Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Risky Biz Podcast: Making Reachability Analysis Work in Real...

Blog post from Socket

Post Details
Company
Date Published
Author
Sarah Gooding
Word Count
330
Company Posts That Month
22
Language
English
Hacker News Points
-
Post removed?
No
Summary

In this episode of the Risky Business podcast, host Patrick Gray and Socket founder Feross Aboukhadijeh discuss the complexities of reachability analysis in vulnerability management, especially in the context of real-world codebases. They address the challenges posed by static analysis and dynamic languages like JavaScript and Python, highlighting the frequent issue of scanners overwhelming teams with alerts that may not indicate actual vulnerabilities. Feross elaborates on Socket's innovative approaches to reachability, including Tier 1 analysis of full application and dependency trees, which significantly reduces noise, and Tier 2 precomputed reachability, which simplifies scaling by using manifest files. The conversation also touches on insights from Socket’s work with Fortune 50 companies, such as the prevalence of "phantom dependencies" and the complexity of managing extensive dependency trees. The acquisition of Coana has enriched Socket's methods with academic research, enhancing their strategies for prioritizing vulnerabilities in dynamic languages.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.