
IoT Security Podcast · 2025-09-16 · 36 min
Key moments - from our scoring
Substance score
47 / 100
Five dimensions, 20 points each
Dylan Kanaburan reflects on two decades running Hack in the Box - one of Asia's premier security conferences alongside Black Hat and DEFCON. The conversation explores how conference formats have adapted post-COVID, including the shift to the new 'Out of the Box' brand and audience-voted talk selection through the GSEC format. Beyond format, Kanaburan laments a fundamental cultural shift in security research: where early 2000s hackers shared exploits openly and walked audiences through methodology (HDMore presenting Metasploit as a framework concept, Vietnamese researchers hand-writing shellcode), today's researchers monetize findings through bug bounties and zero-day sales rather than contributing to collective knowledge. He contrasts the curiosity-driven ethos - where researchers explored infrastructure "just to see if they could" - with today's mentality of "how much can I sell this for?" This shift affects knowledge dissemination, toolset improvement, and mentorship of emerging talent in security research.
Hack in the Box is the original brand operated in the UAE (after being sold in 2018), featuring large-scale events like the flagship HIDB Security Conference and a Pro CTF competition. Out of the Box is a new brand created post-COVID to experiment with different event formats and cater to changing attendee expectations from the pandemic generation.
A review board (including Google Project Zero, Microsoft, and industry experts) shortlists ~30 talks from hundreds of submissions, then attendees vote on which presentations they want to see from that curated list, ensuring higher engagement and preventing talks that have been presented at other major conferences from dominating slots.
The rise of bug bounties and zero-day markets means researchers can earn significant money (e.g., $10 million for a zero-click iOS vulnerability) by selling findings privately rather than sharing methodology at conferences, replacing the early 2000s culture where hackers openly presented tools and step-by-step thinking.
HDMore presented Metasploit as an early framework concept and discovered Server 2003 zero-days live during CTF play; Vietnamese researchers hand-wrote shellcode in hexadecimal in terminals without compilers, and researchers like Hugo Tesla and Jim Giovanni openly demonstrated hacking planes and satellites at conferences purely for the intellectual achievement.
Younger attendees who graduated remotely now value their time differently and weigh travel costs, family time, and hotel expenses against conference value, prompting organizers like Dylan to create new event formats and brands rather than repeat traditional large-scale conference models.
Our reviewer’s read on each dimension, with quotes from the episode.
There are a handful of genuinely interesting observations - the shift from knowledge-sharing to monetization of exploits, the agentic AI paradigm for bug hunting, and the design-flaw framing of future vulnerabilities - but the episode is heavily padded with conference logistics, Covid small-talk, and nostalgic rambling that dilutes the signal-to-noise ratio significantly for a B2B operator audience.
if I found a zero click vulnerability, iOS that's a $10 million exploit, basically, am I going to drop that knowledge on the Internet just for everybody else to enjoy? No
Hacker One number one leaderboard is now AI
The reframing of bug hunters as AI orchestrators who must manage token costs and agent tuning is a moderately fresh angle, and the observation that researchers now hoard methodology rather than just findings is a nuanced point; however, most of the episode trades in familiar hacker-culture nostalgia and broad 'AI is changing everything' takes without a genuinely contrarian or first-principles argument.
you are an orchestrator and you're not actually going to be hunting the bugs by yourselves like literally on the command line. That shit, those days are over
it's not just about the solution, but it's the thinking process behind it, the methodology...What made you look in that direction to begin with?
Dylan Kanaburan is a legitimate 20-year practitioner who built one of Asia's most respected independent security conferences, with real access to elite researchers and firsthand knowledge of how the offensive research community operates; however, he is primarily a conference organizer and community figure rather than a hands-on operator or executive who has scaled a security product or team, which limits his direct B2B operator relevance.
we run this small little conference called HackInTheBox. Uh, we've been around for like 20 something years
HD More was one of our first speakers that came to our first quote unquote international hang the box that we had in Malaysia. Uh, and he presented the metasploit framework as an idea
The episode includes several named data points - HD Moore presenting proto-Metasploit at HITB Malaysia 2003, a live zero-day found against Server 2003, the $10M valuation of an iOS zero-click exploit, and Hacker One's AI leaderboard claim - but most anecdotes are unverified recall from memory and the conference-ratio numbers are hedged; there are no documents, studies, or verifiable metrics cited.
if I found a, uh, zero click vulnerability, iOS that's a $10 million exploit, basically
HD More was one of our first speakers...he presented the metasploit framework as an idea...he found a zero day in it, like live
The host asks topically sensible questions and surfaces useful threads like vibe coding risk and the evolution of security research, but the questions are largely predictable scene-setters with no meaningful pushback, no probing of unverified claims (e.g., the AI leaderboard assertion), and several exchanges devolve into mutual affirmation rather than productive tension.
