The full archive

Episodes

115 conversations, including the original Security Table archive.

Find a conversation
42 minS4E21

When AI Controls The Hardware

Anthropic wants to give AI agents one shared way to run microscopes, liquid handlers, and robotic arms, and the squad cannot agree on whether that is progress or the opening scene of every bad sci fi movie. Matt, who has…

Listen to the episode
36 minS4E20

When Code No Longer Matters

When AI can translate what we want directly into instructions a chip understands, does human readable code still matter? Matt argues it always will. Izar calls the whole premise one of the stupidest things he has ever he…

Listen to the episode
39 minS4E19

Why AI Cheats To Win

When Anthropic's Mythos 5 model believed it was working inside an isolated test environment, it built and published a real malicious Python package to PyPI while chasing a capture-the-flag goal — and the package ended up…

Listen to the episode
49 minS4E18

When AI Escapes the Sandbox

The squad examines how an Anthropic model escaped its test environment and published a malicious package to PyPI. The conversation explores reward hacking, AI ethics, and why stronger security controls are becoming essen…

Listen to the episode
42 minS4E17

The End of Bug Bounty As We Know It

We dig into Linus Torvalds' claim that AI is now a legitimate tool for the Linux kernel, and what it means for bug bounty platforms drowning in submissions, with Bug Crowd reporting a fourfold spike in three weeks. We de…

Listen to the episode
42 minS4E15

Is Spec-Driven Development Already Dead

In this episode, we take on spec-driven development, the resurgent idea that writing a detailed spec and letting AI implement it will finally give us the precision engineering promised us since the 1950s. We push back on…

Listen to the episode
30 minS3E18

The Debate: Is the CIA Triad Truly Dead?

We’re debating an online article claiming that the CIA Triad (Confidentiality, Integrity, Availability) is a relic and needs to be updated for 21st-century threats. The discussion includes whether new properties like aut…

Listen to the episode
28 minS3E14

Making Privacy Less Cringey

Dr. Kim Wuyts and Avi Douglen join us in today's episode. Both guests are fresh from their training sessions at Black Hat and DEF CON in Las Vegas and share a quick overview of their experiences. We discuss a newly devel…

Listen to the episode
49 minS3E13

Decoding Mastro: AI Threat Modeling

We’re discussing the article, “Agentic AI Threat Modeling Framework: Maestro published back in February of this year on the Cloud Security Alliance blog. We discuss the various layers, patterns, and threats outlined in t…

Listen to the episode
46 minS3E7

MCP…Something Could Go Wrong

We’re discussing the complexities of the Model Context Protocol (MCP) and its application in AI systems. Join us for an in-depth discussion about MCP, agent-to-agent communication, and potential security vulnerabilities.…

Listen to the episode
45 minS3E3

The Department of No

We’re discussing the complexities of saying 'yes' or 'no' in the context of security decisions in today’s episode and the enduring challenge of integrating security into software development. The conversation swerves int…

Listen to the episode
47 minS3E2

The Cyber Trust Mark Debate

The Cyber Trust Mark, a new FCC program aimed at assuring the security of IoT devices is the topic of discussion today. We discuss various aspects of the Cyber Trust Mark, the history of similar initiatives like UL certi…

Listen to the episode
45 minS2E31

Why 100X Isn't the Answer

A good discussion today covering two different articles, the first covers CISA's list of product security "bad practices", questioning whether it provides real value or is just content marketing. Then the discussion move…

Listen to the episode
28 minS2E30

We'll Be Here Until We Become Obsolete

This week we explore the multifaceted concept of obsolescence in technology, detailing its planned, unplanned, and forced forms. We delve into the security implications of outdated or unsupported devices and software, wi…

Listen to the episode
30 minS2E29

Everything is Boring

Is everything boring? Chris, Izar and Matt discuss why nothing seems interesting enough lately. Is the excitement of vulnerabilities and ransomware waning? The guys touch on Governance, Risk, and Compliance (GRC) in corp…

Listen to the episode
44 minS2E28

Experts Want to Excel

What constitutes an expert in the field of threat modeling? Today Matt, Chris and Izar explore cultural references, the intricacies of threat modeling practices, and the criteria that define an expert. The discussion tou…

Listen to the episode
29 minS2E26

Philosophizing Cloud Security

In this episode of the Security Table, our hosts discuss the concept of the 'Shared Fate Model' in cloud security. The conversation explores how this model builds on the shared responsibility model and the implications f…

Listen to the episode
32 min

Innovations in Threat Modeling?

