What security teams need to understand about developers

What security teams need to understand about developers

NightVision offers web and API security testing tools built to integrate with developers’ established workflows. NightVision identifies issues by precise area(s) of code, so devs don’t have to chase down and validate vulnerability reports, a process that eats up precious engineering resources. Get started with their docs.

Connect with Kinnaird on LinkedIn.

Stack Overflow user Cecil Curry earned a Populist badge with their exceptionally thoughtful answer to In Python how can one tell if a module comes from a C extension?.

Some great excerpts from this episode:

“From the program side, I would say if you're running a security program or you're starting from day one, there's a danger with security people and being the security person who's out of touch or doesn't know what the life of a developer is like. And you don't want to be that person. And that's not how you have actual business impact, right? So you got to embed with teams, threat model, and then do some preventative security testing, right? Testing things before it gets into production, not just relying on having a bug bounty program.”

“With code scanning, you're looking for potentially insecure patterns in the code, but with dynamic testing, you're actually testing the live application. So we're sending HTTP traffic to the application, sending malicious payloads in forms or in query parameters, et cetera, to try to elicit a response or to send something to an attacker controlled server. And so using this, we're able to. Not just have theoretical vulnerabilities, but exploitable vulnerabilities. I mean, how many times have you looked at something in GitHub security alerts and thought, yeah, that's not real. That's not exploitable. Right. So we're trying to avoid that and have higher quality touch points with developers. So when they look at something, they say, okay, that's exploitable. You showed me how. And you traced it back to code.”

See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(983)

AI, JD, and other letters of the law

AI, JD, and other letters of the law

Ryan chats with Kevin Frazier, director of the AI Innovation and Law program at the University of Texas School of Law, about the legal and social impacts of data centers, the realities of workforce di...

15 Sep 38min

AI cybersecurity is a cat and mouse game

AI cybersecurity is a cat and mouse game

Ryan chats with Sam Curry, CSO at Zscaler, about where human intelligence sits in the new security landscape with AI, why shifting security protections closer to applications helps limit probes for vu...

11 Sep 27min

Java’s age is its AI superpower

Java’s age is its AI superpower

SPONSORED BY IBMRyan welcomes Markus Eisele to the program to talk about why your coding agent should be writing Java. They talk about why the long history of Java both makes for a stable language and...

9 Sep 35min

Scaling your money safely with AI

Scaling your money safely with AI

Episode notes: This episode with Paypal’s CTO Srini Venkatesan was recorded at the Ai4 conference. Listen to our other Ai4 conversation with Greg Jennings, VP of Engineering for AI Products at Anacond...

8 Sep 28min

How to build a secure-by-default AI coding agent

How to build a secure-by-default AI coding agent

Ryan chats with Greg Jennings, VP of Engineering for AI Products at Anaconda, about what it takes to build a secure-by-default AI coding agent, why prompts shouldn't be treated as strict security guar...

4 Sep 32min

The good ol’ days of building Java

The good ol’ days of building Java

Ryan sits down with Tim Lindholm, an early contributor to the Java language at Sun Microsystems, to chat about what it was like building one of the most popular programming languages ever at its incep...

1 Sep 30min

When you keep AI Lean, you keep AI correct

When you keep AI Lean, you keep AI correct

Ryan chats with Leo de Moura, Senior Principal Applied Scientist at AWS and the creator of the Lean language, about proving correctness in AI agents with the Lean language, how automated reasoning com...

28 Aug 25min

Inside LinkedIn's cognitive memory agent for agentic personalization

Inside LinkedIn's cognitive memory agent for agentic personalization

Ryan is joined by Praveen Bodigutla, Principal AI Researcher at LinkedIn, to chat about the four-layer memory system his team built to give LinkedIn's hiring assistant a persistent, personalized state...

25 Aug 32min

Populärt inom Business & ekonomi

framgangspodden
rss-jossan-nina
rss-borsens-finest
varvet
24fragor
uppgang-och-fall
avanzapodden
badfluence
rss-inga-dumma-fragor-om-pengar
svd-tech-brief
bathina-en-podcast
lastbilspodden
fill-or-kill
rss-dagen-med-di
rikatillsammans-om-privatekonomi-rikedom-i-livet
tabberaset
affarsvarlden
rss-hos-psykologen
borsmorgon
rss-kort-lang-analyspodden-fran-di