The Stack Overflow Podcast - What security teams need to understand about developers

NightVision offers web and API security testing tools built to integrate with developers’ established workflows. NightVision identifies issues by precise area(s) of code, so devs don’t have to chase down and validate vulnerability reports, a process that eats up precious engineering resources. Get started with their docs.

Connect with Kinnaird on LinkedIn

Stack Overflow user Cecil Curry earned a Populist badge with their exceptionally thoughtful answer to In Python how can one tell if a module comes from a C extension?.

Some great excerpts from this episode:

“From the program side, I would say if you're running a security program or you're starting from day one, there's a danger with security people and being the security person who's out of touch or doesn't know what the life of a developer is like. And you don't want to be that person. And that's not how you have actual business impact, right? So you got to embed with teams, threat model, and then do some preventative security testing, right? Testing things before it gets into production, not just relying on having a bug bounty program.”

“With code scanning, you're looking for potentially insecure patterns in the code, but with dynamic testing, you're actually testing the live application. So we're sending HTTP traffic to the application, sending malicious payloads in forms or in query parameters, et cetera, to try to elicit a response or to send something to an attacker controlled server. And so using this, we're able to. Not just have theoretical vulnerabilities, but exploitable vulnerabilities. I mean, how many times have you looked at something in GitHub security alerts and thought, yeah, that's not real. That's not exploitable. Right. So we're trying to avoid that and have higher quality touch points with developers. So when they look at something, they say, okay, that's exploitable. You showed me how. And you traced it back to code.”

Read Me a Poem - “Full Moon Rhyme” by Judith Wright

Amanda Holmes reads Judith Wright’s “Full Moon Rhyme.” Have a suggestion for a poem by a (dead) writer? Email us: podcast@theamericanscholar.org. If we select your entry, you’ll win a copy of a poetry collection edited by David Lehman.


This episode was produced by Stephanie Bastek and features the song “Canvasback” by Chad Crouch.




Hosted on Acast. See acast.com/privacy for more information.

It Could Happen Here - What Next for Syria?

James and Robert discuss the downfall of the Assad regime, the future for Syria, and what we can all learn from Syria.

Sources:

Defendrojava.org

https://docs.google.com/document/d/1tJgepOyOt9cjXRjLE4kHdOhoCesJx-l_S9hJ2foQxnI/edit?tab=t.0

https://youtu.be/kuj8zPLY_4E?si=D2SVT1KBQzXwrxEU

See omnystudio.com/listener for privacy information.

array(3) { [0]=> string(150) "https://www.omnycontent.com/d/programs/e73c998e-6e60-432f-8610-ae210140c5b1/78d30acb-8463-4c40-a5ae-ae2d0145c9ff/image.jpg?t=1749835422&size=Large" [1]=> string(10) "image/jpeg" [2]=> int(0) }

CBS News Roundup - 12/09/2024 | World News Roundup Late Edition

Person of interest in custody in connection to the shooting death of UnitedHealthcare CEO was found with a weapon and a manifesto. Not guilty verdict for Marine veteran in New York subway chokehold death. What's next for Syria after fall of Assad regime? CBS News Correspondent Jennifer Keiper with tonight's World News Roundup.

To learn more about listener data and our privacy practices visit: https://www.audacyinc.com/privacy-policy

Learn more about your ad choices. Visit https://podcastchoices.com/adchoices

This Machine Kills - Patreon Preview 384. – Executive Paranoia

We tie together a number of things: first, the assassination of UnitedHealth Group’s CEO and the reactions to this event; second, a new startup in the Thiel family that rehabilitates Sauron as a shining beacon of security for the terrified tech elite; and third, the vision put forward by Marc Benioff, CEO of Salesforce, for an army of ethical techno-slaves that are powered by a new vaporware platform called Agentforce. Pre-order Jathan’s new book! https://www.ucpress.edu/book/9780520398078/the-mechanic-and-the-luddite ••• Why "we" want insurance executives dead https://www.usermag.co/p/yes-we-want-insurance-executives ••• Fearful of crime, the tech elite transform their homes into military bunkers https://www.washingtonpost.com/technology/2024/12/05/tech-ceos-elites-home-security-silicon-valley/ ••• How the Rise of New Digital Workers Will Lead to an Unlimited Age https://time.com/7178872/agents-unlimited-age/ Subscribe to hear more analysis and commentary in our premium episodes every week! https://www.patreon.com/thismachinekills Hosted by Jathan Sadowski (bsky.app/profile/jathansadowski.com) and Edward Ongweso Jr. (www.x.com/bigblackjacobin). Production / Music by Jereme Brown (bsky.app/profile/jebr.bsky.social)

Audio Mises Wire - Sound Money Movement Chalks Up Seven State Legislative Victories in 2024

Not all news from the gold and monetary fronts is bad. In fact, gold made a number of advancements in seven states, including exemptions from taxes and attempts by states to restrict Federal Reserve behavior. Gold is alive and well.

Original article: Sound Money Movement Chalks Up Seven State Legislative Victories in 2024