--- title: "Jim Manico -- MORE OWASP!" url: https://appsecpodcast.com/jim-manico-more-owasp/ date: 2017-07-04 duration_seconds: 2190 guests: ["Jim Manico"] topics: ["OWASP Top 10", "OWASP Projects"] audio: https://www.buzzsprout.com/1730684/episodes/8122715-jim-manico-more-owasp.mp3 transcript: true --- # Jim Manico -- MORE OWASP! *July 4, 2017 · 37 min* with [Jim Manico](https://appsecpodcast.com/guests/jim-manico/) on [OWASP Top 10](https://appsecpodcast.com/topics/owasp-top-10/), [OWASP Projects](https://appsecpodcast.com/topics/owasp-projects/) [Audio](https://www.buzzsprout.com/1730684/episodes/8122715-jim-manico-more-owasp.mp3) ## Show notes How can developers turn OWASP’s many projects into practical help with the code they write? Jim Manico joins Chris and Robert to discuss the resources he helps build and the problems each is meant to solve. He traces his move from software development into security education, then explains the OWASP Java Encoder and how its focused approach differs from a larger security library such as ESAPI. The conversation also explores the debate surrounding the 2017 OWASP Top 10, the value of the Cheat Sheet Series, and the developer-oriented Proactive Controls. Jim shares lessons from writing Iron-Clad Java and from teaching application security. Throughout, he emphasizes accessible guidance, sound security APIs, and community work that helps developers put defenses into practice. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Security Journey provides application security education for developers and everyone in the software development lifecycle. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Jim Manico: → [Jim Manico on LinkedIn](https://www.linkedin.com/in/jmanico) → [Manicode Security](https://manicode.com/) Mentioned in this episode: → [OWASP Java Encoder Project](https://owasp.org/www-project-java-encoder/) → [OWASP ESAPI](https://owasp.org/www-project-enterprise-security-api/) → [OWASP Cheat Sheet Series](https://cheatsheetseries.owasp.org/) → [OWASP Proactive Controls](https://owasp.org/www-project-proactive-controls/) Chapters: 00:00 OWASP projects with Jim Manico 01:01 From software development to security education 02:27 Learning security as a developer 05:12 Joining and contributing to OWASP 10:32 The OWASP Java Encoder 11:56 Java Encoder compared with ESAPI 13:24 Bringing safer APIs into the platform 20:00 The debate around the OWASP Top 10 24:16 Collaboration at the OWASP Summit 25:33 How to use the Cheat Sheet Series 28:10 Proactive Controls for developers 29:25 Writing Iron-Clad Java 31:55 Life, teaching, and opportunities in AppSec ## Transcript *6,337 words · assemblyai* **0:05 Chris Romeo:** The Application Security Podcast. Here we go. Hey everyone, welcome to the next episode of the Application Security Podcast. We're here today with Jim Manico, a project lead for OWASP. Today we dive deeper into some of the projects on his plate. Enjoy. **0:39 Robert Hurlbut:** Hello friends, thanks for joining us this week. Chris and I are joined today with Jim Manico, an application security consultant and trainer. Thanks, Jim, for stopping by. **0:56 Jim Manico:** Well, thank you for having me, Robert. Thank you for having me, Chris. Great to be on your show. **1:01 Robert Hurlbut:** Thank you. So to get started, as we usually do with those we've been interviewing, could you tell us your— what we call our superhero story, or security superhero story? Tell us how you got into this. **1:13 Jim Manico:** Well, Robert, I'm a developer. I've been writing code since I was a little kid, and I was a software engineer professionally. And one day, one of my students in high school— I was actually teaching a computer class in high school— one of the parents of my students said that they see a job where someone is looking for high-tech people. Go, you should go talk to them. And that was Stephen Northcutt from the SANS Institute. And Stephen was like, Jim, you know, anybody can be a good developer. but you wanna be a good developer who's security-minded, and in the future, it's gonna make a big difference to your career. So you should join me and you should serve me, Jim, serve me, and I will teach you the dark arts. And he was right. He was like beyond right, and he was also ahead of his time. He was luring me into security as an area of study and work. probably like 12 years ago. And that's before, that's before the real loud drumbeat that we hear today was playing. So I'm super grateful that Stephen dragged me into this, this industry, no question about it. **2:27 Robert Hurlbut:** Oh, definitely. And same way as we. So in terms of whenever you were going through and trying to figure out what do you do first, what were some things that you were encountering in terms of