Download on the App Store

episodes

  • Episode 190: 20 Years, 300 CVEs. Also: COVID’s Lasting Security Lessons

    In this episode of the podcast (#190), sponsored by LastPass, Larry Cashdollar of Akamai joins us to talk about how finding his first CVE vulnerability, more than 20 years ago, nearly got him fired. Also: Katie Petrillo of LastPass joins us to talk about how some of the security adjustments we’ve made for COVID might not go away any time soon.



    [Full Transcript] | [Larry Cashdollar Transcript] | [Katie Petrillo Transcript]







    When the so-called Zerologon vulnerability in Microsoft Netlogon surfaced in late September word went out far and wide to patch the 10 out of 10 critical software hole. That job was made considerably easier by a number: 2020-1472, the unique Id assigned to the hole under the Common Vulnerabilities and Exposures – or CVE- system. 



    Larry Cashdollar is a Senior Security Response Engineer at Akamai



    Created by MITRE more than 20 years ago, CVE acts as a kind of registry for software holes, providing a unique identifier, a criticality rating as well as other critical information about all manner of software vulnerabilities. Today, it is a pillar of the information security world. But it wasn’t always that way.



    20 Years and 300 CVEs Later…



    With another Cybersecurity Awareness month upon us, we decided to roll back the clock and talk about what life was like before the creation of the CVE system. To guide us, we reached out to Larry Cashdollar, a Senior Security Response Engineer at Akamai into the studio to talk. Larry is a veteran bug hunter with more than 300 CVEs to his name. In celebration of cybersecurity awareness month, Larry talked to me about the first CVE he received way back in 1998 for a hole in a Silicon Graphics Onyx/2 – and how discovering it almost got him fired. He also talks about what life was like before the creation of the CVE system and some of the adventures he’s had on the road to recording some of the 300 CVEs. 



    10 Ways to make Your Remote Work Easy and Secure



    The New New Normal



    Six months into a pandemic that most of us thought might last six weeks, its time to stop asking when things will return to normal and time to start asking what the new normal will look like when the COVID virus is finally beaten. 



    The Essential Role of IAM in Remote Work



    Katie Petrillo is the manager of LastPass Product Marketing at LogMeIn.



    Among the changes to consider are the shifts in the workplace that were expected to be temporary, but are starting to look awfully permanent. Chief among them, the shift to “work from home” and remote work that that has millions of Americans connecting to the office from their dining room tables or home offices. 



    The pandemic has sent a surge of business to companies like LogMeIn, which makes remote access and security tools for remote workers.
    53 min
  • Podcast Episode 189: AppSec for Pandemic Times, A Conversation with GitLab Security VP Jonathan Hunt

    The pandemic isn’t the only thing shaking up development organizations. Application security is a top concern and security work is “shifting left” and becoming more intertwined with development. In this podcast, Security Ledger Editor in Chief Paul Roberts talks about it with Jonathan Hunt, Vice President of Security at the firm GitLab.







    Even before the COVID pandemic set upon us, the information security industry was being transformed. Security was long a matter of hardening organizations to threats and attacks. The goal was “layered defenses” starting with firewalls and gateway security servers and access control lists to provide hardened network perimeter and intrusion detection and endpoint protection software to protect IT assets within the perimeter. 



    Spotlight: Synopsys on democratizing Secure Software Development



    Security Shifting Left



    Jonathan Hunt is the Vice President of Security at GitLab



    These days, however,  security is “shifting left” – becoming part and parcel of the development process. “DEVSECOPS”  marries security processes like code analysis and vulnerability scanning to agile application development in a way that results in more secure products. 



    That shift is giving rise to a whole new type of security firm, including the likes of GitLab, a web-based DevOps lifecycle tool and Git-repository manager that is steadily building its roster of security capabilities. What does it mean to be a security provider in the age of DEVSECOPS and left-shifted security?



    Application Development and COVID



    To answer these questions, we invited Jonathan Hunt, the Vice President of Security at GitLab into the Security Ledger studio to talk about it. In this conversation, Jonathan and I talk about what it means to shift security left and marry security processes like vulnerability scanning and fuzzing with development in a seamless way. 



