflecting on all the conversations that we've had. We hope you enjoy and look forward to the release of season 2 in a few months. Our first clip comes from episode 14, AppSec Awareness: A Blueprint for Security Culture Change. And in this clip, I answer the question, why should I care about application security? So Chris, take it away. When someone asks me the question, why should I even care about application security? Well, because software's in everything, and software that's not secure opens us up to so many different types of challenges. Things— think about where software is between mobile apps, cars, smartphones, medical devices, power plants. Software's everywhere, and it's a part of everything that we do. I haven't yet in the last number of years sat across the table from a customer who said, I just don't care about security. People care about security. They want security in everything. It's even being listed in RFPs. I've seen requirements where companies in an RFP are saying, I demand that you follow your own process. Seems like a crazy thing to have to put in an RFP, but the point is the demand is there. The goal that we have, that I have out of any type of security culture work I'm doing or any type of possible changes or things is I want developers that think like security people. If you take people and you try to give them even the best tools to improve security, if they don't have the foundation in how to do application security or understand the principles, then the tools— they get a report of 30 pages of output from a web application scanner and they look at that and they go, hmm, I don't know what to do with that now. It's really easy to change security culture today. It's even easy, relatively easy, to get that security culture change to last throughout the weekend. The challenge is, can we get— make adjustments to the security culture that in 5 years from now we can look back and say, wow, that was really a good move on our part? Security has been known as the department of no for so long, the department of people that don't have fun, the department of people I don't talk to because I don't want them to block this cool thing I'm trying to do. So we got to change that. We have to be much more engaging. We have to be much more available. We have to become the department of no, But let's figure out how to do something a little more secure that'll still meet your functional needs that you're trying to do. In episode 16, Robert and I had a chance to chat with Adam Szostak, and this next clip really defines what that conversation was about. What does it mean, first of all, when we say we want to teach somebody to think like a hacker?

3:39Robert HurlbutSo when I say think like a hacker or think like an attacker, what I'm thinking about is how would I break this system, right? Where would I, if I was gonna take it apart, where would I first insert my crowbar? What could I make it do that it's not supposed to do? In security, we learn to do that. We learn to analyze a system, we learn to say, oh, here's an open port. I wonder what happens if I send it something unexpected. Here's a database query. I wonder what happens if I put some extra quote marks and semicolons in it. And we learn to do that, and we do it over and over again in the course of prodding at the systems that we're responsible for. The flip side to this is when you ask a normal engineer to do it. And I'll tell your listeners the story, and I'll make this the PG-13 version of the story.

4:43Chris RomeoMm-hmm.

4:45Robert HurlbutIt was a little bit after I had started at Microsoft. I was in a meeting with this guy who— and I said, think like an attacker. And he scowled a little bit, and, you know, being at Microsoft, went back to his laptop, And stopped participating in the meeting. And then afterwards, he politely came out and said, "Can I talk to you for a second?" And said, "You know, I didn't really appreciate when you said think like an attacker." Oh no! Wait, wait, wait. This was Microsoft. This was 2006. He said, "That was the stupidest bleep bleep bleep I've ever heard." And he was really mad. He was really, really mad at me. And I talked to him for a minute and I got him to calm down. And he said, I don't know what the heck it is to think like an attacker. And when you said it, you made me feel dumb. People see the stuff that we do as sort of magical, right? You wave your hands and all of a sudden Clippy is on screen singing. True, true demo that was, that was done for executives at Blue Hat. You can find the story of Clippy Sings out there somewhere. But people don't get it. They don't see, they don't see the steps. They don't see the days or weeks of sitting and looking at assembler or trying to write an exploit. They see the result, and the result is this magic thing. And so that's what really got me thinking about, okay, how do we teach this? How do we transfer these skills in bite-sized learnable pieces?