going, switching from a developer into security? I mean, any issues or problems or things you had to face first or deal with first to jump into that? **2:46 Jim Manico:** No, I mean, it was a natural progression of being a developer. It's just learning, honestly, it's just learning new and old development tricks in a more intense way. Like, we were already doing access control, we were already building login systems, we were already trying to build database queries that were that were safe no matter— that worked no matter what the user threw at us data-wise. So it wasn't a complete 360. It was stuff we were doing already. And just when I joined the SANS Institute back in the day and I worked for SANS for a couple of years, like the first lessons I got from Johannes were you wanna do strict whitelist validation on every single input in an extremely rigorous way. And we're gonna check your work to make sure you're doing it. And again, this is a long time ago. This is well over a decade ago when I got those first lessons from, you know, Dr. Johannes Ullrich from the SANS Institute. And of course, you know, I'm not trying to leak any secret data here. We're talking historically about first lessons around application security from over a decade ago. **3:57 Robert Hurlbut:** Right, right. Yeah, I remember those days. I mean, and as you mentioned, you know, in those early days, there weren't a lot of us around. It was still fairly new. I know that there are really very few training materials out there as well. It was, you know, maybe a few samples on the internet here and there. Of course, SANS was starting to come around and put some training out, but in terms of books and other resources, they just weren't really there. More on the network security side than the software security side. **4:28 Jim Manico:** Ken Van Wyck had published an early book on software security and You know, there were still some of the early consultants who were just starting up practices around around then, and and you know the the obvious industries were were seeking out security service you know security services around software development. And I think what's interesting today is is that it's it's not expected industries that are looking for these kind of services now. I pretty much anyone who touches code or or deals with software in a serious way, you know, I see poking their heads up asking about application security more often than not now. So things have definitely changed a lot, Robert. Oh yeah. **5:12 Chris Romeo:** And Jim, I got a question for you. I mean, I've seen that you do a lot of stuff with OWASP. So now I'm curious as to how did you make the jump from SANS to OWASP, or did you kind of support both of them at the same time, or what's the story behind that? **5:25 Jim Manico:** No, no, SANS is a commercial company and, you know, OWASP is a, Nonprofit think tank, so there couldn't be a more you know night and day kind of company, and and not in a bad way. I think we need professional training outfits that are dedicated to security. You know, I compete with SANS, but by the same time, I also recommend them, and I'm friends with a lot of people who work there. And because the thing is, there's so much need for security education. You know, no one who's a serious educator in the world of information security is hungry. So. You know, you know, especially among my customers here. Here, here we go, Chris. It's like true confessions of security trainers, right? You know, among my customers who want really big programs, I'm a one-man shop essentially. So, you know, I've recommended SANS to my customers who want bigger, bigger programs. They want to get their master's degree. They want certain levels of certification. I never thought I'd be selling a competitor of mine. coming on your show, but that's exactly what I just found myself doing. So no, they put a lot of time into this to get it right. So I definitely respect them. **6:37 Chris Romeo:** Yeah, no, and I'm with you too. I mean, I'm the same way when it comes to SANS. I mean, I don't hold any SANS certifications, but I do see the value that they offer when we compare. And I think lots of different certifications, I'm not a hater of any of them. You know, there's some people who are violently opposed to CSSLP or CISSP or whatever. I'm not, I'm not opposed to any of them. I think they all have their benefits, but I think SANS gives you a little more hands-on kind of experience with a lot of stuff. So that can be good as well. **7:05 Jim Manico:** Yeah, that's one of their fortes for sure. Now switching over to OWASP. OWASP is a 501 not-for-profit charitable organization. Their mission is very general. Their mission is to spread application security and, and people from academia, from the business