Chris and Robert: A Taste of Hi-5
What happens when Chris and Robert trade a single interview topic for five current application security ideas?
Listen to the episode310 episodes, going back to 2016.
What happens when Chris and Robert trade a single interview topic for five current application security ideas?
Listen to the episodeWhat happens when a threat model has to account for patient privacy and clinical harm as well as attackers?
Listen to the episodeIs becoming a CISO the next technical promotion, or a fundamentally different job? Marc French joins Chris and Robert to discuss the role through the eyes of an application security leader.
Listen to the episodeSeason 5 covered application security from tools and threat models to mentoring, self-care, coaching, dependency risk, and program design.
Listen to the episodeWhich parts of an AppSec program should change as a company grows, and which should stay the same?
Listen to the episodeWhy doesn't an executive mandate and a scanning tool add up to a software security program?
Listen to the episodeDevelopers may want to own security, but what helps them turn that intention into safer software? Liran Tal joins Chris and Robert to examine Snyk's 2019 State of Open Source Security research.
Listen to the episodeWhy should developers care about open source security when they already have features, testing, accessibility, and performance to manage?
Listen to the episodeAn SCA tool can find vulnerable libraries and still leave important software supply-chain questions unanswered.
Listen to the episodeWhat does OWASP Dependency-Track add beyond a conventional software composition analysis scanner?
Listen to the episodeSecurity testing is more likely to happen when it fits the way developers already work.
Listen to the episodeWhy should kindness matter in an industry responsible for protecting money, systems, and sometimes lives?
Listen to the episodeSecurity programs improve when developers have someone who can help them want to get better, not merely tell them what they did wrong.
Listen to the episodeWhat would an application security conference look like inside DEF CON? Erez Yalon and Liora Herman explain how a volunteer idea became the Application…
Listen to the episodeWhy did DEF CON have villages for specialized security communities but no home dedicated to application security? Erez Yalon explains how that recurring question became AppSec Village.
Listen to the episodeSoftware producers, customers, and policymakers need a common way to discuss security without pretending that one checklist fits every product.
Listen to the episodeWhat if a system works exactly as designed but gives people new ways to harm one another?
Listen to the episodeWhy threat model when AppSec teams already have scanners, checklists, and testing?
Listen to the episodeArtificial intelligence can help analyze security data, but the systems using it also need protection themselves.
Listen to the episodeA successful security career can still become unsustainable when work crowds out everything else.
Listen to the episodeHow do you keep an intentionally vulnerable application useful while its underlying frameworks keep fixing bugs?
Listen to the episodeWhat makes OWASP Juice Shop useful to developers when many intentionally vulnerable applications feel dated?
Listen to the episodeHow does an intentionally vulnerable application become a community learning movement?
Listen to the episodeSecurity needs more experienced practitioners, but people do not become senior without guidance, advocacy, and opportunities to learn.
Listen to the episode