Christian Wenz: ASP .NET Core Security - Episode 233

Christian Wenz: ASP .NET Core Security - Episode 233

Christian Wenz works as a consultant, trainer, and author with a focus on web technologies and is the author or co-author of over 100 computer books. He regularly contributes to various IT magazines and speaks at conferences around the globe. Christian holds a "Diplom" (the German equivalent of a master's degree) in Computer Sciences, and one in Business Informatics. In his day job, he is one of the founders of the web agency Arrabiata Solutions (http://www.arrabiata.com/) with offices in Munich, Germany, and in London, UK. He also frequently works with development teams to make their applications better performing, more secure, and more reliable.

Topics of Discussion:

[2:51] Has Christian really written over 100 computer books? Christian talks about the books and the high points of technology that he has worked in.

[7:16] What is the OWASP (Open Web Application Security Project) Top 10 list?

[10:33] You always have to be aware that something may go wrong, and have a security mindset.

[12:05] Again and again, make sure that you understand the fundamentals of web app security, because eventually, you will make a mistake in your code.

[12:30] What is insecure design?

[13:43] Christian talks about the enumeration scheme CWE: common weakness enumeration, which basically assigns a number to each risk or attack.

[17:00] How should people be logging into their web sessions now with .NET7?

[18:31] The major mistake you can make these days is to write your own authentication mechanism.

[23:57] What is Christian's favorite mechanism today for securing HTTP web services?

[31:05] What are some of the tools Christian always reaches for, and how do we differentiate between static auditing and dynamically auditing an application?

Mentioned in this Episode:

Clear Measure Way

Architect Forum

Software Engineer Forum

Programming with Palermo — New Video Podcast! Email us programming@palermo.network

Clear Measure, Inc. (Sponsor)

.NET DevOps for Azure: A Developer's Guide to DevOps Architecture the Right Way, by Jeffrey Palermo — Available on Amazon!

Jeffrey Palermo's Twitter — Follow to stay informed about future events!

Architect Tips — Video podcast!

Azure DevOps

Christian Microsoft Profile

ASP.NET Core Security

Christian's Books on Amazon

OWASP

Identity Server

Dependabot

Security Code Scan

Configuring Code Scanning for a Repository

Want to Learn More?

Visit AzureDevOps.Show for show notes and additional episodes.

Episoder(386)

Kevin Kirkus on Automated Testing Embedded Code - Episode 186

Kevin Kirkus on Automated Testing Embedded Code - Episode 186

Kevin Kirkus is a Principal Engineer at Intel. He has been there since 1999, designing, building, and testing Intel processors, both the chip and the code that runs the chips. Kevin is a Post-Silicon ...

28 Mar 202247min

Sam Nasr on Azure AI & ML - Episode 185

Sam Nasr on Azure AI & ML - Episode 185

This week, Sam Nasr returns to the show. Sam is an IT Consultant specializing in .Net, SQL Server, and Azure. He is a Sr. Software Engineer focused on the Microsoft stack of technologies including .Ne...

21 Mar 202235min

Chris Tacke on .NET 6 IoT on Linux - Episode 184

Chris Tacke on .NET 6 IoT on Linux - Episode 184

Chris Tacke is an industry leader in managed application development for industrial process control, medical, telematics, and just about any other embedded industry. Chris specializes in Windows CE an...

14 Mar 202239min

Henry Quillin on Prepping for a Career as a Software Engineer - Episode 183

Henry Quillin on Prepping for a Career as a Software Engineer - Episode 183

Henry Quillin is a high school senior interested in software development, entrepreneurship, and blockchain/crypto. He has completed several internships and other contracts and recently earned the rank...

7 Mar 202238min

Chris Patterson on Messaging systems with MassTransit - Episode 182

Chris Patterson on Messaging systems with MassTransit - Episode 182

Chris Patterson is a Principal Architect at McKesson, the oldest and largest healthcare company in the nation. He is responsible for architecture supporting applications and services that enable McKes...

28 Feb 202243min

Mohamed Kabiruddin on Migrating to Azure SQL - Episode 181

Mohamed Kabiruddin on Migrating to Azure SQL - Episode 181

Mohamed Kabiruddin is a Senior Program Manager in the Azure SQL Product Team and is currently located in Redmond, Washington. Prior to joining the Product Team, he was a Cloud Solution Architect worki...

21 Feb 202232min

Shawn Wildermuth on Next-gen web services  - Episode 180

Shawn Wildermuth on Next-gen web services - Episode 180

Shawn Wildermuth has been tinkering with computers and software since he got a VIC-20 back in the early '80s. He has been a Microsoft MVP, Pluralsight Author, and filmmaker. You can reach him at his b...

14 Feb 202237min

Shaun Walker on Blazor and Oqtane - Episode 179

Shaun Walker on Blazor and Oqtane - Episode 179

Jeffrey welcomes Shaun Walker, creator of Oqtane and also DotNetNuke web application frameworks, which have earned the recognition of being amongst the most pioneering and widely-adopted open-source p...

7 Feb 202241min

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
aftenpodden-usa
forklart
stopp-verden
popradet
det-store-bildet
dine-penger-pengeradet
rss-gukild-johaug
bt-dokumentar-2
lydartikler-fra-aftenposten
hanna-de-heldige
fotballpodden-2
nokon-ma-ga
e24-podden
frokostshowet-pa-p5
aftenbla-bla
rss-ness
rss-penger-polser-og-politikk
rss-dannet-uten-piano