Your Opinion on AI Doesn't Matter. Learned Fragility Does
What happens when a tsunami of AI-written code meets a security industry that has spent decades chasing vulnerabilities? Brook S.E.
Listen to the episodeTopic
Finding what can go wrong before it does — STRIDE, LINDDUN, data flow diagrams, and the practice of doing it at scale.
What happens when a tsunami of AI-written code meets a security industry that has spent decades chasing vulnerabilities? Brook S.E.
Listen to the episodeMost fault trees get built on gut feeling. Petra Vukmirovic did something rarer: she borrowed the actual math from aviation and nuclear-plant safety engineering and pointed it at AI agents.
Listen to the episodeYou don't have to let AI do the thinking for you. In this episode, Vikram Narayan shares why the smartest teams use AI as an accelerant — not a replacement…
Listen to the episodeWhen every employee can generate working software, who owns the risk? Michael Burch, VP of AI Enablement and Acceleration at Security Journey, explains how…
Listen to the episodeIf AI writes all the code and the developer barely reads it, where does AppSec fit?
Listen to the episodeSecurity education often struggles because the people in the room are being talked at instead of invited to participate.
Listen to the episodeAPIs power modern applications, yet many AppSec programs still cannot reliably inventory them, model their threats, or enforce authorization.
Listen to the episodeThe EU Cyber Resilience Act turns product security from a best practice into a market-access requirement, and its effects extend well beyond Europe.
Listen to the episodeA dashboard full of green indicators can still describe an insecure organization. Aram Hovsepyan, founder and CEO of Codific and an OWASP SAMM contributor,…
Listen to the episodeWhat happens when teams add large language models to real applications and discover that familiar AppSec controls are no longer enough?
Listen to the episodeSecurity expert Tanya Janca discusses her new book "Alice and Bob Learn Secure Coding" and shares insights on making security accessible to developers.
Listen to the episodeBrett Crawley discusses the Elevation of Privilege (EoP) card game, a powerful tool for threat modeling in software development.
Listen to the episodeMatin Mavaddat discusses his perspective on security as a systemic concern, developed from his background in requirements engineering and systems architecture.
Listen to the episodeFrançois Proulx shares his discovery of security vulnerabilities in build pipelines. Francois has found that attackers can exploit this often overlooked side of the software supply chain.
Listen to the episodeJeff Williams, a renowned pioneer in the field of application security is with us to discuss Application Detection and Response (ADR), detailing its…
Listen to the episodeSteve Springett, an expert in secure software development and a key figure in several OWASP projects is back. Steve unpacks CycloneDX and the value proposition of various BOMs.
Listen to the episodeJahanzeb Farooq discusses his journey in cybersecurity and the challenges of building AppSec programs from scratch.
Listen to the episodeMatt Rose, an experienced technical AppSec testing leader discusses his career journey and significant contributions in AppSec.
Listen to the episodeRobert and Chris talk with Hendrik Ewerlin, a threat modeling advocate and trainer.
Listen to the episodeJason Nelson, an accomplished expert in information security management, joins Chris to share insights on establishing successful threat modeling programs…
Listen to the episodeChris Hughes, co-founder of Aquia, joins Chris and Robert on the Application Security Podcast to discuss points from his recent book Software Transparency:…
Listen to the episodeIs application security dead, or does it need to grow into something larger? CoverMyMeds security leaders Jay Bobo and Darylynn Ross challenge the…
Listen to the episodeArshan Dabirsiaghi of Pixee joins Robert and Chris to discuss startups, AI in appsec, and Pixee's Codemodder. io.
Listen to the episodeThe first OWASP Top 10 for Large Language Model Applications gave developers and security teams a shared threat model for a rapidly changing technology.
Listen to the episodeTanya Janca, also known as SheHacksPurple, joins the Application Security Podcast again to discuss secure coding, threat modeling, education, and other topics in the AppSec world.
