Artwork

Content provided by Mackenzie Jackson & Dwayne McDaniel, Mackenzie Jackson, and Dwayne McDaniel. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Mackenzie Jackson & Dwayne McDaniel, Mackenzie Jackson, and Dwayne McDaniel or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!

What Tools Miss and Why Humans Matter in AppSec - Yash Shahani

18:02
 
Share
 

Manage episode 484039349 series 3516169
Content provided by Mackenzie Jackson & Dwayne McDaniel, Mackenzie Jackson, and Dwayne McDaniel. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Mackenzie Jackson & Dwayne McDaniel, Mackenzie Jackson, and Dwayne McDaniel or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.

In this episode of the Security Repo Podcast, Dwayne McDaniel sits down with Yash Shahani, a seasoned AppSec engineer and vulnerability hunter, to dive into the nuances of manual code review and the limitations of automated security tools. They explore the evolving role of AI in AppSec, its promise and pitfalls, and why human intuition still plays a vital role in catching complex logic flaws. Yash also shares practical tips for exploring unfamiliar codebases and emphasizes the importance of treating security as a shared responsibility across teams.Yash Shahani is a security researcher and AppSec engineer with a background in building and breaking applications. He holds a Master’s in Information Security from Carnegie Mellon and focuses on finding the vulnerabilities that tools miss. Yash is an active member of the security community and an organizer for BSides San Francisco. He’s passionate about making security easier to adopt - something teams naturally build into software development, not bolt on later.

  continue reading

94 episodes

Artwork
iconShare
 
Manage episode 484039349 series 3516169
Content provided by Mackenzie Jackson & Dwayne McDaniel, Mackenzie Jackson, and Dwayne McDaniel. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Mackenzie Jackson & Dwayne McDaniel, Mackenzie Jackson, and Dwayne McDaniel or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.

In this episode of the Security Repo Podcast, Dwayne McDaniel sits down with Yash Shahani, a seasoned AppSec engineer and vulnerability hunter, to dive into the nuances of manual code review and the limitations of automated security tools. They explore the evolving role of AI in AppSec, its promise and pitfalls, and why human intuition still plays a vital role in catching complex logic flaws. Yash also shares practical tips for exploring unfamiliar codebases and emphasizes the importance of treating security as a shared responsibility across teams.Yash Shahani is a security researcher and AppSec engineer with a background in building and breaking applications. He holds a Master’s in Information Security from Carnegie Mellon and focuses on finding the vulnerabilities that tools miss. Yash is an active member of the security community and an organizer for BSides San Francisco. He’s passionate about making security easier to adopt - something teams naturally build into software development, not bolt on later.

  continue reading

94 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Quick Reference Guide

Listen to this show while you explore
Play