Cybersecurity with 1337% ABV. BarCode is a place where Cybersecurity professionals can unite in a relaxed atmosphere while getting to hear experts opensource their wisdom and insight....outside of conference walls. Untap the knowledge of an industry guru, find out what fuels their drive, or simply kick back, relax, and listen to their story. Due to COVID-19 restrictions, most bars are limited or closed for on-prem service. Therefore, each episode will feature Tony, a virtual bartender who will greet and walk us through making an exceptional yet easy-to-make beverage right from the comfort of your own home. It's Cybersecurity straight up, no chaser.Winner of a 2021 People's Choice Podcast Award (Technology Category).
In this milestone episode, Chris reconnects with old friends at the bar, reflecting on his journey from starting a humble podcast to launching a thriving security firm. The episode sets the stage for the live event in Vegas, where Chris is joined by an impressive lineup of experts, including George Gerchow, Justin Hutchins, Len Neo, Chris Wright, Matthew Canhum, and Izzy Traub.
The panel dives into a series of thought-provoking discussions centered around AI's far-reaching implications. From exploring the ethical dilemmas and security concerns to understanding the dangers of deepfake technology. Industry icon George Gerchow also opens up about the deeply personal story behind the X Foundation, highlighting the critical issue of fentanyl poisoning awareness.
As the conversation unfolds, the experts engage in a compelling exploration of AI's future, its societal impacts, and the evolving relationship between humans and technology. The episode highlights the importance of forward-thinking leadership in guiding us through this transformative shift.
TIMESTAMPS:
00:04:00 - From Bar Talk to Episode 100: A Podcast's Journey
04:17:00 - AI's Impact on Job Automation and Cybersecurity
09:41:00 - A Father's Heartbreaking Story and the Mission of the X Foundation
17:29:00 - The Future of AI: Security, Ethics, and Human Impact
28:43:00 - The Complexities and Ethics of Creating High-Quality Deepfakes
34:05:00 - The Future of Humanity and AI Integration
SYMLINKS
BarCode Security: https://barcodesecurity.com/
BarCode (LinkedIn): https://www.linkedin.com/company/barcodesecurity/
X Foundation: https://xfoundation.org/
Barcode Burger Bar (Las Vegas): https://www.barcodeburgerbar.com/
ThreatLocker: https://www.threatlocker.com/
Exploit Security: https://www.exploitsecurity.io/
Ironwood Cyber: https://www.ironwoodcyber.com/
Sevn-X: https://www.sevnx.com/
The Language of Deception: Weaponizing Next Generation AI: https://www.amazon.com/Language-Deception-Weaponizing-Next-Generation/dp/1394222548/
TED Talk - Fentanyl Poisoning: https://www.youtube.com/watch?v=z651z4pfMZs
Time Magazine Article - Fentanyl Crisis: https://time.com/6277243/fentanyl-deaths-young-people-fake-pills/
OpenAI (Stargate Supercomputer Project): https://sidecarglobal.com/blog/an-overview-of-microsoft-and-openais-ambitious-vision-for-the-future-of-ai-supercomputing
AI Trust Council: https://aitrustcouncil.org/
VFX Los Angeles: https://vfxlosangeles.com/
Inspira AI: https://inspira.ai/
PsyberLabs: https://psyber-labs.com/
DRINK INSTRUCTION
Keep it 1001 oz Captain Morgan 100 proof
1/2 oz Coffee Liqueur
1/4 oz Simple Syrup
1 ½ oz Espresso
Add all ingredients to a shaker and shake. Strain into a coupe glass.
CONNECT WITH US
www.barcodesecurity.comBecome a Sponsor
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
A reputable human systems engineer and PhD candidate, Lisa Flynn’s background encompasses launching technology startups and C-suite executive roles. Her expertise spans information systems, business models, psychology, marketing, and entrepreneurship, all foundational to cognitive security advancements.
We examined the dual-edged nature of AI, addressing both its potential for tremendous advancements and its capacity to facilitate misinformation and disinformation.
TIMESTAMPS:
00:16:00 - Navigating the AI Paradox: Innovation and Danger
07:52:00 - From Tech Entrepreneur to Anti-Trafficking Advocate
12:17:00 - AI Agents Compete Against Human Social Engineers at Defcon
19:47:00 - Innovative Approaches to Cybersecurity Education and Workforce Development
26:51:00 - Combating Deepfake Misinformation in an Increasingly Sophisticated Landscape
31:36:00 - AI’s Impact on Jobs and Cybersecurity
38:16:00 - Connectcon: A Collaborative Cybersecurity Conference Focused on Human-Centered Solutions
41:18:00 - Exploring Unique Bars and Cybersecurity-Themed Drinks in Vegas
SYMLINKS
LinkedIn (personal): https://www.linkedin.com/in/lisaflynncatalyst/
ConnectCon: https://www.connectcon.world/
C&C Generative AI Policy -
DRINK INSTRUCTION
m.AI t.AI1 1/2 oz White Rum
3/4 oz Orange Curacao
3/4 oz Lime Juice
1/2 oz Orgeat Syrup
1/2 Dark Rum
Add the white rum, curacao, lime juice and orgeat into a shaker with crushed ice and shake lightly. Pour into a rocks glass. Float the dark rum over the top. Garnish with a lime wheel and mint sprig.
CONNECT WITH US
www.barcodesecurity.comBecome a Sponsor
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
Chris Wright, founder and CEO of the AI Trust Council (AITC) stops by BarCode to share his perspective on critical issues related to artificial intelligence, corruption in big tech, and government oversight. With over 25 years of experience as an entrepreneur and former US Army attack helicopter pilot, Chris brings a unique perspective on AI and digital trust.
The episode explores the complexities of AI and its societal implications, focusing on ethical considerations, psychological impacts, and the risks of rapid AI development. Chris explains the concept of Artificial General Intelligence (AGI) and its potential to reshape human existence, emphasizing the need for regulated and ethically aligned AI systems. He also highlights the AI Trust Council's mission to promote a pro-human future amidst technological advancements. This discussion provides listeners with a comprehensive, and often not heard, understanding of the challenges and opportunities in the AI landscape.
TIMESTAMPS:
00:00:00 - Chris Wright’s Mission to Combat AI Corruption
00:04:39 - The Future of AI and Its Societal Implications
00:14:12 - The Impending Impact of AI and the Singularity
00:19:10 - Political Corruption and Corporate Influence in AI Legislation
00:21:10 - The Psychological Impact of AI Relationships and Their Realism
00:24:00 - The Impact of Chatbots on Mental Health and Society
00:27:08 - Tech Engineers’ Fascination with AI’s Potential World-Ending Future
00:28:25 - AI-Driven Drone Warfare and Its Rapid Evolution
00:32:44 - Building Trust in AI Through a Pro Human Network
00:40:41 - Exploring AI, Vegas Venues, and Cybersecurity-Themed Bars
SYMLINKS
LinkedIn (personal): https://www.linkedin.com/in/christopherwrightaitc/
AI Trust Council: https://www.theaitc.com/
DRINK INSTRUCTION
Fallen Angel2 oz Dry Gin
1 oz Lemon Juice
2 tsp Creme De Menthe
2 tsp Simple Syrup
2 dashes Aromatic Bitters
Combine all ingredients in a shaker with ice. Shake well for 15-20 seconds for maximum chill, and then strain into a cocktail glass. Optionally, garnish with mint.
CONNECT WITH US
www.barcodesecurity.comBecome a Sponsor
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
Dr. Jessica Barker is an esteemed figure in the realm of cybersecurity with a commendable history of influencing cybersecurity awareness, behavior, and culture across the globe. As the co-founder and co-CEO of Cygenta, she has made notable strides in providing face-to-face cybersecurity awareness sessions to over 50,000 individuals. With accolades such as being named one of the top 20 most influential women in cybersecurity in the UK, her expertise, especially in the human aspect of cybersecurity, is widely recognized and respected. In addition to her corporate achievements, Dr. Barker has also recently been honored with an MBE (Member of the Order of the British Empire) for services to cybersecurity, cementing her status as a leading voice and advocate in the field.
Our discussion focuses on the human element of security breaches and the importance of cultivating a culture of cybersecurity awareness within organizations. Dr. Barker shares her journey into the world of cybersecurity and discusses the evolving landscape of cyber threats, including the use of AI by cybercriminals for social engineering and deepfake technology. We highlight the significance of leadership commitment and values congruence in cultivating a robust cybersecurity culture. The effectiveness of gamification in training, a practical aspect, is also explored. The segment concludes with a personal touch, as Jessica shares her experience of receiving an MBE at Windsor Castle from Prince William. She then provides insights on her new book "Hacked: The Secrets Behind Cyberattacks".
TIMESTAMPS:
00:02:53 - From Civic Design to Cybersecurity: A Human-Centric Journey
00:06:21 - AI's Escalating Role in Cybercrime and Social Engineering
00:09:18 - Strategies for Enhancing Digital Critical Thinking
00:13:00 - Cultivating Successful Cybersecurity Cultures in Organizations
00:16:57 - Rethinking Security Culture and Training Effectiveness
00:20:27 - Dreamlike Investiture: Receiving an MBE from Prince William
00:22:15 - Royal Recognition for Cybersecurity Expertise
00:25:40 - Demystifying Cybersecurity Through Engaging Stories and Practical Advice
00:31:20 - Discovering Local Vegas Gems and Cybersecurity Bar Concepts
SYMLINKS
LinkedIn (personal): https://www.linkedin.com/in/jessica-barker/
Twitter (personal): https://twitter.com/drjessicabarker
Twitter (organization): https://twitter.com/CygentaHQ
Cygenta (company): https://www.cygenta.co.uk/
Hacked: The Secrets Behind Cyber Attacks (book): https://www.amazon.com/Hacked-Uncovering-Strategies-Secrets-Attacks/dp/1398613703
Las Vegas Arts District (location): https://dtlvarts.com/
DRINK INSTRUCTION
Purple Haze2 oz Gin
1 oz Violet Liqueur
1 oz Fresh Lemon Juice
1/2 oz Honey Syrup
1 Dash Orange Bitters
Combine all ingredients in ashaker with ice. Shake well and straininto a chilled glass. Optionally, garnishwith a twist of lemon peel or a sprig of lavender.
CONNECT WITH US
www.barcodesecurity.comBecome a Sponsor
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
SESSION TITLE:WiCys Delaware Valley Career Fair
RECORDED: 4/25/24
VENUE: Chestnut Hill College - www.chc.ed
LOCATION: Philadelphia, PA
GUEST: Job Seekers, Hiring Organizations, and Recruiters
SPONSOR: WiCys Delaware Valley - LinkedIn Page
ABOUT WICYS AND GUESTS:WiCys Delaware Valley - A community focused on fostering professional growth through networking, mentoring, and collaboration. The group brings together individuals, both women and men, who are committed to sharing their knowledge and expertise to support one another in their career advancement and personal development. By cultivating strong relationships and creating a supportive environment, The organization aims to empower its members to achieve their professional goals and enhance their skills. The organization welcomes the participation of male allies who share the same vision of promoting diversity and inclusivity in the workplace.
Pam King - A faculty member and director of the cybersecurity program at Chestnut Hill College, Pam King has played a pivotal role in establishing a robust cybersecurity and digital forensics education curriculum. With both undergraduate and graduate programs under her leadership, King has overseen the implementation of accelerated and online offerings to advance cybersecurity education.
Alex Pickenich -A recent graduate with a double major in computer science and data science and a minor in cybersecurity, Alex Pickenich is actively pursuing a career where she can merge his passion for data science with the field of cybersecurity.
Manasa Pisipati -As a second-year grad student at Penn State University Park and the president of the Women in Cybersecurity student chapter there, Manasa Pisipati leads efforts to create a supportive community for women in the cybersecurity field and to provide them with opportunities for professional development.
Yvonne Brown -A professional seeking a transition into cybersecurity, Yvonne Brown has a background in project management and shares her interest in consulting within cybersecurity, emphasizing the need for mentorship and support in new roles.
Jessica Sylvester -A risk and cybersecurity division lead for TekSystems, Jessica Sylvester has years of experience in tech staffing and professional services, and she provides insight into the recruitment process and the qualities that make candidates stand out.
Emily Rose Nunez - Software Engineer at Leidos, designs, develops, and deploys scalable and secure software solutions for diverse clients, leveraging tools like Jenkins and Jira to automate processes and collaborating with cross-functional teams to deliver innovative, high-quality solutions that meet stakeholder and end-user requirements and expectations.
Tyler Yeagor- IT Client Relations partner at Ark, leverages his strong background in technology services, client relations, and certifications in Sandler Foundation, Microsoft 365 Fundamentals, and AWS Cloud Practitioner to assist businesses with their IT obstacles, projects, and initiatives through consultative insight and timely execution, while passionately creating new and better experiences for customers and partners, and continuously learning and collaborati
CONNECT WITH US
www.barcodesecurity.comBecome a Sponsor
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
Izzy Traub, an innovative entrepreneur at the intersection of film and AI, has traversed from pioneering visual effects in the movie industry to the front lines of AI software development. With qualifications from UCLA and the University of Texas, Izzy co-founded Inspira with his COO and father, Benny, where they have patented computerized productivity systems. His expertise in managing large remote teams and pushing the boundaries of AI in VFX illuminates new possibilities for modern workflows. Izzy shares his journey from early fascination with green screen magic to his pioneering role in adapting deepfake technology. He provides insights into how deepfakes are disrupting the film industry and ignites discussion on the consequences of this powerful technology, from ethical implications to its rapid integration into advertising and beyond, painting a thought-provoking picture of AI's burgeoning role in content creation.
TIMESTAMPS:
00:00:16 - Introduction to deepfakes and their impact on perception
00:02:19 - Background in film and visual effects
00:11:23 - Interest in AI and learning coding
00:14:02 - Increase in deepfake inquiries and major deals
00:16:53 - Responsibility of AI developers in shaping the ethical advancement of deepfake tools
00:20:23 - Simplifying the deepfake production process
00:24:30 - Concerns about AI's impact on the filmmaking process
00:26:42 - Narrow application in AI leading to powerful outcomes
00:31:28 - Lack of identity safeguards for actors in the entertainment industry
00:35:03 - Potential benefits of actors adopting deepfake technology
00:39:55 - Potential impact of deepfakes on politicians and lawmakers
00:41:00 - Potential for real-time deepfakes and their applications in scams and fraud
00:44:30 - Company focus on predicting behavior, implementing AI managers, and automating high leverage tasks
00:50:23 - Benefits of a hybrid approach combining AI and human management
00:51:53 - Utilizing AI for detecting user behavior anomalies and insider threat detection
SYMLINKS
VFX LA (company): https://vfxlosangeles.com/
Sin City (movie): https://www.imdb.com/title/tt0401792/
After Effects (software): https://www.adobe.com/products/aftereffects.html
UCLA Extensions (educational institution): https://www.uclaextension.edu/
Ender's Game (movie): https://www.imdb.com/title/tt1731141/
University of Texas (educational institution): https://www.utexas.edu/
SSRN Paper: https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4739430#
Inspira AI (website): https://www.inspira.ai/
Han Barbecue (restaurant): https://www.yelp.com/biz/han-bbq-burbank
Scum and Villainy Cantina (bar): https://scumandvillainycantina.com/
Buena Vista Cigar Lounge (bar): https://www.yelp.com/biz/buena-vista-cigar-club-beverly-hills
DRINK INSTRUCTION
The Replicant1.5 oz Vodka
3/4 oz Midori
3/4 oz Lemon Juice
1/2 oz Lemon Juice
Combine all ingredients into a shaker with ice. Shake well and strain into a chilled cocktail glass.
CONNECT WITH US
www.barcodesecurity.comBecome a Sponsor
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
Iceman is a renowned figure in the world of RFID hacking, with expertise in NFC and EMV technologies. As one of the lead open-source developers for Proxmark3—a powerful platform for RFID hacking and analysis—Iceman has significantly enhanced its capabilities. He is known for overhauling the user interface and expanding the feature set to allow device owners to maximize their usage. His work in the open source community has been focused on making RFID technology more accessible and understandable, and he continues to contribute actively to the field.
TIMESTAMPS:
00:02:27 - Introduction of Iceman, RFID hacker and contributor to the Proxmark project
00:07:23 - Explanation of Proxmark device capabilities and the development of the Iceman fork
00:14:13 - Formation of the RFID research group and transitioning from a hobby to a public figure
00:17:49 - Introduction of new RFID tools, concepts, and weaponizing RFID readers for unauthorized access
00:20:40 - Effectiveness of RFID wallets and the cat-and-mouse game with weaponized readers
00:24:06 - Development of magic cards for RFID hacking and the potential impact of AI on RFID research
00:28:29 - Participation in RFID hacking competitions, CTFs, and the importance of forums and Discord for knowledge sharing
00:34:42 - Flipper Zero as a well-made tool with an ecosystem for extending functionality
00:35:57 - The future of RFID hacking, including secure communications, advanced crypto, and chip implants by Dangerous Things
00:39:38 - Iceman's experience with metal detectors, TSA, and the exciting future of RFID for hackers and end users
00:42:52 - The need for vendors to allow legal copying of items and the importance of disrupting tracking and logistics systems
00:45:07 - Iceman's recommendations for following his work and joining relevant Discord server
SYMLINKS
X: https://twitter.com/herrmann1001/
YouTube: https://youtube.com/@iceman1001/
Discord: https://discord.com/invite/QfPvGFRQxH/
Proxmark3: https://proxmark.com/
Iceman Fork: https://github.com/RfidResearchGroup/proxmark3/
Dangerous Things: https://dangerousthings.com/
Flipper Zero: https://flipperzero.one/
IceDev: icedev.se
DRINK INSTRUCTION
Wildcard1 oz Cardamaro
1 oz Genever
1 oz Cynar
Add all ingredients to a shaker filled with ice. Stir until chilled and properly diluted. Strain into a lowball glass filled with fresh ice. Optionally garnish with a sprig of rosemary or an orange peel.