    Spotlight Podcast: Intel’s Matt Areno – Supply Chain is the New Security Battlefield



    We also discuss how the COVID pandemic has shaken up development organizations – including GitLab itself – and how the changes wrought by COVID may remain long after the virus itself has been beaten back. 







    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and check us out on SoundCloud, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email.
    28 min
  • Spotlight Podcast: Intel’s Matt Areno – Supply Chain is the New Security Battlefield

    In this Spotlight Podcast, sponsored by The Trusted Computing Group, we speak with Matthew Areno, a Principal Engineer in the Intel Product Assurance and Security (IPAS) group about the fast-changing landscape of cyber threats including attacks on hardware and software supply chains. [Read the full transcript]







    It’s funny that one of the most controversial stories about supply chain security, Bloomberg Businessweek’s scoop on “spy chips” on motherboards by the firm Super Micro that infiltrated “more than 30 companies” is remembered less for what it said than the staunch denials it provoked.



    Matthew Areno is a Principal Engineer in the Intel Product Assurance and Security (IPAS) group at Intel.



    Whether or not that story was accurate, however, security experts have long agreed that the threat it describes is real – and growing. The deep reliance of the high tech industry on software and hardware supply chains that originate in nations like China has created the conditions for compromised technology to infiltrate U.S. homes, businesses and governments at all level.



    Unfortunately, the information security industry has been slow to respond. Companies spend billions of dollars on information security tools and technology every year. But much of that spending is for fighting “the last war:” viruses, spam, application- and denial of service attacks and so on.



    Cyber: Fighting the Last War



    Our guest this week is here to tell you that those aren’t even close to being the only kinds of threats organizations need to worry about. Matthew Areno spent years conducting both offensive and defensive research at some of the most sophisticated and targeted firms in the world: Sandia National Labs in New Mexico and defense contractor Raytheon among them.



    Episode 161: 3 Years after Mirai, IoT DDoS Problem may get Worse



    Areno, who now works at Intel, where he is a Principal Engineer in the Intel Product Assurance and Security (IPAS) group, says his work at companies that were in the crosshairs of nation-state actors opened his eyes to “what was possible” in cyber offense. It also taught him how organizations – even sophisticated ones – often fail to discern the full spectrum of possible attacks on their security, with dire consequences. 



    A Range of Supply Chain Threats



    Supply chain attacks could run the gamut from degrading the performance of a sensor to exfiltrating sensitive data to denial of service attacks. “And these attacks can happen at any point in the lifecycle of these products,” Areno told me. That includes attacks on the design network that manufacturers use, attacks on shared or open source software components and – as with SuperMicro- the introduction of malicious components during manufacturing, which is an issue that Areno said is still probably more hype than reality – even if component piracy and counterfeiting is not.



    “When we’re sendings our designs over the seas, how much confidence and how much trust do we have that what we sent to them is what we got back,
    36 min
  • Spotlight Podcast: Dr. Zulfikar Ramzan on RSA’s Next Act: Security Start-Up

    Thirty eight years after it was founded, RSA Security is embarking on what may be its most challenging journey yet: cybersecurity startup. In this Spotlight Podcast, sponsored by RSA, we’re joined by Chief Digital Officer Dr. Zulfikar Ramzan about the company’s path forward as an independent company. | [Read the full transcript]







    The company which was acquired by storage giant EMC back in 2006 and then became a part of Dell when that company acquired EMC in 2015 re-emerges as an independent company this week, more than six months after it was acquired by a group of investors led by Symphony Technology Group. 



    Zulfikar Ramzan is the Chief Technology Officer at RSA.



    What does independence looks like? What will RSA do with its newfound freedoms? And how does the challenging business environment created the ongoing COVID pandemic figure into the company’s plans? 



    To find out, we invited Dr. Zulfikar Ramzan, RSA’s CTO into the Security Ledger studio. In this conversation, Zulli talks about how RSA’s path forward is informed by the company’s pioneering past, starting all the way in 1977,  when three MIT researchers Ron Rivest Adi Shamir and Len Adleman published research on a novel public key cryptosystem that took their name. 



