23 episodes

Access Control, a podcast providing practical security advice for startups.

Access Control Teleport

    • Technology
    • 5.0 • 3 Ratings

Access Control, a podcast providing practical security advice for startups.

    From SIEM to Detection as Code

    From SIEM to Detection as Code

    In this episode of Access Control, we dive deep into the evolving world of security information and event management (SIEM) with Jack Naglieri, founder and CTO of Panther. Jack shares his insights on transitioning from traditional SIEM systems to modern, cloud-native approaches that leverage detection-as-code.

    Key topics include:

    - The importance of intentionality in security operations
    - Benefits of detection-as-code for governance, collaboration, and scalability
    - Challenges of monitoring diverse cloud environments and SaaS tools
    - Strategies for effective alert prioritization and reducing alert fatigue
    - Cost considerations and selling points for modernizing SIEM systems

    Jack emphasizes the need for a focused approach to security, starting with identifying an organization's most critical assets and potential threats. He discusses how detection-as-code can improve efficiency, collaboration, and adaptability in security teams.

    Whether you're a seasoned security professional or new to the field, this episode offers valuable insights on modernizing security operations for today's cloud-centric world. Join us for a thought-provoking discussion on the future of SIEM and practical tips for enhancing your organization's security postur

    • 28 min
    Certificates, Keys, and Trust: The World of PKI and mTLS.

    Certificates, Keys, and Trust: The World of PKI and mTLS.

    In this episode of the Access Control Podcast, Ben Arent sits down with Ben Burkert and Chris Stolt, the founders of Anchor Security, to discuss the challenges of managing internal TLS and how private CAs can help simplify the process.
    Ben and Chris share their experiences dealing with certificate-related outages and the frustrations that led them to start Anchor. They provide an in-depth look at the evolution of web cryptography, from the early days of SSL to the modern era of TLS and the impact of Let's Encrypt and the ACME protocol.
    The conversation also covers the benefits of using private CAs for internal PKI, including shorter certificate lifetimes, enhanced security, and improved developer experience. Ben and Chris introduce Anchor's new tool, lcl.host, which streamlines local TLS setup for developers.
    Throughout the episode, Ben and Chris offer practical advice for teams looking to implement internal PKI and MTLS, including best practices for certificate hierarchy design, tips for getting started, and the importance of testing your incident response and key rotation processes.
    Whether you're a developer, ops engineer, or security professional, this episode provides valuable insights into the world of internal TLS and how private CAs can help you secure your infrastructure more effectively. Tune in to learn from Anchor's experts and discover how to simplify your internal PKI management.

    • 49 min
    Securing the Open-source Future

    Securing the Open-source Future

    'Access Control,' where we explore the intricate landscape of cryptography and cybersecurity with our esteemed guest, Filippo Valsorda, a distinguished cryptography engineer and an influential open source maintainer.

    For this 21st episode of Access Control Podcast, a podcast providing practical security advice for startups, Director of Developer Relations at Teleport Ben Arent chats with Filippo Valsorda. Filippo is a cryptography engineer and open-source maintainer. From 2018 to 2022, he worked on the Go Team at Google and was in charge of Go Security. In 2022, he became a full-time open source maintainer and still maintains the cryptography packages that ship as part of the Go Standard library along with maintaining a set of cryptographic tools, such as mkcert, and the file encryption tool, Age. This episode covers cryptography, trust, security and open source.

    • 58 min
    From Orange Book to Identity-Native

    From Orange Book to Identity-Native

    A live interview with Ev Kontsevoy about the history of access controls and the future of identity-native infrastructure access.

    • 41 min
    University Access Control

    University Access Control

    is an enlightening podcast that delves into the world of the Open Computing Facility (OCF) at UC Berkeley. In this episode, the General Manager of OCF provides a detailed overview of the organization and its various roles, including running several software mirrors in the Bay Area.

    The discussion touches upon the mechanism of how users are automatically opted into the nearest geographical mirror and elaborates on the myriad other services that the lab supports. A significant portion of the conversation is dedicated to the open source projects run by the OCF, with a specific focus on the core services.

    The General Manager discusses the key infrastructure and security concerns faced by the organization, and how they employ open-source Teleport to address these issues. The podcast delves into the ongoing migration from the legacy tech stack to Teleport, highlighting the anticipated benefits of this transition.

    Listeners gain insights into the process by which OCF prioritizes which technology services to offer to the UC Berkeley community. The episode also shares success stories of how these services have positively impacted the community.

    Looking ahead, the General Manager sheds light on the potential evolution of the OCF, exciting new initiatives, and what might be next for them post-Berkeley. The podcast concludes with practical advice for other university labs and startups to improve access control, making this episode a must-listen for those interested in open computing and technology management in an academic setting.

    • 19 min
    Multi-Layered Security

    Multi-Layered Security

    For this 18th episode of Access Control Podcast, a podcast providing practical security advice for startups, Developer Relations Manager at Teleport Ben Arent chats with Yash Kosaraju. Yash is Chief Security Officer at SendBird. Sendbird's mission is to build connections in a digital world, providing APIs and services for chat products with API and tools to integrate into apps. This episode dives into how teams can build multi-layered security systems to go beyond zero-trust to let teams do their work but also provide checks

    • 32 min

Customer Reviews

5.0 out of 5
3 Ratings

3 Ratings

Top Podcasts In Technology

Acquired
Ben Gilbert and David Rosenthal
All-In with Chamath, Jason, Sacks & Friedberg
All-In Podcast, LLC
Lex Fridman Podcast
Lex Fridman
Hard Fork
The New York Times
The Vergecast
The Verge
TED Radio Hour
NPR