Gary McGraw

The Silver Bullet Security Podcast

with Gary McGraw

Sponsored by Cigital and IEEE Security & Privacy

Show 028 - An Interview with Bill Cheswick

July 15th, 2008

Bill Cheswick

On the 28th episode of The Silver Bullet Security Podcast, Gary interviews Bill Cheswick, a lead member of technical staff at AT&T Research and all around security guru. Bill has been working in computer security for over 35 years. He coined the term “proxy” in 1990 with reference to firewalls, and co-authored the book Firewalls and Internet Security which was used to train an entire generation of sys admins. Gary and Bill discuss whether we’re winning or losing the computer security war, how security threats have evolved from pimply-faced teenagers to organized crime, whether we should move security into “the cloud,” and whether re-naming “Christmas lights” to “solstice lights” would bypass NJ holiday decoration ordinances.

 
icon for podpress  Show 028 - An Interview with Bill Cheswick [23:59m]: Play Now | Play in Popup | Download

Show 027 - An Interview with Gunnar Peterson

June 18th, 2008

Gunnar Peterson

On the 27th episode of The Silver Bullet Security Podcast, Gary interviews software security expert Gunnar Peterson, a Managing Principal at Arctec Group. Gary and Gunnar begin with the age-old question, “What is security?” They go on to discuss how Web 2.0 and SOA security is progressing, the big idea behind “federated identity,” whether all market verticals can follow the software security lead of the financial services industry, and the inherent badness of the color purple.

 
icon for podpress  Show 027 - An Interview with Gunnar Peterson [27:56m]: Play Now | Play in Popup | Download

Show 026 - An Interview with Adam Shostack

May 15th, 2008

Adam Shostack

The 26th episode of The Silver Bullet Security Podcast features Adam Shostack, a security expert on Microsoft’s Secure Development Lifecycle team who has also worked for Zero Knowledge and Reflective. Gary and Adam discuss how Adam got started in computer security, how art/literature informs Adam’s current work, and the main ideas behind Adam’s new book The New School of Information Security. They go on to chat about Adam’s aversion to the term “best practices,” the role IEEE Security & Privacy magazine plays in bringing the science of security to a practical level, and whether the biggest problem of the CardSystems breach was the following the letter, rather than the spirit, of PCI. Also on the agenda, duck-billed platypuses, Kandinski, and books by Pynchon.

(Beginning with this episode, Silver Bullet will be available as a 192k MP3.)

 
icon for podpress  Show 026 - An Interview with Adam Shostack [30:12m]: Play Now | Play in Popup | Download

Show 025 - An Interview with Jon Swartz

April 18th, 2008

Jon Swartz

Jon Swartz, USA Today’s award-winning technology reporter and Pulitzer Prize nominee, is Gary’s guest on the 25th episode of The Silver Bullet Security Podcast. They discuss Jon’s new book, Zero Day Threat: The Shocking Truth of How Banks and Credit Bureaus Help Cyber Crooks Steal Your Money and Identity and the research that went into writing it. Gary and Jon also cover how cybercrime is driven by capitalist principals, why the general public’s attitude is so lax about software security, and how, even though it’s hard to get an accurate count of identity theft instances, they tend to show a sharp upward trend. Jon ends the episode by disclosing his secret dream career.

(Apologies for the below-average sound quality on this episode.)

 
icon for podpress  Show 025 - An Interview with Jon Swartz [27:49m]: Play Now | Play in Popup | Download

Show 024 - An Interview with Mary Ann Davidson

March 14th, 2008

Mary Ann Davidson

Oracle Chief Security Officer Mary Ann Davidson is the guest on the 24th episode of The Silver Bullet Security Podcast. Gary and Mary Ann discuss how an MBA helps in the CSO role, Oracle’s “Unbreakable” campaign, why everyone needs training in secure coding, and how military history informs computer security. They also talk about how a young CSO-to-be got her first library card.

 
icon for podpress  Show 024 - An Interview with Mary Ann Davidson [28:45m]: Play Now | Play in Popup | Download