6:38Chris RomeoIn episode 12, Robert actually interviewed me on the topic of security community. So, Chris, what is security community? In my career, I worked at a large technology company for roughly for the last 10 years. So I left that large technology company this past January. But one of the things that I did in my time there was I really focused on building this thing that we call security community. So I think of security community as inside of a large organization, or maybe even inside of a small organization, How do we get people that are passionate about security to come together and to encourage each other and to teach each other and to motivate each other with the single goal of saying, how do we make the products that exist within our company better from a security perspective? So when I think of security community, that's what I'm thinking of is how do you bring those people together and really fire them up and get them passionate about security? So, if you have a company where people could care less about security, they're not going to have any interest in trying to find any problems in the products. So, when they get that passion, you can drive down the amount of time it takes to fix security problems that are found or those types of bugs that are open. You'll start to get people that are actively applying security into what they do in their day-to-day job. So that's kind of the institutional value that you get out of this type of a security community effort. Listen, if you're not in the security business right now, if you're somebody who's a developer or tester, I got news for you. One of the hottest places in the job market is jobs that have the word security in it. And if you already have development skills and a little bit of passion and a little bit of interest for security, where you can go and learn some things. Developers that speak security are very, very valuable. I think that everyone has a role in being part of the security community. Some people need just a basic level of awareness applied to their world. So for example, a developer, I believe, needs some amount of security training If it's a web developer, they need to understand what is SQL injection, what is cross-site scripting. These should be things that they live and breathe because they truly know what they are. They should understand the secure coding principles of the language that they use. Robert and I are both huge threat modeling proponents. In episode 10, we had a chance to talk with Tony Ysidro-Velez, about this idea of the POSTA methodology for threat modeling.

9:33Robert HurlbutPOSTA today is a 7-stage methodology for threat modeling, for application threat modeling. What is the context of business and information that the application manages? 1. 2, what is the technology footprint of that application? 3rd stage is really simple. It's about mapping together the different application components in terms of information. After that, we want to be able to understand what threats are most likely to affect the application environment based upon substantial threat intelligence. After threat analysis, you go into what's wrong with a vulnerability analysis for your applications, and then you want to prove what's wrong by exploitation. And that is basically stage 6 in the PAWS methodology, is showing proof of concepts for exploitation. And then because this is a risk-centric approach, it ends with a residual risk analysis and countermeasure development phase where, based upon the actual threats that have the biggest impact identified in step 1, what are the remediation or countermeasure strategies that you want to take as an application owner, as a developer Early on in season 1, we did a 2-part episode with Daniel Ramsbrock on the topic of web application penetration testing.

11:05Chris RomeoWhy do I even care about penetration testing at all? Why do I even have to do it? Why can't I just skip this and move on to writing more code?

11:18Robert HurlbutAbsolutely. So there's an idealistic answer and there's the practical answer to it. So in the perfect world, penetration testing is just a sanity check. It's just, you know, at the very end, you've done everything correctly, you have a secure, you know, you have security that's built into your development lifecycle, and at the end you're just kind of making sure you didn't miss anything. In the real world, not a lot of software makes it to a deliverable finalized stage without necessarily having had security baked into it. And so penetration testing often becomes, unfortunately, a method of discovering deeper issues within the application very, very late in the game, at a point where the developers basically are close to being finished or thought they were already finished with the application, or even worse, the application has been in production for years or in some cases decades And you're finding these issues after the fact and kind of hoping that the bad guys haven't also found those issues in the meantime.

12:19Chris RomeoWhat would the developer and the penetration tester, if they were coordinating, what would they be better at if they worked together?

12:26Robert HurlbutI think that the biggest advantage of working together, and, you know, I always prefer this when I have the chance to do it, you know, as Robert was saying, there's really, as a pen tester, as an outsider, you know, I really don't have a good understanding of of the thing that I'm testing, the application or the component. And so, just getting an overview of what is this thing supposed to do, how is it supposed to work, what is normal behavior. And one of the biggest things that I think the tester can often kind of open the developer's eyes to is unintended consequences, right? How you can take certain pieces of functionality that may not have even been designed to be used in conjunction, to combine those and to execute attacks from that, that the developer may not have—

13:11Chris RomeoRight.

13:13Robert Hurlbuthave anticipated.

13:14Chris RomeoJohn McCoy in episode 15 enlightened us and educated us on this idea of reverse engineering when he answered the question, what is reverse engineering?

