Artwork for Three Buddy Problem
Technology

Three Buddy Problem

Security Conversations

The Three Buddy Problem is a popular Security Conversations podcast that goes beyond industry talking points to discuss what others won’t -- nation-state malware, attribution, cyberwar, ethics, privacy, and the messy realities of securing computers and corporate networks. Hosted by three veteran security pros -- journalist Ryan Naraine and malware paleontologists Costin Raiu and Juan Andres Guerrero-Saade -- the weekly show attracts a highly engaged audience of security researchers, corporate defenders, CISOs, and policymakers. Connect with Ryan on Twitter (Open DMs).

  • 235 episodes
  • Updated Friday

Episodes235

  • Jul 16, 2018 · 38 min

    Dan Hubbard, Chief Security Architect, Lacework

    Lacework Chief Security Architect Dan Hubbard joins the podcast to discuss his new research on container security, the challenges of securing cloud deployments, and why technological advancements have widened attack surfaces.

  • Jun 25, 2018 · 46 min

    David Weston, Principal Security Engineering Manager, Microsoft

    David Weston manages the Windows Device and Offensive Security Research teams at Microsoft. He joins the podcast to talk about how proactive red-team exercises push major mitigations to Microsoft's products and the current state of security in the Windows ecosystem.

  • Jun 18, 2018 · 37 min

    Rich Seiersen, SVP and CISO, Lending Club

    SVP and Chief Information Security Officer (CISO) at Lending Club, Rich Seiersen, digs into the nuts and bolts of defending a financial services firm, his approach to finding quality cybersecurity talent, and the importance of confronting security with data. (Recorded during fireside chat at SecurityWeek's <a href="https://cisoforum.com">CISO Forum</a>)

  • May 31, 2018 · 37 min

    Andrew Morris, Founder and CEO, GreyNoise Intelligence

    Founder and CEO of GreyNoise Intelligence Andrew Morris talks about his anti threat-intelligence company, the ways SOCs are using it to filter through scanning noise and the trials and tribulations of bootstrapping a start-up.

  • May 21, 2018 · 26 min

    Yoav Leitersdorf, Managing Partner , YL Ventures

    Managing Partner at YL Ventures, Yoav Leitersdorf, explains the surge in cybersecurity investments in Israel, the priorities for his $75 million fund, and which sectors are ripe for the picking.

  • May 14, 2018 · 1 hr 1 min

    Juan Andrés Guerrero-Saade, Principal Security Researcher, Recorded Future

    Principal Security Researcher at Recorded Futures Insikt Group, Juan Andrés Guerrero-Saade, explains the nuances of good threat intelligence, sheds light on nation-state hacker activity and warns that adversaries don't have to be sophisticated to launch successful attacks.

  • May 10, 2018 · 54 min

    Robert M. Lee, Chief Executive Officer, Dragos Inc.

    The founder and CEO of Dragos, Inc. Robert M. Lee cuts through the hype around threats to critical infrastructure and offers a matter-of-fact take on active defense, “hacking-back,” and nation-state espionage operations.

  • May 9, 2018 · 1 hr 3 min

    Brandon Dixon, Vice President, RiskIQ

    VP of Product at RiskIQ Brandon Dixon delves into nation-state cyber operations, explains why it’s dangerous to underestimate North Korea’s capabilities, and his passion for roasting the perfect coffee bean.

  • May 8, 2018 · 1 hr 4 min

    Ryan Huber, Security Architect, Slack

    Slack security architect Ryan Huber talks about the gargantuan task of defending an organization with 8 million daily active users, burnout, and fatigue in security teams and a range of issues around bug bounties and penetration testing.

  • May 4, 2018 · 1 hr

    Ivan Arce, CTO at Quarkslab

    Chief Technology Officer at Quarkslab Ivan Arce tells stories about the birth of penetration testing platforms, the concentration of hacking talent in Argentina, and his focus on security problems in the Android ecosystem.

  • May 2, 2018 · 44 min

    Sinan Eren, Founder and CEO, Fyde

    Founder and CEO of Fyde (@FydeApp) Sinan Eren discusses the “iOS-ification” of platforms and the security ramifications, the dangers of running AV software, the iOS vs. Android security argument, and his new venture to address mobile phishing attacks.

  • Apr 30, 2018 · 49 min

    Stephen Ridley, Founder and CTO, Senrio

    Founder and CTO at Senrio Stephen Ridley talks about the abysmal state of IoT security, his recent exploitation of an IP camera, and router to exfiltrate corporate data and his experience as a minority in the security industry.

  • Apr 26, 2018 · 39 min

    Mischel Kwon, Founder and CEO, MKA Cyber

    Founder and CEO at MKACyber Mischel Kwon joins the podcast to address the state of the SOC (Security Operations Center) and how businesses should deal with issues around excessive alerts, incident response times, and outdated metrics.

  • Apr 23, 2018 · 48 min

    Thomas Ptacek, Founder, Latacora

    Latacora Security founder Thomas Ptacek joins the podcast to weigh in on the cybersecurity skills shortage, his approach to recruiting and hiring, and what needs to be done to address diversity in the industry.

  • Apr 16, 2018 · 41 min

    Zane Lackey, Chief Security Officer, Signal Sciences

    Co-founder and Chief Security Officer at Signal Sciences Zane Lackey riffs on DevOps, the almost impossible task of defending organizations from intruders, bug bounties versus penetration testing, and the pros and cons of launching a company with venture capital investment.

  • Apr 12, 2018 · 1 hr

    Haroon Meer, CEO, Thinkst Applied Research

    Thinkst founder Haroon Meer talks about building a security company from scratch without VC funding, using Canaries to pinpoint signs of intruder activity, advancements in security research, and the state of the bug bounty market.

  • Apr 11, 2018 · 39 min

    David (int eighty), Dual Core

    Red teamer and security researcher by day, nerdcore rapper by night, ‘int eighty’ joins the podcast to talk about his work breaking into computer systems, common security mistakes that people make, and his double life as a musician in Dual Core.

  • Apr 5, 2018 · 43 min

    Dennis Fisher, Editor-in-Chief, Decipher

    Veteran cybersecurity writer Dennis Fisher joins the podcast to talk about his new journalism venture at decipher.sc, his preference for long-form writing, and the trends worth following in the security space.