The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Exploring Information Security
Exploring Information Security artwork

[RERELEASE] What is the perception of information security - part 2

Exploring Information Security · 2026-05-05 · 29 min

0:00--:--

Key moments - from our scoring

Substance score

38 / 100

Five dimensions, 20 points each

Insight Density8 / 20
Originality7 / 20
Guest Caliber8 / 20
Specificity & Evidence9 / 20
Conversational Craft6 / 20

Timothy D. Block and Chris Madalina continue examining how information security is perceived both within organizations and in the broader public. The episode tackles two critical perception problems: first, that security remains siloed as an IT function rather than a business-wide mindset, exemplified through a penetration test where developers received three pages of vulnerabilities without context, guidance, or understanding of remediation. Second, they address how media coverage and terminology - particularly the term

Key takeaways

  • →Security should not be siloed as an IT function but embedded as a mindset across all departments including development, business, and operations.
  • →Penetration test results are only valuable when security teams translate findings into actionable guidance and work collaboratively with developers, rather than simply handing over raw vulnerability reports.
  • →Process failures - like default passwords or misconfigured devices - are organizational problems that require fixing root causes and establishing preventative processes, not just tactical patching.
  • →The term 'hacker' carries negative connotations in media coverage and should be avoided when communicating security research to external audiences; 'information security professional' is more appropriate.
  • →Security researchers conducting public demonstrations of vulnerabilities risk damaging the credibility of the entire field and should avoid sensationalized media stunts that endanger people or blur ethical lines.

In this episode

  1. 1Security as a Mindset Across All Departments
  2. 2Penetration Testing Communication Failures and Developer Understanding
  3. 3Process Failures in Security Assessment and Reporting
  4. 4Perception of Security Researchers in Media and Public Discourse
  5. 5The Jeep Hacking Case and Ethical Security Research Practices
  6. 6Standards and Professionalism in Security Research

Mentioned

Timothy D. BlockChris MadalinaBurp SuiteShodanTrusted SecRapid7Fiat ChryslerJeep CherokeeChris RobertsMark StanislavBen 10Wired

Guests

Chris Madalina

Topics in this episode

Penetration testingSecure software development lifecycle (SDLC)Burp SuiteShodanDMCA exemptions for security researchersJeep Cherokee vulnerabilityWired magazineFiat ChryslerTrusted SecChris Roberts airplane hacking case

Questions this episode answers

Why should security be considered a guiding function rather than an IT department responsibility?

Security should be embedded across all business functions because vulnerabilities like phishing emails can compromise entire organizations if one person clicks. Developers need to write secure code from the start of the SDLC, requiring security teams to act as mentors and guides rather than purely technical gatekeepers, involving other departments in understanding security implications rather than just listing vulnerabilities.

What does Chris Madalina mean by identifying vulnerabilities as 'process failures'?

Process failures occur when misconfigured devices, default passwords, or poor security posture are found - indicating systemic organizational problems rather than just technical gaps. Rather than simply reporting these findings, security should explain the process that allowed the failure and guide organizations toward preventive controls, avoiding repeated vulnerabilities when hardware is replaced.

How does media sensationalism around security research affect perceptions of security professionals?

Terms like 'hackers' in headlines create ambiguous, sometimes malicious connotations for general audiences, even when describing legitimate security research. The Jeep hacking and airplane vulnerability incidents created PR challenges for researchers because dramatic demonstrations (testing on highways, with journalists) conflated them into the story, complicating their ability to be seen as professionals rather than stunt performers.

Why did the developers in Chris's example refuse to fix vulnerabilities from the penetration test report?

The developers lacked time, didn't understand the vulnerability descriptions, received no explanation of business impact or remediation steps, and had no support from management to allocate time for fixes. The security team failed to interpret results or provide guidance, missing an opportunity to be a guiding force that translates technical findings into actionable business context.

What's the difference between security researchers and 'stunt hacking' according to the episode?

