Welcome to Experience Points by University XP hosted by Dr. Dave Eng. On Experience Points we explore different ways we can learn from games. Find out more at www.universityxp.com I hope you find this show useful. If you’d like to learn more about games-based learning then a great place to start is my blog at universityxp.com/blog. University XP is also on Twitter @University_XP and on Facebook as University XP. Feel free to email me anytime at [email protected] Game on!
…
continue reading
Dave Eng Podcasts
It takes more than great code to be a great engineer. Soft Skills Engineering is a weekly advice podcast for software developers about the non-technical stuff that goes into being a great software developer.
…
continue reading
A behind the scenes podcast where we visit with farmers and learn what it takes to be a sustainable produce grower across the triple bottom line of people, profits and our planet.
…
continue reading
Are we ready for the future of work? 1Huddle’s original podcast series tackles all things jobs, innovation, and future of work. Hear from CEOs, coaches, educators, elected officials, entrepreneurs, and startups as they share their experiences, perspective, and advice for today's workforce. Ready to get to work?
…
continue reading
The Three Buddy Problem is a popular Security Conversations podcast that goes beyond industry talking points to discuss what others won’t -- nation-state malware, attribution, cyberwar, ethics, privacy, and the messy realities of securing computers and corporate networks. Hosted by three veteran security pros -- journalist Ryan Naraine and malware paleontologists Costin Raiu and Juan Andres Guerrero-Saade -- the weekly show attracts a highly engaged audience of security researchers, corporat ...
…
continue reading
1
OpenAI’s Dave Aitel talks Aardvark, economics of bug-hunting with LLMs
2:10:48
2:10:48
Play later
Play later
Lists
Like
Liked
2:10:48Three Buddy Problem - Episode 70: Dave Aitel from OpenAI's technical staff joins the buddies to discuss the just-launched Aardvark, OpenAI’s agentic “security researcher” that claims to read code, finds bugs, validates exploits, and ships patches. We press him on where LLMs beat fuzzers, privacy boundaries, human-in-the-loop realities, SDLC budgets…
…
continue reading
1
Episode 484: How to get a raise after slacking off for YEARS and my PM won't stop DM'ing me
29:27
29:27
Play later
Play later
Lists
Like
Liked
29:27In this episode, Dave and Jamison answer these questions: Hi! Love your show and how casually you talk and make fun of everything! I started my career as a freelancer and then joined a mid-size software development company to learn how the sausage is really made, salary wasn’t that important back then. A few kids and a lot more expensive lifestyle …
…
continue reading
1
Apple’s iOS forensics freeze, WhatsApp zero-click, China outs NSA
2:11:23
2:11:23
Play later
Play later
Lists
Like
Liked
2:11:23Three Buddy Problem - Episode 69: We dig into news that Apple's iOS 26 has quietly killed the shutdown.log forensic artifact used to spot signs of infections and what it means for threat hunters. Plus, whispers of a million-dollar WhatsApp zero-click exploit that never materialized at Pwn2Own, a surreal court case linking a Trenchant exploit develo…
…
continue reading
1
Episode 483: My team hated me from day one and should I stack PTO before my resignation
38:22
38:22
Play later
Play later
Lists
Like
Liked
38:22In this episode, Dave and Jamison answer these questions: How would you handle a situation where a team forms a negative opinion about you from day one — without any clear reason and without ever giving you a real chance to prove yourself? Even when you contribute technically, your suggestions are ignored… until someone else repeats the same thing …
…
continue reading
1
Josefine Schwarzer Applied Games and Mental Health
24:02
24:02
Play later
Play later
Lists
Like
Liked