world, And from, you know, pretty much anyone who's involved in application security can join OWASP and participate in some way. And again, it's a very loose organization. I think it's more disorganized than people think, but that's part of the beauty. A group of people can jump in from different parts of the industry and underneath the OWASP banner, go work on a project, right? Go work on a project or work on a document or help a conference happen in some way. You know, even people who are, who are sales and marketing professionals are OWASP volunteers helping OWASP, especially on the conference circuit, which is one of the main ways OWASP funds itself to run operations and pay staff and similar. And so I'm a big fan of OWASP, even as I, as my job changes, as my, as my career changes, You know, I still hang out with OWASP. I still, you know, participate in a number of projects. And I've— and as an OWASPer, I've both been an elected board member and I've been a project participant. And more enjoyable for me, no question, is being a project participant or document reader and editor at OWASP. Those are the things that I'm most passionate about. As a board member, you It was more like I ended up getting involved in conversations that were not related to application security more so than not. And that was my ignorance around the board position. I thought it would be this application security think tank leadership type position. No, it was not. It was a babysitter job. And that's, you know, that's part of being a board member for a large and popular nonprofit. It's doing it's doing some of the unfun things. And so I lasted about 3 and a half years before I popped and had to— I wouldn't say rage quit, but it was a member of the rage quit family. It was a not rage, but abruptly walk away, which I regret to some degree. But finishing this long-winded thought here, you know, I regret walking away abruptly, But by the same token, I don't regret walking away. I was no longer ready to serve that mission as a board member. It was time for me to let someone else do that. **9:47 Chris Romeo:** Yeah, I've heard that they're actually changing, they're actually switching it now so that you only get one term, basically. I think I heard that, which I think is a great— I think it's great for any organization. Nobody should be setting up shop and creating an infrastructure and a program around their participation. That should be good to get some new ideas. And, you know, OWASP is right in the middle of their board of directors election right now. So if anybody's listening and you were thinking about running for the board, just forget the last minute or two of the content here. But no, that's okay. Jim, I love the fact you're giving us like the real scoop. And I want to poke a little bit more at the projects and stuff you're working on because I've looked at some of the things in the past. I know they're really cool. I want our audience to get some perspective. So— **10:31 Jim Manico:** Yeah. **10:32 Chris Romeo:** What's the project that people ask you about the least that you think is pretty cool at OWASP that you're a part of? **10:38 Jim Manico:** I would say the OWASP Java Encoder Project. So let's get obscure. It's the OWASP Java Encoder Project. So this is a security library meant to be used in production as a legit defensive library. It's used to do manual output escaping. Escaping in various Java web projects to help stop cross-site scripting. I think this is interesting because it was written by a real legit PhD-level software engineer who understands this problem deeply and has performance in mind. Just yesterday, I got email from this project where someone was asking why we encode so few characters in a certain context, and our answer was We're trying to encode the absolute minimal characters needed to provide proper defense in every modern browser for the sake of performance. So, I mean, this is a good merger of something that's performance-friendly, meant to be used at mammoth web scale, and still solves the security need. And Java doesn't do this completely on their own in the core language or in EE, so it fits a niche that that is not solved by the language itself. Hence, I love this project. **11:56 Chris Romeo:** So what about— so this isn't ESAPI then, right? **11:59 Jim Manico:** No, no, no, no. I would not wish SAPI on my worst enemy, Chris. You know, it's a great idea. Let me be a little more respectful to SAPI before I totally trash it, right? I don't think it's ready for prime time. If you have already invested in it, and are hesitant to rip it out, yeah, you can keep using the SAPI, get the latest updates that were pushed out a couple months ago. You can limp along with it. But if I was starting a new project, I would