DevelopSec: Developing Security Awareness podcast artwork

PODCAST · technology

DevelopSec: Developing Security Awareness

Curious about application security? Want to learn how to detect security vulnerabilities and protect your application. We discuss different topics and provide valuable insights into the world of application security.

Publisher-supplied feed metadata · PodParley refreshed May 1, 2026 · Source feed

  1. 133

    Ep. 129: When Security Recommendations Miss The Point

    Ever read a security advisory that told you to “use a VPN” to protect a Bluetooth device? In this episode we talk about how bad or inaccurate recommendations can be a problem with security findings.  We take a look at an example of recommendations that don't relate to the issue at all, leaving people confused at how to respond. Share with us your experience with recommendations that just missed the mark.References:CISA Wheelchair Article - https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-364-01Skateboard Article - https://gizmodo.com/faceplant-exploit-lets-hackers-hijack-an-electric-ska-1722691650Bicycle Shifter Article - https://www.bicycling.com/racing/a61994540/hackers-target-electronic-shifters/Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  2. 132

    Ep. 128: OWASP Top 10 2025

    In this episode James gives an overview of the new OWASP Top 10 2025. He shares some insights into the history, changes, and additional thoughts on the top 10. Do you have any thoughts on the OWASP Top 10? Let us know. References:Medium article of history of top 10 - https://medium.com/@dramkumar/history-of-all-owasp-top-10-over-the-years-9470c0adf43dOWASP Top 10 2025 - https://owasp.org/Top10/2025/Top 10 -> CWE Breakdown - https://drive.google.com/file/d/1SmzWyg_ar1PaMFT0FxYelEAJuGMA690B/view?usp=sharingSend us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  3. 131

    Ep. 127: Importance of Terminology

    In this episode, James talks about the difference between end-to-end encryption and the standard encryption in transit most web applications implement. There is an interesting story (referenced below) that was using end-to-end encryption outside of the standard understanding. Check out what the differences are and what you can do to make sure you are thinking about how terms are used.References:Link to Article: https://www.esecurityplanet.com/threats/kohlers-smart-toilet-camera-isnt-actually-end-to-end-encrypted/Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  4. 130

    Ep. 126: Avoiding Panic and Misunderstandings with Proper Authentication Failure Reporting

    Have you ever felt that feeling of thinking your account has been compromised? It can be a scary feeling. But what about when it didn't really happen? Instead it was just confusing messaging.   That is what I talk about in this episode. The importance of proper messaging in the right context. Even the smallest thing can turn out to be a larger issue.References:Link to Article: https://www.bleepingcomputer.com/news/security/coinbase-to-fix-2fa-account-activity-entry-freaking-out-users/Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  5. 129

    Ep. 125: From Flat Tires to AppSec: The Power of Tools and Process

    In this episode, James shares a story about fixing a flat tire on an E-Scooter and how it relates to security. He shows how the combination of tools, process, and knowledge can lead to a successful outcome.Can you be successful without all three components? Maybe, but it might be more effort that is needed. Tune in to learn how these 3 components work together to create efficient solutions.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  6. 128

    Ep. 124: Double-ClickJacking

    In this episode, I go over what Double-ClickJacking is and what you can potentially do about it to reduce the risk to your applications. Will this be the new finding on everyone's pen tests this year?Paulos Yibelo first described Double-ClickJacking and you can read more from him at his post referenced below.References:Paulos Yibelo Blog: https://www.paulosyibelo.com/2024/12/doubleclickjacking-what.htmlSend us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  7. 127

    Ep. 123: Goals of Security Culture - Sort of?

