Download on the App Store

episodes

  • Podcast Episode 136: The Geopolitics of Cyber Attacks with LookingGlass and Bruce Schneier on Public Interest Cyber

    How will the collapse of the North Korean summit affect that country’s malicious activity online? LookingGlass* joins us to discuss. Also: how to attract more technologists to public interest work.







    Note: this week’s podcast episode (#136) is sponsored by the firm LookingGlass Cyber Solutions.



    President Trump has been courting North Korea, while punishing Iran. In our second segment, we talk with Olga Polishchuk of the firm LookingGlass Cyber Solutions about how geopolitical tensions influence cyber activity online.



    But first: the information security industry is bigger and more diverse than ever. This week, it will converge on San Francisco for the 28th annual RSA Conference. The annual event, which started as a small, clubby gathering of cryptographers, now draws upwards of 40,000 people to downtown San Francisco. As always this year: there’s plenty of business to be done and deals to be struck at RSA on and off the show floor. But cyber security is about more than startups, VC rounds and IPOs. Information security, data security and individual privacy are areas of intense interest and from more than just investors. Lawmakers, civil liberties experts, human rights and non-governmental groups all have a role to play in protecting online privacy and individual rights in the 21st century.



    Podcast Episode 111: Click Here to Kill Everybody and CyberSN on Why Security Talent Walks



    Bridging the gap



    But convincing sought-after professionals to pass on a hot startup to do low paying work in the public interest is harder than it sounds. This year, show organizers at RSA have given over an entire track to explore  that problem. The Thursday session, dubbed “Bridging the Gap: Cybersecurity + Public Interest Tech” will bring together experts from firms like Mozilla, Electronic Frontier Foundation, the Ford Foundation and Harvard University’s Kennedy School of government to talk about the need for information security pros to work within government, NGOs and civil liberties groups.







    In our first session this week, I’m joined by two of the organizers of that event: Bruce Schneier is a fellow and Lecturer at  Harvard ‘sKennedy School and Michael Brennan is a program officer on the Technology and Society team. To start off I asked them to talk about how the idea came about to focus on the need to focus on public interest technologists in the cyber security industry.



    Bruce Schneier is a fellow at the Berkman Center for Internet and Society at Harvard University, a fellow at the Belfer Center at Harvard’s Kennedy School of Government. Michael Brennan is a program officer on the Technology and Society team.



    The Cyber Consequences of “America First”



    President Trump’s summit in Vietnam with North Korean leader Kim Jong Un went bust. But will the breakdown in talks reignite North Korean hacking activity against US targets?


    43 min
  • Spotlight: Synopsys on democratizing Secure Software Development

    In this Spotlight Podcast, sponsored by Synopsys* Ravi Iyer, the Head of Product Management talks to us about the “democratization” of software development, as more and more companies become software publishers. Ravi and I talk about Polaris, a new software integrity platform that integrates a wide range of software testing and analysis tools into a common platform.







    Thirty years ago, software engineering was limited to a few corporations. Companies like IBM, Microsoft, Apple, DEC or Oracle wrote software. Other companies made “stuff.” But it’s a truism these days that nearly every company is a software company. Whether your company makes jet engines, or automobiles or kitchen appliances or even watches and sneakers, the chances are that what you make is running software in some form. Increasingly, your “stuff” is also connected to the Internet, as well.



    All that software offers tremendous new opportunities for organizations. But it also harbors risk in the form of software vulnerabilities – some of them exploitable in ways that pose a risk to the integrity of applications, data, IT environments and even physical safety.



    Waiting for Federal Data Privacy Reform? Don’t Hold Your Breath.



    Software development has become a core competency of modern organizations and so has software security and secure software development.



    Ravi Iyer, Head of Product Management Security Products at Synopsys




    That’s where our guest this week comes in. Ravi Iyer is the senior director of product management at Synopsys and part of the software integrity group there, which is dedicated to helping companies build secure software and to do it in keeping with modern, agile DEV-OPS environments.