    Three Decades On: RSA Labs Sets Course for Future



    The Past Informing the Future



    As Ramzan sees it: the daring and persistence of the founders – whose work helped create the modern Internet, but who initially had to contend with the limitations of contemporary hardware and software, not to mention Cold War era restrictions on the sale of cryptography technology outside the US. That perseverance will serve as an inspiration to RSA as it looks to re-establish its leadership in vastly altered technology and security landscape.



    Spotlight Podcast: Managing the Digital Risk in your Digital Transformation



    To start off I asked Zulli to talk about RSA’s earliest days and what messages he and other company executives take from the company’s origins almost 4 decades ago.







    (*) Disclosure: This podcast and blog post were sponsored by RSA Security for more information on how Security Ledger works with its sponsors and sponsored content on Security Ledger, check out our About Security Ledger page on sponsorships and sponsor relations.



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and check us out on SoundCloud, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to 
    25 min
  • Spotlight Podcast: Taking a Risk-Based Approach to Election Security

    In this Spotlight Podcast, sponsored by RSA, we take on the question of securing the 2020 Presidential election. Given the magnitude of the problem, could taking a more risk-based approach to security pay off? We’re joined by two information security professionals: Rob Carey is the Vice President and General Manager of Global Public Sector Solutions at RSA. Also joining us: Sam Curry, the CSO of Cybereason.



    [Read the full transcript.]







    With just over two months until the 2020 presidential election in the United States, campaigns are entering the final stretch as states and local governments prepare for the novel challenge of holding a national election amidst a global pandemic. 



    As Election Threats Mount, Voting Machine Hacks are a Distraction



    Lurking in the background: the specter of interference and manipulation of the election by targeted, disinformation campaigns like those Russia used during the 2016 campaign – or by outright attacks on election infrastructure. A report by the Senate Intelligence Committee warns that the Russian government is preparing to try to influence the 2020 vote, as well.



    A Risk Eye on the Election Guy



    Securing an election that takes place over weeks or even months across tens of thousands cities and towns – each using a different mix of technology and process – may be an impossible task. But that’s not necessarily what’s called for either.



    Robert J. Carey is the  Vice President and GM of Global Public Sector Solutions at RSA.



    Like large organizations who must contend with a myriad of threats, security experts say that elections officials would do well to adopt a risk-based approach to election security: focusing staff and resources in the communities and on the systems that are most critical to the outcome of the election. 



    What does such an approach look like? To find out, we invited two, seasoned security professionals with deep experience in cyber threats targeting the public sector. 



    Robert J. Carey is the  Vice President and GM of Global Public Sector Solutions at RSA.



    Feds, Facebook Join Forces to Prevent Mid-Term Election Fraud



    Rob retired from the Department of Defense in 2014 after over 31 years of distinguished public service after serving a 3½ years as DoD Principal Deputy Chief Information Officer.



    Sam Curry is the CISO at Cybereason



    Also with us is this week is Sam Curry, Chief Security Officer of the firm Cybereason. Sam has a long career in information security including work as CTO and CISO for Arbor Networks (NetScout)  CSO and SVP R&D at Microstrategy in addition to senior security roles at McAfee and CA. He spent seven years at RSA variously as CSO, CTO and SVP of Product and as Head of RSA Labs. 



    42 min
  • Episode 188: Flock Safety Flies in Surveillance Technology's Gray Zone Episode 188: Flock Safety Flies in Surveillance Technology’s Gray Zone

    In this episode of the Security Ledger Podcast (#188), sponsored* by LastPass, we take a look at the fast-expanding world of crowdsourced surveillance by doing a deep dive on Flock Safety, a start up that sells inexpensive license plate scanners to homeowners and police departments. Also: users know that password security is important…but they can’t seem to change their insecure behavior. In our second segment, We talk about why with Katie Petrillo of LogMeIn and LastPass.