CONNECT WITH US
www.barcodesecurity.comBecome a Sponsor
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
Hutch, an expert in AI and cybersecurity, discusses his early interest in using AI for algorithmic trading and automating social engineering attacks with chatbots. He highlights two main cyber risks of advanced AI - the ability to manipulate people and autonomously execute attacks. Hutch and Chris explore issues like commercialization of AI versus proprietary chatbots, and tech companies' ethical duties to reduce AI risks through testing and responsible development. They delve into potential weaponization of AI in lethal autonomous weapons and "flash wars", as well as risks from intelligent humanoids. The need for global AI partnerships is discussed, but challenged by current geopolitics. Private sector researchers and companies have a key role in addressing AI safety and risks. However, adversaries likely have an edge in exploiting AI vulnerabilities, underscoring the importance of innovative defense strategies.
TIMESTAMPS:
00:02:14 - Introduction to Justin Hutchins (Hutch) and his background
00:03:43 - Hutch's interest in AI and cybersecurity
00:08:43 - Discussion on GPT-4 and its key risks
00:15:21 - Comparison between different AI platforms
00:20:28 - Viability of weaponizing emerging technologies
00:25:10 - Viability of embedding AI into realistic form factors
00:30:53 - Psychological effects of chatbots on humanity
00:35:48 - The need for global partnerships to regulate AI
00:40:36 - Adapting AI capabilities for weaponization
00:47:30 - Adversarial threat actors and their adaptation to AI
00:50:46 - AI systems circumventing security controls
00:53:48 - The concept of singularity in AI
SYMLINKS
Linkedin: https://www.linkedin.com/in/justinhutchens/
X: https://twitter.com/sociosploit/status/1546218889675259904
The Language of Deception- Weaponizing Next Generation: https://www.amazon.com/Language-Deception-Weaponizing-Next-Generation/dp/1394222548/
Socioploit: https://www.sociosploit.com/
Cyber Cognition Podcast: https://www.itspmagazine.com/cyber-cognition-podcast
DRINK INSTRUCTION
The Hallucination1 oz Elderflower Liqueur
1 oz Absinthe
1 oz Fresh Lemon Juice
Guava Soda
Add ice into a chilled cocktail glass. Add the Elderflower Liqueur, Absinthe, and lemon juice into a cocktail shaker without ice. Shake vigorously. Strain into the glass with ice. Top off with guava soda.
CONNECT WITH US
www.barcodesecurity.comBecome a Sponsor
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
Wirefall is an Air Force veteran and cybersecurity expert. Wirefall shares his journey into hacking, from his early days of electronics tinkering to his career in security consulting. He also discusses the founding of the Dallas Hackers Association and the importance of community in the cybersecurity field. Wirefall explores the evolving cyber threat landscape and the potential impact of AI on hacking. Plus, he reveals how his newfound passion for improv has helped him overcome fear and become a better communicator.
TIMESTAMPS:
0:03:37 - Wirefall’s early exposure to technology and computers
0:06:06 - How Wirefall started hacking and manipulating computer systems
0:10:50 - Wirefall’s curiosity about the World Wide Web and exploration of the internet
0:12:40 - Transitioning from a network technician to a security consultant during the dot-com boom
0:14:23 - The need for security on the enterprise level and the awareness of professionals
0:19:31 - The desire for a different format of talks at local cybersecurity groups
0:23:11 - The meetup is held at encore family karaoke
0:28:26 - The threat landscape has remained similar over the years
0:30:22 - Wirefall’s transformation and interest in AI and machine learning
0:35:19 - Wirefall’s experience with improv and its parallels to hacking
0:41:33 - Improv helps with pivoting and redirecting
0:47:46 - Finding Wirefall on social media
SYMLINKS
Twitter: @DHAhole
LinkedIn Profile: https://www.linkedin.com/in/wirefall/
Telesploit: https://www.telesploit.com/
DHA (Dallas Hackers Association): https://www.meetup.com/dallas-hackers-association/
DC214:https://www.meetup.com/dc214dfw/
DRINK INSTRUCTION
Lone Ranger1 1/2 oz Blanco Tequila
3/4 oz Freah Lemon Juice
1/2 oz Simple Syrup
2 oz Sparkling Wine
Lemon Twist
Fill a shaker with ice. Add in tequila. lemon juice and simple syrup. Shake well and then strain into an ice filled glass. Top with sparkling wine. Optionally garnish with a lime twist.
CONNECT WITH US
www.barcodesecurity.comBecome a Sponsor
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
Peter Schwacker is a cybersecurity thought leader with over 25 years of experience. Peter shares his unconventional journey in the industry, his passion for continuous learning, and his belief in the power of curiosity. He also discusses the importance of community building and the need for a deeper understanding of the roots of cybersecurity. With his unique perspective, Peter challenges the status quo and offers insights into the future of the industry.
TIMESTAMPS:
0:03:06 - Discussing Peter's background and journey to Mexico
0:08:47 - Differences between US and Mexican cyber culture
0:11:28 - The impact of niche knowledge in today's world
0:13:15 - Peter's fascination with technology and the concept of magic
0:14:51 - Peter's eclectic approach to security
0:17:38 - The establishment of a Linux user group and practical activities
0:20:19 - The size and structure of the community
0:23:23 - The importance of hands-on experience and practical training
0:25:36 - The significance of software development skills in cybersecurity
0:27:08 - The need to understand the history and foundations of security
0:30:07 - The essential characteristic of security: an intelligent, malicious adversary
0:32:02 - The potential for security to learn from other industries
0:35:03 - The power of the human mind and skepticism towards AI
0:38:38 - Where to find Peter and connect with him onlineP
SYMLINKSPeter Schwacker's LinkedIn
Nearshore Cyber Website
Books and Literature Mentioned:
DRINK INSTRUCTION
Paloma2 oz Blanco Tequila
1/2 oz Fresh Lime Juice
1/2 oz Simple Syrup
1/4 cup Grapefruit Juice
Sparkling water
Ice
Fill a glass with ice. Add in tequila,lime juice, simple syrup and grapefruitjuice. Top off with sparking water. Optionally garnish with a lime.
CONNECT WITH US
www.barcodesecurity.comBecome a Sponsor
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
SESSION TITLE: IBM X-FORCE
RECORDED: 12/13/23
VENUE: City Winery
LOCATION: Philadelphia, PA
GUEST: John Dwyer
SPONSOR: IBM
ABOUT THE GUEST:
John Dwyer - John Dwyer is the Head of Research for IBM Security X-Force. He has extensive experience in cybersecurity research, threat actor behavioral modeling, immersive incident response simulations, and integrated security technologies. John is a highly regarded speaker at industry events and has expertise in AI, threat hunting, and detection engineering.
John Dwyer discusses the impact of artificial intelligence (AI) on the threat landscape and the changing role of AI in security tools. He emphasizes the importance of understanding the goals and objectives of attackers and how AI can be used to enhance security measures. John also highlights the need for proactive risk reduction strategies and the potential of AI in threat detection and response automation. He concludes by discussing the future possibilities of fully immersive deception and the importance of training and awareness in the face of evolving cyber risks.
TIMESTAMPS:
00:01:00 - Introduction and thanks to sponsor IBM
00:02:28 - Introduction of guest, John Dwyer
00:08:28 - Discussion on how AI is changing the threat landscape
00:11:33 - AI’s impact on security tools and risks introduced
00:13:48 - Commercial vs proprietary LLMs for organizations
00:15:06 - Predicting attack surfaces in AI and importance of security fundamentals
00:16:17 - Differentiating between credible threats and hype threats
00:18:13 - Goals of financially motivated threat actors
00:20:35 - Phishing attacks and the need for better defense strategies
00:24:17 - Altering security awareness stance for employees
00:26:09 - AI capabilities in threat detection, response automation, and vulnerability analysis
00:29:11 - Need to invest in infrastructure and innovation to combat crime
00:30:15 - Guidance for proactive risk reduction outside of AI
00:33:57 - IBM Xforce Threat Intelligence index provides year in review
00:37:08 - Closing remarks and thank yous
EVENT PHOTOS
CONNECT WITH US
www.barcodesecurity.comBecome a Sponsor
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
SESSION TITLE: LONE STAR CYBER CIRCUS
RECORDED: 12/7/23
VENUE: Hop and Sting
LOCATION: Grapevine, TX
GUESTS: Various
SPONSOR: IBM
ABOUT THE GUESTS:
Cyber Distortion -Security leaders Kevin Pentecost and Jason Popillion joined forced to create " Cyber Distortion", a leading security podcast which they describe as their own way of paying back an industry that has been so amazing to them over the past couple of decades. They believe that as cybersecurity experts, we all play a critical role in protecting businesses and individuals from cyber threats.
Phillip Wylie - Phillip is an offensive security professional with over 25 years of passion and experience in information technology and cybersecurity specializing in penetration testing, assessments, application security, and threat and vulnerability management. An international speaker and author, Phillip shares his expertise by hosting The Hacker Factory Podcast and Phillip Wylie Show while also serving as a penetration tester, instructor, and founder of the DEFCON Group 940.
Wirefall - As a military and law enforcement veteran, local security community advocate, and entrepreneur behind Telesploit, Wirefall has over 25 years of experience, including founding the Dallas Hackers Association while consulting on attack and penetration tests, having previously served on the boards of BSides DFW and TheLab.MS.
Juneau Jones-Raised in the Alaskan wilderness where she developed her love of hacking through building and breaking things, Juneau later studied computer science and economics before moving to Dallas, Texas and finding her place in the local hacker community where she now works as an adversarial analyst while continuing her cybersecurity research.
NEURAL PHANTOM-@hacknotcrime advocate/Marine Corps Veteran/CISO/Leader of @Hack_FtW/Mentor/Public Speaker/Hacker/Gamer/Meiklejohnian absolutist.
Justin "Hutch" Hutchins -Industry leader in the fields of cybersecurity, artificial intelligence, and technical risk management. He is the creator of Sociosploit, a research blog which examines exploitation opportunities on the social web – a confluence of his interests in both technical hacking and social psychology. He is the host of Cyber Cognition, a podcast focused on trends and risks related to emerging artificial intelligence and machine learning technologies. And he is the author of "The Language of Deception: Weaponizing Next Generation AI." Hutch has also spoken at multiple conferences to include HouSecCon, Texas Cyber Summit, ISSA, ToorCon, DEFCON, and RSA Conference
Quentin Rhoads-Herrera -Seasoned information security professional with over 15 years of experience leading security teams and safeguarding organizations. Expertise includes security analysis, risk assessments, penetration testing, and physical security implementations. Instrumental in building and maturing security programs for Fortune 500 companies, mitigating risks, and protecting critical assets.
The Barcode podcast welcomes cybersecurity leaders and ethical hackers to the Lone Star Cyber Circus LIVE in Grapevine, TX. The guest panel, comprised of Texas-based cybersecurity professionals, discusses the growth of the hacker community in the DFW area and the impact of AI on the threat landscape. They highlight the potential for AI to be used in offensive and defensive cybersecurity strategies, but also cau
CONNECT WITH US
www.barcodesecurity.comBecome a Sponsor
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
Kevin Pentecost and Jason Poppillon, hosts of the Cyber Distortion podcast, stop by BarCode to share their experiences and insights in the field of cybersecurity. We discuss topics such as ransomware, social engineering, and the CISSP. Their podcast combines technical expertise with a fun and engaging approach, making it accessible to both technical and non-technical audiences. They also highlight the importance of networking and building relationships in the cybersecurity industry.
TIMESTAMPS:
0:00: Introductions and cybersecurity importance
0:05: Hosts' backgrounds
0:07: Ransomware attack experience
0:09: Lessons learned
0:11: Preparedness
0:15: How hosts met
0:24: CDP - Goals and approach
0:29: Content delivery balancing
0:31: Episode output
0:34: Memorable guests
0:42: Production workflow
0:47: Process improvements
0:50: Future topics
0:55: CDP future plans
1:08: Where to connect with CDP
SYMLINKSCDP - YOUTUBE
Kevin - Linkedin
Jason - Linkedin DRINK INSTRUCTION
Crooked Tree2 oz Bourbon
3/4 oz Lemon Juice
3/4 oz Honey Syrup
Combine all ingredients into a shaker with ice. Shake it and then fine strain into a rocks glass.
CONNECT WITH US
www.barcodesecurity.comBecome a Sponsor
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
Vivek Ramachandran is a cybersecurity professional and the founder of SquareX, a browser-based cybersecurity solution. He is known for his groundbreaking Wi-Fi attack discoveries, best-selling hacking books, and trainings for cybersecurity professionals worldwide. Vivek is also the creator of the hacker comic book series, "Hackers: Superheroes of the Digital Age."
Vivek stops by the bar to to discuss his background in cybersecurity and his journey to becoming an entrepreneur. He shares how his curiosity and passion for technology led him to teach himself programming and eventually specialize in cybersecurity. He also talks about the inspiration behind VRN Comics, and the importance of demystifying hacking for the general public. Vivek then delves into the concept of SquareX, a deterministic cybersecurity solution that aims to provide productivity-first protection by isolating and disposing of potentially malicious files and websites. He explains how SquareX uses containerization and cloud-based technology to ensure that users can safely open documents and visit websites without the risk of infection. Vivek concludes by discussing the future of malware and the role of AI in cybersecurity, emphasizing the need for deterministic security solutions like SquareX to combat evolving threats.
TIMESTAMPS:
0:00:00: Introduction to Barcode and Elite consulting services
0:01:20: Introduction to Vivek Ramachandran and his achievements
0:02:56: Introduction to the Superhero Sipper cocktail
0:03:34: Vivek's background and journey into cybersecurity
0:08:54: Vivek's experience in college and internships
0:12:37: Vivek's internship opportunity in wireless LAN security
0:13:38: On-site internship at a university in Zurich
0:14:24: WLAN security and lack of practical experience
0:15:03: Early stages of WLAN security and network administration
0:15:37: Learning WLAN and WLAN security quickly
0:16:49: Joining Airtight Networks and getting a lucky break
0:17:49: Getting the opportunity to speak at Defcon and Black Hat
0:18:43: Transitioning from practitioner to entrepreneur
0:19:38: Creating SecurityTube and initial discouragement
0:21:08: Positive feedback and growing readership
0:23:33: Quitting job to pursue research and training full-time
0:26:05: Perseverance and hard work in cybersecurity
0:27:03: Creating VRN comics to demystify hacking
0:29:36: Changing the negative perception of hackers
0:34:55: Identifying the need for a new cybersecurity solution
0:36:21: Problems with existing endpoint security solutions
0:37:50: Moving from probabilistic to deterministic security
0:38:18: SquareX's productivity-first approach to endpoint security
0:39:44: SquareX's seamless user experience and isolation solutions
0:40:40: SquareX's freemium model for both consumers and enterprises
0:43:29: AI's potential to supercharge malware and phishing attacks
0:46:26: SquareX's deterministic security approach in the face of AI threats
0:47:44: Vivek's love for meeting motivated individuals and exchanging ideas
0:48:30: Vivek's unique experience at Black Hat Abu Dhabi
0:50:55: Connect with Vivek and learn more about SquareX at sqrx.com
SYMLINKSVivek - Linkedin
Vivek - XSquareX - Linkedin
SquareX - X
CONNECT WITH US
www.barcodesecurity.comBecome a Sponsor
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
SESSION TITLE: BELOW DECK
RECORDED: 10/26/23
VENUE: Rendezvous (Private Yacht)
LOCATION: Philadelphia, PA
GUEST: David Lingenfelter, Anahi Santiago and Tammy Klotz
SPONSOR: N/A
ABOUT THE GUESTS:
David Lingenfelter -VP of Information Security at Penn Entertainment, with a 30-year career in cybersecurity.
Anahi Santiago - CISO at Christiana Care, the largest health system in Delaware, with a passion for healthcare cybersecurity.
Tammy Klotz - CISO at Trinzio, with 7 years of experience in cybersecurity in the manufacturing industry.
By way of an invation sent by VP of IT for Visit Philadelphia, Keith McMeniman, Chris hosts a live podcast on a yacht with three esteemed Philadelphia based security leaders: David Lingenfelter, Anahi Santiago, and Tammy Klotz. They discuss the current state of cybersecurity, the challenges they face in their respective industries, and the importance of educating and raising awareness among end users. They also touch on the potential of AI in cybersecurity and the need for collaboration between different stakeholders in the organization.