    In this episode, I talk about how security is a part of everyone's role and the labeling of "Security Culture". I share some ideas on how to improve on role based security awareness and building stronger relationships between security and the rest of the organization.For more info go to https://www.developsec.com or follow us on X (@developsec).Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  8. 126

    Ep. 122: Integrating Security Responsibilities into Development

    In this episode I talk about assigning responsibility for secure development and how the dev and security teams should be working together to accomplish a common goal. I also discuss the importance of updating developer job descriptions and creating an expectation around developers having secure development experience.For more info go to https://www.developsec.com or follow us on X (@developsec).Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  9. 125

    Ep. 121 - Evolving Ransomware: Unique Tactics for Payment

    In this episode I talk about the evolving world of ransomware. I discuss a few examples of unique tactics the malicious actors are using to put pressure on organizations to pay the ransom.   Referenced Articles: https://www.theregister.com/AMP/2024/04/30/finnish_psychotherapy_center_crook_sentenced/ https://www.darkreading.com/cyber-risk/hackers-weaponize-sec-disclosure-rules-against-corporate-targets https://www.theregister.com/2024/01/05/swatting_extorion_tactics/   For more info go to https://www.developsec.com or follow us on X (@developsec).   DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  10. 124

    Ep. 120: Addressing Root Cause - Vulnerable Components

    In this episode we talk about addressing the root cause of an issue versus the symptoms. How can the process of keeping application components updated be improved?   For more info go to https://www.developsec.com or follow us on twitter (@developsec).   DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.  Transcript:In this episode, James talks about root cause analysis versus treating the symptoms.   Tackling the challenge to integrate security into the development process, looking for insights, answers and practical solutions to avoid getting overwhelmed. Welcome to the develop SEC podcast where our focus is your success in securing and improving development processes. And here's your host, James Jardine. Hey, everyone, welcome back to the show. Today, I want to talk about addressing the symptoms versus addressing the root problem. And I think in application security, or when we talk about secure development, this is something where a lot of times we address the symptoms, but we never really take the step back to address the actual root cause of what's causing those symptoms. And today, I want to actually talk about vulnerable third party components. This is something that has been kind of brought to the attention a lot more in the past few years, made it into the OWASP, top 10. And it's something I think everybody struggles with, we never know when we'll have a vulnerable third party component, because until somebody actually identifies a vulnerability, we just assume that we're good. And then on top of that, if there is a vulnerability identified, then we also run the chances that we're probably not even using that feature.  So vulnerable third party components are a really interesting aspect, when we think about secure development. Because there is a lot of unknowns, we may know that there's a vulnerability there. But the actual knowledge of do we use that piece and are we vulnerable, can be difficult, which, in the end, ends up adding a whole bunch of extra work and a whole lot of time for us to try to figure this out and address this stuff. And so this is where I talk about addressing the symptoms. In this case, in a lot of places, what we do is we address that symptom, we know that there's an issue of vulnerable third party components, right, that's the symptom, we have a vulnerable third party component. And so most places have some sort of process in place where we're going to identify these right, we're going to scan them all the time, whether using some of the common commercial tools, maybe you're using a free open source tool. But basically, the way it goes is I'm going to scan my repos or I'm going to scan my packages, and I'm going to look for all the dependencies, and then I'll look at their dependencies, and we'll see if there's any known vulnerable components within these right. And that requires having some sort of CVE out there that says, hey, somebody has found this, they've reported it, I remember requiring this to be a repSend us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  11. 123

    Ep. 119: Risks of SpellCheck

    In this episode we talk about the spell check feature of the browser and how it could present a risk to sensitive data.   Link to article referenced:  https://www.darkreading.com/application-security/spellchecking-google-chrome-microsoft-edge-browsers-leaks-passwords     For more info go to https://www.developsec.com or follow us on twitter (@developsec).   DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  12. 122

    Ep. 118: Log4J Sparking Thought on Vulnerable Components

    Log4J has been the talk of the town recently and everyone is focused on the technical details of the specific vulnerabilities found. In this episode, James talks about the overarching ideas around dealing with vulnerable components. Are you vulnerable? If so, what needs to be done?For more info go to https://www.developsec.com or follow us on twitter (@developsec).Join the conversations.. join our slack channel. Email [email protected] for an invitation. DevelopSec provides application security training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  13. 121

