Software Engineering Daily

Software Engineering Daily

By Software Engineering DailyNewsTechnologyTech News
Download on the App Store

Software Engineering Daily episodes

  • Fraud Prevention with Pete Hunt

    When Facebook acquired Instagram, one of the first systems Instagram plugged into was Facebook’s internal spam and fraud prevention system. Pete Hunt was the first Facebook engineer to join the Instagram team. When he joined, the big problems at Instagram were around fake accounts, harassment, and large volumes of spammy comments.

    After seeing the internal Facebook spam prevention tools clean up Instagram, Pete decided to start a company to build products that would allow this type of spam and fraud prevention as a service.

    Smyte provides protection against bad actors on the Internet. Complex marketplaces like Tilt, Meetup, and TaskRabbit plug into Smyte to filter their transactions for suspicious behavior. In this episode, we talk about how this type of behavior manifests, and the event-driven software architecture that the team at Smyte has built.

    The post Fraud Prevention with Pete Hunt appeared first on Software Engineering Daily.

    52 min
  • Ad Tracking with Larry Furr

    When you visit a web page, that web page can write data to a file on your computer, known as a cookie. Scripts on that page can also read from your cookie file to understand where you have been in the past. All of this data about you is getting shared between advertising companies like Google, Facebook, and AppNexus.

    Ghostery is a browser extension that allows you to limit what you share with these online tracking companies. Larry Furr develops products at Ghostery, and on this episode he takes us through the process of how we are tracked through the Internet.

    We also explore the topic of ad fraud, which is a theme we will continue to explore on SE Daily. If you have any information on ad fraud, or have recommendations for guests, please email me at [email protected]

    The post Ad Tracking with Larry Furr appeared first on Software Engineering Daily.

    51 min
  • Ad Fraud with Ben Trenda

    Advertising fraud takes billions of dollars out of the economy every year. We don’t know exactly how much money is being lost, because we don’t know what percentage of Internet users are bots. Are You A Human is a company designed to solve that exact problem and provide a service for verifying whether a user is real or automated.

    Ben Trenda is the CEO of Are You A Human. In this episode, we discuss some of the ways that bots pose as humans–clicking on ads, pretending to read ads, and defrauding marketers and publishers. We also talk about how Are You A Human combats this.

    This episode is part of a series of episodes about advertising fraud. If you know anything about the area, send me an email: [email protected]

    The post Ad Fraud with Ben Trenda appeared first on Software Engineering Daily.

    53 min
  • Container Security with Phil Estes

    Containers have become the unit of infrastructure that many technology stacks deploy to. With the shift to containers, the attack surface of an application has changed, and we need to reconsider our security models; the resource allocation of our containers, the interactions between different containers on a single machine, and the big picture–how the external web may interact with our containers.

    Phil Estes joins the show to discuss container security, as well as the OCI, container orchestration, as well as other container related topics.

    The post Container Security with Phil Estes appeared first on Software Engineering Daily.

    1 hr
  • Slack Security with Ryan Huber

    Security for the popular chat application Slack is a major focus for the company. A corporate Slack account is as valuable to a hacker as a corporate email account. In today’s episode, Ryan Huber and I talk through Slack’s approach to security–from philosophical discussions of how to company approaches security to the technical practices of logging and monitoring, and why Slack has a separate Amazon Web Services account just for the security team.

    Ryan works on security at Slack and has written a Medium post called Distributed Security Alerting, that I recommend checking out. If you haven’t heard it, you might also like the previous episode we did about Slack’s Architecture, with Keith Adams from Slack.

    The post Slack Security with Ryan Huber appeared first on Software Engineering Daily.

    53 min
  • Electronic Frontier Foundation with Nate Cardozo

    When the US government hacks its own citizens, The Electronic Frontier Foundation is often the best source of reporting to find out what laws the government has broken. When a change to the privacy policy of Google or Facebook is made, the Electronic Frontier Foundation is the best place to find out how that change in privacy exploits users. The Electronic Frontier Foundation provides legal defense and editorialism at the intersection of law and technology.

