Niels Tanis — 3rd Party Risk in a .NET World episode artwork

EPISODE · Jan 24, 2020 · 35 MIN

Niels Tanis — 3rd Party Risk in a .NET World

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

How much behavior do you inherit when you add one library to a .NET application? Niels Tanis joins Chris and Robert to examine third-party risk beyond checking a dependency for known vulnerabilities. They revisit the event-stream compromise and Operation ShadowHammer, then look at NuGet packages, transitive dependencies, and functionality developers may never intend to use. A PDF library becomes a concrete example of why network access and other capabilities deserve scrutiny. Niels explores isolation, assembly loading, and constraining library behavior rather than trusting every dependency with the application's full privileges. He also describes using Mono.Cecil and his Fennec tooling to inspect calls, helping developers ask better questions about what their dependencies can actually do.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Niels Tanis:→ LinkedIn→ Niels's blogMentioned in this episode:→ NuGet→ iTextSharp→ Operation ShadowHammer→ Mono.Cecil→ Fennec.CLIFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Introduction03:03 What third-party risk really includes06:25 Compromised dependencies and event-stream11:08 Operation ShadowHammer and trusted updates14:04 Dependency risk in the .NET ecosystem17:03 Hidden capabilities inside familiar libraries21:51 Isolation and least privilege23:48 Constraining libraries with assembly loading28:42 Controlling behavior and micropatches30:21 Inspecting calls with Mono.Cecil and Fennec34:14 Making dependency reviews useful to developers

Episode metadata supplied by the publisher feed · Published Jan 24, 2020

Embed this episode

How much behavior do you inherit when you add one library to a .NET application? Niels Tanis joins Chris and Robert to examine third-party risk beyond checking a dependency for known vulnerabilities. They revisit the event-stream compromise and Operation ShadowHammer, then look at NuGet packages, transitive dependencies, and functionality developers may never intend to use. A PDF library becomes a concrete example of why network access and other capabilities deserve scrutiny. Niels explores i...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Niels Tanis — 3rd Party Risk in a .NET World

0:00 35:54

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 35 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on January 24, 2020.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!