13:29Robert HurlbutIt's looking at a previous application. So like when you look at an HTML web page and you see the HTML for it, you can learn how to do that. I did the same thing with applications. So I pulled apart Microsoft applications to find out what was inside of them, what were the APIs they were using And I actually learned coding from pulling apart other people's programs and looking at the source code some of the time, but most of the time it was just the bytecode inside of it, almost the DNA of the program. On my own, I had always kind of been into reverse engineering and that kind of thing, but I actually didn't have— I didn't know it was a thing. I didn't know it was a security technique. And once I got into security, I found out that I was a powerhouse. Like, in development, I thought I was a weirdo. I usually run people to kind of the core. I work in .NET a lot, .NET, C#. I run them to kind of the core level of .NET at the IL level and get them comfortable of looking at a program through the eyes of IL and look at functions and kind of that forensics approach of like dissecting it like a file table. .NET is an open standard like HTML. It was developed as it's a core ethos to be any language in, any platform out, and it really is delivering. I've done embedded hardware modules to execute attacks and written it all in .NET all the way up the stack. .NET's been evolving, but I've been really impressed with it coming out with a security measure such as code access security, deploying it, seeing if there was ways to get around it, and then evolving in response at the framework level. It always has holes that keep coming up, but it seems like they're actually willing to make core framework changes, even breaking changes, in order to progress the security model.

15:19Chris RomeoIn episode 13, Tracy Maleeth helped us to understand how does somebody get into information or application security and really become involved.

15:33Robert HurlbutNumber one, I would say, is get involved on social media with the InfoSec world.

15:41Chris RomeoYeah. I would say, you know, InfoSec Twitter world is very educational. People share knowledge all the time. So even if you're not interested in tweeting out, just set up a Twitter account, you know, and just so that you can see what's going on, search by InfoSec hashtags even, and just follow things. Second, Get out and go to meetings. Go to meetup.com, see what's in your area. Go to BSides events. Again, you don't have to spend a lot of money. A lot of BSides are free or inexpensive.

16:16Robert HurlbutAnd most likely there's one in your general area.

16:20Chris RomeoSo to the best of your ability, go to either meetups or conventions as you can afford them. But go in person to experience things. And Lastly, I would also just do a lot of reading. And I know that I'm not saying this just because I'm a librarian, but do it, you know, maybe I am.

16:39Robert HurlbutYou need to do reading. There's also a lot of, you know, a lot of books about the history of security.

16:46Chris RomeoPalo Alto Networks, for example, has the Cybersecurity Canon, which is this vetted list of books that they believe every cybersecurity, you know, professional should read.

16:56Robert HurlbutSo there's a lot of history that you need to know as well. And now I was a history major, so this definitely is coming from that point of view.

17:05Chris RomeoYou know, you need to understand where security as an industry came from to really fully appreciate and get where it is now and where it's going.

17:14Robert HurlbutYou need to have some sort of fundamentals, so get reading.

17:17Chris RomeoOkay, so I'm going to recommend this one because a very cool guy who knows a lot about this area recommended this book to me, and I'm about halfway through it. Alan Friedman, he's the Director of Cybersecurity Initiatives at the NTIA, and he recommended to me the Cuckoo's Egg. Here at the conclusion of season 1, I wanted to just recognize a couple of people that are instrumental to making the Application Security Podcast successful. The first person is Daniel Romeo, who is our producer extraordinaire. who assembles these episodes each week. Also Lauren Romeo for her voiceovers that you hear at various times in the show. Robert, my co-host here, plus all the awesome guests that have made time to give back to the bigger security community. We thank you all for your efforts this season, and we look forward to season 2. Thanks for listening to the Application Security Podcast.

18:21Robert HurlbutOur intro music is 8-Bit Kung Fu by Boring and TJ, and the outro is Southern Delight by Stefan Kartenberg.

18:27Chris RomeoYou can find us on Twitter @AppSecPodcast or on the web at www.appsecpodcast.org. Come on.

2,902 words · transcript by assemblyai

More on Threat Modeling

View all episodes →

Get Reasonable AppSec: new episodes and useful picks from the archive.