More VDP Chats & AI Bias Bounty Strats with Keith Hoodlet (Ep. 71)

แชร์
ฝัง
  • เผยแพร่เมื่อ 1 มิ.ย. 2024
  • Episode 71: In this episode of Critical Thinking - Bug Bounty Podcast Keith Hoodlet joins us to weigh in on the VDP Debate. He shares some of his insights on when VDPs are appropriate in a company's security posture, and the challenges of securing large organizations. Then we switch gears and talk about AI bias bounties, where Keith explains the approach he takes to identify bias in chatbots and highlights the importance of understanding human biases and heuristics to better hack AI.
    Follow us on twitter at: / ctbbpodcast
    We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io
    Shoutout to / realytcracker for the awesome intro music!
    ====== Links ======
    Follow your hosts Rhynorater & Teknogeek on twitter:
    / 0xteknogeek
    / rhynorater
    ====== Ways to Support CTBBPodcast ======
    Hop on the CTBB Discord at ctbb.show/discord!
    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
    Sign up for caido.io/ using the referral code CTBBPODCAST for a 10% discount.
    Today’s guest: Keith Hoodlet
    securing.dev/
    Resources:
    Daniel Miessler's article about the security poverty line:
    danielmiessler.com/p/the-cybe...
    Hacking AI Bias:
    securing.dev/posts/hacking-ai...
    Hacking AI Bias Video:
    • Hacking AI Bias with H...
    Sarah's Hoodlet's new book:
    sarahjhoodlet.com
    Link to Amazon Page:
    a.co/d/c0LTM8U
    Timestamps:
    (00:00:00) Introduction
    (00:04:09) Keith's Appsec Journey
    (00:16:24) The Great VDP Debate Redux
    (00:47:18) Platform/Hunter Incentives and Government Regulation
    (01:06:24) AI Bias Bounties
    (01:26:27) AI Techniques and Bugcrowd Contest
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 9

  • @jonathanfillion7890
    @jonathanfillion7890 16 วันที่ผ่านมา +9

    The VPDs are made for poor companies not having the budget to invest in security, that is it. Not for mega corporations to have budget security.

  • @Hack0day-ye2tz
    @Hack0day-ye2tz 16 วันที่ผ่านมา +10

    O come on. When a big company talks about VDP, this is really disgusting. I really hate when they lie

  • @Khal_Rheg0
    @Khal_Rheg0 16 วันที่ผ่านมา +7

    I love the podcast, but I really hate it when billion dollar companies rely on charity for security. They disserve to get ransomeware-ed to bankruptcy. Maybe other companies might think twice on cutting corners when hiring cybersec people.

  • @lowkey_ssh
    @lowkey_ssh 16 วันที่ผ่านมา +4

    boo the vdp hunters,.. simple...

  • @jonathanfillion7890
    @jonathanfillion7890 16 วันที่ผ่านมา +2

    Status: Destroyed

  • @MFoster392
    @MFoster392 16 วันที่ผ่านมา

    Great podcast i agree with you guys I've been following the debate on X

  • @surfersdoit
    @surfersdoit 16 วันที่ผ่านมา +1

    Whooo love these