Izar Tarandach and Matt Coles-- Threat Modeling: A Practical Guide for Development Teams
Threat modeling advice often sounds simple until a development team tries to apply it to a real system.
Listen to the episode312 episodes, going back to 2016.
Threat modeling advice often sounds simple until a development team tries to apply it to a real system.
Listen to the episodeCharles is a Senior Security Consultant for Red Siege. He has over 18 years of experience in IT.
Listen to the episodeLeif Dreizler is the manager of the Product Security team at Segment. Leif got his start in the security industry at Redspin doing security consulting work and was later an early employee at Bugcrowd.
Listen to the episodeVandana Verma is the President of Infosec girls and Infosec Kids, a board of directors member for OWASP, and a leader for BSides Dehli. She joins us to introduce the OWASP Spotlight Series.
Listen to the episodeDr. Anita D’Amico is the CEO of Code Dx, which provides Application Security Orchestration and Correlation solutions to industry and government.
Listen to the episodeAlyssa Miller is a life-long hacker, security advocate, and cybersecurity leader. She is the BISO for S&P Global ratings and has over 15 years of experience in security roles.
Listen to the episodeCloud-native development gives engineers control over more of the stack, but it also gives them more security decisions to get wrong.
Listen to the episodeRobert and I decided to talk about an article I wrote called "DevOps security culture: 12 fails your team can learn from". We hope you enjoy this walkthrough of the 12 fails.
Listen to the episodeA secure software pipeline is more than a collection of scanners. Jim Routh joins Chris and Robert to explain how organizations can build repeatable…
Listen to the episodeHow does a volunteer security community reach the millions of people who build software? Andrew van der Stock reflects on that challenge after becoming OWASP’s executive director in 2020.
Listen to the episodeSoftware bills of materials promise visibility into dependencies, but visibility alone does not create assurance.
Listen to the episodeBrian Reed is Chief Mobility Officer at NowSecure. Brian has over 30 years in tech and 15 years in mobile, security, and apps dating back to the birth of…
Listen to the episodeHow did a group of experienced practitioners turn months of disagreement into a usable Threat Modeling Manifesto?
Listen to the episodeWhat should threat modeling mean when practitioners use the term in very different ways?
Listen to the episodeWhich ideas from Season 7 deserve another listen? Chris and Robert assemble clips from across the season, creating a fast tour through secure development…
Listen to the episodeJb Aviat is CTO and co-founder at Sqreen. Prior to this, Jb worked at Apple as a reverse engineer, pentester and developer.
Listen to the episodeRuby on Rails can provide strong security defaults, but a framework cannot make every design decision for its developers.
Listen to the episodeDmitry Sotnikov serves as Chief Product Officer at 42Crunch – an enterprise API security company.
Listen to the episodeCaroline Wong is the Chief Strategy Officer at Cobalt. io. You cannot hack yourself secure. The challenge is that developers get bored with hacking broken pieces of code after a while.
Listen to the episodeAaron Davis is a founder, dev, and a lead security researcher at MetaMask, a popular Ethereum wallet.
Listen to the episodeDevelopers need to protect data, but should they need to become cryptographers to do it safely?
Listen to the episodeMichael Furman is the Lead Security Architect at Tufin, and is responsible for the security and Security Development Lifecycle (SDL) of Tufin software products.
Listen to the episodeNetwork engineers and application security teams depend on each other, yet often struggle to understand each other’s responsibilities.
Listen to the episodeNeil Matatall is a product security engineer at GitHub. He focuses on designing and engineering user experiences solutions related to authentication and account recovery.
Listen to the episode