Do you think using like AI to vibe code, do you think it's really going to drastically increase like the bugs and the insecurity out there?
Yeah, that's pretty interesting
Computed from the transcript - who did the talking, and the words that came up most.
The dynamic evolution of hacker culture, the ongoing transformation of cybersecurity conferences, and the importance of resilience and curiosity among security researchers are all topics covered in this episode through stories of past and present with Dhillon Kannabhiran, CEO and Founder of Hack In The Box (HITB) and Out Of The Box. He and Phillip Wylie examine the shift from open knowledge sharing and exploration to the monetization and commercialization of cybersecurity exploits. Dhillon offers insights into the unique approaches Hack In The Box and Out of the Box conferences have taken, encouraging people the valuing of persistence and the collaborative spirit that push the community forward.
Transcribed and scored by The B2B Podcast Index.
Speaker A: I think what makes hackers different from everybody else is resilience and our willingness to not give up and not say, oh, this shit doesn't go on bile. So fuck this shit, I'm going to watch Netflix. But figuring it out and making it work, right, I think that that sets us apart. As in that's what makes us, ah, different. As in that's what makes hackers different. Right? Is that, uh, not giving up resilience?
Speaker B: In this episode of the Phosphorus IoT Security Podcast, I'm joined by Dylan Kanaburan, and we discussed cybersecurity conferences in the Middle east and Asia, as well as discussing cybersecurity research and cybersecurity community. I hope you enjoy this episode. Hello and welcome to another episode of the Phosphorus IoT Security Podcast. Today I'm, um, joined by Dylan Kanaburan. Uh, Dylan and I have been connected on social media for many years. I think we originally connected on Twitter, now rebranded as X. And I got to speak at his Hack in the Box conference in Singapore back in 2022, the first time we actually got to meet in person. So it's an honor to have you join us today and welcome to the show.
Speaker A: Thanks for having me, man. Thanks for having me. Always a privilege, always fun. Yeah.
Speaker B: Great to virtually see you. It's been too long since the last time. I've got to get out to one of your conferences again.
Speaker A: Yeah, man, time flies, right, when you're having fun, so. But yeah, it does.
Speaker B: Definitely.
Speaker A: You just mentioned 2022, and I'm like, was it really that long ago? I was kind of. Doesn't feel like it. But, yeah, time's really gone by, man.
Speaker B: It was crazy, too, because this was still, you know, we still had Covid to deal with because I remember when I was there that you had, uh, the week. The week after I left is when they. They removed the mask mandate, so.
Speaker A: Oh, yes.
Speaker B: Had to. Yeah. Yeah.
Speaker A: Huh? Yeah, man. Yeah, Covid's a bad word. You know what I mean? It's a time that we all want to forget, but, like, yeah, it was, uh. There's a distinction between BC before COVID and, like, AC, I guess, you know, it's. But yeah, 2022 was. Yeah, you're right. It was still in the mask mandate. Social distancing, sanitize your hands. But, yeah, interesting times that we live through, right?
Speaker B: Like, yeah, definitely, definitely. Good to have that behind us now. So, uh, so some of the folks that may not know who you are, if you wouldn't mind introducing yourself and Telling the listeners about your background.
Speaker A: Sure. Uh, yeah. So basically we run this small little conference called HackInTheBox. Uh, we've been around for like 20 something years. Uh, always say we're similar to Black Hat and defcon, except we're in Asia. So we started out in Malaysia in like 2002, 2003. Uh, we've done events since then in the Middle east. So we were in Dubai and Abu Dhabi for a couple of years. We've then expanded to Europe. Uh, and yeah, so it's been like 20, 22, 23 years, something like that. Like a long, long time that like I've had so much gray hair. I didn't have this much gray hair when I started. But this is what happens when you run conferences. Yeah,
Speaker B: It's usually people's children that give them the gray hair.
Speaker A: Yeah, I have attendees to worry about and speakers which are like children also I suppose y. A different set of all those. Yeah.
