Skip to content
AppSec PodcastThe Application Security Podcast — home
30 min

OWASP Top 10 2021 Peer Review

With OWASP

Threat ModelingOWASP Top 10API SecurityVulnerabilities and Exploits

Chris and Robert conduct a practitioner peer review of the 2021 OWASP Top 10, examining what changed, what moved, and what the new structure communicates to development teams. They compare the list with the 2017 edition, discuss the broader treatment of injection, and unpack additions such as insecure design, software and data integrity failures, and server-side request forgery.

Audio hosted by Buzzsprout. Nothing loads until you press play.

Episode chapters · 11 chapters
  1. 00:00Peer reviewing the OWASP Top 10:2021AudioVideo ↗
  2. 03:00Broken access control moves to number oneAudioVideo ↗
  3. 04:52Injection and cross-site scripting are consolidatedAudioVideo ↗
  4. 07:46Vulnerable and outdated componentsAudioVideo ↗
  5. 10:50Software and data integrity failuresAudioVideo ↗

About this episode

Chris and Robert conduct a practitioner peer review of the 2021 OWASP Top 10, examining what changed, what moved, and what the new structure communicates to development teams. They compare the list with the 2017 edition, discuss the broader treatment of injection, and unpack additions such as insecure design, software and data integrity failures, and server-side request forgery. The review also questions how categories map to real weaknesses, CVEs, and verification practices. Along the way, they connect the Top 10 to ASVS, threat modeling, dependency analysis, and the difficult balance between a widely recognized awareness document and actionable engineering guidance.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with OWASP:
OWASP Top 10
OWASP Foundation

Resources
OWASP Top 10:2021
OWASP ASVS
Threat Modeling Manifesto
OWASP Dependency-Check
CycloneDX

Actionable

From this conversation

  1. Use threat modeling to prevent insecure design

    With that, it takes us to A4 for 2021, insecure design, the one that causes all of us threat modeling people to run around and dance and jump up and down and be so happy and excited because If you have a flaw of insecure design, you're going to have to have a preventative measure of threat modeling.

    5:44
  2. Ask questions about crypto use

    I love this set of questions right here, that developers should be asking themselves as they're thinking about, their use of crypto.

    22:06
  3. Review the Top 10, add comments, and submit pull requests

    Review it, add comments to it, do pull requests, like give back to your community.

    28:28
Transcript · 30 min conversation

0:01Chris RomeoOn this episode of the Application Security Podcast, Robert and I break down the OWASP Top 10 2021 Peer Review Edition that just dropped in the last week or so. We walk through and give you our insights and highlights of the things that stand out to us, the questions we have. And so we think it'll be valuable for you to get a good understanding about what the OWASP Top 10 2021 is likely going to look like when it comes out. But we also want to encourage you to Go and do your own peer review of the document and submit your own pull requests and feedback and issues and stuff on GitHub, because together as a community, that's how we make this document better. So we hope you enjoy this conversation with Robert and I as we break down the OWASP Top 10 2021. Are you trying to build a security champions program? Everyone is these days. One challenge of rolling out security champions is how do we educate all these new folks? Security Journey has your answer. We provide a Security Dojo environment with level-based security education that gives your newfound champions a path to follow. And the best part? It requires almost zero administration by you. Visit www.securityjourney.com to set up a demo and learn how you can use the Security Dojo to connect with your security champions. Hey folks, welcome to another edition of the Application Security Podcast. This is Chris Romeo, CEO of Security Journey and co-host of SED podcast. I am joined once again by Robert Hurlbut. Hey Robert, how you doing today?

1:36Robert HurlbutHey Chris, doing well. You know, threat modeling architect, and, uh, you know, this is going to be an interesting podcast, a little bit different than we normally do, but looking forward to it.