24:02Josefine Schwarzer Applied Games and Mental Health In this episode of Experience Points, Dave Eng interviews Josefine Schwarzer, a German occupational therapist exploring how tabletop RPGs and LARPs support mental health. Josefine shares how role-play creates safe, expressive spaces that boost self-esteem and break from anxiety. She recounts client…
…
continue reading
1
JAGS LABScon 2025 keynote: Steps to an ecology of cyber
31:00
31:00
Play later
Play later
Lists
Like
Liked
31:00Three Buddy Problem (Episode 68): The buddies are trapped in timezone hell with cross-country travel this week. In this special episode, we present Juan Andres Guerrero-Saade's LABScon 2025 keynote-day presentation on the state of cybersecurity and why this phase of our collective project has failed, and how to build something smarter, more sustain…
…
continue reading
1
Long Island Landscaper to 20 Acres of Vegetables with Jon & Karin of Bear Roots Farm: EP34
1:29:59
1:29:59
Play later
Play later
Lists
Like
Liked
1:29:59Text me a message! Today’s episode comes to you from Williamstown Vermont where we visit with Jon Waner and Karin Bellemare of Bear Roots Farm and The Roots Farm Market. Together they’ve built up a 20 acre vegetable farm and local goods store in Central Vermont. Jon starts off by sharing how they got started in Long Island, and how they ramped up t…
…
continue reading
1
Episode 482: I got a promotion, but a tiny raise and an imposter interviewed for my team
31:47
31:47
Play later
Play later
Lists
Like
Liked
31:47In this episode, Dave and Jamison answer these questions: After a year of trying, I recently got promoted to staff engineer! It’s great to receive recognition for my work, but i’m not actually very happy, because I only got a 4% raise! I spoke with a former coworker about how much a staff engineer in my role should expect, and he said that he would…
…
continue reading
1
Apple Exploit-Chain Bounties, Wireless Proximity Exploits and Tactical Suitcases
2:23:02
2:23:02
Play later
Play later
Lists
Like
Liked
2:23:02Three Buddy Problem - Episode 67: We discuss the rise of automated red-teaming, Apple’s $2 million exploit chain bounties aimed at outbidding spyware brokers and the iPhone maker's focus on wireless proximity attacks and “tactical suitcase” Wi-Fi exploits. We also hit the news of Paragon spyware targeting European executives and the bizarre story o…
…
continue reading
1
Chris Eng on lessons learned from the NSA, @Stake, Veracode, and 20 years in cybersecurity
44:54
44:54
Play later
Play later
Lists
Like
Liked
44:54By Security Conversations
…
continue reading
1
Episode 481: I'm bored and will I ever find out why I was fired?
29:03
29:03
Play later
Play later
Lists
Like
Liked
29:03
…
continue reading
1
Michael Low and Luna Uni: A New World of RPG Writing Instruction
28:24
28:24
Play later
Play later
Lists
Like
Liked
28:24Michael Low and Luna Uni: A New World of RPG Writing Instruction In this episode of Experience Points, host Dave Eng welcomes Michael Low—educator, game designer, and creator of Stories RPG. Michael shares the powerful story behind Luna Uni, a tabletop role-playing curriculum that transforms writing instruction through collaborative storytelling. F…
…
continue reading
1
Oracle cl0p ransomware crisis, EU drone sightings, Cisco bootkit fallout
2:03:28
2:03:28
Play later
Play later
Lists
Like
Liked
2:03:28Three Buddy Problem - Episode 66: We discuss drone sightings that shut down airports across Europe and what they reveal about hybrid warfare and the changing nature of conflict; Oracle ransomware/extortion campaign tied to unpatched E-Business Suite vulnerabilities and the company’s muted response. Plus, the TikTok–Oracle deal and the strange role …
…
continue reading
1
Episode 480: Do I just coast until I quit and going back to work after a long time
27:09
27:09
Play later
Play later
Lists
Like
Liked
27:09In this episode, Dave and Jamison answer these questions: (follow-up from question 449) Hello. Return question asker here. You answered my question from episode 449 “my tech lead ignored my warnings”. I want to give a follow up. I sat by and did not say anything else, he shipped the broken feature, and it broke in production. Instead of fixing it h…