Security researchers conduct controlled, responsible vulnerability testing in appropriate environments to identify genuine risks, while stunt hacking prioritizes dramatic public impact and media attention, sometimes through unsafe demonstrations (like highway vehicle testing) that endanger lives and undermine the credibility of legitimate security professionals in the eyes of policymakers and the public.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

8 / 20

There are a handful of genuinely useful practitioner observations - particularly the pen-test-report-to-developer communication failure and the 'process failure' framing for misconfigured devices - but they are surrounded by a lot of agreeable meandering, throat-clearing, and obvious observations about security maturity. Insight rate is low relative to runtime.

they each got like three pages of paper like stapled together that was just like on our desk Monday morning that had a list of vulnerabilities...she's like, I don't know, it was worthless
those are process failures. Because somewhere something in that organization said that was okay to implement that with default settings

Originality

7 / 20

The episode recycles broadly circulating 2015-era infosec discourse - security-as-guiding-force, hacker terminology in media, responsible disclosure debates - without adding a genuinely fresh or contrarian angle. The 'process failure' framing is interesting but is explicitly credited to someone else seen at a conference.

fear and shame, that's kind of our big two. Uh, and they're very effective
information security is very much in its teenage stage right now

Guest Caliber

8 / 20

Chris Madalina appears to be a working security consultant who does real penetration tests and vulnerability assessments with clients, giving him legitimate practitioner credibility. However, there is no indication of notable seniority, scale of work, or any distinguishing accomplishment surfaced in the transcript.

one of the things that we try to call out is um, process failures
I sat them down, I showed my wife, showed her Burp suite and I pulled up Shodan and just kind of went through and showed her basically just simple open source intelligence

Specificity & Evidence

9 / 20

There are some commendably concrete details - the Jeep Cherokee vulnerability, the $300 dealership firmware charge, named tools (Burp Suite, Shodan), a named speaker (Mark Stanislav, Rapid7) at a named event - but no hard metrics, timelines, or dollar figures tied to actual security outcomes, and the TrustedSec presenter's name is forgotten mid-anecdote.

in their contract they, they forced like the dealerships to charge $300 for the
Mark Stanislav for Rapid7 gave a. Gave the keynote that Saturday. And, uh, one of the things he mentioned...he went before. I want to say it was Congress...seeking exemption from the DMCA for security researchers

Conversational Craft

6 / 20

The host frequently agrees before the guest finishes a thought and rarely challenges any claim; the few follow-up questions ('Was that from the pen test team?' and 'So your wife's company has like a security team?') are clarifying rather than probing. The conversation meanders without the host steering toward deeper specificity or productive disagreement.

I think you're absolutely right. I agree with you totally
Right. Yeah.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B70%
  • Speaker A30%

Most-used words

security56hacker14perception13team12process10test10developers9guiding8didn8conferences8back8understand7researchers7twitter7report6password6

Episode notes

In the second episode of the refreshed edition of the Exploring Information Security (EIS) podcast (wow, that's a mouthful), I talk with Chris Maddalena about the perception of information security. Chris recently gave a talk on FUD at BSides Detroit and CircleCityCon this past Summer, prompting me to explore the topic of information security perception with him. I think perception is something very important to the infosec community, especially, now that it is becoming more relevant in the public eye. In part two of this two part series we talk about perception: Security can be a friendly face. The word hacker. Developers vs. security. What is the perception of information security - part 2 With Chris Maddalena [ RSS Feed ] [ iTunes ]

Full transcript

29 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: This is part two of what is a perception of Information Security. Welcome to the Exploring Information Security podcast, where you will learn, explore and grow your security mindset. Uh, I am your host, Timothy D. Block, and in this episode, Chris Madalina and I will continue our discussion of what is perception of information security. I think you're absolutely right. I agree with you totally. Um, I don't think security is an IT position and I think I've even been. I. A lot of us come up through it too. Um, you know, oh, yeah, you got the hacker culture, which is very technical type of thing, so that's going to be a hard tie to sever. But we are, I think we should at some point be moving more towards a guiding factor, because security should be within every role. I mean, even within the business function, because they've got to pay attention to, like you said, the phishing emails. Because, you know, one person clicks on a phishing email, that entire agency organization could be owned by that one person if there's certain things in place. Um, so I think security is something that is going to be a mindset that a lot of other departments are going to have to take part in. I mean, developers, for example, need to be writing. That's one of the problems right now is writing secure code at the outset, at the beginning of the SDLC profit. So security, we need to be at the early stages of the SDLC process. Um, so I'm very much in agreement with you on that.

