Artwork

Content provided by Day One. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Day One or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!

From Cryptography to AppSec: Scott Contini on Building Practical Security

42:16
 
Share
 

Manage episode 479997811 series 3463790
Content provided by Day One. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Day One or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.

Episode Summary

Scott Contini has a PhD in cryptography with more than a dozen research publications, and has spent the last 15 years focused on solving real-world security problems. After switching from academia to industry in 2008, Scott has identified hundreds of cryptographic implementation flaws across the world, written widely read blogs on common coding mistakes, and contributed significantly to the 2021 OWASP Top 10 topic of Cryptographic Failures. He joins Cole Cornford to discuss how cryptography often goes wrong in practice, why secure-by-default APIs are reshaping security today, and the importance of clear communication and community-building in advancing the field. Scott also shares stories from working alongside legendary figures in cryptography, and offers advice for anyone looking to build a sustainable and impactful security career.

Timestamps

00:20 - Scott’s background in cryptography and transition to AppSec

02:00 - Moving from theory to real-world security challenges

05:00 - Common cryptography mistakes in the industry

07:50 - Why using the wrong encryption modes leads to vulnerabilities

10:10 - How Java’s cryptography design led to widespread issues

14:40 - The rise of secure-by-default APIs in cryptography

17:00 - Stories from working with cryptographic legends

22:00 - Improving advice in the OWASP community

27:50 - The value of writing and public speaking in AppSec careers

33:00 - Advice for newcomers in security: think like an attacker and keep learning

Mentioned in this episode:

Call for Feedback


This podcast uses the following third-party services for analysis:
Podtrac - https://analytics.podtrac.com/privacy-policy-gdrp
Spotify Ad Analytics - https://www.spotify.com/us/legal/ad-analytics-privacy-policy/
  continue reading

50 episodes

Artwork
iconShare
 
Manage episode 479997811 series 3463790
Content provided by Day One. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Day One or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.

Episode Summary

Scott Contini has a PhD in cryptography with more than a dozen research publications, and has spent the last 15 years focused on solving real-world security problems. After switching from academia to industry in 2008, Scott has identified hundreds of cryptographic implementation flaws across the world, written widely read blogs on common coding mistakes, and contributed significantly to the 2021 OWASP Top 10 topic of Cryptographic Failures. He joins Cole Cornford to discuss how cryptography often goes wrong in practice, why secure-by-default APIs are reshaping security today, and the importance of clear communication and community-building in advancing the field. Scott also shares stories from working alongside legendary figures in cryptography, and offers advice for anyone looking to build a sustainable and impactful security career.

Timestamps

00:20 - Scott’s background in cryptography and transition to AppSec

02:00 - Moving from theory to real-world security challenges

05:00 - Common cryptography mistakes in the industry

07:50 - Why using the wrong encryption modes leads to vulnerabilities

10:10 - How Java’s cryptography design led to widespread issues

14:40 - The rise of secure-by-default APIs in cryptography

17:00 - Stories from working with cryptographic legends

22:00 - Improving advice in the OWASP community

27:50 - The value of writing and public speaking in AppSec careers

33:00 - Advice for newcomers in security: think like an attacker and keep learning

Mentioned in this episode:

Call for Feedback


This podcast uses the following third-party services for analysis:
Podtrac - https://analytics.podtrac.com/privacy-policy-gdrp
Spotify Ad Analytics - https://www.spotify.com/us/legal/ad-analytics-privacy-policy/
  continue reading

50 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Quick Reference Guide

Listen to this show while you explore
Play