TIMESTAMPS:
0:00:06 - Introduction to the podcast and the guests
0:04:18 - Priorities in different industries: manufacturing, healthcare, and gaming
0:08:32 - Lessons learned from recent breaches and social engineering attacks
0:13:18 - Importance of continuous cybersecurity training and awareness
0:14:51 - Innovations on the horizon to combat cyber risks
0:14:51 - Introduction to the topic of cyber risks and new technologies
0:15:39 - Buzz around artificial intelligence and its potential
0:17:28 - Recognition of innovative cybersecurity startups
0:18:43 - Discussion on the adoption and governance of AI technologies
0:21:22 - Importance of user awareness and education
0:22:03 - AI's role in enabling end users to understand risks
0:25:26 - Engaging with end users and understanding their needs
0:27:08 - AI's impact on healthcare diagnosis and complex cases
0:28:38 - Collaboration between cybersecurity and clinical experts
0:30:20 - Conclusion on the need for collective decision making in AI implementation
0:30:18 - Discussion about the need for a team to solve problems
0:30:39 - Importance of involving stakeholders in conversations
0:31:48 - Question about favorite bar in Philadelphia
0:32:26 - David talks about his basement bar, the Underground Cantina
0:32:55 - David's bourbon of choice
0:33:17 - Anahi's preference for watching the Super Bowl in Las Vegas
0:33:26 - Anahi's favorite bar, St. Stephen's Green
0:33:47 - Tammy mentions she doesn't have a favorite Philly bar
0:34:03 - Chris mentions Barcode Security and its advisory services
EVENT PHOTOS
CONNECT WITH US
www.barcodesecurity.comBecome a Sponsor
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
Paul V. McEnroe is an award-winning engineer and former IBM executive who played a pivotal role in the development of the universal product code (UPC), also known as the barcode. With over two decades of experience at IBM, McEnroe led a team that created one of the most influential technologies of our generation. He is the author of the business memoir titled "The Barcode," which tells the story of his journey and the development of the barcode.
McEnroe shares his background, from being adopted as a child to his education and career at IBM. He discusses how he became involved in the development of the barcode and the challenges he faced along the way. McEnroe also reflects on the unexpected uses and impact of the barcode, such as its role in Amazon's operations. He emphasizes the importance of teamwork and mentorship in achieving success and offers advice for structuring effective teams.
TIMESTAMPS:
0:01:27: Introduction to Paul V. McEnroe and his role in developing the barcode
0:02:20: Paul's background and journey to IBM
0:04:09: Paul's role in starting a new business at IBM
0:06:21: Choosing the point of sale industry for barcode implementation
0:08:43: The selection of IBM's barcode as the industry standard
0:10:15: The complexity of developing the barcode system
0:12:05: The technological challenges and innovations in barcode implementation
0:14:32: The unexpected impact and innovative uses of the barcode
0:14:51: Conclusion and final thoughts on the barcode's legacy
0:15:23: Jeff Bezos made money on barcodes through Amazon automation
0:16:39: Barcode technology wiped out traditional stores like Macy's.
0:17:49: 18 states passed laws against barcodes, causing legal issues
0:19:19: Paul had to become a lobbyist to explain barcode benefits
0:20:59: Canadian woman found barcode system helpful for price comparison
0:22:14: IBM lawyers worried about eye safety and laser suicide
0:25:04: Paul became president of Trilogy after leaving IBM
0:27:49: QR codes were a natural evolution of barcode technology
0:29:10: QR codes offer more data but may not compete with barcodes
0:30:06: Reading barcodes at high speeds was a challenge in development
0:30:33: Paul recalls the CEO's skepticism about the barcode project
0:31:11: The CEO tests the barcode's functionality and is amazed
0:32:18: Barcodes are still relevant and have magnetic encoding for retail
0:34:18: Paul shares his motivation for writing a memoir about the barcode
0:37:18: Paul emphasizes the importance of teamwork in achieving goals
0:39:14: Paul discusses the composition of his barcode development team
0:41:11: Paul adds more engineers to his team to cover various expertise
0:43:31: Communication and leadership are crucial for a successful team
0:45:16: Problem with the code: it needed to be small
0:46:03: X scan for the barcode
0:48:10: Importance of teamwork in creating the barcode
0:49:06: Mentorship played a pivotal role in Paul's success
SYMLINKSENTREPRENEUR.COMThe Barcode: How a Team Created One of the World's Most Ubiquitous Technologies DRINK INSTRUCTION
The U.P.C.1 oz Unaged Rum
1 oz Peach Liquor
1 oz Cranberry JuiceCombine all ingredients in a glass with ice.
CONNECT WITH US
www.barcodesecurity.comBecome a Sponsor
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
Ron Nissim, co-founder and CEO of Entitle IO, joins Chris at the bar to discuss identity and access management (IAM) in the cloud. They explore the differences between traditional IAM and cloud IAM, as well as the pain points organizations commonly face with access requests and approval processes. Ron shares a specific incident that sparked the idea for Entitle IO and explains how their platform has helped organizations improve their IAM efforts. He also discusses the future of IAM and upcoming features from Entitle IO.
TIMESTAMPS:
0:00:16 - Introduction to IAM and its importance in security
0:01:49 - Differences between traditional IAM and cloud IAM
0:05:33 - The need for cloud IAM due to common access management issues
0:08:18 - Pain points in traditional access requests and approval processes
0:11:49 - Success story of a company implementing Entitle IO
0:12:45 - Rapid deployment of Entitle IO
0:13:12 - Importance of cloud native approach and reducing administrative privileges
0:14:59 - Difficulty of calculating ROI in security
0:16:14 - Overcoming resistance to change in organizations
0:19:07 - Strategies for organizations hesitant to transition to new methodologies
0:22:19 - Features and differentiators of Entitle IO as an innovative solution
0:26:17 - Change management policy and attribute-based model for access provisioning.
0:27:20 - Automated governance and visibility into access and permissions.
0:28:15 - Future of privileged access management (PAM) for cloud resources.
0:29:03 - Evolving aspects of PAM: connectivity, authentication, authorization, and session recording.
0:31:43 - Entitle IO's upcoming open source project for connectivity and authentication.
0:33:12 - Importance of collaboration and feedback from industry professionals.
0:33:54 - Contact information for Ron Nistam and Entitle IO.
SYMLINKSRon Nissim - Linkedin
Entitle.io - Linkedin
Entitle.io
DRINK INSTRUCTION
GOTHAM MARTINI
2 oz Vodka
1 splash Blackberry Schnapps
1 splash Black Sambuca
In a cocktail shaker filled with ice,combine all ingredients. Shakevigorously for 10-15 seconds.Strain into chilled glass.
EPISODE SPONSOREntitle.io
CONNECT WITH US
www.barcodesecurity.comBecome a Sponsor
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
Mike Petrie, a pioneer in the fraud investigative industry, discusses his journey into the field and the evolution of investigative techniques. He emphasizes the importance of social media intelligence and the role it plays in uncovering fraud. Mike also highlights the need for education on protecting personal information and the integration of AI in fraud detection and prevention. He shares advice for aspiring investigators and discusses the concept of Webutation, a platform for protecting online reputations. Discover the hidden truths, covert operations, and the art of undercover work that define the intriguing realm of sub rosa AKA "Under The Rose" investigations.
TIMESTAMPS:
0:00:16 - The role of private investigators
0:02:15 - Mike's background and interest in investigative work
0:04:24 - Getting started in the private investigation industry
0:06:12 - Opening a startup in the investigative field
0:07:40 - Working on fraud cases in the insurance industry
0:09:06 - The methodology used pre-internet for gathering evidence
0:11:37 - Challenges and dangers faced during field surveillance
0:13:11 - Pretexting and social engineering as methods of gathering information
0:13:44 - Ensuring personal safety in dangerous situations
0:13:36 - Gaining intel pre-OSINT and pre-social media
0:14:06 - Ensuring personal safety through preparation and blending in
0:15:56 - Transitioning to leverage OSINT as an intelligence tool
0:20:45 - Educating individuals about the criticality of protecting personal data
0:24:35 - Fraud techniques evolving and the need to inform others
0:25:14 - The impact of removing metadata on investigators and using OSINT
0:26:33 - The abundance of social network sites and their usefulness
0:26:54 - Discussion on the deep web and illegal activities
0:27:40 - Warning about dangerous chat room sites for kids
0:29:15 - Integration of AI in fraud detection and prevention
0:30:09 - Use of facial recognition software in investigations
0:31:46 - Limitations of relying on Google for investigations
0:32:53 - AI's role in analyzing images, videos, and data
0:35:49 - Importance of human involvement in research
0:36:32 - Advice for aspiring investigators and learning resources
0:40:53 - Mike's expertise and public speaking engagements
0:41:24 - Building and selling a search platform
0:41:53 - Importance of online reputation and its impact on trust
0:42:37 - Social media intelligence gathering for critical decision-making
0:43:40 - Advocating for thorough gun purchase background checks
0:44:39 - Webutation benefits both individuals and businesses
0:45:08 - Webutation's URL: webutation.io
0:46:03 - Special thanks to family, business partner, and mentors
0:46:49 - Favorite bars in Philadelphia and outside of Philly
0:48:06 - Recommended bar in Mumbai and recent favorites in Miami
SYMLINKSLinkedIn
Webutation
DRINK INSTRUCTION
THE SHADOW
2 Oz Gin
1 Oz Chilled Earl Gret Tea
1/2 Oz Creme De Violette
1/2 Oz Fresh Lemon Juice
Lemon Twist (Optional)
In a cocktail shaker, combine gin,chilled Earl Grey tea, Crème deViolette, and fresh lemon juice.Fill the shaker with ice, and shakevigorously. Strain into chilled glass.Optionally, garnish with a lemon twist.
EPISODE SPONSORN/A
CONNECT WITH USBecome a Sponsor
Support us on Patreon
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
SESSION TITLE: METAWAR
RECORDED: 8/10/23
VENUE: Virgil's Real BBQ
LOCATION: Las Vegas, NV
GUEST: Winn Schwartau
SPONSOR: Sayers
TIMESTAMPS:
0:02:30 - Introduction to the METAWAR Project and the challenge of reality distortion
0:04:00 - Explanation of the six steps of the METAWAR thesis
0:05:58 - Discussion on immersive experiences and reality distortion
0:09:37 - Explanation of reality distortion and the difference between disinformation and misinformation
0:15:38 - Discussion on the addictive nature of rewards in the metaverse
0:18:02 - Exploration of the potential benefits of the metaverse
0:20:50 - Conversation on the impact of the metaverse on mental and physical health
0:26:48 - Discussion on the fluid nature of the metaverse and the potential for involuntary addiction
0:28:49 - Explanation of compliance and the need for governance in the metaverse
0:30:45 - Fun question about opening a metaverse-themed bar and signature drinks
EVENT VIDEO
EVENT PHOTOS
CONNECT WITH USBecome a Sponsor
Support us on Patreon
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
SESSION TITLE: How I Rob Banks
RECORDED: 8/9/23
VENUE: BAR CODE BURGER BAR
LOCATION: Las Vegas, NV
GUEST: FC (Freaky Clown)
SPONSOR: Cyber Job Academy
TIMESTAMPS:
0:00:22 - Introduction and discussion about FC's book "I Rob Banks"
0:01:12 - Reconnaissance and the importance of overplanning
0:02:07 - Digital recon and the limitations of Google Maps
0:03:36 - The value of extensive recon and avoiding people
0:04:21 - Possibility of book adaptation into a feature film
0:05:00 - Speculation on who would play the author in a movie
0:06:04 - The author's best skill in social engineering: avoiding people
0:06:34 - Successfully getting into secure areas without physical tools
0:07:09 - Exploiting cultural tendencies in social engineering
0:08:34 - The importance of the letter of authority in social engineering
0:10:57 - A dangerous encounter with armed guards during an engagement
0:12:42 - The shift in physical security assessments at Cygenta
0:16:04 - The limitations of AI in recon and information gathering
0:18:18 - Organizations' trust in AI as a potential vulnerability
0:19:20 - Where to find the author online
0:20:32 - The author's go-to beverage for decompressing
0:21:20 - Discussion on opening a cybersecurity-themed bar
0:22:57 - Filming a documentary and closing remarks
EVENT VIDEO
EVENT PHOTOS
CONNECT WITH USBecome a Sponsor
Support us on Patreon
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
In the unpredictable landscape of the digital mountains, a remarkable group of Sherpas thrives as guides, offering vital information during expeditions. Among them, Tracy Z. Maleeff stands out as a cybersecurity expert, leading and inspiring others on their journey. Her story takes her from the humble setting of a library to the forefront of cybersecurity, where she provides essential guidance and support, navigating through the peaks and valleys of the cyber realm.
TIMESTAMPS:
0:03:25 - Tracy's journey from law firm librarian to cybersecurity
0:08:33 - Tracy's transition into the technology field
0:17:26 - Tracy's experience with tech meetups and finding her niche
0:22:41 - The importance of putting in the work to transition careers
0:33:59 - The value of diversity of thought in the cybersecurity industry
0:40:00 - Tracy's passion for creating a culture of diversity and inclusion
0:51:57 - The importance of approachability and empathy in cybersecurity
SYMLINKSLinktr.eeLinkedIn
Twitter
Medium
DRINK INSTRUCTION
NON-FICTION
1 1/2 Oz Gin
3/4 Oz Elderflower Liqueur
1/2 Oz Fresh Lemon Juice
1/2 Oz Lavender Syrup
2 Dashes Orange Bitters
Sprig of Fresh Lavender
INTERVIEWERSChris Glanden
Rohan Light
EPISODE SPONSORCrowdSec
CONNECT WITH USBecome a Sponsor
Support us on Patreon
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
Cybersecurity professionals are essential for keeping organizations safe from potential threats and ensuring business continuity. According to recent studies, the demand for cybersecurity professionals has surged significantly, and this trend is expected to continue. Unfortunately, qualified people are still having a hard time breaking into the industry, although it's not impossible. And there is help from insiders that are here to help with the process.
Colleen Lennox, founder of Cyber Job Central, and Jason Brooks, co-founder of Relative AI, discuss the challenges faced by aspiring professionals trying to break into the cybersecurity industry. They introduce Cyber Job Academy, a platform that offers courses taught by industry experts to help individuals prepare for a career in cybersecurity. They also highlight the benefits of using AI technology, such as Relative.ai's avatar, ARIA, to practice and improve interview skills. The goal is to provide individuals with the tools, resources, and cheat codes needed to succeed in the cybersecurity field.
TIMESTAMPS:
0:02:46 - Challenges faced by aspiring professionals in breaking into the cybersecurity industry
0:09:39 - Overview of Cyber Job Academy and its role in addressing these challenges
0:11:38 - Introduction to Relative AI and its role in enhancing interview skills
0:14:15 - Discussion on ARIA, the avatar used in the Cyber Job Academy
0:16:59 - The ability of ARIA to pivot responses based on applicant input
0:23:00 - Advantages of Cyber Job Academy for students
0:27:30 - The potential of AI to eliminate bias in the hiring process
0:34:03 - Where to find more information about Cyber Job Central and the Academy
0:41:41 - The best bar in Philly and favorite drinks for Colleen and Jason
SYMLINKSLinkedin - Jason Brooks
Linkedin - Colleen Lennox
Cyber Job Central
Relativ.ai
DRINK INSTRUCTION
AVATAR
1 Oz Vodka
1/2 Oz Blue Curacao
1/2 Cup Lemonade
1/4 Cup Orange Juice
Ice
Pour all ingredients over ice into a glass and top off with Orange Juice.
INTERVIEWERSChris Glanden
EPISODE SPONSORN/A
CONNECT WITH USBecome a Sponsor
Support us on Patreon
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
Often, risk and reward collide. Corporate giants and high-stakes gamblers unknowingly walk parallel paths. Their worlds may seem separate to outsiders, although fate has a way of intertwining their destinies. Both are driven by ambition, chasing triumph. But as their desires for success grow, a hidden truth begins to reveal itself. LLMs, like the roll of Snake Eyes in a dice game, hold the power to shape kismet and shatter dreams. The line between success and ruin is as fragile as the edge of a dice. As corporate entities collide with the ultimate risktakers, a new game emerges.
Allen Woods served as a soldier in the British Army, primarily with Infantry battalions. Afterwards, he made a pivotal decision to enter into the world of computing. He devoted himself to studies, and eventually reached the esteemed level of a degree . He is a Charter member of the British Computer Society, and has extensive experience in building information management frameworks. He stops by BarCode to share his incredible journey of transformation, risk, and lifelong pursuit of knowledge. We focus on software development, Cybernetics, LLMs and fragility within data relationships.
TIMESTAMPS:
0:06:12 - Military IT Career and Knowledge Sharing
0:12:43 - The Value of Connecting Databases
0:17:45 - Incorporating Cybernetics in Software Development
0:21:02 - Technological Economy's Low Equilibrium State
0:27:01 - Importance of Due Diligence
0:32:03 - Exploiting Relationships in Network Science
0:38:59 - The UK Post Office's Horizon System
0:42:47 - Limits of Probability Testing in AI
0:48:28 - LLMs in Small Businesses
SYMLINKSLinkedIn
British Computer Society
Ludwig von Bertalanffy’s “General Systemology”
"Autopoiesis and Congition: The Realization of the Living" by Humberto Maturana
"Brain of the Firm" by Stafford Beer
"The Heart of Enterprise" by Stafford Beer
"Living Systems" by James Greer Miller
Stephen Wolfram Writings
Common Crawl Dataset
Project Gutenberg
Network Science by Barabási
UK Post Office Horizon Case
"The Age of Surveillance Capitalism" by Shoshana Zuboff
DRINK INSTRUCTION
THE LAST MECHANICAL ART
3/4 Oz Mezcal
3/4 Oz Cynar
3/4 Oz Sweet Vermouth
3/4 Oz Campari
Stir all ingredients in an ice-filled mixing glass and strain into a chilled coupe. Optionally garnish with an Orange twist.