Speaker B: Yeah, one of, kind of think of, um, the SDLC process. One of the anecdotes that I've told people, I don't think people really believe me how true this is, though. Um, my wife, uh, is a web developer and, uh, so I know tons of people that she works with that are all web developers. And, uh, they came to me one day, uh, because they were all kind of stressed out because they had a pen test coming up. And they weren't stressed out because of that, but it was because the last time they had a pen test, uh, whoever had done it, like, brought down their network. It sounded like that it wasn't poorly, it was poorly executed. Or, uh, you know, they told them just go, go crazy or something. Like, oh, yes, we had to get this done and this had to be checked in. We had to do, you know, all of all this, like, cram in as much work as we could so they could do this over the weekend. And I said, oh, cool. I said, do you know what they're gonna do? And they were like, no, I Don't know. That's the security team. The security team set it up. I said, but you don't know what they're gonna do. And they're like, no, what do you mean? I was like, they're testing your stuff. You don't know what they're gonna do. And so I sat them down, I showed my wife, showed her Burp suite and I pulled up Shodan and just kind of went through and showed her basically just simple open source intelligence and some of the tools and showed her what in like 30 minutes I could pull up on her company and on, on some of the apps that her team works on that were externally facing or, you know, could be accessed from the outside for whatever reason. And she was kind of surprised at what I was able to do with it. I said, yeah, this is roughly what they're going to be doing, you know, over the weekend, right? And, you know, come, you know, then a couple of weeks later, um, she comes, yeah, we got the report from the pen test. I, I said, okay, cool. I said, um, you know, anything interesting? She's like, I don't know. I said, well, what do you mean you don't know? And she was like, well, we each got like three pages of paper like stapled together. That was just like on our desk Monday morning that had a list of, it was just, I didn't see it, but it was like just a list of vulnerabilities, like one of you know, cross site scripting, like on this app, like where it was found and then next vulnerability. And like, she's like, I don't know, it was worthless.

Speaker A: Was that from the pen test team?

Speaker B: So my, my, my assumption is that like the security team probably got like a big report. They handed it off to like the development, you know, like her manager who you know, took like a piece of it, you know, for the team, eventually got right, you know, narrowed down like these like three pages that they printed off and gave to each one of them. But I was like, so you're gonna fix them? And she's like, no. Like, we don't have time for that. No one's giving us time. Uh, no, you know, and also we don't, we don't understand them. Like, I don't know what this is. And I said, well, you know, you see. Did you try to Google it? She's like, I don't have time to sit there and Google what this report means. And that is like, I don't know who failed. Like, maybe the report was awesome. So I don't know who did it anyway. So I can't really, you know, be down on the pen testers. I was like, but like, man, what a failure. What a total missed opportunity. That's whether it was the pen test team that did a bad job or a management failure, that that report wasn't disseminated properly. But, you know, so those probably aren't going to be fixed or, you know, they'll be fixed later, you know, because the people that needed to do the actual work had no understanding, didn't receive, uh, an explanation as to why it was relevant, um, and why any of it mattered or what it, what the implications were. Well, and that was a lot of it where, you know, they didn't even understand, like, well, what can you even do with this?

Speaker A: Like, I, well, so, but, but so your wife's company has like a security team.

Speaker B: Yeah, yeah.

