Jessica Robinson and Vandana Verma-- WIA: Women in #AppSec
How can application security become a field where more women enter, contribute, and advance?
Listen to the episode310 episodes, going back to 2016.
How can application security become a field where more women enter, contribute, and advance?
Listen to the episodeWhat should OWASP members expect from the foundation’s executive leadership, and how can a global nonprofit remain connected to its volunteer community?
Listen to the episodeLearning DevSecOps is hard when setting up the lab becomes a project of its own. Mohammed Imran introduces DevSecOps Studio, an environment designed to help…
Listen to the episodeFramework defaults can prevent common vulnerabilities, but developers still need to understand when their code bypasses those protections.
Listen to the episodeFinding vulnerabilities is only part of improving software security; the harder work is changing how people build and operate applications.
Listen to the episodeHow can a small AppSec team make sense of thousands of applications and a growing pile of security work?
Listen to the episodeWhat developers need from a threat model is often a clear set of requirements they can implement.
Listen to the episodeCan security become a normal part of DevOps without turning every release into an audit? Julien Vehent, author of Securing DevOps, shares what his team learned protecting Firefox services at Mozilla.
Listen to the episodeHow can one open-source rule set protect applications across competing products and very different architectures?
Listen to the episodeWhat changed when Chrome began labeling ordinary HTTP pages as not secure, and why did that decision provoke resistance?
Listen to the episodeWhich practices belong in a complete application security program? The Season 3 finale answers by assembling clips that move from early development…
Listen to the episodeOWASP is widely recognized, but do people understand the community behind its famous Top 10?
Listen to the episodeA bug bounty can create a productive relationship with security researchers—or damage trust on both sides.
Listen to the episodeHow do you turn a security requirement into something a development team can build and test?
Listen to the episodeCould familiar hiring and management practices be keeping talented people out of security?
Listen to the episodeWhere does application security end when software controls bootloaders, firmware, processors, and connected devices?
Listen to the episodeYour application knows when a user does something that should be impossible, but does that knowledge help stop an attack?
Listen to the episodeAn application can inherit serious vulnerabilities from code its developers never wrote.
Listen to the episodeFinding a vulnerable library in one build is only the beginning: how do you find every affected application across an organization?
Listen to the episodeCan a threat modeling community bring different methods together without forcing everyone into the same process?
Listen to the episodeDevelopers need concrete security answers, but finding trustworthy guidance can take longer than writing the code.
Listen to the episodeA log file does little good if nobody can use it to detect or investigate an attack.
Listen to the episodeWhat if the strongest argument for funding application security is better software delivery rather than fear of a breach?
Listen to the episodeWhich books, sites, conferences, and communities are genuinely useful for learning application security? Chris and Robert compare their personal recommendations and explain what each resource offers.
Listen to the episode