Listen to the episodeJeff Willams of Contrast Security joins Chris and Robert on the Application Security Podcast to discuss runtime security, emphasizing the significance of…
Listen to the episodeMaril Vernon is passionate about Purple teaming and joins Robert and Chris to discuss the intricacies of purple teaming in cybersecurity.
Listen to the episodeKim Wuyts discusses her work in privacy threat modeling with LINDDUN, a framework inspired by Microsoft's STRIDE for security threat modeling.
Listen to the episodeSoftware supply chain -- how deep does the problem go? François is here to help us realize how deep the rabbit hole of the supply chain is and enlighten us with strategies to get out of the hole.
Listen to the episodeJeevan Singh, the director of product security at Twilio, discusses the future of application security engineers.
Listen to the episodeHave you ever considered using an SBOM to inform your threat modeling? Tony Turner has. Tony joins us to discuss SBOMs, threat modeling, and the importance of Cyber Informed Engineering.
Listen to the episodeChristian Frichot, an AppSec hacker, security leader, and developer of hcltm. He discusses the DevOps threat modeling tool he dreamed up and built.
Listen to the episodeSarah-Jane Madden is the Chief Information Security Officer of Sensing Technology Group. - part of Fortive.
Listen to the episodeRobyn Lundin started working in tech after a coding boot camp as a developer for a small startup.
Listen to the episodeAlex leads the Cyber Security Consulting Group, part of Rakuten's Cyber Security Defense Department.
Listen to the episodeJ. Wolfgang Goerlich is an Advisory CISO for Cisco Secure. He has been responsible for IT and IT security in the healthcare and financial services verticals.
Listen to the episodeIn this episode of the Application Security Podcast, Chris Romeo walks through the origin story of Security Journey and shares some experiences taking a security startup from bootstrap to acquisition.
Listen to the episodeCan machines make threat modeling faster without stripping away the judgment that makes it useful?
Listen to the episodeAlex Mor is a passionate cybersecurity defender or breaker depending on the time of day, providing expert technical guidance to product teams and building security in their platforms.
Listen to the episodeJoern Freydank is a Lead Cyber Security Engineer with more than 20 years of experience. He is currently establishing the Threat Modeling Program at a major insurance company.
Listen to the episodeAdam is a leading expert on threat modeling, and a consultant, expert witness, author and game designer. He has decades of experience delivering security.
Listen to the episodeOchaun Marshall is an Application Security Consultant. In his roles of secure ideas, he works on on-going development projects utilizing Amazon web services and breaks other people's web applications.
Listen to the episodeWhy do application security programs stall even after teams buy tools and define processes? James Ransome and Brook S. E.
Listen to the episodeChris and Robert conduct a practitioner peer review of the 2021 OWASP Top 10, examining what changed, what moved, and what the new structure communicates to development teams.
Listen to the episodeThreat modeling needs to fit the way developers work if it is going to survive a fast delivery cycle.
Listen to the episodeSoftware security has spent decades alternating between prevention, detection, and response. Kevin Greene joins Chris and Robert to ask what a balanced approach should look like now.
Listen to the episodeJeevan Singh is a Security Engineer Manager at Segment, where he is embedding security into all aspects of the software development process.
Listen to the episodeThreat modeling advice often sounds simple until a development team tries to apply it to a real system.
Listen to the episodeVandana Verma is the President of Infosec girls and Infosec Kids, a board of directors member for OWASP, and a leader for BSides Dehli. She joins us to introduce the OWASP Spotlight Series.
Listen to the episodeAlyssa Miller is a life-long hacker, security advocate, and cybersecurity leader. She is the BISO for S&P Global ratings and has over 15 years of experience in security roles.
Listen to the episodeRobert and I decided to talk about an article I wrote called "DevOps security culture: 12 fails your team can learn from". We hope you enjoy this walkthrough of the 12 fails.
Listen to the episodeHow did a group of experienced practitioners turn months of disagreement into a usable Threat Modeling Manifesto?
Listen to the episodeWhat should threat modeling mean when practitioners use the term in very different ways?
Listen to the episodeDevelopers need to protect data, but should they need to become cryptographers to do it safely?
