Download on the App Store

episodes

  • Episode 160 Right to Repair’s Summer of Love – Sort of.

    In this week’s episode of the Podcast, # 160: call it Right to Repair’s “Summer of Love.” Summer 2019 saw developments on a number of fronts in the nation-wide battle to win a digital right to repair. In this podcast, we talk with Nathan Proctor of US PIRG’s Right to Repair campaign and Kyle Wiens of iFixit about the developments.







    Summer is typically a slow time, but for those in the trenches of the struggle to create a digital “right to repair,” the Summer of 2019 was anything but sleepy.



    Following a legislative  season in which 20 states brought forth right to repair legislation, with almost all encountering stiff opposition from industry, this summer brought glimmers of hope. In July, the Federal Trade Commission hosted a workshop dubbed “Nixing the Fix” that delved into industry restrictions on repair. Then, in August, right to repair advocates (including yours truly) traveled to Las Vegas to speak as part of Ethics Village at the annual DEF CON hacking conference.



    Opinion: my Grandfather’s John Deere would support our Right to Repair



    Nathan Proctor heads up the national Right to Repair campaign for US PIRG



    In the headlines, August saw Apple on both sides of the repair divide. First, the company was excoriated for disabling battery health monitoring features on iPhones that had batteries replaced by non “authorized” Apple repair technicians. That highlighted what repair advocates warn are increasingly aggressive moves to block independent and owner based repairs and servicing on the Cupertino, California company’s products.



    Introducing Securepairs.org: Fighting Infosec FUD for the Right to Repair



    Paradoxically, it was Apple that just days later delivered an unexpected victory to repair advocates when it announced, last week, that it was launching an Independent Repair Provider program and would begin selling Apple parts to independent repair shops that were not part of its authorized service providers program. (That program may be less than it appears, but more on that in the podcast.)



    Podcast Episode 139: the State(s) of Right to Repair and API Insecurity on GitHub



    Kyle Wiens is the CEO of iFixit



    This left us here at the Security Ledger wondering: what just happened? And, with 2019 drawing to a close: where do things stand with the right to repair? Is Apple’s end of summer decision on replacement parts the beginning of the end of resistance to a digital right to repair or,
    25 min
  • Episode 159: Deep Fakes and Election (in)Security with ZeroFOX

    In this week’s episode of the podcast (#159) we delve into the myriad challenges to election security with Sam Small, the Chief Security Officer at the firm ZeroFOX. While public attention may be focused on voting machinery, an even bigger risk comes from social manipulation of the voting public using platforms like Facebook and Twitter, as well as so-called ‘deep fake’ videos and audio to sow confusion, Small tells me.







    The Voting Village at the recent DEFCON Conference in Las Vegas put the spotlight on both software and physical security holes in electronic voting equipment used all over the United States. But that’s old news – to say the least. And, as we’ve argued before: they may even be a distraction.



    Voting Machine insecurity is a Distraction



    The question we should be asking is this: are the parties who want to influence the outcome of, say, the 2020 presidential race in the United States even interested in tampering with voting machines? After all: there are many other ways to effect the outcome of an election and many more ready tools with which to do so than wonky, 20 year old electronic voting systems. 




    Welcome to @defcon @VotingVillageDC — where the voter ID check in machine has no BIOS password so we can boot whatever we want onto the machine. pic.twitter.com/FpJBI3ZAPZ— Rachel Tobac (@RachelTobac) August 10, 2019




    Take social media. (Please!) Facebook’s former CISO, Alex Stamos warned this week in an interview that Facebook’s popular Instagram photo sharing service might be weaponized during the 2020 presidential race.



    Stamos, who left Facebook in 2018 and now serves as the director of the Internet Observatory at Stanford University, said that Instagram’s picture-first platform would pose little challenge to the Russian Internet Research Agency which, Stamos notes, employs teams of people to craft sophisticated visual “memes” that can be shared on platforms like Instagram. 



