EPISODE · May 31, 2024 · 44 MIN
James Berthoty -- Is DAST Dead? And the future of API security
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
James Berthoty, a cloud security engineer with a diverse IT background, discusses his journey into application and product security. James highlights his career trajectory from IT operations to cloud security, his experiences with security tools like Snyk and StackHawk, and the evolving landscape of Dynamic Application Security Testing (DAST) and API security. They delve into the practical challenges of CVEs, reachability analysis, and the complexities of patching in mid-sized companies. James shares his views on the often misunderstood role of WAF and the importance of fixing issues over merely identifying them. James Berthoty has been in technology for over 10 years in engineering and security roles.The Application Security Podcast is brought to you by Security Journey.About Security JourneyWe provide application security training for not just your developers, but for all roles in your SDLC.→ Learn more about Security JourneyConnect with James Berthoty:→ AppSec Kool-Aid Statements I Disagree With→ What is Art by Leo TolstoyMentioned in this episode:→ AppSec Kool-Aid Statements I Disagree With→ What is Art by Leo Tolstoy→ Snyk→ StackHawk→ AppSec Kool-Aid Statements I Disagree With→ National Vulnerability Database (NVD)→ eBPF→ KubernetesFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet James Berthoty: Is DAST Dead? And the future of API security04:11 Mm-hmm. So when I think about your trajectory here, so you've06:48 Let's start with this idea of DAST. And so anyone who's10:02 So when you, when you're seeing these API scanners these days13:07 You still using the term DAST or have you replaced it14:49 What's your, what, what are your thoughts on this16:42 Okay. That's helpful. What about reachability analysis19:22 Patching really still that hard22:43 The million dollar question then, is AI going to solve the28:04 Yeah. I mean, fix it yourself and generate a PR, submit32:22 I'm, I mean, let's, let's just talk about WAF and, and36:12 Yeah, I think that's, uh, that's definitely true. Well, you got38:01 Okay. Next. Like, celebration time. Yep. We passed. All right. So41:29 Yeah. Yeah, definitely. So, all right, let's do a couple of42:29 Question is, if you could have display a single message on
Embed this episode
What this episode covers
James Berthoty, a cloud security engineer with a diverse IT background, discusses his journey into application and product security. James highlights his career trajectory from IT operations to cloud security, his experiences with security tools like Snyk and StackHawk, and the evolving landscape of Dynamic Application Security Testing (DAST) and API security. They delve into the practical challenges of CVEs, reachability analysis, and the complexities of patching in mid-sized companies. Jame...
Ready to play
James Berthoty -- Is DAST Dead? And the future of API security
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.