Download on the App Store

episodes

  • Spotlight Podcast: Building Resilience into the IoT with Rob Spiger

    In this Spotlight edition of the Security Ledger Podcast, sponsored by Trusted Computing Group*: we’re joined by Rob Spiger, a principal security strategist at Microsoft and co-chair of the cyber resilient technologies working group at Trusted Computing Group. Rob talks to us about efforts to make more resilient connected devices and how the advent of the Internet of Things is changing TCG’s approach to building cyber resilient systems.







    When the trusted computing group first hit the scene 20 years ago, the idea was to provide a so-called “root of trust” from which security operations might be launched, and a secure enclave from which devices could recover should all else fail.



    But attacks these days aren’t as simple as removing malware from a windows system and getting it back up and running. Destructive malware like Shamoon, NotPetya and WannaCry have shown that disruption and even physical destruction of devices may be the objective of malware infections and hacks. At the same time, so-called “advanced persistent threat” (APT) actors have made a practice of stealthy, long-lived compromises designed to harvest information or extend control over compromised environments.



    A Focus on Cyber Resilience



    And, as Internet of Things devices permeate both commercial and private networks, the cyber physical consequences of comprises mount. That’s why the Trusted Computing Group is expanding its work on what it calls “cyber resilient technologies” that can help restore connected devices to a working state in the event of a cyber attack or other disruption.



    In this spotlight edition of the podcast, we invited Rob Spiger of Microsoft into the studio to talk about this concept of “cyber resilience.” Rob is a 17 year veteran of Microsoft and the co-chair of the Cyber Resilient Technologies Working Group at TCG.



    Breaking the Ice on DICE: scaling secure Internet of Things Identities



    Rob Spiger is a principal security analyst at Microsoft and co-chair of the Cyber Resilient Technologies Working Group at Trusted Computing Group.



    In this conversation, Rob and I talk about how the importance of cyber resilience has grown in recent years and how TCG is adapting to address the unique challenges of the Internet of Things, including the need to manage physically remote devices and devices deployed at massive scale.



    Rob notes that the concept of resilience is not so much different today from what it was 20 years ago when TCG was first setting up shop, even though technology use cases have changed dramatically.



    “The concept is that devices could be come compromised and you need re-establish them to a trusted stage and resume normal or limited operations if mitigations are not available immediately,” Spiger told me. “The basic concept is to provide better protections and detect if an attack has occurred and then to recover from that attack to a trusted state.”



    28 min
  • Spotlight Podcast: Beyond HIPAA – a Conversation with Nemours CPO Kevin Haynes

    In this Spotlight edition of The Security Ledger Podcast, sponsored by RSA Security*, the Chief Privacy Officer at Nemours Healthcare, Kevin Haynes, joins us to talk about the fast evolving privacy demands on healthcare firms and how the Chief Privacy Officer role is evolving to address new privacy and security threats.







    In just a couple weeks The California Consumer Privacy Act – or CCPA – will take effect. Considered the most comprehensive data privacy law in the country, the CCPA could become a de-facto federal standard akin to the EU’s GDPR, at least in the absence of a matching federal law.



    The law, enforcement of which begins in July, 2020, will be a wake up call to many industries that have made a business of collecting, mining and even re-selling their customers data. One industry that is unlikely to be phased by the new requirements, however, is healthcare. That’s because a comprehensive patient data privacy law, HIPAA, has governed that industry for more than two decades.



    Spotlight Podcast: RSA CTO Zulfikar Ramzan on confronting Digital Transformation’s Dark Side



    Healthcare Industry beset by Changes



    Kevin Haynes is the Chief Privacy Officer at Nemours Healthcare.



    But the existence of a strong federal data protection law for patient health information doesn’t leave the healthcare industry immune from controversies, risks or questions about the extent of privacy protections. That’s especially true as a new generation of connected medical devices work their way into clinical settings, exposing them to cyber and operational risks in new ways. And, as data hungry firms like Google look to expand their reach into the massive healthcare industry, healthcare firms are needing to balance their interest in new treatments and better customer service against the privacy rights and concerns of their members. Concerns about data privacy and the abuse of medical information, for example, has dogged initiatives like Google’s Project Nightingale since its inception.



    The Role of Healthcare CPO: Beyond HIPAA



    To learn more about the unique challenges facing healthcare organizations, we invited Kevin Haynes, the Chief Privacy Officer of the Nemours Foundation – a pediatric health provider in six states and the District of Columbia – about how the role of Chief Privacy Officer is changing and adapting to the challenges and threats facing healthcare organizations.



