Ken Johnson and Seth Law
Absolute AppSec
A weekly podcast of all things application security related. Hosted by Ken Johnson and Seth Law.
Author
Ken Johnson and Seth Law
Category
Podcast website
Latest episode
Jul 7, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 100: Virtual Conferences, Bots, DDoS, Ebay 16.06.2020
Seth and Ken break the 100 episode barrier by talking about virtual conferences. Discussions about bots, distributed denial of service attacks, and Ebay stalking of a newsletter.
Episode 99: Contact Tracing, GnuTLS, Breaches 09.06.2020
Seth and Ken are back to security and technology this week. Discussions about contact tracing applications, privacy and freedom vs. security, the GnuTLS CVE, and possible Honda breach.
Episode 98: Bug Bounty Programs, Work when World is Crazy 02.06.2020
Seth and Ken go full rant mode about bug bounties and trying to work while the world goes insane.
Episode 97: Stefan Edwards and Brian Glas - Threat Modeling 26.05.2020
Stefan (@lojikil) and Brian (@infosecdad) are back to talk about threat modeling with Seth and Ken. Discussion covers risk assessment, threat modeling, asset inventory, and software maturity.
Episode 96: Fuzzing and Static Analysis Tools 19.05.2020
Seth and Ken discuss fuzzing techniques, recommendations, and experience. Stories of fuzzing in production. How static analysis tools have changed and where they fit.
Episode 95: Jessica Rozhin (@JessicaRozhin) and Lady Christina Liu (cliuthulu) - Incident Response, Lockpicking, Building an Infosec Culture 12.05.2020
Jessica Rozhin (@JessicaRozhin) and Lady Christina Liu (@cliuthulu) join Seth and Ken to talk about alternate routes into security, including accounting and joining a circus. Discussions on forensics, incident response, and how lock picking can help build an infosec culture.
Episode 94: Bug Bounty, Microservices vs. Monoliths, and CVE Fatigue 05.05.2020
Seth and Ken discuss tips for running a bug bounty program, risk of webhooks, Segment's move to and from microservices, and having CVE Fatigue.
Episode 93: Huntr Dev - Securing Open Source Software 21.04.2020
Seth and Ken are joined by the Huntr Dev team to talk about securing open source software, bug bounties, and writing secure code.
Episode 92: Working from Home, Skreen, Evolution of AppSec 14.04.2020
Seth struggles with internet access during a discussion with Ken on working from home, employee surveillance, and Sneek. Additional thoughts on the evolution of application security and penetration testing since the beginning of our careers.
Episode 91: Stefan Edwards - More Voatz, Zoom, Code Reviews, Report Writing, Threat Models, and Risk Assessments 07.04.2020
LOJI IS BACK! Stefan joins Seth and Ken to talk about his work on Trail of Bits assessment of the Voatz mobile application, share thoughts on Zoom, and discuss the assessment process. Discussions on report writing, risk assessments, threat modeling, and other appsec goodness.
Episode 90: Voatz, HackerOne, Bug Bounties, GraphQL, Shodan Network Trends 31.03.2020
Seth and Ken provide their take on the Voatz mobile app dismissal from HackerOne. Additional discussion of network trends during social distancing and COVID-19 as reported by Shodan. Finally some thoughts on the new OWASP Firmware Testing Guide and InQL, a GraphQL Burp Suite Pro plugin.
Episode 89: Kat Sweet - Incident Response, DevOps and Developer Training, Breaking into Security 24.03.2020
Kat Sweet (@TheSweetKat) continues our discussion from DevSecOps Days Austin. Topics include incident response, staying right while you push left, developer training, and getting into information security.
Episode 88: Kevin Johnson - Secure Ideas, Star Wars, Passing it On 17.03.2020
Kevin Johnson of Secure Idea joins Seth and Ken in a discussion on his path into security, Star Wars (yes, really), and giving back to the community. This includes passing on teaching, sharing knowledge, and mentoring those that ask for it.
Episode 87: Abhay Bhargav - Threat Modeling, DevSecOps, Microservices 03.03.2020
Abhay Bhargav, founder of We45, joins Seth and Ken in a discussion on threat modeling in an agile development methodology, the rise and role of DevSecOps, and security within microservices.
Episode 86: Rohan Johsi - QA Security Testing, Security Champions, Paypal Vulnerabilities 25.02.2020
Seth and Ken discuss bug bounties and a recent article on Paypal issues. Joined by Rohan Joshi to discuss building an application security program, QA security testing, and security champions.
Episode 85: David Lindner - Voting Apps, Bug Bounties, IAST/RASP/WAF 18.02.2020
David Lindner (@golfhackerdave) joins Seth and Ken discuss the voting applications, including the Iowa debacle and the Voatz application. Ranting on bug bounties and response times for researcher findings. An explanation of IAST, RASP, and WAFs.
Episode 84: Tinfoil Hat Tuesday - Backdoors, Application Libraries, Equifax 11.02.2020
Seth and Ken discuss the latest security news, including CIA Backdoors in the Crypto AG products, FBI release of wanted Chinese nationals related to the Equifax breach, protecting applications against nation state actors, and securing open source libraries.
Episode 83: Ron Perris - NPM, Developer Training, React 06.02.2020
Ron Perris (@ronperris), Software Security Engineer from npm, Inc. joins Seth and Ken to talk about module security, developer interactions, and recent node security issues. DOM Clobbering.
Episode 82: Kelley Robinson - MFA, SHAKEN, STIR 28.01.2020
Kelley Robinson (@kelleyrobinson), Security Advocate at Twilio/Authy joins Seth and Ken to talk about multifactor authentication, her path into security, and advances in voice security (SHAKEN/STIR).
Episode 81: Matias Madou - Application Security Training 21.01.2020
Ken and Seth are joined by Matias Madou, CTO of Secure Code Warrior. Discussion of current state of application security training, static analysis tools, and just-in-time-training.
Episode 80: Louis Barratt - SIRT and AppSec 14.01.2020
Louis Barrett of the Segment SIRT team joins Seth and Ken to discuss his path into security, mentors, and SIRT. Discussions on approaching SIRT, creating a SIRT team, and how to integration AppSec into the SIRT.
Episode 79: Live from DevSecOpsDays Austin - Next up in AppSec/DevSecops 17.12.2019
Seth and Ken host the podcast live from DevSecOpsDays Austin, with multiple guests from conference speakers. Discussions on what each guest feels is up next in AppSec and DevSecOps for the forseeable future.
Episode 78: Breaches, Passwords, and Chicken Fingies 10.12.2019
Seth and Ken host Seth and Santa's Secure Workshop as a pair this week. The discussion revolves around the Hacker 1 "breach", Practical Pentest Lab's storage and sending of plaintext passwords, chicken fingie injection, and toxicity of infosec social media. May or may not be a discussion on squirrels and pigeons in cowboy hats.
Episode 77: Clint Gibler, DevSecOps, TLDR; Sec 03.12.2019
Seth and Ken are joined this week by Clint Gibler (@clintgibler) to talk about DevSecOps, what he sees in the industry as effective security, and his newsletter TLDR; Sec (https://bit.ly/tldrsec). Comments on prioritization, asset inventory, and effectively quashing bug classes.
Episode 76: Guy Podjarny, Snyk, AppScan, SCA 26.11.2019
Guy Podjarny (@guypod), founder of Snyk, joins Ken and Seth to talk about Snyk, the origins of AppScan Standard, Software Composition Analysis and his origin story. A discussion of building developer focused security tools and how this can benefit security in the long run.
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.