Alice and Bob Learn: Recent Episodes

Tanya Janca - SheHacksPurple

This podcast explores the questions posed in each chapter of the book Alice and Bob Learn Application Security. Hosted by Tanya Janca, the author of the book, she and guests discuss each question to try to find a complete answer of how to secure all the things.

View Details

Guests: Aaron Lord, Abhi Arora, Dominique Righetto (Technical editor of the book)

Questions to be answered:

  1. What does the term “shared responsibility” mean?

  2. What is the difference between Infrastructure as a Service (IaaS) and Platform as a Service (PaaS)? Which one(s) do you have to patch and maintain yourself?

  3. Why is there (or is there not) more risk to online storage? Which of the CIA Triad can apply to online storage?

  4. Name one new risk that the cloud has that a traditional or on-premises data center does not have.

  5. What is the difference between a container, a virtual machine, and a physical server?

  6. Name one advantage of Infrastructure as Code.

  7. Name one advantage of DevOps over Waterfall SDLC.

  8. Which of the modern tooling options sounded most interesting to you? Why?

  9. Which of the modern tactics sounded most interesting to you? Why?

  10. After reading this chapter, what do you see missing in your organization? What can you improve, and how can you do it?

Buy the book https://www.amazon.ca/Alice-Bob-Learn...

Take the course: https://academy.wehackpurple.com/ #tanyajanca #AppSec #devsecops #applicationsecurity #cloudsecurity

View Details

  1. Get ready to create a learning plan for yourself for the next year.
    ■ Which books will you read?
    ■ Will you attend a conference? Name the one you want.
    ■ Will you join a professional organization or other professional community? Name it.
    ■ Will you listen to podcasts? Which ones?
    ■ Attend meetups? Which ones?
    ■ Will you create your own project for learning or do a CTF or other hands-on activity? Which ones?
    ■ Will you attend formal training?

  2. How will you make time for this in your life? Will your boss give you time? Will you carve our personal time? What priority will you give this in your life?

  3. List three new things you want to learn this year and why.

  4. Name three things that if you learned would make you better at your job.

  5. How do you learn best? Reading? Listening? Doing? Watching? Another way? Explain your learning style as best you can.

  6. What motivates you to learn? Rewards? Recognition? Extra leisure time? Sweet desserts? Think of what motivates you and how you can use this to ensure you keep learning, all year round.

  7. What format works best for you to absorb information? Class time? Job shadowing? Mentoring? Contests? Name your favorite formats.

  8. Where will you do your learning? At home? At work? At a café near your house on Saturdays? Will you use your work laptop or home PC? What equipment do you need? Where will you carve out space for this? You need to know when and where you will do your learning.

  9. How will you get access to the resources you need to learn? Are they free (podcasts)? Will you be able to convince your workplace to pay? Are there ways that you can pay on your own? Create a budget at the end of your learning plan (next page).

Buy the book https://www.amazon.ca/Alice-Bob-Learn...

Take the course: https://academy.wehackpurple.com/ #tanyajanca #AppSec #devsecops #applicationsecurity #cloudsecurity

View Details

Questions to be answered:

  1. What are some of the risks of technical debt?

  2. Should you post private information on social media if you only have friends following you?

  3. Why are multi-factor authentication adoption rates so low? Name three ways we could increase adoption.

  4. Which password manager do you use? (Note: “I don’t use one” is the wrong answer here.)

  5. Which security policy at your office makes it hard to get your job done? Have you spoken to the security team about updating it? Is there a potential compromise that could be made?

  6. Name an activity you think might make a good “fire drill.”

Buy the book https://www.amazon.ca/Alice-Bob-Learn...

Take the course: https://academy.wehackpurple.com/ #tanyajanca #AppSec #devsecops #applicationsecurity #cloudsecurity

View Details

Questions to be answer:

  1. Give one reason why maintaining an up-to-date application inventory is valuable for any organization.

  2. Give one example of an alert that your application could give. What type of behavior would cause such an alert, and why is it a problem?

