All Episodes
DevelopSec: Developing Security Awareness — 133 episodes
Ep. 129: When Security Recommendations Miss The Point
Ep. 128: OWASP Top 10 2025
Ep. 127: Importance of Terminology
Ep. 126: Avoiding Panic and Misunderstandings with Proper Authentication Failure Reporting
Ep. 125: From Flat Tires to AppSec: The Power of Tools and Process
Ep. 124: Double-ClickJacking
Ep. 123: Goals of Security Culture - Sort of?
Ep. 122: Integrating Security Responsibilities into Development
Ep. 121 - Evolving Ransomware: Unique Tactics for Payment
Ep. 120: Addressing Root Cause - Vulnerable Components
Ep. 119: Risks of SpellCheck
Ep. 118: Log4J Sparking Thought on Vulnerable Components
Ep. 117: How Browsers are Helping with Security
Ep. 116: Chrome Retires XSS Auditor
Ep. 115: Is CSRF Really Dead?
Ep. 114: Investing in People for Better Application Security
Ep. 113: What is your mother's maiden name?
Ep. 112: Application Fingerprinting
Ep. 111: Authentication Alerts
Ep. 110: Implementation Matters
Ep. 109: 2018 Reflection
Ep. 108: Dunkin Donuts Breach, Maybe??
Ep. 107: Credential Stuffing
Ep. 106: Facebook Breach Take-aways and Insights
Ep. 105: Interview with Eric Johnson
Ep. 104: Securing Devops with Julien Vehent
Ep. 103: Is 3rd Party Authentication Right For Your Application?
Ep. 102: Intro to Web Security Policies
Ep. 101: You're not always right and that is ok
Ep. 100: Choosing Security Tools
Ep. 99: Shifting Left in the SDLC
Ep. 98: Efail and News Hype
EP. 97: Gmail / Netflix Potential Scam
Ep. 96: Security Flaws as Defects
Ep. 95: MyFitnessPal Breach Take-Aways
Ep. 94: Penetration Testing
Ep. 93: Code Review
Ep. 92: 2-Factor Authentication
DevelopSec Podcast #91 - OWASP Top 10 2017 Thoughts
Ep. 90: 5 Steps to Help Secure Your Database
Ep. 89: New Year's Resolutions
Ep. 88: Meteor Security with Tim Medin
Ep. 87: Apple Sign-in Bug Take-Aways
Ep. 86: Vulnerable 3rd Party Components
Ep. 85: Open Redirect Revisited
Ep. 84: Understanding the Technology
Ep. 83: Authorization Overview
Ep. 82: Equifax Take-aways
Ep. 81: JavaScript in HREF and SRC (XSS)
Ep. 80: Understanding Security of Your Platforms
Ep. 79: Marketing with USB Drives
Ep. 78: MySpace Lessons - Looking At Account Recovery
Ep. 77: Interactive Application Security Testing
Ep. 76: Validation - Client vs. Server
Ep. 75: IAM with Geurt van Wijk
Ep. 74: Audio Driver Key Logger Lessons Learned
Ep. 73: Identity with Vittorio Bertocci
Ep. 72: Where to Perform Output Encoding
Ep. 71: Sub Resource Integrity
Ep. 70: Considering security when selecting an application platform
Ep. 69: Concurrent User Sessions
Ep. 68: How the AWS disruption can help us
Ep. 67: Clearing up HTTPOnly and Secure Cookie Attributes
Ep. 66: Forgot Username
Ep. 65: Security Questions: Good or Bad?
Ep. 64: Using Stolen Passwords to Protect User Accounts
Ep. 63: Remember Me Feature: Security Considerations
Ep. 62: MongoDB Ransomware Attacks
Ep. 61: Multi-factor Authentication
Ep. 60: Yahoo Breach Takeaways
Ep. 59: All About Cookie Protection
Ep. 58: "Untrusted" Data
Ep. 57: Source Code Review
Ep. 56: Security Contacts
Ep. 55: Scoping an application security assessment (Applications)
Ep. 54: WAFs and Pen Testing
Ep. 53: Chrome Changing Secure Notifications
Login Forms and HTTPS
Ep. 52: Importance of UI to Security
Ep. 51: Everything is a target
Ep. 50: How Serious is Username Enumeration
Ep. 49: Should Password Change Invalidate Access Tokens?
Ep. 48: Pokemon Go Security Discussions
Ep. 47: Account Lockouts and auto-unlock
Ep. 46: Password Confirm Boxes
Ep. 45: The importance of WHY
Ep. 44: "We don't support Macs"
Ep. 43: Reflecting on Current AppSec Training
Ep. 42: The Need for Better Secure Code Examples
Ep. 41: Why You Need an Application Inventory
Ep. 40: Getting More Value from Pen Tests
Ep. 39: Authentication
Ep. 38: Static Analysis: Tips for Successful Program
Ep. 37: CSRF Chaining
Ep. 36: Intro to Cross Site Request Forgery (CSRF)
Ep. 35: An Introduction to Open Redirects
Ep. 34: Importance of Hacking
Ep. 33: Holiday Gift Security Considerations
Ep. 32: Dynamic Analysis: An Overview
Ep. 31: Response Splitting and Header Injection
Newscast - Oct. 20, 2015
Newscast - Sept. 30, 2015
Newscast - Sept. 23, 2015
Ep. 30: HTTP Strict Transport Security (HSTS): Intro
Ep. 29: FTC Start with Security Guidelines
Ep. 28: What is Penetration Testing
Ep. 27: Importance of Security for BA and PM
Ep. 26: The Importance of Security for QA
Ep. 25: Static Analysis: Analyzing the Options
Ep. 24: The Importance of Baselines
Ep. 23: 3rd Party CMS Security Thoughts
Ep. 22: Black lists vs. White Lists
Ep. 21: Sensitive Data and Storage
EP. 20: MoonPig Take-aways
Ep. 19: Target Environments
Ep. 18: Planning for an Assessment
Ep. 17: Authorization
Ep. 16: The Cloud: Is it Safe?
Ep. 15: Security Testing - QA can do this!!
Ep. 14: Input Validation and Output Encoding
Ep. 13: Introduction to Cross Site Scripting
DS: Ep 12: Ebay hacked. All about Cookies
Ep. 11: Not your Grandpa's Phishing
Ep. 10: Threat Modeling
Ep. 9: Windows XP and HeartBleed
Ep. 8: Oversharing is not Caring
Ep. 7: Data Breaches
Ep. 6: Mobile Security
Ep. 5: SQL Injection
Ep. 4: Web Proxies
Ep. 3:Connected System Security
Ep. 2: All About Passwords
Ep. 1: Introduction to the Podcast