Episode 36

full
Published on:

3rd Aug 2026

L0pht Legend Chris Wysopal on the Evolution of Application Security

Chris Wysopal, a distinguished figure in the realm of cybersecurity and a celebrated L0pht legend, engages in a profound dialogue with Joe Carson, delving into his remarkable journey from scavenging for Unix manuals to pioneering modern application security. Central to the discussion is the evolution of application security practices, particularly as they pertain to the emergence of artificial intelligence in coding. Wysopal recounts the storied ascent of the L0pht, traversing through pivotal roles at @stake and Symantec, ultimately culminating in the establishment of Veracode. The episode further explores the implications of AI-generated code on security, shedding light on the challenges and opportunities that this technological advancement presents for the cybersecurity landscape today. Listeners are invited to glean insights from Wysopal's extensive experience, which not only reflects on the past but also poses critical questions about the future of cybersecurity practices in an increasingly automated world. Chris Wysopal, a luminary in the realm of cybersecurity, recounts his remarkable journey from the nascent days of hacking to the forefront of application security. He shares anecdotes of his early experiences, such as dumpster diving for Unix manuals and the camaraderie fostered within the L0pht, a hacker collective that became a beacon of innovation and activism in the 1990s. Wysopal's narrative is interspersed with reflections on the evolution of cybersecurity and the societal implications of technology, particularly as he transitioned from the L0pht to @stake and subsequently co-founding Veracode. The conversation delves into the intricacies of application security, the challenges posed by AI-generated code, and the pressing need for a paradigm shift in how security is integrated into the software development lifecycle. This episode is a compelling exploration of Wysopal's contributions to the field and his insights into the future of cybersecurity in an increasingly complex digital landscape.

Takeaways:

  • Chris Wysopal's journey illustrates the evolution of cybersecurity from its nascent stages to its current complexity.
  • The transition from the L0pht to Veracode highlights the necessity of adapting to modern security challenges.
  • AI-generated code represents both an advancement and a significant challenge for application security today.
  • Understanding the security landscape requires a holistic approach, integrating hardware, software, and human factors.
  • The importance of early intervention in the software development life cycle for effective security cannot be overstated.
  • Continuous learning and adaptation are essential in the fast-paced field of cybersecurity, especially with emerging technologies.
Transcript
Speaker A:

Hi everyone.

Speaker A:

Welcome to another episode of the Security by Default podcast.

Speaker A:

I'm the host of the show, Joe Carson, and it's a pleasure to be here with you all.

Speaker A:

As usual, it's my favorite time to get to talk to amazing people and also learn.

Speaker A:

One of my favorite things about the podcast is that it's an opportunity for me to hear stories, amazing people's kind of journeys, and also one of some of the things they're doing to make the world a safer place, especially in the world we live in, which is always a bit chaotic.

Speaker A:

And a lot of the guests provide that visibility to the clarity, the visibility to make sure that we have knowledge and insights for those who might be on their journey in their cybersecurity world and career path as well.

Speaker A:

This is an opportunity kind of for you to learn from some people who's been through that experience and maybe give you some good insights about where your journey in the future of your career might go.

Speaker A:

So I'm joined today by amazing person in the industry who's been around for a long time and I do get to listen to his talks once in a few times at different conferences.

Speaker A:

So welcome to the podcast.

Speaker A:

Welcome, Chris.

Speaker A:

If you want to give the audience a bit of background about yourself and how your journey started.

Speaker B:

Sure, sure.

Speaker B:

So, hi, Joe, Great to see you again and thank you so much for having me on your podcast.

Speaker B:

So I'm, as you can tell from my gray in my beard, I'm, I'm an old timer.

Speaker B:

I, I've been doing this professionally now for, I don't know, I think around 28 years.

Speaker B:

But you know, it goes back earlier than that because before 28 years ago, there barely was a cybersecurity.

Speaker B:

Right.

Speaker B:

It was, it was people who worked in manage the firewall or put antivirus on machine, on machines.

Speaker B:

They really didn't do much else.

Speaker B:

Right.

Speaker B:

And, but back, back in the 90s, I got my start really going from, you know, just a curious person, you know, back before the Internet even.

Speaker B:

Look, going on bulletin boards, trying to find information about technology, the Internet, you know, the kind of stuff you couldn't find in the bookstore.

Speaker B:

Right.

Speaker B:

That was, or the library.

Speaker B:

Those were your only other choices, right?

Speaker B:

There was no, there was no Internet, there was no TV show really about this.

Speaker B:

And certainly they didn't teach it to you in, in, in high school or, or even college, right?

Speaker B:

In, in college I didn't, there was no cybersecurity classes.

Speaker B:

So back then you kind of just had to teach yourself and just trying to find resources and People to talk to.

Speaker B:

And I was lucky enough to be living in an area that had a concentration of technology people, which was Boston.

Speaker B:

Right.

Speaker B:

We have MIT and Harvard and a dozen other universities.

Speaker B:

And actually back when I was, you know, sort of exploring this in the, in the late 80s, early 90s, Boston was one of the centers of software.

Speaker B:

I mean, obviously there's still a lot of software here, but this is before, you know, Microsoft rose up or even Apple was really a software company.

Speaker B:

And so there's a huge amount of software colleges, networking, computer companies, and you know, that, that made it so that there was a lot of resources available.

Speaker B:

And some of those resources you, you had to, you know, be creative.

Speaker B:

Right.

Speaker B:

So back then, getting access to hardware was something that, you know, you, you, you couldn't just go to the store and buy a computer.

Speaker B:

They were really, really expensive.

Speaker B:

And when you did that, you got a, you know, you got an IBM PC or you got an Apple, right.

Speaker B:

And it's like, well, you know, I wanted to learn about Unix, right.

Speaker B:

I wanted to learn about other operating enterprises and the government running on.

Speaker B:

Right.

Speaker B:

They weren't running on Windows, Apple or, you know, Commodore 64.

Speaker B:

So you know, getting access to that either meant you did dumpster diving and found it, or you had a friend who worked at a company and said, hey, there's all this stuff on the closet they're getting rid of, you know, if you can help me haul it away.

Speaker B:

Or universities would do the same thing.

Speaker B:

So there was a lot of sort of creative scrounging, dumpster diving, trying to figure out, you know, who was throwing away stuff.

Speaker B:

And it wasn't just the computers, it was the manuals too.

Speaker B:

Right.

Speaker B:

Because there was not, you couldn't, you couldn't go online and do this.

Speaker B:

Actually my.

Speaker B:

When I was in a junior in college at Rensselaer Polytechnic Institute, I did a co op job and my job was working for IBM.

Speaker B:

And we were putting up one of the first online places people could get documentation stuff.

Speaker B:

It was called faxback.

Speaker B:

You could dial up on a phone, type in keys to have it, pocket menu to you, and you could find documents you needed for troubleshooting or, you know, installation or, or, or even repair people like, this is totally like pre Internet.

Speaker B:

And it was a fun project because I learned about TTMF decoding.

Speaker A:

Absolutely.

Speaker B:

But you know, it gives you an example of how hard it was to get the resources.

Speaker B:

So getting the resources was like a superpower, Right.

Speaker B:

If you could get an old Spark or you could get the manual for once.

Speaker B:

Spark is A, you know, a Sun.

