In this weeks episode we are lucky to be joined by Scott Arciszewski to discuss all things Security.
We start off by chatting about a recent talk he gave at DEF CON 25 and the importance of secure API design.
From here we highlight Google Tink, misunderstandings of how PHP has changed over the years and what CVE’s are.
This leads us on to delve into the tools and processes used within the reconnaissance phase of a security engagement.
Finally, we briefly mention Quantum Computing and its impact on cryptography - followed by best practises for securely managing secrets within web applications.
Show Links
Paragon Initiative EnterprisesScott Arciszewski on TwitterNaCl - Networking and Cryptography librarygoogle/tinkPHP Implementation? - google/tink - GitHubPHP RFC - Flexible Heredoc and Nowdoc SyntaxesCommon Vulnerabilities and Exposures (CVE)Common Weakness EnumerationShodanNmap - the Network MapperBurp Suite ScannerPuppy Linuxklange/ponyos - My Little Unix, Kernels are Magic!Fiddler - Web Debugging ProxyCharles Web Debugging ProxyOWASP Zed Attack Proxy Project - OWASPHow and Why Developers Use Asymmetric (Public Key) Cryptography in Real-World ApplicationsSecrets, Secrets, Are No Fun - PHP RoundtableKeeping Credentials Secure in PHPSecuring Credentials for PHP with DockerVault by HashiCorpAWS Secrets Manager