Michel Chamberland
Chat with a White Hat
Real stories from the people breaking and defending the internet Every week, Michel Chamberland sits down with a cybersecurity professional to dig into the moments that shaped their career, from their first encounter with a computer to the coolest hack they ever pulled off. Every guest answers the same core questions, giving you a unique window into how different people approach the same craft. Whether you're a seasoned red teamer, a bug bounty hunter, a vulnerability analyst, or just getting started, there's something here for you.
Author
Michel Chamberland
Category
Podcast website
Latest episode
Jun 13, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Bureaucracy in Security Testing 15.04.2026 0:46
The conversation delves into the art of bureaucracy and its impact on security testing, emphasizing the need to remove bureaucracy and reduce friction in user interfaces for effective testing. Takeaways Bureaucracy as an art Reducing friction in user interfaces Chapters 00:00 The Art of Bureaucracy
Slow Down: Key to Effective Security Testing 15.04.2026 4:31
The conversation emphasizes the importance of slowing down and conducting thorough reconnaissance in cybersecurity testing. It highlights the need to pay attention to details and avoid making assumptions based on incomplete information. Takeaways Slow down Thorough reconnaissance Chapters 00:00 Importance of Slowing Down and Thorough Reconnaissance
Web App Pentesting: Eye-Opening Factor 14.04.2026 0:56
Nick Aures discusses his fascination with web application pen testing, highlighting the enjoyment, eye-opening factor, and impact of reporting on vulnerabilities. He emphasizes the prevalence of web applications in modern life. Takeaways Fascination with web app pen testing Prevalence of web applications in modern life Chapters 00:00 The Fascination with Web Application Pen Testing
Pentesting: More Than Just Hacking 14.04.2026 0:56
The conversation delves into the multifaceted role of a cybersecurity consultant, highlighting the responsibilities, client interactions, and report generation. It also explores the balance between pen testing and consultancy, emphasizing the importance of being a consultant as well as a pen tester. The discussion concludes with a reflection on the dual role of a cybersecurity professional. Takeaw...
Market Economy Hides Cyber Exploits 13.04.2026 1:06
The conversation delves into the impact of market economy on the visibility of remote system exploits, highlighting the concealment of such exploits due to economic factors. It also explores the influence of the highest bidder in the cybersecurity industry, leading to the secrecy and privatization of valuable exploits. Takeaways Market economy conceals remote exploits Tyranny of the highest bidder...
Cybersecurity Threats Are Piling Up Faster Than Ever 13.04.2026 0:09
The conversation delves into the rising frequency of cyber vulnerabilities and its impact on defensive measures. It also explores the challenges in cybersecurity, defensive measures, and strategies, as well as the offensive side of cybersecurity with a focus on cyber attacks and offensive strategies. Takeaways Rising frequency of cyber vulnerabilities Challenges in cybersecurity Chapters 00:00 Ris...
Reverse Engineering IIS Exploit 12.04.2026 0:50
The conversation delves into the discovery of exploits and the impact of reverse engineering on program modification and distribution. Takeaways Reverse Engineering Impact of Exploits Chapters 00:00 Uncovering Exploits and Reverse Engineering
Pentesting: More Than Just Hacking 12.04.2026 0:56
The conversation highlights the importance of consulting in the day-to-day work of a cybersecurity consultant, emphasizing the need for pen testers to also act as consultants and not just focus on hacking tricks. Takeaways Consulting is a significant part of a cybersecurity consultant's day-to-day work. Pen testers need to also be consultants and not just focus on showing off their hacking tricks....
AI Boosts Penetration Testing Speed 11.04.2026 1:04
The conversation delves into the impact of cloud code on penetration testing, highlighting the significant power it provides to pen testers. Additionally, the need for increased testing frequency is discussed, emphasizing the rapid changes in technology and the necessity for more frequent and efficient testing methods. Takeaways Cloud code Penetration testing Testing frequency Chapters 00:00 The P...
The Hidden Threat: Market Economy & Exploits 11.04.2026 4:45
The conversation delves into the underestimation of vulnerabilities, the impact of the market economy on security, and the centralization of skills in the industry. It highlights the hidden nature of vulnerabilities, the influence of market economy on the visibility of exploits, and the decreasing number of skilled individuals in the field. Takeaways Hidden vulnerabilities Impact of market economy...
AI in Security: Hype, Reality, and Future 10.04.2026 4:40
The conversation explores the impact of AI on security testing and technology, drawing parallels to the impact of cloud technology. It delves into the changes in offensive and defensive security testing due to AI and compares the initial hype and subsequent evolution of AI to that of cloud technology. Takeaways Impact of AI on offensive and defensive security testing Comparison of AI impact to the...
