OWASP at 23 Years: What Changed and What Didn’t

▶ Watch (4:07)

The OWASP Top 10 dates to 2003. Cross-site scripting was the top risk then and remained in the list for nearly two decades. Modern frameworks like React and Next.js largely neutralize it when used as intended. OWASP started with three people and now counts 345 projects and 8,339 members. The founding chapters in Los Angeles and London still meet. OWASP enforced SSL on its own website only after 2011, nine years after the site launched.

Password Rotation Was Never the Answer

▶ Watch (6:00)

The first password strength paper came from 1979. Robert Morris and Brian Kernighan measured 760 hours to crack all upper and lowercase password combinations on a PDP-11, running only at nights and weekends. Their paper recommended one-way hashing and salting. The standard derived from it mandated rotation instead. Smartphones are roughly a billion times faster than a PDP-11. There is no rotation interval fast enough to outpace modern cracking. NIST 800-63B prohibits mandatory rotation. OWASP ASVS has prohibited it since 2017.

Projects Built for the Wrong Audience

▶ Watch (19:41)

OWASP’s 345 projects assume waterfall development and target AppSec professionals. Most developers never encounter them. A developer tool that does not add value every working moment will not get used. Van der Stock wants OWASP inside developer IDEs. Cloud and CI/CD must become first-class targets, since infrastructure is now code. OWASP spent up to $30,000 per year exhibiting at RSA and Black Hat. Developers at PyCon this year had not heard of OWASP. That money should shift to developer conferences.

Building an Academic Foundation for AppSec

▶ Watch (23:13)

Application security has no standard academic home. Van der Stock wants OWASP to publish an open curriculum that any university can adopt, including those in developing nations without the budget to build their own. Every software engineering degree should include at least one AppSec module. Security is a discipline, the same way structural engineering is one specialization within engineering. Open textbooks would remove the cost barrier. Van der Stock’s target: at least a semester-long syllabus that any lecturer can pick up and teach.

AI Will Reshape Penetration Testing

▶ Watch (33:14)

Van der Stock predicts most basic penetration testing will be handled by bots within 25 years. Skilled practitioners will supervise AI rather than run scans themselves. Scanning tools will gain AI components that outperform today’s automated approaches. AI cannot take responsibility for outcomes. He demonstrated the problem with an image generator: prompt “kiwis” and you get the bird and the nationality, because the model cannot tell which you want. How to oversee AI at scale is, in van der Stock’s framing, the open question.

Membership, Funding, and the Next Generation

▶ Watch (36:38)

OWASP has 8,339 paying members at $50 per year. Van der Stock’s three-year target is 16,000, enough to make the foundation self-sustaining on membership alone. Events do not scale the same way: doubling venue size more than doubles cost. Membership scales linearly. The next-generation problem is personal. Van der Stock is 54, with 13 to 17 years left in his career. People at his level need to actively train mid-level AppSec practitioners, who in turn bring up early-career entrants.

Notable Quotes

password rotation was a good idea even Andrew van der Stock · ▶ Watch (6:43)

it’s just not going to get used just not Andrew van der Stock · ▶ Watch (21:11)

we’ve got 26,000 people in slack Andrew van der Stock · ▶ Watch (15:56)

54 I have basically 13 to 17 years left Andrew van der Stock · ▶ Watch (37:33)

Key Takeaways

  • NIST 800-63B and OWASP ASVS both prohibit mandatory password rotation. Stop enforcing it.
  • OWASP’s 345 projects must reach developers inside their IDEs; most PyCon attendees had never heard of OWASP.
  • Basic penetration testing will be AI-supervised within 25 years, but human oversight at scale remains an open problem.

About the Speaker(s)

Andrew van der Stock is a web application security specialist and enterprise security architect. He has served as Executive Director of the OWASP Foundation since June 2020, making him the organization’s longest-serving person in that role. He co-leads the OWASP Top 10, helped lead the ASVS 4.0 release, and released the Developer Guide 2.0 in 2005. He has worked in application security since 1998.