    The challenge, Ravi tells me, is that software development is a complex and multi faceted process – and is only becoming more-so. Modern development spans software design and development, quality assurance and testing, deployment and management. Increasingly, software integrity issues go all the way up to the C-Suite as executives consider how software based risks might affect their overall organizational risk.



    In this conversation, Ravi and talk about a new platform that Synopsys introduced this week. Dubbed Polaris, a software integrity platform that  integrates a wide range of software testing tools for static and dynamic testing, software composition analysis, interactive security testing and more into a common platform.



    Tread Lightly with Threat Intel Add-Ons



    In this conversation, Ravi and I discuss the changing dynamics of development organizations. This includes what Ravi calls the democratization of security. “It used to be that security was managed by a single organization that was the gatekeeper. That has proven to not be very effective.” Now, he says, security is the responsibility of an entire organization. That, in turn, requires more and more different types of roles in the software development process.



    Ironically, one of the areas of greatest needs in an organization is ...
    30 min
  • Podcast Episode 135: The Future of Passwords with Google Account Security Chief Guemmy Kim

    In this week’s episode (#135):  we continue our series on the future of passwords as we are joined by Guemmy Kim, a group product manager at Google in charge of that company’s account security initiatives. Guemmy and I talk about Google’s fast evolving security program to protect user passwords and data.







    It goes without saying that Google is one of the Internet’s largest identity providers, alongside firms like Microsoft and Facebook. With billions of users of google products like YouTube, Gmail the G-Suite productivity applications, Google has its hands full protecting both high profile users and billions of ordinary Internet denizens.



    Phish talk



    In this conversation, Guemmy and I talk about one of the biggest threats to the security of online accounts: spear phishing and targeted account hacking. She gives us some insight into the trends Google is seeing as hackers look to circumvent account protections to gain control over victim identities and data.



    Massive Facebook Breach Affects 90 Million Accounts



    Securing the 1% and the 99%



    Guemmy Kim is a Group Product Manager at Google.



    Guemmy and I also talk about Google’s Advanced Account Protection program, which offers high risk users like politicians, human rights workers and journalists extra protections for their account. With fewer than 10% of Google users taking advantage of multi factor authentication, Among other things, I ask Guemmy whether we’ll ever see the end of the password and if so, what that future will look like.



    Four More Collections, 700 Million Stolen Passwords Discovered



    A note: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted. 
    38 min
  • Podcast Episode 134: The Deep Fake Threat to Authentication and analyzing the PEAR Compromise

    In this week’s episode, #134:  deep fakes aren’t just a problem for celebrities. They risk undermining a range of voice and image based authentication technologies. Vijay Balasubramaniyan of Pindrop joins us to talk about it. And, in our second segment, Sam Bisbee the CSO of the firm ThreatStack joins us to talk about last month’s hack of the PEAR open source package manager and why data deserialization attacks are a growing threat to projects that use open source components.







    The Deep Fake Threat to Authentication



    The world has adapted itself – albeit unhappily- to a U.S President accustomed to making outrageous or factually inaccurate statements. But what if even the most temperate and measured leader could be made to say outrageous and inflammatory things? How destabilizing might that be to societies and economies? That’s the risk posed by so-called “deep fake” audio and video, which use advancements in deep learning – a kind of artificial intelligence – to seamlessly manipulate both audio and video content, producing real-seeming forgeries.



    So-called “deep fake” audio and video may complicate biometric authentication schemes in years to come warns Vijay Balasubramaniyan of the firm Pindrop.



    Thus far, deep fakes have been the fodder of celebrity pornography sites and academic conference demonstrations. But experts like our first guest, Vijay Balasubramaniyan of the firm PinDrop, say that deep fakes are almost certain to become more common and pose risks not just to social stability, but also to a wide variety of image and voice based authentication technologies.



    Podcast Episode 94: Black Report takes Hacker View and Securing the Open Source Supply Chain



    In our first segment, Vijay and I talk about the evolution of deep fakes and the risk posed by convincing audio counterfeits.



