Skip to content
AppSec PodcastThe Application Security Podcast — home
31 min

Jim Manico -- The #OWASP Cheat Sheet Project

With Jim Manico

OWASP ProjectsAPI Security

Developers need concrete security answers, but finding trustworthy guidance can take longer than writing the code. Jim Manico explains how the OWASP Cheat Sheet Series turns specialist knowledge into focused, practical references.

Listen

Audio hosted by Buzzsprout. Nothing loads until you press play.

Episode chapters · 12 chapters
  1. 00:00Practical security guidance with Jim ManicoAudio
  2. 01:54Jim’s work across OWASP projectsAudio
  3. 07:08Open-source projects are a team effortAudio
  4. 08:18What the Cheat Sheet Series providesAudio
  5. 09:37How the project startedAudio

About this episode

Developers need concrete security answers, but finding trustworthy guidance can take longer than writing the code. Jim Manico explains how the OWASP Cheat Sheet Series turns specialist knowledge into focused, practical references. He describes the project’s origins, the contributors who keep it useful, and how topics move from an idea to reviewed guidance. The conversation explores how developers can navigate subjects such as authentication, access control, and cross-site scripting, and how the cheat sheets complement the OWASP Proactive Controls. Jim also discusses maintenance, drafts, and the challenge of keeping recommendations accurate as technology changes. Alongside a look at his other OWASP work, he invites listeners to review, improve, or finish a resource rather than wait for somebody else to do it.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Jim Manico:
Jim Manico — Manicode Security

Resources
OWASP Cheat Sheet Series
OWASP Proactive Controls
OWASP Java Encoder

Actionable

From this conversation

  1. Use OWASP Cheat Sheets for secure coding

    It's a collection of single-topic guides on primarily secure coding, but AppSec in general.

    8:27
  2. Keep security guidance up to date

    With all the cheat sheets and all the different topics, and of course over the years, I imagine some of them you have to keep them up to date, right?

    13:28
  3. Prioritize the highest-risk security work

    That's where you should focus your attention.

    27:05
Transcript · 31 min conversation

0:00Chris RomeoHey folks, welcome to season 3, episode 11 of the AppSec Podcast. On this episode, Robert and I are joined by Jim Manico, and Jim is back for a 3rd visit to the AppSec Podcast. And this episode, he focuses in on the OWASP Cheat Sheets project. What are they? How do you use them? And how do they impact developers? We hope you enjoy. The Application Security Podcast, here We go.

0:32Robert HurlbutHello folks, and welcome to another episode of the Application Security Podcast. So today, Chris and I are joined by Jim Manico, who actually has a distinction of being with us for 3 times. We're just thinking about crowning him as the king here because 3 times here. Welcome, Jim.

1:12Jim ManicoI gotta say, Robert, that's a real nice way to introduce me. You know, my wife often when I'm at home, she'll be like, hey, Your Majesty, you need— you want some water? And I don't feel the sincerity of when she refers to me as Your Majesty. And you, I feel a lot more sincerity from you, Robert.

1:31Robert HurlbutI appreciate that.

1:31Jim ManicoOf course.

1:32Robert HurlbutYou're welcome.

1:32Jim ManicoVery kind. I'm honored. I'm honored to be the king of the AppSec podcast. I'll take that for now. And I wanna challenge other great speakers and other great AppSec thinkers to take my crown and do 4 and keep going. 'Cause this is a great conversation, an important conversation to have.

1:54Chris RomeoYeah, and I'm gonna— absolutely, I want to go off the script here for a second because I just thought of something that, uh, I'm curious as to. You know, you're— Jim, you're really heavily involved in the OWASP universe, and I'm curious as to what have you been working on lately? I know one of the things you've been working on lately, but what are some of the other things that you've been doing lately as, uh, as you're moving projects forward?

