Download on the App Store

episodes

  • Episode 153: Hacking Anesthesia Machines and Mayors say No to Ransoms
    In this week’s podcast episode (#153): The researcher who discovered serious remote access security flaws in anesthesia machines by GE says such security holes are common. Also: the US Conference of Mayors voted unanimously to swear off paying ransoms for cyber attacks. But is that a smart idea? We’re joined by Andrew Dolan of the Multi State Information Sharing and Analysis Center to talk about it.

    In our first segment: the Department of Homeland Security on Tuesday warned hospitals about a serious and remotely exploitable security hole has been found in two anesthesia devices made by GE Healthcare. ICS Medical Advisory (ICSMA-19-190-01), released Tuesday, warns that the GE Aestiva and GE Aespire Anesthesia Machines, versions 7100 and 7900 contain software that could allow a remote attacker to connect to and remotely modify device configurations without first authenticating to them.
    Take a deep breath…or not!
    In our first segment in this week’s podcast, we speak with  the man who discovered the flaw: Elad Luz, the Head of Research at CyberMDX.
    He tells us that the GE anesthesia machines – like many medical devices – were not designed to be connected directly to local- or wide area networks that are now common in clinical settings. That connectivity comes by way of so-called “terminal servers,” that translate the serial port communications used by medical devices into TCP/IP, the lingua franca of most networks and the Internet.
    Unfortunately, GEs devices allow anyone able to communicate with a terminal server to send commands directly to the anesthesia devices without further authenticating to them. And, while many clinical organizations might wish to remotely monitor telemetry from devices like anesthesia machines, the GE devices allow remote actors to configure the machine: changing the makeup of the gasses distributed to patients, changing the time settings on the device or suppressing alarms.
    Luz said that serious and potentially life threatening security lapses like this aren’t uncommon, with medical device makers frequently failing to disable diagnostic or calibration features prior to release, or offering them to customers as a convenience without considering how they might be abused by a malicious actor.
    Mayor say ‘no’ to ransoms…then what?
    Amid a scourge of ransomware attacks affecting municipal networks, the U.S. Conference of Mayors voted unanimously this week to adopt a resolution opposing payment of  ransoms to cyber criminal groups. That’s a laudable declaration, but is it smart?
    Recent cases like the ransomware infection that hit the City of Baltimore (check out Podcast  #151 where we talk to IOActive’s Cesar Cerrudo about this) suggest that, absent strong IT security controls and a robust backup and recovery practice, some communities may face a difficult and expensive road to recovery should they tell ransomware groups to take a hike.
    That has certainly been the case in Atlanta and Baltimore where decisions to forego ransom demands of tens of thousands of dollars have led to weeks long disruptions in services and necessitated cleanup and recovery operations measured in millions of dollars.
    So is telling ransomware gangs to stuff it  really the best response? In our second segment,
    34 min
  • Episode 152: What the Silex Malware says about IoT Insecurity and Cloud Security CEO Steve Mullaney on Amazon ReInforce

    In this week’s podcast episode, #152: we talk with Akamai researcher Larry Cashdollar about his discovery of Silex, a new example of IoT killing malware allegedly authored by a 14 year old. Also: Steve Mullaney, the CEO of the cloud security start up Aviatrix joins us to talk about Amazon’s new cloud security conference: Re:Inforce.







    When Akamai researcher Larry Cashdollar checked the contents of a honeypot operates from his home network on a recent morning, he was surprised by what he saw. Buried in a binary file that turned up in his honeypot was an apologetic message from an unknown malware author for hacking and then bricking his device.



    Malware…and an Apology



    The binary turned out to be a new malicious program, which Cashdollar dubbed Silex, that was designed to break into and then wipe clean any Internet of Things device running embedded versions of the Linux operating system. 



    In our first segment, we talk to Larry about his discovery and about its alleged teenage author. We also talk about the bigger problem of insecure Internet of things devices, which are proving to be easy targets for malicious programs. 



    Larry Cashdollar is a senior security information response engineer at Akamai. 



    When Amazon brought its re:inforce show to Boston in late June,  the goal was to highlight the latest efforts that the massive cloud computing provider is taking to make its environment friendly for application developers and for security companies. But is Amazon and its AWS service a playground for new security startups, or a competitor to them? 



    In securing the Cloud is Amazon Friend or Foe?



    Watch out RSA Conference. Amazon – the world’s biggest cloud provider – hosted its first ever security conference last week: Re:inforce. But for would be cloud security providers, is the world’s biggest commercial cloud company a partner or a competitor?  



