The Security Repo

The Security Repo

By Mackenzie Jackson & Dwayne McDanielTechnology
Download on the App Store

The Security Repo episodes

  • Rotating Secrets At Scale, Automatically, and With High Availability - Kenton McDonough

    In this episode of The Security Repo Podcast, we take a look at how to do secrets rotation in a highly available systems reliably.


    We are joined by Kenton McDonough. Kent got his MS in Computer Science from Virginia Tech in 2021 with a focus on systems and networking. He currently does security automation for Viasat Inc, a global Satellite internet service provider, with an emphasis on credential management and RBAC systems.


    We walk through the tech stack that Kent works with, which includes a little of everything. We revisit his talk topic at BSides as Vegas 2024 with a discussion of 'blue/green' secrets rotation. By the end, we uncover some best practices to keep in mind when architecting a scalable, highly available application with regard to secrets management.


    Links shared in the episode:

    kent07[at]bt.edu


    "Zero downtime credential rotation" at BSides Las Vegas 2024

    https://www.youtube.com/live/b22uT4pYpk8?feature=shared&t=17092

    36 min
  • Countering Shadow IT Through Nudging Intervention - Garret Gross

    In this episode of The Security Repo Podcast, let's talk about the largest IT threat outside of IT, and maybe out of the line of site of Security teams, Shadow IT.


    We are joined by Garrett Gross, a seasoned cybersecurity professional with over twenty years of experience. Garrett currently holds the position of Head of Product Success at Nudge Security. His primary focus is on implementing innovative strategies to address SaaS sprawl and mitigate the risks associated with shadow IT. With a strong background in security operations, incident response, and threat research, Garrett's expertise and dedication to the field are evident. He actively contributes to the cybersecurity community by collaborating with organizations such as OWASP and ISSA, aiming to elevate industry standards and best practices.


    We start with a look at how bad the issue of shadow IT really is today and what it is potentially costing companies. From there, we talk about how blocking people from working is a less-than-optimal way to implement security since people will often bypass those restrictions. By the end, we discuss the idea of nudging people, using guardrails, and some clever automation, to do the right thing and improve security for us all.


    Links from this episode:

    https://www.linkedin.com/in/garretthgross/


    https://nudgesecurity.com


    https://www.nudgesecurity.com/our-approach


    29 min
  • What Does The Future Hold For The Security Repo Podcast? Some Changes & Introducing Our New Co-Host

    We have had so much fun making The Security Repo Podcast, and we hope you have learned as much as we have along the way.

    The tides of change have finally reached our shore, and we are sad to announce the departure of Mackenzie Jackson, our original founder, producer, and co-host of the podcast, from our regular episodes. We wish him much success in his new adventures.
    We are also announcing a brand new chapter in the history of the program. Dwayne McDaniel will now be joined weekly by
    Kayssar Daher, the head of security at GitGuardian.
    As an active security practitioner, Kayssar asks different kinds of questions that we know you will most find insightful and engaging.
    We have some amazing things planned for the future of the show. Thank you for listening and being part of the Security Repo Podcast community.

    1 min
  • Data Loss Prevention and Stopping Breaches Before They Start

    In this episode of The Security Repo Podcast, we explore all things Data Loss Prevention (DLP).


    We are joined by Daniel Jay, Senior Director of Product Management at GTB Technologies.


    We start with a quick high-level of the topic of Data Loss Prevention and how we met at the RSA Conference 2024. By the end, we turn the conversation to AI and balance the risks of using LLMs with faster output.


    Links mentioned in this episode:

    https://www.linkedin.com/in/daniel-jay-a683b635/


    GTTB.com

    37 min
  • Security Automation And Leveraging AI To Deal With Security At Scale - Huxley Barbee

    In this episode of The Security Repo Podcast, we look at security automation and how we can engineer our way to better security overall.


    We are joined, once again by Huxley Barbee, who has been a fixture of the security community for over 20 years. Professionally, he was a security consultant working with customers in finance, insurance, manufacturing, and higher education. Currently, he leads the security engineering group at a fintech company. Beyond the day job, he is also active in the security and hacker community. He started attending DEF CON in the late 90s, has spoken at many conferences throughout the US, and is the lead organizer for BSidesNYC. He lives in New York. You should connect with him on social media, buy him a drink, or both.


