Skip to content
AppSec PodcastThe Application Security Podcast — home
38 min

Nancy Gariché and Tanya Janca — DevSlop, the movement

With Tanya Janca and Nancy Gariché

OWASP ProjectsSecurity TestingDevSecOps and CI/CD

How does an intentionally vulnerable application become a community learning movement? Nancy Gariché and Tanya Janca explain the evolution of OWASP DevSlop from a project into a live, collaborative way to teach application security.

Listen

Audio hosted by Buzzsprout. Nothing loads until you press play.

Episode chapters · 13 chapters
  1. 00:00DevSlop as a movementAudio
  2. 02:11Meet Nancy Gariché and Tanya JancaAudio
  3. 05:11What OWASP DevSlop isAudio
  4. 09:03API security and the project’s scopeAudio
  5. 11:14Learning through the DevSlop ShowAudio

About this episode

How does an intentionally vulnerable application become a community learning movement? Nancy Gariché and Tanya Janca explain the evolution of OWASP DevSlop from a project into a live, collaborative way to teach application security. They describe the DevSlop Show, its deliberately imperfect demonstrations, and the value of learning in public without pretending every experiment will work. The conversation explores Pixi, Paddy the Pipeline, and integrations with free security tools including ZAP, dependency scanning, and web application firewalls. Nancy and Tanya also explain how contributors can start small, join broadcasts, document what they learn, and help expand the project. Their approach treats mistakes as useful teaching material and makes hands-on AppSec education more welcoming to developers and security newcomers.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Nancy Gariché and Tanya Janca:
Nancy Gariché and OWASP DevSlop
Tanya Janca on LinkedIn

Resources
OWASP DevSlop
Pixi
OWASP ZAP
Burp Suite
Mend
OWASP ModSecurity Core Rule Set
Qualys SSL Labs

Actionable

From this conversation

  1. Keep learning new technologies and defenses

    Not only do we have to keep up with all the technology, we have to keep up with all the things about security to the new ways to protect things

    13:30
  2. Use free tools to learn your security pipeline

    There are so many free security tools.

    15:12
  3. Verify security throughout DevOps delivery

    Fix things And verify your security.

    35:35
Transcript · 38 min conversation

0:00Chris RomeoNancy Guerresche and Tanya Janca are 2 of the project leads for the OWASP DevSlop project. As we learn more about DevSlop, we realize that it is much more than a project. It's a movement. DevSlop is about the learning and sharing of 4 awesome women and is a platform for them to share what they've learned with the community. DevSlop consists of 4 different modules. 1, Paddy, an Azure DevSecOps pipeline. 2, Pixie CRS and Pixie CRS Zap, 2 CircleCI pipelines that demonstrate adding a WAF to your pipeline for automatic tuning before moving your apps to production. 3, Pixie, an intentionally vulnerable app that consists of a vulnerable web app and an API service. And 4, the DevSlop Show, where they bring all of their learning together in this video streaming series that they do live, and then they edit and place on YouTube. So, we hope you enjoy this conversation with Nancy and Tanya. I want to take a moment to introduce you to Security Journey. At Security Journey, we believe security is every developer's job. We work with our customers to help them build long-term sustainable security culture amongst all their developers. Our approach is to provide security education that is conversational, quick, hands-on, and fun. We don't do lectures. Instead, we let the experts talk about what's important. The modules are quick, 10 to 20 minutes in length. We believe in hands-on experiments, builder and breaker style, that allow developers to put what they learned into action. And lastly, fun. Training doesn't have to be boring. We make it engaging and fun for the developers. Visit www.securityjourney.com to sign up for a free trial of the Security Dojo.

1:41The Application Security Podcast. Here we go.

2:11Chris RomeoHey folks, welcome to this episode of the Application Security Podcast. This is Chris Romeo, co-host and CEO of Security Journey, and Robert is also here. Robert, welcome.

2:23Hi, yeah, thanks Chris. Yeah, it's Robert Horvath and also co-host And threat modeling architect.

2:29Chris RomeoAll right.

2:31And today we are joined by Tanya Janca and Nancy Guerresche, and they are here to talk to us about the DevSlop project. As everybody knows that listens to this podcast, Robert and I are huge fans of the OWASP universe, and anytime we get to, to have any type of conversation about anything OWASP, we're always excited to have that conversation.