Listen to the episodeNetwork engineers and application security teams depend on each other, yet often struggle to understand each other’s responsibilities.
Listen to the episodeGrant Ongers (@rewtd) is co-founder of the bearded trio called Secure Delivery, with a philosophy and purpose for optimal delivery and security in one dynamic package.
Listen to the episodeAdam Shostack is a leading expert on threat modeling, and consultant, entrepreneur, technologist, author and game designer.
Listen to the episodeAdam joins us to discuss remote threat modeling, and we do a live threat modeling exercise to figure out how remote threat modeling actually works.
Listen to the episodeA system can protect data from attackers and still violate the privacy of the people using it.
Listen to the episodeWhat happens when society’s dependence on software grows faster than its ability to make that software safe?
Listen to the episodeAutomating security tests is useful, but it does not by itself make a development team secure.
Listen to the episodeHow did Microsoft's Security Development Lifecycle become a repeatable engineering practice rather than a one-time security push?
Listen to the episodeWhat happens when Chris and Robert trade a single interview topic for five current application security ideas?
Listen to the episodeWhat happens when a threat model has to account for patient privacy and clinical harm as well as attackers?
Listen to the episodeSeason 5 covered application security from tools and threat models to mentoring, self-care, coaching, dependency risk, and program design.
Listen to the episodeWhy doesn't an executive mandate and a scanning tool add up to a software security program?
Listen to the episodeWhat if a system works exactly as designed but gives people new ways to harm one another?
Listen to the episodeWhy threat model when AppSec teams already have scanners, checklists, and testing?
Listen to the episodeSecurity teams learn something different when they leave their own conferences and listen to the industries using their products.
Listen to the episodeWhat if developers could describe threats in the same place they describe their software?
Listen to the episodeWhat happens when a threat model takes days to produce but the development team has already moved on?
Listen to the episodeWhat can the wider AppSec community learn from Israel’s unusually dense security ecosystem?
Listen to the episodeA threat model that lives in an old document rarely keeps pace with the code it describes.
Listen to the episodeA list of weaknesses is not the same thing as an understanding of the threats facing a business.
Listen to the episodeWhat developers need from a threat model is often a clear set of requirements they can implement.
Listen to the episodeCan a threat modeling community bring different methods together without forcing everyone into the same process?
Listen to the episodeWhich books, sites, conferences, and communities are genuinely useful for learning application security? Chris and Robert compare their personal recommendations and explain what each resource offers.
Listen to the episodeWhen a team is already ten sprints into a product, stopping to threat model everything can sound impossible.
Listen to the episodeWhat is a security champion, and how can an organization build a program that lasts? Chris and Robert compare definitions, alternative titles, and the qualities that make a champion effective.
Listen to the episodeMoving a security scanner earlier in the pipeline is not the same as building security into development.
Listen to the episodeWhy does OWASP matter beyond its famous Top 10 list? The Season 2 finale revisits guests who demonstrate the breadth of the foundation’s work.
Listen to the episodeHow do you find security problems in a design before they become expensive changes to running software?
Listen to the episodeThreat modeling is easier to adopt when its tools fit the way developers already work.
Listen to the episodeFixing vulnerable code is only part of application security; a flawed design can survive every code-level check. Brook S. E.
Listen to the episodeWhat defined the first season of the Application Security Podcast? Chris and Robert revisit clips that established the show’s early themes: thinking like an…
Listen to the episodeWhat does “think like an attacker” actually ask a developer to do? Adam Shostack joins Chris and Robert to challenge a familiar instruction that can leave…
Listen to the episodeA useful threat model should explain how an attacker could harm the business, not just complete a checklist.
Listen to the episodeCan you learn enough about a development team’s security practices in an hour to give it useful direction?
Listen to the episodeHow should application security change when a team moves from Waterfall to Agile? Chris and Robert compare the two development models and map security work onto each one.
Listen to the episodeWhich activities turn a secure development lifecycle from an aspiration into repeatable work?
Listen to the episode