Artwork for Three Buddy Problem
Technology

Three Buddy Problem

Security Conversations

The Three Buddy Problem is a popular Security Conversations podcast that goes beyond industry talking points to discuss what others won’t -- nation-state malware, attribution, cyberwar, ethics, privacy, and the messy realities of securing computers and corporate networks. Hosted by three veteran security pros -- journalist Ryan Naraine and malware paleontologists Costin Raiu and Juan Andres Guerrero-Saade -- the weekly show attracts a highly engaged audience of security researchers, corporate defenders, CISOs, and policymakers. Connect with Ryan on Twitter (Open DMs).

  • 235 episodes
  • Updated Friday

Episodes235

  • Apr 10, 2023 · 32 min

    Serial entrepreneur Rishi Bhargava on building another cybersecurity company

    Episode sponsors: - Binarly (https://binarly.io) - FwHunt (https://fwhunt.run) Rishi Bhargava and the team of entrepreneurs behind Demisto’s $560 million exit are back at it with a new startup building technology in the customer identity market. The new company, called Descope, raised an abnormally large $53 million seed-stage funding round with ambitious plans to take on rivals big and small in the customer identity and authentication space. On this episode of the podcast, Bhargava joins

  • Mar 6, 2023 · 35 min

    Claude Mandy on CISO priorities, data security principles

    Episode sponsors: - Binarly (https://binarly.io) - FwHunt (https://fwhunt.run) Symmetry Systems executive Claude Mandy joins the show to discuss a career in the security trenches, life as a CISO during the WannaCry crisis, and first principles around data security. We dig into the emerging Data Security Posture Management (DSPM) category and how it extends the Zero Trust philosophy to hybrid cloud data stores.

  • Feb 15, 2023 · 31 min

    Sidra Ahmed Lefort dishes on VC investments and cyber uncertainties

    Episode sponsors: - Binarly (https://binarly.io) - FwHunt (https://fwhunt.run) Munich Re Ventures investment principal Sidra Ahmed Lefort joins Ryan for a frank discussion on the state of VC funding in cybersecurity, the rise (and coming fall?) of 'unicorns', the massive early-stage funding rounds and what they mean, layoffs and contractions, and the areas in security still ripe for innovation.

  • Jan 19, 2023 · 47 min

    Paul Roberts on wins and losses in the 'right to repair' battle

    Episode sponsors: - Binarly (https://binarly.io) - FwHunt (https://fwhunt.run) SecuRepairs.org co-founder Paul Roberts joins the show to discuss his passion for the right to repair consumer electronic devices, the big-ticket lobbyists working to undermine the movement, and how changing consumer spending patterns are helping to rack up regulatory wins.

  • Dec 8, 2022 · 33 min

    Katie Moussouris on where bug bounties went wrong

    Episode sponsors: - Binarly (https://binarly.io) - FwHunt (https://fwhunt.run) Luta Security founder and chief executive Katie Moussouris joins the show to dish on the bug-bounty ecosystem, the abuse of hacker labor, and the common mistakes made by even the most mature security programs. A security industry pioneer, Moussouris argues for better use of bug bounty metrics to drive decisions and a heavy focus on reducing duplicate vulnerability submissions.

  • Nov 8, 2022 · 30 min

    Robinhood CSO Caleb Sima on a career in the security trenches

    Episode sponsors: - Binarly (https://binarly.io) - FwHunt (https://fwhunt.run) Caleb Sima is a cybersecurity lifer now responsible for security at Robinhood, a mobile stock trading platform. Caleb joins Ryan on the show to discuss the early hacking scene in Atlanta, building SPI Dynamics in a webapp security powerhouse, the evolution of attack surfaces, the CISO's changing priorities, and more...

  • Oct 18, 2022 · 59 min

    Charlie Miller on hacking iPhones, Macbooks, Jeep and Self-Driving Cars

    Episode sponsors: - Binarly (https://binarly.io) - FwHunt (https://fwhunt.run) Famed hacker Charlie Miller joins Ryan on the podcast to discuss a career in vulnerability research and software exploitation. Charlie talks about hacking iPhones and Macbooks at Pwn2Own, the 'No More Free Bugs' campaign, the Jeep hack that led to a recall and his current work securing Cruise's self-driving fleet.

  • Oct 17, 2022 · 52 min

    JAG-S on big-game malware hunting and a very mysterious APT

    * Episode sponsors: [Binarly](https://binarly.io/) and [FwHunt](https://fwhunt.run/) - Protecting devices from emerging firmware and hardware threats using modern artificial intelligence. SentinelLabs malware hunter Juan Andres Guerrero-Saade (JAG-S) returns to the show to discuss how big-game attribution has changed over the years, the nation-state APT landscape, Mudge and the nightmares facing CISOs, and a mysterious actor named Metador.