    Steve Mullaney is the President and CEO of the firm Aviatrix. 



    In our second segment this week, we’re joined by someone who should know. Steve Mullaney, the President and CEO Of Aviatrix, a startup that focuses on securing multi-cloud environments. In this conversation, Steve and I talk about the rapid computing transformation, as enterprise IT migrates swiftly to the cloud. Steve and I discuss the security needs that companies have as they migrate to cloud environments like AWS and whether Amazon, Google and Microsoft are partners to security providers, or competitors.







    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and check us out on SoundCloud, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted.
    33 min
  • Episode 151: Ransoming the City with Cesar Cerrudo of IOActive

    In this week’s episode, #151: Cesar Cerrudo, the head of research at the firm IOActive joins us to talk about the recent spate of massive ransomware payouts and why municipal government networks are the favorite target of hackers these days.







    It happened again. Less than a week after Riviera Beach Florida agreed to pay a whopping $600,000  ransom to get their data back from hackers, another Sunshine State city’s administration has been forced to do the same. On Monday, the City Council of  Lake City Florida, population of 65,000, voted to pay a ransom demand of 42 bitcoins, worth nearly $500,000.



    Podcast Episode 141: Massive Data Breaches Just Keep Happening. We Talk about Why.



    Cesar Cerrudo is the CTO at IOActive.



    This follows incidents in bigger cities, including Baltimore which notoriously turned down a $70,000 ransom demand, and ended up paying upwards of $18 million to recover data from thousands of city systems. 



    But why are cyber criminals going after the computers and networks of cash strapped municipalities?



    Report: Obvious Security Flaws Make ICS Networks Easy Targets



    To better understand what’s going on we invited Cesar Cerrudo, the Chief Technology officer in charge of Research at the firm IOActive. Cesar is the founder of Securing Smart Cities, a non profit that provides guidance and advice to city governments on how to secure their networks. 



    He is also the author of the IOActive report “An Emerging US (and World) Threat: Cities Wide Open to Cyber Attacks.” (PDF)



    I started our conversation by asking Cesar what explained the surge in attacks against cash-strapped municipal computer networks.







    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and check us out on SoundCloud, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted. 


    22 min
  • Episode 150: Microsoft’s Tanya Janca on securing Azure and Armor Scientific’s CTO on Life after Passwords

    In this week’s episode, #150: Microsoft cloud evangelist Tanya Janca joins us to talk about securing Azure and the challenges of pushing security left. Also: we continue our series on life after passwords as we speak with Nick Buchanan, CTO of Armor Scientific joins us to talk about the imminent demise of the password and what might replace it. 







    Microsoft dominated the 1980s, 90s and 2000s as the pre-eminent supplier of desktop and server operating systems and the maker of the most popular office productivity suite, web browser, email client – you name it.



    But in 2019, the days of the desktop computer are numbered and Microsoft’s future – like that of every other technology company – is intimately linked to the cloud – specifically: Azure, Microsoft’s massive cloud platform. 



    Podcast Episode 135: The Future of Passwords with Google Account Security Chief Guemmy Kim



    Secure and Azure



    Tanya Janca is a cloud developer advocate at Microsoft.



    But how do you get a population of tens of millions of developers who are used to Windows and Windows applications to start developing for the cloud? That’s part of the job of our first guest: Tanya Janca, a senior cloud advocate at Microsoft. 



    Where Microsoft grew in the 1980s and 90s by putting Windows, Office and Internet Explorer on every desktop and laptop PC (thus pushing out smaller rivals), Microsoft can’t hope to dominate the new era of cloud computing so completely, especially since its chief rival, Amazon, largely invented the space. 



    That requires a different take and a different touch, says Janca, who writes and Tweets) with the handle @shehackspurple. Among other things, it means playing nice with other “not developed here” clouds and technologies and making sure that the sheer complexity of multi cloud environments doesn’t cause customers are accidentally leaving data and assets exposed. 



    Microsoft ‘Bluekeep’ Flaw threatens Medical Devices, IoT



    In our first segment this week, Tanya and I talk about her work as an Azure evangelist and how to promote security in the age of cloud and DEVOPS. 



    Life after the Password with Armor Scientific



    Up Next: as much as people complain about the weak security offered by alphanumeric passwords, they’re still plenty popular. Possibly that’s because so many otherwise unsophisticated technology users are familiar with them – and because they’re easy.



    Nick Buchanan is the CTO of Armor Scientific



    After all, the last 10 years has brought an explosion of password alternatives into common use: fingerprint biometrics, face biometrics, hard second factors, soft second factors and so on. 



