Chris Romeo — The State of Security and the Importance of Empathy episode artwork

EPISODE · Aug 27, 2020 · 43 MIN

Chris Romeo — The State of Security and the Importance of Empathy

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Network engineers and application security teams depend on each other, yet often struggle to understand each other’s responsibilities. In this rebroadcast from The Hedge, Chris Romeo joins hosts Russ White and Tom Ammon to explore that divide. They discuss encrypted traffic, denial-of-service attacks, DNS, and the limits of relying on network controls to protect applications. Chris explains threat modeling as a repeatable way to question assumptions, including assumptions about cloud services and insider access. The conversation then turns to infrastructure automation, changing engineering roles, and the frustration created when security policies arrive without technical understanding. Their practical message is to learn one another’s language and build empathy through real experience with the systems other teams operate.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Chris Romeo:→ Chris Romeo on LinkedInMentioned in this episode:→ The Hedge episode 48→ National Vulnerability DatabaseFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Chris joins The Hedge to discuss security02:01 Where network and application security meet04:29 Encrypted traffic and network responsibilities06:04 Certificates, DNS, and interception threats07:51 Threat modeling as a way of questioning assumptions09:23 How denial-of-service defenses evolved12:23 Revisiting models as threats change17:45 Where network engineers can improve security22:21 Helping developers and application teams24:46 Routing, segmentation, and control-plane risks28:18 Insider threats and shared control31:11 Infrastructure as code and changing engineering roles34:51 Empathy between network and security teams39:39 Learning paths for network engineers

Episode metadata supplied by the publisher feed · Published Aug 27, 2020

Embed this episode

Network engineers and application security teams depend on each other, yet often struggle to understand each other’s responsibilities. In this rebroadcast from The Hedge, Chris Romeo joins hosts Russ White and Tom Ammon to explore that divide. They discuss encrypted traffic, denial-of-service attacks, DNS, and the limits of relying on network controls to protect applications. Chris explains threat modeling as a repeatable way to question assumptions, including assumptions about cloud services...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Chris Romeo — The State of Security and the Importance of Empathy

0:00 43:53

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 43 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on August 27, 2020.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!