Absolute AppSec

Absolute AppSec

By Ken Johnson and Seth LawTechnologyTech News
Download on the App Store

Absolute AppSec episodes

  • Episode 186 - Security Trainings, Web3 Bounties, MFA
    Ken is back in the land of the living, so of course he and Seth dig into the current state of information security training, how SCORM is the worst for developer training, and what goes into creating and teaching a course. Discussions on bug bounties in the web3/defi space and the nature of payouts. Finally, a discussion on MFA fatigue and how theoretical attacks have become reality.
    58 min
  • Episode 185 - Daniel Ting (hoodiepony) - Breaches, Optus, Uber
    Ken (cktricky) is out sick today, so Seth is joined by Daniel (https://twitter.com/hoodiepony) from Australia to talk about recent breaches. Specifically, the recent breach of Optus in Australia has led to the exposure of about 10 million identity records. Daniel and Seth reference the recent Optus and Uber breaches to discuss weaknesses in identity protection, access control, and data disclosure.
    1 hr 20 min
  • Episode 184 - Sources, Payloads, Patreon, Ethereum, Starbucks
    Ken is back to lead a discussion on identification of interesting sources for the podcast and specifically how XSS just is not as interesting to him and Seth as it was a decade ago. A new project for analyzing and bypassing 403 responses from proxies and WAFs. Opinions on Patreon's recent layoffs and hot takes around security issues. Finally, web3-related topics of the recently-complete Ethereum merge along with Starbucks NFTs.
    1 hr 4 min
  • Episode 183 - Information Warfare w/LegendaryPatMan
    Ken is away, so Loji comes to play. Absolute AppSec is hosted this week by Seth and Stefan (@lojikil) to go outside the normal topics of application security to address questions about information warfare, Ukraine, and propaganda with Stefan Edwards (@lojikil) and @LegendaryPatMan.
    1 hr 29 min
  • Episode 182 - Twitter, LastPass, Testing Edge Cases
    A late decision to record an episode this week after thinking it would be scratched due to life ended up with a long discussion on the recent Twitter drama and whistleblower revelations around their security problems. Both Seth and Ken express opinions about disclosures and building out security programs. Further discussion on password managers and LastPass breach. Finally, a bug bounty report shows the importance of testing edge cases and using a bounty program to supplement integration testing.
    53 min
  • Episode 181 - (Post DEFCON)
    Finally returned from the wasteland that is Las Vegas, or at least the fun that is #hackersummercamp and #defcon30, Ken and Seth break down their different experiences and impressions from the conference, including training. A discussion on in-app browsers for mobile applications and how they are bad and should feel bad. Finally, encoding of malicious strings in DNA, of all things.
    58 min
  • Episode 180 - Logging! Attacks!
    It's time for hacker summer camp, so the duo starts out discussing upcoming events and interesting talks. A discussion of LOGGING to warms Seth's heart as it comes to light that logging of sensitive data was the cause of a recently successful web3 wallet-draining attack. Further topics include deserialization of objects in multiple sensitive data disclosures. Discussion on importance of identity provides as well as the difference between application security and product security.
    55 min
  • Episode 179 - Starting in AppSec, Threat Modeling
    Ken pulls Seth back into an episode to talk through the steps anyone can take to get into Application or Product Security based on some recent articles. True security professionals can come from anywhere. This leads to a discussion on threat assessment and threat modeling across the industry.
    1 hr 1 min
  • Episode 178 - Wallet Attacks(!) and Data Privacy
    The duo is back and live, with an episode stolen from _some_ headlines. Specifically, a breakdown of various attacks against crypto wallets and how they stem from traditional security risks. Followed up by a discussion of data privacy disclosure, business ethics, and the tradeoffs associated with disclosing data as both a consumer and organization.
    1 hr 8 min
  • Episode 177 - That Post-LocoMocoSec Glow
    Seth and Ken recap some of their experiences from LocoMocoSec, followed by a discussion on the recent Bugcrowd revelation that an employee attempted to re-submit reports for gain. A review of LaLuka's 60 RCEs in 60 minutes. Finally, thoughts on the recent Chinese data leak.
    1 hr 7 min

About Absolute AppSec

From the publisher's feed

A weekly podcast of all things application security related. Hosted by Ken Johnson and Seth Law.

More shows like Absolute AppSec

Stuff You Should Know by iHeartPodcasts

Stuff You Should Know

78,422 Listeners

Planet Money by NPR

Planet Money

30,701 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,054 Listeners

Application Security Weekly (Audio) by Mike Shema

Application Security Weekly (Audio)

13 Listeners