2:55Chris RomeoBut first, we have to ask Nancy to share with us her security origin story. You heard Tanya's origin story a couple seasons ago when we first interviewed her, but Nancy is a new guest to the podcast.

3:10So Nancy, how did you get started in this crazy world that we call security?

3:15Well, like about everyone, it's an accident. I just started in computer science, a degree in computer science, and joined as a co-op student, the RCMP. The RCMP is actually the Canadian FBI of Canada. Maybe a bit not as cool. We don't have like movies about the FBI, about the RCMP, but we do have really cool projects. And I started as a sysadmin there. And it was a really good section to start in where I could play with different type of technologies. But at some point, I needed to specialize. I felt the need to specialize. And that's where I had an opportunity to move to Ottawa. and, um, and joined the RCMP security team. And, um, that's how I started my journey into security.

4:05That is very cool because I came from the same background as you, not from the RCMP, but from the sys— the world of sysadmin. Uh, that's how I was— my path to security as well. So I always love to hear a fellow sysadmin out there who has made this journey into Did you ever get to ride a horse when you were in the RCMP?

4:28Because aren't they the Royal Mounted Police?

4:30Oh no, I'm not an animal person, so even if they offered, I probably would have said no.

4:37You totally could have made it up and I would never have known.

4:41I would have fallen for it too if you'd have been like, oh yeah.

4:45That would have been a cooler, cooler hero story, but it's not a true one.

4:52All right, well, let's— thanks, Nancy, for sharing that. Let's jump into the world of DevSlop. And so, it's gotta be about the most interesting name in the world of OWASP. First, I'll give you that tag for the name of the project, 'cause when I mention it to people, it certainly does catch their attention. They're like, what'd you just say?

5:11Chris RomeoDevSlop?

5:12Where did that name come from, first of all?

5:14It was Nicole Becker's idea. So, there's 3 project leaders of our project, Nicole Becker, who's not here today, Nancy, and I, and then a project member, Franziska Bühler. And Nicole was— wanted, you know, we wanted to know how we could weave security through DevOps. And she's like, yeah, DevSlop, like sloppy DevOps. And that sort of became our mantra.

5:40This is— it's definitely a great name. I really appreciate it.

5:46Now, behind that name, what is DevSlop is basically a collective of 4 women, and we all had different angles of DevOps where we wanted to see how we fit into them. We wanted to learn as security professionals, you know, where's our place? So, it started with a vulnerable app named Pixie that Nicole made, and that's our first module.

6:15Okay.

6:15of our project. Then I created Paddy the pipeline, and that was our second module. Then I couldn't figure out how to share it, so I started video streaming me building it. Then Nancy joined and she joined our video stream, so that's another module is the DevSlap Show. Then Franziska made a bunch of really cool pipelines. She just keeps making new pipelines all the time. She has one that has a WAF in it, another one that has a WAF, and then it had Zap attacking Pixies through the WAF and automatically tuning itself. And she's working on a new one, but I will not spoil things.

6:50Yeah, we don't want to have to have a spoiler alert here. And for those people that are on the edge of their seat for kind of where we're going in the world of DevSlop. But okay, so DevSlop then is, it's a number of different things kind of that all come together, things that you refer to as modules. And so, we talked quite extensively about Pixie in our first interview, but maybe let's just walk through each of these and dive a little bit deeper into what these things are. So, starting with Pixie, and Pixie, since we covered it before, we can probably cover it, you know, just the shortest amount of time. But Pixie, what can I do with Pixie?

7:28Pixie is an intentionally vulnerable web app with microservices APIs behind it, and it's on the MEAN stack, so Mongo, Express, Node. And it's highly, highly vulnerable, and the idea is, is you can put it up, it comes in a Docker container, you can start it assuming you have Docker installed and turned on with just 2 lines, and then you can just play with this Instagram-esque app and interact with it and try to learn how do you test a more modern web application. There's lots of very big vulnerabilities, so it's huge wins over and over again. Nicole and I used to give a whole bunch of workshops about it before life took over and we couldn't just do that all the time.

8:19How much of the OWASP Top 10 then is represented in the Pixie vulnerable app?

8:24I would say about half. Then there's a bunch of other, like there's injection but not SQL injection, different injection. There's cross-site scripting everywhere. There's cross-site request forgery. There's things that aren't really the OWASP Top 10, as we know, it's just the beginning. the top 10 most known and worst vulnerabilities, but there's a lot more. There's a whole bunch of other vulnerabilities that Nicole put into it, including deleting on a GET request and then it doesn't authenticate the user, etc. It's pretty cool. It certainly taught me a lot, definitely.