Speaker A: So that's, I think where the failure is and that's where security gets a bad, bad reputation is the fact that security team, uh, we should be, you know, we're talking about being the guiding factor here. We should be interpret, interpreting the results and going, okay, this is. And if, you know, they, maybe they don't have a good understanding of web application security, but if they don't, that's an area they've got to start pulling up Google and doing it. And you know, I don't have a good, great understanding of application security. I've worked a lot with it in the last year and a half. But I will go sit down with the developers and let's go figure this out together. And that's kind of like the approach that I take with a lot of different things. So, and I think that's, uh, I think, and m. We talked about this pregame too, is that just there's a lot of lack of mentorship, um, within, within the security space. And you know, I think security can be a very friendly face. I've been to the security conferences. Everyone's great, everyone's friendly. We can be friendly with and we can take that friendliness and be friendly with other departments and you know, because like you said, everyone else is under pressure to get the job done and you're, you know, the developers have a timeline to get stuff done and get, get everything. But, but that, and that also, uh, again, comes, has to come from support from the top as well. So management has to go, wait, my people, my people don't understand this. You got to help us, uh, understand this so we can go fix these problems. And you know, there's A little bit of a. It might sound like there's maybe a little bit of accountability thing there. So they may have just had a pen test to check off a box, which is just a whole nother podcast in itself.

Speaker B: Yeah, that's. There's many roads to go down with that one anecdote of. Ah, because the other thing too is um, not to pick on them too much but like, you know, that security team, I don't even know if they're a, if they have a soc. Are they actually like a security team or are they the people tasked with security that are part of it? Which could be a big difference because when you. And this is also the reason that we don't often get into. Of uh, why don't we want to be considered it. It's not really like we don't want to be part of your group. Um, it's really more the fact that I can't be managing systems and like imaging new computers or doing all that while also handling security because then I would be way too busy to try to guide anyone or explain things.

Speaker A: And I think a lot of people are struggling with that. I know I've struggled that with my job. I've had to run the antivirus server and I've had to run the. I've had to fill out website requests. Uh, because it sort of has a security lane. So it falls because we block web ads and some other things in it and it helps with doing some kind of invest incident response type of things. But yeah, you're absolutely right. But I think security is still very much maturing.

Speaker B: Yeah, I definitely think you're right there. That um, and actually just that made me think of uh. The thing that I think a lot about is, and I try to stress this when I'm talking with clients and also just even internally, uh, at my company is when we're looking at uh, doing a vulnerability assessment, one of the things that we try to call out is um, process failures. And this is something that I, um, got from. I forget his name. I saw a presentation he gave. It was one of the um, uh, one of the auditors at Trusted sec. They, they talked a lot in this one presentation I saw about the uh, idea of a process failure. And that really stuck with me because he, he lumped in. He's like, well, you know, if you have a misconfigured device or a, a default password or a really bad password, you know, something that would. You look at it and if you were doing a penetration test, you get that and you're like, I'm in, done. You know, then you proceed to do like, post exploitation, um, and you kind of wrap things up in record time. Uh, you know, he said, he's like, well, those are process failures. Because somewhere something in that organization said that was okay to implement that with default settings. You know, put that out there with the default password or use this bad password. And one of the things that we want to do is obviously, you know, from the red Team side. Um, and I think some people get caught up in the idea of like, kind of the glory of like, I want to be like a hacker from the movies. I'm going to break into things. And so they're perfectly happy to take those easy roads when they open up. Um, but really it's almost like the pen test becomes so much less valuable when that's one of your roads in. Because you're not testing a mature program. You're testing a, ah, very much an immature program because there's a broken process somewhere. Um, or they're not doing regular assessments if maybe they changed that process. But no one ever went back and made sure that the existing hardware was set up properly. Um, so really you want to call that out and say, hey, you know, and again, be that guiding force, not say, oh, you have a vulnerability here. Say, hey, we noticed that there is a default password. That's what let us get in. Um, and you know, why don't you go fix that and don't do, uh, you know, and calling it out as a pro, as a process failure and letting them know how to fix it, that, hey, put it, get a process in place to do something so these passwords don't get, you know, don't go into the unchanged or, you know, make sure you're always setting these devices up properly. Um, you know, and then say, okay, then come back to us and let's do it, do it again and we'll see if we can find another way in. Um, because we always want to be testing a mature program. Because if we're just testing, um, you know, an immature program, then the next time we come in, they might have just changed that password, but then they put in a new router or whatever and then you find the same problem because they just did the tactical response of change the passwords, right, Update the settings, and then they, you know, checked off the boxes in your report, said, okay, I did it. And then a year later they call you back to do another pen test and you find a similar way in because they replaced something and didn't have that updated process in place. Ah, yeah, that's definitely where I can see, um, a guiding force coming into play of explaining to them what should be changed and why, uh, it would be a good idea to do so.