In this episode of The Security Table, hosts Chris Romeo, Izar Tarandach, and Matt Coles dive into the evolving concept of threat models, stepping beyond traditional boundaries. They explore 'Rethinking Threat Models for…

Listen to the episode
40 minS2E24

The Illusion of Secure Software

In this episode of The Security Table Podcast, hosts ChriS, Izar and Matt dive into the recent statement by CISA's Jen Easterly on the cybersecurity industry's software quality problem. They discuss the implications of h…

Listen to the episode
46 minS2E22

Computing Has Trust Issues

Join us in this episode of The Security Table as we dive into the world of cybersecurity, starting with a nostalgic discussion about our favorite security-themed movies like 'Sneakers,' 'War Games,' and 'The Matrix.' We …

Listen to the episode
24 minS2E21

The Stages of Grief in Incident Response

Join Chris, Izar, and Matt as they sit around the Security Table to dissect and discuss the different stages of dealing with security incidents. In this episode, they explore the developer's stages of grief during an inc…

Listen to the episode
28 minS2E20

To SSH or Not?

In this episode of 'The Security Table,' we are back from our midsummer break to discuss OpenSSH regression vulnerability. We dig into the nuances of this race condition leading to remote code execution, explore the chai…

Listen to the episode
46 minS2E14

12 Factors of Threat Modeling

Chris, Matt and Izar share their thoughts on an article published by Carnegie Mellon University’s Software Engineering Institute. The list from the article covers various threat modeling methodologies such as STRIDE, PAS…

Listen to the episode
40 minS2E12Transcript

Nobody's Going To Mess with Our STRIDE

Matt, Izar, and Chris take issue with a controversial blog post that criticizes STRIDE as being outdated, time-consuming, and does not help the right people do threat modeling. The post goes on to recommend that LLMs sho…

Listen to the episode
38 minS2E11Transcript

SQLi All Over Again?

Chris, Matt, and Izar discuss a recent Secure by Design Alert from CISA on eliminating SQL injection (SQLi) vulnerabilities. The trio critiques the alert's lack of actionable guidance for software manufacturers, and they…

Listen to the episode
41 minS2E7Transcript

Selling Fear, Uncertainty, and Doubt

Matt, Izar, and Chris discuss the impact of fear, uncertainty, and doubt (FUD) within cybersecurity. FUD is a double-edged sword - while it may drive awareness among consumers, it also leads to decision paralysis or misg…

Listen to the episode
42 minS2E2Transcript

Threat Modeling Capabilities

This week around the Security Table Matt, Izar and Chris discuss the recently-published Threat Modeling Capabilities document. They explore how capabilities serve as measurable goals that organizations either possess or …

Listen to the episode
41 minS2E1Transcript

Open Source Puppies and Beer

Chris, Izar, and Matt address the complexities of open-source component usage, vulnerability patches, civic responsibility, and licensing issues in this Security Table roundtable. Sparked by a LinkedIn post from Bob Lord…

Listen to the episode
48 minS1E39Transcript

AppSec Resolutions

Join us for the final episode of The Security Table for 2023. Chris, Izar, and Matt answer fan mail, make fun predictions for the upcoming year, discuss their resolutions for improving cybersecurity, and make a call to a…

Listen to the episode
46 minS1E37Transcript

Looking Back, Looking Forward

Join Izar, Matt, and Chris in a broad discussion covering the dynamics of the security community, the evolving role of technology, and the profound impact of social media on our lives. As the trio considers what they are…