1:46Chris RomeoYeah, the topic of the day is the OWASP Top 10 for 2021. So OWASP has released a peer review version of the Top 10. We know how impactful the Top 10 is in our industry, and we'll talk about some things that they added to this document to address some of the ways that this document is very influential in our industry. But I thought one— the way we would start here is the peer review version has a nice high-level overview of what's changed in the Top 10 for 2021. And so I just want to review this to help our listeners that haven't had a chance to maybe dive into it yet to understand what's changed, and also, you know, kind of our opinion of it as 2 people who like to think we swim in the deep end of the world of application security. So starting with A1 for 2021 is broken access control. And so what we see here in the list is that broken access control has vaulted up from A5, where it was in 2017, up to the A1 position. So, that is interesting all to itself. I think the other thing that's interesting is injection is no longer at the top of the list.

3:05Robert HurlbutRight.

3:06Chris RomeoI feel like we should maybe just cheer for the fact that injection has made its way down a little further on the list. I have a standard joke, my standard OWASP joke I say all the time. Hey, the OWASP Top 10, why don't we just focus on the OWASP Top 1? Let's put all of our influence into one particular thing. And then I would go into injection and how, but now I got, I'm gonna have to change my, change that up a little bit. So yeah, I think it's, I think it's good to see broken access control make its way to the top. I don't, and we'll dive in deeper into that a little bit, but I don't have any disagreement from that. It seems very realistic.

3:48Robert HurlbutYeah.

3:49Chris RomeoBased on what we see in modern apps right now?

3:50Robert HurlbutWell, yeah, if you think about my own work and yours, as well, whenever we're thinking about threat modeling— I know we'll talk about that some more today, but as we do many times— but, you know, we talk about access control. And if you are able to run with more access than you should have, I mean, it's game over, right? And so it makes sense in some ways, why wasn't this moved up earlier? But it's the right time, and it's good to know and good to see. And so it makes a lot of sense to be now first.

4:26Chris RomeoSo now A.2 is cryptographic failures. So some new language, but they're mapping this from what used to be called sensitive data exposure in 2017. Now they're calling cryptographic failures. And that I've— in reviewing this version, they've added a lot of additional things to that. We'll get into some of that detail as we go forward.

4:50Robert HurlbutYeah.

4:51Chris RomeoAnd then injection falls all the way to A3. Poor injection. No one's even going to give you any love anymore. No one's going to pay you any attention. We all— we know that's not the case, right? We know that injection is going to be a big thing. Now, one of the interesting things that I saw here is that they included cross-site scripting under the header of injection. So what are your thoughts on that, Robert?

5:14Robert HurlbutWell, I think it makes sense on one hand, although, you know, there's some, some questions and I've seen some of the chatter for the OWASP team and others who have indicated, well, okay, but could it be lost? That's a good question. But I think it does make sense to put it under injection. It is an injection problem. And I think also You only have 10 slots, right? You can't put everything in. So, putting it into injection makes some sense there as well.

5:44Chris RomeoYeah. You got to make all 10 of those slots count to the best of their ability. And with that, it takes us to A4 for 2021, insecure design, the one that causes all of us threat modeling people to run around and dance and jump up and down and be so happy and excited because If you have a flaw of insecure design, you're going to have to have a preventative measure of threat modeling.

6:11Robert HurlbutThreat modeling.

6:13Chris RomeoSo, this is an exciting moment for us as threat modelers. And, you know, based on all the stuff we did with Threat Modeling Manifesto to try to draw attention to threat modeling, and I know it's something that both of us are spending a lot of time talking about in the industry and You know, talking about training, teaching people, as many people as we can on how to do it. I feel like we've arrived.

6:36Robert HurlbutWe have arrived. It's a great, great thing to see. Absolutely.

6:40Chris RomeoSo then, A5 is security misconfiguration. So, this is just a transfer from 2017. It was A6. So, it moved up a whopping one place to A5. They also included XXE, XML External Entity style attacks, in security misconfiguration. I want to hear more from the top 10 team as to why that kind of slid into that particular one. But I don't, I don't know that I have a good answer for that right now.

