Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Chris and Robert -- Controversy within the OWASP Top 10 RC

31 min30 maj 2017

Om avsnittet

Why did the 2017 OWASP Top 10 release candidate provoke such a strong reaction? Chris and Robert walk through the proposed categories, compare them with earlier editions, and examine the project’s role as both awareness document and de facto testing target. They discuss merged and removed risks, injection, authentication, sensitive data, XML external entities, access control, cross-site scripting, insecure deserialization, components with known vulnerabilities, and insufficient attack protection. The hosts question whether new categories are sufficiently general, whether tools and frameworks already address some risks, and how modern APIs and microservices affect the list. The episode preserves the uncertainty of a release-candidate debate while helping listeners understand the technical and governance questions behind a widely used standard.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Chris Romeo and Robert Hurlbut:
Chris Romeo on LinkedIn
Robert Hurlbut on LinkedIn

Mentioned in this episode:
OWASP Top 10
OWASP Top 10 2017
OWASP AppSensor Project
OWASP Top 10 A9 (Using Components with Known Vulnerabilities)

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 The controversial OWASP Top 10 candidate
01:25 The Top 10’s history and influence
03:17 How tools use the list
05:08 Reaction to the 2017 release candidate
06:36 Merged and renamed categories
08:01 Removed risks
09:20 Framework protections and remaining responsibility
11:13 Injection and authentication
13:47 Which risks apply beyond web applications
15:14 Cross-site scripting and browser defenses
16:46 Access control must be consistent
18:37 Automating security verification
20:20 Insufficient attack protection
22:01 Application-level detection and response
23:53 Insecure deserialization
25:48 Components with known vulnerabilities
27:09 APIs, microservices, and attack surface
29:00 Security through obscurity
31:00 Final assessment of the candidate

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.