The Boring AppSec Podcast

The Boring AppSec Podcast
The Boring AppSec Podcast

In this podcast, we will talk about our experiences having worked at different companies - from startups to big enterprises, from tech companies to security companies, and from building side projects to building startups. We will talk about the good, the bad, and everything in between. So join us for some fun, some real, and some super hot takes about all things Security in the Boring AppSec Podcast.

Episodes

  1. 20 MAY

    S1E10 - Future Security Predictions

    Welcome to the Boring AppSec Podcast! In Episode 10, we discuss some security predictions that we hope to see in the near future. Some of them are: AI agents - different kinds - activity based and/or persona based Security talent is going to get better, hiring is important AI powered security engineers - up leveling junior engineers AI code review assistants - GPT4-o et al Company consolidations happening in the security industry - D&R space ASPM predictions and how AI agents will help evolve this space CISA’s guidance on building secure by default frameworks Automated red teaming Hiring security engineers vs changes in interviewing Tune in to find out more! References mentioned in the episode: OpenAI Security Bots - https://github.com/openai/openai-security-bots Build an AI Appsec Team - https://srajangupta.substack.com/p/building-an-ai-appsec-team CISA and secure design - https://www.cisa.gov/news-events/news/cisa-announces-secure-design-commitments-leading-technology-providers Awesome secure defaults - https://github.com/tldrsec/awesome-secure-defaults Slack vs MSFT teams - https://x.com/TrungTPhan/status/1640866391485194241 The Innovator's Dilemma - https://www.amazon.com/Innovators-Dilemma-Revolutionary-Change-Business/dp/0062060244 Contacting Anshuman LinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/in/anshumanbhartiya/⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠  Twitter: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://twitter.com/anshuman_bh⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠  Website: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://anshumanbhartiya.com/⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ Instagram: ⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.instagram.com/anshuman.bhartiya/⁠⁠⁠⁠⁠⁠⁠⁠⁠  YouTube: ⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.youtube.com/@AnshumanBhartiya⁠⁠⁠⁠⁠⁠⁠⁠⁠    Contacting Sandesh LinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/in/anandsandesh/⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠  Twitter: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://twitter.com/JubbaOnJeans/⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠  Website: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://boringappsec.substack.com/⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠

    51 min
  2. 1 APR

    S1E05 - Threat Modeling

    Welcome to the Boring AppSec Podcast! In Episode 5, we dig deep into what threat modeling is from a practitioner's perspective. We compare it with design reviews and discuss when/how/why of threat modeling. In the end, we wrap up by talking about how Gen AI could help threat modeling significantly. References: We will try and add information about all the references we make here. Please enter rabbit holes at will :)  Threat modeling manifesto - Threatmodelingmanifesto.org STRIDE framework - https://en.wikipedia.org/wiki/STRIDE_(security)  Tools for threat modeling ⁠https://learn.microsoft.com/en-us/azure/security/develop/threat-modeling-tool⁠ ⁠https://www.iriusrisk.com/threat-modeling/freemium⁠ ⁠https://owasp.org/www-project-threat-dragon/⁠ ⁠https://excalidraw.com/⁠ ⁠https://www.securitycompass.com/sdelements/⁠ Talks on threat modeling https://www.youtube.com/watch?v=KGy_KCRUGd4⁠  ⁠https://www.youtube.com/watch?v=wVSyqFdO-D8⁠  Articles - https://www.scaletozero.com/episodes/understanding-threat-modeling-with-jeevan-singh/  Gen AI related threat modeling tools/companies Stride GPT- https://stridegpt.streamlit.app/ Nullify - https://www.nullify.ai/ Remysec - https://www.remysec.com/ Seezo - https://seezo.io/ https://www.sarahtavel.com/p/ai-startups-sell-work-not-software  https://github.com/captn3m0/ideas  Contacting Anshuman LinkedIn: ⁠⁠⁠⁠⁠https://www.linkedin.com/in/anshumanbhartiya/⁠⁠⁠⁠⁠  Twitter: ⁠⁠⁠⁠⁠https://twitter.com/anshuman_bh⁠⁠⁠⁠⁠  Website: ⁠⁠⁠⁠⁠https://anshumanbhartiya.com/⁠⁠⁠⁠⁠ Instagram: ⁠⁠⁠⁠https://www.instagram.com/anshuman.bhartiya/⁠⁠⁠⁠  YouTube: ⁠⁠⁠⁠https://www.youtube.com/@AnshumanBhartiya⁠⁠⁠⁠    Contacting Sandesh LinkedIn: ⁠⁠⁠⁠⁠https://www.linkedin.com/in/anandsandesh/⁠⁠⁠⁠⁠  Twitter: ⁠⁠⁠⁠⁠https://twitter.com/JubbaOnJeans/⁠⁠⁠⁠⁠  Website: ⁠⁠⁠⁠⁠https://boringappsec.substack.com/⁠⁠⁠⁠⁠

