Björn Kimminich — The new JuiceShop, GSOC, and Open Security Summit episode artwork

EPISODE · Jun 1, 2019 · 28 MIN

Björn Kimminich — The new JuiceShop, GSOC, and Open Security Summit

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

How do you keep an intentionally vulnerable application useful while its underlying frameworks keep fixing bugs? Björn Kimminich returns with an update on OWASP Juice Shop and the work required to maintain realistic security challenges. He describes new exercises involving promotional content, coupons, privacy, and two-factor authentication, then explains what happens when dependency or browser changes accidentally remove a vulnerability. The conversation also covers customization for different audiences, contributions through Google Summer of Code, and the balance between welcoming help and reviewing it carefully. Björn closes with plans for collaborative work at the 2019 Open Security Summit. This archive episode shows both the technical craft and community effort behind a widely used application security learning project.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Björn Kimminich:→ Björn Kimminich on GitHubMentioned in this episode:→ OWASP Juice Shop→ Open Security SummitFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 What was new in OWASP Juice Shop02:25 New features and hacking challenges05:19 Working two-factor authentication with TOTP07:21 Keeping the right parts intentionally vulnerable08:15 When dependency updates remove a challenge09:43 Privacy features and GDPR-related exercises11:16 Customizing Juice Shop for different audiences13:05 Google Summer of Code contributions16:14 Reviewing contributions and sharing maintenance17:09 Getting help and giving feedback19:22 Introducing the 2019 Open Security Summit21:42 Planned Juice Shop working sessions24:50 Adapting the summit around participants’ needs26:30 Where to find Juice Shop resources

Episode metadata supplied by the publisher feed · Published Jun 1, 2019

Embed this episode

How do you keep an intentionally vulnerable application useful while its underlying frameworks keep fixing bugs? Björn Kimminich returns with an update on OWASP Juice Shop and the work required to maintain realistic security challenges. He describes new exercises involving promotional content, coupons, privacy, and two-factor authentication, then explains what happens when dependency or browser changes accidentally remove a vulnerability. The conversation also covers customization for differe...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Björn Kimminich — The new JuiceShop, GSOC, and Open Security Summit

0:00 28:32

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 28 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on June 1, 2019.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!