Speaker B:

A Sun UNIX computer ran Solaris.

Speaker B:

That was, that was how you, that's what, how, how you had to learn.

Speaker B:

Like they had different commands, they had different stuff than you had on your PC.

Speaker B:

It was a different operating system.

Speaker B:

So that's how I spent probably, you know, a good five years, like from the late 80s to the early 90s, was just trying to figure all this stuff out.

Speaker B:

And as I was doing this, I was going to 2,600 meetings in, in Boston Monthly.

Speaker B:

And I, I found a bulletin board called the Works where a lot of technical people hung out that were, you know, sort of in their early 20s.

Speaker B:

Some people were younger, and they even had their own meetups.

Speaker B:

There was a work.

Speaker B:

They called it the Work Gathering and they had those on a monthly basis.

Speaker B:

So started to meet people in real life, crossing over from, you know, and this is part of, the, part of the way you get to know that, you know, some, some company is throwing out some old computers, right?

Speaker B:

You have to know the people who work there.

Speaker B:

And, and then eventually I ran into the Loft guys.

Speaker B:

So I became a member of the Loft.

Speaker B:

And we were actually a, you know, a hacker space that had a physical space where we kept equipment and manuals and we had a network connection before we had an Internet connection.

Speaker B:

We ran a bulletin board, right?

Speaker B:

So that was where you all of a sudden got a concentration of equipment knowledge, manuals.

Speaker B:

And that was sort.

Speaker B:

Things had kind of exploded.

Speaker B:

And that was around 92.

Speaker B:

And then I just started learning so much.

Speaker B:

Like, people would come and visit the Loft, like from New York.

Speaker B:

They would be in Boston.

Speaker B:

They would come and they'd say, hey, yeah, I'd love to, love to come visit.

Speaker B:

They'd sit down, they'd say, hey, you know, I got this new exploit with Split vp, which was a Unix, a Linux utility, to split your screen into two.

Speaker B:

So you could have a shell on the bottom and maybe do IRC on top, right?

Speaker B:

Like, like a graphical user interface.

Speaker B:

It's crazy to think that you needed a utility to do that.

Speaker B:

But I have an overflow in Split VT and it's very popular for people using irc.

Speaker B:

Let me show you how it worked.

Speaker B:

And so this was learning, learning a crazy amount from, from, from lots of people.

Speaker B:

And then, you know, I got to be the point where, you know, I had learned enough at the Loft.

Speaker B:

And so now I'm, I'm, I'm writing them and I'm discovering exploits and I'm publishing research and I'm teaching other people, and that's One of the great things about the hacking community is the open exchange of information, you know, and it's always been that way around vulnerabilities and exploits, you know, because that's like the most exciting and most powerful stuff to have.

Speaker B:

So that stuff gets shared really, really wide, widely.

Speaker B:

But tools do too.

Speaker B:

And so I eventually started, you know, writing writing tools.

Speaker B:

You know, we, at the loft, we famously took some of our research into the weakness of Windows passwords, which were just, it's almost like if you could, you couldn't do it work, right?

Speaker B:

It was really, it was, it was really, really poor implementation.

Speaker B:

Even though it, it did use, you know, I think it used triple DES or DES for the, for the Landman hash and they used, I think it was MD5 for the, for the NTLM hash.

Speaker B:

But the implementation was real, was really bad and we found all these implementation problems.

Speaker B:

And that's the thing about crypto, right?

Speaker B:

Like, if you have a poor implementation, it doesn't matter how great the algorithm is.

Speaker B:

If you're writing the code, which Microsoft did, you can do all kinds of dumb stuff, right?

Speaker B:

And like the most dumb thing they ever did was they, they split the password into seven character halves, right?

Speaker B:

So you had a 14 character password and that was actually the max at the time.

Speaker B:

But they split it into two seven character halves and encrypted each one separately.

Speaker B:

So now you're brute forcing seven characters and they did some really other dumb things like they upperc paste it, they didn't do mixed paste.

Speaker B:

So all of a sudden your key space is gone by 26, right?

Speaker B:

So think about seven characters alphanumeric.

Speaker B:

You're looking at, you know, sev.

Speaker B:

How does it work?

Speaker B:

Seven to the 36, right?

Speaker B:

That's not that big a number compared to the modern stuff we have today, right?

Speaker B:

So, you know, writing tools for that was fun learning experience and you know, it put me on a path to help actually professionalize cybersecurity as opposed to it being a bunch of individual researchers and hobbyers, hobby people who are just having fun, right?

Speaker B:

To be like, actually someone needs to be doing this full time, right?

Speaker B:

Someone needs to be doing something like vulnerability research full time.

Speaker B:

Someone needs to be pen testing and doing assessments of infrastructure and software full time.

Speaker B:

And that's how I kind of transitioned from being a software engineer and doing this, doing this on the side to saying I'm going to do this full time.

Speaker B:

And that happened around, I hate to say, 28, 26, 27 years ago.

Speaker B:

And here we are, so.

Speaker A:

But I have a Question.

Speaker A:

So one of the things that I'd like to kind of know as well is that usually there's an environment around you that kind of gets you, catches your interest.

Speaker A:

And I think, you know, what I always remember back was I was seven years old, I met this family from Belgium that I was going to stay at.

Speaker A:

And they had an Atari:

Speaker A:

And that got me really interested into games.

Speaker A:

And of course, you know, I wanted a games console and I ended up getting an Atari 800XL, which wasn't a games console, but it was a hybrid.

Speaker B:

Type of play games.

Speaker B:

But it was really a PC.

Speaker A:

It was really PC.

Speaker A:

And that's where I started basically coding at the time.

Speaker A:

And basic for you, what was, was it.

Speaker A:

You know, because for me, I wasn't in a family that was very connected with technology.

Speaker A:

It was that that gaming interest is what got me addicted to, you know, and took my path down to where I am today.

Speaker A:

What was, what was it your family kind of that you had around you that kind of got you interested in technology, or was it your own kind of path that you found?

Speaker B:

Yeah, so it didn'.

Speaker B:

It didn't.

Speaker B:

It didn't come from, from, from my family.

Speaker B:

Like, my dad was a, was an engineer at GE Aircraft Engines, and he did material science stuff, right?

Speaker B:

And they didn't really use computers for that back then.

Speaker B:

I think there was like a big mainframe or something where they just managed the manufacturing process.

Speaker B:

So it was, it wasn't that.

Speaker B:

I'm not, I'm not 100% sure what piqued my interest, but the closest I can, I can say is, was Radio Shack, okay?

Speaker B:

And we had a local Radio Shack.

Speaker B:

And I would go there and I would just be interested in electronics and what, what, what, what could I learn or build or something like that?

Speaker B:

And, and one day there was a TRS 80 computer in there.

Speaker B:

And so the TRS 80 was one of the very first PCs that you could purchase.

Speaker B:

And we couldn't, we couldn't afford one.

Speaker B:

I, I finally got a PC, I'm gonna say about eight years later, when I was in college, but up until then, so we never had one in.

Speaker B:

When I was in high school, so I would, I would go to Radio Shack and I would use their computer.

Speaker B:

I would, I would write out, I would take out books in the library.

Speaker B:

I would learn basic.

Speaker B:

I would write my program on paper.

Speaker B:

I would go in, I would key it in, I would save it on cassette.

