Visualização de leitura

AMA: I'm Larry Pesce. 20+ years of IoT and wireless hacking, software supply chain security, SANS course author, and Paul's Security Weekly. Ask me anything!

Hey r/cybersecurity!

I'm Larry Pesce, VP of Services at Finite State. I've spent the last two decades-plus breaking (and then helping fix) the things most people don't think of as computers: medical devices, cars, industrial control systems, IP cameras, routers, and basically anything with a radio or a debug header.

A quick rundown of what I've been up to over the years:

  • Hardware and firmware hacking. Pulling firmware off devices via JTAG, UART, SPI, and chip-off, reverse engineering it, and finding the bugs vendors hoped nobody would look for. I recently led the vulnerability disclosure for a consumer IP camera that shipped with some genuinely wild supply chain issues baked into its cloud stack.
  • Wireless security. This is where I got my start. I co-author SANS SEC617 (Wireless Penetration Testing and Ethical Hacking) and SEC556 (IoT Penetration Testing), and I've spent a lot of hours in parking lots with antennas that raised questions from security guards.
  • Software supply chain security. These days a huge part of my work is helping device manufacturers understand what's actually inside their firmware: third-party components, SBOMs, VEX, vulnerability reachability, and navigating regulations like the EU Cyber Resilience Act and FDA premarket requirements. Spoiler: most vendors don't know what's in their own products.
  • Podcasting. I've been part of Paul's Security Weekly for over 20 years. If you've listened at any point since the early 2000s, you've probably heard me ramble about hardware hacking, wireless shenanigans, or whatever device I'd taken apart that week.
  • Community. DEF CON, Black Hat, BSides, GIAC certs, a few books on networking and open source security tools, and a lot of time mentoring folks trying to break into offensive security.

Why am I doing this AMA?

Honestly, because the intersection of IoT, supply chain, and regulation is getting genuinely interesting right now. The CRA is coming, SBOMs are moving from buzzword to requirement, and the gap between "we make a connected product" and "we understand our connected product's security" is still enormous. I think there's a lot worth discussing, and I always learn something from these threads too.

One line on my $DAYJOB since the rules ask for it: Finite State does binary firmware analysis and product security services for connected device manufacturers. I've spent the last 20 years giving back to the community through sharing what I know: That's it, no pitch. I'm here to talk shop.

Ask me anything about:

  • IoT and embedded device hacking (hardware, firmware, or both)
  • Wireless security, past and present
  • Software supply chain security, SBOMs, VEX, and the regulatory wave (CRA, FDA, etc.)
  • Vulnerability disclosure and dealing with vendors
  • Careers in offensive security and pentesting
  • 20+ years of security podcasting and how the community has changed

I'll be answering questions today, September 8th, 2026 roughly during business hours on the East coast of the US - I will keep checking in during the evening, and I would encourage questions over the next few days for those of you all over the planet. Fire away!

Transparency note per the AMA guidelines: I may use generative AI to help polish some longer answers, but the experiences, opinions, and war stories are all mine.

submitted by /u/Disastrous-Brush1327
[link] [comments]

One man team

I'm the sole cybersecurity person for mid-size local government municipality (around 600 users), came in about 8 months ago. Landscape here is pretty wild west…minimal governance, no real established program but slowly building it out. I’m running EDR/NDR, a firewall/log platform, email security, and phishing awareness training (all different platforms) while also owning policy development, policy gap analysis (establishing NIST CSF 2.0 framework), risk assessments, audits and quarterly reporting to leadership.

It’s a lot of work and something always loses. Policy work in particular keeps getting bumped because incidents/investigations always outrank it in the moment. The problem isn't any one part of the job.. i can do investigations, I can write policy, I can run the security tools, I can build training programs. I actually enjoy those things…The problem is all of it landing on my desk at the same time. I honestly am starting to question if I’m even good at my job because I can’t make it all work.

Questions for anyone who's been here:

-If you've been a solo practitioner..how did you actually prioritize across investigation, GRC, tooling, and training without letting any one of them rot?

-Is this genuinely a "normal growing pain" for a first year solo, or a sign to run..

Not looking for sympathy, just want to know if I'm missing a better way to run this!

submitted by /u/ComfortableYou333
[link] [comments]

Code analysis methodology

Hello everyone.

After a few years in the auditing/pentesting world, I identified that I am lacking experience on the code analysis topics.