    Consider the Deep Fake…



    Or what about deep fake videos? With machine learning technology now able to morph video and audio to suit the needs of anyone with a laptop and some time on their hands, there is really no limit to how a campaign narrative might become distorted or driven off course. 



    How worried should we be? In this episode of the podcast we sat down to talk with someone who should know: Sam Small, the Chief Security Officer of the firm ZeroFOX.



    Sam Small is the Chief Security Officer at the firm ZeroFOX.



    In this interview, Sam and I talk about the myriad threats to the integrity of our elections and whether our public institutions as well as private platforms like Facebook and Twitter are up to the challenge of securing the integrity of democratic elections. 



    Sam notes that,
    22 min
  • Episode 158: How NotPetya has Insurers grappling with Systemic Cyber Risk

    In this episode of the The Security Ledger podcast (#158): the NotPetya malware outbreak in 2017 raised red flags about the potential for malware to pose systemic risk to insurers: affecting broad swaths of the economy. We talk to Bruce McConnell of the East West Institute about how insurers are responding.







    NotPetya spread across Europe and North America at lightening speed. It was one of the most expensive malware attacks of all time: with damages totaling $10 billion. And, for companies impacted, it was impressively damaging: halting production lines and operations at global corporations in shipping, pharmaceuticals and manufacturing. one of the most virulent malware attacks ever.



    Read Security Ledger coverage of NotPetya here.



    But NotPetya was important for other reasons, as well. It exposed gaps in traditional approaches to information security. For industries like insurance, NotPetya underscored the prospect of “systemic cyber risk”: the ability of a malware, believed to be of Russian origin, to cause ripple effects that could spread beyond its immediate victims and throughout an economy.



    Bruce McConnell is the Executive Vice President at the East West Institute



    NotPetya’s rapid spread from small Ukrainian firms to some of the biggest companies in the world and the disruption it caused hinted at the kinds of ripple effects a devastating malware outbreak could have if it targeted a commonly used software component or a major services or infrastructure provider. 



    To better understand what systemic cyber risk is all about and how the insurance industry is taking steps to address it, we invited Bruce McConnell, the Executive Vice President of the East West Institute into The Security Ledger podcast to talk. East West has authored a report : Cyber Insurance and Systemic Market Risk—to provide a framework to better understand and address the systemic nature of cyber risk and the challenges it presents to the burgeoning cyber insurance industry. 



    In this interview, Bruce and I talk about the growing specter of systemic cyber risk and how insurance companies are adapting to that risk. 







    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and check us out on SoundCloud, Stitcher, Radio Public and more. Also: if you enjoy this podcast,
    26 min
  • Episode 157: Do we need an FDA for Software? Also: operationalizing Threat Intelligence

    In this week’s episode of the Podcast, # 157, sponsored by LookingGlass Cyber Solutions: Sarah Zatko of the Cyber Independent Testing Lab joins us to talk about CITL’s big new study of firmware security. In our second segment, we’re joined by Allan Thomson who is the Chief Technology Officer at LookingGlass* to talk about the growing use of cyber threat intelligence and the need to evolve cybersecurity practices to keep ahead of fast-evolving threats.







    On Firmware Security: Nobody’s Trying



    The Mirai Botnet caught the world’s attention back in 2016 as the first, high profile IoT botnet. Since then, attacks on Internet of Things devices have grown rapidly. Why? Well, for one thing: they’re easy marks. Two decades ago, Microsoft’s Windows Operating System, IE browser and Office software were the primary targets of malicious hackers because they were widely used and widely known to be vulnerable to attack. Today, those platforms are far more secure and boast protections against a wide range of common attacks like buffer overflows.



    On the Internet of Things, however, things are different. Connected devices like home routers, IP enabled cameras and digital video recorders or smart televisions and appliances commonly run software – or “firmware” – that lacks even basic protections against common threats like buffer overflow attacks. That makes them easy prey for hackers looking to gain a foothold on a home or business network, or interested in building powerful “botnets” of infected devices to do their bidding.



