Christian Wenz: ASP .NET Core Security - Episode 233

Christian Wenz: ASP .NET Core Security - Episode 233

Christian Wenz works as a consultant, trainer, and author with a focus on web technologies and is the author or co-author of over 100 computer books. He regularly contributes to various IT magazines and speaks at conferences around the globe. Christian holds a "Diplom" (the German equivalent of a master's degree) in Computer Sciences, and one in Business Informatics. In his day job, he is one of the founders of the web agency Arrabiata Solutions (http://www.arrabiata.com/) with offices in Munich, Germany, and in London, UK. He also frequently works with development teams to make their applications better performing, more secure, and more reliable.

Topics of Discussion:

[2:51] Has Christian really written over 100 computer books? Christian talks about the books and the high points of technology that he has worked in.

[7:16] What is the OWASP (Open Web Application Security Project) Top 10 list?

[10:33] You always have to be aware that something may go wrong, and have a security mindset.

[12:05] Again and again, make sure that you understand the fundamentals of web app security, because eventually, you will make a mistake in your code.

[12:30] What is insecure design?

[13:43] Christian talks about the enumeration scheme CWE: common weakness enumeration, which basically assigns a number to each risk or attack.

[17:00] How should people be logging into their web sessions now with .NET7?

[18:31] The major mistake you can make these days is to write your own authentication mechanism.

[23:57] What is Christian's favorite mechanism today for securing HTTP web services?

[31:05] What are some of the tools Christian always reaches for, and how do we differentiate between static auditing and dynamically auditing an application?

Mentioned in this Episode:

Clear Measure Way

Architect Forum

Software Engineer Forum

Programming with Palermo — New Video Podcast! Email us programming@palermo.network

Clear Measure, Inc. (Sponsor)

.NET DevOps for Azure: A Developer's Guide to DevOps Architecture the Right Way, by Jeffrey Palermo — Available on Amazon!

Jeffrey Palermo's Twitter — Follow to stay informed about future events!

Architect Tips — Video podcast!

Azure DevOps

Christian Microsoft Profile

ASP.NET Core Security

Christian's Books on Amazon

OWASP

Identity Server

Dependabot

Security Code Scan

Configuring Code Scanning for a Repository

Want to Learn More?

Visit AzureDevOps.Show for show notes and additional episodes.

Avsnitt(393)

Bob Ward: SQL Server - Episode 321

Bob Ward: SQL Server - Episode 321

Bob Ward is a Principal Architect for the Microsoft Azure Data team, which owns the development for Microsoft SQL Edge to Cloud. Bob has worked for Microsoft for 30-plus years on every version of SQL ...

28 Okt 202440min

Jeff Wouters: PowerShell Programming - Episode 320

Jeff Wouters: PowerShell Programming - Episode 320

Jeff was born and raised in The Netherlands and is an IT geek with a passion for automation. At the young age of 6, he had his very first computer and started developing his own Pacman to learn Batch ...

21 Okt 202433min

Database Hygiene: Grant Fritchey - Episode 319

Database Hygiene: Grant Fritchey - Episode 319

Grant Fritchey has over thirty years of experience in IT, specializing in development and database administration. He works for Red Gate Software as a Product Advocate and writes articles for SQL Serv...

14 Okt 202437min

Programming Windows: Dave Plummer - Episode 318

Programming Windows: Dave Plummer - Episode 318

Dave was a developer or development manager on each of the major operating systems from MS-DOS 6.2 through Server 2003 while at Microsoft from 1993 to 2003. He's worked on MS-DOS products, OLE objec...

7 Okt 202429min

Jeff Sutherland: The History of Agile - Episode 317

Jeff Sutherland: The History of Agile - Episode 317

Jeff is the co-creator of Scrum and a leading expert on how the framework has evolved to meet the needs of today's business. The framework he developed in 1993 and formalized in 1995 with Ken Schwaber...

30 Sep 202438min

Ryan Riley: Leading a Software Engineering Team - Episode 316

Ryan Riley: Leading a Software Engineering Team - Episode 316

Ryan Riley is a Principal Software Engineer at Wise Rock in Houston, TX. He enjoys learning and collaborating on simple, creative solutions to problems, and implementing those solutions with others th...

23 Sep 202439min

Erik Darling: Database Technical Debt - Episode 315

Erik Darling: Database Technical Debt - Episode 315

Erik Darling makes your database faster in exchange for money. He is a DBA, developer, and architect with a track record of tackling even the most challenging technical issues. He runs a SQL Server Co...

16 Sep 202446min

Kent Beck: Tidy First - Episode 314

Kent Beck: Tidy First - Episode 314

Kent Beck is an original signer of the Agile Manifesto, author of the Extreme Programming book series, rediscoverer of Test-Driven Development, and an inspiring Keynote Speaker. I read his TDD book 20...

9 Sep 202439min

Populärt inom Politik & nyheter

aftonbladet-krim
svenska-fall
rss-krimstad
p3-krim
fordomspodden
spar
flashback-forever
rss-sanning-konsekvens
rss-expressen-dok
rss-vad-fan-hande
aftonbladet-daily
motiv
grans
rss-frandfors-horna
rss-krimreportrarna
rss-flodet
krimmagasinet
blenda-2
rss-aftonbladet-krim
olyckan-inifran