  3. Is testing the most important part of an AppSec program? If so, why? If not, why not?

  4. Is it more valuable to buy a RASP or WAF tool (a shield for your applica- tion) or to spend that money on ensuring your code is secure? Explain your choice.

  5. Describe a type of security incident that would require the assistance of developer. What would be needed of the developer?

  6. If you could give software developers one tool to help them, what would it be? Explain your choice.

  7. If you could give developers one learning resource, what would it be? Explain your choice.

  8. What is the difference between SAST and SCA?

  9. What is the difference between SAST and DAST?

  10. Set a potential goal for your application security program at your office, a school project, or in a made-up place that you hope to work at some day. What goal did you set? Why did you choose this? How will you measure your progress?

  11. Do you have current roadblocks stopping you from starting your first AppSec program where you work? If so, what are they? And better yet, how can you overcome them?

Buy the book
https://www.amazon.ca/Alice-Bob-Learn...

View Details

Questions to be answered:
1. When should you use your own identity on the network (user account) versus a service account? Give two examples for each and explain your reasoning.

  1. Explain possible reasons or situations why C and C++ are still widely used in our industry when RUST (a memory-safe language) exists. Try to think of two or more.

  2. What is your favourite programming language and/or framework, and why?

  3. Which programming language and/or framework do you think is the most secure? Why?

  4. Why do we need to protect user sessions?

  5. If an attacker where able to get a hold of someone else’s user session while they are logged in to their online banking, what could the attacker do?

  6. If you were going to explain the difference between authentication and authorization to a non-technical co-worker, how would you explain it?

  7. Should C-level executives have special privileges on your network and other computer systems? If so, why? If not, why not? What types of privileges would you give them, if you gave them any?

  8. Should network system administrators have special privileges on your network and other computer systems? If so, why? If not, why not? What types of privileges would you give them, if you gave them any?

  9. Should help desk employees have special privileges on your network and other computer systems? If so, why? If not, why not? What types of privi- leges would you give them, if you gave them any?

  10. Your boss tells you that turning on logging and monitoring will cost too much. How do you explain its value and importance from a security perspective? Write a paragraph to convince your boss. Remember to make sure you explain what the potential risk is to the business, in a way your boss can understand (who is a smart, but not overly technical, person). If you speak over your audience’s head, you will not pass this question, nor will you convince your boss.

https://www.amazon.ca/Alice-Bob-Learn-Application-Security/dp/1119687357

AppSec #devsecops #applicationsecurity #cloudsecurity

View Details

Questions to be answered: 
1. Someone on your project team wants to accept serialized objects from an untrusted source. You know this is a bad idea. How do you explain the risk effectively to your teammate? Write down your answer. Be persuasive and clear. 

  1. The OWASP Top Ten is a standard: Yes or no. 

  2. Name three of the OWASP Top Ten that we already covered in this book before Chapter 5. 

  3. Does the XXE vulnerability apply to JSON? Does it apply to YAML? If so, why? If not, why not? 

  4. Name an example of a race condition (it does not need to be computer related). 

  5. Why do we roll back incomplete transactions? Why does that matter? Give an example of when not rolling back an incomplete transaction would be problematic. 

tanyajanca #AppSec #devsecops #applicationsecurity #cloudsecurity

View Details

Questions to be answered:
1. If you could only choose one type of testing to perform on your application, which type would it be and why?

  1. Which type of testing do you think would be the fastest?Why?

  2. Which type of testing do you think would be the slowest? Why?

  3. What types of vulnerabilities would you want to look for in regression testing? Name at least two, and why you chose each one.

  4. Does your workplace have a zero-trust network design? If you don’t know the answer, your homework is to find out.

  5. Does your workplace allow use of a CI/CD pipeline? If you don’t know the answer, your homework is to find out.

  6. In a CI/CD environment, should you implement a Static Application Security Testing (SAST) tool and run a complete scan of all of the code, every time there is a new build? Why? Why not?

  7. Why is it critical to put all new changes into a code repository?

  8. Why do we test integration points between different systems? Is it more or less valuable than testing the rest of each system?

