Your Cyber Path: How to Get Your Dream Cybersecurity Job · Kip Boyle

EP 111: SDP 8 Open Design

·22 min·1 clip
AES was chosen through an open competition, not a black box.
1. Your Cyber Path: How to Get Your Dream Cybersecurity Job EP 111 centers on the security architecture principle of open design. 2. Kip Boyle hosts with Jason Dion, and both frame the topic for people trying to enter cybersecurity or level up in it. 3. The episode asks whether a 1975 principle can still guide modern security and whether open design makes systems more attack resistant. 4. Kip quotes the paper’s definition: “the protection mechanism should not depend on attackers being ignorant of its design.” 5. Jason stresses that open design is not the same as open source, and that proprietary code can still follow the principle. 6. They use a learning management system example to show why companies worry about exposing design details and source code. 7. The conversation separates open design from a bug bounty program, which Jason says is related but not the same thing. 8. Kip and Jason bring up LastPass, noting that a source-code theft and encrypted customer password databases were disclosed in the past year. 9. They contrast LastPass with 1Password, which Jason says has fully disclosed its architecture for how encrypted data is protected. 10. Jason revisits his late-1990s and early-2000s penetration-testing work to explain why security by obscurity became a common shortcut. 11. He uses port 8888, Nmap port scanning, and unusual server placements like email on port 80 as examples of weak hiding tactics. 12. Kip says obscurity can create false security, while Jason says it is not useless for passwords or encryption keys. 13. The episode then shifts to AES, where Jason describes DES, triple DES, and 56-bit keys as older approaches that became brute-forceable. 14. Jason says NIST ran an open competition for a new standard, with federal participants including the NSA and public review of candidate algorithms. 15. He names RC4, RC5, and the Rijndael cipher as part of that selection process before explaining that AES is the chosen standard. 16. Kip says AES shows the value of open design because the algorithm is public while the key remains the thing that protects the data. 17. Jason links open design to career growth by mentioning RFCs, public comment on standards like Wi‑Fi 6, and work on the NIST cybersecurity framework version 2. 18. The tone is conversational and explanatory, with back-and-forth examples, short detours, and practical career advice. 19. Listeners who want cybersecurity architecture examples, encryption history, and career tactics will get the most value. 20. Listeners wanting a deep technical protocol analysis with no career discussion may skip it.

As heard by us

A practical lesson in why hiding a system can raise confidence without raising real security.

Security design gets its cleanest stress test when a harmless shortcut begins carrying real risk, and this episode uses security by obscurity to draw that line.

Read the full review in PlayNext →

Why you'd press play

You will see how a web service on an unusual port can feel hidden from casual visitors while still sitting open for anyone who knows to look.

Read the full recommendation in PlayNext →
Listen to the show on