Christian Wenz: ASP .NET Core Security - Episode 233

Christian Wenz: ASP .NET Core Security - Episode 233

Christian Wenz works as a consultant, trainer, and author with a focus on web technologies and is the author or co-author of over 100 computer books. He regularly contributes to various IT magazines and speaks at conferences around the globe. Christian holds a "Diplom" (the German equivalent of a master's degree) in Computer Sciences, and one in Business Informatics. In his day job, he is one of the founders of the web agency Arrabiata Solutions (http://www.arrabiata.com/) with offices in Munich, Germany, and in London, UK. He also frequently works with development teams to make their applications better performing, more secure, and more reliable.

Topics of Discussion:

[2:51] Has Christian really written over 100 computer books? Christian talks about the books and the high points of technology that he has worked in.

[7:16] What is the OWASP (Open Web Application Security Project) Top 10 list?

[10:33] You always have to be aware that something may go wrong, and have a security mindset.

[12:05] Again and again, make sure that you understand the fundamentals of web app security, because eventually, you will make a mistake in your code.

[12:30] What is insecure design?

[13:43] Christian talks about the enumeration scheme CWE: common weakness enumeration, which basically assigns a number to each risk or attack.

[17:00] How should people be logging into their web sessions now with .NET7?

[18:31] The major mistake you can make these days is to write your own authentication mechanism.

[23:57] What is Christian's favorite mechanism today for securing HTTP web services?

[31:05] What are some of the tools Christian always reaches for, and how do we differentiate between static auditing and dynamically auditing an application?

Mentioned in this Episode:

Clear Measure Way

Architect Forum

Software Engineer Forum

Programming with Palermo — New Video Podcast! Email us programming@palermo.network

Clear Measure, Inc. (Sponsor)

.NET DevOps for Azure: A Developer's Guide to DevOps Architecture the Right Way, by Jeffrey Palermo — Available on Amazon!

Jeffrey Palermo's Twitter — Follow to stay informed about future events!

Architect Tips — Video podcast!

Azure DevOps

Christian Microsoft Profile

ASP.NET Core Security

Christian's Books on Amazon

OWASP

Identity Server

Dependabot

Security Code Scan

Configuring Code Scanning for a Repository

Want to Learn More?

Visit AzureDevOps.Show for show notes and additional episodes.

Avsnitt(387)

Mads Torgersen: The Latest in C# - Episode 291

Mads Torgersen: The Latest in C# - Episode 291

Mads is the Lead Designer of the C# language and has been at Microsoft for 18 years. Prior to this, Mads was a professor and contributed to a language starting with J. He was previously on episode 164...

1 Apr 202452min

Mark Miller: Voice User Interface - Episode 290

Mark Miller: Voice User Interface - Episode 290

Mark Miller, is an eight-year C# MVP with strong expertise in decoupled design, plug-in architectures, and great user interfaces. He is the Chief Architect of the IDE Tools division at Developer Expre...

25 Mars 202454min

Richard Lander: Containerization and Linux - Episode 289

Richard Lander: Containerization and Linux - Episode 289

Richard Lander is a Principal Program Manager on the .NET team at Microsoft. He's been with Microsoft since 2000, and working on .NET since 2003! Currently, he's working on runtime features, docker co...

18 Mars 202454min

Rockford Lhotka: Philosophy on Architecture - Episode 288

Rockford Lhotka: Philosophy on Architecture - Episode 288

Rockford Lhotka is VP of Strategy at Xebia and Chief Software Architect at Marimer LLC. He is the creator of the open-source CSLA .NET development framework, the author of numerous books, and regularl...

11 Mars 202450min

Jared Parsons: Designing C# and Testing a Compiler - Episode 287

Jared Parsons: Designing C# and Testing a Compiler - Episode 287

Jared Parsons, the Principal Developer Lead on the C# Compiler Team. Everybody tuning in probably uses his code on a day-to-day basis! Jared started at Microsoft 20 years ago as a Developer; moved on ...

4 Mars 202435min

Michael Washington: Azure OpenAI - Episode 286

Michael Washington: Azure OpenAI - Episode 286

Michael is an ASP.NET and C# programmer who has extensive knowledge in process improvement, AI and Large Language Models, and student information systems. He also is the founder of two websites — AISt...

26 Feb 202438min

Kent Beck: Tidy First - Episode 285

Kent Beck: Tidy First - Episode 285

Original signer of the Agile Manifesto, author of the Extreme Programming book series, rediscoverer of Test-Driven Development, and inspiring Keynote Speaker. I read his TDD book 20 years ago. Topic...

19 Feb 202440min

Paul Yuknewicz: Cloud Native & Serverless - Episode 284

Paul Yuknewicz: Cloud Native & Serverless - Episode 284

Paul Yuknewicz is a Lead Product Manager for Azure Developer Experience at Microsoft; he is responsible for the PM team that designs the developer experience for building and diagnosing cloud-native a...

12 Feb 202438min

Populärt inom Politik & nyheter

motiv
aftonbladet-krim
p3-krim
spar
flashback-forever
rss-viva-fotboll
svenska-fall
rss-sanning-konsekvens
rss-krimstad
aftonbladet-daily
svd-dokumentara-berattelser-2
rss-vad-fan-hande
rss-krimreportrarna
rss-frandfors-horna
krimmagasinet
rss-aftonbladet-krim
olyckan-inifran
dagens-eko
fordomspodden
svd-ledarredaktionen