
Sign up to save your podcasts
Or


Static analysis is the process of evaluating code for errors, memory leaks, and security vulnerabilities. The “static” part refers to the fact that the code is not running. This differentiates it from unit tests and integration tests, which evaluate the runtime characteristics of code.
If you use an IDE or a linter, you are using a basic form of static analysis all the time. More sophisticated static analysis tools can be used to analyze code in sensitive domains like healthcare or automobiles.
During static analysis, we can discover problems in the code by evaluating the structure of a program. Buffer overruns can be identified before they turn into a vulnerability like Heartbleed. Null pointer exceptions can be fixed before they cause a segmentation fault. Concurrency issues can be serialized before they result in a problematic race condition.
Today’s guest Paul Anderson is the VP of engineering at GrammaTech, where he works on CodeSonar, a static analysis tool. We discussed how static analysis works, why it is useful, and how it fits into a modern software delivery pipeline. Full disclosure: GrammaTech is a sponsor of Software Engineering Daily.
The post Static Analysis with Paul Anderson appeared first on Software Engineering Daily.
Online advertising enables free content and services of the Internet. One of the free services that is powered by advertising is the browser. 60% of web browsing is done through Chrome, which is owned by Google, which is powered by advertising.
The application that most of us use to explore the web is made by a company that relies on ads, so it is unsurprising that the default of that browser is to allow close tracking of user behavior. When you hit a website, a variety of trackers are logging your data for the purpose of serving you better ads.
Some people don’t like ads, and they don’t like being tracked–but what is the alternative? How else can we get all the content we want? Since the 90’s, engineers have envisioned an Internet powered by micropayments. A micropayments system in your browser would allow users to pay for content with money instead of adtech.
Brave is a web browser built with a modern view of advertising, privacy, and economics. Brave users can pay for content with their money OR by paying attention to ads. This system is formalized through the Basic Attention Token (BAT), a cryptocurrency that can be used to purchase user attention.
Jonathan Sampson is a senior developer relations specialist with Brave Software. He joins the show to talk about the problems with the browsing experience and what Brave is doing to stop it.
If you like this episode, we have done many other shows about privacy, with guests like Bruce Schneier and Samy Kamkar. Download the Software Engineering Daily app for iOS to hear all of our old episodes, and easily discover new topics that might interest you. You can upvote the episodes you like and get recommendations based on your listening history. With 600 episodes, it is hard to find the episodes that appeal to you, and we hope the app helps with that.
The post Brave Browser with Jonathan Sampson appeared first on Software Engineering Daily.
When a cyber attack occurs, how do we identify who committed it? There is no straightforward answer to that question.
Even if we know Chinese hackers have infiltrated our power grid with logic bombs, we might not be able to say with certainty whether those hackers were state actors or rogue Chinese hackers looking for an offensive asset to sell to their government.
Even if we know someone in Russia launched an attack on the banking system in Ukraine, we might not know whether that attack came from the government or from aggressive non-governmental forces.
Accurate cyberattack attribution is key to preventing diplomatic mistakes in the modern battleground of the Internet.
Today’s guest John Davis is one of the authors of the report called “Stateless Attribution: Toward International Accountability in Cyberspace”.
John is a senior information scientist with RAND Corporation, a non-profit institution that helps improve policy and decisionmaking through research and analysis. This report was commissioned by Microsoft, and it provides a deep assessment of our current ability to attribute a cyberattack to the perpetrator of that attack.
If you like this episode, we have done many other shows about security, with guests like Bruce Schneier and Samy Kamkar. You can check out our back catalog by downloading the Software Engineering Daily app for iOS, where you can listen to all of our old episodes, and easily discover new topics that might interest you. You can upvote the episodes you like and get recommendations based on your listening history. With 600 episodes, it is hard to find the episodes that appeal to you, and we hope the app helps with that.
The post Attack Attribution with John Davis appeared first on Software Engineering Daily.
Ransomware and DDoS attacks happen all the time. Sometimes they affect large swaths of users. WannaCry ransomware froze the computer systems in hospitals. Mirai botnet DDoS attacks took down a DNS provider, making Netflix and Twitter inaccessible for a short period of time.
These are innocent attacks compared to what we could face from a world where cars, heart rate monitors, and other safety critical machinery become connected to the Internet. This is not a new subject–we have covered it in previous episodes about security. But it’s a deep subject, and there is much ground to cover.
Chris Craig joins the show for this episode–he is a security researcher at Oak Ridge National Lab. He studies network and cloud security, and in this episode he brings his broad expertise to subjects like IoT security, car security, and the question of standards–what do we need to standardize and certify as the internet becomes connected to physical infrastructure?
