Uploaded May 2025 | Updated September 2026, 3 weeks ago
What really happened at RSA 2024? Daniel Miessler and Jason Haddix break it down.
Fresh off a whirlwind RSA week, Daniel sits down with Jason Haddix (Arcanum Information Security) to talk about what mattered—beyond the show floor noise. From off-site innovation summits to real-world AI implementation, this deep dive covers:
-Where the real innovation happened (hint: not on the show floor)
-Key takeaways from the OpenAI and Airbnb AI Security events
-Jason’s talk on AI pentesting methodology and the Prompt Injection Taxonomy
-The future of cybersecurity moats and the risk of AI-native disruption
-Why agents aren’t the main character—data is
-DARPA's AIxCC competition and the rise of Cyber Reasoning Systems
-Challenges with evals, autonomous security workflows, and VDP backlash
-Behind the scenes at RSA: puppies, parties, burnout, and brutal honesty
They also explore content creation, the future of platform-native context, and why being opinionated (with receipts) matters more than ever in security and tech.
Jason's Company
arcanum-sec.com
00:00 – Intro + RSA recap: FUD, parties, and innovation
03:52 – Offsite events vs. the show floor
07:11 – OpenAI Security Summit insights
11:25 – Airbnb’s take: AI implementation in the real world
14:05 – Jason’s AI pentesting methodology + taxonomy
21:35 – Prompt injection and bypass techniques
25:45 – Daniel on unified entity context and data moats
30:10 – AI agents vs. context-rich data lakes
34:30 – DARPA’s AI Cyber Challenge explained
38:25 – What matters more: model or scaffolding?
44:05 – The eval problem + security-specific challenges
49:40 – Automation myths + vulnerability management realities
55:15 – The spending vs. layoffs paradox at RSA
58:20 – Smaller, smarter events and future plans
1:03:30 – Why most security products are just features
1:07:10 – Vulnerability disclosure vs. bug bounties
1:14:40 – Building opinionated content as a creator
1:18:55 – PRDs, vibe coding, and AI-assisted workflows
What really happened at RSA 2024? Daniel Miessler and Jason Haddix break it down.
Fresh off a whirlwind RSA week, Daniel sits down with Jason Haddix (Arcanum Information Security) to talk about what mattered—beyond the show floor noise. From off-site innovation summits to real-world AI implementation, this deep dive covers:
-Where the real innovation happened (hint: not on the show floor)
-Key takeaways from the OpenAI and Airbnb AI Security events
-Jason’s talk on AI pentesting methodology and the Prompt Injection Taxonomy
-The future of cybersecurity moats and the risk of AI-native disruption
-Why agents aren’t the main character—data is
-DARPA's AIxCC competition and the rise of Cyber Reasoning Systems
-Challenges with evals, autonomous security workflows, and VDP backlash
-Behind the scenes at RSA: puppies, parties, burnout, and brutal honesty
They also explore content creation, the future of platform-native context, and why being opinionated (with receipts) matters more than ever in security and tech.
Jason's Company
arcanum-sec.com
00:00 – Intro + RSA recap: FUD, parties, and innovation
03:52 – Offsite events vs. the show floor
07:11 – OpenAI Security Summit insights
11:25 – Airbnb’s take: AI implementation in the real world
14:05 – Jason’s AI pentesting methodology + taxonomy
21:35 – Prompt injection and bypass techniques
25:45 – Daniel on unified entity context and data moats
30:10 – AI agents vs. context-rich data lakes
34:30 – DARPA’s AI Cyber Challenge explained
38:25 – What matters more: model or scaffolding?
44:05 – The eval problem + security-specific challenges
49:40 – Automation myths + vulnerability management realities
55:15 – The spending vs. layoffs paradox at RSA
58:20 – Smaller, smarter events and future plans
1:03:30 – Why most security products are just features
1:07:10 – Vulnerability disclosure vs. bug bounties
1:14:40 – Building opinionated content as a creator
1:18:55 – PRDs, vibe coding, and AI-assisted workflows










