Case file

The most influential hacker episodes and posts of the last twenty years

Influence is measurable in behavior. A piece of security writing or audio qualifies for the Sentinel’s canon if practitioners can point to something the field did differently because it existed — a control deployed, a myth retired, a research program started, a regulator embarrassed into motion. These are the podcast episodes and blog posts of the last twenty years that pass that test, selected editorially and dated (September 2026). Titles link to primary sources where the origin hosts them freely.

Episodes that moved the field

Security Now — the 2008 DNS cache-poisoning coverage. When Dan Kaminsky coordinated a record-sized fix for the DNS flaw he found, it was Steve Gibson’s multi-hour technical explainer on Security Now that translated the world’s largest silent patch for the practitioners and IT managers who had to apply it — podcasting proving it could do what the trade press couldn’t: teach at length, the same week.

Malicious Life — the Stuxnet series, with Ralph Langner. Ran Levi’s interviews with the industrial-control researcher who cracked the worm’s purpose turned the decade’s most important malware discovery into an oral history. For a generation of analysts, this series — not the government press releases — is where the Natanz story actually got learned.

Darknet Diaries — the Xbox Underground story. An early episode of Jack Rhysider’s show, telling the tale of the crew who broke into game-industry networks through a router vulnerability and careless SPE. It demonstrated the format this list’s podcast curation now takes for granted: practitioner-length narrative with the subjects close to the microphone, and it pulled a mainstream audience into a technical genre.

Darknet Diaries — Operation Trojan Horse. The episode that walked the commercial spyware market into the open for a general audience — years before the platform-consolidation leaks made the trade front-page news and governments started issuing usage bans. As with the show’s other case files, the influence was agenda-setting rather than technical.

Risky Business — the Shadow Brokers coverage. Through 2016 and 2017, Patrick Gray’s interviews were where the community processed the leaked equation-group toolkits — coverage that foreshadowed, in near-real time, the exploits behind WannaCry and NotPetya. The episodes remain the cleanest contemporary record of the industry deciding how it felt about offensive tools escaping.

Posts and essays that moved the field

Marcus Ranum — “The Six Dumbest Ideas in Computer Security” (2005). Technically a month inside the door of the twenty-year window’s start, and two decades later still the sharpest statement of what security thinking gets wrong by default — from “default permit” to “Penetrate and Patch” as strategy. The essay practitioners still reach for when a meeting goes wrong.

Coding Horror — “You’re Probably Storing Passwords Incorrectly” (2007). Jeff Atwood’s plain-language teardown of password storage mistakes reached an order of magnitude more working developers than any standard. The arguments in its comments — including with the bcrypt author — reshaped what mainstream web frameworks shipped by default within a few years.

Mat Honan — “How Apple and Amazon Security Flaws Led to My Epic Hacking” (WIRED, 2012), and “Kill the Password” (2012). The reporter’s first-person post-mortem of his own destruction — and his follow-up argument that the password itself was the failure — drove Apple, Amazon, and effectively the whole industry to change account-recovery and support authentication. The clearest example on this list of one piece of writing forcing structural change.

Schneier — “The Internet of Things Is Wildly Insecure — And Often Unpatchable” (WIRED essay, 2014). Bruce Schneier named the coming insecure-device epidemic years before Mirai proved it, and supplied the “feudal security” and market-failure framings that regulators eventually wrote into law.

Heartbleed.com (2014). Not a blog post but the disclosure site the researchers built: a template for responsible vulnerability communication — what happened, who’s affected, what to do — that every subsequent major disclosure has been measured against.

Troy Hunt — “Our password hashing has no clothes” (2016). The post that retired the industry’s comfortable lie that a fast hash plus a long-enough password was adequate, using the LinkedIn breach’s cracked hashes as the receipts. Do-it-right guidance followed in its wake; the post is still the citation practitioners use to end the argument.

James Mickens — “This World of Ours” (USENIX ;login:, 2014). The funniest thing ever published about security culture, and secretly one of the truest: security people as “the students who stayed late at the computer lab.” Its real influence is recruitment — an entire cohort of practitioners cites it as the piece that made the field feel like theirs.

KrebsOnSecurity — “KrebsOnSecurity Hit With Record DDoS” (2016). The post where Brian Krebs documented the 620-Gbps attack on his own site — the event that introduced Mirai-class IoT botnets to the mainstream, killed the old assumption that anyone could survive a DDoS alone, and reshaped how every publication thinks about attack surface.

Latacora — “Cryptographic Right Answers” (2018, periodically updated). The post that replaced a thousand hours of argued-over cryptography decisions with a maintained cheat sheet. Its influence is quiet and total: when a developer picks AES-GCM, XSalsa20, or libsodium without a meeting, this document is why.

James Kettle — “HTTP Desync Attacks: Request Smuggling Reinvented” (2019). The PortSwigger research post that turned a decade-old curiosity into a systematic, tool-supported technique class — and into thousands of discovered vulnerabilities across real CDNs and proxies. The clearest demonstration of the last decade that “old bug class” is not “dead bug class”.

Google Project Zero (Ian Beer) — “A very deep dive into iOS exploit chains found in the wild” (2019). The multi-part analysis of real, in-the-wild iPhone exploit chains — published at a depth the vendor disclosures never reached, and arguably the single most-discussed piece of technical writing of its year. It set the standard for what “documenting a real attack chain” should look like in public.

Honorable mentions

  • The launch and steady operation of Have I Been Pwned (2013) — less a post than a public institution born from one.
  • Adam Langley’s ImperialViolet notes on TLS and certificate pragmatics — repeated individual posts that moved browsers.
  • CISA’s joint advisories as a genre: the state-sponsored-attribution write-ups of the 2020s that made primary-source reading a mainstream practice.

Sources & attributions

  1. Every title above links to the primary source where the origin host publishes it freely; where an episode is described, the description follows the show’s own published notes.
  2. Selection criterion (demonstrated behavioral influence) and dating: editorial judgment of the Sentinel, 20 September 2026, revisited annually — see Disclosures — editorial & sourcing policy.
  3. The 2005 Ranum essay is included with its date stated plainly: it is one month outside the strict twenty-year window and inside every relevant syllabus.