Speaker B:

This.

Speaker B:

They didn't even have a floppy disk.

Speaker B:

That's how Antiquated this was.

Speaker B:

And I could then take the cassette home and then when I had more time, I could go back and work on my same program.

Speaker B:

And then I finally did it.

Speaker B:

In high school we got some Commodore business machines which were, which were CBM.

Speaker B:

It was like the PET.

Speaker B:

The Commodore PET had a green screen 80 by 25 monitor all built in.

Speaker B:

One really cool looking machine, sort of that retro futuristic look.

Speaker B:

And that allowed me to really program in basic.

Speaker B:

arn assembly language program:

Speaker B:

And I'm like, wow, you can use these things called peaks and pokes in BASIC and access, you know, absolute memory locations.

Speaker B:

Right.

Speaker B:

Like sort of like pointers in C. And you could, you could talk, you could talk directly to the graphics controller so that you could like.

Speaker B:

I could make the whole screen flash white and black by just in a loop peeking and I mean poking.

Speaker A:

Those are some of the.

Speaker A:

I remember writing one of the magazines has a, a BASIC program.

Speaker A:

I remember spending a month writing that thing and all it did was was take a line and just kept rotating around.

Speaker A:

So it ended up, it created a really cool graphic in the end, but it was, it's like, you know, it's so much time spent.

Speaker A:

But in the end the results were, were pretty amazing.

Speaker A:

Kind of artistic, kind of using the visualization ended up learning a lot as well.

Speaker A:

Especially when a lot of the times they'd misprinted something and you couldn't get it to run and then you got the reprint the month after and correction what line it was on.

Speaker A:

So it was always, it was a, it was a love hate kind of relationship with computers at the time.

Speaker B:

So, so, so I would say that that got me into computers, but what got me into, you know, sort of packing and CyberSecurity was really BBSS.

Speaker B:

Right.

Speaker A:

Okay.

Speaker B:

The bulletin board just finding the right BBS that had interesting files on it, interesting people to have conversations with.

Speaker B:

And we, we call this.

Speaker B:

And I, you know, I mentioned how being in Boston was great for hardware and people access.

Speaker B:

Uh, but they, they call it the, you know, the, the area code lottery.

Speaker A:

Yep.

Speaker B:

Right.

Speaker B:

If you ended up in 61 7, which is Boston, you could dial all these great VBSs that, you know, basically leverage all the knowledge in the community and you could find people.

Speaker B:

And it was really the connections with people that really got me excited about learning more about hacking.

Speaker A:

Absolutely.

Speaker A:

I think it was one of the, it was one of those bullets and boards as well that I remember I downloaded some of my first kind of hacker Handbooks back in the.

Speaker A:

It was the late 80s, early 90s.

Speaker A:

And I still actually find it.

Speaker A:

I still have the original downloaded copy.

Speaker A:

I've kept it.

Speaker A:

But I went back and bought the.

Speaker A:

Eventually bought the physical books as well to add to my collection.

Speaker A:

But you're absolutely right about is the knowledge, the learning.

Speaker A:

They kind of want to learn how things work in the background.

Speaker A:

And you know, I think I remember as a child growing up I was more interested in the manuals for things than reading fictional books.

Speaker A:

So for me it was the manual.

Speaker A:

And I read that thing inside out to learn as much as I possibly could about how do I maximize the value of the technology that you got.

Speaker B:

I think in the past too the manuals were so much better.

Speaker B:

I picked up a little portable reel to reel tape recorder at an antique store basically like from the 60s and the manual I actually had to find online and download.

Speaker B:

But it was amazing.

Speaker B:

Like it, it.

Speaker B:

It had a full schematic, it had pictures of all the circuit boards and everything in there and it, and it matched up number to number with the schematic.

Speaker B:

It had a parts list, it had the troubleshooting wasn't like turn it on and off.

Speaker B:

It was like three pages long, right.

Speaker B:

With like 20 different things you could do.

Speaker B:

And I just, I mean the, the resources for learning were available in the manual for the device.

Speaker B:

Now everything is just like sort of a steel box and it doesn't even come with a manual.

Speaker B:

You got to find one online and it's totally anemic.

Speaker B:

You're supposed to just figure everything out, right?

Speaker B:

It's the, it's so intuitive.

Speaker B:

You can just figure it out.

Speaker B:

But, but by doing that you have no information, right?

Speaker B:

You just have the physical UI and you know, I, I don't know if this is helping us in the future with the way kids are learning about technology.

Speaker A:

So sometimes it does force you to do more exploratory findings as well.

Speaker A:

You know, it forces you to kind of try to slowly take it apart to understand what's behind, you know, you know, and identify everything.

Speaker A:

So one of the things for you as that, you know, during that time, the transition, you know, from.

Speaker A:

Because I remember in the 90s that when I was working in I, I was assist administrator in the hospitals and doing medical records and ambulance services, stuff like that.

Speaker A:

So I was just operating systems providing services and security for me was something I would do on the side.

Speaker A:

You know, it's.

Speaker A:

You'd update the antivirus software in the systems.

Speaker A:

You would make sure that everyone was using you know path using passwords and that it wasn't just the key to the door.

Speaker A:

It wasn't just the only remaining security was left.

Speaker A:

But for you, what was that transition?

Speaker A:

security full time until the:

Speaker A:

For you, what was the transition like?

Speaker A:

And, and what did you focus on?

Speaker A:

Because I always say there was two kind of paths.

Speaker A:

It was the very hardware focused side of things and there was also the software.

Speaker A:

Which path did you kind of feel more connected to?

Speaker B:

Yeah, so I was interested in both hardware and software.

Speaker B:

And so when I went to, to university, I did computer engineering instead of computer science or electrical engineering, which is like choosing one or the other, which I, I loved it.

Speaker B:

Right.

Speaker B:

We had like microprocessor lab and I built a microcomputer on a breadboard with a microprocessor, figured out what is, what is booting.

Speaker B:

And, and, and, and so that crossover between hardware and software is really what, what I was really interested in.

Speaker B:

I eventually did gravitate to software.

Speaker B:

Um, and my first job was as a software engineer.

Speaker B:

And then I continued on the, on sort of on the software side.

Speaker B:

But I've, I've always been, always been interested in hardware.

Speaker B:

And I, you know, I'm a ham radio guy and I, you know, I take Iot devices apart and all of that, but I should say amateur radio.

Speaker B:

I'm not sure ham radio is.

Speaker B:

And.

Speaker B:

Because then you understand like the physical layer of communication, right?

Speaker A:

Yep.

Speaker A:

Because in the end, in the end, everything's a signal.

Speaker A:

Everything's, you know, everything's a signal.

Speaker B:

And those could be going over a wire, like with Ethernet, or they could be going over WI Fi or, you know.

Speaker B:

Now Laura, and mesh is the new, new cool thing.

Speaker B:

So we have a great network here in Boston.

Speaker B:

I'm part of.

Speaker B:

But so I, I've always had an interest in, in hardware.

Speaker B:

And that's still my sort of my hobby side.

Speaker A:

Okay.

Speaker B:

Where professionally I've, I've focused on, on, on, on the software, on the software side.

Speaker A:

Okay.

Speaker A:

And so what was like, you know, in that time at the loft, what was it like for you being around some, you know, so many amazing people, including yourself, and, and where did your hacker handle come from?

