596 episodes
- Can you recover working software from a photograph of a microchip?
Embedded systems reverse engineer Travis Goodspeed demonstrates how to extract the original Game Boy’s 256-byte boot ROM from a microscopic photograph of the mask ROM inside its CPU.
The source image was created by combining 22 microscope photographs captured at 50x magnification. Using his free, open-source Mask ROM Tool, Travis marks 2,048 ROM bit locations, separates the ones from the zeros and checks for possible recognition errors. He then determines the logical order of the bits, disassembles the program and shows how it can be exported as a ROM file for use in an emulator.
Travis also explains the Game Boy’s unusual copy-protection system. During startup, its boot ROM displays logo data supplied by the cartridge and compares it with Nintendo’s internal copy. If the logos do not match, the game does not boot. Requiring cartridges to contain Nintendo’s trademark gave the company legal leverage against unlicensed publishers.
The video also explores techniques from Travis’s book, Microcontroller Exploits. These include extracting protected firmware from an access-control reader, chemically decapsulating chips while preserving their operation and using ultraviolet light with a nail-polish mask to remove memory protection without erasing the program.
The Mask ROM Tool, Game Boy chip photograph and step-by-step tutorial are publicly available, allowing you to reproduce the ROM-decoding demonstration without owning a microscope or chemistry lab.
// Sponsored SEGMENT //
Big thank you to Proton Pass for sponsoring this video. Take your security to the next level by getting Proton Pass using the following be www.proton.me/davidbombal
// Link to No Starch Website for Travis’ Book //
Order Microcontroller Exploits and get the eBook free.
https://nostarch.com/microcontroller-...
Use Coupon Code GOODSPEED25 for 25% off Microcontroller Exploits at NoStarch.com
// Travis Goodspeed SOCIAL //
GitHub: https://github.com/travisgoodspeed
// GitHub link to GameBoy ROM Tutorial //
https://github.com/travisgoodspeed/gb...
// David's SOCIAL //
Discord: discord.com/invite/usKSyzb
Twitter: www.twitter.com/davidbombal
Instagram: www.instagram.com/davidbombal
LinkedIn: www.linkedin.com/in/davidbombal
Facebook: www.facebook.com/davidbombal.co
TikTok: tiktok.com/@davidbombal
YouTube: / @davidbombal
Spotify: open.spotify.com/show/3f6k6gE...
SoundCloud: / davidbombal
Apple Podcast: podcasts.apple.com/us/podcast...
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
// MENU//
0:00 - Coming Up
0:40 - Intro
03:28 - Book Overview
05:27 - Proton Pass Ad
07:29 - Demonstration Context
09:56 - Demo Begins
12:48 - Marking the Chip Rows
18:27 - How Travis Wrote his Book
19:55 - Design Rule Check
23:11 - How to Decode the Binary
28:36 - Can the Binary Numbers Change?
30:30 - Why is this Method Useful?
34:24 - More book Overviews
40:48 - Conclusion
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
#gameboy #reverseengineering #rom - Your internet speed can look fine while your Wi-Fi is still failing. Packet loss, latency, congested channels, interference and poor configuration can all damage performance, but a normal speed test will not show you the full picture.
In this video, I test the Ookla Speedtest Pulse, a pocket-sized Wi-Fi 7 diagnostic tool that measures more than 25 network metrics in around 45 seconds. We test Wi-Fi at the Natural History Museum in London and examine results from an Airbnb to identify whether the problem comes from the Wi-Fi network, wired connection or internet service provider.
Matt explains how the device tests 2.4, 5 and 6 GHz Wi-Fi, detects channel problems, measures signal quality and gives you practical recommendations in plain English.
We also compare Speedtest Pulse with the normal Speedtest application, laptopbased tools and the Ekahau Sidekick 2. You will see its current limitations, upcoming continuous monitoring features and how it could help technicians finally capture intermittent Wi-Fi problems.
Big thanks to OOKLA for sponsoring this video. To get your own Speedtest Pulse please use the following link: https://wifi.ekahau.com/david-bombal-...
// Matt Starling’s SOCIAL //
LinkedIn: / matt-starling-03913633
X: https://x.com/mattstarling?s=21
// Ookla’s SOCIAL //
LinkedIn: / ookla
// David's SOCIAL //
Discord: discord.com/invite/usKSyzb
Twitter: www.twitter.com/davidbombal
Instagram: www.instagram.com/davidbombal
LinkedIn: www.linkedin.com/in/davidbombal
Facebook: www.facebook.com/davidbombal.co
TikTok: tiktok.com/@davidbombal
YouTube: / @davidbombal
Spotify: open.spotify.com/show/3f6k6gE...
SoundCloud: / davidbombal
Apple Podcast: podcasts.apple.com/us/podcast...
