<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Reasonable Application Security</title>
    <description>Striving to make application security reasonable.</description>
    
    <link>https://appsec.beehiiv.com/</link>
    <atom:link href="https://rss.beehiiv.com/feeds/qzqvvIt0tM.xml" rel="self"/>
    
    <lastBuildDate>Thu, 11 Jun 2026 21:56:30 +0000</lastBuildDate>
    <pubDate>Tue, 12 Nov 2024 17:00:00 +0000</pubDate>
    <atom:published>2024-11-12T17:00:00Z</atom:published>
    <atom:updated>2026-06-11T21:56:30Z</atom:updated>
    
      <category>Software Engineering</category>
      <category>Cybersecurity</category>
    <copyright>Copyright 2026, Reasonable Application Security</copyright>
    
    <image>
      <url>https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/publication/logo/88ffc572-6d6a-4408-b113-da68c5295d75/Reasonable-800x800.png</url>
      <title>Reasonable Application Security</title>
      <link>https://appsec.beehiiv.com/</link>
    </image>
    
    <docs>https://www.rssboard.org/rss-specification</docs>
    <generator>beehiiv</generator>
    <language>en-us</language>
    <webMaster>support@beehiiv.com (Beehiiv Support)</webMaster>

      <item>
  <title>Reasonable 🔐AppSec #76 -  Five Security Articles and Podcast Corner</title>
  <description>A review of application security happenings and industry news from Chris Romeo.</description>
  <link>https://appsec.beehiiv.com/p/reasonable-appsec-75-why-the-secure-by-design-pledge-won-t-save-us-from-appsec-failures-five-securit-61b7</link>
  <guid isPermaLink="true">https://appsec.beehiiv.com/p/reasonable-appsec-75-why-the-secure-by-design-pledge-won-t-save-us-from-appsec-failures-five-securit-61b7</guid>
  <pubDate>Tue, 12 Nov 2024 17:00:00 +0000</pubDate>
  <atom:published>2024-11-12T17:00:00Z</atom:published>
    <dc:creator>Chris Romeo</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><b>Hey there,</b></p><p class="paragraph" style="text-align:left;">In this week’s issue, please enjoy the following:</p><ul><li><p class="paragraph" style="text-align:left;">Five security articles 📰 that are worth YOUR time</p></li><li><p class="paragraph" style="text-align:left;">Podcast 🎙️Corner</p></li><li><p class="paragraph" style="text-align:left;">Where to find Chris? 🌎</p></li></ul><h2 class="heading" style="text-align:left;" id="five-security-articles-that-are-wor">Five Security Articles 📰 that Are Worth YOUR Time</h2><ol start="1"><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://googleprojectzero.blogspot.com/2024/10/from-naptime-to-big-sleep.html?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-76-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">From Naptime to Big Sleep: Using Large Language Models To Catch Vulnerabilities In Real-World Code</a> — Google&#39;s Project Zero team has advanced their &quot;Naptime&quot; framework into &quot;Big Sleep,&quot; collaborating with Google DeepMind to enhance large language models (LLMs) for vulnerability research. This evolution led to the discovery of a stack buffer underflow in SQLite, demonstrating the potential of AI agents in identifying previously unknown exploitable memory-safety issues in widely used software. <b>[</b><span style="background-color:#FFFFFF;"><b>This is an area to watch over the next 1-2 years.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/pulse/redefining-security-devsecops-derek-fisher-alwwe/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-76-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Redefining Security in DevSecOps</a>—Threat modeling is essential for integrating security into the DevSecOps process. It addresses the challenges of speed and complexity in modern software development by identifying potential vulnerabilities throughout the application lifecycle. Emphasizing a proactive security culture, organizations are encouraged to incorporate threat modeling iteratively, use automation tools, and foster collaboration among development and security teams to enhance resilience and mitigate risks effectively. <b>[</b><span style="background-color:#FFFFFF;"><b>I still maintain that DevSecOps is dead.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://aws.amazon.com/blogs/security/how-aws-built-the-security-guardians-program-a-mechanism-to-distribute-security-ownership/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-76-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">How AWS built the Security Guardians program, a mechanism to distribute security ownership</a> — The AWS Security Guardians program aims to distribute security ownership by integrating security experts, known as Guardians, directly into product development teams to prioritize security throughout the development lifecycle. This initiative fosters a culture of proactive security ownership, empowering teams to build and deploy products more securely and efficiently. <b>[</b><span style="background-color:#FFFFFF;"><b>Scale always catches my attention - the AWS Security Guardians is rumored to be the most extensive Champion program on the planet.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://genai.owasp.org/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-76-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Top 10 for LLM Project, Expands Initiatives & Publishes New AI Security Guidance</a> — The OWASP Top 10 for LLM & Generative AI Security project offers comprehensive guidance on securing applications that utilize Large Language Models (LLMs) and generative AI technologies. It provides a curated list of the most critical vulnerabilities and actionable recommendations to help developers, data scientists, and security experts navigate the complex landscape of AI application security. <b>[</b><span style="background-color:#FFFFFF;"><b>Top 10 for LLM are leading the pack.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://arxiv.org/abs/2410.20911?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-76-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Hacking Back the AI-Hacker: Prompt Injection as a Defense Against LLM-driven Cyberattacks</a> — Mantis is a defensive framework designed to counter LLM-driven cyberattacks by exploiting large language models&#39; vulnerability to adversarial prompt injection. By embedding crafted inputs into system responses, Mantis can misdirect or disrupt the attacker&#39;s LLM, achieving over 95% effectiveness in experiments. <b>[</b><span style="background-color:#FFFFFF;"><b>Just when you thought the hackback issue had exited the building.</b></span><b>]</b></p></li></ol><h2 class="heading" style="text-align:left;" id="podcast-corner">Podcast Corner</h2><p class="paragraph" style="text-align:left;">I love making podcasts. In Podcast Corner, you get a single place to see what I’ve put out this week. Sometimes, they are my podcasts. Other times, they are podcasts that have caught my attention.</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://appsec.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-76-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Application Security Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Tanya Janca -- What Secure Coding Means (<a class="link" href="https://www.buzzsprout.com/1730684/episodes/13812971?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-76-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/HpD_7JvK_-A?si=bpxiFxp9qSVPxaVK&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-76-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Tanya Janca, SheHacksPurple, returns to discuss the importance of secure coding practices and the need for a robust, secure system development life cycle (SDLC) to uphold security claims genuinely.</p></li><li><p class="paragraph" style="text-align:left;">Emphasizing proactive measures such as input validation and the principle of distrust and verification, Tanya shares personal anecdotes from threat modeling sessions to illustrate the necessity of anticipating vulnerabilities.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitytable.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-76-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Security Table</a></p><ul><li><p class="paragraph" style="text-align:left;">The Future Role of Security and Shifting off the Table (<a class="link" href="https://www.buzzsprout.com/2094080/episodes/13785721?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-76-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/2Uf3bsMaezk?si=8XyIhnNB917DhBWI&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-76-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Hosts Chris, Izar, and Matt discuss the evolving application security landscape. Chris suggests that security functions may eventually be integrated into development teams to reduce friction and enhance efficiency despite common misconceptions about the impact of security breaches on brand reputation.</p></li><li><p class="paragraph" style="text-align:left;">The conversation also addresses the &quot;shift left&quot; movement in application security, highlighting the need for clarity in what this term entails and advocating for starting security considerations from the project&#39;s requirements phase to ensure meaningful implementation.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://threatmodel.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-76-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Threat Modeling Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Nandita Rao Narla -- Privacy Threat Modeling Wins, Losses, and Tools (<a class="link" href="https://www.buzzsprout.com/2152378/episodes/15068747?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-76-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Hosts Chris and Nandita Rao Narla discuss the pitfalls of privacy threat modeling programs, including high costs, friction in development processes, and misalignment with compliance-focused strategies rather than risk management.</p></li><li><p class="paragraph" style="text-align:left;">Nandita emphasizes successful strategies for improving privacy threat modeling, such as using existing security resources, simplifying methodologies, and fostering a culture that prioritizes understanding potential risks, ultimately advocating for stronger integration of privacy and security threat modeling practices.</p></li></ul></li></ul></li></ul><h2 class="heading" style="text-align:left;" id="threat-model-for-free">Threat Model for Free</h2><p class="paragraph" style="text-align:left;">Welcome to <b>Simple, Collaborative</b> Threat Modeling by Devici.</p><p class="paragraph" style="text-align:start;">Introducing the modern drawing tool that&#39;s user-friendly, customizable, and easy on the eyes. Individuals and teams work together – no matter their location. Devici helps build a scalable threat modeling process for multi-disciplinary and geographically dispersed teams, ensuring everyone can contribute.</p><p class="paragraph" style="text-align:start;">Visit <a class="link" href="http://devici.com?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-76-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">devici.com</a> to experience <a class="link" href="https://app.devici.com/sign-up?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-76-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">threat modeling for free</a>.</p><div class="image"><a class="image__link" href="https://app.devici.com/sign-up?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-76-five-security-articles-and-podcast-corner" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/76ff3f8d-4c7b-46a9-a5ce-3e294c14410b/image.png?t=1724951951"/></a></div><h2 class="heading" style="text-align:left;" id="where-to-find-chris">Where to find Chris? 🌎</h2><ul><li><p class="paragraph" style="text-align:left;">Nothing is on the docket now, but stay tuned for the next webinar!</p></li></ul><p class="paragraph" style="text-align:left;">🤔<i> Have questions, comments, or feedback? I&#39;d love to </i><span style="text-decoration:underline;"><i><b><a class="link" href="mailto:chris@kerr.ventures?ref=ReasonableAppSec" target="_blank" rel="noopener noreferrer nofollow">hear</a></b></i></span><i> from you!</i></p><p class="paragraph" style="text-align:start;">🔥<i> Reasonable AppSec is brought to you by </i><span style="text-decoration:underline;"><i><b><a class="link" href="https://kerr.ventures?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-76-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Kerr Ventures</a></b></i></span><i>.</i></p><p class="paragraph" style="text-align:start;">🤝<i> Want to partner with Reasonable AppSec? Reach out, and let’s chat.</i></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=e6ca703a-107f-4df9-b27a-1ba458eb79a9&utm_medium=post_rss&utm_source=reasonable_application_security">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Reasonable 🔐AppSec #75 -   Why the &#39;Secure by Design&#39; pledge won&#39;t save us from AppSec failures, Five Security Articles and Podcast Corner</title>
  <description>A review of application security happenings and industry news from Chris Romeo.</description>
  <link>https://appsec.beehiiv.com/p/reasonable-appsec-75-why-the-secure-by-design-pledge-won-t-save-us-from-appsec-failures-five-securit</link>
  <guid isPermaLink="true">https://appsec.beehiiv.com/p/reasonable-appsec-75-why-the-secure-by-design-pledge-won-t-save-us-from-appsec-failures-five-securit</guid>
  <pubDate>Mon, 04 Nov 2024 16:00:00 +0000</pubDate>
  <atom:published>2024-11-04T16:00:00Z</atom:published>
    <dc:creator>Chris Romeo</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><b>Hey there,</b></p><p class="paragraph" style="text-align:left;">In this week’s issue, please enjoy the following:</p><ul><li><p class="paragraph" style="text-align:left;">Five security articles 📰 that are worth YOUR time</p></li><li><p class="paragraph" style="text-align:left;">Featured focus: <span style="color:rgb(5, 0, 40);font-family:Open Sans, sans-serif;font-size:15px;">Why the &#39;Secure by Design&#39; pledge won&#39;t save us from AppSec failures</span></p></li><li><p class="paragraph" style="text-align:left;">Application Security Podcast 🎙️Corner</p></li><li><p class="paragraph" style="text-align:left;">Where to find Chris? 🌎</p></li></ul><h2 class="heading" style="text-align:left;" id="five-security-articles-that-are-wor">Five Security Articles 📰 that Are Worth YOUR Time</h2><ol start="1"><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/pulse/chaos-engineering-systems-embracing-failure-security-testing-dave-fegjf/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-75-why-the-secure-by-design-pledge-won-t-save-us-from-appsec-failures-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Chaos Engineering in IT Systems: Embracing Failure and Security Testing for a More Resilient Future</a> — Chaos Engineering and Security Chaos Engineering allows organizations to proactively identify vulnerabilities and improve resilience by intentionally introducing failures and simulating security incidents. By employing strategies like continuous monitoring, safety mechanisms, and fostering a blameless culture, these methodologies help ensure systems can withstand and recover from unexpected disruptions and cyber threats. <b>[</b><span style="background-color:#FFFFFF;"><b>I’ve been a fan of chaos since its early days — never had a chance to implement it, but it makes sense to change things up and break the status quo.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.itpro.com/software/development/software-developers-are-spending-more-time-every-week-fixing-security-issues-and-its-costing-companies-a-fortune?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-75-why-the-secure-by-design-pledge-won-t-save-us-from-appsec-failures-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Software developers are spending more time every week fixing security issues – and it’s costing companies a fortune</a> — Software developers are increasingly spending more time each week addressing security issues, which is costing companies significant amounts of money. This trend highlights the growing complexity of software security and the need for improved tools and processes to help developers manage vulnerabilities effectively and reduce the financial impact on organizations. <b>[</b><span style="background-color:#FFFFFF;"><b>If software developers had implemented secure and private by design and default, they’d spend much less time fixing issues.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://unit42.paloaltonetworks.com/jailbreak-llms-through-camouflage-distraction/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-75-why-the-secure-by-design-pledge-won-t-save-us-from-appsec-failures-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Deceptive Delight: Jailbreak LLMs Through Camouflage and Distraction</a> — Large language models (LLMs) can be manipulated through tactics such as camouflage and distraction, which exploit their vulnerabilities and influence their outputs. These techniques raise significant concerns about the security and reliability of AI systems, particularly in critical applications where accuracy and trustworthiness are paramount. <b>[</b><span style="background-color:#FFFFFF;"><b>This just in — LLMs have security problems.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/technologist-bruce-schneier-on-security-society-and-why-we-need-public-ai-models/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-75-why-the-secure-by-design-pledge-won-t-save-us-from-appsec-failures-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Technologist Bruce Schneier on security, society and why we need &#39;public AI&#39; models</a> — Bruce Schneier emphasizes the critical need for public AI models to enhance security and societal benefits, advocating for transparency and collaboration in the development of AI technologies. He argues that public models can improve accountability and foster a more equitable digital landscape, mitigating risks associated with proprietary systems. <b>[</b><span style="background-color:#FFFFFF;"><b>Schneier says one or two things worth paying attention to per year — you decide if this is one of them.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.darkreading.com/application-security/shift-left-pushback-triggers-security-soul-searching?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-75-why-the-secure-by-design-pledge-won-t-save-us-from-appsec-failures-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">&#39;Shift Left&#39; Gets Pushback, Triggers Security Soul Searching</a> — The pushback against the &quot;shift left&quot; approach in application security has prompted a period of introspection among security professionals, highlighting challenges in balancing speed and security in the development process. This reflection reveals a need for improved collaboration between development and security teams to address the complexities of integrating security measures early in the software lifecycle. <b>[</b><span style="background-color:#FFFFFF;"><b>Shift left is a joke.</b></span><b>]</b></p></li></ol><h2 class="heading" style="text-align:left;" id="featured-focus-why-the-secure-by-de">Featured Focus: Why the &#39;Secure by Design&#39; pledge won&#39;t save us from AppSec failures</h2><p class="paragraph" style="text-align:left;">[I’m giving a talk on this topic later this week, so I decided to use my column to gather my thoughts into a semi-cohesive pile.]</p><p class="paragraph" style="text-align:left;">CISA’s ‘<a class="link" href="https://www.cisa.gov/sites/default/files/2024-05/CISA%20Secure%20by%20Design%20Pledge_508c.pdf?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-75-why-the-secure-by-design-pledge-won-t-save-us-from-appsec-failures-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Secure by Design Pledge</a>’ brought much hope for a kinder, gentler, more secure world. The only problem is that it has no teeth. It is a toothless pledge with no ramifications for lack of meeting or exceeding the goal.</p><p class="paragraph" style="text-align:left;">The content is acceptable—the requirements are precise and point us in the right direction as an industry: multi-factor authentication, reducing default passwords, reducing entire classes of vulnerabilities, increasing the installation of secure patches, publishing a vulnerability disclosure policy, transparency in reporting CVEs, and increasing the ability to gather evidence after an incident.</p><p class="paragraph" style="text-align:left;">Here is my first rub — ‘this is a voluntary pledge … a good-faith effort to work towards the goals.’ This means nothing — voluntary in that nobody has to participate, and good faith is the most wishy-washy terminology that could be used. Good faith means I’ll try my best, and no matter where I land, I’ll get a trophy for participation.</p><p class="paragraph" style="text-align:left;">Ladies and gentlemen, I&#39;ve produced the ‘Secure by Design Pledge Trophy’ for participation. I’ll mail one to each of the pledge signers.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/bb2346ee-c853-4d8b-a4e1-927c28e0f75b/image.png?t=1730726923"/></div><p class="paragraph" style="text-align:left;">My second rub is that you can divide the companies that have signed on to the pledge into two categories—those that already meet all the requirements and those that want to kiss a** to CISA and think they’ll gain some marketing advantage by signing. Nobody is doing this for the good of the Internet or the world; everybody has the motivation to try to get something for nothing.</p><p class="paragraph" style="text-align:left;">Do you want to make a pledge that has some teeth? Write the requirements in any way you want — for the sake of argument, we’ll keep what they have today. The thing we’ll change is the consequences. If you don’t demonstrate 10% improvement in all categories identified, you must donate 10% of your gross profit to a technology-focused charity that brings new folks into our industry. Now, we’d have a pledge with teeth, and nobody would sign up to play.</p><h2 class="heading" style="text-align:left;" id="podcast-corner">Podcast Corner</h2><p class="paragraph" style="text-align:left;">I love making podcasts. In Podcast Corner, you get a single place to see what I’ve put out this week. Sometimes, they are my podcasts. Other times, they are podcasts that have caught my attention.</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://appsec.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-75-why-the-secure-by-design-pledge-won-t-save-us-from-appsec-failures-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Application Security Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Kayra Otaner -- DevSecOps (<a class="link" href="https://www.buzzsprout.com/1730684/episodes/16006275?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-75-why-the-secure-by-design-pledge-won-t-save-us-from-appsec-failures-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/mcNu7sPUU5g?si=aCQP1pYbRtVh1ehB&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-75-why-the-secure-by-design-pledge-won-t-save-us-from-appsec-failures-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Hosts Chris and Robert welcome Kayra Otaner, the Director of DevSecOps at Roche, who asserts that traditional DevSecOps is &quot;dead&quot; and emphasizes the need for organizations to tailor their approaches based on size and specific needs.</p></li><li><p class="paragraph" style="text-align:left;">Kayra introduces &quot;security as code&quot; and &quot;policy as code&quot; as more effective strategies and highlights the emergence of Application Security Posture Management (ASPM) tools as the &quot;SIEM for AppSec,&quot; suggesting that AI-enhanced tools can help manage the influx of security alerts faced by development teams.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitytable.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-75-why-the-secure-by-design-pledge-won-t-save-us-from-appsec-failures-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Security Table</a></p><ul><li><p class="paragraph" style="text-align:left;">We&#39;ll Be Here Until We Become Obsolete (<a class="link" href="https://www.buzzsprout.com/2094080/episodes/15976875?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-75-why-the-secure-by-design-pledge-won-t-save-us-from-appsec-failures-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/apRv_lsj-LA?si=tYXqcOTOiran6JOA&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-75-why-the-secure-by-design-pledge-won-t-save-us-from-appsec-failures-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">We explore the multifaceted concept of obsolescence in technology, discussing its planned, unplanned, and forced forms while highlighting the security implications of outdated devices and software.</p></li><li><p class="paragraph" style="text-align:left;">The conversation focuses on vulnerabilities in cloud-connected vehicles, examines architectural decisions and regulatory requirements, and reflects on real-world incidents like the OnStar hack, underscoring the necessity for robust security protocols.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://threatmodel.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-75-why-the-secure-by-design-pledge-won-t-save-us-from-appsec-failures-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Threat Modeling Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Akira Brand -- Gaining Experience by Threat Modeling (<a class="link" href="https://www.buzzsprout.com/2152378/episodes/13676193?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-75-why-the-secure-by-design-pledge-won-t-save-us-from-appsec-failures-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Hosts Chris and Akira Brand discuss her journey into threat modeling, emphasizing the importance of collaboration, understanding applications, and utilizing tools and diagrams to enhance the process.</p></li><li><p class="paragraph" style="text-align:left;">Akira draws parallels between surgical checklists and the STRIDE model, highlighting how her hands-on approach and teamwork across engineering, data analytics, and security led to successful threat modeling outcomes.</p></li></ul></li></ul></li></ul><h2 class="heading" style="text-align:left;" id="threat-model-for-free">Threat Model for Free</h2><p class="paragraph" style="text-align:left;">Welcome to <b>Simple, Collaborative</b> Threat Modeling by Devici.</p><p class="paragraph" style="text-align:start;">Introducing the modern drawing tool that&#39;s user-friendly, customizable, and easy on the eyes. Individuals and teams work together – no matter their location. Devici helps build a scalable threat modeling process for multi-disciplinary and geographically dispersed teams, ensuring everyone can contribute.</p><p class="paragraph" style="text-align:start;">Visit <a class="link" href="http://devici.com?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-75-why-the-secure-by-design-pledge-won-t-save-us-from-appsec-failures-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">devici.com</a> to experience <a class="link" href="https://app.devici.com/sign-up?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-75-why-the-secure-by-design-pledge-won-t-save-us-from-appsec-failures-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">threat modeling for free</a>.</p><div class="image"><a class="image__link" href="https://app.devici.com/sign-up?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-75-why-the-secure-by-design-pledge-won-t-save-us-from-appsec-failures-five-security-articles-and-podcast-corner" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/76ff3f8d-4c7b-46a9-a5ce-3e294c14410b/image.png?t=1724951951"/></a></div><h2 class="heading" style="text-align:left;" id="where-to-find-chris">Where to find Chris? 🌎</h2><ul><li><p class="paragraph" style="text-align:left;">Speaking at <a class="link" href="https://www.theelephantinappsec.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-75-why-the-secure-by-design-pledge-won-t-save-us-from-appsec-failures-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">the Elephant in AppSec Conference</a> on Thursday, November 7, 14:25 Eastern time, on “Why the ‘Secure by Design’ pledge won’t save us from AppSec failures.”</p></li><li><p class="paragraph" style="text-align:left;">I’m at Triangle Infosecon in Raleigh this Friday, November 8, and I&#39;ll give a talk at 15:30 on “The Paradox of Secure and Private by Design and Default.”</p></li></ul><p class="paragraph" style="text-align:left;">🤔<i> Have questions, comments, or feedback? I&#39;d love to </i><span style="text-decoration:underline;"><i><b><a class="link" href="mailto:chris@kerr.ventures?ref=ReasonableAppSec" target="_blank" rel="noopener noreferrer nofollow">hear</a></b></i></span><i> from you!</i></p><p class="paragraph" style="text-align:start;">🔥<i> Reasonable AppSec is brought to you by </i><span style="text-decoration:underline;"><i><b><a class="link" href="https://kerr.ventures?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-75-why-the-secure-by-design-pledge-won-t-save-us-from-appsec-failures-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Kerr Ventures</a></b></i></span><i>.</i></p><p class="paragraph" style="text-align:start;">🤝<i> Want to partner with Reasonable AppSec? Reach out, and let’s chat.</i></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=bf4de37d-1004-42c3-a25d-fb2407e94e77&utm_medium=post_rss&utm_source=reasonable_application_security">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Reasonable 🔐AppSec #74 -   The absence of vulnerability, Five Security Articles and Podcast Corner</title>
  <description>A review of application security happenings and industry news from Chris Romeo.</description>
  <link>https://appsec.beehiiv.com/p/reasonable-appsec-74-the-absence-of-vulnerability-five-security-articles-and-podcast-corner</link>
  <guid isPermaLink="true">https://appsec.beehiiv.com/p/reasonable-appsec-74-the-absence-of-vulnerability-five-security-articles-and-podcast-corner</guid>
  <pubDate>Tue, 29 Oct 2024 14:49:28 +0000</pubDate>
  <atom:published>2024-10-29T14:49:28Z</atom:published>
    <dc:creator>Chris Romeo</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><b>Hey there,</b></p><p class="paragraph" style="text-align:left;">In this week’s issue, please enjoy the following:</p><ul><li><p class="paragraph" style="text-align:left;">Five security articles 📰 that are worth YOUR time</p></li><li><p class="paragraph" style="text-align:left;">Featured focus: The absence of vulnerability</p></li><li><p class="paragraph" style="text-align:left;">Application Security Podcast 🎙️Corner</p></li><li><p class="paragraph" style="text-align:left;">Where to find Chris? 🌎</p></li></ul><h2 class="heading" style="text-align:left;" id="five-security-articles-that-are-wor">Five Security Articles 📰 that Are Worth YOUR Time</h2><ol start="1"><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cloudguardrails.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-74-the-absence-of-vulnerability-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Cloud Guardrails</a> — Check out a comprehensive suite of tools designed to enhance security and compliance for cloud environments by automating governance policies and best practices. Organizations can proactively manage risks by implementing these guardrails, ensuring their cloud operations align with industry standards and regulations. <b>[</b><span style="background-color:#FFFFFF;"><b>I am a huge fan of guardrails, and this resource is a catalog of guardrails that you can mix and match.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://therecord.media/cybersecurity-software-liability-standards-white-house-struggle?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-74-the-absence-of-vulnerability-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">The struggle for software liability: Inside a ‘very, very, very hard problem’</a> — The White House faces challenges establishing cybersecurity software liability standards as stakeholders express concerns about the potential implications for innovation and security practices. The effort aims to create a framework that holds software developers accountable for vulnerabilities, but balancing regulatory measures with industry needs remains contentious. <b>[</b><span style="background-color:#FFFFFF;"><b>Can anyone say “NIGHTMARE”? The good news is the first case will get tied up on appeal for a decade.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://krebsonsecurity.com/2024/10/the-global-surveillance-free-for-all-in-mobile-ad-data/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-74-the-absence-of-vulnerability-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">The Global Surveillance Free-for-All in Mobile Ad Data</a> — Mobile advertising data has become a new battleground for global surveillance, with companies increasingly collecting and monetizing personal information from users without clear consent or oversight. The article highlights concerns over the implications of this pervasive data collection on user privacy and security and the challenges regulators face in establishing meaningful protections in an industry driven by profit. <b>[</b><span style="background-color:#FFFFFF;"><b>I didn’t realize the depth of mobile ad data and how it is misused.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/playlist?list=PL9fPq3eQfaaB2scbXRczwvjVH0ckX4bwt&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-74-the-absence-of-vulnerability-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">DEF CON 32 Main Stage Talks</a> — This playlist features a wealth of insights into the latest trends and challenges in cybersecurity, with discussions covering topics such as ransomware defenses, AI implications, and innovative vulnerabilities. Listeners can expect to learn from industry leaders and gain valuable perspectives on enhancing security practices in today&#39;s rapidly evolving digital landscape. <b>[</b><span style="background-color:#FFFFFF;"><b>Missed Vegas? Don’t fret; the DC talks are on YouTube.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://phoenix.security/aspm-reachability-analysis-overview/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-74-the-absence-of-vulnerability-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">The Ultimate Guide to Reachability Analysis Which reachability is good for you: Enhancing Code, Library, and Container Security with ASPM</a> — ASPM (Application Security Posture Management) reachability analysis provides a method to assess the accessibility of an application’s components, identifying potential vulnerabilities based on how these components interact with each other and the external environment. By understanding reachability, organizations can enhance their security posture, ensuring that only necessary access points are exposed and reducing the risk of exploitation. <b>[I’m bullish on ASPM, so I&#39;m sharing a resource to help you unpack its capabilities.]</b></p></li></ol><h2 class="heading" style="text-align:left;" id="featured-focus-the-absence-of-vulne">Featured Focus: The absence of vulnerability</h2><p class="paragraph" style="text-align:left;">On a soon-to-be-released AppSec Podcast episode, Matin, our guest, offered a definition of security that I’ve never heard before, and it’s got me thinking. He defines security as “the absence of vulnerabilities.” Stop and think about that for a second—the absence of vulnerabilities?</p><p class="paragraph" style="text-align:left;">I’ve always considered security an active issue. As a programmatic thinker, I approach problems by considering how we can systemize a solution that will allow the scaling of resources to address the problem at all levels. </p><p class="paragraph" style="text-align:left;">Security is people, processes, tools, and governance. The people secure the things, while the processes guide and attempt to make things unilateral. The tools make things easier for the people (in theory), and governance ensures that the right things are done at the correct times to protect the right things.</p><p class="paragraph" style="text-align:left;">Matin’s definition is a measurable state of a thing instead of a program to create a thing. This definition makes me wonder whether this is the Matrix. </p><p class="paragraph" style="text-align:left;">Tune in to this episode next week to hear Matin’s explanation for this definition and the exploration of anti-requirements. It will cause you to stop and think. If you have an epiphany on this definition, hit reply and share it with me. I’d love to hear other opinions.</p><h2 class="heading" style="text-align:left;" id="podcast-corner">Podcast Corner</h2><p class="paragraph" style="text-align:left;">I love making podcasts. In Podcast Corner, you get a single place to see what I’ve put out this week. Sometimes, they are my podcasts. Other times, they are podcasts that have caught my attention.</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://appsec.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-74-the-absence-of-vulnerability-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Application Security Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">François Proulx - Arbitrary Code Execution 0-day in Build Pipeline of Popular Open Source Packages (<a class="link" href="https://www.buzzsprout.com/1730684/episodes/15971947?