Speaker A:

What was, what was it was.

Speaker A:

What was the background into?

Speaker A:

WellPond.

Speaker B:

Yeah.

Speaker B:

So it's, it's, it's totally goofy as you might expect, because it's, you know, it's not, the handle is not, you know, Lord Demon or something.

Speaker B:

And it was really just a place in the Boston Area.

Speaker B:

And it was when I was signing onto the works bulletin board.

Speaker B:

A lot of the bulletin boards I went to, you could go as a guest or you would just use a throwaway, you know, name.

Speaker B:

But the works, like it seemed like a community.

Speaker B:

And I, I, I decided I need something persistent here and, and they didn't allow real names.

Speaker B:

They're like, no, real names.

Speaker B:

We don't want to know.

Speaker B:

So I don't know, I was just kind of put on the spot.

Speaker B:

I hadn't thought of it before when I decided I probably should have taken a step back and why don't I just wait before I set my name and I'll come back tomorrow and figure it out.

Speaker B:

I didn't do that.

Speaker B:

I'm like, how am I going to come up with a name?

Speaker B:

And I just, there was a map of the Boston area over my desk and I'm like, I'm just going to put my finger on it and that's what I'm going to be.

Speaker B:

And my finger landed on Weld Pond in Dedham, Massachusetts.

Speaker B:

And I'm like, yeah, that, that works.

Speaker B:

It's actually two words.

Speaker B:

Like it could be a first and last name.

Speaker B:

And so it's kind of a silly, a silly thing.

Speaker B:

But you know, hacker, Hacker handles are silly, right?

Speaker B:

There are a lot of what they're meant to be.

Speaker B:

Yeah.

Speaker B:

Like there was guys on the bulletin board named Tweety Fish.

Speaker B:

Like it's just completely silly.

Speaker B:

At least that's a character from a cartoon.

Speaker B:

But so that's where that came from, you know.

Speaker B:

The loft.

Speaker B:

When I joined the loft, we were just sort of figuring out the name, right?

Speaker B:

We, it was sort of, I think a few months after it was kind of founded and it was just sort of a few guys Count Zero and Brian Oblivion getting together and using some of the space that their wives had actually rented for a hat making business.

Speaker B:

And they had too much space.

Speaker B:

And, and they, and they're like, hey, we, we, we have more space than we need.

Speaker B:

And like we need, we would like to spend much less money on rent.

Speaker B:

So why don't you guys take this half of the room?

Speaker B:

And that's how it started building.

Speaker B:

And they kept inviting people over and saying, hey, you know, why don't we give you a desk here?

Speaker B:

And it will be like $150 a month for space and, and paying for electricity.

Speaker B:

I'm, I'm sorry.

Speaker B:

We didn't have to pay for electricity.

Speaker B:

Paying for the phone 9 or eventually Internet.

Speaker B:

And that was one of the nice things about the Place you didn't have to pay electricity, which is kind of crazy.

Speaker B:

But it was, it was on the same line as the reef space below, which was a carpentry shop.

Speaker B:

And it was, it actually, it was hard for the landlord to rent this space because you couldn't use it during the daytime because it was too loud.

Speaker B:

No one wants to be above a carpentry shop, but we were only there at night when they went home, so, so it actually worked out good.

Speaker B:

And it was free electricity because it was on the same lines as the carpentry shop below.

Speaker B:

They hadn't separated the circuit.

Speaker B:

I can only imagine what their electricity bill was on installed saws all day.

Speaker B:

So we were able to sort of hide our expensive electricity bill along with the carpentry shop.

Speaker B:

And we actually even wired up a PDP 11 in there which was two phase 240 and you can imagine how much, how many watts that's sucking down.

Speaker B:

And like the landlord didn't blink an eye.

Speaker B:

So it was, it was, it was a great, you know, luck to be able to find that space to be able to meet these people and, and, and, and sort of like be accepted as someone who could contribute to this hacker space.

Speaker B:

Right.

Speaker B:

And you know, it was, it was an intense learning time and then also then just a growth time like doing projects with people like working together with other people on, on, on project.

Speaker B:

And that was how the loft sort of evolved from just sort of this random, you know, just come and hang out, put your computers here to this forest of vulnerability research.

Speaker B:

And then beyond like publicizing what we were learning and saying, hey, people should know that Microsoft isn't actually trying to make their product secure.

Speaker B:

And these things that are really easy to find, we can find them without source code they obviously aren't looking for because we can find these easily.

Speaker B:

And it was, we were able to wake up a lot of people to the fact that, you know, hackers have a way of exploiting software and software companies aren't doing anything about it.

Speaker B:

And the industry's response is like more AV and better firewalls.

Speaker B:

And we all know that that doesn't work because the reason you have a firewall is because you want traffic to go in and out of your network connection.

Speaker B:

If you didn't want traffic to go in and out, you just wouldn't have the network connection.

Speaker B:

The traffic is going in and out.

Speaker B:

We can figure out a way to exploit that, right?

Speaker B:

It's either an open port on the way in or client side vulnerability on the way out.

Speaker B:

And like that Took a few years for people to wake up to.

Speaker B:

I don't know how many IT people I talked to and they, I said I was in cybersecurity and they say I'm happy we have a firewall.

Speaker B:

I'm like, I'm happy you have one too.

Speaker B:

But you know that's like, that gets you from FD in your security.

Speaker B:

Right.

Speaker B:

And the same thing with, with antivirus.

Speaker B:

It's like maybe that now gets you to a C. You will get breached if that's all you're doing.

Speaker A:

Absolutely.

Speaker B:

So it was a fun time to be in the industry to wake people up to the way people actually really bypassed all that stuff with bugs in software and misconfigurations and social engineering and all the stuff that is still going on today.

Speaker B:

And you know, I would say that I'm helping on the misconfiguration and, and, and the bugs in software side but you know, other people help with social engineering and it's definitely needed today still.

Speaker A:

So.

Speaker A:

Question.

Speaker A:

So one of the things, you know, from the loft side and then it moved into the loft Heavy industries and what became at stake and then was acquired by Sematic.

Speaker A:

What was the transition from all of that during that time into more the, you know, from you know, transitioning and disrupting the world and creating the vulnerability, you know, kind of programs and creating cybersecurity of you know, what it, what it has turned in today.

Speaker A:

What was that transition like for you going through from, from Loft at Stake and then Symantec.

Speaker B:

Yeah, so it was sort of like the.

Speaker B:

After we had the Senate testimony in 98, I. I was actually working at BBN with, with Mudge and Brian Oblivion worked there.

Speaker B:

He worked in a different department.

Speaker B:

He was sort of in radio and satellites and me and Mudge were in the IT security and Paul Nash, Zil Kosis was there which was.

Speaker B:

He was one of the later LOFT members who also worked there.

Speaker B:

And you know, we were doing IT networking for, I'm sorry networking security for a, you know, for a huge, you know, backbone network providing company.

Speaker B:

BBN was one of the first ones.

Speaker B:

So I was, I was learning a lot there but I wasn't really able to do sort of the vulnerability research I wanted to do and.

Speaker B:

Cause it was more, it was more IT security.

Speaker B:

It's like, like let's get the firewalls working and the network and authentication and things like that.

