Ep. 123: Goals of Security Culture - Sort of?

Ep. 123: Goals of Security Culture - Sort of?

Author: Jardine Software Inc. February 18, 2025 Duration: 7:56
In this episode, I talk about how security is a part of everyone's role and the labeling of "Security Culture". I share some ideas on how to improve on role based security awareness and building stronger relationships between security and the rest of the organization. For more info go to https://www.developsec.com or follow us on X (@developsec). Send us Fan Mail For more info go to https://www.developsec.com or follow us on X (@developsec). The DevelopSec podcast is brought to you by Jardine...

Ever find yourself wondering how the digital tools you build every day can be made more resilient? DevelopSec: Developing Security Awareness, from Jardine Software Inc., digs into the practical realities of application security. This isn't about abstract theory; it's a grounded conversation for developers, engineers, and tech leaders who know that security is now a core part of the development lifecycle. Each episode focuses on a specific topic, breaking down how vulnerabilities emerge in code and, more importantly, how to identify and mitigate them before they become a problem. You'll hear straightforward discussions on everything from common coding flaws to emerging threats, providing actionable insights you can apply directly to your projects. The goal is to build a more intuitive security mindset, transforming it from a compliance checkpoint into a natural part of the development process. Tune into this podcast for a clear-eyed look at securing applications, where complex concepts are made accessible without sacrificing depth. It's a resource for anyone ready to move beyond curiosity and actively strengthen their work.
Author: Language: English Episodes: 100

DevelopSec: Developing Security Awareness
Podcast Episodes
Ep. 68: How the AWS disruption can help us [not-audio_url] [/not-audio_url]

Duration: 15:22
I am sure you have heard about the AWS service disruption that occurred. Have you seen how we can learn from this when we look at our own tools and processes? James talks about how we need to look at our own applications…
Ep. 67: Clearing up HTTPOnly and Secure Cookie Attributes [not-audio_url] [/not-audio_url]

Duration: 9:23
I hear a lot of people struggling with HTTPOnly and Secure attributes on cookies. The names may be confusing to some. Change your viewpoint and it may become easier.. For more info go to https://www.developsec.com or fol…
Ep. 66: Forgot Username [not-audio_url] [/not-audio_url]

Duration: 14:45
We always talk about Forgot Password... But what about Forgot Username? Listen in as James discusses why protecting this functionality is important and the ways it could be abused if not properly handled. For more info g…
Ep. 65: Security Questions: Good or Bad? [not-audio_url] [/not-audio_url]

Duration: 18:07
In this episode, James talks about security questions, or secret questions. We see them used in many different places. People complain they are horrible. So are they that bad that you shouldn't use them? Is it possible t…
Ep. 64: Using Stolen Passwords to Protect User Accounts [not-audio_url] [/not-audio_url]

Duration: 14:27
A few months ago, it was announced that some companies buy stolen passwords off of the black market to help protect their users. This is done by determining if the user's password was part of that list and forcing a rese…
Ep. 63: Remember Me Feature: Security Considerations [not-audio_url] [/not-audio_url]

Duration: 15:06
Are you, or have you, implemented a remember me feature for your application? What do you remember, username, password, or both? James talks about some security considerations around implementing a remember me feature fo…
Ep. 62: MongoDB Ransomware Attacks [not-audio_url] [/not-audio_url]

Duration: 13:53
Do you use MongoDB? If so, is it exposed to the internet? Recent news (listed below) had shown that a large number of MongoDB instances are being infected with ransomware. James talks about the issue and ways to help ens…
Ep. 61: Multi-factor Authentication [not-audio_url] [/not-audio_url]

Duration: 17:24
Implementing multi-factor authentication isn't just about a second factor. There are many considerations that need to be included. One in particular, how do you handle the user losing their means of that second factor. J…
Ep. 60: Yahoo Breach Takeaways [not-audio_url] [/not-audio_url]

Duration: 18:49
Yahoo has announced yet another breach from back in 2013 affecting a very large number of user accounts. https://investor.yahoo.net/ReleaseDetail.cfm?&ReleaseID=1004285 This creates an opportunity to discuss password sto…
Ep. 59: All About Cookie Protection [not-audio_url] [/not-audio_url]

Duration: 23:06
It is the holiday season. It is appropriate to talk about cookies. Not the kind that you bake, but the ones in your applications. James talks about the security mechanisms for cookies and clarifies what they are for. For…