Thanks to Jared Smith for the introduction.
When Safety and Security Become One
Standardisation and Certification of the ‘Internet of Things’
The post Car and IoT Security with Chris Craig appeared first on Software Engineering Daily.
Quality assurance testing is a form of testing that closely mirrors user behavior. Sometimes it is manual, sometimes it is automated. Automated QA tests are scripts that validate correct data representation as the application mechanically runs through high-level workflows–like a login page. Manual QA testers act out use cases of an application to see if there are any bugs that were missed during automated test cases. Manual QA testing is often necessary for complex applications where it is not possible to enumerate all potential workflows within a script.
Different companies have radically different workflows for QA testing. There are a variety of ticketing systems, testing frameworks, and team chat applications that play a role in a tester’s daily life. QASymphony is a platform for testing tools that integrates with other popular technologies to centralize a QA testing workflow.
Jonathan Alexander is the CTO at QASymphony. He’s also the author of Codermetrics: Analytics for Improving Software Teams. He joins the show to discuss the past and present of QA and his strategies for managing the team that is building QASymphony. Thanks to Kevin Wolf for the intro.
The post QA Testing with Jonathan Alexander appeared first on Software Engineering Daily.
Shopify is a company that helps customers build custom online storefronts. Shopify has built upon the same Ruby on Rails application since the founding of their business 12 years ago starting with Rails 0.5 and moving all the way to Rails 5.
MRuby is a lightweight implementation of the Ruby language. Shopify made the decision to use mruby to allow customers to create custom scripts that are run every time a customer adds items to their cart. However, since mruby was a language implementation that was not widely used, Shopify opted to post a Bug Bounty to the HackerOne bug bounty platform to find security vulnerabilities in their use of mruby. What followed was a payout of over $500,000 as report after report flooded in of security vulnerabilities inside mruby itself. There was so many reports that Shopify made the decision to sandbox the mruby execution into separate processes and decreased the bounty awards by 90%.
In this episode, Jeremy Jung interviews Daniel Bovensiepen (BOH-ven-see-pen) about mruby and the Shopify bug bounty.
Mruby: http://mruby.org/
The $500,000 release: http://mruby.sh/201703270126.html
HackerOne bounty page: https://hackerone.com/shopify-scripts
American Fuzzy Lop: http://lcamtuf.coredump.cx/afl/
The post MRuby and Language Security with Daniel Bovensiepen appeared first on Software Engineering Daily.
At Coinbase, security is more important than anything else. Coinbase is a company that allows for storage and exchange of cryptocurrencies. Protecting banking infrastructure is difficult, but in some ways the stakes are higher with Coinbase, because bitcoin is fundamentally unregulated.
If a hacker were able to syphon all of the money out of Coinbase accounts, Coinbase would have no recourse–which means this is a more sensitive problem than the regulated banking system, where transactions can often be reversed.
Philip Martin is the director of security at Coinbase. He joins the show today to explain why his love of complex and high-stakes security challenges brought him to Coinbase. Philip has some specific points about Coinbase and some more abstract points about security that were very useful to me.
This is the third and final episode in our series about Coinbase. Our first two episodes covered the currencies of Coinbase and the fraud prevention techniques the company uses. We’d love to hear your thoughts on this series, and any other suggestions or feedback you have. Send me an email–[email protected]
The post Coinbase Security with Philip Martin appeared first on Software Engineering Daily.
A cryptocurrency exchange faces a uniquely difficult fraud problem. A hacker who steals my credentials can initiate a transfer of all my bitcoin to another wallet, and it is a non-reversible, non-identifiable payment. So it is really important to prevent those kinds of fraudulent transactions.
At the third Software Engineering Daily Meetup, Coinbase director of data science Soups Ranjan explained how Coinbase stays ahead of fraudsters, and he describes some of the cutting-edge social engineering attacks that are being used to try to steal cryptocurrency–including cell phone takeover attacks.
Next week, we will be airing three shows I did on-site at Coinbase–interviews with engineers from three different teams. Check out those shows for a deep dive into cryptocurrency uses, fraud, and infrastructure. Coinbase is an exciting company, and it was a lot of fun getting a panorama for how several parts of the organization function.
The next Meetup will be in New York. We don’t know when it will be yet, but sign up to follow us at softwareengineeringdaily.com/meetup.
The post Fighting Fraud at Coinbase with Soups Ranjan appeared first on Software Engineering Daily.
From the publisher's feed