7:13Robert HurlbutNo, no, it is interesting. But, you know, in a similar way, I think that when you look at the entire list, they had a few more things they want. I think it was 3, if I remember correctly. In fact, looking at your graphic there, 3 items that were new. And so they had to figure out how to add those as well as try to keep some emphasis on what was already there. So it still again makes sense, but curious to know some of these about why they, they got pushed into something else. But it makes sense.

7:44Chris RomeoYeah.

7:46Robert HurlbutYeah.

7:46Chris RomeoAnd then A6 for 2021, vulnerable and outdated components. So I love the way they rewrote that. We had A9 for 2017, using components with known vulnerabilities. Now you have vulnerable and outdated components. So I don't think anybody in the year 2021 is going to argue with that being a particular issue because of, you know, SolarWinds and the number of other supply chain style attacks that we've seen. I guess the only question I have on this one is like, is it, is it in the right spot? Should it be up higher? Like, that's my concern. Like, it's, it's, I think I can make an argument for that being in the number 1 seat no matter what the data says. Just because if you look at, you know, macro-level events that are happening in our industry and macro-level challenges and stuff, like, I don't know, man, what do you think? Does that— you think that's in the right spot or do you think it should be higher?

8:38Robert HurlbutProbably higher. Probably higher. I mean, like I said, supply chain and other kinds of concerns that are making the news as well as emphasis and focus right now. I think it may make sense to move it up higher than it is right now. Yeah.

8:55Chris RomeoAnd in the notes here, I'm just seeing that it was number 2 in the industry survey. So what the top 10 team did is they sent out a survey to AppSec practitioners and I participated. I sent my input in. They allowed us to give our input into a list of things that they were considering adding. And they're saying that that was number 2 in the industry survey as something that needed to be getting more consideration. But it also had the data from the data analysis they did for it to be represented on the list. So yeah, I mean, that's, I guess, just kind of our opinion and our thoughts as practitioners along the way. A7 takes us to identification and authentication failures.

9:37Robert HurlbutSo this is—

9:38Chris Romeobroken authentication was A2 in 2017. Now it slides down to A7, and they add that identification to this idea of broken authentication.

9:48Robert HurlbutOkay.

9:48Chris RomeoSo, you know, it moves a little bit, but still, as they say, still an integral part of the top 10.

9:53Robert HurlbutRight.

9:54Chris RomeoAnd then A8 is our second new one on the list. This is software and data integrity failures. So interesting new category. You know, they're saying, you know, focuses on making assumptions related to software updates, critical data, and CI/CD pipelines without verifying integrity. Interestingly, they added insecure deserialization to this one. So that, that, that got me kind of thinking about it and saying, well, it's interesting, you have software and data integrity failures. So a software failure, I guess, would be insecure deserialization. And then integrity failures are things like software updates and stuff like that. So, I mean, it makes sense to me. Like, it's— I've seen that be a pretty big issue in a lot of different places. So it makes sense that we're focusing on it now.

10:46Robert HurlbutOh, definitely. Definitely.

10:50Chris RomeoOh, A9 2021, security logging and monitoring failures. Finally, logging on a top 10 list has made it out of the number 10 seed.

11:01Robert HurlbutYay!

11:02Chris RomeoEvery time we have logging, we put it on a number 10. It's always like, poor logging. Someday maybe you'll make it up higher when we fix all the other problems that exist in the world.

11:12Robert HurlbutAll right.

11:14Chris RomeoI always feel bad for logging and monitoring.

11:15Robert HurlbutWell, it's one of those— I don't know if you remember back in 2017 when it came out, you know, they would say, well, if a company said we can do all the top 10 things, well, how are you testing for this? How are you checking for security logging and monitoring? And so it's still there, and it's now moved up. And so it's not an easy problem to solve to make sure that you have really good logging and monitoring across your enterprise, across your applications and so forth. And so it's important. It's still important.

