Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

David Habusha -- Third Party Software is not a Cathedral, It’s a Bazaar

37 min13 april 2018

Om avsnittet

An application can inherit serious vulnerabilities from code its developers never wrote. David Habusha, then a product leader at WhiteSource, explains the problem behind the 2017 OWASP Top 10 category on components with known vulnerabilities. He brings a product-management perspective to the discussion, connecting dependency choices to business outcomes and the realities of modern development. Chris and Robert ask why static and dynamic testing may miss this problem, what software composition analysis actually identifies, and how accurate component matching can be. The conversation uses Apache Struts and the Equifax breach to examine inventory, notification, and remediation. David closes by describing open source as a bazaar rather than a cathedral, where continuous awareness and maintenance matter more than expecting any component to remain permanently safe.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with David Habusha:
David Habusha on LinkedIn

Mentioned in this episode:
OWASP Top 10 2017 — Vulnerable Components
WhiteSource — now Mend.io
Apache Struts vulnerability CVE-2017-5638

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Understanding vulnerable third-party components
01:30 David’s security background
04:09 A product manager’s perspective on AppSec
08:48 What components with known vulnerabilities means
12:28 How much software comes from dependencies?
14:54 The consequences of vulnerable components
18:14 Why SAST and DAST are not enough
20:35 What software composition analysis does
24:02 Accuracy and component identification
27:29 What the Equifax breach teaches about SCA
32:58 Why dependency security is continuous work

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.