Artwork

Contenido proporcionado por Tromzo. Todo el contenido del podcast, incluidos episodios, gráficos y descripciones de podcast, lo carga y proporciona directamente Tromzo o su socio de plataforma de podcast. Si cree que alguien está utilizando su trabajo protegido por derechos de autor sin su permiso, puede seguir el proceso descrito aquí https://es.player.fm/legal.
Player FM : aplicación de podcast
¡Desconecta con la aplicación Player FM !

EP 49 — Semgrep’s Colleen Dai on Building Security Strategies and Relationships with Other Teams

20:14
 
Compartir
 

Manage episode 381721298 series 3330694
Contenido proporcionado por Tromzo. Todo el contenido del podcast, incluidos episodios, gráficos y descripciones de podcast, lo carga y proporciona directamente Tromzo o su socio de plataforma de podcast. Si cree que alguien está utilizando su trabajo protegido por derechos de autor sin su permiso, puede seguir el proceso descrito aquí https://es.player.fm/legal.

In this special episode of the Future of Application Security, recorded at the Developers & Security are Friends Day, Eric speaks with Colleen Dai, Senior Security Researcher at Semgrep, an open source static analysis tool. They discuss strategies security teams can take to reduce false positives, use secure defaults to eliminate bug classes, and reduce complexity in security decision-making. They also talk about ways to build the relationships between security, developers, and engineers, which includes aligning on goals, communication, and recognition.

Topics discussed:

  • Colleen's background and what her security research role at Semgrep entails.
  • How to use secure defaults to eliminate bug classes and reduce the complexity in security decisions.
  • How to reduce false positives by writing rules and checks, especially ones that are customized to your organization.
  • How to better align the goals of security and developers by focusing on creating good software — and good software is secure software.
  • How to build relationships with engineers through communication and recognition, not just talking through Jira tickets.
  • Why security and developers still struggle with cross-site scripting and how it can be fixed.
  continue reading

60 episodios

Artwork
iconCompartir
 
Manage episode 381721298 series 3330694
Contenido proporcionado por Tromzo. Todo el contenido del podcast, incluidos episodios, gráficos y descripciones de podcast, lo carga y proporciona directamente Tromzo o su socio de plataforma de podcast. Si cree que alguien está utilizando su trabajo protegido por derechos de autor sin su permiso, puede seguir el proceso descrito aquí https://es.player.fm/legal.

In this special episode of the Future of Application Security, recorded at the Developers & Security are Friends Day, Eric speaks with Colleen Dai, Senior Security Researcher at Semgrep, an open source static analysis tool. They discuss strategies security teams can take to reduce false positives, use secure defaults to eliminate bug classes, and reduce complexity in security decision-making. They also talk about ways to build the relationships between security, developers, and engineers, which includes aligning on goals, communication, and recognition.

Topics discussed:

  • Colleen's background and what her security research role at Semgrep entails.
  • How to use secure defaults to eliminate bug classes and reduce the complexity in security decisions.
  • How to reduce false positives by writing rules and checks, especially ones that are customized to your organization.
  • How to better align the goals of security and developers by focusing on creating good software — and good software is secure software.
  • How to build relationships with engineers through communication and recognition, not just talking through Jira tickets.
  • Why security and developers still struggle with cross-site scripting and how it can be fixed.
  continue reading

60 episodios

Todos los episodios

×
 
Loading …

Bienvenido a Player FM!

Player FM está escaneando la web en busca de podcasts de alta calidad para que los disfrutes en este momento. Es la mejor aplicación de podcast y funciona en Android, iPhone y la web. Regístrate para sincronizar suscripciones a través de dispositivos.

 

Guia de referencia rapida