The Application Security Podcast

Jeff Williams -- The History of OWASP

• Chris Romeo and Robert Hurlbut

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 43:32

OWASP became a reference point for software security, but it began with people sharing knowledge and trying to solve problems together. Jeff Williams joins Chris to trace that early history, from their consulting roots to the first Top 10, the Foundation, and the growth of community events. He explains the tradeoffs behind an awareness list, the importance of independence, and why recognition alone does not make software safer. Their conversation also examines open-source project visibility, participation, and the difficulty of turning useful work into something more developers can discover and adopt. Jeff’s firsthand account offers both a history lesson and a challenge to the community: simplify security, communicate the value of its tools, and keep expanding who can contribute.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey

Connect with Jeff Williams:
→ Jeff Williams on LinkedIn
→ Contrast Security

Mentioned in this episode:
→ OWASP Foundation
→ OWASP Top 10
→ OWASP WebGoat
→ OWASP DefectDojo
→ OWASP Dependency-Check

Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook

Chapters:
00:00 OWASP’s history with Jeff Williams
01:39 Shared roots in security consulting
07:47 The early days of OWASP
11:13 Creating the first OWASP Top 10
14:22 Evidence, judgment, and the Top 10
17:48 Independence and outside interests
18:12 The Top 10’s growing influence
20:27 Simplifying the work of fixing vulnerabilities
23:15 Forming the Foundation and early conferences
29:46 Helping people discover OWASP projects
30:33 DefectDojo and communicating project value
33:20 Dependency-Check and broader adoption
35:49 Improving OWASP through participation

People on this episode

Podcasts we love

Check out these other fine podcasts recommended by us, not an algorithm.

AI Security Table Artwork

AI Security Table

Izar Tarandach, Matt Coles, and Chris Romeo