    Ep. 117: How Browsers are Helping with Security

    Chrome has announced a few changes that we need to watch out for in the near future. We previously talked about the default value for samesite that is coming up fast. I wrote about this here:  https://www.jardinesoftware.net/2019/10/28/samesite-by-default-in-2020/Also, they are getting ready to start blocking mixed content downloads: https://blog.chromium.org/2020/02/protecting-users-from-insecure.html For more info go to https://www.developsec.com or follow us on twitter (@developsec).Join the conversations.. join our slack channel. Email [email protected] for an invitation. DevelopSec provides application security training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  14. 120

    Ep. 116: Chrome Retires XSS Auditor

    It was recently announced that Chrome was dropping the XSS Auditor in Chrome 78. What does that mean and how does that change things for you as a developer?  https://www.chromium.org/developers/design-documents/xss-auditorFor more info go to https://www.developsec.com or follow us on twitter (@developsec).Join the conversations.. join our slack channel. Email [email protected] for an invitation. DevelopSec provides application security training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  15. 119

    Ep. 115: Is CSRF Really Dead?

    In 2020, Chrome will default the SameSite attribute to Lax on all cookies. SameSite helps mitigate CSRF, but does that mean CSRF is Dead?For more info go to https://www.developsec.com or follow us on twitter (@developsec).Join the conversations.. join our slack channel. Email [email protected] for an invitation. DevelopSec provides application security training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  16. 118

    Ep. 114: Investing in People for Better Application Security

    In this episode, James talks about investing in the development teams to increase application security priorities.For more info go to https://www.developsec.com or follow us on twitter (@developsec).Join the conversations.. join our slack channel. Email [email protected] for an invitation. DevelopSec provides application security training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  17. 117

    Ep. 113: What is your mother's maiden name?

    In this episode, James talks about some of the risks and recommendations around security questions and their implementation. For more info go to https://www.developsec.com or follow us on twitter (@developsec).Join the conversations.. join our slack channel. Email [email protected] for an invitation. DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  18. 116

    Ep. 112: Application Fingerprinting

    Does your application give away details about it server, framework, or other components?  How is this information used by an attacker? Check out this episode to learn more.For more info go to https://www.developsec.com or follow us on twitter (@developsec).Join the conversations.. join our slack channel. Email [email protected] for an invitation. DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  19. 115

    Ep. 111: Authentication Alerts

    Would you know if someone authenticated to your account? With the breaches we see in the news, and attacks like credential stuffing, there must be a way to be alerted to account access. James talks about authentication alerts, what they are, and why you may want to use them.For more info go to https://www.developsec.com or follow us on twitter (@developsec).Join the conversations.. join our slack channel. Email [email protected] for an invitation. DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  20. 114

    Ep. 110: Implementation Matters

    James discusses how implementation matters with security controls and how it changes priorities. This came about after reading the following story:  https://www.theverge.com/2018/12/31/18162541/vein-authentication-wax-hand-hack-starbugFor more info go to https://www.developsec.com or follow us on twitter (@developsec).Join the conversations.. join our slack channel. Email [email protected] for an invitation. DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  21. 113

    Ep. 109: 2018 Reflection

    I talk about some of what happened in 2018 and what I am looking to do in 2019. I also ask you to think about your previous year and goals. I also talk about some new training I am providing. For more info go to https://www.developsec.com or follow us on twitter (@developsec). Join the conversations.. join our slack channel. Email [email protected] for an invitation.   DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  22. 112

    Ep. 108: Dunkin Donuts Breach, Maybe??