11:50Chris RomeoI'm going to get a t-shirt that says security logging and monitoring for number 1. I want to see it make its way up all the way to the top. So A10 is number 1 from the industry survey, SSRF or server-side request forgery. We had heard some rumblings in the industry a year or two ago that this one was trending towards making its way the top 10. And so it kind of, you know, it makes sense that it's there now. You know, Robert, I'm curious on your thoughts on this one on SSRF. But when I think about SSRF, I was like, I'm trying to rationalize, like, isn't it broken access control if there's an SSRF?

12:29Robert HurlbutThere's certainly an aspect of it. But there's also that idea of what you can do inside as well. That's part of this, at least from what I understand.

12:41Chris RomeoYeah, I guess there's the transfer, there's bypassing, there's getting through the web app, and then there is the whole portion of doing something to some other site or some other web app or some other internal resource that's inside the organization. So I was just, as I was reading it, I was just thinking like, is this kind of a broken access control? Like, I could see an argument being made to say, and maybe that'll happen in the future, maybe SSRF You want to get some visibility on it right now?

13:11Robert HurlbutYeah.

13:11Chris RomeoI mean, granted, it is, you know, it's been proven that it took down, you know, some of the big incidents from a couple of years ago were SSRF-driven. And so I think from an awareness perspective, it's great to get the word out. I just wonder in, you know, 2024, does it migrate its way into— I think very possible.

13:30Robert HurlbutI think very possible. I think, you know, just like logging and monitoring, in 2017 is that they added it to give it awareness finally. And it very well could— this one could also funnel into something else to give us awareness to a new thing perhaps in the next, in the next version of this.

13:50Chris RomeoYeah. And I should have said this right off the bat, like, yes, we're going through and doing some critiquing of this document as the peer review version, but we appreciate the OWASP Top 10 team that works to put this together. I mean, Andrew Vanderstock is still leading that team, and, you know, he's got a couple other folks that are working with him on this. And so this is not— we are, we are so happy and thankful for all of the efforts they put into this document. And I know it's a, it is a labor of love, and they put hundreds and hundreds of hours into this. And so this isn't us critiquing or criticizing them. This is us just saying, hey, this is, as practitioners, this is our—

14:31Robert HurlbutYeah.

14:32Chris RomeoKind of what we see with this particular document.

14:34Robert HurlbutYeah, definitely. Yeah, absolutely agree. It's just phenomenal, the work that this team does. And you and I watch some of the work that we see people working on. At least I know I've seen a number of things that are coming across. So it's just phenomenal, just what this team has done in 2017 and again this year as well.

14:58Chris RomeoYep. And we had a chance to interview them when 2017 was coming out. We were in Orlando.

15:02Robert HurlbutYeah.

15:03Chris RomeoSo we're going to have to do that again here at some point in the future. So here's a new section of the document now. For how many years have we been saying, OWASP Top 10 is not a standard, people stop calling it a standard, right? You know what? I think they made the right call here and they just said, you know what, we give up. You want to call it a standard? Fine. Here's a little bit of guidance about how You can refer to this thing as a standard, you know, so they've got the various use case categories here and then they've got, you know, some references to, you know, how you can use the OWASP Top 10 2021 to solve it, how you can use, you know, where should the ASVS come into it. So I think it's a good idea. I mean, Yeah. The industry thinks of the OWASP Top 10 as a standard. It's, it's funny, it's not really standardized under any particular organization. So normally when you have a standard like it's an IETF standard or IEEE standard or something that's been ratified by a large group of practitioners, in this case the industry has made this a standard. It's probably a whole other podcast. Yeah, right. Trace down where the standard— where this idea of it being a standard came from. But it is what it is.

16:14Robert HurlbutIt is. No, and I like that they, they do point to the Application Security Verification Standard. I mean, that is the standard. And then where and how this relates, you know, in some cases, as it says, entry level for training and occasionally for unit testing and so on. So this is good. It helps you, helps frame it where it really fits if you're going to use it that way.