Listen to the episode
46 minS1E35Transcript

An SBOM Lifecycle

Aditi Sharma joins Matt, Izar, and Chris around the Security Table to discuss Software Bill of Materials (SBOMs). The team discusses potential advantages as well as challenges of SBOMs in different contexts such as SaaS …

Listen to the episode
37 minS1E34Transcript

An SBOM Fable

Join Chris, Matt, and Izar for a lively conversation about an article that offers 20 points of "essential details" to look for in a Software Bill of Materials (SBOM). They dissect and debate various points raised in the …

Listen to the episode
56 minS1E30Transcript

The Hamster Wheel of Scan and Fix

Matt and Izar join in a debate with Chris Romeo as he challenges the paradigm of "scan and fix" in application security. Chris references a LinkedIn post he made, which sparked significant reactions, emphasizing the repe…

Listen to the episode
32 minS1E29Transcript

Threat Modeling Conference

The Security Table gathers to discuss the upcoming ThreatModCon 2023 (https://www.threatmodelingconnect.com), the inaugural and only conference dedicated entirely to threat modeling.ThreatModCon 2023 Sunday, October 29, …

Listen to the episode
37 minS1E28Transcript

AppSec vs. ProdSec

Chris Romeo, Matt Coles, and Izar Tarandach attempt to demystify the concepts of Application Security (AppSec) and Product Security (ProdSec). They find that even defining and differentiating both concepts is challenging…

Listen to the episode
35 minS1E27Transcript

Imposter Syndrome

Imposter Syndrome is when a person feels inadequate despite their accomplishments. Not unique to the field of cybersecurity or even software development, imposter syndrome can affect any professional as they advance and …

Listen to the episode
34 minS1E26Transcript

The Return on Investment of Threat Modeling

The Security Table team dialogues about the importance of data and metrics in understanding and communicating risk. After Matt defines ROI, Izar emphasizes that while data is crucial, it doesn't always come in numerical …

Listen to the episode
39 minTranscript

Secure by Design

"Secure by Design" has garnered attention with the release of a document by CISA. What does it mean? How does it fit with Threat Modeling? And do you know if Secure by Design will answer our need for secure software?"Sec…

Listen to the episode
49 minTranscript

Why Do Engineers Hate Security?

There is a relationship between security professionals and engineers. Explore the possibility of engineers disliking security personnel and how security professionals can improve their relationship with engineers.Securit…

Listen to the episode
45 minS1E21Transcript

Security Posture is a Thing

What is security posture? Izar was at a conference in Amsterdam, where he was asked to define security posture and how to measure it. Is security posture qualitative or quantitative, and can it be compared across teams, …

Listen to the episode
23 minS1E18Transcript

We Don't Know What We Don't Know

Certificate pinning is a security measure used in computer networking and something Chris candidly admits to his lack of understanding.Matt and Izar explain certificate pinning, a client-side operation that adds an extra…

Listen to the episode
43 minTranscript

Security Guardrails and Paved Roads

Guard rails and paved roads -- how do they fit together in application security? Guardrails are security tools in the pipeline that help ensure the software doesn't drift too far from established standards. These guardra…

Listen to the episode
41 minTranscript

Capture the Flag or NOT?

There is an overemphasis on Capture The Flag in the security world. Instead, the industry should focus more on the 'builder' perspective to develop robust systems rather than the 'breaker' mindset typically associated wi…

Listen to the episode
38 minTranscript

Simple Product Security Requirements

Matt, Izar, and Chris discuss the United Kingdom's new minimum security standards for all Internet-connected consumer products. They highlight three key aspects of these new standards:Banning of Universal Default and Eas…

Listen to the episode
49 min

Should security give up on developers?

The gang discusses whether security should or could give up on developers. We explore what the development world would look like if security did all the security, and the developer's responsibility ended when they commit…

Listen to the episode