Absolute AppSec

Absolute AppSec

By Ken Johnson and Seth LawTechnologyTech News
Download on the App Store

Absolute AppSec episodes

  • Episode 166 - Web App Firewalls, ProtestWare, CSP Level 3
    As sands through the hourglass, another episode is falls on a Tuesday in late March. It was not _the_ first episode, but it was an episode as Ken and Seth talk about the origins of web application firewalls (WAFs) to go along with an article describing current WAF usage patterns. A heated discussion on recent software supply issues related to ProtestWare (or the changing of open source packages to highlight maintainer-focused causes). Finally, a quick look into Content Security Policy (CSP) Level 3 and upcoming browser support for the protocol.
    59 min
  • Episode 165 - Portswigger 2021 Top 10, Supply Chain Attacks, TLS Certs
    Welcome to the latest nihilism and bitch session. In this episode, Seth and Ken review Portswigger's Top 10 list of the "most significant web security research released in the last year". Discussion of weak links in the NPM supply chain and what developers can look at to ascertain the security of packages they depend on. Finally, Russia has begun issuing its own TLS certificates, which always leads to better privacy and security for the general public..../s
    1 hr 10 min
  • Episode 164 - Supply Chain Security, Cyber Attacks, 2FA, AutoWarp
    What now? Another episode? You have to be kidding me. Now I get to write another summary per my job description. At least this episode covers some security topics like as Software Supply Chain Security using socket.dev and protecting yourself with security basics as a package maintainer. And the discussion of recent cyber attacks against Toyota hardware suppliers and AutoWarp vulnerability for Azure was at least interesting. Listen, or don't, I'm just required to write the description.
    57 min
  • Episode 163 - IT Army, Secrets, Access Control
    And we are live, with our 163 episode of Absolute AppSec. Say hi to Ken and Seth once again as they start out with a discussion on the IT Cyber Army and issues with enlisting to help in cyber attacks. Next up is a series of opinions on the security of environment variables and inclusion of secrets within application architectures and the cloud. Finally, a discussion on authorization and access control based on viewer demand. Yes, it's hard, yes, you should do it.
    1 hr 6 min
  • Episode 162 - Mike McCabe (@mccabe615) - Cloud Security
    After a week's hiatus, the Absolute AppSec-ers return with guest Mike McCabe (@mccabe615) to talk about all things Cloud Security. Discussions on cloud security tools, various differences between AWS and Azure, infrastructure as code (IaC), and predictions on cloudsec merging with appsec in the future.
    1 hr 7 min
  • Episode 160 - Mental Health, Open Source Bug Bounties, IDOR
    The duplicitous duo returns with another episode that starts out in left field away from security topics by addressing mental health and how to keep sane when life gets busy, in both good and bad ways. Security does eventually become a topic in a discussion around bug bounties in the news as the European Government announces bug bounties for multiple open source projects. Finally, a discussion on the existence of IDOR _everywhere_ and how to identify it in more complex scenarios.
    1 hr 6 min
  • Episode 159 - Neil Matatall - CSP, Infosec Hiring, Languages + Framework Security
    Ken and Seth are back to talk with a blast from the past. Neil Matatall (@ndm) of Twitter, Github, and now TikTok fame joins the discussion (again) to talk about CSP. The conversation wanders from there to hiring people in information security and tech jobs. Opinions on language and framework security defaults and why Ruby cannot be beat, errr, or is so good. Finally getting back to CSP and misunderstandings on what it provides to developers.
    0 min
  • Episode 158 - More Supply Chains, 2021 Top Ten, CORS + CSRF
    Yet another episode. Always something to discuss. Ken and Seth talk about a recent article covering *theoretical* software supply chain exploits and how this will be a big thing this year. A review of Portswigger's nominations for Top Ten Web Hacking techniques of 2021. Finally, a discussion on the upcoming Chrome changes to do pre-flight requests for non-routable IP address CSRF requests.
    59 min
  • Episode 157 - 2022 Predictions, Schema Libraries, NPM and Open Source Packages
    NEW YEAR, NEW SECURITY MADNESS! The duo is back with their application security predictions for 2022. A discussion on 3rd party library differences, in particular how URL/URI Schema libraries and parsing can lead to security flaws. Finally, a discussion on recent NPM news where a developer pushed package versions that undermine the trust developers and corporations have with open source maintainers.
    0 min

About Absolute AppSec

From the publisher's feed

A weekly podcast of all things application security related. Hosted by Ken Johnson and Seth Law.

More shows like Absolute AppSec

Stuff You Should Know by iHeartPodcasts

Stuff You Should Know

78,422 Listeners

Planet Money by NPR

Planet Money

30,701 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,054 Listeners

Application Security Weekly (Audio) by Mike Shema

Application Security Weekly (Audio)

13 Listeners