What security teams need to understand about developers

What security teams need to understand about developers

NightVision offers web and API security testing tools built to integrate with developers’ established workflows. NightVision identifies issues by precise area(s) of code, so devs don’t have to chase down and validate vulnerability reports, a process that eats up precious engineering resources. Get started with their docs.

Connect with Kinnaird on LinkedIn.

Stack Overflow user Cecil Curry earned a Populist badge with their exceptionally thoughtful answer to In Python how can one tell if a module comes from a C extension?.

Some great excerpts from this episode:

“From the program side, I would say if you're running a security program or you're starting from day one, there's a danger with security people and being the security person who's out of touch or doesn't know what the life of a developer is like. And you don't want to be that person. And that's not how you have actual business impact, right? So you got to embed with teams, threat model, and then do some preventative security testing, right? Testing things before it gets into production, not just relying on having a bug bounty program.”

“With code scanning, you're looking for potentially insecure patterns in the code, but with dynamic testing, you're actually testing the live application. So we're sending HTTP traffic to the application, sending malicious payloads in forms or in query parameters, et cetera, to try to elicit a response or to send something to an attacker controlled server. And so using this, we're able to. Not just have theoretical vulnerabilities, but exploitable vulnerabilities. I mean, how many times have you looked at something in GitHub security alerts and thought, yeah, that's not real. That's not exploitable. Right. So we're trying to avoid that and have higher quality touch points with developers. So when they look at something, they say, okay, that's exploitable. You showed me how. And you traced it back to code.”

See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(987)

Professional skepticism is a dev’s best skill

Professional skepticism is a dev’s best skill

Ryan chats with David Burns, Head of Developer Advocacy and Open Source at BrowserStack, about the value of professional skepticism in an AI-driven world, applying test-driven development to agentic e...

25 Sep 28min

Multiplayer AI: Why your team (and its agents) need a group chat

Multiplayer AI: Why your team (and its agents) need a group chat

SPONSORED BY SLACK BY SALESFORCEIn this episode, Ryan chats with the GM of Slack, Rob Seaman, about how their new Code Channels feature is bringing multiplayer AI to your team chats. They discuss how ...

23 Sep 30min

Haters think AI agents can't write GPU code? This'll ROCm

Haters think AI agents can't write GPU code? This'll ROCm

Ryan chats with Anush Elangovan, VP of Software at AMD, about ROCm's open-source unified toolchain for GPUs, how agentic AI is drastically lowering the barrier to entry for low-level hardware programm...

22 Sep 26min

The AI magic words

The AI magic words

Ryan sits down with Tim O'Reilly, founder and CEO at O'Reilly Media, to talk about the role of books as user interfaces to knowledge, the power of "magic words" to extract better outputs from AI, and ...

18 Sep 24min

AI, JD, and other letters of the law

AI, JD, and other letters of the law

Ryan chats with Kevin Frazier, director of the AI Innovation and Law program at the University of Texas School of Law, about the legal and social impacts of data centers, the realities of workforce di...

15 Sep 38min

AI cybersecurity is a cat and mouse game

AI cybersecurity is a cat and mouse game

Ryan chats with Sam Curry, CSO at Zscaler, about where human intelligence sits in the new security landscape with AI, why shifting security protections closer to applications helps limit probes for vu...

11 Sep 27min

Java’s age is its AI superpower

Java’s age is its AI superpower

SPONSORED BY IBMRyan welcomes Markus Eisele to the program to talk about why your coding agent should be writing Java. They talk about why the long history of Java both makes for a stable language and...

9 Sep 35min

Scaling your money safely with AI

Scaling your money safely with AI

Episode notes: This episode with Paypal’s CTO Srini Venkatesan was recorded at the Ai4 conference. Listen to our other Ai4 conversation with Greg Jennings, VP of Engineering for AI Products at Anacond...

8 Sep 28min

Populært innen Business og økonomi

stopp-verden
dine-penger-pengeradet
e24-podden
rss-penger-polser-og-politikk
rss-borsmorgen-okonominyhetene
rss-pa-konto
rss-skravla-gar
pengepodden-2
livet-pa-veien-med-jan-erik-larssen
lederpodden
finansredaksjonen
tid-er-penger-en-podcast-med-peter-warren
stormkast-med-valebrokk-stordalen
rss-orjasater
pengesnakk
morgenkaffen-med-finansavisen
liberal-halvtime
utbytte
okonomiamatorene
rss-markedspuls-2