EPISODE · May 30, 2017 · 31 MIN
Chris and Robert -- Controversy within the OWASP Top 10 RC
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Why did the 2017 OWASP Top 10 release candidate provoke such a strong reaction? Chris and Robert walk through the proposed categories, compare them with earlier editions, and examine the project’s role as both awareness document and de facto testing target. They discuss merged and removed risks, injection, authentication, sensitive data, XML external entities, access control, cross-site scripting, insecure deserialization, components with known vulnerabilities, and insufficient attack protection. The hosts question whether new categories are sufficiently general, whether tools and frameworks already address some risks, and how modern APIs and microservices affect the list. The episode preserves the uncertainty of a release-candidate debate while helping listeners understand the technical and governance questions behind a widely used standard.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Chris Romeo and Robert Hurlbut:→ Chris Romeo on LinkedIn→ Robert Hurlbut on LinkedInMentioned in this episode:→ OWASP Top 10→ OWASP Top 10 2017→ OWASP AppSensor Project→ OWASP Top 10 A9 (Using Components with Known Vulnerabilities)Follow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 The controversial OWASP Top 10 candidate01:25 The Top 10’s history and influence03:17 How tools use the list05:08 Reaction to the 2017 release candidate06:36 Merged and renamed categories08:01 Removed risks09:20 Framework protections and remaining responsibility11:13 Injection and authentication13:47 Which risks apply beyond web applications15:14 Cross-site scripting and browser defenses16:46 Access control must be consistent18:37 Automating security verification20:20 Insufficient attack protection22:01 Application-level detection and response23:53 Insecure deserialization25:48 Components with known vulnerabilities27:09 APIs, microservices, and attack surface29:00 Security through obscurity31:00 Final assessment of the candidate
Embed this episode
What this episode covers
Why did the 2017 OWASP Top 10 release candidate provoke such a strong reaction? Chris and Robert walk through the proposed categories, compare them with earlier editions, and examine the project’s role as both awareness document and de facto testing target. They discuss merged and removed risks, injection, authentication, sensitive data, XML external entities, access control, cross-site scripting, insecure deserialization, components with known vulnerabilities, and insufficient attack protect...
Ready to play
Chris and Robert -- Controversy within the OWASP Top 10 RC
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.