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-74-the-absence-of-vulnerability-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/2mdmVxzUfwY?si=s5Ti2FMtnoW4707g&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-74-the-absence-of-vulnerability-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Hosts Chris Romeo and François Proulx discuss the discovery of security vulnerabilities in build pipelines, emphasizing how attackers can exploit this often-overlooked aspect of the software supply chain.</p></li><li><p class="paragraph" style="text-align:left;">To combat this issue, François&#39;s team developed an open-source scanner called Poutine, designed to identify vulnerable build pipelines at scale and provide remediation guidance, leveraging his extensive experience in application security and his role as founder of the NorthSec conference in Montreal.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitytable.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-74-the-absence-of-vulnerability-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Security Table</a></p><ul><li><p class="paragraph" style="text-align:left;">Everything is Boring (<a class="link" href="https://www.buzzsprout.com/2094080/episodes/15930294?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-74-the-absence-of-vulnerability-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/669v5Ko1gzs?si=GTvj9Zgg3x4ph0Pv&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-74-the-absence-of-vulnerability-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Hosts Chris, Izar, and Matt delve into the perception that recent cybersecurity topics, such as vulnerabilities and ransomware, have become less exciting, prompting a discussion about the waning interest in these issues.</p></li><li><p class="paragraph" style="text-align:left;">They explore the roles of Governance, Risk, and Compliance (GRC), the complexities of cyber insurance, and the fading novelty of AI, emphasizing that while essential security tasks may seem mundane, they remain crucial to maintaining effective security practices.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://threatmodel.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-74-the-absence-of-vulnerability-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Threat Modeling Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">The Four Question Framework with Adam Shostack (<a class="link" href="https://www.buzzsprout.com/2152378/episodes/12826352?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-74-the-absence-of-vulnerability-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Chris and Adam dive into the four-question framework for threat modeling, explaining the meaning and purpose of each question to simplify the process.</p></li><li><p class="paragraph" style="text-align:left;">They discuss the importance of retrospectives, the evolution of the framework, and its application in various situations, highlighting that the questions serve as a practical foundation for threat modeling.</p></li></ul></li></ul></li></ul><h2 class="heading" style="text-align:left;" id="threat-model-for-free">Threat Model for Free</h2><p class="paragraph" style="text-align:left;">Welcome to <b>Simple, Collaborative</b> Threat Modeling by Devici.</p><p class="paragraph" style="text-align:start;">Introducing the modern drawing tool that&#39;s user-friendly, customizable, and easy on the eyes. Individuals and teams work together – no matter their location. Devici helps build a scalable threat modeling process for multi-disciplinary and geographically dispersed teams, ensuring everyone can contribute.</p><p class="paragraph" style="text-align:start;">Visit <a class="link" href="http://devici.com?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-74-the-absence-of-vulnerability-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">devici.com</a> to experience <a class="link" href="https://app.devici.com/sign-up?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-74-the-absence-of-vulnerability-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">threat modeling for free</a>.</p><div class="image"><a class="image__link" href="https://app.devici.com/sign-up?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-74-the-absence-of-vulnerability-five-security-articles-and-podcast-corner" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/76ff3f8d-4c7b-46a9-a5ce-3e294c14410b/image.png?t=1724951951"/></a></div><h2 class="heading" style="text-align:left;" id="where-to-find-chris">Where to find Chris? 🌎</h2><ul><li><p class="paragraph" style="text-align:left;"><span style="text-decoration:underline;"><i><a class="link" href="https://www.reversinglabs.com/webinar/supercharge-threat-modeling-with-sscs?utm_source=Guest%20Speaker&utm_medium=referral&utm_term=Chris%20Romeo%20Promo" target="_blank" rel="noopener noreferrer nofollow">Webinar: Supercharge Threat Modeling with Software Supply Chain Security</a></i></span> — TODAY! (Tuesday, October 29) @ noon (Eastern)</p></li></ul><p class="paragraph" style="text-align:left;">🤔<i> Have questions, comments, or feedback? I&#39;d love to </i><span style="text-decoration:underline;"><i><b><a class="link" href="mailto:chris@kerr.ventures?ref=ReasonableAppSec" target="_blank" rel="noopener noreferrer nofollow">hear</a></b></i></span><i> from you!</i></p><p class="paragraph" style="text-align:start;">🔥<i> Reasonable AppSec is brought to you by </i><span style="text-decoration:underline;"><i><b><a class="link" href="https://kerr.ventures?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-74-the-absence-of-vulnerability-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Kerr Ventures</a></b></i></span><i>.</i></p><p class="paragraph" style="text-align:start;">🤝<i> Want to partner with Reasonable AppSec? Reach out, and let’s chat.</i></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=ddd04674-8c2a-4e55-a4d7-43e1dd8fd93b&utm_medium=post_rss&utm_source=reasonable_application_security">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Reasonable 🔐AppSec #73 -  It is my birthday, Five Security Articles and Podcast Corner</title>
  <description>A review of application security happenings and industry news from Chris Romeo.</description>
  <link>https://appsec.beehiiv.com/p/reasonable-appsec-73-it-is-my-birthday-five-security-articles-and-podcast-corner</link>
  <guid isPermaLink="true">https://appsec.beehiiv.com/p/reasonable-appsec-73-it-is-my-birthday-five-security-articles-and-podcast-corner</guid>
  <pubDate>Tue, 22 Oct 2024 16:00:00 +0000</pubDate>
  <atom:published>2024-10-22T16:00:00Z</atom:published>
    <dc:creator>Chris Romeo</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><b>Hey there,</b></p><p class="paragraph" style="text-align:left;">We’re doing a threat modeling game for Cyber Security Month, and it’s fast approaching. The event will occur on October 24, 2024, at Noon Eastern/US. Sign up now, as you are almost out of time. Check out our <a class="link" href="https://devici.com/lp/maybe-you-shouldve-threat-modeled-that?utm_campaign=October+2024+Cyber+Month+Game&utm_content=310461253&utm_medium=social&utm_source=linkedin&hss_channel=lcp-98637378" target="_blank" rel="noopener noreferrer nofollow">landing page</a>. It’s a free game where you’ll join a team and perform a threat modeling exercise against other teams, battling to be THE threat modeling champion! </p><p class="paragraph" style="text-align:left;">P.S. Custom Lego sets from Devici are the prize for winning.</p><p class="paragraph" style="text-align:left;">In this week’s issue, please enjoy the following:</p><ul><li><p class="paragraph" style="text-align:left;">Five security articles 📰 that are worth YOUR time</p></li><li><p class="paragraph" style="text-align:left;">Featured focus: It is my birthday</p></li><li><p class="paragraph" style="text-align:left;">Application Security Podcast 🎙️Corner</p></li><li><p class="paragraph" style="text-align:left;">Where to find Chris? 🌎</p></li></ul><h2 class="heading" style="text-align:left;" id="five-security-articles-that-are-wor">Five Security Articles 📰 that Are Worth YOUR Time</h2><ol start="1"><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://security.googleblog.com/2024/09/eliminating-memory-safety-vulnerabilities-Android.html?m=1&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-73-it-is-my-birthday-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow"><b>Eliminating Memory Safety Vulnerabilities at the Source</b></a> — Google&#39;s Android team has successfully reduced memory safety vulnerabilities from 76% in 2019 to 24% in 2024 by transitioning to memory-safe languages, such as Rust. This shift focuses on preventing new vulnerabilities through safe coding practices, which have been shown to lower overall security risks without extensive rewrites of older code. <b>[</b><span style="background-color:#FFFFFF;"><b>The proof is in the pudding, and this proof is tasty and expected — memory-safe languages improve security.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://content.reversinglabs.com/learn-commercial-software-risk/threat-modeling-sscs?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-73-it-is-my-birthday-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Threat modeling and binary analysis: Supercharge your risk strategy</a> — Threat modeling and binary analysis are essential for improving software risk management strategies, particularly in securing supply chains. By integrating these approaches, organizations can better anticipate vulnerabilities, manage risks proactively, and enhance the security posture of their software assets.<b>[</b><span style="background-color:#FFFFFF;"><b>I was featured in this article, sharing thoughts about the intersection of threat modeling and software supply chain.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://danaepp.com/attacking-apis-using-json-injection?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-73-it-is-my-birthday-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Attacking APIs using JSON Injection</a> — JSON injection can exploit APIs by inserting malicious data into JSON streams, leading to vulnerabilities like SQL injection and remote code execution. It highlights the risks posed by inconsistencies in how different JSON parsers handle data, emphasizing the importance of thoroughly vetting API components to prevent such attacks.<b> [</b><span style="background-color:#FFFFFF;"><b>I had never looked at JSON injection before, and this one gave me context and perspective.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.infosecurity-magazine.com/news/confusedpilot-attack-targets-ai/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-73-it-is-my-birthday-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">New ConfusedPilot Attack Targets AI Systems with Data Poisoning</a><b> </b>— The ConfusedPilot attack targets AI systems, particularly Retrieval-Augmented Generation (RAG) models like Microsoft 365 Copilot, by introducing malicious content into documents the AI references. This data poisoning can cause the AI to generate misinformation or incorrect responses, posing a significant risk to organizations relying on such systems for decision-making.<b> [</b><span style="background-color:#FFFFFF;"><b>Data poisoning fleshed out deeper than what you’ll find in the OWAP Top Ten for LLM.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://pulse.latio.tech/p/how-to-do-vulnerability-prioritization?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-73-it-is-my-birthday-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">How to do Vulnerability Prioritization</a> — Effective Vulnerability Prioritization moves beyond simple CVSS base scores and incorporates factors such as exploit status, environmental context, and patch availability. It emphasizes the importance of using a comprehensive threat intelligence approach and scalable data platforms to manage large numbers of vulnerabilities. <b>[</b><span style="background-color:#FFFFFF;"><b>Challenging thing for teams — James provides an easy-to-follow structure that considers the data.</b></span><b>]</b></p></li></ol><h2 class="heading" style="text-align:left;" id="featured-focus-it-is-my-birthday">Featured Focus: It is my birthday</h2><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/18bee443-a661-4cb7-9d9d-01fccb0c51d2/image.png?t=1729607439"/></div><p class="paragraph" style="text-align:left;">Today is my birthday. I wouldn’t say I like celebrating birthdays, but I should be excited to be experiencing another lap around the solar system. I’m not writing this because it’s my birthday, but instead, because this concept of celebration got me thinking.</p><p class="paragraph" style="text-align:left;">We don&#39;t celebrate enough in security, and application security specifically. I’m from a generation where the thought of everyone getting a trophy makes us nauseous, so I’m not talking about everybody being recognized. We don’t celebrate our small and big wins with enough fervor.</p><p class="paragraph" style="text-align:left;">As a general principle, at Security Journey, we had an all-hands meeting for the 20+ team members each Monday. A segment of that meeting was always small wins, where folks could send in small victories that they experienced or saw others experience, and we could all celebrate those victories together and recognize the success.</p><p class="paragraph" style="text-align:left;">We need to do more of this in security. We need to pinpoint the small wins and find ways to celebrate them. Celebration is more than just the security team—look for ways to celebrate with the security and privacy supporting teams, development, operations, and anyone else. Culture was created over time, and Rome wasn’t built in a day. Celebrate.</p><h2 class="heading" style="text-align:left;" id="podcast-corner">Podcast Corner</h2><p class="paragraph" style="text-align:left;">I love making podcasts. In Podcast Corner, you get a single place to see what I’ve put out this week. Sometimes, they are my podcasts. Other times, they are podcasts that have caught my attention.</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://appsec.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-73-it-is-my-birthday-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Application Security Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Varun Badhwar -- The Developer Productivity Tax (<a class="link" href="https://www.buzzsprout.com/1730684/episodes/13747948?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-73-it-is-my-birthday-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/AQBoPUFSX10?si=quR1eQDnELwsoK9R&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-73-it-is-my-birthday-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Varun Badhwar joins to discuss the &quot;Developer Productivity Tax,&quot; highlighting the challenges developers face when overwhelmed by vulnerabilities that often lack actionable context.</p></li><li><p class="paragraph" style="text-align:left;">Varun emphasizes the integration of SBOM plus VEX to improve vulnerability management, advocating for &quot;Scanning with Context&quot; to reduce false positives and ensure that only relevant threats are addressed effectively.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitytable.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-73-it-is-my-birthday-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Security Table</a></p><ul><li><p class="paragraph" style="text-align:left;">Experts Want to Excel (<a class="link" href="https://www.buzzsprout.com/2094080/episodes/15893090?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-73-it-is-my-birthday-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/szejcJBDRLI?si=NSwM1dJt1CFp_v2O&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-73-it-is-my-birthday-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">We explore the criteria that define an expert in threat modeling, discussing the cultural references and intricacies of threat modeling practices and the roles of facilitators.</p></li><li><p class="paragraph" style="text-align:left;">The conversation humorously addresses the challenges of scaling practices in large organizations while highlighting how expertise can inspire others. It includes tangents on movies, old media technologies, sports analogies, and competitive Excel.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://threatmodel.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-73-it-is-my-birthday-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Threat Modeling Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Product-led threat modeling (<a class="link" href="https://www.buzzsprout.com/2152378/episodes/12987495?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-73-it-is-my-birthday-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Explore the connection between threat modeling and product development, emphasizing the importance of understanding user needs while applying lean product management principles.</p></li><li><p class="paragraph" style="text-align:left;">They discuss best practices for conducting threat modeling sessions, including methodologies like rapid risk assessment and STRIDE, and stress the significance of collaboration and communication among product managers, architects, and technical leaders to align threat modeling with product goals.</p></li></ul></li></ul></li></ul><h2 class="heading" style="text-align:left;" id="threat-model-for-free">Threat Model for Free</h2><p class="paragraph" style="text-align:left;">Welcome to <b>Simple, Collaborative</b> Threat Modeling by Devici.</p><p class="paragraph" style="text-align:start;">Introducing the modern drawing tool that&#39;s user-friendly, customizable, and easy on the eyes. Individuals and teams work together – no matter their location. Devici helps build a scalable threat modeling process for multi-disciplinary and geographically dispersed teams, ensuring everyone can contribute.</p><p class="paragraph" style="text-align:start;">Visit <a class="link" href="http://devici.com?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-73-it-is-my-birthday-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">devici.com</a> to experience <a class="link" href="https://app.devici.com/sign-up?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-73-it-is-my-birthday-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">threat modeling for free</a>.</p><div class="image"><a class="image__link" href="https://app.devici.com/sign-up?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-73-it-is-my-birthday-five-security-articles-and-podcast-corner" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/76ff3f8d-4c7b-46a9-a5ce-3e294c14410b/image.png?t=1724951951"/></a></div><h2 class="heading" style="text-align:left;" id="where-to-find-chris">Where to find Chris? 🌎</h2><ul><li><p class="paragraph" style="text-align:left;"><span style="text-decoration:underline;"><i><a class="link" href="https://www.reversinglabs.com/webinar/supercharge-threat-modeling-with-sscs?utm_source=Guest%20Speaker&utm_medium=referral&utm_term=Chris%20Romeo%20Promo" target="_blank" rel="noopener noreferrer nofollow">Webinar: Supercharge Threat Modeling with Software Supply Chain Security</a></i></span> — Tuesday, October 29 @ noon (Eastern)</p></li></ul><p class="paragraph" style="text-align:left;">🤔<i> Have questions, comments, or feedback? I&#39;d love to </i><span style="text-decoration:underline;"><i><b><a class="link" href="mailto:chris@kerr.ventures?ref=ReasonableAppSec" target="_blank" rel="noopener noreferrer nofollow">hear</a></b></i></span><i> from you!</i></p><p class="paragraph" style="text-align:start;">🔥<i> Reasonable AppSec is brought to you by </i><span style="text-decoration:underline;"><i><b><a class="link" href="https://kerr.ventures?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-73-it-is-my-birthday-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Kerr Ventures</a></b></i></span><i>.</i></p><p class="paragraph" style="text-align:start;">🤝<i> Want to partner with Reasonable AppSec? Reach out, and let’s chat.</i></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=306e2346-fe94-4c3d-8237-79203116710c&utm_medium=post_rss&utm_source=reasonable_application_security">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Reasonable 🔐AppSec #72 -  Highlighting some good folks, Five Security Articles and Podcast Corner</title>
  <description>A review of application security happenings and industry news from Chris Romeo.</description>
  <link>https://appsec.beehiiv.com/p/reasonable-appsec-71-threat-modeling-a-vacation-or-the-lack-thereof-five-security-articles-and-podca-c5ed</link>
  <guid isPermaLink="true">https://appsec.beehiiv.com/p/reasonable-appsec-71-threat-modeling-a-vacation-or-the-lack-thereof-five-security-articles-and-podca-c5ed</guid>
  <pubDate>Tue, 15 Oct 2024 20:11:12 +0000</pubDate>
  <atom:published>2024-10-15T20:11:12Z</atom:published>
    <dc:creator>Chris Romeo</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><b>Hey there,</b></p><p class="paragraph" style="text-align:left;">We’re doing a threat modeling game for Cyber Security Month, and it’s fast approaching. The event will occur on October 24, 2024, at Noon Eastern/US. Sign up now, as you are almost out of time. Check out our <a class="link" href="https://devici.com/lp/maybe-you-shouldve-threat-modeled-that?utm_campaign=October+2024+Cyber+Month+Game&utm_content=310461253&utm_medium=social&utm_source=linkedin&hss_channel=lcp-98637378" target="_blank" rel="noopener noreferrer nofollow">landing page</a>. It’s a free game where you’ll join a team and perform a threat modeling exercise against other teams, battling to be THE threat modeling champion! </p><p class="paragraph" style="text-align:left;">P.S. Custom Lego sets from Devici are the prize for winning.</p><p class="paragraph" style="text-align:left;">In this week’s issue, please enjoy the following:</p><ul><li><p class="paragraph" style="text-align:left;">Five security articles 📰 that are worth YOUR time</p></li><li><p class="paragraph" style="text-align:left;">Featured focus: Highlighting some good folks</p></li><li><p class="paragraph" style="text-align:left;">Application Security Podcast 🎙️Corner</p></li><li><p class="paragraph" style="text-align:left;">Where to find Chris? 🌎</p></li></ul><h2 class="heading" style="text-align:left;" id="five-security-articles-that-are-wor">Five Security Articles 📰 that Are Worth YOUR Time</h2><ol start="1"><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://ramimac.me/dsqs?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-72-highlighting-some-good-folks-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Answering &quot;Dumb Security Questionnaires&quot;</a> — The Developer Security Questions (DSQs) framework enhances software development security by offering teams a structured approach to identify and address security concerns early. By integrating DSQs into the software development lifecycle, organizations can cultivate a security-focused culture and improve collaboration between development and security teams. <b>[</b><span style="background-color:#FFFFFF;"><b>Security questionnaires have been the bane of many folk’s existence for YEARS. Can’t we all agree on a standard way of describing this stuff? (and don’t say SOC2</b></span><b>).]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://permiso.io/blog/exploiting-hosted-models?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-72-highlighting-some-good-folks-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">When AI Gets Hijacked: Exploiting Hosted Models for Dark Roleplaying</a> — Exploiting hosted models poses significant security risks, as attackers can manipulate vulnerabilities in the underlying infrastructure to gain unauthorized access or disrupt services. The article highlights the importance of implementing robust security measures and monitoring practices to protect against such threats and ensure the integrity of hosted applications. <b>[</b><span style="background-color:#FFFFFF;"><b>AI is scary, and it’s not even Halloween yet!</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/pulse/mishaps-ryan-heffernan-rjwmc?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-72-highlighting-some-good-folks-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">MISHAPS: A New Approach to Threat Modeling</a> — Ryan Heffernan reflects on recognizing and learning from mishaps in professional settings, emphasizing that mistakes can lead to valuable insights and growth. By sharing personal experiences, he advocates for fostering a culture that encourages openness and accountability, ultimately enhancing team dynamics and performance. <b>[</b><span style="background-color:#FFFFFF;"><b>I applaud the effort, but it lacks the simplicity that makes STRIDE so powerful and makes folks want to build something new and better.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://threat-modeling.net/is-retro-threat-modeling-a-team/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-72-highlighting-some-good-folks-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Is Retro = Threat Modeling a Team?</a> — Retro threat modeling focuses on analyzing and identifying security vulnerabilities in systems after their development, emphasizing the importance of collaboration among team members. The article advocates for a structured approach to retroactive assessments to improve security measures and foster a proactive security culture within organizations. <b>[</b><span style="background-color:#FFFFFF;"><b>I like Hendrik’s thought processes on threat modeling, so check out how he wraps retro and TM together.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/pulse/strategic-use-attack-trees-cybersecurity-derek-fisher-kf4fe/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-72-highlighting-some-good-folks-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">The Strategic Use of Attack Trees in Cybersecurity</a>—Attack trees help organizations visualize potential attack vectors and improve risk assessment processes. By systematically identifying vulnerabilities, attack trees enable teams to prioritize security efforts and enhance their defenses against cyber threats. <b>[</b><span style="background-color:#FFFFFF;"><b>Attack trees do not replace TM but provide a different perspective.</b></span><b>]</b></p></li></ol><h2 class="heading" style="text-align:left;" id="featured-focus-highlighting-some-go">Featured Focus: Highlighting some good folks</h2><p class="paragraph" style="text-align:left;">I don’t listen to content about application security. GASP, I know; I host three AppSec-focused podcasts. I feel like I get enough AppSec by interviewing and debating with people while recording.</p><p class="paragraph" style="text-align:left;">That said, I want to highlight some folks in our industry doing great things to advance content and provide you with learning opportunities.</p><ol start="1"><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/channel/UCu2vcMyF-dFjQV-4x63PPZw?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-72-highlighting-some-good-folks-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">The Elephant in AppSec</a> (Alexandra Charikova)—I was honored to appear on this show for an episode about why Shift Left is wrong.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/in/confidencestaveley/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-72-highlighting-some-good-folks-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Confidence Staveley</a> — I was honored to write the foreword for Confidence’s API security book and find her API Kitchen show, which melds security and cooking.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/in/resilientcyber/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-72-highlighting-some-good-folks-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Chris Hughes</a> — Chris writes the Resilient Cyber newsletter and podcast and has authored a few books. He is a force of nature when it comes to content creation. His newsletter is well-written, researched, and thought out.</p></li></ol><p class="paragraph" style="text-align:left;">If you have a platform, highlight folks others need to know about. Our industry must continue to expand, and we encourage that behavior through new sources of information.</p><h2 class="heading" style="text-align:left;" id="podcast-corner">Podcast Corner</h2><p class="paragraph" style="text-align:left;">I love making podcasts. In Podcast Corner, you get a single place to see what I’ve put out this week. Sometimes, they are my podcasts. Other times, they are podcasts that have caught my attention.</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://appsec.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-72-highlighting-some-good-folks-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Application Security Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Varun Badhwar -- The Developer Productivity Tax (<a class="link" href="https://www.buzzsprout.com/1730684/episodes/13747948?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-72-highlighting-some-good-folks-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/AQBoPUFSX10?si=quR1eQDnELwsoK9R&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-72-highlighting-some-good-folks-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Varun Badhwar joins to discuss the &quot;Developer Productivity Tax,&quot; highlighting the challenges developers face when overwhelmed by vulnerabilities that often lack actionable context.</p></li><li><p class="paragraph" style="text-align:left;">Varun emphasizes the integration of SBOM plus VEX to improve vulnerability management, advocating for &quot;Scanning with Context&quot; to reduce false positives and ensure that only relevant threats are addressed effectively.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitytable.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-72-highlighting-some-good-folks-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Security Table</a></p><ul><li><p class="paragraph" style="text-align:left;">Experts Want to Excel (<a class="link" href="https://www.buzzsprout.com/2094080/episodes/15893090?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-72-highlighting-some-good-folks-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/szejcJBDRLI?si=NSwM1dJt1CFp_v2O&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-72-highlighting-some-good-folks-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">We explore the criteria that define an expert in threat modeling, discussing the cultural references and intricacies of threat modeling practices and the roles of facilitators.</p></li><li><p class="paragraph" style="text-align:left;">The conversation humorously addresses the challenges of scaling practices in large organizations while highlighting how expertise can inspire others. It includes tangents on movies, old media technologies, sports analogies, and competitive Excel.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://threatmodel.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-72-highlighting-some-good-folks-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Threat Modeling Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Product-led threat modeling (<a class="link" href="https://www.buzzsprout.com/2152378/episodes/12987495?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-72-highlighting-some-good-folks-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Explore the connection between threat modeling and product development, emphasizing the importance of understanding user needs while applying lean product management principles.</p></li><li><p class="paragraph" style="text-align:left;">They discuss best practices for conducting threat modeling sessions, including methodologies like rapid risk assessment and STRIDE, and stress the significance of collaboration and communication among product managers, architects, and technical leaders to align threat modeling with product goals.</p></li></ul></li></ul></li></ul><h2 class="heading" style="text-align:left;" id="threat-model-for-free">Threat Model for Free</h2><p class="paragraph" style="text-align:left;">Welcome to <b>Simple, Collaborative</b> Threat Modeling by Devici.</p><p class="paragraph" style="text-align:start;">Introducing the modern drawing tool that&#39;s user-friendly, customizable, and easy on the eyes. Individuals and teams work together – no matter their location. Devici helps build a scalable threat modeling process for multi-disciplinary and geographically dispersed teams, ensuring everyone can contribute.</p><p class="paragraph" style="text-align:start;">Visit <a class="link" href="http://devici.com?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-72-highlighting-some-good-folks-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">devici.com</a> to experience <a class="link" href="https://app.devici.com/sign-up?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-72-highlighting-some-good-folks-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">threat modeling for free</a>.</p><div class="image"><a class="image__link" href="https://app.devici.com/sign-up?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-72-highlighting-some-good-folks-five-security-articles-and-podcast-corner" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/76ff3f8d-4c7b-46a9-a5ce-3e294c14410b/image.png?t=1724951951"/></a></div><h2 class="heading" style="text-align:left;" id="where-to-find-chris">Where to find Chris? 🌎</h2><ul><li><p class="paragraph" style="text-align:left;">Nothing on the docket now, but stay tuned for the next webinar!</p></li></ul><p class="paragraph" style="text-align:left;">🤔<i> Have questions, comments, or feedback? I&#39;d love to </i><span style="text-decoration:underline;"><i><b><a class="link" href="mailto:chris@kerr.ventures?ref=ReasonableAppSec" target="_blank" rel="noopener noreferrer nofollow">hear</a></b></i></span><i> from you!</i></p><p class="paragraph" style="text-align:start;">🔥<i> Reasonable AppSec is brought to you by </i><span style="text-decoration:underline;"><i><b><a class="link" href="https://kerr.ventures?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-72-highlighting-some-good-folks-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Kerr Ventures</a></b></i></span><i>.</i></p><p class="paragraph" style="text-align:start;">🤝<i> Want to partner with Reasonable AppSec? Reach out, and let’s chat.</i></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=3abd0ff8-76ad-48e0-9ab1-21b3e5b4cb3d&utm_medium=post_rss&utm_source=reasonable_application_security">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Reasonable 🔐AppSec #71 -  Threat modeling a vacation, or the lack thereof, Five Security Articles and Podcast Corner</title>
  <description>A review of application security happenings and industry news from Chris Romeo.</description>
  <link>https://appsec.beehiiv.com/p/reasonable-appsec-71-threat-modeling-a-vacation-or-the-lack-thereof-five-security-articles-and-podca</link>
  <guid isPermaLink="true">https://appsec.beehiiv.com/p/reasonable-appsec-71-threat-modeling-a-vacation-or-the-lack-thereof-five-security-articles-and-podca</guid>
  <pubDate>Tue, 08 Oct 2024 16:00:00 +0000</pubDate>
  <atom:published>2024-10-08T16:00:00Z</atom:published>