    How bad is it on the Internet of Things? It has been hard to say. Unlike Windows or Office – which were made and managed by a single company – there are thousands, even tens of thousands of device makers out there. Each is distributing its own device firmware. Up until now, nobody has ever undertaken the job of studying this software to figure out how secure it is. But that changed last week, when the Cyber Independent Testing Lab released data from what it is calling the first longitudinal study of IoT device security. The results were not surprising, but they were surprisingly bad.



    The CITL study surveyed firmware from 18 vendors including ASUS, D-link, Linksys, NETGEAR, Ubiquiti and others. In all, more than 6,000 firmware versions were analyzed, totaling close to 3 million binaries created from 2003 to 2018. Time and again, firmware from commonly used manufacturers failed to implement basic security features even when researchers studied the most recent versions of the firmware.



    Even worse, CITL researchers found no clear progress in any protection category over time, said Zatko. Researchers documented 299 positive changes in firmware security scores over the 15 years covered by the study…but 370 negative changes over the same period. Looking across its entire data set, in fact, firmware security actually appeared to get worse over time, not better, CITL said.



    In our first segment this week, Security Ledger is airing an interview that I did with Sarah Zatko, the Chief Scientist of CITL last week in Las Vegas. Sarah was presenting the CITL’s findings at an event sponsored by the Hewlett Foundation. I started by asking her about one of the proposals she made for shoring up software security: to create an agency akin to the FDA just to manage software security. Wasn’t that the job of the FTC, I wanted to know?



    Does Threat Intelligence make you Smarter?



    In our second segment: threat intelligence services have fast emerged as a critical tool in the tool belt of enterprise security teams. But what is security intelligence really?


    33 min
  • Spotlight Podcast: Unpacking Black Hat Hacks with Digicert CTO Dan Timpson

    In this Spotlight Podcast, we broadcast from the Black Hat Briefings in Las Vegas Nevada. Dan Timpson, the Chief Technology Officer at DigiCert* joins us to talk about some of the high profile hacks at this week’s “hacker summer camp” and the common weaknesses and security lapses that are common to all of them.







    In this week’s episode of the Podcast, # 156: we’re back at “hacker summer camp” in Las Vegas this week – also known as the Black Hat, B-Sides and DEF CON conferences, which bring tens of thousands of the world’s top security experts to the Las Vegas Strip. 



    The three conferences, collectively, feature hundreds of presentations on security vulnerabilities, exploits and attacks on all manner of devices – from airplanes to vacuuming robots. 



    “What was a conversation about authentication on the web is now accelerated to all kinds of avenues in the ecosystem” – Dan Timpson, Chief Technology Officer, Digicert



    Authentication, Encryption and Code Authenticity Core Issues



    Dan Timpson is the Chief Technology Officer at DigiCert



    But if you look behind many of the security demonstrations, a common theme emerges: poor security designs and implementation centered on a trifecta of issues: authentication, encryption and code signing.



    Our guest this week, Dan Timpson, sees this first hand at the Chief Technology Officer at DigiCert, one of the world’s largest certificate authorities. In this conversation with The Security Ledger, Dan and I dig into some of the hot talks at this year’s show and talk about the underlying security issues that inform them, including poor implementations of PKI technologies and, increasingly, threat modeling that is inadequate to the new context of the Internet of Things. 



    To start off, Dan and I talk about the shifting conversation about PKI and authentication that has come with the Internet of Things and how events like the Edward Snowden leak of data from the CIA changed the conversation about protecting sensitive data and authenticating transactions. 







    (*) Disclosure: This podcast was sponsored by Digicert. For more information on how Security Ledger works with its sponsors and sponsored content on Security Ledger, check out our About Security Ledger page on sponsorships and sponsor relations.



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and check us out on SoundCloud, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted. 


    26 min
  • Episode 156: Looming over Black Hat: doing Security at Massive Scale

    In this episode of the Security Ledger Podcast (#156), we’re joined by Michael Coates, the former Chief Information Security Officer at Twitter and the CEO and co-founder of Altitude Networks.* With “hacker summer camp” kicking off in Las Vegas, Michael and I talk about the pre-eminent challenge for the information security industry: how to do security at the massive scale and speed of cloud environments like AWS.