Speaker B: And the interesting thing is is you, you really operate a high quality conference. Because one of the things I was really m amazed is still one of the best conferences I've spoken at. I can't. I was amazed at the. The artwork on the stage, the audio and video setup was like really, really very nice. I mean I remember uh, because yeah, it was pretty amazing. I was really impressed, especially considering it wasn't like a really huge conference, but just the level of quality of the conference all the way through the. Because I know a lot of the speakers had original research because I actually got to meet uh, uh, a young man that's originally from Cuba, Sebastian Castro. He was there. He had some Windows security related uh, research, uh, that he had done. So there's a lot of original research and top notch speakers there. So it was a pretty amazing conference.
Speaker A: Yeah, it was nice to have you over, man. So basically I think you attended the Singapore event. And so for the listeners and for the viewers, I guess essentially we had a few different types of conferences that we run. So we had the flagship event which is called the HIDB Security Conference. And that's like a large scale event that we used to do in Amsterdam. Used to be like our largest event. And then uh, we decided, well, we should do something more bespoke. And so we did an event called HRD with gsec. And the difference was that we allowed the audience to kind of uh, choose the talks. So you actually got invited, uh, because the audience wanted you there. We uh, decided that um, since people are paying tickets to attend these kind of things and then usually not that cheap. We should probably let them have a say in who they're going to see uh, on stage and what kind of talks they want to listen to. Because yeah, we have a review board and they're like you know, Google Project Zero and the who's who of the security industry, folks from Microsoft and so on and so on. But it's all fine and well. But uh, they might not speak to what you are personally interested in. So if you're buying a ticket, ultimately I think you should have a say in what's interesting to you. For me I love AI and all AI stuff. So if I had a choice I'd be like, yeah, vote for all the AI talks. So we decided to do this different format and we call it GSEC where people could vote on the talks. And uh, it was just a different style of event, so a little bit smaller. But um, perhaps I would say uh, attendee wise engagement will probably be a little bit higher since everybody kind of like really wanted to be there and wanted to see your talk. Right. Or. And everybody else's.
Speaker B: Yeah, it's kind of, kind of makes having not. It makes it to where you really don't have to have a review board having that case because the attendees are the review board.
Speaker A: Well we still had the review board choose the high level um, list. Okay, so let's just say we. Because it was, I believe it was like a, a single track conference that we ran for two days if memory serves me right. So excuse the old man, I might not remember but I think it was a single track over two days. But anyway, uh, which would mean we have like something like I don't know, let's just say 12 talks, right? So six per day. So six speakers per day. Uh, and they would shortlist uh, say 30 that they felt uh, worthy because most of the time we have a ratio of something like uh, for like really big hack in the box events is something like 15 to 20, uh, to 1. So which means 20 submissions to every one slot that we have, which means choosing the TOCs becomes ridiculous. Right. Uh, so in Singapore I think it was a little bit more manageable, something like maybe 8 to 1 or something like that. So they chose the 30 favorite toms that they thought were like worthy of filling the 12 slots or whatever that we had. Uh, and then we shortlisted that and provided that list as a shortlisted list for people to vote on because um, essentially uh, it will become overwhelming if we let the audience kind of choose from a list of 100 something talks because there's lots of overlap and uh, the nuances in what's different between Presentation A and B, they might not be the best person in order to kind of like pick that out, right? And that's what we have our CFA review board for. Uh, so they would choose between A and B that's talking about the same topic, but which is talking about something that maybe hasn't been fully explode perhaps. Uh, so that would be our choice because it's not been said before, or it's a slightly different angle or slightly different take on the same problem, but approaching it from a different way or a different outlook. Um, so we would say that because Talk A perhaps has been presented as black hat, um, we wouldn't choose Talk A not because it's been presented before, but if Talk B brings enough value and enough difference to the table, then it doesn't matter who the speaker is. It's like that point of view, you know what I mean? Even though he might be a bigger speaker and Talk A bigger in the sense of like more famous or has presented many times before, but I guess that's how um, things stay fresh and uh, you kind of surface up new talents, you know what I mean?
Speaker B: Yeah, that's pretty interesting. Back to the quality of the conferences, the talks and stuff, it's kind of different because most conferences that I'm used to going to, yeah, there will be some people that has some original research, but that is just not normal. Whereas I know the conference I spoke at, Hack in the Box Singapore, you actually had two different tracks. One was like a research track and the other one was a security track because I did a Talk on securing APIs through external attack service management. But then the other track was research. So that's one of the stages that Sebastian spoke on.
