Security Weekly Podcast Network (Video)

Discovering a common Salesforce mistake launched this security professional's career - Aaron Costello - ESW #379


Listen Later

Aaron was already a skilled bug hunter and working at HackerOne as a triage analyst at the time. What he discovered can't even be described as a software bug or a vulnerability. This type of finding has probably resulted in more security incidents and breaches than any other category: the unintentional misconfiguration.

There's a lot of conversation right now about the grey space around 'shared responsibility'. In our news segment later, we'll also be discussing the difference between secure design and secure defaults. The recent incidents revolving around Snowflake customers getting compromised via credential stuffing attacks is a great example of this. Open AWS S3 buckets are probably the best known example of this problem. At what point is the service provider responsible for customer mistakes? When 80% of customers are making expensive, critical mistakes? Doesn't the service provider have a responsibility to protect its customers (even if it's from themselves)?

These are the kinds of issues that led to Aaron getting his current job as Chief of SaaS Security Research at AppOmni, and also led to him recently finding another common misconfiguration - this time in ServiceNow's products. Finally, we'll discuss the value of a good bug report, and how it can be a killer addition to your resume if you're interested in this kind of work!

Segment Resources:

  • Aaron's blog about the ServiceNow data exposure.
  • The ServiceNow blog, thanking AppOmni for its support in uncovering the issue.

Show Notes: https://securityweekly.com/esw-379

...more
View all episodesView all episodes
Download on the App Store

Security Weekly Podcast Network (Video)By Security Weekly

  • 4.7
  • 4.7
  • 4.7
  • 4.7
  • 4.7

4.7

35 ratings


More shows like Security Weekly Podcast Network (Video)

View all
Security Now (Audio) by TWiT

Security Now (Audio)

1,986 Listeners

Security Weekly Podcast Network (Audio) by Security Weekly Productions

Security Weekly Podcast Network (Audio)

208 Listeners

Discovery by BBC World Service

Discovery

967 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

639 Listeners

The Joe Rogan Experience by Joe Rogan

The Joe Rogan Experience

225,811 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

369 Listeners

Exchanges by Goldman Sachs

Exchanges

980 Listeners

Hacked by Hacked

Hacked

180 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

7,962 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

174 Listeners

The Matt Walsh Show by The Daily Wire

The Matt Walsh Show

27,926 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

77 Listeners

All-In with Chamath, Jason, Sacks & Friedberg by All-In Podcast, LLC

All-In with Chamath, Jason, Sacks & Friedberg

9,248 Listeners

Morning Wire by The Daily Wire

Morning Wire

26,474 Listeners

The Tucker Carlson Show by Tucker Carlson Network

The Tucker Carlson Show

15,525 Listeners