Ep. 104: Securing Devops with Julien Vehent

Ep. 104: Securing Devops with Julien Vehent

Author: Jardine Software Inc. August 30, 2018 Duration: 45:07
James sits down with Julien Vehent to discuss his new book "Securing DevOps" and talk about security in a devOps world. Julien (@jvehent) is a security architect and engineering manager with over 15 years of experience in large organizations and web companies. He is currently responsible for the operational security of Firefox's backend infrastructure at Mozilla, and is the author of Securing DevOps. Check out the book (Securing DevOps) at https://www.manning.com/books/securing-devops S...

Ever find yourself wondering how the digital tools you build every day can be made more resilient? DevelopSec: Developing Security Awareness, from Jardine Software Inc., digs into the practical realities of application security. This isn't about abstract theory; it's a grounded conversation for developers, engineers, and tech leaders who know that security is now a core part of the development lifecycle. Each episode focuses on a specific topic, breaking down how vulnerabilities emerge in code and, more importantly, how to identify and mitigate them before they become a problem. You'll hear straightforward discussions on everything from common coding flaws to emerging threats, providing actionable insights you can apply directly to your projects. The goal is to build a more intuitive security mindset, transforming it from a compliance checkpoint into a natural part of the development process. Tune into this podcast for a clear-eyed look at securing applications, where complex concepts are made accessible without sacrificing depth. It's a resource for anyone ready to move beyond curiosity and actively strengthen their work.
Author: Language: English Episodes: 100

DevelopSec: Developing Security Awareness
Podcast Episodes
Ep. 119: Risks of SpellCheck [not-audio_url] [/not-audio_url]

Duration: 12:35
In this episode we talk about the spell check feature of the browser and how it could present a risk to sensitive data. Link to article referenced: https://www.darkreading.com/application-security/spellchecking-google-ch…
Ep. 118: Log4J Sparking Thought on Vulnerable Components [not-audio_url] [/not-audio_url]

Duration: 24:27
Log4J has been the talk of the town recently and everyone is focused on the technical details of the specific vulnerabilities found. In this episode, James talks about the overarching ideas around dealing with vulnerable…
Ep. 117: How Browsers are Helping with Security [not-audio_url] [/not-audio_url]

Duration: 13:49
Chrome has announced a few changes that we need to watch out for in the near future. We previously talked about the default value for samesite that is coming up fast. I wrote about this here: https://www.jardinesoftware.…
Ep. 116: Chrome Retires XSS Auditor [not-audio_url] [/not-audio_url]

Duration: 14:07
It was recently announced that Chrome was dropping the XSS Auditor in Chrome 78. What does that mean and how does that change things for you as a developer? https://www.chromium.org/developers/design-documents/xss-audito…
Ep. 115: Is CSRF Really Dead? [not-audio_url] [/not-audio_url]

Duration: 15:09
In 2020, Chrome will default the SameSite attribute to Lax on all cookies. SameSite helps mitigate CSRF, but does that mean CSRF is Dead? For more info go to https://www.developsec.com or follow us on twitter (@developse…
Ep. 114: Investing in People for Better Application Security [not-audio_url] [/not-audio_url]

Duration: 24:37
In this episode, James talks about investing in the development teams to increase application security priorities. For more info go to https://www.developsec.com or follow us on twitter (@developsec). Join the conversati…
Ep. 113: What is your mother's maiden name? [not-audio_url] [/not-audio_url]

Duration: 21:00
In this episode, James talks about some of the risks and recommendations around security questions and their implementation. For more info go to https://www.developsec.com or follow us on twitter (@developsec). Join the…
Ep. 112: Application Fingerprinting [not-audio_url] [/not-audio_url]

Duration: 21:04
Does your application give away details about it server, framework, or other components? How is this information used by an attacker? Check out this episode to learn more. For more info go to https://www.developsec.com o…
Ep. 111: Authentication Alerts [not-audio_url] [/not-audio_url]

Duration: 16:07
Would you know if someone authenticated to your account? With the breaches we see in the news, and attacks like credential stuffing, there must be a way to be alerted to account access. James talks about authentication a…
Ep. 110: Implementation Matters [not-audio_url] [/not-audio_url]

Duration: 19:17
James discusses how implementation matters with security controls and how it changes priorities. This came about after reading the following story: https://www.theverge.com/2018/12/31/18162541/vein-authentication-wax-han…