Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Björn Kimminich — The new JuiceShop, GSOC, and Open Security Summit

29 min1 juni 2019

Om avsnittet

How do you keep an intentionally vulnerable application useful while its underlying frameworks keep fixing bugs? Björn Kimminich returns with an update on OWASP Juice Shop and the work required to maintain realistic security challenges. He describes new exercises involving promotional content, coupons, privacy, and two-factor authentication, then explains what happens when dependency or browser changes accidentally remove a vulnerability. The conversation also covers customization for different audiences, contributions through Google Summer of Code, and the balance between welcoming help and reviewing it carefully. Björn closes with plans for collaborative work at the 2019 Open Security Summit. This archive episode shows both the technical craft and community effort behind a widely used application security learning project.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Björn Kimminich:
Björn Kimminich on GitHub

Mentioned in this episode:
OWASP Juice Shop
Open Security Summit

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 What was new in OWASP Juice Shop
02:25 New features and hacking challenges
05:19 Working two-factor authentication with TOTP
07:21 Keeping the right parts intentionally vulnerable
08:15 When dependency updates remove a challenge
09:43 Privacy features and GDPR-related exercises
11:16 Customizing Juice Shop for different audiences
13:05 Google Summer of Code contributions
16:14 Reviewing contributions and sharing maintenance
17:09 Getting help and giving feedback
19:22 Introducing the 2019 Open Security Summit
21:42 Planned Juice Shop working sessions
24:50 Adapting the summit around participants’ needs
26:30 Where to find Juice Shop resources

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.