Chris and Robert -- Controversy within the OWASP Top 10 RC episode artwork

EPISODE · May 30, 2017 · 31 MIN

Chris and Robert -- Controversy within the OWASP Top 10 RC

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Why did the 2017 OWASP Top 10 release candidate provoke such a strong reaction? Chris and Robert walk through the proposed categories, compare them with earlier editions, and examine the project’s role as both awareness document and de facto testing target. They discuss merged and removed risks, injection, authentication, sensitive data, XML external entities, access control, cross-site scripting, insecure deserialization, components with known vulnerabilities, and insufficient attack protection. The hosts question whether new categories are sufficiently general, whether tools and frameworks already address some risks, and how modern APIs and microservices affect the list. The episode preserves the uncertainty of a release-candidate debate while helping listeners understand the technical and governance questions behind a widely used standard.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Chris Romeo and Robert Hurlbut:→ Chris Romeo on LinkedIn→ Robert Hurlbut on LinkedInMentioned in this episode:→ OWASP Top 10→ OWASP Top 10 2017→ OWASP AppSensor Project→ OWASP Top 10 A9 (Using Components with Known Vulnerabilities)Follow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 The controversial OWASP Top 10 candidate01:25 The Top 10’s history and influence03:17 How tools use the list05:08 Reaction to the 2017 release candidate06:36 Merged and renamed categories08:01 Removed risks09:20 Framework protections and remaining responsibility11:13 Injection and authentication13:47 Which risks apply beyond web applications15:14 Cross-site scripting and browser defenses16:46 Access control must be consistent18:37 Automating security verification20:20 Insufficient attack protection22:01 Application-level detection and response23:53 Insecure deserialization25:48 Components with known vulnerabilities27:09 APIs, microservices, and attack surface29:00 Security through obscurity31:00 Final assessment of the candidate

Episode metadata supplied by the publisher feed · Published May 30, 2017

Embed this episode

Why did the 2017 OWASP Top 10 release candidate provoke such a strong reaction? Chris and Robert walk through the proposed categories, compare them with earlier editions, and examine the project’s role as both awareness document and de facto testing target. They discuss merged and removed risks, injection, authentication, sensitive data, XML external entities, access control, cross-site scripting, insecure deserialization, components with known vulnerabilities, and insufficient attack protect...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Chris and Robert -- Controversy within the OWASP Top 10 RC

0:00 31:20

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 31 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on May 30, 2017.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!