9:03Yeah. I think Nicole also focused a lot on API security.

9:08Definitely.

9:08Okay. Which is a huge area of the industry that we definitely need a lot more attention paid to that, the whole thing of API. And I was just talking to somebody yesterday about— and it's funny that you brought that up, Tanya, about deleting on a GET request. I was just talking to somebody yesterday about that same topic, that same idea of people violating the intentions of the actual protocol itself. in the name of functionality or trying to do something clever. And the fact that doing clever things like that as developers always gets us in trouble, even though we feel like it was a really cool thing, like we, we did something really cool.

9:44Yes, please follow the protocol, please.

9:48All right, so that kind of talked— that's a little bit about Pixie. So Nancy, what, um, Tanya said you had joined up to work to kind of be part of the, uh, the video stream and kind of the show part of this.

10:03Chris RomeoTell me a little bit more about what that is.

10:04Yeah, that's the DevSwap show. So as you know, Tanya has been speaking all over the world this year and has been quite busy. So at some point she reached out to me and said if I— and asked if I could help out a couple of shows and co-host the show with her sometimes. And yeah, I got more and more involved. And so we use this opportunity to basically have some hands-on experience on things that we want to learn about. So we, we go to conferences, we learn about different topics, we go, we get involved in our OAF chapters, but sometimes we don't have the opportunity to get the experience to see demos of things working in front of us. So we invite guests over and ask them to talk about their project, and it often involves a demo. And we, we had even one of your guests.

10:57Yeah.

10:58Jeff Hill talked about rapid threat modeling, but then came on our show and we had an example. And the last part, the last half hour of the show, he could demonstrate and had an example and go through the methodology. So that was really, really helpful.

11:14Yeah, that's great too. So I've seen a couple of the episodes myself, but maybe for our audience, Nancy, just Just give the audience a little bit of a perspective on, hey, if they go and they track down one of these shows and they watch it or they're watching the livestream, what's the experience going to be like? What are they going to see? What are they going to get out of it?

11:34Okay. So, what we try to— we try to limit it to a 1-hour show. It doesn't always work out that way. But we have a guest on who has her specialty normally and talk about that, talk about that project and get an introduction of her, a bit like we do on this podcast, right? And then we do move on to the demo part of whatever they want to talk about and make sure how we can apply that. And we want to make sure that when people finish watching the show, they actually have the tools and the resources that they can use when they go back to work or wherever, whatever they're doing, and be able to use that and not just be left with the theory, right? With some practice.

12:20Yeah. Yeah, that's a great, great principle and a great approach to get hands— let people work hands-on after teaching them something and then letting them get hands-on with it. And I think that's really how you learn is by putting your hands on the keyboard and making something work behind the scenes.

12:38Absolutely. And I personally work in risk management and I get introduced to new technologies all the time with a lot of people in engineering thinking that I know everything about everything and I don't. And these— this is a great opportunity to learn about new things and understand how things are built and get my hands dirty and eventually be able to provide better advice to secure their solutions. So sometimes you don't get the opportunity at work or even on your own in your own lab to touch something, but then you have an expert for an hour that's able to talk to us about whatever we're curious about. So that's really fun.

13:18Yeah, and it's, it's so important to— in being a successful security professional is that thirst to continually learn new things because—

13:29Absolutely.

13:30Industry is changing so fast, technology is moving so fast, and not only do we have to keep up with all the technology, we have to keep up with all the things about security to the new ways to protect things and all that type of good stuff. So yeah, that's— this is, this is really neat to hear about how this is an educational-based project where you're truly looking to expose people to new technologies and new techniques and give it in such a way that they can grab ahold of it and then do something with it. That's really cool.

14:00Yeah, give them the tools.

14:02Chris RomeoTanya, then what—

14:05we talked about pipelines here. Tell us, let's start with Patty the Pipeline. So explain kind of what I want to know where Patti the Pipeline, where the name came from, first of all.