    Flying in Surveillance’s Gray Zone



    Like many technology entrepreneurs, Garret Langley’s company started with a question that he just couldn’t answer. The solve rate for property crime in his community outside Atlanta was pitifully low. Just one in six property crimes like break ins and car thefts nationally was ever solved.



    The problem, Langley came to understand, is a lack of hard evidence: without a clear way to tie criminals to a crime scene, it is difficult for local law enforcement to even make arrests, let alone win convictions. 



    Garrett Langley is the Founder and CEO of Flock Safety



    More license plate readers would help, the police told him. But licensing so called Automated License Plate Reader (ALPR) technology is prohibitively expensive. 



    Like many entrepreneurs before him Langley found salvation in his pocket: his iPhone. Consumer smart phones, Langley realized, have all the components needed to function as capable ALPR cameras. All they needed was some weather proofing, an Internet connection and the software to manage the video feeds captured by the phones.



    The company that grew out of that revelation was Flock Safety, a start up in the surveillance market that sells inexpensive Automated License Plate Reader (ALPR) cameras to law enforcement, home owners associations and individuals. But the growing use of ALPRs, including by individuals raises a host of privacy and civil liberties concerns.



    Episode 84: Free Alexa! Cory Doctorow on jailbreaking Voice Assistants and hacking diversity with Rapid7’s Corey Thomas



    In our first segment of this week’s podcast, we do a deep dive on Flock. First, we interview Garrett about how Flock got started, how its inexpensive ALPR technology works and how the company is trying to navigate the “gray zone” of public safety, civil liberties and privacy that its technology inhabits.



    Dave Maass is a Senior Investigative Researcher at the Electronic Frontier Foundation (EFF)



    For a better understanding of those tensions, we also invited Dave Maass, a senior investigative researcher at The Electronic Frontier Foundation (EFF), into the studio. In our conversation, Dave says that the growth of consumer surveillance gear like Flock and the Ring smart doorbell raise serious privacy and civil liberties concerns for U.S. citizens, who increasingly inhabit a world saturated with private and publicly owned surveillance technology. 



    Password Security: Consistently Bad



    In our second segment this week, we have some good news: Internet users are well aware of the danger posed by weak or re-used passwords. Now the bad news: for more than three years,
    52 min
  • Episode 187: Filtergate is DRM for Water

    In this episode of the podcast (#187), sponsored by Virsec, we talk with journalist and author Cory Doctorow of BoingBoing.net about the recent GE Filtergate incident and how DRM is invading our homes. Also, Satya Gupta the Chief Technology Officer of the firm VirSec joins us to talk about how application runtime monitoring is gaining traction in the age of DevSecOps and left-shifted security.



    Read the: [full transcript] | [Corey Doctorow] | [Satya Gupta]



    DRM: An Invitation to Mischief



    Back when it passed in the 1990s the Digital Millennium Copyright Act was about protecting songs, video games and movies from digital piracy. Thirty years later, however, the DMCA’s prohibition on tampering with digital locks has been used by manufacturers of all kinds of devices to create de-facto digital monopolies on parts and services/ The same digital rights management (or DRM) technology that more or less dictates what kind of replacement ink cartridge you can put in your printer may soon compel you to only use your automakers preferred tire when you get a flat or manufacturer-approved bread for your smart toaster. That’s a scenario our guest this week has posited. Cory Doctorow is a journalist, the editor of the site Boing Boing and an author of books like Homeland, Down and Out in the Magic Kingdom and Little Brother. 



    Doctorow is an author and the editor of BoingBoing.net (Photo by Paul Roberts.)



    In this conversation Corey and I talk about the insidious spread of DRM and digital monopolies. We discuss one recent example of this, the so-called GEFiltergate incident, which saw a fridge owner going to great lengths to circumvent GE implanted RFID tags in GE-approved water filters. 



    To start off, Corey talks about how we got here and how the notion of digital rights has evolved in the last thirty years – essentially criminalizing circumventing copyright protections. That, Corey says, is an “invitation to mischief.” 



    Shifting Left with Application Runtime Monitoring



    In our second segment: information security has a scale problem. Simply put: there are too many threats, and too many threat actors for cyber defenders to keep up. Despite vast improvements in defensive technologies and so-called “incident response,” the bad guys are adapting as well – and staying one step ahead. 



