David Habusha -- Third Party Software is not a Cathedral, It’s a Bazaar episode artwork

EPISODE · Apr 13, 2018 · 37 MIN

David Habusha -- Third Party Software is not a Cathedral, It’s a Bazaar

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

An application can inherit serious vulnerabilities from code its developers never wrote. David Habusha, then a product leader at WhiteSource, explains the problem behind the 2017 OWASP Top 10 category on components with known vulnerabilities. He brings a product-management perspective to the discussion, connecting dependency choices to business outcomes and the realities of modern development. Chris and Robert ask why static and dynamic testing may miss this problem, what software composition analysis actually identifies, and how accurate component matching can be. The conversation uses Apache Struts and the Equifax breach to examine inventory, notification, and remediation. David closes by describing open source as a bazaar rather than a cathedral, where continuous awareness and maintenance matter more than expecting any component to remain permanently safe.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with David Habusha:→ David Habusha on LinkedInMentioned in this episode:→ OWASP Top 10 2017 — Vulnerable Components→ WhiteSource — now Mend.io→ Apache Struts vulnerability CVE-2017-5638Follow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Understanding vulnerable third-party components01:30 David’s security background04:09 A product manager’s perspective on AppSec08:48 What components with known vulnerabilities means12:28 How much software comes from dependencies?14:54 The consequences of vulnerable components18:14 Why SAST and DAST are not enough20:35 What software composition analysis does24:02 Accuracy and component identification27:29 What the Equifax breach teaches about SCA32:58 Why dependency security is continuous work

Episode metadata supplied by the publisher feed · Published Apr 13, 2018

Embed this episode

An application can inherit serious vulnerabilities from code its developers never wrote. David Habusha, then a product leader at WhiteSource, explains the problem behind the 2017 OWASP Top 10 category on components with known vulnerabilities. He brings a product-management perspective to the discussion, connecting dependency choices to business outcomes and the realities of modern development. Chris and Robert ask why static and dynamic testing may miss this problem, what software composition...

Distinct summary based on available episode metadata or transcript content.

Ready to play

David Habusha -- Third Party Software is not a Cathedral, It’s a Bazaar

0:00 37:02

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 37 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on April 13, 2018.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!