Speaker B:

And there was other guys at, at the loft who were like working at like Comp USA or they were working as a security guard somewhere.

Speaker B:

So there was other people who didn't have jobs at all in security.

Speaker B:

And we said, you know, we would love to do the stuff we're doing at the loft, you know, full, full time.

Speaker B:

And, and we had visions of being like the, the team in sneakers, right?

Speaker B:

Like, you know, sneakers was.

Speaker B:

I, I still think it's the best hacker movie.

Speaker B:

And it was because you had this multi, multidisciplinary team where you had the social engineers, you had the hardware hackers, you had the software hackers, you had the phone freaks, you had people who understood, you know, rf.

Speaker B:

And it's the full spectrum of security we use.

Speaker B:

All, all of these things are part of the security mechanisms.

Speaker B:

The full hardware stack, the full software stack, the full human stack, the physical security stack, right?

Speaker B:

And that, that, that's what I think we wanted to be.

Speaker B:

You know, it's, it's a movie, it's a little bit of a fantasy.

Speaker B:

I don't think anything truly exists like that.

Speaker B:

But you know, it was aspirational.

Speaker B:

We even thought that we wanted a, you know, a bread truck like that outfitted with the equipment inside it.

Speaker B:

That never came to pass.

Speaker B:

But that was sort of our vision.

Speaker B:

And actually we tried doing that at a company called Cambridge Technology Partners, which was a consulting company that had a small sort of pen testing, infrastructure assessment, software assessment, like five people kind of thing out of a thousand.

Speaker B:

Right?

Speaker B:

It was a consulting company and which is how a lot of it the companies were back then, IBM and Deloitte, they all had a tiny team of, of people.

Speaker B:

It hadn't broken out to be a big, a big deal yet.

Speaker B:

And we tried to get in with them and you know, we, we offered to give them a, a free penetration test so they could see what we could do.

Speaker B:

And we were adamant that this was like a no holds bar, right?

Speaker B:

Like everything, full spectrum hardware, security, physical security systems, social engineering, everything.

Speaker B:

And that turned out to be quite interesting because while we were doing that we were actually negotiating with them around what would the team be, what would our salaries be, you know, what would the benefits be.

Speaker B:

And all of this stuff.

Speaker B:

Meanwhile, we're reading their email, right?

Speaker B:

We're in their voicemail system so we can see everything they're doing and they've given us the jail out of free card to be in all these systems.

Speaker B:

So I don't think they completely thought that one through.

Speaker B:

Probably because they didn't really realize how devastating.

Speaker A:

How much, how much access you can get to.

Speaker B:

Yeah, how much access you can get.

Speaker B:

Like they probably weren't even thinking, but one of the lead guys, the VP who would be, you know, running our team.

Speaker B:

You know, I think his password was the default, which was 4, 5, 6.

Speaker B:

So that was kind of, kind of, kind of funny.

Speaker B:

Anyway, that didn't work out.

Speaker B:

You know, they didn't, didn't, they didn't know how valuable it would be.

Speaker B:

They just didn't want to put the resources into it.

Speaker B:

The equipment we wanted, the things we wanted to do, the salaries we thought we needed.

Speaker B:

And then we sort of, we retrenched and said, all right, well maybe we'll start our own company.

Speaker B:

We started looking at vc.

Speaker B:

None of us had any kind of business experience really and you know, management experience.

Speaker B:

We all had just been individual contributors.

Speaker B:

No one had started a company.

Speaker B:

I don't, I had worked at a startup that was as close as, as it, it, it, it came.

Speaker B:

Actually it failed.

Speaker B:

So maybe I, you know, I didn't, I didn't get any good lessons.

Speaker B:

And, and so that didn't work out either.

Speaker B:

We weren't able to raise VC or, or, or team up with the right people.

Speaker B:

And so when we ran into the people who were forming At Stake, they had venture, venture backing, some of the people from Cambridge Technology Partners that were actually not the management, but some of the other consultants had already gone over there and we're starting, starting to work there.

Speaker B:

So there was a core of people there, like David Goldsmith was there, Window Snyder was there, people who would go on to, you know, run, run big security stuff in the future.

Speaker B:

And, and Dan Geer was thinking about joining there when we were thinking about it.

Speaker B:

And we're like, hey, we're getting here.

Speaker B:

The company is still in stealth.

Speaker B:

We can influence it.

Speaker B:

And essentially At Stake did a, did a bulk hire, right?

Speaker B:

They did a buyout of the loft to just get the people and to form, to form, you know, we called it At Stake Labs, right?

Speaker B:

And we started, we did our vulnerability research and the idea was we would come up with tools and techniques and then the consultants would go on site or you know, use them, use the tools and to do the work.

Speaker B:

And that was, that was a new model, right?

Speaker B:

No one was doing that.

Speaker B:

You know, people would use tools, but they were things that were, they would just download.

Speaker B:

Like most, most consultants, security consulting teams used open source tools or commercial tools.

Speaker B:

They didn't build their own.

Speaker B:

Right?

Speaker B:

And if you're doing vulnerability research and you find big problems like password weakness in an operating system, you know, you, you need, you need a tool to exploit that.

Speaker B:

So we were building tools and it made it a really cool, unique place, place to work.

Speaker B:

But after like a year or so, it started to get further from the vision of the loft.

Speaker B:

Right.

Speaker B:

And you know, we never got to that Sneakers phase and it just became more and more like a standard consulting company.

Speaker B:

You know, it started to feel like, hey, we're a division of IBM basically and we're doing work for, you know, Morgan Stanley and they, they just want us to do the same thing that IBM was doing.

Speaker B:

And it was, it was, it was, it was challenging for, you know, a, a few different individuals were, who were more on the sort of the bleeding edge, more loft style than corporate, right?

Speaker B:

Like, I was pretty corporate.

Speaker B:

I had a, I had worked in software at big companies like Lotus and you know, it, it didn't, it didn't work out.

Speaker B:

We couldn't keep the team together.

Speaker B:

People ended up leaving and then eventually there was a few of us left after four years when we got bought by, by Symantec.

Speaker B:

But, you know, it was, it was, it was kind of a sad situation seeing like this, this vision slowly sort of go away.

Speaker B:

And even though we were creating an amazing, you know, security consulting company, let's not get that wrong.

Speaker B:

At Stake was an amazing security consulting company.

Speaker B:

It just wasn't what we thought it could be.

Speaker B:

Right.

Speaker B:

Which may have.

Speaker B:

Maybe our vision was like way too far out, but we attracted amazing talent to come, to come to come work at Stake.

Speaker B:

You know, Katie Masuris worked there, Dave Vitel worked there.

Speaker B:

Really amazing talent came and made their mark and then went on and, you know, learned from that and went on and so I wouldn't, I wouldn't say I didn't, I didn't love the experience and I would want to do it again.

Speaker B:

Maybe with the lessons learned I could do better, but that was an amazing time.

Speaker B:

But then when Symantec came and bought At Stake and put us in their business consulting division, it was less about assessments than it was more about figuring out the topology to put an email.

Speaker B:

Email gateway, right?

Speaker B:

It's like everything was through a lens of an At Stake was product agnostic, right?

Speaker B:

We were like, we are not going to recommend products, right?

Speaker B:

We are going to.

Speaker B:

If we recommend anything you need to do in your infrastructure, we're going to talk about like you need firewalls with these capabilities, right?