    <dc:creator>Chris Romeo</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><b>Hey there,</b></p><p class="paragraph" style="text-align:left;">Before you dive in — we’re doing a threat modeling game for Cyber Security Month, so if you’d like to check it out and sign up, check out our <a class="link" href="https://devici.com/lp/maybe-you-shouldve-threat-modeled-that?utm_campaign=October+2024+Cyber+Month+Game&utm_content=310461253&utm_medium=social&utm_source=linkedin&hss_channel=lcp-98637378" target="_blank" rel="noopener noreferrer nofollow">landing page</a>. It’s a free game where you’ll join a team and perform a threat modeling exercise against other teams, battling to be THE threat modeling champion! P.S. Custom Lego sets from Devici are the prize for winning.</p><p class="paragraph" style="text-align:left;">In this week’s issue, please enjoy the following:</p><ul><li><p class="paragraph" style="text-align:left;">Five security articles 📰 that are worth YOUR time</p></li><li><p class="paragraph" style="text-align:left;">Featured focus: Threat modeling a vacation, or the lack thereof</p></li><li><p class="paragraph" style="text-align:left;">Application Security Podcast 🎙️Corner</p></li><li><p class="paragraph" style="text-align:left;">Where to find Chris? 🌎</p></li></ul><h2 class="heading" style="text-align:left;" id="five-security-articles-that-are-wor">Five Security Articles 📰 that Are Worth YOUR Time</h2><ol start="1"><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.darkreading.com/application-security/managing-devops-security-posture-necessary-to-escape-the-stone-age-?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-71-threat-modeling-a-vacation-or-the-lack-thereof-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Moving DevOps Security Out of &#39;the Stone Age&#39;</a> — Managing the security posture of DevOps practices is essential for organizations to avoid falling behind in an increasingly complex threat landscape. By adopting proactive security measures and integrating them into the development lifecycle, companies can strengthen their defenses and ensure a more resilient application security framework. <b>[</b><span style="background-color:#FFFFFF;"><b>Nice summary of the current state of DevOps and where things need to move forward for better success. I still think DevSecOps is dead.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.offsec.com/blog/mental-toughness-in-cybersecurity/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-71-threat-modeling-a-vacation-or-the-lack-thereof-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Mental Toughness in Cybersecurity: Preparing Teams for High-Pressure Situations</a> — Developing mental toughness is crucial for cybersecurity professionals to navigate the challenges and stresses inherent in the field. By fostering resilience, adaptability, and a positive mindset, individuals can enhance their performance and cope with the demands of a rapidly evolving cybersecurity landscape. <b>[</b><span style="background-color:#FFFFFF;"><b>The career field we have chosen is challenging — no matter your job description. This article caught my attention, given the nature of building mental toughness. I love the concept.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.gyan.ca/things-to-know-about-your-tech-salary/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-71-threat-modeling-a-vacation-or-the-lack-thereof-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Things You Need to Know About Your Tech Salary</a> — Understanding key factors influencing tech salaries, such as skills, experience, and industry demand, is essential for professionals navigating their careers. By staying informed about market trends and salary benchmarks, individuals can better advocate for themselves and make informed decisions regarding their compensation. <b>[</b><span style="background-color:#FFFFFF;"><b>You must advocate for yourself, your salary, and your career. Know before you go into that salary discussion with your boss.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.scworld.com/perspective/the-20-year-application-security-blindspot-can-adr-finally-fix-it?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-71-threat-modeling-a-vacation-or-the-lack-thereof-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">The 20-year application security blindspot: Can ADR finally fix it?</a> — A longstanding blindspot in application security has hindered organizations&#39; ability to detect and respond to threats effectively, often leaving vulnerabilities unaddressed for years. Application detection and response (ADR) offers a potential solution by enhancing visibility and enabling proactive security measures throughout the software lifecycle to bridge this critical gap. <b>[</b><span style="background-color:#FFFFFF;"><b>I’m fascinated by ADR and reading everything I can about it. It could genuinely bridge the gap and bring AppSec truly into the fold.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://arstechnica.com/security/2024/09/rogue-whois-server-gives-researcher-superpowers-no-one-should-ever-have/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-71-threat-modeling-a-vacation-or-the-lack-thereof-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Rogue WHOIS server gives researcher superpowers no one should ever have</a> — A rogue WHOIS server has emerged that grants unauthorized access to sensitive information, allowing researchers to exploit domain name registration data in ways that could pose significant security risks. This development raises concerns about privacy and potential abuse, highlighting the need for improved oversight and security measures in domain registration practices. <b>[</b><span style="background-color:#FFFFFF;"><b>This is a reminder about the legacy stuff that exists on the Internet and how it can be used to create modern-day nightmares.</b></span><b>]</b></p></li></ol><h2 class="heading" style="text-align:left;" id="featured-focus-threat-modeling-a-va">Featured Focus: Threat modeling a vacation, or the lack thereof</h2><p class="paragraph" style="text-align:left;">This past week, I decided to take a short vacation. A friend was available to join me, and one of his bucket list items was seeing and experiencing the Grand Canyon. At this point, I’ve never seen the Grand Canyon in person, only from the window of a plane on the way to the West Coast. I thought, “I need to see the Grand Canyon at some point in this life, so let’s do it.”</p><p class="paragraph" style="text-align:left;">We have a family friend who is a vacation planner/travel agent, so I called her and empowered her to plan the trip. She asked for a word to describe the trip, and I went with “adventure.” She generated an itinerary for us with activities around the Grand Canyon, and last Monday morning, we went off to the airport.</p><p class="paragraph" style="text-align:left;">We arrived in Flagstaff, found our hotel, and prepared for our first adventure the following day. We had a hike planned with a guide at the Grand Canyon. I did not do any due diligence on what this meant, the two words “a hike.” My mental model was a pleasant stroll down a controlled, paved path with guard rails. What I found was something that was initially extraordinarily shocking.</p><p class="paragraph" style="text-align:left;">Hiking the Grand Canyon means walking down a trail four to six feet wide, with one side being the cliff face and the other sometimes a drop of thousands of feet. I forgot to mention earlier that my fear of heights has been exacerbated as I&#39;ve gotten older. So, there I was, beginning the descent down the trail, and I caught a glimpse over the side of the trail. (My hands are sweating again now as I replay the experience.)</p><p class="paragraph" style="text-align:left;">At that point, I had a choice: I could turn around and give up, as many people had done at the same spot, or I could push through and face my fear. I was more driven in my decision because my friend’s bucket list item was to hike the Grand Canyon, and if I turned around, it would ruin his experience.</p><p class="paragraph" style="text-align:left;">So we pressed on. Our guide, Kevin, was excellent. He told me that if I wanted to continue, he would walk next to me, on the drop side, and allow me to walk nearest the cliff wall. We began our descent, with me staring at the ground, Kevin at my side, and my friend taking in all the sights.</p><p class="paragraph" style="text-align:left;">We crossed through the “Oh Ah” point, which, as Kevin explained, is where most people turn around and go back up. Kevin asked if we wanted to continue, and I said we’ll go for it.</p><p class="paragraph" style="text-align:left;">We continued our descent and reached Cedar Ridge, a vast plane 1.5 miles down the trail into the Canyon. It was a nice break to be in such a flat space. I could eat dinner, recharge, and enjoy the sunset&#39;s views.</p><p class="paragraph" style="text-align:left;">I did look on as two young folks creating influencer videos stood on a dead tree at the edge of the Canyon to capture a video of themselves. The threat modeling person within was about to scream. Dead tree, side of Canyon with thousand-foot drops—you get the picture.</p><p class="paragraph" style="text-align:left;">Then we began our 1.5-mile ascent, which was a chore, but cresting the final hill and walking back across the parking lot gave me the opportunity for a victory dance. I had reached Cedar Ridge, a place within the Grand Canyon that only 1% of visitors will ever see. </p><p class="paragraph" style="text-align:left;">I’m proud that I pushed through and faced my fear, and I also learned some things to apply to application security from this experience.</p><ol start="1"><li><p class="paragraph" style="text-align:left;"><b>Security, too, is about the people</b>: Kevin, the hiking guide, taught me techniques for walking down and up the trail and coached me through. He also kept the conversation going nonstop to take my mind off the danger I felt. Security people must strive to coach and walk alongside developers, showing empathy toward their situations.</p></li><li><p class="paragraph" style="text-align:left;"><b>Spend time on the ground, not just looking from the plane&#39;s window</b>: When you roll up your sleeves and connect with the people on the ground, you learn more about your organization. Build your security strategy based on the details you can see from the ground.</p></li><li><p class="paragraph" style="text-align:left;"><b>Find people who love what they do</b>: People who love what they do are infectious. Kevin is a perfect example of somebody who loves their job so much they would do it for free. Find security champions passionate about security and help them unlock their security knowledge and experience.</p></li><li><p class="paragraph" style="text-align:left;"><b>Threat model your vacation destinations!</b>: I’m glad I didn’t threat model this experience because I would never have begun descending the Canyon. In general, threat model your experiences to ensure you know the risk.</p></li></ol><h2 class="heading" style="text-align:left;" id="podcast-corner">Podcast Corner</h2><p class="paragraph" style="text-align:left;">I love making podcasts. In Podcast Corner, you get a single place to see what I’ve put out this week. Sometimes, they are my podcasts. Other times, they are podcasts that have caught my attention.</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://appsec.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-71-threat-modeling-a-vacation-or-the-lack-thereof-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Application Security Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Steve Wilson -- The Developer&#39;s Playbook for Large Language Model Security: Building Secure AI Applications (<a class="link" href="https://www.buzzsprout.com/1730684/episodes/15848921?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-71-threat-modeling-a-vacation-or-the-lack-thereof-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/It1HDlYJ-w0?si=dPCtjDLfJugCAZ1G&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-71-threat-modeling-a-vacation-or-the-lack-thereof-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">We welcome Steve Wilson to discuss his book &#39;The Developer’s Playbook for Large Language Model Security, which covers AI hallucinations, trust, and future AI challenges.</p></li><li><p class="paragraph" style="text-align:left;">Steve offers insights on security boundaries and LLM-specific testing tools and addresses vital concerns in the evolving AI landscape.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitytable.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-71-threat-modeling-a-vacation-or-the-lack-thereof-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Security Table</a></p><ul><li><p class="paragraph" style="text-align:left;">A Show About Nothing That Turned into Something (<a class="link" href="https://www.buzzsprout.com/2094080/episodes/13734109?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-71-threat-modeling-a-vacation-or-the-lack-thereof-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/-kQRk7uGsmM?si=7YIEVdBtb_5sAfds&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-71-threat-modeling-a-vacation-or-the-lack-thereof-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Chris Romeo, Izar Tarandach, and Matt Coles discuss how Application Security tools should automate tasks that humans can perform but with incredible speed and efficiency.</p></li><li><p class="paragraph" style="text-align:left;">Izar highlights the difficulty of managing attention spans and context-switching across multiple Slack channels, while Chris teases the possibility of AppSec becoming obsolete.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://threatmodel.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-71-threat-modeling-a-vacation-or-the-lack-thereof-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Threat Modeling Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">What is the Essence of Threat Modeling? (<a class="link" href="https://www.buzzsprout.com/2152378/episodes/12732554?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-71-threat-modeling-a-vacation-or-the-lack-thereof-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Chris Romeo discusses different definitions of threat modeling, exploring whether it overlaps with risk assessment and emphasizing early threat identification and mitigation through structured brainstorming.</p></li><li><p class="paragraph" style="text-align:left;">He highlights the Threat Modeling Manifesto&#39;s definition, noting that threat modeling blends art, science, and collaboration to address security and privacy concerns in systems.</p></li></ul></li></ul></li></ul><h2 class="heading" style="text-align:left;" id="threat-model-for-free">Threat Model for Free</h2><p class="paragraph" style="text-align:left;">Welcome to <b>Simple, Collaborative</b> Threat Modeling by Devici.</p><p class="paragraph" style="text-align:start;">Introducing the modern drawing tool that&#39;s user-friendly, customizable, and easy on the eyes. Individuals and teams work together – no matter their location. Devici helps build a scalable threat modeling process for multi-disciplinary and geographically dispersed teams, ensuring everyone can contribute.</p><p class="paragraph" style="text-align:start;">Visit <a class="link" href="http://devici.com?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-71-threat-modeling-a-vacation-or-the-lack-thereof-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">devici.com</a> to experience <a class="link" href="https://app.devici.com/sign-up?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-71-threat-modeling-a-vacation-or-the-lack-thereof-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">threat modeling for free</a>.</p><div class="image"><a class="image__link" href="https://app.devici.com/sign-up?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-71-threat-modeling-a-vacation-or-the-lack-thereof-five-security-articles-and-podcast-corner" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/76ff3f8d-4c7b-46a9-a5ce-3e294c14410b/image.png?t=1724951951"/></a></div><h2 class="heading" style="text-align:left;" id="where-to-find-chris">Where to find Chris? 🌎</h2><ul><li><p class="paragraph" style="text-align:left;">Nothing on the docket now, but stay tuned for the next webinar!</p></li></ul><p class="paragraph" style="text-align:left;">🤔<i> Have questions, comments, or feedback? I&#39;d love to </i><span style="text-decoration:underline;"><i><b><a class="link" href="mailto:chris@kerr.ventures?ref=ReasonableAppSec" target="_blank" rel="noopener noreferrer nofollow">hear</a></b></i></span><i> from you!</i></p><p class="paragraph" style="text-align:start;">🔥<i> Reasonable AppSec is brought to you by </i><span style="text-decoration:underline;"><i><b><a class="link" href="https://kerr.ventures?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-71-threat-modeling-a-vacation-or-the-lack-thereof-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Kerr Ventures</a></b></i></span><i>.</i></p><p class="paragraph" style="text-align:start;">🤝<i> Want to partner with Reasonable AppSec? Reach out, and let’s chat.</i></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=4733f4ce-8c07-41f9-b51f-fc91b04444ca&utm_medium=post_rss&utm_source=reasonable_application_security">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Reasonable 🔐AppSec #70 -  DevSecOps is dead, Five Security Articles and Podcast Corner</title>
  <description>A review of application security happenings and industry news from Chris Romeo.</description>
  <link>https://appsec.beehiiv.com/p/reasonable-appsec-70-devsecops-is-dead-five-security-articles-and-podcast-corner</link>
  <guid isPermaLink="true">https://appsec.beehiiv.com/p/reasonable-appsec-70-devsecops-is-dead-five-security-articles-and-podcast-corner</guid>
  <pubDate>Tue, 01 Oct 2024 16:00:00 +0000</pubDate>
  <atom:published>2024-10-01T16:00:00Z</atom:published>
    <dc:creator>Chris Romeo</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><b>Hey there,</b></p><p class="paragraph" style="text-align:left;">In this week’s issue, please enjoy the following:</p><ul><li><p class="paragraph" style="text-align:left;">Five security articles 📰 that are worth YOUR time</p></li><li><p class="paragraph" style="text-align:left;">Featured focus: DevSecOps is dead</p></li><li><p class="paragraph" style="text-align:left;">Application Security Podcast 🎙️Corner</p></li><li><p class="paragraph" style="text-align:left;">Where to find Chris? 🌎</p></li></ul><h2 class="heading" style="text-align:left;" id="five-security-articles-that-are-wor">Five Security Articles 📰 that Are Worth YOUR Time</h2><ol start="1"><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.nodejs-security.com/blog/raw-sql-queries-better-for-security-than-orms?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-70-devsecops-is-dead-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Raw SQL Queries are Actually Better for Security Than ORMs?</a> — Raw SQL queries can enhance security by giving developers greater control over query structure and execution, reducing the risk of vulnerabilities associated with Object-Relational Mappers (ORMs). The article argues that while ORMs simplify database interactions, they can introduce complexity that may lead to security issues, making raw SQL a more secure choice in specific scenarios. <b>[</b><span style="background-color:#FFFFFF;"><b>This seems like sacrilege — read it closer to see if you agree or disagree?</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.theverge.com/2024/9/23/24251945/microsoft-security-report-secure-future-initiative?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-70-devsecops-is-dead-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Microsoft’s largest ever security transformation detailed in new report</a> —</p><p class="paragraph" style="text-align:left;">Microsoft&#39;s latest security report highlights the growing importance of integrated security measures as organizations face increasingly sophisticated cyber threats. The initiative aims to strengthen collaboration between tech companies and businesses to create a more resilient security ecosystem, emphasizing proactive strategies and continuous improvement. <b>[</b><span style="background-color:#FFFFFF;"><b>Going back to 2003 with the memo and the dawn of Trustworthy Computing, MSFT has pushed the envelope. I’ll be following this new movement as it progresses.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://technology.toasttab.com/entry/living-the-blueberry-muffin-principle-baked-in-security-for-developers/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-70-devsecops-is-dead-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Living the Blueberry Muffin Principle: Baked-In Security for Developers</a> — </p><p class="paragraph" style="text-align:left;">The &quot;Blueberry Muffin Principle&quot; emphasizes integrating security measures directly into the development process rather than treating them as an afterthought. Organizations can enhance their security posture and reduce vulnerabilities by fostering a culture where security is fundamental to development. <b>[</b><span style="background-color:#FFFFFF;"><b>I’m a sucker for a good software security illustration.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/intel-informs-customers-about-over-a-dozen-processor-vulnerabilities/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-70-devsecops-is-dead-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Intel Warns of 20+ Vulnerabilities, Advises Firmware Updates</a> — Intel has notified customers about more than a dozen vulnerabilities in its processors, which could potentially allow attackers to execute arbitrary code or gain unauthorized access to sensitive information. The company is working on patches to mitigate these risks and urges users to update their systems to enhance security. <b>[</b><span style="background-color:#FFFFFF;"><b>I’ve always thought that the most effective exploit possible is a processor vulnerability that allows an exploit.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.apheris.com/resources/blog/a-devsecops-journey-to-secure-and-standardize-github-repositories?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-70-devsecops-is-dead-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Managing Github as code: A DevSecOps approach</a> — A DevSecOps journey focused on securing and standardizing GitHub repositories aims to enhance software development security and streamline collaboration among development, security, and operations teams. The organization seeks to ensure compliance and reduce vulnerabilities by implementing best practices and automated tools. <b>[</b><span style="background-color:#FFFFFF;"><b>Very thorough explanation of DevSecOps in real life.</b></span><b>]</b></p></li></ol><h2 class="heading" style="text-align:left;" id="featured-focus-dev-sec-ops-is-dead">Featured Focus: DevSecOps is dead</h2><p class="paragraph" style="text-align:left;">I feel like DevSecOps has had its moment/time in the sun/fifteen minutes of fame, and it’s time to move on. This idea was sparked by a conversation with Jeff Williams on the AppSec Podcast, mentioned below. In discussing ADR, Jeff shared the reality of the disconnect between the operations team and AppSec.</p><p class="paragraph" style="text-align:left;">Our industry has promoted the idea that DevSecOps involves all three groups walking hand in hand toward secure software. Jeff shared that operations were never at the table and are unaware of what is happening in the AppSec world. Development and security have done an okay job of adding tooling to pipelines and focusing more heavily on security, but operations were never in sync.</p><p class="paragraph" style="text-align:left;">Perhaps it’s time to move on from the industry&#39;s focus on DevSecOps. DevSecOps is how we build software with pipelines, but everybody I know uses Agile or Kanban to source and track work. Let’s let the hype dry up on DevSecOps in the future. It’s not like we don’t have other problems to solve. Find something else to talk about at a conference.</p><h2 class="heading" style="text-align:left;" id="podcast-corner">Podcast Corner</h2><p class="paragraph" style="text-align:left;">I love making podcasts. In Podcast Corner, you get a single place to see what I’ve put out this week. Sometimes, they are my podcasts. Other times, they are podcasts that have caught my attention.</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://appsec.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-70-devsecops-is-dead-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Application Security Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Jeff Williams -- Application Detection & Response (ADR) (<a class="link" href="https://www.buzzsprout.com/1730684/episodes/15805086?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-70-devsecops-is-dead-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/mOnMTooPiw4?si=FP8xpOuEb-dcpsNi&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-70-devsecops-is-dead-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Hosts Chris Romeo and Robert Hurlbut engage with Jeff Williams, a pioneer in application security, to explore the transformative potential of Application Detection and Response (ADR) in production environments. </p></li><li><p class="paragraph" style="text-align:left;">Jeff shares insights from his career, including the founding of OWASP and his views on security assurance, providing valuable perspectives for newcomers and seasoned professionals in the AppSec field.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitytable.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-70-devsecops-is-dead-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Security Table</a></p><ul><li><p class="paragraph" style="text-align:left;">The Hamster Wheel of Scan and Fix (<a class="link" href="https://www.buzzsprout.com/2094080/episodes/13659947?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-70-devsecops-is-dead-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/AMfNzGicIqA?si=SFhWU0GZzWdanWI-&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-70-devsecops-is-dead-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Hosts Chris Romeo, Matt, and Izar engage in a lively debate about the limitations of the &quot;scan and fix&quot; approach in application security, with Chris critiquing the prevalent tools that often generate lengthy lists of vulnerabilities filled with false positives. </p></li><li><p class="paragraph" style="text-align:left;">The discussion highlights the necessity for more innovative, context-aware security solutions, emphasizing the importance of actionable insights and the human factor in security practices, ultimately advocating for a shift away from traditional methodologies.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://threatmodel.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-70-devsecops-is-dead-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Threat Modeling Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Nandita Rao Narla -- Privacy Threat Modeling Wins, Losses, and Tools (<a class="link" href="https://www.buzzsprout.com/2152378/episodes/15068747?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-70-devsecops-is-dead-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Hosts Chris Romeo and Nandita Rao Narla discuss the common pitfalls of privacy threat modeling programs, including high costs, friction in development processes, and a focus on compliance over risk management. </p></li><li><p class="paragraph" style="text-align:left;">Nandita also shares effective strategies for improvement, such as simplifying methodologies, leveraging existing resources, and fostering a proactive mindset towards potential risks, emphasizing the need for a strong partnership between privacy and security threat modeling.</p></li></ul></li></ul></li></ul><h2 class="heading" style="text-align:left;" id="threat-model-for-free">Threat Model for Free</h2><p class="paragraph" style="text-align:left;">Welcome to <b>Simple, Collaborative</b> Threat Modeling by Devici.</p><p class="paragraph" style="text-align:start;">Introducing the modern drawing tool that&#39;s user-friendly, customizable, and easy on the eyes. Individuals and teams work together – no matter their location. Devici helps build a scalable threat modeling process for multi-disciplinary and geographically dispersed teams, ensuring everyone can contribute.</p><p class="paragraph" style="text-align:start;">Visit <a class="link" href="http://devici.com?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-70-devsecops-is-dead-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">devici.com</a> to experience <a class="link" href="https://app.devici.com/sign-up?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-70-devsecops-is-dead-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">threat modeling for free</a>.</p><div class="image"><a class="image__link" href="https://app.devici.com/sign-up?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-70-devsecops-is-dead-five-security-articles-and-podcast-corner" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/76ff3f8d-4c7b-46a9-a5ce-3e294c14410b/image.png?t=1724951951"/></a></div><h2 class="heading" style="text-align:left;" id="where-to-find-chris">Where to find Chris? 🌎</h2><ul><li><p class="paragraph" style="text-align:left;">Nothing on the docket at the moment, but stay tuned for the next webinar!</p></li></ul><p class="paragraph" style="text-align:left;">🤔<i> Have questions, comments, or feedback? I&#39;d love to </i><span style="text-decoration:underline;"><i><b><a class="link" href="mailto:chris@kerr.ventures?ref=ReasonableAppSec" target="_blank" rel="noopener noreferrer nofollow">hear</a></b></i></span><i> from you!</i></p><p class="paragraph" style="text-align:start;">🔥<i> Reasonable AppSec is brought to you by </i><span style="text-decoration:underline;"><i><b><a class="link" href="https://kerr.ventures?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-70-devsecops-is-dead-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Kerr Ventures</a></b></i></span><i>.</i></p><p class="paragraph" style="text-align:start;">🤝<i> Want to partner with Reasonable AppSec? Reach out, and let’s chat.</i></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=057d1ec6-149a-47ed-94ad-4147f860cd14&utm_medium=post_rss&utm_source=reasonable_application_security">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Reasonable 🔐AppSec #69 -  Should I Stay or Should I Go Now?, Five Security Articles and Podcast Corner</title>
  <description>A review of application security happenings and industry news from Chris Romeo.</description>
  <link>https://appsec.beehiiv.com/p/reasonable-appsec-69-stay-go-now-five-security-articles-podcast-corner</link>
  <guid isPermaLink="true">https://appsec.beehiiv.com/p/reasonable-appsec-69-stay-go-now-five-security-articles-podcast-corner</guid>
  <pubDate>Tue, 24 Sep 2024 16:00:00 +0000</pubDate>
  <atom:published>2024-09-24T16:00:00Z</atom:published>
    <dc:creator>Chris Romeo</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><b>Hey there,</b></p><p class="paragraph" style="text-align:left;">In this week’s issue, please enjoy the following:</p><ul><li><p class="paragraph" style="text-align:left;">Five security articles 📰 that are worth YOUR time</p></li><li><p class="paragraph" style="text-align:left;">Featured focus: Should I Stay or Should I Go Now?</p></li><li><p class="paragraph" style="text-align:left;">Application Security Podcast 🎙️Corner</p></li><li><p class="paragraph" style="text-align:left;">Where to find Chris? 🌎</p></li></ul><h2 class="heading" style="text-align:left;" id="five-security-articles-that-are-wor">Five Security Articles 📰 that Are Worth YOUR Time</h2><ol start="1"><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://softwareanalyst.substack.com/p/redefining-cnapp-a-complete-guide?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-69-should-i-stay-or-should-i-go-now-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Redefining CNAPP: A Complete Guide To the Future of Cloud Security</a> — This report provides a holistic view of cloud security&#39;s evolution, tracing its significant milestones, a detailed breakdown of the critical vendors today, and evolving market shifts. It presents a new framework for redefining Cloud Native Application Protection Platforms (CNAPP), addressing its limitations and contradictions while offering a comprehensive roadmap to navigate the future of cloud security. <b>[</b><span style="background-color:#FFFFFF;"><b>Lately, you’ve seen me comment that “I’m a big fan of…” on stuff. The same goes for this one — I’m a big fan of James Berthoty and the breath of fresh air he’s bringing to analyzing our industry.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.reversinglabs.com/blog/fake-recruiter-coding-tests-target-devs-with-malicious-python-packages?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-69-should-i-stay-or-should-i-go-now-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Fake recruiter coding tests target devs with malicious Python packages</a> — Fake recruiters target developers with malicious Python packages disguised as coding tests, posing significant security risks. The blog highlights the importance of vigilance and caution when downloading and running third-party packages to avoid falling victim to these scams. <b>[</b><span style="background-color:#FFFFFF;"><b>I’ve been around a long time in this industry, but I’m always most sickened when attackers prey on desperate people.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://ramimac.me/scorecarding?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-69-should-i-stay-or-should-i-go-now-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Scorecarding Security</a> — Scorecarding is introduced as a method for evaluating the security posture of applications and organizations through quantitative metrics. This approach helps identify strengths and weaknesses in security practices, enabling better decision-making and resource allocation to improve overall security. <b>[</b><span style="background-color:#FFFFFF;"><b>Scorecards are crucial to governance, connecting results for security investments with visibility to the entire business.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.endorlabs.com/lp/2024-dependency-management-report?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-69-should-i-stay-or-should-i-go-now-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">2024 Dependency Management Report</a> — The 2024 Dependency Management Report reveals crucial insights into the challenges organizations face with software dependencies, including security vulnerabilities and management complexities. It emphasizes the need for improved practices and tools to manage dependencies and enhance overall software security. <b>[</b><span style="background-color:#FFFFFF;"><b>Software supply chain should be so easy to solve.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.resourcely.io/post/the-road-to-simplicity?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-69-should-i-stay-or-should-i-go-now-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">The Road to Simplicity</a> — Focusing on simplicity in organizational processes and tools is essential for improving team efficiency and effectiveness. By streamlining workflows and minimizing complexity, organizations can empower their members to prioritize value creation, reduce frustration, and achieve their goals more effectively. <b>[</b><span style="background-color:#FFFFFF;"><b>Simple is always the answer to any problem.</b></span><b>]</b></p></li></ol><h2 class="heading" style="text-align:left;" id="featured-focus-should-i-stay-or-sho">Featured Focus: Should I Stay or Should I Go Now?</h2><p class="paragraph" style="text-align:left;">“Should I stay, or should I go now?<br>Should I stay, or should I go now?<br>If I go, there will be trouble<br>And if I stay, it will be double<br>So come on and let me know”</p><p class="paragraph" style="text-align:left;">— The Clash</p><p class="paragraph" style="text-align:left;">The song is famous, and you might be hearing it in your head now. (You’re welcome.) It’s got me thinking about the future of my public speaking career.</p><p class="paragraph" style="text-align:left;">I’m at InfoSec World in Orlando, FL. They say this town and the Disney properties are “the happiest place on earth.” Based on the number of children screaming in public places at the hotel, I&#39;m unsure. But I digress.</p><p class="paragraph" style="text-align:left;">I’ve begun to think about my future role in our industry. Over the years, I’ve had the luxury and the gift of being invited to speak at many major conferences, from RSA to DefCon AppSec Village to OWASP Global. Speaking has been a large part of my career since 2016 after I started Security Journey. I enjoy attending conferences and sharing my experience and insights into our industry.</p><p class="paragraph" style="text-align:left;">The question I’m pondering is when it is time to slow down and let others have a turn. Am I blocking others from having an opportunity on the stage by continuing to submit to conferences? I will ponder this over the coming months and think about my approach for 2025.</p><p class="paragraph" style="text-align:left;">My current thought is to step back and do less speaking while continuing to contribute to the podcasts I am a part of. Podcasts have a different reach and a different lifespan than conference talks.</p><p class="paragraph" style="text-align:left;">If I decide to proceed with this plan and step back, I’ll miss the opportunities to meet and encourage new people in our industry. I’ll miss seeing friends at various events, some of whom I worked with decades ago. Every industry has this experience where you do something for the last time. Everything we do has a “last time” you’ll do it. This is part of maturing and part of bringing a phase of a career to a close. </p><p class="paragraph" style="text-align:left;">I won’t miss the travel and preparation that goes into each talk, but I will miss the opportunity to teach. I’m a teacher at heart. I guess I’ll have to find a new avenue to teach from. Perhaps it’s time to take what I’ve been blessed to learn and know and share it in other avenues, such as the university system. Time will tell.</p><p class="paragraph" style="text-align:left;">If you have any thoughts on this topic, please message me. I’d love to get other perspectives on this issue. </p><h2 class="heading" style="text-align:left;" id="podcast-corner">Podcast Corner</h2><p class="paragraph" style="text-align:left;">I love making podcasts. In Podcast Corner, you get a single place to see what I’ve put out this week. Sometimes, they are my podcasts. Other times, they are podcasts that have caught my attention.</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://appsec.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-69-should-i-stay-or-should-i-go-now-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Application Security Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Phillip Wylie -- Pen Testing from Somebody Who Knows about Pen TWsting (<a class="link" href="https://www.buzzsprout.com/1730684/15763999?