1. EachPod

DevelopSec: Developing Security Awareness - Podcast

DevelopSec: Developing Security Awareness

Curious about application security? Want to learn how to detect security vulnerabilities and protect your application. We discuss different topics and provide valuable insights into the world of application security.

Technology Education Training
Update frequency
every 13 days
Average duration
19 minutes
Episodes
128
Years Active
2014 - 2025
Share to:
Ep. 84: Understanding the Technology

Ep. 84: Understanding the Technology

You know your development language and platform, but do you really know the ins and outs of web application technology? How well do you know HTTP, HTML, etc? James talks about a few scenarios where r…

00:23:30  |   Tue 31 Oct 2017
Ep. 83: Authorization Overview

Ep. 83: Authorization Overview

In this episode, James talks about authorization and some common areas where it poses a risk. He also goes over some techniques to help test authorization.

  

For more info go to https://www.developsec…

00:20:54  |   Wed 18 Oct 2017
Ep. 82: Equifax Take-aways

Ep. 82: Equifax Take-aways

The Equifax breach was a major news story. James talks about some of the security controls mentioned and how to start a conversation within your organization about them. 

Want to listen on YouTube?  C…

00:25:55  |   Fri 29 Sep 2017
Ep. 81: JavaScript in HREF and SRC (XSS)

Ep. 81: JavaScript in HREF and SRC (XSS)

We talk about cross-site scripting (XSS) all the time, but often overlook the ability to use javascript: in anchor tags.  James talks about this unique ability and how to protect your applications fr…

00:20:20  |   Mon 18 Sep 2017
Ep. 80: Understanding Security of Your Platforms

Ep. 80: Understanding Security of Your Platforms

We use a lot of platforms and frameworks when we develop an application. These platforms may provide security features, but do you know which ones? James talks about the importance of understanding y…

00:19:35  |   Wed 23 Aug 2017
Ep. 79: Marketing with USB Drives

Ep. 79: Marketing with USB Drives

James talks about the risk of USB thumb drives and their risk using the recent BCBS marketing campaign as an example. (http://www.fiercehealthcare.com/privacy-security/bcbs-alabama-re-evaluates-usb-m…

00:15:40  |   Mon 31 Jul 2017
Ep. 78: MySpace Lessons - Looking At Account Recovery

Ep. 78: MySpace Lessons - Looking At Account Recovery

James talks about a recent vulnerability report regarding MySpace's Account Recovery system (https://www.wired.com/story/myspace-security-account-takeover/).  He talks about considerations around acc…

00:19:14  |   Mon 24 Jul 2017
Ep. 77: Interactive Application Security Testing

Ep. 77: Interactive Application Security Testing

In this episode, James talks about Interactive Application Security Testing, or IAST. It is a sort of hybrid approach that is similar to both dynamic and static analysis. Listen in to learn more abou…

00:14:47  |   Fri 07 Jul 2017
Ep. 76: Validation - Client vs. Server

Ep. 76: Validation - Client vs. Server

Are you thinking about client vs. server-side input validation?  Curious why each is important and when to use them?  James talks about the basic concepts and how to apply them to create more secure …

00:13:09  |   Mon 19 Jun 2017
Ep. 75: IAM with Geurt van Wijk

Ep. 75: IAM with Geurt van Wijk

In this episode I sit down with Geurt van Wijk from IDdriven to discuss IAM and IDaaS. Geurt has many years of experience around Identity and shares some great insights into considerations when worki…

00:41:45  |   Mon 05 Jun 2017
Ep. 74: Audio Driver Key Logger Lessons Learned

Ep. 74: Audio Driver Key Logger Lessons Learned

It was recently reported that an audio driver on HP systems was logging key strokes to a local file.  Accidental?  Malicious?  Instead, we talk about how to try and avoid this from happening in the f…

00:16:25  |   Wed 24 May 2017
Ep. 73: Identity with Vittorio Bertocci

Ep. 73: Identity with Vittorio Bertocci

I sat down with Vittorio Bertocci from Microsoft at the Microsoft Build 2017 conference in Seattle Washington.  Vittorio shared some great insights into Identity and some new things around Azure AD a…

00:30:26  |   Wed 17 May 2017
Ep. 72: Where to Perform Output Encoding

Ep. 72: Where to Perform Output Encoding

Over the years I have had many people ask about encoding before storing data in the database.  Here are my thoughts and recommendations.

For more info go to https://www.developsec.com or follow us on …

00:13:37  |   Thu 11 May 2017
Ep. 71: Sub Resource Integrity

Ep. 71: Sub Resource Integrity

Do you use hosted content on a CDN? How do you know the file hasn't been modified?  James describes Sub Resource Integrity and how it is used to help detect and prevent loading modified files.  For d…

00:14:47  |   Mon 17 Apr 2017
Ep. 70: Considering security when selecting an application platform

Ep. 70: Considering security when selecting an application platform

Do you struggle with trying to pick the most secure application platform? Are you focusing on the right questions? James talks about ways to look at application platforms and be secure, no matter whi…

00:21:02  |   Mon 27 Mar 2017
Ep. 69: Concurrent User Sessions

Ep. 69: Concurrent User Sessions

Do you allow users to login into their accounts across multiple browsers or devices? Does this raise a security concern? James talks about how to handle this question and analyze the root issue.

For m…

00:21:23  |   Fri 10 Mar 2017
Ep. 68: How the AWS disruption can help us

Ep. 68: How the AWS disruption can help us

I am sure you have heard about the AWS service disruption that occurred.  Have you seen how we can learn from this when we look at our own tools and processes?  James talks about how we need to look …

00:15:22  |   Fri 03 Mar 2017
Ep. 67: Clearing up HTTPOnly and Secure Cookie Attributes

Ep. 67: Clearing up HTTPOnly and Secure Cookie Attributes

I hear a lot of people struggling with HTTPOnly and Secure attributes on cookies. The names may be confusing to some. Change your viewpoint and it may become easier..

For more info go to https://www.d…

00:09:23  |   Fri 24 Feb 2017
Ep. 66: Forgot Username

Ep. 66: Forgot Username

We always talk about Forgot Password... But what about Forgot Username? Listen in as James discusses why protecting this functionality is important and the ways it could be abused if not properly han…

00:14:45  |   Wed 22 Feb 2017
Ep. 65: Security Questions: Good or Bad?

Ep. 65: Security Questions: Good or Bad?

In this episode, James talks about security questions, or secret questions. We see them used in many different places. People complain they are horrible. So are they that bad that you shouldn't use t…

00:18:07  |   Wed 15 Feb 2017
Disclaimer: The podcast and artwork embedded on this page are the property of Jardine Software Inc.. This content is not affiliated with or endorsed by eachpod.com.