• November’s ASW turned into Adrian Sanabria Weekly!

    SW logo

    Episode 306

    The month kicked off with Grant McCracken discussing bug bounties and a modern approach to pentesting. While I would still love to see the costs of fixing flaws, seeing the costs of security flaws quantified through bounties is always eye-opening. Plus, it’s always good to see other approaches to security testing that carry a more predictable budget. Now if only those bugs didn’t make it to production in the first place…

    Episode 307

    Melinda Marks returned to the show to talk about what modern appsec practices look like and why appsec needs to catch up to how modern apps are created. Unsurprisingly, “cloud native” comes up in the conversation, but there are important nods to orgs stuck with figuring out how to keep their legacy apps alive.

    This also had a fun news segment with John Kinsella that covered everything from a very-minimum-max-critical bug to infotainment vulns to demastering pop punk like it was meant to be. (Special shout out to Adrian for keeping a music-related theme going for the show.)

    Episode 308

    The month wrapped up with the biometric frontiers of security, resiliency, and privacy. Adrian spoke with Andras Cser and Enza Iannopollo on the benefits of biometrics and steps to keeping them secure.

    This episode also had a news segment with a ton of articles that I would have had strong reactions to, from LLMs doing everything! (lol, no) to safer C++ (positive performance, but pessimistic prospects for the language overall).

    Subscribe to ASW to find these episodes and more! Also check out the October 2024 recap.

    ASW on Apple Podcasts

    • • •
  • LLMs and generative AI were unavoidable appsec topics this year. Here’s a recap of some relevant articles and associated interviews.

    SW logo

    Background

    Prompt injection & manipulating models

    Finding flaws & augmenting appsec

    Episode 284 (segment 1)

    Caleb Sima demystified some of the hype around AI and pointed out how a lot of its security needs match the mundane maintenance of building software. We didn’t get into defining all the different types of AIs, but we did identify the need for more focus on identity and authenticity in a world where LLMs craft user-like content.

    Episode 284 (segment 2)

    Keith Hoodlet stopped by to talk about his first-place finish in the DoD’s inaugural AI Bias bug bounty program. He showed how manipulating prompts leads to unintentional and undesired outcomes. Keith also explained how he needed to start fresh in terms of techniques since there’s no deep resources on how to conduct these kinds of tests.

    Be sure to check these out for my variants on the “walks into a bar” joke.

    Episode 285

    The AI conversations continued with Sandy Dunn, who shared how the OWASP Top 10 for LLMs came about and how it continues to evolve. We talked about why this Top 10 has a mix of items specific to LLMs and items that are indistinguishable from securing any other type of software. It reinforced a lot of the ideas that we had talked about with Caleb the week before.

    Episode 291

    Stuart McClure walked through the implications in trusting AI and LLMs to find flaws and fix code. The fixing part is compelling – as long as that fix preserves the app’s intended behavior. He explains how LLMs combined with agents and RAGs have the potential to assist developers in writing secure code.

    Episode 292

    Allie Mellen pointed out where elements of LLM might help with reporting and summarizing knowledge, but where they also fall short of basic security practices. LLMs won’t magically create an asset inventory, nor will they have context about your environment or your approach to risk. She also notes where AI has been present for years already – we just call it machine learning as applied to things like fraud detection and behavioral analysis.

    Subscribe to ASW to find these episodes and more!

    ASW on Apple Podcasts

    • • •
  • October was the month when tales of terror became timely and the days took a fearful turn towards Halloween.

    I love Halloween and horror movies. A favorite recent series is “The Edge of Sleep” (which originated as a podcast). The found footage genre is near and dear to my heart, so I also have to recommend “Deadstream” as another recent-ish favorite.

    SW logo

    Episode 302

    We started a new month with an old friend. Simon Bennetts returned, along with Ori Bendet, to talk about ZAP’s new collaboration with Checkmarx.

    We first talked about building ZAP and its community with Simon over a year ago in episode 254. Then he and Mark Curphy stopped by in April to talk about finding sustainable funding for the project. It’s great to see ZAP now have long-term support and, as Simon explained, how that support will create new opportunities for ZAP to expand its features.

    Episode 303

    Then Kalyani Pawar joined as a new co-host! We celebrated episode 303 by having the three of us talk about striking appsec fear in three words – like, “written in Perl” or “cybersecurity awareness month”…

    There was plenty of news to cover, from how many vulns legacy code can hold to how many parsers you can pack into a package. As always, John Kinsella added his insights on secure defaults, isolating resources, and wrangling repos.

    Episode 304

    Scott Piper shared some advice on how to ratchet up security within an org’s environment, why securing clouds (and creating those guardrails) remains complex, and some tips on tracking down shadow clouds.

    Creating guardrails within clouds has become a favored appsec design pattern that increases security without sacrificing development – when they’re done well.

    Despite all those clouds, he shed lots of light onto strategies for enacting change that makes secure defaults better for everyone!

    Episode 305

    Adrian Sanabria stopped by for our almost-Halloween episode.

    The two of us talked about some appsec lessons inspired from the slow transition to IPv6, fun hardware hacking stories, and my hypothesis that on a CPU-cycle-per-CPU-cycle basis fuzzing will outshine LLMs for finding flaws.

    It was also nice for Adrian to stop by since I’ll be out for a few episodes in November and he’ll be stepping in.

    We won’t have to change a thing. Just think of ASW as Adrian Sanabria Weekly…

    Subscribe to ASW to find these episodes and more! Also check out the September 2024 recap.

    ASW on Apple Podcasts

    • • •