Download on the App Store

episodes

  • Episode 178: Killing Encryption Softly with the EARN IT Act. Also: SMBs Struggle with Identity
    In this episode of the Security Ledger Podcast sponsored* by LogMeIn and LastPass: the EARN IT Act is slouching its way to passage on Capitol Hill, alarming privacy and civil liberties experts. Andrea Little Limbago the Chief Social Scientist at the firm Virtu joins us to talk about why EARN IT is so dangerous. Also: small and medium sized businesses are the majority of businesses in the U.S., but they are often overlooked by the companies marketing and selling security solutions. Rachael Stockton of LogMeIn and LastPass joins us to talk about a new survey of SMBs that reveals struggles to manage identity and authentication challenges.
    52 min
  • Spotlight Podcast: How DU Telecom Manages Digital Transformation Risk

    In this Spotlight* podcast, Sayed Ali the Head of Cyber Security Risk Management & Business Continuity at DU TELECOM in the UAE joins us to talk about how digital transformation is shaking up the once-staid telecommunications industry and how his company is staying on top of both the risks and opportunities created by digital transformation.







    There are lots of terms to describe the way that technology is transforming businesses around the globe. Business leaders talk about Industry 4.0, Internet of Things and, increasingly, Digital Transformation. But for every benefit that flows from innovations like mobility, cloud computing, DEVOPS and agile development or the Internet of Things, there is a challenge.



    More than ever new, nimble competitors find it easier to leverage new technologies and disrupt legacy businesses. At the same time, cloud based applications and mobile workers strain the ability of legacy security and monitoring tools to keep threats at bay.



    Spotlight Podcast: RSA CTO Zulfikar Ramzan on confronting Digital Transformation’s Dark Side



    Sayed is Head of Cyber Security Risk Management & Business Continuity at DU Telecom.



    One of the industries feeling the weight of these changes is telecommunications, where profitable legacy businesses like fixed line telephony and text messaging are falling victim to technology fueled changes. Meanwhile, a roster of ambitious, disruptive startups stands poised to snatch away even more business, should circumstances, regulations and consumer preferences permit it.



    So how are telecommunications firms addressing both the business and IT risk that digital transformation brings? We sat down with Sayed Ali, the Head of Cyber Security Risk Management & Business Continuity at DU TELECOM in the United Arab Emirates. DU is one of just two telecommunications firms offering fixed line, mobile telephony, internet and digital television services across the UAE.



    In this conversation, Sayed and I talk about the changing risk landscape that incumbents like DU face, as well as how best to manage the growing cyber risk that goes along with digital transformation initiatives.







    (*) Disclosure: This podcast and blog post were sponsored by RSA Security for more information on how Security Ledger works with its sponsors and sponsored content on Security Ledger, check out our About Security Ledger page on sponsorships and sponsor relations.



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You 
    26 min
  • Episode 177: The Power and Pitfalls of Threat Intelligence

    In this week’s podcast (#177) we’re back from RSA Conference and talking about the growing prominence of cyber threat intelligence services with Eric Olson of the firm LookingGlass Cyber Solutions.  







    Last week’s RSA Security Conference in San Francisco showcased the latest the technology industry has to offer against sophisticated hackers, bots and viruses – even as a real world virus, COVID-19, stalked the streets of San Francisco and prompted the city government to declare a state of emergency mid-way through the event.



    Threats – Virtual and Otherwise



    That was a reminder, if any was needed, that the threats facing global organizations today are more varied and harder to predict than ever. Global pandemics can interrupt critical supply chains or bring business operations to a screeching halt. So too malware and denial of service attacks aimed at you, or just a region or third party you rely on.



    Eric Olson is the senior vice president of product management at LookingGlass Cyber Solutions.



    That cold reality may go some way towards explaining why so-called threat intelligence is all the rage among organizations both large and small. By one count, there were 79 vendors alone at RSA offering some variation of threat intelligence services.



    Words of Advice from the Justice



    The hunger for threat intelligence is so great that the Department of Justice, in recent weeks, issued guidance to private firms that were considering threat intelligence, warning them away from actions or business partners that might cross the line from gathering information on malicious activities to engaging in them.



    Managed Threat Hunting Bridges the Talent Gap



    What is threat intelligence and what value does it offer to companies worried about falling victim to sophisticated cyber actors? In this RSA wrap-up podcast, we’re taking on the challenge of answering that question. And, to do so, we’ve invited an expert on the subject into the studio.