Speaker A: So I think we've covered the perception within the business pretty well. Is there anything else you'd like to mention that we haven't already discussed?

Speaker B: Oh, man. I was just. Just trying to go through everything we've talked about.

Speaker A: It's. Yeah, it's a little bit difficult.

Speaker B: We kind of covered a lot of ground. Yep, that's fine.

Speaker A: I mean, you know, we. There's also the perception out in the real world with like all the TV shows and stuff that we could talk about. But I. And I'm really kind of. And that's kind of what I expected we'd talk about. We've kind of talked a lot more about the business and I think that's good as well. Uh, because it's a lot. I think that's a lot of where, uh. Obviously that's where a lot of us work, but, you know, that's. That's where a lot of us need to start making some strides and changing the perception of security. And I think there's some interesting ideas here from. Because I've never thought about that. Uh, I've thought about the guiding factor, but I have also always thought about security as kind of like an IT role. But that's because I've come up through it. Um, but it's not. If you do think about it, like you said, it's not like you have an understanding of all that. But really it's not it. Because it's just. It's telling people how processes should be done and how things should be configured.

Speaker B: Yeah, definitely. And kind of to speak to. Yeah. Kind of out there in the real world though, is that there are some of what we talked about does, um, affect that as well. Like one of the big ones. And, um, we saw that a lot,

Speaker A: um,

Speaker B: with the Jeep hacking this past week. Uh, because that was. That's going on like kind of right now while we're recording this. I guess just to quickly go over that if, um, you know, if it's been forgotten by the time this goes up is a couple of security researchers found a vulnerability in the latest, uh, I think the Jeep Cherokee. Um, and it basically allows them to take remote control over the car and cause a bunch of problems. Um, and it made a really big splash this past week because. And I take a little bit of umbrage with how the security researchers did it.

Speaker A: Uh, I'm with you.

Speaker B: Yeah. They've been on Twitter going, like, see, look, we can get press for like, one of them was out there saying on Twitter, see, we can get press without having like a goofy logo and a crazy name for our vulnerability. And I wanted to be like, oh, uh, yeah, but you did this huge sensationalist, like, article with Wired.

Speaker A: Well, now they're the story and the question is, you know, security research. And that's a whole nother podcast. But they've kind of inserted themselves into the story. It's not a story about G packing. It's. It's about. It's kind of also. It's a story about that, but it's also a story about what's the proper way to do some of this research in a safe manner. Not shut down the car on highway with a journalist in it.

Speaker B: Yeah. Which is, um, yeah. So to kind of briefly touch on what you said, that's. That could be a whole like hour long conversation at least is a lot of people. Um, and Ben 10 had had a really good blog post about this where he had a couple of, um, examples of tweets that, uh, some people reported as like, you know, security researchers disable Jeep. Like, okay, that's interesting, you know, but that's not a very snappy headline. So some people ran with like, hackers, you know, take control over. And that's. It's still accurate. Right. We didn't really change. But to the outside world, a hacker is always a bad guy. Like, people don't really identify hackers as being good or bad. Unless, uh, you're. Because if you think about it, anytime you've probably had a conversation where you referred to like a good hacker, at some point you went, there's good and bad ones. Okay. And then you, um. So we refer to ourselves as hackers. Uh, you know, uh, we. A lot of the conferences say like hacker convention, you know, like as a subtitle to it. Um, and that's fine because it tells us, the community, what it is, but to the outside world it's still like a. That becomes very ambiguous or a little bit scary. So to say like hackers take control over a Jeep, that sounds very, uh, malicious. It doesn't sound like there's some research from these two security researchers that allowed them to do this. So it becomes kind of a lie to say hackers did it because you're playing on the idea that the reader thinks like bad criminal did something to someone's car.