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
// MENU //
0:00 - Coming Up
0:58 - Testing Public Wi-Fi in London
01:40 - What Is the Speedtest Pulse?
03:40 - Pulse vs Speedtest vs Sidekick 2
06:19 - Making Wi-Fi Troubleshooting Easy
07:44 - Running a Wi-Fi Test
09:22 - Understanding Wi-Fi Performance Scores
11:16 - Reports and Cloud Results
13:00 - Active vs Continuous Pulse
15:14 - Wired and Wireless Network Testing
18:05 - Why Not Just Use a Laptop?
21:02 - Mobile Support and Wi-Fi 7 Hardware
23:17 - Understanding Your Wi-Fi Score
26:54 - Wi-Fi Security and PMF
29:03 - Signal Strength and Transmit Power
30:19 - Wi-Fi Channels and Interference
31:58 - How to Improve Your Wi-Fi
33:12 - WPA3 Best Practices
34:16 - Price and Coverage Mapping
35:59 - Pulse vs Sidekick 2 for Interference
38:36 - Solving Intermittent Wi-Fi Problems
40:32 - Cloud Monitoring and Multi-Site Management
42:12 - Final Thoughts
Please note that links listed may be affiliate links and provide me with a small
percentage/kickback should you use them to purchase any of the items listed or recommended.
Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
#ookla #speedtest #wifi - Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal
AI is changing cybersecurity, but simply using more AI to defend against AI attacks may not be the answer.
David Bombal sits down with Danny Jenkins, CEO of ThreatLocker, to discuss the security risks created by AI, autonomous agents, zero-day vulnerabilities, ransomware, and the rapidly expanding attack surface businesses now have to deal with.
Danny explains one of the fundamental problems with AI security: AI can understand what something does, but it may not understand the intent behind it. The same action could be performed legitimately by an administrator or maliciously by an attacker.
They also discuss how AI is giving attackers capabilities that previously required significantly more expertise and resources, including vulnerability discovery and
sophisticated phishing attacks.
But AI creates another problem inside organizations. Autonomous agents can potentially access files, upload data, perform actions, and make mistakes extremely quickly. Every new piece of software adds attack surface, and powerful AI agents can dramatically increase that risk. Danny argues that the answer isn't simply AI versus AI.
Instead, organizations need to rethink trust itself.
The discussion covers deny by default, application control, restricting what software and AI agents are allowed to access, and why AI should be used as an additional
security layer rather than becoming your primary defense.
Topics include:
• AI security risks
• Autonomous and agentic AI
• Why AI struggles with intent
• How hackers are using AI
• AI-powered vulnerability discovery
• Zero-day vulnerabilities
• Ransomware
• AI attack surfaces
• Application control
• Deny by default security
• Why AI alone can't solve AI security
• Securing AI inside businesses
// Danny Jenkins’ SOCIAL //
LinkedIn: / dannyjenkinscyber
// ThreatLocker’s SOCIAL //
LinkedIn: https://www.linkedin.com/company/thre...
X: https://x.com/threatlocker
Instagram: / threatlocker
Website: https://www.threatlocker.com/
// David's SOCIAL //
Discord: discord.com/invite/usKSyzb
Twitter: www.twitter.com/davidbombal
Instagram: www.instagram.com/davidbombal
LinkedIn: www.linkedin.com/in/davidbombal
Facebook: www.facebook.com/davidbombal.co
TikTok: tiktok.com/@davidbombal
YouTube: / @davidbombal
Spotify: open.spotify.com/show/3f6k6gE...
SoundCloud: / davidbombal
Apple Podcast: podcasts.apple.com/us/podcast...
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
// MENU //
0:00 - Coming Up
0:34 - Introduction
0:46 - Why Businesses Are Afraid of AI
02:17 - AI Can Be Used for Good or Bad
03:29 - The Race to Adopt AI
05:02 - AI Gives Attackers Nation-State Capabilities
06:09 - Why AI Can't Be Your Primary Defense
07:59 - How AI Is Expanding the Attack Surface
08:53 - Solving AI Security With Limited Access
11:04 - The Deny-by-Default Security Model
14:12 - AI-Powered Vulnerability Hunting
17:29 - How ThreatLocker Actually Uses AI
20:01 - Why Deny-by-Default Beats Chasing Zero-Days
21:15 - What Cybersecurity Customers Are Most Worried About
22:16 - AI Hype, Jobs & Closing Thoughts
24:55 - ThreatLocker Advert
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
#threatlocker #bhusa2026 #blackhat - Note: Hak5 did not pay me to make this video. But, I'm marking it as sponsored because Darren was kind enough to give me some cool Hak5 gadgets. Get your own using my link: https://davidbombal.wiki/gethak5
// Darren Kitchen SOCIAL //
YouTube: https://www.youtube.com/darrenkitchen
Website: https://hak5.org/pages/hack-across-america
X: https://x.com/hak5darren
// Hak5 WEBSITE (affiliate) //
https://davidbombal.wiki/gethak5
// David's SOCIAL //
Discord: discord.com/invite/usKSyzb
Twitter: www.twitter.com/davidbombal
Instagram: www.instagram.com/davidbombal
LinkedIn: www.linkedin.com/in/davidbombal
Facebook: www.facebook.com/davidbombal.co
TikTok: tiktok.com/@davidbombal
YouTube: / @davidbombal
Spotify: open.spotify.com/show/3f6k6gE...