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-69-should-i-stay-or-should-i-go-now-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/OVt55RXQ_r4?si=9NatoPxZOyIXg1TB&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-69-should-i-stay-or-should-i-go-now-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">We welcome Philip Wylie, who shares his fascinating journey from professional wrestling to becoming a renowned pen tester.</p></li><li><p class="paragraph" style="text-align:left;">He offers entertaining stories and insights from his unique background.</p></li><li><p class="paragraph" style="text-align:left;">The episode includes in-depth discussions on application security and valuable advice for those looking to start a career in cybersecurity, making it a rich resource for listeners interested in pen testing and career development.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitytable.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-69-should-i-stay-or-should-i-go-now-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Security Table</a></p><ul><li><p class="paragraph" style="text-align:left;">Numb to Data Breaches and How it Impacts Security of the Average Feature (<a class="link" href="https://www.buzzsprout.com/2094080/15772033?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-69-should-i-stay-or-should-i-go-now-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/g4N_lbpbzek?si=EeS7yoKPOhpyZWga&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-69-should-i-stay-or-should-i-go-now-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Explore the evolving landscape of modern security approaches, discussing the shift from strategy to tactics and the growing desensitization to data breaches.</p></li><li><p class="paragraph" style="text-align:left;">The conversation emphasizes the importance of understanding security&#39;s business side and highlights product managers&#39; role as essential security champions.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://threatmodel.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-69-should-i-stay-or-should-i-go-now-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Threat Modeling Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Nandita Rao Narla -- Privacy Threat Modeling (<a class="link" href="https://www.buzzsprout.com/2152378/14365330?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-69-should-i-stay-or-should-i-go-now-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Hosts Chris Romeo and Izar Tarandach welcome Nandita Rao Narla, who introduces the basics of privacy in software, discussing privacy threats, threat modeling, and the principles of privacy by design.</p></li><li><p class="paragraph" style="text-align:left;">The episode emphasizes the importance of understanding and mitigating privacy concerns for anyone involved in handling user information, making it an essential primer for incorporating privacy into software design.</p></li></ul></li></ul></li></ul><h2 class="heading" style="text-align:left;" id="threat-model-for-free">Threat Model for Free</h2><p class="paragraph" style="text-align:left;">Welcome to <b>Simple, Collaborative</b> Threat Modeling by Devici.</p><p class="paragraph" style="text-align:start;">Introducing the modern drawing tool that&#39;s user-friendly, customizable, and easy on the eyes. Individuals and teams work together – no matter their location. Devici helps build a scalable threat modeling process for multi-disciplinary and geographically dispersed teams, ensuring everyone can contribute.</p><p class="paragraph" style="text-align:start;">Visit <a class="link" href="http://devici.com?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-69-should-i-stay-or-should-i-go-now-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">devici.com</a> to experience <a class="link" href="https://app.devici.com/sign-up?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-69-should-i-stay-or-should-i-go-now-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">threat modeling for free</a>.</p><div class="image"><a class="image__link" href="https://app.devici.com/sign-up?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-69-should-i-stay-or-should-i-go-now-five-security-articles-and-podcast-corner" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/76ff3f8d-4c7b-46a9-a5ce-3e294c14410b/image.png?t=1724951951"/></a></div><h2 class="heading" style="text-align:left;" id="where-to-find-chris">Where to find Chris? 🌎</h2><ul><li><p class="paragraph" style="text-align:left;">Nothing on the docket at the moment, but stay tuned for the next webinar!</p></li></ul><p class="paragraph" style="text-align:left;">🤔<i> Have questions, comments, or feedback? I&#39;d love to </i><span style="text-decoration:underline;"><i><b><a class="link" href="mailto:chris@kerr.ventures?ref=ReasonableAppSec" target="_blank" rel="noopener noreferrer nofollow">hear</a></b></i></span><i> from you!</i></p><p class="paragraph" style="text-align:start;">🔥<i> Reasonable AppSec is brought to you by </i><span style="text-decoration:underline;"><i><b><a class="link" href="https://kerr.ventures?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-69-should-i-stay-or-should-i-go-now-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Kerr Ventures</a></b></i></span><i>.</i></p><p class="paragraph" style="text-align:start;">🤝<i> Want to partner with Reasonable AppSec? Reach out, and let’s chat.</i></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=11fd6161-0a86-4d88-9f79-d6cbf916ae1e&utm_medium=post_rss&utm_source=reasonable_application_security">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Reasonable 🔐AppSec #68 -  My favorite boss, Five Security Articles and Podcast Corner</title>
  <description>A review of application security happenings and industry news from Chris Romeo.</description>
  <link>https://appsec.beehiiv.com/p/reasonable-appsec-68-favorite-boss-five-security-articles-podcast-corner</link>
  <guid isPermaLink="true">https://appsec.beehiiv.com/p/reasonable-appsec-68-favorite-boss-five-security-articles-podcast-corner</guid>
  <pubDate>Tue, 17 Sep 2024 16:04:50 +0000</pubDate>
  <atom:published>2024-09-17T16:04:50Z</atom:published>
    <dc:creator>Chris Romeo</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><b>Hey there,</b></p><p class="paragraph" style="text-align:left;">In this week’s issue, please enjoy the following:</p><ul><li><p class="paragraph" style="text-align:left;">Five security articles 📰 that are worth YOUR time</p></li><li><p class="paragraph" style="text-align:left;">Featured focus: My favorite “boss”</p></li><li><p class="paragraph" style="text-align:left;">Application Security Podcast 🎙️Corner</p></li><li><p class="paragraph" style="text-align:left;">Where to find Chris? 🌎</p></li></ul><h2 class="heading" style="text-align:left;" id="five-security-articles-that-are-wor">Five Security Articles 📰 that Are Worth YOUR Time</h2><ol start="1"><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.iansresearch.com/resources/press-releases/detail/new-research-reveals-security-budgets-only-increased-2-points-in-2024--while-12--of-cisos-faced-reductions?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-68-my-favorite-boss-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">New Research Reveals Security Budgets Only Increased 2 Points in 2024, While 12% of CISOs Faced Reductions</a> — Security budgets increased by only 2% in 2024, reflecting a modest rise in financial commitment to cybersecurity despite rising threats. Additionally, 12% of CISOs experienced budget reductions, signaling financial constraints and potential challenges in maintaining security investments. <b>[</b><span style="background-color:#FFFFFF;"><b>This is consistent with what I’ve seen in the market — budgets are tighter, and even security teams are forced to make hard decisions.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://cybernews.com/tech/your-phone-listening-in/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-68-my-favorite-boss-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">They&#39;ll deny it, but your phone is listening in</a> — Concerns are growing about smartphones secretly listening to conversations and collecting personal data without users&#39; explicit consent. Despite these fears, experts highlight that many apps and services use permissions and data collection practices that are often misunderstood by users, raising questions about privacy and transparency. <b>[</b><span style="background-color:#FFFFFF;"><b>We’ve invited the phone to encapsulate every angle of our lives — we are too dependent on these privacy-breaching devices that we carry around in our pockets, every place we go. I’m considering a move back to a flip phone.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://nahsra.hashnode.dev/sustained-attention-fatigue-in-vulnerability-analysis?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-68-my-favorite-boss-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Sustained Attention Fatigue in Vulnerability Analysis</a> — Sustained attention fatigue in vulnerability analysis results in decreased effectiveness and oversight due to prolonged focus on security issues. Improved strategies and tools are necessary to manage attention and maintain vigilance against persistent security challenges. <b>[</b><span style="background-color:#FFFFFF;"><b>AI could play a role in summarizing this data in such a way as to remove some of the fatigue.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://betterappsec.com/making-sense-of-the-application-security-product-market-b659a8e81b6b?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-68-my-favorite-boss-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Making Sense of the Application Security Product Market</a> — Understanding the application security product market requires recognizing the diversity of tools available, from static and dynamic analysis to software composition analysis and more. Each product addresses different security needs, so evaluating their specific strengths and fit for your organization’s unique challenges is essential. <b>[</b><span style="background-color:#FFFFFF;"><b>I enjoyed this view of the market — looking at how others categorize our space is helpful. It makes me think deeper about how I bucketize the different categories of what we do as an industry.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://ventureinsecurity.net/p/lifting-the-world-out-of-the-cybersecurity?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-68-my-favorite-boss-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Lifting the world out of the cybersecurity poverty</a> — Cybersecurity talent shortages and high demand drive up wages, pushing companies to invest more in training and retention strategies. To address these issues, organizations must foster a culture of continuous learning and adapt their hiring practices to cultivate and retain skilled professionals. <b>[</b><span style="background-color:#FFFFFF;"><b>Grow your own — that is my strategy for any team I run. I take folks and grow them up in cybersecurity. Yes, this does mean that sometimes I invest in them, and they move on to bigger and better things, but that is a sign of success!</b></span><b>]</b></p></li></ol><h2 class="heading" style="text-align:left;" id="featured-focus-my-favorite-boss">Featured Focus: My favorite boss</h2><p class="paragraph" style="text-align:left;">My first boss at Cisco was a guy named Tom Sweeney. Tom was an early Cisco employee and is famous for being Cisco’s first employee in NYC and for wiring Wall Street during Cisco’s land grab with such a strategic part of the world. Tom had a standing pool match with Cisco&#39;s CEO at every sales conference.</p><p class="paragraph" style="text-align:left;">Tom taught me a lot in my few years working for him, but one thing still sticks with me. He said, “Manage your career not by the number of people you manage but by the number of managers you create.” I can’t say that I understood the gravity of this statement while reporting to Tom, but as I reflect on almost three decades of my professional career, I realize the depth of this statement.</p><p class="paragraph" style="text-align:left;">Many people judge themselves based on the size of their team, and they say, “I manage one hundred people” on my team as if that is a badge of honor. Tom would recommend counting the number of people you lead to become managers. This is the approach that I take today in my career.</p><p class="paragraph" style="text-align:left;">Focus on growing people up. Tom gave me a functional area within our team’s business, got out of my way, and let me do my thing. Team autonomy was another lesson I learned from Tom. He did have one rule: “Don’t let somebody come after you to me without me knowing in advance.” I only had to brief him once about a team that I ticked off, and that was coming for my head. Tom had my back that day. Tom was the best manager of my career, and I’m grateful for the time I spent working with him. You never worked FOR Tom; you always worked with him. That was how he introduced you, and if you ever said, “I work for Tom,” he would correct you by saying, “We work together.” </p><p class="paragraph" style="text-align:left;">Thank your mentors, folks. Take what you learned from them and pour it into others as they poured into you.</p><h2 class="heading" style="text-align:left;" id="podcast-corner">Podcast 🎙️ Corner</h2><p class="paragraph" style="text-align:left;">I love making podcasts. In Podcast Corner, you get a single place to see what I’ve put out this week. Sometimes, they are my podcasts. Other times, they are podcasts that have caught my attention.</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://appsec.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-68-my-favorite-boss-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Application Security Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Maril Vernon -- You Get What You Inspect, Not What You Expect (<a class="link" href="https://www.buzzsprout.com/1730684/13488250?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-68-my-favorite-boss-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/5dWYUaGthaY?si=pOQ9hOGloaBd3kxW&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-68-my-favorite-boss-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Maril Vernon highlights the importance of integrating developers and security teams through purple teaming, emphasizing how framing recommendations in developer-centric language can bridge communication gaps and make security measures more actionable.</p></li><li><p class="paragraph" style="text-align:left;">She predicts a shift towards automation and AI in purple teaming. Still, she stresses that human red teamers&#39; creative and intuitive input will remain crucial, advocating for a more holistic approach to security that fosters cross-departmental collaboration.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitytable.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-68-my-favorite-boss-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Security Table</a></p><ul><li><p class="paragraph" style="text-align:left;">Philosophizing Cloud Security (<a class="link" href="https://www.buzzsprout.com/2094080/15730714?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-68-my-favorite-boss-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/FI7g__d21bY?si=QCov7w-lHpkuPIKe&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-68-my-favorite-boss-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Chris Romeo, Izar Tarandach, and Matt Coles discuss the &#39;Shared Fate Model&#39; in cloud security, building on the shared responsibility model to explore its impact on cloud service providers and consumers.</p></li><li><p class="paragraph" style="text-align:left;">They cover the evolution of internet service providers, technical details of cloud infrastructure security, and the philosophical implications of implementing robust default security measures.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://threatmodel.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-68-my-favorite-boss-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Threat Modeling Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Dr. Michael Loadenthal -- Intersectional, Harm Reduction Approach to Threat Modeling (<a class="link" href="https://www.buzzsprout.com/2152378/13462262?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-68-my-favorite-boss-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Dr. Michael Loadenthal expands threat modeling beyond technology to include political, legal, ethical, and social dimensions, emphasizing a comprehensive and multidisciplinary approach to addressing complex challenges.</p></li><li><p class="paragraph" style="text-align:left;">His unique &quot;intersectional threat modeling&quot; approach, influenced by social movements and activism, integrates tools like mind maps and the harm reduction framework to address various threats, benefiting diverse clients, from companies to high-profile individuals.</p></li></ul></li></ul></li></ul><h2 class="heading" style="text-align:left;" id="threat-model-for-free">Threat Model for Free</h2><p class="paragraph" style="text-align:left;">Welcome to <b>Simple, Collaborative</b> Threat Modeling by Devici.</p><p class="paragraph" style="text-align:start;">Introducing the modern drawing tool that&#39;s user-friendly, customizable, and easy on the eyes. Individuals and teams work together – no matter their location. Devici helps build a scalable threat modeling process for multi-disciplinary and geographically dispersed teams, ensuring everyone can contribute.</p><p class="paragraph" style="text-align:start;">Visit <a class="link" href="http://devici.com?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-68-my-favorite-boss-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">devici.com</a> to experience <a class="link" href="https://app.devici.com/sign-up?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-68-my-favorite-boss-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">threat modeling for free</a>.</p><div class="image"><a class="image__link" href="https://app.devici.com/sign-up?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-68-my-favorite-boss-five-security-articles-and-podcast-corner" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/76ff3f8d-4c7b-46a9-a5ce-3e294c14410b/image.png?t=1724951951"/></a></div><h2 class="heading" style="text-align:left;" id="where-to-find-chris">Where to find Chris? 🌎</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/events/7237134350381674496/about/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-68-my-favorite-boss-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Webinar: Threat Modeling and Secure Coding with Tanya Janca</a> — Thursday, September 19 @ noon (Eastern) — THIS WEEK! Get signed up now.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.infosecworldusa.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-68-my-favorite-boss-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">InfoSec World</a> — Sept 22-25, 2024</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.infosecworldusa.com/isw24/session/2225964/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-68-my-favorite-boss-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">The Modern Application Security Rocket Ship</a> — Monday, Sept 23, 10:15 AM</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.infosecworldusa.com/isw24/session/2225998/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-68-my-favorite-boss-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">The Paradox of Secure and Private By Design</a> — Tuesday, Sept 24, 1:30 PM</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.infosecworldusa.com/isw24/workshops/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-68-my-favorite-boss-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Workshop: Threat Modeling Championship: Breaker vs. Builder</a> — Sunday, Sept 22, 9 AM - 12 PM</p></li></ul></li></ul><p class="paragraph" style="text-align:left;">🤔<i> Have questions, comments, or feedback? I&#39;d love to </i><span style="text-decoration:underline;"><i><b><a class="link" href="mailto:chris@kerr.ventures?ref=ReasonableAppSec" target="_blank" rel="noopener noreferrer nofollow">hear</a></b></i></span><i> from you!</i></p><p class="paragraph" style="text-align:start;">🔥<i> Reasonable AppSec is brought to you by </i><span style="text-decoration:underline;"><i><b><a class="link" href="https://kerr.ventures?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-68-my-favorite-boss-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Kerr Ventures</a></b></i></span><i>.</i></p><p class="paragraph" style="text-align:start;">🤝<i> Want to partner with Reasonable AppSec? Reach out, and let’s chat.</i></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=32c7c9ff-e886-4f00-bed7-98df9fa0ebe7&utm_medium=post_rss&utm_source=reasonable_application_security">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Reasonable 🔐AppSec #67 -  Priorities, Five Security Articles and Podcast Corner</title>
  <description>A review of application security happenings and industry news from Chris Romeo.</description>
  <link>https://appsec.beehiiv.com/p/reasonable-appsec-67-priorities-five-security-articles-podcast-corner</link>
  <guid isPermaLink="true">https://appsec.beehiiv.com/p/reasonable-appsec-67-priorities-five-security-articles-podcast-corner</guid>
  <pubDate>Tue, 10 Sep 2024 16:00:00 +0000</pubDate>
  <atom:published>2024-09-10T16:00:00Z</atom:published>
    <dc:creator>Chris Romeo</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><b>Hey there,</b></p><p class="paragraph" style="text-align:left;">In this week’s issue, please enjoy the following:</p><ul><li><p class="paragraph" style="text-align:left;">Five security articles 📰 that are worth YOUR time</p></li><li><p class="paragraph" style="text-align:left;">Featured focus: Priorities</p></li><li><p class="paragraph" style="text-align:left;">Application Security Podcast 🎙️Corner</p></li><li><p class="paragraph" style="text-align:left;">Where to find Chris? 🌎</p></li></ul><h2 class="heading" style="text-align:left;" id="five-security-articles-that-are-wor">Five Security Articles 📰 that Are Worth YOUR Time</h2><ol start="1"><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://tldrsec.com/p/tldr-every-ai-talk-bsideslv-blackhat-defcon-2024?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-67-priorities-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">TL;DR: Every AI Talk from BSidesLV, Black Hat, and DEF CON 2024</a> — Key insights from AI-focused talks at BSidesLV, Black Hat, and DEF CON 2024 are summarized, covering emerging trends, critical discussions, and advancements in AI security. <b>[</b><span style="background-color:#FFFFFF;"><b>Kudos to Clint Gibler for summarizing the action from Vegas for those who don’t like desert climates or couldn’t make the trip.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://ian.sh/tsa?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-67-priorities-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Bypassing airport security via SQL injection</a> — A security researcher discovered a vulnerability in the TSA&#39;s Known Crewmember (KCM) system due to an SQL injection flaw in FlyCASS, allowing unauthorized individuals to bypass security checks. Despite disclosing the issue to the Department of Homeland Security, the TSA downplayed the risk, although the flaw was later fixed after the system was disabled. <b>[</b><span style="background-color:#FFFFFF;"><b>SQLi continues to pay off in 2024 — oh, when will we ever get this thing to disappear? 2042?</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/pulse/when-your-puzzle-has-few-broken-peices-derek-fisher-jwqje/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-67-priorities-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">When your puzzle has a few broken pieces</a> — We greatly rely on open-source software (OSS) in software development, emphasizing its benefits and security risks. While OSS accelerates innovation, it also introduces vulnerabilities, highlighting the need for organizations to adopt secure practices such as software composition analysis (SCA) and rigorous code reviews to mitigate risks associated with malicious or vulnerable packages. <b>[</b><span style="background-color:#FFFFFF;"><b>Another well-thought-out and researched analysis by Derek Fisher.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://true-positives.com/appsec-blog/rethinking-threat-models-for-the-modern-age?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-67-priorities-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Rethinking Threat Models for the Modern Age</a> — Traditional threat models need to be expanded to account for modern communication habits and external human factors, such as the decline in answering phone calls and alert fatigue. Organizations should incorporate behavioral insights and external risks into their threat modeling to enhance security, ensuring their applications remain effective and resilient in a rapidly evolving technological landscape. <b>[</b><span style="background-color:#FFFFFF;"><b>We discussed this on the Security Table and debated it to some degree.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://research.checkpoint.com/2024/server-side-template-injection-transforming-web-applications-from-assets-to-liabilities/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-67-priorities-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Server-Side Template Injection: Transforming Web Applications From Assets to Liabilities</a> — Server-Side Template Injection (SSTI) is a vulnerability that allows attackers to inject and execute malicious code on a server via template engines. This can result in server compromise, data theft, and remote code execution, highlighting the need for secure coding practices, regular vulnerability assessments, and prompt patching to protect web applications from such exploits. <b>[</b><span style="background-color:#FFFFFF;"><b>This feels like it’s been around for a while, but it could be moving up the ranks as we mature past things like CSRF.</b></span><b>]</b></p></li></ol><h2 class="heading" style="text-align:left;" id="featured-focus-priorities">Featured Focus: Priorities</h2><p class="paragraph" style="text-align:left;">A few months ago, I experienced a momentous life achievement: I became a grandfather for the first time. Yes, to all you parents out there, what they say is true: raising grandchildren differs from raising your kids. </p><p class="paragraph" style="text-align:left;">A few additional decades of age have caused me to appreciate a baby more than I did before with my kids. We were a crazy house with four children separated by a total of four and a half years, so we were always on the move, and we lived an orderly, chaotic life, if it is even possible to put those two things together.</p><p class="paragraph" style="text-align:left;">Now, I stare into this kid&#39;s eyes and think about how I need to teach him to code securely to prevent XSS and SQLi and how to threat model. I kid, I kid. I’ll be happy if he has nothing to do with cybersecurity, but I won’t object if he wants to follow in his Granddad’s footsteps.</p><p class="paragraph" style="text-align:left;">You’re wondering what this article is doing in an application security-focused newsletter. I want to use this as an opportunity to remind you about priorities in life. Cybersecurity can consume us day and night, and our families can be the ones to suffer. Remember that you cannot return those days, months, and years with your children. Put down the laptop, throw the phone out the window, and enjoy prioritizing life focused on the people that matter the most. The work will be waiting for you in the morning.</p><h2 class="heading" style="text-align:left;" id="podcast-corner">Podcast 🎙️ Corner</h2><p class="paragraph" style="text-align:left;">I love making podcasts. In Podcast Corner, you get a single place to see what I’ve put out this week. Sometimes, they are my podcasts. Other times, they are podcasts that have caught my attention.</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://appsec.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-67-priorities-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Application Security Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Steve Springett -- Software and System Transparency (<a class="link" href="https://www.buzzsprout.com/1730684/15658049?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-67-priorities-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/-GKKpRIoRsI?si=djDtoGYs_y3FL34K&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-67-priorities-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Steve Springett discusses CycloneDX and the BOM landscape, highlighting new projects that aim to unify the security industry and enhance secure software development.</p></li><li><p class="paragraph" style="text-align:left;">The episode also offers a personal glimpse into Steve’s life outside of technology, sharing insights into his hobbies and interests.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitytable.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-67-priorities-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Security Table</a></p><ul><li><p class="paragraph" style="text-align:left;">Innovations in Threat Modeling? (<a class="link" href="https://www.buzzsprout.com/2094080/15654409?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-67-priorities-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/6hqAC2nPBSk?si=M8SF_p2Ast_3uTgn&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-67-priorities-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Hosts Chris Romeo, Izar Tarandach, and Matt Coles explore the evolving concept of threat models, examining the impact of user behavior, alert fatigue, and psychological acceptability on modern threat modeling.</p></li><li><p class="paragraph" style="text-align:left;">They discuss the article &quot;Rethinking Threat Models for the Modern Age&quot; by Evan Oslick, debating integrating broader human factors into threat modeling practices.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://threatmodel.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-67-priorities-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Threat Modeling Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Akira Brand -- Gaining Experience by Threat Modeling (<a class="link" href="https://www.buzzsprout.com/2152378/13676193?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-67-priorities-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Akira Brand discusses her journey into threat modeling, highlighting the critical role of collaboration, understanding the application, and using visual tools like data flow diagrams to ensure comprehensive security solutions.</p></li><li><p class="paragraph" style="text-align:left;">Drawing parallels between surgical checklists and the STRIDE model, Akira emphasizes that successful threat modeling involves practical, hands-on approaches and teamwork across engineering, data analytics, and security to address potential risks.</p></li></ul></li></ul></li></ul><h2 class="heading" style="text-align:left;" id="threat-model-for-free">Threat Model for Free</h2><p class="paragraph" style="text-align:left;">Welcome to <b>Simple, Collaborative</b> Threat Modeling by Devici.</p><p class="paragraph" style="text-align:start;">Introducing the modern drawing tool that&#39;s user-friendly, customizable, and easy on the eyes. Individuals and teams work together – no matter their location. Devici helps build a scalable threat modeling process for multi-disciplinary and geographically dispersed teams, ensuring everyone can contribute.</p><p class="paragraph" style="text-align:start;">Visit <a class="link" href="http://devici.com?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-67-priorities-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">devici.com</a> to experience <a class="link" href="https://app.devici.com/sign-up?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-67-priorities-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">threat modeling for free</a>.</p><div class="image"><a class="image__link" href="https://app.devici.com/sign-up?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-67-priorities-five-security-articles-and-podcast-corner" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/76ff3f8d-4c7b-46a9-a5ce-3e294c14410b/image.png?t=1724951951"/></a></div><h2 class="heading" style="text-align:left;" id="where-to-find-chris">Where to find Chris? 🌎</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/events/thesynergybetweenthreatmodeling7229594660409610242/theater/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-67-priorities-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Webinar: The Synergy Between Threat Modeling & Security Champions, with Dustin Lehr</a> — Tuesday, September 10 @ 2 PM (Eastern)</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/events/7237134350381674496/about/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-67-priorities-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Webinar: Threat Modeling and Secure Coding with Tanya Janca</a> — Thursday, September 19 @ noon (Eastern) — registration is open!</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.infosecworldusa.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-67-priorities-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">InfoSec World</a> — Sept 22-25, 2024</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.infosecworldusa.com/isw24/session/2225964/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-67-priorities-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">The Modern Application Security Rocket Ship</a> — Monday, Sept 23, 10:15 AM</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.infosecworldusa.com/isw24/session/2225998/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-67-priorities-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">The Paradox of Secure and Private By Design</a> — Tuesday, Sept 24, 1:30 PM</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.infosecworldusa.com/isw24/workshops/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-67-priorities-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Workshop: Threat Modeling Championship: Breaker vs. Builder</a> — Sunday, Sept 22, 9 AM - 12 PM</p></li></ul></li></ul><p class="paragraph" style="text-align:left;">🤔<i> Have questions, comments, or feedback? I&#39;d love to </i><span style="text-decoration:underline;"><i><b><a class="link" href="mailto:chris@kerr.ventures?ref=ReasonableAppSec" target="_blank" rel="noopener noreferrer nofollow">hear</a></b></i></span><i> from you!</i></p><p class="paragraph" style="text-align:start;">🔥<i> Reasonable AppSec is brought to you by </i><span style="text-decoration:underline;"><i><b><a class="link" href="https://kerr.ventures?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-67-priorities-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Kerr Ventures</a></b></i></span><i>.</i></p><p class="paragraph" style="text-align:start;">🤝<i> Want to partner with Reasonable AppSec? Reach out, and let’s chat.</i></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=bfc19cdf-c132-45e6-a2d0-b4c96f792638&utm_medium=post_rss&utm_source=reasonable_application_security">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Reasonable 🔐AppSec #66 -  Threat Modeling as Culture, Five Security Articles and Podcast Corner</title>
  <description>A review of application security happenings and industry news from Chris Romeo.</description>
  <link>https://appsec.beehiiv.com/p/reasonable-appsec-66-threat-modeling-culture-five-security-articles-podcast-corner</link>
  <guid isPermaLink="true">https://appsec.beehiiv.com/p/reasonable-appsec-66-threat-modeling-culture-five-security-articles-podcast-corner</guid>
  <pubDate>Tue, 03 Sep 2024 16:00:00 +0000</pubDate>
  <atom:published>2024-09-03T16:00:00Z</atom:published>
