1. EachPod

DevelopSec: Developing Security Awareness - Podcast

DevelopSec: Developing Security Awareness

Curious about application security? Want to learn how to detect security vulnerabilities and protect your application. We discuss different topics and provide valuable insights into the world of application security.

Technology Education Training
Update frequency
every 13 days
Average duration
19 minutes
Episodes
128
Years Active
2014 - 2025
Share to:
Ep. 124: Double-ClickJacking

Ep. 124: Double-ClickJacking

In this episode, I go over what Double-ClickJacking is and what you can potentially do about it to reduce the risk to your applications. 

Will this be the new finding on everyone's pen tests this year…

00:21:07  |   Mon 24 Feb 2025
Ep. 123: Goals of Security Culture - Sort of?

Ep. 123: Goals of Security Culture - Sort of?

In this episode, I talk about how security is a part of everyone's role and the labeling of "Security Culture". I share some ideas on how to improve on role based security awareness and building stro…

00:07:56  |   Tue 18 Feb 2025
Ep. 122: Integrating Security Responsibilities into Development

Ep. 122: Integrating Security Responsibilities into Development

In this episode I talk about assigning responsibility for secure development and how the dev and security teams should be working together to accomplish a common goal. 

I also discuss the importance o…

00:18:04  |   Mon 10 Feb 2025
Ep. 121 - Evolving Ransomware: Unique Tactics for Payment

Ep. 121 - Evolving Ransomware: Unique Tactics for Payment

In this episode I talk about the evolving world of ransomware. I discuss a few examples of unique tactics the malicious actors are using to put pressure on organizations to pay the ransom.

  

 Referenc…

00:17:44  |   Tue 07 May 2024
Ep. 120: Addressing Root Cause - Vulnerable Components

Ep. 120: Addressing Root Cause - Vulnerable Components

In this episode we talk about addressing the root cause of an issue versus the symptoms. How can the process of keeping application components updated be improved?

  

 For more info go to https://www.d…

00:16:30  |   Tue 31 Jan 2023
Ep. 119: Risks of SpellCheck

Ep. 119: Risks of SpellCheck

In this episode we talk about the spell check feature of the browser and how it could present a risk to sensitive data.

  

 Link to article referenced:  https://www.darkreading.com/application-security…

00:12:35  |   Thu 19 Jan 2023
Ep. 118: Log4J Sparking Thought on Vulnerable Components

Ep. 118: Log4J Sparking Thought on Vulnerable Components

Log4J has been the talk of the town recently and everyone is focused on the technical details of the specific vulnerabilities found. In this episode, James talks about the overarching ideas around de…

00:24:27  |   Sun 19 Dec 2021
Ep. 117: How Browsers are Helping with Security

Ep. 117: How Browsers are Helping with Security

Chrome has announced a few changes that we need to watch out for in the near future. We previously talked about the default value for samesite that is coming up fast. I wrote about this here:  https:…

00:13:49  |   Sun 09 Feb 2020
Ep. 116: Chrome Retires XSS Auditor

Ep. 116: Chrome Retires XSS Auditor

It was recently announced that Chrome was dropping the XSS Auditor in Chrome 78. What does that mean and how does that change things for you as a developer?  

https://www.chromium.org/developers/desig…

00:14:07  |   Fri 15 Nov 2019
Ep. 115: Is CSRF Really Dead?

Ep. 115: Is CSRF Really Dead?

In 2020, Chrome will default the SameSite attribute to Lax on all cookies. SameSite helps mitigate CSRF, but does that mean CSRF is Dead?

For more info go to https://www.developsec.com or follow us on…

00:15:09  |   Wed 06 Nov 2019
Ep. 114: Investing in People for Better Application Security

Ep. 114: Investing in People for Better Application Security

In this episode, James talks about investing in the development teams to increase application security priorities.

For more info go to https://www.developsec.com or follow us on twitter (@developsec).

00:24:37  |   Tue 29 Oct 2019
Ep. 113: What is your mother's maiden name?

Ep. 113: What is your mother's maiden name?

In this episode, James talks about some of the risks and recommendations around security questions and their implementation. 

For more info go to https://www.developsec.com or follow us on twitter (@d…

00:21:00  |   Tue 28 May 2019
Ep. 112: Application Fingerprinting

Ep. 112: Application Fingerprinting

Does your application give away details about it server, framework, or other components?  How is this information used by an attacker? Check out this episode to learn more.

For more info go to https:/…

00:21:04  |   Tue 22 Jan 2019
Ep. 111: Authentication Alerts

Ep. 111: Authentication Alerts

Would you know if someone authenticated to your account? With the breaches we see in the news, and attacks like credential stuffing, there must be a way to be alerted to account access. James talks a…

00:16:07  |   Mon 14 Jan 2019
Ep. 110: Implementation Matters

Ep. 110: Implementation Matters

James discusses how implementation matters with security controls and how it changes priorities. This came about after reading the following story: 

 https://www.theverge.com/2018/12/31/18162541/vein-…

00:19:17  |   Mon 07 Jan 2019
Ep. 109: 2018 Reflection

Ep. 109: 2018 Reflection

I talk about some of what happened in 2018 and what I am looking to do in 2019. I also ask you to think about your previous year and goals. I also talk about some new training I am providing.

 For mor…

00:27:26  |   Wed 02 Jan 2019
Ep. 108: Dunkin Donuts Breach, Maybe??

Ep. 108: Dunkin Donuts Breach, Maybe??

In this episode James talk about the Dunkin Donuts Perks breach. This is an interesting situation as the accounts were access using the victim's username and password found from another data breach. …

00:18:25  |   Wed 12 Dec 2018
Ep. 107: Credential Stuffing

Ep. 107: Credential Stuffing

In this episode James talks about what credential stuffing is, how if affects your apps, and how you can look to defend against it. 

 For more info go to https://www.developsec.com or follow us on twi…

00:18:36  |   Fri 09 Nov 2018
Ep. 106: Facebook Breach Take-aways and Insights

Ep. 106: Facebook Breach Take-aways and Insights

James talks about the Facebook breach and shares some insights into how you can take steps to prevent this type of incident in your applications. 

 For more info go to https://www.developsec.com or fo…

00:31:18  |   Thu 04 Oct 2018
Ep. 105: Interview with Eric Johnson

Ep. 105: Interview with Eric Johnson

I sit down with Eric Johnson to talk about security in the IDE and other fun topics. A bit longer than usual, but full of great information. 

You can reach out to Eric on twitter @emjohn20  or check o…

00:57:11  |   Thu 20 Sep 2018
Disclaimer: The podcast and artwork embedded on this page are the property of Jardine Software Inc.. This content is not affiliated with or endorsed by eachpod.com.