Eric Johnson -- Continuous Integration in .NET
Security testing loses value when its results arrive outside the developer’s normal workflow.
Listen to the episode310 episodes, going back to 2016.
Security testing loses value when its results arrive outside the developer’s normal workflow.
Listen to the episodeEvery software organization accumulates technical debt, but security debt raises the cost and risk of every future change.
Listen to the episodeWhy did the 2017 OWASP Top 10 release candidate provoke such a strong reaction? Chris and Robert walk through the proposed categories, compare them with…
Listen to the episodeFixing vulnerable code is only part of application security; a flawed design can survive every code-level check. Brook S. E.
Listen to the episodeWhat defined the first season of the Application Security Podcast? Chris and Robert revisit clips that established the show’s early themes: thinking like an…
Listen to the episodeWhat separates a useful security consultant from someone who merely arrives with answers?
Listen to the episodeWhat does “think like an attacker” actually ask a developer to do? Adam Shostack joins Chris and Robert to challenge a familiar instruction that can leave…
Listen to the episodeHow does a developer learn to take software apart and use that knowledge to build it more securely?
Listen to the episodeA security awareness program needs to change daily behavior, not simply record who completed a course.
Listen to the episodeCan a career in library science become a foundation for information security? Tracy Maleeff joins Chris and Robert while making that transition, bringing…
Listen to the episodeHow can a company build a security community when it has only a few interested people and little budget?
Listen to the episodeTechnical ability can open a door in security, but communication and relationships often determine what happens next.
Listen to the episodeA useful threat model should explain how an attacker could harm the business, not just complete a checklist.
Listen to the episodeHow do you keep a secure development lifecycle useful as products, teams, and delivery methods change?
Listen to the episodeSecurity advice only helps when it connects to the needs of the people building and running the business.
Listen to the episodePart two follows Daniel Ramsbrock into the practical workflow of a web application penetration test.
Listen to the episodeWhat should developers and security teams understand before commissioning a web application penetration test?
Listen to the episodeCan you learn enough about a development team’s security practices in an hour to give it useful direction?
Listen to the episodeProtecting data from attackers does not answer every question about privacy. Elena Elkina joins Chris and Robert to explain the relationship between…
Listen to the episodeHow should application security change when a team moves from Waterfall to Agile? Chris and Robert compare the two development models and map security work onto each one.
Listen to the episodeWhich activities turn a secure development lifecycle from an aspiration into repeatable work?
Listen to the episodeIn the inaugural episode of the Application Security Podcast, Chris Romeo and Robert Hurlbut introduce themselves, trace the experiences that brought them…
Listen to the episode