    Massive Marriott Breach Underscores Risk of overlooking Data Liability



    Haynes says that – despite laws like HIPAA and even CCPA- privacy protecti...
    30 min
  • Episode 171: Stopping the 21st Century’s Plumbers – Defending Digital Campaigns from Hackers

    In this week’s episode of the podcast (#171): as voters go to the polls in the UK and primaries loom here in the U.S., we sit down with Michael Kaiser, the CEO of a new group: Defending Digital Campaigns and Joel Wallenstrom, the CEO of secure collaboration platform Wickr to discuss efforts to extend an information security lifeline to political campaigns in an era of epidemic campaign hacking and online disinformation.







    Cyber attacks on high profile political campaigns aren’t just an artifact of the 2016 presidential campaign in the U.S. or the 2015 Brexit referendum in the UK. In fact, attacks on campaigns – at home and abroad- predate those events and have now become more the rule than the exception. Just in the last year, there is evidence of campaign hacks and damaging leaks in the US midterm elections and in the lead-up to this week’s Parliamentary elections in the UK.



    Episode 106: Election Trolls Are Afoot. We Talk To The Guy Who Watches Them



    There are many explanations for why campaign hacks and attacks have become a fixture of modern elections. For one thing: campaigns operate almost entirely online these days, making the crowbar and flashlight routine of the Watergate burglars unnecessary. But campaigns are also slap dash affairs: spun up quickly, with ever evolving and revolving staff, and spun down just as quickly after the voting is finished.



    Michael Kaiser is the CEO of Defending Digital Campaigns.



    Furthermore, despite the never-ending media fixation on hacks of voting infrastructure, malicious operations to discredit candidates and campaigns are easier and have been shown to actually sway outcomes.



    And finally: campaigns run on shoestring budgets, with most of their available cash devoted to getting the candidate’s message out to voters. Cyber security tools and talent are not a high priority.



    Still: in the wake of the 2016 election hacking, plenty of cyber security firms stood ready to offer both tools and talent…for free, or at steep discounts. But then there’s the matter of federal election rules, which consider such discounts as ‘in kind’ gifts that were disallowed campaign donations.



    Enter Defending Digital Campaigns (DDC). The not-for-profit group that was created to give campaigns access to cybersecurity products, services and information regardless of party affiliation.



    Episode 146: Elections Loom, Political Parties struggle with Cyber Security and Securing Cloud with Aporeto’s Amir Sharif



    36 min
  • Episode 170: Cyber Monday is for Hackers

    In this episode of the podcast, sponsored by Signal Sciences: Cyber Monday may have been the biggest yet – and not just for shoppers and online retailers. Hackers use the year’s biggest online shopping day to cover their tracks. Brendon Macaraeg joins us to talk about Cyber Monday and the rising tide of e-commerce hacks.







    Cyber Monday 2019 is in the rear view mirror and this year’s holiday shopping bonanza looks to be the biggest ever. Adobe Analytics estimated this week that sales from Thanksgiving through Cyber Monday will exceed $29 billion. And, in just one measure of how shopping habits are changing, the online sales platform Shopify, which is used by more than a million merchants, reported that sales on the platform had already surpassed $1.5 billion, which is more than the sales from the full Thanksgiving weekend last year, according to reports.



    But the post-Thanksgiving weekend isn’t just big for shoppers and retailers. It is also one of the busiest weekends for cyber criminals, who find cover for their attacks and fraud among the millions of legitimate online shoppers.



    Critical Flaws in VxWorks affect 200 Million Connected Things



    Brendon Macaraeg is a Senior Director of Product Marketing at the firm Signal Sciences.



    And it isn’t just during the holiday season that online criminals hide in the crowd. A recent study by the firm Signal Sciences* found that attacks on e-commerce applications jump on the 15th and 30th of the month — pay days when overall shopping volume is higher as well.



    What does this mean for e-tailers? To find out, we invited Brendon Macaraeg of the firm Signal Sciences back into the Security Ledger Studios to talk about that company’s research which finds a rising tide of e-commerce fraud.



    Data Breach Exposes Records of 114 Million U.S. Citizens, Companies



    To start off, I asked Brendon about Cyber Monday and how e-tailers are struggling to balance a concern about security and fraud with the desperate need to have their e-commerce operation humming from Black Friday on. 







    (*) Disclosure: This podcast was sponsored by Signal Sciences. For more information on how Security Ledger works with its sponsors and sponsored content on Security Ledger, check out our About Security Ledger page on sponsorships and sponsor relations.



