2016 AppSec USA – An Update on the WebGoat Project

WebGoat is a deliberately insecure web application maintained by OWASP designed to teach web application security lessons. It is one of the most used projects at OWASP. With the current team headed by Bruce Mayhew, Nanne Baars and Jason White, work is moving forward on the creation of new content for creating training lessons for

The Low Cost of High Caliber Developers

There is a vast difference in individual developer productivity.  You could argue that for certain intractable problems that there is an infinite difference in productivity since some developers will just never be able to solve a certain problem in any period of time.  Also, one of the hardest things in software is keeping everything as

Modern Software: A Shell Game of Near Infinite Dimensions

“While we can delegate the authority to write large portions of our applications to the open source community, the ultimate responsibility for quality remains our own.“ — Mike Hansen For decades, software development generally required that teams write their entire application stack.  Early on, there was a little help from the operating system and then

Mad Men

Mad Men and What You Need to Know About Their Software

Plot Summary: Who would buy food without knowing what’s in the package? When is the last time you went to the grocery store  and just threw stuff into your basket without at least a cursory glance at the ingredient list? The dilemma is, it’s not just the consumer who doesn’t know the ingredients  in the software package,  the creators