    In this week’s episode of the Podcast, # 156: It’s time for Hacker Summer Camp again, as the The Black Hat Briefings kick off this week in Las Vegas along with B-Sides Las Vegas and, of course, the DEF CON Conference. 



    As the world’s top security professionals gather on the Las Vegas Strip, one question hanging in the air is ‘how to secure the cloud?’ A vast and growing cloud-based infrastructure today runs dynamic start-ups and unicorns like Slack and Lyft but also industry stalwarts up and down the Fortune 500. 



    Capital One a Warning on Cloud Insecurity



    Michael Coates is the CEO and co-founder of Altitude Networks.



    The recent breach at Capitol One is a fresh reminder of the risks that go along with cloud adoption. In that incident, information on more than 100 million credit card applicants was snatched from an Amazon S3 storage bucket by a rogue AWS employee. The incident has rattled the technology world and prompted at least one U.S. Senator in recent days to demand an explanation by Amazon CEO Jeff Bezos of how such a breach could happen. (Server side request forgery, maybe?)



    Our guest this week knows a thing or two about securing vast, cloud-based infrastructure. Michael Coates is the former Chief Information Security Officer at Twitter and the CEO and co-founder of Altitude Networks, a startup that does data security for cloud collaboration platforms. Altitude just emerged from stealth mode with a $9 million series A round from Felicis Ventures, Accomplice and a personal investment from former Facebook CISO Alex Stamos. The company will be demonstrating its technology at Black Hat’s Innovation City. 



    Altitude Networks focuses on securing data in cloud-based collaboration platforms.



    Secure Everything. Everywhere. At Massive Scale.



    In this conversation, Michael and I talk about how cloud based collaboration platforms like G-Suite, Office 365 and DropBox present a unique challenge to the security industry. As Michael notes: they require organizations to secure “everything, everywhere and at massive scale.” It’s a challenge that Coates experienced first hand as the CISO at Twitter, where just monitoring how data was moving was a challenge- let alone whether that movement constituted a risk or security breach. 



    Check out our full conversation in the podcast!







    (*) Disclosure: This podcast was sponsored by Altitude Networks. For more information on how Security Ledger works with its sponsors and sponsored content on Security Ledger,
    25 min
  • Episode 155: Disinformation is a Cyber Weapon and APTs warm to Mobile Malware

    In this week’s episode of the Podcast (#155): Jerome Segura of Malwarebytes joins us to talk about how disinformation campaigns and cyber crime are part of the same toxic cocktail in the world’s trouble spots, like Ukraine. Also: Adam Meyers of CrowdStrike joins us to talk about that company’s first ever report on mobile malware, which is gaining currency with advanced persistent threat (APT) groups.







    What MH-17 tell us about our Future



    Online rumors, conspiracy theories, disinformation campaigns: these are the tools of modern information warfare and they can be used to devastating effect: sowing distrust of institutions and making it difficult if not impossible for casual observers to ascertain the truth about important and consequential events.



    Jerome Segura is the Director of Threat Intelligence at the firm Malwarebytes.



    But as the researchers at Malwarebytes noted recently, disinformation campaigns don’t exist in a vacuum. Increasingly, rumors and disinformation campaigns are part of a global cocktail of instability that also includes cyber attacks and even kinetic attacks and conflict. 



    In our first segment, we speak with Jerome Segura, the director of threat intelligence at Malwarebytes, about Russian efforts to shape public understanding of the downing of Malaysian Airlines Flight 17 which was shot down over Eastern Ukraine in July 2014 by rebels armed by the Russian military.



    In this conversation, Segura talks about how Ukraine has become a theater on which the future of conflict is playing out – a future that includes the intersection of military, paramilitary and criminal actors, including cyber criminal groups operating beyond the reach of the law. 