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and check us out on SoundCloud, Stitcher,
    27 min
  • Episode 169: Ransomware comes to the Enterprise with PureLocker

    In this episode of the podcast, sponsored by PureVPN*, Michael Kajiloti of the firm Intezer Labs joins us to talk about the origins and makeup of PureLocker, a new family of ransomware designed to target production servers in the enterprise.







    Ransomware attacks are making headlines all over the world, as the malicious, file encrypting software wreaks havoc everywhere from school districts in small town America to hospitals in France and beyond. 



    Up to now, ransomware attacks have followed a pattern: attackers target organizations indiscriminately using phishing email campaigns and malicious websites. For those unfortunate enough to click on a malicious link or open a malicious email attachment, the punishment is swift and severe: ransomware crawls their network finding, infecting and encrypting every hard drive it can find. 



    Do Cities deserve Federal Disaster Aid after Cyber Attacks?



    Michael Kajiloti is a security researcher a the firm Intezer



    Ransom fit for the Enterprise



    But as the ransomware plague continues unabated, new variants of ransomware are emerging: less noisy and more particular about the organizations and systems they will infect.



    One example of this is the recently discovered PureLocker malware: a new ransomware variant that was identified by researchers at IBM X-Force and the Israeli firm Intezer. Unlke other common ransomware, PureLocker is shy and retiring by comparison: programmed to run only on production servers deployed in the enterprise – and only under conditions most favorable to the malware’s spread. 



    Destructive Shamoon Malware Attacks Italian Oil Services Firm



    Sold as a service, the new ransomware is difficult to detect. Under the hood, it bears a striking resemblance malware used by hacking groups like Fin6 and the Cobalt Gang and linked to the same malware as a service group. 



    What does this mean about the evolution of the ransomware problem and the types of companies and assets that may be targeted?



    To find out, we invited Michael Kajiloti, a security researcher a Intezer, which discovered the malware, into the Security ledger studios to discuss PureLocker and how clues in the ransomware code helped researchers understand where it came from. 







     (*) Disclosure: This podcast and blog post were sponsored by PureVPN. For more information on how Security Ledger works with its sponsors and sponsored content on Security Ledger, check out our About Security Ledger ...
    18 min
  • Spotlight Podcast: Two Decades On, Trusted Computing Group tackles IoT Insecurity

    In this spotlight edition of the podcast, sponsored by Trusted Computing Group* Steve Hanna joins us to talk about TCG’s 20th anniversary and how the group is tooling up to confront the challenge of securing billions of Internet of Things devices.







    Twenty years ago, the Trusted Computing Group formed as a consortium of technology vendors concerned about the scourges of viruses and worms, which were then ravaging the still-young Internet. 







    That’s not unusual. The last two decades has witnessed the formation and then slow, silent deaths of hundreds of similar industry groups. But TCG’s story turned out quite differently. Today, the group counts more than 100 members across industries.



    Steve Hanna is the senior principle at Infineon technologies and co-chair of the embedded systems workgroup at The Trusted computing group. 



    Critical Flaws in VxWorks affect 200 Million Connected Things



    Even more important: the technology it has developed and promoted, including its trusted platform module (or TPM) chips, today power more than a billion devices including virtually all enterprise personal computer, many servers, networking equipment, storage drives and a growing number of embedded systems.



    Securing Billions of Devices



    But as the second decade of the 21st century draws to a close, TCG faces a monumental challenge: as computing shifts from PCs, laptops and servers to a vast universe of other devices – the Internet of Things. 



    Spotlight Podcast: Fixing Supply Chain Hacks with Strong Device Identities



    As our guest this week, Steve Hanna of Infineon, points out: many of those devices are not suited to run traditional TPM type technologies – because they are too small, too power constrained or both.



    In this spotlight podcast, Steve and I talk about how Trusted Computing Group is making the transition to the IoT and bring hardware based roots of trust to a much larger and more diverse population of devices. We also talk about why TCG succeeded when so many other industry consortiums have failed, and how the early backing from the likes of Microsoft and IBM gave Trusted Computing Group technologies a critical boost in the marketplace. 







    (*) Disclosure: This podcast and blog post were sponsored by Trusted Computing Group. For more information on how Security Ledger works with its sponsors and sponsored content on Security Ledger, check out our About Security Ledger page on sponsorships and sponsor relations.



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and check us out on 
    26 min
  • Episode 168: Application Security Debt is growing. Also: Web App Security in the Age of IoT

    In this week’s episode of the podcast (#168), sponsored by Signal Sciences, Chris Eng of Veracode joins us to talk about the 10th annual State of Software Security Report and the problem of application security debt. Also, Brendon Macaraeg of Signal Sciences talks about the expanding landscape of web application attacks and defenses.







