Absolute AppSec podcast

Absolute AppSec

Ken Johnson and Seth Law

Subscribe
Share
A weekly podcast of all things application security related. Hosted by Ken Johnson and Seth Law.

1 Episode

  • Absolute AppSec podcast

    Episode 329 - AI exploitability, IDOR prevention, Smart TV Proxies

    7/28/2026

    In this episode, sponsored by GuardSquare (guardsquare.com), Ken Johnson and Seth Law discuss OpenAI's reported Hugging Face security incident, questioning whether the model demonstrated genuinely novel offensive capability or mostly chained known vulnerability patterns at high inference cost, while also considering the defense-contract and marketing angles around "dangerous" frontier models. The main technical discussion returns to AppSec fundamentals through an article on preventing IDOR, emphasizing authorization as a core control, the difficulty of role and tenant isolation in complex systems, and the need for framework-level patterns, typed IDs, tenant checks, and thorough authorization testing. They also cover Krebs' reporting on LG banning residential proxy SDKs from smart TV apps, explaining how free TV apps can turn consumer devices into proxy infrastructure and why IoT app ecosystems need stronger review. The episode closes with DEF CON logistics, Hacker Tracker updates, and upcoming guest plans.

Get the whole world of podcasts with the free GetPodcast app.

Subscribe to your favorite podcasts, listen to episodes offline and get thrilling recommendations.

iOS buttonAndroid button
  • Privacy Policy
  • Imprint
  • United States
© radio.de GmbH 2026radio.net logo
A company fromMADSACK