    <dc:creator>Chris Romeo</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><b>Hey there,</b></p><p class="paragraph" style="text-align:left;">In this week’s issue, please enjoy the following:</p><ul><li><p class="paragraph" style="text-align:left;">Five security articles 📰 that are worth YOUR time</p></li><li><p class="paragraph" style="text-align:left;">Featured focus: Threat Modeling as Culture</p></li><li><p class="paragraph" style="text-align:left;">Application Security Podcast 🎙️Corner</p></li><li><p class="paragraph" style="text-align:left;">Where to find Chris? 🌎</p></li></ul><h2 class="heading" style="text-align:left;" id="five-security-articles-that-are-wor">Five Security Articles 📰 that Are Worth YOUR Time</h2><ol start="1"><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.resilientcyber.io/p/softwares-iron-triangle-cheap-fast?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-66-threat-modeling-as-culture-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Software&#39;s Iron Triangle: Cheap, Fast, and Good - Pick Two</a> — Navigating the &quot;Iron Triangle&quot; in software development—cost, speed, and quality—requires careful balance, as focusing too heavily on one aspect often impacts the others, ultimately influencing the project&#39;s overall success and efficiency. <b>[</b><span style="background-color:#FFFFFF;"><b>We’ve been saying that security is part of quality since at least the early 2000s. The challenge is nobody did anything about it. Great article by Hughes expanding on the issue — everything he writes is thorough and thought-provoking!</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://kevincox.ca/2024/08/24/cors/?utm_source=tldrnewsletter" target="_blank" rel="noopener noreferrer nofollow">CORS is Stupid</a> — CORS (Cross-Origin Resource Sharing) is critical for managing how web applications interact with resources across different domains, and the article provides insights into its functionality, issues, and best practices for implementation. <b>[</b><span style="background-color:#FFFFFF;"><b>CORS is stupid. I agree. Let’s make something more straightforward, such as a paved road, that works and provides the same level of protection. Anybody raising their hand?</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://unit42.paloaltonetworks.com/large-scale-cloud-extortion-operation/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-66-threat-modeling-as-culture-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Leaked Environment Variables Allow Large-Scale Extortion Operation of Cloud Environments</a> — A large-scale cloud extortion operation is detailed, revealing how attackers exploit cloud environments to demand ransoms, emphasizing the need for enhanced security measures to combat such threats. <b>[</b><span style="background-color:#FFFFFF;"><b>This caught my attention because of the environment variable leakage. I’ve wrestled with whether it’s time to stop recommending env variables as a step toward secret vaults. It’s time to move to secret vaults as the only answer.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/pulse/unraveling-privacy-threat-modeling-complexity-conceptual-kim-wuyts-r5zee/?trackingId=Hd2MrVZtpeeqs2QN9H4gkA%3D%3D&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-66-threat-modeling-as-culture-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Unraveling Privacy Threat Modeling Complexity: Conceptual Privacy Analysis Layers</a> — </p><p class="paragraph" style="text-align:left;">Kim Wuyts explores the complexities of privacy threat modeling, highlighting the conceptual challenges and the need for robust frameworks to address privacy risks in various scenarios effectively. <b>[</b><span style="background-color:#FFFFFF;"><b>Dr. Wuyts is brilliant — read anything she puts out.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.armosec.io/blog/unraveling-the-state-of-kubernetes-security-2024/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-66-threat-modeling-as-culture-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Unraveling the State of Kubernetes Security in 2024</a> — Kubernetes security in 2024 is assessed, focusing on the latest threats, such as vulnerabilities and misconfigurations, best practices for mitigating these risks, and evolving strategies to enhance the protection of containerized environments amidst growing complexity and adoption. <b>[</b><span style="background-color:#FFFFFF;"><b>K8s feels like the forgotten component hidden deep in the infrastructure. I don’t hear much about it anymore in my circles.</b></span><b>]</b></p></li></ol><h2 class="heading" style="text-align:left;" id="featured-focus-threat-modeling-as-c">Featured Focus: Threat Modeling as Culture</h2><p class="paragraph" style="text-align:left;">I did a webinar with GitGuardian on August 29 on the topic of secure and private by design/default. During the event, we asked, “Is threat modeling currently part of your or your organization’s security strategy?”</p><p class="paragraph" style="text-align:left;">89% of people polled are not doing threat modeling as a discipline within their SDLC. You could argue that the sample size isn’t representative of our industry. Still, based on my anecdotal evidence of talking to different organizations over the past year, I think it’s pretty darn close to correct.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/69f1cb57-a88f-44d7-9571-bc2782d3b89c/image.png?t=1724952489"/></div><p class="paragraph" style="text-align:left;">Threat modeling is due for a renaissance, and all the noise we’ve made about it over the past years with the Threat Modeling Manifesto and Capabilities is just the tip of the iceberg. We have more work to do.</p><div class="image"><img alt="" class="image__image" style="" src="https://files.oaiusercontent.com/file-mC0kNFled7Czu5YNtgmPIfwS?se=2024-08-29T17%3A36%3A26Z&sp=r&sv=2024-08-04&sr=b&rscc=max-age%3D604800%2C%20immutable%2C%20private&rscd=attachment%3B%20filename%3Da8b37a12-e2de-4c0c-b2ec-72bce3260603.webp&skoid=7c382de0-129f-486b-9922-6e4a89c6eb7d&sktid=a48cca56-e6da-484e-a814-9c849652bcb3&skt=2024-08-28T22%3A24%3A30Z&ske=2024-08-29T23%3A24%3A30Z&sks=b&skv=2024-08-04&sig=dTS91HfCVBDBzC3omWppPIb%2BWr7MEWhTAH5RV1HrcZw%3D"/></div><p class="paragraph" style="text-align:left;">As I see it, the value proposition and return on investment for threat modeling are not front and center with Executives yet. There is a collection of unique companies out there that are early adopters and get the value prop, and they are building programs that are pushing threat modeling down to the developer layer. Too often, threat modeling for security and privacy is considered a security team&#39;s responsibility. This is great if you want to scale to five threat models for the entire company. I dream big, and I want developers to threat model every story. We only get there by moving the modeling down to the developer layer. </p><p class="paragraph" style="text-align:left;">We must work toward moving threat modeling forward at the organizational level. Threat modeling must escape the security team and become seen as a crucial step in designing software.</p><h2 class="heading" style="text-align:left;" id="podcast-corner">Podcast 🎙️ Corner</h2><p class="paragraph" style="text-align:left;">I love making podcasts. In Podcast Corner, you get a single place to see what I’ve put out this week. Sometimes, they are my podcasts. Other times, they are podcasts that have caught my attention.</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://appsec.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-66-threat-modeling-as-culture-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Application Security Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Mark Curphey and John Viega -- Chalk (<a class="link" href="https://www.buzzsprout.com/1730684/13527225?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-66-threat-modeling-as-culture-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/O7tJeJSrnhs?si=GlH4iZEMY2oztENl&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-66-threat-modeling-as-culture-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Mark Curphey and John Viega introduce Chalk, a new tool by Crash Override while discussing the reasons behind ZAP&#39;s departure from OWASP to join the Software Security Project and the importance of corporate contributions to open-source projects.</p></li><li><p class="paragraph" style="text-align:left;">The conversation highlights the challenges large tech firms face in managing software engineering processes. Chalk offers a solution for clarity and efficiency and emphasizes the need for an &quot;outside-in&quot; perspective to enhance decision-making in software development.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitytable.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-66-threat-modeling-as-culture-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Security Table</a></p><ul><li><p class="paragraph" style="text-align:left;">The Illusion of Secure Software (<a class="link" href="https://www.buzzsprout.com/2094080/15578228?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-66-threat-modeling-as-culture-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/RRo_YU7Sumo?si=WlXMPtB5qQp12TLD&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-66-threat-modeling-as-culture-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Hosts Chris, Izar, and Matt examine Jen Easterly’s statement on the cybersecurity industry&#39;s software quality problem, discussing its implications, recurring themes in security guidelines, and whether the core issues lie with people or technology.</p></li><li><p class="paragraph" style="text-align:left;">The discussion explores the roles of developers, QA engineers, and emerging AI tools in improving security and questions whether current industry practices are leading to meaningful change.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://threatmodel.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-66-threat-modeling-as-culture-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Threat Modeling Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">A Comprehensive Threat Modeling Strategy (<a class="link" href="https://www.buzzsprout.com/2152378/13366767?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-66-threat-modeling-as-culture-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Chris outlines a comprehensive strategy for effective threat modeling, emphasizing the importance of aligning it with organizational culture, tech debt, and risk posture and integrating it incrementally into the development process.</p></li><li><p class="paragraph" style="text-align:left;">Successful threat modeling requires defining clear success metrics, keeping the model updated, and focusing on domain-specific problems while leveraging automation for domain-agnostic issues.</p></li></ul></li></ul></li></ul><h2 class="heading" style="text-align:left;" id="threat-model-for-free">Threat Model for Free</h2><p class="paragraph" style="text-align:left;">Welcome to <b>Simple, Collaborative</b> Threat Modeling by Devici.</p><p class="paragraph" style="text-align:start;">Introducing the modern drawing tool that&#39;s user-friendly, customizable, and easy on the eyes. Individuals and teams work together – no matter their location. Devici helps build a scalable threat modeling process for multi-disciplinary and geographically dispersed teams, ensuring everyone can contribute.</p><p class="paragraph" style="text-align:start;">Visit <a class="link" href="http://devici.com?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-66-threat-modeling-as-culture-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">devici.com</a> to experience <a class="link" href="https://app.devici.com/sign-up?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-66-threat-modeling-as-culture-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">threat modeling for free</a>.</p><div class="image"><a class="image__link" href="https://app.devici.com/sign-up?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-66-threat-modeling-as-culture-five-security-articles-and-podcast-corner" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/76ff3f8d-4c7b-46a9-a5ce-3e294c14410b/image.png?t=1724951951"/></a></div><h2 class="heading" style="text-align:left;" id="where-to-find-chris">Where to find Chris? 🌎</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/events/thesynergybetweenthreatmodeling7229594660409610242/theater/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-66-threat-modeling-as-culture-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Webinar: The Synergy Between Threat Modeling & Security Champions, with Dustin Lehr</a> — Tuesday, September 10 @ 2 PM (Eastern)</p></li><li><p class="paragraph" style="text-align:left;">Webinar: Threat Modeling and Secure Coding with Tanya Janca — Thursday, September 19; <i>registration link coming soon!</i></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.infosecworldusa.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-66-threat-modeling-as-culture-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">InfoSec World</a> — Sept 22-25, 2024</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.infosecworldusa.com/isw24/session/2225964/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-66-threat-modeling-as-culture-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">The Modern Application Security Rocket Ship</a> — Monday, Sept 23, 10:15 AM</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.infosecworldusa.com/isw24/session/2225998/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-66-threat-modeling-as-culture-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">The Paradox of Secure and Private By Design</a> — Tuesday, Sept 24, 1:30 PM</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.infosecworldusa.com/isw24/workshops/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-66-threat-modeling-as-culture-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Workshop: Threat Modeling Championship: Breaker vs. Builder</a> — Sunday, Sept 22, 9 AM - 12 PM</p></li></ul></li></ul><p class="paragraph" style="text-align:left;">🤔<i> Have questions, comments, or feedback? I&#39;d love to </i><span style="text-decoration:underline;"><i><b><a class="link" href="mailto:chris@kerr.ventures?ref=ReasonableAppSec" target="_blank" rel="noopener noreferrer nofollow">hear</a></b></i></span><i> from you!</i></p><p class="paragraph" style="text-align:start;">🔥<i> Reasonable AppSec is brought to you by </i><span style="text-decoration:underline;"><i><b><a class="link" href="https://kerr.ventures?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-66-threat-modeling-as-culture-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Kerr Ventures</a></b></i></span><i>.</i></p><p class="paragraph" style="text-align:start;">🤝<i> Want to partner with Reasonable AppSec? Reach out, and let’s chat.</i></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=65651404-5007-44a7-b873-f1a06d7baaa4&utm_medium=post_rss&utm_source=reasonable_application_security">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Reasonable 🔐AppSec #65 -  Secure and Privacy by Design and Default: The Convergence with Threat Modeling, Five Security Articles and Podcast Corner</title>
  <description>A review of application security happenings and industry news from Chris Romeo.</description>
  <link>https://appsec.beehiiv.com/p/reasonable-appsec-65-secure-privacy-design-default-convergence-threat-modeling-five-security-article</link>
  <guid isPermaLink="true">https://appsec.beehiiv.com/p/reasonable-appsec-65-secure-privacy-design-default-convergence-threat-modeling-five-security-article</guid>
  <pubDate>Tue, 27 Aug 2024 16:00:00 +0000</pubDate>
  <atom:published>2024-08-27T16:00:00Z</atom:published>
    <dc:creator>Chris Romeo</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><b>Hey there,</b></p><p class="paragraph" style="text-align:left;">In this week’s issue, please enjoy the following:</p><ul><li><p class="paragraph" style="text-align:left;">Five security articles 📰 that are worth YOUR time</p></li><li><p class="paragraph" style="text-align:left;">Featured focus: Secure and Privacy by Design and Default: The Convergence with Threat Modeling</p></li><li><p class="paragraph" style="text-align:left;">Application Security Podcast 🎙️Corner</p></li><li><p class="paragraph" style="text-align:left;">Where to find Chris? 🌎</p></li></ul><h2 class="heading" style="text-align:left;" id="five-security-articles-that-are-wor">Five Security Articles 📰 that Are Worth YOUR Time</h2><ol start="1"><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://center-for-threat-informed-defense.github.io/threat-modeling-with-attack/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-65-secure-and-privacy-by-design-and-default-the-convergence-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Threat Modeling with ATT&CK v1.0.0</a> — Threat modeling with the MITRE ATT&CK framework offers a structured method for identifying and addressing potential security threats by mapping adversary tactics and techniques to strengthen defenses and improve overall security posture. <b>[</b><span style="background-color:#FFFFFF;"><b>It’s about time that somebody melded these two concepts together!</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://siliconangle.com/2024/08/05/cybersecurity-tool-sprawl-control-going-get-worse/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-65-secure-and-privacy-by-design-and-default-the-convergence-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Cybersecurity tool sprawl is out of control – and it’s only going to get worse</a> — As organizations increasingly adopt various disparate cybersecurity tools, the problem of tool sprawl is expected to intensify, highlighting the urgent need for improved integration and management to ensure cohesive and effective security. <b>[</b><span style="background-color:#FFFFFF;"><b>It will be fun to watch and see if ASPM pays off as much as possible, offering a single place for AppSec results to gather and triage. We have too much noise and a lack of fidelity of results with the modern AppSec stack.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://dev.to/thenjdevopsguy/what-you-actually-need-to-know-for-a-cybersecurity-job-3nnk?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-65-secure-and-privacy-by-design-and-default-the-convergence-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">What You ACTUALLY Need To Know For A Cybersecurity Job</a> — To excel in cybersecurity, you need a solid understanding of core security concepts, hands-on experience with security tools and practices, and the ability to stay updated with evolving threats and technologies. <b>[</b><span style="background-color:#FFFFFF;"><b>I get asked this question constantly, and this article tracks with much of what I tell people.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://owaspai.org/docs/ai_security_overview/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-65-secure-and-privacy-by-design-and-default-the-convergence-with-threat-modeling-five-security-articles-and-podcast-corner#periodic-table-of-ai-security" target="_blank" rel="noopener noreferrer nofollow">Threat model with controls - GenAI as-is</a> — The OWASP AI Security Overview provides a comprehensive guide to AI security. It includes a periodic table that categorizes various AI security threats and mitigations to help organizations effectively manage and protect their AI systems. <b>[</b><span style="background-color:#FFFFFF;"><b>Many folks are writing about AI and security; the periodic table is a good resource to attempt to bucketize all the various threats.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.deep-kondah.com/cve-2022-21587-oracle-e-business-suite-unauthenticated-rce-rasp-or-adr/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-65-secure-and-privacy-by-design-and-default-the-convergence-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">CVE-2022-21587(Oracle E-Business Suite RCE): Could RASP or ADR Have Prevented It? And How?</a> — CVE-2022-21587 exposes a critical unauthenticated, remote code execution vulnerability in Oracle E-Business Suite, with the discussion focusing on how Runtime Application Self-Protection (RASP) and Automated Dynamic Analysis (ADR) can help mitigate the risk. <b>[</b><span style="background-color:#FFFFFF;"><b>Thorough technical analysis of whether RASP/ADR would have prevented this issue.</b></span><b>]</b></p></li></ol><h2 class="heading" style="text-align:left;" id="featured-focus-secure-and-privacy-b">Featured Focus: Secure and Privacy by Design and Default: The Convergence with Threat Modeling</h2><p class="paragraph" style="text-align:left;">[Note: this is a post based on my primary conference talk for this year.]</p><p class="paragraph" style="text-align:left;">In today&#39;s ever-evolving digital landscape, ensuring security and privacy isn&#39;t just a technical requirement—it&#39;s a fundamental philosophy that must permeate every aspect of software design and development. This philosophy, known as Secure and Privacy by Design and Default (SPbDD), is more than a set of guidelines; it’s a mindset shift toward prioritizing protection over new features from the very inception of a project.</p><h3 class="heading" style="text-align:left;" id="understanding-secure-and-privacy-by">Understanding Secure and Privacy by Design and Default</h3><p class="paragraph" style="text-align:left;">SPbDD is the art and science of embedding security and privacy into the DNA of your applications. It’s not just about compliance or ticking off boxes in a regulatory checklist. Instead, it’s about building solutions that inherently protect devices, data, and applications against the ever-present and inevitable security threats. Think of it as a journey, not a destination—a continuous process of refining and enhancing security and privacy measures as threats evolve.</p><h3 class="heading" style="text-align:left;" id="the-customers-perspective">The Customer’s Perspective</h3><p class="paragraph" style="text-align:left;">Customers have clear wants and needs regarding security and privacy. They expect that any product or service they purchase will protect their personally identifiable information (PII) or company data immediately—no extra steps are required. They want solutions that are self-updating, automated, and capable of defending themselves without user intervention. In essence, customers demand a secure and private experience by default.</p><h3 class="heading" style="text-align:left;" id="core-tenets-of-s-pb-dd">Core Tenets of SPbDD</h3><p class="paragraph" style="text-align:left;">At the heart of SPbDD are four core principles:</p><ul><li><p class="paragraph" style="text-align:left;">Holistic Security and Privacy Approach: Security and privacy must be considered whole, not isolated.</p></li><li><p class="paragraph" style="text-align:left;">Mindset Shift: Developers need to prioritize protection over adding new features.</p></li><li><p class="paragraph" style="text-align:left;">Business Priorities: Security and privacy should be business imperatives, not merely technical challenges.</p></li><li><p class="paragraph" style="text-align:left;">Default State: Features should be secure and private by default, requiring no extra configuration from the user.</p></li></ul><h3 class="heading" style="text-align:left;" id="the-challenges">The Challenges</h3><p class="paragraph" style="text-align:left;">While the principles of SPbDD are clear, implementing them is anything but straightforward. Traditional security practices and regulatory guidelines often fail to address the complexities of modern software ecosystems. There’s a significant gap between theory and practice, where security and privacy must be woven seamlessly into every aspect of the development process.</p><h3 class="heading" style="text-align:left;" id="designing-for-security-and-privacy-">Designing for Security and Privacy: A Strategic Approach</h3><p class="paragraph" style="text-align:left;">Implementing SPbDD requires a strategic approach to design decisions:</p><ul><li><p class="paragraph" style="text-align:left;">Security and Privacy-Enforcing Stack: The strength of your software stack dictates the security ceiling. Choose a stack that inherently supports secure and private operations, from memory-safe languages to privacy-protecting storage solutions.</p></li><li><p class="paragraph" style="text-align:left;">User Experience: Balance security and usability by creating non-disruptive user flows. Ensure that users have control over their data, with clear and transparent communication about how their information is used and stored.</p></li><li><p class="paragraph" style="text-align:left;">Protecting PII and Customer Data: Adopt privacy policies and data minimization, encryption, and de-identification strategies. You can only protect what you fully understand.</p></li><li><p class="paragraph" style="text-align:left;">Locking Down the System: Securely configure solutions to reduce the attack surface. Remove unnecessary interfaces and features to make it harder for attackers to find vulnerabilities.</p></li><li><p class="paragraph" style="text-align:left;">Responsible Open Source Usage: Develop a strategy for using open source software that includes data processing and security review criteria. If not managed correctly, the software supply chain can be vulnerable.</p></li><li><p class="paragraph" style="text-align:left;">Code Integrity: Implement standards and tools for secure coding, code review, and automated checks to ensure that the design decisions are reflected in the final product.</p></li><li><p class="paragraph" style="text-align:left;">Vulnerability Management: Establish clear processes for handling vulnerabilities when they arise. Transparency is key to maintaining customer trust and managing risk effectively.</p></li></ul><h3 class="heading" style="text-align:left;" id="what-are-security-and-privacy-patte">What Are Security and Privacy Patterns?</h3><p class="paragraph" style="text-align:left;">Security and privacy patterns are blueprints that guide the implementation of specific controls within an application. They encapsulate best practices and provide a repeatable framework for developers to address common security and privacy concerns. By applying these patterns consistently, organizations can ensure that their applications are secure and private by default and resilient against evolving threats. Patterns + property planned for design decisions form the basis of a secure and private application.</p><h3 class="heading" style="text-align:left;" id="key-patterns">Key Patterns</h3><ol start="1"><li><p class="paragraph" style="text-align:left;"><b>Authentication and Multi-Factor Authentication (MFA)</b></p><ul><li><p class="paragraph" style="text-align:left;"><b>Description:</b> Strong authentication mechanisms ensure only authorized users can access the system. MFA adds a layer of security by requiring more than one verification method.</p></li><li><p class="paragraph" style="text-align:left;"><b>Application:</b> This pattern is critical for protecting against spoofing attacks and is a foundational element in any secure application.</p></li><li><p class="paragraph" style="text-align:left;"><b>Example Implementation:</b> Integrating MFA with an Identity Provider (IdP) to support various authentication factors, such as mobile codes or hardware tokens.</p></li></ul></li><li><p class="paragraph" style="text-align:left;"><b>Access Control and Authorization</b></p><ul><li><p class="paragraph" style="text-align:left;"><b>Description:</b> This pattern regulates what authenticated users can do within the system by enforcing strict access controls. It often employs Attribute-Based Access Control (ABAC) to provide fine-grained permissions.</p></li><li><p class="paragraph" style="text-align:left;"><b>Application:</b> Protects against elevation of privilege attacks by ensuring users access only the necessary resources.</p></li><li><p class="paragraph" style="text-align:left;"><b>Example Implementation:</b> Paved road authorization strategies incorporating ABAC, ensuring consistent access control enforcement across services.</p></li></ul></li><li><p class="paragraph" style="text-align:left;"><b>Validation, Sanitization, and Encoding</b></p><ul><li><p class="paragraph" style="text-align:left;"><b>Description:</b> Helps prevent injection attacks by ensuring all input data is properly validated, sanitized, and encoded before processing.</p></li><li><p class="paragraph" style="text-align:left;"><b>Application:</b> This pattern is essential for protecting against tampering and injection vulnerabilities, such as SQL injection or Cross-Site Scripting (XSS).</p></li><li><p class="paragraph" style="text-align:left;"><b>Example Implementation:</b> Standard validation, sanitization, and encoding libraries are integrated into the development pipeline to ensure consistency and security.</p></li></ul></li><li><p class="paragraph" style="text-align:left;"><b>Secure Logging</b></p><ul><li><p class="paragraph" style="text-align:left;"><b>Description:</b> Implements logging mechanisms that ensure all security-relevant events are recorded and can be audited while protecting the confidentiality and integrity of the log data.</p></li><li><p class="paragraph" style="text-align:left;"><b>Application:</b> Helps detect and respond to incidents by providing a clear and accurate audit trail.</p></li><li><p class="paragraph" style="text-align:left;"><b>Example Implementation:</b> Logs are securely transmitted to a Security Information and Event Management (SIEM) system, monitored, and analyzed in real time.</p></li></ul></li><li><p class="paragraph" style="text-align:left;"><b>Proper Password Storage and Initiation</b></p><ul><li><p class="paragraph" style="text-align:left;"><b>Description:</b> Ensures that passwords are stored securely using modern hashing algorithms and that password policies enforce strong, unique passwords.</p></li><li><p class="paragraph" style="text-align:left;"><b>Application:</b> This protects against credential stuffing and brute-force attacks by ensuring that passwords cannot be easily exploited even if compromised.</p></li><li><p class="paragraph" style="text-align:left;"><b>Example Implementation:</b> Use bcrypt or Argon2 for hashing passwords, with strict password policies and regular rotation of credentials.</p></li></ul></li><li><p class="paragraph" style="text-align:left;"><b>Data Protection</b></p><ul><li><p class="paragraph" style="text-align:left;"><b>Description:</b> Safeguards sensitive data through encryption, both at rest and in transit, and ensures that encryption keys are managed securely.</p></li><li><p class="paragraph" style="text-align:left;"><b>Application:</b> Protects against information disclosure by ensuring that even if data is intercepted, it cannot be read without the proper decryption keys.</p></li><li><p class="paragraph" style="text-align:left;"><b>Example Implementation:</b> End-to-end encryption for all data flows, with robust key management practices to prevent unauthorized access.</p></li></ul></li><li><p class="paragraph" style="text-align:left;"><b>Scalability</b></p><ul><li><p class="paragraph" style="text-align:left;"><b>Description:</b> Designs the system to handle increased loads without compromising security or privacy. This includes ensuring high availability and redundancy.</p></li><li><p class="paragraph" style="text-align:left;"><b>Application:</b> Protects against denial-of-service (DoS) attacks by ensuring the system can scale to meet demand and continue operating securely under load.</p></li><li><p class="paragraph" style="text-align:left;"><b>Example Implementation:</b> Load balancing, auto-scaling, and orchestration technologies that ensure the system remains available and secure even during peak usage.</p></li></ul></li></ol><h3 class="heading" style="text-align:left;" id="checking-the-work-the-role-of-threa">Checking the Work: The Role of Threat Modeling</h3><p class="paragraph" style="text-align:left;">Threat modeling is critical in ensuring that SPbDD principles are correctly applied. Organizations can identify potential threats and develop appropriate mitigations by assembling a diverse team and leveraging frameworks like STRIDE and OWASP. This proactive approach ensures that security and privacy are not just theoretical concepts but embedded in the application&#39;s fabric.</p><h3 class="heading" style="text-align:left;" id="measuring-what-matters">Measuring What Matters</h3><p class="paragraph" style="text-align:left;">To truly embrace SPbDD, organizations need to measure the effectiveness of their design decisions. Customized dashboards can track the implementation of security and privacy patterns across different product versions, providing valuable insights into the correlation between these patterns and mitigating specific threats.</p><h3 class="heading" style="text-align:left;" id="conclusion-start-the-journey-today">Conclusion: Start the Journey Today</h3><p class="paragraph" style="text-align:left;">SPbDD is not just a trend—it’s the future of secure and private software development. By embracing this philosophy, organizations can build applications that meet today’s security and privacy standards and are resilient against tomorrow&#39;s challenges. The journey begins now, with every design decision contributing to a more secure and private digital world.</p><h2 class="heading" style="text-align:left;" id="podcast-corner">Podcast 🎙️ Corner</h2><p class="paragraph" style="text-align:left;">I love making podcasts. In Podcast Corner, you get a single place to see what I’ve put out this week. Sometimes, they are my podcasts. Other times, they are podcasts that have caught my attention.</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://appsec.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-65-secure-and-privacy-by-design-and-default-the-convergence-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Application Security Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Maril Vernon -- You Get What You Inspect, Not What You Expect (<a class="link" href="https://www.buzzsprout.com/1730684/13488250?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-65-secure-and-privacy-by-design-and-default-the-convergence-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/5dWYUaGthaY?si=E_Z-6cj6tFI4hvSH&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-65-secure-and-privacy-by-design-and-default-the-convergence-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Maril Vernon highlights the importance of purple teaming by fostering collaboration between developers and security teams, emphasizing the need to communicate remediation recommendations in developer-centric language to bridge gaps and make them actionable.</p></li><li><p class="paragraph" style="text-align:left;">Looking ahead, Maril envisions automation and AI enhancing purple teaming efficiency while valuing human red teamers&#39; irreplaceable creativity and suggesting a future where a more integrated approach or &quot;white teams&quot; could replace traditional purple teams.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitytable.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-65-secure-and-privacy-by-design-and-default-the-convergence-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Security Table</a></p><ul><li><p class="paragraph" style="text-align:left;">The Intersection of Hardware and Software Security (<a class="link" href="https://www.buzzsprout.com/2094080/15543506?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-65-secure-and-privacy-by-design-and-default-the-convergence-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/MAj8foT-GoI?si=AoIlDfsqwD0AMzzZ&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-65-secure-and-privacy-by-design-and-default-the-convergence-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Chris, Izar, and Matt delve into threat modeling for hardware, focusing on the intersection of hardware and software security and highlighting challenges like speculative execution faults and supply chain vulnerabilities.</p></li><li><p class="paragraph" style="text-align:left;">They emphasize the importance of understanding attack surfaces and discuss the ongoing hardware and software security integration to address these critical issues effectively.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://threatmodel.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-65-secure-and-privacy-by-design-and-default-the-convergence-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Threat Modeling Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Software-Centric Threat Modeling (<a class="link" href="https://www.buzzsprout.com/2152378/13200165?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-65-secure-and-privacy-by-design-and-default-the-convergence-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Farshad Abasi emphasizes the importance of asset-based and user story-focused threat modeling, recommending early architectural threat modeling and periodic reviews while integrating threat modeling into the DevSecOps process and using pull request templates for consistency.</p></li><li><p class="paragraph" style="text-align:left;">He highlights the need for a simplified and developer-friendly approach to threat modeling, ensuring that it is actionable and scalable by adopting practices that align with development workflows and improve threat management.</p></li></ul></li></ul></li></ul><h2 class="heading" style="text-align:left;" id="where-to-find-chris">Where to find Chris? 🌎</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://c.gitguardian.com/ggz?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-65-secure-and-privacy-by-design-and-default-the-convergence-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Webinar: Designing Secure and Private Software by Default</a> — August 29 @ 3 PM (Eastern)</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/events/thesynergybetweenthreatmodeling7229594660409610242/theater/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-65-secure-and-privacy-by-design-and-default-the-convergence-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Webinar: The Synergy Between Threat Modeling & Security Champions, with Dustin Lehr</a> — Tuesday, September 10 @ 2 PM (Eastern)</p></li><li><p class="paragraph" style="text-align:left;">Webinar: Threat Modeling and Secure Coding with Tanya Janca — Thursday, September 19; <i>registration link coming soon!</i></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.infosecworldusa.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-65-secure-and-privacy-by-design-and-default-the-convergence-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">InfoSec World</a> — Sept 22-25, 2024</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.infosecworldusa.com/isw24/session/2225964/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-65-secure-and-privacy-by-design-and-default-the-convergence-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">The Modern Application Security Rocket Ship</a> — Monday, Sept 23, 10:15 AM</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.infosecworldusa.com/isw24/session/2225998/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-65-secure-and-privacy-by-design-and-default-the-convergence-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">The Paradox of Secure and Private By Design</a> — Tuesday, Sept 24, 1:30 PM</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.infosecworldusa.com/isw24/workshops/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-65-secure-and-privacy-by-design-and-default-the-convergence-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Workshop: Threat Modeling Championship: Breaker vs. Builder</a> — Sunday, Sept 22, 9 AM - 12 PM</p></li></ul></li></ul><p class="paragraph" style="text-align:left;">🤔<i> Have questions, comments, or feedback? I&#39;d love to </i><span style="text-decoration:underline;"><i><b><a class="link" href="mailto:chris@kerr.ventures?ref=ReasonableAppSec" target="_blank" rel="noopener noreferrer nofollow">hear</a></b></i></span><i> from you!</i></p><p class="paragraph" style="text-align:start;">🔥<i> Reasonable AppSec is brought to you by </i><span style="text-decoration:underline;"><i><b><a class="link" href="https://kerr.ventures?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-65-secure-and-privacy-by-design-and-default-the-convergence-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Kerr Ventures</a></b></i></span><i>.</i></p><p class="paragraph" style="text-align:start;">🤝<i> Want to partner with Reasonable AppSec? Reach out, and let’s chat.</i></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=65ff4ffd-62f6-4808-997e-b1b2ea422c6a&utm_medium=post_rss&utm_source=reasonable_application_security">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Reasonable 🔐AppSec #64 - Trusting AI to Fix Vulns, Five Security Articles and Podcast Corner</title>