    Satya Gupta is the CTO of Virsec



    Many propose the solution to this is more automation: using computers guided by machine learning and artificial intelligence to do the work fo scarce human operators. But such approaches carry real risks. Among them: false positives and false negatives, not to mention the unplanned down time each creates. 



    Our next guest says a better approach may be to stop playing whack a mole with attackers and instead focus on what matters: ensuring that code behaves as it was intended to. Satya Gupta is the CTO at the firm VirSec. In this conversation, he and I talk about how the firm started- in the wake of the SQL Slammer outbreak – and how technologies like application runtime mapping are taking on new relevance in the age of DEVSECOPS and “shift left.” 







    (*) Disclosure: This podcast was sponsored by VirSec. For more information on how Security Ledger works with its...
    49 min
  • Spotlight Podcast: QOMPLX CISO Andy Jaquith on COVID, Ransomware and Resilience

    In this Spotlight podcast* we’re joined by Andrew Jaquith, the CISO at QOMPLX to talk about how the COVID pandemic is highlighting longstanding problems with cyber risk management and cyber resilience. We also talk about how better instrumenting of information security can help companies get a grip on fast-evolving cyber risks like human-directed ransomware campaigns.







    There has been much speculation about what the long term impact of the COVID 19 pandemic will be on the private sector. Already, business leaders and investors are betting that the forced, mass experiment in remote work will produce long term changes in how companies manage their workforce.



    Andy Jaquith is the Chief Information Security Officer at QOMPLX Inc.



    But one byproduct of the shift to remote work is already clear: a marked increase in cyber attacks on corporate environments that take advantage of employees’ anxiety about the virus and lax home office security.



    Episode 151: Ransoming the City with Cesar Cerrudo of IOActive



    Ransomware’s Dangerous Rise



    Among the most scary of those attacks are so called human-directed ransomware attacks, which have sidelined sophisticated organizations ranging from the fin-tech startup Finastra to DMI, a cyber security contractor that counts the US space agency NASA as a customer. 



    Episode 107: What’s Hot at Black Hat & does DHS need its new Risk Management Center?



    What’s to be done? Our guest In this spotlight edition of the podcast, Andy Jaquith, says that COVID is exposing some rifts in corporate cyber security.



    New Tech Meets Old Tools



    While the ways in which organizations deploy and use technology has changed dramatically in the last two decades, the ways that they measure and account for cyber risk have not. 



    Andy is an amazing resource on all matters cyber security. A former Managing Director at both JP Morgan Chase and Goldman Sachs, he was also the Chief Technology Officer at the firm Silver Sky, a cloud-based MSSP.



    Episode 185: Attacking COVID, Protecting Privacy



    In this conversation, Andy and I talk about how COVID is highlighting larger issues around cyber resilience. We also talk about Andy’s new company, QOMPLX, which is working to improve ways to instrument cyber security with an eye to improve both cyber defense and risk management. 



    To start off, I asked Andy about his storied tenure in the cyber security field including his work as an analyst for Forrester and his stint at the seminal cyber security firm, @stake. You can listen using the embedded player above, or by downloading
    36 min
  • Spotlight Podcast: As Attacks Mount, ERP Security Still Lags

    In this Spotlight podcast* we’re joined by Jason Fruge, the VP of Business Application Cybersecurity at Onapsis to talk about the growing attacks against critical systems like ERP and General Ledger applications by SAP and Oracle. We also talk about why these critical systems often lag on key security measures.







    Security experts have been banging the drum about “risk based security” for years. The idea is simple: identify the assets and data within your organization that are critical to your mission, then concentrate resources – including staff and technology spending- on securing them. 



    That sounds sensible, but are companies listening? By one measure, they are not. Specifically: security for critical business systems such as Enterprise Resource Planning (ERP) and General Ledger systems continues to lag. A recent survey of 430 IT decision makers by the firm IDC, for example, found that 64% of ERP deployments had been breached within the preceding 24 months. Those incidents exposed financial, sales and HR data as well as intellectual property and personally identifiable information on customers, IDC found. 



