Three Buddy Problem

Rob Ragan on the excitement of AI solving security problems


Listen Later

Episode sponsors:

  • Binarly (https://binarly.io)
  • FwHunt (https://fwhunt.run)
  • Rob Ragan, principal architect and security strategist at Bishop Fox, joins the show to share insights on scaling pen testing, the emergence of bug bounty programs, the value of attack surface management, and the role of AI in cybersecurity. We dig into the importance of proactive defense, the challenges of consolidating security tools, and the potential of AI in augmenting human intelligence. The conversation explores the potential of AI models and their impact on various aspects of technology and society and digs into the importance of improving model interaction by allowing more thoughtful and refined responses.

    We also discuss how AI can be a superpower, enabling rapid prototyping and idea generation. The discussion concludes with considerations for safeguarding AI models, including transparency, explainability, and potential regulations.

    Takeaways:

    • Scaling pen testing can be challenging, and maintaining quality becomes difficult as the team grows. Bug bounty programs have been a net positive for businesses, providing valuable insights and incentivizing innovative research.
    • Attack surface management plays a crucial role in identifying vulnerabilities and continuously monitoring an organization's security posture.
    • Social engineering attacks, such as SIM swapping and phishing, require a multi-faceted defense strategy that includes technical controls, policies, and user education.
    • AI has the potential to augment human intelligence and improve efficiency and effectiveness in cybersecurity. Improving model interaction by allowing more thoughtful and refined responses can enhance the user experience. Algorithms can be used to delegate tasks and improve performance, leading to better results in complex tasks.
    • AI is an inflection point in technology, comparable to the internet and the industrial revolution. Can be game-changing to automate time-consuming tasks, freeing up human resources for more strategic work.
    • Autocomplete and code generation tools like Copilot can significantly speed up coding and reduce errors. AI can be a superpower, enabling rapid prototyping, idea generation, and creative tasks.
    • Safeguarding AI models requires transparency, explainability, and consideration of potential biases. Regulations may be necessary to ensure responsible use of AI, but they should not stifle innovation. Global adoption of AI should be encouraged to prevent technological disparities between countries.
    • Links:

      • Rob Ragan's Theoradical.ai
      • Testing LLM Algorithms While AI Tests Us — Testing LLM Algorithms While AI Tests Us
      • LLM Testing Findings Templates — This collection of open-source templates is designed to facilitate the reporting and documentation of vulnerabilities and opportunities for usability improvement in LLM integrations and applications.
      • Rob Ragan on Twitter
      • Rob Ragan on LinkedIn
      • Bishop Fox Labs
      ...more
      View all episodesView all episodes
      Download on the App Store

      Three Buddy ProblemBy Security Conversations

      • 4.9
      • 4.9
      • 4.9
      • 4.9
      • 4.9

      4.9

      54 ratings


      More shows like Three Buddy Problem

      View all
      Security Now (Audio) by TWiT

      Security Now (Audio)

      1,971 Listeners

      Risky Business by Patrick Gray

      Risky Business

      361 Listeners

      SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

      SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

      628 Listeners

      Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

      Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

      367 Listeners

      CyberWire Daily by N2K Networks

      CyberWire Daily

      1,007 Listeners

      Smashing Security by Graham Cluley & Carole Theriault

      Smashing Security

      311 Listeners

      Click Here by Recorded Future News

      Click Here

      406 Listeners

      Darknet Diaries by Jack Rhysider

      Darknet Diaries

      7,864 Listeners

      Cybersecurity Today by Jim Love

      Cybersecurity Today

      169 Listeners

      CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

      CISO Series Podcast

      187 Listeners

      Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

      Defense in Depth

      74 Listeners

      Cyber Security Headlines by CISO Series

      Cyber Security Headlines

      128 Listeners

      Risky Bulletin by risky.biz

      Risky Bulletin

      33 Listeners

      Oxide and Friends by Oxide Computer Company

      Oxide and Friends

      47 Listeners

      The 404 Media Podcast by 404 Media

      The 404 Media Podcast

      312 Listeners