The Security Repo

The Security Repo

By Mackenzie Jackson & Dwayne McDanielTechnology
Download on the App Store

The Security Repo episodes

  • Solving Secret Zero: The Future of Machine Identities & SPIFFE with Mattias Gees

    Today we dive into the challenges of securing modern IT infrastructures, focusing on "Secret Zero" and its implications for authentication practices. Our guest, Mattias Gees of Venify, discusses the SPIFFE framework and its role in transitioning from traditional security methods to dynamic workload identities. We explore practical strategies for implementing SPIFFE to enhance digital security across cloud environments. Join us for a comprehensive look at evolving cybersecurity measures and the future of identity management.


    Show Notes:

    Mattias Social Links

    Linkedin - https://www.linkedin.com/in/mattiasgees/

    Twitter (X) - https://twitter.com/MattiasGees


    You also might like our episode with Uri Sarid - https://www.youtube.com/watch?v=reKbGE1c5Ig

    Introduction: 0:00
    What is secret zero: 1:39
    Why is machine identity so hard: 4:15
    The machine identifies vs user identities: 11:06
    What is SPIFFE? (Secure Production Identity Framework for Everyone): 14:20
    SPIFFE fundamentals/architecture: 17:15
    GitGuardian: 20:08
    How to implement SPIFFE: 21:00
    Why we aren't leveraging identify best practices: 26:40
    Will SPIFFE be the future? 27:27
    Secrets Managers vs SPIFFEE: 31:05
    Venify and identify management: 32:38
    Best and worst security advice: 38:28
    Wrap up: 41:00

    43 min
  • Building secure platforms with Kubernetes: Bridging the DevOps-Security Divide with John Dietz

    This week, we dive deep into the world of Kubernetes with John Dietz, co-founder of Kubefirst and a seasoned IT professional with over two decades of experience. John shares his extensive insights into the transformative power of Kubernetes and infrastructure as code (IaC) in modern cloud environments. Reflecting on his personal journey from skepticism about containerization to embracing Kubernetes. John discusses the critical role of governance and security in successfully deploying and managing cloud-native technologies. We also explore challenges and strategies for integrating security practices into DevOps, ensuring robust governance, and leveraging IaC for efficient and secure infrastructure management. Whether you're an IT veteran or new to the field, join us as we unpack the complexities of Kubernetes, security through governance, and the future of cloud-native platforms.

    Show Notes:
    Kubefirst: https://kubefirst.io/
    Johns articles on The News Stack https://thenewstack.io/author/john-dietz/
    John Dietz sociales
    X (Twitter): https://twitter.com/vitamindietz
    Linkedin: https://www.linkedin.com/in/jd-k8s/
    Introduction: 0:00
    Kubernetes skeptic to advocate: 1:09
    Governance in Kubernetes & IaC: 8:30
    Who owns security with IaC and K8: 24:36
    Common K8 mistakes: 32:16
    Why care about Kubernetes: 38:23
    Best and worst: 47:15
    Links and show notes: 54:22

    57 min
  • Authorization vs. Authentication: Decoding the Layers of Security with Emre Baran

    In this episode we dive deep into the world of authorization with Emre Baran, CEO and co-founder of Cerbos. As a seasoned entrepreneur and software expert, Emre brings over 20 years of experience to the table, discussing the subtle yet significant distinctions between authorization and authentication, and why these concepts are pivotal in today's cloud-based and development environments.