    Jason Fruge is the VP of Application Cybersecurity at Onapsis



    Report: Cybercriminals target difficult-to-secure ERP systems with new attacks



    With all the talk about protecting organizations’ “crown jewels,” how is it that platforms like SAP and Oracle – the IT equivalent of the Tower of London where those jewels are kept – are often left unlocked and unprotected? 



    To understand a bit more, we invited Jason Fruge into the Security Ledger studios. Jason is the Vice President of Business Application Cybersecurity at Onapsis and a former CISO at fashion design firm Fossil Group.   



    How Digital Transformation is forcing GRC to evolve



    In this interview, Jason and I talk about both the technical and cultural challenges of securing applications like Oracle and SAP. Those applications are so complex and bespoke that they often frustrate analysis using traditional vulnerability scanners and other security tools. We discuss the increase in attacks targeting these systems and what organizations can do to fend off attacks.



    We also talk about the recent Onapsis publication of a slew of vulnerabilities in Oracle Business Suite, which Onapsis dubbed BigDebIt. That publication accompanies patches issued by Oracle. If left unpatched, the BigDebit vulnerabilities could allow an attacker to launch unauthenticated attacks on Oracle EBS platforms. 







    (*) Disclosure: This podcast and blog post were sponsored by Onapsis. For more information on how Security Ledger works with its sponsors and sponsored content on Security Ledger, check out 
    26 min
  • Spotlight Podcast: Two Decades On TCG Tackles Trustworthiness For The Internet of Things

    In this Spotlight Edition of The Security Ledger Podcast, sponsored by Trusted Computing Group (TCG), we’re joined by Intel Fellow Claire Vishik to talk about the evolving concept of online “trust.” Vishik is a TCG Director and spent 14 years as the Director of Trusted Technologies at Intel. We talk about how the Internet of Things is rapidly changing conversations about online “trust” and “privacy,” and the challenge of securing devices from attacks.







    You might not have heard of the Trusted Computing Group but you have definitely used technology it helped develop and deliver. The industry consortium pioneered technologies such as the Trusted Platform Modules that are in nearly every computer and personal electronic device made today, providing a hardware based “root of trust” that validates the identity, integrity and proper functioning of the device. 



    But, if you haven’t noticed, computing environments are becoming more diverse and complex. The Internet of Things is invading business and home networks and the built environment. Cloud based applications and resources have dissolved the network perimeter – and that was before the COVID pandemic sent millions of workers home to work.



    Re-Thinking Trust



    Claire Vishik, Intel Fellow & Director, Trusted Computing Group



    For this podcast, we invited Claire Vishik into the Security Ledger studios to talk. Claire is an Intel Fellow and the Chief Technology Office at Intel’s Governments, Markets and Trade group  (GMT). She spent 14 years as the Director of Trusted Technologies at Intel and is a Director at the Trusted Computing Group.



    What does a concept like “trustworthiness” mean in the era of cloud computing, smart homes and cities and the Internet of Things? How are the notions of security, privacy and trust evolving?



    Spotlight Podcast: Securing the Enterprise’s New Normal



    In this conversation, Claire and I discuss the fast-evolving future of both the Trusted Computing Group and the notion of trusted computing, as both innovation and changing technology use patterns create opportunities and risks in areas like cyber security and privacy. I started by asking Claire to talk about some of her responsibilities at both Intel and TCG. 



    As Claire sees it, the challenge in answering that question is that concepts like “cyber security” and “online trust” are incredibly broad and resist simple or reductive solutions or formulations.



    How NIST Is Securing The Quantum Era



    Connected Jewelry to Power Stations



    “When the computing age started, the platforms were distinct and not connected,” Vishik notes. “Now we have a huge diversity in both the platforms and the environments. They are as different as connected jewelry and nuclear power stations and smart grid. They are as complex as smart cities or as simple as a single function, single use sensor. Both of these systems or systems of systems are connected and need to be protected, but in different ways.”



    22 min