Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

AMA: I'm Larry Pesce. 20+ years of IoT and wireless hacking, software supply chain security, SANS course author, and Paul's Security Weekly. Ask me anything!

0
Medium
Published: 09/08/2026 (09/08/2026, 13:03:25 UTC)
Source: Reddit Cybersecurity

Description

This content is an Ask Me Anything (AMA) session hosted by Larry Pesce, a cybersecurity expert with over 20 years of experience in IoT, wireless hacking, and software supply chain security. The post is an invitation for the community to ask questions about various security topics, including hardware and firmware hacking, wireless security, supply chain security, and regulatory compliance. It does not describe a specific vulnerability, exploit, or active threat.

Reddit Discussion

r/cybersecurity·posted by u/Disastrous-Brush1327
00

Hey r/cybersecurity!

I'm Larry Pesce, VP of Services at Finite State. I've spent the last two decades-plus breaking (and then helping fix) the things most people don't think of as computers: medical devices, cars, industrial control systems, IP cameras, routers, and basically anything with a radio or a debug header.

A quick rundown of what I've been up to over the years:

  • Hardware and firmware hacking. Pulling firmware off devices via JTAG, UART, SPI, and chip-off, reverse engineering it, and finding the bugs vendors hoped nobody would look for. I recently led the vulnerability disclosure for a consumer IP camera that shipped with some genuinely wild supply chain issues baked into its cloud stack.
  • Wireless security. This is where I got my start. I co-author SANS SEC617 (Wireless Penetration Testing and Ethical Hacking) and SEC556 (IoT Penetration Testing), and I've spent a lot of hours in parking lots with antennas that raised questions from security guards.
  • Software supply chain security. These days a huge part of my work is helping device manufacturers understand what's actually inside their firmware: third-party components, SBOMs, VEX, vulnerability reachability, and navigating regulations like the EU Cyber Resilience Act and FDA premarket requirements. Spoiler: most vendors don't know what's in their own products.
  • Podcasting. I've been part of Paul's Security Weekly for over 20 years. If you've listened at any point since the early 2000s, you've probably heard me ramble about hardware hacking, wireless shenanigans, or whatever device I'd taken apart that week.
  • Community. DEF CON, Black Hat, BSides, GIAC certs, a few books on networking and open source security tools, and a lot of time mentoring folks trying to break into offensive security.

Why am I doing this AMA?

Honestly, because the intersection of IoT, supply chain, and regulation is getting genuinely interesting right now. The CRA is coming, SBOMs are moving from buzzword to requirement, and the gap between "we make a connected product" and "we understand our connected product's security" is still enormous. I think there's a lot worth discussing, and I always learn something from these threads too.

One line on my $DAYJOB since the rules ask for it: Finite State does binary firmware analysis and product security services for connected device manufacturers. I've spent the last 20 years giving back to the community through sharing what I know: That's it, no pitch. I'm here to talk shop.

Ask me anything about:

  • IoT and embedded device hacking (hardware, firmware, or both)
  • Wireless security, past and present
  • Software supply chain security, SBOMs, VEX, and the regulatory wave (CRA, FDA, etc.)
  • Vulnerability disclosure and dealing with vendors
  • Careers in offensive security and pentesting
  • 20+ years of security podcasting and how the community has changed

I'll be answering questions today, September 8th, 2026 roughly during business hours on the East coast of the US - I will keep checking in during the evening, and I would encourage questions over the next few days for those of you all over the planet. Fire away!

Transparency note per the AMA guidelines: I may use generative AI to help polish some longer answers, but the experiences, opinions, and war stories are all mine.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/08/2026, 14:37:07 UTC

Technical Analysis

The provided information describes a Reddit AMA event featuring Larry Pesce, a seasoned security professional specializing in IoT and wireless security, software supply chain security, and vulnerability disclosure. The post outlines his background and areas of expertise and invites the cybersecurity community to engage with him on related topics. There is no technical vulnerability or threat detailed in the content.

Potential Impact

No direct security impact or threat is described in this content. It is an informational and community engagement event rather than a report of a vulnerability or exploit.

Defensive Guidance

No mitigation actions are required as this content does not describe a security vulnerability or threat.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Domain
null
Newsworthiness Assessment
{"score":30,"reasons":["external_link","non_newsworthy_keywords:course","established_author","recent_news"],"isNewsworthy":true,"foundNewsworthy":[],"foundNonNewsworthy":["course"]}
Has External Source
false
Trusted Domain
false

Threat ID: 6aa01d90acd9273b49c73c51

Added to database: 09/08/2026, 14:37:04 UTC

Last enriched: 09/08/2026, 14:37:07 UTC

Last updated: 09/09/2026, 03:22:06 UTC

Views: 13

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses