loader from loading.io

SE Radio 658: Tanya Janca on Secure Coding

Software Engineering Radio - the podcast for professional software developers

Release Date: 03/06/2025

SE Radio 669: Will McGugan on Text-Based User Interfaces show art SE Radio 669: Will McGugan on Text-Based User Interfaces

Software Engineering Radio - the podcast for professional software developers

Will McGugan, the CEO and founder of Textualize, speaks with host about how to use packages such as Rich and Textual to build text-based user interfaces (TUIs) and command-line interfaces (CLIs) in Python. Along with discussing the design idioms that enable developers to create TUIs in Python, they consider practical strategies for efficiently rendering the components of a TUI. They also explore the subtle idiosyncrasies of implementing performant TUI frameworks like Textual and Rich and introduce the steps that developers would take to create their own CLI or TUI. This episode is sponsored...

info_outline
SE Radio 671: Carson Gross on HTMX show art SE Radio 671: Carson Gross on HTMX

Software Engineering Radio - the podcast for professional software developers

In this episode, SE Radio host explores HTMX with its creator, Carson Gross, who is also creator of Hyperscript, the mind behind the Grug Brained Developer, a professor of software engineering at Montana State University, and co-author of . HTMX is a modern JavaScript library that allows developers to access AJAX, WebSockets, CSS Transitions, and Server-Sent Events directly in HTML using attributes. It represents a return to hypermedia-driven application architecture while supporting modern user experiences. The episode starts with a look at the current complexity in web development and...

info_outline
SE Radio 670: Matthias Endler on Prototype in Rust show art SE Radio 670: Matthias Endler on Prototype in Rust

Software Engineering Radio - the podcast for professional software developers

Matthias Endler, Rust developer, open-source maintainer, and consultant through his company Corrode, speaks with SE Radio host about prototyping in Rust. They discuss prototyping and why Rust is excellent for prototyping, and Matthias recommends a workflow for it, including what parts of Rust to use, and what parts to avoid at this stage. He describes the key components that Rust provides to help us validate ideas via prototypes, as well as tips and tricks to reach for.  In addition, the conversation explores type inference, unwrap(), expect(), anyhow crate, bacon crate, cargo-script,...

info_outline
SE Radio 668: Steve Summers on Securing Test and Measurement Equipment show art SE Radio 668: Steve Summers on Securing Test and Measurement Equipment

Software Engineering Radio - the podcast for professional software developers

Steve Summers speaks with SE Radio host  about securing test and measurement equipment. They start by differentiating between IT and OT (Operational Technology) and then discuss the threat model and how security has evolved in the OT space, including a look some of the key drivers. They then examine security challenges associated with a specific device called a CompactRIO, which combines a Linux real-time CPU with a field programmable gate array (FPGA) and some analog hardware for capturing signals and interacting with real-world devices. Brought to you by  and .

info_outline
SE Radio 667: Ashley Peacock on Cloudflare show art SE Radio 667: Ashley Peacock on Cloudflare

Software Engineering Radio - the podcast for professional software developers

Ashley Peacock, the author of Serverless Apps on Cloudflare, speaks with host Jeremy Jung about content delivery networks (CDNs). Along the way, they examine dependency injection with bindings, local development, serverless, cold starts, the V8 runtime, AWS Lambda vs Cloudflare workers, WebAssembly limitations, and core services such as R2, D1, KV, and Pages. Ashley suggests why most users use an external database and discusses eventually consistent data stores, S3-to-R2 migration strategies, queues and workflows, inter-service communication, durable objects, and describes some example...

info_outline
SE Radio 666: Eran Yahav on the Tabnine AI Coding Assistant show art SE Radio 666: Eran Yahav on the Tabnine AI Coding Assistant

Software Engineering Radio - the podcast for professional software developers

Eran Yahav, Professor of Computer Science at Technion, Israel, and CTO of Tabnine, speaks with host about the Tabnine AI coding assistant. They discuss how the design and implementation allows software engineers to use code completion and perform tasks such as automated code review while still maintaining developer privacy. Eran and Gregory also explore how research in the field of natural language processing (NLP) and large language models (LLMs) has informed the features in Tabnine. Brought to you by  and .

info_outline
SE Radio 665: Malcolm Matalka on Developing in OCaml with Zero Frameworks show art SE Radio 665: Malcolm Matalka on Developing in OCaml with Zero Frameworks

Software Engineering Radio - the podcast for professional software developers

Malcolm Matalka, founder of Terrateam, joins host  to talk about the reasoning behind choosing a not-so-widespread language (OCaml) and (almost) totally avoiding frameworks for the development of Terrateam. While discussing the reasons for choosing this specific programming language and the advantages and disadvantages of using external frameworks, they also consider a range of related topics, including static vs. dynamic typing, the use of monorepos, and the advantages of choosing a single language that can be used both for web front ends and server back ends. The episode ends with...

info_outline
SE Radio 664: Emre Baran and Alex Olivier on Stateless Decoupled Authorization Frameworks show art SE Radio 664: Emre Baran and Alex Olivier on Stateless Decoupled Authorization Frameworks

Software Engineering Radio - the podcast for professional software developers

Emre Baran, CEO and co-founder of Cerbos, and Alex Olivier, CPO and co-founder, join SE Radio host to explore “stateless decoupled authorization frameworks. The discussion begins with an introduction to key terms, including authorization, authorization models, and decoupled frameworks. They dive into the challenges of building decoupled authorization, as well as the benefits of this approach and the operational hurdles. The conversation shifts to Cerbos, an open-source policy-based access control framework, comparing it with OPA (Open Policy Agent). They also delve into Cerbos’s technical...

info_outline
SE Radio 663: Tyler Flint on Managing External APIs show art SE Radio 663: Tyler Flint on Managing External APIs

Software Engineering Radio - the podcast for professional software developers

Tyler Flint, CEO of , joins host Robert Blumen for a conversation about managing external vendor dependencies, including several best practices for adoption. They start with a look at internal versus external services, including details such as the footprint of external services within a micro-services application, and difficulties organizations have tracking their service consumption, quantifying service consumption, and auditing external services. Tyler also discusses the security implications of external services, including authentication and authorization. They examine metrics and...

info_outline
SE Radio 662: Vlad Khononov on Balancing Coupling in Software Design show art SE Radio 662: Vlad Khononov on Balancing Coupling in Software Design

Software Engineering Radio - the podcast for professional software developers

Software architect and author Vlad Khononov joins host for a discussion on balancing coupling in software design. They start by examining coupling and its relationship to complexity and modularity. Vlad explains the historical models for assessing coupling and introduces his updated approach, integration strength, which aims to simplify earlier frameworks and adapt them for modern practices. The episode explores three dimensions of coupling: integration strength (knowledge sharing), distance (proximity of components), and volatility (likelihood of change). Vlad illustrates how design...

info_outline
 
More Episodes

Tanya Janca, author of Alice and Bob Learn Secure Coding, discusses secure coding and secure software development life cycle with SE Radio host Brijesh Ammanath. This session explores how integrating security into every phase of the SDLC helps prevent vulnerabilities from slipping into production. Tanya strongly recommends defining security requirements early, and discusses the importance of threat modeling during design, secure coding practices, testing strategies such as static, dynamic, and interactive application security testing (SAST, DAST and IAST), and the need for continuous monitoring and improvement after deployment.

This episode is sponsored by Codegate.ai