Matt Clapham — A perspective on appsec from the world of medical software
Security teams learn something different when they leave their own conferences and listen to the industries using their products.
Listen to the episode310 episodes, going back to 2016.
Security teams learn something different when they leave their own conferences and listen to the industries using their products.
Listen to the episodeHow can hackers and corporate security teams work together when each sees the other through a different set of assumptions?
Listen to the episodePutting an application in Kubernetes does not solve the problem of getting secrets to it safely.
Listen to the episodeWhat if developers could describe threats in the same place they describe their software?
Listen to the episodeHow do you make a powerful security testing tool approachable to the developers who need it?
Listen to the episodeThe shortage of AppSec practitioners will not disappear just by posting more job openings.
Listen to the episodeA secure mobile application can still sit on a compromised device or depend on an insecure cloud service.
Listen to the episodeWhat stood out across a season spanning DevOps, pipelines, community, chaos engineering, dependency risk, and IoT?
Listen to the episodeWhat happens when a threat model takes days to produce but the development team has already moved on?
Listen to the episodeMoving an application to Azure changes which security controls you operate yourself and which ones the platform can provide.
Listen to the episodeDevelopers need useful findings in their workflow, not another collection of security tools to operate by hand.
Listen to the episodeWhat can the wider AppSec community learn from Israel’s unusually dense security ecosystem?
Listen to the episodeAn IoT product’s attack surface extends well beyond the device in the box. Daniel Miessler explains that broader view while walking Chris and Robert through the 2018 OWASP IoT Top 10.
Listen to the episodeWhat if a security team measured success partly by making developers’ work easier? Travis McPeak explains that approach to SecOps through concrete examples from Netflix’s cloud environment.
Listen to the episodeChanging security culture requires more than distributing policies or buying another training platform.
Listen to the episodeWhy are SQL injection and cross-site scripting still with us after years of knowing how to prevent them?
Listen to the episodeOWASP became a reference point for software security, but it began with people sharing knowledge and trying to solve problems together.
Listen to the episodeCan an intentionally broken online shop help change an organization’s security culture?
Listen to the episodeMobile apps can hide credentials, expose powerful backend access, and repeat familiar web security mistakes.
Listen to the episodeWhat does a bug bounty look like from both sides of the relationship? Adam Bacchus and Jon Bottarini of HackerOne compare the responsibilities of the…
Listen to the episodeA JavaScript library can keep working long after its security problems become public.
Listen to the episodeA threat model that lives in an old document rarely keeps pace with the code it describes.
Listen to the episodeA list of weaknesses is not the same thing as an understanding of the threats facing a business.
Listen to the episodeHow do you know a security control will work when the system around it fails? Aaron Rinehart introduces chaos engineering as a way to test assumptions about…
Listen to the episode