I recently (in Sept and Nov respectively) gave two slightly different talks at OWASP events -- a short version and a long version -- on the ESAPI. The title of the talk was
OWASP ESAPI: A Retrospective - The Good, the Bad, & the Ugly
If you're brave enough (and dosed up with sufficient caffeine), take a listen:
- OWASP 20th Anniversary -
- OWASP Global AppSec US 2021 Virtual -
The main difference between the two talks is that I go into a bit more technical depth in the longer version.
All the talks have now been uploaded from both events and TBH, there are, IMO at least, several are way better than mine. You can find them all under the
OWASP YouTube channel, but to find the ones not explicitly listed on that page, you first need to click 'Play All' on the respective event.
If you listen to the ESAPI talks we'd be interested in knowing what you think.
-kevin
--