    Nate Cardozo joins the show today to discuss the mission of the EFF and his work at the organization. We have a wide ranging conversation, ranging from governments to corporations to Stuxnet to how the internal discussions at the EFF lead to the stances taken by the EFF.

    The post Electronic Frontier Foundation with Nate Cardozo appeared first on Software Engineering Daily.

    58 min
  • Data Breaches with Troy Hunt

    When you hear about massive data breaches like the recent ones from LinkedIn, MySpace, or Ashley Madison, how can you find out whether your own data was compromised?

     

    Troy Hunt created the website HaveIBeenPwned.com to answer this question. When a major data breach occurs, Troy acquires a copy of the stolen data and provides a safe way for individuals to check if their credentials have been stolen.

    Troy is an expert on data breaches, and he works as a regional director at Microsoft. Our conversation explores passwords, IoT security, Stuxnet, and the dark, bizarre world of data breaches.

    The post Data Breaches with Troy Hunt appeared first on Software Engineering Daily.

    57 min
  • Security and Machine Learning in the Call Center with Pindrop Security’s Chris Halaschek

    Call centers are a vulnerable point of attack for large enterprises. Fraud accounts for more than $20 billion in lost money every year, and a significant portion of that fraud is due to customer service representatives being fraudulent social engineering attacks.

     

    Chris Halaschek joins the show today to discuss how Pindrop Security is addressing this attack vector. Every phone call that gets made to a call center has a unique phoneprint, and the machine learning model at Pindrop Security uses these phoneprints to assign a risk score to each call. Chris also discusses the challenges associated with scaling a cloud security company.

    The post Security and Machine Learning in the Call Center with Pindrop Security’s Chris Halaschek appeared first on Software Engineering Daily.

    57 min
  • Secret Management and Vault with Hashicorp’s Seth Vargo

    Every software application has secrets. User passwords and database credentials must be managed carefully, because poor access controls can lead to disaster scenarios. Vault is a tool for secret management, developed at Hashicorp, a company that builds software tools for application delivery and infrastructure management.

    Seth Vargo is a software engineer and open source advocate at Hashicorp, and in today’s episode he discusses the advantages of having a single tool to manage all of your secrets. If you aren’t a security expert, don’t worry, we discuss some of the basics of security. And if you are a security expert, you will appreciate the comparisons we discuss between Hashicorp and other tools that have been used for secret management.

    • Vault Website
    • Shamir Secret Sharing
    • HashiConf US

    • The post Secret Management and Vault with Hashicorp’s Seth Vargo appeared first on Software Engineering Daily.

      48 min
    • Internet of Things and DevOps with Anders Wallgren

      “The three legs of the stool are culture, process, and tooling, and I think process and tooling are the easy ones.”

      The Internet of Things era is upon us, and with it the related concerns of security, privacy and reliability of the connected systems. This episode explores these issues and how companies can prevent these problems through better development processes and lifecycle management.

      Anders Wallgren is the CTO of Electric Cloud, which builds products to help companies optimize their software build, test, and deployment process.

      Questions
      • How far away are we realistically from IoT becoming truly mainstream?
      • What are the big security vectors that worry you?
      • Should each area of IoT applications have their own domain-specific principles?
      • What are the privacy concerns with in home internet connected devices?
      • What is your definition of agile in the context of IoT software development?
      • How did Honeywell for example change as a technology organization as they started going after connected thermostats?
      • Links
        • Electric Cloud
        • The Internet of Things and the Honda Recall
        • Anders on Twitter
        • Sponsors

          Hired.com is the job marketplace for software engineers. Go to hired.com/softwareengineeringdaily to get a $600 bonus upon landing a job through Hired.

          Digital Ocean is the simplest cloud hosting provider. Use promo code SEDAILY for $10 in free credit.

          The post Internet of Things and DevOps with Anders Wallgren appeared first on Software Engineering Daily.

          45 min

        About Software Engineering Daily

        From the publisher's feed

        Technical interviews about software topics.