Magen Wu -- Hustle and Flow: Dealing With Burnout in Security
In a profession that rewards constant vigilance, how do you recognize when dedication has become burnout?
Listen to the episode310 episodes, going back to 2016.
In a profession that rewards constant vigilance, how do you recognize when dedication has become burnout?
Listen to the episodeA feature built into XML processing can become a path to file disclosure, internal requests, or denial of service.
Listen to the episodeBuying more scanners does not automatically create a better application security program.
Listen to the episodeWhen a team is already ten sprints into a product, stopping to threat model everything can sound impossible.
Listen to the episodeWhat happens when data arriving at an application is allowed to recreate objects and trigger unexpected behavior?
Listen to the episodeWhat is a security champion, and how can an organization build a program that lasts? Chris and Robert compare definitions, alternative titles, and the qualities that make a champion effective.
Listen to the episodeMoving a security scanner earlier in the pipeline is not the same as building security into development.
Listen to the episodeWhy does OWASP matter beyond its famous Top 10 list? The Season 2 finale revisits guests who demonstrate the breadth of the foundation’s work.
Listen to the episodeContainers make deployment repeatable, but insecure images, excessive privileges, and unmanaged secrets can travel with them.
Listen to the episodeA web application firewall can buy time during a vulnerability crisis, but only if somebody understands and maintains its rules.
Listen to the episodeWhy can an IoT product look secure in one component and still fail as a complete system?
Listen to the episodeWhere should the OWASP Proactive Controls go after giving developers a concise defensive counterpart to the Top 10?
Listen to the episodeHow should the OWASP Top 10 balance data, expert judgment, community feedback, and a format people can actually use?
Listen to the episodeHow do you find security problems in a design before they become expensive changes to running software?
Listen to the episodePassword advice changes as attackers, hardware, and identity standards evolve. Chris and Robert examine how passwords are guessed, cracked, stored, and…
Listen to the episodeAPIs may lack a visible interface, but that does not make them hidden or safe. Tanya Janca and Nicole Becher use OWASP DevSlop and its Pixi application to…
Listen to the episodeAgile delivery promises fast feedback, but where does application security fit when teams are already moving continuously?
Listen to the episodeDoes moving an application into Docker make it safer, or simply change the risks you need to manage?
Listen to the episodeWhat can practitioners learn from a new OWASP document, an upcoming conference, and an industry analyst report in one conversation?
Listen to the episodeWhat should an application security professional take away from a conference famous for spectacular hacks?
Listen to the episodeDevelopers hear plenty about vulnerabilities, but what should they actually build into their applications to prevent them?
Listen to the episodeHow can developers turn OWASP’s many projects into practical help with the code they write?
Listen to the episodeThreat modeling is easier to adopt when its tools fit the way developers already work.
Listen to the episodeStatic analysis can help developers find security flaws early, but buying a scanner does not create an effective program.
Listen to the episode