…
continue reading
1
Cisco firewall zero-days and bootkits in the wild
1:54:49
1:54:49
Play later
Play later
Lists
Like
Liked
1:54:49Three Buddy Problem - Episode 65: We zero in on one of the biggest security stories of the year: the discovery of a persistent multi-stage bootkit implanting malware on Cisco ASA firewalls. Details on a new campaign, tied to the same threat actors behind ArcaneDoor, exploiting zero-days in Cisco’s 5500-X series appliances, devices that sit at the h…
…
continue reading
1
Live at LABScon: Aurora Johnson and Trevor Hilligoss on China's 'internet toilets'
22:13
22:13
Play later
Play later
Lists
Like
Liked
22:13Three Buddy Problem - Episode 64: SpyCloud Labs researchers Aurora Johnson and Trevor Hilligoss discuss the world of “internet toilets," the toxic online communities in China where harassment, stalking, and sextortion thrive. We explore how these groups operate, from doxing ex-lovers and enemies to running coordinated campaigns of cyberbullying tha…
…
continue reading
1
Live at LABScon: Visi Stark shares memories of creating the APT1 report
28:50
28:50
Play later
Play later
Lists
Like
Liked
28:50Three Buddy Problem - Episode 63: Co-founder of the Vertex Project Visi Stark joins the buddies to reminisce about his work writing Mandiant's famous APT1 report, the China-nexus threat landscape, the value of cyber threat intelligence, APT-naming schemes, and more... (Recorded at LABScon 2025) Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Vis…
…
continue reading
1
Live at LABScon: Lindsay Freeman on tracking Wagner Group war crimes
31:52
31:52
Play later
Play later
Lists
Like
Liked
31:52Three Buddy Problem - Episode 62: Lindsay Freeman, Director of the Technology, Law & Policy program at the Human Rights Center, UC Berkeley School of Law, joins the show to discuss her team's meticulous work to document the Wagner Group's chain of command, military operations in parts of Africa, and the broadcasting of war crimes on social media pl…
…
continue reading
1
Episode 479: Contractors to the rescue and dinged for delay
34:57
34:57
Play later
Play later
Lists
Like
Liked
34:57In this episode, Dave and Jamison answer these questions: Hey skillet nation, long time skilletee first time skilleter here. I started at a scale up about 6 months ago and recently, I was asked to help with a project that was greatly behind schedule. The folks responsible for the original system are no longer at the company, and the team currently …
…
continue reading
1
Shaun McMillan on Turning Lectures into Games
30:13
30:13
Play later
Play later
Lists
Like
Liked
30:13Shaun McMillan on Turning Lectures into Games In this episode of Experience Points, host Dave Eng interviews educational game designer Shaun McMillan about transforming traditional lectures into interactive, game-like experiences. Shaun shares his framework for designing lectures around a single compelling multiple-choice scenario, enabling student…
…
continue reading
1
Mushrooms, Veggies, Meat and More! From Farmers Market to on Farm Cider House at 1000 Stone Farm: EP33
1:34:24
1:34:24
Play later
Play later
Lists
Like
Liked
1:34:24Text me a message! Today’s Episode comes to you from Brookfield Vermont where we visit with Kyle Dodda and Betsy Simpson of 1000 Stone Farm. They’ve got many balls in the air with a wide range of crops from veggies to perennial fruit, eggs and meat, hard cider and a restaurant. They sell retail out of a farmstore, wholesale, CSA & go to a farmers m…
…
continue reading
1
Episode 478: Can you coach self-awareness and my boss is an llm
38:18
38:18
Play later
Play later
Lists
Like
Liked
38:18In this episode, Dave and Jamison answer these questions: Can you coach self-awareness? I manage someone who seems to believe their skill set is on par with their teammates, regardless of their constant PR feedback regarding the same issues over and over, the extra attention they are regularly given to help them overcome coding challenges, and the …
…
continue reading
1
Can Apple's New Anti-Exploit Tech Stop iPhone Spyware Attacks?