Speaker B:

Or you need a gateway with this kind of capability.

Speaker B:

We didn't recommend products because that was one of the problems in the consulting industry, right.

Speaker B:

Like people.

Speaker B:

Like one of the first companies that did consulting was secure computing, right?

Speaker B:

They did it, they existed before at stake problem was they weren't independent of the hardware that they sold.

Speaker B:

So all their consulting was focused on putting that hardware.

Speaker B:

And if that hardware wasn't the best solution or they didn't have a solution for a particular problem, you didn't get any recommendations there.

Speaker B:

And this is, this is what we are trying to fight at at stake was, was exactly what we ended up being rolled into at Symantec.

Speaker B:

We used to say, like, all we're doing is figuring out how to sell more yellow boxes, whether it was software or appliances.

Speaker B:

And you know, that's, that's what that business needs.

Speaker B:

They sell software and yellow appliances.

Speaker B:

Right.

Speaker B:

So nothing, nothing wrong with that.

Speaker B:

It's just like, I think there's a better way.

Speaker B:

And that was what we were doing at stake.

Speaker B:

So eventually once we got the semantic, you know, people really started to, we.

Speaker B:

And the team that I was on, which was basically the at stake research team, as it, as it, as it ended up after four years, we were building, you know, binary static analysis tools.

Speaker B:

And so we were building these tools that the consultants could use that they could basically do a code review on a binary.

Speaker B:

And we're like, wow, this is, this will be super powerful.

Speaker B:

Because when they go in to do an assessment, they don't always have all the code to all the things that they need to need to assess, you know, plugins and libraries and other software that interacted with say, the system that they wanted to secure.

Speaker B:

And we thought that this was a breakthrough technology and it was.

Speaker B:

But when we got to Symantec, they weren't, weren't interested.

Speaker B:

Right.

Speaker B:

They were a, you know, a host security company, an email security company, and they didn't do anything around the whole software development lifecycle.

Speaker B:

And they said, this is a, this is a completely new, you know, this is a completely new business.

Speaker B:

Right.

Speaker B:

We're not, we're not going to, we're not going to invest in this.

Speaker B:

This isn't, this isn't our strategy.

Speaker B:

And that's when I kind of learned like, you could have the best tool, but it doesn't always fit into the sales motions and the way that you're able to finance things.

Speaker B:

And these are the things you learn when you actually run a company.

Speaker B:

It doesn't always make sense.

Speaker B:

And that's why people spin off stuff.

Speaker B:

Right?

Speaker B:

They spin off.

Speaker A:

Sometimes it's the timing as well.

Speaker A:

So there's organizations.

Speaker A:

Yeah, it could have been in the, at the right time for them.

Speaker B:

So yeah, we could have been too early.

Speaker A:

Yeah.

Speaker A:

Because that's where our, our past we, we had such a, like a short overlap during Symantec time.

Speaker A:

Just literally relieving when I was through another acquisition because they just kept acquiring companies and technologies and it's the same, same experiences that when they acquired Altiris, they didn't acquire the application security part of it because they just didn't feel it fitted into their strategy and vision of the future, which eventually turned into identity security, which ended up becoming a massive industry by itself as well.

Speaker A:

So sometimes it's just that it doesn't align with their vision.

Speaker A:

They kind of struggle to change and see it beyond a couple of quarters or a few years where the industry's going.

Speaker A:

And sometimes it's a timing and a missed opportunity for those organizations.

Speaker B:

Yeah, there was actually one part of the timing was really bad was.

Speaker B:

I don't know if people remember, but Symantec was, was originally not a security company.

Speaker B:

It was, it was just a general purpose software company that, all kinds of different software and they actually made developer tools like they made compilers, they, they had a developer tool.

Speaker B:

And I guess in the, in the, in the early 90s they bought Norton.

Speaker B:

Right.

Speaker B:

So they bought Norton Antivirus and that exploded.

Speaker B:

And they're like, we're going to focus on this and we're going to divest ourselves of these other things like remote.

Speaker B:

I think they kept PC anywhere, right?

Speaker A:

Yeah, that was one of the, one of the products I ended up having at one point in my path, you know, either was Partition Magic.

Speaker A:

Partition Magic.

Speaker A:

Yeah, Partition Magic as well.

Speaker A:

Ghost.

Speaker B:

Yeah.

Speaker B:

So they had a few tools, but they got rid of a lot of the stuff that wasn't security related.

Speaker B:

Yep.

Speaker B:

And they had gotten rid of their developer tools.

Speaker B:

So us coming in and saying, hey, we could sell this.

Speaker B:

Development teams, they were like, we got rid of all the people who sell the stuff, the development team.

Speaker B:

So it wasn't even like new.

Speaker B:

It was, it was like, no, we're getting rid of that stuff.

Speaker B:

So it just wasn't the right place.

Speaker B:

But that was great because then I was able to say, all right, well sell us then.

Speaker B:

Right?

Speaker B:

Let me go out and get VC funding.

Speaker B:

Let's, let's get funding to buy the technology and the team and the patent that we had out of Symantec and form another company and you'll get, you'll get a percentage of the new company.

Speaker B:

That's how we'll pay you in cash and percentage, which is pretty, pretty common in spinoff.

Speaker B:

And, and that worked out great because, you know, barcode is still here today.

Speaker B:

, liquidity event way back in:

Speaker B:

I can't believe it was nine years ago.

Speaker B:

But as an 11 year old company we got bought by Computer CA Technologies and which eventually got bought by Broadcom and we spun out, we spun out.

Speaker A:

Again which bought Symantec as well, which.

Speaker B:

Then also bought Symantec.

Speaker B:

Right.

Speaker B:

So we, we spun out of Broadcom right around the time they were buying Symantec.

Speaker B:

So I almost worked at Symantec twice.

Speaker B:

Yeah.

Speaker B:

But you know, it, it, it, it worked out for the best.

Speaker B:

You know, being an independent company allows you to, you know, chart your destiny so much better.

Speaker A:

So if you give the audience a little bit of kind of background and so you know what, what Vernacode does and what, you know.

Speaker B:

Yeah.

Speaker A:

How it's evolved over the years.

Speaker A:

You know, as you mentioned, you're looking at binary reviews and doing static analysis, which is a lot of kind of where basically through how code works and understanding about how it's linked together and what it contains.

Speaker A:

So what are veri codes kind of do and what's it doing today?

Speaker B:

Sure.

Speaker B:

So we started off like doing binary analysis because that's what we originally that was the target was C and C. C binary lang compiled languages.

Speaker B:

But quickly we realized that businesses don't run on C and C. Maybe independent software vendors write software on Apple, businesses run on Java and.

Speaker B:

Net and then other languages.

Speaker B:

So quickly we supported Java and.

Speaker B:

Net and, and that's, that's, those are bytecode languages so they're still compiled.

Speaker B:

But the beauty of that is the decompilation is perfect.

Speaker B:

Right.

Speaker B:

You don't have to guess what types are and it's essentially a perfect reversing process.

Speaker B:

So it's almost like you're starting with source code but you're able to look at the, the thing that's actually running.

Speaker B:

So we did a little bit of binary stuff.

Speaker B:

We switched to being a mostly bytecode company but we kept calling it Binary.