16:40Chris RomeoYeah. But yeah, I mean, it's the good thing is they just finally acknowledged it. and said, we're just, we're not gonna fight it anymore. Like, it is what it is, you know?

16:49Robert HurlbutRight.

16:49Chris RomeoLet's just deal with it. So, um, I guess for a couple of minutes, I'd love to just kind of walk through these and glance at some of these and just talk about some of the things we're seeing. One of the big things that's really hit me is the dependence and connection that they've had from Common Weakness Enumeration. So they've really leaned into CWE, which I love CWE as a standard. I think everybody should be aware of CWE and should be using it as a reference and using it as a teaching mechanism and as something that's integrated with all the tooling so that we can start using this common vocabulary as an industry amongst all the various tools and trainings and stuff that are out there. So, it was interesting for me, just being someone who loves CWE, to see the dependence that they had on that. here in this new version of the Top 10. Right.

17:44Robert HurlbutIt helps people, like you said, a common vocabulary that we understand CWE. Many look to that as a good reference. And so when you have these ties, and they've done that with some other documents in the past, too, but even more so, I like that they've done that here, as well.

18:01Chris RomeoYeah. And, you know, as we're looking, CWE-352, cross-site request forgery, is one of the ones that they mapped against broken access control. That's what got me thinking about SSL. CSRF. I started thinking, I saw that, I was like—

18:14Robert HurlbutI was thinking that too. It used to be one of the, uh, the items, right? And then they got moved, but now we're here again, and that's great.

18:21Chris RomeoThat, uh, yeah, and that's a good example of the success the OWASP Top 10s had over the years, right? Cross-Site Request Forgery, I don't remember, it wasn't 2017, it must have been—

18:31Robert HurlbutNo, it was 2014, I think, uh, was maybe the last time it was there. Yeah, uh, I could be wrong, but I think that's when it was the last time.

18:39Chris RomeoBut then it got, it got eradicated As an industry, we added protections against CSRF in the frameworks. So you got to the point where you had to disable a security function to make CSRF possible. To make it actually work, right? Yeah, so when people got, you know, we got to the point where the frameworks were just protecting us and like, okay, I guess we're, you know, we're good now. Like the frameworks are, we have built in a built-in security control that prevents cross-site request forgery. So it is a model for where we can go in the future. though, with additional effort, we can see the framework start to eliminate more and more classes of these types of vulnerabilities. I think about injection in ORMs, right?

19:25Robert HurlbutRight.

19:26Chris RomeoWhy do we still have SQL injection? Well, we have SQL injection because people are still doing string concatenation for SQL calls. And the ORM makes your life So much easier. All you do is make an object call and it gives you the data back. Why would we not want to do that with everything that's out there? But we don't. It's just kind of a statement of how things work today in the modern web.

19:59Robert HurlbutRight.

20:00Chris RomeoOne thing I saw that kind of caught my eye that was interesting is that I thought I'd ask your opinion of this. They have in how to prevent, just like for all these under broken access control, they have implement access control mechanisms once and reuse them throughout the application. Love it. Something that I say all the time. But then they have including minimizing CORS usage.

20:21Robert HurlbutMm-hmm.

20:21Chris RomeoAnd so I was like, hmm, that's an interesting statement there. I was thinking to myself, do I agree with minimizing the use of CORS? Yes. CORS can be difficult. I've had to try to create some of those header definitions and stuff, but do we want it to not be used just because it's hard? I mean, it's not CSP hard. Good luck with Content Security Policy trying to get that implemented. That's a good question.

20:50Robert HurlbutUnless you're forcing— I mean, why do you need to use it is because you are doing some kind of cross-site requests, right? So how do you prevent it? By not doing it, I guess. And it's an interesting thing. When do you need it? Typically when you are allowing it. So that's sort of how I maybe read that, but I'm torn on it as well in the language there.

