--- title: "Josh Grossman, Avi Douglen, and Ofer Maor -- AppSec in Israel and Three Talks to watch from AppSec USA" url: https://appsecpodcast.com/josh-grossman-avi-douglen-and-ofer-maor-appsec-in-israel-and-three-talks-to-watch-from-appsec-usa/ date: 2019-01-11 duration_seconds: 1835 guests: ["Josh Grossman", "Ofer Maor", "Avi Douglen"] topics: ["Threat Modeling", "Security Testing", "Conferences and Community"] audio: https://www.buzzsprout.com/1730684/episodes/8122657-josh-grossman-avi-douglen-and-ofer-maor-appsec-in-israel-and-three-talks-to-watch-from-appsec-usa.mp3 transcript: true --- # Josh Grossman, Avi Douglen, and Ofer Maor -- AppSec in Israel and Three Talks to watch from AppSec USA *January 11, 2019 · 31 min* with [Josh Grossman](https://appsecpodcast.com/guests/josh-grossman/), [Ofer Maor](https://appsecpodcast.com/guests/ofer-maor/), [Avi Douglen](https://appsecpodcast.com/guests/avi-douglen/) on [Threat Modeling](https://appsecpodcast.com/topics/threat-modeling/), [Security Testing](https://appsecpodcast.com/topics/security-testing/), [Conferences and Community](https://appsecpodcast.com/topics/conferences-and-community/) [Audio](https://www.buzzsprout.com/1730684/episodes/8122657-josh-grossman-avi-douglen-and-ofer-maor-appsec-in-israel-and-three-talks-to-watch-from-appsec-usa.mp3) ## Show notes What can the wider AppSec community learn from Israel’s unusually dense security ecosystem? Josh Grossman, Avi Douglen, and Ofer Maor join Chris at AppSec USA to discuss how military experience, universities, startups, and a thriving OWASP chapter feed the local community. Each guest also introduces a conference talk with a practical lesson: getting better value from penetration tests, connecting threat modeling to business priorities, and automating security work alongside development. The conversation examines black-box testing, tester skill, clearer reporting, and feedback into engineering backlogs. Along the way, the guests explain how community events grow through consistent participation and shared ownership. It is both a snapshot of AppSec in Israel and a guide to three talks worth revisiting. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Security Journey provides application security education for developers and everyone in the software development lifecycle. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Josh Grossman, Avi Douglen, and Ofer Maor: → [Josh Grossman on LinkedIn](https://www.linkedin.com/in/joshcgrossman) → [Avi Douglen on LinkedIn](https://www.linkedin.com/in/avidouglen) → [Ofer Maor on X](https://x.com/OferMaor) Mentioned in this episode: → [OWASP Israel](https://nest.owasp.org/chapters/israel) → [OWASP Global AppSec conferences](https://owasp.org/events/) → [Maker’s Schedule, Manager’s Schedule](https://paulgraham.com/makersschedule.html) Chapters: 00:00 AppSec in Israel and three conference talks 02:31 How security experience shapes AppSec work 04:20 Avi Douglen’s security origin story 07:16 Israel’s security ecosystem 08:52 Growing the OWASP Israel community 11:04 Universities and the security talent pipeline 14:00 Community lessons after the break 16:18 Getting value from penetration testing 19:07 Black-box testing and development teams 23:01 Value-driven threat modeling 25:23 Automating application security work 27:26 Feeding security results into the backlog 29:05 Talks and final recommendations ## Transcript *5,664 words · assemblyai* **0:00 Chris Romeo:** Hey folks, season 4, episode 23 of the AppSec Podcast. On this episode, we're joined by 3 individuals who were at the AppSec USA conference from Israel, and they were there to speak. So we talk about the AppSec scene in Israel in general, and we also provide a high-level view as to what they were there to speak about. So this may give you some pointers to a couple different talks at AppSec USA that you want to go look up on the YouTube channel. We also want to congratulate Ofer Meir, who is one of the individuals interviewed here, as he has been appointed as a, a member of the OWASP Board of Directors. So we wish him good luck in that endeavor and hope to hear from him again here soon as he starts making stuff happen in the OWASP universe. We hope you enjoy. The Application Security Podcast. Here we go. Hey folks, welcome to this episode of the AppSec Podcast where we are at AppSec USA, and I am joined by a collection of gentlemen who are responsible for OWASP in Israel. And so as we always do on the AppSec Podcast, we're going to start with a couple of origin stories. One of our guests, Ofer, who has actually been with us before, so you've already heard his origin story. But let's go ahead and start with Josh. Why don't you go ahead and introduce yourself and tell us, how did you get started in AppSec? **1:45** Uh, yeah, hi, my name's, uh, Josh Grossman. Um, I guess I was always interested in it from school days. It's something that I found interesting technology security, but it took me a while to figure out how to actually make it into my day job. So after doing computer science, I started off in IT risk and then focused on IT security, and now