    Data Deserialization and Open Source Risk



    In January, the maintainers at the PEAR took down their official website (pear-php.net) after they found that someone has replaced the original PHP PEAR package manager (go-pear.phar) with a modified and malicious version in the core PEAR file system.



    PEAR developers suspected that the website had been serving the installation file contaminated with the malicious code to download for at least half a year. But how did the attack happen? One theory: that attackers used a so-called “data deserialization” attack.



    In our second segment, we’re joined by Sam Bisbee of the firm Threatstack to talk about the PEAR compromise and why data deserialization attacks are a growing threat to development organizations.



    In our conversation, Bisbee notes that data deserialization and similar attacks rely on the fact that developers in fast moving environments take for granted the integrity of tools like the PEAR package managers.



    Episode 108: DEF CON’s Car Hacking Village and is the Open Source Model Failing on Security



    “Developers aren’t typically going in and opening up and trying to understand how their package manager works or what third party dependencies are that they’re pulling in because they want to just use them and not have to t...
    42 min
  • Podcast Episode 133: Quantum Computing’s Security Challenge and Life After Passwords

    In this week’s episode of the podcast (#133): the arrival of functional quantum computers may be closer than you think. I’m joined by Avesta Hojjati, Head of DigiCert Labs and Brian LaMacchia, Distinguished Engineer and Head of the Security and Cryptography Group at Microsoft Research to talk about coming quantum revolution and what it means for security. Also: what will it really take for consumers and businesses to ditch the user name and password? This week we’re kicking of a series on the future of passwords and authentication with George Avetisov, the CEO of the startup HYPR.







    Quantum’s Security Challenge



    Quantum computers sound like the stuff of science fiction: with the zeros and ones that are the foundation of modern computing giving way to ethereal qubits that can be either zero or one or both at the same time as well as everything in between. 



    Brian LaMacchia is a Microsoft Corporation Distinguished Engineer and heads the Security and Cryptography team within Microsoft Research (MSR) where he works on the development of quantum-resistant public-key cryptographic algorithms and protocols.



    But the arrival of functional quantum computers may be closer than you think. Estimates vary from the first such system being available anytime from five years or so from now to 20 or more. Once they’re here, quantum computers will make short work of many of the most commonly used encryption schemes, which protect much of the world’s sensitive data. And, for cryptography experts worried about the security of data protected with powerful encryption algorithms, a decade or two hence is close enough to begin preparing now. 



    One small step in that direction happened this week, as Microsoft teamed with the certificate authority DigiCert and the firm Utimaco, announcing a successful test implementation of a Microsoft-developed algorithm known as “Picnic” which can create quantum-safe digital certificates used to encrypt, authenticate and provide integrity for connected devices commonly referred to as the Internet of Things (IoT).  Though still in development, the companies say that Picnic will protect IoT devices from future threats quantum computing could pose to today’s widely used cryptographic algorithms.



    To understand more about the problem that the advent of quantum computing poses for the security of the Internet and the Internet of things, we sat down with Avesta Hojjati, Head of DigiCert Labs and Brian LaMacchia, Distinguished Engineer and Head of the Security and Cryptography Group at Microsoft Research, and an inventor of the Picnic algorithm to talk about the coming quantum revolution and what it means for security. 



    Life after passwords



    In just the last month, hundreds of millions of user names and passwords have been exposed by researchers: the contents of online compendiums known as collections 1 through 5. They’re the fruits of data breaches and hacks going back years, and they are a useful tool to cyber criminals who can carry out credential stuffing attacks against a wide range of sites.



    George Avetisov is Cofounder and Chief Executive Officer of HYPR



     



    The password problem gets even worse when you think about the...
    42 min
  • Podcast Episode 132: NERC issues a Big Fine – does it matter?

    In this week’s episode of the podcast (#132): in the wake of news of the biggest fine yet for violations of the NERC Critical Infrastructure Protection (CIP) standard, we talk with Willy Leichter and Saurabh Sharma of the firm Virsec about whether the industry’s main security standard even matters in an age of sophisticated, nation-backed hackers.