Speaker A: Right.

Speaker B: Um, and so that, that definitely, I think is a, is a big hurdle for us to overcome because I don't think we're going to let go of the word hacker because it has a lot of flavor. We really like it. It's been sort of with that industry, with the industry, um, for a long time. There's plenty of people that consider themselves hackers. You don't have to even be in security for it. Right. It's not a security specific role, just MacGyver.

Speaker A: MacGyver's a hacker.

Speaker B: Yeah, yeah. You're curious, you're putting your cobbling things together, you're screwing around with things. You're a hacker solving problems.

Speaker A: Yeah, absolutely.

Speaker B: So it's fun. You know, people take pride in being a hacker and they should. Um, but, uh, yeah, it's. With how it's used in the media, we have to be careful, I think, with how it gets used kind of outside of like the conferences, because it can really color the impression of, uh, you know, when you're trying to be that guiding force to say, like to start using words like that, you know, kind of go back to, you need to know your audience. Um, so if you start throwing out words like that and you're talking to the wrong people or your uh, you know, your articles going up in front of a certain audience, it's going to color the perception of that, right?

Speaker A: Absolutely. Yep. And I keep thinking about hacker almost because it is, uh, sensationalized, but it's also, to me, it almost has like a horror movie type of connotation. You know, people, you know, a bad guy hacking up some teenagers.

Speaker B: Yeah, yeah. Full blown, like, yeah, hoodie.

Speaker A: It's. That's. Yeah. And that's going to be laptops in the back of a van with a mask and some gloves on that you really probably couldn't type with. But yeah, absolutely. So, yeah, losing the hacker. And I know a lot of people want to hold on to the name hacker and I think that's admirable. I think though, at some point we are going to have to also accept the fact that we are information security professionals. And that just sounds more professional within that space. And if we start switching to that, it's going to kind of help with the perception a little bit. So, yeah.

Speaker B: Ah, and to that point though is that uh, with how hacker has been kind of taken on this life of its own and it's kind of difficult for us to use it and be taken seriously or not have that miscolored perception, um, that's to go back to The G packing, um, and then earlier this year with Chris Roberts and the planes and all that. Um, it's like, you know, I've. I've talked to Chris Roberts. I think he's an awesome guy. No, he's.

Speaker A: He's fantastic. Yeah.

Speaker B: Yeah, he's cool. And I don't really. And you know, and he has owned, like, what he said on Twitter. You know, he was a mistake. Shouldn't have said it. It caused. You know, he definitely did not mean for it to be, like, taken so seriously. Yeah, there's a spread like that.

Speaker A: Yeah, there's a perception issue right there. Yeah.

Speaker B: Yes. But so now, um, like, also to, uh. Uh, at Bsides District, mark Stanislav for Rapid7 gave a. Gave the keynote that Saturday. And, uh, one of the things he mentioned that, um. There's a lot that he says in that keynote, actually, if you have heard it, that, uh, is controversial and is definitely very much his opinion. But one of the things that I took away from it was he went before. I want to say it was Congress. Um, the week after, kind of all of that blew up, and he was seeking, um, exemption from the DMCA for security researchers. And while Chris Roberts never meant any harm with what he was saying on Twitter, and it probably shouldn't have affected Mark. You know, one of the questions Mark says he got, like, first thing was, why should we trust security researchers and exempt them from the DMCA when they're doing that.

Speaker A: Right.

Speaker B: And it's like, ah, uh, well, yeah, you know what? Fair question. Touche. Hey, you know, and then you see the thing with the Jeep that, you know, and whether or not, um. Like, I'm still kind of unclear of exactly what went on with the Jeep. Hacking, you m. Know, with the highway. And some of it was done in the parking lots, and some of it was on a high.

Speaker A: All of that could have been done in a parking lot, to be honest.