2:45:46
2:45:46
Play later
Play later
Lists
Like
Liked
2:45:46Three Buddy Problem - Episode 61: We cover a pair of software supply chain breaches (Salesforce Salesloft Drift and NPM/GitHub) that raises big questions about SaaS integrations and the ripple effects across major security vendors. Plus, Apple’s new Memory Integrity Enforcement in iPhone 17 and discussion on commercial spyware infections and the va…
…
continue reading
1
Episode 477: Four months and I already hate my job and grumpy and fuzzy
37:51
37:51
Play later
Play later
Lists
Like
Liked
37:51In this episode, Dave and Jamison answer these questions: Hey guys, I have been working for four months at my job and I already don’t like it. This is my first job out of college and I work as a C# backend engineer for a small B2B SaaS company. I really think this company is a dead end. There is a lot of technical debt and antipatterns and we have …
…
continue reading
AP Table Talk: Take That In this episode of AP Table Talk, Brian and Dave dig into the “Take That” game mechanic. From classics like UNO, Sorry!, and Risk to modern favorites like Munchkin, Blood Rage, and King of Tokyo: Duel, they explore how denial, betrayal, and revenge fuel tension, drama, and unforgettable tabletop stories. If you liked this e…
…
continue reading
1
Episode 476: How much help is too much help and guarding against slop
37:36
37:36
Play later
Play later
Lists
Like
Liked
37:36In this episode, Dave and Jamison answer these questions: Two junior engineers recently joined my team, and I’ve been tasked with onboarding them. This is the first time I’ve been responsible for junior devs, and I’m struggling with how to coach them up. For context, we’re a small engineering team where self-sufficiency is highly valued; processes/…
…
continue reading
1
Salt Typhoon IOCs, Google floats ‘cyber disruption unit’, WhatsApp 0-click
2:24:48
2:24:48
Play later
Play later
Lists
Like
Liked
2:24:48Three Buddy Problem - Episode 60: We dissect a fresh multi-agency Salt Typhoon advisory (with IOCs and YARA rules!), why it landed late, why the wall of logos matters (and doesn’t), and what’s actually usable for defenders: new YARA, tool hashes, naming ambiguity across reports, the mention of Chinese vendors, and a Dutch note that smaller ISPs wer…
…
continue reading
1
Episode 475: Am I too loyal to my big tech job and politely preserving time
33:26
33:26
Play later
Play later
Lists
Like
Liked
33:26In this episode, Dave and Jamison answer these questions: Hi! I’m currently working for a big tech company and I’ve just accepted an internal transfer to another team. At the same time, an external company reached out, offering me a job for a role I’m interested in and twice my current compensation. I’m not sure what to do. The offer from the new c…
…
continue reading
Types of Games Today, we’re diving into something that might seem simple on the surface, but as it turns out, it's anything but. In this episode, we’re going to be talking about game types, and not just your usual categories like board games or video games. We’re digging deeper: into the psychology, the structure, and the social impact of how we pl…
…
continue reading
1
Zero-day reality check: iOS exploits, MAPP in China and the hack-back temptation
2:32:15
2:32:15
Play later
Play later
Lists
Like
Liked
2:32:15Three Buddy Problem - Episode 59: Apple drops another emergency iOS patch and we unpack what that “may have been exploited” language really means: zero-click chains, why notifications help but forensics don’t, and the uncomfortable truth that Lockdown Mode is increasingly the default for high-risk users. We connect the dots from ImageIO bugs to geo…
…
continue reading
1
Episode 474: I hate the idea of firing a low performer and cheaper context switching
38:04
38:04
Play later
Play later
Lists
Like
Liked
38:04In this episode, Dave and Jamison answer these questions: Hi Dave & Jamison, Long time listener, first time google-form filler outer! I work in a hybrid role as a lead developer and manager of a small team (less than 5). I’m new to management and most of ny experience so far has been with smart, motivated engineers. . . UNTIL! My new recruit is dri…
…
continue reading
1
On AI’s future, security’s failures, and what comes next...