  9. Why do we test databases, even though they aren’t publicly accessible?

  10. Why do we test APIs, even though they aren’t publicly accessible? (This might be a trick question.)

  11. When does it make sense to do a penetration test versus a security assessment of a system? Explain your answer.
    Buy the book https://www.amazon.ca/Alice-Bob-Learn-Application-Security/dp/1119687357

Take the course: https://academy.wehackpurple.com/

tanyajanca #AppSec #devsecops #applicationsecurity #cloudsecurity

View Details

Questions to be answered:
1. When should data be encrypted?

  1. What are some possible ways that we can ensure the third-party components we use are secure? How can we minimize risk in this area?

  2. Where should you store your application’s secrets? How should your application access your secrets?

  3. Name three types of “secrets.”

  4. What are some of the potential threats that a mobile banking application would face? Name three threats and rate how likely they are and how damaging they are based on a scale of low, medium, and high.

  5. Name three threats that could apply to a “smart” car. Rate the threats (low, medium, or high) in terms of likelihood and potential damage.

  6. Name five different types of security functionality that would potentially be offered in a modern framework.

https://www.amazon.ca/Alice-Bob-Learn-Application-Security/dp/1119687357

AppSec #devsecops #applicationsecurity #cloudsecurity

View Details

#Tanya @shehackspurple will be streaming Chapter 2 from Alice and Bob learn application security: SECURITY REQUIREMENTS #AppSec #devsecops #applicationsecurity #cloudsecurity . @righettod & @haroonmeer @alissaknight Nancy Gariché will be on with us . Questions to be answered:
1. List two more potential security requirements for a web application (which are not already listed).

  1. List two more potential security requirements for an operating system in a car.

  2. List two more potential security requirements for a “smart toaster.”

  3. List two more potential security requirements for an application that handles credit cards.

  4. Which security requirement is the most valuable? Why is it the most valuable one to you and/or your organization?

  5. If you had to remove one of the requirements from this chapter from a web app project, which one would it be? Why?

Buy the book here: https://www.amazon.com/Alice-Bob-Learn-Application-Security/dp/1119687357 . AppSec Video Course: https://academy.wehackpurple.com/

View Details

Tanya Janca and guests Ron Brash, Dominique Righetto and Ray LeBlanc, meet up to discuss security fundamentals, the first chapter of Alice and Bob Learn Application Security. This two-hour, thought-provoking discussion covers;

  • Confidentiality, Integrity and Availability,
  • the merits of multi-factor authentication and what the factors are,
  • least privilege,
  • security by obscurity,
  • hard coding,
  • usable security

They also discussed answers to all of the questions at the end of chapter 1.

  1. Bob sets the Wi-Fi setting on his pacemaker to not broadcast the name of his Wi-Fi. What is this defensive strategy called?
  2. Name an example of a value that could be hard coded and why. (What would be the motivation for the programmer to do that?)
  3. Is a captcha usable security? Why or why not?
  4. Give one example of a good implementation of usable security.
  5. When using information from the URL parameters do you need to validate that data? Why or why not?
  6. If an employee learns a trade secret at work and then sells it to a competitor, this breaks which part(s) of CIA?
  7. If you buy a “smart” refrigerator and connect it to your home network, then have a malicious actor connect to it and change the settings so that it’s slightly warmer and your milk goes bad, which part(s) of CIA did they break?
  8. If someone hacks your smart thermostat and turns off your heat, which part(s) of CIA did they break?
  9. If a programmer adds an Easter egg (extra code that does undocumented functionality, as a “surprise” for users, which is unknown to management and the security team), does this qualify as an insider threat? If so, why? If not, why not?
  10. When connecting to a public Wi-Fi, what are some of the precautions that you could take to ensure you are doing “defense in depth”?
  11. If you live in an apartment with several roommates and you all have a key to the door, is one of the keys considered to be a “factor of authentication”?

We are hosting these live discussions monthly, until we have finished all 11 chapters. Each month their will be new guests (and some repeats!). Join us live, every 4th Saturday of 2021. Sign up for invites here.

Tanya Janca is the founder of We Hack Purple, a training academy and online community dedicated to teaching everyone how to make more secure software.