The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
The Application Security Podcast
Neil Matatall -- AppSec at Scale
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Neil Matatall is an engineer with a background in security. He has previously worked at GitHub and Twitter and is a co-founder of Loco Moco Product Security Conference. Neil joins us for his second visit, to discuss account security at scale. He describes the underlying principles behind security at scale, how he worked to build a sign-in analysis feature, and how attacks were detected. We ended the conversation with an authentication lightning round, with Neil responding to various statements about authentication off the cuff! We hope you enjoy this episode with Neil Matatall. He's previously worked at GitHub and Twitter and is a co-founder of the LocoMoco Product Security Conference.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Neil Matatall is an engineer with a background in security.
→ Learn more about Security Journey
Connect with Neil Matatall:
→ Loco Moco Product Security Conference
→ Have I Been Pwned
Mentioned in this episode:
→ Loco Moco Product Security Conference
→ Have I Been Pwned
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet Neil Matatall: AppSec at Scale
05:46 Any kind of other thoughts on that from that perspective about
07:28 Something like, well, I was going to borrow it and use
10:19 You've sort of, I think, spoken to this in terms of
13:13 Did you build this sign-in analysis piece
20:14 The thing I love that you're bringing out in this conversation
24:57 Do I need to change it now
27:20 You've talked about quite a few ways of detecting the different
30:18 Using the API example, let's play this one out a little
34:32 No, that's neat that GitHub detects that as they come in
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
AI Security Table
Izar Tarandach, Matt Coles, and Chris Romeo