use— I'd use different tools. SAPI is not fully maintained and it's got baggage in terms of how it was designed. And I just philosophically believe rather than having one monolithic library for security, I'd much rather have a series of libraries that are individually maintained and individually kept up to date. I just think it's a better architectural decision. I'm like one thumb down on the SAPI, but thumbs up for the idea. Why it's important is it helped us define at a function level what controls that we need for a Java web application. It was a great conversation starter. And it definitely fit a niche back in the day that wasn't being scratched. So it was important back in the day. The concept of an ESAPI is more important than the ESAPI project itself, though. **13:24 Chris Romeo:** Yeah. Why don't they take— so has any work been done to take that Java encoder and actually get it rolled into the Java platform itself so it would just come built in, or am I— Am I living a dream here with unicorns and things flying and pigs flying through the air? **13:40 Jim Manico:** No, this is my personal mission, which I've not been good at following up on. But I take responsibility for trying to get this library into at least Java EE, at least the Enterprise Edition. The core, probably not, because this is a web-only defensive library. I don't think the core of the library wants it. It also interferes with their current encoding functions that it overlaps with. So it's non-trivial. It's non-trivial. You know, I wish I could be like, here, Java, taketh this library, and snap my fingers, and it was like magically woven into the language in a revert back from Java 2 and above. That's my dream that will never be fulfilled. So it's on my list. It's on my list, Chris. And it's the right thinking. It's the right question to ask even though the answer is not what I want. **14:33 Chris Romeo:** Yeah, I mean, I've always been a big proponent of let's squeeze stuff into the frameworks and then over time, it's not gonna fix anything in real time here in this immediate moment. But if we look 5 years down the road, a lot of things that are happening in frameworks now from a web security perspective, people wouldn't have done those It's just because they got embedded into the actual libraries and frameworks and things themselves, the input validation, the output encoding. That's the reason they're actually used so prevalently now. I think it's a great plan to move forward. I'm hoping the Java folks will be receptive to this idea of taking that piece and putting it in. **15:13 Jim Manico:** Chris, if you look at things like Spring Security, it's very rare where a Java web developer is just using plain old Java to build a web app. They're usually using a modern framework. Apache Shiro is one of them, Spring, there's Spring Security, there's lots of other frameworks that developers use out there in the Java world. They very often have some of these controls built in. So I usually advise using, you know, mastering your framework, using your framework controls that are built in, but, you know, it's good to be aware of what your framework does and doesn't provide. And And less and less so do developers actually build their own authentication layer from scratch. More and more so, they're using other projects or services that provide that for them in some way. So the idea of a security library has changed a lot as federation and delegation have changed a lot as well. And another issue is access control, where I don't think we have good controls for access control built into Java or even built into Spring for that matter. Like, I tend to prefer a capabilities model, like the whole ABAC or permission-based access control. And, you know, that's a design issue that Java doesn't handle well. So, again, the whole idea of having one security library to handle all these issues, as these issues have gotten more complex in the last 10 years, I think a monolithic library is less and less likely to be useful. Now, if a company built their own library that was for security that used a lot of different tools underneath the hood, that's probably more realistic, right? And that was part of Asapi's vision as well, where it's not that just providing services, where it's a hook, a series of standard security APIs with hooks underneath that you can tie into different products and services. And I like that. But hey, Chris, let's switch gears. Let's hop to a different OWASP project. Have you heard of the OWASP Top 10, right? **17:17 Chris Romeo:** We have. We actually, Robert and I actually talked about this, the release candidate, about a few episodes ago. So we went through and broke down for the listeners and said, hey, here's the changes, here's where some of the