  • Oct 13, 2022 · 47 min

    Chainguard's Dan Lorenc gets real on software supply chain problems

    * Episode sponsors: [Binarly](https://binarly.io/) and [FwHunt](https://fwhunt.run/) - Protecting devices from emerging firmware and hardware threats using modern artificial intelligence. Dan Lorenc and team or ex-Googlers raised $55 million in early-stage funding to build technology to secure software supply chains. On this episode of the show, Dan joins Ryan to talk about the different faces of the supply chain problem, the security gaps that will never go away, the decision to raise an unusu

  • Aug 7, 2022 · 1 hr 7 min

    Vinnie Liu discusses a life in the offensive security trenches

    A conversation with Bishop Fox chief executive Vinnie Liu on the origins and evolution of the pentest services business, the emerging continuous attack surface management space, raising $75m as a 'growth mode' investment, cybersecurity's people problem, and much more...

  • Jul 25, 2022 · 1 hr 7 min

    Down memory lane with Snort and Sourcefire creator Marty Roesch

    Network security pioneer Marty Roesch takes listeners on a trip down memory lane, sharing stories from the creation of Snort back in the 1990s, the startup journey of building Sourcefire into an IDS/IPS powerhouse and selling the company for $2 billion, the U.S. government killing a Check Point acquisition, and his newest adventure as chief executive at Netography.

  • Jun 1, 2022 · 34 min

    Subbu Rama, co-founder and CEO, BalkanID

    Serial entrepreneur Subbu Rama joins the show to talk about building a cybersecurity business, addressing the problem of entitlement sprawl and raising seed funding for intelligent access governance technology.

  • May 10, 2022 · 42 min

    Project Zero's Maddie Stone on the surge in zero-day discoveries

    Maddie Stone is a security researcher in Google's Project Zero team. Over the last few years, she has publicly tracked the discovery and disclosure of zero-day malware attacks seen in the wild. On this episode, Maddie joins Ryan to chat about three years of zero-day exploitation data, the nuances around 0day disclosures, the never-ending struggle to mitigate memory corruption attacks and the need for transparency among affected vendors.

  • May 6, 2022 · 46 min

    Prof. Mohit Tiwari on the future of securing data at scale

    Symmetry Systems co-founder Mohit Tiwari has been studying data security and control flow access for more than a decade. On this episode of the podcast, he discusses his transition from academia to data security entrepreneurship, first principles around the data security and privacy, the exploding DSPM (data security posture management) space, and the mission to solve one of cybersecurity's biggest problems.

  • Apr 4, 2022 · 40 min

    Google's Shane Huntley on zero-days and the nation-state threat landscape

    Director at Google's Threat Analysis Group (TAG) Shane Huntley joins the show and talks about lessons from the 2009 Aurora attacks, the surge in zero-day discoveries, the usefulness of IOCs, North Korean APT operations, private sector mercenary hackers, the expanding nation-state threat actor map, and much more...

  • Mar 21, 2022 · 26 min

    Lamont Orange, CISO, Netskope

    Netskope security chief Lamont Orange joins the show to chat about the changing role of the Chief Information Security Officer (CISO), managing security as a business enabler, the cybersecurity skills shortage, and his own unique approach to security leadership.

  • Mar 19, 2022 · 1 hr 15 min

    Haroon Meer on the business of cybersecurity

    Thinkst founder and CEO Haroon Meer joins Ryan Naraine on the show to talk about building a successful cybersecurity company without venture capital investment, fast-moving attack surfaces and the never-ending battle to mitigate memory corruption issues.

  • Feb 22, 2022 · 19 min

    Tony Pepper, co-founder and CEO, Egress

    Chief executive officer at Egress Tony Pepper joins the show to talk about entrepreneurship in the fast-paced age of modern computing, the state of e-mail security, and his company's bet on securing the future of messaging in the enterprise.

  • Jan 8, 2022 · 27 min

    Microsoft's Justin Campbell on offensive security research

    Justin Campbell leads Microsoft’s Offensive Research and Security Engineering (MORSE) team. He joins the show to talk about his team's discovery of a SolarWinds in-the-wild zero-day, the never-ending stream of memory safety vulnerabilities, the evolving 'shift-left' mindset and Redmond's ongoing work to reduce attack surfaces.

  • Dec 23, 2021 · 41 min

    Costin Raiu on the .gov mobile exploitation business

    Global director of Kaspersky's GReAT research team Costin Raiu returns to the show for an indepth discussion on the mobile surveillance business, the technically impressive FORCEDENTRY iOS exploit, the ethical questions facing exploit developers and the role of venture capitalists in the mobile malware ecosystem.