INTERVIEWERSChris Glanden
Rohan Light
Mike Elkins
EPISODE SPONSORTUXCARE
CONNECT WITH USBecome a Sponsor
Support us on Patreon
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
Embark on a captivating journey as we venture into the enigmatic and clandestine world lurking below the surface of the internet. Prepare to explore the depths of cybercrime, illicit trades, and covert activities that take place in the digital underworld.
Larry Herzog, a Senior Sales Engineer for Thales, joins me at the bar to discuss the origins of the Darkweb, the technological underpinnings, aestetics, diverse marketplace services and the potential pitfalls of using it.
TIMESTAMPS:
0:02:56 - An Overview of Its Architecture and Anonymity Features
0:09:14 - Tails OS and Privacy Tools
0:11:11 - Understanding the Risks of Cash Access, Credit, and Debit Services
0:13:16 - The Risks of Credit Card Fraud and How to Protect Yourself
0:17:13 - Dark Web Search Engines: Exploring User Friendliness and Functionality
0:19:01 - Search Engines, Illegal Drugs, and Contract Killers
0:22:20 - Cybercriminal Services and "As-A-Service" Price Points
0:24:33 - Exploits, RaaS, and Crowdfunding
0:29:35 - Bitcoin Mixing and Tumbling Services
0:32:20 - Obtaining Services, Equipment, and New Identities
0:34:05 - An Overview of Marketplace Services and Cybercrime Networks
0:38:20 - The Risk of Operating on the Dark Web
0:40:42 - Exit Node Monitoring and Social Engineering
0:42:13 - Ransomware Protection Mechanisms
SYMLINKSLinkedIn
Twitter
Internet 2
Freenode IRC
TOR
Tails OS
AlphaBay
Dream Market
Silk Road
DRINK INSTRUCTION
LABYRINTH
1 Part Rye Bourbon
1/2 Part Oloroso Sherry
1/4 Part Amaretto
3 dashes Angostura Bitters.
Stir all ingredients with ice. Strain into a rocks glass over a large cube.
Optionally, garnish with an orange peel and a cherry.
INTERVIEWERSChris Glanden
EPISODE SPONSORTHALES
CONNECT WITH USBecome a Sponsor
Support us on Patreon
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
In the covert world of intelligence and espionage, where shadows merge with reality, there exists a select group of individuals who operate on the razor's edge between life and death. Among them is a man named Ric Prado, AKA the "Shadow Warrior."
Ric's story is a testament to the indomitable human spirit and the unyielding pursuit of justice in the face of adversity. A true warrior with a heart of steel, Ric has spent his entire life on the frontlines of some of the most dangerous and classified missions the world has ever seen. His esteemed career spans over three decades, defined by his unwavering commitment to national security and counterterrorism. From his early years as a military officer to his exceptional service in the CIA, Ric's expertise in counterterrorism and intel operations is unparalleled.
TIMESTAMPS:
0:03:09 - Impact of the Cuban Revolution on Private Businesses and Education
0:05:38 - Operation Peter Pan and Ric’s journey to the US
0:10:46 - Transition from an Orphanage to Hialeah, FL
0:12:34 - From High School Troublemaker to Elite Pararescueman
0:14:47 - A Professional Diver's Journey to Becoming a Pararescueman and Joining the Central Intelligence Agency
0:16:26 - CIA Recruitment and President Reagan's Latin American Policy
0:22:27 - Ric’s Journey from Miami to Honduras and Beyond
0:29:09 - Entry into the Counterterrorist Center
0:31:08 - Plank Owner of the Bin Laden Task Force
0:34:35 - Billy Waugh: Legendary Green Beret and CIA Paramilitary Operations Officer
0:36:10 - Ric's Experiences in North Africa and Korea with the Bin Laden Task Force
0:40:38 - The Mental and Physical Fortitude Required for High-Risk Missions
0:42:21 - Recounting Near-Death Experiences
0:46:07 - CIA Operations Officer's Dedication to the Mission
0:47:37 - Unwavering Love of Country: The Challenges of Counterterrorism in the 21st Century
0:52:31 - Private Military Contractors and the Rise of ISIS
0:56:31 - Blackwater's Role in Saving the Polish Ambassador's Life
0:57:44 - The Use of Private Military Contractors in the Ukraine Conflict
1:02:06 - Cybersecurity and His New Book "Black Ops: The Life of a CIA Shadow Warrior
1:07:53 - The Benefits of Responsible Training
1:14:00 - The Proper Usage of Handguns for Effective Security
SYMLINKSLinkedIn
Ric Prado - Black Ops
Black Ops: Life of a CIA Shadow Warrior
Operation Peter Pan
Cofer Black
Billy Waugh
Buzzy Krongard
Erik Prince
Blackwater
Four Branches
DRINK INSTRUCTION4 BRANCHES BOURBON
Founder's Blend
Pour 2 oz of Bourbon into a whiskey glass. Swirl, smell the aromas, take small sip, savor the flavors, swallow and then exhale.
Enjoy slowly.
INTERVIEWERSChris Glanden
Doug Gotay
EPISODE SPONSORN/A
CONNECT WITH USBecome a Sponsor
Support us on Patreon
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
Philip Wiley, AKA The Hacker Maker, is an experienced pentester, educator, author and speaker. He has been invited to give presentations at countless cons. He currently hosts a top ranked podcast, "Hacker Factory" and his self-titled podcast, "Philip Wiley Show", recently launched.
He returns to the bar to talk all things CON, including his own experience, CFP differentiators, structuring a talk, defeating imposter syndrome, and more.
TIMESTAMPS:
0:03:18 - Experience with Conference Presentations
0:05:26 - Reflections on Public Speaking and Ethical Hacking
0:07:37 - Getting Started in Pen Testing and Public Speaking
0:09:19 - Conveying Complex Technical Concepts to a Non-Technical Audience
0:11:12 - Explaining Acronyms and Incorporating Real-World Examples into Presentations
0:12:40 - Positioning Yourself as a Conference Speaker: Tips for Differentiating Yourself from Other Applicants
0:14:25 - Tips for Submitting a Successful Conference Talk Proposal
0:21:05 - Conquering Nerves and Building Confidence for Public Speaking
0:22:42 - Engaging Presentations, Measuring Success, and His New Podcast
0:31:49 - Content Creation and Personal Branding with Streamed Podcasts
0:33:12 - Combining Different Passions in Cybersecurity
0:35:07 - The Philip Wiley Show and Sharing Resources
SYMLINKS
Linkedin
Twitter
Toastmasters
The Pentester Blueprint
The Hacker Factory
Phillip Wylie Show
YouTube
DRINK INSTRUCTIONTEXAS TORNADO
1 part SoCo
1 Part Pineapple Juice
1 Part Sprite
Combine all ingredients in shaker. Shake, then pour into a rocks glass with ice. Leave it for a few minutes to chill. Seek shelter.
EPISODE SPONSORTuxCare
CONNECT WITH USBecome a Sponsor
Support us on Patreon
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
Pentera is a company that specializes in automated security testing and vulnerability management. Its platform uses a combination of automated and manual testing techniques to identify and prioritize security vulnerabilities in an organization's infrastructure. By doing so, Pentera helps unmask hidden vulnerabilities and provide visibility into potential security threats. Their "Automated Security Validation" component continuously validates cyber defenses. It's a method of testing that is becoming increasingly more popular as attackers have become more sophisticated. In fact, it was recently recognized by Gartner as its own category.
Nelson Santos, a Senior SE with Pentera, is a security professional with years of experience in both attack and defense teams. He holds multiple top-tier security certifications and has trained under some of the best known researchers in the field. His interests range from exploit development and vulnerability research to machine learning and artificial intelligence.
We engage in a discussion that defines automated security validation, and why it's different from traditional methods of security testing.
TIMESTAMPS:
0:03:29 - Automated Security Validation: Benefits, Vendor Landscape, and Trends
0:05:29 - Effect of Automated Security Validation in the Age of COVID-19
0:07:11 - Challenges and Best Practices
0:12:39 - The Impact of Automated Security Validation Tools on DevOps Workflows
0:15:54 - Automated Security Tools for Mid-Sized Enterprises
0:17:22 - Automated Security Validation Tools for Enterprises
0:22:09 - Pentera's History
0:23:41 - Conversation Summary: Exploring Pantier's Security Validation and Differentiators for Success
0:28:07 - Trends in Cybersecurity and Threat Intelligence Integration
0:30:15 - Pentera's Rap Battle at RSA and Black Hat Conferences
0:31:58 - Exploring Israel and Opening a Cybersecurity Theme Bar
SYMLINKSNelson's LinkedIn
Pentera's - LinkedIn
Pentera's - Twitter
Pentera's Website
DRINK INSTRUCTIONSCANALYZER
1 oz Gin
3/4 oz Lime Juice
Tonic Water
Fill a glass with ice. Pour in the gin and lime juice. Top off with Tonic Water.
EPISODE SPONSORPentera
CONNECT WITH USBecome a Sponsor
Support us on Patreon
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
SESSION TITLE: CISOs Riff on the Latest in Cybersecurity
RECORDED: 4/19/23
LOCATION: Valley Forge Casino and Event Center
GUESTS: David Lingenfelter (VP, Information Security, PENN Entertainment), Krista Arndt (CISO, United Musculoskeletal Partners) and Bistra Lutz (Director of Global Information Security Operations, Crown Holdings)
CONNECT WITH USBecome a Sponsor
Support us on Patreon
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
FC has gone through extreme adversity and has come out stronger on the other side. He grew up in a very negative environment, which unfortunately led to the development of complex PTSD. But from that emerged a unique talent, one that is both a gift and a curse: hypervigilance. He refused to allow his past define him and instead, leveraged the state of increased alertness to fuel his passion for security.
FC talks with us about his breakthrough into ethical hacking and physical security assignments, his 100% success rate at breaking into banks and other highly secured government facilities, the reason physical security engagements are NOT helpful to the business, uniting digital/physical/human-factor for optimal security, and the risk of investing in new tech. FC also details some truly insane stories, including the time he kidnapped the guard at a facility protected by ex-military Gurkhas. Finally, he reveals his advice for aspiring hackers and details on his soon to be released book, "How I Rob Banks: And Other Such Places".
TIMESTAMPS0:03:49 - The Origin of an Ethical Hacker
0:05:49 - Early Computing and Hacking Experiences
0:10:04 -The Cursed Gift of Hypervigilance
0:13:25 - Social Engineering and Physical Security Assessments
0:20:30 - The Inevitability of Security Breaches
0:22:38 - The Lack of Focus on Human and Physical Security in Organizations
0:24:35 - Challenges of Adopting Cutting Edge Technology
0:26:53 - The Impact of AI on Ethical Hacking
0:34:16 - Methods of Social Engineering
0:36:29 - Identifying Entry Points and Planning an Attack
0:42:07 - Security Breach Simulation at a Data Center protected by Ex-Military Gurkhas
0:44:31 - Advice for Aspiring Security Professionals
0:48:46 - Cybersecurity Education and Certifications
SYMLINKSLinkedIn
Twitter
Cygenta
Hackthebox
Tryhackme
Pentest Academy
Book: Breaking into Information Security: Learning the Ropes 101
Book: How I Rob Banks: And Other Such Places
DRINK INSTRUCTIONKOMBUCHA MOJITO
1 Cup Kombucha
1 TBSP Honey
8-10 Mint Leaves
1/2 Lime (Juiced)
Club Soda
Muddle 8-10 mint leaves and 1/2 a lime, juiced. Add 1 tbsp of honey and 1 cup of kombucha. Pour mixture into a highball glass. Top with club soda and stir gently.
EPISODE SPONSORN/A
CONNECT WITH USBecome a Sponsor
Support us on Patreon
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
Grit in the context of behavior is defined as “firmness of character; indomitable spirit.” Andres Andreu, a NYC bred leader, has a career built on grit and sheer perseverance with experience spanning from the D.E.A. to corporate America.
Co-Host, and cybersecurity sales veteran Doug Gotay and I post up with Andres and talk about overcoming adversary as a youth, his time within the D.E.A., his mastery in the judo philosophy, and traversing his unique skillset and mentality into success in the boardroom.
TIMESTAMPS0:03:46 - Reflection on Growing Up in Queens in the 1980s
0:07:30 - The Judo Philosphophy: Discussion on Physical and Mental Strength Resilience for Life and Business
0:15:10 - Transitioning from NYC to the DEA
0:19:05 - Reflections on the DEA Hiring Process and Title Three Intercepts
0:23:07 - Self-Taught Technology and Creative Problem Solving
0:27:49 - The Origins of Blockchain Technology
0:29:27 - Analytical thinking in Government Investigations
0:31:47 - The Impact of Intelligence Sharing on Drug Enforcement Coordination
0:33:45 - Threat Intelligence and its Role in Cybersecurity
0:36:05 - Proactive Security Strategies
0:38:34 - Understanding the Global Dynamics of Information Sharing
0:40:47 - Human Trafficking and Technology's Role in Prevention
0:43:30 - Analysis of Metadata and Its Impact on Law Enforcement Investigations vs. Cybersecurity Investigations
0:48:52 - Personal Security During Time at the DEA
0:51:01 - The Benefits of Adapting to Different Situations
0:54:39 - The Human Element of Sales
0:56:17 - Understanding the Need for Key Man Insurance Policies
0:58:15 - Executive Kidnapping and the Need for Balance in Business and Physical Fitness
1:01:23 - Executive Protection and Cybersecurity Transitioning
1:04:26 - The need for Soft Skills and Technical Chops
1:07:46 - Finding Balance in Professional Development
1:09:06 - The Importance of Self-Growth and Seeking Help for Success
SYMLINKSLinkedIn
Gallery
Website
DRINK INSTRUCTIONpic
EPISODE SPONSORN/A
CONNECT WITH USBecome a Sponsor
Support us on Patreon
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
The Sociotechnical Theory is an organizational theory that emphasizes the importance of both social and technical factors in designing and managing systems. Sociotechnical systems are deeply embedded within society and prone to "hacking", a term meaning to subvert a systematic rules in unintended way. In his most recent book, "A Hacker's Mind", Bruce Schneier takes hacking beyond computer systems and uses it to analyze the systems that underpin our society.
He stops by and we define the true definition of hacking, who has the edge in the endless arms race, revealing who the world's best hackers are, how AI will impact the future of hacking, and the truth about AI democratization.
TIMESTAMPS0:02:37 - Exploring the Hacker's Mindset and How to Bend Society's Rules
0:04:53 - The Importance of System Hacking in Today's World
0:06:42 - The Inevitability of System Hacks and the Impact of AI
0:14:41 - Digital Simulation Technology on Policy and Legal Code
0:16:21 - Impact of Hacking on Existing Inequalities
0:18:21 - Hacking Resources and Loopholes
SYMLINKSA Hacker's Mind
Schneier on Security Blog
"Security Engineering" by Ross Anderson
"Threats" by Adam Shostack
DRINK INSTRUCTIONpic
EPISODE SPONSORTuxCare
CONNECT WITH USBecome a Sponsor
Support us on Patreon
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
As a large language model trained by OpenAI, ChatGPT has been designed to understand and generate human-like text based on a massive amount of data. From writing creative stories and poetry to answering complex questions and providing personalized recommendations, ChatGPT seems to be running on all cylinders, and still accelerating.
The possibility of ChatGPT extends beyond text, via Voice AI. John Miller, Co-Founder of Launchvox stops by to about ChatGPT's potential, mainstream adoption, ethics, and security implications through the lens of a creator.
TIMESTAMPS0:03:31 - Reflection on the Artistic Experience of the Renaissance Era
0:07:51 - War and Innovation in the 19th Century
0:12:50 - Ransomware and the Russian Revolution
0:14:16 - The Evolving Landscape of Security and Hacking
0:18:03 - The Future of Cybersecurity and the Use of Chat GPT and Resemble AI
0:19:53 - Voice Synthesis and Audio Processing
0:21:10 - Utilizing Virtual Voice Actors and Mastering Processes for Content Production
0:23:15 - Exploring the Ethical Implications of AI-Generated Voice Replication in the Entertainment Industry
0:27:50 - Security and Ethics in AI Development
0:30:52 - The Impact of Chat GPT on Business and Personal Use Cases
0:36:04 - The Need for Accuracy in Fact Checking with Chat GPT
0:38:03 - AI and Immersive Technologies with Launchvox
SYMLINKSLaunchvox
LinkedIn - Launchvox
LinkedIn - John MillerStable Diffusion
ChatGPT
Getty | Stable Diffusion Lawsuit Resemble
Adobe Audition
DRINK INSTRUCTIONpic
EPISODE SPONSORN/A
CONNECT WITH USBecome a Sponsor
Support us on Patreon
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
The Harkness method is a discussion-based learning style that emphasizes student centric discussion and active participation in a classroom setting. The goal is to create an environment where students can share their thoughts and perspectives, engage in meaningful conversations, and learn from each other.
Jason Brooks, a native of South Central Los Angeles, taught Mandarin, Spanish & Mathematics for 18 years. During COVID-19, as he tracked student interaction by hand, he quickly recognized the potential for artificial intelligence to fuel better meeting performance. In October 2021, he founded HARKNESS.AI, an early stage startup whose vision is to empower everyone - on every team - to meaningfully contribute their voice at work, in school, or any other group... free from friction, fear or bias.