controversy lies. And so yeah, we've recently done a deep dive, but I'm curious as to your take on the kind of where that project is right now. **17:38 Jim Manico:** Well, when I looked at the OWASP Top 10 2017 Release Candidate 1, right, I had to go through 5 stages. First was like complete and utter denial, then anger, then bargaining, where I joined the list and started debating things, then depression, knowing that a vendor had taken over the OWASP Top 10 almost completely, like full Darth Vader style, but then acceptance because the vendor, I think the current leads realized that there is a forever level of controversy. And they gave the helm of the project to one of the board members of OWASP. Andrew van der Stok is now the project lead. Yep. And I know Andrew van der Stok well. He's an Australian security researcher who's probably been doing AppSec longer than any of us, period. He's one of the originals who was, you know, back debating AppSec, back when, you know, Jeremiah Grossman and some of the originals were first joining the industry. You know, I give Jeff and Dave credit for that as well. They were, they were firing up their own services back then as well. So I know, I know Andrew, and I respect him. I think he's a little bit of a son of a bitch, which in a good way, like he's tough and he's, he's not gonna let, you know, anything— he's gonna hear all parties and make intelligent decisions and not be swayed in any, in any direction. So I'm, I'm a fan of Andrew. I think it's— I think it solves every concern I had about the OWASP Top 10 and how it's being created. And a side note, you know, Dave Wickers is still actively working on it. It's not like the previous leaders disappeared. They're still strongly and actively working with Andrew To do a good job here. So I'm I'm at five, Chris. I'm at acceptance now, where I'm much better with what's going on, and they made good moves, and I want to I want to give them a chance. So now is the time to participate. Any of you who want to influence the OWASP top ten in some way, I would I would jump on the list and provide commentary. I think it's under new management, and that's a good thing. And again, all my concerns have been dealt with by this move. So I'm feeling good, Chris, feeling good. **20:00 Chris Romeo:** And like you said there, I mean, this is almost one of those type of roles that you wouldn't wish on an enemy because there's always going to be controversy around the OWASP Top 10. I had somebody ask me the other day, hey, is this a prioritized list? And I was like, no, not as far as I'm concerned. This is the list of 10 that we could think of that we thought were the most important, but one's not necessarily more important than 2 or than 10. They're all important altogether. So, it's a tough job. And I've met Andrew in my travels as well, and I think he'll be good to stabilize that project and really ensure that there's an independent viewpoint that's really at the helm. And I think it's good. I know Dave, I know Jeff, so I don't think they were actually trying to really manipulate everything. I think they were trying to Get a couple of different things to occur. But I think it's like you said, I think it's going the right direction. I think it's going to be good for OWASP and good for the industry with the new setup. **20:58 Jim Manico:** I'll talk smack. I think they made some very poor choices. Let's give them benefit of the doubt. Let's say that they weren't making a choice to benefit their personal business, right? Let's say it was just a coincidence. Even if it was just a coincidence, it looked bad. it looked like they were being impartial. And when you're a curator of a large open-source project, I think you should have the wisdom not to make moves that even look like you're screwing around with the integrity of the organization. So again, I want to give them the benefit of the doubt. I'm not saying that they were, they were directly doing it, but it looked bad and it stirred up a controversy that was not necessary. So I still, I still give them thumbs down on their decision-making abilities. But I give Dave a thumbs up for having the wisdom to step aside because they know me as a, as a complainer. Like, I've been— I frequently, like, questioned some of their activities around OWASP, but that— but I have history with them and I'm very biased. It wasn't just me, Chris. **22:00 Chris Romeo:** Yeah. **22:00 Jim Manico:** The number of security professionals who were up in arms, I mean, pitchforks and all, like, getting the catapult with the flaming Game of Thrones pitch balls ready. They were at the gate screaming about this. So I think that's a good thing. That's my, that's my take on it. That's my take. **22:19 Chris Romeo:** I mean, you know, it's— you