the last few years I've been working in application security. So now I'm at a company called ComSec Global, which is a large consultancy based out of Israel, and my day job is now application penetration testing, architecture review, So, coming from an IT risk background first, how is that— **2:31 Chris Romeo:** how do you see that impacting your approach to AppSec? **2:34** I think it gives a wider view of what's the business impact as well. It's not just looking, okay, what is this application? It's also looking at what is the business purpose of this application? What's the business risk of this application? Along the way, I also picked up a Chartered Accountancy qualification. Again, that also helps emphasize the business impact, which to me is the big driver for buying for AppSec. It's got to be, okay, why is this important to the business? Why should the business put priority on this? **3:05 Chris Romeo:** Was that like a certification or the qualification that you mentioned? **3:08** What is that? **3:09** Yeah, that was Chartered Accountancy in the UK. **3:13 Chris Romeo:** Okay, so it's like a— is it something— it's IT risk specific or is it like finance or— **3:17** Oh no, that was back in the IT risk days when They offered me the opportunity to do regular chartered accountancy as well, and something I felt would be a good addition to that. I've always very much specialized on the technology side and technology risk, but it gave that business context which I didn't necessarily have coming from purely technology background. **3:35 Chris Romeo:** Yeah, and I think that's missing from a lot of, a lot of people that do pen testing. They're missing that IT risk side of what's the actual business impact of what I'm doing. They're all about how am I going to break it. And not really what is the bigger impact. So that's good for people that are potentially getting started in or wanting to get started in the testing side. Understand that business risk and be really good at breaking stuff and you're going to make your way to the top of the pile, at least from my perspective. **4:01** No, definitely. I mean, I've got a team of consultants who work with me and I do a lot of report reviews of application penetration test report reviews. A lot of the time I'll come back to them and say, okay, this is a great finding, but let's make sure we're bringing out What is the business risk? What is going to happen to the business if this finding gets exploited? Yeah, I think that's an important point. **4:20** Cool. **4:20 Chris Romeo:** All right, Avi, what's your security origin story? If there was a comic book about Avi, what would episode 1 look like? **4:27** Hey, I'm Avi from House Dublin. I started my way as a programmer. I was working as a programmer at a software company and, you know, asking the annoying questions of why does this work this way and that. I also realized the authentication system was really a bit dodgy and flaky, and that was the first time that I started noticing software security issues. Very easy to get past the authentication system to hack people's salaries. But I noticed this as the programmer side. And then in 2001, I got a job as a programmer working for the Israel National Police. Which as national police departments go, it's one of the largest. I mean, it's about the size of the New York City Police Department, but different challenges as a national police department. So I was working there as a programmer on software security infrastructure. We were building out access control systems for other applications, a whole lot of isolation, segregation, and permissions. So that's when I really started getting into in-depth a lot of security issues. And from there, I got recruited into a company by the name of ComSec, which you just heard about. This was long before Josh joined. So, there I really like went to school there and spent a lot of time as a software security consultant, more on the white box side of things, more on the building code correctly, secure coding, design, and things like that. I spent some time at Microsoft. doing security for their enterprise firewall. That's, I think, where I first started really practicing threat modeling in the Microsoft school. After a few years, I left, I went freelance for a while, and then I opened my own consulting company called Bounce Security, small boutique, and we focus on what I call value-driven security, high-end things that bring the most value to your product and not everything that needs to be done. And that's what I was talking about here. My talk was on value-driven threat modeling and how to take this big monster of threat modeling and being able to apply this to agile workflows. **6:39 Chris Romeo:** And so going back to that whole vulnerability that you found, you didn't change your own salary though, right? **6:48** It was for— it was the product for customers. **6:50 Chris Romeo:** Ah, it's probably far enough along in the history that— but no, I didn't think you'd— **6:56** It never occurred to me to go black hat. I wish it did. **6:59 Chris Romeo:** I'm glad it