  <description>A review of application security happenings and industry news from Chris Romeo.</description>
  <link>https://appsec.beehiiv.com/p/reasonable-appsec-64-trusting-ai-fix-vulns-five-security-articles-podcast-corner</link>
  <guid isPermaLink="true">https://appsec.beehiiv.com/p/reasonable-appsec-64-trusting-ai-fix-vulns-five-security-articles-podcast-corner</guid>
  <pubDate>Tue, 20 Aug 2024 16:00:00 +0000</pubDate>
  <atom:published>2024-08-20T16:00:00Z</atom:published>
    <dc:creator>Chris Romeo</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><b>Hey there,</b></p><p class="paragraph" style="text-align:left;">In this week’s issue, please enjoy the following:</p><ul><li><p class="paragraph" style="text-align:left;">Five security articles 📰 that are worth YOUR time</p></li><li><p class="paragraph" style="text-align:left;">Featured focus: Trusting AI to Fix Vulns</p></li><li><p class="paragraph" style="text-align:left;">Application Security Podcast 🎙️Corner</p></li><li><p class="paragraph" style="text-align:left;">Where to find Chris? 🌎</p></li></ul><h2 class="heading" style="text-align:left;" id="five-security-articles-that-are-wor">Five Security Articles 📰 that Are Worth YOUR Time</h2><ol start="1"><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://designingsecuresoftware.com/writings/threat_modeling_itself/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-64-trusting-ai-to-fix-vulns-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Threat Modeling ‘threat’ modeling</a> — Applying threat modeling to the process can uncover hidden risks, improve transparency, and strengthen security practices. <b>[</b><span style="background-color:#FFFFFF;"><b>This one caught my eye because of my lack of threat modeling a sidewalk from last week’s featured focus. BTW, Loren is one of the folks that invented STRIDE.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.infoworld.com/article/3478308/nist-releases-new-tool-to-check-ai-models-security.html?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-64-trusting-ai-to-fix-vulns-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">NIST releases new tool to check AI models’ security</a><a class="link" href="https://cloud.google.com/blog/transform/to-securely-build-ai-on-google-cloud-follow-these-best-practices-infographic?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-64-trusting-ai-to-fix-vulns-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow"> </a>— NIST has released a new tool to help organizations evaluate the security and trustworthiness of their AI models, addressing growing concerns about AI vulnerabilities and biases. <b>[</b><span style="background-color:#FFFFFF;"><b>Can we create a tool to check how something we don’t understand works?</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.calcalistech.com/ctechnews/article/b1a1jn00hc?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-64-trusting-ai-to-fix-vulns-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">The Gili Ra’anan model: Questions emerging from Cyberstarts&#39; remarkable success</a><a class="link" href="https://www.calcalistech.com/ctechnews/article/b1a1jn00hc?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-64-trusting-ai-to-fix-vulns-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow"> </a>— Cyberstarts&#39; remarkable success is partly attributed to a unique model that offers CISOs equity in the fund, creating potential conflicts of interest as these cybersecurity leaders may favor Cyberstarts&#39; portfolio companies, boosting their growth and valuations. <b>[</b><span style="background-color:#FFFFFF;"><b>This confirms my hypothesis that the CISO is not the best buyer of AppSec solutions. They are buried in noise from too many sources.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.isaca.org/resources/news-and-trends/isaca-now-blog/2023/six-things-devops-wants-from-infosec?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-64-trusting-ai-to-fix-vulns-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Six Things DevOps Wants from InfoSec</a><a class="link" href="https://cloud.google.com/blog/transform/to-securely-build-ai-on-google-cloud-follow-these-best-practices-infographic?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-64-trusting-ai-to-fix-vulns-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow"> </a>— DevOps teams want InfoSec to empower them with tools, clear guidance, trust, and autonomy to build secure code without hindrance. <b>[</b><span style="background-color:#FFFFFF;"><b>This is a stark reminder of how to serve developers, which SHOULD be the primary focus of AppSec.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://solcyber.com/https-how-secure-is-it-and-do-we-really-need-it/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-64-trusting-ai-to-fix-vulns-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">HTTPS: How secure is it, and do we really need it? (Part 1 of 2)</a><a class="link" href="https://cloud.google.com/blog/transform/to-securely-build-ai-on-google-cloud-follow-these-best-practices-infographic?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-64-trusting-ai-to-fix-vulns-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow"> </a>— HTTPS is essential for securing online communication, as it encrypts data, ensures privacy, and protects against cyber threats, making it a must-have for any website handling sensitive information. <b>[</b><span style="background-color:#FFFFFF;"><b>Great history lesson on HTTPS and its impact over the last two decades.</b></span><b>]</b></p></li></ol><h2 class="heading" style="text-align:left;" id="featured-focus-trusting-ai-to-fix-v">Featured Focus: Trusting AI to Fix Vulns</h2><p class="paragraph" style="text-align:left;">I keep seeing solutions claiming they can create pull requests to fix vulnerabilities using AI. GitHub is the latest that I’ve seen hit the streets. My humble opinion is that the technology behind AI is not yet ready to be trusted in such a manner.</p><p class="paragraph" style="text-align:left;">The primary challenge to trusting an AI-related fix is predictability. When I use an LLM today and ask it a question, I often get different answers on multiple runs. With this lack of predictability in an answer, how can I guarantee that a fix eliminates the vulnerability?</p><p class="paragraph" style="text-align:left;">The secondary challenge is the future of laziness. This is connected to my primary challenge: as I see a world where we become more dependent on AI, we will become lazy about checking its results. We could easily reach a false sense of security about automated PRs and see them automatically approved.</p><p class="paragraph" style="text-align:left;">What is the answer then? Are you donning the hat of a Luddite and swearing off AI for security? No, that isn’t the answer. The answer is being more patient as we wait for this technology to develop. We’ll reach the point where AI can competently fix vulnerabilities, but I don’t think we’re there today. Patience isn’t something people write about or think of as a pillar of a security program, but that doesn’t mean it isn’t the best strategy for now.</p><h2 class="heading" style="text-align:left;" id="podcast-corner">Podcast 🎙️ Corner</h2><p class="paragraph" style="text-align:left;">I love making podcasts. In Podcast Corner, you get a single place to see what I’ve put out this week. Sometimes, they are my podcasts. Other times, they are podcasts that have caught my attention.</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://appsec.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-64-trusting-ai-to-fix-vulns-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Application Security Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Dan Küykendall -- Why All Application Security Products Suck (<a class="link" href="https://www.buzzsprout.com/1730684/13448538?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-64-trusting-ai-to-fix-vulns-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/ZGZ8c8M5hj0?si=Z7fOICdYKGxwWMMj&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-64-trusting-ai-to-fix-vulns-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Dan Küykendall discusses his series &quot;Why All AppSec Products Suck&quot; and emphasizes the importance of understanding the limitations and appropriate uses of security tools.</p></li><li><p class="paragraph" style="text-align:left;">The hosts remember Kevin Mitnick, explore the challenges of DAST scanners with modern apps, and highlight the need for comprehensive security training for engineers.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitytable.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-64-trusting-ai-to-fix-vulns-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Security Table</a></p><ul><li><p class="paragraph" style="text-align:left;">Computing Has Trust Issues (<a class="link" href="https://www.buzzsprout.com/2094080/15506162?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-64-trusting-ai-to-fix-vulns-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/aZfnbHMnHo0?si=VV7bzLHA2_8T_Czj&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-64-trusting-ai-to-fix-vulns-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Chris, Izar, and Matt discuss classic security-themed movies like &#39;Sneakers&#39; and &#39;War Games&#39; before delving into Secure Boot vulnerabilities and the complexities of key management.</p></li><li><p class="paragraph" style="text-align:left;">They also cover password management, passkeys, and the challenges of securing digital identities in today&#39;s landscape.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://threatmodel.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-64-trusting-ai-to-fix-vulns-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Threat Modeling Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Product-led threat modeling (<a class="link" href="https://www.buzzsprout.com/2152378/12987495?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-64-trusting-ai-to-fix-vulns-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Product-led threat modeling integrates security into product management by aligning threat assessments with user needs, using methodologies like STRIDE and rapid risk assessment.</p></li><li><p class="paragraph" style="text-align:left;">Michal and Chris emphasize collaboration across teams, with product managers taking ownership of security, applying lean principles, and utilizing threat libraries and cookbooks to address security challenges.</p></li></ul></li></ul></li></ul><h2 class="heading" style="text-align:left;" id="where-to-find-chris">Where to find Chris? 🌎</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://c.gitguardian.com/ggz?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-64-trusting-ai-to-fix-vulns-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Webinar: Designing Secure and Private Software by Default</a> — August 29 @ 3 PM (Eastern)</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/events/thesynergybetweenthreatmodeling7229594660409610242/theater/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-64-trusting-ai-to-fix-vulns-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Webinar: The Synergy Between Threat Modeling & Security Champions, with Dustin Lehr</a> — Tuesday, September 10 @ 2 PM (Eastern)</p></li><li><p class="paragraph" style="text-align:left;">Webinar: Threat Modeling and Secure Coding with Tanya Janca — Thursday, September 19; <i>registration link coming soon!</i></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.infosecworldusa.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-64-trusting-ai-to-fix-vulns-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">InfoSec World</a> — Sept 22-25, 2024</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.infosecworldusa.com/isw24/session/2225964/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-64-trusting-ai-to-fix-vulns-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">The Modern Application Security Rocket Ship</a> — Monday, Sept 23, 10:15 AM</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.infosecworldusa.com/isw24/session/2225998/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-64-trusting-ai-to-fix-vulns-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">The Paradox of Secure and Private By Design</a> — Tuesday, Sept 24, 1:30 PM</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.infosecworldusa.com/isw24/workshops/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-64-trusting-ai-to-fix-vulns-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Workshop: Threat Modeling Championship: Breaker vs. Builder</a> — Sunday, Sept 22, 9 AM - 12 PM</p></li></ul></li></ul><p class="paragraph" style="text-align:left;">🤔<i> Have questions, comments, or feedback? I&#39;d love to </i><span style="text-decoration:underline;"><i><b><a class="link" href="mailto:chris@kerr.ventures?ref=ReasonableAppSec" target="_blank" rel="noopener noreferrer nofollow">hear</a></b></i></span><i> from you!</i></p><p class="paragraph" style="text-align:start;">🔥<i> Reasonable AppSec is brought to you by </i><span style="text-decoration:underline;"><i><b><a class="link" href="https://kerr.ventures?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-64-trusting-ai-to-fix-vulns-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Kerr Ventures</a></b></i></span><i>.</i></p><p class="paragraph" style="text-align:start;">🤝<i> Want to partner with Reasonable AppSec? Reach out, and let’s chat.</i></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=40a86acd-beb0-4adf-83f0-332852fd2335&utm_medium=post_rss&utm_source=reasonable_application_security">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Reasonable 🔐AppSec #63 - Slip and Fall, Five Security Articles and Podcast Corner</title>
  <description>A review of application security happenings and industry news from Chris Romeo.</description>
  <link>https://appsec.beehiiv.com/p/reasonable-appsec-63-slip-fall-five-security-articles-podcast-corner</link>
  <guid isPermaLink="true">https://appsec.beehiiv.com/p/reasonable-appsec-63-slip-fall-five-security-articles-podcast-corner</guid>
  <pubDate>Tue, 13 Aug 2024 16:00:00 +0000</pubDate>
  <atom:published>2024-08-13T16:00:00Z</atom:published>
    <dc:creator>Chris Romeo</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><b>Hey there,</b></p><p class="paragraph" style="text-align:left;">In this week’s issue, please enjoy the following:</p><ul><li><p class="paragraph" style="text-align:left;">Five security articles 📰 that are worth YOUR time</p></li><li><p class="paragraph" style="text-align:left;">Featured focus: Slip and Fall</p></li><li><p class="paragraph" style="text-align:left;">Application Security Podcast 🎙️Corner</p></li><li><p class="paragraph" style="text-align:left;">Where to find Chris? 🌎</p></li></ul><h2 class="heading" style="text-align:left;" id="five-security-articles-that-are-wor">Five Security Articles 📰 that Are Worth YOUR Time</h2><ol start="1"><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.deep-kondah.com/smashing-runtime-application-self-protection-rasp/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-63-slip-and-fall-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Smashing Runtime Application Self-Protection (RASP)</a> — This post explores why RASP, or Runtime Application Self-Protection, cannot always protect your Java applications and can be bypassed. <b>[</b><span style="background-color:#FFFFFF;"><b>RASP has been a hot topic for the past few years, and I think of it as something cutting edge for an AppSec program. This one caught my attention as it posits that perhaps RASP is not as strong as the market believes.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-63-slip-and-fall-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">How a North Korean Fake IT Worker Tried to Infiltrate Us</a><a class="link" href="https://cloud.google.com/blog/transform/to-securely-build-ai-on-google-cloud-follow-these-best-practices-infographic?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-63-slip-and-fall-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow"> </a>— A North Korean agent attempted to infiltrate KnowBe4 by posing as a legitimate IT worker with a stolen identity and AI-enhanced photo. Still, the scheme was detected when malware was found on the employee&#39;s device. <b>[</b><span style="background-color:#FFFFFF;"><b>This scenario happens more than anyone thinks — interview well and check those references!</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://cybersecuritynews.com/bitdefender-ssrf-vulnerability/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-63-slip-and-fall-five-security-articles-and-podcast-corner#google_vignette" target="_blank" rel="noopener noreferrer nofollow">Bitdefender Vulnerability Let Attackers Trigger SSRF Attacks</a><a class="link" href="https://cloud.google.com/blog/transform/to-securely-build-ai-on-google-cloud-follow-these-best-practices-infographic?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-63-slip-and-fall-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow"> </a>— A critical vulnerability in Bitdefender&#39;s GravityZone Update Server, identified as CVE-2024-6980, could allow attackers to execute server-side request forgery (SSRF) attacks, posing significant risks to affected systems. <b>[</b><span style="background-color:#FFFFFF;"><b>SSRF is still up and coming, so I added this article as a case study into what SSRF looks like in the real world.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://trufflesecurity.com/blog/anyone-can-access-deleted-and-private-repo-data-github?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-63-slip-and-fall-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Anyone can Access Deleted and Private Repository Data on GitHub</a><a class="link" href="https://cloud.google.com/blog/transform/to-securely-build-ai-on-google-cloud-follow-these-best-practices-infographic?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-63-slip-and-fall-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow"> </a>— GitHub repositories, including deleted and private ones, can still access their data through forks, posing a significant security risk by allowing unauthorized access to sensitive information. <b>[</b><span style="background-color:#FFFFFF;"><b>Architecture is important, and a flaw like this is architectural, as a design decision that allowed this to happen was made somewhere in the past.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://opensourcesecurity.io/2024/06/03/why-are-vulnerabilities-out-of-control-in-2024/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-63-slip-and-fall-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Why are vulnerabilities out of control in 2024?</a><a class="link" href="https://cloud.google.com/blog/transform/to-securely-build-ai-on-google-cloud-follow-these-best-practices-infographic?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-63-slip-and-fall-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow"> </a>— Vulnerabilities are surging in 2024 due to the collapse of NVD, an overwhelming number of Linux kernel CVE IDs, and insufficient resources to handle the growing volume of open-source software issues. <b>[</b><span style="background-color:#FFFFFF;"><b>Is there anything different for 2024? Vulns have been consistently reported for as long as I can remember.</b></span><b>]</b></p></li></ol><h2 class="heading" style="text-align:left;" id="featured-focus-slip-and-fall">Featured Focus: Slip and Fall</h2><p class="paragraph" style="text-align:left;">Last week, I was out walking my dog. I believe in threat modeling and encourage people to do it for everything they do, whether building software or going on vacation. Threat modeling has a role in every situation.</p><p class="paragraph" style="text-align:left;">Here is how the story goes — I’m walking down the sidewalk, not paying attention, enjoying my morning walk with my dog. Tropical storm Debby had made its way through our area and dumped a lot of rain. I walked the same path every morning. As I was walking down the sidewalk, not paying enough attention, I slipped on a thin amount of mud the storm had pushed across the sidewalk and smacked down on the ground. </p><p class="paragraph" style="text-align:left;">As I was lying there assessing my injuries, including a nice cut on my leg, elbow, and shoulder and a muscle pull in the neck, I had a thought. There is a lesson to be learned from my experience and a good reminder: I should have threat modeled the situation. I should have looked at the sidewalk before me and analyzed that representation of a quarter inch of mud. So, at the end of the day, you can use threat modeling for everything, even keeping yourself from a slip and fall.</p><h2 class="heading" style="text-align:left;" id="podcast-corner">Podcast 🎙️ Corner</h2><p class="paragraph" style="text-align:left;">I love making podcasts. In Podcast Corner, you get a single place to see what I’ve put out this week. Sometimes, they are my podcasts. Other times, they are podcasts that have caught my attention.</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://appsec.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-63-slip-and-fall-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Application Security Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Irfaan Santoe -- The Power of Strategy in AppSec (<a class="link" href="https://www.buzzsprout.com/1730684/15506236?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-63-slip-and-fall-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/6joDiRchwQA?si=kFpykDxKizVO8Ul9&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-63-slip-and-fall-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">We discuss measuring AppSec maturity, ROI, and bridging gaps between CISOs and AppSec knowledge.</p></li><li><p class="paragraph" style="text-align:left;">Irfaan shares his journey from consulting to being an AppSec professional, offering insights for scaling AppSec programs and aligning them with business goals.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitytable.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-63-slip-and-fall-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Security Table</a></p><ul><li><p class="paragraph" style="text-align:left;">The Stages of Grief in Incident Response (<a class="link" href="https://www.buzzsprout.com/2094080/15465490?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-63-slip-and-fall-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/apDQQdxFYcY?si=yOhHFrU4uF1g6CDw&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-63-slip-and-fall-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Chris, Izar, and Matt discuss the developer&#39;s stages of grief during incidents and analyze a recent large-scale IT incident.</p></li><li><p class="paragraph" style="text-align:left;">They share insights from their extensive security experience, examining system fragility and the role of luck in security failures.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://threatmodel.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-63-slip-and-fall-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Threat Modeling Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Gavin Klondike -- Threat modeling for large language model applications (<a class="link" href="https://www.buzzsprout.com/2152378/15519510?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-63-slip-and-fall-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Gavin Klondike discusses threat modeling, especially in AI and machine learning contexts.</p></li><li><p class="paragraph" style="text-align:left;">Gavin shares a detailed case study, challenges of large language models (LLMs), and a comprehensive threat model for LLM applications.</p></li></ul></li></ul></li></ul><h2 class="heading" style="text-align:left;" id="where-to-find-chris">Where to find Chris? 🌎</h2><ul><li><p class="paragraph" style="text-align:left;">Webinar: Secure by Design, August 29 @ 3 PM Eastern; register link coming soon.</p></li><li><p class="paragraph" style="text-align:left;">Webinar: The Intersection of Security Champions and Threat Modeling, with Dustin Lehr — Tuesday, September 10</p></li><li><p class="paragraph" style="text-align:left;">Webinar: Threat Modeling and Secure Coding with Tanya Janca — Thursday, September 19</p></li><li><p class="paragraph" style="text-align:left;">InfoSec World, Sept 22-25, 2024</p><ul><li><p class="paragraph" style="text-align:left;">The Modern Application Security Rocket Ship — Monday, Sept 23, 10:15 AM</p></li><li><p class="paragraph" style="text-align:left;">The Paradox of Secure and Private By Design — Tuesday, Sept 24, 1:30 PM</p></li><li><p class="paragraph" style="text-align:left;">Workshop: Threat Modeling Championship: Breaker vs. Builder — Sunday, Sept 22, 9 AM - 12 PM</p></li></ul></li></ul><p class="paragraph" style="text-align:left;">🤔<i> Have questions, comments, or feedback? I&#39;d love to </i><span style="text-decoration:underline;"><i><b><a class="link" href="mailto:chris@kerr.ventures?ref=ReasonableAppSec" target="_blank" rel="noopener noreferrer nofollow">hear</a></b></i></span><i> from you!</i></p><p class="paragraph" style="text-align:start;">🔥<i> Reasonable AppSec is brought to you by </i><span style="text-decoration:underline;"><i><b><a class="link" href="https://kerr.ventures?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-63-slip-and-fall-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Kerr Ventures</a></b></i></span><i>.</i></p><p class="paragraph" style="text-align:start;">🤝<i> Want to partner with Reasonable AppSec? Reach out, and let’s chat.</i></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=d4d489c8-4b79-44bf-ae92-37f826807fc5&utm_medium=post_rss&utm_source=reasonable_application_security">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Reasonable 🔐AppSec #62 - The AppSec Hype Cycle, Five Security Articles and Podcast Corner</title>
  <description>A review of application security happenings and industry news from Chris Romeo.</description>
  <link>https://appsec.beehiiv.com/p/reasonable-appsec-62-appsec-hype-cycle-five-security-articles-podcast-corner</link>
  <guid isPermaLink="true">https://appsec.beehiiv.com/p/reasonable-appsec-62-appsec-hype-cycle-five-security-articles-podcast-corner</guid>
  <pubDate>Wed, 07 Aug 2024 16:00:00 +0000</pubDate>
  <atom:published>2024-08-07T16:00:00Z</atom:published>
    <dc:creator>Chris Romeo</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><b>Hey there,</b></p><p class="paragraph" style="text-align:left;">In this week’s issue, please enjoy the following:</p><ul><li><p class="paragraph" style="text-align:left;">Five security articles 📰 that are worth YOUR time</p></li><li><p class="paragraph" style="text-align:left;">Featured focus: The AppSec Hype Cycle</p></li><li><p class="paragraph" style="text-align:left;">Application Security Podcast 🎙️Corner</p></li><li><p class="paragraph" style="text-align:left;">Where to find Chris? 🌎</p></li></ul><h2 class="heading" style="text-align:left;" id="sponsor-post-devici-is-the-threat-m">Sponsor post: Devici is THE threat modeling platform and a program in a box.</h2><p class="paragraph" style="text-align:left;">Threat modeling requires so much more than a tool. Sure, a tool is the program&#39;s foundation, but what if your threat modeling tool could help you run your program? Welcome to Devici. Workflows, custom threats, mitigations, and custom templates create the threat modeling program you need, and Devici helps you execute your strategy.</p><p class="paragraph" style="text-align:left;">Devici has a free plan for forever, so you can try us out. You get three comprehensive threat models. Create an account today and start threat modeling for free! You can invite up to nine colleagues to your account to model together in a collaborative environment. Visit <a class="link" href="https://devici.com?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-62-the-appsec-hype-cycle-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">devici.com</a> today to sign up.</p><h2 class="heading" style="text-align:left;" id="five-security-articles-that-are-wor">Five Security Articles 📰 that Are Worth YOUR Time</h2><ol start="1"><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://true-positives.com/appsec-blog/ai-revolutionizing-software-engineering-and-security?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-62-the-appsec-hype-cycle-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Will AI Revolutionize Software Engineering and Security?</a><a class="link" href="https://cloud.google.com/blog/transform/to-securely-build-ai-on-google-cloud-follow-these-best-practices-infographic?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-62-the-appsec-hype-cycle-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow"> </a>— AI is revolutionizing software engineering and security by advancing threat detection, automating routine tasks, and boosting overall efficiency, leading to more effective and proactive security measures.<b>[</b><span style="background-color:#FFFFFF;"><b>Short answer: yes and no. In the short term, no. In the long term, I see a path towards AI-enhancing developers and security people to achieve 100% more productivity.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.phylum.io/new-tactics-from-a-familiar-threat/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-62-the-appsec-hype-cycle-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">New Tactics from a Familiar Threat</a><a class="link" href="https://cloud.google.com/blog/transform/to-securely-build-ai-on-google-cloud-follow-these-best-practices-infographic?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-62-the-appsec-hype-cycle-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow"> </a>— Phylum has exposed North Korean threat actors attacking software developers in the open-source supply chain for over a year. This blog post highlights evolving tactics from a North Korean campaign that began in September 2023 with a package published on 4 July 2024 in npm. Like a snake shedding its old skin, this attacker&#39;s evasive attempts have introduced some novelties, but many of the same patterns and idioms we have seen throughout this campaign remain. <b>[</b><span style="background-color:#FFFFFF;"><b>This is not a topic I usually cover, but when nation-state actors come for the supply chain, it’s time to dive in.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://samcurry.net/hacking-millions-of-modems?utm_source=vulnu.mattjay.com&utm_medium=newsletter&utm_campaign=vulnerable-u-067" target="_blank" rel="noopener noreferrer nofollow">Hacking Millions of Modems (and Investigating Who Hacked My Modem)</a><a class="link" href="https://cloud.google.com/blog/transform/to-securely-build-ai-on-google-cloud-follow-these-best-practices-infographic?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-62-the-appsec-hype-cycle-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow"> </a>— Sam Curry details how millions of modems are vulnerable to hacking due to weak security practices, exposing significant risks of unauthorized access and control over network devices. <b>[</b><span style="background-color:#FFFFFF;"><b>Vulns with mass scale always catch my attention. Excellent research by Sam.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://orca.security/resources/blog/2024-state-public-cloud-report-risk-prioritization/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-62-the-appsec-hype-cycle-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">2024 State of Cloud Security Report Shows That More Risk Prioritization is Needed</a><a class="link" href="https://cloud.google.com/blog/transform/to-securely-build-ai-on-google-cloud-follow-these-best-practices-infographic?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-62-the-appsec-hype-cycle-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow"> </a>— The 2024 State of Public Cloud Report from Orca Security highlights key risks and prioritization strategies for securing public cloud environments, emphasizing the need for comprehensive risk management to address evolving threats and vulnerabilities. <b>[</b><span style="background-color:#FFFFFF;"><b>Takeaway: Your cloud is not secure enough.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://learn.microsoft.com/en-gb/security/engineering/securing-artificial-intelligence-machine-learning?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-62-the-appsec-hype-cycle-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Securing the Future of Artificial Intelligence and Machine Learning at Microsoft</a><a class="link" href="https://cloud.google.com/blog/transform/to-securely-build-ai-on-google-cloud-follow-these-best-practices-infographic?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-62-the-appsec-hype-cycle-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow"> </a>— Microsoft&#39;s guide on securing artificial intelligence and machine learning emphasizes the importance of integrating robust security measures to protect AI systems from vulnerabilities and threats throughout their lifecycle. <b>[</b><span style="background-color:#FFFFFF;"><b>Check out how a big company is packaging up security for AI.</b></span><b>]</b></p></li></ol><h2 class="heading" style="text-align:left;" id="featured-focus-the-app-sec-hype-cyc">Featured Focus: The AppSec Hype Cycle</h2><p class="paragraph" style="text-align:left;">Plenty of hype cycle-style analyses are floating around, so here is mine.</p><p class="paragraph" style="text-align:left;"><b>Trending downward: DevSecOps</b></p><p class="paragraph" style="text-align:left;">I continue to see conference presentations, podcast episodes, and blog posts on DevSecOps five years after DevSecOps took our industry by storm. DevSecOps is tired and needs to drift away. For years, I’ve been saying we should call it DevOps and include security as a natural step in building software. It’s time to stop treating it as a separate thing and let it go.</p><p class="paragraph" style="text-align:left;"><b>So far down that it should be six feet under: Shifting Left</b></p><p class="paragraph" style="text-align:left;">I just saw this one again today on LinkedIn. It’s so weathered, worn out, and tired, yet people continue to drag it back out. Let this one go as well — it started as a marketing term, had a good run, and made sense for technical people, but now it’s back to a marketing term. Let it go.</p><p class="paragraph" style="text-align:left;"><b>Everyone is gaga for it: Application Detection and Response (ADR)</b></p><p class="paragraph" style="text-align:left;">Can anyone count the detection and response technology types we now have? ADR is the latest, and many vendors are morphing their language from their existing products to align with ADR. Time will tell if this becomes a valid technology type that is a must-have for the AppSec stack. It’s worth a look, but the jury is still unsure about its value/return on investment.