1. EachPod

DevelopSec: Developing Security Awareness - Podcast

DevelopSec: Developing Security Awareness

Curious about application security? Want to learn how to detect security vulnerabilities and protect your application. We discuss different topics and provide valuable insights into the world of application security.

Technology Education Training
Update frequency
every 13 days
Average duration
19 minutes
Episodes
128
Years Active
2014 - 2025
Share to:
Ep. 45: The importance of WHY

Ep. 45: The importance of WHY

We are too quick to just give generic recommendations for resolving security vulnerabilities.  We need to make sure that the application teams understand why these are vulnerabilities and why they ar…

00:22:45  |   Fri 03 Jun 2016
Ep. 44:

Ep. 44: "We don't support Macs"

When a developer was presented with a but they tried to say that it wasn't an issue because it was found by a tester using a Mac.  "We don't support Macs"   James talks about how this is a fundamenta…

00:12:02  |   Fri 27 May 2016
Ep. 43: Reflecting on Current AppSec Training

Ep. 43: Reflecting on Current AppSec Training

James reflects on the current way we expect application teams to get security training and potential short falls.  Is there a better way?  Listen as I talk through some different points on the topic.…

00:22:01  |   Sat 21 May 2016
Ep. 42: The Need for Better Secure Code Examples

Ep. 42: The Need for Better Secure Code Examples

How do you get your secure coding information?  Do you pull code snippets from the internet?  Who doesn't.  How many of those actually use secure coding best practices.  We have a challenge where mos…

00:21:38  |   Sun 24 Apr 2016
Ep. 41: Why You Need an Application Inventory

Ep. 41: Why You Need an Application Inventory

Do you use an application inventory in your application security program?  James discusses what an application inventory is and why it is important.  Here is a list of a few tools that can be used to…

00:18:21  |   Tue 19 Apr 2016
Ep. 40: Getting More Value from Pen Tests

Ep. 40: Getting More Value from Pen Tests

Penetration tests provide a measuring stick for security, but are you missing out on additional value?  James discusses ways to use the pen test results to get more value out of a penetration test.

 

J…

00:16:48  |   Tue 08 Mar 2016
Ep. 39: Authentication

Ep. 39: Authentication

James discusses what authentication is and some things to look out for. 

 

 

For more info go to https://www.developsec.com or follow us on twitter (@developsec).

Presented by Jardine Software Inc. (http…

00:19:49  |   Mon 29 Feb 2016
Ep. 38: Static Analysis: Tips for Successful Program

Ep. 38: Static Analysis: Tips for Successful Program

In this episode, James Jardine talks about some of the things you need to consider when trying to implement a static analysis program. It is more than just a tool you drop in.  To build a successful …

00:39:14  |   Sun 07 Feb 2016
Ep. 37: CSRF Chaining

Ep. 37: CSRF Chaining

James Jardine discusses CSRF chaining, using the combination of multiple CSRF requests to perform a task. Typically we believe that CSRF can only be done with one request, but with a little javascrip…

00:17:51  |   Tue 26 Jan 2016
Ep. 36: Intro to Cross Site Request Forgery (CSRF)

Ep. 36: Intro to Cross Site Request Forgery (CSRF)

In this episode, James talks about what CSRF is, why it is a risk, and different ways to protect against it.  CSRF is #8 on the OWASP Top 10 https://www.owasp.org/index.php/Top_10_2013-A8-Cross-Site_…

00:23:46  |   Thu 07 Jan 2016
Ep. 35: An Introduction to Open Redirects

Ep. 35: An Introduction to Open Redirects

James discusses Open Redirects, or on the OWASP Top 10 what is referred to as Unvalidated Redirects and Forwards (https://www.owasp.org/index.php/Top_10_2013-A10-Unvalidated_Redirects_and_Forwards)  …

00:17:05  |   Tue 15 Dec 2015
Ep. 34: Importance of Hacking

Ep. 34: Importance of Hacking

James discusses Hacking, what is it, why is it important.  It is more than what you see in the media of the bad guys hacking computers.  It is a curiosity, a hobby, an interesting in pushing limits. …

00:25:18  |   Fri 11 Dec 2015
Ep. 33: Holiday Gift Security Considerations

Ep. 33: Holiday Gift Security Considerations

James discussing some things to consider this holiday season when searching for that perfect gift.  It is important to understand the privacy policy (what is collected and how it is used) as well as …

00:18:38  |   Tue 24 Nov 2015
Ep. 32: Dynamic Analysis: An Overview

Ep. 32: Dynamic Analysis: An Overview

James Jardine provides an overview of Dynamic Analysis and why it is important.  Like any automation, there are pros and cons.   Listen to find out why dynamic analysis is useful. 

 

Some links to some…

00:22:27  |   Sat 21 Nov 2015
Ep. 31: Response Splitting and Header Injection

Ep. 31: Response Splitting and Header Injection

Join James Jardine as he discusses what Response Splitting/Header Injection is and how it works.  He also discusses how ASP.Net helps defend against this attack. 

This is a quick overview of the vulne…

00:18:40  |   Mon 09 Nov 2015
Newscast - Oct. 20, 2015

Newscast - Oct. 20, 2015

Hi and welcome to the DevelopSec newscast for October 20th, 2015.  I am James Jardine and I wanted to take a few moments to talk about some recent news stories over the past week.

  • Apple removes severa…
00:26:16  |   Tue 20 Oct 2015
Newscast - Sept. 30, 2015

Newscast - Sept. 30, 2015

James breaks down a few news stories from the previous week.  The following stories were discussed, including some brief points.

 

00:23:52  |   Thu 01 Oct 2015
Newscast - Sept. 23, 2015

Newscast - Sept. 23, 2015

James breaks down a few news stories from the previous week.  The following stories were discussed, including some brief points.

00:15:31  |   Thu 24 Sep 2015
Ep. 30: HTTP Strict Transport Security (HSTS): Intro

Ep. 30: HTTP Strict Transport Security (HSTS): Intro

James talks about HTTP Strict Transport Security (HSTS) and what it is for.  For more information, check out the corresponding post https://www.developsec.com/2015/09/17/http-strict-transport-securit…

00:14:41  |   Fri 18 Sep 2015
Ep. 29: FTC Start with Security Guidelines

Ep. 29: FTC Start with Security Guidelines

Just recently, the FTC released "Start with Security: A Guide for Busines" which is a set of 10 items businesses can do to help secure their assetts.  The full guide can be found at https://www.ftc.g…

00:24:58  |   Thu 30 Jul 2015
Disclaimer: The podcast and artwork embedded on this page are the property of Jardine Software Inc.. This content is not affiliated with or endorsed by eachpod.com.