can think of this— it's kind of a couple different ways to think about it though. You can almost think of that as a good way. There were some positives that came out of that though, because there were all these people that were in an uproar and all fired up about it. And now hopefully we can channel some of that energy back into other OWASP projects as these people people are starting to absorb whatever the new changes that's going to come out if they do a Release Candidate 2 or whatever they do. But yeah, I think it was good to see how many passionate people we have in the industry. I just hope now that we can transition some of that passion into other things because, you know, Jim, you can probably attest there's 1,000 projects at OWASP and there's not a project— I don't think there's a project at OWASP that you could say, eh, you know what, they're fully staffed. **23:02 Jim Manico:** Yeah. **23:03 Chris Romeo:** There's nothing anybody could help them with. So there's a huge opportunity for folks to get involved. I just hope we can get some of those, some of those folks to jump in. **23:10 Jim Manico:** And Chris, I would say that's already happening. The good part about what I see after Andrew has taken over the OWASP Top 10 is that now there's a community of people talking about the OWASP Top 10 on a risk-by-risk basis. So right now, the OWASP Project Summit just finished. Dave and Andrew and several others were at the Project Summit actively debating this in what I hear are very good positive ways. We saw lots of activity on the list and GitHub list with people commenting on individual OWASP Top 10 items. And now, and I jumped back in as well as did many other people, now there's this very loud and detailed conversation on a risk-by-risk level as the OWASP Top 10 nears its next release candidate. That's awesome. So That's the good side. That's the, that's the good side of this Machiavellian process is that now we have lots more participants in this specific project. So we do have a community helping make the choice, right? And I'm, I'm very fond of that. Yeah. **24:16 Chris Romeo:** Yeah. Robert was actually at the summit last— or no, you were— Robert participated remotely, but Robert, anything you want to say about the— give us any updates about what you heard or what you experienced through the summit? **24:27 Robert Hurlbut:** Well, same thing. I was under the threat model track, but I did, you know, catch some of the things that were happening on the top 10 as well every so often to see what was coming out of that. And same thing, I, I was very, very pleased to see Andrew working on that as well. In fact, I just saw an announcement he's moving to the US, so he's no longer going to be in Australia. He's going to be on the West Coast. And so it's just great to see some of the things that came out of that last week in terms of firing up people and getting them involved. And like you said, a community building around this. And so lots and lots of great things that came out of last week. **25:02 Jim Manico:** You know, and I give Dave Wickers a lot of credit because he could have easily said, fine, I'm, I'm going to take my brain and go home now. I'm not going to work on this anymore because he dropped leadership. But he is super active still helping the project. It's something that he still cares about. So this is, you know, I've had conflict with Dave in the past, but Why I respect him is because he still, he participates. He's still in the game trying to help in some way. So props to him and the team working on the OWASP Top 10. **25:33 Chris Romeo:** Yeah, definitely. So what else? Now you do stuff with the cheat sheets too, right? I wanna make sure our listeners know. Some of our listeners may not even know what a cheat sheet is in the OWASP connotation. **25:44 Jim Manico:** This project has gotten a life of its own. This is the OWASP Cheat Sheet Series. This is one of the projects I'm the project manager of. I can only take so much credit. The number of people who have added a cheat sheet to this series, and there's like 30 or 40 of them right now, there's a large community of people who have helped build, augment, and work on these cheat sheets. And the goal is to be individual topic brief guides. to help developers on a certain topic. Like, there's an AJAX security cheat sheet, there's an authentication cheat sheet, there's a Java Bean validation cheat sheet, a Ruby on Rails cheat sheet, and John Stephen worked on a password storage cheat sheet that gets a lot of topic and debate to this day, and many others, right? And so, and, you know, I saw a few different OWASP authors making their own individual cheat sheets. So I just wrapped a banner around it, added more cheat sheets, and encouraged different