
Sign up to save your podcasts
Or


Ever read a security advisory that told you to “use a VPN” to protect a Bluetooth device?
In this episode we talk about how bad or inaccurate recommendations can be a problem with security findings. We take a look at an example of recommendations that don't relate to the issue at all, leaving people confused at how to respond.
Share with us your experience with recommendations that just missed the mark.
References:
CISA Wheelchair Article - https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-364-01
Skateboard Article - https://gizmodo.com/faceplant-exploit-lets-hackers-hijack-an-electric-ska-1722691650
Bicycle Shifter Article - https://www.bicycling.com/racing/a61994540/hackers-target-electronic-shifters/
Send us Fan Mail
For more info go to https://www.developsec.com or follow us on X (@developsec).
The DevelopSec podcast is brought to you by Jardine Software Inc.
In this episode James gives an overview of the new OWASP Top 10 2025. He shares some insights into the history, changes, and additional thoughts on the top 10.
Do you have any thoughts on the OWASP Top 10? Let us know.
References:
Medium article of history of top 10 - https://medium.com/@dramkumar/history-of-all-owasp-top-10-over-the-years-9470c0adf43d
OWASP Top 10 2025 - https://owasp.org/Top10/2025/
Top 10 -> CWE Breakdown - https://drive.google.com/file/d/1SmzWyg_ar1PaMFT0FxYelEAJuGMA690B/view?usp=sharing
Send us Fan Mail
For more info go to https://www.developsec.com or follow us on X (@developsec).
The DevelopSec podcast is brought to you by Jardine Software Inc.
In this episode, James talks about the difference between end-to-end encryption and the standard encryption in transit most web applications implement. There is an interesting story (referenced below) that was using end-to-end encryption outside of the standard understanding.
Check out what the differences are and what you can do to make sure you are thinking about how terms are used.
References:
Link to Article: https://www.esecurityplanet.com/threats/kohlers-smart-toilet-camera-isnt-actually-end-to-end-encrypted/
Send us Fan Mail
For more info go to https://www.developsec.com or follow us on X (@developsec).
The DevelopSec podcast is brought to you by Jardine Software Inc.
Have you ever felt that feeling of thinking your account has been compromised?
It can be a scary feeling. But what about when it didn't really happen? Instead it was just confusing messaging.
That is what I talk about in this episode. The importance of proper messaging in the right context. Even the smallest thing can turn out to be a larger issue.
References:
Link to Article: https://www.bleepingcomputer.com/news/security/coinbase-to-fix-2fa-account-activity-entry-freaking-out-users/
Send us Fan Mail
For more info go to https://www.developsec.com or follow us on X (@developsec).
The DevelopSec podcast is brought to you by Jardine Software Inc.
In this episode, James shares a story about fixing a flat tire on an E-Scooter and how it relates to security. He shows how the combination of tools, process, and knowledge can lead to a successful outcome.
Can you be successful without all three components? Maybe, but it might be more effort that is needed. Tune in to learn how these 3 components work together to create efficient solutions.
Send us Fan Mail
For more info go to https://www.developsec.com or follow us on X (@developsec).
The DevelopSec podcast is brought to you by Jardine Software Inc.
In this episode, I go over what Double-ClickJacking is and what you can potentially do about it to reduce the risk to your applications.
Will this be the new finding on everyone's pen tests this year?
Paulos Yibelo first described Double-ClickJacking and you can read more from him at his post referenced below.
References:
Paulos Yibelo Blog: https://www.paulosyibelo.com/2024/12/doubleclickjacking-what.html
Send us Fan Mail
For more info go to https://www.developsec.com or follow us on X (@developsec).
The DevelopSec podcast is brought to you by Jardine Software Inc.
In this episode, I talk about how security is a part of everyone's role and the labeling of "Security Culture". I share some ideas on how to improve on role based security awareness and building stronger relationships between security and the rest of the organization.
For more info go to https://www.developsec.com or follow us on X (@developsec).
Send us Fan Mail
For more info go to https://www.developsec.com or follow us on X (@developsec).
The DevelopSec podcast is brought to you by Jardine Software Inc.
In this episode I talk about assigning responsibility for secure development and how the dev and security teams should be working together to accomplish a common goal.
I also discuss the importance of updating developer job descriptions and creating an expectation around developers having secure development experience.
For more info go to https://www.developsec.com or follow us on X (@developsec).
Send us Fan Mail
For more info go to https://www.developsec.com or follow us on X (@developsec).
The DevelopSec podcast is brought to you by Jardine Software Inc.
In this episode I talk about the evolving world of ransomware. I discuss a few examples of unique tactics the malicious actors are using to put pressure on organizations to pay the ransom.
Referenced Articles:
https://www.theregister.com/AMP/2024/04/30/finnish_psychotherapy_center_crook_sentenced/
https://www.darkreading.com/cyber-risk/hackers-weaponize-sec-disclosure-rules-against-corporate-targets
https://www.theregister.com/2024/01/05/swatting_extorion_tactics/
For more info go to https://www.developsec.com or follow us on X (@developsec).
DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.
Send us Fan Mail
For more info go to https://www.developsec.com or follow us on X (@developsec).
The DevelopSec podcast is brought to you by Jardine Software Inc.
In this episode we talk about addressing the root cause of an issue versus the symptoms. How can the process of keeping application components updated be improved?
For more info go to https://www.developsec.com or follow us on twitter (@developsec).
DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.
Transcript:
In this episode, James talks about root cause analysis versus treating the symptoms.
Tackling the challenge to integrate security into the development process, looking for insights, answers and practical solutions to avoid getting overwhelmed. Welcome to the develop SEC podcast where our focus is your success in securing and improving development processes. And here's your host, James Jardine. Hey, everyone, welcome back to the show. Today, I want to talk about addressing the symptoms versus addressing the root problem. And I think in application security, or when we talk about secure development, this is something where a lot of times we address the symptoms, but we never really take the step back to address the actual root cause of what's causing those symptoms. And today, I want to actually talk about vulnerable third party components. This is something that has been kind of brought to the attention a lot more in the past few years, made it into the OWASP, top 10. And it's something I think everybody struggles with, we never know when we'll have a vulnerable third party component, because until somebody actually identifies a vulnerability, we just assume that we're good. And then on top of that, if there is a vulnerability identified, then we also run the chances that we're probably not even using that feature.
So vulnerable third party components are a really interesting aspect, when we think about secure development. Because there is a lot of unknowns, we may know that there's a vulnerability there. But the actual knowledge of do we use that piece and are we vulnerable, can be difficult, which, in the end, ends up adding a whole bunch of extra work and a whole lot of time for us to try to figure this out and address this stuff. And so this is where I talk about addressing the symptoms. In this case, in a lot of places, what we do is we address that symptom, we know that there's an issue of vulnerable third party components, right, that's the symptom, we have a vulnerable third party component. And so most places have some sort of process in place where we're going to identify these right, we're going to scan them all the time, whether using some of the common commercial tools, maybe you're using a free open source tool. But basically, the way it goes is I'm going to scan my repos or I'm going to scan my packages, and I'm going to look for all the dependencies, and then I'll look at their dependencies, and we'll see if there's any known vulnerable components within these right. And that requires having some sort of CVE out there that says, hey, somebody has found this, they've reported it, I remember requiring this to be a rep
Send us Fan Mail
For more info go to https://www.developsec.com or follow us on X (@developsec).
The DevelopSec podcast is brought to you by Jardine Software Inc.
From the publisher's feed
Curious about application security? Want to learn how to detect security vulnerabilities and protect your application. We discuss different topics and provide valuable insights into the world of…