241 episodes

A weekly podcast of all things application security related. Hosted by Ken Johnson and Seth Law.

Absolute AppSec Ken Johnson and Seth Law

    • Technology
    • 4.9 • 17 Ratings

A weekly podcast of all things application security related. Hosted by Ken Johnson and Seth Law.

    Episode 241 - Secure Defaults, Using LLMs for Code Review

    Episode 241 - Secure Defaults, Using LLMs for Code Review

    **Video may be required**: this episode is focused on demonstrating uses of LLMs against various code. As such, listeners may want to watch the stream to see these uses rather than just listening. Also, Seth and Ken talk briefly at the beginning of the episode about a new tldr;sec project (thanks Clint!) called awesome secure defaults that lists out useful libraries and projects that are secure by default.

    Episode 240 - Code Smells, XZ Backdoor, Hallucinations

    Episode 240 - Code Smells, XZ Backdoor, Hallucinations

    After a week of travel, Seth and Ken return to the podcast with a breakdown of their travel experiences at multiple conferences and teaching their first Practical Secure Code Review course using LLMs to enhance the methodology. This is followed by reinforcement of code review steps including library research, a discussion of the recent XZ backdoor, and an article reviewing LLM hallucinations when recommending libraries.

    Episode 239 - AppSec Intel, CVEs, Authorization

    Episode 239 - AppSec Intel, CVEs, Authorization

    When Ken is away, the geeks will play. Seth is joined by podcast regular Stefan Edwards (@lojikil) to catch up on his recent work around threat hunting. This progresses into a discussion on threat intelligence and what is available for applications. A recent blog post on the utility of the CVE system spurs thoughts on the usefulness of published CVEs. Finally, opinions fly on authorization issues and how simple misconfigurations result in the many vulnerabilities or attack chains.

    Episode 238 - AppSec vs. Enterprise Sec, Supply Chain Tool Analysis

    Episode 238 - AppSec vs. Enterprise Sec, Supply Chain Tool Analysis

    Ken and Seth are back to talk about the difference and competing priorities of Application and Enterprise Security. In short, recent news contends that Enterprise or Infrastructure security is lacking, whereas Application or Product Security is in a good state. This is followed by a discussion on supply chain security tools due to a recent analysis conducted by DoyenSec comparing false positives and negatives from the leading tools.

    Episode 237 - Security 101, Nation State Hackers, Malicious Code

    Episode 237 - Security 101, Nation State Hackers, Malicious Code

    Ken and Seth return for another episode, starting out with pointers on getting into security and finding a niche, all based on a recently released Microsoft project to introduce anyone to security. This is followed by a discussion on Chinese hacking groups and recent breaches among those groups. Finally, a discussion protecting the software supply chain due to recent forking and upload of malicious repositories on GitHub.

    Episode 236 - Memory Safe Languages, LLM Supply Chain Security

    Episode 236 - Memory Safe Languages, LLM Supply Chain Security

    Seth and Ken review the recent Whitehouse report on going back to the basics for software security and vulnerabilities. Specifically, how is the use of memory unsafe languages like C and C++ affecting the overall security of the internet landscape. This include a discussion on formal verification and crocs and socks of software testing. Finally, thoughts are shared on the recent use of Hugging Face and Github to host malicious code/packages and how this is a natural progression for popular package repositories.

Customer Reviews

4.9 out of 5
17 Ratings

17 Ratings

Top Podcasts In Technology

Lex Fridman Podcast
Lex Fridman
All-In with Chamath, Jason, Sacks & Friedberg
All-In Podcast, LLC
Acquired
Ben Gilbert and David Rosenthal
TED Radio Hour
NPR
Dwarkesh Podcast
Dwarkesh Patel
Hard Fork
The New York Times

You Might Also Like

Risky Business
Patrick Gray
Risky Business News
risky.biz
The Application Security Podcast
Chris Romeo and Robert Hurlbut
Smashing Security
Graham Cluley & Carole Theriault
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
Malicious Life
Malicious Life