    Each new layer of authentication in theory adds to the security of your system: raising the bar for attackers. But it also adds work and complexity for your users. That, in turn, can hamper productivity or – even worse – drive users to look for shortcuts. 



    49 min
  • Episode 149: How Real is the Huawei Risk?

    In this episode of the podcast we’re joined by Priscilla Moriuchi of the firm Recorded Future, which released a report this week analyzing the security risks posed by Huawei, the Chinese telecommunications and technology giant.







    In recent months, the Trump Administration has made the technology and telecommunications giant Huawei Technologies a poster child for its assault on China’s anti-competitive practices.



    The Shenzen maker of everything from networking equipment to smart phones, Huawei has over $100 billion in sales and 180,000 employees globally. It is a key participant in China’s ambitious Belt and Road initiative to develop and modernize a broad swath of Africa, Asia and even Europe.



    Priscilla Moriuchi is the Director of Strategic Threat Development at Recorded Future



    Western doubts about Huawei’s intentions are nothing new. Silicon Valley competitors and lawmakers have long warned about Huawei’s business practices and the ties of the company and its founder Ren Zhengfei’s ties to the Chinese Military and the Communist Party. 



    The Trump Administration has ratcheted up the pressure on the company, indicting 10 senior executives on charges of theft of trade secrets and warning U.S. government agencies and allied not to use Huawei’s technology and warning companies that do business with the US government to beware. There’s evidence that the warnings are having an impact, especially in countries closely aligned with the U.S.



    DoJ Charges Huawei Execs in Broad Indictment Spanning 10 Years of Criminal Activity



    But China’s government has retaliated: warning US and western firms about the dangers of participating in Washington’s ban. That leave businesses in a pinch. But  our guest this week suggests that they may do well to be wary of Huawei, regardless of what the US Government and the Trump Administration says.  Priscilla Moriuchi is the director of strategic threat development at Recorded Future. In a report released this week, Moriuchi and Recorded Future warn that Huawei’s risk to western companies is more than just a hypothetical. The company is unique because of the breadth of its technology portfolio – everything from undersea cables to smart phones. By extension, that makes it unique in the breadth of data that it collects from customers world-wide. Today – or at any point in the future -that data could prove irresistible to a Communist Party interested in lifting China’s stature as a global superpower and wary of democratic values like free expression and freedom of association, Moriuchi says. 



    A map showing undersea cables that Huawei has laid or upgrade...
    35 min
  • Episode 148: Joseph Menn on Cult of the Dead Cow also Veracode CEO Sam King on InfoSec’s Leaky Talent Pipeline

    In this week’s episode of the podcast: Joseph Menn’s new book Cult of the Dead Cow: How the Original Hacking Supergroup Might Just Save the World hit store shelves this week. We reprise our March interview with Joe and talk about the origins of CDC. Also: is the talent pipeline for information security empty, or has it sprung a leak? We’re joined by Veracode * CEO Sam King to talk about one of the top problems facing organizations: how to cultivate and keep information security talent.







    Joseph Menn’s new book on the seminal hacking group Cult of the Dead Cow was making headlines months before its release, after Menn – a reporter at Reuters – broke the news that presidential candidate Beto O’Rourke was a long standing member of the group. That scoop helped propel Menn’s book to become a top selling cyber security book on Amazon even before it was released. With the book’s release finally here, we’re reprising an interview with did with Joe back in March (episode 138).



    The Cult of the Cult of the Dead Cow



    In our first segment, Joe and I talk about the origins of CDC in the early days of the Internet in the 1980s and 1990s to the group’s growth and release of the Black Orifice hacking tool in the late 1990s. 



    Joseph Menn is an investigative reporter for Reuters and author of Cult of the Dead Cow: How the Original Hacking Supergroup Might Just Save the World.



    Joe tells me that the group’s early incarnations were more creative than technical: a loose gathering of computer enthusiasts exchanging ideas, writing and conversation via online bulletin boards. CDC was consistently irreverent and, even more important, fun and funny. Over time, that drew people to the group: more skilled hackers like Josh Buchbinder (“Sir Dystic”), Peiter Zatko (aka “Mudge”) and Christien Rioux (aka “Dildog”). The addition of new, more skilled members drove CDC’s evolution into a more serious hacking group that produced “Back Orifice,” a remote administration tool for Microsoft Windows that was among the first and most widely used Windows hacking tools.