1:57:44
1:57:44
Play later
Play later
Lists
Like
Liked
1:57:44Three Buddy Problem - Episode 58: The buddies react to the Brandon Dixon episode, digging into what it’s really like to scale products inside a tech giant, navigate politics, and bring features to millions of machines. Plus, an exploration of the AI cybersecurity gold rush, the promise and hype, and the gamble for startups versus the slow-moving ad…
…
continue reading
1
Episode 473: Mental health support and overcoming FOMO of taking a break from work
35:59
35:59
Play later
Play later
Lists
Like
Liked
35:59In this episode, Dave and Jamison answer these questions: Hi Jamison and Dave! I am not a developer, but my question is hopefully transferable. I sit in between lawyers and developers. I advise on technology that can be applied to legal processes and I support our teams in using a range of platforms and AI tools to be more efficient across their wo…
…
continue reading
1
Ercan Altug Yilmaz Gamification in Action The TOY Framework
22:00
22:00
Play later
Play later
Lists
Like
Liked
22:00Ercan Altug Yilmaz Gamification in Action The TOY Framework In this episode, Dave Eng interviews Ercan Altuğ Yilmaz, a leading gamification expert and creator of the TOY Framework—an evolution of existing models like Werbach’s D6 and Octalysis. Drawing from over a decade of experience and 100+ projects, Yilmaz explains how TOY’s ten-step structure …
…
continue reading
1
Live from Black Hat: Brandon Dixon parses the AI security hype
1:30:14
1:30:14
Play later
Play later
Lists
Like
Liked
1:30:14Three Buddy Problem - Episode 57: Brandon Dixon (PassiveTotal/RiskIQ, Microsoft) leads a deep-dive into the collision of AI and cybersecurity. We tackle Google’s “Big Sleep” project, XBOW’s HackerOne automation hype, the long-running tension between big tech ownership of critical security tools and the community’s need for open access. Plus, the fu…
…
continue reading
1
Episode 472: Should my junior dev use AI and thrown in to ETL
26:59
26:59
Play later
Play later
Lists
Like
Liked
26:59In this episode, Dave and Jamison answer these questions: I’m the CTO of a small startup. We’re 3 devs including me and one of them is a junior developer. My current policy is to discourage the use of AI tools for the junior dev to make sure they build actual skills and don’t just prompt their way through tasks. However I’m more and more questionin…
…
continue reading
1
Enjoying Retirement While Still Living on the Farm with Dave Pierson of Pierson Farm: EP32
1:08:10
1:08:10
Play later
Play later
Lists
Like
Liked
1:08:10Text me a message! Today’s Episode comes to you from Bradford Vermont where we visit with David Pierson of Pierson Farm. After 42 years of running a mixed vegetable farm to supply a roadside farm stand, with 3 acres of strawberries being one of the big draws, he was able to retire, leasing the farm to a long time employee Dan. We start off the epis…
…
continue reading
1
Rethinking APT Attribution: Dakota Cary on Chinese Contractors and Espionage-as-a-Service
1:51:42
1:51:42
Play later
Play later
Lists
Like
Liked
1:51:42Three Buddy Problem - Episode 56: China-focused researcher Dakota Cary joins the buddies to dig into China’s sprawling cyber ecosystem, from the HAFNIUM indictments and MSS tasking pipelines to the murky world of APT contractors and the ransomware hustle. We break down China’s “entrepreneurial” model of intelligence collection, why public visibilit…
…
continue reading
1
Episode 471: Why does my junior engineer do so little and I fell asleep in a Zoom meeting
28:34
28:34
Play later
Play later
Lists
Like
Liked
28:34In this episode, Dave and Jamison answer these questions: I’m a senior developer on a small team, and I’m feeling frustrated with a junior developer I work with. They’re smart and perfectly capable, but they stick very strictly to the confines of their assigned work. They’ll finish their tickets, but unless they’re directly asked, they don’t offer …
…
continue reading
Games as Mediums for Interactions In today’s episode, we’re diving into how games function as mediums for interaction: as art, as social spaces, and as powerful tools for learning. We’ll explore everything from virtual worlds to tabletop classics and even some of the more unexpected ways games impact real life. If you liked this episode please cons…
…
continue reading
1
Microsoft Sharepoint security crisis: Faulty patches, Toolshell zero-days
1:55:13
1:55:13
Play later
Play later
Lists
Like
Liked