didn't. So, you know, we need more white hats in the world. So I guess one of the main things we want to chat about here is— I certainly realized that we should also recognize that Ofer is with us as well here. And welcome, Ofer. Thanks for being here with us as well. **7:15** Thank you for having me again. **7:16 Chris Romeo:** And so when I think about You know, cybersecurity in general, you hear a lot of, a lot of about things that are happening in Israel, a lot of startups and a lot of focus. And so I guess if we just logically kind of follow down that, that thread, there's going to be a burgeoning AppSec community there. And so I'd love to hear, when I say the AppSec scene in Israel, what is the AppSec scene in Israel? What does it look like? And, and what's, what's kind of happening there? **7:45** So I think when you look at technology companies in general around the world, ecosystem is a great thing to have around you. And so application security started in Israel pretty early. And if you look at some of the first vendors in the space, right? So Imperva was a WAF vendor early in 2000 and AppScan, which was the first DAST scanner, they all emerged in Israel and that sort of kicked off the AppSec scene in Israel. And so around that, more and more companies formed AppSec vendors and technologies and consultancies, and then bigger companies started recruiting people in Israel because there's this ecosystem. So I think that overall Israel has a surprisingly large AppSec community, and if you look at the AppSec events that we have in Israel, we get almost 1,000 people registering. Wow. And You know, 70%, 80% of that showing up in events, that it's just huge compared to how big Israel is. I think our mailing list has how many now, Avi? **8:52** The mailing list I think has 1,600. The Meetup group has 1,300. I don't even know how many on the LinkedIn group. **9:00** I mean— And this is all in a country that's just 8 million people. So it's a fraction of the population of California. **9:07 Chris Romeo:** So you got to be one of the biggest OWASP chapters then. I mean, I know New York, the Metro New York area chapter is huge. You got to be up in Bay Area chapters big, but you got to be like top 3. Yeah. **9:19** Um, according to the meetup, according to the meetup, we're the 7th largest OWASP meetup. **9:23** Okay. **9:25** Because there's one in like Eastern Europe is all Eastern Europe and Germany is a big, is like all of the region. Yeah. **9:31** Yeah. **9:31** And then you have LA, which is like 3 different chapters all in one. **9:35** And, um, but yeah, definitely it's definitely one of the largest ones. **9:38** Uh, one correction about Ophir's numbers, actually the registrations were, uh, closer to 1,500 and we had 850 people show up this year. So the numbers just keep going up. **9:47 Chris Romeo:** Yeah, that's, and that's a big event. I mean, that's not quite AppSec USA where we're sitting right now, but it's not too far away from the numbers that we have in this, in this style of event. So, so what do you say, you think, you think the reason for that then is, is it the AppSec scene then that's driving this in Israel? Is it— where are all these AppSec people coming from? **10:08** I think there's a deep culture of paranoia in Israel. It comes naturally with a culture of being defensive. And yes, we're all cowboys, but we also want to have a very strong perimeter and, you know, strong, robust systems. And as cowboys, we tend to see how things break very quickly. Right? I think, you know, I didn't have the military experience with computers, but there are— that obviously definitely feeds into it. There's a lot of units that we don't know about. There's the AD200, and there's a lot of other units that are not as well known because they're actually better. So there's a lot of history, a lot of technology work going on in there behind the scenes. So eventually soldiers come out and, you know, they either open startups or join other companies. **11:00** Yeah. **11:00** So there's a lot of A lot of talent there. **11:04 Chris Romeo:** Is the university system also pumping out some people from a security perspective more than other places? **11:11** I would say that unfortunately that's not the case yet. Okay. There are a couple of colleges that are trying to do more security programs, but it's mostly graduate programs, not undergrad. **11:24** I think the past few years some of them are starting to put some into that. And I think that's also partly because we've been doing a lot of interaction with the universities. We're hosted this year at Tel Aviv University. The last few years we're hosted at other technical colleges. So I think that interaction also feeds back the other way also. So they're starting to also have a bit more of a security program. **11:48 Chris Romeo:** That's probably a lesson learned for other chapters out there in the OWASP universe, that having a partnership with a local university is a good, good feeder, because you must have gotten some people that were just computer science students that just went, oh look, there's