184 episodes

The OWASP Podcast Series is a recorded series of discussions with thought leaders and practitioners who are working on securing the future for coming generations.

The OWASP Podcast Series The OWASP Podcast Series

    • Technology
    • 4.5 • 22 Ratings

The OWASP Podcast Series is a recorded series of discussions with thought leaders and practitioners who are working on securing the future for coming generations.

    ep2023-07 What's Audit got to do with IT

    ep2023-07 What's Audit got to do with IT

    In this episode we talk with Zain Haq and take a leap and bound over the first and second line to discover more about the third line - internal audit. We discover answers to a number of questions: What role does audit play in the overall cybersecurity of an organization? What does the CISO gain from having an audit function? What makes a good auditor? Learn how to get the most out of audit and what they bring to the table. Special thanks to Tina Turner for inspiring the show title. ;-)

    Show Links:

    - Zain Haq: https://www.linkedin.com/in/zainhaq25/

    • 33 min
    SBOMS, CycloneDX and Dependency Track: Automation for Survival with Steve Springett

    SBOMS, CycloneDX and Dependency Track: Automation for Survival with Steve Springett

    Software supply chain seems to be front and center for technologists, cybersecurity and many governments. One of the early pioneers in this space was Steve Springett with two highly successful projects: OWASP Dependency Track and CycloneDX. In this episode, we catch up with Steve to talk about how he got started in software supply chain management as well as the explosive growth for Dependency Track and ClycloneDX. We also touch on future developments for CycloneDX and places where Steve never expected to see his projects go. Enjoy!

    Show Links:

    - OWASP Dependency Track: https://dependencytrack.org/
    - Dependency Track Github: https://github.com/DependencyTrack
    - CycloneDX: https://cyclonedx.org/
    - CycloneDX Github: https://github.com/CycloneDX
    - Software Component Verification Standard: https://scvs.owasp.org/
    Social Media links:
    - https://twitter.com/stevespringett
    - https://infosec.exchange/@stevespringett
    - https://www.linkedin.com/in/stevespringett/

    • 29 min
    AppSec at 40,000 feet

    AppSec at 40,000 feet

    In this episode I speak with Jerry Hoff who provides some very interesting perspective on application security especially at scale and from a high level view like that of a CISO. Even if you're not in a senior leadership position, you're likely to be reporting to one. Understanding that point of view can help you successfully frame your work and accomplish your goals. We touch on multiple topics and have some great back and forth that I'm sure will entertain and inform you. Enjoy!

    • 44 min
    2023-04 Rethinking WAFs: OWASP Coraza

    2023-04 Rethinking WAFs: OWASP Coraza

    WAFs have been with us a while and it's about time someone reconsidered WAFs and their role in AppSec given the cloud-native and Kubernetes landscape. The OWASP Coraza is not only asking these questions but putting some Go code behind their ideas. Should WAFs work in a mesh network? Why create an open source WAF? What's next for the OWASP Coraza project? These and more topics are covered in this episode. I had a great time recording it and I think you'll have the same while listening.

    Show Link:
    - Coraza Website: https://coraza.io/
    - Coraza Github Repo: https://github.com/corazawaf/coraza
    - Coraza Twitter: https://twitter.com/corazaio
    - AppSec EU 2023 presentation on Coraza - https://www.youtube.com/watch?v=S_TtvDFmia4

    • 29 min
    2023-03 Point of Scary - the POS ecosystem

    2023-03 Point of Scary - the POS ecosystem

    In this episode I speak with Aaron about Point of Sale or POS systems. He's been investigating the security of POS systems for quite some time now and brings to light the state of the POS ecosystem. Buckle your seat belts, this is going to be a bumpy and very interesting ride.

    • 34 min
    2023-02 Isolation is just PEACHy

    2023-02 Isolation is just PEACHy

    In this episode I speak with Amitai Cohen who's been thinking a lot about tenant isolation. This is a problem for more then just cloud providers. Anyone with a SaaS offering or even large enterprise may want to isolate customers or parts of their business from each other. Several useful items came out of this including the Cloud VulnDB which catalogs security issues in cloud services and the PEACH tenant isolation framework. You may not think you need to worry about tenant isolation, but I bet you should at least keep it in mind. Enjoy!

    Show Links:
    - Cloud VulnDB: https://www.cloudvulndb.org/
    - PEACH Framework: https://www.peach.wiz.io/
    - OWASP Cloud Tenant Isolation Project: https://owasp.org/www-project-cloud-tenant-isolation/

    • 33 min

Customer Reviews

4.5 out of 5
22 Ratings

22 Ratings

DJ Mangus ,

Nice

Worth a listen for any web dev. Could do without the sound effects but content makes dealing with it worth it.

Brian Contos ,

Keep up the great work!

This is an excellent podcast with great interviews. It’s one of the best sources for a wide array of application security information on the net.

rampanteer ,

Very Well Done!

By far, the best podcast dealing with webapp security that I've found.

Top Podcasts In Technology

Jason Calacanis
Lex Fridman
The New York Times
NPR
Ben Gilbert and David Rosenthal
Andrew Gelina

You Might Also Like

Johannes B. Ullrich
CISO Series
David Spark, Mike Johnson, and Andy Ellis
ITWC
N2K Networks
N2K Networks