Christian Wenz: ASP .NET Core Security - Episode 233

Christian Wenz: ASP .NET Core Security - Episode 233

Christian Wenz works as a consultant, trainer, and author with a focus on web technologies and is the author or co-author of over 100 computer books. He regularly contributes to various IT magazines and speaks at conferences around the globe. Christian holds a "Diplom" (the German equivalent of a master's degree) in Computer Sciences, and one in Business Informatics. In his day job, he is one of the founders of the web agency Arrabiata Solutions (http://www.arrabiata.com/) with offices in Munich, Germany, and in London, UK. He also frequently works with development teams to make their applications better performing, more secure, and more reliable.

Topics of Discussion:

[2:51] Has Christian really written over 100 computer books? Christian talks about the books and the high points of technology that he has worked in.

[7:16] What is the OWASP (Open Web Application Security Project) Top 10 list?

[10:33] You always have to be aware that something may go wrong, and have a security mindset.

[12:05] Again and again, make sure that you understand the fundamentals of web app security, because eventually, you will make a mistake in your code.

[12:30] What is insecure design?

[13:43] Christian talks about the enumeration scheme CWE: common weakness enumeration, which basically assigns a number to each risk or attack.

[17:00] How should people be logging into their web sessions now with .NET7?

[18:31] The major mistake you can make these days is to write your own authentication mechanism.

[23:57] What is Christian's favorite mechanism today for securing HTTP web services?

[31:05] What are some of the tools Christian always reaches for, and how do we differentiate between static auditing and dynamically auditing an application?

Mentioned in this Episode:

Clear Measure Way

Architect Forum

Software Engineer Forum

Programming with Palermo — New Video Podcast! Email us programming@palermo.network

Clear Measure, Inc. (Sponsor)

.NET DevOps for Azure: A Developer's Guide to DevOps Architecture the Right Way, by Jeffrey Palermo — Available on Amazon!

Jeffrey Palermo's Twitter — Follow to stay informed about future events!

Architect Tips — Video podcast!

Azure DevOps

Christian Microsoft Profile

ASP.NET Core Security

Christian's Books on Amazon

OWASP

Identity Server

Dependabot

Security Code Scan

Configuring Code Scanning for a Repository

Want to Learn More?

Visit AzureDevOps.Show for show notes and additional episodes.

Jaksot(386)

Donovan Brown is Retiring -  Episode 242

Donovan Brown is Retiring - Episode 242

Donovan Brown is a Partner Program Manager in the Azure CTO Incubations team at Microsoft. The Incubations team focuses on forward-looking development and innovation to facilitate the development of n...

24 Huhti 202345min

Tim Corey: Learning Programming - Episode 241

Tim Corey: Learning Programming - Episode 241

Tim learned software development the hard way, with lots of dead-ends, confusion, and knowledge gaps. He kept thinking, "It shouldn't be this hard!" Now he teaches students how to think and code lik...

17 Huhti 202343min

Bojan Magusic: Azure Security  - Episode 240

Bojan Magusic: Azure Security - Episode 240

Bojan Magusic is a Product Manager on the Customer Acceleration Team and acts as a technology expert for Fortune 500 companies to help them realize the full value of Microsoft Defender for Cloud and i...

10 Huhti 202332min

Thomas Vitale- Kubernetes - Episode 239

Thomas Vitale- Kubernetes - Episode 239

Thomas Vitale is a software engineer and architect specializing in building cloud-native, resilient, and secure enterprise applications. He designs and develops software solutions at Systematic, Denma...

3 Huhti 202337min

Chris Sainty: Blazor in Action - Episode 238

Chris Sainty: Blazor in Action - Episode 238

Chris is a Microsoft MVP, author, and software engineer with over 17 years of experience with ASP.NET. Passionate about sharing his knowledge with the community, he regularly writes both for his own b...

27 Maalis 202341min

Toni Solarin-Sodara: Developer Tools for Test Automation - Episode 237

Toni Solarin-Sodara: Developer Tools for Test Automation - Episode 237

Toni Solarin-Sodara is a Software Engineering Lead at Microsoft. He specializes in developer tooling, working at the client platform layer, and building the runtime libraries and tools that enable shi...

20 Maalis 202342min

Grant Fritchey: SQL Server Performance Tuning - Episode 236

Grant Fritchey: SQL Server Performance Tuning - Episode 236

A Microsoft Data Platform MVP, Grant Fritchey works for Red Gate Software as a Product Advocate. Grant has more than 30 years of experience in the industry as a DBA and developer. Grant is an active p...

13 Maalis 202344min

Christoph Vollmer: Automated Testing Techniques - Episode 235

Christoph Vollmer: Automated Testing Techniques - Episode 235

Christoph Vollmer is an internationally experienced IT Manager with strong experience in software development and team leadership. He has worked for several years as a developer with multiple language...

6 Maalis 202338min

Suosittua kategoriassa Politiikka ja uutiset

aikalisa
tervo-halme
rss-ootsa-kuullut-tasta
ootsa-kuullut-tasta-2
politiikan-puskaradio
viisupodi
rss-vaalirankkurit-podcast
otetaan-yhdet
et-sa-noin-voi-sanoo-esittaa
rss-podme-livebox
io-techin-tekniikkapodcast
linda-maria
rikosmyytit
rss-tasta-on-kyse-ivan-puopolo-verkkouutiset
rss-asiastudio
the-ulkopolitist
rss-uusi-juttu
rss-fi-lainsaadanto-paremmaksi
rss-hyvaa-huomenta-bryssel
rss-50100-podcast