something happening here, I think I'll go. Or teachers that said, hey, send— you know, I'm taking— you guys get the day off, I'm sending you to go and attend this event because it's here on campus. **12:10** So yeah. And usually you'd find somebody in the university who, like a professor, that wants to do more in cybersecurity, and that's how we can partner with them, and that feeds on their internal agenda to build a cybersecurity program in the university. And we've had talks in AppSec Israel coming from graduates who put their thesis for a talk in AppSec Israel. So that was very interesting stuff we got. **12:36 Chris Romeo:** Yeah, kind of gives you some more of that academic perspective that we tend to not, you know, like at least at the big conferences, AppSec USA and EU, we tend not to get a lot of that academic. At least it doesn't— maybe they get submitted, but they don't make it to the final kind of setup. So yeah, that's, that's pretty, pretty cool. **12:55** I do want to point out that in addition to the universities and colleges, there's actually a really interesting program going on now in high schools. **13:02** Oh, really? **13:03** Led by the Ministry of Education and the Army to be part of the matriculation exam. And one of the choices that students can have is they call it the Cyber Defense Program. I mean, they don't really learn hacking and stuff like that, which is probably a good thing to not teach a bunch of 15-year-olds with, you know, over Yeah, so what they do teach them is, you know, really in-depth programming. So it's Python, they learn in-depth networking, they understand how to take the protocols apart, they learn operating systems, so that when they graduate and go into those units in the Army, they already have that very strong basis on how to do those things. **13:39** Okay. **13:39** And it's a really smart program because up until last year— I don't know what's going on this year— but up until last year, they did interaction with a lot of people from the industry. that experienced people, not just teachers, they brought in people like myself and a lot of other people that, uh, with experience in security and programming, brought them in to mentor the high school kids. **13:58** Okay. **14:00 Chris Romeo:** After the break, we'll hear from the team about how they draw people to come and attend the events that they host in Israel. The Application Security Podcast operates with support from Security Journey. A security belt program provides the 3 pillars of successful AppSec Learning, application, and experience. Visit us on the web at www.securityjourney.com to learn how you can teach and empower your developers using a new kind of security training. With your monthly meetups, what are some of the things that you do to draw all these people to come and attend these events? **14:42** So we have a lot of really interesting talks. We always get one of the companies to give in some of their recent research, and we have a lot of other interesting talks. Some of them are definitely conference-level talks. **14:54 Chris Romeo:** Okay. **14:55** I think one of the big things that a lot of people come to the meetup is actually the community. A lot of people come just because it's such a warm, embracing— they come just, you know, it's kind of like a high school reunion every month. You know, it's like to see everybody, and there's always new people there, and they come and meet all the other people in the industry, and it's just A very explosive feeling of community there. **15:18 Chris Romeo:** And that's, that's another, I think, lesson learned for other chapters out there that are trying to grow. If you don't have that type of a feel in your meetup, then something's not working right. Like, these things are supposed to be educational but also networking for the people that are, that are coming. And if you only— if you're only getting that one box checked of, well, we have great talks, but yet people Just kind of get up and walk out at the end and they don't really— it's like a lecture and not a community. **15:47** I think an important tip here is always make enough time in the beginning and in the middle of your agenda that is a big break. Because what happens sometimes I see chapters doing, it's like people get there, the talks start immediately, 3 talks in a row, and then it's done. People will usually not hang out after the last talk. It's just normal psychology. So if you want to get people to sit and talk, you need to have a proper, you know, 20-30 minute break in the middle. **16:18 Chris Romeo:** Yeah, that's a good, uh, that's a good idea. It's a good, good thing that other chapter leaders can take away and, and use that. So I guess the other question I had for, for you guys was, I'm really curious, you know, kind of a, from a almost a quick couple of minute answer, what's the most interesting thing that you're working on in AppSec right now? And I'm going to start with Josh over here because I know he's done a talk, and everybody, everybody here represented at the table is doing a talk at AppSec USA. So, but