Speaker A: Okay, okay, okay, okay. Yeah, I mean we normally. So that's the thing. When everybody always asks me like, how do I get a speaking slot at Hack in the Box? I'm like, well, um, submit your best research. And it doesn't really have to be like um, zero day level stuff. Of course we love the zero day, uh, every prioritize attack based stuff mainly because they're exciting, uh, not because we don't think defense is important, but it's like from an attendee standpoint, like it's exciting to see stuff getting hacked. You know what I mean? So we uh, always prioritize zero days. But I always tell folks that like submit your best research because at the end of the day it's not me Juicy. And so I Might have my own biases of what I think makes a cool talk. But, um, we trust our review board to be, um, to have a holistic view on where the industry is going. And there's so many folks in our review board anyway, so it kind of balances out anyway that, you know, you have some folks that will say, like, yeah, this topic has been covered many times before and others will be arguing for, well, yeah, okay, it has, but this particular portion of the research is novel and this particular researcher, uh, hasn't had stage time. Why not give them an opportunity? Uh, and you never know what happens from there, you know what I mean? Because, um, yeah, there's lots of smart people, you know what I mean? So it's like not everybody might be a household name.
Speaker B: Yeah, yeah, that's. And that's the thing too is just because someone is well known doesn't always mean that it's the best. Also topics they bring. But then again, at the same time, some of these people are well known. They're. They're presenting a lot of these same topics that's been heard. So it's very interesting that you bring it, that you bring in the quality of speaker that you do. So, uh, one of the things that's interesting too, I just recently noticed, was that you have, uh, a series of conferences called outside of the output out of the box. So what's the difference between hack in the box and out of the box
Speaker A: out of the box. Yeah. So basically, um, so hang the box. We essentially sold the brand and the business back in, like 2018, um, to the UAE. So anything that happens outside of the UAE, we have to call it something else. Uh, and since we are, uh, now in a post Covid era, we were thinking that, you know, looking at the way the competence are these days and attendees and the, you know, looking at the next generation, right? And the fact that they grew up through living through a pandemic. Some of them graduated remotely, didn't really go to classes, had remote classes. Like, the expectation from an attendee for an event is quite different from you and I, who are much older with the gray hair. You know, we had a different need when we went for conferences. It was, it was a different time. Right. And, um, now in the post Covid era, it's like, you know, a lot of things are done remotely. Like even this podcast, for example, right? Like this food podcast. Probably be something we would have done at a conference in a room, uh, and having met each other in person and then sat down and had this podcast Recorded. But now we're doing everything remotely. I haven't seen you in three years, so you know what I mean?
Speaker B: Yeah.
Speaker A: So the younger generation and even attendees, um, want something else because, um, you know, having lived through a pandemic, you now value your time differently. As in time away from family and you know, time spent on the road, uh, flying, staying in hotels, blah, blah, blah. All the costs have gone up as well. And you weigh all of those things very differently. Right. So we were thinking like, well, we have an opportunity to then now have a new brand, uh, and thus create a new experience or something completely different. Why not? I mean, it's like, why do you want to do the same old thing that we've done before? And not to say that we can't do a hang in the box event anymore. We just do those in uae, much larger event. We have the pro CTF where you Invite the top 10 teams from CTF time to come compete. And it's like a completely different thing. Right. So now we have the flexibility of adding something new. We should, like all good hackers, experiment and try it out and see what happens. You know what I mean? Uh, what's the worst that can happen anyway, right?
Speaker B: Yeah. And for someone that comes from an offensive security background and really appreciates hacking, I really appreciate conferences that have a lot of focus around hacking and security research. Because a lot of, a lot of conferences here in the States are really not so much, uh, offensive oriented. There's a lot of stuff around a defense, which, there's a need for it, but it's. For those of us that work on the offensive side, really appreciate the hacker conferences because for us there's, there's some around here, but it's just, I don't know, there is not as much emphasis, I guess on some of these conferences. On the offensive side or research side.
Speaker A: I guess we grew up differently, right? I mean, we're from a time when we were in exploratory. As in, you, uh, know, we grew up in a time where you book into a hotel and you start exploring the WI fi. It's like, you know what I mean? It's like normal. It wasn't something that you would. Why would you do that? Is it. It connects to the Internet, you're fine, you can download stuff, right? We'll be like, no, let's look at the infrastructure, let's try mapping stuff out, see whether there's any authentication problems, see if we can get into the admin level. Not because we wanted to cause any trouble, but Just because, uh, we were just curious to see whether we could. Right. And so we've always been, I think, um, offensive focused in that sense. Let's see what happens if we poke this thing and really break. Right. Uh, and I guess that sense of, um, curiosity, I suppose, still drives a lot of what we do, even though now we are much older and much younger, I suppose, quote unquote wiser, uh, in everything that we approach, we kind of approach it with a more sense of play, you know what I mean? In the sense that, like, what's the worst that can happen, bro? Like, you know, just experiment and try. Right? Like, you can always go back to what worked before anyway. Right. Like, but there's no harm in trying something else. What happens when you double space? Double space. You know,
Speaker B: it's. It's really interesting how security and the conference scene and hacking in general has, has evolved because, you know, when we were younger, getting started out, you didn't have bug bounties.
