1. EachPod

DevelopSec: Developing Security Awareness - Podcast

DevelopSec: Developing Security Awareness

Curious about application security? Want to learn how to detect security vulnerabilities and protect your application. We discuss different topics and provide valuable insights into the world of application security.

Technology Education Training
Update frequency
every 13 days
Average duration
19 minutes
Episodes
128
Years Active
2014 - 2025
Share to:
Ep. 28: What is Penetration Testing

Ep. 28: What is Penetration Testing

In this episode, James Jardine talks about what penetration testing, "pen testing", is and how it really has a lot of meanings to different people.  A pen test isn't something that should be consider…

00:20:45  |   Fri 17 Jul 2015
Ep. 27: Importance of Security for BA and PM

Ep. 27: Importance of Security for BA and PM

In this episode James covers some thoughts on how business analysts and project managers are crucial to the security role for applications.  It doesn't take a huge change in the way work is done and …

00:15:54  |   Thu 18 Jun 2015
Ep. 26: The Importance of Security for QA

Ep. 26: The Importance of Security for QA

QA plays a crucial role in testing for security flaws within applications.  They have the Proximity, Knowledge of the Application and it is an extension to the role they currently fill.  James Jardin…

00:22:20  |   Tue 26 May 2015
Ep. 25: Static Analysis: Analyzing the Options

Ep. 25: Static Analysis: Analyzing the Options

Static analysis is an important part of the secure development lifecycle.  There are some things to think about when you are considering a static analysis option.  James discusses the questions in th…

00:17:09  |   Fri 10 Apr 2015
Ep. 24: The Importance of Baselines

Ep. 24: The Importance of Baselines

Understanding baselines of our networks, applications, traffice, etc is important to identifying security issues.  James Jardine shares some thoughts on the need for these baselines and why they are …

00:14:44  |   Thu 02 Apr 2015
Ep. 23: 3rd Party CMS Security Thoughts

Ep. 23: 3rd Party CMS Security Thoughts

CMS platforms are an easy way to get content to the internet, but we still have to consider security.   James talks about some of the concerns and things to think about when thinking about these secu…

00:21:35  |   Wed 11 Mar 2015
Ep. 22: Black lists vs. White Lists

Ep. 22: Black lists vs. White Lists

I came across an interesting tweet https://twitter.com/suffert/status/567486188383379456  depicting a good example of a black list that didn't quite cover everything I think they wanted too.    This …

00:16:35  |   Thu 19 Feb 2015
Ep. 21: Sensitive Data and Storage

Ep. 21: Sensitive Data and Storage

James talks about the need for developers, QA, business analysts and project managers to understand the type of application they are creating and the requirements around sensitive data. 

 

Reference Li…

00:19:59  |   Wed 04 Feb 2015
EP. 20: MoonPig Take-aways

EP. 20: MoonPig Take-aways

I discuss the lessons learned from the recent Moonpig security disclosure.  This is full of information for a developer or QA tester.   For more information, visit https://www.developsec.com

Send us a…

00:23:11  |   Fri 09 Jan 2015
Ep. 19: Target Environments

Ep. 19: Target Environments

Are you looking to test our your security skills?  There are lots of targets that are freely available to you that can be quite helpful.  The good news is you won't be getting in trouble for hacking …

00:20:22  |   Sun 30 Nov 2014
Ep. 18: Planning for an Assessment

Ep. 18: Planning for an Assessment

No matter what size company you are, sooner or later you will be subject to some form of security assessment.  Whether that is a penetration test, architecture review, code review or some other asses…

00:18:56  |   Sun 12 Oct 2014
Ep. 17: Authorization

Ep. 17: Authorization

Are you sure you are performing proper authorization checks everyplace?  What does Authorization even mean?  James Jardine talks about Authorization and how QA, Dev and others can reinforce its imple…

00:19:40  |   Fri 03 Oct 2014
Ep. 16: The Cloud:  Is it Safe?

Ep. 16: The Cloud: Is it Safe?

In this episode, James Jardine talks about the recent breaches regarding cloud services and whether or not we should be running for the hills.  Lets focus on the real issue, not the hype of nude phot…

00:20:03  |   Fri 05 Sep 2014
Ep. 15: Security Testing - QA can do this!!

Ep. 15: Security Testing - QA can do this!!

In this episode, James talks about security testing... scratch that, testing.  There really is no difference between security testing and regular testing.  The app is functioning in a way it was not …

00:23:36  |   Fri 22 Aug 2014
Ep. 14: Input Validation and Output Encoding

Ep. 14: Input Validation and Output Encoding

The debate is out there, which is more important.  I discuss what they are and how they both play a key role in securing an application.

Send us a text

For more info go to https://www.developsec.com or…

00:13:22  |   Sun 27 Jul 2014
Ep. 13: Introduction to Cross Site Scripting

Ep. 13: Introduction to Cross Site Scripting

This episode gives a high level overview of what XSS is and why it is of concern.  Future episodes will dig deeper into the vulnerability.

Send us a text

For more info go to https://www.developsec.com

00:14:57  |   Fri 27 Jun 2014
DS: Ep 12: Ebay hacked.  All about Cookies

DS: Ep 12: Ebay hacked. All about Cookies

We discuss a little about eBay and their unfortunate hack, how sourceforge has upgraded their password storage and a lot about cookies.   What are cookies, how are they used, how do we secure them.  …

00:19:56  |   Tue 27 May 2014
Ep. 11: Not your Grandpa's Phishing

Ep. 11: Not your Grandpa's Phishing

In this episode, we talk about phishing.  Mass email and spear phishing.  What you should know about the topic and how to protect yourself.

Send us a text

For more info go to https://www.developsec.com

00:14:57  |   Fri 09 May 2014
Ep. 10: Threat Modeling

Ep. 10: Threat Modeling

This episode introduces the new Microsoft Threat Modeling Tool 2014.  No more requirement for Visio..  woohoo.   Lots of talk about threat modeling and its benefits.

 

Threat Modeling Tool 2014: http:/…

00:14:58  |   Fri 25 Apr 2014
Ep. 9: Windows XP and HeartBleed

Ep. 9: Windows XP and HeartBleed

In this episode we take a look at the two hottest topics.. Windows XP End of Life and Heartbleed.  If you haven't heard of either of these, your under a rock (and you should listen).   This is not an…

00:12:05  |   Fri 11 Apr 2014
Disclaimer: The podcast and artwork embedded on this page are the property of Jardine Software Inc.. This content is not affiliated with or endorsed by eachpod.com.