Transcript
Manoj Tandon:
Hello everyone, and welcome to another episode of Dark Rhiino Security Confidential. I’m your host, Manoj Tandon. Before we get started, please take a moment to like and subscribe—we could use a little love. As we all know, we work for the algorithms, and every click helps us continue bringing you this content.
Today we have an incredible guest joining us. He has well over 20 years of hands-on experience in cybersecurity. His name is Daniel Lowrie. Daniel began his career back when workstations were still a thing, and he has spent decades in ethical hacking, security training, and helping people understand how systems actually work. Like many of us, he was inspired by movies such as WarGames and Sneakers, and he turned that inspiration into a long and impactful career. Daniel, thank you so much for joining us.
Daniel Lowrie:
Thank you for having me, Manoj. I love doing this kind of thing—talking technology, security, and especially training. I’ve been fortunate to help thousands of people get into cybersecurity careers. One of the most rewarding parts is meeting people at conferences who tell me they took my training for certifications like CEH, Pentest+, CISSP, or CISA, and that it helped them land a job they love.
I’ve heard incredible stories—people who were delivering pizzas, struggling financially, or even going through chemotherapy—who used that time to study, earn certifications, and completely change their lives. Some people feel like they know me personally because my training was with them during pivotal moments in their lives. I wouldn’t trade that experience for anything.
Manoj Tandon:
That’s meaningful work. You’ve genuinely impacted people’s lives in a positive way, and that’s about as good as it gets.
Let’s talk about your background. I firmly believe that if you can light a spark in someone—whether it’s music, technology, healthcare, or anything else—that person can accomplish things they never imagined. Something clearly lit that spark in you. What was it? How did this all begin?
Daniel Lowrie:
My first computer was a TI-99 back in the early 1980s. Technology in the home was still very new, especially for everyday people. I grew up poor—my dad was a truck driver. He worked for an electronics company and one day came home with a TI-99 they gave him. We hooked it up to a TV, plugged in cartridge-based games, and I never wanted to leave it.
From there, I became the kid who took everything apart just to see how it worked. Electronics spoke to me. As a teenager, I got into bulletin board systems, dial-up modems, IRC, and early online communities. A friend of mine even had a handwritten list of every website on the internet—literally manual DNS on a single page.
Movies like WarGames and Sneakers captured my imagination. They showed that systems could be understood, manipulated, and explored. It wasn’t realistic in every detail, but it sparked curiosity. I wanted to understand how things really worked.
Manoj Tandon:
Those movies definitely inspired a generation. Some of what they showed was exaggerated, but not all of it.
Daniel Lowrie:
Absolutely. WarGames, for example, was fairly accurate when it came to war dialing. Back then, systems were built to work first and security came later—if at all. That’s been a repeating pattern throughout history. Build it, get people addicted to it, then bolt security on later.
Manoj Tandon:
Back then, the internet’s roots were in survivability—DARPANET was about ensuring messages got through during a nuclear war. Security simply wasn’t part of the original design.
Daniel Lowrie:
Exactly. Nobody was worried about confidentiality when everything might be glowing in the dark. The goal was communication, not protection. That gave us an incredible playground, but also created long-term security problems we’re still dealing with.
Manoj Tandon:
What was the first hack you remember doing?
Daniel Lowrie:
Probably the Ping of Death—sending oversized packets to crash Windows machines. I was working in a hospital at the time and experimenting on friends on the LAN. Net Send was another classic—we’d send confusing messages to mess with people in chat rooms.
But honestly, my first hacks were physical. In middle school, I’d shoulder-surf locker combinations, break into lockers, copy notes, and put them back. I’d also break into sports equipment closets, stash the good gear elsewhere, and grab it later during gym class. That was physical security testing before I even knew the term.
Manoj Tandon:
Those principles still apply today. Shoulder surfing, keypad access, gated communities—it’s often just the illusion of security.
Daniel Lowrie:
Exactly. We love the illusion of security.
Manoj Tandon:
Fast-forward to today. If someone wants to get into cybersecurity now, what path would you recommend?
Daniel Lowrie:
It depends on what they want to do, but foundations are non-negotiable. You can’t start in the middle and expect to be effective. You need to understand operating systems, networking, and basic security concepts.
I also recommend learning a scripting language—Python, PowerShell, Bash—just enough to understand logic, variables, input, and automation. You don’t need to become a developer, but understanding how code works will pay dividends.
I made the mistake of trying to skip steps early in my career and had to backfill later. When I got into web application testing, I had to learn HTTP, APIs, JavaScript, and how applications actually function. Once you have those fundamentals, everything in cybersecurity makes far more sense.
Manoj Tandon:
That aligns with my thinking. Understanding foundational architecture is where you really find vulnerabilities.
Daniel Lowrie:
Exactly. Most real vulnerability research comes from understanding code, not just running tools. People reverse engineer applications, analyze logic flaws, and identify missing validation. That’s what separates elite practitioners from tool drivers.
Manoj Tandon:
Those people are rare.
Daniel Lowrie:
They are—and that’s why they win at competitions like Pwn2Own and command top salaries.
Manoj Tandon:
Why do so many vulnerabilities make it through the development lifecycle?
Daniel Lowrie:
It’s a mix of things. Developers are often too close to their own code. They don’t see flaws because the logic makes sense to them. Deadlines, business pressure, and “done is better than perfect” mentality dominate. Security gets deprioritized in favor of shipping a minimum viable product.
Pair programming and code reviews help, but ultimately security is still viewed as a cost center rather than a strategic advantage.
Manoj Tandon:
How do we change that mindset?
Daniel Lowrie:
It’s difficult because buyers value convenience over security. People want things to be easy first and secure second. That conflict drives most security failures. Vendors optimize for speed, cost, and usability—not resilience. Until security becomes a buying decision that truly matters, this tension will remain.
Manoj Tandon:
Let’s talk about AI. It’s impossible to have a cybersecurity conversation without it now.
Daniel Lowrie:
AI is a force multiplier. It lets people build applications quickly—even without knowing the language. But unless you explicitly ask it to check for security issues, it won’t. It doesn’t care.
I’ve used AI for CTFs and troubleshooting. It’s great at research and filling knowledge gaps, but it’s not a thinking machine. It struggles with creativity and lateral problem-solving. Still, people should absolutely be learning how to use AI effectively. Those who can operate and guide AI will be the ones who remain valuable as companies reduce headcount.
Manoj Tandon:
That’s a critical point.
Daniel Lowrie:
AI won’t replace everyone—but it will replace people who don’t know how to use it.
Manoj Tandon:
We’re at the hour already. This flew by. Before we wrap up, what would you like to share with our audience?
Daniel Lowrie:
I run two live streams each week— CyberCast IRL on Fridays at 10 a.m. and CyberCast After Dark on Wednesdays at 9 p.m. We talk security, tech, careers, and take live questions.
I also recently released a Pentest+ course through Simply Cyber Academy at academy.simplycyber.io. It’s hands-on, demo-driven, and designed for both red and blue teamers. No boring slide decks—just real-world walkthroughs and practical skills.
Manoj Tandon:
That’s fantastic. We’ll link everything in the show notes. Daniel, thank you again—it’s been an absolute pleasure.
Daniel Lowrie:
Thank you. I had a great time. Let’s definitely do this again.
Manoj Tandon:
Absolutely. Take care.