    As we reported last week, NERC – the North American Electric Reliability Corporation – issued a $10 million fine and a 250 page report (PDF) detailing the failure by one of its member companies to abide by the organization’s main cyber security regulation the Critical Infrastructure Protection or CIP standards.



    Thirteen of the violations listed were rated as a “serious risk” to the operation of the Bulk Power System and 62 were rated a “moderate risk.” Together, the “collective risk of the 127 violations posed a serious risk to the reliability of the (Bulk Power System),” NERC wrote.



    NERC fined a firm identified in reports as Duke Energy for violations of the Critical Infrastructure Protection (CIP) cybersecurity standard.



    Spotlight Podcast: At 15 Cybersecurity Awareness Month Grows with Cyber Risk



    The report was heavily redacted: blacking out the name of the fined entity (or entities) as well as some details of the violations. Still, subsequent, public reports citing unnamed energy industry sources have identified Duke Energy Corp. as the subject of the fines. In a statement to the Security Ledger that company said that it could not confirm or deny that allegation citing the “potential physical and cyber security risks that a disclosure could pose to the industry.” 



    With all the secrecy around the company who was penalized and the violations, it can be hard to assess the importance of the fine itself. Is a $10m NERC CIP violation a major development in the electric generation and distribution industry? And, with nation-states like China and Russia dialed in on US critical infrastructure, do the NERC CIP standards even matter anymore? To answer some of those questions, we reached out to some experts on critical infrastructure security and invited them into the Security Ledger studios to talk. 



    Episode 107: What’s Hot at Black Hat & does DHS need its new Risk Management Center?



    Willy Leichter is the Vice President of  marketing and Saurabh Sharma is the Vice President of Business Development at the firm Virsec, which works with major corporations as well as intelligence agencies to secure critical infrastructure including parts of the US electric grid. 



    In this interview, Willy, Surabh and I talk about the state of play in the critical infrastructure space and whether NERC’s enforcement action and the CIP standard is likely to have an impact on the overall security of the electrical grid in an environment of growing risks. 
    29 min
  • Podcast Episode 131: suing Yahoo! Executives…and winning

    In this week’s episode (#131): a shareholder lawsuit targeting Yahoo! executives was settled quietly. But it could have big implications for the C-Suite at breached firms. Also: as the US pursues criminal charges against Huawei for corporate espionage, we look at one of the federal government’s most potent tools to stop the transfer of sensitive IP: the Committee on Foreign Investment in the US.







    The C-Suite’s Bitter Pill



    This week, U.S. District Court judge Lucy Koh slapped down a proposed settlement of a class action lawsuit filed against Yahoo! (now part of Verizon Media) over a 2013 hack that exposed data on billions of its users. It’s just the latest twist in the saga of the once great search giant, who fell victim to hackers and then – astoundingly – conspired to keep the breach a secret for years. But another Yahoo! lawsuit that was quietly settled late last year may have far bigger long term consequences for breached private sector firms and their executives.



    That case, a so-called “derivative lawsuit,” was filed on behalf of Yahoo! shareholders against the company’s executives, including former CEO Marissa Mayer. The suit alleged that they breached their fiduciary duties in the reckless handling of customer data. The result: a $29 million settlement, including $11 million in attorneys’ fees. The balance, some $18 million will go to Yahoo or, as it is now known, Altaba, part of Verizon. (PDF)



    Craig Newman is a partner and head of the data privacy practice at the New York law firm of Patterson, Belknap, Web and Tyler



    While that might not sound like much, our first guest on the podcast this week notes that derivative suits are notoriously hard to win and that, even when they are won, any cash settlement in a derivative suit beyond attorneys fees is exceedingly rare.



    What does the success of the suit mean for the heads of other companies that are the victims of sophisticated hacks? Craig Newman, the head of the data privacy practice at the New York law firm of Patterson, Belknap, Web and Tyler dropped in to the Security Ledger studios to talk about the derivative suit against Marissa Mayer and the other Yahoo! executives and its ramifications. 



