Go offline with the Player FM app!
Secure Designs, UX Dragons, Vuln Dungeons - Jack Cable - ASW #328
Fetch error
Hmmm there seems to be a problem fetching this series right now. Last successful fetch was on April 30, 2025 08:36 ()
What now? This series will be checked again in the next hour. If you believe it should be working, please verify the publisher's feed link below is valid and includes actual episode links. You can contact support to request the feed be immediately fetched.
Manage episode 479881030 series 2591184
In this live recording from BSidesSF we explore the factors that influence a secure design, talk about how to avoid the bite of UX dragons, and why designs should put classes of vulns into dungeons.
But we can't threat model a secure design forever and we can't oversimplify guidance for a design to be "more secure". Kalyani Pawar and Jack Cable join the discussion to provide advice on evaluating secure designs through examples of strong and weak designs we've seen over the years. We highlight the importance of designing systems to serve users and consider what it means to have a secure design with a poor UX. As we talk about the strategy and tactics of secure design, we share why framing this as a challenge in preventing dangerous errors can help devs make practical engineering decisions that improve appsec for everyone.
Resources
- https://owasp.org/Top10/A042021-InsecureDesign/
- https://dl.acm.org/doi/10.5555/1251421.1251435
- https://www.threatmodelingmanifesto.org
- https://www.ietf.org/rfc/rfc9700.html
- https://www.cisa.gov/resources-tools/resources/secure-by-design
Visit https://www.securityweekly.com/asw for all the latest episodes!
Show Notes: https://securityweekly.com/asw-328
3198 episodes
Fetch error
Hmmm there seems to be a problem fetching this series right now. Last successful fetch was on April 30, 2025 08:36 ()
What now? This series will be checked again in the next hour. If you believe it should be working, please verify the publisher's feed link below is valid and includes actual episode links. You can contact support to request the feed be immediately fetched.
Manage episode 479881030 series 2591184
In this live recording from BSidesSF we explore the factors that influence a secure design, talk about how to avoid the bite of UX dragons, and why designs should put classes of vulns into dungeons.
But we can't threat model a secure design forever and we can't oversimplify guidance for a design to be "more secure". Kalyani Pawar and Jack Cable join the discussion to provide advice on evaluating secure designs through examples of strong and weak designs we've seen over the years. We highlight the importance of designing systems to serve users and consider what it means to have a secure design with a poor UX. As we talk about the strategy and tactics of secure design, we share why framing this as a challenge in preventing dangerous errors can help devs make practical engineering decisions that improve appsec for everyone.
Resources
- https://owasp.org/Top10/A042021-InsecureDesign/
- https://dl.acm.org/doi/10.5555/1251421.1251435
- https://www.threatmodelingmanifesto.org
- https://www.ietf.org/rfc/rfc9700.html
- https://www.cisa.gov/resources-tools/resources/secure-by-design
Visit https://www.securityweekly.com/asw for all the latest episodes!
Show Notes: https://securityweekly.com/asw-328
3198 episodes
All episodes
×Welcome to Player FM!
Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.