2:13Jim ManicoYou know, it's— you know, since I was on the board, my participation has waned. You know, I'm still actively doing things that I want to talk about, but I'm trying to back up and support other AppSec rock stars who have time and passion to donate to OWASP. So, you know, one of the original projects that I worked on is the Cheat Sheet series, and I'm in transition of moving that to Dominique Vergetto, one of our European OWASP members, and he's been helping make suggestions that are that really raised the bar in a lot of areas around the cheat sheet. Things like the work he's done with the Java injection cheat sheet. So these are taking cheat sheets from thought pieces to code samples. And so we're co-leaders now, and anywhere I can help do that, I think is good for me as an OWASP leader to bring in fresh meat and fresh blood to help, you know, help the volunteer efforts of producing quality content. Let me actually answer your question though. Your question was, what else am I working on? I'm doing some of the work on the ASVS. We're a little bit behind right now. We're trying to get ASVS 3.1 out, which triages lots of questions and comments from the field from 3 and 3.01. That's the Application Security Verification Standard. That's what I got to get my eyeballs into. I did a little bit like last month and I really got to dive into that to bring that to completion. That's a project, a lot of visibility into it these days, that's led by Andrew Vanderstock and Daniel Cuthbert and myself. So that's something. And today we're just wrapping the OWASP Pro Active Controls 3.0. This is a project that Andrew Vanderstock and myself started a while ago. I've been keeping up with it, and Katie Anton and Jim Byrd have joined the project as co-leads. And a lot of it's— a lot of the work of the OS proactive controls comes from a broad audience of people. And we're finishing up the final polish of the doc. The editing's done. We're getting that to final, like, artistic final PDF creation and getting it on the wiki. But we're about to release the proactive controls. And I wasn't— those 2 projects, I have some lead. I have some kind of leadership attachment to it. One of the projects I just participate in is the OWASP Top 10. And Andrew van der Stok and 3 other awesome people have taken over leadership of the project. I'm super happy. They asked me if I wanted my name on it. I said, no, I don't deserve it. And they're like, Jim, you have, you know, just math, you have one of the top number of comments in GitHub who has hassled us with questions, so you might as well be on it. So, that's very That's very kind of them. I'm happy to— I'm very proud to have my name on a document like the OWASP Top 10 because of the level of visibility. And other things, you know, we see little bugs being submitted to the OWASP Java Encoder, some kind of dependency issue with some of the SAP integration stuff that— I'm not like doing it myself. I'm more like handling email and asking other intelligent people like Jeff Ikonowski or Jeremy Long to do the work. But, you know, I'm playing like a like a triage project manager role on some projects like that. And yeah, those are the things I think are cool. Oh yeah, one more. I keep an eye on the OWASP HTML Sanitizer, and this is the work of mostly Michael Samuel. I'm on the list and help with that wiki and play with the library once in a while to make sure everything's humming along, but this is mostly Michael Samuel's work. It's a Java-based sanitizer that takes untrusted HTML, runs it through a rule system, and spits out safe HTML. Again, this is mostly Michael Samuel's work, but it's an instrumental tool in the world of Java. I know a lot of people are using it. I've spent years promoting this work, and it's a pain in the butt to keep this control up to date. It's basically an HTML5 parser. I digress. That's the collection of things that I'm working on in the OWASP world. I love OWASP. And I find that I'm happier and more effective if I keep my nose out of politics and do more like technical contribution. That's kind of my personal mantra. And I fail to do that from time to time, and I pay the price with mental anguish. But I love technically contributing to OWASP. That's kind of my theme. All right, there you go. We need some more questions. What's going on here?

6:59Robert HurlbutWell, thanks. That's a long list. We appreciate it.

7:03Jim ManicoWhoa, a lot going on there.

7:07Robert HurlbutA lot going on.

7:08Jim ManicoAnd keep in mind, with every project I mentioned, there's other people, right? There's OP. There's a lot of other intelligent people who are contributing, pushing, helping, coding in some way. So these are just efforts I'm related to. I'm not, I'm not like holding them up on my own. These are, these are team sports, and I have, you know, I have one part in it in some way. It's like, you know, I feel embarrassed to even mention the OWASP Java Encoder. What do I do? I edit the wiki, right? Yeah, big deal. I edit the wiki and look at support calls, but someone's got to do it. Someone's got to keep the pulse going. But the real brains behind a lot of these projects are other people that I'm trying to support in some way. And I'm okay with that. I'm okay with that place in the universe, right? That's a good place to be.

7:54Robert HurlbutIt is. It takes a lot, you know. to work on things, to put things together, keep it going. So I appreciate everything that you do, and plus all the other people that are not named. We're not, you know, we don't even know some of them maybe, but they're out there, they're working for this. And so we appreciate all of them doing what they're doing.

8:12Jim ManicoAbsolutely, absolutely, yourself included, Robert. Thank you.

8:18Robert HurlbutSo today we're going to talk about cheat sheets. You mentioned at the beginning, we're going to continue that cheat sheets, OWASP cheat sheets. What is it, essentially?