Co-founder Keenan Hale Jr. graduated from Syracuse University as a Big East Conference Football Champion & 2-time bowl winner with a degree in Communications and Rhetorical Studies. He began his career as a Chief of Staff and Campaign Manager for Mayoral Candidate Rochelle Robinson in Douglasville, GA. He later served as Legislative Assistant and senior advisor to Congressman Al Green. Most recently, Keenan worked as a registered lobbyist advising and providing political & regulatory insight to multiple trade associations and Fortune 500 clients.
Co-hosts Rohan and Mike join us to discuss the conversation trust factor, targeting miscommunication and how that corrodes trust and team, their aim to promote self-awareness within the team structure, and the ability to help people ask hard cultural questions safely.
TIMESTAMPS0:03:28 - The Genesis of Harkness AI: A Story of Overcoming Adversity and Finding Success in Education
0:05:20 - Harnessing the Power of Data Science to Transform School Culture During the Pandemic
0:06:57 - Exploring Ed Tech Innovation in the Pandemic
0:13:14 - The Benefits of Adult Online Learning Platforms
0:14:45 - The Use of AI-Powered Technology in Business, Couples Therapy, and Dispute Resolution
0:17:45 - The Impact of Technology on Trust and Acceleration of Artificial Intelligence
0:20:02 - AI Ethics: Combining Soft and Hard Skills for Business Success
0:21:35 - AI-Powered Real-Time Coaching for Improved Communication in the Workplace
0:24:41 - The Promise of AI to Transform the Way We Do Things
0:27:00 - The Potential of AI to Mitigate Miscommunication and Conflict
0:29:09 - Exploring the Humanistic Approach to AI
0:31:56 - The Power of Language and AI to Connect People and Transform Lives
0:34:34 - Cultural and Communication Differences
0:36:18 - Awareness to Physical Presence in Meetings
0:37:56 - Incorporating Team Members for Maximum Efficiency
0:45:31 - Voice Suppression in the EdTech and Workforce Surveillance Risk Areas
0:47:46 - Establishing Trust and Ethics in the Digital Age
0:50:41 - Virtual Observers and Their Impact on Communication
0:53:14 - Benefits of Using Data to Make Decisions in the Workplace
0:54:57 - Creating a Culture of Respect and Clarity
0:58:11 - Exploring Cross-Cultural Communication
1:02:57 - Benefits of Leveraging Harkness to Improve Team Dynamics
1:09:54 - Connecting People Across Different Use Cases
1:14:56 - Combining Visual and Auditory Learning
SYMLINKSHarkness.ai
DRINK INSTRUCTIONpic
EPISODE SPONSORTUXCARE
CONNECT WITH USBecome a Sponsor
Support us on Patreon
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
Jim "Mad Dog" Lawler is a national security consultant, serving as the Senior Partner at MDO Group, which provides HUMINT training to the Intelligence Community and the commercial sector focused on WMD, CI, technical and cyber issues. He served for 25 years as a CIA case officer and is a noted speaker on Insider Threat within the government sector.
He stops by and we discuss CIA war stories, Misconceptions of the Agency, Espionage, Counter Intelligence, Detecting Insider Threats and Spy Novels.
TIMESTAMPS0:04:08 - The roots of a CIA operative
0:05:43 - Reflections on a Career Path Not Taken
0:09:01 - Exploitation, Subvertion, and Corruption
0:10:47 - Reflecting on 25 Years of Living Undercover and Clandestine Operations
0:15:58 - Experience with a Potential Spy
0:20:28 - Counterintelligence Analysis of Espionage Motivations
0:22:02 - Polygraph for Recruited Asset
0:24:04 - Recruiting People for Espionage and Preventing Insider Threats
0:27:44 - Preventing Employee Straggling Through Fair Treatment and
Understanding
0:29:49 - Preventing Insider Threats in the Workplace
0:33:08 - Employee Monitoring and Performance Feedback
0:35:06 - Discrepancies Between Outside Perceptions and Reality of CIA Case Officers
0:39:22 - CIA Operations and Challenges Overcome
0:41:21 - Recruiting Intelligence Officers: The Power of Patience and Perseverance
0:45:07 - Balancing Personal Feelings and Mission Objectives
0:46:53 - Spy Recruitment: Strategies for Successful Case Officers
0:48:48 - Ethical Decision Making
0:51:36 - The Commitment to Protect Covert Assets
0:53:15 - Origin of the Alias "Mad Dog"
0:54:42 - Espionage, Iranian Nuclear Weapons Program, and Novels
0:56:25 - "Living Lies," "In The Twinkling of an Eye," and "A Traitor's Tale"
SYMLINKSLinkedIn
The Clandestine Service
MICER
Spies, lies and nukes conference
Living Lies
In The Twinkling of an Eye
DRINK INSTRUCTIONMAD DOG 20/20
Ready to serve
EPISODE SPONSORCIS
CONNECT WITH USBecome a Sponsor
Support us on Patreon
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
Mike Jones AKA the H4unt3d hacker, is a security researcher who formerly hacked underGROUND groups. He served in the military for several years within SIGINT operations. Mike started the H4unt3d hacker podcast from scratch, wanting to give people a unique point of view about cybersecurity. He has built a global community of members from different walks of life, religions, backgrounds and disciplines.
Mike transends into BarCode to discuss his origins, Hacktivism, SIGNIT, in the military, podcasting takeaways, Hackers For Vets, and Podcasting in the Metaverse.
TIMESTAMPS0:02:43 - The origin of Mike Jones AKA the Haunted Hacker
0:04:34 - How Aspergers Amplified his Life of Hacking
0:06:07 - Signals Intelligence: How It All Began
0:07:44 - Military intelligence to hacktivist
0:10:21 - The Impact of Hacktivism on Civil Rights
0:12:07 - Podcasting Success
0:18:15 - The Future of the Haunted Hacker Podcast
0:19:57 - The Benefits and Use Cases of Virtual Reality
0:22:46 - The Benefits and Challenges of Creating Virtual Reality Videos
0:24:12 - Cyber Beard Shaved Charity Raises $120,000
0:28:04 - Hackers for Vets: A Mission to Help Military Veterans Transition to the Civilian World
0:30:41 - The Dark Side and horror films
SYMLINKSLinkedin
Twitter
the H4unt3d Hacker podcast
the H4unt3d Hacker YouTube
Hacker For Vets
Horizon Worlds
Ghost Tours of Chattanooga
SALEM'S LOT
SAW
ESCAPE ROOM
Unknown Caller | Chattanooga, TN
The Blue Light | Chattanooga, TN
The Church | Denver, CO
Excaliber | Chicago, IL
Snow Crash by Neal Stephenson
DRINK INSTRUCTIONRED RUM
2 oz Rum
1 oz Grenadine
2 1/2 oz Orange Juice
Mix rum and grenadine in a cocktail shaker. Pour into a highball glass over crushed ice and orange juice.
EPISODE SPONSORTuxCare
CONNECT WITH USBecome a Sponsor
Support us on Patreon
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
Robert Bateman, head of content at GRC World Forums, is a well-respected expert on data protection, privacy, and security law. He built his reputation by producing in-depth reports on legal updates, compliance guidance documents for businesses, and news articles about the latest industry trends. He also has a deep interest in digital rights and is an avid supporter of free speech.
We discuss EU-US Data Privacy Framework, Upstream and Prism NSA, Meta's Threat to the EU, Clearview, Open AI (Dall-E/ ChatGPT), Twitter VS. Mastodon.
Boozebot uses ChatGPT to generate "Death in the Afternoon".
TIMESTAMPS0:00:00 - CIS Controls Version 8: Updates and Changes
0:04:15 - The Impact of the Snowden Leaks on Data Protection and Privacy
0:06:16 - The EU-US Privacy Dispute: What's at Stake and How to Fix It
0:12:49 - Facebook, Instagram, and WhatsApp Facing Fines for Privacy Violations
0:14:40 - The Impact of Social Media on Personal Data
0:22:46 - Twitter's GDPR Fine and Data Management Issues
0:24:56 - Twitter Authentication Problems Run Deep
0:27:07 - Twitter vs. Mastodon: Which is Better for Security Practitioners?
0:29:31 - The Infosec Community on Twitter vs. LinkedIn
0:31:45 - The ethical implications of OpenAI's technology
0:34:06 - The Impact of AI on Ground Truth and Job Loss
0:39:12 - The Benefits and Risks of Artificial Intelligence\
0:41:22 - The Benefits and Risks of AI
SYMLINKSLinkedin
Twitter
GRC World Forums
DRINK INSTRUCTION
EPISODE SPONSORCenter For Internet Security (CIS)
CONNECT WITH USBecome a Sponsor
Support us on Patreon
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
Crane Hassold is a threat researcher at Abnormal Security who specializes in discovering and analyzing malicious email campaigns targeting enterprises. He also works closely with law enforcement agencies to help bring these bad actors out into the open. Before joining Abnormal Security, Hassold was a senior investigator at the Federal Bureau of Investigations (FBI), where he worked for over eleven years. While there, he focused on identifying and tracking emerging threats such as sophisticated spearphishing attacks against government organizations.
Crane stops by to discuss BEC attacks, romance scams, “Active Defense”, his 1-on-1 with the Demonware Ransomware gang, empathy for cybercriminals and more.
TIMESTAMPS0:03:05 - Transition from FBI Intelligence Analysis to Cybersecurity
0:05:06 - Cyber Behavioral Analysis Center: Applying Violent Crime Profiling Concepts to Cyber Threats
0:06:47 - Cyber Threat Intelligence
0:08:48 - Threat Intelligence: A Primer
0:12:02 - The Impact of Human Behavior on Cybersecurity
0:14:06 - The Human Side of Cybercrime
0:16:08 - Active Defense in the Fight Against Business Email Compromise
0:17:46 - Active Defense Against Business Email Compromise Attacks
0:21:18 - Demonware Ransomware: A Case Study
0:24:13 - Active Defense: A Conversation with a Nigerian Cybercriminal
0:25:46 - How Financial Motivation Overrides Red Flags in Cyber Attacks
0:31:53 - The Relationship Between Romance Scams and Business Email Compromise
0:34:03 - The Evolution of Social Engineering: From Nigerian Print Scams to BEC Actor Attacks
0:38:18 - The Impact of Automation on Cyber Criminal Activity
0:40:16 - The Impact of Automation on Business Email Compromise Attacks
0:42:32 - The Impact of Ransomware on Business Email Compromise Attacks
0:44:43 - BEC Attacks Incorporating Deep Fake Audio
0:47:24 - The Impact of Third Party Impersonation Attacks on Business Email Communications
0:49:30 - The Evolution of Email-Based Attacks
0:51:25 - The Importance of Cybersecurity Awareness
SYMLINKSLinkedin
Twitter
Abnormal Security
intelligence.abnormalsecurity.com
Cybernews: Baiting the scammers
FBI Behavioral analysis unit
What is BEC
HUSHPUPPI
DEMONWARE ENGAGEMENT
2022 Verizon DBIR
Deepfake Audio in BEC
DRINK INSTRUCTION
EPISODE SPONSORCenter For Internet Security (CIS)
CONNECT WITH USBecome a Sponsor
Support us on Patreon
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
Mikko Hyppönen is considered one of the world’s foremost cybersecurity experts. He is known for his work on IoT security, where he coined the term “The Hyppönen law”. Currently he is working as Chief Research Officer at Withsecure and as Principal Research Advisor at F Secure. He has lectured at the universities of Stanford and Oxford and is a regular contributor to the New York Times, the Wall Street Journal and Scientific American. He was named among the 50 most influential people on the web by PC World Magazine and listed in the FP Global 100 Thought Leaders list. He speaks regularly at conferences such as Black Hat, DEF CON, HackInTheBox, OWASP, RSA, SOURCE, Security BSides Las Vegas and Shmoocon. He has advised companies such as Microsoft, Facebook, HPE, Google, Huawei, Dell and Cisco. He also advises governments around the globe including the United States, Canada, China, Japan, South Korea, Taiwan, Russia and Saudi Arabia.
Mikko serves as Chairman on a number of industry organizations such as the Electronic Frontier Foundation (EFF), Digital Citizens Alliance (DCA) and Internet Archive. He is also a member of the board of directors of the International Association for Cryptologic Research (IACR).
He sits down with us to chat about his background, the internet, the future of the web and what advice he would give to aspiring security professionals.
TIMESTAMPS0:03:41 - Background/ Experience
0:07:10 - The Internet: A Passion
0:08:59 - The Impact of the Internet on Crime
0:11:01 - The Impact of Technology on Law Enforcement
0:13:43 - The Impact of Strong Encryption on Privacy and Security
0:15:19 - The Use of Technology in Criminal Activity
0:17:19 - The Impact of AI on Cybersecurity
0:19:03 - The Benefits and Risks of Investing in Cryptocurrency
0:22:05 - The Future of NFTs: A Conversation with an Expert
0:25:02 - The Importance of Blockchain Technologies
0:28:49 - History of Malware
0:32:33 - The Evolution of Ransomware: From Viruses to Double Extortion
0:34:19 - The Importance of Specialization in the Cybersecurity Field
0:37:29 - The Importance of Being Proactive
SYMLINKSMikko Hyppönen – Website
Mikko Hyppönen – Wikipedia
Mikko – Twitter
Mikko – LinkedIn
PCWORLD – The 50 most important people on the Web
WithSecure
TED talks
If it’s Smart, It’s Vulnerable
Liberty or Death | Helsinki Finland
ARKADE BAR | Helsinki Finland
Bar Chaplin | Helsinki Finland
Logan Arcade | Chicago IL
DRINK INSTRUCTION
EPISODE SPONSORCenter For Internet Security (CIS)
CONNECT WITH USBecome a Sponsor
Support us on Patreon
Follow us on LinkedIn
Tweet us at @BarCodeSecurity
Email us at info@barcodesecurity.com
As Imprivata’s VP of Worldwide Engineering, Cyber, Joel Burleson-Davis is responsible for overseeing teams in the organization that build and deliver cybersecurity solutions. Prior to joining Imprivata, he was an engineering manager in Sydney, Australia for 6 years. He holds a master’s degree in liberal arts from St. Edward’s University where his focus was on philosophy and behavioral sciences applied to technology. He has been working in cybersecurity for over 20 years and we link up at the bar to talk about the history of supply chain vulnerabilities, winning the good versus evil arms race, the recent explosion in supply chain disruptions, the risks within software supply chains, and if supply chain security is an underrated threat.
Danny Boy pulls the trigger switch on a “Chainsaw” shot.
Support the showContact BarCode
Thanks for listening, and we will see you next round!
Most of what we do in the cybersecurity field is a direct result of a sinister underworld that most of us will never have full visibility into. This is a story of an individual who started, and led ShadowCrew, a major cybercrime syndicate within that underworld. After being identified and placed on the US Most Wanted List, he was ultimately captured, imprisioned, escaped prison, and captured again. He served his time, and now is considered a leading authority on internet crime, identity theft, and cybersecurity. He has been featured on Netflix, Hulu, New York times and many more. He has also worked with the FBI, Microsoft, Arkose and countless others.
Co-host Matt Canham and I go inside the mind of reformed fraudster and notorious cybercriminal, Brett Johnson aka “The Original Internet Godfather”.
Tony transforms a real “Decepticon”.
Support the showContact BarCode
Thanks for listening, and we will see you next round!
Eran Sinal is the CEO of IDSeal, a company that is dedicated to helping people keep their identities secure and protected from identity thieves. Based out of Charlotte in North Carolina, Eran has been in the business for 25 years and is very passionate about identity protection. He and his company work very hard to keep their clients safe and has dedicated his life to safeguarding people and their reputations. Eran believes that identity theft is one of the biggest security challenges for any who is in the public eye or work online. He strives to continuously raise awareness about the dangers of online scams, fraud, and digital based identity theft. He is an activist in the field and dedicates his time to sharing his vast knowledge of cyber security, identity theft, consumer protection, and finance restoration. IDSeal has a very happy client base and a long history of creating affordable solutions for identity theft and preventing personal fraud. Through using state of the art and cutting edge technologies, IDSeal is growing in the cyber protection world just as the online threats are too. A passionate pioneer in the industry, Eran is a real life modern day Knight in Shining Armor who advocates protection and identification safety for his friends, family, and clients.
He stops by BarCode, and we discuss his unique journey from professional soccer player to ESPN radio host, to finally landing in the security industry. We also chat about investigating identity theft crimes, preventing online fraud, IDSeal, and his own special craft cocktail hobby.
Tony spins up a “CyCLONE”.
Support the showContact BarCode
Thanks for listening, and we will see you next round!
Robert Leale is the president of CanBusHack, President of Pivvit and is also Founder of Car Hacking Village which can be seen at Def Con, DerbyCON, GrrCON, CypherCon, THOTCON, and many more hacking conferences across the globe. He stops by BarCode and we discuss vulnerable technology in automobiles, manufacturer responsibilities, car hacking tools, how to secure your vehicle and Car Hacking Village.
Tony floors a “VTEC Punch”.
Support the showContact BarCode
Thanks for listening, and we will see you next round!
Jack Rhysider is the creator and host of the Darknet Diaries podcast, which features true stories from the dark side of the Internet. He stops by BarCode and we discuss the origin of his own story, masking of his identity, developing storytelling skills, growing an audience, productivity hacks for entrepreneurial content creators, and more.
Boozebot reveals a “Storyteller”.
