
Daniel Miessler -- OWASP IoT Top 10
Om avsnittet
An IoT product’s attack surface extends well beyond the device in the box. Daniel Miessler explains that broader view while walking Chris and Robert through the 2018 OWASP IoT Top 10. Before reviewing the risks, he describes the project’s audience, how the team gathered and evaluated data, and the challenge of balancing recurring failures with emerging concerns. The list covers passwords, exposed services, ecosystem interfaces, updates, components, privacy, data protection, device management, defaults, and physical hardening. Real testing examples show how a secure-looking connection can hide other unprotected paths or services. Daniel closes with guidance for developers who want to understand their product’s full ecosystem and use the list as a starting point for better security decisions.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Daniel Miessler:
→ Daniel Miessler
→ OWASP Internet of Things project
Mentioned in this episode:
→ OWASP Application Security Verification Standard
→ OWASP Proactive Controls
→ National Vulnerability Database
→ Cloud Security Alliance
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 The 2018 IoT Top 10 with Daniel Miessler
01:27 Daniel’s security origin story
04:25 Why the IoT Top 10 exists
07:30 Manufacturers, developers, and other audiences
11:56 Gathering data and deciding the rankings
19:27 Historical findings and emerging risks
22:39 Passwords and insecure network services
24:23 Insecure ecosystem interfaces
26:13 Lack of secure update mechanisms
28:31 Insecure or outdated components
30:41 Privacy and unexpected connections
33:05 Data protection at rest and in transit
35:29 Device management and insecure defaults
37:45 Physical hardening
40:18 Takeaways for developers
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.