21:19Chris RomeoYeah. And then if you look at the above in the kind of description where they have the common access control vulnerabilities, they say CORS misconfiguration allows unauthorized API access. Yeah. Like, CORS is not easy to set up. It's not easy to update and modify. So I thought there was just a little bit of tension there between, you know, do we want to— are we telling people to not do it? Like, I think that's a bad idea. Like, I don't know that there's a better way to secure cross-site. You know, there are cross-site things we have to do on the internet. Like, that's the way things work, you know?

21:51Robert HurlbutRight.

21:52Chris RomeoSo that one just caught my attention as like, huh. You know, is that, is that, you know, kind of the guidance and stuff that I'm expecting to see? But I don't know. I mean, the community will work it out, I guess.

22:04Robert HurlbutYes.

22:06Chris RomeoSo cryptographic failures, thought we'd just touch on this one for a second. I love this set of questions right here, you know, that developers should be asking themselves as they're thinking about, you know, their use of crypto. And we've talked about crypto a number of times. We have Anastasia Voitava on the show a number of times, you know, One of my favorite lines that, you know, it was, use crypto, don't learn it.

22:29Robert HurlbutDon't learn it.

22:30Chris RomeoWas what she talked to us about in one of her first episodes with us. And I was like, that one always stuck with me. It's like, yeah, don't learn crypto developers. It's like, you're not a cryptographer, you know, just use the right libraries and stuff. So, but I think cryptographic failures is kind of like the, it's the weakness that sits, that is the opposite of what she was saying. Like, it's, it's people are either they're not using the right algorithms, they're not doing the right number sets of protections and stuff. I think that's part of the challenge.

22:56Robert HurlbutAgree.

23:00Chris RomeoNot enough.

23:03Robert HurlbutSo there's a lot of good stuff here. I think this is going to be one— this particular area here is going to be one that we'll see a number of things come out in terms of peer review because it's absolutely critical to get it right. So I'm really I'm really looking forward to see, you know, where this one goes as well.

23:24Chris RomeoYeah. And I love that they added use of hardcoded passwords, CWE-259. So like a default credential or hardcoded password. Like, I think that's a great— it's a great thing to be added under here as a cryptographic failure with things like broken or risky crypto algorithms, insufficient entropy, you know, all these things that are crypto influencing. I just— I love this. I love the way this thing, this one came together. I think this is a powerful message, and it's so much stronger than sensitive data exposure.

23:51Robert HurlbutOh, yes.

23:52Chris RomeoLike, that was a piece of this, but this is really getting to the heart of what the issue is.

23:58Robert HurlbutRight.

23:58Chris RomeoAnd so they got a lot of good stuff. Like, I love we've got Argon2 listed as a—

24:02Robert Hurlbutyeah, yeah.

24:03Chris RomeoStore passwords using strong adaptive and salted hashing functions with a work factor such as Argon2, which, you know, the cheat sheets and stuff have gone in that direction as well. And so I love to see that. Like, that's That's pushing the envelope. And, you know, it's where you're building anything new, you better be using Argon2 at this point, from my perspective.

24:22Robert HurlbutRight.

24:24Chris RomeoSo that was cryptographic failures. I'm going to skip injection. I want to look at insecure design just because, I mean, come on, it's the best one on the list. I mean, please, for those threat modeling aficionados that are listening out there.

24:38Robert HurlbutFor the threat modeling aficionados, it's almost the only one on the list at the moment.

24:44Chris RomeoWe have our, we have our own top 10 list. It only includes A4 insecure design. It's the threat modeling top 10. It just says A4 insecure, A1 insecure design, A2 insecure design, A3 insecure design. We got them all listed there. So I think this one's— this is a section that could, you know, it could use a little more, a little more detail to it. But I just love the fact that it's included on the list.

25:05Robert HurlbutRight.

25:06Chris RomeoI want to see the reference. I want to see the Threat Modeling Manifesto listed as a reference here. It's something that I'm going to put in as a piece of feedback because I think that's something that can provide some value to people out there as they're trying to deal with this.

