Daniel Miessler -- OWASP IoT Top 10 episode artwork

EPISODE · Jan 1, 2019 · 44 MIN

Daniel Miessler -- OWASP IoT Top 10

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

An IoT product’s attack surface extends well beyond the device in the box. Daniel Miessler explains that broader view while walking Chris and Robert through the 2018 OWASP IoT Top 10. Before reviewing the risks, he describes the project’s audience, how the team gathered and evaluated data, and the challenge of balancing recurring failures with emerging concerns. The list covers passwords, exposed services, ecosystem interfaces, updates, components, privacy, data protection, device management, defaults, and physical hardening. Real testing examples show how a secure-looking connection can hide other unprotected paths or services. Daniel closes with guidance for developers who want to understand their product’s full ecosystem and use the list as a starting point for better security decisions.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Daniel Miessler:→ Daniel Miessler→ OWASP Internet of Things projectMentioned in this episode:→ OWASP Application Security Verification Standard→ OWASP Proactive Controls→ National Vulnerability Database→ Cloud Security AllianceFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 The 2018 IoT Top 10 with Daniel Miessler01:27 Daniel’s security origin story04:25 Why the IoT Top 10 exists07:30 Manufacturers, developers, and other audiences11:56 Gathering data and deciding the rankings19:27 Historical findings and emerging risks22:39 Passwords and insecure network services24:23 Insecure ecosystem interfaces26:13 Lack of secure update mechanisms28:31 Insecure or outdated components30:41 Privacy and unexpected connections33:05 Data protection at rest and in transit35:29 Device management and insecure defaults37:45 Physical hardening40:18 Takeaways for developers

Episode metadata supplied by the publisher feed · Published Jan 1, 2019

Embed this episode

An IoT product’s attack surface extends well beyond the device in the box. Daniel Miessler explains that broader view while walking Chris and Robert through the 2018 OWASP IoT Top 10. Before reviewing the risks, he describes the project’s audience, how the team gathered and evaluated data, and the challenge of balancing recurring failures with emerging concerns. The list covers passwords, exposed services, ecosystem interfaces, updates, components, privacy, data protection, device management,...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Daniel Miessler -- OWASP IoT Top 10

0:00 44:30

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 44 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on January 1, 2019.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!