EPISODE · Jan 24, 2020 · 35 MIN
Niels Tanis — 3rd Party Risk in a .NET World
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
How much behavior do you inherit when you add one library to a .NET application? Niels Tanis joins Chris and Robert to examine third-party risk beyond checking a dependency for known vulnerabilities. They revisit the event-stream compromise and Operation ShadowHammer, then look at NuGet packages, transitive dependencies, and functionality developers may never intend to use. A PDF library becomes a concrete example of why network access and other capabilities deserve scrutiny. Niels explores isolation, assembly loading, and constraining library behavior rather than trusting every dependency with the application's full privileges. He also describes using Mono.Cecil and his Fennec tooling to inspect calls, helping developers ask better questions about what their dependencies can actually do.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Niels Tanis:→ LinkedIn→ Niels's blogMentioned in this episode:→ NuGet→ iTextSharp→ Operation ShadowHammer→ Mono.Cecil→ Fennec.CLIFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Introduction03:03 What third-party risk really includes06:25 Compromised dependencies and event-stream11:08 Operation ShadowHammer and trusted updates14:04 Dependency risk in the .NET ecosystem17:03 Hidden capabilities inside familiar libraries21:51 Isolation and least privilege23:48 Constraining libraries with assembly loading28:42 Controlling behavior and micropatches30:21 Inspecting calls with Mono.Cecil and Fennec34:14 Making dependency reviews useful to developers
Embed this episode
What this episode covers
How much behavior do you inherit when you add one library to a .NET application? Niels Tanis joins Chris and Robert to examine third-party risk beyond checking a dependency for known vulnerabilities. They revisit the event-stream compromise and Operation ShadowHammer, then look at NuGet packages, transitive dependencies, and functionality developers may never intend to use. A PDF library becomes a concrete example of why network access and other capabilities deserve scrutiny. Niels explores i...
Ready to play
Niels Tanis — 3rd Party Risk in a .NET World
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.