25:21Robert HurlbutAgreed.

25:22Chris RomeoLet's look at software and data integrity failures as another one that was new on the scene here. I mean, I went to the example attack scenarios to really help me understand what they were going after here. You know, insecure deserialization, interesting that it fits under this category. This almost feels like a little bit of a— I guess they used to call it a potpourri. I'd be dating myself to some degree here, but like a miscellaneous category is what this one kind of feels a little bit too miscellaneous.

25:59Robert HurlbutYeah.

26:00Chris RomeoLike, could we tighten it up a little bit and Because, I mean, you got insecure deserialization, which is a software problem. You got updates without signing. That's a data integrity problem. But we're kind of crushing 2 things into the same bucket here.

26:16Robert HurlbutYeah, this should be good to see where this goes as well.

26:20Chris RomeoYeah. I mean, I love the fact that in prevention, they're saying, hey, use a software supply chain security tool such as DependencyCheck or OWASP CycloneDX. I mean, I love it. That's great advice. That could also be advice that sits up in the, you know, the new one for software, for third-party and open-source vulnerabilities, the new one that was written, the using components, vulnerable and outdated components. Like, that could fit there as well, though. And then let's just take a quick peek at SSRF because it's another new one on the list. And, you know, this one I thought was, was well described. It was well defined as far as what it is, you know, to your earlier point about, you know, stuff that can happen Inside, they had some good examples here of port scanning internal servers, sensitive data, accessing metadata storage of cloud services, and then compromising internal services all through that SSRF kind of gateway.

27:13Robert HurlbutRight, right.

27:14Chris RomeoYeah, so I think at the end of the day, I mean, this is a great update on what we've seen for 2017. I think there's a lot of work and effort that went into making this, getting it to where it is now. I think this is going to push us as an industry. And that's what we got to ask ourselves every time, like when there's a new version of the OWASP Top 10, like how is this pushing us to be better? Because we know people are looking at it as an industry standard. They're building their tools against it. They're measuring their programs or putting it in RFPs all the time.

27:45Robert HurlbutRight?

27:46Chris RomeoLike this is what we're going to be judged against. And so I think it's— I think we're really, you know, we're— this one's pushing even more than 2017 did, pushing us as an industry to get to that next level.

27:57Robert HurlbutAbsolutely. Absolutely. No, I'm very happy with this and where we're heading with this. So yeah, looking forward to where this takes us, you know, in a good way, in a good place, I think.

28:10Chris RomeoSo yeah. I don't even want to make a prediction on how much this is, if any, going to change from the peer review version. You know, 2000— older versions did have some change that occurred.

28:21Robert HurlbutIt could. It could.

28:23Chris RomeoI mean, this one feels It feels a lot more right the way it's sitting right now to me.

28:27Robert HurlbutAgreed.

28:28Chris RomeoAgreed. Well, Robert, thanks once again for joining me on this journey through the OWASP Top 10 2021 Peer Review Edition. I guess our call to action for our audience out there is, hey, go look at this. It's on GitHub in the OWASP Top 10. Review it, add comments to it, do pull requests, like give back to your community. You know, you got an opportunity here. If you gotta— don't, don't come to a— don't come to us in a year and be like, well, there's this problem with the OWASP Top 10, because the question I'm going to ask you is, did you add it as an issue? And if the answer is no, sorry, you get your, your moment is now if you want to influence this document. So, um, thanks, Robert. Have a great rest of your day. Thanks, Chris.

29:10Robert HurlbutYou too. Thanks.

29:10Chris RomeoThanks for listening to the Application Security Podcast. You'll find the show on Twitter @AppSecPodcast and on the web at www.securityjourney.com/resources/podcast. You can also find Chris on Twitter @edgeroute and Robert @roberthurlbut. Remember, with application security, there are many paths, but only one destination.

5,276 words · transcript by assemblyai

More on API Security

View all episodes →

Get Reasonable AppSec: new episodes and useful picks from the archive.