Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Liran Tal — Cloud native application security, what’s a developer to do?

42 min9 mars 2021

Om avsnittet

Cloud-native development gives engineers control over more of the stack, but it also gives them more security decisions to get wrong. Liran Tal, an open-source contributor and developer advocate, joins Chris and Robert to explore that expanding responsibility. They define cloud-native applications, examine containers and infrastructure as code, and discuss how security ownership changes when developers choose runtimes, dependencies, and deployment configurations. Liran explains why vulnerability severity alone is a poor guide to remediation and why usable feedback matters more than another long list of findings. The conversation also covers practical container-building mistakes, production behavior, and the value of asking what could go wrong while writing code. His advice centers on awareness, helpful defaults, and tools that support developers.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Liran Tal:
Liran Tal’s website

Mentioned in this episode:
Node.js
Docker
Kubernetes
Snyk

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Cloud-native application security with Liran Tal
05:25 Defining cloud-native development
07:26 What is changing in the cloud-native stack
09:36 Who owns application and infrastructure security
13:32 Security in the local developer workflow
15:15 Threats in cloud-native applications
16:46 Infrastructure as code and security visibility
22:08 Least privilege and cloud configuration
24:12 Helping developers take on new responsibilities
27:27 AppSec practices in a cloud-native world
29:31 Prioritizing vulnerabilities beyond severity
31:49 Giving developers the tools to help themselves
33:08 Building safer Node.js container images
37:10 Differences between development and production
38:40 Practical takeaways and a threat modeling mindset

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.