Support the show
Charlie Northrup is the co-founder of NeurSciences, a software technology, architecture, and solutions development company that provides there artificially intelligent digital brain applications to integrate, manage, and automate the things that truly matter to us. He’s focused on the digital transformation of the web into an ecosphere of ecosystems operated by and for the benefit of intelligent agents, working for individuals, households, and organizations.
Co-hosts Mike Elkins and Rohan Light join me in this thought provoking conversation on Web 1.0-5.0, hyperconnected worlds, digital ecosystems, blockchain, human consciousness, “graphs”, “things” and where the matrix resides.
Kyle the Bartender reveals a “Hologram shot”.
Support the show
Arun Vishwanath, a leading expert in human cyber risk, has held faculty positions at the University at Buffalo, Indiana University, and the Berkman Klein Center for Internet & Society at Harvard University. He has published close to 50 peer-reviewed papers on human cyber vulnerabilities and also written for CNN, The Washington Post, and other major media outlets.
Special co-host Dr. Matthew Canham joins me as well. Matt is an expert in Cognitive Psychology, Social Engineering and the Human Factor of cybersecurity. He spent time at the FBI where he handled insider threat cases, managed their Emerging Technology Program and consulted with their Behavioral Analysis Unit.
We discuss his perspective on end user training tools, ineffectiveness of security awareness programs, injecting “human-factor” security into industry frameworks, developing security conscious habits, bridging the gap from Academia to industry, and his book, “THE WEAKEST LINK: HOW TO DIAGNOSE, DETECT, AND DEFEND USERS FROM PHISHING”.
Danny Boy HOOKS us up with a “Phish Bowl”.
Support the show
Jeff Jockisch is a privacy expert with experience in privacy rights, privacy laws, data breaches, intrusion detection, as well as other areas, such as cognitive computing, content development and trust systems. He is also cohost of “Your Bytes, Your Rights” podcast. Dave Burnett is the head of global business development at Zero Biometrics. He’s a serial entrepreneur who brings global executive expertise and experience from private and public companies into the security, biometric, and digital identity markets.
We discuss biometric systems and how they work, biometric system attack vectors, privacy concerns, public perception, regulatory and legal implications, and Zero Biometrics.
Danny Boy distributes “The Red Pill”.
Support the show
Alyssa Miller is a life-long hacker and experienced security executive. She has a passion for security which she advocates to fellow business leaders and industry audiences both as a high-level cyber security professional and through her presence in the security community. She blends a unique mix of technical expertise and executive experience to bridge the gap that can often form between security practitioners and business leaders. Her goal is to change the way we look at the security of our interconnected way of life and focus attention on defending privacy and cultivating trust.
We discuss her own journey into Security, breaking into cybersecurity a ground level, advice for career transitioners, the unwritten educational elements, Certs, training, mentorship, networking groups and of course her new book.
Kyle schools us with a “Class Act”.
Support the show
Anastasia Edwards is an innovative thinker and Cybersecurity Professional with refreshing soft skills in empathy, emotional intelligence, awareness communications, and cultural change implementation. Her sweet spot is melding Cybersecurity Awareness together with Insider Threat monitoring and detection. She is a forward thinking Cybersecurity professional with dreams and aspirations of bringing Cybersecurity awareness and best practices for a safer digital lifestyle, to people all over the world. Anastasia developed Re-Framework, a concept aimed to optimize Human Risk Factor programs. She also has created The Friday 15 | A Cyber Speed Networking Project, which pairs up CyberIT agents, practitioners, and professionals of all levels for a casual “Happy Hour” style 15 minute virtual meeting on Discord. Tapping into her artistic ability, she has also designed GeVees, “Quality. Fashionable footwear for the IT and Cyber Agent.”
We discuss her recruitment into Security, her passion for the Human Factor, Culture-building, cyber core values, Re-Framework, The Friday 15, fusing fashion and security, and her own line of cyber footware.
Danny Boy designs a “Renegade”.
Support the show
Mark Carney and Victoria Kumaran are the founders/ organizers of the up and coming Quantum Village that will debut DEFCON 30, August 2022.
Mark, aka @LargeCardinal is a researcher and Technical Specialist in Quantum Cybersecurity and ML at a bank. He has specialist knowledge in many areas, including cryptography, embedded systems, quantum information and maths. He has contributed a chapter to various papers and a book, and consults to numerous companies and research groups, including academic and commercial.
Victoria, @V__Wave has worked with several startups in wide ranging areas, from deep tech for cybersecurity to consumer lifestyle brands. She studied art and design at Central St. Martins before working in finance as an equity market strategist. Her focus areas include cybersecurity and technology in society, leading her to question and explore the effects that new and emerging tech will have in our lives.
We catch up at the bar to discuss their entry into quantum computing, explaining quantum, challenges involved, the impact to cybersecurity, educational resources, “Prime Time” acceptance, the debut of Quantum Village and what attendees can expect.
BoozeBOT superpositions an “Absinthe Drip”.
Support the show
Pablos Holman is a notorious hacker, inventor, entrepreneur and technology futurist who thinks differently to solve the world’s biggest problems by inventing new technology. At The Intellectual Ventures Lab, he has worked on a brain surgery tool, a machine to suppress hurricanes, 3D food printers, and a laser that can shoot down mosquitos – part of an impact invention effort to eradicate malaria with Bill Gates. Previously, Pablos helped build spaceships with Jeff Bezos at Blue Origin, the world’s smallest PC, 3D printers at Makerbot, artificial intelligence agent systems, and the Hackerbot (a robot that can steal passwords on a Wi-Fi network). Pablos’ TED talks have been watched over 30+ million times (his first TEDx talk, from 2012, has over 20 million views).
We discuss his origin story, the Cypherpunk era, Bitcoin volatility, the future of crypto and blockchain, human created protocols, 3D Printing, hackers in product development, hacking time, technology for World Peace, and more.
Danny Boy revolutionizes the “Flux Incapacitator”.
Support the show
Frankie McRae is a storied former US Army Special Forces soldier and assault team leader. Since his retirement, Frankie has developed Range 37PSR, founded Raidon Tactics (a premiere training organization), deployed all over the world as a contractor to both combat zones and disaster areas, and taken the stand as an expert witness in homicide cases involving soldiers brought charged with shootings during combat operations.
We catch up at the bar to discuss his storied experience, mission planning, physical/digital threat assessments, active shooter preparedness, “conscious suspicion”, home defense, WFH security, successful teaching methodologies and much more.
Danny Boy (the FNG) pulls the trigger on a “Gunfire”.
Support the show
Experienced Intelligence Analyst and creator of the Cognitive Stairways of Analysis Framework, Nicole Hoffman has a passion for developing the analytic tradecraft. Her work, research, and presentations have inspired and educated others around the international analytic community.
For someone diagnosed with ADHD, intelligence analysis can be mentally taxing. An experienced speaker, Nicole developed frameworks to dive deeper into the process of sensemaking in order to increase her analytic capability. She has presented work at the 2021 SANS CTI Summit, GRIMMCON, SOCstock, the 2020 SANS Threat Hunting & Incident Response Summit, All the Talks Con, and so much more.
Nicole was inspired by her kids to write a children’s book that could introduce threat intelligence concepts through a whimsical medieval tale. Nicole believes children are the future and wants to empower the next generation of Intelligence Analysts.
Nicole and I meet up and discuss her transition from the medical field to cybersecurity, her love of threat intel, her struggle with ADHD and the Cognitive Stairways of Analysis framework, her new book, “The Mighty Threat Intelligence Warrior”, and her podcast “IT Wolves”.
Danny Boy joins BarCode, and strikes with a “Spider Byte”.
Support the show
For those unfamiliar with the snowboarding slang term Shred, it means “to ride with exceptional speed, ability, or enthusiasm, especially in difficult terrain and conditions”.
Sumo Logic’s CSO, George Gerchow, applies this methodology whether it’s by way of Board, or by Way of Life.
George has been carving up IT and Systems Management territory for over 20 years. His background has allowed him to gain unmatched expertise in the areas of security, compliance, and cloud computing. His thoughtful insights make him a highly regarded speaker, and panelist on topics such as DevSecOps, cloud secure architecture design, virtualization, compliance, Bug Bounties, and operational security and compliance. George has been on the bleeding edge of public cloud security and privacy since being a co-founder of the VMware Center for Policy & Compliance. Mr. Gerchow is an active Board Member for several technology start-ups and the co-author of the CIS Quick Start Cloud Infrastructure Benchmark v1 and the MISTI Fundamentals in Cloud Security. He is also Faculty Member for IANSand the Cloud Academy.
He traverses into BarCode and we catch up on Supply Chain security, SMB best practices, the Center of Data, ZTA, Zero Day Vulnerabilities, Bug Bounties, his self-described “biggest bonehead move ever” and owning it, the MMA-INFOSEC connection and much much more. George also opens up about the meaning of his newly founded X Foundation, a non profit organization that has spawned from a personal, heartbreaking story which is critical for everyone to hear.
Tony carves “Blue Steel”.
Support the show
Louis Rosenberg, PhD is a technology pioneer in fields of virtual reality (AR), augmented reality (AR) and artificial intelligence (AI). He founded Unanimous AI to amplify the intelligence of networked human groups using the biological principle of Swarm Intelligence combined with AI. The idea panned out, resulting in Swarm AI, an award-winning technology used by a wide range of organizations from Fortune 500 corporations to the United Nations. Rosenberg began his career at Stanford University where he earned his BS, MS, and PhD degrees. Working at Air Force Research Laboratory in the early 1990’s, Rosenberg created the Virtual Fixtures platform, the first functional AR system merging the real and the virtual into a unified interactive reality. He then founded the early VR company Immersion Corp (1993) and brought the company public in 1999. He also founded Microscribe, maker of 3D tools used in the production of animated films, including Shrek, Ice Age, and Bugs Life (acquired in 2009). Rosenberg also founded Outland Research in 2004, a developer of mobile media and AR technologies (acquired in 2011). Rosenberg was also a Professor at California State University (Cal Poly) teaching engineering, design, ed-tech, and entrepreneurship. A prolific inventor, Rosenberg has been awarded more than 300 patents worldwide for his efforts in VR, AR, and AI.
I run into him at the bar, and we talk about the early pioneering days of AI, once forecasting the superfecta of the 2016 Kentucky Derby, AI advancements in the medical field, improving accuracy, data integrity, Unanimous AI, Swarm technology, and security risks of the Metaverse.
Tony forecasts a "Mint Julep".
Support the show
The YinYang philosophy says that the universe is composed of competing and complementary forces governed by a cosmic duality, sets of two opposing and complementing principles or energies that can be observed in nature.
Similarly, the nature of offensive security requires a balance of proper mindset and technical expertise. To truly master this security discipline, you must learn to balance and draw from different sides of experiences in life, including the psychological aspect as well as the ones and Zeros.
Jeremy “Harbinger” Miller is an InfoSec professional primarily interested in how security skills are taught, learned, and applied by individuals and organizations. He is currently the Product Manager of Content Development at Offensive Security. We catch up at the bar to discuss his unorthodox path into Infosec, his background in teaching martial arts, the true meaning of OffSec’s mantra, “Try Harder”, and the importance of counterbalancing mind and technical skills.
Tony synchronizes a “YinYang Martini”.
Support the show (https://www.patreon.com/barcodepodcast)
Matt Barnett is a nationally recognized expert on physical and cybersecurity, incident response, identity theft, and digital forensics. His expertise is backed by decades of combined information security and law enforcement experience. As a certified forensic analyst, Matt conducts various investigations for clients in the public and private sectors. It is with his technical competency, professionalism, and strategies, that he is able to protect his clients from threats and cyberterrorism. Education is at the forefront of Matt’s passion in the security industry. He has been asked to speak at various information security conferences, has served on the advisory board for the Information Security curriculum at Delaware Technical Community College. Because of his expertise and recognition in the field, Matt is consistently regarded as the go-to cybersecurity expert for NBC in Philadelphia. As a seasoned interviewer, he has made countless appearances on the news as well as on web and podcast shows. With his arsenal of applications, strategies and procedures, Matt is able to assist clients in achieving better cybersecurity.
He hijacks BarCode and we get into the Art of Physical Security engagements, SEVN-X, the ideal skillset of a physical security assessor, readiness techniques, and of course a few scary stories from the frontline. He also reveals why yoga is critical, and it’s not for the reason you may be thinking.
Tony goes M.I.A. while a “007x Martini” gets shaken, not stirred.
Support the show (https://www.patreon.com/barcodepodcast)
Gummo is a former blackhat hacker and reverse engineer turned whitehat who has been breaking shit since '86. His success has been attributed to a unique gift we discuss as well as his extensive knowledge of defeating secure networks and physical vectors.
His deep understanding of crypto allowed him to create four supercomputers that were able to mine more than 5.1 billion U.S. dollar’s worth of bitcoin. He has also created high capacity, ultra-secure systems and networks for trading & hedge funds that are currently used today within high-frequency algorithmic trading platforms. He is Founder and Host of the popular podcast, HACKERS, which is the #1 hacking podcast with over 1.6M subscribers.
He has a hell of a story to tell and although typically he doesn't do interviews, he kindly obliged to a conversation at BarCode. We discuss his intense journey starting from his childhood fascination with computers to his progression into hacking, which includes a path of tragedy to triumph. We also get into the rise of bitcoin, the power of blockchain, the underlying value of NFTs and where the digital universe is going next.
Tony the Bartender pours an immutable "Cryptonite".
Support the show (https://www.patreon.com/barcodepodcast)
Jim Tiller is a security executive with over two decades of information security experience, leadership, a history of outstanding performance and growth, business turnarounds, and global recognition for innovation in security strategies and execution. He currently serves as the global CISO for Harvey Nash Group.
He joins me at BarCode to discuss organizational targets that have typically stayed in the shadows, security challenges associated with those organizations, the COVID “accelerator”, injecting security into unsuspecting SMBs, the future of Cyber Insurance and much more!
Tony sets the temperature to “110 in the Shade”.
Support the show (https://www.patreon.com/barcodepodcast)
Adi Elliott is the Chief Revenue Officer at Canopy, Data Breach Response Software. He has extensive experience building and leading high-performance marketing, sales, product, and strategy teams. He’s also held leadership roles at three companies with $100M+ liquidity events, led multiple marketing and product teams recognized for innovation, and led the positioning, branding, and definition of three of the strongest corporate & product brands in the eDiscovery market. He has deep experience in business operations, strategic planning, and corporate development.
He makes the trek from Chi-Town to BarCode to discuss important topics such Data Breach Response within the IR process, preventing data loss, the power of AI within data security, privacy laws and regulation for connected cars, and more.
Tony reveals the schema for a “Chicago Apple Cider”.
Support the show (https://www.patreon.com/barcodepodcast)
Igor Volovich has built a career as a global CISO, strategist, advisor, author, speaker, and global cybersecurity leader with 20+ years of service to the world’s largest private and public-sector entities, Fortune 100 firms, and US policy, legislative, and regulatory communities. As a cyber strategy advisor and leader, he has helped large multinationals develop and execute enterprise risk management programs designed to protect hundreds of millions of consumers and billions of dollars in assets and revenues across diverse industries ranging from manufacturing and telecoms to consumer goods and nuclear energy.
In his current role as VP of Compliance Strategy at Qmulos, he leads strategic planning and business development, while fostering product innovation and adoption, driving strategic customer and partner engagement, and evangelizing the company’s innovative approach to unified compliance, risk, and security maturity management. I run into him at BarCode, where we discuss modernizing the approach to compliance, transitioning to “NextGen Compliance”, the secret to marketing something boring in an innovative and fun way, the Qmulos vision, and much more!
Tony enters a “Time Warp”.
Support the show (https://www.patreon.com/barcodepodcast)
Regina Bluman is an infosec professional who previously worked in IT Marketing for almost a decade, before leaving the dark side and moving across! She is an experienced panelist, guest author, podcast guest, and was recently nominated as ‘Technical Employee of the Year’, ‘Role Model of the Year’, ‘Rising Star’, and ‘Woman of the Year’ in the CRN Women in Channel Awards. She also volunteers for the Cyber House Party and is part of the Ladies of London Hacking Society. When not working, Regina can still often be found at her computer, working on various hacking labs or CTFs, and when not ‘geeking out’, she tries to catch as many Welsh rugby and Liverpool football games as she can. Away from a screen, she loves to spend time outside hiking, camping, and snowboarding.
She joins me at BarCode to discuss her move from IT Marketing to Security, knowledge shaming, creating original content, security leader perspectives and why it’s important for them not to agree, self-doubt, advice for negative critics and much more.
Tony puts down a “Suffering Bastard”.
Support the show (https://www.patreon.com/barcodepodcast)
Dr. Magda Chelly is a keynote speaker, serial entrepreneur and a senior security expert.
She is a strong activist for women in security, and founded Women on Cyber in Singapore, which is focused on supporting female professionals in the industry.
She’s is also the founder of of Responsible Cyber, and a member of the Advisory Board for the Executive Summit at Black Hat Asia. She has conducted research on Cyber Security, the future of localization and positioning, education and more, with publications featured by IEEE, RSA, CyberSec, World Congress on Internet Security, Cyber Risk Leaders Magazine, among many others.
She joins me at the bar to discuss her journey into cybersecurity, cybersecurity awareness, social media messaging, “Hollywood Hackers”, cyber risk and how it varies per geographic region, her upcoming book, and more!
Tony makes a sinister “Neon Nightmare”.
