
Mark Curphey and John Viega -- Chalk
Om avsnittet
Development, operations, and security teams generate oceans of data yet still struggle to answer basic questions about what code is running, who owns it, and which findings matter. OWASP founder Mark Curphey and security veteran John Viega introduce Chalk, an open-source telemetry and observability tool designed to connect repositories, builds, deployments, and production systems. They explain how better provenance can eliminate irrelevant alerts, prioritize deployed software, trace incidents back to owners and commits, and confirm that fixes actually reached production. The conversation covers small-company and enterprise use cases, lessons from Log4Shell, performance overhead, supported platforms, and Chalk’s event model. Mark and John also discuss open-source sustainability and the Software Security Project before closing with candid views on where application security gets priorities wrong.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Mark Curphey and John Viega:
→ Mark Curphey on LinkedIn
→ John Viega on LinkedIn
→ Chalk
→ Crash Override
Mentioned in this episode:
→ Crash Override
→ Chalk
→ The Software Security Project
→ Atomic Habits
→ Start With Why
→ OWASP ZAP
→ Sigstore
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet Mark Curphey and John Viega: Chalk
01:46 John’s path into application security
04:20 The de facto silos separating development and production
07:52 Chalk as telemetry for software engineering
12:12 Why startups also need production visibility
15:18 Log4Shell and the challenge of finding deployed software
17:08 How security teams can use Chalk
23:10 Chalk’s performance impact in production
25:00 Supported platforms and frameworks
28:00 Events, protocols, and outbound telemetry
42:18 Holding commercial users of open source accountable
46:32 Controversial opinions about AppSec
48:09 Industry messages, books, and closing thoughts
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.