Josh, let's go ahead and start with you. Like, what, what's the most interesting thing you're working on in AppSec right now? **16:52** So I suppose the main thing that I'm thinking about at the moment is again around the application security testing. So I think, you know, one of the features of these conferences is there's a lot of sort of forward-looking talks, a lot of ways, you know, how you can change your overall strategy. But I think one of the One of the main points that I see is that most companies, their primary control at the moment is the application security testing, as in application penetration testing, getting someone to come in and test their applications. You know, I spoke to some of the sponsors here to see if their experience matches mine, and I asked them what they did, and they said, we do application architecture and secure design and assisting developers. And I asked them what the split of the work was between that and the application penetration testing, and they came back with something along the lines of 80% penetration testing. And so what my talk here was about was trying to say, okay, look, everyone's doing this anyway. Let's try and build more value into the process. Let's try and think slightly more upfront. Let's try and tailor the scope better towards the application, towards the company, to make sure they're getting the most value out of that. And to me, the main, main ways of doing that are trying to take as white box approach as possible. trying to be as transparent as possible to make sure the tester really understands what's going on behind the scenes in the application they're testing. **18:11 Chris Romeo:** Mm-hmm. **18:12** And also, you know, very much maintain a dialogue between the tester and the developers, the architects in the application that's being tested, to make sure that the tester can go to the developers saying, what does this do? What happens when I press this button? What's this process? Where does this data end up? And the developer understands better, you know, what is the tester looking for? What sort of things are they going to try and do? What more other information can I give to the tester that will help them provide a more tailored service? So that really was the basis of my talk. It was about here are loads of ideas, some of which will be applicable to some people, some of which will be applicable to other people, but hopefully everyone can take these ideas and go away and think, okay, how can I get more value out of this process that we're doing anyway and we're going to be doing for the foreseeable future until tools are developed that are good enough to replace that process. **19:07 Chris Romeo:** So most of the tests that people are doing these days, are they black box with limited communication between the tester, the outside tester, and the development team? Like, are people not— so are you recommending these things because people are just flat out not doing them right now? **19:22** I think that's the main challenge. I think that Because companies are being required to do them. If they're a big company, maybe they've got regulation that requires it. If they're a small company, maybe they have customers that require it. And I think a lot of companies maybe see it as a checkbox, say, okay, we just need to get this done so we've got a piece of paper and we can move on. And I think that, again, if they're doing it anyway, they can put that little bit of extra effort in there, extra thought in. **19:51** Yeah. **19:52** And really get a much greater result, much more high-value result. **19:56** Yeah, that's— **19:58 Chris Romeo:** yeah, that makes sense. I mean, I think a lot of times those tests happen in that the company is just like, hey, I just want to— I just want to get this done. I don't want to have to— this is a checkbox moment. Like, I just got to check the box that says that, hey, I did the test, versus actually wanting to get good positive security change as a result of the findings. **20:21** So yeah, I think, I think the black box part comes from, yeah, as a direct result of that, saying, okay, let's just, let's just get this started. We'll find a tester, we'll throw them some URLs, we'll throw them some users and say, knock yourself out. **20:32 Chris Romeo:** Yeah. **20:33** Um, and what happens is that the tester doesn't necessarily know as well what's going on behind the scenes, and if they could ask a few, a few straightforward questions, a few clarifying questions, or I mean, you can go a lot further. I've had tests where they've provided me with the source code to the application, and suddenly instead of spending an hour, 2 hours tailoring payloads to try and guess what's going to go past, I just look in the code, see what that particular function does, see what payload is going to work, and I'm done. Ultimately, I've spent the same amount of time, but I've had time that I spent guessing payloads, I'm now spending working on other areas of application, other possible vulnerabilities. **21:10** Okay. **21:10 Chris Romeo:** Okay, versus, yeah, versus crafting the