
Sign up to save your podcasts
Or


Undergraduate students are the future of cyber security! Camille’s talking with undergraduate students Ifesi Dimma Onubogu, Isabella Siu, and Sarah Schaber, Princeton-Intel 2021 Alumni and participants in the summer Research Experience for Undergraduates Program. These students worked in areas such as network security and software, and they are looking to future careers like biomedical imaging and electrical engineering. Hear these students’ insights on the program, their thoughts on cybersecurity across disciplines, and advice they have for high school students!
The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.
Have you been hearing about the new Infrastructure Bill that passed Congress? Are you curious about what moves the government is making to address the semiconductor shortage? Camille and Tom are getting into the Infrastructure Bill recently signed into law with Jason Oxman, President and CEO, Information Technology Industry Council (ITI). Their conversation covers the implications of the new bill in terms of cybersecurity, who the bill is serving and why, and how the government is making sure the networks deployed in this bill are secure. With over $40 billion planned investment towards improving broadband and equity across the country, the Infrastructure Bill will benefit the tech industry, underserved communities, and even national security concerns. They also discuss the related CHIPS Act and how it both provides incentive to build more semiconductor plants in the U.S. and to provide R&D funding to support the Department of Defense’s semiconductor needs. Hear their thoughts on all this and more!
The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.
The semiconductor chip shortage is a major global problem that urgently needs solving, and the CHIPS Act is an attempt at this! Camille and Tom are talking with Ollie Whitehouse, Group CTO for NCC Group, about the intent behind and the possible implications of the CHIPS Act and how it could impact the shortage of semiconductors. In this episode, they answer the question of what is the CHIPS Act, give predictions to how the act will impact supply and demand for CPUs, discuss the economic incentives proposed by the act, and consider the geopolitical implications of passing the CHIPS Act. Through tax breaks on materials for CPU manufacturing and improving national infrastructure to meet the global demand for semiconductors, the CHIPS Act deserves the tech industry’s full attention.
The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.
Why should data privacy matter to you? Find out why as Camille discusses data anonymization with Kristin Ulrich, Senior Solutions Specialist at SAP for HANA architecture. You’ll learn what data anonymization means, the difference between pseudonymization and anonymization, what questions you should ask before sharing your data with another company, as well as how different legislations across international lines impact data anonymization and data sharing. While data anonymization certainly increases security, you can’t always guarantee complete anonymity. Listen in to learn all this and more!
The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.
In the spirit of Thanksgiving, Tom and Camille are highlighting the work their guests are doing that they are most thankful for — including ethical considerations of artificial intelligence, why the race for AI is so important for humankind, cyber security and digital manufacturing technologies, and how academia and the cyber security industry can work together to understand future trends.
The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.
The kinds of personal information we put out there may seem safe today, but what about five, ten, twenty or thirty years down the line? Tom and Camille are joined by guest Alex Ionescu, a founder of Windsider Seminars & Solutions Inc. and the previous VP of Endpoint Engineering at CrowdStrike, to talk about how privacy concerns change and evolve over time and how what we deem acceptable now could quickly become outdated. In their conversation, the three dive into examples of how cybersecurity has already changed over time, existing major vulnerabilities, the improvement of security through virtualization in cloud environments, the inclusion of privacy and ethics in security, how the data we share today might be cause for concern in the future, and how artificial intelligence is currently applied in cybersecurity. Listen to learn about all this and more!
The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.
Supply chain security has taken on new importance, especially in a post-COVID world. From healthcare to finance, the cybersecurity threats posed to people’s lives are very real.
In this episode, Tom and Camille are joined by Rick Martinez, Sr. Distinguished Engineer, Office of CTO at Dell Technologies, and John Boyle, Cybersecurity Solutions & Supply Chain Security Product Management at Dell Technologies, to break down what companies are doing to mitigate supply chain risks, what best practices entail, and how Dell and Intel have partnered up on the road to boosted supply chain security. Listen in to also learn more about why a transparent supply chain is so important, how supply chain security is optimized, what Secure Verification Component is, and how to keep your system up-to-date to prevent cyber attacks!
The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.
There are infinite vulnerabilities out there that make us susceptible to instances of cyberattack, and as of this year, we’re on track to have identified 20,000 of them. While there’s a whole risk mitigation ecosystem in place, CVE (formerly known as the Common Vulnerabilities and Exposures Program) has played a huge role in establishing a dictionary-esque database with IDs and definitions for each known vulnerability.
On this episode of What That Means, Camille is joined by returning guest Katie Trimble-Noble (Intel - Director, PSIRT & Bug Bounty) to describe the critical nature of CVE in greater detail.