8:27Jim ManicoSo the OWASP Cheat Sheet series is a series of wiki pages. That's it. It's a series of wiki pages that contain a collection of high-value information on web security topics. You know, it was originally built primarily to be developer guides, like how to stop cross-site request forgery, how to deal with access control, how to do third-party JavaScript management, Java Bean validation cheat sheet, little topics, digestible topics specific to developers. The intention is we're basically writing a secure coding project in some way where all the different subjects would be maintained independently and autonomously at different paces. And it's done pretty good in that area. This is some of the most heavily hit pages within the OWASP Foundation. We also have folks from the assessment world, the mobile world, the Defender world. There's a lot of draft work that we have that hasn't been published yet, that's still ongoing. It's just a collection of single-topic guides on primarily secure coding, but just AppSec in general.

9:37Robert HurlbutOkay. Yeah, I know I've seen quite a few references in OWASP Top 10 and, of course, proactive controls and so forth. That's good to know. So, when did it start and how did it start? I mean, what was the origin of the cheat sheets?

9:51Jim ManicoOh, wow. I wish I had the exact date, but it started perhaps even 10 years ago. And I'll give props to the true original creators of cheat sheets and OWASP. This was like the first 3 people, I believe, were Jeff Williams, who did the XSS Defense Cheat Sheet, Dave Wickers, who did, like, the SQL Injection Cheat Sheet, and Eric Sheridan, who did the cross-site request forgery cheat sheet. And from there, I jumped in, again, other people's work, but I jumped in and built a wrapper project around that, helped participate in the original cheat sheets, and helped expand it from a 3-cheat-sheet project to like a 30 or 40-cheat-sheet project that we have today. And again, this is not my work. There's literally I'd probably say about 50 different authors who have actively done major contribution that I've interacted with in some way over the last many years. So it's a large community of people, the idea being that individual experts on individual topics can jump into one, you know, one micro topic and make it great, make it awesome, so it's sensible for developers who want to address that particular risk or defense category. Again, again, again, the theme of the podcast is, you know, it's a lot of other people assisting and doing work to make it happen.

11:16Robert HurlbutWell, how did they come up with ideas? How do you get people to do these cheat sheets? And how do they then say, hey, I'm really— I really want to do this. I have a topic I'd like to talk about. How do they get into putting these together?

11:30Jim ManicoIt's a combination of ways. Like early on to really build the project, I went out and recruited people. Like I knew people who were like, Yeah, Robert, I knew people. Yeah, I know people, right? So, hey, you know people? Yeah, I know people. So yeah, I know people in AppSec, and I would go and try to guilt them into volunteering their time, or I'd see open source guides, contact the author and say, can I port this to OWASP and have you keep working on it? And most everyone is very cool about it. Like at one point, I'd say one of the most popular guides in AppSec, if we go back over 10 years, very famous guide. It was the Filter Evasion Cheat Sheet over at Hacker's website from Robert Hanson. And this is a massively hit artifact that we ported over to OWASP because he was closing down his site. So there's a second way. Some people just want to migrate content that fits the series here well. The third way is people will— now that the project has gotten uptick, now that we've recruited enough people, enough people have volunteered to do missing topics. Now that we've got momentum, we just get a lot of people who just want, want to add to the project in some way. And, you know, our goal as leaders of the project is to help facilitate getting the writing done, sometimes help tune up the wiki, and to make sure that we're adding the right content, right? So, you know, and we're making— we're making sure that we're curating properly in some way. And I've been very casual in how I do it, right? I'm just very happy to get writing contributors. As Dominique joins the project as lead, he's putting more of an academic bent on it, a little more of a fine-tooth comb on it, and putting more rigor into the content than I have in my leadership there. So this is great. We need fresh blood to push, make it even— to make it better, right? And so that's kind of the transition we're under and what we're working on now. And Keep an eye on our roadmap. You'll be able to see plans that we have to make things better.

13:28Robert HurlbutWell, with all the cheat sheets and all the different topics, and of course over the years, I imagine some of them you have to keep them up to date, right? What happens there? Do you— does somebody, or yourself, or somebody just continue to look at them and verify data that's out there or information that's out there?

