<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>web02.fireside.fm</fireside:hostname>
    <fireside:genDate>Wed, 15 Apr 2026 12:44:30 -0500</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>Three Buddy Problem - Episodes Tagged with “Crypto”</title>
    <link>https://securityconversations.fireside.fm/tags/crypto</link>
    <pubDate>Fri, 04 Oct 2024 12:00:00 -0700</pubDate>
    <description>The Three Buddy Problem is a popular Security Conversations podcast that goes beyond industry talking points to discuss what others won’t -- nation-state malware, attribution, cyberwar, ethics, privacy, and the messy realities of securing computers and corporate networks. 
Hosted by three veteran security pros -- journalist Ryan Naraine and malware paleontologists Costin Raiu and Juan Andres Guerrero-Saade -- the weekly show attracts a highly engaged audience of security researchers, corporate defenders, CISOs, and policymakers.
&lt;a href="https://twitter.com/ryanaraine"&gt;Connect with Ryan on Twitter&lt;/a&gt; (Open DMs).
</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>A Security Conversations podcast</itunes:subtitle>
    <itunes:author>Security Conversations</itunes:author>
    <itunes:summary>The Three Buddy Problem is a popular Security Conversations podcast that goes beyond industry talking points to discuss what others won’t -- nation-state malware, attribution, cyberwar, ethics, privacy, and the messy realities of securing computers and corporate networks. 
Hosted by three veteran security pros -- journalist Ryan Naraine and malware paleontologists Costin Raiu and Juan Andres Guerrero-Saade -- the weekly show attracts a highly engaged audience of security researchers, corporate defenders, CISOs, and policymakers.
&lt;a href="https://twitter.com/ryanaraine"&gt;Connect with Ryan on Twitter&lt;/a&gt; (Open DMs).
</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/cover.jpg?v=15"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:keywords>cybersecurity, ciso, infosec, security, hacking, information security, research</itunes:keywords>
    <itunes:owner>
      <itunes:name>Security Conversations</itunes:name>
      <itunes:email>naraine@gmail.com</itunes:email>
    </itunes:owner>
<itunes:category text="Technology"/>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<itunes:category text="Technology"/>
<item>
  <title>Careto returns, IDA Pro pricing controversy, crypto's North Korea problem</title>
  <link>http://securityconversations.fireside.fm/tbp-ep15</link>
  <guid isPermaLink="false">dae2bdfe-9bc3-41af-88f1-c41782d35f84</guid>
  <pubDate>Fri, 04 Oct 2024 12:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/dae2bdfe-9bc3-41af-88f1-c41782d35f84.mp3" length="73939478" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem Episode 15: Juanito checks in from Virus Bulletin with news on the return of Careto/Mask, a ‘milk-carton’ APT linked to Spain. We also cover the latest controversy surrounding IDA Pro's subscription model, a major new YARA update, and ongoing issues with VirusTotal's value and pricing. The conversation shifts to North Korean cyber operations, particularly the infiltration of prominent crypto companies, Tom Rid's essay on Russian disinformation results, and the US government's ICE department using commercial spyware from an Israeli vendor.

Cast: Juan Andres Guerrero-Saade (SentinelLabs), Costin Raiu (Art of Noh) and Ryan Naraine (SecurityWeek).</itunes:subtitle>
  <itunes:duration>1:30:38</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/d/dae2bdfe-9bc3-41af-88f1-c41782d35f84/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 15:  Juanito checks in from Virus Bulletin with news on the return of Careto/Mask, a ‘milk-carton’ APT linked to Spain. We also cover the latest controversy surrounding IDA Pro's subscription model, a major new YARA update, and ongoing issues with VirusTotal's value and pricing. The conversation shifts to North Korean cyber operations, particularly the infiltration of prominent crypto companies, Tom Rid's essay on Russian disinformation results, and the US government's ICE department using commercial spyware from an Israeli vendor.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs) (SentinelLabs), Costin Raiu (https://twitter.com/craiu) (Art of Noh) and Ryan Naraine (https://twitter.com/ryanaraine) (SecurityWeek).