    In this episode James talk about the Dunkin Donuts Perks breach. This is an interesting situation as the accounts were access using the victim's username and password found from another data breach. The issue: Password Reuse.  Could D&D have prevented this? Listen in to hear my thoughts.  Please feel free to share your thoughts as well.Article from Today: https://www.today.com/food/dunkin-reveals-security-breach-here-s-what-it-may-mean-t144139Dunkin Donuts Release: https://www.dunkindonuts.com/content/dam/dd/pdf/Security_Update.pdfFor more info go to https://www.developsec.com or follow us on twitter (@developsec).Join the conversations.. join our slack channel. Email [email protected] for an invitation. DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  23. 111

    Ep. 107: Credential Stuffing

    In this episode James talks about what credential stuffing is, how if affects your apps, and how you can look to defend against it.  For more info go to https://www.developsec.com or follow us on twitter (@developsec). Join the conversations.. join our slack channel. Email [email protected] for an invitation.   DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  24. 110

    Ep. 106: Facebook Breach Take-aways and Insights

    James talks about the Facebook breach and shares some insights into how you can take steps to prevent this type of incident in your applications.  For more info go to https://www.developsec.com or follow us on twitter (@developsec). Join the conversations.. join our slack channel. Email [email protected] for an invitation.   DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  25. 109

    Ep. 105: Interview with Eric Johnson

    I sit down with Eric Johnson to talk about security in the IDE and other fun topics. A bit longer than usual, but full of great information. You can reach out to Eric on twitter @emjohn20  or check out his site at https://www.pumascan.com. For more info go to https://www.developsec.com or follow us on twitter (@developsec). Join the conversations.. join our slack channel. Email [email protected] for an invitation.   DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  26. 108

    Ep. 104: Securing Devops with Julien Vehent

    James sits down with Julien Vehent to discuss his new book "Securing DevOps" and talk about security in a devOps world. Julien (@jvehent) is a security architect and engineering manager with over 15 years of experience in large organizations and web companies. He is currently responsible for the operational security of Firefox's backend infrastructure at Mozilla, and is the author of Securing DevOps.Check out the book (Securing DevOps) at https://www.manning.com/books/securing-devopsSpecial 40% discount code for Developsec listeners: poddevelopsec18 For more info go to https://www.developsec.com or follow us on twitter (@developsec). Join the conversations.. join our slack channel. Email [email protected] for an invitation.   DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  27. 107

    Ep. 103: Is 3rd Party Authentication Right For Your Application?

     The headlines are filled with credential breaches. One way to avoid being those headlines is to not store credentials. Instead, use a 3rd party to authenticate your users. While this cuts a lot of work out of your development time, it is important to understand the pros and cons to each method. James talks through some of these risks to help better understand which method might be right for you.   Links from show:Ep. 92: 2-Factor Authentication -  http://podcast.developsec.com/ep-92-2-factor-authenticationEp. 61: Multi-factor Authentication -  http://podcast.developsec.com/ep-61-multi-factor-authenticationEp. 39: Authentication - http://podcast.developsec.com/ep-39-authenticationEp. 2: All About Passwords -  http://podcast.developsec.com/ep-1-all-about-passwordsEp. 73: Identity with Vittorio Bertocci - http://podcast.developsec.com/ep-73-identity-with-vittorio-bertocci   For more info go to https://www.developsec.com or follow us on twitter (@developsec). Join the conversations.. join our slack channel. Email [email protected] for an invitation.   DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  28. 106

    Ep. 102: Intro to Web Security Policies

    In this episode James introduces us to the idea of web security policies stored in a security.txt file. We have talked about vulnerability disclosure before and this ties directly into that conversation.Link to Draft: https://tools.ietf.org/html/draft-foudil-securitytxt-03Link to form to create the file: https://securitytxt.org/Link to our blog post: https://www.developsec.com/2018/06/26/overview-of-web-security-policies/For more info go to https://www.developsec.com or follow us on twitter (@developsec).   Join the conversations.. join our slack channel.  Email [email protected] for an invitation.  DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  29. 105

    Ep. 101: You're not always right and that is ok

    In this episode, James shares a story of learning from a mistake and how we can't be right every time. Hear what he learned and how you can learn too. For more info go to https://www.developsec.com or follow us on twitter (@developsec). Join the conversations.. join our slack channel. Email [email protected] for an invitation.   DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  30. 104