    CFIUS Interest in Cyber Deals Grows



    As hearings on Capitol Hill confirmed this week, cyber offensives by U.S. adversaries like Russia, China, Iran and North Korea are at the forefront of U.S. foreign policy.



    And, in the background of those hearings was evidence of a more muscular U.S. response, as prosecutors at the Department of Justice filed criminal charges against Huawei Technologies Co., China’s largest technology company, alleging it stole trade secrets from an American rival and committed bank fraud by violating sanctions against doing business with Iran.



    34 min
  • Podcast Episode 130: Troy Hunt on Collection 1 and Tailit’s Tale of IoT Security Redemption
    In this week’s episode (#130): we speak with security researcher Troy Hunt, founder of HaveIBeenPwned.com about his latest disclosure: a trove of more than 700 million online account credentials he’s calling “Collection #1.” Also we speak to Martin Hagen of the Norwegian device firm Tailit about how failing a security audit of the company’s GPS watch sparked a security make-over at the company. 

    Yes, you’ve been pwned!
    Troy Hunt made a name for himself calling attention to massive data leaks via his blog, troyhunt.com and – especially – haveibeenpwned.com, his online tool for checking to see if your credentials have been stolen. (They have.)
    But even by Troy’s standards, the trove of email addresses, passwords and other data he uncovered last week was impressive: a 773 million strong archive of credentials spanning some 12,000 separate files that he dubbed “Collection #1.”  A kind of “breach of breaches,” the collection represents the sum total of many leaks and credential thefts going back years. But Hunt said the treasure trove of credentials still poses a serious risk today. That’s especially true because we users aren’t learning the lesson about the need for strong, unique passwords to protect our accounts. One measure of that: despite containing credentials for more than 700 million accounts, Collection 1 revealed just 21 million unique passwords.
    See also: Expert says: Hack your Smart Home to Secure It
    Even more worrying: Collection #1 isn’t the only repository of stolen credential out there. In this interview Hunt talks about subsequent dumps he has come across since first publicizing Collection #1 last week. Collections 2-5 represent hundreds of gigabytes of data, Hunt told me, though it may be days or weeks before he has fully parsed it.
    Troy last spoke with us back in Podcast Episode 123: HaveIBeenPwned’s Troy Hunt on Marriott’s Big Mess and GreatHorn on the Asymmetric Threat of Email. You might want to give a listen to that podcast, as well.
    Tailit’s Tale of IoT Security Redemption
    In our second segment this week: we’re used to hearing stories about connected device makers getting caught out with shoddy device security, insecure applications, dodgy data collection practices – or all three. But after the headlines have faded and the conversation has moved on, what is the best way for connected device companies to move on? Often it is by closing up shop, or by making apologies and then continuing as they were, in the hope of not getting caught again.
    See also: More Questions as Expert Recreates Chinese Super Micro Hardware Hack
    The Norwegian connected device maker Tailit is another example. In our second segment, we speak with Martin Hagen, the CMO at Tailit about how his company used revelations of a host of security flaws in a GPS smart watch for kids to accelerate security transformation at the company.
    Among other things, Tailit hired teams of hackers to probe their personal GPS tracking devices.
    35 min
  • Podcast Episode 129: Repair Eye on the CES Guy and Sensor Insecurity
    In this week’s podcast: For all the great new gadgets unveiled in Las Vegas, how many can be repaired? Kyle Wiens of iFixit joins us to report from the CES show. Also: more and more our physical surroundings are populated by small, wireless sensors. How secure are they from hacking and manipulation? Not very says our second guest, Roi Mit of the firm Regulus Cyber.