    Opinion: AI and Machine Learning will power both Cyber Offense and Defense in 2020



    Eric Olson is the senior vice president of product management at LookingGlass Cyber Solutions. In this conversation, Eric talks about what the term “threat intelligence” means in 2020, how companies are turning threat intelligence to their advantage and about some simple steps that organizations who haven’t already invested in this type of information service can take to start making threat intelligence work for them.







    (*) Disclosure: This podcast was sponsored by LookingGlass Cyber Solutions or more information on how Security Ledger works with its sponsors and sponsored content on Security Ledger, check out 
    31 min
  • Spotlight Podcast: The Demise of the Password may be closer than you think!

    In this Spotlight* podcast, Yaser Masoudnia of LogMeIn and LastPass talks about the continued persistence of the password in enterprise IT environments and how its inevitable demise (and replacement) may be closer than you would think.







    If you look back the seminal hacking film, 1983’s War Games, not much about the technology will seem familiar. The computer monitors are monochrome. There are modems instead wired – let alone wireless networks – to connect computers to the Internet and each other. Data is stored on 5 1/2” floppy disks. But one bit of technology is strikingly familiar: the password.



    High school student David Lightman ( played by Matthew Broderick) makes a game of finding and using them: hacking into his school’s grading system and, eventually, guessing the password needed to access a back door account on a military supercomputer.



    Senior Director Product Management, Identity Access Management, at LogMeIn



    More than 35 years later, the security of a discomforting number of modern IT systems and networks is protected by the same flimsy and vulnerable defense. But how do we finally ditch the password and embrace something stronger, that’s resilient, easier to use and harder to abuse? The solution may be closer than you think.



    To talk about it, we invited Yaser Masoudnia, the Senior Director Product Management, Identity Access Management at LogMeIn into the studio to talk. In this conversation, Yaser and I talk about some of the struggles that organizations have abandoning passwords and the trends that are moving organizations towards a passwordless future – and what password-less means.







    (*) Disclosure: This podcast was sponsored by LastPass, a LogMeIn brand. For more information on how Security Ledger works with its sponsors and sponsored content on Security Ledger, check out our About Security Ledger page on sponsorships and sponsor relations.



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and check us out on SoundCloud, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted. 
    21 min
  • Episode 176: Security Alarms in Census II Open Source Audit. Also: The New Face of Insider Threats with Code42
    In this week’s episode of The Security Ledger Podcast, sponsored* by Code42, we do a deep dive on the security implications of the recently released Census II audit of open source software. We’re joined in our first segment by Frank Nagle of Harvard University’s Laboratory for Innovation Science and Mike Dolan, the Vice President of Strategic Programs at The Linux Foundation. In our second segment: tools like Slack and Microsoft Teams are revolutionizing how workers collaborate and communicate, but they also make it easier than ever for employees or malicious insiders to abscond with sensitive information. Joe Payne the CEO of Code42 joins us to talk about how the challenge of data breach prevention is changing.











    But first: software is eating the world, as the saying goes, and these days much of that munching is happening courtesy of free and open source software. Since the open source software movement first got going in the early 1980 with the GNU Project, the use of open source has grown exponentially. Today, open source libraries and other components can be found in virtually every substantial software application in use.




    Census II exposes OSS Security Debt




    But the rapid and friction-less adoption of open source isn’t without a cost. Namely: security debt. While the popular wisdom is that the wisdom and energy of the crowd is sufficient to keep open source software components secure and stable, history has indicated otherwise, as bugs like Heartbleed in the ubiquitous OpenSSL software opened the eyes of the security community to the fact that serious bugs and exploitable holes may lurk in other, widely used open source components. But surveying such a massive repository of code is a Herculean task. Better to know which open source components are the most widely used and shared, and which pose the greatest security risks.





    That’s why the folks at Harvard University’s Laboratory for Innovation Science and The Linux Foundation teamed up on the second open source Census and the first ever census to identify and measure how widely open source software is deployed within applications by private and public organizations. The goal was to draw a more complete picture of FOSS usage including through analyzing usage data provided by partner Software Composition Analysis (SCA) companies.





    Their report, dubbed “Vulnerabilities in the Core,” and recommendations it offers are a unique insight into the security challenges facing the open source community.