Speaker B:

And then we realized that, you know, the, the future was a lot of software was, was, was interpreted right.

Speaker B:

Python gained traction.

Speaker B:

Then JavaScript kind of took over the world on the server side and the client side.

Speaker B:

There's a million different frameworks around JavaScript and then you had all the mobile languages.

Speaker B:

So over time we've become a binary bytecode and source code company.

Speaker B:

Right.

Speaker B:

Because we're, we're looking at, we're looking at that artifact that, that, that executes.

Speaker B:

And I would say now I think our number one language still is Java.

Speaker B:

Okay.

Speaker B:

Just because there's so much legacy code and.net is number two, but JavaScript is now number three.

Speaker A:

Okay.

Speaker B:

And so we support like 20 different languages, all these different mobile languages, all these different frameworks.

Speaker B:

And the idea for Veracode is every company has a software estate.

Speaker B:

Whether you are a, a bank healthcare company or you are a SaaS company, you're a mobile company, you're a cloud company.

Speaker B:

You know, every, everyone runs on software, right?

Speaker B:

Everyone runs on software.

Speaker B:

It's almost the size of your company dictates how much software risk you have.

Speaker B:

More than the, even the industry vertical you're you're in because the larger you are, the more you're running on software you're using.

Speaker A:

I remember some large companies, you know, their application software kind of library was in the tens, 30,000 plus applications.

Speaker A:

A piece of software.

Speaker B:

Oh yeah, we used to do like estimations of how many applications they had, like at these global banks.

Speaker B:

And they would say, I think we have about 5,000 applications.

Speaker B:

And then we would look and they would have like 20,000 applications.

Speaker B:

So like being off by a factor of four was, was pretty, pretty common.

Speaker B:

People just have no idea.

Speaker B:

And the crazy thing is like half of those are connected to the Internet and any one of those let someone get in and start to pivot.

Speaker B:

Right.

Speaker B:

So we started to explain to people like, what is this software risk?

Speaker B:

It's like, oh, I have a firewall.

Speaker B:

It's like, yeah, but you're letting port 443 in, right.

Speaker B:

And you have SQL injection vulnerabilities.

Speaker B:

So so basically what Veracode does, it's able to, while the software is being written, work with the development team, hook into their development life cycle and whenever they make a change to the software, assess that the code.

Speaker B:

Right.

Speaker B:

Assess that change for security problems.

Speaker A:

So you're really in the shift left.

Speaker A:

Kind of that whole momentum of kind of moving it to not just doing, you know, checking code afterwards, but trying to at least get it earlier in the phase of the development life cycle.

Speaker A:

So that when people's coding that is helping show a potential where they might be not using the right kind of methods and providing more secure kind of, you know, options.

Speaker B:

Yeah.

Speaker B:

So, you know, shift left is really a necessity because of, because of dev DevOps.

Speaker B:

You know, this code is changing and put into production in, in typically hours, but it can be even less.

Speaker B:

It could be, it could be minutes.

Speaker B:

And when are you going to have time to assess it if you're not built into that life cycle between writing the code, building, testing the code and putting the code into production.

Speaker B:

So just like, just like you're testing for functionality before, you know, between writing the code and putting into production.

Speaker B:

That's where security has to live, has to live now.

Speaker B:

And you know, it's just, it's just a necessity.

Speaker B:

So we went from, you know, days to scan an application to hours to scan an application, to minutes to scan an application.

Speaker B:

So in order to fit into the developer's workflow, you have to, you have to optimize for speed.

Speaker B:

So can you pre compute things?

Speaker B:

Can you use old, you know, old modeling you've done in the past?

Speaker B:

How do you, how do you, how do you cut down the, the, the, the amount of code you have to model to have a reasonable security analysis?

Speaker B:

And it can't be just the code that changed, right?

Speaker B:

That's one of the problems where, you know, we, we see some security scanners might be good on SQL injection or you know, weak crypto implementations and be bad on things like cross site scripting and log injection because they, they, they're, they're not looking at the entire data flow, right?

Speaker B:

They can't because in order to be fast or in order to do the analysis at all, they're, they're, they're not even looking at, you know, inter procedural or inter, inter file.

Speaker B:

They're just looking at what code changed and, and, and what's in that method.

Speaker B:

And you get these really shallow analysis.

Speaker B:

So we, we never wanted to trade off B for a shallow, a shallow analysis because then you just get a false sense of security, right?

Speaker B:

You're just, you're just missing things.

Speaker B:

So, so we, we've had to do a lot of optimization, fit into that.

Speaker A:

And now we're, we're moving to a world where everyone's becoming a developer coder, whether it being Vibe coding.

Speaker B:

Everyone's Vibe, everyone's Vibe coding.

Speaker B:

So, so yeah, so this is, the challenge is like how do you, how do you fit into the Vibe, the Vibe coders and you know, the answer from the AI companies is like, you know, we'll write the code and we'll secure, test the code and we'll secure the code for you, right?

Speaker B:

And you know, we've done research at Veracode and you know, while, you know, these, these, these, these LLM coding assistants are really good at writing code, they're really bad at writing secure code.

Speaker B:

And we've been coming out with a, a report twice a year, the Gen I coding report.

Speaker B:

And it's crazy to think of how much these coding assistants have gotten with syntax and functionality improvements.

Speaker B:

We can show you that three years ago, 50% of the time they wrote broken code.

Speaker B:

And today it's actually 99.9% of the time they write correct code.

Speaker B:

Right.

Speaker B:

0.1% Of the time they're, they're, they're writing syntactically incorrect code.

Speaker B:

I don't know if it's, you know, there's no bug, but at least it's syntactically correct.

Speaker B:

But what we've seen is as far as writing code that has a vulnerability in it, and we call this, like, if you ask it to do a, a code completion task, right, you say, hey, you know, add a new field to this form from this database, right?

Speaker B:

So you describe something you're adding to a program.

Speaker B:

The, the best, the best LLMs get it right around 60% of the time, okay.

Speaker B:

And, and, and, and the, and the worst ones get it right around 50% of the time.

Speaker B:

So there's not much of a gap.

Speaker B:

Okay.

Speaker B:

And, and this hasn't improved much over the, the three years we've been looking at.

Speaker B:

Actually, the report's been out for two years.

Speaker B:

We went retrospective for a year, so we have three coming out with our next report.

Speaker B:

In a couple weeks it'll be out, and we are seeing a little bit of movement, but not much.

Speaker B:

Not much.

Speaker B:

And so if you think about the code volume that these coding assistants give you, right?

Speaker B:

Like someone can write 10 times as much code as before.

Speaker B:

And if you think about the vulnerability, density isn't better than we've had historically in the past with humans, because of course, is complex, it's hard to write secure code.

Speaker B:

All of these LLMs have learned on the code that humans wrote that it's not very much different.

Speaker B:

And I think there can be a concerted effort to improve this.

Speaker B:

I think the companies are working on this now.

Speaker B:

I see them hiring a lot of security resources.

Speaker B:

They're mostly looking at finding vulnerabilities, not writing secure code, which we all know are two different things, right?

Speaker B:

Finding a vulnerability to.

Speaker B:

You find one thing and you're able to exploit that.

Speaker B:

Right?

Speaker B:

The exploit.

Speaker B:

Right?

Speaker B:

Your exploit chain.