</p><p class="paragraph" style="text-align:left;"><b>It would be best if you were looking at it: Application Security Posture Management (ASPM)</b></p><p class="paragraph" style="text-align:left;">Alert fatigue is a real thing. Face it: our tools are generating 10x the findings they should, and we need to increase the fidelity of the data feed we send to developers. ASPM is the answer to this challenge and should be added to your stack soon.</p><p class="paragraph" style="text-align:left;"><b>Terms vendors are jumping on board with: Guardrails / Paved Roads</b></p><p class="paragraph" style="text-align:left;">I’m not sure who first used these terms, but if you look around, you will see that many vendors now use them to define their product suites. I predict these terms are the next “shift left” for our industry and will cross into the marketing world within six months.</p><p class="paragraph" style="text-align:left;">That ends my first AppSec Hype Cycle analysis. I hope you enjoyed it. Reply and let me know if you agree or disagree with these statements.</p><h2 class="heading" style="text-align:left;" id="podcast-corner">Podcast 🎙️ Corner</h2><p class="paragraph" style="text-align:left;">I love making podcasts. In Podcast Corner, you get a single place to see what I’ve put out this week. Sometimes, they are my podcasts. Other times, they are podcasts that have caught my attention.</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://appsec.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-62-the-appsec-hype-cycle-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Application Security Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Andrew Van Der Stock -- The New OWASP Top Ten (<a class="link" href="https://www.buzzsprout.com/1730684/15457153?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-62-the-appsec-hype-cycle-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/99nnp1CjFQs?si=Wj8kaS8hC48DoneT&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-62-the-appsec-hype-cycle-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Andrew Van Der Stok joins Chris Romeo and Robert Hurlbut to discuss OWASP Top 10 Project updates, emphasizing data collection and developer engagement.</p></li><li><p class="paragraph" style="text-align:left;">The episode covers the methodology for the OWASP Top 10, framework security, and key insights for shaping the future of web application security.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitytable.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-62-the-appsec-hype-cycle-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Security Table</a></p><ul><li><p class="paragraph" style="text-align:left;">Why Do Engineers Hate Security? (<a class="link" href="https://www.buzzsprout.com/2094080/13296708?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-62-the-appsec-hype-cycle-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/UNIGZahlfR4?si=WYldkpGRI_bRR8eY&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-62-the-appsec-hype-cycle-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Chris, Matt, and Izar discuss why security professionals should develop empathy, soft skills, and integration strategies to avoid being perceived as intrusive by engineers.</p></li><li><p class="paragraph" style="text-align:left;">Building strong relationships requires understanding engineers&#39; perspectives and effectively communicating the value of security measures.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://threatmodel.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-62-the-appsec-hype-cycle-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Threat Modeling Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">The Four Question Framework with Adam Shostack (<a class="link" href="https://www.buzzsprout.com/2152378/12826352?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-62-the-appsec-hype-cycle-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Chris and Adam dive into the four-question framework for threat modeling, explaining the meaning and purpose of each question to simplify the process.</p></li><li><p class="paragraph" style="text-align:left;">They discuss the importance of retrospectives, the evolution of the framework, and its application in various situations, highlighting that the questions serve as a practical foundation for threat modeling.</p></li></ul></li></ul></li></ul><h2 class="heading" style="text-align:left;" id="where-to-find-chris">Where to find Chris? 🌎</h2><ul><li><p class="paragraph" style="text-align:left;">Webinar: Secure by Design, August 29 @ 3 PM Eastern; register link coming soon.</p></li><li><p class="paragraph" style="text-align:left;">InfoSec World, Sept 22-25, 2024</p><ul><li><p class="paragraph" style="text-align:left;">The Modern Application Security Rocket Ship — Monday, Sept 23, 10:15 AM</p></li><li><p class="paragraph" style="text-align:left;">The Paradox of Secure and Private By Design — Tuesday, Sept 24, 1:30 PM</p></li><li><p class="paragraph" style="text-align:left;">Workshop: Threat Modeling Championship: Breaker vs. Builder — Sunday, Sept 22, 9 AM - 12 PM</p></li></ul></li></ul><p class="paragraph" style="text-align:left;">🤔<i> Have questions, comments, or feedback? I&#39;d love to </i><span style="text-decoration:underline;"><i><b><a class="link" href="mailto:chris@kerr.ventures?ref=ReasonableAppSec" target="_blank" rel="noopener noreferrer nofollow">hear</a></b></i></span><i> from you!</i></p><p class="paragraph" style="text-align:start;">🔥<i> Reasonable AppSec is brought to you by </i><span style="text-decoration:underline;"><i><b><a class="link" href="https://kerr.ventures?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-62-the-appsec-hype-cycle-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Kerr Ventures</a></b></i></span><i>.</i></p><p class="paragraph" style="text-align:start;">🤝<i> Want to partner with Reasonable AppSec? Reach out, and let’s chat.</i></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=b7c737e3-4a89-457e-a0f4-6668eb630224&utm_medium=post_rss&utm_source=reasonable_application_security">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Reasonable 🔐AppSec #61 - Sticking with anything, Five Security Articles and Podcast Corner</title>
  <description>A review of application security happenings and industry news from Chris Romeo.</description>
  <link>https://appsec.beehiiv.com/p/reasonable-appsec-61-sticking-anything-five-security-articles-podcast-corner</link>
  <guid isPermaLink="true">https://appsec.beehiiv.com/p/reasonable-appsec-61-sticking-anything-five-security-articles-podcast-corner</guid>
  <pubDate>Mon, 29 Jul 2024 16:00:00 +0000</pubDate>
  <atom:published>2024-07-29T16:00:00Z</atom:published>
    <dc:creator>Chris Romeo</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><b>Hey there,</b></p><p class="paragraph" style="text-align:left;">In this week’s issue, please enjoy the following:</p><ul><li><p class="paragraph" style="text-align:left;">Five security articles 📰 that are worth YOUR time</p></li><li><p class="paragraph" style="text-align:left;">Featured focus: Sticking with anything</p></li><li><p class="paragraph" style="text-align:left;">Application Security Podcast 🎙️Corner</p></li><li><p class="paragraph" style="text-align:left;">Where to find Chris? 🌎</p></li></ul><h2 class="heading" style="text-align:left;" id="five-security-articles-that-are-wor">Five Security Articles 📰 that Are Worth YOUR Time</h2><ol start="1"><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://yieldcode.blog/post/lets-blame-the-dev-who-pressed-deploy/?utm_source=tldrnewsletter" target="_blank" rel="noopener noreferrer nofollow">Let&#39;s blame the dev who pressed &quot;Deploy&quot;</a>—Blaming software engineers for bugs and outages overlooks the broader issues caused by CEO decisions, customer demands, IT department pressures, and unrealistic regulations, contributing to systemic failures in the tech industry. [Blame culture has existed<span style="background-color:#FFFFFF;"><b> for as long as software has had bugs. Over the last few weeks, root cause analyses have ended with some people exiting the building. We should be past blame culture, but we’re not.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://ventureinsecurity.net/p/palo-alto-isnt-going-to-buy-everyone?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-61-sticking-with-anything-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Palo Alto isn’t going to buy everyone: the anatomy of cybersecurity startup exits</a><a class="link" href="https://cloud.google.com/blog/transform/to-securely-build-ai-on-google-cloud-follow-these-best-practices-infographic?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-61-sticking-with-anything-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow"> </a>— Speculating that Palo Alto Networks will acquire any cybersecurity startup is misguided, as most acquisitions are strategic, focusing on early leaders in specific markets, and many don&#39;t result in significant financial gains for founders or employees. <b>[</b><span style="background-color:#FFFFFF;"><b>Insight into the cybersecurity startup space, fueled by recent Wiz news about walking away from the Google deal. If you’re an early-stage founder, don’t look at this as discouragement but intelligence.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.nytimes.com/2024/06/24/business/media/netflix-corporate-culture.html?unlocked_article_code=1.2U0.upEj.EIos50pozWp5&smid=url-share&utm_source=tldrnewsletter" target="_blank" rel="noopener noreferrer nofollow">Responsibility Over Freedom: How Netflix’s Culture Has Changed</a><a class="link" href="https://cloud.google.com/blog/transform/to-securely-build-ai-on-google-cloud-follow-these-best-practices-infographic?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-61-sticking-with-anything-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow"> </a>— Netflix&#39;s internal culture, characterized by transparency, freedom, and responsibility, has been central to its success, though it continually evolves, emphasizing &quot;People Over Process&quot; and refining its principles to balance openness with practical constraints. <b>[</b><span style="background-color:#FFFFFF;"><b>Netflix is always a good case study, as they’ve been cutting-edge for so long.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://securelist.com/biometric-terminal-vulnerabilities/112800/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-61-sticking-with-anything-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">QR code SQL injection and other vulnerabilities in a popular biometric terminal</a><a class="link" href="https://cloud.google.com/blog/transform/to-securely-build-ai-on-google-cloud-follow-these-best-practices-infographic?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-61-sticking-with-anything-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow"> </a>— ZKTeco biometric terminals have vulnerabilities, such as SQL injection via QR codes, that can allow unauthorized access and compromise authentication processes and biometric data security. <b>[</b><span style="background-color:#FFFFFF;"><b>I don’t usually share the vuln of the week, but this one caught my attention because of the novel attack vector.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://adtmag.com/Articles/2024/06/12/Docker-2024-State-of-AppDev-Report.aspx?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-61-sticking-with-anything-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Docker&#39;s 2024 State of Application Development Report Highlights Key Trends for Developers</a><a class="link" href="https://cloud.google.com/blog/transform/to-securely-build-ai-on-google-cloud-follow-these-best-practices-infographic?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-61-sticking-with-anything-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow"> </a>— Docker&#39;s 2024 State of Application Development Report highlights trends such as a shift to cloud-based development, rising microservices adoption, ongoing security challenges, and increased integration of AI tools like ChatGPT and GitHub Copilot in development processes. <b>[</b><span style="background-color:#FFFFFF;"><b>If you want to improve at #AppSec, study the details about developers and their worlds. Please get to know them better.]</b></span></p></li></ol><h2 class="heading" style="text-align:left;" id="featured-focus-sticking-with-anythi">Featured Focus: Sticking with anything</h2><p class="paragraph" style="text-align:left;">If you’ve been on this planet for over five seconds, you know that things sometimes get challenging. Whether we’re talking about work or personal-related things, challenges are a fact of life. This is for the person struggling with something, feeling like there is no solution or a positive path forward.</p><p class="paragraph" style="text-align:left;">I want to encourage you. When things get tough, it can seem like there is no possible positive outcome. I&#39;ve had many ups and downs in my almost three-decade career. I’ve been blessed to have more ups than downs when they all add up, but I have also had some tough times.</p><p class="paragraph" style="text-align:left;">I have found value in sticking with whatever the challenge lies before me and having the attitude of not giving up. There is immense value in resiliency, in finding a path forward to the challenge. </p><p class="paragraph" style="text-align:left;">One time in my career, the path forward was switching teams after I was forced out of my first management role. In their defense, I wasn’t a great manager in those days. (I learned an immense amount from that experience.) While those days appeared dark, a sun rose on the horizon. The new team that I switched to was Cisco’s Secure Development Lifecycle team, and that was the change that put me on the AppSec path way back in 2009. Was it tough in the moment? Heck yeah. I wanted to run away, but sticking with it, I changed the focus of my career.</p><p class="paragraph" style="text-align:left;">So, could you stick with anything? Things will sometimes be tough in the short term, but resiliency means pushing forward and finding a better outcome.</p><h2 class="heading" style="text-align:left;" id="podcast-corner">Podcast 🎙️ Corner</h2><p class="paragraph" style="text-align:left;">I love making podcasts. In Podcast Corner, you get a single place to see what I’ve put out this week. Sometimes, they are my podcasts. Other times, they are podcasts that have caught my attention.</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://appsec.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-61-sticking-with-anything-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Application Security Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Derek Fisher -- Hiring in Cyber/AppSec (<a class="link" href="https://www.buzzsprout.com/1730684/15421342?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-61-sticking-with-anything-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/ifc5CMNLajM?si=b1M60HrxRnMu-BZd&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-61-sticking-with-anything-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Chris and Robert discuss cybersecurity hiring and entry-level role challenges with Derek Fisher.</p></li><li><p class="paragraph" style="text-align:left;">They cover the value of certifications, the necessity of lifelong learning, and the importance of networking.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitytable.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-61-sticking-with-anything-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Security Table</a></p><ul><li><p class="paragraph" style="text-align:left;">To SSH or Not? (<a class="link" href="https://www.buzzsprout.com/2094080/15424755?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-61-sticking-with-anything-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/DKngvtjFXhc?si=IehHH_uoKBBypVDS&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-61-sticking-with-anything-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Chris, Matt, and Izar discuss the OpenSSH regression vulnerability, detailing a race condition leading to remote code execution and debating SSH&#39;s necessity in modern cloud-native environments.</p></li><li><p class="paragraph" style="text-align:left;">They explore the chain of security updates, the role of QA in preventing regressions, and who should catch vulnerabilities first—QA teams, pentesters, or automated tools.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://threatmodel.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-61-sticking-with-anything-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Threat Modeling Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">What is the Essence of Threat Modeling? (<a class="link" href="https://www.buzzsprout.com/2152378/12732554?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-61-sticking-with-anything-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Chris Romeo explores various definitions of threat modeling from industry experts, discussing whether risk assessment and threat modeling are the same, the essence of threat modeling, collaboration and documentation, and proactive security.</p></li><li><p class="paragraph" style="text-align:left;">The podcast favors the Threat Modeling Manifesto&#39;s definition, emphasizing threat modeling as analyzing system representations to highlight security and privacy concerns involving art, science, collaboration, and brainstorming.</p></li></ul></li></ul></li></ul><h2 class="heading" style="text-align:left;" id="where-to-find-chris">Where to find Chris? 🌎</h2><ul><li><p class="paragraph" style="text-align:left;">Webinar: Modern Threat Modeling: Business vs. Technical Perspectives, July 29 @ 1 PM Eastern; <a class="link" href="https://www.linkedin.com/events/7211825043473862656/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-61-sticking-with-anything-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">register here</a>.</p></li><li><p class="paragraph" style="text-align:left;">Webinar: Secure by Design, August 29 @ 3 PM Eastern; register link coming soon.</p></li><li><p class="paragraph" style="text-align:left;">InfoSec World, Sept 22-25, 2024</p><ul><li><p class="paragraph" style="text-align:left;">The Modern Application Security Rocket Ship — Monday, Sept 23, 10:15 AM</p></li><li><p class="paragraph" style="text-align:left;">The Paradox of Secure and Private By Design — Tuesday, Sept 24, 1:30 PM</p></li><li><p class="paragraph" style="text-align:left;">Workshop: Threat Modeling Championship: Breaker vs. Builder — Sunday, Sept 22, 9 AM - 12 PM</p></li></ul></li></ul><p class="paragraph" style="text-align:left;">🤔<i> Have questions, comments, or feedback? I&#39;d love to </i><span style="text-decoration:underline;"><i><b><a class="link" href="mailto:chris@kerr.ventures?ref=ReasonableAppSec" target="_blank" rel="noopener noreferrer nofollow">hear</a></b></i></span><i> from you!</i></p><p class="paragraph" style="text-align:start;">🔥<i> Reasonable AppSec is brought to you by </i><span style="text-decoration:underline;"><i><b><a class="link" href="https://kerr.ventures?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-61-sticking-with-anything-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Kerr Ventures</a></b></i></span><i>.</i></p><p class="paragraph" style="text-align:start;">🤝<i> Want to partner with Reasonable AppSec? Reach out, and let’s chat.</i></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=9f79a563-bad2-4582-a7c5-0f261612fa04&utm_medium=post_rss&utm_source=reasonable_application_security">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Reasonable 🔐AppSec #60 - Five Security Articles and Podcast Corner</title>
  <description>A review of application security happenings and industry news from Chris Romeo.</description>
  <link>https://appsec.beehiiv.com/p/reasonable-appsec-60-five-security-articles-podcast-corner</link>
  <guid isPermaLink="true">https://appsec.beehiiv.com/p/reasonable-appsec-60-five-security-articles-podcast-corner</guid>
  <pubDate>Mon, 22 Jul 2024 16:00:00 +0000</pubDate>
  <atom:published>2024-07-22T16:00:00Z</atom:published>
    <dc:creator>Chris Romeo</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><b>Hey there,</b></p><p class="paragraph" style="text-align:left;">In this week’s issue, please enjoy the following:</p><ul><li><p class="paragraph" style="text-align:left;">Five security articles 📰 that are worth YOUR time</p></li><li><p class="paragraph" style="text-align:left;">Application Security Podcast 🎙️Corner</p></li><li><p class="paragraph" style="text-align:left;">Where to find Chris? 🌎</p></li></ul><h2 class="heading" style="text-align:left;" id="sponsor-post-devici-is-the-threat-m">Sponsor post: Devici is the threat modeling platform you’ve been waiting for</h2><p class="paragraph" style="text-align:left;">Simple, intelligent, scalable: these words describe the Devici threat modeling platform.</p><p class="paragraph" style="text-align:left;">Devici has a free forever plan. We provide three comprehensive threat models for free forever. Create an account today and start threat modeling for free! You can invite up to nine colleagues to your account to model together in a collaborative environment. Visit <a class="link" href="https://devici.com?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-60-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">devici.com</a> today to sign up.</p><h2 class="heading" style="text-align:left;" id="five-security-articles-that-are-wor">Five Security Articles 📰 that Are Worth YOUR Time</h2><ol start="1"><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.itpro.com/security/cisos-plan-to-start-downsizing-security-teams-because-of-ai-but-experts-warn-its-a-shortsighted-and-dangerous-path-to-take?blaid=6289581&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-60-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">CISOs plan to start downsizing security teams because of AI – but experts warn it’s a “shortsighted and dangerous&quot; path to take</a><a class="link" href="https://cloud.google.com/blog/transform/to-securely-build-ai-on-google-cloud-follow-these-best-practices-infographic?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-60-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow"> </a>— CISOs are planning to reduce security team sizes due to AI adoption. Still, experts warn that this is a shortsighted and dangerous approach as AI should complement rather than replace human expertise in cybersecurity. <b>[</b><span style="background-color:#FFFFFF;"><b>What is a word larger than shortsighted and dangerous? We’ve been short on security team sizes for as long as I can remember, and now AI will result in shedding headcount. I don’t think so. Bad plan.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://techxplore.com/news/2024-07-simple-firmware-device-bluetooth-fingerprint.html?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-60-five-security-articles-and-podcast-corner#google_vignette" target="_blank" rel="noopener noreferrer nofollow">A simple firmware update completely hides a device&#39;s Bluetooth fingerprint</a><a class="link" href="https://cloud.google.com/blog/transform/to-securely-build-ai-on-google-cloud-follow-these-best-practices-infographic?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-60-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow"> </a>— Researchers at the University of California San Diego have developed a firmware update that completely hides a device&#39;s Bluetooth fingerprint, preventing it from being used to track the device by randomizing the device&#39;s unique signal characteristics. <b>[</b><span style="background-color:#FFFFFF;"><b>Shouldn’t this be included within the core operating system?</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://tldrsec.com/p/business-of-secure-defaults?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-60-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">The Race to Make a Business of Secure Defaults</a> — Modern security teams, with support from government and tech companies, are using secure defaults—tools and processes that inherently integrate security—to help developers build secure applications quickly while reducing the need for explicit security decisions. <b>[</b><span style="background-color:#FFFFFF;"><b>There is tension between secure defaults, paved roads, guard rails, and innovation. With too many lockdowns, we start to build cookie-cutter things that are all the same.]</b></span></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://danaepp.com/3-ways-to-improve-appsec-code-auditing-with-graudit?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-60-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">3 ways to improve appsec code auditing with graudit</a> — Improve application security code auditing with Graudit by customizing dangerous function databases, reducing false positives using <b>flatline.db</b> and <b>fruit.db</b>, and using non-destructive review tools like <b>vi</b> with aliases for <b>highlight</b> and <b>less</b>. <b>[</b><span style="background-color:#FFFFFF;"><b>Code auditing is a skill, and new tools are always worth a look.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://ramimac.me/rasp?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-60-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">What happened to RASP?</a> — RASP&#39;s initial promise of in-app security monitoring and protection has faced challenges due to technical issues and non-technical critiques, leading to interest in the newer Application Detection and Response (ADR) approach as a potential solution. <b>[</b><span style="background-color:#FFFFFF;"><b>This is a counterpoint to what I thought of as the industry&#39;s current state. ADR? Really? Do we need another DR solution?</b></span><b>]</b></p></li></ol><h2 class="heading" style="text-align:left;" id="podcast-corner">Podcast 🎙️ Corner</h2><p class="paragraph" style="text-align:left;">I love making podcasts. In Podcast Corner, you get a single place to see what I’ve put out this week. Sometimes, they are my podcasts. Other times, they are podcasts that have caught my attention.</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://appsec.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-60-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Application Security Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Tanya Janca -- Secure Guardrails (<a class="link" href="https://www.buzzsprout.com/1730684/15383701?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-60-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/xoITqZgRs3I?si=rhJnvnME1JRENtDa&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-60-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Join Tanya Janka, aka SheHacksPurple, when she discusses secure guardrails, the distinction between them and paved roads, and their implementation in application security.</p></li><li><p class="paragraph" style="text-align:left;">Tanya, an award-winning speaker and SEMGREP&#39;s head of education, also shares insights on creating secure software, teaching developers, and her passion for her hobby farm and gardening.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitytable.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-60-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Security Table</a></p><ul><li><p class="paragraph" style="text-align:left;">Rethinking Security Conferences: Engagement and Innovation (<a class="link" href="https://www.buzzsprout.com/2094080/15354254?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-60-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/lh7G9v2iF5U?si=j9jGQosHyDiOU6LX&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-60-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Chris, Matt, and Izar discuss the current state of security conferences, evaluating the value of various types of gatherings, the importance of networking, and the need for engaging, participatory formats catering to introverts and extroverts.</p></li><li><p class="paragraph" style="text-align:left;">They share personal experiences and preferences for attending and speaking at conferences and explore hybrid approaches that combine presentations with facilitated discussions and interactive elements.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://threatmodel.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-60-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Threat Modeling Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Nandita Rao Narla -- Privacy Threat Modeling (<a class="link" href="https://www.buzzsprout.com/2152378/14365330?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-60-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Nandita Rao Narla introduces the basics of privacy in software, covering privacy threats, threat modeling, and privacy by design, which is essential for anyone handling user information.</p></li><li><p class="paragraph" style="text-align:left;">This episode of the Threat Modeling Podcast is a primer on assessing and mitigating privacy concerns and implementing privacy-focused design in projects.</p></li></ul></li></ul></li></ul><h2 class="heading" style="text-align:left;" id="where-to-find-chris">Where to find Chris? 🌎</h2><ul><li><p class="paragraph" style="text-align:left;">Webinar: Modern Threat Modeling: Business vs. Technical Perspectives, July 29 @ 1 PM Eastern; <a class="link" href="https://www.linkedin.com/events/7211825043473862656/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-60-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">register here</a>.</p></li><li><p class="paragraph" style="text-align:left;">Webinar: Secure by Design, August 29 @ 3 PM Eastern; register link coming soon.</p></li><li><p class="paragraph" style="text-align:left;">InfoSec World, Sept 23-25, 2024</p><ul><li><p class="paragraph" style="text-align:left;">The Modern Application Security Rocket Ship — Time/date TBD</p></li><li><p class="paragraph" style="text-align:left;">The Paradox of Secure and Private By Design — Time/date TBD</p></li><li><p class="paragraph" style="text-align:left;">Workshop: Threat Modeling Championship: Breaker vs. Builder — Time/date TBD</p></li></ul></li></ul><p class="paragraph" style="text-align:left;">🤔<i> Have questions, comments, or feedback? I&#39;d love to </i><span style="text-decoration:underline;"><i><b><a class="link" href="mailto:chris@kerr.ventures?ref=ReasonableAppSec" target="_blank" rel="noopener noreferrer nofollow">hear</a></b></i></span><i> from you!</i></p><p class="paragraph" style="text-align:start;">🔥<i> Reasonable AppSec is brought to you by </i><span style="text-decoration:underline;"><i><b><a class="link" href="https://kerr.ventures?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-60-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Kerr Ventures</a></b></i></span><i>.</i></p><p class="paragraph" style="text-align:start;">🤝<i> Want to partner with Reasonable AppSec? Reach out, and let’s chat.</i></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=e57403bc-6a53-40d0-819c-d48351fe768a&utm_medium=post_rss&utm_source=reasonable_application_security">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Reasonable 🔐AppSec #59 - FOMO or something else?, Five Security Articles, and Podcast Corner</title>
  <description>A review of application security happenings and industry news from Chris Romeo.</description>
  <link>https://appsec.beehiiv.com/p/reasonable-appsec-59-fomo-something-else-five-security-articles-podcast-corner</link>
  <guid isPermaLink="true">https://appsec.beehiiv.com/p/reasonable-appsec-59-fomo-something-else-five-security-articles-podcast-corner</guid>
  <pubDate>Tue, 16 Jul 2024 16:00:00 +0000</pubDate>
  <atom:published>2024-07-16T16:00:00Z</atom:published>
    <dc:creator>Chris Romeo</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><b>Hey there,</b></p><p class="paragraph" style="text-align:left;">In this week’s issue, please enjoy the following:</p><ul><li><p class="paragraph" style="text-align:left;">Five security articles 📰 that are worth YOUR time</p></li><li><p class="paragraph" style="text-align:left;">Featured focus: FOMO or something else?</p></li><li><p class="paragraph" style="text-align:left;">Application Security Podcast 🎙️Corner</p></li><li><p class="paragraph" style="text-align:left;">Where to find Chris? 🌎</p></li></ul><h2 class="heading" style="text-align:left;" id="five-security-articles-that-are-wor">Five Security Articles 📰 that Are Worth YOUR Time</h2><ol start="1"><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://content.reversinglabs.com/best-of-rl-blog/platform-engineering-secure-by-design?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-59-fomo-or-something-else-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">How platform engineering helps you get a good start on Secure by Design</a><a class="link" href="https://cloud.google.com/blog/transform/to-securely-build-ai-on-google-cloud-follow-these-best-practices-infographic?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-59-fomo-or-something-else-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow"> </a>— Platform engineering facilitates the adoption of &quot;secure by design&quot; principles by embedding security measures early in development. This integration enhances system resilience and reduces vulnerabilities through core engineering practices. <b>[</b><span style="background-color:#FFFFFF;"><b>I provided some thoughts on the intersection of platform and SbD.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://trufflesecurity.com/blog/stop-recommending-jwts?utm_source=tldrinfosec" target="_blank" rel="noopener noreferrer nofollow">Stop Recommending JWTs (with symmetric keys)</a><a class="link" href="https://cloud.google.com/blog/transform/to-securely-build-ai-on-google-cloud-follow-these-best-practices-infographic?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-59-fomo-or-something-else-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow"> </a>— Using JSON Web Tokens (JWTs) poses security risks like key exposure and token forgery. Switching to asymmetric keys or alternative token formats is recommended to enhance security. <b>[</b><span style="background-color:#FFFFFF;"><b>The more you know.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://addepar.com/blog/introducing-redflag-using-ai-to-scale-addepar-s-offensive-security-team?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-59-fomo-or-something-else-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Introducing RedFlag: Using AI to Scale Addepar&#39;s Offensive Security Team</a> — Addepar introduces RedFlag, an AI-powered tool to enhance their offensive security team by automating the scoping of manual security tests. Leveraging Anthropic’s Claude v3 model, RedFlag analyzes pull requests, enriches them with related information, and generates focused security test plans, significantly reducing the time and effort needed for comprehensive security assessments. <b>[</b><span style="background-color:#FFFFFF;"><b>This fits within my vision for AI in the next five years — AI doing a labor-intensive task, allowing the humans to focus on the part that needs “brainstorming.”</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/pulse/you-might-secure-design-part-1-mark-winstead-ay5wc/?trackingId=cI5hWB8kR0pP5cl2TlRL8g%3D%3D&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-59-fomo-or-something-else-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">If _____, you might not be Secure By Design Part 1</a> <a class="link" href="https://cloud.google.com/blog/transform/to-securely-build-ai-on-google-cloud-follow-these-best-practices-infographic?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-59-fomo-or-something-else-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow"> </a>— &quot;Secure By Design&quot; emphasizes the importance of reducing and managing complexity to enhance security. Increased complexity heightens vulnerabilities, complicates situational awareness, and undermines the system&#39;s robustness, making simplicity a fundamental principle in effective security design. <b>[</b><span style="background-color:#FFFFFF;"><b>Simplicity is essential for security and privacy, but it is hard to maintain within a functioning system.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://tldrsec.com/p/dont-security-engineer-asymmetry?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-59-fomo-or-something-else-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Don’t Security Engineer Asymmetric Workloads</a> — Matt Schellhas’ &quot;Asymmetric Workloads&quot; concept highlights leadership failures, particularly the unfair distribution of workload burdens. This issue is relevant to security engineers, where the imbalance can lead to inefficiencies and resentment, ultimately undermining collaboration and organizational security. <b>[</b><span style="background-color:#FFFFFF;"><b>This isn’t workloads as you think with orchestration, but instead is focused on a human capital problem.</b></span><b>]</b></p></li></ol><h2 class="heading" style="text-align:left;" id="featured-focus-blah">Featured focus: FOMO or something else?</h2><p class="paragraph" style="text-align:justify;">OWASP Global Lisbon and ThreatModCon took place a few weeks ago. I didn’t attend either event. I’m an avid conference attendee and speaker (when I get the chance), but this time, I didn’t get the FOMO I expected.