Security Weekly Podcast Network (Video)

Discovering a common Salesforce mistake launched this security professional's career - Aaron Costello - ESW #379


Listen Later

Aaron was already a skilled bug hunter and working at HackerOne as a triage analyst at the time. What he discovered can't even be described as a software bug or a vulnerability. This type of finding has probably resulted in more security incidents and breaches than any other category: the unintentional misconfiguration.

There's a lot of conversation right now about the grey space around 'shared responsibility'. In our news segment later, we'll also be discussing the difference between secure design and secure defaults. The recent incidents revolving around Snowflake customers getting compromised via credential stuffing attacks is a great example of this. Open AWS S3 buckets are probably the best known example of this problem. At what point is the service provider responsible for customer mistakes? When 80% of customers are making expensive, critical mistakes? Doesn't the service provider have a responsibility to protect its customers (even if it's from themselves)?

These are the kinds of issues that led to Aaron getting his current job as Chief of SaaS Security Research at AppOmni, and also led to him recently finding another common misconfiguration - this time in ServiceNow's products. Finally, we'll discuss the value of a good bug report, and how it can be a killer addition to your resume if you're interested in this kind of work!

Segment Resources:

  • Aaron's blog about the ServiceNow data exposure.
  • The ServiceNow blog, thanking AppOmni for its support in uncovering the issue.

Show Notes: https://securityweekly.com/esw-379

...more
View all episodesView all episodes
Download on the App Store

Security Weekly Podcast Network (Video)By Security Weekly

  • 4.7
  • 4.7
  • 4.7
  • 4.7
  • 4.7

4.7

35 ratings


More shows like Security Weekly Podcast Network (Video)

View all
Security Now (Audio) by TWiT

Security Now (Audio)

1,962 Listeners

MacBreak Weekly (Audio) by TWiT

MacBreak Weekly (Audio)

2,014 Listeners

Risky Business by Patrick Gray

Risky Business

363 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

633 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

372 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,006 Listeners

Smashing Security by Graham Cluley & Carole Theriault

Smashing Security

313 Listeners

Click Here by Recorded Future News

Click Here

388 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

7,787 Listeners

Techmeme Ride Home by Ride Home Media

Techmeme Ride Home

945 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

141 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

187 Listeners

Practical AI by Practical AI LLC

Practical AI

193 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

120 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

33 Listeners