1:55:13Three Buddy Problem - Episode 55: A SharePoint zero-day exploit chain from Pwn2Own Berlin becomes a full-blown security crisis with Chinese nation-state actors exploiting vulnerabilities that Microsoft struggled to patch properly, leading to trivial bypasses and a cascade of new CVEs. The timeline is messy, the patches are faulty, and ransomware gr…
…
continue reading
1
Episode 470: I said something stupid in a meeting and just want to code
30:12
30:12
Play later
Play later
Lists
Like
Liked
30:12In this episode, Dave and Jamison answer these questions: I was on a meeting with a team generally regarded to be pretty annoying to deal with and not particularly useful. The meeting was pretty annoying and not particularly useful. I audibly said to myself after leaving “holy crap what a waste of time.” Turns out I hadn’t left and may not have bee…
…
continue reading
1
Train brake hack, GRU sanctions, Wagner war crimes, Microsoft's Chinese ‘digital escorts’
1:48:45
1:48:45
Play later
Play later
Lists
Like
Liked
1:48:45Three Buddy Problem - Episode 54: Europol busted pro‑Russian hacktivist crew NoName 057(16), the Brits announce sanctions on Russia’s GRU cyber units, Wagner‑linked “war influencers” streamed atrocities from Africa, and fresh tech worries ranged from a $500 RF flaw that can hijack U.S. train brakes. Plus, ProPublica on Microsoft’s China‑based “digi…
…
continue reading
1
Episode 469: Passed over for lead role and perhaps I'm the jerk
35:53
35:53
Play later
Play later
Lists
Like
Liked
35:53In this episode, Dave and Jamison answer these questions: I’m a long time listener to the podcast. Thanks for reading and answering my question! I have over 20+ yrs experience as a manual QA and 6+ yrs experience as a SDET. I’m in a new role as a hybrid manual QA / SDET for a company that hasn’t had QA for a few years. After a couple of months a ne…
…
continue reading
Game Goals vs Learning Outcomes In this episode, we’ll explore how learning objectives and game goals overlap, how serious games are designed for impact, and how we measure success beyond just ‘winning.’ So, buckle up—because today, we’re unlocking the next level of game-based learning! If you liked this episode please consider commenting, sharing,…
…
continue reading
1
How did China get Microsoft's zero-day exploits?
1:49:05
1:49:05
Play later
Play later
Lists
Like
Liked
1:49:05Three Buddy Problem - Episode 53: We dig into news of the first-ever arrest of a Chinese intelligence-linked hacker in Italy, unpack the mystery behind HAFNIUM and how they somehow got their hands on the same Microsoft Exchange zero-days that researcher Orange Tsai discovered - was it coincidence, inside access, or something more sinister? Plus, Ch…
…
continue reading
1
Episode 468: Should I take a mini-retirement and doubling down on anachronisms
31:12
31:12
Play later
Play later
Lists
Like
Liked
31:12In this episode, Dave and Jamison answer these questions: Hi Dave and Jamison, Long-time listener, first-time question asker. Thank you both for the wisdom, perspective, and jokes you bring to the podcast. I recently received an inheritance of around $500,000. It’s not “quit your job and buy a yacht” money, but it is enough to reshape my life. I’m …
…
continue reading
1
Increasing Acreage & Narrowing the Crop Mix with John Hirsch at Clearfield Farm: EP31
1:47:50
1:47:50
Play later
Play later
Lists
Like
Liked
1:47:50Text me a message! Today’s episode comes from Granville Vermont where we visit with John Hirsch of Clearfield Farm. With over 10 years under his belt he’s refined his farm business to be lean on labor and focused in scope as his primary crops are wholesale carrots and potatoes. He’s also excited to be getting into grain and doing more intensive rot…
…
continue reading
1
Who’s hacking who? Ivanti 0-days in France, China outs 'Night Eagle' APT
1:34:16
1:34:16
Play later
Play later
Lists
Like
Liked
1:34:16Three Buddy Problem - Episode 52: Fresh intelligence reports out of Europe and China: France’s ANSSI documents a string of Ivanti VPN zero-days ('Houken'), and Quanxin frames a stealth Microsoft Exchange-zero-day chain linked to a North American 'Night Eagle' threat actor. We dissect the technical bread-crumbs, questions the attribution math, and c…
…
continue reading
1
Episode 467: I can't get promoted if I do my job and should I get a degree to get a job in this economy
40:52
40:52
Play later
Play later
Lists
Like
Liked
40:52In this episode, Dave and Jamison answer these questions: I am a data scientist and was recently passed over for promotion to senior because my projects weren’t “senior level” enough, and I do too many ad hoc requests that delay delivery of my bigger projects. I am a go to for VP and C suite level execs in my company and am commonly asked to help w…
…
continue reading