</p><p class="paragraph" style="text-align:justify;">Each summer for the past fourteen years (except for COVID), I’ve run a summer camp in Eastern Europe, in Moldova. This camp is focused on serving young people from this country. This is a 180 turn from what I do in my “day job.” Instead of spending time on calls, answering emails, and dreaming up new features, I act as a camp director for this summer camp. It’s a busy week, starting at 6 AM and often cruising towards a 10 PM wrap-up for the day.</p><p class="paragraph" style="text-align:justify;">This experience always reminds me that there is more to life than work and more to life than professional things. I share this experience to encourage everyone to find things away from work that add value to the world. Don’t live to work, work to live. </p><p class="paragraph" style="text-align:justify;">I hope you&#39;ll be able to find your summer camp-style experience for the future.</p><h2 class="heading" style="text-align:left;" id="devicis-notsowellhidden-advertiseme">Devici&#39;s not-so-well-hidden advertisement</h2><p class="paragraph" style="text-align:left;">Hey, what did you expect? We needed a sponsor, and now we have one. </p><p class="paragraph" style="text-align:left;">Did you know that Devici, the threat modeling company I founded, has a free forever plan? We provide three comprehensive threat models that are free forever. Create an account today and start threat modeling for free! Invite up to ten colleagues into your account to model together in a collaborative environment. Visit <a class="link" href="https://devici.com?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-59-fomo-or-something-else-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">devici.com</a> today to sign up.</p><h2 class="heading" style="text-align:left;" id="podcast-corner">Podcast 🎙️ Corner</h2><p class="paragraph" style="text-align:left;">I love making podcasts. In Podcast Corner, you get a single place to see what I’ve put out this week. Sometimes, they are my podcasts. Other times, they are podcasts that have caught my attention.</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://appsec.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-59-fomo-or-something-else-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Application Security Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Jahanzeb Farooq -- Launching and executing an AppSec program (<a class="link" href="https://www.buzzsprout.com/1730684/15340944?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-59-fomo-or-something-else-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/p8kOsgxgA-Q?si=QC3Y9X2EPPt0Slk3&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-59-fomo-or-something-else-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Jahanzeb Farooq discusses his journey in cybersecurity, emphasizing the importance of understanding developer needs and implementing appropriate tools based on his experiences at Siemens, Novo Nordisk, and Danske Bank.</p></li><li><p class="paragraph" style="text-align:left;">The conversation also explores the complexities of cybersecurity in pharmaceutical and financial sectors, focusing on regulatory requirements, software&#39;s role in critical industries, security education, threat modeling, and digital transformation.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitytable.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-59-fomo-or-something-else-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Security Table</a></p><ul><li><p class="paragraph" style="text-align:left;">Privacy vs. Security: Complexity at the Crossroads (<a class="link" href="https://www.buzzsprout.com/2094080/15271494?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-59-fomo-or-something-else-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/zoxl1awFO_0?si=angp86xbfZixPCuo&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-59-fomo-or-something-else-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Chris, Izar, and Matt discuss the shift in cybersecurity from a product-centric to an architectural-centric approach, focusing on integrating inherent capabilities rather than relying on add-on products.</p></li><li><p class="paragraph" style="text-align:left;">They examine the intersections of security and privacy, the challenges of privacy threat modeling, and the evolving nature of regulations, emphasizing the importance of understanding the broader data ecosystem and continuous threat modeling.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://threatmodel.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-59-fomo-or-something-else-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Threat Modeling Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Akira Brand -- Gaining Experience by Threat Modeling (<a class="link" href="https://www.buzzsprout.com/2152378/13676193?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-59-fomo-or-something-else-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Akira Brand joins Chris to discuss her journey into threat modeling, highlighting the importance of collaboration, understanding the application, and using tools and diagrams to aid the process, drawing parallels between surgical checklists and the STRIDE model for a comprehensive approach.</p></li><li><p class="paragraph" style="text-align:left;">Her initial threat modeling identified significant security risks due to excessive permissions. She emphasized the power of collaboration across engineering, data analytics, and security teams to create holistic security solutions, showcasing true success in threat modeling.</p></li></ul></li></ul></li></ul><h2 class="heading" style="text-align:left;" id="where-to-find-chris">Where to find Chris? 🌎</h2><ul><li><p class="paragraph" style="text-align:left;">Webinar: Modern Threat Modeling: Business vs. Technical Perspectives, July 25 @ 1 PM Eastern; <a class="link" href="https://www.linkedin.com/events/7211825043473862656/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-59-fomo-or-something-else-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">register here</a>.</p></li><li><p class="paragraph" style="text-align:left;">Webinar: Secure by Design, August 29 @ 3 PM Eastern; register link coming soon.</p></li><li><p class="paragraph" style="text-align:left;">InfoSec World, Sept 23-25, 2024</p><ul><li><p class="paragraph" style="text-align:left;">The Modern Application Security Rocket Ship — Time/date TBD</p></li><li><p class="paragraph" style="text-align:left;">The Paradox of Secure and Private By Design — Time/date TBD</p></li><li><p class="paragraph" style="text-align:left;">Workshop: Threat Modeling Championship: Breaker vs. Builder — Time/date TBD</p></li></ul></li></ul><p class="paragraph" style="text-align:left;">🤔<i> Have questions, comments, or feedback? I&#39;d love to </i><span style="text-decoration:underline;"><i><b><a class="link" href="mailto:chris@kerr.ventures?ref=ReasonableAppSec" target="_blank" rel="noopener noreferrer nofollow">hear</a></b></i></span><i> from you!</i></p><p class="paragraph" style="text-align:start;">🔥<i> Reasonable AppSec is brought to you by </i><span style="text-decoration:underline;"><i><b><a class="link" href="https://kerr.ventures?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-59-fomo-or-something-else-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Kerr Ventures</a></b></i></span><i>.</i></p><p class="paragraph" style="text-align:start;">🤝<i> Want to partner with Reasonable AppSec? Reach out, and let’s chat.</i></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=28658cd8-28df-4e5d-9861-9f3ef9981422&utm_medium=post_rss&utm_source=reasonable_application_security">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Reasonable 🔐AppSec #58 - Secure and Private by Design Converge with Threat Modeling, Five Security Articles, and Podcast Corner</title>
  <description>A review of application security happenings and industry news from Chris Romeo.</description>
  <link>https://appsec.beehiiv.com/p/reasonable-appsec-58-update-five-security-articles-podcast-corner</link>
  <guid isPermaLink="true">https://appsec.beehiiv.com/p/reasonable-appsec-58-update-five-security-articles-podcast-corner</guid>
  <pubDate>Mon, 01 Jul 2024 16:00:00 +0000</pubDate>
  <atom:published>2024-07-01T16:00:00Z</atom:published>
    <dc:creator>Chris Romeo</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><b>Hey there,</b></p><p class="paragraph" style="text-align:left;">In this week’s issue, please enjoy the following:</p><ul><li><p class="paragraph" style="text-align:left;">Five security articles 📰 that are worth YOUR time</p></li><li><p class="paragraph" style="text-align:left;">Featured focus: Secure and Private by Design Converge with Threat Modeling</p></li><li><p class="paragraph" style="text-align:left;">Application Security Podcast 🎙️Corner</p></li><li><p class="paragraph" style="text-align:left;">Where to find Chris? 🌎</p></li></ul><p class="paragraph" style="text-align:left;">Did you know that Devici, the threat modeling company I founded, has a free forever plan? We provide three comprehensive threat models that are free forever. Create an account today and start threat modeling for free! Invite up to ten colleagues into your account to model together in a collaborative environment. Visit <a class="link" href="https://devici.com?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-58-secure-and-private-by-design-converge-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">devici.com</a> today to sign up.</p><h2 class="heading" style="text-align:left;" id="five-security-articles-that-are-wor">Five Security Articles 📰 that Are Worth YOUR Time</h2><ol start="1"><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://futurism.com/the-byte/study-chatgpt-answers-wrong?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-58-secure-and-private-by-design-converge-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Study Finds That 52 Percent of ChatGPT Answers to Programming Questions Are Wrong</a><a class="link" href="https://cloud.google.com/blog/transform/to-securely-build-ai-on-google-cloud-follow-these-best-practices-infographic?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-58-secure-and-private-by-design-converge-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow"> </a> — A study by Purdue University found that 52% of ChatGPT&#39;s answers to programming questions contain misinformation, with many users preferring its polite and comprehensive style despite its inaccuracies. This highlights the challenges and risks of relying on AI-generated code solutions, stressing the need to carefully validate such responses. <b>[</b><span style="background-color:#FFFFFF;"><b>And people wonder why I suggest GPT is not a replacement for a threat modeling tool? The challenge I have is that it is not predictable. You can get two different answers right after the other.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.reversinglabs.com/blog/the-state-of-appsec-are-we-getting-better-or-worse?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-58-secure-and-private-by-design-converge-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">The state of AppSec: Are we getting ahead of attackers — or falling behind?</a> — Over the past five years, application security (AppSec) has improved in secure programming languages and container security, but software supply chain security challenges persist. Despite advancements, AppSec must evolve rapidly to keep pace with modern threats, requiring better tools, investment in people, and a comprehensive understanding of security risks throughout the software development lifecycle. <b>[</b><span style="background-color:#FFFFFF;"><b>Nice report on the state of AppSec across many different categories.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.globalbankingandfinance.com/pci-dss-4-0-simplified-what-you-need-to-know/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-58-secure-and-private-by-design-converge-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">PCI DSS 4.0 Simplified: What You Need to Know</a> — PCI DSS 4.0 introduces several changes to improve the security of payment card data, emphasizing secure network maintenance, data protection, vulnerability management, access control, and regular monitoring and testing. Organizations must adopt comprehensive security policies, ensure minimal data storage, and continuously update and audit their security practices to comply with these standards. <b>[</b><span style="background-color:#FFFFFF;"><b>Many impactful changes for AppSec in 4.0. Worth a closer look.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.darkreading.com/cybersecurity-operations/the-ceo-is-next?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-58-secure-and-private-by-design-converge-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">The CEO Is Next</a> — Government agencies will soon seek to hold CEOs personally liable for insufficient cybersecurity investments, as the actual costs of breaches often impact consumers more than companies. The Biden administration&#39;s National Cybersecurity Strategy and recent actions, such as the SEC&#39;s case against SolarWinds, reflect a shift towards holding CEOs accountable, highlighting the need for corporate leadership to prioritize and adequately fund cybersecurity measures. <b>[</b><span style="background-color:#FFFFFF;"><b>How does this change the game in the CEO’s office and the board room? It seems challenging to prove personal liability unless there is gross negligence.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://danaepp.com/why-hast-is-important-to-api-hackers?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-58-secure-and-private-by-design-converge-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Why HAST is important to API hackers</a> — Human Application Security Testing (HAST) involves creating manual tests that can be automated to find security vulnerabilities in APIs, providing deeper insights than traditional automated tools like SAST and DAST. HAST allows for context-aware testing, continuous security validation, and detection of complex attack chains, making it crucial for thorough and effective API security. <b>[</b><span style="background-color:#FFFFFF;"><b>Nice methodology to think through from Dana about manual API testing.</b></span><b>]</b></p></li></ol><h2 class="heading" style="text-align:left;" id="featured-focus-blah">Featured focus: Secure and Private by Design Converge with Threat Modeling</h2><p class="paragraph" style="text-align:justify;">My talk from RSAC 2024, “<a class="link" href="https://youtu.be/xX9HRsb_TBA?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-58-secure-and-private-by-design-converge-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Secure and Private by Design Converge with Threat Modeling</a>,” was recently published on YouTube.</p><p class="paragraph" style="text-align:justify;">I created this talk because I saw something missing from all the hoopla around secure by design. Plenty of things looked secure by design and were sold as secure by design, but none provided a way to ACHIEVE secure by design.</p><p class="paragraph" style="text-align:justify;">In this talk, I describe a framework for achieving secure and private by design and default. I broke this process into four components: design decisions, data flow diagrams, security and privacy patterns, and checking the work (threat modeling.)</p><p class="paragraph" style="text-align:justify;">With design decisions, I provided a list of things to consider before starting a new application. Such as language and framework choice (a security and privacy enforcing stack), mechanisms to protect PII and customer data, and the responsibility to use open source responsibly. Many of these are not new, but I ordered them in such a way as to make them matter for a new design. Just so you know, you can also apply these design decisions to other existing things that you have written.</p><p class="paragraph" style="text-align:justify;">Data flow diagrams are the heart of the design analysis, using a simple and structured format to draw a picture of the design. I find data flow diagrams the best way to visualize what I need to analyze. With a conversation, it is easy to get lost. A DFD is a reference you can continuously return to and revise.</p><p class="paragraph" style="text-align:justify;">Security and privacy patterns are the paved roads that security teams can define and then make available to developers via a menu of options. These patterns include authentication/multi-factor, access control/authorization, and validation/sanitization/encoding. They provide the building blocks for a solid security and privacy foundation.</p><p class="paragraph" style="text-align:justify;">Threat modeling is the final step, where the work is checked. The DFD exists from step two, and adding the details of the patterns provides a final design for proper threat modeling. Proper threat modeling considers threats and focuses on the best ways to mitigate them.</p><p class="paragraph" style="text-align:justify;">These steps together provide a framework for embracing secure and private by design and default so that you can make this concept a reality! So put down your pledges, hide the reference documents, and focus on deploying a process that creates secure and private by design instead of all the other movements that talk about it.</p><h2 class="heading" style="text-align:left;" id="podcast-corner">Podcast 🎙️ Corner</h2><p class="paragraph" style="text-align:left;">I love making podcasts. In Podcast Corner, you get a single place to see what I’ve put out this week. Sometimes, they are my podcasts. Other times, they are podcasts that have caught my attention.</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://appsec.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-58-secure-and-private-by-design-converge-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Application Security Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Steve Wilson -- OWASP Top Ten for LLMs (<a class="link" href="https://www.buzzsprout.com/1730684/13028318?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-58-secure-and-private-by-design-converge-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/Seut2_XuIbI?si=5taPafB63M_EhCFI&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-58-secure-and-private-by-design-converge-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">The OWASP Top Ten for LLMs project, led by Steve Wilson, aims to create standardized guidelines for building secure AI applications using large language models like ChatGPT, addressing traditional security issues and introducing a new discipline of AI security engineering.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitytable.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-58-secure-and-private-by-design-converge-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Security Table</a></p><ul><li><p class="paragraph" style="text-align:left;">Privacy and the creepiness factor of collecting data (<a class="link" href="https://www.buzzsprout.com/2094080/13025006?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-58-secure-and-private-by-design-converge-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/mOV8dquLL48?si=89mCm5nfBKdwKRoF&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-58-secure-and-private-by-design-converge-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Ally O&#39;Leary, a privacy compliance expert, explains the intersection of privacy and security, emphasizing the importance of understanding personal information and data storage within company systems.</p></li><li><p class="paragraph" style="text-align:left;">She highlights that privacy, often triggered by regulations like GDPR, is distinct from security but closely related. It requires regular data flow reviews, audits, and collaboration between privacy and security professionals during development.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://threatmodel.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-58-secure-and-private-by-design-converge-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Threat Modeling Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">Dr. Michael Loadenthal -- Intersectional, Harm Reduction Approach to Threat Modeling (<a class="link" href="https://www.buzzsprout.com/2152378/13462262?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-58-secure-and-private-by-design-converge-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Dr. Michael Loadenthal emphasizes a comprehensive threat modeling approach considering political, legal, ethical, and social dimensions. This approach, developed from his experience in social movements and activism, addresses threats beyond the technical realm.</p></li><li><p class="paragraph" style="text-align:left;">He utilizes multidisciplinary tools like mind maps and the harm reduction framework, collaborating with diverse teams to develop context-specific solutions for companies, non-profits, and high-profile individuals, enhancing the effectiveness of threat modeling.</p></li></ul></li></ul></li></ul><h2 class="heading" style="text-align:left;" id="where-to-find-chris">Where to find Chris? 🌎</h2><ul><li><p class="paragraph" style="text-align:left;">Webinar: Modern Threat Modeling: Business vs. Technical Perspectives, July 25 @ 1 PM Eastern; <a class="link" href="https://www.linkedin.com/events/7211825043473862656/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-58-secure-and-private-by-design-converge-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">register here</a>.</p></li><li><p class="paragraph" style="text-align:left;">InfoSec World, Sept 23-25, 2024</p><ul><li><p class="paragraph" style="text-align:left;">The Modern Application Security Rocket Ship — Time/date TBD</p></li><li><p class="paragraph" style="text-align:left;">The Paradox of Secure and Private By Design — Time/date TBD</p></li><li><p class="paragraph" style="text-align:left;">Workshop: Threat Modeling Championship: Breaker vs. Builder — Time/date TBD</p></li></ul></li></ul><p class="paragraph" style="text-align:left;">🤔<i> Have questions, comments, or feedback? I&#39;d love to </i><span style="text-decoration:underline;"><i><b><a class="link" href="mailto:chris@kerr.ventures?ref=ReasonableAppSec" target="_blank" rel="noopener noreferrer nofollow">hear</a></b></i></span><i> from you!</i></p><p class="paragraph" style="text-align:start;">🔥<i> Reasonable AppSec is brought to you by </i><span style="text-decoration:underline;"><i><b><a class="link" href="https://kerr.ventures?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-58-secure-and-private-by-design-converge-with-threat-modeling-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Kerr Ventures</a></b></i></span><i>.</i></p><p class="paragraph" style="text-align:start;">🤝<i> Want to partner with Reasonable AppSec? Reach out, and let’s chat.</i></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=202e5cb1-fc09-442a-b481-39658efaa929&utm_medium=post_rss&utm_source=reasonable_application_security">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Reasonable 🔐AppSec #57 - Secure by Design at Scale, Five Security Articles, and Podcast Corner</title>
  <description>A review of application security happenings and industry news from Chris Romeo.</description>
  <link>https://appsec.beehiiv.com/p/reasonable-appsec-57-secure-design-scale-five-security-articles-podcast-corner</link>
  <guid isPermaLink="true">https://appsec.beehiiv.com/p/reasonable-appsec-57-secure-design-scale-five-security-articles-podcast-corner</guid>
  <pubDate>Mon, 24 Jun 2024 16:00:00 +0000</pubDate>
  <atom:published>2024-06-24T16:00:00Z</atom:published>
    <dc:creator>Chris Romeo</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><b>Hey there,</b></p><p class="paragraph" style="text-align:left;">In this week’s issue, please enjoy the following:</p><ul><li><p class="paragraph" style="text-align:left;">Five security articles 📰 that are worth YOUR time</p></li><li><p class="paragraph" style="text-align:left;">Featured focus: Secure by Design at Scale</p></li><li><p class="paragraph" style="text-align:left;">Application Security Podcast 🎙️Corner</p></li><li><p class="paragraph" style="text-align:left;">Where to find Chris? 🌎</p></li></ul><h2 class="heading" style="text-align:left;" id="five-security-articles-that-are-wor">Five Security Articles 📰 that Are Worth YOUR Time</h2><ol start="1"><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://securelist.com/trusted-relationship-attack/112731/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-57-secure-by-design-at-scale-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Trusted relationship attacks: trust, but verify</a> — Trusted relationship attacks exploit connections between organizations and their service providers, allowing attackers to infiltrate less-protected networks of small or medium-sized service providers and use legitimate credentials to access the target organization’s infrastructure. This approach lets attackers carry out large-scale, often undetected cyberattacks, leveraging vulnerabilities, compromised credentials, and sophisticated phishing methods. <b>[</b><span style="background-color:#FFFFFF;"><b>Side channel attacks will become more prevalent as we continue to invest in building up our defenses attached to the front door.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://codific.com/owasp-samm-benchmark-data/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-57-secure-by-design-at-scale-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">OWASP SAMM Benchmark Data</a> — The OWASP SAMM Benchmark Data provides insights into the average scores of various business functions within the Software Assurance Maturity Model (SAMM) across different organizations. The report highlights key findings, such as the highest and lowest-scoring security activities, emphasizing the importance of real-world data for guiding improvements in software security practices. <b>[</b><span style="background-color:#FFFFFF;"><b>SAMM benchmark is the open source answer to what has previously been a high-priced, follow-the-hed pay-to-play space. SAMM needs more data to achieve this goal — the data can be anonymous.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://devici.com/resources/blog/introducing-design-static-application-security-testing-dsast-with-devici-code-genius?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-57-secure-by-design-at-scale-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Introducing Design Static Application Security Testing (DSAST) with Devici Code Genius</a> — Devici Code Genius introduces Design Static Application Security Testing (DSAST), a novel approach to security testing that generates threat models from existing code, enhancing security and reducing development time. This method scans code to extract design information, automating threat model creation and allowing developers to address security issues efficiently. <b>[</b><span style="background-color:#FFFFFF;"><b> I’m fond of this one. </b></span>😂<b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.propublica.org/article/microsoft-solarwinds-golden-saml-data-breach-russian-hackers?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-57-secure-by-design-at-scale-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Microsoft Chose Profit Over Security and Left U.S. Government Vulnerable to Russian Hack, Whistleblower Says</a> — Microsoft allegedly ignored warnings about a critical security flaw in their software to avoid jeopardizing government contracts. Russian hackers later exploited this flaw in the SolarWinds attack, allowing access to sensitive data from multiple U.S. federal agencies. <b>[</b><span style="background-color:#FFFFFF;"><b>I’m struggling with this one, as big companies have thousands of bugs they are attempting to triage at any given time. Expecting perfection seems like a setup for failure. It stinks that this flaw was used for SolarWinds access, but it seems like a stretch to say they chose profit over security. They are a for-profit company, though, by the way.</b></span><b>]</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thenewstack.io/guide-to-kubernetes-security-posture-management-kspm/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-57-secure-by-design-at-scale-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Guide to Kubernetes Security Posture Management (KSPM)</a><a class="link" href="https://cloud.google.com/blog/transform/to-securely-build-ai-on-google-cloud-follow-these-best-practices-infographic?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-57-secure-by-design-at-scale-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow"> </a> — Kubernetes Security Posture Management (KSPM) emphasizes the importance of assessing and managing the security posture of Kubernetes clusters to protect against common attack vectors. It provides a comprehensive guide on hardening clusters, incident response, and maintaining a defense-in-depth strategy for robust security. <b>[</b><span style="background-color:#FFFFFF;"><b>Ahhh, yes, another PM category of tooling. When will it end?</b></span><b>]</b></p></li></ol><h2 class="heading" style="text-align:left;" id="featured-focus-blah">Featured focus: Secure by Design at Scale</h2><p class="paragraph" style="text-align:left;">Secure by design is a hot topic—so hot, in fact, that CISA wrote a whole pledge and held a signing ceremony 🤮 at RSA. I wish I could say that a pledge would move the industry forward, but perhaps it would be a tiny step. </p><p class="paragraph" style="text-align:left;">When we think about scaling anything, we must consider how to make the concept work for five developers and five thousand. Scaling secure by design is in the same category. </p><p class="paragraph" style="text-align:left;">Secure-by-design principles are challenging to implement at scale because they require that the security team build a collection of shared security services that can be incorporated into all applications. These shared security services include multi-factor authentication, SAML/OIDC/SSO, session management, attribute-based access control (ABAC), and input validation/output encoding. </p><p class="paragraph" style="text-align:left;">These services are complex to implement but even more complex to create in a way developers can use. Shared security services aim to simplify the implementation and make it less time-consuming than a developer building something from scratch. This is the essence of paved roads that everyone talks about—provide paved roads that are easier for developers to drive on than if they had to build their own roads. Implementing secure-by-design at scale means building paved roads as shared security services developers can easily consume.</p><p class="paragraph" style="text-align:left;">Platform engineering should work toward automating as much of the application and product security tool suites as possible. Even more importantly, the platform should invest heavily in improving the fidelity of tool results to ensure that developers are not slowed down by the noise the tool suites generate. Hyperfocus on the five most critical items developers must deal with to deploy a feature that respects security and privacy.</p><p class="paragraph" style="text-align:left;">Secure by design is scalable, but unlocking scalability requires an investment in building the pieces that make it easy for developers. That is the key — ease of use; make security easier than not doing security.</p><h2 class="heading" style="text-align:left;" id="podcast-corner">Podcast 🎙️ Corner</h2><p class="paragraph" style="text-align:left;">I love making podcasts. In Podcast Corner, you get a single place to see what I’ve put out this week. Sometimes, they are my podcasts. Other times, they are podcasts that have caught my attention.</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://appsec.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-57-secure-by-design-at-scale-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Application Security Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">David Quisenberry -- Building Security People and Programs (<a class="link" href="https://www.buzzsprout.com/1730684/15267144?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-57-secure-by-design-at-scale-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/G0rdTOvzFnU?si=5CIu727EpBFLe1hv&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-57-secure-by-design-at-scale-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">With guest David Quisenberry, we discuss his security journey, building AppSec programs in small to mid-sized companies, and the importance of data-driven decision-making.</p></li><li><p class="paragraph" style="text-align:left;">The conversation also covers the value of mentoring, trust with engineering teams, mental health, and community in the industry while sharing personal stories highlighting the importance of relationships and life balance.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitytable.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-57-secure-by-design-at-scale-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Security Table</a></p><ul><li><p class="paragraph" style="text-align:left;">AppSec Resolutions (<a class="link" href="https://www.buzzsprout.com/2094080/14275063?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-57-secure-by-design-at-scale-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>; <a class="link" href="https://youtu.be/lh532zWuYr4?si=f9SsI90fseFoKUCq&utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-57-secure-by-design-at-scale-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">YouTube</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Chris, Izar, and Matt answer fan mail, make fun predictions for 2024, discuss their cybersecurity resolutions, and call global listeners to action. They highlight the podcast&#39;s reach and explain topics like large language models (LLMs), Quantum LLMs, and Software Bill of Materials (SBOM).</p></li><li><p class="paragraph" style="text-align:left;">They emphasize the importance of teaching secure coding from the high school level and share their passion for making cybersecurity more accessible, practical, and effective through critical discussions and innovative ideas.</p></li></ul></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://threatmodel.buzzsprout.com/?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-57-secure-by-design-at-scale-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Threat Modeling Podcast</a></p><ul><li><p class="paragraph" style="text-align:left;">A Comprehensive Threat Modeling Strategy (<a class="link" href="https://www.buzzsprout.com/2152378/13366767?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-57-secure-by-design-at-scale-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Audio only</a>)</p><ul><li><p class="paragraph" style="text-align:left;">Make threat modeling holistic and straightforward, starting after the high-level design phase and continuously revisiting the model throughout a product&#39;s lifecycle. Concentrate on domain-specific problems and use automated approaches for domain-agnostic issues.</p></li><li><p class="paragraph" style="text-align:left;">Special thanks to Iswarya Subramanian Balachandar, Kuldeep Kumar, Abdoulkader (Abdo) Dirieh, Rob van der Veer, and Tony Turner for their feedback on this episode.</p></li></ul></li></ul></li></ul><h2 class="heading" style="text-align:left;" id="where-to-find-chris">Where to find Chris? 🌎</h2><ul><li><p class="paragraph" style="text-align:left;">Webinar: Modern Threat Modeling: Business vs. Technical Perspectives, with Sarah-Jane Madden and Izar Tarandach, hosted by yours truly. Stay tuned for a registration link. </p></li><li><p class="paragraph" style="text-align:left;">InfoSec World, Sept 23-25, 2024</p><ul><li><p class="paragraph" style="text-align:left;">The Modern Application Security Rocket Ship — Time/date TBD</p></li><li><p class="paragraph" style="text-align:left;">The Paradox of Secure and Private By Design — Time/date TBD</p></li><li><p class="paragraph" style="text-align:left;">Workshop: Threat Modeling Championship: Breaker vs. Builder — Time/date TBD</p></li></ul></li></ul><p class="paragraph" style="text-align:left;">🤔<i> Have questions, comments, or feedback? I&#39;d love to </i><span style="text-decoration:underline;"><i><b><a class="link" href="mailto:chris@kerr.ventures?ref=ReasonableAppSec" target="_blank" rel="noopener noreferrer nofollow">hear</a></b></i></span><i> from you!</i></p><p class="paragraph" style="text-align:start;">🔥<i> Reasonable AppSec is brought to you by </i><span style="text-decoration:underline;"><i><b><a class="link" href="https://kerr.ventures?utm_source=appsec.beehiiv.com&utm_medium=newsletter&utm_campaign=reasonable-appsec-57-secure-by-design-at-scale-five-security-articles-and-podcast-corner" target="_blank" rel="noopener noreferrer nofollow">Kerr Ventures</a></b></i></span><i>.</i></p><p class="paragraph" style="text-align:start;">🤝<i> Want to partner with Reasonable AppSec? Reach out, and let’s chat.</i></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=625ea950-10c2-4ffc-b132-688b7df6ab1e&utm_medium=post_rss&utm_source=reasonable_application_security">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

  </channel>
</rss>