SoundCloud: / davidbombal
Apple Podcast: podcasts.apple.com/us/podcast...
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
// MENU//
0:00 - Coming up
01:00 - 21 Years of Hak5 // Device overview
05:30 - USB Rubber Ducky
09:22 - Bash Bunny
12:41 - Plunder Bug
13:28 - Shark Jack & Shark Jack Display
16:28 - Packet Squirrel
18:51 - Key Croc
21:51 - Screen Crab
24:07 - Lan Turtle Hub
28:14 - WiFi Pineapple
33:16 - WiFi Pineapple Pager
37:32 - Hak5 books
39:15 - Darren's favourite tools
41:27 - Future projects // Conclusion
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
#hak5 #hackinggadgets #hacktool - Thank you to Threatlocker for sponsoring my trip to Black Hat so I can interview amazing people.
Jen Easterly joins David Bombal to discuss why today’s cybersecurity problem may actually be a software quality problem.
For decades, users and organizations have been blamed for failing to patch systems, change default passwords, or enable MFA. Jen argues that the bigger question is whether software vendors should be held responsible for shipping insecure products in the first place.
They discuss Secure by Design, software vulnerabilities, memory safety, AI security, zero-day attacks, rogue AI agents, critical infrastructure, vendor accountability, and how artificial intelligence could dramatically shorten the time between discovering a vulnerability and weaponizing it.
Jen also shares lessons from her career at the NSA, the White House, CISA, Morgan Stanley, the U.S. Army, and now RSAC, including her advice for hackers, cybersecurity professionals, and future leaders.
Topics include:
Why cybersecurity may be a software quality problem
Why users are blamed for insecure software
CISA’s Secure by Design initiative
Why default passwords should disappear
AI agents behaving in unexpected ways
AI and the future of zero-day attacks
Memory safety, C, C++ and Rust
Government regulation and vendor accountability
The EU Cyber Resilience Act
Why Patch Tuesday may eventually become unacceptable
How AI could help defenders find and fix vulnerabilities
Jen Easterly’s advice for cybersecurity professionals
If you work in cybersecurity, ethical hacking, software development, networking, AI security, or critical infrastructure, this is a conversation you don’t want to miss.
// Jen Easterly’s SOCIAL //
LinkedIn: / jen-easterly
// Website REFERENCE //
https://www.cisa.gov/
// David's SOCIAL //
Discord: discord.com/invite/usKSyzb
Twitter: www.twitter.com/davidbombal
Instagram: www.instagram.com/davidbombal
LinkedIn: www.linkedin.com/in/davidbombal
Facebook: www.facebook.com/davidbombal.co
TikTok: tiktok.com/@davidbombal
YouTube: / @davidbombal
Spotify: open.spotify.com/show/3f6k6gE...
SoundCloud: / davidbombal
Apple Podcast: podcasts.apple.com/us/podcast...
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
// MENU //
0:00 - Coming up
0:55 - Jen Easterly introduction & background
04:20 - Advice for the youth
07:10 - Advice for ethical hackers and leadership
11:35 - Software security // Who's to blame?
17:39 - Power and responsibility
21:17 - Secure by design
26:38 - Is it important to attend RSAC? // Conclusion
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
#rsac #bhusa2026 #securebydesign
More Technology podcasts
Trending Technology podcasts
About David Bombal
Want to learn about IT? Want to get ahead in your career? Well, this is the right place!
On this channel, I discuss Python, Ethical Hacking, Networking, Network Automation, CCNA, Virtualization and other IT related topics.
This YouTube channel has new videos every week! Subscribe for technical, detailed, no fluff content.
David’s details:
Discord: https://discord.com/invite/usKSyzb
Twitter: https://www.twitter.com/davidbombal
Instagram: https://www.instagram.com/davidbombal
LinkedIn: https://www.linkedin.com/in/davidbombal
Facebook: https://www.facebook.com/davidbombal.co
Website: http://www.davidbombal.com
YouTube: https://www.youtube.com/davidbombal
All the best!
David
Podcast websiteListen to David Bombal, Search Engine and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


David Bombal
Scan code,
download the app,
start listening.
download the app,
start listening.

