attacks and spending their time figuring out things that you can see in the source code. **21:17** Yeah, exactly. **21:18 Chris Romeo:** Yes, I mean, what do you see as far as the kind of skill level? I mean, one of the complaints I hear a lot of people— I work with a lot of different companies, and there seems to be a pretty large divide between kind of what abilities that exist by penetration testers. And so Is there really kind of a bottom feeder type of layer of app testers? Do the scanning testers still exist out there? The ones that run the scanning tool and then send you the report for $25,000 or something? **21:49** I haven't seen it personally, but there are people in here nodding their heads, that's for sure. I, as part of other projects I've worked on that are not strictly penetration testing, I've seen other reports. I've been less impressed. I think that that does exist, and you do risk that you end up with a report where you read it and you think, okay, well, that doesn't seem like a finding to me, or maybe that is a finding, but if it wasn't for the fact that I've been doing this for years, I wouldn't necessarily understand why it was important. **22:21** Yeah. **22:23** And again, one of the big suggestions I brought out yesterday at the talk was get sample reports from the tester. If you don't know what you're getting at the end, then You're not— you're gonna run the risk of, you know, even if they've got skilled testers, if they can't articulate that in a report, if they can't produce a report that's really going to explain to you, okay, here's what you need to do and here's why you need to do it, then you haven't necessarily got that value. **22:45 Chris Romeo:** Yeah, and so that's, yeah, kind of a value approach to the kind of the penetration testing side. So Avi, then you're kind of focused on the value-driven threat modeling. **22:57** Yes. **22:57 Chris Romeo:** So your talk wasn't called Value-Driven Penetration Testing though, right? **23:00** No, although maybe we should coordinate. **23:01 Chris Romeo:** It would have been like a nice kind of connection. Yeah, so value-driven threat modeling. I mean, what is that? What does that actually mean? I mean, I've done a lot of threat modeling. We've had probably 10 episodes of this podcast with everybody's kind of idea about threat modeling. What is value-driven threat modeling? **23:17** So threat modeling gives a huge amount of value. It's a great thing to be doing, except that there is a very strong correlation of diminishing returns. So you get most— what's the point of doing threat modeling? To build secure features. And you can do that with probably, you know, 20-30% of the effort that you do in a full-size threat model. And you get most of the value out of that because you're building the secure features. Sure, there's a huge amount of value to be squeezed out by doing full-size, really rigorous, you know, very formal threat model. But you can get the developers and you can scale a lot better if you do minimal amount of— I call this minimally viable threat model or just enough threat model. And that's something that you can translate for developers to be able to do as part of the regular process. Because if you try to get them to do a full-size threat model, it's not gonna happen, or they'll do it in the least useful way possible. Developers are smart people. They know how to get around any kinds of things that— the rules that they don't want to do. But if you give them something that's easy and simple and that they feel that they should be doing anyway, then they'll do that. And they again get most of that value out of it because they're building secure features, which is the point. **24:26 Chris Romeo:** Yeah, and I always think about, like, you know, I spend a lot of time studying developers and thinking about how do we best interact with them. And a lot of security people don't realize that developers actually have a flow to how they work, and they don't work like, you know, there's like the manager versus maker schedule. I don't know if you've ever seen that. It was posted on Y Combinator 20, 15 years ago or whatever, but it's still valid today. And that the manager schedule, we have meetings every 30 minutes and our schedule is completely booked. The maker schedule, the developer is somebody who that kills their flow. If you give them a meeting at 10:30 and one at 2:30, you've almost killed their whole day because they can't get back in the zone already. And so when I think of like, when I hear value-driven threat modeling, I'm thinking of something that fits inside of that flow. It's in their normal process and how they work, and it doesn't cause them to have to leave and task switch away from the way that they're already working. **25:20** Yeah, absolutely. Exactly that. **25:22** Okay. **25:23 Chris Romeo:** Ofer, what, um, what are— what's the most interesting thing in AppSec that you're, uh, working on these days? **25:28** So it's interesting we got to the developer workflow because I think that's probably what I spend most of my time on now. So I'm also