Jay Beale -- Docker Security and AppSec episode artwork

EPISODE · Aug 22, 2017 · 44 MIN

Jay Beale -- Docker Security and AppSec

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Does moving an application into Docker make it safer, or simply change the risks you need to manage? Jay Beale of InGuardians joins Robert to explain containers, how they differ from virtual machines, and why sharing a Linux kernel matters for security. He examines container breakouts, the danger of assuming isolation is stronger than it is, and practical defenses using Linux security controls. The conversation then turns to patching: teams need to rebuild and replace images, track the software they contain, and test updates before deployment. Jay connects those responsibilities to third-party application libraries and explains why container convenience does not remove operational accountability. He closes with resources for keeping pace with Docker and Linux security.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Jay Beale:→ Jay Beale on LinkedIn→ InGuardiansMentioned in this episode:→ Docker→ Kubernetes→ Linux kernel→ LXCFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Docker security with Jay Beale01:50 From Linux hardening to security consulting05:36 Containers compared with virtual machines10:35 Sharing the Linux kernel14:35 Why Docker changed the developer workflow16:08 Container breakouts and new security risks21:53 Controls that reduce breakout risk26:51 Rebuilding images and keeping containers patched28:29 Finding vulnerable software in containers32:53 Third-party libraries and application security36:31 Testing updates before deployment39:09 Where to keep learning about Docker security42:55 Final advice and training resources

Episode metadata supplied by the publisher feed · Published Aug 22, 2017

Embed this episode

Does moving an application into Docker make it safer, or simply change the risks you need to manage? Jay Beale of InGuardians joins Robert to explain containers, how they differ from virtual machines, and why sharing a Linux kernel matters for security. He examines container breakouts, the danger of assuming isolation is stronger than it is, and practical defenses using Linux security controls. The conversation then turns to patching: teams need to rebuild and replace images, track the softwa...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Jay Beale -- Docker Security and AppSec

0:00 44:46

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 44 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on August 22, 2017.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!