14:15Well, Nicole named her app Pixie, and I thought that was super cute. So then I wanted to name mine something that started with a P. So it was going to be Patti the Perfect Pipeline, but she's really not very perfect. I started working for Microsoft and I wanted to learn about— I want to be the master of the things I have to work with, if you know what I mean. So I'm like, oh, I'm going to make this awesome pipeline and put millions security tools in it, and it's going to publish our website for our project, which is devslop.co. I'm like, this will be great. The website, I'll torture our website. I'm always messing around with it. It's basically a proof of concept. Then I'll publish it and then I'll share my pipeline. But it turns out it's really hard to share a pipeline because of the licensing for all the different tools. Then I have, it calls a virtual machine and all these other things.

15:11Right.

15:12was like, how am I going to share this? So I decided I would just make a video of me being a nerd, and then another one, and then another one. And then before you knew it, we're doing a lot of them. And so the DevSlop Show is partially about Paddy. So it'll be me fixing bugs, like security bugs, or me upgrading a framework, me implementing a new, I don't know, like a new tool in my pipeline that I want, and then us running through and testing it. And sometimes we do it with a guest, and sometimes I just do it solo. because it's easier. I can't believe how many free things there are. There are so many free security tools. So we'll like go in depth with these security tools and like, this is how it works, this is how if you want to use it, the things you need to know or the things you have to set up. So I'm hoping that that helps other people that, for instance, let's say they want to use SSL Labs in their pipeline, and then they can see, oh, it took Tanya like 8 minutes to set that up and it's free. Maybe we should all use it. Spoiler alert, you should.

16:15Most definitely. So, then, I guess, what are some of the other free security tools that you've integrated into Paddy the Pipeline that our listeners might be able to learn about and apply to some of the things they're working on?

16:31We have OWASP ZAP in there. That is working really well. You have to have a virtual machine, to run ZAP though, so you have to pay the pennies on the dollar for the virtual machine time to run it. We were using Snyk, we're not using it now because we're an open-source project, it's free. Sometimes we use Azure DevOps Toolkit, which is free. We use WhiteSource Bolt, that's great. It runs asynchronously from your pipeline, so it runs the code through but your pipeline continues and then it gives you a report after and tells you how you're doing because static code analysis is really slow. I really like that one though. I wanted to do a new one from Microsoft called Risk Detection. It's brand new, I haven't used it yet. We also have been playing around with making unit tests and then turning them into negative unit tests where they're malicious, but we keep just throwing them out and starting again. But yeah, theoretically, I'm going to finish that at some point. I mean, eventually. Um, there's, there's a pile of tools, and I feel kind of frustrated because I don't get to have free license to all of them, despite the fact that I think that— I think that any company should want to give us a license so we could show it off on our show. But I'm biased because I want the free license.

18:00Any, uh, any application security testing and tool vendors that are out there You heard it here first that the DevSlop project is ready for some free licenses so they can showcase your stuff for you.

18:15Absolutely. Yeah. Burp Suite or PortSwigger gave us one for Burp Suite Enterprise, but then I was too slow. We ended up running into trouble when we were trying to install it, and then I just, you know, went on Microsoft Ignite, the tour forever, and I just forgot. And then my 60 days ran out. I'm like, oh no. But I'm going to write them again really nicely and see if they'll go for it. I'm sure they will. They're very reasonable. And Burp Suite's not free, but I love it.

18:47Nice companion with Zap and, you know, some of the other tools that you mentioned there. You mentioned WhiteSource Bolt. What is WhiteSource Bolt?

18:59It does very brief and obvious static code analysis. So, it's very brief. And it will check your open source components for vulnerabilities. It runs in just a couple minutes. It's very quick. It found a ton of stuff wrong with my app, and sometimes it finds things and it's like, there's no known fix for this, but we want you to know this is here. Or one time it actually told me to edit the code of one of my plugins because it was being exploited in the wild and there was no— because there's still a zero-day, there's no patch for it. But mostly it's just It was telling me to upgrade my jQuery, but I did it, so it can stop telling me that now.

19:40That's what third-party package management is all about, though. It's about getting that message quickly and then being able to triage and make those problems go away.

19:50Exactly, exactly. Okay.

19:54And then, so I guess the last kind of module that we described in the introductory moments of this conversation was there were some additional pipelines that you said Franziska had created.