13:46Jim ManicoWell, some people will just let us know, hey, there's this big mistake in your cheat sheet. And I'm like, yeah, how can we make it better? And they'll say, well, you should do this, this, and this. And then I go do that. Nice and simple. Sometimes, like, I follow a lot of the XSS defense theory out there. So, you know, I tend to keep a close eye on those pages, make sure they're up to date. Just did a bunch of changes to the DOM-based prevention cheat sheet to clean up those rules. When was I last digging into that? I was digging into that, like, in late November. I did a couple a couple dozen edits to the DOM cheat sheet to make sure that was all clean. And it's a hodgepodge. It's a random push from a variety of different efforts, people complaining, people just who are supporting individual topics already. Like, I see a group of folks when it comes to the HTTPS cheat sheet. I don't even have a lot of conversations. This is the Transport Layer Protection cheat sheet. Just people jump in and keep it up to date because it's a hot topic. You know, we lost James Bowie. What did James do? James also jumped in in December just to make a little surgical hit. He updated the link to where the EV certificate validation guide is located. You know, nothing, nothing crazy, but you know, little edits are done on a very regular basis. And there's, there's Torsten Giegler. He's one of the main, um, contributors to this. He made quite a few small edits to it recently to update to update a couple of things. So people jump in and participate in a variety of different ways. Again, our job as leaders is when people email our main list or they make a suggestion and they may not have a wiki account and it's a good suggestion to make something better, we have to take it seriously, make sure that change is triaged, and either they get a wiki account or we just go and take it upon ourselves to make the edit. So we take all the advice from the community seriously to make it better over time. And if we're If we're disciplined enough to keep doing that, then the project just naturally gets better and up to date over time.

15:50Robert HurlbutOkay. Well, thinking about those who are using the cheat sheets, so let's say, for example, developers, you know, if you're targeting developers primarily. So a developer comes to the site, comes to OWASP, hears about a cheat sheet, looks at it. What can they get out of the cheat sheet? What would be some things that they should be looking for when they're looking at a cheat sheet typically?

16:13Jim ManicoWell, if secure coding is new for them, they can flip on the master cheat sheet tab and look at the major topics that we're addressing, like authentication, session management, access control. Now, this also is in line with the OWASP Proactive Controls, which is a nice sister document to read to help absorb some of the cheat sheets as well. Once you know what individual topic you want to dive into, like, say, Say you've heard about clickjacking and you want to read more about it, clickjacking cheat sheet will— like, in the main structure of all cheat sheets is like this, where we start by briefly talking about what the category is, what clickjacking UI redress is. Because it's already been well addressed at OWASP, has its own link on clickjacking, we just link out to it and then talk about the defense categories, how to defend with CSP frame ancestor, how to defend with X-Frame-Options, how to defend with best for now pure JavaScript, and so on. And so the developers should be able to read this and be able to actively use it to provide defense on their web application in a relatively short amount of time. So that's some of the cheat sheets like clickjacking. Other ones like access control, access control is insane, Robert. It's a It's a ginormous topic, almost as big as authentication, because we can talk about role-based access control, we can talk about attribute-based access control, otherwise known as permission-based access control, we can talk about the different trade-offs, different ways to enforce access control at different layers of your application, we can talk about function-level access control, we can talk about URL-level access control, or we can basically talk about like app-level exposure access control versus function-level access control versus data-level access control. It's a party and it's complex. The access control cheat sheet is more like a mini guide, and developers are still going to have questions after even reading that guide. It's just a complex topic when you really get into it. What else? Other guides like authentication are also comprehensive. And other guides like, say, CSRF are single topics. So again, for some of these topics that are really narrow-focused, developers can jump in, gain some defensive benefit, and they're out, right? In other ways, developers are gonna need to dig deeper. Like for authentication, you can't just casually go fix authentication per se. There's a series of cheat sheets that are in the family. There's the authentication cheat sheet, the forgot password cheat sheet, the password storage cheat sheet, and we haven't even gotten into more complex topics like OAuth or OpenID Connect or SAML or federation systems. And so depending on the topic, the cheat sheet will address that topic at a different level.

19:14Chris RomeoHey Jim, I'm looking at the OWASP cheat sheets website.

19:19Jim ManicoRight on.

19:19Chris RomeoI see the kind of setup of developer builder, assessment breaker. Then there's this draft and beta section at the bottom. I was just curious, are those ready for— if a developer comes to this page and they see application security architecture, but it's in the draft and beta section, does that mean you would recommend that they still use it, or should they use it with some caution, or what's your guidance there?

19:45Jim ManicoThat's a good question. So, you know, sometimes you have dirty laundry. Sometimes you got to put that dirty laundry out and you got to not be ashamed of the dirty laundry because we all have it, Chris. You got dirty laundry too, Chris.