Unfortunately when pentesting/auditing, I seldom had the time to look at the code of the applications I am auditing due to time constraints as the white-box approach we take does not systematically include an access to the Gitlab of the entities I audit.

I would like to avoid being overwhelmed by an eventual audit of source code of an entreprise-grade application that I might have to do.

Would any of you share you code audit methodology ?

By that, I mean how do you tackle the following topics :

- Secure coding / Best coding practices

- Secure secret management of the app

- For very large codebase, what types of tools do you use to automate some of your work ?

- What specific things in your checklist do you look for systematically ? (Do include the "obvious" one like how authentication is handled)

I know the subject is quite broad and dependent of the tech-stack used for each case.

Thank you for reading. :)

submitted by /u/RozPetal
[link] [comments]

Confusion between data analyst and SOC analyst

22M, from New Delhi INDIA.

I am studying to be a SOC analyst, but freshers aren't getting jobs as SOC analysts, and in cybersecurity they also say certificates hold value, so I am thinking of pivoting myself to a data analyst role.

Can someone tell me how fresher jobs are in both SOC analyst and data analyst roles, because I am having this doubt that there is a huge crowd in data analyst but freshers manage to get jobs, whereas in SOC analyst the crowd is slightly lower, but getting a job as a fresher is very difficult? Please help.

submitted by /u/XORDION69
[link] [comments]

How a PortSwigger lab turned into a 15-hour investigation and exposed a silent bug in the BApp Store's #1 extension (JWT Editor).

How a PortSwigger lab turned into a 15-hour investigation and exposed a silent bug in the BApp Store's #1 extension (JWT Editor).

Hey everyone,

Have you ever followed a lab walkthrough perfectly, word for word, and it still failed?

I recently spent 5 hours refusing to accept that "it just doesn't work." What started as a stuck lab turned into a fifteen-hour investigation, a silent bug, and a GitHub issue against the #1 most popular extension (JWT Editor) in the Burp Suite BApp Store as of today.

I wrote a full deep-dive into the methodology, how I tracked this silent bug down to its root cause, how to bypass it, and how the investigation ultimately led to the maintainer releasing a new version fixing the problem.

And how I reached out to PortSwigger directly to highlight that their official lab solution is broken, pushing them to update their documentation so others don't fall into the same trap.

If you enjoy debugging, reverse-engineering, and the mindset of not taking "it happens because it happens" for an answer, I’d love for you to read the full journey here:

https://RivenX173.medium.com/when-burp-extension-breaks-lab-b5bce69fc89a

Let me know your thoughts!

submitted by /u/RivenX173_
[link] [comments]

Should access review changes go through normal ticketing, or is the review spreadsheet enough evidence?

Fairly large org, some high-risk systems. To get access (or a change to access) requires a ticket and approval from your manager/

  1. Separately, we run access reviews twice a year:
  2. Reviewer sends the current access list (Excel) to managers.
  3. Managers markup changes, e.g. "user left, remove access" or "needs modified access."
  4. Reviewer makes those changes directly on the system.
  5. Question: During these reviews should managers (or the reviewer, on their behalf) raise a proper ticket for these changes and note the ticket number on the sheet, rather than the markup alone on the excel sheet triggering the change?
  6. My take: yes, the manager should raise a ticket as ultimately it is a change request. However, I do accept the spreadsheet does show a manager requested a change.
  7. How do others handle this, same ticket/approval workflow as normal requests, or is the review sheet treated as sufficient on its own?
submitted by /u/Efficient_Bus_923
[link] [comments]

Random app files that dont show up as actual apps

This is probably a stupid question but I’m asking just to be safe, since I’m new to the whole online privacy thing. But when I look on MiX and DevCheck it shows me files like AigcService, Adreno graphics drivers, android.qvaoverlay.common, basic daydreams, ect. (I could write down the whole list but it’s a lot) I’m assuming these are normal system apps but i just wanna make sure i didn’t accidentally download a virus, because I have been downloading a few apps/games from somewhat trusted websites, but I checked them in virustotal, and I have sophos and bitdefender downloaded. They do show the possibly unwanted apps threat but I only see the stuff I know I downloaded in there.

I’m so sorry if this is a ridiculous question but I just wanna make sure I didn’t accidentally download something bad. Please don’t answer with jokes if it was a stupid question :)

Edit: IM ON ANDROID BTW!!!

submitted by /u/Sweaty_Ad_5400
[link] [comments]
❌