Listen to the Security by Default Podcast Now
-
Passwords, Passkeys & Rogue AI Agents | Credentials in the Age of AI with Evil Mog
We assert that agentic AI constitutes a profound and immediate threat to passwords, passkeys, and credential stewardship when such agents are afforded unfettered operational or contractual authority without deterministic guardrails. I describe, with technical specificity, how agents that hold passkeys or password-manager access can act autonomously to transact, alter accounts, or execute legally binding operations,… Read more
-
From Legacy to Modern PAM: A Migration Playbook with Erik Siebler
Navigating the intricate landscape of identity security has evolved dramatically over the past two decades. Once characterized by a mere username and password, the contemporary environment demands that employees manage an astonishing array of digital identities—approximately one hundred per individual, not accounting for the emerging complexities introduced by agentic AI. Joe Carson engages Erik Siebler,… Read more
-
Navigating the Convergence of Physical Security and Digital Access | Daniel Raines
Daniel Raines, a luminary in the realm of electronic security, shares his extensive journey through the intricate landscape of physical security and digital access. With three decades of experience, he has transitioned from hands-on installation of access control systems to software development, addressing vulnerabilities and enhancing security measures. Our discourse delves into the convergence of… Read more
-
L0pht Legend Chris Wysopal on the Evolution of Application Security
Chris Wysopal, a distinguished figure in the realm of cybersecurity and a celebrated L0pht legend, engages in a profound dialogue with Joe Carson, delving into his remarkable journey from scavenging for Unix manuals to pioneering modern application security. Central to the discussion is the evolution of application security practices, particularly as they pertain to the… Read more
-
Ransomware Unmasked: Inside the World’s Biggest Cybercrime Gang | Geoff White
The discourse surrounding ransomware takes center stage as we engage with investigative journalist Geoff White, whose extensive research delves into the notorious Conti Ransomware gang. This episode elucidates the profound implications of ransomware attacks, which have escalated beyond mere data encryption to encompass severe extortion tactics that threaten the integrity of personal and organizational data… Read more
-
The Voice of the Customer: Why Listening Beats Selling with David Muniz
The paramount focus of this podcast episode is the critical necessity of amplifying the voice of the customer in the contemporary business landscape. I engage in a profound dialogue with David Muniz from Segura, exploring the integral role that understanding customer pain points plays in the provision of effective solutions. We delve into the importance… Read more
-
Why Identity Is Becoming Every CISO’s Biggest Challenge | Vlad Shapiro
Vlad Shapiro, a distinguished mathematician turned identity management expert, articulates his transformative journey in this episode, offering profound insights into the intersection of identity and business. He elucidates how the realm of identity has evolved into a critical pillar for organizational functionality, emphasizing that without effective identity management, business operations may falter. Our discussion delves… Read more
-
How Hackers Attack AI: The New Battle to Secure Intelligent Machines | Harriet Farlow
This podcast episode delves into the intricate nexus of artificial intelligence and security, featuring an enlightening conversation with Harriet, the author of a newly released book Practical AI Security. We explore her compelling journey from a background in physics and anthropology to becoming a pivotal figure in the realm of cybersecurity, particularly focusing on the… Read more
-
AI Is Not Magic: The Truth Behind the Technology Changing Everything | Diana Kelley
This podcast episode elucidates the evolution of artificial intelligence, particularly focusing on the transition from earlier models such as ELIZA and Watson to contemporary systems like ChatGPT and Claude. Our discussion emphasizes the importance of understanding the context and limitations of AI, as well as the implications of its rapid advancement on our professional landscape.… Read more
-
Why Cybersecurity Fails Without Trust: The Human Side of Defense | JC Vega
This podcast episode elucidates the critical importance of effective communication and leadership within the realm of cybersecurity. We engage in a profound discussion with JC Vega, who shares his extensive background in both operational security and cybersecurity, emphasizing the necessity of translating complex technical concepts into relatable business language. We explore the pivotal role of… Read more
