Explore why security often fails and discover practical solutions in this 24-minute OWASP Foundation talk by Richard Ford, CTO of Praetorian. Delve into real-world examples from security assessments, ranging from basic cloud misconfigurations to sophisticated nation-state level attacks. Learn valuable lessons from the field and understand how these insights can be translated into open-source products. Examine whether security truly needs to be as challenging as it often appears, or if smarter approaches can simplify the process. Gain actionable steps to enhance your security practices, including insights on versioning, automation, access control, and low-noise tools. Discover the concept of LocalExec and its implications for command injection vulnerabilities. Conclude with an introduction to SnowCamp and practical solutions to common security challenges.
Why Security Fails and How to Solve It - Lessons from Real-World Assessments