
The DevSecOps Experiment
DJ Schleen talks about his upcoming 15 part video series, "The DevSecOps Experiment", where he will walk through the setup of a software supply chain, including building in security during every step ...
10 Des 201814min

Open Source Vulnerabilities - Who is Ultimately Responsible
In this broadcast, I speak with Chris Roberts and Derek Weeks about lines of responsibility and npm package highjacking in light of the event-stream vulnerability announcement last week. The announce...
3 Des 201846min

event-stream: Analysis of a Compromised npm Package
Once again, the pattern of taking over a known package and modifying it with malicious intent has happened. In this case, it's with the event-stream module in the npm repository. In this broadcast I s...
27 Nov 201821min

Spy vs Spy in Application Security: Harvesting Adversaries
"The guy who wrote wifi software with SSID never imagined that someone could use that SSID to transmit data by writing two smaller applications to leverage it. We are constantly going to be in this [t...
2 Nov 201816min

Moving from Projects to Products w/ Mik Kersten
"If you look inside a large enterprise IT organization, they have this very bizarre and broken layer that's completely separating the way that business thinks in terms of products, budgets and costs, ...
31 Okt 201839min

The Journey to Open Source at Capital One w/ Tapabrata "Topo" Pal
Why would you allow open source usage in your company. What are the compelling reasons to take the risk. In this discussion, I talk with Topo Pal and Derek Weeks about the industry perception of open ...
29 Okt 201819min

The Future of Software and DevOps / with Sacha Labourey
"The compensation, the incentives that people have are very much anchored in short term objectives that do not take into account the vision for the bigger transformations that are happening within th...
17 Sep 201823min

How to Build Chapter Engagement at OWASP
While at 2018 AppSec EU, I spoke with Sam Stepanyan and Grigorios Fragkos, chapter leaders of one of OWASP's largest chapters. The conversation centered around what does it take to grow a community, w...
17 Sep 201816min



















