EPISODE · Sep 3, 2020 · 35 MIN
Michael Furman — SameSite Cookies
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Michael Furman is the Lead Security Architect at Tufin, and is responsible for the security and Security Development Lifecycle (SDL) of Tufin software products. Michael is passionate about application security for over 13 years already and evangelizes about application security at various conferences (including OWASP conferences) and security meetups. Michael joins us to break down SameSite cookies, which are all the rage in browsers these days. He describes what they are, the threats they counter, and how SameSite + the Synchronizer Token Pattern work together to counter CSRF. We hope you enjoy this conversation with.... He's worked in this space for 13 years and evangelizes AppSec at various conferences, including OWASP and security meetups.The Application Security Podcast is brought to you by Security Journey.About Security JourneyMichael Furman is the lead security architect at Tufin and is responsible for the security and secure development lifecycle of Tufin software products.→ Learn more about Security JourneyConnect with Michael Furman:→ Tufin→ ChromiumMentioned in this episode:→ Tufin→ ChromiumFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Michael Furman: Michael Furman — SameSite Cookies02:17 Excellent. And so to get started, what we usually do is04:54 Yeah, and I'll definitely second what you're saying about application security07:17 Okay. And so SameSite's been around then for just a couple08:52 That makes sense in terms of some of the things that11:19 Yeah, and I think the last I heard for the previous14:37 So with the— what you're modeling in the test csrf.htm here17:09 Yeah. So one of the patterns that we've used in the19:14 It sounds like you could still use the synchronizer pattern, but30:39 We can only hope and dream that that is a world32:29 Yeah, that's great. That provides our users with some additional information
Embed this episode
What this episode covers
Michael Furman is the Lead Security Architect at Tufin, and is responsible for the security and Security Development Lifecycle (SDL) of Tufin software products. Michael is passionate about application security for over 13 years already and evangelizes about application security at various conferences (including OWASP conferences) and security meetups. Michael joins us to break down SameSite cookies, which are all the rage in browsers these days. He describes what they are, the threats they co...
Ready to play
Michael Furman — SameSite Cookies
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.