Speaker B: But, yeah, it probably should have been. Yeah, it's. Or a test track of some kind. And, um. And so now they're getting a lot of, um. I don't know. I actually don't know because I haven't read. I've been trying to read the articles, but I haven't read all of them yet or, you know, all the ones I have, like, bookmarked. But, you know, but they're getting, uh. You know, they're getting kind of Dan. Like, look what these. These guys are crazy. They're, uh. They endangered lives. And so now it's. Again, we're. If we keep this up. Eventually security researcher will be like, oh, you're a security researcher. Do you do research or do you, you know, screw around with planes and jeeps on highways? Like, if we want to do something that's perhaps, uh, of in a gray area, maybe let's move away from moving vehicles in the, you know, in the sky or.

Speaker A: Right, absolutely.

Speaker B: If we could just move away from that for a few months.

Speaker A: Well, and I think, I think that's something that is just going to have mature within the security industry, is that we're going to have to that perception and, you know, kind of define standards. So, you know, you can kind of define the difference between security researcher and the term stunt hacking. Uh, which, which, you know, stunt hacking has its uses in making an impact, but the impact here is that it's, you know, they're starting to be drawn into being part of the story. Uh, the good thing that they did have was that there is, there's a recall now for crisis. Yeah, so that's, that's a, that's very much positive and that's something I think they can be proud of. But now they're having to also, instead of being able to get back to their security research, they're having to combat, uh, the PR and some of that stuff of, of, well, you know, the kind of the moral of doing, you know, that article or putting that journalist on the highway and, you know, having some of the other stuff going on. So it's, it's, you know, I think what we've done is good and sometimes it requires that, but we also need to keep in mind that we are professionals and uh, we need to be conscious of our perception.

Speaker B: Yeah, I think it kind of goes back to that earlier point we talked about. It's a really easy motivator using fear, you know, and who knows if they had, um. I mean, I want to say they were reporting it to, to Fiat Chrysler, um, and weren't getting the traction that, uh, they wanted. Um, I think I'd seen, um, a couple of mentions that it was reported them like three months before the, the car was to release for this year, which, so it was like already going out to dealership. So they would have, they didn't want to do a recall. Um, they do have a firmware update available for it, but it's like, but in, in their contract they, they forced like the dealerships to charge $300 for the. So it's like, well, you want your car to be vulnerable or you can pay us $300 and we'll give you the new software. You know, it's, um. So this definitely had a much better, uh, response from Fiat. But, yeah, there's that whole debate that we just kind of had on was it a good way to go about it? Um, I don't think so. But again, you know, it's. It. That's kind of been our fallback a lot that I hope we can get away from. Uh, using fear to be like, look, you know, or shame. Fear and shame, that's kind of our big two. Uh, and they're very effective.

Speaker A: Yeah. Information security is very much in its teenage stage right now. We're about to maybe head into college where we do some more. I don't know.

Speaker B: I don't know.

Speaker A: Maybe we're already in the college stage. I honestly don't know. Um, but yeah, uh, I think it's just a maturity thing. And, uh, I think we can do a better job of trying to improve our perception, like everyone. Because I think, you know, like I said, hacker is kind of like a recluse creature, but you go to these security conferences and they're absolutely great people, so.

Speaker B: Oh, yeah. Yeah. And that's the one thing I, um. When I have. And also to be clear, like, I love security researchers.

Speaker A: I. Yeah, we're not knocking them. Yeah.