    1h 2m
  3. 18 MAR

    S1E03 - Bug Bounties

    Welcome to the Boring AppSec Podcast! In Episode 3, we discuss all things bug bounties. The researcher side as well as the program owner's side. Enter at your own will as we have a lot of hot takes. References: We will try and add information about all the references we make here. Please enter rabbit holes at will :)  ⁠Bug Bounty Platforms Bugcrowd - https://www.bugcrowd.com/  HackerOne - https://www.hackerone.com/  Intigrity - https://www.intigriti.com/  Synack - https://www.synack.com/  2. Vulnerability Disclosure Process - https://www.cisa.gov/coordinated-vulnerability-disclosure-process  3. Google’s Project Zero vulnerability disclosure policy - https://googleprojectzero.blogspot.com/p/vulnerability-disclosure-faq.html   4. CVSS Calculator - https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator   5. Handling A Bug Bounty program From A Blue Team Perspective - https://www.youtube.com/watch?v=Vgy150R4bRw&t=0s 6. Consumer Bug Bounty Panel - https://www.youtube.com/watch?v=Y8X6pV7rdbA&t=0s Contacting Anshuman LinkedIn: ⁠⁠⁠https://www.linkedin.com/in/anshumanbhartiya/⁠⁠⁠  Twitter: ⁠⁠⁠https://twitter.com/anshuman_bh⁠⁠⁠  Website: ⁠⁠⁠https://anshumanbhartiya.com/⁠⁠⁠ Instagram: ⁠⁠https://www.instagram.com/anshuman.bhartiya/⁠⁠  YouTube: ⁠⁠https://www.youtube.com/@AnshumanBhartiya⁠⁠    Contacting Sandesh LinkedIn: ⁠⁠⁠https://www.linkedin.com/in/anandsandesh/⁠⁠⁠  Twitter: ⁠⁠⁠https://twitter.com/JubbaOnJeans/⁠⁠⁠  Website: ⁠⁠⁠https://boringappsec.substack.com/⁠⁠⁠

    1h 11m
  4. 4 MAR

    S1E01 - Asset Inventory

    Welcome to the Boring AppSec Podcast! In Episode 1, we discuss software inventories. What they are, why we need them, and what are our favorite ways to build them.  References: We will try and add information about all the references we make here. Please enter rabbit holes at will :)  Cartography - ⁠https://github.com/lyft/cartography⁠  GenAI + Cartography ⁠https://shinobi.security/#how-it-works⁠  ⁠https://github.com/samvas-codes/cspm-gpt⁠  Commercial asset inventory mentioned on the show: ⁠https://www.jupiterone.com/⁠  Talk by Sandesh and Satyaki on automating asset inventory generation at Razorpay: ⁠https://www.youtube.com/watch?v=8q42Pw9F44k&ab_channel=HasgeekTV⁠  XKCD about too many standards - ⁠https://m.xkcd.com/927/⁠  Arvind Narayanan on Gen AI chatbots and rock-paper-scissors: ⁠https://x.com/random_walker/status/1755684956502728969?s=20⁠    Emily Oster on parenting - ⁠https://emilyoster.net/⁠ . She has now moved her newsletter away from Substack. You can sign up at ⁠https://parentdata.org/⁠  Contacting Anshuman LinkedIn: ⁠https://www.linkedin.com/in/anshumanbhartiya/⁠  Twitter: ⁠https://twitter.com/anshuman_bh⁠  Website: ⁠https://anshumanbhartiya.com/⁠ Instagram: https://www.instagram.com/anshuman.bhartiya/  YouTube: https://www.youtube.com/@AnshumanBhartiya    Contacting Sandesh LinkedIn: ⁠https://www.linkedin.com/in/anandsandesh/⁠  Twitter: ⁠https://twitter.com/JubbaOnJeans/⁠  Website: ⁠https://boringappsec.substack.com/⁠

    45 min

About

In this podcast, we will talk about our experiences having worked at different companies - from startups to big enterprises, from tech companies to security companies, and from building side projects to building startups. We will talk about the good, the bad, and everything in between. So join us for some fun, some real, and some super hot takes about all things Security in the Boring AppSec Podcast.

To listen to explicit episodes, sign in.

Stay up to date with this show

Sign-in or sign-up to follow shows, save episodes and get the latest updates.

Select a country or region

Africa, Middle East, and India

Asia Pacific

Europe

Latin America and the Caribbean

The United States and Canada