The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
#168Security Cryptography Whatever81.8 / 100Get badge
← The Index
Security Cryptography Whatever artwork
Engineering & DevToolsNEW this period

Security Cryptography Whatever

Hosted by Deirdre Connolly, Thomas Ptacek, David Adrian

Some cryptography & security people talk about security, cryptography, and whatever else is happening.

65 episodes · publishes monthly · latest 2026-07-02 · ~64 min/episode

Rank

#168

Substance

81.8

/ 100

Breakdown

Scored 2026-07
Updated monthly

Engineering & DevTools rank

#25 of 289

Best B2B Engineering & DevTools Podcasts →

Across the index

#168 of 6182

Substance

Top 3%

outscores 97% of the index

Why it scores where it does

Security Cryptography Whatever ranks #168 on The B2B Podcast Index with a substance score of 81.8 out of 100, scored across 5 recent episodes. It scores highest on guest caliber and insight density. Nicholas Carlini is among the most credible guests possible for this topic - he has published extensively on adversarial ML and security, led this exact research at Anthropic, and demonstrated it in practice at scale. He speaks with hard-earned authority grounded in months of real-world experimentation, not abstract theorizing. Few people on earth have done this work at this depth.

The five-dimension breakdown

Averaged across 5 recently scored episodes, with cited evidence.

Insight Density

16.8 / 20

The episode is densely packed with concrete technical insights about LLM capabilities in vulnerability discovery - oracle design, constraint propagation in fuzzing, checksum generation, protocol-aware exploitation, and the asymmetry between finding and patching bugs. However, substantial portions involve methodological explanation and clarification that, while necessary, dilutes pure insight density.

“We have, I don't know, let's say, 10-line Bash script plus Docker container. I just sort of point it at the thing and be like, I've compiled this program with ASan. Please run against it, read the source code, and try to find a bug.”

“The thing that we've been finding most recently is you don't really have to try very hard.”

Originality

15.8 / 20

The work itself is original - demonstrating that minimal prompting (no special harnesses, no domain-specific scaffolding) on production models can find real zero-days at scale is genuinely novel. However, the framing around LLM capability improvement and the observation that 'scaling works' is now relatively well-trodden territory; the originality lies in the concrete execution and measurement, not the conceptual framework.

“the models have gotten good enough that you can do security, meaning use the models to help you with security”

“You don't really have to put in a huge amount of work, which is both good and bad.”

Guest Caliber

17.6 / 20

Nicholas Carlini is among the most credible guests possible for this topic - he has published extensively on adversarial ML and security, led this exact research at Anthropic, and demonstrated it in practice at scale. He speaks with hard-earned authority grounded in months of real-world experimentation, not abstract theorizing. Few people on earth have done this work at this depth.

“I used to do pen testing stuff and this was like the thing that got me into security in large part”

“I have walked through the trace of myself. I spun up the thing because I'm still very paranoid the model is just going to lie to me. I don't want to be the person generating AI slop.”

Specificity & Evidence

16.8 / 20

The episode is rich with named examples (Ghost CMS, Firefox, FFmpeg, Linux kernel NFS daemon) and specific metrics (122 crashing inputs to Mozilla with 100% true positive rate, 22 CVEs, 500 zero-days from OSS-Fuzz). However, some claims lack hard numbers - exact iteration counts vary ('20 times or something,' 'maybe 5 or 10 times'), token costs are dismissed rather than quantified, and generalization curves are acknowledged as unmeasured ('I don't have a very nice scientific plot yet').

“we sent Mozilla 122 crashing inputs and like they confirmed all of these are bugs. Like 100% of the things we crashed them, perfect true positive rate, all bugs”

“It found a SQL injection that goes, nice, an unauthenticated user who has literally no perms, who can compromise the admin database, mint themself a new admin account”

Conversational Craft

14.8 / 20

The hosts ask solid, probing follow-up questions (why stop iterating? how many passes before moving on? what changed between 4.5 and 4.6?) and push back on claims (asking about the generalizability of the approach, comparing to prior work). However, they occasionally let Carlini drift into lengthy explanations without interrupting for clarification, and some conversational threads peter out ('I thought I had more to say about that'). The dynamic is warm but could be tighter.

“I'm stuck on like, so first of all, I said there is like, there were some screenshots of the presentation”

“Do you have your own homegrown spidey sense of being a vulnerability researcher about which files you're like, all right, you've given it a pass or two, but like, I really want you to do like 5 or 10 passes”

Standout episodes

  • AI Finds Vulns You Can't With Nicholas Carlini

    2026-03-26

    100
  • Python Cryptography Breaks Up with OpenSSL with Paul Kehrer and Alex Gaynor

    2026-02-02

    100
  • Facing the Vulnpocalypse with lcamtuf

    2026-06-15

    95

Rank over time

First period on the Index - history builds from here.

Episodes

10 scored on substance · 60 tracked in total.