experts of different, you know, different levels of subject matter expertise to contribute additional cheat sheets. And now it's off and rolling on its own. Like, I just had the OWASP Montreal group, the OWASP Montreal chapter, send me a cheat sheet on vulnerability management and how to run a bug bounty and similar. So This series is just growing on its own right now. Again, it's called the OWASP Cheat Sheet Series. On the main tab, just scroll down a little bit, and you'll see the list of cheat sheets broken up into developer-builder, assessment-breaker, mobile, and Defender cheat sheets. **27:29 Chris Romeo:** And so what was somebody— when somebody opens one of these, do they actually— do you have code snippets and stuff in there, like examples of actual code? **27:38 Jim Manico:** Yes, well, some do. Some are concept papers, some are code examples, depending on the exact cheat sheet. Excuse me. There's one cheat sheet that's the JSON Web Token for Java cheat sheet that's very much full of exact code samples on the different concepts that he's talking about, where other cheat sheets like the password storage cheat sheet, this is more algorithmic, discussing the pattern you want for for doing password storage in a web application or similar. So it depends on the cheat sheet. **28:10 Robert Hurlbut:** Another, if I remember correctly, proactive controls is something related to, similar to top 10, but the other side for developers who need to find out how do I deal with some of these issues. That's something you've also talked about and worked with as well, is that right? **28:26 Jim Manico:** Yeah, this project you just mentioned is called the OWASP Proactive Controls or the OWASP Top 10 Proactive Controls. This is a project that's led by Jim Bird, Katie Anton, and myself, and the 3 of us have already put out 2 releases. We're on release 2.0, and the top 10 items are like number 1, verify for security early and often, parameterize your queries, encode data, validate all input, and so on. At the top 10, top 10 defensive things that developers should do to write secure code. It's actually difficult to come up with a list of 10 items that are the most important useful items for this particular world. So it's evolving, and we're coming up with a new list for our, for our 3rd iteration coming up for next year. But yeah, here's a top 10 list that's defensive and developer-centric in nature. Excellent. **29:25 Robert Hurlbut:** Another thing I know that you worked on and I'm very familiar with is your book. You co-authored a book on Java web application security. That's a book that actually I remember reading that a few years ago and really impressed by it. It's one I even recommend to .NET developers, believe it or not, as probably one of the best books out there on web application security. How was it to write that and are you considering updating any new editions coming out? In the future? **29:51 Jim Manico:** This is a book called Ironclad Java, Building Secure Web Applications with Java. My co-author was August Detlefsson, another Java architect who helped write the book. And, you know, this is a fool's journey, right? This is a— I'm in rusty armor charging the windmill. Yeah, go ahead, let's write a book. So from a financial pay perspective, it was horrifically bad. There are people who are like working in factories underage who probably make more than I did writing the book. But the intellectual experience in doing it, I wouldn't trade that for the world. It helped me solidify my own understanding of secure coding and helped me organize my own thoughts about the topic and what I think were good ways. So I'm also grateful for the relationship. I worked with Oracle Press, and Milton Smith on this book and the people I got to work with and looking at the process of writing a book, I thought was very fascinating. And so there was a full staff working on that with me. And that was a really awesome experience. I would definitely do it again. And I think one of the weaknesses of the book is that it didn't get into Java security enough, right? **31:14 Robert Hurlbut:** Yeah, what I saw was— what I remember is it was enough that somebody could get the basics and understand. And like I said, you can apply it to a lot of things. And there's some Java security, there's some Java in there, but almost anybody could pick it up and any developer can get some things out of it and apply to their own particular situation. At least that's what I found in my experience. **31:32 Jim Manico:** Yeah, I call it like Java-flavored book, you know. It was— I didn't go over like the Java EE APIs for security enough. We really do, but it's good for anyone who wants to learn about web security. That's both a strength and a weakness of the book, I