1. EachPod

DevelopSec: Developing Security Awareness - Podcast

DevelopSec: Developing Security Awareness

Curious about application security? Want to learn how to detect security vulnerabilities and protect your application. We discuss different topics and provide valuable insights into the world of application security.

Technology Education Training
Update frequency
every 13 days
Average duration
19 minutes
Episodes
128
Years Active
2014 - 2025
Share to:
Ep. 64: Using Stolen Passwords to Protect User Accounts

Ep. 64: Using Stolen Passwords to Protect User Accounts

A few months ago, it was announced that some companies buy stolen passwords off of the black market to help protect their users.  This is done by determining if the user's password was part of that l…

00:14:27  |   Mon 23 Jan 2017
Ep. 63: Remember Me Feature: Security Considerations

Ep. 63: Remember Me Feature: Security Considerations

Are you, or have you, implemented a remember me feature for your application?  What do you remember, username, password, or both?  James talks about some security considerations around implementing a…

00:15:06  |   Tue 17 Jan 2017
Ep. 62: MongoDB Ransomware Attacks

Ep. 62: MongoDB Ransomware Attacks

Do you use MongoDB?  If so, is it exposed to the internet?  Recent news (listed below) had shown that a large number of MongoDB instances are being infected with ransomware.  James talks about the is…

00:13:53  |   Tue 10 Jan 2017
Ep. 61: Multi-factor Authentication

Ep. 61: Multi-factor Authentication

Implementing multi-factor authentication isn't just about a second factor.  There are many considerations that need to be included.  One in particular, how do you handle the user losing their means o…

00:17:24  |   Thu 05 Jan 2017
Ep. 60: Yahoo Breach Takeaways

Ep. 60: Yahoo Breach Takeaways

Yahoo has announced yet another breach from back in 2013 affecting a very large number of user accounts. https://investor.yahoo.net/ReleaseDetail.cfm?&ReleaseID=1004285   This creates an opportunity …

00:18:49  |   Thu 15 Dec 2016
Ep. 59: All About Cookie Protection

Ep. 59: All About Cookie Protection

It is the holiday season.  It is appropriate to talk about cookies.  Not the kind that you bake, but the ones in your applications.  James talks about the security mechanisms for cookies and clarifie…

00:23:06  |   Wed 14 Dec 2016
Ep. 58:

Ep. 58: "Untrusted" Data

Have you heard someone mention "untrusted" data?  Applications take data from multiple data sources and we are often confused on what should be trusted or not.  In this episode, James Jardine talks a…

00:21:40  |   Wed 16 Nov 2016
Ep. 57: Source Code Review

Ep. 57: Source Code Review

Are you an organization looking to do source code review?  Are you trying to hire a pen tester with source code review as a duty?  

James talks about Secure Code Review and some common implementations…

00:21:59  |   Fri 04 Nov 2016
Ep. 56: Security Contacts

Ep. 56: Security Contacts

Do you have a clear path for users to contact you about potential security issues in your application or device?  Is there a potential for the communication to be lost in the mix?  James talks about …

00:12:32  |   Wed 26 Oct 2016
Ep. 55: Scoping an application security assessment  (Applications)

Ep. 55: Scoping an application security assessment (Applications)

Having a penetration test performed against your applications?  Do you have mobile and web applications performing the same functionality?  James talks about the reason behind doing these assessments…

00:12:03  |   Wed 28 Sep 2016
Ep. 54: WAFs and Pen Testing

Ep. 54: WAFs and Pen Testing

Your pen tester want you to white list them in your WAF?  What should you do?  Why do they ask?  James breaks it down for you in this episode.

For more info go to https://www.developsec.com or follow …

00:16:19  |   Wed 21 Sep 2016
Ep. 53: Chrome Changing Secure Notifications

Ep. 53: Chrome Changing Secure Notifications

We talk HTTP/HTTPS all the time.  Google just announced that in January they are going to change how they display their secure/not secure indicators for HTTP sites that have passwords or credit cards…

00:17:09  |   Thu 15 Sep 2016
Login Forms and HTTPS

Login Forms and HTTPS

Are your login forms secure?  Are you sure?  In this episode James talks about potential risks with presenting your login forms when using HTTPS and how to avoid them.  We often are focused on HTTPS …

00:10:28  |   Wed 07 Sep 2016
Ep. 52: Importance of UI to Security

Ep. 52: Importance of UI to Security

The user interface plays a big part in the security of an application.  We often only look at flaws such as XSS, but here James provides an example of the lack of Input Validation messages creating a…

00:11:37  |   Mon 05 Sep 2016
Ep. 51: Everything is a target

Ep. 51: Everything is a target

James discusses how all applications, big or small, are a potential target and need to have secure coding practices.  We often only look at our big applications from a security perspective, but in re…

00:12:48  |   Mon 29 Aug 2016
Ep. 50: How Serious is Username Enumeration

Ep. 50: How Serious is Username Enumeration

In this episode, James talks about what Username Enumeration is, how it can be used by attackers, and some ways to help reduce the risk of it. 

 

For more info go to https://www.developsec.com or follo…

00:23:06  |   Thu 28 Jul 2016
Ep. 49: Should Password Change Invalidate Access Tokens?

Ep. 49: Should Password Change Invalidate Access Tokens?

Interesting question was raised around changing a password and the need to invalidate all the access tokens for the associated mobile devices.  James talks about his view on the topic and how you can…

00:16:13  |   Mon 25 Jul 2016
Ep. 48: Pokemon Go Security Discussions

Ep. 48: Pokemon Go Security Discussions

Pokemon Go has taken the world by storm and as always, it brings up some things to talk about regarding security.  In this episode James talks about some out of the box security thoughts regarding mo…

00:18:58  |   Mon 18 Jul 2016
Ep. 47: Account Lockouts and auto-unlock

Ep. 47: Account Lockouts and auto-unlock

A question came in regarding auto-unlock of accounts and account lockout in general.  James discusses his thoughts on this process and how he approaches these types of questions.

 

For more info go to …

00:10:54  |   Fri 17 Jun 2016
Ep. 46: Password Confirm Boxes

Ep. 46: Password Confirm Boxes

A question came in around the need for the password confirm box on registration screens and the security implications.  In this episode I respond to the question and give some insights on how to appr…

00:11:41  |   Fri 10 Jun 2016
Disclaimer: The podcast and artwork embedded on this page are the property of Jardine Software Inc.. This content is not affiliated with or endorsed by eachpod.com.