<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Application Security on Rietta Cybersecurity</title>
    <link>https://rietta.com/tags/application-security/</link>
    <description>Recent content in Application Security on Rietta Cybersecurity</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <copyright>1999-2026 Rietta Inc. All Rights Reserved.</copyright>
    <atom:link href="https://rietta.com/tags/application-security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>The Five Pillars of Information Security (And Why We Audit Accessibility)</title>
      <link>https://rietta.com/blog/five-pillars-infosec-ada-accessibility/</link>
      <pubDate>Sat, 25 Jul 2026 15:00:00 +0000</pubDate>
      <guid>https://rietta.com/blog/five-pillars-infosec-ada-accessibility/</guid>
      <description>Rietta is a cybersecurity firm. So why have the last three posts on this blog been about missing document titles, undefined languages, and metadata fields in government PDFs? My reasoning comes down to this: accessibility failures are security failures, specifically, they&amp;rsquo;re availability failures, and detecting them at scale is exactly the discipline our industry already practices.&#xA;To explain why, it helps to back up and lay out the actual model we use to reason about security in the first place.</description>
    </item>
    <item>
      <title>UUID as a secure API token for API RESTful endpoints? (Video)</title>
      <link>https://rietta.com/blog/uuid-api-security-token-video/</link>
      <pubDate>Tue, 14 May 2024 22:36:00 -0500</pubDate>
      <guid>https://rietta.com/blog/uuid-api-security-token-video/</guid>
      <description>In this video excert, I discussed the the role of the UUID as an API token and how to improve the security of an application when using them.&#xA;Specifically, the RFC 4122, Section 6 Security Considerations, cautions developers to &amp;ldquo;not assume that UUIDs are hard to guess; they should not be used as security capabilities (identifiers whose mere possession grants access), for example. A predictable random number source will exacerbate the situation.</description>
    </item>
    <item>
      <title>An Honest Conversation About Cyber Security (Video)</title>
      <link>https://rietta.com/blog/conversation-about-cyber-security/</link>
      <pubDate>Tue, 28 Nov 2023 10:00:00 -0500</pubDate>
      <guid>https://rietta.com/blog/conversation-about-cyber-security/</guid>
      <description>I recently sat down with Jeremy Duvall of 7Factor Software to discuss Cyber Security and application developers. We talk about the ins and outs of modern cyber security practices, weaknesses, how the development environment has changed and stayed the same over twenty years, and what small companies can do to impact improve security!</description>
    </item>
    <item>
      <title>Prioritizing cybersecurity (Pluralsight)</title>
      <link>https://rietta.com/blog/prioritizing-cybersecurity/</link>
      <pubDate>Wed, 27 Sep 2023 10:00:00 -0500</pubDate>
      <guid>https://rietta.com/blog/prioritizing-cybersecurity/</guid>
      <description>Vikas Rewani and I collaborated on an article about Prioritizing Cybersecurity for the Pluralsight blog last year.&#xA;I want to highlight here one of the topics that was discussed in the article, the importance of breaking down silos:&#xA;The structure and siloing of a large enterprise organization can thwart security efforts. For instance, security often lives under the IT umbrella, while software development is part of R&amp;amp;D.&#xA;Further, organizations may utilize a combination of technical resources—in-house, outsourced, onshore and offshore—all reporting to different people, who have varying business goals.</description>
    </item>
    <item>
      <title>How to win the race with hackers when new vulnerabilities are publicly disclosed!</title>
      <link>https://rietta.com/blog/win-cve-race-with-hackers-on-public-vuln-disclosure/</link>
      <pubDate>Tue, 04 Apr 2023 10:00:00 -0500</pubDate>
      <guid>https://rietta.com/blog/win-cve-race-with-hackers-on-public-vuln-disclosure/</guid>
      <description>My article written for security executives explaining the critical role of automated testing for long term application security is published! Those who have known and work with me know this topic has been close to my heart for while now. Most organizations are not mature enough to be able to patch within hours. However, we can do a lot better as a industry on proactive security in web app software.</description>
    </item>
    <item>
      <title>Snowfroc 2020 - Application Security and Development</title>
      <link>https://rietta.com/blog/snowfroc-2020-appsec-takeaways/</link>
      <pubDate>Wed, 01 Apr 2020 06:00:00 -0600</pubDate>
      <guid>https://rietta.com/blog/snowfroc-2020-appsec-takeaways/</guid>
      <description>I recently attended the Snowfroc conference that took place in Denver early this month. There were a number of talks about creating secure software in the context of a security team working with a development team from the outside, including one by our founder, Frank Rietta. I&amp;rsquo;ll be doing my best to condense the ideas from many of these talks into a single source. My sources are the following talks: Patch Production Now by Frank Rietta, Why Appsec is Hard for Devs by Scott Gerlach, and Climbing AppSec Mountains by Adam Schaal.</description>
    </item>
  </channel>
</rss>