    Ten Years On: Application Security Debt is growing



    If you want a good measure of the growth in the web application space, you might look to Veracode’s annual State of Software Security report, which has taken the measure of that company’s application vulnerability scanning activity each year (more or less) for the last decade.



    Chris Eng is the Chief Research Officer at Veracode



    The report covered a little more than 1,500 applications in its first year. In its tenth iteration, Veracode compiled data from scans of more than 85,000 applications. 



    Despite the greater volume, however, you could be forgiven for confusing the tenth SOSS with the first: most of the  vulnerabilities encountered in application scans are more or less the same as a decade ago. And it seems that companies haven’t made much progress in addressing vulnerabilities in a timely fashion. The result: mountains of security debt is piling up in enterprises as application security vulnerabilities are left unaddressed even as new vulnerabilities are created on top of them.



    In our first segment, we speak with Chris Eng, the Chief Research Officer at Veracode, about why companies still  struggle to address application security, how security debt accumulates and what organizations can do to get it off their books. 



    Opinion: Better Code Won’t Save Developers in the Short Run



    Securing Web Applications in the Age of the IoT



    As more and more businesses migrate legacy applications to the cloud, while adopting a cloud-first strategy for new initiatives, Web application security has moved from the periphery to the center of enterprise IT concerns. In our second segment, we’re joined by Brendon Macaraeg of the firm Signal Sciences* to talk about the expanding landscape of web application threats. Web application security is about more than spotting vulnerabilities in code. Once those applications are deployed they need to be defended against all manner of attacks. That’s where our next guest comes in.



    Brendon Macaraeg is a Senior Director of Product Marketing at the firm Signal Sciences. 



    Brendon Macaraeg is the Senior Director of Product Marketing at Signal Sciences, a next generation Web Application Firewall and RASP (runtime application self protection) technology.



    In this conversation, Brendon and I talk about the changing landscape of web application protection including the growing risks posed by insecure web application APIs – application program interfaces- and how growth in the Internet of Things is compounding web application security risk. 







    37 min
  • Spotlight Podcast: RSA CTO Zulfikar Ramzan on confronting Digital Transformation’s Dark Side

    In this Spotlight Edition of the podcast we’re speaking with RSA Security* Chief Technology Officer Zulfikar Ramzan about how his company is adapting to help its customers confront the dark side of digital transformation initiatives: increased digital risk, including from cloud, artificial intelligence and the Internet of Things.







    More than three decades ago, RSA Security was one of the original entrants in a market that we now know as “information security.” The company, which was formed to help commercialize the revolutionary RSA public key encryption technology became a pioneer in areas like data security, identity management and – later- fraud detection. 







    Three decades later, the information security landscape is a crowded place, while the security demands on companies are compounded by what is often referred to as “digital transformation”: an embrace of disruptive technologies like cloud computing, machine learning, artificial intelligence and the Internet of Things. 



    Three Decades On: RSA Labs Sets Course for Future



    Where does that leave RSA? The company’s President, Rohit Ghai, has likened digital transformation to climate change: a large scale transformation that creates both opportunities and challenges. Like climate change brought about by the burning of fossil fuels, digital transformation brought about by developments like machine learning, cloud computing and the Internet of Things demands new approaches to problems like cyber risk, and an “all hands on deck” approach.



    In this conversation, recorded at the recent RSA Charge Conference in Orlando Florida, I speak with Zulfikar Ramzan of RSA about how RSA is gearing up to help companies manage the digital risk that goes along with digital transformation.



    Zulfikar Ramzan is the Chief Technology Officer at RSA.



    RSA Labs: cloud, microservices, mobility shift terrain for security providers



    In this conversation, Zulfikar and I talk about the conundrum that organizations find themselves in: unable to ignore or pass on digital transformation initiatives, but unsure about the digital risks that digital transformation initiatives may introduce to their business. 



    To start out I asked Zulfikar to talk about the interplay between digital transformation and digital risk and whether companies pursuing digital transformation initiatives are attuned to the risk implications of those initiatives. 



    Check out our full conversation above!







    (*) Disclosure: This podcast and blog post were sponsored by RSA Security for more information on how Security Ledger works with its sponsors and sponsored content on Security Ledger, check out our About Security Ledger page on sponsorships and sponsor relations.

    29 min
  • Episode 167: Made in America? Trade Tensions highlight Supply Chain Risk

    In this episode of the podcast (#167): two stories this week – one from Pittsburgh and one from New York – have highlighted anxiety about Chinese made cameras and other security gear deployed in U.S. government agencies and in cities and towns. We’re joined by Terry Dunlap the co-founder of ReFirm Labs to talk about why software supply chain risks are real -and growing.