They cover:
- The origins and evolution of CVE (formerly known as the Common Vulnerabilities and Exposures Program)
- Why CVE matters, and what it does and doesn’t do
- How NVD (the National Vulnerability Database) and CVSS (the Common Vulnerability Scoring System) differ from and apply to CVE
- How risk severity is actually scored
- Who and what CVE Naming Authorities (CNA) are, why they’re important, and the process of becoming one
... and more. Really interesting stuff, so tune in!
*And if you like what you hear, catch an earlier conversation Camille had with Katie in WTM Episode 26: Bug Bounty and Crowdsourced Security; Alexander (RoRo) Romero joins them for a great discussion, and you don’t want to miss it: https://bit.ly/3mv9yVr
The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.
Here are some key takeaways:
- CVE makes up an important part of the mitigation ecosystem, and its main mission is to catalog and identify known vulnerabilities; we can think of it as a sort of dictionary in that it tells you the definitions of vulnerabilities.
- Although CVE does not expand on the severity of vulnerabilities, it does list which ones are in your network; NVD and CVSS help to paint a clearer picture of risk level.
- While ideally everything would be patched, there has to be a hierarchy of priority; that’s what makes CVE so crucial, because it enables system admins to differentiate and decide what to patch first based on risk analysis.
- CVE also helps to identify vulnerabilities in a universally recognizable way.
- Some vulnerabilities can intersect to form an attack chain, which is a common phenomenon that’s often referred to as a “daisy chain.”
- CNAs are vendors, government agencies and research organizations that have a deep knowledge of vulnerabilities because they own a product or have done extensive research on it; these CNAs can publish directly to the CVE Master List.
- There are currently 161 CNAs around the world, one of which is Intel.
- In 2021, 20,000 vulnerabilities are on track to be identified to date.
- There is no cookie cutter response to risk, because the things that get fixed and in what order are dependent upon implementation.
- It’s important for consumers to put pressure on manufacturers to be transparent about vulnerabilities, because in the end, it strengthens the entire ecosystem.
Some interesting quotes from today’s episode:
“Everyone uses CVE. And the reason that you use CVE is when you’re doing your risk analysis to patch management, your system admins need to know what are we vulnerable to so that they can make that risk-based decision of what gets patched first.”
“Really risk is in the eye of the beholder. I can’t say what’s more important for you to patch because you have certain mitigating compensating controls on your end, the implementation end of the user. The implementation really dictates how things get fixed in what order they get fixed.”
“It’s not the mission of the CVE program to really get into some of those kind of theoretical details. It’s more sticking to the mission of the CVE program to identify and catalog those vulnerabilities so that you can enable the user end with the best risk-based program that can be available. It’s all about transparency and truth.”
“There was a lot of back and forth about what exactly is an exposure. So ultimately it was decided that in the best interest of the community, it was better to focus on CVEs in the form of vulnerability identification.”
“The CVE Master List is really just a reflection of the known vulnerabilities; there are an infinite number of vulnerabilities out there.”
“I mean, my Fitbit could have vulnerabilities and that’s not something you saw 10 years ago.”
“I think that we’re going to continue to see a rapid increase in the quantity of vulnerabilities that have been identified. And that’s why it’s so important to have that community based approach, those CNAs, those people who are sitting there cataloging vulnerabilities in their systems.”
“As the consumer, you want to put pressure on your product manufacturer to build a secure product.”
“If you can attack that insulin pump and you can cause an insulin pump to dump all the insulin in one minute, you can kill a person. That is a frightening vulnerability and those kinds of real-world sort of impacts they’re not theoretical anymore. They’re very real today.”
“When you disclose vulnerabilities, you make the overall ecosystem stronger and better and smarter.”
Why would a tech employee turn to e-crime? It often has to do with feelings of discontentment within their jobs or their lives. So, how can companies best mitigate insider threats? Tom and Camille are joined today by guest Rick Jordan, CEO and Founder of ReachOut Technology, to discuss the topics of insider threats, ethical hacking, and the human element of cybersecurity. Ever wonder who gets involved with e-crime and why? Or how e-crime groups target disgruntled tech employees to create insider threats? They have the answers! The discussion also touches on why this year in particular has been so stressful for security and engineers and how automation and AI factor into risk management. You won’t want to miss this one!
The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.
As the technological landscape moves ever onward and upward, it can be difficult for legislation to keep up. How well is security policy maintaining pace, especially when aspects of security are viewed differently around the globe? Camille is joined by Dr. Amit Elazari Bar On, Director, Global Cybersecurity Policy at Intel, and Dr. Anahit Tarkhanyan, IOT Security Architect and Principal Engineer at Intel, to discuss all things security policy. In their discussion, they cover whether or not the concept of security is consistent around the world and its effects on policy making, the roles of the National Institute of Standards and Technology (NIST), the importance of measurable security policy standards, the six key pillars NIST says your IOT (Internet of Things) device must support, and more!
The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.
From the publisher's feed