
Three Buddy Problem
Security Conversations
All episodes
Best episodes
Top 10 Three Buddy Problem Episodes
Goodpods has curated a list of the 10 best Three Buddy Problem episodes, ranked by the number of listens and likes each episode have garnered from our listeners. If you are listening to Three Buddy Problem for the first time, there's no better place to start than with one of these standout episodes. If you are a fan of the show, vote for your favorite Three Buddy Problem episode by adding your comments to the episode page.

Ep3: Dave Aitel joins debate on nation-state hacking responsibilities
Three Buddy Problem
07/05/24 • 64 min
The 'Three Buddy Problem' Podcast Episode 3: Former NSA computer scientist Dave Aitel (Immunity Inc., Cordyceps Systems) joins Juan Andres Guerrero-Saade for a frank discussion on the OpenSSH unauthenticated remote code execution vulnerability and the challenges around patching and exploitation, the CISA 'secure-by-design' pledge and its impact on software vendor practices, Microsoft lobbying and the CSRB report, and changing face of government's attempts at cybersecurity regulations.
We discuss the disruption caused by political changes and the potential implications for cybersecurity policies, impact from the Supreme Court Chevron ruling, security regulations and the challenges of writing laws for future technology, the role of CISA and its accomplishments, the debate around offensive cyber operations and the responsibility of companies like Google in addressing vulnerabilities.
The need for clear separation between counterterrorism and espionage operations is highlighted, as well as the importance of understanding both defensive and offensive perspectives.
- Costin Raiu is on vacation.
Links:
- Transcript (unedited, AI-generated)
- Qualys: Remote Unauthenticated Code Execution in OpenSSH
- CSRB report on Microsoft hack
- CISA secure-by-design pledge
- CCC Talk: Operation Triangulation
- Lawfare: Responsible Cyber Offense
- Google: Stop Burning Counterterrorism Operations
- Follow Dave Aitel on Twitter
- J. A. Guerrero-Saade on Twitter
- Costin Raiu on Twitter
- Follow Ryan Naraine (@ryanaraine) on Twitter
- LABScon - Security Research in Real Time

Kim Zetter, Journalist and Author
Three Buddy Problem
12/29/17 • 52 min
Award-winning security journalist and author Kim Zetter talks about her work tracking cyber-espionage campaigns, why she uses an old school cassette player to record sensitive interviews and the dramatic changes sweeping the security industry.
Links:

Wim Remes, CEO and Principal Researcher, Wire Security
Three Buddy Problem
07/23/18 • 40 min
Founder and CEO of Wire Security, Wim Remes, joins the podcast to discuss the intricacies of penetration testing, red-teaming, bug bounty programs, and calls for defenders to embrace continuous pen-testing.
Links:

Jaime Blasco, AT&T Cybersecurity
Three Buddy Problem
04/14/20 • 31 min
AT&T Cybersecurity's Jaime Blasco talks about falling in love with security as a high-school student in Spain, finding a career path in pen-testing and offense, shifting to building defensive technologies and his current passion for exploring the value of machine learning.
Links:

Andy Greenberg, Senior Writer, Wired
Three Buddy Problem
08/11/20 • 59 min
Cybersecurity journalist and author Andy Greenberg joins the podcast to talk about his career as a journalist, the ins-and-outs of negotiating a big story with sources, the intricacies of writing a good book, and some of his biggest stories to date.
Links:

Andrew Morris, Founder and CEO, GreyNoise Intelligence
Three Buddy Problem
05/31/18 • 37 min
Founder and CEO of GreyNoise Intelligence Andrew Morris (andrew___morris) talks about his “anti threat-intelligence” company, the ways SOCs are using it to filter through scanning noise and the trials and tribulations of bootstrapping a start-up.
https://securityconversations.com/wp-content/uploads/2018/05/andrew_morris.mp3Links:

Collin Mulliner, Security Engineer, Cruise
Three Buddy Problem
04/04/20 • 33 min
Mobile security pioneer Collin Mulliner talks about the early days of hacking PalmOS devices, the current state of smartphone platforms, his work on securing self driving cars, and why he built and open-sourced a firmware analyzer tool.
Links:
- Firmware Analyzer — FwAnalyzer is a tool to analyze (ext2/3/4), FAT/VFat, SquashFS, UBIFS filesystem images, cpio archives, and directory content using a set of configurable rules.
- Collin's blog
- PDF: Continuous Automated Firmware Security Analysis

Tim MalcomVetter, Red Team Lead, Walmart
Three Buddy Problem
05/05/20 • 59 min
[ DISCLAIMER: These are the personal opinions of Tim MalcomVetter and do not construe an official endorsement or business relationship of his employer with any product or service. ]
Walmart Red Team lead Tim MalcomVetter joins the podcast to talk about red-team/blue team dynamics, the adversarial relationship between the two sides, the mentality of a determined attacker, and why everyone in cybersecurity should give jiu-jitsu a try.
Links:

Dan Hubbard, Chief Security Architect, Lacework
Three Buddy Problem
07/16/18 • 38 min
Lacework Chief Security Architect Dan Hubbard joins the podcast to discuss his new research on container security, the challenges of securing cloud deployments, and why technological advancements have widened attack surfaces.
Links:

A half-dozen Microsoft zero-days, Juniper router backdoors, advanced bootkit hunting
Three Buddy Problem
03/14/25 • 125 min
Three Buddy Problem - Episode 38: On the show this week, we look at a hefty batch of Microsoft zero-days exploited in the wild, iOS 18.3.2 fixing an exploited WebKit bug, a mysterious Unpatched.ai being credited with Microsoft Access RCE flaws, and OpenAI lobbying for the US to ban China's DeepSeek.
Plus, discussion on a Binarly technical paper with new approach to finding UEFI bootkits, Mandiant flagging custom backdoors on Juniper routers, and MEV 'sandwich attacks' front-running cryptocurrency transactions.
Cast: Juan Andres Guerrero-Saade, Costin Raiu and Ryan Naraine.
Links:
- Transcript (unedited, AI-generated)
- Microsoft Flags Six Active Zero-Days, Patches 57 Flaws
- Unpatched.ai discoveries
- Apple Ships iOS 18.3.2 to Fix Already-Exploited WebKit Flaw
- Apple iOS 18.3.2 and iPadOS 18.3.2 documentation
- Citizen Lab: Predator in the wires
- FreeType Zero-Day Being Exploited in the Wild
- CVE-2020-15999: FreeType Heap Buffer Overflow
- Mandiant : Ghost in the Juniper router
- Jun OS out-of-cycle security bulletin (CVE-2025-21590)
- Juniper Malware Removal Tool
- Binarly: UEFI Bootkit Hunting -- In-Depth Search for Unique Code Behavior
- Crypto Trader Loses $215,000 in MEV Sandwich Attack on Uniswap
- The Secretive World Of MEV, Where Bots Front-Run Crypto Investors For Big Profits
- Reuters journalist Raphael Satter loses overseas citizenship
- Yanis Varoufakis: Trump’s tariff chaos explained
- Technofeudalism: What Killed Capitalism (Yanis Varoufakis)
Show more best episodes

Show more best episodes
FAQ
How many episodes does Three Buddy Problem have?
Three Buddy Problem currently has 159 episodes available.
What topics does Three Buddy Problem cover?
The podcast is about News, Information Security, Security, Infosec, Research, Tech News, Hacking, Podcasts, Technology and Cybersecurity.
What is the most popular episode on Three Buddy Problem?
The episode title 'Unpacking the UK government's secret iCloud backdoor demand' is the most popular.
What is the average episode length on Three Buddy Problem?
The average episode length on Three Buddy Problem is 56 minutes.
How often are episodes of Three Buddy Problem released?
Episodes of Three Buddy Problem are typically released every 7 days.
When was the first episode of Three Buddy Problem?
The first episode of Three Buddy Problem was released on Dec 6, 2017.
Show more FAQ

Show more FAQ