    Solving Infosec’s Pipeline Problem



    In our second segment: its common knowledge that there are too few information security workers to meet the needs of our domestic economy or – indeed – the global economy, where the shortage of cyber security pros numbers in the millions. Furthermore, of the information security workers who are available to hire, there is an acute lack of diversity. They’re 50% to 51% of the population, but just 20 percent of information security professionals globally are women. In countries like the U.S., racial and ethnic diversity is also a challenge in the information security space, which can exacerbate conditions for those working in the field.  



    Epis...
    30 min
  • Episode 147: Forty Year Old GPS Satellites offer a Warning about securing the Internet of Things

    A programming glitch in GPS satellite software grounded planes in China and other countries. But what does it tell us about the security of the Internet of Things? Bill Malik of Trend Micro joins us to discuss.











    You’ve  no doubt heard about (or lived through) the Y2K crisis. You remember: Y2K was the software “dragon” that lurked just beyond midnight on December 31st 1999, threatening to destroy civilization as date counters rolled over from 99 to 00. Maybe you spent New Year’s Eve in a bunker instead of at a party.



    A shot of a rolled over date counter on a Boeing plane in China in April. (Image courtesy of Simpleflying.com)



    But have you been following the Y2019 scare? That went down (quietly) on April 6 of this year, when older Global Positioning System (GPS) satellites rolled over a critical date counter that is used to calculate the satellite’s position in orbit.



    The rollover prompted the satellites to feed unreliable data to earthbound systems, grounding Boeing 787 planes in China and causing other disruptions globally.  



    Disaster averted?



    As it turned out the Y2019 issue wasn’t the disaster some expected. That might be due to the fact that it wasn’t the first time the world had encountered this problem. An identical rollover occurred in the fall of 1999. Also: many, newer GPS satellites use a much more robust date counter and were not affected by the flaw.



    Bill Malik is the Vice President of Infrastructure Strategies at Trend Micro.



    How Digital Transformation is forcing GRC to evolve



    But don’t get too comfortable. Our guest this week, William Malik, the Vice President of Infrastructure Strategies with Trend Micro, says that the rollover problem with GPS satellites is a small example of a much more widespread problem. Namely: poorly architected cyber-physical systems. Decisions about architecture made decades ago can have long term and often unexpected consequences today, he notes. Even worse: poor decision making in the design of connected products today could bite the world on the backside decades hence.  



    Spotlight Podcast: Managing the Digital Risk in your Digital Transformation



    Lurking problems



    The big question going forward, says Malik, is what other date counters or similar features are out there ready to rollover, expire or otherwise barf? As we move to the Internet of Things, we are living more and more in a system of systems in which any malfunction can have a cascading effect and cyber-physical consequences. 



    RSA Recap: CTO Zulfikar Ramzan talks about Trust, Zero Trust and the Debate over Going Dark



    In this conversation with The Security Ledger, Bill and I talk about the recent GPS rollover and the bigger problem of securing operational systems for the long term. 



    As always,  you can check our full conversation in 
    23 min
  • Episode 146: Elections Loom, Political Parties struggle with Cyber Security and Securing Cloud with Aporeto’s Amir Sharif

    In this week’s episode, #146: we speak with the researchers behind a new analysis of more than 20 political parties in the US and Europe showing that many suffer from poor cyber security. Also: DEV-OPS methodologies are transforming the way organizations are creating and consuming software. But security technology is stuck in the past. In our second segment, we speak with the  Amir Sharif of the firm Aporeto*, a provider of identity-based access control for the cloud. 







    It’s the Cyber Security, Stupid!



    There is ample evidence that nations like Russia, China and Iran are interested in inserting themselves into elections in the West as a way to influence the outcome in their favor. Whether or not they will succeed depends, in part, on the cyber security of political parties in the U.S. and Europe. That’s why a new study from the firm SecurityScorecard is reason for concern. 



    The survey of more than 20 political parties in the EU and four major political parties in the U.S. found indicators of poor security hygiene in almost all political parties. Those ranged from expired web site certificates to insecure web applications and evidence of malware and botnet infestations. 



    Still – the news wasn’t all bad. To get a better sense of what political parties are getting wrong (and right) we invited two of the study’s authors in to speak with us. Jason Casey is the CTO  and Paul Gagliardi is the director of threat intelligence  at Security Scorecard. 



    In this conversation, Paul, Jason and I talk about their survey of political party cyber security hygiene and how weak party cyber security can contribute to disinformation campaigns designed to undermine public faith in the election system. 



    Cloud is the Future, so why are Security Tools stuck in the Past?



    Change is afoot in the enterprise. The embrace of DEV-OPS methodologies is fast replacing monolithic software stacks with more nimble, distributed architectures. At the same time, organizations are swapping out physical data centers and moving workloads to both public and private clouds. 