  • Trump's Golden Post-Quantum EO(s)

    2026-07-02 · 57 min

    80 / 100
  • Facing the Vulnpocalypse with lcamtuf

    2026-06-15 · 1h 11m

    95 / 100
  • AI Finds Vulns You Can't With Nicholas Carlini

    2026-03-26 · 1h 16m

    100 / 100
  • Standardizing Pure PQC

    2026-03-10 · 8 min

    27 / 100
  • Python Cryptography Breaks Up with OpenSSL with Paul Kehrer and Alex Gaynor

    2026-02-02 · 1h 13m

    100 / 100
  • The IACR Can't Decrypt with Matt Bernhard

    2025-12-31 · 57 min

    90 / 100
  • Apple’s Memory Integrity Enforcement

    2025-10-31 · 57 min

    78 / 100
  • Stop Using Encrypted Email with William Woodruff

    2025-08-23 · 1h 11m

    90 / 100
  • Alex Gaynor

    2025-08-16 · 1h 25m

    95 / 100
  • Vegas, Baby!

    2025-07-29 · 1h 1m

    70 / 100

Frequently asked

What is Security Cryptography Whatever's substance score?
Security Cryptography Whatever scores 81.8 out of 100 for substance and ranks #168 on The B2B Podcast Index. That puts it ahead of 97% of the B2B podcasts we rank and #25 of 289 in Engineering & DevTools. The score reflects insight density, originality, guest caliber, specificity and conversational craft across recent episodes - not downloads.
Is Security Cryptography Whatever worth listening to?
Yes - Security Cryptography Whatever outscores 97% of the B2B engineering & devtools podcasts and shows we rank on substance, so a engineering & devtools operator is likely to come away with something useful.
Who hosts Security Cryptography Whatever?
Security Cryptography Whatever is hosted by Deirdre Connolly, Thomas Ptacek, David Adrian.
How often does Security Cryptography Whatever publish?
Security Cryptography Whatever publishes monthly, has 65 episodes, released its most recent episode on 2026-07-02.
Which Security Cryptography Whatever episode should I start with?
Our highest-scoring recent episode is "AI Finds Vulns You Can't With Nicholas Carlini" (100/100) - a good place to start.

Show off your #25 rank in Engineering & DevTools

Add this badge to your site - it links back here and updates automatically as you rank.

Ranked #25 on The B2B Podcast Index
Embed code
<a href="https://index.fame.so/show/security-cryptography-whatever" target="_blank" rel="noopener">
  <img src="https://index.fame.so/badge/security-cryptography-whatever/badge.svg" alt="Ranked #25 on The B2B Podcast Index" width="360" height="136" />
</a>
Markdown & other formats →

Track Security Cryptography Whatever's rank

Get an email whenever this show moves up or down the Index. Monthly at most, no spam.

Listen / subscribe:WebsiteRSS

Frequently discusses

Companies, products and tools that come up most across this show's episodes.

Google · 5Chrome · 5Cloudflare · 2NIST · 2NSA · 2Apple · 2iOS · 2Firefox · 2Signal · 2Yubikey · 2WhatsApp · 2KyberFIPSCMVPAmerican Fuzzy LopBitcoinMythicXZ

Guests who've appeared

Alex Gaynor · 2lcamtuf (Michael Leski)Nicholas CarliniMr. Tom RiddlePaul KehrerMatt BernhardWilliam Woodruff

Topics this show covers

The themes that come up most across this show's episodes.

Post-Quantum Cryptography (PQC) · 2NIST FIPS standardsCNSA 2.0Elliptic curve discrete logarithm problemP-256 ECDSANeutral atom quantum computersCMVP (Cryptographic Module Validation Program)CAVP (Cryptographic Algorithm Validation Program)Store now decrypt later threatGoogle quantum computing researchAmerican Fuzzy Lop (AFL)Coverage-guided fuzzingLLM-powered vulnerability discoveryFrontier LabsAgent-based vulnerability discoveryMemory-safety vulnerabilitiesBrowser exploitation (Chrome, iOS, Safari)Zero-day economics

More Engineering & DevTools podcasts

See all →
  • Mik + One

    Dr. Mik Kersten: Author of Project to Product and Founder and CEO of Tasktop

    96.0
  • DevOps Daily with Fexingo

    Fexingo

    91.0
  • The Developer Tools Podcast with Fexingo

    Fexingo

    90.4
  • Rust in Production

    Matthias Endler

    90.0
  • mnemonic security podcast

    mnemonic

    88.8
  • Software Unscripted

    Richard Feldman

    88.0

Similar shows

Podcasts that dig into the same topics.

  • Secure & Simple

    Dejan Kosutic

    76.2
  • Shielded

    PQShield

    69.8
  • The Azure Security Podcast

    Michael Howard, Sarah Young, Gladys Rodriguez and Mark Simos

    81.0
  • Cybersecurity Today

    Jim Love

    61.0
  • Rust in Production

    Matthias Endler

    90.0
  • Security & GRC Decoded

    Raj Krishnamurthy

    88.2