Ep. 47: Account Lockouts and auto-unlock

Ep. 47: Account Lockouts and auto-unlock

Author: Jardine Software Inc. June 17, 2016 Duration: 10:54
A question came in regarding auto-unlock of accounts and account lockout in general. James discusses his thoughts on this process and how he approaches these types of questions. For more info go to https://www.developsec.com or follow us on twitter (@developsec). Presented by Jardine Software Inc. (https://www.jardinesoftware.com) Jardine Software provides application security consulting and training to add value to your application security program. Contact us today to see how w...

Ever find yourself wondering how the digital tools you build every day can be made more resilient? DevelopSec: Developing Security Awareness, from Jardine Software Inc., digs into the practical realities of application security. This isn't about abstract theory; it's a grounded conversation for developers, engineers, and tech leaders who know that security is now a core part of the development lifecycle. Each episode focuses on a specific topic, breaking down how vulnerabilities emerge in code and, more importantly, how to identify and mitigate them before they become a problem. You'll hear straightforward discussions on everything from common coding flaws to emerging threats, providing actionable insights you can apply directly to your projects. The goal is to build a more intuitive security mindset, transforming it from a compliance checkpoint into a natural part of the development process. Tune into this podcast for a clear-eyed look at securing applications, where complex concepts are made accessible without sacrificing depth. It's a resource for anyone ready to move beyond curiosity and actively strengthen their work.
Author: Language: English Episodes: 100

DevelopSec: Developing Security Awareness
Podcast Episodes
Ep. 79: Marketing with USB Drives [not-audio_url] [/not-audio_url]

Duration: 15:40
James talks about the risk of USB thumb drives and their risk using the recent BCBS marketing campaign as an example. (http://www.fiercehealthcare.com/privacy-security/bcbs-alabama-re-evaluates-usb-marketing-campaign-ami…
Ep. 78: MySpace Lessons - Looking At Account Recovery [not-audio_url] [/not-audio_url]

Duration: 19:14
James talks about a recent vulnerability report regarding MySpace's Account Recovery system (https://www.wired.com/story/myspace-security-account-takeover/). He talks about considerations around account recovery and the…
Ep. 77: Interactive Application Security Testing [not-audio_url] [/not-audio_url]

Duration: 14:47
In this episode, James talks about Interactive Application Security Testing, or IAST. It is a sort of hybrid approach that is similar to both dynamic and static analysis. Listen in to learn more about it. The video versi…
Ep. 76: Validation - Client vs. Server [not-audio_url] [/not-audio_url]

Duration: 13:09
Are you thinking about client vs. server-side input validation? Curious why each is important and when to use them? James talks about the basic concepts and how to apply them to create more secure applications. A video v…
Ep. 75: IAM with Geurt van Wijk [not-audio_url] [/not-audio_url]

Duration: 41:45
In this episode I sit down with Geurt van Wijk from IDdriven to discuss IAM and IDaaS. Geurt has many years of experience around Identity and shares some great insights into considerations when working with it. If you ty…
Ep. 74: Audio Driver Key Logger Lessons Learned [not-audio_url] [/not-audio_url]

Duration: 16:25
It was recently reported that an audio driver on HP systems was logging key strokes to a local file. Accidental? Malicious? Instead, we talk about how to try and avoid this from happening in the future. Original Article:…
Ep. 73: Identity with Vittorio Bertocci [not-audio_url] [/not-audio_url]

Duration: 30:26
I sat down with Vittorio Bertocci from Microsoft at the Microsoft Build 2017 conference in Seattle Washington. Vittorio shared some great insights into Identity and some new things around Azure AD and Azure AD B2C. Liste…
Ep. 72: Where to Perform Output Encoding [not-audio_url] [/not-audio_url]

Duration: 13:37
Over the years I have had many people ask about encoding before storing data in the database. Here are my thoughts and recommendations. For more info go to https://www.developsec.com or follow us on twitter (@developsec)…
Ep. 71: Sub Resource Integrity [not-audio_url] [/not-audio_url]

Duration: 14:47
Do you use hosted content on a CDN? How do you know the file hasn't been modified? James describes Sub Resource Integrity and how it is used to help detect and prevent loading modified files. For details referenced in th…
Ep. 70: Considering security when selecting an application platform [not-audio_url] [/not-audio_url]

Duration: 21:02
Do you struggle with trying to pick the most secure application platform? Are you focusing on the right questions? James talks about ways to look at application platforms and be secure, no matter which one you choose. Fo…