
Play Stupid Games, Win Stupid Prizes by SinisterMatrix - HTB Village at H@ctivityCon 2021
Source: YouTube · Hack The Box · published Sep 22, 2021 · 27:52
The video explores the tension between security and development teams, advocating for security integration throughout the development lifecycle rather than treating it as an afterthought 14:22.
Key Takeaways:
• Security teams focus on threat detection and response, while development teams prioritize delivering functional code quickly, creating an inherent clash in priorities 2:14-3:23
• Secure coding is essential to prevent data breaches, maintain customer trust, and avoid costly retroactive fixes 8:01-9:01
• Basic secure coding practices include code obfuscation, avoiding shortcuts, using automated scanning, and proper auditing 10:01-14:22
• "Shifting left" means addressing security earlier in the development lifecycle rather than waiting until the testing phase 15:05-17:44
Effective collaboration between security and development teams requires building a culture of security, providing proper training, implementing security champions, and utilizing automated tools 19:49-27:32.
Sources:
- 2:14-3:23 Discussion of the divide between security and development team priorities
- 8:01-9:01 Explanation of why secure coding matters in today's landscape
- 10:01-14:22 Basic secure coding checklist and best practices
- 14:22-17:44 Concept of "shifting left" in security testing
- 19:49-27:32 Proposed solutions for security-development collaboration
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
welcome everyone welcome to play stupid games win stupid prizes so just a quick who am i my current role is community coordinator to hack the box i pretty much oversee the meetups program coordinate sponsorships at b2c events and also help with moderation of hack the box discord my previous experience i started my journey in infosec kind of in the it world so i started as a junior i.t administrative kind of consultant and i basically provided consultancy service within the private public sector hobbies i have many hobbies but one of my favorites is definitely music i actively enjoy listening to many different genres and also play guitar as well both acoustic and electric i enjoy ctfs i'm actually currently the team captain emeritus of cxp i love doing cyber security research especially res…