    These are times of rising international trade tensions, as the U.S. and its chief rival China impose sanctions on each other and hold on-again off again talks. In the meantime, the U.S. Congress has been aggressive in calling out the Chinese threat to domestic businesses. It has also taken action: using the most recent national defense authorization act (PDF) to ban the use or procurement of telecommunications and video surveillance services or equipment by a wide range of vendors from mainland China including Huawei, ZTE, Hytera Communications Corporation, Hangzhou Hikvision Digital Technology Company, or Dahua Technology Company.



    That decision followed years of warnings from security professionals about security vulnerabilities, back door accounts and suspicious patterns of behavior from cameras and other technology manufactured in the People Republic of China. But two stories this week suggest that simply ordering the U.S. government to swear off Chinese hardware is easier said than done.



    Witness the scene in Pittsburgh where Allegheny County District Attorney Steven Zappala bought cameras by Dahua and deployed throughout the greater Pittsburgh area. That deployment includes cameras at Fifth Avenue and Craig Street in Oakland, an intersection that gives the cameras a view of Carnegie Mellon’s Software Engineering Institute has a $731 million contract with the Air Force and the Rand Corporation, which does millions of work for the Departments of Defense and Homeland Security.



    Terry Dunlap is the co-founder of ReFirm Labs



    Or consider the case unveiled involving the principles of a New York firm, Aventura Technologies, which made tens of millions of dollars selling “Made in America” surveillance cameras, body cameras, turnstiles and other security equipment to the US military, the Department of Energy and the Treasury, among other govt. agencies. The cameras, branded as made in America, were actually made in the People’s Republic of China.



    To understand the threat that software and hardware from China poses to organizations here in the U.S. we invited Terry Dunlap of the firm ReFirm Labs back into the Security Ledger studio.



    Terry is a former NSA employee who specializes in firmware security. It was his research into Dahua that exposed the suspicious behavior of that company’s cameras, eventually leading to a U.S. government ban on the technology.



    In this conversation, Terry and I talk about the news from Pennsylvania and New York, the ways in which vulnerable and insecure hardware poses a risk to security-conscious organizations and what companies can do to address supply chain risk within their network.


    27 min
  • Episode 166: But Why, AI? ZestAI’s Quest to make Artificial Intelligence Explainable

    In this episode of the podcast (#166): Jay Budzik, the Chief Technology Officer at ZestAI, joins us to talk about that company’s push to make artificial intelligence decisions explainable and how his company’s technology is helping to root out synthetic identity fraud.







    At some point in the last decade, artificial intelligence silently crossed an invisible border that separates “cool future tech” from “technology that’s so ubiquitous we don’t even notice it.”



    Today, if you have a smart phone – and use it – it is likely that artificial intelligence is influencing everything from your travel to the office to your choice of restaurants after work -and possibly even your companion at that restaurant. In sectors like healthcare, AI is flagging tumors and other irregularities on X-rays and MRIs. In industries like high finance and banking, artificial intelligence is shaping lending and investment decisions and – of course – being used to spot illegal or suspicious behavior before it becomes costly. 



    A.I.: fighting bias, or scaling it?



    The value of this huge. According to Gartner, the business value created by artificial intelligence will reach $3.9 trillion by the year 2022 – that’s Trillion with a “T.” But with critical, life- and business sustaining decisions riding on an algorithm, the need to understand not just what an artificial intelligence system decided but why it decided the way it did has become paramount. As researchers have noted: designed or applied improperly, artificial intelligence risks recreating the biases of its authors, then dressing them up as bloodless objectivism. As McKinsey has noted: “AI can help reduce bias, but it can also bake in and scale it.”



    “In order for AI to be successful, you have to trust what its saying. And in order to to trust what it is saying, you have to understand why it thinks it is saying that.” Jay Budzik, CTO at Zest.ai



    Jay Budzik is CTO of Zest.ai



    Concerns about the “why” of algorithmic decision making has led to a push for so-called “explainable AI”: a way to reduce artificial decision making to its core elements and allow humans to make sense of why a particular decision was reached and – if they’re visible – spot the flaws in the logic the AI system used. 



    Our guest this week is an expert on making AI explainable. Jay Budzik is the Chief Technology Officer at Zest AI, a 10 year-old firm that makes artificial intelligence (AI) software for the credit industry.



    The company is a pioneer in the area of “explainable AI” In this conversation, Jay and I talk about what that means, and also about how artificial intelligence and machine learning technologies are being applied to spotting “synthetic identity fraud” – one of the most costly and hard to spot types of fraud in the banking and credit industries. 



    25 min