    The Growing Threat of Mobile Malware



    The information security industry has been raising red flags about mobile malware for more than a decade. Most of those warnings however turned out to be (way) premature. To date, mobile malware represents just a sliver of all the malware detected in a given year.



    But that may be changing. As mobile devices become the go to platform for billions of Internet users, mobile threats are finally gaining traction, not only with cyber criminals but by Advanced Persistent Threat (APT) and nation-state groups. 



    Adam Meyers is the Vice President of Threat intelligence at the firm CrowdStrike.



    In our second segment, we welcome Adam Meyers, the Vice President of Intelligence at CrowdStrike into the Security Ledger studio to talk about the growing threat posed by mobile malware, as everyone from repressive governments to run of the mill thieves look to gain a foothold on mobile devices. 







    As always,  you can check our full conversation in our latest Security Ledge...
    32 min
  • Spotlight Podcast: To Fix Remote Access, CyberArk Alero Ditches Passwords and VPNs
    In this Spotlight edition of The Security Ledger Podcast, sponsored by CyberArk*, we interview serial entrepreneur Gil Rapaport about his latest creation: Alero, a new remote authentication tool that promises to fix remote vendor access by doing away with passwords…and agents…and VPNs. If that sounds like a tall order, check out our podcast to learn how he does it! 

    Third party risk is exploding for organizations. Whether the organization is in healthcare (where EHR hacks are a huge problem) or e-commerce where groups like Magecart have been targeting insecure deployments on platforms like Amazon’s S3 storage cloud. The fact is: more data breaches and network compromises are being linked to third party vendors such as contractors, managed service firms and SaaS providers. Cyber criminal groups and nation states are pursuing a “weakest link” strategy gain access to sensitive networks and data – and its working.
    Authentication: the Weak Link in Remote Vendor Access
    That puts the onus on companies to shore up the systems they use to manage third party providers and third party access to their environments. Historically, that job has fallen to technologies like Virtual Private Networks (or VPN), which create a secure tunnel from a third party into protected networks. But these days, few organizations are willing to grant third parties unfettered access to protected networks. Permissions – if they’re granted at all – will be limited to a specific application and a specific user role for that application – a use case that VPN was not designed for.
    And even the most granular access policy can be undermined by weak authentication schemes and account takeovers. Simply put: how does your company know that the third party seeking access to your trusted application is who they claim to be? The cost of not knowing is high. Granting access to an attacker or malicious actor – even to a single application – can spell disaster if your organizations handles highly sensitive or regulated data. (Just as British Airways and Marriott!)
    Alero: Beyond Passwords, Beyond VPN
    That’s where our guest this week comes in. Gil Rapaport is the co-founder of the firm Viewfinity, which made Windows least privilege management and application control software and was purchased by the firm CyberArk back in 2015. An expert in password management and application control, Rapaport’s next act he’s taking on the third party authentication challenge. As you would expect, he’s doing that by launching a startup, Alero, that promises to solve third party access by dispensing not just with VPNs but with passwords, also.
    What’s unusual is that rather than go it alone, this time Rapaport is launching his new company from within the confines of CyberArk itself: turning himself back into an entrepreneur without leaving the company that facilitated his latest exit.
    In this conversation, recorded on the sidelines of CyberArk’s Impact Conference in Chicago last week, Gil and I talk about Alero and how it works, as well as the larger problem of moving beyond passwords.

    (*) Disclosure: This podcast was sponsored by CyberArk. For more information on how Security Ledger works with its sponsors and sponsored content on Security Ledger,
    21 min
  • Spotlight Podcast: To Fix Remote Access, CyberArk Alero Ditches Passwords and VPNs
    In this Spotlight edition of The Security Ledger Podcast, sponsored by CyberArk*, we interview serial entrepreneur Gil Rapaport about his latest creation: Alero, a new remote authentication tool that promises to fix remote vendor access by doing away with passwords…and agents…and VPNs. If that sounds like a tall order, check out our podcast to learn how he does it! 

