Hosted by Delta Systems
Listed under News › Tech News, Technology, Business › Entrepreneurship
Welcome to SaaS That App: Building B2B Web Applications. The podcast for those who are building or thinking about starting a tech-enabled business, especially a SaaS. We dive deep into the real stories behind tech startups - how they got started, the challenges they faced, and the lessons learned along the way.
63 episodes · publishes weekly · latest 2026-09-15 · ~37 min/episode
Rank
#583
Substance
76.8
/ 100
Breakdown
Scored 2026-09
Updated monthly
Across the index
#583 of 6203
Substance
Top 9%
outscores 91% of the index
SaaS That App ranks #583 on The B2B Podcast Index with a substance score of 76.8 out of 100, scored across 5 recent episodes. It scores highest on specificity & evidence and insight density. The episode names specific libraries (libvips, Rails Active Storage), tools (Dependabot, GitHub security scanning), affected services (AWS, OpenAI, Anthropic, Resend, SendGrid, Mailchimp), and provides concrete decision criteria (three personal friends vs. tens of thousands of users). However, the explanation lacks quantitative data on exploitation timelines, patch deployment metrics, actual downtime experienced, or comparative severity data across past CVEs. The vulnerability mechanics are described conceptually rather than with specific technical detail.
Averaged across 5 recently scored episodes, with cited evidence.
The episode delivers substantive technical information about CVE severity ratings, vulnerability exploitation paths, and practical remediation strategies. However, significant portions consist of banter, promotional content, and repetitive metaphors (Swiss cheese, concentric circles) that dilute the density of novel insights. The core vulnerability explanation and credential rotation discussion are solid but not exceptional.
“the vulnerability was specifically with file uploads. And I believe it had to do with. There was a check that's important to run on certain file uploads, it's not important to run on others. And there was a way to basically circumvent that check.”
“The patch was two steps. You had to make sure that your underlying library version, which in this particular case is called libvips, was sufficiently upgraded that it had the support for that flag that turned off this vulnerable thing.”
While the specific CVE discussion is timely and practical, the episode relies heavily on well-worn security frameworks (defense-in-depth, concentric circles of security, Swiss cheese model). The advice about credential rotation, patching, and network segmentation represents standard industry best practice rather than contrarian or first-principles thinking. No novel approaches to security posture or vulnerability response are introduced.
“So one of them is we call it concentric circles of security. So every individual circle is stupid, but the net sum of them together is how you stop from having these catastrophic failures.”
“The security answer to that is you assume that you're breached and you do all the rolling.”
Justin Edwards is a practitioner with direct operational experience managing this vulnerability in production systems across multiple customer environments. He demonstrates genuine technical depth, hands-on decision-making authority, and real-world remediation experience. He's not a researcher or talking head - he actually had to patch and manage fallout. This is higher-caliber guest work, though the format (co-host without outside perspective) limits the dimension somewhat.
“I've only seen a handful in my career. This is probably the second, second or third worst one that I've seen.”
“What we did immediately is we patched, we upgraded these library versions and uh, underlying library and then active storage versions and published everywhere that we was using that.”
The episode names specific libraries (libvips, Rails Active Storage), tools (Dependabot, GitHub security scanning), affected services (AWS, OpenAI, Anthropic, Resend, SendGrid, Mailchimp), and provides concrete decision criteria (three personal friends vs. tens of thousands of users). However, the explanation lacks quantitative data on exploitation timelines, patch deployment metrics, actual downtime experienced, or comparative severity data across past CVEs. The vulnerability mechanics are described conceptually rather than with specific technical detail.
“CVE is assigned to criticality on a scale of 1 to 10. And I don't think they actually ever issue a 10. So 9.5 is about as high as they can get.”
“There's one step to dump any file on the server or container down to the user, and two steps to do remote code execution.”
The host asks solid foundational questions and follows up appropriately (e.g., asking about decision-making for credential rotation, probing on frequency of similar issues). However, opportunities for productive pushback are missed. The conversation accepts Justin's security orthodoxy without challenge - there's no debate about cost-benefit trade-offs, no adversarial questioning about assumption-breach-and-rotate dogma, and no deep drilling into why certain practices are adopted vs. alternatives. The tone is collaborative rather than investigatively sharp.
“Was there a window of active exploitation? There was. And the most prudent thing to do would be to roll them if you're going to be 100% correct or anal retentive about it.”
“So is this stepping back from this particular situation, but these exploits in general that Might require this type of rolling of credentials across. Also presumably client structures and not M, just internal ones. How do you make the assessment or how do you decide that?”
4 periods tracked.
9 scored on substance · 62 tracked in total.
9.5 CVE, Zero Warning: Inside the Rails Active Storage Bug
2026-09-01 · 21 min
The $30K Invoice That Killed a 10-Year Customer Relationship
2026-07-28 · 27 min
SaaS Sales: The Playbook Every Founder Needs to Scale
2026-07-07 · 42 min
The 200-Hour SaaS Build: A Real Workflow Breakdown
2026-06-23 · 47 min
AI-Assisted Development in 2026
2026-06-09 · 46 min
Healthcare AI Is Failing And the Fix Isn't More Data
2026-05-26 · 30 min
Your Product Isn’t Ready for AI Until You Fix These Software Mistakes
2026-05-12 · 32 min
Why Most SaaS Companies Fail to Scale in the AI Era
2026-04-28 · 47 min
Hype or Game Changer? How Developers Are Actually Using Claude Code
2026-04-21 · 31 min
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/saas-that-app-building-tech-enabled-businesses" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/saas-that-app-building-tech-enabled-businesses/badge.svg" alt="Ranked #21 on The B2B Podcast Index" width="360" height="136" />
</a>Track SaaS That App's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
Companies, products and tools that come up most across this show's episodes.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.