<description>&lt;p&gt;Not all infosec advice is helpful. Bad advice wastes time, makes people less secure, and takes focus away from making software more secure. Bob Lord talks about his efforts to tamp down hacklore -- the security myths and mistakes that crop up in news stories and advice to users. He talks about how these myths come about, why they're harmful, and how they're related to the necessity of building software that's secure by design.&lt;/p&gt; &lt;p&gt;Segment Resources:&lt;/p&gt; &lt;ul&gt; &lt;li&gt; &lt;p&gt;&lt;a href="https://www.hacklore.org/" target="_blank" rel= "noopener"&gt;https://www.hacklore.org/&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; &lt;li&gt; &lt;p&gt;&lt;a href= "https://medium.com/@boblord/lets-stop-hacklore-d5c86a0fdad8" target="_blank" rel= "noopener"&gt;https://medium.com/@boblord/lets-stop-hacklore-d5c86a0fdad8&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; &lt;li&gt; &lt;p&gt;&lt;a href="https://www.cisa.gov/securebydesign" target="_blank" rel="noopener"&gt;https://www.cisa.gov/securebydesign&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; &lt;li&gt; &lt;p&gt;&lt;a href= "https://medium.com/@boblord/recurring-classes-of-software-weaknesses-2007-vs-2025-c2cd56125e1a" target="_blank" rel= "noopener"&gt;https://medium.com/@boblord/recurring-classes-of-software-weaknesses-2007-vs-2025-c2cd56125e1a&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; &lt;li&gt; &lt;p&gt;&lt;a href= "https://www.ncsc.gov.uk/report/a-method-to-assess-forgivable-vs-unforgivable-vulnerabilities" target="_blank" rel= "noopener"&gt;https://www.ncsc.gov.uk/report/a-method-to-assess-forgivable-vs-unforgivable-vulnerabilities&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; &lt;li&gt; &lt;p&gt;&lt;a href= "https://99percentinvisible.org/episode/nut-behind-wheel/" target= "_blank" rel= "noopener"&gt;https://99percentinvisible.org/episode/nut-behind-wheel/&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; &lt;li&gt; &lt;p&gt;&lt;a href= "https://timharford.com/2022/05/cautionary-tales-short-a-screw-loose-at-17000ft/" target="_blank" rel= "noopener"&gt;https://timharford.com/2022/05/cautionary-tales-short-a-screw-loose-at-17000ft/&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; &lt;/ul&gt; &lt;p&gt;Visit &lt;a href="https://www.securityweekly.com/asw" target= "_blank" rel="noopener"&gt;https://www.securityweekly.com/asw&lt;/a&gt; for all the latest episodes!&lt;/p&gt; &lt;p&gt;Show Notes: &lt;a href="https://securityweekly.com/asw-365" target= "_blank" rel="noopener"&gt;https://securityweekly.com/asw-365&lt;/a&gt;&lt;/p&gt;</description>

Application Security Weekly (Audio)

Security Weekly Productions

Secure By Design Is Better Than Secure By Myth - Bob Lord - ASW #365

JAN 13, 202653 MIN
Application Security Weekly (Audio)

Secure By Design Is Better Than Secure By Myth - Bob Lord - ASW #365

JAN 13, 202653 MIN

Description

Not all infosec advice is helpful. Bad advice wastes time, makes people less secure, and takes focus away from making software more secure. Bob Lord talks about his efforts to tamp down hacklore -- the security myths and mistakes that crop up in news stories and advice to users. He talks about how these myths come about, why they're harmful, and how they're related to the necessity of building software that's secure by design. Segment Resources: https://www.hacklore.org/ https://medium.com/@boblord/lets-stop-hacklore-d5c86a0fdad8 https://www.cisa.gov/securebydesign https://medium.com/@boblord/recurring-classes-of-software-weaknesses-2007-vs-2025-c2cd56125e1a https://www.ncsc.gov.uk/report/a-method-to-assess-forgivable-vs-unforgivable-vulnerabilities https://99percentinvisible.org/episode/nut-behind-wheel/ https://timharford.com/2022/05/cautionary-tales-short-a-screw-loose-at-17000ft/ Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-365