    Third party risk is exploding for organizations. Whether the organization is in healthcare (where EHR hacks are a huge problem) or e-commerce where groups like Magecart have been targeting insecure deployments on platforms like Amazon’s S3 storage cloud. The fact is: more data breaches and network compromises are being linked to third party vendors such as contractors, managed service firms and SaaS providers. Cyber criminal groups and nation states are pursuing a “weakest link” strategy gain access to sensitive networks and data – and its working.
    Authentication: the Weak Link in Remote Vendor Access
    That puts the onus on companies to shore up the systems they use to manage third party providers and third party access to their environments. Historically, that job has fallen to technologies like Virtual Private Networks (or VPN), which create a secure tunnel from a third party into protected networks. But these days, few organizations are willing to grant third parties unfettered access to protected networks. Permissions – if they’re granted at all – will be limited to a specific application and a specific user role for that application – a use case that VPN was not designed for.
    And even the most granular access policy can be undermined by weak authentication schemes and account takeovers. Simply put: how does your company know that the third party seeking access to your trusted application is who they claim to be? The cost of not knowing is high. Granting access to an attacker or malicious actor – even to a single application – can spell disaster if your organizations handles highly sensitive or regulated data. (Just as British Airways and Marriott!)
    Alero: Beyond Passwords, Beyond VPN
    That’s where our guest this week comes in. Gil Rapaport is the co-founder of the firm Viewfinity, which made Windows least privilege management and application control software and was purchased by the firm CyberArk back in 2015. An expert in password management and application control, Rapaport’s next act he’s taking on the third party authentication challenge. As you would expect, he’s doing that by launching a startup, Alero, that promises to solve third party access by dispensing not just with VPNs but with passwords, also.
    What’s unusual is that rather than go it alone, this time Rapaport is launching his new company from within the confines of CyberArk itself: turning himself back into an entrepreneur without leaving the company that facilitated his latest exit.
    In this conversation, recorded on the sidelines of CyberArk’s Impact Conference in Chicago last week, Gil and I talk about Alero and how it works, as well as the larger problem of moving beyond passwords.

    (*) Disclosure: This podcast was sponsored by CyberArk. For more information on how Security Ledger works with its sponsors and sponsored content on Security Ledger,
    21 min
  • Episode 154: Richard Clarke on Defending the Fifth Domain
    The Pentagon calls cyberspace “the fifth domain” of conflict. But what does that mean? And how do you defend a human-made space that’s everywhere and nowhere? In this episode of the podcast, Richard Clarke joins us to discuss his new book, The Fifth Domain: Defending Our Country, Our Companies, and Ourselves in the Age of Cyber Threats. 
     When we last spoke to Richard Clarke, he was on tour to promote his book Warnings: Finding Modern Cassandras to Stop Catastrophes. That book saw Clarke and a co-author: R.P. Eddy interviewing people who had warned fruitlessly about pending disasters like 9/11 and the Fukushima Daiichi nuclear power plant melt-down. That book was a way to get everyone thinking about the Cassandras among us and who are warning about coming storms, including Cyber War.
    In his latest book, The Fifth Domain co-written with Robert Knake, Richard goes deep on that very topic. The title, is reference to military parlance for cyber space, which has joined land, sea, air and space as a theater of warfare.
    But cyber space is different from those theaters. In this conversation we talk about how it is different and how those differences warrant new thinking about how to secure and protect the Internet and everything in our lives that has come to depend on it.
    To start off, Richard and I talk about his last book with Mr. Knake, Cyber War, which a decade ago predicted many of the trends we now see every day, including destructive cyber attacks launched by militaries – claims that at the time were considered “fiction.”
    Richard Clarke is the CEO at Good Harbor Consulting. He’s a former National Coordinator for Security, Infrastructure Protection and Counter-terrorism for the United States and a veteran of four administrations, from President Ronald Reagan through to President George W. Bush His new book, The Fifth Domain: Defending our Country, Our Companies and Ourselves in the Age of Cyber Threats.
    29 min