19:57Robert HurlbutYup.

19:57Jim ManicoWe all do and it's got to be washed. So that's the dirty laundry section. That's our shame. Those are cheat sheets that are half done or somewhat done that are parked and not ready to be pushed live. At the top of each of those cheat sheets, you'll see draft cheat sheet work in progress. So at least even if someone clicks on individual draft cheat sheet, it will show that it's not ready to go. So what, what we've committed to do this year, Dominique and I, and I've said this for a couple years now, but this is the year we're actually going to do it, right? And that's we're either going to update the draft items there and promote them to a live cheat sheet when they're ready to go, or we're going to take them off the project and get rid of them. So We're under guns to actually do this. And there's a method to my madness. What I'll do is someone says they want to do a key management cheat sheet and they seem legitimate, like they want to do it. I'll put that key, I'll put it up there. Yeah, I'm going to push that live. That looks good, actually. Look at this key management cheat sheet. Let's look at this. There's the intro, general guidelines, considerations, algorithm. I got to read it one more time, but this looks— Oh wow, this looks like it's actually ready to get a push. So I need to go through some of these. I think the key management is one that I wanna see integrated into the project 'cause it's close to being ready to go. Others like the, like what are the other ones? How about the business logic security? Yeah, we're getting some of that done. That needs a once-over before it could be pushed live. Let's keep going. Let's go one more, Chris. Insecure direct object reference. Man, that looks pretty damn lovely too. Yeah, so it looks like a lot of these are ready to be pushed.

21:43Chris RomeoAnd I guess one of the calls to action we can have coming outta here for folks that are listening is if you've been looking for an OWASP project to get involved in, go to the cheat sheets, take a look at draft and beta and see, 'cause I'm looking at a couple of these going, you know, I could probably give you some insight on Secure SDLC.

22:00Jim ManicoGood man.

22:01Chris RomeoSo yeah, I'm going to take a look at some of these as well and look for ways to potentially help on this side. But for our listeners as well, take a look at the Cheat Sheets project, look in the draft and beta, and if you're an expert or you know a lot about something in one of these categories, reach out to these folks and get involved. That's my message about OWASP. Get involved.

22:23Jim ManicoAwesome. So more concise answer to your question, I'm either going to push, promote a few of these into the project today. Some of these are going to be on our— need a lot of work, and they'll be on our draft list to work on through 2018. And then on New Year's Day, we're going to have a cheat party, me and Dominique. It's going to be a really brief party where we make a decision that it's either ready to go or it's out of the project. So there will not be a draft and beta section anymore as the project moves into 2019, or just the project matures this year. So I'm glad you pointed that out.

22:56Chris RomeoYeah.

22:56Jim Manicopointed that out. We got to have— because that just confuses people, and a few people have complained about that. Its days are numbered, Chris. That's what I'm trying to say.

23:04Robert HurlbutSo you have less than a year to, uh, to go in and, and, uh, make a decision on some of these if you haven't already, right? So if somebody's interested in something, save the draft cheat sheet.

23:17Jim ManicoThat's, that's the message here.

23:18Chris RomeoIf you want to save any of these things, you got to step up today, or these things are going off the cliff And I gotta say, this is all—

23:26Jim Manicothese are all heavily hit resources. It's— these are things that, that I, I really, I really want to take seriously. So I'm gonna make sure that I contact any of the existing authors who've listed themselves as authors before we drop it out of the project and still track those out of the project in some way to still get people and encourage people and help people to, to work on these, these cheat sheets. It's okay to cheat, so I'm trying to say. Yeah.

23:53Robert HurlbutExcellent.

23:54Jim ManicoExcellent.

23:55Robert HurlbutOkay, well, you talked a little bit about some of the future here. Any other things that you're seeing long-term, next few years, beyond that, in terms of cheat sheets? Any other thoughts on that?