    Ep. 100: Choosing Security Tools

    In this episode we talk about choosing the right security tools for your environment. There are lots of vendors offering solutions to help identify security issues within our applications. The trick is to learn to identify which ones make the most sense for your environment.   For more info go to https://www.developsec.com or follow us on twitter (@developsec). Join the conversations.. join our slack channel. Email [email protected] for an invitation.   DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  31. 103

    Ep. 99: Shifting Left in the SDLC

    In this episode, James talks about what it means to shift left in the SDLC.  For more info go to https://www.developsec.com or follow us on twitter (@developsec). Join the conversations.. join our slack channel. Email [email protected] for an invitation.   DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  32. 102

    Ep. 98: Efail and News Hype

    In this episode we talk about efail and the HYPE around security news.    For more info go to https://www.developsec.com or follow us on twitter (@developsec).   Join the conversations.. join our slack channel. Email [email protected] for an invitation.   DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  33. 101

    EP. 97: Gmail / Netflix Potential Scam

    ** Check out our new Live Fundamentals of Application Security training starting on May 1, 2018. Don't wait to sign up. For schedules and information check out https://www.jardinesoftware.com/fundamentals-of-application-security/ **In this episode, James shares his thoughts on an interesting scam potential was brought up regarding Gmail and Netflix. A lot of the discussion is on a unique Gmail feature most haven't heard of. James breaks this down in this episode.The original story was shared at  https://www.theregister.co.uk/2018/04/10/gmail_netflix_phishing_vector/   For more info go to https://www.developsec.com or follow us on twitter (@developsec). Join the conversations.. join our slack channel. Email [email protected] for an invitation.   DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  34. 100

    Ep. 96: Security Flaws as Defects

    In this episode we talk about treating security flaws as defects and embedded vs. built-in security. Do you treat security flaws differently? What barriers does that create?   For more info go to https://www.developsec.com or follow us on twitter (@developsec). Join the conversations.. join our slack channel. Email [email protected] for an invitation.   DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  35. 99

    Ep. 95: MyFitnessPal Breach Take-Aways

    In this episode we talk about the MyFitnessPal breach and some of the key points that we as developers, security, and users can take away from it.   Tweet with Graph of Largest Breaches mentioned: https://twitter.com/EricTopol/status/979556839015661568   Link to article about the breach:  https://www.cnet.com/news/millions-of-myfitnesspal-accounts-hacked-under-armour-says/   For more info go to https://www.developsec.com or follow us on twitter (@developsec). Join the conversations.. join our slack channel. Email [email protected] for an invitation.   DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  36. 98

    Ep. 94: Penetration Testing

    In this episode we talk about penetration testing and what you need to know to get the most out of the activity. Tune in to hear some of our thoughts on the topic.  To take the training course survey go to https://forms.office.com/Pages/ResponsePage.aspx?id=dUTTGKfrY0SMJRLyejG00DrfDtlb8W5HpqoXHgPDektUNDgxVU9SNlVRNVhXMTY4UUxSU041MFVWTC4u   For more info go to https://www.developsec.com or follow us on twitter (@developsec). Join the conversations.. join our slack channel. Email [email protected] for an invitation.   DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  37. 97

    Ep. 93: Code Review

    In this episode we talk about secure code review with a mention of static analysis. Do you know the difference? What is the issue of doing one over the other, or just outright replacing actual code review with static analysis? Tune in to hear some of our thoughts on the topic.   For more info go to https://www.developsec.com or follow us on twitter (@developsec). Join the conversations.. join our slack channel. Email [email protected] for an invitation.   DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  38. 96

    Ep. 92: 2-Factor Authentication

    In this episode James talks about 2-factor authentication, why we use it, and maybe why we don't. Is your 2-factor implementation getting in your way? The DevelopSec YouTube Channel - https://www.youtube.com/channel/UCdAqgfdGs0-hPa8FhsODwNw   For more info go to https://www.developsec.com or follow us on twitter (@developsec). Join the conversations.. join our slack channel. Email [email protected] for an invitation.   DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  39. 95

