AMA: I'm Larry Pesce. 20+ years of IoT and wireless hacking, software supply chain security, SANS course author, and Paul's Security Weekly. Ask me anything!
Hey r/cybersecurity!
I'm Larry Pesce, VP of Services at Finite State. I've spent the last two decades-plus breaking (and then helping fix) the things most people don't think of as computers: medical devices, cars, industrial control systems, IP cameras, routers, and basically anything with a radio or a debug header.
A quick rundown of what I've been up to over the years:
- Hardware and firmware hacking. Pulling firmware off devices via JTAG, UART, SPI, and chip-off, reverse engineering it, and finding the bugs vendors hoped nobody would look for. I recently led the vulnerability disclosure for a consumer IP camera that shipped with some genuinely wild supply chain issues baked into its cloud stack.
- Wireless security. This is where I got my start. I co-author SANS SEC617 (Wireless Penetration Testing and Ethical Hacking) and SEC556 (IoT Penetration Testing), and I've spent a lot of hours in parking lots with antennas that raised questions from security guards.
- Software supply chain security. These days a huge part of my work is helping device manufacturers understand what's actually inside their firmware: third-party components, SBOMs, VEX, vulnerability reachability, and navigating regulations like the EU Cyber Resilience Act and FDA premarket requirements. Spoiler: most vendors don't know what's in their own products.
- Podcasting. I've been part of Paul's Security Weekly for over 20 years. If you've listened at any point since the early 2000s, you've probably heard me ramble about hardware hacking, wireless shenanigans, or whatever device I'd taken apart that week.
- Community. DEF CON, Black Hat, BSides, GIAC certs, a few books on networking and open source security tools, and a lot of time mentoring folks trying to break into offensive security.
Why am I doing this AMA?
Honestly, because the intersection of IoT, supply chain, and regulation is getting genuinely interesting right now. The CRA is coming, SBOMs are moving from buzzword to requirement, and the gap between "we make a connected product" and "we understand our connected product's security" is still enormous. I think there's a lot worth discussing, and I always learn something from these threads too.
One line on my $DAYJOB since the rules ask for it: Finite State does binary firmware analysis and product security services for connected device manufacturers. I've spent the last 20 years giving back to the community through sharing what I know: That's it, no pitch. I'm here to talk shop.
Ask me anything about:
- IoT and embedded device hacking (hardware, firmware, or both)
- Wireless security, past and present
- Software supply chain security, SBOMs, VEX, and the regulatory wave (CRA, FDA, etc.)
- Vulnerability disclosure and dealing with vendors
- Careers in offensive security and pentesting
- 20+ years of security podcasting and how the community has changed
I'll be answering questions today, September 8th, 2026 roughly during business hours on the East coast of the US - I will keep checking in during the evening, and I would encourage questions over the next few days for those of you all over the planet. Fire away!
Transparency note per the AMA guidelines: I may use generative AI to help polish some longer answers, but the experiences, opinions, and war stories are all mine.
[link] [comments]