Stephen de Vries -- Threat Modeling with a bit of #Startup
Stephen de Vries joins to discuss Threat Modeling and the unique approach that he takes by using tooling. We also discuss application security and startups.
Listen to the episode304 episodes, going back to 2016. Showing 241–264.
Stephen de Vries joins to discuss Threat Modeling and the unique approach that he takes by using tooling. We also discuss application security and startups.
Listen to the episodeJulien Vehent joins us to discuss all things DevOps + Security. We talk through Julien's new book, Securing DevOps, and go in-depth about his journey to building security into DevOps at his job.
Listen to the episodeChristian Folini joins Chris at AppSec EU for this episode about ModSecurity and the Core Rule Set project from OWASP.
Listen to the episodeSean Wright joins Chris to discuss the changes Google made to handle the HTTP Protocol. They also dive into TLS and some other pieces of crypto that relate to #AppSec.
Listen to the episodeThe conclusion of Season 3, all the best highlights, and some great advice from our guests on what you need to build an #AppSec Program.
Listen to the episodeMartin Knobloch joins Chris and Robert to discuss all things OWASP. They dive into the history of OWASP and some of the plans for the future. You can find Martin on Twitter @knoblochmartin.
Listen to the episodeDevin McMasters joins Chris to talk about bug bounties and how to make them successful.
Listen to the episodeIn this episode, Robert speaks about Malicious User Stories and DevOps with Apollo Clark. He discusses how to properly handle user stories in a world being taken over by DevOps.
Listen to the episodeMegan Roddie joins Robert at the SOURCE Conference in Boston. She talks about how neurodiverse people can truly help an organization.
Listen to the episodeChase Schultz joins to discuss the combination of AppSec and hardware. He also dives into how the Meltdown and Spectre attacks worked.
Listen to the episodeJohn Melton joins to discuss the #OWASP AppSensor project. He talks about how AppSensor works and how it can be used in your application.
Listen to the episodeDavid Habusha joins to discuss the OWASP Top 10 A9: Using components with known vulnerabilities. He also dives into the Software Composition Analysis (SCA) market.
Listen to the episodeSteve Springett joins the show to talk about Dependency Check and Dependency Track. He also discusses how they can help prevent you from using components with known vulnerabilities.
Listen to the episodeSteven Wierckx joins Robert and Chris this week to talk about the #OWASP Threat Modeling project that he’s involved in.
Listen to the episodeJim Manico joins us to discuss some of the changes with the OWASP Cheat Sheets and their plans for that project's future.
Listen to the episodeNeil Smithline joins this week to discuss one of the new items on the OWASP Top 10 List, Insufficient Logging and Monitoring.
Listen to the episodeJim Routh joins the podcast to discuss selling #AppSec up the chain. Jim has built five successful software security programs in his career and serves as a CISO now.
Listen to the episodeChris and Robert go over a plethora of recommendations they have accumulated over their years of experience in the industry. Chris’s recommendations 1.
Listen to the episodeMagen Wu works through the topic of burnout and mental health in security. She gives examples of handling this and recognizing if people around you are burning out.
Listen to the episodeKaty Anton joins this week to discuss number four on the OWASP Top 10. She dives into what XXE is, how to deal with it, and other new items on the OWASP Top 10 2017.
Listen to the episodePete Chestna is an advocate for SAST, DAST, and IAST tools and a passionate #AppSec enthusiast.
Listen to the episodeIrene Michlin operates at the intersection of security and agility. She teaches about incremental threat modeling and how to make threat modeling when living in an Agile or DevOps world.
Listen to the episodeBill Sempf joins to talk about insecure deserialization. We do a deep dive and contextual review of the generalities of deserialization and the specifics of…
Listen to the episodeSecurity champions are the hands and feet of any well-equipped product security team.
Listen to the episode