Security Weekly Podcast Network (Video)

Discovering a common Salesforce mistake launched this security professional's career - Aaron Costello - ESW #379


Listen Later

Aaron was already a skilled bug hunter and working at HackerOne as a triage analyst at the time. What he discovered can't even be described as a software bug or a vulnerability. This type of finding has probably resulted in more security incidents and breaches than any other category: the unintentional misconfiguration.

There's a lot of conversation right now about the grey space around 'shared responsibility'. In our news segment later, we'll also be discussing the difference between secure design and secure defaults. The recent incidents revolving around Snowflake customers getting compromised via credential stuffing attacks is a great example of this. Open AWS S3 buckets are probably the best known example of this problem. At what point is the service provider responsible for customer mistakes? When 80% of customers are making expensive, critical mistakes? Doesn't the service provider have a responsibility to protect its customers (even if it's from themselves)?

These are the kinds of issues that led to Aaron getting his current job as Chief of SaaS Security Research at AppOmni, and also led to him recently finding another common misconfiguration - this time in ServiceNow's products. Finally, we'll discuss the value of a good bug report, and how it can be a killer addition to your resume if you're interested in this kind of work!

Segment Resources:

  • Aaron's blog about the ServiceNow data exposure.
  • The ServiceNow blog, thanking AppOmni for its support in uncovering the issue.

Show Notes: https://securityweekly.com/esw-379

...more
View all episodesView all episodes
Download on the App Store

Security Weekly Podcast Network (Video)By Security Weekly Productions

  • 4.7
  • 4.7
  • 4.7
  • 4.7
  • 4.7

4.7

35 ratings


More shows like Security Weekly Podcast Network (Video)

View all
Security Now (Audio) by TWiT

Security Now (Audio)

2,004 Listeners

RunAs Radio by Richard Campbell

RunAs Radio

83 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

Network Break by Packet Pushers

Network Break

101 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,021 Listeners

Security Weekly News (Audio) by Security Weekly Productions

Security Weekly News (Audio)

33 Listeners

The Matt Walsh Show by The Daily Wire

The Matt Walsh Show

28,441 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

188 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

139 Listeners

Morning Wire by The Daily Wire

Morning Wire

26,636 Listeners