Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Nancy Gariché and Tanya Janca — DevSlop, the movement

38 min21 maj 2019

Om avsnittet

How does an intentionally vulnerable application become a community learning movement? Nancy Gariché and Tanya Janca explain the evolution of OWASP DevSlop from a project into a live, collaborative way to teach application security. They describe the DevSlop Show, its deliberately imperfect demonstrations, and the value of learning in public without pretending every experiment will work. The conversation explores Pixi, Paddy the Pipeline, and integrations with free security tools including ZAP, dependency scanning, and web application firewalls. Nancy and Tanya also explain how contributors can start small, join broadcasts, document what they learn, and help expand the project. Their approach treats mistakes as useful teaching material and makes hands-on AppSec education more welcoming to developers and security newcomers.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Nancy Gariché and Tanya Janca:
Nancy Gariché and OWASP DevSlop
Tanya Janca on LinkedIn

Mentioned in this episode:
OWASP DevSlop
Pixi
OWASP ZAP
Burp Suite
Mend
OWASP ModSecurity Core Rule Set
Qualys SSL Labs

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 DevSlop as a movement
02:11 Meet Nancy Gariché and Tanya Janca
05:11 What OWASP DevSlop is
09:03 API security and the project’s scope
11:14 Learning through the DevSlop Show
16:15 Security tools in Paddy the Pipeline
18:47 Dependency scanning with Mend
21:36 Web application firewalls and ModSecurity
23:45 Making mistakes in public
27:47 How new contributors can begin
30:46 Community participation as the real output
32:51 DevSlop’s channels and identity
36:55 Closing thoughts

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.