</description>
  <itunes:keywords>Virus Bulletin, Careto, HexRays, IDA Pro, Yara, VirusTotal, North Korea, Russia, crypto, spyware, Paragon</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 15</strong>:  Juanito checks in from Virus Bulletin with news on the return of Careto/Mask, a ‘milk-carton’ APT linked to Spain. We also cover the latest controversy surrounding IDA Pro&#39;s subscription model, a major new YARA update, and ongoing issues with VirusTotal&#39;s value and pricing. The conversation shifts to North Korean cyber operations, particularly the infiltration of prominent crypto companies, Tom Rid&#39;s essay on Russian disinformation results, and the US government&#39;s ICE department using commercial spyware from an Israeli vendor.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a> (SentinelLabs), <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> (Art of Noh) and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> (SecurityWeek).</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1UaVJw7KE2Bl1p1ftqiE5g_CvMXe91eqNfv1_pKAx9uY/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="VB abstract: The Mask has been unmasked again" rel="nofollow" href="https://www.virusbulletin.com/conference/vb2024/abstracts/mask-has-been-unmasked-again/">VB abstract: The Mask has been unmasked again</a></li><li><a title="Discover IDA 9.0" rel="nofollow" href="https://hex-rays.com/blog/discover-ida-9.0-exciting-new-features-and-improvements">Discover IDA 9.0</a></li><li><a title="Binary Ninja" rel="nofollow" href="https://binary.ninja/">Binary Ninja</a></li><li><a title="Vertex Synapse" rel="nofollow" href="https://vertex.link/synapse">Vertex Synapse</a></li><li><a title="YARA-X" rel="nofollow" href="https://virustotal.github.io/yara-x/">YARA-X</a></li><li><a title="Microsoft on Star Blizzard disruption" rel="nofollow" href="https://blogs.microsoft.com/on-the-issues/2024/10/03/protecting-democratic-institutions-from-cyber-threats/">Microsoft on Star Blizzard disruption</a></li><li><a title="Tom Rid: The lies Russia tells itself" rel="nofollow" href="https://archive.ph/ZCFqK">Tom Rid: The lies Russia tells itself</a></li><li><a title="North Korea caught targeting German missile manufacturer" rel="nofollow" href="https://www.securityweek.com/north-korea-hackers-linked-to-breach-of-german-missile-manufacturer/">North Korea caught targeting German missile manufacturer</a></li><li><a title="How North Korea infiltrated the crypto industry" rel="nofollow" href="https://www.coindesk.com/tech/2024/10/02/how-north-korea-infiltrated-the-crypto-industry/">How North Korea infiltrated the crypto industry</a></li><li><a title="ICE signs $2M contract with spyware maker Paragon" rel="nofollow" href="https://archive.ph/nCEjT">ICE signs $2M contract with spyware maker Paragon</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 15</strong>:  Juanito checks in from Virus Bulletin with news on the return of Careto/Mask, a ‘milk-carton’ APT linked to Spain. We also cover the latest controversy surrounding IDA Pro&#39;s subscription model, a major new YARA update, and ongoing issues with VirusTotal&#39;s value and pricing. The conversation shifts to North Korean cyber operations, particularly the infiltration of prominent crypto companies, Tom Rid&#39;s essay on Russian disinformation results, and the US government&#39;s ICE department using commercial spyware from an Israeli vendor.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a> (SentinelLabs), <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> (Art of Noh) and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> (SecurityWeek).</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1UaVJw7KE2Bl1p1ftqiE5g_CvMXe91eqNfv1_pKAx9uY/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="VB abstract: The Mask has been unmasked again" rel="nofollow" href="https://www.virusbulletin.com/conference/vb2024/abstracts/mask-has-been-unmasked-again/">VB abstract: The Mask has been unmasked again</a></li><li><a title="Discover IDA 9.0" rel="nofollow" href="https://hex-rays.com/blog/discover-ida-9.0-exciting-new-features-and-improvements">Discover IDA 9.0</a></li><li><a title="Binary Ninja" rel="nofollow" href="https://binary.ninja/">Binary Ninja</a></li><li><a title="Vertex Synapse" rel="nofollow" href="https://vertex.link/synapse">Vertex Synapse</a></li><li><a title="YARA-X" rel="nofollow" href="https://virustotal.github.io/yara-x/">YARA-X</a></li><li><a title="Microsoft on Star Blizzard disruption" rel="nofollow" href="https://blogs.microsoft.com/on-the-issues/2024/10/03/protecting-democratic-institutions-from-cyber-threats/">Microsoft on Star Blizzard disruption</a></li><li><a title="Tom Rid: The lies Russia tells itself" rel="nofollow" href="https://archive.ph/ZCFqK">Tom Rid: The lies Russia tells itself</a></li><li><a title="North Korea caught targeting German missile manufacturer" rel="nofollow" href="https://www.securityweek.com/north-korea-hackers-linked-to-breach-of-german-missile-manufacturer/">North Korea caught targeting German missile manufacturer</a></li><li><a title="How North Korea infiltrated the crypto industry" rel="nofollow" href="https://www.coindesk.com/tech/2024/10/02/how-north-korea-infiltrated-the-crypto-industry/">How North Korea infiltrated the crypto industry</a></li><li><a title="ICE signs $2M contract with spyware maker Paragon" rel="nofollow" href="https://archive.ph/nCEjT">ICE signs $2M contract with spyware maker Paragon</a></li></ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
