DiscoverYou Gotta Hack That
You Gotta Hack That
Claim Ownership

You Gotta Hack That

Author: You Gotta Hack That

Subscribed: 7Played: 76
Share

Description

Felix explores Internet of Things (IoT) and Operational Technology cyber security. Perfect for project managers, developers, and those learning about penetration testing in this niche area.

Email Felix using [email protected]
Get more information at the website: yougottahackthat.com
Find You Gotta Hack That on LinkedIn and X @gotta_hack
31 Episodes
Reverse
Nerds vs suits

Nerds vs suits

2026-02-2521:36

In this episode of You Gotta Hack That, Felix sits down with Alex Ward to unpack the real gap in OT security, nerds versus suits. They dig into why “good enough” thinking persists, how risk gets lost in translation between engineers and the board, and why signing off risk can focus minds fast. They also get into the uncomfortable bits, safety, insider threats, and why recovery and business continuity often matter as much as prevention in industrial environments. Expect blunt talk, practical framing, and a few war stories from the OT frontline.
From carbon-copy receipts and zip-zap machines to mag stripes, chip and PIN, contactless and mobile wallets, payment tech keeps evolving, and attackers evolve right alongside it. Felix sits down with Gareth, a payments industry veteran of 30 years, to unpack the real hardware attack surface: skimmers in stripe readers, ATM overlays, contactless relay tricks, and why static QR codes are basically begging to be abused. They also dig into why raising contactless limits changes theft economics, how phone theft turns into credential theft, and why the EU Cyber Resilience Act means you need to think about hardware security now.
In this episode, Felix is joined by Anjan, a cybersecurity engineer working at the sharp end of OT product security and compliance in UK manufacturing. They dig into what it really looks like to build security into connected industrial kit, especially with major regulation deadlines looming. Anjan shares a practical path into the industry, starting with bug bounty and vulnerability disclosure, then moving into IoT and OT during his Masters, including work on an autonomous vehicle project. Expect honest talk on “audit equals secure” myths, risk-based security, and how to start building an OT security career.
In this episode, Felix continues his conversation with David Rogers (Copper Horse) about the latest State of Vulnerability Disclosure report and why “what counts as IoT” is messy. They explore how consumer devices end up everywhere (including factories), how category labels can become compliance loopholes, and why good vulnerability disclosure needs more than a generic support page. David also shares concerns about the EU Cyber Resilience Act drifting toward tick-box compliance, and what that could mean for product security teams and, ultimately, all of us. Plus: the report’s dataset is open for anyone to check.
In the first of this two-part episode, Felix is joined by David Rogers (Copper Horse) to unpack a surprisingly powerful way to measure IoT security: vulnerability disclosure policies. David shares what eight years of research reveals about how easy (or impossible) it can be for security researchers to report flaws. We discuss why the lack of a clear route to report vulnerabilities to a vendor is an “insecurity canary” and how security researchers and businesses struggle to get along without enabling easy communications on these topics. We dig into the results from the Copper Horse annual report, the impact of new regulation, and why retailers might be the hidden force improving the market. Plus: the long tail of ultra-cheap devices, and why security shouldn’t be a luxury.
loading
Comments