Jonathan Carter – OWASP and Mobile Security
On the day before Black Hat 2014 kicked off, I was able to sit with Jonathan Carter to talk about his work and the projects he participates on in OWASP. The audio recording is a bit raw because the...
View ArticleSarah Baso – The Final OWASP Interview [AUDIO]
Sarah Baso is leaving OWASP at the end of the month. As executive director, she has been at the helm of the organization, helping to set up and run OWASP as a business. In our conversation we talk...
View ArticleWait! Wait! Don’t pwn me! from AppSec Europe 2014
It’s become a regular thing at AppSec: test the experts on their knowledge of current software security news events. This session was recorded at AppSec Europe 2014 with panelists Chris Eng, Matt...
View ArticleEoin Keary on Women in Security and Growing an OWASP Chapter
Eoin (pronounced Owen for you Yankees) Keary runs a software security practice in Ireland. In his “spare time”, he is a global board member for OWASP. At the AppSec Europe 2014 Conference in Cambridge,...
View ArticleAchim Hoffmann and the o-Saft Project for Scanning SSL Connections
Achim Hoffmann is a researcher who has created a tool for listing information about remote target’s SSL certificate and testing the remote target against a given list of ciphers. This OWASP project,...
View ArticleThe Results Are In: 4th Annual Open Source and Application Security Survey
3300 people responded to the 4th Annual Open Source and Application Security Survey. It’s time to see the results of that survey: 56% have an open source policy (up from 43% last year) Component...
View ArticleDavid A. Wheeler on the Current State of Application Security [AUDIO]
“Typically, people divide the (software) world into cost, schedule, functionality, quality. In my experience, almost everyone when they talk ‘quality’, are excluding security.” — David A. Wheeler...
View ArticleIf you don’t talk to your kids about vulnerable open source components,...
It seems odd to me that the majority of software security conversations and tools are around code scanning when 90% of most software is made of pre-packaged components. We need to change the discussion...
View ArticleMay 9, 2014 – Security from the Inside Out with Chris Eng
This segment of TSWA Network News includes commentary on the South Carolina data breach and one month later, after Heartbleed. View the entire segment with Chris Eng Resources: WLTX 19: SC Data Breach...
View ArticleMay 7, 2013 – Space Rogue and Mark Miller on Recent Security News
In this segment, Space and I talk about Symantec’s announcement that anti-virus software is dead, and then we switch to the known vulnerability risks in some open source components. View the video with...
View ArticleOmkhar Arasaratnam on Open Source Usage within the Large Enterprise
“I think with development practices, such as CI, we’re going to get to a point that rather than having this one, monolithic milestone where you’re given these hundreds of defects, instead the developer...
View ArticleDwayne Melancon, CTO – A Glimpse of the Future at Tripwire
At Source Conference in Boston last month, I sat down several times with Tripwire CTO Dwayne Melancon. Our discussion centered around his work with the development and engineering teams at Tripwire,...
View ArticleOWASP Top 10 Privacy Risks Project with Florian Stahl and Stefan Burgmair
The OWASP Top 10 Privacy Risks Project aims to develop a top 10 list for privacy risks in web applications because currently there is no such catalog available. I spoke with co-leads Florian Stahl and...
View ArticleApril 24, 2014 – Security from the Inside Looking Out with Chris Eng
In this first installment with Chris Eng, we discuss the new alliance for the funding of open source projects and conclude with how easy it is to hack medical equipment. Resources for this segment:...
View ArticleApril 23, 2014 – The Lone Star State DevOps Edition with James Wickett [VIDEO]
In today’s segment, James tackles the topics of Google end-to-end encryption, and the recent generation of social engineering schemes. Resources for this segment: The Hacker News: Google Working On...
View ArticleThe Run Up to a Massive Cyber Security Month with Tom Brennan
In anticipation of Security Awareness Month in October, Tom Brennan is planning an event featuring a cross section of various cyber groups in New York and New Jersey. A few weeks ago, I attended a Meet...
View ArticleApril 22, 2014 – A DevOps Point of View with Damon Edwards
In today’s segment, we talk about the long term effects of the HeartBleed incident and acknowledge the highest frequently attacked applications: web apps and point of sales systems. Watch the full...
View ArticleWolfgang Goerlich on a Real World Example of The Phoenix Project in Action
At 2014 SOURCE Boston, Josh Corman told me that Wolfgang Goerlich had an interesting DevOps story to tell. I sat down and spoke with Wolfgang and was astounded to hear a tale that could have come...
View ArticleAllison Miller and the Society for Information Risk Analysts [AUDIO INTERVIEW]
Allison Miller caught my attention at the end of her session at 2014 Source Boston when she ‘Risk Rolled’ the audience and had them sing along with a talking head embedded in her presentation. I knew...
View ArticleRyan Berg on Post-HeartBleed Password Management
As many of you are already well aware of there has been a serious flaw in OpenSSL that is a foundational open source library used for SSL encryption. There are plenty of places to get more information...
View Article