20:06Yeah. So, Franziska is a WAF expert, so web application firewall. And she used to work for the Swiss Post, but now she works for PiXLL. I think I'm saying it wrong. It's a Swiss company. I'm sorry if I'm saying it wrong. And she writes— so, she's on the core ruleset team from OWASP with Christian Fellini. And all the other really cool team that that are on there, and so she writes a bunch of the regular expressions for the core rule set, which is essentially what like web application firewall signatures, which are generally used with mod_security, which is the first and I think only open source web application firewall, which is also from OWASP. And so she has experienced. I mean, so many times the developers make something and then they're telling her, you know, your WAF broke my app when it got to prod. So she's like, oh yeah? So she made a pipeline with Pixie in it and put the WAF in front of it and then has all these automated tests to make sure that legitimate business requests get through, but the bad ones don't, so that you can tune your WAF. with your new changes in your app before it gets to prod, so then the WAF never breaks your app. Then she made another one that has Zap where it's like attacking Pixie and she can turn it on and off so you can see the difference. She did a demo for us. Was it last week? Last week.

21:36Yeah, last week they were both on the show, Christian and Francisca, and there was a really short and sweet introduction to WAF. Yeah, it was, uh, I learned a lot. I knew what the WAF was, but then we went into the code, into the log, and understand what it meant and how to configure it. Uh, you should really go back to either, uh, our Twitch channel or Mixer, and a bit later, uh, in a couple weeks, we'll have it also on our YouTube channel.

22:03Yeah, it was great though, and she, she gave a demo showing like, there, the WAF was on and it blocked it, the WAF was off Disaster. It was really good.

22:15Yeah.

22:15That's great. I have not seen that one, so I'll go definitely check that one out. And I'm just chuckling at the comment that you said, the developer saying that your WAF broke my app. Not the— I mean, that's just, that's funny to me that they, you know, we know as security professionals, well, actually, your app broke as a result of some security problem in it. It's not the fact that we have a new WAF rule, it's your app, but they flip it back around. Oh yeah, security broke my thing, my stuff.

22:46I would have to say sometimes it's the WAF. Like, sometimes they add a new rule and it's blocking legitimate traffic, and then that's bad, right?

22:55So yeah.

22:56They spoke a lot about false positive and how, you know, in the beginning you need to spend some time fine-tuning your WAF to make sure that it works properly. So eventually it does become helpful, but in In the beginning, it can be a bit of effort to get it right.

23:13It sounds like both of you, Nancy and Tanya, have really, as a part of this project, it seems like you're learning a lot as you go. That's one of the things, one of the reasons Robert and I started this podcast a few years ago. It was primarily for us to learn more about cool things that were happening. And so it's just, it's so awesome to hear about how you've, you've, you have this, this show, but it's also enabling you to learn a whole lot of other things and expose others, you know, to these, these new concepts.

23:45Absolutely. And something I wanted to say is how, and, and just give props to Tanya because she's really, really, um, open to just make mistake on air. And we, we go on, we record, uh, she has a plan and she's like, okay, Nancy, let's try this tool. And we go on and sometimes we do spend 2 hours not getting anywhere and we might not put it on, on the YouTube channel, but we do try things and we do experiment and we don't get it right the first time, but then we go again and then edit our videos and put it out there for people to learn. So it is definitely for other people, but for us it is a great— and especially for me, a great opportunity to learn more and to have opportunities to make mistakes and then learn from them.

24:31I was curious, have you had— I mean, that's great because sometimes our Our mistakes, we learn from it, others learn from it as well. But have you had some good feedback or different feedback that helps you also fine-tune or answer, you know, questions or update documentation, things like that as well?

24:50People interact with us live throughout the entire show.

24:55Oh, okay, interesting.

24:57The audience— Nancy, you're like— so Nancy interacts with the audience a lot more than I do. She's so great for like paying attention and making sure everyone gets answers. And the audience will help us. They'll be like, no, Tanya, not there, it's this.

25:14Yes, yes, absolutely. They, they, they participate and they sometimes have— we have experts on that are listening to us and, and they're listening to the show to help us. So they're, they're even— I, I think at one show, um, Tanya went on a call with, with one of our auditors and she gave him a link to Skype, and he went, he hopped on and helped her finish it, and then eventually we published the rest of the video online. So, yeah, yeah. The audience participates in the chat live, and then, of course, you don't have that experience when you watch a video on YouTube, but I think there's a different experience when you watch us live because you can contribute to the show and ask your questions and have the expert right there.

