Christian Wenz: ASP .NET Core Security - Episode 233

Christian Wenz: ASP .NET Core Security - Episode 233

Christian Wenz works as a consultant, trainer, and author with a focus on web technologies and is the author or co-author of over 100 computer books. He regularly contributes to various IT magazines and speaks at conferences around the globe. Christian holds a "Diplom" (the German equivalent of a master's degree) in Computer Sciences, and one in Business Informatics. In his day job, he is one of the founders of the web agency Arrabiata Solutions (http://www.arrabiata.com/) with offices in Munich, Germany, and in London, UK. He also frequently works with development teams to make their applications better performing, more secure, and more reliable.

Topics of Discussion:

[2:51] Has Christian really written over 100 computer books? Christian talks about the books and the high points of technology that he has worked in.

[7:16] What is the OWASP (Open Web Application Security Project) Top 10 list?

[10:33] You always have to be aware that something may go wrong, and have a security mindset.

[12:05] Again and again, make sure that you understand the fundamentals of web app security, because eventually, you will make a mistake in your code.

[12:30] What is insecure design?

[13:43] Christian talks about the enumeration scheme CWE: common weakness enumeration, which basically assigns a number to each risk or attack.

[17:00] How should people be logging into their web sessions now with .NET7?

[18:31] The major mistake you can make these days is to write your own authentication mechanism.

[23:57] What is Christian's favorite mechanism today for securing HTTP web services?

[31:05] What are some of the tools Christian always reaches for, and how do we differentiate between static auditing and dynamically auditing an application?

Mentioned in this Episode:

Clear Measure Way

Architect Forum

Software Engineer Forum

Programming with Palermo — New Video Podcast! Email us programming@palermo.network

Clear Measure, Inc. (Sponsor)

.NET DevOps for Azure: A Developer's Guide to DevOps Architecture the Right Way, by Jeffrey Palermo — Available on Amazon!

Jeffrey Palermo's Twitter — Follow to stay informed about future events!

Architect Tips — Video podcast!

Azure DevOps

Christian Microsoft Profile

ASP.NET Core Security

Christian's Books on Amazon

OWASP

Identity Server

Dependabot

Security Code Scan

Configuring Code Scanning for a Repository

Want to Learn More?

Visit AzureDevOps.Show for show notes and additional episodes.

Episoder(386)

Damian Brady: GitHub Copilot - Episode 258

Damian Brady: GitHub Copilot - Episode 258

Damian Brady is a Developer Advocate Manager at GitHub. He's a developer, speaker, and author specializing in DevOps, MLOps, developer process, and software architecture. Formerly a Cloud Advocate at ...

14 Aug 202349min

Glenn Burnside: Managing Developers - Episode 257

Glenn Burnside: Managing Developers - Episode 257

Glenn Burnside is the Principal Engineer at Skimmer. For 11 years, he was the Executive Vice President at Headspring until they were acquired by Accenture. Before that, he held a number of development...

7 Aug 202334min

Dennis van der Stelt: Microservices and Distributed Systems - Episode 256

Dennis van der Stelt: Microservices and Distributed Systems - Episode 256

Dennis van der Stelt is a Software Architect who loves building distributed systems and the challenges they bring. To be better than the day before, he continuously searches for new ways to improve hi...

31 Jul 202338min

Giorgi Dalakishvili: Beyond Relational Data with Entity Framework - Episode 255

Giorgi Dalakishvili: Beyond Relational Data with Entity Framework - Episode 255

Giorgi Dalakishvili is a software developer with more than a decade of experience. He works mainly with C#, ASP.NET MVC/ASP.NET Core, REST, WCF, Xamarin, Android, iOS, Entity Framework, Azure, SQL Ser...

24 Jul 202327min

Mitchel Sellers: Architecting .NET MAUI - Episode 254

Mitchel Sellers: Architecting .NET MAUI - Episode 254

Mitchel Sellers is globally known as a 15-time Microsoft MVP, an ASPInsider, a DNN MVP, an MCP (Microsoft .NET, ASP.NET, and SQL Server), and CEO of IowaComputerGurus Inc. Sellers has a deep understan...

17 Jul 202338min

Mike Brind on Razor Pages in Action - Episode 253

Mike Brind on Razor Pages in Action - Episode 253

Mike Brind spent the first 20 years of his working life in a series of successful sales and marketing roles, towards the end of which he was introduced to HTML and databases. A dormant inner geek took...

10 Jul 202328min

Brian Lagunas on Establishing Quality - Episode 252

Brian Lagunas on Establishing Quality - Episode 252

Brian Lagunas is a Microsoft MVP, a Microsoft Patterns & Practices Champion, leader of the Boise .Net Developers User Group (NETDUG), board member of Boise Code Camp, speaker, trainer, and Pluralsight...

3 Jul 202338min

Kevin LaBranche: Leading teams through DevOps - Episode 251

Kevin LaBranche: Leading teams through DevOps - Episode 251

Kevin is a software developer who finds great joy in teaching and learning from others. He's been honing my craft for over two and a half decades. If he's not in code, he's near it. Kevin is often wor...

26 Jun 202337min

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
aftenpodden-usa
forklart
popradet
stopp-verden
det-store-bildet
bt-dokumentar-2
rss-gukild-johaug
dine-penger-pengeradet
nokon-ma-ga
lydartikler-fra-aftenposten
fotballpodden-2
hanna-de-heldige
frokostshowet-pa-p5
rss-penger-polser-og-politikk
aftenbla-bla
e24-podden
rss-dannet-uten-piano
rss-ness