Absolute AppSec

Absolute AppSec

By Ken Johnson and Seth LawTechnologyTech News
Download on the App Store

Absolute AppSec episodes

  • Episode 196 - API Reviews, Web App Security Features
    Seth and Ken dig into a topic that was raised by a member of our Slack community. The initial half of the show reviews both the risks and dynamic or static review items associated with microservices. This is followed by a discussion that starts by asking the question "what are the must-have security features for a web application?"
    1 hr 1 min
  • Episode 195 - 2022 CVEs, CORS, GraphQL
    Ken (@cktricky) and Seth (@sethlaw) take a step away from the news to review technical articles and research released in the last couple of weeks. This includes analysis done by Jerry Gamblin on total CVEs released during 2022, a new tool for exploiting weak CORS configurations, an excellent writeup on usage along with an intentionally-vulnerable GraphQL application, and finally some thoughts on prototype pollution style vulnerabilities in other interpreted languages (specifically python).
    1 hr
  • Episode 194 - Frank Wang (dbtlabs) - Organization Security, AI/ML
    Frank Wang from dbtlabs (@ffwang2 on twitter) joins Seth and Ken for a discussion on current security landscape, artificial intelligence, and machine learning. Follow Frank on twitter or through his blog at https://franklyspeaking.substack.com/. Discussion starts with current breaches and how organizations approach security through their first security hire. This is followed by a discussion on AI related to ChatGPT and how it will affect security in the future.
    59 min
  • Episode 193 - Security Metrics, End-User Security
    @cktricky and @sethlaw host another episode starting with a lengthy discussion on security metrics spurred by a recent post by Leif Drezler (@leifdreizler). Security metrics are highly specific and custom to the organization and target audience, as evidenced by the lively discussion between the hosts. This is followed by a discussion of improvements in end-user security based on recent Apple iOS releases that change encryption and protection mechanisms for various services.
    1 hr 4 min
  • Episode 192 - Blogs, GoLang Security, ChatGPT
    What do _you_ want for an AppSec Christmas! Another episode featuring Ken and Seth, for sure. The duo starts the conversation talking about useful AppSec and Security Blogs while featuring a recent GoLang Security post from Cole Cornford. Followed by an in-depth discussion on ChatGPT to welcome our new AI overlords. Finally, Seth and Ken both talk about what they wish to see this next year for AppSec-mas.
    1 hr 9 min
  • Episode 191 - DNS Attacks, Organizational Risk, Mastadon
    Going into the final month of 2022, the dynamic duo graces us with their presence. It begins with discussion of DNS Attacks based on Kaminsky-style attacks spurred by research presented at DeepSec by Timo Longen of Sec Consult. Followed by a conversation straight out of Slack about considerations involving organization and technical risks, specifically how to incorporate technical risk into organizational risk ratings. Finally, everyone is moving to Mastadon, but maybe they shouldn't be. Code is open source and there have been more than one flaw already identified in the service, although AppMap also shows how to use their tool to review Mastadon's source to sink interactions.
    56 min
  • Episode 190 - Immutable Laws of Security
    Ken and Seth break down the recently-released Immutable Laws of Security from Microsoft's Security Best Practices recommendations. Points of special interest being "Cybersecurity is a team sport", "Not keeping up is falling behind", and "Ruthless Prioritization is a survival skill".
    1 hr 8 min
  • Episode 189 - Security Bypasses, AppMap, Dastardly
    Seth and Ken kickoff another unique discussion by looking at a recent scholarly paper on security bypasses and workarounds by health care workers. Followed by a demo of AppMap, a development tool that shows code traces based on dynamic use. Finally, a discussion of Portswigger's new Dastardly CI/CD tool and where it fits in the security SDLC.
    1 hr 3 min
  • Episode 187 - Hacking your Health, Fortinet, Secrets in Source
    Back once again, Ken and Seth riff off of recent health discussions to talk about hacking health and maintaining a descent work/life balance. Discussion of recent Fortinet authorization issue and how to both search for and protect against flaws in COTS (commercial-off-the-shelf) products. To close out, a quick discussion on detecting custom secrets in source and using Github regexes to monitor for them.
    1 hr 4 min

About Absolute AppSec

From the publisher's feed

A weekly podcast of all things application security related. Hosted by Ken Johnson and Seth Law.

More shows like Absolute AppSec

Stuff You Should Know by iHeartPodcasts

Stuff You Should Know

78,422 Listeners

Planet Money by NPR

Planet Money

30,701 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,054 Listeners

Application Security Weekly (Audio) by Mike Shema

Application Security Weekly (Audio)

13 Listeners