    But all that change brings with it cyber risk and security technologies are generally stuck in the past: assuming more static environments with on premises, physical IT assets.



    In our second segment, we’re joined by Amir Sharif, the co-founder of the firm Aporeto which provides identity based access control for users and applications in hybrid on premises and cloud environments. In this conversation Amir and I talk about how DEV OPS and cloud are transforming risk – and security – for enterprises.  



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and check us out on SoundCloud, Stitcher, 
    47 min
  • Spotlight Podcast: Managing the Digital Risk in your Digital Transformation

    Companies are pursuing digital transformation at all costs. But do they really understand the risks lurking in their digital transformation strategies? In this Spotlight Podcast, sponsored by RSA,* we’re joined by RSA Portfolio Strategist Steve Schlarman for a discussion of managing the risks in digital transformation. 







    Scan through the pages of your favorite business publication or consultants report and the term “digital transformation” is likely to jump out at you. A broad term, digital transformation can mean the adoption of nearly any technology advancement: artificial intelligence, cloud based computing and micro services, DEVOPS methodologies for delivering new applications and features the application of machine learning, the use of automation and robotics…you name it.







    The focus of digital transformation narratives is almost always about the benefits of the transformation, measured in profits, productivity, market share – disrupting old and inefficient ways of doing business.



    But what about the risks that digital transformation strategies and technologies bring with them? A recent survey by Deloitte found that while organizations are prioritizing digital transformation initiatives, only 14 percent of cyber budgets are allocated to securing transformation efforts.



    Three Decades On: RSA Labs Sets Course for Future



    Our guest this week is here to sound the alarm about the digital risk inherent in digital transformation. Steve Schlarman is a portfolio manager at RSA. He was also my guest at a special webinar “Mastering Digital Risk: Taking on Digital Transformation.” In this conversation, Steve says that innovation opens new doors for organizations but that legacy security and risk management functions are not keeping pace with those changes.



    Re-Thinking Cyber Risk



    Steve Schlarman is a Risk Management Strategist at RSA.



    In this conversation, Steve and I talk about how digital transformation is changing the nature of cyber risk management from trying to prevent discrete events – like a data breach – to more business focused goals. The question now is how to both leverage digital transformation and keep data and assets secure, while protecting the organization’s reputation.



    We also take some time to respond to questions from the webinar.



    As always,
    33 min
  • Episode 145: Veracode CTO Chris Wysopal and Life After Passwords with Plurilock

    In this week’s episode, #145 Veracode CTO Chris Wysopal joins us to talk about the early days of the information security industry with L0pht and securing software supply chains. Also: we continue our series on life after the password by speaking to Ian Paterson, the CEO of behavioral authentication vendor Plurilock.







    Chris Wysopal (aka Weld Pond) is one of the most recognized and recognizable figures and voices in the information security space. As the co-founder of the seminal Boston hacking collective L0pht Heavy Industries, Wysopal was one of seven members of the L0pht who testified before the U.S. Senate’s Governmental Affairs Committee in 1998.



    More than two decades later, as co-founder and Chief Technology Officer at Veracode, he is a successful technology entrepreneur and one of the clearest voices calling for more attention to secure design and coding as a solution for endemic online problems like hacking and data theft.



    Chris Wysopal is the Chief Technology Officer of Veracode



    Abine says Blur Password Manager User Information Exposed



    In this interview, recorded on the floor of the RSA Conference in San Francisco in March, I had the opportunity to talk to Chris about his early days at L0pht and the information security industry, discovering the first stack overflow in Internet Explorer and the modern challenges of securing software supply chains.



    The Persistence of Passwords



    When the virtualization software firm Citrix said in March that it was the victim of a months long cyber espionage campaign, law enforcement attention focused on a so-called “password spraying” attack as the likely culprit. The low-tech hack simply requires criminals to attempt to remotely access Citrix accounts using known usernames in combination with weak passwords.



    Attacks like that are common – just one more proof point that single factor authentication, though vulnerable, remains incredibly common.



    Bank Attacks Put Password Insecurity Back in the Spotlight



    In our second segment, we sit down with someone who wants to change that. Ian Patterson is the CEO of the firm Plurilock – which is one of a slew of next-generation behavioral authentication firms to crop up in recent years.



    In this conversation, Patterson and I talk about why organizations cling to passwords and what – if anything – will replace them. He says that the writing is already on the wall for traditional passwords, as password managers are fast turning even alphanumeric passwords from something you know and can remember to something you have.
    39 min