logo
episode-header-image
Sep 6
27m 16s

3411: Why The Browser Is The New Securit...

NEIL C. HUGHES
About this episode

When I invited Or Eshed, CEO and co-founder of LayerX Security, onto Tech Talks Daily, I wanted to challenge a blind spot most teams carry into work each day. We talk about phishing, ransomware, and endpoint controls, yet we skip the place where employees actually live online. The browser. That quiet tab bar has become the front door to identities, payments, SaaS, and now AI. Or calls it a different operating system in its own right, and once you hear his examples of how extensions can intercept cookies, mimic logins, or even meddle with AI chats, the penny drops fast.

Here’s the thing. Blocking extensions across the board no longer fits how people work. Developers, marketers, sales teams, and support agents all lean on extensions for real productivity gains. Or’s argument is simple. If the business depends on extensions, security has to meet people where they are with continuous, risk-based controls inside the browser itself. That means assessing code, permissions, ownership changes, and live behaviors, not relying on a static allow list that grows and grows while attackers slip through the cracks.

We also unpack Extensionpedia, LayerX’s free resource that lets anyone look up the risk profile of a specific extension. It is part education, part early warning system, and it serves a wider mission to raise the floor for everyone. Or shares how a technology alliance with Google has helped the team analyze extensions at serious scale, and why better data beats clever slogans in a space where signals change hour by hour.

Malicious Extensions, AI Shortcuts, And The Culture Shift Security Needs

One of the standout moments is a real-world story that starts at home and ends inside a corporate network. A spouse installs a screen-recording extension on a personal device, the browser profile syncs at work, and suddenly corporate credentials and sensitive sessions are mirrored to an untrusted machine. No shadowy APT needed. Just everyday sync doing exactly what it was designed to do. It is messy, human, and exactly why policy needs to be paired with continuous visibility in the browser.

We explore the gray zone where productivity tools collide with privacy. Password managers, VPN helpers, and AI-everywhere extensions promise convenience, yet they can scrape data across SaaS apps or sync credentials in ways security leaders never intended. Or’s advice is refreshingly pragmatic. Assume extensions are staying. Instrument the browser, score risk in real time, and adapt access based on what an extension actually does, not what it claims on a store page.

Looking ahead, Or sees the browser taking an even bigger role as email, SaaS, and AI agents converge in one place. With AI companies building their own browsers, the last mile of user interaction gets denser, faster, and more valuable to protect. If 99 percent of enterprise users already run at least one extension, the task is clear. Know which ones are in play, understand how they behave, and keep policy dynamic. If this conversation sparks a rethink of your own approach, check your extensions in Extensionpedia, and then consider what modern, in-browser controls would look like in your environment. After this episode, you may never look at that tidy row of icons the same way again.

*********

Visit the Sponsor of Tech Talks Network:

Land your first job  in tech in 6 months as a Software QA Engineering Bootcamp with Careerist

https://crst.co/OGCLA

Up next
Yesterday
3447: How DXC Is Using AI to Outsmart Cybercriminals
In this episode, Mike Baker, Vice President and Global CISO at DXC Technology, says the cyber industry has been focusing on the wrong side of AI. He believes too many companies use it only to block threats instead of studying how criminals use it to scale phishing, bypass defense ... Show More
28m 36s
Oct 8
3446: How Atlassian Is Redefining Teamwork with AI at Team 25
What happens when the future of teamwork collides with the power of AI? That’s the question at the heart of this episode as Tiffany from Atlassian joins me from Barcelona during Team 25, where Atlassian is showcasing how AI-powered collaboration is redefining how work gets done. ... Show More
34m 26s
Oct 7
3445: Why AI Won’t Replace Human Testers at Jalasoft
As AI tools race into every corner of software development, a simple question keeps coming back to me. Will AI replace human testers, or will it force us to rethink what great testing looks like in the first place. In today’s conversation, I talk with Santiago Komadina Geffroy, a ... Show More
24m 34s
Recommended Episodes
Feb 2025
Rethinking Cloud Security Strategies
Cloud security is more complex than ever. Organizations move fast, but security teams often struggle to keep up. In this episode of Threat Vector, host David Moulton speaks with Amol Mathur, SVP of Products for Prisma Cloud at Palo Alto Networks, about how platformization is resh ... Show More
35m 28s
Mar 2025
#243 Greg Osuri: Why the Future of AI Depends on Decentralized Cloud Platforms
This episode is sponsored by Indeed. Stop struggling to get your job post seen on other job sites. Indeed's Sponsored Jobs help you stand out and hire fast. With Sponsored Jobs your post jumps to the top of the page for your relevant candidates, so you can reach the people you wa ... Show More
59m 19s
Dec 2024
Behind the Scenes with Palo Alto Networks CIO and CISO Securing Business Success with Frictionless Cybersecurity
In this episode of Threat Vector, David Moulton speaks with Meerah Rajavel, CIO of Palo Alto Networks, and Niall Browne, CISO of the organization, about the importance of aligning IT strategy with cybersecurity.  Meerah and Niall discuss how frictionless security, AI integration, ... Show More
39m 17s
Jun 2025
Bridging the Gap: AI and Cybersecurity in the Enterprise
In this episode of Cybersecurity Today, host Jim Love is joined by Krish Banerjee, the Canada Managing Director at Accenture for AI and Data. They begin the discussion with a report from Accenture that highlights the gap between the perceived and actual preparedness for cybersecu ... Show More
50m 50s
Jun 2025
Unlocking Enterprise Efficiency Through AI Orchestration - Kevin Kiley of Airia
Today’s guest is Kevin Kiley, President of Airia. With extensive experience helping large enterprises implement secure and scalable AI systems, Kevin joins Emerj Editorial Director Matthew DeMello to explore how agentic AI is reshaping enterprise workflows across industries like ... Show More
20m 59s
Sep 24
AI's Next Frontier: Privacy-Preserving Neural Networks
Jimmy Secretan, CTO of JustWin, explores the latest innovations in privacy-preserving neural networks, and explains how JustWin is leveraging AI to help small businesses win government contracts. He also explores the future directions of AI, and the impact of AI on user autonomy ... Show More
36m 44s
Feb 2025
DeepSeek: The Game-Changer in AI and the Impact on Cybersecurity
In this episode of Cybersecurity Today, host Jim Love dives deep into the latest advancements in AI technology with a focus on the new open-source model, DeepSeek, from China. Love discusses the significant cost differences in training and running this model compared to competito ... Show More
48m 19s
Jul 28
Cyber risk and security in an AI world: what’s in store?
In today's digital world, artificial intelligence, data storage and cybersecurity are a critical triumvirate, intersecting to form a dynamic ecosystem that underpins modern technological infrastructure. They are strategic pillars that drive innovation, operational efficiency and ... Show More
26m 10s
Oct 2024
Balancing Security with Usability in Cybersecurity
In this episode of Threat Vector, host David Moulton talks with guest speaker Brian Wrozek, Forrester Principal Analyst in Security & Risk, about the complexities of aligning security strategies across global teams. Brian draws on his extensive experience in cybersecurity, operat ... Show More
41m 41s
Sep 10
LIVE from Rare Evo: How Citi is Bridging The Gap Between Web2 and Web3
Ryan Rugg, Global Head of Digital Assets for Citibank’s Treasury and Trade Solutions (TTS), discusses their approach to integrating Web 2.0 and 3.0. She shares insights on Citi Token Service, a new solution designed to provide 24/7 liquidity and borderless transactions, and expla ... Show More
18m 22s