Speaker A: Yeah.
Speaker B: So it was. So you didn't have those opportunities.
Speaker A: He said, this is basically is what gets sense to you, man.
Speaker B: Yeah. And it's interesting too, because you mentioned the curiosity, because back then people could do things out of curiosity and not really have to worry about, uh, repercussions, you know, because a lot of times people were doing it out of curiosity, not malicious intent. So it's just kind of interesting how that's kind of changed. Nowadays security researchers really have to be careful about what they're doing, or they could find themselves in legal trouble.
Speaker A: I don't know, man. I think actually the amount of legal trouble you could find yourself in is probably the same as it was before. It's just that right now I think people don't share as openly the coolness about it. As in, like, it always has to be something big. As in, and when it becomes something big, it's more of like, uh, how can I monetize this? It's the question that today people will ask themselves. As in, like, if I found a vulnerability in iOS, let's just give an example, right? If I found a, uh, zero click vulnerability, iOS that's a $10 million exploit, basically, am I going to drop that knowledge on the Internet just for everybody else to enjoy? No, right? Even it used to be that, okay, I'll save that knowledge and present it at Black Hat, or present it at Hack in the Box or whatever, right? Like, as in, I'll save it for a special occasion. Right now it'll be like, who can I sell it to? And who's going to pay me enough for it, right? And can I trust them to actually pay me for it or are they going to rip me off? That's like today's thinking. Um, so you have folks that are kind of like sitting on knowledge, which, uh, in itself is probably not really useful, but when chained with a lot of other stuff can become useful, but nobody wants to share anymore, it's like everybody's keeping all the goodies for themselves, right? Where. As opposed to in the early Dan Kaminsky days, for example, where he was on stage making money spit out of an atf. Like, those shit days are over, man. Like, we're not going to see that anymore. Which is a shame. Uh, the days of Hugo Tesla getting up on stage and saying I can hack a plane, or Jim Giovanni saying I can take over a satellite and showing it, um, not because we can do something with it that's malicious other than getting free Internet, but that was in itself cool. As if we could get free Internet using satellites. Like, wow, man, that's cool, man. When would I use it? I don't know, man, but it's still cool. And those days are over. And that's a shame. That's a crying shame for the younger guys who never got to experience that. You know, the joy of just uh, finding something that you don't think about, like, oh shit, like, how much money can I make from this? It's more of like, hey, let me show some guys, because this is cool and this is interesting and isn't this peculiar, you know what I mean? Like this, see what I discovered, you know, I mean, like, this is cool, this is fun. Uh, and it wasn't so much about the bragging rights, which was at some point it was about the bragging rights and then now it's literally about the money.
Speaker B: So it's more about someone just sharing something, some cool technology, some cool hack that they found instead of just the monetary piece of it and kind of
Speaker A: walking you through the thought process, which is like, I don't think shown so much these days. Uh, people kind of like show the problem and, you know, how they approached it perhaps, and then exploit. But they don't really show their tool set and their, uh, thinking or you know, what exact the steps, like, you know, literally step by step, kind of like walking you through it, like where, as opposed to kind of like the earlier days, people would actually literally put in your hands, you know what I mean? The code and the methodology and how they got to where the solution, as in it's not just about the solution, but it's the thinking process behind it, the methodology. And I think that's really where the value is, you know, I mean, that's where the knowledge is. You know what I mean? Teaching somebody the trick behind the exploit, you know what I mean? Like, how exactly do you find it, how exactly you write it, and how did you discover it? Right? Like, what made you look in that direction to begin with? Right? What was the thing that kind of like jumped out at you that. That you notice that other people glossed over? Like, there's so many vulnerabilities these days that, like, you know, in open source software that have been there for like, God, Lord knows, it's like a decade or some shit, nobody found it. And it's like, major ass vulnerability. How the hell did you decide to download this package, look through it, and what is it about it that jumped out at you? Was it a fuzzing tool? Fuzzing toolchain? What is it? Is it like, what. What's the special sauce, bro? Like, nobody wants to share their knowledge. And that's a shape because it's actually like, you know, if I was a toolset author and I've written a whole bunch of like, nonsense scripts and shit, if somebody used it and made it better, I would want to know what they did to make it better and so that I could improve it myself. Uh, and so I feel like people are missing out on the kind of like, sharing the knowledge in order to move everybody forward rather than just, I win, everybody else just remain stagnant, which is the current status quo. Uh, it's a shame, you know what I mean? It used to be that we all move forward together, you know what I mean? I presented at a talk or whatever, and everybody else kind of gets access to it and does stuff with it and it's cool.
