The Application Security Podcast

Mark Curphey and John Viega -- Chalk

Chris Romeo Season 10 Episode 22

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 55:23

Development, operations, and security teams generate oceans of data yet still struggle to answer basic questions about what code is running, who owns it, and which findings matter. OWASP founder Mark Curphey and security veteran John Viega introduce Chalk, an open-source telemetry and observability tool designed to connect repositories, builds, deployments, and production systems. They explain how better provenance can eliminate irrelevant alerts, prioritize deployed software, trace incidents back to owners and commits, and confirm that fixes actually reached production. The conversation covers small-company and enterprise use cases, lessons from Log4Shell, performance overhead, supported platforms, and Chalk’s event model. Mark and John also discuss open-source sustainability and the Software Security Project before closing with candid views on where application security gets priorities wrong.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Mark Curphey and John Viega:
Mark Curphey on LinkedIn
John Viega on LinkedIn
Chalk
Crash Override

Mentioned in this episode:
Crash Override
Chalk
The Software Security Project
Atomic Habits
Start With Why
OWASP ZAP
Sigstore

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Meet Mark Curphey and John Viega: Chalk
01:46 John’s path into application security
04:20 The de facto silos separating development and production
07:52 Chalk as telemetry for software engineering
12:12 Why startups also need production visibility
15:18 Log4Shell and the challenge of finding deployed software
17:08 How security teams can use Chalk
23:10 Chalk’s performance impact in production
25:00 Supported platforms and frameworks
28:00 Events, protocols, and outbound telemetry
42:18 Holding commercial users of open source accountable
46:32 Controversial opinions about AppSec
48:09 Industry messages, books, and closing thoughts

Follow the Application Security Podcast:

➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast

People on this episode

Podcasts we love

Check out these other fine podcasts recommended by us, not an algorithm.

The Security Table Artwork

The Security Table

Izar Tarandach, Matt Coles, and Chris Romeo