    We start with a great discussion of what to automate and what not to automate when thinking about security. From there, we explore the role of AI in the security tool belt and how we can best leverage it to improve our posture. By the end, we get some updates about BSides NYC and elsewhere.


    Links from this episode:

    Previous Appearance:

    https://youtu.be/vDNPsAPnSDc


    Socials:

    https://www.linkedin.com/in/jhbarbee/



    BSides NYC:

    https://bsidesnyc.org/


    40 min
  • Developer Awareness Training and AI Assisted Tooling for Improving Security - Chris Lindsey

    In this episode of The Security Repo Podcast, we take a look at the role developer training and awareness have in improving security.

    We are joined by Chris Lindsey, Application Security Evangelist at Mend.io. He is a seasoned speaker who has appeared at conferences, webinars, and private events.  Chris draws on expertise from more than 15 years of direct security experience leading and building security programs and over 35 years of experience leading teams in programming software, solutions, and security architecture.
    We start with how training and awareness are the start of the process but not all that is needed. From there, we discuss developer tooling vs security tooling and what gaps exist. By the end, we get into AI and how to think about a future with auto-remediation.
    Links from this episode:
    https://www.linkedin.com/in/chris-lindsey-39b3915/

    37 min
  • Improving Your Security by Leveraging AI: The Arcanum Cyber Security Bot - Jason Haddix

    In this episode of The Security Repo Podcast, we dive deep into how AI is helping the Red, Blue, and Purple teams and how we can leverage ChatGPT to stay ahead of attackers.

    We are joined once again by Jason Haddix Founder, CEO and Head of Training at Arcanum Information Security. He is also the creator of the Arcanum Cyber Security Bot:
    https://chatgpt.com/g/g-HTsfg2w2z-arcanum-cyber-security-bot
    Listen in to find out what you have been missing about AI.
    https://www.linkedin.com/in/jhaddix/

    47 min
  • DeepCover & DART Academy: Fighting Scammers Through Educating Seniors

    In this episode of The Security Repo Podcast, we dive deep into a rather troubling phenomenon: scammers who target senior citizens.

    We are joined by Anita Nikolich, a speaker and a university-based cybersecurity researcher specializing in network security and cryptocurrency analytics. She joins us as the founder and co-principal Investigator of DART, a collective of researchers, security experts, game designers, and community-based organizations who have come together to combine their expertise and passion to develop the Deception Awareness and Resilience Training (DART) platform.
    We discuss real-world examples, the realities of scammers and cybercrime, and why they target the people they attack. We also get into how the DART collective is working to ensure we raise awareness in a way that affects the most people without being too heavy-handed. Anita shares some free resources to help protect the people you love and tells us how we can get involved to help.

    Learn more at https://dartcollective.net/

    https://dartcollective.net/deepcover/

    32 min
  • Mining for Vulnerabilities: Hidden Dangers of Open Buckets

    In this episode of The Security Repo Podcast, we dive deep into a pervasive cybersecurity issue: open data buckets. Joined by Glen Helton, Director of Information Security at a major multinational and founder of the Sky Witness Project, we explore how improperly secured cloud storage—commonly known as "open buckets"—can expose sensitive data to the world. Glen shares insights on the scale of the problem, revealing that billions of files are currently accessible to anyone with the right tools. We discuss real-world examples, the challenges of responsible disclosure, and practical advice for organizations to secure their data. Whether you're a seasoned security professional or a curious listener, this episode will make you rethink how you handle and protect data in the cloud.


    43 min
  • The Frontline of Cybersecurity: Defending Against Supply Chain Intrusions - Jossef Harush Kadouri

    In this episode of The Security Repo, we sit down with Jossef Harush Kadouri, a pioneer in software supply chain security and founder of Dustico, now part of Checkmarx. Jossef shares his journey from startup to acquisition, detailing the ever-evolving landscape of supply chain attacks. We explore how malicious actors are exploiting open-source ecosystems, the challenges of maintaining secure software, and practical steps developers and organizations can take to protect themselves. Whether you're a seasoned security professional or new to the field, this episode offers valuable insights into safeguarding your software's supply chain.


    Show Notes: Linkedin - https://linkedin.com/in/jossef

    45 min

About The Security Repo

From the publisher's feed

The security repo is a podcast that focuses on real world security issues we are all facing today. We will take deep dives into news events and have exclusive interviews with security leaders on the…