Speaker B: Yeah, that is very interesting. And so I know you've seen running conferences around the globe like you have before we started our, uh, uh, or recording the podcast you were talking about some people just writing out exploits, uh, of stuff within Notepad with very minimal tools and creating these really cool hacks and stuff. So if you wouldn't mind kind of explaining some of the things you've seen there.
Speaker A: Yeah, I mean, uh, so we're talking like early 2000s, right? So in fact, um, yeah, it was in 2003. HDMore was one of our first speakers that came to our first quote unquote international hang the box that we had in Malaysia. Uh, and he presented the metasploit framework as an idea, as in, it wasn't even like, you know what it is today, right, which is Rapid seven and blah, blah, blah, right? And it was just a framework. And, uh, he was poking and God, Lord knows what. I think we just did server 2003 or something like that. And he found a zero day in it, like live. He was just playing around with stuff, uh, at the CTF that we had and he found some vulnerability and we called Microsoft Malaysia and it was like, cool to see this in action. As in, like, he wasn't safeguarding it, he wasn't saying, oh, I'm going to use this to my own advantage and not share it. I found something cool. It's like, you know, you guys can't see about it. He was like, we were literally seeing discovery being made in person, as in like a bug hunter. Literally like hunting a hacker, doing what he does best. And it was awesome. Like, and so those early, uh, days, and then we had folks like from Vietnam who were playing cdf and they came. That Internet access for them came a little bit later. Uh, but they were writing exploit code in the terminal, like Shellcode, without using any kind of tool set or compiler or any shit. The guy was just writing like, hexa. And I'm like, what the fuck, man? How the fuck do you do that, man? How do you even read it? And it's like, you just read it. It's like English. I'm like, you are, uh, different. You and I are not the same, man. You are on some next level, bro.
Speaker B: Yeah, that's really cool to get to see that and see how things have evolved. So for someone that wanted to get into security research now, what would you recommend since things have changed so much over the years?
Speaker A: Uh, yeah, I don't know, man. Honestly, I would say don't. But if you really want to get into security research, uh, realize that, um, the methodologies and things that you're doing today, uh, fundamentals are probably still important, but essentially the approach to bug hunting is going to change so drastically. I mean, I'm talking AI, obviously, agentic AI, stuff like Expo, uh, you know, Hacker One number one leaderboard is now AI. So does that mean bug hunting is dead? You know what I mean? Like, why bother hunting bugs manually? Like, you know, people have been evolving obviously to write buzzing toolchains and stuff like that to help their workflow, and now AI is just the next iteration in it. So adopt the technologies now rather than later and kind of like imagine a new paradigm. You know what I Mean like that, uh, everything is agentic and essentially you are an orchestrator and you're not actually going to be hunting the bugs by yourselves like literally on the command line. That shit, those days are over bro. You're going to have like a uh, couple of agents and uh, specialized agents that are going to be able to surface certain bugs. Your job is to direct them so that you don't waste your tokens, which are going to be expensive at least for the time being. Right, because every context window in AI and how big the context window is and how big your, how much memory utilization you're using determines the cost of your request. Right? So if your prompt isn't succinct or if your instructions are not tight, sharp, if your agents are not, well fine tuned, you'll end up spending a lot. But essentially your job is not going to be actually running the fuzzing tools and writing the exploits for the offsets. You're going to have to be thinking bigger picture and how systems interconnect and how exploits can surface not because of a technicality, but usually because of a design flaw. Most often than not, uh, AIs might still be building most of the back end stuff, but there's still going to be humans connecting shit together and people inherently make mistakes. So that will be my advice.
Speaker B: Yeah, kind of thinking along the lines of that. Do you think using like AI to vibe code, do you think it's really going to drastically increase like the bugs and the insecurity out there?
