Security Journey's hi/5

How Yahoo Built a Culture of Cybersecurity, minimaxir/big-list-of-naughty-strings, Issue #4409, OWASP A08:2021, Apache Servers


Listen Later

  • How Yahoo Built a Culture of Cybersecurity- https://hbr.org/2021/09/how-yahoo-built-a-culture-of-cybersecurity

Commentary: Security culture continues to grow as a non-negotiable piece of a security strategy.

  • ​ minimaxir/big-list-of-naughty-strings​ – https://github.com/minimaxir/big-list-of-naughty-strings

Commentary: Safe list input validation is always our go to, but the big list of naughty strings is a nice input for testing!

  • Have Trusted Types API built directly into the jQuery Core Files · Issue #4409 jquery/jquer-  https://github.com/jquery/jquery/issues/4409

Commentary: jQuery is still widely in use across the web, and adopting trusted types is a strong security step forward.​

  • Making sense of OWASP A08:2021 – Software & Data Integrity Failures​- Encryption is easy, key management is hard - https://www.securityjourney.com/post/making-sense-of-owasp-a08-2021-software-data-integrity-failures

Commentary: Software and data integrity failures are the root cause of many supply chain debacles in the past few y

  •  Apache Servers Actively Exploited in the Wild, and the Importance of Prompt Patching - https://blog.sonatype.com/apache-servers-actively-exploited-in-wild-importance-of-prompt-patching

Commentary: We often think of patching as a security problem that has been solved – patching is always challenging!​


...more
View all episodesView all episodes
Download on the App Store

Security Journey's hi/5By Security Journey