logo
episode-header-image
Aug 2022
16m 37s

Episode 109 - Verify and Verify Again

Mark and Allen
About this episode

Making sure our #VoiceFirst applications are written securely and use secure components is important. And when one of those components has a security bug, it is important that we update it as soon as we can. Mark highlights a recent security vulnerability in the node-forge module, which is used by the alexa-verifier-middleware module. Mark and Allen then discuss what the verifier does and how we can be careful when it comes to using libraries.

Some references:

  • alexa-verifier-middleware: https://www.npmjs.com/package/alexa-verifier-middleware
  • Alexa verification: https://developer.amazon.com/en-US/docs/alexa/custom-skills/host-a-custom-skill-as-a-web-service.html#manually-verify-request-sent-by-alexa
  • Issues with node-forge: https://github.com/advisories/GHSA-x4jg-mjrx-434g
Up next
Aug 13
From Google Glass to the Next Wearables Wave
In this episode, Allen Firstenberg is joined by guest host Cecilia Abadie, a computing pioneer who has been at the forefront of every major tech wave—from personal computers to mobile, wearables, and now AI. They look back on their shared roots at the 2012 Google Glass Foundry, t ... Show More
26m 38s
Aug 6
AI Agents: Six Lessons from Six Years of Two Voice Devs
Happy 6th Anniversary to Two Voice Devs! In this milestone episode, Mark Tucker and Allen Firstenberg look back at six years of podcasting and discuss how the industry is coming full circle. We started in the era of hardware assistants like Alexa and Google Assistant, shifted int ... Show More
26 m
Jul 16
The Intersection of AI, Fashion, Design, and Development
In this episode, Allen Firstenberg welcomes GDE Margaret Maynard-Reid as guest host to discuss the exciting intersection of AI, art, design, and fashion. Margaret shares her hands-on experiences testing Google's Gemini Omni Flash and Veo models, highlighting the game-changing cap ... Show More
22m 14s
Recommended Episodes
Aug 2024
Essential tools with critical security challenges. [Research Saturday]
Snir Ben Shimol from ZEST Security on their work, "How we hacked a cloud production environment by exploiting Terraform providers." In this blog, ZEST discusses the security risks associated with Terraform providers, particularly those from community sources. The research highlig ... Show More
22m 17s
Jun 2025
OWASP vulnerable and outdated components (noun) [Word Notes]
Please enjoy this encore of Word Notes. Software libraries, frameworks, packages, and other components, and their dependencies (third-party code that each component uses) that have inherent security weaknesses, either through newly discovered vulnerabilities or because newer vers ... Show More
8m 4s
Nov 2017
Revisions to the US VEP (and comparisons to China's). DPRK hacking. Laurel mole hunt. BlueBorne is back. Snakes in the Play Store. Can you sound like a child?
In today's podcast, we get an update on the US Vulnerabilities Equities Process, which now promises more transparency, accountability, and stakeholder representation in handling zero-days. A look at China's equivalent…doesn't. Worries about North Korean hacking. Mole hunting at F ... Show More
19m 11s
Apr 2025
OWASP security misconfiguration (noun) [Word Notes]
Please enjoy this encore of Word Notes. The state of a web application when it's vulnerable to attack due to an insecure configuration. CyberWire Glossary link: ⁠https://thecyberwire.com/glossary/owasp-security-misconfiguration⁠ Audio reference link: ⁠“What Is the Elvish Word for ... Show More
7m 3s
Jan 2023
Flagging firmware vulnerabilities. [Research Saturday]
Roya Gordon from Nozomi Networks sits down with Dave to discuss their research on "Vulnerabilities in BMC Firmware Affect OT/IoT Device Security." Researchers at Nozomi Networks has revealed that there are thirteen vulnerabilities that affect BMCs of Lanner devices based on the A ... Show More
15m 54s