24:06Jim ManicoOn this specific project? Take a look at our roadmap. This is Dominique jumping in, who is taking a much closer look at the project and what's hit and what needs work, and we can see that there's 5 different cheat sheets on our immediate radar that we're both looking at. We want to get the server-side request forgery cheat sheet up and running. This is a really important web service topic around how malicious input sent to an external web service can manipulate the path of a dynamically created link that talks to an internal service, and you can even reroute those internal requests. This is again SSRF, server-side request forgery. It is legit and for real. We need to create it. So Dominique's gonna take lead there. I'll definitely help. There's the forgot password cheat sheet. This is already in a good place in terms of the content there. This is one of our older cheat sheets that's been maintained by a group of us from some banks and other big security companies. And so we're gonna get some proof of concept code in there to help augment that heavily hit resource. There's the password storage cheat sheet. We wanna talk about Argon2 with a code sample. I also wanna add in, it's usually a good idea to hash before you salt and before you use one of your— especially before you use one of the adaptive algorithms to make sure you're saving your password storage system from very long passwords or truncation problems in algorithms like bcrypt. I believe some bcrypt implementations they truncate down to like 72 bytes. So if we hash first and then bcrypt, it'll be a much, much more rigorous or much better defense mechanism. Those are the edits we're making to the password storage cheat sheet. OS command cheat sheet, we just need a little beef there and some demos or demo code on how to actually do the right defense in certain situations. And Ruby on Rails, that just needs a lot of love. It needs to be updated. And someone jumped in and said they wanted to help. So, you know, on our, on our roadmap, we've listed him as someone who wants to work on this. This is a place that we can now park our work-in-progress cheat sheets without muddying up other parts of the project. A lot of this is Dominique's leadership coming in. Gotta— I can only support what he's doing, what he's trying to accomplish here. There you go. There's some of the things that we're working on to augment the project over the next couple of months.

26:40Robert HurlbutGreat. Lots of work. I appreciate it. We all appreciate it. And for our listeners, again, if you'd like to help, like to work on this, get in touch. Or if you've never heard about this, go check it out. See what's going on there. Well, Jim, we really appreciate you being here with us today. Do you have any maybe final words you'd like to impart to our listeners about cheat sheets or anything about OWASP?

27:05Jim ManicoWell, it's great to cheat. These cheat sheets are highly visible, heavily hit resources that helps developers all over the world and other security professionals over the world care about application security in some way. So if you have anything from the smallest little edit suggestion to a desire to write your own cheat sheet from scratch and maintain it forever, you're your volunteerism, your consumerism of these, and any feedback is always greatly appreciated. You can reach me at [email protected], J-I-M @owasp.org. And there's a lot of— my thoughts on OWASP are there's a lot of waves at OWASP, political, and that's what happens when human beings congregate. And that's awesome, but What I think is even more awesome is the massive amount of technical contribution that we see at OWASP through the wiki, through GitHub, through the different content projects and actual code projects at the organization, and the people going to conferences and giving talks and doing training. Really, they're not doing this to make a big buck. They're doing this because they care about the community. And it's easy to complain and look at parts of OWASP that don't suit your personal needs. It's easy. for me to point that out for myself. But even more important is to find places within OWASP that do feed you, that do support you in some way, or places that you can actively help without causing too much turmoil. I'll add that one in there. So you can find some positive ways to contribute to OWASP. That's where you should focus your attention. That's my thought of OWASP. thought about OWASP after being a part of the foundation for almost a decade now. There's, there's such a huge organization with so much going on. It's easy to find things to complain about, but it's also easy to find places that, that thrill you and do good. Then put your attention there. That's, that's my word of the day about OWASP.

29:12Robert HurlbutAnd we appreciate it. Well, Jim, thanks again for joining Chris and I today. And you're always welcome back. We'll make sure that your crown's here for now, but as you said, you know, the challenge is out there to others as well. So again, welcome, we welcome you again anytime, and thanks for joining us today.

29:34Jim ManicoAnd one more, you two guys, so Chris and Robert, you guys are the AppSec Podcast now. So you've really done great work, and I know as you do your first podcast, you're like, Is this gonna work? Are we gonna do this? But now you're like, you're cranking now. You're a production machine putting out AppSec podcasts on an extremely regular basis with what I think is great content. You're doing a great job. You guys are the AppSec podcast. Keep up the great work.

30:01Robert HurlbutThanks. Thank you.

30:04Jim ManicoThanks for listening to the Application Security Podcast. If you enjoy the podcast, please do us a favor and visit the iTunes Store and give us a 5-star rating. Our intro music is 8-Bit Kung Fu by Born and TJ, and the outro is Southern Delight by Stefan Cartenberg. You can find us on Twitter @AppSecPodcast or on the web at www.appsecpodcast.org.

5,328 words · transcript by assemblyai

More like this

View all episodes →

Get Reasonable AppSec: new episodes and useful picks from the archive.