Why AI Code Review Will Replace Human Review Faster Than You Think
Jim Manico thinks the era of human code review is ending, and that clinging to it will hurt your company.
Listen to the episodeTopic
REST and GraphQL, authentication and authorization, and the object-level access control failures that dominate real breaches.
Jim Manico thinks the era of human code review is ending, and that clinging to it will hurt your company.
Listen to the episodeTraditional SAST is deterministic but shallow; AI can reason about context but may answer differently every time. Can the two approaches make each other better?
Listen to the episodeGitGuardian found 29 million hard-coded secrets in public GitHub commits in one year—a 34% increase and its largest jump yet. Why is a supposedly simple problem getting worse?
Listen to the episodeAPIs power modern applications, yet many AppSec programs still cannot reliably inventory them, model their threats, or enforce authorization.
Listen to the episodeMatin Mavaddat discusses his perspective on security as a systemic concern, developed from his background in requirements engineering and systems architecture.
Listen to the episodeJeff Williams, a renowned pioneer in the field of application security is with us to discuss Application Detection and Response (ADR), detailing its…
Listen to the episodeAndrew Van Der Stok, a leading web application security specialist and executive director at OWASP joins us for this episode.
Listen to the episodeJames Berthoty, a cloud security engineer with a diverse IT background, discusses his journey into application and product security.
Listen to the episodeMukund Sarma, the Senior Director for Product Security at Chime, talks with Chris about his career path from being a software engineer to becoming a leader in application security.
Listen to the episodeWhat is zero trust, and how does it impact the world of applications and application security?
Listen to the episodeGraphQL gives clients remarkable flexibility, but that same flexibility can expose authorization gaps, denial-of-service paths, and unexpected routes to sensitive data.
Listen to the episodeBrett Smith is a Software Architect/Engineer/Developer with 20+ years of experience.
Listen to the episodeNeil Matatall is an engineer with a background in security. He has previously worked at GitHub and Twitter and is a co-founder of Loco Moco Product Security Conference.
Listen to the episodeChris and Robert conduct a practitioner peer review of the 2021 OWASP Top 10, examining what changed, what moved, and what the new structure communicates to development teams.
Listen to the episodeCloud-native development gives engineers control over more of the stack, but it also gives them more security decisions to get wrong.
Listen to the episodeDmitry Sotnikov serves as Chief Product Officer at 42Crunch – an enterprise API security company.
Listen to the episodeGrant Ongers (@rewtd) is co-founder of the bearded trio called Secure Delivery, with a philosophy and purpose for optimal delivery and security in one dynamic package.
Listen to the episodeFuzz testing can sound specialized and difficult, but Zsolt Imre argues that teams can start small and learn quickly.
Listen to the episodeWhy did APIs need a security Top 10 of their own? Erez Yalon joins Chris and Robert to explain the gaps that led to the OWASP API Security project and walk through its original 2019 list.
Listen to the episodeWhat happens when a threat model takes days to produce but the development team has already moved on?
Listen to the episodeA list of weaknesses is not the same thing as an understanding of the threats facing a business.
Listen to the episodeDevelopers need concrete security answers, but finding trustworthy guidance can take longer than writing the code.
Listen to the episodeHow do you find security problems in a design before they become expensive changes to running software?
Listen to the episodeAgile delivery promises fast feedback, but where does application security fit when teams are already moving continuously?
Listen to the episodeDevelopers hear plenty about vulnerabilities, but what should they actually build into their applications to prevent them?
Listen to the episodeWhy did the 2017 OWASP Top 10 release candidate provoke such a strong reaction? Chris and Robert walk through the proposed categories, compare them with…
Listen to the episode