Discoverno dogma podcast#170 Tanya Janca, Building Security Into Software
#170 Tanya Janca, Building Security Into Software

#170 Tanya Janca, Building Security Into Software

Update: 2023-02-01
Share

Description

Summary

Tanya Janca talks about fixing your developer process so that security is part of the life cycle.

Details

Who she is, what she does. Becoming a penetration tester. Being a developer advocated. Adding security at the end of the software development life cycle; people wish there was a silver bullet for security. "We're secure, we don't need to test our security". Security should start at the project kickoff. Who owns security, the devs or the security team; getting authority and responsibility. Choosing what to fix; likelihood, potential losses, cost. Security stories during development iterations. Security gets in the way. Feature switches to turn off security in dev environments. Negotiating about what to fix; working around the process. Should security programming be a specialty. Don't build a tool if you can buy it. Copy pasting your way into trouble; Stack Overflow has a security section now; team to build core security tools. Buying services for authentication/authorization. Communicating with other applications. Why no HTTPS. Why encryption at rest when data is in the cloud. Security testing - static analysis, dependencies vulnerabilities, dynamic analysis. Security tools.

Support this podcast

Full show notes
@SheHacksPurple
SheHacksPurple
Tanya's music
We Hack Purple
Why No HTTPS
Other Security Podcast Episodes

Comments 
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

#170 Tanya Janca, Building Security Into Software

#170 Tanya Janca, Building Security Into Software

no dogma podcast