Speaker A: I don't know about the bugs per se, although we have seen a lot of uh, examples recently about like, you know, certain apps and services, um, that have gotten compromised. And obviously the joke is that, oh, it must be a barcoded app. Uh, whether that's true or not, I would say to a certain extent, yes. If you have uh, somebody who is not a developer who doesn't understand the programmatic nature of computers in the sense that normally you as a programmer you would approach a program, a problem and chunk it as in like look at it in like smaller subsystems and smaller sub problems that need to be solved and kind of like a flow uh, of like top down or whatever it is and we would think of things in a logical manner. And as long as you uh, a designer or have developed software before, you probably will not encounter these vibe coded bugs because you would have prompted it in such a way that you would have been succinct in the fact that you would have taken into consideration that certain actions need to be Performed server side, not client side. So do not expose this API key. Do not you know the simple ass mistakes that an AI would make if you just ask for a poc, which is a completely different thing from a production app, like, sure, we're making it work in your laptop and like on your little small, you know, demo is all fine and well, but then pushing that code to production, that's where the problem becomes because it's like you're not thinking of like, well, what happens when RLS only takes care of the role, but you need access control to the column, then you need an app secret and you cannot use it in uh, a client side exposed API. It needs to be completely server side. Right? Shit like that. As in, if you've never encountered those problems before and you try and whiteboard something, then yeah, of course your app is going to be like hacked like day after tomorrow. You know what I mean? But you'll learn, so it's not the end of the world. Uh, you won't be the first person to get hacked anyway. So, you know, don't feel bad, you know, if shit breaks, just fix it. I think it's the more of, um, I think what makes hackers different from everybody else is resilience and our willingness to not give up and not say, oh, this shit doesn't go, so fuck this shit, I'm going to watch Netflix. But I choose it. Figuring it out and making it work. Right. I think that that sets us apart. As in, that's what makes us different. As in that's what makes hackers different. Right. Is that not giving up resilience?
Speaker B: Yes, it's that persistence for stubbornness. Because I got my start, start like a lot of folks in security and it. And I remember I'd be working and people say, you're really patient and said, no, I'm stubborn. It's like, I got to solve this problem.
Speaker A: Exactly. When somebody says it cannot be done, I'm like, hold my coffee. Are you sure? Let me try. You know, and I guess like, um, in a way, um, it's not that, that, that burn and that fire, I don't think it's dead. I do see that still alive in a lot of younger guys and a lot of like, you know, I've been to conferences in um, uh, uh, you know, Kazakhstan, for example. So, uh, and it's completely different vibe from anything that we have in Europe or North America or even in Asia. And like that fire of like, hold my beer, let me show you is still alive and well. So you know, I'm not, um, I'm still quite hopeful that, uh, that hacker spirit of like, you know, let me show you, and I don't believe you. And, you know, I'm going to try, Try myself just to satisfy my own curiosity. Maybe you're right, maybe you're wrong, it doesn't matter. But I'm going to try myself. And that, um, stubbornness or that resilience to learn something, even if it's like, quote unquote difficult, uh, is not dead. So that gives me a lot of hope.
Speaker B: Yeah, that's good. And one of the things I think that people should take in consideration is there's conferences are great, but there's also when the conferences are not going on, there's still community out there that you can share with and collaborate and learn from.
Speaker A: 100. And I think, like, you know, a lot of people shouldn't be so afraid of putting themselves out there, you know, I mean, like, now that I'm older, when I was younger, right? So a lot of times I would build something and I'll be like, nah, I'm not going to share this with anybody.
Speaker B: It's.
Speaker A: It's silly. You know what I mean? It's just a nonsense app, right? But, um, now I, I'm older and I don't give a. So I feel some nonsense happen. I just put it on GitHub anyway, right? And people downloaded the pocket and they started and they, they, they write to me and say, like, hey, you know, it was cool, it's good, you know, it helped me. Or like, you know, I, Whatever, I used it for something. Uh, and that to me in itself is, is worth, worth the effort then. You know what I mean? So don't prejudge what you're working on because to you, you've been, you're so deep in it and you're so entrenched in it that it seems simple. But to somebody else who's from the outside, like, we were talking earlier and you asked me, like, do you know much about IoT stuff? I was like, I know some. But like, you know, I'm not an expert, uh, because I don't spend that much time in that area. So for somebody who works in Iot, uh, they might be working on something and they'll be like, this is simple shit, bro. Like, everybody knows this, right? And like, I don't. So somebody else might not either. So, you know, just put it out there, upload a YouTube video, write a blog post, make a tweet, whatever it is, whatever, whatever, Floats your boat. Whatever medium that you think works best, uh, just share it. Because ultimately that's all there is. Man. Life is short. Don't silo stuff and don't keep stuff on your hard drive. Musicians always say, don't keep your music on your hard drive. Just release it, put it up on YouTube or uh, put it up wherever. Let people listen to it. And your job is not to decide whether people will like it or not. Your job is just to put it out there anyway. Because like, you know, where does the information come from anyway, right? Where does inspiration come from? Where does knowledge come from? Where do we find exploits? Right? Where does the ah, uh, I think this is where this would be how I'm going to solve this problem. Where does that inspiration come from? Who the fuck knows, man? But it comes from somewhere. But it certainly didn't come from side you. So take it, process it and put it back out is my take.
