DevelopSec: Developing Security Awareness

DevelopSec: Developing Security Awareness

By Jardine Software Inc.NewsTechnologyEducationTech News
Download on the App Store

DevelopSec: Developing Security Awareness episodes

  • Ep. 119: Risks of SpellCheck

    In this episode we talk about the spell check feature of the browser and how it could present a risk to sensitive data.

      

     Link to article referenced:  https://www.darkreading.com/application-security/spellchecking-google-chrome-microsoft-edge-browsers-leaks-passwords

      

      

     For more info go to https://www.developsec.com or follow us on twitter (@developsec).

      

     DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.

    Send us Fan Mail

    For more info go to https://www.developsec.com or follow us on X (@developsec).

    The DevelopSec podcast is brought to you by Jardine Software Inc. 

    13 min
  • Ep. 118: Log4J Sparking Thought on Vulnerable Components

    Log4J has been the talk of the town recently and everyone is focused on the technical details of the specific vulnerabilities found. In this episode, James talks about the overarching ideas around dealing with vulnerable components. Are you vulnerable? If so, what needs to be done?

    For more info go to https://www.developsec.com or follow us on twitter (@developsec).

    Join the conversations.. join our slack channel. Email [email protected] for an invitation.

     DevelopSec provides application security training to add value to your application security program. Contact us today to see how we can help.

    Send us Fan Mail

    For more info go to https://www.developsec.com or follow us on X (@developsec).

    The DevelopSec podcast is brought to you by Jardine Software Inc. 

    25 min
  • Ep. 117: How Browsers are Helping with Security

    Chrome has announced a few changes that we need to watch out for in the near future. We previously talked about the default value for samesite that is coming up fast. I wrote about this here:  https://www.jardinesoftware.net/2019/10/28/samesite-by-default-in-2020/

    Also, they are getting ready to start blocking mixed content downloads:

     https://blog.chromium.org/2020/02/protecting-users-from-insecure.html

     

    For more info go to https://www.developsec.com or follow us on twitter (@developsec).

    Join the conversations.. join our slack channel. Email [email protected] for an invitation.

     DevelopSec provides application security training to add value to your application security program. Contact us today to see how we can help.

    Send us Fan Mail

    For more info go to https://www.developsec.com or follow us on X (@developsec).

    The DevelopSec podcast is brought to you by Jardine Software Inc. 

    14 min
  • Ep. 116: Chrome Retires XSS Auditor

    It was recently announced that Chrome was dropping the XSS Auditor in Chrome 78. What does that mean and how does that change things for you as a developer?  

    https://www.chromium.org/developers/design-documents/xss-auditor

    For more info go to https://www.developsec.com or follow us on twitter (@developsec).

    Join the conversations.. join our slack channel. Email [email protected] for an invitation.

     DevelopSec provides application security training to add value to your application security program. Contact us today to see how we can help.

    Send us Fan Mail

    For more info go to https://www.developsec.com or follow us on X (@developsec).

    The DevelopSec podcast is brought to you by Jardine Software Inc. 

    15 min
  • Ep. 115: Is CSRF Really Dead?

    In 2020, Chrome will default the SameSite attribute to Lax on all cookies. SameSite helps mitigate CSRF, but does that mean CSRF is Dead?

    For more info go to https://www.developsec.com or follow us on twitter (@developsec).

    Join the conversations.. join our slack channel. Email [email protected] for an invitation.

     DevelopSec provides application security training to add value to your application security program. Contact us today to see how we can help.

    Send us Fan Mail

    For more info go to https://www.developsec.com or follow us on X (@developsec).

    The DevelopSec podcast is brought to you by Jardine Software Inc. 

    16 min
  • Ep. 114: Investing in People for Better Application Security

    In this episode, James talks about investing in the development teams to increase application security priorities.

    For more info go to https://www.developsec.com or follow us on twitter (@developsec).

    Join the conversations.. join our slack channel. Email [email protected] for an invitation.

     DevelopSec provides application security training to add value to your application security program. Contact us today to see how we can help.

    Send us Fan Mail

    For more info go to https://www.developsec.com or follow us on X (@developsec).

    The DevelopSec podcast is brought to you by Jardine Software Inc. 

    25 min
  • Ep. 113: What is your mother's maiden name?

    In this episode, James talks about some of the risks and recommendations around security questions and their implementation. 

    For more info go to https://www.developsec.com or follow us on twitter (@developsec).

    Join the conversations.. join our slack channel. Email [email protected] for an invitation.

     DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.

    Send us Fan Mail

    For more info go to https://www.developsec.com or follow us on X (@developsec).

    The DevelopSec podcast is brought to you by Jardine Software Inc. 

    21 min
  • Ep. 112: Application Fingerprinting

    Does your application give away details about it server, framework, or other components?  How is this information used by an attacker? Check out this episode to learn more.

    For more info go to https://www.developsec.com or follow us on twitter (@developsec).

    Join the conversations.. join our slack channel. Email [email protected] for an invitation.

     DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.

    Send us Fan Mail

    For more info go to https://www.developsec.com or follow us on X (@developsec).

    The DevelopSec podcast is brought to you by Jardine Software Inc. 

    22 min
  • Ep. 111: Authentication Alerts

    Would you know if someone authenticated to your account? With the breaches we see in the news, and attacks like credential stuffing, there must be a way to be alerted to account access. James talks about authentication alerts, what they are, and why you may want to use them.

    For more info go to https://www.developsec.com or follow us on twitter (@developsec).

    Join the conversations.. join our slack channel. Email [email protected] for an invitation.

     DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.

    Send us Fan Mail

    For more info go to https://www.developsec.com or follow us on X (@developsec).

    The DevelopSec podcast is brought to you by Jardine Software Inc. 

    17 min
  • Ep. 110: Implementation Matters

    James discusses how implementation matters with security controls and how it changes priorities. This came about after reading the following story: 

     https://www.theverge.com/2018/12/31/18162541/vein-authentication-wax-hand-hack-starbug

    For more info go to https://www.developsec.com or follow us on twitter (@developsec).

    Join the conversations.. join our slack channel. Email [email protected] for an invitation.

     

    DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.

    Send us Fan Mail

    For more info go to https://www.developsec.com or follow us on X (@developsec).

    The DevelopSec podcast is brought to you by Jardine Software Inc. 

    20 min

About DevelopSec: Developing Security Awareness

From the publisher's feed

Curious about application security? Want to learn how to detect security vulnerabilities and protect your application. We discuss different topics and provide valuable insights into the world of…