    To discuss their work, we invited Frank Nagle of Harvard Business School and Mike Dolan of the Vice President of Strategic Programs at The Linux Foundation in to talk about the Census II findings and what they mean for the larger project of securing open source code.




    The New Face(s) of Insider Threat




    Back in the Watergate era, stealing sensitive data was a cloak and dagger affair. The burglars hired to obtain sensitive strategy documents from the Democratic National Committee needed physical access to offices and file cabinets and went equipped with flash lights, lock picks, and other implements to do the job.





    46 min
  • Spotlight Podcast: How Machine Learning is revolutionizing Application Fuzzing

    In this Spotlight episode of the Podcast, sponsored* by ForAllSecure we speak with CEO David Brumley about application “fuzzing” and how advancements in machine learning technology are allowing security researchers to find more and more serious vulnerabilities faster. The challenge now, Brumley says, is to keep up with the machines.







    The media’s focus on artificial intelligence and machine learning technologies are mostly confined to digital voice assistants like Amazon’s Alexa or the many AI and ML applications in healthcare, public safety – even criminal justice and medicine. But the same technologies are bringing about a quiet revolution in the field of information security.



    One area that have seen rapid advancement thanks to ML and AI is the tried and true practice of “fuzzing” – or testing software applications for defects and exploitable vulnerabilities.



    A highly specialized discipline, bug hunting is also highly data- and work intensive. That’s driven bug hunters to look for ways to speed and automate the discovery and testing of software holes.



    David is the CEO of ForAllSecure



    Our guest for this episode of the podcast, David Brumley, said that machine learning is transforming fuzzing as a strategy, as advanced machine learning algorithms are being coupled with analytic methods like “symbolic execution” to model the operation of software applications and note the presence of serious security flaws.



    (Check out our previous podcast conversation with David about security automation here.)



    In this conversation, David and I talk about the growing importance of application fuzzing as a security tool and some of the complications that large scale vulnerability discovery has created.







    (*) Disclosure: This podcast was sponsored by ForAllSecure for more information on how Security Ledger works with its sponsors and sponsored content on Security Ledger, check out our About Security Ledger page on sponsorships and sponsor relations.
    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and check us out on SoundCloud, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted. 
    25 min
  • Episode 175: Campaign Security lags. Also: securing Digital Identities in the age of the DeepFake
    Sponsored by DigiCert. In our first segment, Andrew Peterson, the CEO of the cyber security firm Signal Sciences joins us to talk about the struggles that campaigns have managing online security. In our second segment: in an age of deep fakes and software supply chain hacks, securing online identity these days is about a lot more than lock icons in your browser window. In part 2 of our podcast we’re joined by Dan Timpson, Chief Technology Officer at Digicert to talk about the fast expanding terrain of securing online identities.
    46 min
  • Episode 174: GE’s Very Bad Day – Unpacking the MDHex Vulnerabilities

    The U.S. Department of Homeland Security warned of critical vulnerabilities in a range of products by GE. We speak with Elad Luz, the head of research at CyberMDX, which discovered the holes.







    Caring for sick patients in a hospital is as much about mastering technology these days as it is about mastering biology, physiology and chemistry. The modern hospital room is a forest of beeping, blinking computer hardware that does everything from measuring vital signs to administering medication or life saving treatments.



    Report: Hacking Risk for Connected Vehicles Shows Significant Decline



    All that hardware and software is prone to cyber security vulnerabilities, however, and cyber risk is a growing concern for providers. Witness the warning issued by the Department of Homeland Security on January 23 about a slew of vulnerabilities in products by healthcare giant GE.



    Elad Luz is the head of research at CyberMDX.



    DHS’s ICS CERT warned that a collection of six cybersecurity vulnerabilities discovered in a range of GE Healthcare devices could allow an attacker to make changes at the software level of the device. Those changes could render the device unusable, interfere with its proper functioning, expose Patient Health Information – or all of the above.



    The vulnerabilities – collectively referred to as MDhex – were discovered by the firm CyberMDX, which was looking into the product’s use of a deprecated open source component known as “webmin” as well as what the company described as “problematic open port configurations” in GE CARESCAPE patient monitoring workstation. Five of the vulnerabilities were given CVSS (v3.1) values of 10, while the remaining vulnerability scored an 8.5 on the National Infrastructure Advisory Council’s (NIAC) 1-10 scale for assessing the severity of computer system vulnerabilities.



