Log in

mnemonic security podcast - Hack my (hard-coded) heart
share icon

Hack my (hard-coded) heart

mnemonic security podcast

03/09/20

29m

About

Comments

Featured In

In this episode, we chat with the former Head of the SOC at the Norwegian National CERT, and current member of mnemonic’s Threat Intelligence team. She also happens to have a personal interest in the "Internet of Things" and medical devices.

In 2011, Marie Moe received a pacemaker to help her heart maintain a consistent beat. As a security researcher, she felt the need to do her homework and figure out everything she could about the device that had newly been introduced to her body. What she found prompted her to join the "I Am The Cavalry" group, an organisation focusing on the impact computer security has on public safety and human life, which since then has lead a revolution in the medical device industry.

Technical level: 1/5
Host: Robby Peralta
Producer: Paul Jæger
Show notes:

Hippocratic Oath for Connected Medical Devices: https://www.iamthecavalry.org/domains/medical/oath/

Software Transparency and the SBOM multistakeholder process at the US NTIA: https://www.ntia.doc.gov/SoftwareTransparency

New EU regulations for medical devices: https://ec.europa.eu/growth/sectors/medical-devices/new-regulations_en

Send us Fan Mail

Previous Episode

In this episode, we chat with the CISO of consumer goods conglomerate Orkla - Antonio Martiradonna.
In 2017, he accepted the task of building up a security organisation to secure 300 brands, helping us to keep food in our fridges and beauty products in our bathrooms. In our conversation, we discuss the following:

· How it has been to build a security organization from the ground up

· How to work with the governance of so many brands

· Security around the physical production of products

Technical level: 1/5
Host: Robby Peralta
Producer: Paul Jæger

Send us Fan Mail

Next Episode

undefined - Bug Bounties and Unicorns
Bug Bounties and Unicorns

March 23, 2020

35m

In this episode, we speak with a security expert that is actually willing to pay money to "hackers" - the Product Security Director in Visma, Espen Johansen.
As you can imagine, eliminating software vulnerabilities in a company with 5,000 developers is no easy task. Mr. Johansen and his developers always aim to improve the security of their software, among other things through organising both private and public bug bounty programs. If you are interested in bug bounty programs, this interview is a great place to start! As he shares his advise for when and what it takes for an organisation to be ready for bug bounty.
Technical difficulty: 2/5
Host: Robby Peralta
Producer: Paul Jæger
Related reading:
https://hackerone.com/visma
https://www.visma.com/trust-centre/smb/security-and-privacy/operational/responsible-disclosure/
https://www.visma.com/trust-centre/smb/security-and-privacy/operational/responsible-disclosure/hall-of-fame/

Send us Fan Mail

Promoted