    Part 1: Repair Eye on the CES Guy
    The Consumer Electronics Show wrapped up last week. All the hoopla about VR, AI, drones, massive TV screens and powerful new laptops drowned out a nagging question: how long will any of this new technology last? What will happen to it when it breaks? When batteries expire or parts fail? Such questions are forbidden at glitzy shows like CES that focus on the wonders of new gadgets but ignore the burdens of old ones.
    Fortunately, at least one person among the 180,000 or so visitors to CES was thinking about issues like repair and reuse. He is Kyle Wiens, the founder and chief evangelist at iFixit.org, the Internet’s leading repair website. In the first segment of our podcast this week, we sat down with Kyle to talk about what he saw at CES, whether repair was on the agenda at the show and whether any of the cool new things on the show floor there are fix-able.
    See also: Researchers Warn of Physics-Based Attacks on Sensors
    Kyle said the lack of conversation about the durability of new devices is shocking, as is the tendency towards less sturdy, serviceable stuff: laptops and headphones that are glued, rather than screwed together. Electronics with batteries that cannot be replaced. The culture of consumer electronics is a culture of waste, he says, and nobody seems to be talking about it.
    Part 2: Sensing insecurity
    From automobiles to industrial robots to street lights and smart personal electronics, more and more of our private and public space is being equipped with sensors. Small, wireless sensors that communicate using bluetooth or long range wireless technologies monitor everything from braking and tire pressure on a moving vehicle to the load on a bridge, the pressure in a gas line to a patient’s heart rate.
    See also: Updated: A New Lobbying Group is fighting Right to Repair Laws
    But are these sensors secure and, if not, how will we know if the information they’re feeding us about the world is accurate and reliable? Those are questions that Regulus, an Israel based cyber security start up is tackling. In our second segment, we sat down with Roi Mit, Regulus’s chief marketing officer, about the company’s technology and the sensor security problem.
    Roi told me that attacks on sensors are still rare, but that the stakes of such attacks are growing by the day, as businesses and individuals come to rely more on automation and sensing machines such as smart and driverless vehicles.
    31 min
  • Podcast Episode 128: Do Security and Privacy have a Booth at CES?
    In this episode of The Security Ledger podcast (#128): you’re going to hear a lot from the annual Consumer Electronics Show (CES) out in Las Vegas this week, but are any of the new gadgets being released secure? And do security and privacy have a seat at the table at the world’s largest electronics event? We sit down with IoT luminary and influencer Stacey Higginbotham of the Internet of Things podcast and the StaceyonIoT blog to find out.
    If its early January, then it must be CES. This week: the massive Consumer Electronics Show kicked off in Las Vegas, with more than 4,400 exhibiting companies covering more than 2.7 million net square feet of exhibit space. More than 182,000 industry professionals will attend to see the latest gadgets – ranging from cars to refrigerators to watches and everything in between.
    You’ll hear plenty this week about massive new TVs and computer monitors, vendor hook ups (see also: Apple iTunes on Samsung Smart TVs), not to mention smart city and smart home products and services. But in a world where sensors are proliferating and pretty much everything sports an IP address, where do issues like information security, device integrity, resilience and data privacy fit in?  Its clearer than ever that the Internet of Things is getting bigger – and CES is a showcase for new IoT technologies. But is it getting any more secure as it grows?
    See also: Consumer Reports: Flaws Make Samsung, Roku TVs Vulnerable
    The news of the last year suggests that 2018 may be the year that the worm turned on what Bruce Schneier has called “surveillance capitalism:” the business model embraced by Facebook and Google in which the customer (and her data) is the real product. The serial scandals about Facebook’s back room deals with advertisers and shoddy handling of user data and the New York Times’ expose on mobile applications tracking users movements, suggest that concerns about privacy, data security and commercial surveillance are raising eyebrows, even amid the pitches about fantastic new technology at CES.
    You might also want to read: Expert says: Hack your Smart Home to Secure It
    To help answer those questions we invited someone who knows the IoT space better than any other, and who is on the ground at this year’s CES ready to take it all in and report out. Stacey Higginbotham is the host of the Internet of Things Podcast and the editor of the StaceyOnIoT blog and newsletter. Stacey is one of the smartest people out there writing and podcasting about the IoT. She’s also a veteran of CES, having been covering technology sector for 18 years.
    We caught up with Stacey in her hotel in LV just at the start of CES. Check out our full interview in this week’s Security Ledger podcast!
    26 min