

A Conversation with Jason Haddix @Jhaddix | Securing Bridges Podcast With Alyssa Miller | Episode 42
9 snips Jun 16, 2023
Cybersecurity expert, Jason Haddix, discusses transitioning from offensive security to leadership, the importance of bug bounty work, AI in offensive security, and the trend towards increased privacy awareness. The podcast also touches on the realities of the CISO role and the skills needed beyond technical expertise.
AI Snips
Chapters
Transcript
Episode notes
Prioritization for CISOs
- CISOs should prioritize external-to-internal attacks and user protection.
- If a CISO isn't technical, they should have a skilled person nearby for guidance.
Ubisoft Interview
- Jason Haddix got the CISO job at Ubisoft by doing thorough reconnaissance on their external landscape.
- He presented a threat model of their business and even found hardcoded credentials on GitHub.
AI in Bug Bounties
- Jason Haddix used AI during a bug bounty to analyze source code and find API endpoints that didn't require authentication.
- He fed code to the AI, which identified endpoints needing authentication tokens.