looking at application security testing from tools and automation perspective, and I think finding the right way to fit it into the developer flow is today our biggest challenge. And I think You know, I've been preaching to get developers more involved in application security for most of my career. **25:54** Mm-hmm. **25:54** But I think what's now is making the case for us is the move to faster development, the move to CI/CD, to pipelines that have a much faster cadence. So if we talk about developer workflow, it's much faster now than it used to be. And these interruptions that security causes are a killer to this process. **26:17 Chris Romeo:** Mm-hmm. **26:17** And so what I've had my talk about today is how do we build a way to do test automation, security test automation, as part of this workflow of continuous delivery where we get organizations pushing hundreds of updates every day into production? How do we find a way to do this efficiently and but at the same time to manage risk. And basically what I'm talking about is having parallel tracks of testing where some of them are inline, are part of that process, and can be run by the developers and used by the developers because they are completely integrated in their workflow and they're easy and they are instant and they don't disturb the developers and they do a certain amount of risk reduction for us, right? They don't find everything, but they find a lot and help us fix it. And then we have parallel tracks that are slower where we can have the more rigorous testing, the deeper testing, maybe driven by security people at this point. But these don't interrupt the cadence of releases of the CI/CD, but rather creates entries in the backlog so that they can fix in a certain period of time. **27:26 Chris Romeo:** And so you've got that kind of in your model, you've got that completely automated. So the parallel tracks Then are feeding back into the backlog without— or is there a person that has to watch those parallel tracks and put in issues? **27:39** So the fast track has to be fully automated. It can have zero human interference in it because then it's too slow. And then the slower tracks, that depends already on what you want. Maybe you don't have resources, so you're going to bring managed services. So there's already human interference there, but that's fine because that's on a slower track and it doesn't slow down your developers. Maybe you want to have, you know, full rigorous pen testing at the end and somebody to look at and decide what's high priority, what's low priority. That's fine. We're not going to be able to automate every single security process in the workflow, but we need to understand that every workflow that is not automated has to be on the side on a slower track and not become a blocker Yeah, that makes sense. **28:30 Chris Romeo:** And so, um, so yeah, I think what I'd like to do for our listeners is the— one of the beautiful things about AppSec USA is that they record and publish the talks after, as well as the slides and everything. So, um, I think we've given the listeners enough of a description and kind of an abstract of what each of your talks are actually going to, going to be about so that they can then go and check out kind of the full versions. But, um, Avi, can you just give us the full name of your talk so that when people go to look it up, they'll Don't know what it is. **29:00** Value-driven threat modeling. **29:01 Chris Romeo:** Okay, and Ofer? **29:02** Scratching the surface of your CV. **29:05 Chris Romeo:** Okay, and Josh? **29:06** How to get the best AppSec test of your life. **29:10 Chris Romeo:** Wow, Josh is the best marketing title right there out of all of you. Sorry, but that's a great marketing title. **29:16** To be fair, I may have based it off a pre-existing talk, but I based it off sort of the parallel in there. The intro to my talk was basically saying if you're a security tester and you want to give a better test, or you want to know new techniques new methodologies, there's loads of resources out there. But for somebody who wants to get a better test, there isn't so much. So I based it off one of the talks about giving a better test. Yeah, sort of mirrored it. **29:38 Chris Romeo:** That's good. Well, gentlemen, thank you for taking the time here out of your busy schedules at AppSec USA to provide this interview, and I'll encourage all the listeners to go and check out the recordings of these talks when they're posted in the next couple of months and Have a great rest of AppSec USA. **29:55** Thank you. Thanks so much. **29:56** Thanks for having us. **30:00** Thanks for listening to the Application Security Podcast. If you enjoy the podcast, please do us a favor and visit the iTunes Store and give us a 5-star rating. Our intro music is 8-Bit Kung Fu by Born and TJ, and the outro is Southern Delight by Stefan Cartenberg. You can find us on Twitter @AppSecPodcast or on the web at www.appsecpodcast.com. --- Source: https://appsecpodcast.com/josh-grossman-avi-douglen-and-ofer-maor-appsec-in-israel-and-three-talks-to-watch-from-appsec-usa/