    DevelopSec Podcast #91 - OWASP Top 10 2017 Thoughts

    The new OWASP Top 10 2017 is out. We look at some of the changes and how you can effectively use the list to better your security program. We are also launching a new DevelopSec Live broadcast. To check out the first episode, go to https://www.youtube.com/watch?v=kfDuxwFScOE(The first 2 minutes are just a place holder as I was starting, feel free to skip those.  That will go away in future episodes). The DevelopSec YouTube Channel - https://www.youtube.com/channel/UCdAqgfdGs0-hPa8FhsODwNw For more info go to https://www.developsec.com or follow us on twitter (@developsec).Join the conversations.. join our slack channel. Email [email protected] for an invitation. DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  40. 94

    Ep. 90: 5 Steps to Help Secure Your Database

     James sits down with Perry Krug, from Couchbase to discuss some important steps to take to secure your database.   Perry Krug - https://twitter.com/perrykrug Couchbase - https://twitter.com/couchbase Couchbase - https://www.couchbase.com/ CouchbaseSecurity Documents -  https://developer.couchbase.com/documentation/server/current/security/security-intro.html   For more info go to https://www.developsec.com or follow us on twitter (@developsec). Join the conversations.. join our slack channel. Email [email protected] for an invitation.   DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  41. 93

    Ep. 89: New Year's Resolutions

     Welcome to 2018! Another year down and time for many of us to start making promises to ourselves of things we will start doing in this new year. In this episode James talks about some lessons we should take from 2017 and ways to use them in 2018.    For more info go to https://www.developsec.com or follow us on twitter (@developsec). Join the conversations.. join our slack channel. Email [email protected] for an invitation.   DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  42. 92

    Ep. 88: Meteor Security with Tim Medin

    In this episode, James talks with Tim Medin regarding Meteor and security. If you develop with Meteor or have to test it, there is a lot of information packed in.More about Tim Medin (@timmedin):Red Seige website - https://www.redsiege.com/ Link to Meteor Minor and other tools Tim mentioned:https://github.com/nidemTim Medin's Bsides Orlando 2017 Presentation - Tim Medin -  Mining Meteor B-Sides Orlando 2017 For more info go to https://www.developsec.com or follow us on twitter (@developsec). Join the conversations.. join our slack channel. Email [email protected] for an invitation. DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  43. 91

    Ep. 87: Apple Sign-in Bug Take-Aways

    You have heard about the Apple Sign-in Bug on High Sierra. Now lets talk about how we can use this example to better our current development processes to protect ourselves.Link to mentioned article:  https://www.theguardian.com/technology/2017/nov/30/apple-macos-high-sierra-fix-breaks-file-sharing-password-security-flaw-emergency-patch For more info go to https://www.developsec.com or follow us on twitter (@developsec).Join the conversations.. join our slack channel. Email [email protected] for an invitation.DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help. Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  44. 90

    Ep. 86: Vulnerable 3rd Party Components

    In this episode, James talks the use of 3rd party components and how to handle determining if they are vulnerable or not.Links: OWASP Dependancy Check - https://www.owasp.org/index.php/OWASP_Dependency_Check GitHub Blog - https://github.com/blog/2470-introducing-security-alerts-on-github RetireJS - https://retirejs.github.io/retire.js/ For more info go to https://www.developsec.com or follow us on twitter (@developsec).Join the conversations.. join our slack channel.  Email [email protected] for an invitation.DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  45. 89

    Ep. 85: Open Redirect Revisited

    In this episode, James talks about open redirect and why it matters from a security perspective. He also shows how this information can be used in your personal technology use, not just in development.  For more info go to https://www.developsec.com or follow us on twitter (@developsec).   Join the conversations.. join our slack channel.  Email [email protected] for an invitation.  DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  46. 88

