
Debating the Priority and Value of Memory Safety
Chris, Izar, and Matt tackle the first point of the recent White House report, "Back to the Building Blocks: a Path toward Secure and Measurable Software." They discuss the importance of memory safety...
12 Maalis 202434min

Selling Fear, Uncertainty, and Doubt
Matt, Izar, and Chris discuss the impact of fear, uncertainty, and doubt (FUD) within cybersecurity. FUD is a double-edged sword - while it may drive awareness among consumers, it also leads to decisi...
27 Helmi 202441min

Prioritizing AppSec: A Conversation Between a VP of Eng, a Product Manager, and a Security "Pro"
Prompted by fan mail, Chris, Izar, and Matt engage in a role-playing scenario as a VP of engineering, a security person, and a product manager. They explore some of the challenges and competing perspe...
20 Helmi 202437min

Villainy, Open Source, and the Software Supply Chain
Matt, Izar, and Chris have a lively discussion about how security experts perceive open-source software. Referencing a post that described open source as a 'hive of scum and villainy,' the team dissec...
13 Helmi 202432min

Adam Shostack -- Thinking like an Attacker and Risk Management in the Capabilities
Threat modeling expert Adam Shostack joins Chris, Izar, and Matt in this episode of the Security Table. They look into threat actors and their place in threat modeling. There's a lively discussion on ...
6 Helmi 202446min

Bug Bounty Theater and Responsible Bug Bounty
Izar, Matt, and Chris discuss the effectiveness of bug bounty programs and delve into topics such as scoping challenges, the ethical considerations of selling exploits, and whether it is all just bug ...
30 Tammi 202427min

Threat Modeling Capabilities
This week around the Security Table Matt, Izar and Chris discuss the recently-published Threat Modeling Capabilities document. They explore how capabilities serve as measurable goals that organization...
23 Tammi 202441min

Open Source Puppies and Beer
Chris, Izar, and Matt address the complexities of open-source component usage, vulnerability patches, civic responsibility, and licensing issues in this Security Table roundtable. Sparked by a LinkedI...
16 Tammi 202440min