26:04Yeah, it's really cool because sometimes, you know, because Nancy and I are coming at it from a security background, but not everyone that watches the show has the same experiences that we do. Just the same as like Nancy knows a lot more about risk management, auditing, and like just managing and making sure all the security things actually get done, while I'm more like the programmer, like kind of more, I guess, um, AppSec-y breaking crap all the time person. And so, so just as like show bring other things to the table that I don't have, like the audience. It's so awesome. Like, um, it was Carl that helped me write some unit tests because I was following the instructions and then it just didn't work. And he's like, oh, oh, it's this, it's this. And so he made a pull request and we pulled it in. Or like Dominique Raito, he, he made a pull request and we pulled it into the project. Just say awesome human beings.

26:58Yeah.

26:59From our community. We actually, so we blew our entire budget on captioning as many shows as we could because we really wanted people for whom English is not their first language or people who are hard of hearing to be able to understand the show. And then several community members have actually fully translated many shows for us, which is just, it's so beautiful the way the community comes together. It's very touching.

27:27Now that we've kind of, we've got a decent perspective on the different modules and the different pieces here in DevSlop, let's kind of go through a scenario here. So, let's say somebody that's listening has never had any interaction with DevSlop before. They're just hearing for the first time, hey, this project exists, here's the different pieces.

27:47Chris RomeoHow would you recommend they get started interacting with DevSlop?

27:50Well, I'll start for the show. Definitely, I would say email us. It's [email protected] and tell us, uh, what you would want to see on the show and if you would want to participate as a guest. And let us know what kind of information you would want to share with our audience. That's for the show. As for— I'll let you take it over for the other modules, Tanya.

28:17For the other modules, we don't tend to have too many other people participate. I've had a lot of people offer and want to get involved. But managing a project, I'm sure you know, the more people that are under you, uh, and I don't mean that like— I don't know, do you know what I mean? Like, if you're leading a project, the more people involved, the more work it is. And if you're the person doling out the work and you only have to dole it out to yourself, it's really easy.

28:42It is.

28:43I'm trying really hard this year to work more collaboratively with others But I'm a lone wolfy type of person. Generally, we just create our own module and just run with it or ask for help if the other one needs it. But it's not like a regular open-source project. Because generally, open-source projects build a tool and then people can go use it. Well, with ours, it's more like we're stumbling through learning these things, and then we want to show you what we've learned so you can learn it too. So, it's not the same way, like, where, you know, if there's a bug that is in, you know, the devswap.co website, it's like, oh, well, I want to make an episode out of fixing that. No, please don't go fix it. Or, like, if you fix it, we need to fix it together live on air, right? And so, usually OWASP projects are a lot more open to having lots of other people participate. And it's not that we're trying to be unfriendly. It's just Yeah, I know. It's just getting worse and worse. Nancy, help me recover.

29:51No, it's just that I find that if you ask for a volunteer to help out, you need to be responsive and you need to be available and to provide direction. And if we don't have that, I think we shouldn't be, you know, calling for more people to come and see us. So we're not— definitely not organized to do that. to have too much input. But definitely, I think for the show is a good way to come in and start talking about what you're passionate about if you have something to share. That's at all level. I have reached out to different guests and potential guests, and some people are like, well, I'm not an expert in this. We don't need you to be the person that built a tool, but if you just learned something new and you have something very specific to to share, you know, we're open to that as well.

30:46Yeah, and it sounds like, just to kind of summarize what I took away from this, the whole kind of getting started conversation. And so, what I'm taking away is really the true output of the OWASP project is all of the experiences and things that you're learning as you go through and try out these new technologies. And so, really, if I'm somebody who's getting started, But the real answer that I'm thinking is to go to the archives of the show and just start to watch and see all of the things that the team has learned as you've made your way through this. Is that a fair summary?

31:23Absolutely. Definitely. 100%.

31:27So, I guess one last kind of bigger question, and that is, where do you see DevSlop going in the future? continue down this road of just finding new things, new problems, and trying to solve them? Or do you have some— is there a bigger strategy that's driving you behind the scenes?

31:46I would love to tell you that we have a very big strategy. But mostly, it's just whatever piques our interests. Nancy's like, this looks cool. Let's do a show about that. I'm like, yeah, Let's do it.

32:04Okay.

