140: Web Application Security, Part 1 with Scott Arciszewski

Published: Jan. 18, 2018, 9:30 a.m.

b'In this weeks episode we chat with Scott Arciszewski about all things Security and Cryptography.\\nWe start off the show by explaining how he got interested in this field of work, correcting PHP security related answers on Stack Overflow and why he focuses on PHP security.\\nFrom here, we move on to highlight what the OWASP Top Ten is, how you can distill many security principles into data/code seperation and what is involved in a software audit.\\nThis leads us on to discuss what HTTPS actually is, touching on TLS, PKI\\u2019s, Ciphersuites, and reported attacks against TLS and ECB.\\nFinally, we highlight some important browser security features that can be used, pushing new software releases in a secure manor, thoughts on Cryptocurrencies and how everyone wants to solve their problem with a blockchain at this time.'