    In this discussion, Emre explains why many organizations still grapple with these issues in 2024, highlighting common pitfalls in security practices and offering insights into the sophisticated challenges of implementing fine-grained access control. He also shares his views on the evolving landscape of regulatory standards and introduces us to "Cerbos," his solution designed to streamline and secure authorization processes efficiently.
    Show Notes
    Learn about Corbos: https://www.cerbos.dev/
    Cerbos GitHub: https://github.com/cerbos/cerbos
    Follow Emre Baran
    X / Twitter - https://twitter.com/emre
    Linkedin: https://www.linkedin.com/in/emrebaran/
    Time Stamps
    Intro: 0:00
    Why are we still struggling with authz: 1:12
    Difference Authentication &Authorization: 6:16
    What is Cerbos?: 9:35
    The auth trap: 11:58
    Is it scalable: 13:20: Scaling Auth
    Who owns auth: 16:31
    Regulation and compliance: 20:32
    GitGuardian: 22:12
    What is ZSP (Zero standing Privileges): 23:00
    Best and Worst: 28:00
    Links and followup: 32:00

    35 min
  • Unpacking ASPM: Trends, Truths, and the Future of Security Tools

    In this engaging episode of "The Security Repo," host Dwayne McDaniel and esteemed guest Rachel Stephens, delve into the rapidly evolving world of security tooling, with a special focus on the buzz around Application Security Posture Management (ASPM). They tackle the complexities and confusions surrounding the burgeoning category of security solutions, offering listeners a clear-eyed view of what ASPM means for developers, security professionals, and the tech industry at large. Through a candid and enlightening conversation, they explore the history and potential future of security practices, the push towards simplification and consolidation of tools, and the real challenges of effectively managing security risks in today's dynamic digital environments. Join us for a thought-provoking discussion that demystifies ASPM and provides valuable insights into the direction of security tooling and practices.

    Show Notes:
    Learn more about ASPM - https://blog.gitguardian.com/good-application-security-posture-requires-good-data/Learn more about RedMonk https://redmonk.com/ Listen on Spotify: https://open.spotify.com/show/2emgX3m3dJSzlmAG3axBGa Listen on Apple Podcasts: https://podcasts.apple.com/us/podcast/the-security-repo/id1634401017

    29 min
  • Decoding Security: An Analyst's Perspective on Trends and Tools

    In this episode of The Security Repo podcast, we dive deep into the evolving landscape of security within software development with our guest, Rachel Stephens, a senior analyst at RedMonk. Rachel sheds light on the broader implications of the "shift left" movement, emphasizing the integration of security practices throughout the entire software development lifecycle rather than viewing it as an isolated final step. This conversation explores how developers and security professionals can work together more effectively, the role of tools in aiding or hindering this collaboration, and the importance of understanding security from a holistic viewpoint. With insights into the latest trends, challenges, and solutions in securing our software development processes, this episode is a must-listen for anyone interested in the intersection of development, security, and industry analysis.

    Show Notes
    https://redmonk.com/
    Introduction: 0:00
    Analyst Role / RedMonk: 2:18
    Shift Lift: 4:27
    Dev and Sec in Conflict: 6:20
    Shift Left Where?: 9:35
    What about micro applications?: 11:08
    What is Shift Right?: 15:15
    GitGuardian:20:22
    How do you Shift Left?: 21:20
    Measure what matters: 25:20
    Best and Worst Advice: 27:30
    RedMonk: 29:39

    32 min
  • Building Conferences and Communities in Cybersecurity with Huxley Barbee

    This week, join us as we sit down with Huxley Barbee, the lead organizer of B-Sides New York City and a security evangelist at RunZero. With over two decades of experience as a software engineer and security consultant, Huxley shares his profound insights and journey through the evolving landscape of cybersecurity.

    From his early days attending DefCon in 1999 to spearheading B-Sides conferences that champion technical excellence, community engagement, and accessibility, Huxley's story is one of passion, dedication, and innovation. He offers a fresh perspective on the recent shift of DefCon to the Las Vegas Convention Center and recounts memorable anecdotes that highlight the unique culture of hacker communities.
    Moreover, Huxley sheds light on the critical topic of exposure management, moving beyond traditional vulnerability scanning to encompass advanced techniques and strategies for securing modern networks. His advice on asset inventory and the importance of understanding your network's vulnerabilities is indispensable for both seasoned professionals and newcomers to the field.
    So, whether you're a cybersecurity veteran, an aspiring hacker, or simply curious about the digital world's inner workings, this episode is packed with valuable insights, fascinating stories, and practical advice. Don't miss out on this deep dive into the challenges and triumphs of securing our digital future with Huxley Barbee.