32:05I want to build a new thing for whatever reason, especially if I have to learn a thing for work. I'm like, oh great, let's make an episode about it and stumble through it and then give them some real feedback. Or if I meet someone new that's really cool, like when I was in— where was I? Somewhere in Asia, I met a woman who does AI and ML, so artificial intelligence and machine learning. I said, is this weird? Can I just interview you for a couple minutes and just ask you general questions I've always wanted to ask? And she said yes, and it was great. So we just kind of just try to— Nancy, any thoughts? Except the rebrand, you can— we're changing our video channel.

32:51Yeah, well, the rebrand is more about Tanya traveling a lot and having her own content and having She Hacks Purple channel and DevSlop having its own channel. That's why you may see less video in our YouTube channels, but we're cleaning it up and making sure that our content is focused on DevSlop. Other than that, for the future, Tanya and Nicole promoted me as a project leader. I'm trying to find my space in the technical world of DevSlop. I had the opportunity to go to local MoSec in Hawaii, and attend Jimmy Mesta's training on container security. And that was fantastic. That was a great training. And I think I want to introduce that. I want to introduce that to the project because it's something that we're not touching on. So we do a lot of DevOps, a lot of API, the WAF, but we haven't really talked about containers and container security. And that is something I think we have space to So, that, for me, is definitely in the future. Great.

34:02And so, we did mention that there is a Gmail address for the DevSlop team for those that want to interact with them, [email protected]. What's the best way for any other community members who are listening here to interact with the project and also to interact with Tanya and Nancy?

34:21Well, we're both on Twitter. So, if you look up our names, or I'm @shehackspurple, and Nancy, how do you pronounce your Twitter handle?

34:29I'd say @NancyTweets. It's probably better in the show notes. But we have— we're a bit everywhere. But for DevSlop specifically, there's a handle for DevSlop as well. We have the YouTube channel. And I would say even the meetup, because the meetup is our way for us to publish our show. Just search OWASP DevSlop in meetup.com and you'll find our meetup.

34:55Chris RomeoAwesome.

34:56and we publish our show in advance, and it provides you with notification and reminders of when we go live. And yeah, that's one of the best ways to keep in touch.

35:10Right.

35:10And know what's next.

35:11Follow us on Twitter because sometimes we say things. Awesome.

35:21Yeah, so I guess kind of from a Any final thoughts then? What, I guess let's start, Tanya, why don't you go ahead and go first as we're kind of landing the plane here? What's, I guess, one kind of final key takeaway you'd leave for our audience?

35:35We really want developers to take security into consideration, and especially those doing DevOps as we move faster, you know, move fast and break things. I know that's the thing, but also fix things And also verify your security. We're really excited about DevSecOps, you know, making sure security is in the middle and the whole way through for DevOps and where we are as application security professionals in that specter or area of IT.

36:11Great. Nancy, how about a final key takeaway from you?

36:17Well, takeaway, I don't know, but I will say that at the end of May, we'll be— we'll both be at, uh, the OWASP Global AppSec Conference in Tel Aviv, uh, and they are hosting a project showcase and we'll be talking about DevSlop. So if you're there, please come and say hi. If you're not, I hope that it's— it'll probably be on video and you can see a bit, um, our presentation about DevSlop.

36:40Yeah, presentation. presentation and a showcase. So, come meet us because we're cool.

36:45I can attest to that, having met you both at a conference at one of the AppSec events. I don't— I think it was AppSec USA.

36:55USA, yes.

36:56I think it was also USA.

36:58USA in Orlando, yes.

37:00Well, Tanya and Nancy, thank you for being with us today and sharing all the different insights and things about DevSlop. We're very excited that our listeners are going to get a chance to know more about DevSlop and then figure out, you know, how they can interact with the show and look at all those back archives and tap into all the learnings that your team has done over the last couple of years. So, we thank you so much for being with us today.

37:27Thank you for having us. This has been great.

37:30Yes, thank you very much.

37:32Chris RomeoThanks for listening to the Application Security Podcast. Our intro music is 8-Bit Kung Fu by Born and TJ, and our outro music is Southern Delight by Stefan Cartenberg. You'll find the show on Twitter @AppSecPodcast or on the web at www.securityjourney.com/application-security-podcast. You can also find Chris on Twitter @edgeroute and Robert @RobertHurlbut. Remember, security is a journey.

38:03A journey, not a destination.

6,329 words · transcript by assemblyai

More like this

View all episodes →

Get Reasonable AppSec: new episodes and useful picks from the archive.