dare say. Anyways. **31:50 Chris Romeo:** So I do have another question for you. And so— **31:54 Jim Manico:** Please. **31:55 Chris Romeo:** You live in Hawaii, right? **31:57 Jim Manico:** Yeah, I live on the island of Kauai, one of the Hawaiian Islands. Yes, I do. **32:02 Chris Romeo:** Okay. So is that— it's just kind of a loaded question, but is that not the best It's got to be one of the best places on earth to potentially live. **32:08 Jim Manico:** Well, people ask me all the time, is Kauai like you see in the movies? Is it nice weather all the time, really awesome people, and just this tropical paradise? Is that the way it really is? Chris, the answer is yes. Yes, it is. That is exactly— that's exactly what it is, Chris. **32:26 Chris Romeo:** You're making me even more jealous now as I sit here, and I live in a nice place. I live in Raleigh, North Carolina. So it's a, but it's not quite the beaches of Hawaii, but maybe someday. **32:37 Jim Manico:** And Chris, let's be honest with you. I'm off island up to 9 or more months a year. Like right now is the golden age of security. Right now is the biggest need to teach developers about secure software. So yes, I'm trying to make a good buck, but I'm also, I'm on mission, Chris. **32:58 Chris Romeo:** Yep. **32:59 Jim Manico:** I need to be out and about teaching about this stuff while it's, you know, while it's helpful and while it's relevant. So my mission is to be in planes and hotels. And Chris, a lot of people say to me all the time, wow, you have such a glamorous life. You live in Hawaii and travel the world. Chris, it's a grind. I'm not trying to cry, but it's a— as someone who's been on the road a lot yourself, it is a, a physically, emotionally, and mentally extremely challenging, uh, thing to be on the road so much living out of hotels and suitcases. So yeah, it's not, it's not a glamour road. It's, it's a, it's hard work is what it is, right? **33:43 Chris Romeo:** Yeah, yeah. But I think, you know, like, like you said, I think this, this mission is valid. And, you know, between yourself and Robert and I, we're all, we're all on this mission from slightly different perspectives. **33:54 Robert Hurlbut:** Yeah. **33:55 Chris Romeo:** And I just love being in this industry because people, you know, they always ask, hey, you know, what about this working in security thing? And it's like, I never have to worry that I'm not going to have anything to do or I'm not going to have any work to do because unless everybody wakes up tomorrow morning and decides to be good, like all the bad people switch over and decide to be good, which I don't think is going to happen, There's gonna be— there's opportunities for us, for all of us that have experience, uh, to, to get out there, and there's plenty of work to be done. So it's, it's definitely a good place to be. **34:26 Jim Manico:** Yeah, you know, I, I, I— maybe I'm being dramatic, but I don't just see it as a job. I see it as my mission, right? So I'm— when, when folks call, it's not even about— but when folks call, regardless of what the ending looks like, I feel obligated to lend assistance in some way, or at least point them in the right direction. And, you know, those are the kinds of people I work with. I look around, you know, it's— I joke, but my friends are complicated, Chris. I don't know about you, but all of my friends are really complicated. They're involved in security, and they got themselves involved in protecting either trillions of dollars of assets or government or— Incredibly sensitive work across all of them. So it's complicated. It's a pain. It's stressful. But it's our mission right now, right? It's our industry's mission. **35:23 Chris Romeo:** And we wouldn't— I know I wouldn't trade it for the world. So it's a challenging mission, but it is a very— it can be rewarding at different stages of the time through. So I think we're just about out of time today, Jim. I want to you. I mean, this has been a fascinating conversation, and, uh, I want to offer you an open invitation to come back and just talk about whatever as we go forward. So we'll definitely reach out to you again, but thanks for the time today. And, um, if you want to leave a last thought for the audience— **35:52 Jim Manico:** My last thought is, hey Robert, hey Chris, thank you so much for having me on your show. It's a, it's a big honor to be here, so thank you very much. **35:59 Chris Romeo:** Cool, thank you. **36:00 Jim Manico:** Thanks for listening to the Application Security Podcast. Our intro music is 8-Bit Kung Fu by Boring and TJ, and the outro is Southern Delight by Stefan Cartenberg. You can find us on Twitter @appsecpodcast or on the web at www.appsecpodcast.org. --- Source: https://appsecpodcast.com/jim-manico-more-owasp/