Speaker B: White papers and stuff that they put out. I understand, like, half of it. And then just kind of marvel at the, you know, might as well skip conclusion most of the time and be like, wow, that's okay. I understand what you're telling me. I don't understand how you found it. But that's. But yeah, it's, uh. I guess I wish there was a way that they could tell, you know, in that perfect world where they could just tell someone something's wrong, it just gets fixed. But absolutely. But yeah, it's the other thing to do with the security conference. Like you've mentioned that there's. The people at the conferences are awesome. And I. I know that, uh, you know, that if they could get in front of people and present it, you know, present things like they present at the security conferences in that same way, in that friendly way, uh, that we could probably gain some traction where right now we struggle. Um, but, uh, the other thing we have to remember too, is that, uh, there's this. That kind of vicious cycle where the security people look at, uh, like the IT people and the stupid developers always making the same mistakes in their web apps. And then the developers look at, like, stupid IT people. Can't keep my server up. The IT people say, Stupid developers don't know how to write a service. Their server keeps going down, you know, and there's like this circle of everyone is just thinks someone else is being stupid and everyone hates security because security is waving a stick at them. Um, and the thing to remember is that we often get, uh, that perception from the security committee is often we get defensive, like, no, we're telling you the right way to do things. You should listen to us. But remember that the crew that you see at security conferences, the people at the just showed up to a security conference and did some networking and saw some talks, are like already leagues ahead of most of the security people that are, that do nothing. But they check in at 9 o', clock, they, you know, wave their stick at some developers and then, you know, check out at 5. Uh, there are definitely people out there just like there are honestly bad developers that are making the same mistakes when they know they shouldn't and you know, people that are leaving all kinds of services open to the Internet or, you know, whatever, making those same mistakes that we uh, um, that you find on pen tests and assessments. Um, those same people exist in security, so no one is perfect. Uh, and so that's the other way. We're out there guiding people, trying to spread our knowledge, um, and talk to people. We can also, uh, reach people that aren't showing up at the conferences. Security people that could, uh, we kind of mentioned in the pre game where you talked about, uh, at the state level you don't always get some of the best talent because the pay is not great or uh, just with how the hiring is, uh, the really good talent might end up at private companies. Um, and that's totally fine because sometimes those people are great, they're diamonds in the rough that you don't realize what their potential is because they've been stuck on the help desk for the last eight years. Um, but they really know their stuff. But everyone's going to make mistakes and if no one's there to, you know, to say, hey, no, this is wrong, do it this way, um, or at least have that debate with them so they can figure out what the right or wrong way to do something is, they'll just keep doing it their way forever until someone stops them.

Speaker A: Right? Yeah.

Speaker B: So they don't have anyone there to be a mentor, you know?

Speaker A: Yeah. So I think our takeaway here is to be a guiding factor both within the community and with that and outside of it with. Even with your family.

Speaker B: Yeah, I think so. All right.

Speaker A: Uh, well that's going to do it. Hopefully you learned something if you didn't. Drop me a line on Twitter, timothydblock, or email me@timothy.deblockmail.com and let me know what you what you didn't learn. And we'll try to cover that in a future podcast. I think we've got quite a few future podcasts out of this one. Some hopefully. Hopefully. Uh, plan to cover. Chris, uh, go ahead and give the people your Twitter handle and anything else you'd like to plug.

Speaker B: Uh, sure. So you can find me on Twitter. Uh, Madalina. That's just C, M, M, A, D, D, A, L, E, N A. Uh, and I don't really have anything to plug. Just. Thanks for having me, Tim.

Speaker A: All right. Awesome. All right. Uh, that's going to be it. Have a good one.

Speaker B: Sam.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Pursuing strategic partnerships to tackle Cobalt Strike abuseHealthcare Strategies · on Penetration testing85 / 100
  • The Internet Will Never Be This Secure Again, IEEE's Kevin Curran on AI and CybersecurityThe Business of Cybersecurity · on Penetration testing81 / 100
  • Risky Business #844 - China closes AI vulndev gap as USA lifts Fable banRisky Business · on Burp Suite77 / 100
  • Gary Martin from Scan Ninja AIEnergytech Startups · on Penetration testing77 / 100
  • From Ransomware to Recovery: How One Rural Hospital Transformed Its CybersecurityEncrypted Ambition: Where Ambition Meets Encryption · on Penetration testing75 / 100
  • Ep 110: Empowering K-12 for a Digital Future with Mark RobuckLevelUp Cyber · on Burp Suite70 / 100

More from Exploring Information Security

All episodes →
  • [RERELEASE] What is the perception of information security - part 1
  • Exploring the Quantum Horizon: Why We Need CBOMs Today
  • Exploring the Risks of Model Context Protocol (MCP) with Casey Bleeker
  • From Combat Zones to Corporate Lobbies: A Guide to Physical Security with Josh Winter
  • [RERELEASE] What is a SIEM?
Explore the best B2B Ops podcasts →
All Exploring Information Security episodes →