Who Authorized That Tool Call?
Veracode I have been going to Black Hat for more than 25 years, and I have spent many of those years on the Review Board. New technologies keep changing the shape of the systems we secure. The questions I find myself asking stay remarkably familiar. Where does untrusted data enter? What authority does a component have? Which boundary controls a sensitive operation? How do we know that control worked?