Support the show (https://www.patreon.com/barcodepodcast)
The US government and military have recently confirmed investigations and sightings of UFOs, reigniting the phenomenon of aliens among us. Ironically, an unidentified spaceship descends into BarCode, and official contact is made.
Sherri Davidoff is the CEO of LMG Security and the author of “Data Breaches.” She is a recognized expert in cybersecurity and data breach response, co-author of Network
Forensics: Tracking Hackers Through Cyberspace and is the subject for the book , Breaking and Entering: The Extraordinary Story of a Hacker Called “Alien”.
Our close encounter involves a discussion on her recent visit with the Senate Committee, LMG explorations, Ransomware and the 4th dimension, Cyberinsurance, and other unexplained phenomena.
Tony identifies an extraterrestrial “Alien Brain Hemorrhage”.
Support the show (https://www.patreon.com/barcodepodcast)
In recent years, there has been significant consumer demand for instant payments through their mobile phones. Unfortunately, the security aspect of mobile NFC payments has been ignored and mobile wallet theft is real threat.
Timur Yunusov is a Security Expert in the area of payment security and application security, one of the organizers of Payment Village. He has authored extensive research in the field of payment security. He regularly speaks at conferences and has previously spoken at CanSecWest, Black Hat USA, Black Hat Europe, HackInTheBox, Nullcon, NoSuchCon, Hack In Paris, ZeroNights and Positive Hack Days.
We link up and talk about mobile wallet security, platform safeguards, his vulnerability research, privacy implications and how he is bringing awareness of the issue.
Tony spends a “Fast Buck”.
Support the show (https://www.patreon.com/barcodepodcast)
At this moment, more than 70% of us are currently compromised by cybersecurity attacks that we underplay, ignore, or simply aren’t aware of because of their hyper-stealthy and invisible nature. In fact, most individuals and businesses will have been compromised for more than 3 years before they realize what’s happened. It's vital to help other's understand the genuine threat of cybersecurity attacks while delivering steps they can take to quickly and easily develop a proactive plan to mitigate exposure and damage and ensure the security of their businesses, their families, and their futures.
Dr. Eric Cole, AKA the OG, is a former CIA hacker, cybersecurity commissioner to the Obama administration, and advisor to clients including the Obama family, Bill Gates, Lockheed Martin, and McAfee. Eric stops by BarCode, and special co-host Mike Elkins and I engage in a conversation with him that includes translating the importance of cybersecurity to executives, the importance of technical aptitude needed for a CISO role, dealing with haters, risk taking, his new book and more!
Tony the Bartender empowers us with the "Godfather".
This episode is sponsored by Nucleus Security.
Support the show (https://www.patreon.com/barcodepodcast)
Predicted to be a $20 Billion cybercrime empire by the end of 2021, Ransomware is impacting businesses like never before… resulting in loss of revenue, reputation, and resources for organizations of all types. To put things in perspective, it is reported that an attack hits once every 11 seconds, and as if that stat isn’t hard enough to fathom, it’s predicted to worsen in the near future.
As the war against Ransomware continues, I catch up with Ransomware-focused expert Greg Edwards at BarCode. Greg is the CEO at Cryptostopper, and his mission is to build a superior, global cybersecurity firm to defend businesses from the cybercriminals lurking in the shadows of the Internet.
We chat about the evolution of ransomware, recent ransomware attacks, why it’s unstoppable, unorthodox variants in the wild, and his ongoing pursuit to stop the bleeding.
Tony the Bartender locks down an “Epic Fail”.
Support the show (https://www.patreon.com/barcodepodcast)
Organizations are increasingly adopting a Zero Trust model, which is based on the philosophy that there should be no implicit trust in a corporate network. Rooted in the principle of “Never Trust, Always Verify”, Zero Trust is designed to protect modern digital environments against successful data breaches. While it has existed for over a decade, Zero Trust is one of the most misused “buzzwords” in the industry today. Vendor marketing and other misleading data has unfortunately caused mass confusion about what Zero Trust really is and how to use it properly.
Former Forrester Research analyst and creator of Zero Trust, John Kindervag, stops in to demystify the term, while explaining how it’s a proven security strategy within enterprise security. Our conversation at the bar includes properly defining the term, the value of adoption, implementation techniques, exemptions, and more!
Tony the Bartender develops a “Python”.
Support the show (https://www.patreon.com/barcodepodcast)
Engines require three vital elements to generate power: AIR, SPARK, and FUEL. If any of these three elements aren’t present, the engine will struggle to function or even start. Fuel injectors are a vital part of a complex system that delivers the fuel to an engine, so it’s a critical component for ensuring successful ignition.
In the startup world, air and spark may come naturally… such as an idea, concept, or solution to a major problem. Although, let’s think of the third element, FUEL, as sustenance. In other words, endurance and strength that can only be supplied by an expert with frontline experience and in-depth knowledge. Then, and only then, will the power to succeed be evident. Joseph Schorr is a Cybersecurity and Risk Services Executive at LogicGate. In this episode, he provides the fuel to help power cybersecurity startups and aspiring entrepreneurs, security for SMBs, GRC and LogicGate.
Tony the Bartender revs up a “Sidecar”.
Support the show (https://www.patreon.com/barcodepodcast)
A former data scientist at Facebook, Sophie Zhang was tasked with investigating “fake engagements” although instead, discovered global political manipulation and opposition harassment in 25 countries. She was fired from Facebook in September 2020, after declining a $64,000 severance package attached to an NDA, restricting her ability to speak publicly about it.
Upon leaving, she posted a 7,800 word departure letter to Facebook’s internal message board outlining Facebook’s failure to combat political manipulation.
PART II
The second installment of this special series picks up where PART I left off. Sophie continues walking us through her experience including writing her infamous Facebook exit memo, how it was leaked to the public, her current relationship with the social network giant, content regulation & election integrity, potential solutions moving forward, her preception of being labeled a “whistleblower” and much more!
Tony the Bartender follows a “Lemon Drop”.
Support the show (https://www.patreon.com/barcodepodcast)
A former data scientist at Facebook, Sophie Zhang was tasked with investigating “fake engagements” although instead, discovered global political manipulation and opposition harassment in 25 countries. She was fired from Facebook in September 2020, after declining a $64,000 severance package attached to an NDA, restricting her ability to speak publicly about it.
Upon leaving, she posted a 7,800 word departure letter to Facebook’s internal message board outlining Facebook’s failure to combat political manipulation.
PART I
Sophie graciously agrees to join me, and special co-host Alex Srebroski at the bar to begin walking us through her experience, in addition to providing her thoughts on misinformation VS disinformation and much more.
Tony the Bartender posts a “Mind Eraser”.
Support the show (https://www.patreon.com/barcodepodcast)
nu·cle·us /n/ : the central and most important part of an object, movement, or group, forming the basis for its activity and growth.
Having a nucleus to your Threat and Vulnerability Management Program is critical, as well as having an established TVM program itself.
In this episode, I chat with Scott Kuffer, co-founder and COO of Nucleus Security. He is an expert in vulnerability management and workflow optimization. We discuss the critical pillar of cybersecurity and his Nucleus Security program.
Tony the Bartender unifies sources for a "Gin Rickey".
Support the show (https://www.patreon.com/barcodepodcast)
Jacob Horne is the Managing Director at DEFCERT where he specializes in DFARS and CMMC level three compliance for manufacturers in the Defense Industrial Base. As a former NSA intelligence analyst and U.S. Navy cryptologic technician, Jacob has over 14 years of experience in offensive and defensive cybersecurity operations. As a civilian he has led Governance, Risk, and Compliance teams at AT&T, Northrop Grumman, and the NIST Manufacturing Extension Partnership. He has developed and taught numerous cybersecurity training programs for organizations including the NSA National Crypotologic School, UCLA, and UC Irvine. Jacob has a master’s degree in cybersecurity risk and strategy from the NYU School of Law and is an MBA candidate at the UC Irvine Paul Merage School of Business.
Jacob joins me at the bar to simply define CMMC, what organization’s are in scope, what they need to know, how the landscape is changing and explanation of it’s inner workings. We travel through time to truly understand it’s relevance in the Past, Present, and the Future.
Tony the Bartender summons a "Corpse Reviver #2".
Support the show (https://www.patreon.com/barcodepodcast)
William Lin became an avid technology enthusiast after building his very first computer in elementary school and then began experimenting with the latest venture-backed consumer business models in his spare time. He is now Managing Director and a founding team member at ForgePoint Capital, a VC firm focused on cybersecurity startups. he has worked with more than 20 cybersecurity companies to date. In his spare time he enjoys connecting friends, enabling serendipity and building communities.
He joins me and special co-host Gabe Doncel at the bar to discuss his evolution as a venture capitialist, the levels of funding that exists, different types of investors, how to take an idea to relaity, what he would listen to in a 30 second elevator pitch, and much more!
Tony the Bartender attacks with an “Electric Shark”.
Support the show (https://www.patreon.com/barcodepodcast)
Dr. Matthew Canham is the CEO of Beyond Layer 7 (a cybersecurity consulting firm specializing in human security and data analytics), and a Research Professor of Cybersecurity at the Institute of Simulation and Training, University of Central Florida. Previously, as a federal investigator, Dr. Canham investigated cybercrimes, intellectual property theft, and insider threats. He holds a PhD in Cognitive Neuroscience with specialized expertise in human-centered security, data analytics, and behavioral engineering.
Live from Sin City, special co-host Ken Corris and I met up with Matt in an empty, oversized Mandalay Bay conference room, immediately following his Blackhat presentation on Deepfake Social Engineering. He expanded on his talk and shared his insight on the origin of deepfakes, using deepfake for social engineering, the pros and cons of deepfakes, and the future of deepfakes.
In fact, the image featured within this very episode’s artwork above is essentially a deepfake. It’s not really Matthew Canham. In fact, it’s not even a real person at all. It was generated by the site, “thispersondoesnotexist.com”, an artificial-intelligence powered website that uses a GAN algorithm to generate hyper-realistic portraits of completely fake people.
Tony Phony the Bartender goes all in with a “High Roller”.
Support the show (https://www.patreon.com/barcodepodcast)
Re-running this great chat with Ron Gula from the early days! A fierce visionary, Ron Gula has redefined the security landscape and continues to do so. From co-creating Tenable, developing Dragon IDS, and now serving as President of Gula Tech Adventures, his incredible story is far from over. He joins me at the bar to discuss the conception of Tenable, his "Data-Care" approach, challenges during the COVID era, Cybersecurity’s #1 myth, advice for entrepreneurs and his new foundation which will provide millions of dollars in competitive grants to cybersecurity non-profits.
Tony the Bartender rings in a “Manhattan”.
Support the show (https://www.patreon.com/barcodepodcast)
The quickly growing field of vendors in cybersecurity getting attention of security leaders is becoming more difficult by the day. The fatigue of the continuous vendor attempts to fill up their time is very real. Getting your solution seen and even getting a few minutes with these leaders requires a tactical and strategic approach and proving your value with the time you get is more important than ever. Cybersecurity Sales experts Neil Saltman and Doug Gotay stop by BarCode to discuss better ways to sell to leaders and descion makers, the key to building trust, arming the CISO with buying power, rookie mistakes to avoid, the Sales Rep/Sales Engineer relationship, and much more.
Tony the Bartender is out, so BoozeBot returns to shed “Tiger Blood”.
Support the show (https://www.patreon.com/barcodepodcast)
Brazilian Jiu-Jitsu (BJJ) is extremely difficult to master since it goes against conventional thinking. It is procedural and it is technical. While in combat, chaos ensues although the fighters must stay laser focused. Just as one needs to apply the proper technique in BJJ, cybersecurity professionals must find ways to creatively apply their techniques in unconventional attack scenarios as well. It’s proven that implementing fundamental BJJ concepts and principles will help strengthen the core of your security strategy, tactics and overall mindset. The methodology also will help minimize the risk of an organizational tapout.
Security experts and highly skilled BJJ practitioners Jeremiah Grossman, Jeremiah Batac and Tyler Bohlmann join me to watch the main event at BarCode. As the highly anticipated Jiu-Jitsu match progresses, we discuss the parallels between security and BJJ including the importance of preparation, mind-preparedness, training, energy conservation, overcoming adversary, embracing the grind and keys to victory.
Tony the Bartender submits a “Caipirinha”.
Support the show (https://www.patreon.com/barcodepodcast)
Cyber threats still exist in the sky. Therefore, security controls within the Aviation industry is needed to protect the aircraft vessel, as well as it’s interconnected technology. Past investigations performed by hackers, researchers, and flight authorities have cast doubt on the industry’s perceived culture of safety. The need to address the novel challenges posed by modern-day cyber threats is evident and the importance is often overlooked. Nothing less than pure havoc would occur if compromise occurs.
Based in Germany, Martin Pacher is a Senior First Officer for Lufthansa Airlines, a Telecommunications Engineer, and a cybersecurity expert. As a pilot, he advocates for aviation safety, both physically and digitally and is occasionally giving speeches at aviation and cybersecurity conferences about the pilot’s viewpoint on cyber. He flies into BarCode to discuss security from his perspective, the potential risks involved, infiltration points, cyber-terrorists, Supply-Chain attacks within aviation, Aircraft pentesting, and the elevated future of aviation security.
Tony the Bartender serves a first-class “Tequila Sunrise”.
Support the show (https://www.patreon.com/barcodepodcast)
Paul Asadoorian is a security veteran that has spent time “in the trenches” implementing comprehensive security programs across a wide array of industries. A proven cybersecurity leader and innovator, Paul founded “Security Weekly” – a podcast network providing free knowledge for the entire security community to benefit from. As former Product Evangelist for Tenable, Paul built a library of materials on the topic of vulnerability management. He has also spent time as an instructor for The SANS Institute, an IANS faculty member and has presented at security conferences including RSA, Derbycon, BruCon, SOURCE Conference and more.
I run into him at the bar, and we chat about his journey into cyber, the ability to deliver quality content to his audience while staying ahead of the game, his thoughts on vulnerability researchers, the public portrayal of hackers, and the one finding you'd see in a gap analysis of the entire cybersecurity industry.
Tony the Bartender cranks up a “King’s Jubilee”.
Support the show (https://www.patreon.com/barcodepodcast)
John Sileo left hi-tech consulting and became an entrepreneur to reclaim his greatest priority – being present, every day, for his wife Mary and their dream of starting a family. Six successful years, a $2M business and two precious daughters later, he lost it all to cybercrime. Because the cybercriminal, a company insider, masked the crimes using John’s identity, John was held legally and financially responsible for the felonies committed. The losses destroyed his company, decimated his finances and consumed two years of his family life as he fought to stay out of jail.
So, driven by his own experience as a victim of identity theft, John has become a world-renowned identity theft speaker and expert on data theft, striving to help organizations take proactive steps in preventing identity fraud. We catch up at the bar and discuss his story and how it became the premise for a Hollywood movie, a unique approach on how to sell better, why the term “Zero Trust” is cultural suicide, his own concept of Deep Trust, and more!
Tony the Bartender gives us “The Final Answer”.
Support the show (https://www.patreon.com/barcodepodcast)
Videogame studios are under serious attack, partly because they don't need to adhere to the same security requirements and regulatory demands as more prominent industries. From an attacker's viewpoint, it's very lucrative. Not only are game developers at risk for attack, so are the gamers themselves. Access to one's XBOX LIVE account, or game profile could cause irreversible damage in gameplay as well as personal financial loss.
Matt Huysman, Co-Founder and COO of Cyrex, specializes in software development and application security, with a very strong focus on the gaming industry. His company is in full control of this space when it comes to APPSEC and Pentesting services. Matt's extremely proficient in hacking any game engine, protocol or architecture, in turn helping secure many well known gaming titles such as DOOM ETERNAL, TERA, FROZEN FLAME, KINGDOM UNDER FIRE II and many more.
He plugs in as Player 2 at the bar, and we join forces to discuss the history of online game hacking, adversary motives, exploiting game architecture, reverse-engineering and testing methodologies, player safeguards, Anti-Cheat mechanisms and much more!
Tony the Bartender accelerates a "Sonic" shot.
Support the show (https://www.patreon.com/barcodepodcast)
"AM I NEXT???" That's a question CEOs WORLDWIDE are asking themselves. Recent Ransomware attacks on JBS and the Colonial Pipeline have certainly elevated alert levels, although Ransomware remains an industry plague. With seemingly no end in sight, the attacks continue to cripple businesses while making its perpetrators millionaires.
Aviv Grafi is CEO & Founder of Votiro, an award-winning cybersecurity company specializing in neutralizing weaponized files of all kinds through Secure File Gateway solutions. Aviv is the principal software architect for Votiro's enterprise technologies, which protect against 100% of file-borne cyber threats within an organization. He joins me at the bar to discuss the true criticality of ransomware, why businesses are still susceptible to attack and Votiro's unique approach to mitigate the threat.
Tony the Bartender constructs a "Red Hook".
Support the show (https://www.patreon.com/barcodepodcast)
Joe Grand is an electrical engineer, hardware hacker, product designer and the founder of Grand Idea Studio, Inc. He specializes in creating, exploring, manipulating, and teaching about electronic devices.
Also known as Kingpin, Joe was a member of the legendary hacker group L0pht Heavy Industries, where he helped raise awareness of the hacker ethos and the importance of independent security vulnerability research. He also brought engineering to the masses as a co-host of Discovery Channel’s Prototype This, which followed the real-life design process of a unique prototype every episode.
