
Hosted by Paul Asadoorian
For the latest in computer security news, hacking, and research! We sit around, drink beer, and talk security. Our show will feature technical segments that show you how to use the latest tools and techniques. Special guests appear on the show to enlighten us and change your perspective on information security.
638 episodes · publishes weekly · latest 2026-07-02 · ~119 min/episode
Rank
#530
Substance
76.0
/ 100
Breakdown
Scored 2026-07
Updated monthly
Across the index
#530 of 6183
Substance
Top 9%
outscores 91% of the index
Paul's Security Weekly ranks #530 on The B2B Podcast Index with a substance score of 76.0 out of 100, scored across 1 recent episode. It scores highest on guest caliber and specificity & evidence. Sandy Bird is a genuine practitioner: co-founded Q1 Labs (became IBM QRadar), served as CTO of IBM Security for five years, and is now CTO of a cloud IAM startup - real at-scale operational experience. The segment is sponsor-funded, which limits candor, but Bird's domain depth is evident throughout.
Averaged across 1 recently scored episode, with cited evidence.
The episode contains genuinely useful technical material - particularly Sandy Bird's default-deny whitelist model using activity history, and Paul's detailed Fortibleed breakdown including the SHA-256/PBKDF2 upgrade nuance - but roughly half the runtime is consumed by banter, circular fundamentals debate, and tangents (Gaelic names, quantum hashing speculation, Larry's Gmail anecdote) that yield nothing actionable.
“we inverted the logic to basically restrict the privileged permissions at the global level. So everybody was denied. No one could create a vpc. No one could create a created access key...But we use the history to then make exceptions in those global policies for the things that needed them”
“it stores the SHA256/in the config somewhere in that storage post upgrade is only in the show full a uh, configuration backup...It does that because...you upgraded from 7 to 7 11, now you get the new password hashing algorithm. But something else broke and I need to revert”
Sandy Bird's historical-activity-based whitelist inversion and the automated quarantine concept are genuinely non-obvious product design choices, but the rest of the episode recycles standard security takes: patch your firmware, enable MFA, don't expose management interfaces, focus on fundamentals - all delivered without a contrarian or first-principles frame.
“instead of telling the developers, go fix the identity on the app, we used all this analytics to go back in history...we inverted the logic to basically restrict the privileged permissions at the global level”
“admin3 doesn't exist as a user account on a default like fortinet device...that's a backdoor account that threat actors added after they compromised a bunch of Fortinet devices”
Sandy Bird is a genuine practitioner: co-founded Q1 Labs (became IBM QRadar), served as CTO of IBM Security for five years, and is now CTO of a cloud IAM startup - real at-scale operational experience. The segment is sponsor-funded, which limits candor, but Bird's domain depth is evident throughout.
“I was one of the founders of a company called Q1 Labs many, many years ago...we ended up selling that to IBM. And when I moved over to IBM after the acquisition, I was the CTO of their security division for five years”
“92% of the identities in any cloud, the humans, the workloads, the AI agents are over privileged in every cloud”
The episode is well-stocked with concrete data: specific Fortinet version thresholds, named hashing algorithms, exact CVE counts and CVSS scores, scan statistics, and chipset model numbers. The Sandy Bird segment also provides named AWS policy primitives (SCPs, RCPs) and real product comparisons (Datadog, Wiz).
“versions prior to 7.2.11. 7.4.8 and 7.6.1. So before those versions you are storing passwords that are either SHA 256 hashed...Fortinet switched it so that the passwords are being hashed with PBKDF2”
“in less than a year there have been seven vulnerabilities in the Cisco Catalyst SDWAN family of products...Three of which are 10.0 on the CVSS”
The Sandy Bird interview is a soft, sponsor-driven PR chat with no meaningful pushback; Paul even volunteers personal anecdotes to fill airtime. The multi-host news discussion is livelier - Larry's question about whether proxy SDK functions are actually reachable is a genuine technical challenge - but the fundamentals debate runs in circles for many minutes with hosts largely agreeing with each other.
“Are the components for the proxy stuff actually reachable by any of the software in use or is it just present in the apps and they don't really get into that in the article?”
“Sandy, anything else you want to share with our audience?”
First period on the Index - history builds from here.
1 scored on substance · 61 tracked in total.
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/pauls-security-weekly-audio" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/pauls-security-weekly-audio/badge.svg" alt="Ranked #54 on The B2B Podcast Index" width="360" height="136" />
</a>Track Paul's Security Weekly's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.
Security Weekly Podcast Network
Security Weekly Productions
The Azure Security Podcast
Michael Howard, Sarah Young, Gladys Rodriguez and Mark Simos
AI Proving Ground Podcast
World Wide Technology: Artificial Intelligence Experts
Secure & Simple
Dejan Kosutic
401 Access Denied
Delinea
AI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop
ClearTech Research / Jo Peterson