
Chris and Robert -- Controversy within the OWASP Top 10 RC
Om avsnittet
Why did the 2017 OWASP Top 10 release candidate provoke such a strong reaction? Chris and Robert walk through the proposed categories, compare them with earlier editions, and examine the project’s role as both awareness document and de facto testing target. They discuss merged and removed risks, injection, authentication, sensitive data, XML external entities, access control, cross-site scripting, insecure deserialization, components with known vulnerabilities, and insufficient attack protection. The hosts question whether new categories are sufficiently general, whether tools and frameworks already address some risks, and how modern APIs and microservices affect the list. The episode preserves the uncertainty of a release-candidate debate while helping listeners understand the technical and governance questions behind a widely used standard.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Chris Romeo and Robert Hurlbut:
→ Chris Romeo on LinkedIn
→ Robert Hurlbut on LinkedIn
Mentioned in this episode:
→ OWASP Top 10
→ OWASP Top 10 2017
→ OWASP AppSensor Project
→ OWASP Top 10 A9 (Using Components with Known Vulnerabilities)
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 The controversial OWASP Top 10 candidate
01:25 The Top 10’s history and influence
03:17 How tools use the list
05:08 Reaction to the 2017 release candidate
06:36 Merged and renamed categories
08:01 Removed risks
09:20 Framework protections and remaining responsibility
11:13 Injection and authentication
13:47 Which risks apply beyond web applications
15:14 Cross-site scripting and browser defenses
16:46 Access control must be consistent
18:37 Automating security verification
20:20 Insufficient attack protection
22:01 Application-level detection and response
23:53 Insecure deserialization
25:48 Components with known vulnerabilities
27:09 APIs, microservices, and attack surface
29:00 Security through obscurity
31:00 Final assessment of the candidate
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.