    Ep. 84: Understanding the Technology

    You know your development language and platform, but do you really know the ins and outs of web application technology? How well do you know HTTP, HTML, etc? James talks about a few scenarios where really understanding how the technologies works helps better understand vulnerability risks.For more info go to https://www.developsec.com or follow us on twitter (@developsec).   Join the conversations.. join our slack channel.  Email [email protected] for an invitation.  DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  47. 87

    Ep. 83: Authorization Overview

    In this episode, James talks about authorization and some common areas where it poses a risk. He also goes over some techniques to help test authorization.  For more info go to https://www.developsec.com or follow us on twitter (@developsec).   Join the conversations.. join our slack channel.  Email [email protected] for an invitation.  DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  48. 86

    Ep. 82: Equifax Take-aways

    The Equifax breach was a major news story. James talks about some of the security controls mentioned and how to start a conversation within your organization about them. Want to listen on YouTube?  Check out our channel where we are releasing episodes starting from episode 1 at https://www.youtube.com/channel/UCdAqgfdGs0-hPa8FhsODwNwFor more info go to https://www.developsec.com or follow us on twitter (@developsec).Join the conversations.. join our slack channel.  Email [email protected] for an invitation.DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  49. 85

    Ep. 81: JavaScript in HREF and SRC (XSS)

    We talk about cross-site scripting (XSS) all the time, but often overlook the ability to use javascript: in anchor tags.  James talks about this unique ability and how to protect your applications from it. The related blog post for this can be found at https://www.developsec.com/2017/09/06/javascript-in-an-href-or-src-attribute/Want to listen on YouTube?  Check out our channel where we are releasing episodes starting from episode 1 at https://www.youtube.com/channel/UCdAqgfdGs0-hPa8FhsODwNwFor more info go to https://www.developsec.com or follow us on twitter (@developsec).Join the conversations.. join our slack channel.  Email [email protected] for an invitation.DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

  50. 84

    Ep. 80: Understanding Security of Your Platforms

    We use a lot of platforms and frameworks when we develop an application. These platforms may provide security features, but do you know which ones? James talks about the importance of understanding your platforms and what to consider.For more info go to https://www.developsec.com or follow us on twitter (@developsec).Join the conversations.. join our slack channel.  Email [email protected] for an invitation.DevelopSec provides application security consulting and training to add value to your application security program. Contact us today to see how we can help. Send us Fan MailFor more info go to https://www.developsec.com or follow us on X (@developsec).The DevelopSec podcast is brought to you by Jardine Software Inc. 

Type above to search every episode's transcript for a word or phrase. Matches are scoped to this podcast.

Searching…

We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.

No matches for "" in this podcast's transcripts.

Showing of matches

No topics indexed yet for this podcast.

Loading reviews...

ABOUT THIS SHOW

Curious about application security? Want to learn how to detect security vulnerabilities and protect your application. We discuss different topics and provide valuable insights into the world of application security.

HOSTED BY

Jardine Software Inc.

Frequently Asked Questions

How many episodes does DevelopSec: Developing Security Awareness have?

DevelopSec: Developing Security Awareness currently has 50 episodes available on PodParley. New episodes are automatically indexed when they're published to the podcast feed.

What is DevelopSec: Developing Security Awareness about?

Curious about application security? Want to learn how to detect security vulnerabilities and protect your application. We discuss different topics and provide valuable insights into the world of application security.

How often does DevelopSec: Developing Security Awareness release new episodes?

DevelopSec: Developing Security Awareness has 50 episodes. Check the episode list to see recent publication dates and frequency.

Where can I listen to DevelopSec: Developing Security Awareness?

You can listen to DevelopSec: Developing Security Awareness on PodParley by clicking any episode. We provide an embedded audio player for direct listening, and you can also subscribe via your preferred podcast app using the RSS feed.

Who hosts DevelopSec: Developing Security Awareness?

DevelopSec: Developing Security Awareness is created and hosted by Jardine Software Inc..
URL copied to clipboard!