Speaker B: Yeah, I love your comments on the sharing thing because that's one of the things that we can do at any level beginner to, you know, someone that's been in this for a long time is sharing. Just sharing information. Doesn't matter because I used to, I learned so much from my students when I taught at Dallas College. I taught pen testing. You had people coming in brand new that they were finding new resources that some of us veterans didn't know about because we'd been in it for a while. We weren't looking for educational stuff, but they learn this stuff and share it with us all the way. And so that's one of the things I always like to share with people. Been doing this for a while. Don't underestimate the new folks. They're finding some really cool stuff.
Speaker A: Precisely. Like I was like getting into, we're talking about by coding, so I was getting into by coding stuff and like all these new frameworks and all of this new like, you know, I'm so I'm from like C, Cobol C. So like you know, old school PHP is probably the most quote unquote modern language that I've last coded in by hand, as in manually. Um, and then now it's Next JS and it's whatever the fuck Rails and you know, Redis and all sorts of other shit on top of it and super base and you're like, what the fuck is all this shit, man? And like so you know, having to learn something from scratch, it's like it's always interesting and so there's always something new to learn and like There's, I always feel like there's never, um, if you find something interesting, it's somebody else has probably, is probably going to encounter the same difficulty that you had as well, you know what I mean? And so if you can help somebody out and even if it seems trivial, you never really know the trickle on effect or, you know, like pebble in a lake effect or whatever it is. Right? Like as in the ripple effect. Right. Like, so what might happen from you, you just sharing that piece of knowledge and who you might meet and friends you might make. Um, so yeah, I think the younger generation just needs to kind of like share more. Don't care less, care less about what people think because honestly, people don't think about anything, you know, I mean, they don't think about you as much as you think. You're not the lead role in their life, man. You're only the lead role in your own life. So don't overthink it. Just like put stuff out there, you know, I mean, uh, I spoke to a bunch of university students in Kazakhstan and they were like, you know, so what do you think we should do next? And I'm like, what do you should do next? I'm like, well, whatever it is that's interesting to you today, it doesn't matter how basic it is or whatever it is, but whatever it is that you're kind of like, man, this is cool. And like, you know, I'm going to spend the next this weekend reading about it or learning about it, write a blog post about it or record a video if that's your medium and you like it. Record a TikTok if you like explaining it, because you'll probably end up realizing that you're actually absorbing the knowledge a lot better by trying to explain it to somebody else. And uh, if you surprise yourself like just by reading it, you might find out, oh yeah, I understand this shit. But when you try to explain it to somebody else and you have to try and recall all of the stuff that you read, you make connections to certain topics or certain areas or certain viewpoints that you might not have stumbled across just by passively reading it. Uh, so try that out and see how that works out for you would be my advice to them.
Speaker B: Great advice. It was great, uh, chatting with you today. It's been too long and hopefully we get to see each other in person again sometime soon. But thanks for, thanks for joining. And where can people find you?
Speaker A: Uh, well, you can follow me on Twitter. I'm at, uh, LeapDog. So L3T Dawg. Or you can search for my name, which has a very long Last name, on LinkedIn, and you can find me there. But essentially, if you try hard enough, you'll find me without much trouble.
Speaker B: Well, thanks again.
Speaker A: Uh, thank you for having me, brother. I hope to see you at Bangkok, uh, next year. And tell Chris you should come along as well, so, you know, go hang out together.
Speaker B: Will do.
Speaker A: Thanks, man. Take care, brother. Thanks a lot, man.
Speaker B: Thanks for joining us on this episode of the phosphorus IoT security podcast. If you enjoy the podcast, check out Phosphorus IO at, uh, Phosphorus IO. You can find more podcast episodes, white papers on IoT security, as well as blog posts and other information to help you secure your OT and IOT infrastructures.
Speaker A: Sam.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.