AI: The New Computer 10.04.2026 1:07
The conversation explores the parallels between AI adoption and computer adoption, highlighting the potential for AI to bring efficiency and free up time for other activities. It also delves into the impact of AI on work and art, expressing hope for a future where AI enhances human creativity and productivity. Takeaways AI adoption similar to computer adoption AI will bring efficiency and free up...
Cybersecurity: Learn the Core Science 09.04.2026 1:03
The conversation covers the comparison between cybersecurity and computer science degrees, emphasizing the importance of theoretical computer science. It also delves into the concept of thinking inside the box and the limitations it imposes. Takeaways Cybersecurity degree vs. computer science Importance of theoretical computer science Chapters 00:00 Choosing the Right Education
AI: Not Innovative, Just Fast 09.04.2026 1:17
The conversation delves into the limitations of AI and its inability to be truly innovative, as well as the concept of artificial creativity. The discussion highlights the fact that AI is limited to predefined tasks and lacks the ability to generate new ideas or solutions. Takeaways AI limitations Artificial creativity Chapters 00:00 AI Limitations and Creativity
Mastering Assembler for C Fluency 08.04.2026 0:51
The conversation delves into the importance of mastering the core concepts, deep understanding of programming languages, achieving fluency, and the application of knowledge to all code. It emphasizes the significance of practice and open source code, as well as the idea that all code is open source and can be understood through reading the assembler. Takeaways Master the core concepts Achieve flue...
Security Testing: More Than Just Scanning 07.04.2026 1:02
The conversation delves into the misconceptions surrounding security testing and highlights the manual probing and hard thinking involved in the process. Takeaways Misconceptions about security testing Manual probing and hard thinking involved in security testing Chapters Misconceptions About Security Testing
Pentesting: A Fool's Errand 06.04.2026 0:46
The conversation covers Neil Kettle's favorite type of testing and the challenges of pen testing, highlighting the dilemma and pressure associated with it. Takeaways Favorite testing type Challenges of pen testing
AI in Cybersecurity: 2026 Advice 06.04.2026 0:55
Advice for breaking into cybersecurity and pen testing in 2026, including the importance of showcasing seriousness and considering automation with AI. Takeaways Show seriousness and dedication Consider automation with AI
Nick Aures Talks Zero Days and Exploit Techniques 05.04.2026 0:18
The conversation covers zero-day discoveries and cloud code exploits. Nick discusses his recent findings of zero-day vulnerabilities and his improved understanding of obscure exploit techniques. Additionally, the use of cloud code to write exploits is explored, highlighting its potential for executing commands and writing code. Takeaways Zero-day discoveries Cloud code exploits
Just Start: Hands-On Cybersecurity 05.04.2026 1:01
The conversation emphasizes the importance of hands-on experience in cybersecurity, highlighting the transition from network play to CTFs and the value of practical keyboard experience in learning. Takeaways Hands-on experience is crucial CTFs are a valuable learning tool Chapters 00:00 The Value of Hands-On Keyboard Experience
Slow Down: CTF & Pen Testing Mistakes 05.04.2026 0:41
In this conversation, the speaker discusses the importance of slowing down in pen testing and CTFs to avoid missing critical vulnerabilities and attack chains. They emphasize the need to focus on the details and not rush to the end goal. Takeaways Slowing down is crucial in pen testing and CTFs Low severity vulnerabilities can pose high risk when combined Chapters 00:00 The Need to Slow Down
Nick Aures (Senior Pentester) 04.04.2026 31:30
Nick Aures, a senior pen tester, shares his journey into cybersecurity, the evolution of his interest in computers, and the impact of AI on pen testing. He also discusses the underestimated attack vector of 'execution after redirect' and offers advice for aspiring cybersecurity professionals. Takeaways Continuous pen testing models are essential for staying on top of new vulnerabilities and threat...
Hacking Mac OS X 04.04.2026 0:29
The conversation covers the topic of key logging on Mac OS X without informing the user, and the process of reverse engineering Apple's implementation to achieve this. The discovery of the backdoor in Mac OS X is also discussed. Takeaways Key logging on Mac OS X without user notification Discovery of backdoor in Mac OS X
Exploiting EDR Console for Mass Deployment 04.04.2026 0:49
A security breach led to unauthorized access to the EDR console, allowing for the deployment of payloads and extensive access to the organization's systems. Takeaways Unauthorized access to EDR consoles can lead to the deployment of payloads and extensive system access. EDR consoles are often overlooked as a potential point of compromise in a security breach. Chapters 00:00 Unauthorized Access to...
AI Boosting Red Teaming Efficiency 04.04.2026 0:54
The conversation explores the impact of AI on red teaming and the considerations of efficiency and cost for companies. Takeaways AI can enhance red teaming Efficiency and cost are key considerations for companies Chapters 00:00 The Impact of AI on Red Teaming
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.