The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
The Application Security Podcast
Brett Smith -- Security is a Necessary Evil
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Brett Smith is a Software Architect/Engineer/Developer with 20+ years of experience. Specialties: Automation, Continuous Integration/Delivery/Testing/Deployment Expertise: Linux, packaging, and tool design. Brett joins us to discuss why he hates security and shares his vast knowledge of building a secure and cutting-edge build pipeline. We hope you enjoy this conversation with... Brett Smith is a software architect, engineer, developer with 20+ years of experience. His specialties include automation, continuous integration, delivery, testing, deployment, plus he has expertise in Linux packaging and tool design. Now, don't hang up right now. There's a lot more to his thoughts on security. He also has vast knowledge building a secure and cutting-edge build pipeline, and so he's going to walk you through the different phases and things that you need to be thinking about when building a secure build pipeline.
You are now listening to the Application Security Podcast brought to you by Security Journey.
About Security Journey
Hey folks, welcome to another episode of the Application Security Podcast.
→ Learn more about Security Journey
Connect with Brett Smith:
→ SLSA
→ in-toto
Mentioned in this episode:
→ SLSA
→ in-toto
→ Rekor (Sigstore)
→ OpenVEX spec
→ OWASP Threat Dragon
→ eBPF
→ GitHub Dependabot
→ VEX
→ Jenkins
→ Snyk
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet Brett Smith: Security is a Necessary Evil
01:19 I'm going to get to asking Brett his origin story in
08:30 So you wouldn't, you wouldn't give yourself the moniker or title
12:18 I mean, there is a weakest link, right
17:05 That's a good startup idea right there. Just follow somebody around
21:11 I mean, that's kind of like a bare minimum level of
23:14 Do you get to that exploitability and being able to measure
26:03 With eBPF, this is gonna be more from like, Linux-based applications
33:30 I've heard other people with that same idea. Back on the
38:10 Yeah, I mean, I think you've given us some different concepts
40:53 From a key takeaway perspective or a call to action, we've
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
The Security Table
Izar Tarandach, Matt Coles, and Chris Romeo