    In this episode of the podcast, we invited Elad Luz, the head of research at CyberMDX into the studio to talk about the security holes. Luz and CyberMDX discovered the flaws, reported them to GE and then worked with the company and DHS on a coordinated disclosure of the holes. In this conversation, Elad and I talk about the flaws CyberMDX discovered and some of the challenges facing healthcare organizations as they try to secure medical hardware and software deployed in clinical settings.


    22 min
  • Episode 173: Iran’s Cyber Payback for Soleimani Killing may have a Long Fuse

    As it weighs further response to the assassination of General Qasem Soleimani, Iran is almost certain to consider the use of cyber attacks. We talk with Levi Gundert at the firm Recorded Future about what cyber “payback” from Tehran might look like.







    When missiles from Iran landed near U.S. military bases in Iraq, the world assumed that it was an escalation of tensions between Iran and the U.S. in response to the January 3rd U.S drone assassination of General Qasem Soleimani, a high-ranking member of the Iranian government and the architect of the country’s Middle East policy.



    But fears of a shooting war between the U.S. and Iran have eased in the days following the Iranian missile launch, which caused no U.S. casualties and little damage and which were followed by mollifying comments from both the Iranian and U.S. leadership.



    Disaster averted? Not so fast.



    Levi Gundert, Recorded Future



    Disaster averted? Not so fast, say Middle East experts. “Killing Soleimani crossed a significant threshold in the US-Iran conflict,” Kiersten Todt, managing director of the Cyber Readiness Institute told CNN.  “Iranians will certainly try to retaliate — definitely in the region and they will also look at options in our homeland. Of the options available to them, cyber is most compelling.”



    Government, Private Sector Unprepared for 21st Century Cyber Warfare



    With Iran’s kinetic response mostly symbolic, speculation is now focused on the cyber theater, where Iran’s government has used hacking to advance both domestic and geopolitical objectives before. In recent memory, for example, the country tapped the Chafer hacking group to target aviation repair and maintenance firms in 2018 in an apparent effort to obtain information needed to shore up the safety of that country’s fleet of domestic aircraft, according to research by the firm Symantec.



    Those concerns prompted the U.S. Department of Homeland Security to issue a warning to private sector firms to prepare for the worst. But what might “the worst” look like?



    Episode 80: APT Three Ways



    A well-developed Offensive Cyber Program



    Iran has a well-developed offensive cyber program and has been linked to attacks against public and private interests in Saudi Arabia, the United States and Europe, according to experts. The country already has successfully executed several known major cyber attacks against the United States, with two notable ones occurring in
    22 min
  • Episode 172: Securing the Election Supply Chain

    In this episode of the podcast (#172), Jennifer Bisceglie, the founder and CEO of Interos to talk about the links between America’s voting infrastructure and countries with a history of trying to subvert democracy.







    With an election year upon us, the media’s attention has swung back the vexing issue of election security. Given the documented interference by Russia in the 2016 presidential election and anomalies in the performance of electronic voting systems in both 2016 and 2018, as well as the recent UK Parliamentary elections, both government and watchdog groups worry about foreign actors tampering with election results in crucial (“swing”) districts.



    Report: Chinese Ties to US Tech Firms put Federal Supply Chain at Risk



    Supply chain: the unseen election risk



    Jennifer Bisceglie is the CEO of the firm Interos.



    But efforts to secure voting systems at election time can only go so far, according to research released this month from the firm Interos. The company found that one fifth (20%) of the hardware and software components in a popular voting machine came from suppliers in China. Furthermore, close to two-thirds (59%) of components in that voting machine came from companies with locations in both China and Russia.



    Podcast Episode 142: On Supply Chains Diamond-based Identities are forever



    Heightened awareness of supply chain risk



    The study comes as the U.S. government and Trump Administration are issuing guidance to private sector firms and government agencies to steer clear of hardware and software from countries with a history of spying and espionage within the U.S., including hardware giants like the Chinese firm Huawei.



    In this week’s podcast, we sat down with Jennifer Bisceglie, the founder and CEO of Interos to talk about the links between America’s voting infrastructure and countries with a history of trying to subvert democracy.



    In this conversation, Jennifer and I also talk about the larger issue of supply chain risk, which Bisceglie says goes well beyond cyber security, encompassing ethical sourcing, environmental risks and more.







    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and check us out on SoundCloud, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted. 
    23 min