
Niels Tanis — 3rd Party Risk in a .NET World
Om avsnittet
How much behavior do you inherit when you add one library to a .NET application? Niels Tanis joins Chris and Robert to examine third-party risk beyond checking a dependency for known vulnerabilities. They revisit the event-stream compromise and Operation ShadowHammer, then look at NuGet packages, transitive dependencies, and functionality developers may never intend to use. A PDF library becomes a concrete example of why network access and other capabilities deserve scrutiny. Niels explores isolation, assembly loading, and constraining library behavior rather than trusting every dependency with the application's full privileges. He also describes using Mono.Cecil and his Fennec tooling to inspect calls, helping developers ask better questions about what their dependencies can actually do.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Niels Tanis:
→ LinkedIn
→ Niels's blog
Mentioned in this episode:
→ NuGet
→ iTextSharp
→ Operation ShadowHammer
→ Mono.Cecil
→ Fennec.CLI
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Introduction
03:03 What third-party risk really includes
06:25 Compromised dependencies and event-stream
11:08 Operation ShadowHammer and trusted updates
14:04 Dependency risk in the .NET ecosystem
17:03 Hidden capabilities inside familiar libraries
21:51 Isolation and least privilege
23:48 Constraining libraries with assembly loading
28:42 Controlling behavior and micropatches
30:21 Inspecting calls with Mono.Cecil and Fennec
34:14 Making dependency reviews useful to developers
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.