DiscoverApplication Security Weekly (Video)Uniting software development and application security - Jonathan Schneider, Will Vandevanter - ASW #342
Uniting software development and application security - Jonathan Schneider, Will Vandevanter - ASW #342

Uniting software development and application security - Jonathan Schneider, Will Vandevanter - ASW #342

Update: 2025-08-05
Share

Description

Maintaining code is a lot more than keeping dependencies up to date. It involved everything from keeping old code running to changing frameworks to even changing implementation languages. Jonathan Schneider talks about the engineering considerations of refactoring and rewriting code, why code maintenance is important to appsec, and how to build confidence that adding automation to a migration results in code that has the same workflows as before.

Resources

Then, instead of our usual news segment, we do a deep dive on some recent vulns NVIDIA's Triton Inference Server disclosed by Trail of Bits' Will Vandevanter. Will talks about the thought process and tools that go into identify potential vulns, the analysis in determining whether they're exploitable, and the disclosure process with vendors. He makes the important point that even if something doesn't turn out to be a vuln, there's still benefit to the learning process and gaining experience in seeing the different ways that devs design software. Of course, it's also more fun when you find an exploitable vuln -- which Will did here!

Resources

Show Notes: https://securityweekly.com/asw-342

Comments 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Uniting software development and application security - Jonathan Schneider, Will Vandevanter - ASW #342

Uniting software development and application security - Jonathan Schneider, Will Vandevanter - ASW #342