DevelopSec: Developing Security Awareness cover art

All Episodes

DevelopSec: Developing Security Awareness — 133 episodes

#
Title
1

Ep. 129: When Security Recommendations Miss The Point

2

Ep. 128: OWASP Top 10 2025

3

Ep. 127: Importance of Terminology

4

Ep. 126: Avoiding Panic and Misunderstandings with Proper Authentication Failure Reporting

5

Ep. 125: From Flat Tires to AppSec: The Power of Tools and Process

6

Ep. 124: Double-ClickJacking

7

Ep. 123: Goals of Security Culture - Sort of?

8

Ep. 122: Integrating Security Responsibilities into Development

9

Ep. 121 - Evolving Ransomware: Unique Tactics for Payment

10

Ep. 120: Addressing Root Cause - Vulnerable Components

11

Ep. 119: Risks of SpellCheck

12

Ep. 118: Log4J Sparking Thought on Vulnerable Components

13

Ep. 117: How Browsers are Helping with Security

14

Ep. 116: Chrome Retires XSS Auditor

15

Ep. 115: Is CSRF Really Dead?

16

Ep. 114: Investing in People for Better Application Security

17

Ep. 113: What is your mother's maiden name?

18

Ep. 112: Application Fingerprinting

19

Ep. 111: Authentication Alerts

20

Ep. 110: Implementation Matters

21

Ep. 109: 2018 Reflection

22

Ep. 108: Dunkin Donuts Breach, Maybe??

23

Ep. 107: Credential Stuffing

24

Ep. 106: Facebook Breach Take-aways and Insights

25

Ep. 105: Interview with Eric Johnson

26

Ep. 104: Securing Devops with Julien Vehent

27

Ep. 103: Is 3rd Party Authentication Right For Your Application?

28

Ep. 102: Intro to Web Security Policies

29

Ep. 101: You're not always right and that is ok

30

Ep. 100: Choosing Security Tools

31

Ep. 99: Shifting Left in the SDLC

32

Ep. 98: Efail and News Hype

33

EP. 97: Gmail / Netflix Potential Scam

34

Ep. 96: Security Flaws as Defects

35

Ep. 95: MyFitnessPal Breach Take-Aways

36

Ep. 94: Penetration Testing

37

Ep. 93: Code Review

38

Ep. 92: 2-Factor Authentication

39

DevelopSec Podcast #91 - OWASP Top 10 2017 Thoughts

40

Ep. 90: 5 Steps to Help Secure Your Database

41

Ep. 89: New Year's Resolutions

42

Ep. 88: Meteor Security with Tim Medin

43

Ep. 87: Apple Sign-in Bug Take-Aways

44

Ep. 86: Vulnerable 3rd Party Components

45

Ep. 85: Open Redirect Revisited

46

Ep. 84: Understanding the Technology

47

Ep. 83: Authorization Overview

48

Ep. 82: Equifax Take-aways

49

Ep. 81: JavaScript in HREF and SRC (XSS)

50

Ep. 80: Understanding Security of Your Platforms

51

Ep. 79: Marketing with USB Drives

52

Ep. 78: MySpace Lessons - Looking At Account Recovery

53

Ep. 77: Interactive Application Security Testing

54

Ep. 76: Validation - Client vs. Server

55

Ep. 75: IAM with Geurt van Wijk

56

Ep. 74: Audio Driver Key Logger Lessons Learned

57

Ep. 73: Identity with Vittorio Bertocci

58

Ep. 72: Where to Perform Output Encoding

59

Ep. 71: Sub Resource Integrity

60

Ep. 70: Considering security when selecting an application platform

61

Ep. 69: Concurrent User Sessions

62

Ep. 68: How the AWS disruption can help us

63

Ep. 67: Clearing up HTTPOnly and Secure Cookie Attributes

64

Ep. 66: Forgot Username

65

Ep. 65: Security Questions: Good or Bad?

66

Ep. 64: Using Stolen Passwords to Protect User Accounts

67

Ep. 63: Remember Me Feature: Security Considerations

68

Ep. 62: MongoDB Ransomware Attacks

69

Ep. 61: Multi-factor Authentication

70

Ep. 60: Yahoo Breach Takeaways

71

Ep. 59: All About Cookie Protection

72

Ep. 58: "Untrusted" Data

73

Ep. 57: Source Code Review

74

Ep. 56: Security Contacts

75

Ep. 55: Scoping an application security assessment (Applications)

76

Ep. 54: WAFs and Pen Testing

77

Ep. 53: Chrome Changing Secure Notifications

78

Login Forms and HTTPS

79

Ep. 52: Importance of UI to Security

80

Ep. 51: Everything is a target

81

Ep. 50: How Serious is Username Enumeration

82

Ep. 49: Should Password Change Invalidate Access Tokens?

83

Ep. 48: Pokemon Go Security Discussions

84

Ep. 47: Account Lockouts and auto-unlock

85

Ep. 46: Password Confirm Boxes

86

Ep. 45: The importance of WHY

87

Ep. 44: "We don't support Macs"

88

Ep. 43: Reflecting on Current AppSec Training

89

Ep. 42: The Need for Better Secure Code Examples

90

Ep. 41: Why You Need an Application Inventory

91

Ep. 40: Getting More Value from Pen Tests

92

Ep. 39: Authentication

93

Ep. 38: Static Analysis: Tips for Successful Program

94

Ep. 37: CSRF Chaining

95

Ep. 36: Intro to Cross Site Request Forgery (CSRF)

96

Ep. 35: An Introduction to Open Redirects

97

Ep. 34: Importance of Hacking

98

Ep. 33: Holiday Gift Security Considerations

99

Ep. 32: Dynamic Analysis: An Overview

100

Ep. 31: Response Splitting and Header Injection

101

Newscast - Oct. 20, 2015

102

Newscast - Sept. 30, 2015

103

Newscast - Sept. 23, 2015

104

Ep. 30: HTTP Strict Transport Security (HSTS): Intro

105

Ep. 29: FTC Start with Security Guidelines

106

Ep. 28: What is Penetration Testing

107

Ep. 27: Importance of Security for BA and PM

108

Ep. 26: The Importance of Security for QA

109

Ep. 25: Static Analysis: Analyzing the Options

110

Ep. 24: The Importance of Baselines

111

Ep. 23: 3rd Party CMS Security Thoughts

112

Ep. 22: Black lists vs. White Lists

113

Ep. 21: Sensitive Data and Storage

114

EP. 20: MoonPig Take-aways

115

Ep. 19: Target Environments

116

Ep. 18: Planning for an Assessment

117

Ep. 17: Authorization

118

Ep. 16: The Cloud: Is it Safe?

119

Ep. 15: Security Testing - QA can do this!!

120

Ep. 14: Input Validation and Output Encoding

121

Ep. 13: Introduction to Cross Site Scripting

122

DS: Ep 12: Ebay hacked. All about Cookies

123

Ep. 11: Not your Grandpa's Phishing

124

Ep. 10: Threat Modeling

125

Ep. 9: Windows XP and HeartBleed

126

Ep. 8: Oversharing is not Caring

127

Ep. 7: Data Breaches

128

Ep. 6: Mobile Security

129

Ep. 5: SQL Injection

130

Ep. 4: Web Proxies

131

Ep. 3:Connected System Security

132

Ep. 2: All About Passwords

133

Ep. 1: Introduction to the Podcast