Ken Johnson and Seth Law

Absolute AppSec

A weekly podcast of all things application security related. Hosted by Ken Johnson and Seth Law.

Author

Ken Johnson and Seth Law

Category

Technology

Podcast website

absoluteappsec.com

Latest episode

Jul 7, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 75: Brian Glas, OWASP Top 10, OWASPSAMM 19.11.2019

Ken and Seth are back! Joined in this episode by Brian Glas, aka @infosecdad, aka Professor Glas to talk about all things OWASP Top 10 2017, the path to his involvement, and how it almost split AppSec in two. Also a discussion on OWASPSAMM vs. OpenSAMM vs. BSIMM.

Episode 74: Ernest Mueller, DevOps, Security and Cloud Computing 23.10.2019

Ernest Mueller (@ernestmueller) joins Seth and Ken to talk about the his path into technology, operations, and security. Additional discussions on the beginnings of DevOps, Security, and Cloud Computing.

Episode 73: Kevin Cody, CORS, and Lockpicking 17.10.2019

Kevin Cody (@kevcody) is back with Seth and Ken to talk about his collaboration with Tim Tomes (@LaNMaSteR53) on CORS. Also discussions on lockpicking, travel tips, and a wide range of topics. Remember, CORS is a anti-security control.

Episode 72: Consulting Horror Stories 01.10.2019

Seth and Ken kickoff October with a discussion of consulting horror stories, both from personal experiences and listener-provided. Additional discussions around Cloudflare's WARP.

Episode 71: Evan Johnson, Cloudflare and Lastpass 17.09.2019

Eric Johnson (@ejcx_), one of the first podcast guests to join Seth and Ken revisits to talk about recent industry revelations, including the Lastpass vulnerability from Google's Project Zero. Further discussions on Cloudflare Access and ranging topics including Coke's 80s lawsuit involving trade secrets.

Episode 70: Andrew Wilson, OWASP and Training New AppSec Resources 03.09.2019

Andrew Wilson (@azwilsong) , a friend and partner at Bishop Fox joins Seth and Ken to discuss OWASP, running a consultancy, organizing CactusCon, and training new AppSec resources.

Episode 69: Eric Ellett, Development vs. Security 27.08.2019

Seth and Ken are joined by Eric Ellett (@EricEllett) to talk about software supply chain security. Development vs. Security and how to develop a good relationship with development instead of an antagonistic one.

Episode 68: Jerry Gamblin, DEF CON 27 Recap 19.08.2019

Jerry Gamblin (@jgamblin) joins Seth and Ken to talk about #hackersummercamp, DEF CON 27, and all things Vegas. Discussion includes NULL license plates, software bill of materials, and more.

Episode 67: Kubernetes Security with Stefan and Bobby 12.08.2019

Seth and Ken are joined by Stefan (@lojikil) and Bobby (@b0bbytabl3s) to talk about Kubernetes Security based on the assessment they conducted at Trail of Bits.

Episode 66: Capital One Breach, NPM, and Secure Code Reviews 30.07.2019

Seth and Ken discuss the latest news, including the Capital One Breach, Project Zero's recent iOS vusnerability disclosures, and further malicious NPM package takeovers. Further topics include learning who to trust and security code reviews.

Episode 65: Adam Baldwin, 3rd Party Dependencies, and Supply Chain Security 16.07.2019

Seth and Ken are joined by Adam Baldwin (@adam_baldwin) to discuss a topic we've been talking a lot about - 3rd party dependency and supply chain security. Adam gave a talk at this year's LocoMoco Security conference where he discuss fascinating and VERY relevant topics such as "developer burnout as an attack vector" as well as providing stats such as 97% of modern node applications rely on the co...

Episode 64: Hijacked Gems, Zoom RCE, and Marriott Fines 09.07.2019

Seth and Ken discuss conference proposals submissions and how to stand out. Also discussions on the latest security news, including the Zoom vulnerability disclosure, European fines for Marriott, and the latest hijacked/backdoored third-party library.

