Search a title or topic

Over 20 million podcasts, powered by 

Player FM logo
Artwork

Content provided by Dave Lewis, 1Password and Dave Lewis. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Dave Lewis, 1Password and Dave Lewis or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Chasing Entropy Podcast 022: Michael Farnum on building security communities & navigating agentic AI

36:40
 
Share
 

Manage episode 508059255 series 3662462
Content provided by Dave Lewis, 1Password and Dave Lewis. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Dave Lewis, 1Password and Dave Lewis or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

From a tank driver in the Gulf War to the founder of one of the U.S.’s largest regional cybersecurity conferences, Michael Farnum’s journey is a study in discipline, community, and curiosity. He shares how early exposure to cryptography, BASIC programming pranks, and first encounters with firewalls led him into security.

We dive into how Farnum built the Houston Security Conference (HOU.SEC.CON) from 120 attendees in 2010 into a 3,000-person international event
He also discusses the rapid rise of agentic AI, what excites him, and the risks of unauthenticated MCP servers, shaky credential governance, and invisible AI triggers. Despite looming challenges, Farnum is optimistic that security conversations are starting earlier this time around.

He closes with timeless advice: don’t be overly cautious, advocate for your value and take the smart risks you might otherwise pass up.

Key Takeaways

  • Military lessons: Encryption mishaps in the Gulf War taught discipline, planning, and after-action reviews that later informed his cybersecurity mindset
  • The hook into security: First exposure to a Unix firewall showing live traffic convinced him this was the path to follow
  • Community builder: Founded HOU.SEC.CON to unite a fragmented Houston infosec scene; it has since grown into a national/international draw with thousands of attendees
  • AI & agentic AI: Rising volume of submissions at security conferences; risks include unauthenticated MCP endpoints, hidden triggers, and weak credential governance
  • CISO struggles:
    • Data security remains the #1 challenge—knowing what you have, where it is, and who can access it.
    • Application security continues to lag despite new tools.
    • Modern infrastructure & APIs can help if applied well.
    • AI-driven SOCs are already shifting MDR/MSSP models, often without customers realizing
  • Career advice: Be less cautious and ask for what you’re worth, take smart risks, and don’t undersell yourself
  continue reading

24 episodes

Artwork
iconShare
 
Manage episode 508059255 series 3662462
Content provided by Dave Lewis, 1Password and Dave Lewis. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Dave Lewis, 1Password and Dave Lewis or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

From a tank driver in the Gulf War to the founder of one of the U.S.’s largest regional cybersecurity conferences, Michael Farnum’s journey is a study in discipline, community, and curiosity. He shares how early exposure to cryptography, BASIC programming pranks, and first encounters with firewalls led him into security.

We dive into how Farnum built the Houston Security Conference (HOU.SEC.CON) from 120 attendees in 2010 into a 3,000-person international event
He also discusses the rapid rise of agentic AI, what excites him, and the risks of unauthenticated MCP servers, shaky credential governance, and invisible AI triggers. Despite looming challenges, Farnum is optimistic that security conversations are starting earlier this time around.

He closes with timeless advice: don’t be overly cautious, advocate for your value and take the smart risks you might otherwise pass up.

Key Takeaways

  • Military lessons: Encryption mishaps in the Gulf War taught discipline, planning, and after-action reviews that later informed his cybersecurity mindset
  • The hook into security: First exposure to a Unix firewall showing live traffic convinced him this was the path to follow
  • Community builder: Founded HOU.SEC.CON to unite a fragmented Houston infosec scene; it has since grown into a national/international draw with thousands of attendees
  • AI & agentic AI: Rising volume of submissions at security conferences; risks include unauthenticated MCP endpoints, hidden triggers, and weak credential governance
  • CISO struggles:
    • Data security remains the #1 challenge—knowing what you have, where it is, and who can access it.
    • Application security continues to lag despite new tools.
    • Modern infrastructure & APIs can help if applied well.
    • AI-driven SOCs are already shifting MDR/MSSP models, often without customers realizing
  • Career advice: Be less cautious and ask for what you’re worth, take smart risks, and don’t undersell yourself
  continue reading

24 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Copyright 2025 | Privacy Policy | Terms of Service | | Copyright
Listen to this show while you explore
Play