Show 023 - An Interview with Chris Wysopal

February 19th, 2008

Chris Wysopal

On the 23rd episode of The Silver Bullet Security Podcast, Gary talks with Chris Wysopal, founder and CTO of Veracode and author of The Art of Software Security Testing. Chris was one of the seven original members of the L0pht hacker collective (operating under the hacker handle Weld Pond) and later went on to work for @stake. Gary and Chris reminisce about L0pht (and the warehouse full of stuff) and discuss the role of security researchers now versus in the mid-late ’90s. They also talk about the current state of the software security market and its continued growth.

 
icon for podpress  Show 023 - An Interview with Chris Wysopal [24:48m]: Play Now | Play in Popup | Download

Show 022 - An Interview with Ed Amoroso

January 23rd, 2008

Ed Amaroso

On the 22nd episode of The Silver Bullet Security Podcast, Gary interviews Ed Amoroso, Chief Information Security Officer of AT&T. They discuss how Peter Neumann influenced Ed, the difference between bugs and flaws and whether bugs are getting too much attention, the propensity for confusion around how security actually works, privacy, security, and monitoring, and software correctness/quality vs software security. They also discuss the Hugh Thompson show now airing on AT&T’s Tech Channel.

 
icon for podpress  Show 022 - An Interview with Ed Amoroso [32:25m]: Play Now | Play in Popup | Download

Show 021 - A Panel Discussion with Cigital’s Principals

December 21st, 2007

Cigital Logo

For the 21st episode of The Silver Bullet Security Podcast, Gary hosts a panel discussion with Cigital’s principals. Participants include Sammy Migues (Director of Training and Knowledge Management), John Steven (Principal Consultant) and Pravir Chandra (Principal Consultant). The group discusses the best ways for large companies to get started with software security and the similarities between CLASP, Microsoft’s SDL, and the Security Touchpoints. They also ponder how much the security testing burden should fall on QA and whether developing expertise in architectural risk analysis or threat modeling is more helpful. John Steven also discusses the hole in his dining room, which threat modeling would not have helped to prevent.

 
icon for podpress  Show 021 - A Panel Discussion with Cigital's Principals [23:35m]: Play Now | Play in Popup | Download

Happy Holidays from Silver Bullet

December 21st, 2007

Get the Flash Player to see this player.

Show 020 - An Interview with Markus Jakobsson

November 16th, 2007

Markus Jakobsson

For the landmark 20th episode of The Silver Bullet Security Podcast, Gary interviews Markus Jakobsson, soon to be a reseacher at PARC after a stint as an Associate Professor of Informatics and associate director of the Center for Applied Cybersecurity Research at Indiana University. Gary and Markus discuss the difference between academic and corporate research, the idea of “perfect privacy,” moving from hardcore cryptography to sociology, how reality is mimicking phishers, and how cartoons can be used to teach security. In addition, Markus mentions the best place in Southeast Asia to get a haircut.

 
icon for podpress  Show 020 - An Interview with Markus Jakobsson [24:29m]: Play Now | Play in Popup | Download


Resources
> Overview
> Your Account
> Podcast
> Blog
> Case Studies
> White Papers
> Publications
> Books
> Security Articles
> Presentations

Silver Bullet Security Podcast

RSS

iTunes

PodcastAlley.com Feeds

Recent Entries
  • Show 028 - An Interview with Bill Cheswick
  • Show 027 - An Interview with Gunnar Peterson
  • Show 026 - An Interview with Adam Shostack
  • Shows
    0. Gary McGraw
    1. Avi Rubin
    2. Dan Geer
    3. Marcus Ranum
    4. Dana Epp
    5. Ed Felten
    6. Michael Howard
    7. John Stewart
    8. Brian Chess
    9. Bruce Schneier
    10. Fortify's TAB
    11. Dorothy Denning
    12. Becky Bace
    13. Ross Anderson
    14. Peter Neumann
    15. Annie Antón
    16. Greg Hoglund
    17. Eric Cole
    18. Eugene Spafford
    19. Mikko Hyppönen
    20. Markus Jakobsson
    21. Cigital's Principals
    22. Ed Amoroso
    23. Chris Wysopal
    24. Mary Ann Davidson
    25. Jon Swartz
    26. Adam Shostack
    N. Subscribe to IEEE S&P
    Promo

    Podcasters: download the Silver Bullet Podcast promo for your show (30 sec, 128k MP3).

    Credits

    Theme song "Zagreb" provided by The Cheebacabra

    Bullet photo provided by Pedro Saenz