Co-Host Pete Klabe joins me as Kingpin talks us through how he himself is wired. Topics include his background as a technological juvenile delinquent, the hidden benefits of Imposter Syndrome, dealing with the rollercoaster ride of success and failure, IoT, his ULTIMATE Smart-Home setup, ulterior motives of modern technology, and his awesome prototype of a pizza compass that has since replaced my GPS System.
Tony the Bartender operationalizes a “Kombucha Grand Mule”.
Support the show (https://www.patreon.com/barcodepodcast)
At this moment, more than 70% of us are currently compromised by cybersecurity attacks that we underplay, ignore, or simply aren’t aware of because of their hyper-stealthy and invisible nature. In fact, most individuals and businesses will have been compromised for more than 3 years before they realize what’s happened. It's vital to help other's understand the genuine threat of cybersecurity attacks while delivering steps they can take to quickly and easily develop a proactive plan to mitigate exposure and damage and ensure the security of their businesses, their families, and their futures.
Dr. Eric Cole, AKA the OG, is a former CIA hacker, cybersecurity commissioner to the Obama administration, and advisor to clients including the Obama family, Bill Gates, Lockheed Martin, and McAfee. Eric stops by BarCode, and special co-host Mike Elkins and I engage in a conversation with him that includes translating the importance of cybersecurity to executives, the importance of technical aptitude needed for a CISO role, dealing with haters, risk taking, his new book and more!
Tony the Bartender empowers us with the "Godfather".
Support the show (https://www.patreon.com/barcodepodcast)
In Cybersecurity, we aim to protect the most valuable assets. In the games of chess, that asset is the king. Developing a successful chess strategy requires time, effort, and patience. There is also no universal strategy, and every move a player makes is crucial.
In this episode, the iconic Security Blogger and co-host of the popular Smashing Security podcast, Graham Cluley visits Barcode. We talk about his influencers, Cybersecurity's biggest challenge currently, Buzzword buzzkill, NFTs, threats on the horizon, and I also ask Graham the WORST question he has ever been asked in his 30 year career.
Tony the Bartender in unavailable, so SJ is in to crown "The King".
Support the show (https://www.patreon.com/barcodepodcast)
Identity theft occurs when someone uses another person's personal identifying information, like their name, identifying number, or credit card number, without their permission, to commit fraud or other crimes. At one point in time, the Social Security number was described as the skeleton key needed to unlock theft of your assets, your identity, and your life. Although that's since changed, and the skeleton key now is much more accessible... and it's ease of obtainability may surprise you.
Adam Levin is a nationally recognized expert on cybersecurity, privacy, identity theft, fraud, and personal finance and has distinguished himself as a fierce consumer advocate for the past 40 years. Within his list of esteemed positions include former Director of the New Jersey Division of Consumer Affairs, founder of Cyberscout and co-founder of Credit.com. He is also author of the critically acclaimed book, Swiped: How to Protect Yourself in a World Full of Scammers, Phishers, and Identity Thieves. We chat at the bar about how to prevent identity theft, the new threat to remote workers and businesses, the advancements of AI deepfakes and the future of identity theft, and much more.
Tony the Bartender (presumably) captures a "Rye Bandit".
Support the show (https://www.patreon.com/barcodepodcast)
A Flying Fish will leap out of the water and use its winglike pectoral fins to glide over the surface. Then, once below the surface, it is out of site and flows amongst the others in different directions until it appears above water again.
Rohan Light is an expert on governance, strategy and risk capability throughout the data, evidence and decision management value chain. He is also well versed in Artificial Intelligence, trusted data use and platform governance. He, along with special co-host Mike Elkins, join me to discuss his Flying Fish Theory of Change Model, AI Ethics, and more.
Tony the Bartender assigns BoozeBOT to serve up a "Mojito" that's off the hook.
Support the show (https://www.patreon.com/barcodepodcast)
Social engineering is the art of exploiting human psychology. There is no perimeter defense for this method of infiltration. Known as the “People Hacker”, Jenny Radcliffe has spent a lifetime learning how to use the human element to gain access to the buildings, data and information, and the things we would wish to keep private. Her main objective is to smash security measures, using psychology, con-artistry, subliminal linguistics, cunning and guile.
She’s an international keynote speaker, TEDx contributor, Award-Winning Podcast Host, and a go-to guest expert on TV, Radio and other online media. We socialize at the bar on subjects such as Social Engineering recon, deception techniques, skillsets needed, and tips for those looking to learn human hacking. Oh, plus how one break-in she was involved in intensified rapidly.
Tony the Bartender coaxes us into “Hypnosia”.
Support the show (https://www.patreon.com/barcodepodcast)
Nato Riley takes what others know to be true and is still able to find something hidden below the surface. It’s a mind frame that proves that seeing the invisible is not impossible. Equipped with true XRAY Vision, Nato joins me at the bar to discuss DevSecOps beyond the SDLC, Security Maturity, his homegrown "Olympiad" SIEM, Man VS Machines, and the potential of technology takeover.
Tony the Bartender rigs up a "Carnivore".
Support the show (https://www.patreon.com/barcodepodcast)
The 2020 Xfinity Cyber Health Report cites an estimate that 854 million connected-home devices will be shipped by manufacturers in 2020, with that number is projected to grow to nearly 1.4 billion by 2024. Most of the consumers of these products don’t realize is that once a smart devices goes online, it poses serious security risks.
Tony Reinert manages the DevSecOps Transformation program for Comcast, the largest cable TV company and largest home Internet service provider in the United States. His program empowers product and engineering teams to build security into products and services that ultimately reside in the homes of Comcast subscribers. He emphasizes the importance of having residential digital armor; a protective layer over informational assets that's intended to deflect or diffuse damaging forces. We also discuss Threat Intel, IoT Security, Device Product Testing, Bug Bounty Programs, protection of residential smart home eco-systems, and advice to aspiring Product Security testers.
Tony the Bartender equips us with a "Midnight Stinger".
Support the show (https://www.patreon.com/barcodepodcast)
The major cause of insecurity is the lack of secure software development practices. It’s crucial to understand the importance of security within the SDLC. Jim Manico is the founder of MANICODE Security where he trains software developers on secure coding and security engineering. He stops by BarCode to help us define “DevSecOps”, building an Effective CI/CD Pipeline, the differences between SAST/SCA/RASP/DAST and IAST, Security Team/ Development Team Cohesion, what most organizations GET WRONG with implementing DevSecOps, cloud involvement within the SDLC, and helpful OWASP resources.
Tony the Bartender gits “Radioactive”.
Support the show (https://www.patreon.com/barcodepodcast)
Overseeing security and privacy challenges in COVID era is an extremely difficult task—and it’s even more complicated if you’re a Healthcare CISO. You must monitor the vital signs of your security program while keeping the pulse on threat vectors and adversaries.
Anahi Santiago meets with me at the bar to discuss being a CISO during the pandemic, medical device security, Ransomware, advice for aspiring healthcare security professionals and more.
Tony the Bartender administers a “Vitamin C”.
Support the show (https://www.patreon.com/barcodepodcast)
The great Philosopher Seneca once said "While we teach, we learn”.
The Protege Effect states that the best way to learn is to teach someone else. This powerful theory is further explained by cybersecurity leader and mentor, Naomi Buckwalter during her stop at Barcode.
We also get into topics such as cybersecurity mentoring, privacy post-pandemic, cybersecurity myths, Philly Tech Sistas, stopping cybercrime, breaking into cyber, advice for cybersecurity recruiters, and much more.
Tony the Bartender keeps us hydrated with "H2O".
Support the show (https://www.patreon.com/barcodepodcast)
Data is always the main target in an attacker’s scope. Therefore, organization’s should take a “data first” approach to preventing a strike that could cripple them with one shot.
I catch up with Purandar Das, Founder and CEO of Sotero, to discuss his data protection strategy. Purandar started Sotero with the conviction that today’s data protection was deficient and that a better approach was needed to protect data. He is a firm believer that security, where the core focus is not the data, is not a viable option.
We chat about creating a data-centric mindset, avoiding vendor fatigue, eliminating workflow disruption, addressing legacy systems, as well as Sotero’s overall mission.
Tony the Bartender decodes a “Crypto Cocktail”.
Support the show (https://www.patreon.com/barcodepodcast)
Debbie Reynolds, AKA “The Data Diva,” is a world-renowned technologist, thought leader and advisor to multinational corporations for handling global data privacy, cyber data breach response, and complex cross-functional data-driven projects. She's also an internationally published author, highly sought-after speaker, and top media presence for global data privacy, data protection, and technology issues. Debbie joins me at the bar along with special co-host Ken Corris, to discuss data privacy in the pandemic era, streamlining cryptography, "Data Purpose Jacking", advice for aspiring professionals focused on data security, and more.
Tony the Bartender posts the return value of a "Divatini".
Support the show (https://www.patreon.com/barcodepodcast)
nu·cle·us /n/ : the central and most important part of an object, movement, or group, forming the basis for its activity and growth.
Having a nucleus to your Threat and Vulnerability Management Program is critical, as well as having an established TVM program itself.
In this episode, I chat with Scott Kuffer, co-founder and COO of Nucleus Security. He is an expert in vulnerability management and workflow optimization. We discuss the critical pillar of cybersecurity and his Nucleus Security program.
Tony the Bartender unifies sources for a "Gin Rickey".
Support the show (https://www.patreon.com/barcodepodcast)
An aviator is an expert of the skies and must know how to properly navigate through clouds. Fully understanding cloud formations and their potential dangers when flying is a vital part their profession.
Flying through clouds is just like driving through fog – little visibility can represent extreme danger for those unaware of the circumstance.
To help us understand, Cloud Security expert Ashish Rajan, host of the popular Cloud Security Podcast, joins me and my special co-host Mike in BarCode's Skybox to discuss his incredible nephological knowledge.
In this episode, we cover common cloud security misconceptions, cloud challenges in 2021, data immutability within in the cloud, and why he thinks CASBs are on the way out.
Tony the Bartender provisions a "SkyLab".
Support the show (https://www.patreon.com/barcodepodcast)
Often, data goes Absent Without Official Leave. No one within the organization grants it permission to vacate the premises. How do organizations protect and secure their data and stay ahead of the bad actors?
A data breach is the intentional or unintentional release of private/confidential information to an untrusted environment. It's extremely crucial that the risk and consequences of a data breach transcends to the public. Confidentially is the 1st tenant in the CIA triad. For those who may not be aware, CIA Is confidentiality, integrity, and availability. Together, these three principles form the cornerstone of any organization’s security infrastructure.
Alexandre Blanc became cyber risk subject matter expert, from local infrastructures to global threat landscape analysis through 20+ years of infrastructure management, protecting and securing systems from online threats. He loves to correlate information from OSINT, and draw global trends in cyber threat landscape. His hands on experience on protecting sensitive infrastructures, combined with daily threats trend analysis and awareness raising, brought him to an essential position in regard to risk analysis overview, information sharing, from low to high level perspectives.
He joins me at the bar to discuss prime attack vectors, Ransomware defense, data exfiltration, Incident Response, and more.
Tony the Bartender gets an office, and BoozeBOT returns to output a "Death Flip".
Support the show (https://www.patreon.com/barcodepodcast)
To defend against modern day hackers, you must train your mind to think like one.
Ted Harrington is the author of "HACKABLE: How To Do Application Security Right", which is an Amazon BEST SELLER in 9 Categories. He is also Executive Partner at Independent Security Evaluators (ISE), the security organization famous for hacking everything from cars to medical devices to smartphones, and more. Ted has been named both Executive of the Year and 40 Under 40. He also co-founded and organizes the popular IoT Village, and currently hosts the "Tech Done Different" Podcast.
He steps into the BarCode to drop knowledge on application security, DEFCON's IoT Village, and even gives us the inside info on how to hack your way into a bar!
Tony the Bartender executes "The Infection".
Support the show (https://www.patreon.com/barcodepodcast)
A "Suplex" is an offensive move used in wrestling by which an attacker uses his weight to throw a defender.
Phillip Wylie’s unusual journey into the field of cybersecurity is preceded by his career as a powerlifter and pro wrestler for the WCW. He has since taken full control in the industry as an offensive security professional. He is an established Red Teamer, Pentester, Ethical Hacking Instructor, and founder of the PWN School Project - an education focused cybersecurity organization that offers free pentesting and ethical hacking education to the public. Phillip and I overtake the bar to discuss his exhilarating path into cybersecurity, bug bounties, ethical hacking learning resources, and more!
Tony the Bartender pins a Negroni.
Support the show (https://www.patreon.com/barcodepodcast)
HD Moore, famed developer of the wildly used Metasploit penetration testing tool spoke with me about his current focus, RUMBLE, in addition to his perspective on bug bounty programs, advice for aspiring pentesters and more. Of course, we also discussed the happening bar scene in Austin TX and how the city has become known as Silicon Hills.
Tony the Bartender reveals "The Getaway".
Support the show (https://www.patreon.com/barcodepodcast)
Grayson Milbourne is the Security Intelligence Director for Webroot, Inc., an OpenText company that focuses on endpoint security and threat intelligence. He joins me at the bar to discuss new and emerging threats, securing our homes during the COVID era, IoT security and cybersecurity trends we should expect to develop in 2021 and beyond.
Deepfake Phony digitally transforms a “Long Island IoT”.
Support the show (https://www.patreon.com/barcodepodcast)
Currently the Senior Director for Cyber Intelligence Strategy for Anomali, A.J. Nash is a cyber intelligence strategist and public speaker focused on building cyber intelligence programs that capitalize on disparate data and information to create and deliver tactical, operational, and strategic intelligence to protect personnel, facilities, data, and information systems. I speak with him about the cultural differences in Cybersecurity between the Government and Private Sector, his time spent at the NSA, Threat Intelligence best practices and more.
Tony the Bartender is unexpectedly replaced by BoozeBOT, who programs a “Whiskey Sour”.
Support the show (https://www.patreon.com/barcodepodcast)
A fierce visionary, Ron Gula has redefined the security landscape and continues to do so. From co-creating Tenable, developing Dragon IDS, and now serving as President of Gula Tech Adventures, his incredible story is far from over. He joins me at the bar to discuss the conception of Tenable, his "Data-Care" approach, challenges during the COVID era, Cybersecurity’s #1 myth, advice for entrepreneurs and his new foundation which will provide millions of dollars in competitive grants to cybersecurity non-profits.
In honor of the New Year finally upon us, Tony the Bartender rings in a “Manhattan”.
Support the show (https://www.patreon.com/barcodepodcast)
Internationally renowned security guru, privacy specialist and author, Bruce Schneier, stops by BarCode to discuss the FireEye Hack, Covid-19 Vaccine Cold Chain Attacks, CISA, and Net Neutrality. I'm also joined by special guest co-host Alex, and Tony the Bartender explains his theorem for a "Blitzen".
Support the show (https://www.patreon.com/barcodepodcast)
Open source intelligence (OSINT) describe the techniques used to gather information online from publicly available sources. This methodology can be used to target specific individuals for nefarious purposes, or alternatively, provide direct evidence against perpetrators and bring them to justice. Stephen Adams, Intelligence specialist with a focus in Internet Investigations and based in the UK, speaks with me about OSINT, SOCMINT, ethics and available tools. We also discuss "Intelligence With Steve", an educational platform he created that provides comprehensive and relevant Criminal and Security Intelligence training content. Tony the bartender provides the intel for a "Painkiller".
Support the show (https://www.patreon.com/barcodepodcast)
I have the privilege of speaking with an AI trailblazer and a member of Forbes 30 Under 30, Przemek Chojecki. We discuss "Contentyze", a platform he created that aims to fix the inefficiencies in journalism with automated content generation. We also talk Machine Learning, Deepfake Technology, and also where the intersection of AI and Cybersecurity meet. The virtual bartender makes an epoch drink, "The Anomaly".
Support the show (https://www.patreon.com/barcodepodcast)
It's a BarCode NCSAM/ HALLOWEEN special, where I speak with established author and iconic security professional who is no stranger to disguises, deception and duplicity - Ira Winkler! We discuss security awareness, his time in the NSA, Secure Mentem, his new book "You CAN Stop Stupid", and some of his insane espionage expeditions that make James Bond look like 006. The virtual bartender social engineers a scary good Dracula Margarita.
Support the show (https://www.patreon.com/barcodepodcast)
I tap into the knowledge of Stan Ivanov - Industry Expert in Secure Programming, Cryptography and Entrepreneurship. We verbally decipher Cryptocurrency, Quantum Crypto, "Secure My Files" and advice for Start-Ups. The virtual bartender discloses the algorithm for a Sapphire Alpine.
Support the show (https://www.patreon.com/barcodepodcast)
Cybersecurity and 3D Printing unite! Cybersecurity professionals Gabriel Doncel and Scott Darkow meet up with me at the bar to discuss cyber risk involving both personal and enterprise-grade 3D printing. The virtual bartender manufactures a Next-Gen Fireball.
Support the show (https://www.patreon.com/barcodepodcast)
I recently caught up with security legend Troy Hunt and got to discuss cyber attack vectors in the COVID era, VPNs, IoT Security and why he decided to opensource HIBP. You don't want to miss this one! The virtual bartender securely transfers a Blue Monday.
Support the show (https://www.patreon.com/barcodepodcast)
Joshua Feldman, VP of Security Architecture and Engineering at Radian joins me at the bar to discuss Strategy, APPSEC, and Advice for Cyber-Sales Professionals. The virtual bartender deploys a kamikaze.
Support the show (https://www.patreon.com/barcodepodcast)