    43 min
  • The Evolution of DevSecOps: Strategies for Integrating Security into DevOps with Gregory Zagraba

    This episode of The Security Repo Podcast features an insightful discussion with Gregory Zagraba on the challenges and strategies of integrating security practices within the DevOps landscape. Covering the evolution of DevOps, the emergence of DevSecOps, and the importance of a culture shift in large organizations, the conversation delves into practical advice on automation, the significance of backups, and fostering a security-conscious mindset. Through real-world examples and expert insights, the episode sheds light on creating robust, secure systems in the fast-paced world of software development and data protection.


    Show Notes:

    Git Protect https://gitprotect.io/

    Git Protect Blog https://gitprotect.io/blog/

    37 min
  • Hacking the Hackers: The Art of Compromising C2 Servers with Vangelis Stykas

    In this episode of the Security Repo podcast, listeners will dive into the intriguing world of hacking the hackers with Vangelis Stykas. Stykas, a notable figure in cybersecurity, shares his experiences and methodologies for compromising C2 servers—central nodes used by hackers to control malware-infected computers. He reveals how simple web application vulnerabilities can lead to significant breaches in the security of these servers. The discussion also covers the ethical and legal nuances of Stykas' work, including the challenges and risks involved in targeting these digital underworld operatives. Additionally, Stykas touches on his professional journey, including his role as the CTO of Atropos, a company specializing in web application and API security. This episode promises to uncover key discoveries about the shadowy aspects of cybersecurity and the ongoing battle between hackers and those who hack them.

    Show Notes:
    Atropos - https://atropos.ai/
    Stalking the Stakers Blog Post - https://atropos.ai/stalking-the-stalkers/
    DefCon Talk - https://www.youtube.com/watch?v=fMxSRFYXMV0
    Social Media
    X.com - https://twitter.com/evstykas
    Linkedin - https://www.linkedin.com/in/vangelis-stykas/

    35 min
  • The Evolution of Offensive Security with Erik Cabetas
    In this episode, we delve into the mind of Erik Cabetas, a renowned figure in offensive security and Defcon CTF winner. Erik shares his unique journey from hacking to offensive security, detailing the critical turning points that shaped his career. Together with Mackenzie and Dwayne, Eric discusses the evolution of security practices, the importance of ethical hacking in today's digital world, and offers some advice for aspiring hackers. Join us to explore the fascinating intersection of technology, ethics, and security through Erik's expert lens.
    42 min
  • From Bank Heists to Security Insights: The Jayson E. Street Story

    In this episode of The Security Repo, Jayson E. Street delves into his unconventional journey into cybersecurity, emphasizing the essence of hacking as a manifestation of curiosity rather than mere technical skill. He shares anecdotes from his extensive experience in ethical hacking, including bank heists and corporate security breaches, to underscore the importance of creative problem-solving in security. Street also critiques the narrow perceptions of hacking, advocates for diversity in the security field, and offers unconventional advice for enhancing corporate security awareness. His stories, ranging from audacious exploits to thoughtful reflections on personal and professional growth, provide a compelling narrative on the importance of thinking outside the box in cybersecurity.


    More links on Jayson

    Hacker Answers Penetration Test Questions From Twitter  https://www.youtube.com/watch?v=6i-84wqc_qU


    Penetration tester Jayson E. Street helps banks by hacking them https://www.youtube.com/watch?v=02Vf3NjTPsI


    Social Links

    X - https://twitter.com/jaysonstreet

    Linkedin - https://www.linkedin.com/in/jstreet/


    56 min

About The Security Repo

From the publisher's feed

The security repo is a podcast that focuses on real world security issues we are all facing today. We will take deep dives into news events and have exclusive interviews with security leaders on the…