Speaker B:

You need the one thing attacker can get in.

Speaker B:

The challenge is the people that are securing this have to have to fix all the things, right?

Speaker A:

So we're keeping, we're keeping, we're keeping the pressure on the, on the patching.

Speaker B:

We're keeping the pressure on the patching, right?

Speaker B:

And hopefully they'll move to more of.

Speaker B:

Let's, let's write secure code.

Speaker A:

Yeah.

Speaker B:

Right.

Speaker A:

So more secure code and less.

Speaker A:

And less patching because patching is, is still one of our Achilles heel, it's still the one that gives us lots of pain.

Speaker A:

And if we have better coding, we will have to do that less, which, you know, takes a lot of the pressure off at later stages.

Speaker A:

What's, what's some of.

Speaker A:

I'll definitely make sure that for the, the audience will get the link to the last report in the show notes as well, so it'll be easy for them to access.

Speaker A:

So how, how do you stay up to date?

Speaker A:

I mean this, this moves so fast.

Speaker A:

This industry is at such a fast pace and I've never seen it move as fast as it hasn't been the recent years.

Speaker A:

What's, how do you, how do you stay up to date?

Speaker A:

You know, are looking at the, the books and the light, you know, the bookstores, or is there other methods that you're using to, to keep up to date and learning?

Speaker B:

Yeah, I think, I think the, the books are, are probably a little obsolete now.

Speaker B:

So most, most things are, are online.

Speaker B:

You know, people do write, you know, wonderful articles now online, you know, like semi long form, right.

Speaker B:

Where you can learn from.

Speaker B:

But you know, it just seems like everything is moving so fast.

Speaker B:

You have to be close to the source which is the, you know, the Twitter post or the blog entry or you know, being on a mailing list or private slack, private signal, you know, and I, and I realized like private slacks and private signal, you already have to know people who invite you to be on those things.

Speaker B:

Right.

Speaker B:

I haven't myself created any of those things, but I've been invited so that, that keeps me up to date.

Speaker B:

But that isn't, that isn't very useful to your audience.

Speaker B:

But I think, you know, frankly following people on Twitter and LinkedIn is probably, and a little bit on, on Mastodon around to round out.

Speaker B:

But I, I, I, I, you know, it unfortunately we're fragmented across I think those three resources.

Speaker B:

I'm on Blue sky, but I don't see a lot of security content there across Mastodon.

Speaker B:

LinkedIn and, and Twitter is probably the best.

Speaker B:

It's not very efficient, right, because you got to look through a lot of other crap to, to get that like,.

Speaker A:

You know, you got a filter, you got to have a good filter to be able to see what's happening.

Speaker B:

Yeah, you can't, Yeah, you can't get, yeah, you have to steer clear of people that are trying to get you upset.

Speaker B:

But absolutely, you know, I, I think through those things you can meet people, you can find out about the conferences and the talks to go to and there's Nothing better than meeting people.

Speaker B:

Right.

Speaker B:

So I, you, you can't just be online.

Speaker B:

I mean, that was a lesson I learned early on.

Speaker B:

It's super powerful to meet people and find people that you get along with that you might actually want to work with.

Speaker B:

Right.

Speaker B:

And whether it's working at a job and that helps with networking towards, you know, being asked to come work at a startup or when you go to apply for a job, you know, some of the people who work there or a friend of a friend kind of thing.

Speaker B:

So obviously you need to get to that networking stage, but you can learn those resources through online.

Speaker B:

Like, who are these people that are speaking at the conference who are posting this stuff?

Speaker B:

I can go and I can, I can go and meet them.

Speaker B:

You know, a lot of conferences have these, you know, roundtables and workshops and things like that, which is, you know, great, a great way and, you know, hallway con is the best, is always there.

Speaker A:

It's my favorite, favorite con.

Speaker B:

Yeah.

Speaker B:

So I guess that's, you know, I keep up day to day, but I do go to a lot of, I do go to a lot of conferences and that's also a great way to keep up to.

Speaker A:

Fantastic.

Speaker A:

And for the audience as well, if they do have follow up questions, what's the best way to contact you?

Speaker A:

If they have questions afterwards?

Speaker A:

I guess LinkedIn or on one of the other platforms.

Speaker B:

So LinkedIn or Twitter is probably where I am.

Speaker B:

Where I am.

Speaker A:

Fantastic.

Speaker A:

Fantastic.

Speaker A:

We'll make sure all of those get started.

Speaker A:

The show notes.

Speaker A:

So, Chris, it's an honor always chatting with you and I always learned so much and you know, what you've done for the industry.

Speaker A:

You're definitely a legend and a rock star.

Speaker A:

So thank you for everything and look forward to catching up with you in the near future.

Speaker A:

I'm pretty sure we'll catch up at one of the hallway cons for sure.

Speaker B:

Definitely.

Speaker B:

I'll definitely be, be at Black Hat and defcon.

Speaker B:

That'll be a great place.

Speaker B:

So, yeah, thank you so much for inviting me to come on and talk and it's always great talking with you too.

Speaker A:

It's a pleasure as always.

Speaker A:

So everyone, this is the security by default podcast.

Speaker A:

Bringing you, you know, amazing lessons learned, helping you see the, you know, the, you know, through the chaos and you get clarity and hopefully you'll be able to have a, A, you know, exciting future or career no matter what path you take.

Speaker A:

As always, great lessons we can learn from the past.

Speaker A:

So stay safe, everyone.

Speaker A:

Tune in every two weeks for new episodes, new podcasts and new guests.

Speaker A:

All the best.

Speaker A:

And thank you.

Speaker A:

Stay safe.

Speaker A:

Take care.

Show artwork for Security by Default

About the Podcast

Security by Default
Security by Default is a cybersecurity podcast hosted by Joseph Carson, a renowned ethical hacker and security expert. Each episode dives into the latest security trends.
Security by Default is a cybersecurity podcast hosted by Joseph Carson, a renowned ethical hacker and security expert. Each episode dives into the latest security trends, real-world threats, and practical advice for staying safe in the digital world. With insightful interviews and clear explanations, Joseph makes complex topics accessible for both IT professionals and curious listeners alike.

About your host

Profile picture for Joseph Carson

Joseph Carson

I am a distinguished cybersecurity professional with over 30 years of experience in enterprise security and infrastructure.

Throughout my career, I have been an active contributor to the cybersecurity community, serving as an educator, ethical hacker, and speaker at global conferences. I hold both the Certified Information Systems Security Professional (CISSP) and Offensive Security Certified Professional (OSCP) certifications as well as advise various governments, critical infrastructure organizations, and industries such as finance and transportation on cybersecurity matters.
I am the author of "Cybersecurity for Dummies," a book that has gained global recognition for helping companies integrate people, processes, and technology to strengthen their defense against cyberattacks. The book has over 50,000 readers worldwide and provides a straightforward approach to understanding cybersecurity.

In addition to my writing, I have authored numerous articles and research papers, contributing to publications such as The Wall Street Journal, USA Today, Dark Reading, and CSO Magazine. I also host the bi-weekly podcast "Security by Default" which offers insights from leading cybersecurity experts and discusses best practices for navigating security challenges.
I am dedicated to educating the next generation of cybersecurity leaders and his commitment to building a safer internet have made him a respected figure in the cybersecurity community.