Michael Furman — SameSite Cookies episode artwork

EPISODE · Sep 3, 2020 · 35 MIN

Michael Furman — SameSite Cookies

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Michael Furman is the Lead Security Architect at Tufin, and is responsible for the security and Security Development Lifecycle (SDL) of Tufin software products. Michael is passionate about application security for over 13 years already and evangelizes about application security at various conferences (including OWASP conferences) and security meetups. Michael joins us to break down SameSite cookies, which are all the rage in browsers these days. He describes what they are, the threats they counter, and how SameSite + the Synchronizer Token Pattern work together to counter CSRF. We hope you enjoy this conversation with.... He's worked in this space for 13 years and evangelizes AppSec at various conferences, including OWASP and security meetups.The Application Security Podcast is brought to you by Security Journey.About Security JourneyMichael Furman is the lead security architect at Tufin and is responsible for the security and secure development lifecycle of Tufin software products.→ Learn more about Security JourneyConnect with Michael Furman:→ Tufin→ ChromiumMentioned in this episode:→ Tufin→ ChromiumFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Michael Furman: Michael Furman — SameSite Cookies02:17 Excellent. And so to get started, what we usually do is04:54 Yeah, and I'll definitely second what you're saying about application security07:17 Okay. And so SameSite's been around then for just a couple08:52 That makes sense in terms of some of the things that11:19 Yeah, and I think the last I heard for the previous14:37 So with the— what you're modeling in the test csrf.htm here17:09 Yeah. So one of the patterns that we've used in the19:14 It sounds like you could still use the synchronizer pattern, but30:39 We can only hope and dream that that is a world32:29 Yeah, that's great. That provides our users with some additional information

Episode metadata supplied by the publisher feed · Published Sep 3, 2020

Embed this episode

Michael Furman is the Lead Security Architect at Tufin, and is responsible for the security and Security Development Lifecycle (SDL) of Tufin software products. Michael is passionate about application security for over 13 years already and evangelizes about application security at various conferences (including OWASP conferences) and security meetups. Michael joins us to break down SameSite cookies, which are all the rage in browsers these days. He describes what they are, the threats they co...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Michael Furman — SameSite Cookies

0:00 35:34

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 35 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on September 3, 2020.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!