Research Insights Made Simple 3 Title: Security by Design at Google (Category Security)
In third episode We discuss Chirstoph Kern’s interesting whitepaper “Secure by Design at Google” on security with a human face from Google, which talked about how to create secure software on a large scale. In the analysis, a cool guest helps me - Artem Meretz, my colleague. Artem was a developer and 10 I moved to information security years ago. He actively built AppSec when it started in Russia as a stream, then became addicted to attacks and for several years broke the infrastructure and applications of various companies in Russia and abroad. S 2021 Artem helps build the protection of T-Bank as an architect.
The scientific article itself is available at Google, and my blog does. analysis
In this issue, we discussed the following topics: General impressions of the article Logical vulnerabilities and Google approaches
- Complexities of safe development Security by Design Concept Safety examples from the automotive industry
- Code audit problems Safe Design Principles
- Problems with invariants Automation and categorization of invariants
- Application of invariant Security problems in systems Examples of protection against malicious acts
- Design for safety Shift left everything in development Problems and solutions for security
- Yaga project in T-Bank
- Logical vulnerabilities Safe development ecosystem Problems with memory and microservice architecture Security and infrastructure problems The story of an intern-saboteur at ByteDance
- Artifact control and security Ecosystem for developers
#Architecture #Security #CI #CD #Devops #Software #Management #Leadership #Engineering #Podcast