EPISODE · Jan 11, 2022 · 34 MIN
Jeroen Willemsen and Ben de Haan -- Dirty little secrets
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Secrets management fails in surprisingly ordinary ways: credentials land in code, deployment files, containers, and cloud resources, then quietly become part of the system’s attack surface. Jeroen Willemsen and Ben de Haan join Chris and Robert to introduce OWASP WrongSecrets, an intentionally vulnerable application built to teach those failure modes. They explain how the project grew from incident-response experience, why cloud services change the threat model, and how teams can reason about blast radius and maturity. The conversation closes with practical guidance for scaling secrets management across an organization and using hands-on challenges to turn abstract advice into memorable engineering lessons.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Jeroen Willemsen and Ben de Haan:→ Jeroen Willemsen on LinkedIn→ OWASP WrongSecretsMentioned in this episode:→ OWASP WrongSecrets→ WrongSecrets on GitHub→ Secrets management deployment guidance→ Terraform→ Docker→ KubernetesFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 The dirty little secrets in software delivery02:00 How incident response shaped the project05:51 Introducing OWASP WrongSecrets08:46 Why secrets management keeps failing11:22 Cloud storage and common mistakes16:33 Maturity, threat models, and blast radius19:23 Turning real failures into challenges23:03 Secrets hidden in containers and deployment files27:36 Advice for security and engineering teams30:02 Scaling secrets management31:54 Written guidance and project resources33:39 Final takeaways
Embed this episode
What this episode covers
Secrets management fails in surprisingly ordinary ways: credentials land in code, deployment files, containers, and cloud resources, then quietly become part of the system’s attack surface. Jeroen Willemsen and Ben de Haan join Chris and Robert to introduce OWASP WrongSecrets, an intentionally vulnerable application built to teach those failure modes. They explain how the project grew from incident-response experience, why cloud services change the threat model, and how teams can reason about...
Ready to play
Jeroen Willemsen and Ben de Haan -- Dirty little secrets
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.