Episode 63: Julian Berton, AppSec Day, Developer Training, and Security Standards 02.07.2019

Julian Berton joins Seth and Ken to talk about Developer Training, Security Standards and AppSec Day, a global Application Security conference in Melbourne, Australia. They also discuss the latest lodash vulnerability and Boeing's outsourcing of developers.

Episode 62: Abdullah Munawar, Ben Pick, Global AppSec DC, and Running an OWASP Chapter 18.06.2019

Seth and Ken welcome Abdullah Munawar and Ben Pick to the show. They discuss their path into application security, current roles, and OWASP involvement. Specifically, Abdullah and Ben talk about running the OWASP NoVA chapter and challenges in organizing the Global AppSec DC conference.

Episode 61: Tanya Janca, DevSlop, Diversity, and Inclusion 11.06.2019

Based on demand, Seth and Ken are joined by Tanya Janca (@shehackspurple) to talk about all things OWASP, travel, and experinces. Topics include OWASP DevSlop, diversity, and inclusion

Episode 60: Stefan Edwards, Huawei, Android Security, and Programming Languages 21.05.2019

Seth is joined once again by Stefan Edwards to talk about current events and ruin another portion of information security. Topics include Huawei, Android Security, and Programming Languages.

Episode 59: James Wickett on DevOps 14.05.2019

Seth and Ken discuss Minecraft mod hacking and applying AppSec tools to the practice. Joined by James Wickett (@wickett) to talk about the history of DevOps, why software security people should learn to code, and current trends in the DevOps space.

Episode 58: David Lindner on RASP, Mobile, IoT 07.05.2019

Seth and Ken discuss Edge Side Include Injection. Subsequently joined by David Lindner (@golfhackerdave), the current head of AppSec at Contrast Security. David talks all about RASP, mobile and IoT security plus talk a little bit about appsec program building.

Episode 57: OWASP WIA (Women in AppSec) Committee 30.04.2019

Seth and Ken are joined by the OWASP WIA (Women in AppSec, @owaspwia) Committee. We discuss diversity in security and how the committee and OWASP is making the community more inclusive. Topics include first security conferences, how to get involved, and more.

Episode 56: Learn to Code / Loco Moco Sec Recap 23.04.2019

Seth and Ken get back together to talk about Loco Moco Sec and recent industry news. Specifically, should all security people be able to code? Is it a strict requirement? Ken gives his take on the talks from LocomocoSec and why we should all be there in 2020.

Episode 55: Stefan Edwards ruins Infosec - Testing Edition 18.04.2019

Seth is joined once again by Stefan Edwards. First in the series "Lojikil ruins Infosec". Ken is at LocomocoSec in Hawaii, so Seth and Stefan (@lojikil) talk all things testing, including symbolic execution, fuzzing, and why everything is awful. Seth becomes a nihilist.

Episode 54: Recon-NG and Burp Suite v2 with Tim Tomes 09.04.2019

Seth and Ken are joined by Tim Tomes, aka LaNMaSteR53. We discuss Tim's path into application security, his work on Recon-NG, and his analysis of Burp Suite Professional's version 2.

Episode 53: Building AppSec at Github with Greg Ose 02.04.2019

Seth and Ken talk AppCache vulnerabilities and postMessage exploits from PortSwigger's Top 10 web hacking techniques of 2018. Greg Ose joins them to talk about building application security programs, developer involvement, his background, and product security at Github.

Episode 52: Serialization Vulns, Managing Careers, and Hacking your Happiness with Chris Gates 26.03.2019

Seth and Ken talk about serialization vulnerabilities, number 6 in the top web hacking techniques of 2018. Discussions on continuous integration, hacking jenkins, reading code to find vulns, maintaining your edge, career growth, and hacking your happiness with Chris Gates.

Episode 51: XXE review and techniques, Assessment Reporting and Process with Jessica Ryan 19.03.2019

Seth and Ken talk about new techniques for exploiting XXE, number 7 in the top web hacking techniques of 2018. Discussions on assessment process, including reporting, note taking and soft skills with Jessica Ryan.

Listen to the Absolute AppSec podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.