Download on the App Store

episodes

  • Podcast Episode 127: Donnie, Talk to China and Other Lessons from 2018
    In this week’s episode of The Security Ledger Podcast (#127): cybersecurity’s smartest and funniest executive, David Aitel, the Chief Security Technical Officer at Cyxtera Technologies, joins us for this year end wrap up. We talk about the supply chain attack on Super Micro, China’s continued attacks on western firms, U.S. indictments of Russian and Chinese hackers and what 2019 may have in store. 

    2019: A New Hope?!?
    As 2018 winds down, the headlines are filled with worrying news that may or may not have a root in cyber security. In just the last week, we’ve had a nation-wide outage of the 9-1-1 emergency response system by way of a disruption at ISP CenturyLink and Tribune media, the owner of top U.S. newspapers acknowledged that a malware attack kept them from publishing newspapers on time.
    In case you missed the pattern: cyberattacks are hitting closer and closer to home. In 2018, they impacted not just our computers and smart phones, but the systems that we rely on to order our society and, literally, keep the lights on.
    Also listen to: Podcast Episode 111: Click Here to Kill Everybody and CyberSN on Why Security Talent Walks
    Looked at one way, 2018 may be remembered as the year when the pushing elevated to shoving between the world’s major cyber powers: with US indictments of leading Russian and Chinese cyber actors and reports of poisoned hardware and software supply chains affecting leading firms.
    To talk about what we learned in the last year and what 2019 might have in store, we invited David A-Tel, the Chief Security Technical Officer at Cyxtera Technologies and the founder of Immunity Inc. to talk about the events of the past year, from the recent reports on the actions of APT-10, which has links to the government of China, to Bloomberg’s blockbuster story about a supply chain hack of motherboard maker super micro.
     Donnie, Talk to China
    In an era of nation state actors, Aitel observes, no hardware, software, company or person is safe from predation. Take the Bloomberg story about a supply chain compromise of SuperMicro. The publication of that story generated a flurry of denials from SuperMicro, Apple, Amazon and others named in it. But Aitel observes (correctly, I think) that – in the big picture – it doesn’t matter whether Bloomberg got the details of the story correct. What matters is that Bloomberg’s story about what happened really could have happened.
    “Its almost more true if its not true,” Aitel tells me. “We know that what could happen in cyber always does happen in cyber. Someone going to fund it. Its not that expensive to do.”
    In other words: an adversary who is willing and capable of interdicting and modifying hardware or physically invading your home or business is impossible to thwart. The solution, therefore, is to forge international agreements and codes of conduct between nation-state actors.
    “Whether and not the details in particular for any of these things are correct, we need to have a massive equities discussion about what nation states will do to supply chains.” While the Trump administration may be trying to erect walls between the economies of China and the U.S.,
    36 min
  • Die Hard is a Movie About Building Automation Insecurity. Discuss.
    In this episode of the Security Ledger Podcast (#126): Die Hard has finally been embraced as the bloody, violent, feel-good Christmas movie its always been. But the film, which turns 30 this year, is about more than the power of ordinary guys to stand up to evil. Did you know it’s also a (very) early warning about the dire insecurity of building automation systems? We speak with Ang Cui of the firm Red Balloon Security about the dire risk of cyber attacks on building automation software and company’s work to secure this often-overlooked critical infrastructure. 

    Yipee Ki Yay, Process Controller!
    Die Hard, the 1988 blockbuster made Bruce Willis’s career and cemented Alan Rickman’s sneering, erudite Hans Gruber in the pantheon of Hollywood villains. But behind the performances of Willis, Rickman, and Reginald Vel Johnson as beat cop and everyman Sergeant Al Powell, there’s critical and often overlooked character on the screen: Nakatomi Plaza, the Los Angeles high rise where Willis’s character, John McClane, battles it out against Gruber’s murderous band of criminals. Of particular interest to Gruber’s men: the state of the art building automation software that runs pretty much every aspect of the high rise’s operation, from its doors and elevators to its ventilation and doors. The building automation system is, in fact, one of Gruber’s first victims. It falls to the nimble hands of Theo, the gang’s resident hacker, in one of the movie’s opening scenes.
    See also: Spotlight: as Attacks Mount, how to secure the Industrial Internet
    Of course, that was 30 years ago. Surely the building automation systems in use today are much more robust and secure than those deployed in the 1980s, when Internet use was still limited to government research labs and universities, right?  
Don’t be so sure. Building automation systems are even more prevalent now than they were thirty years ago, and – like most everything else – they’re much more likely to be connected to the Internet. In fact, the FBI this month issued a warning about a widespread vulnerability affecting building automation systems.  Major universities, state governments, and communications companies are at risk of having their building-system data exposed, the bureau said in an industry advisory.
    How real is the threat to building automation systems? “Very real,” says our guest this week. Ang Cui. He is the CEO of cyber security start up Red Balloon security and an expert on the subject who has done research for the Department of Homeland Security.  These days, the hardware and software running modern office buildings and high rises might be of the same vintage as the systems running Nakatomi Plaza in Die Hard. And while the software that runs them may be a bit younger than the software Theo hacks so easily in Die Hard, it almost certainly isn’t much more secure, Cui told me.
    You might also be interested in: Black Box Device Research reveals Pitiful State of Internet of Things Security
    In this podcast, Ang and I talk about how and how it is that building automation system software came to be so insecure,
    35 min
  • Spotlight: as Attacks Mount, how to secure the Industrial Internet
    In this spotlight edition* of The Security Ledger Podcast, Steve Hanna of Infineon joins us to talk about the growing risk of cyber attacks on industrial systems and critical infrastructure. “Industry 4.0” is poised to transform the global economy, Hanna said, but not if the issue of cyber risk can’t be managed. We talk about how that might be done and the need for strong identity and hardware based roots of trust!

    Just like the Mirai botnet illustrated the danger posed by insecure, low value Internet of Things endpoints, the NotPetya wiper malware which appeared in June 2017 underscored the way software attacks could cripple hard infrastructure such as manufacturing lines, ports and logistic hubs and more. How do industrial networks and endpoints get targeted by malicious actors and why are they so vulnerable to software based attacks? Our guest this week has some thoughts on the risks to industrial systems and some ideas on what it will take to improve the security of manufacturing, critical infrastructure and other sectors with heavy investment in industrial control hardware and software.
    Steve Hanna is a senior principal at the chip maker Infineon and the co-chair of the embedded systems, IoT and Industrial Work Groups at the Trusted Computing Group. In this spotlight conversation, Steve and I talk about the evolving cyber risks to industrial control systems. Steve tells us that industrial control environments face a wide range of challenges when it comes to cyber security, including both targeted and indiscriminate malware attacks that can targeted the outdated and insecure hardware and software common in industrial settings. Industrial firms often have difficulty implementing common security practices like patching, especially when continuity of service is paramount.
    In this conversation, Steve and I talk about the state of industrial IOT security and what it will take to make the industrial IoT resilient to attack.”Industrial IoT or Industry 4.0 is happening now. It’s going to continue to happen. It’s our job as security people to tell people how they can do it safely,” Hanna told me.
    You should also listen to: Podcast Episode 87: Vulnerability Reports Down the Memory Hole in China and the Groups Hacking ICS
    But the Industrial IoT isn’t a candidate for, say, anti virus software. Rather, security will have to be built into industrial systems and controllers – ideally in hardware so that important data can’t be lost to cyber attacks. That isn’t to say that hardware based security is a cure all. “There are always bugs and vulnerabilities that need to be patched,” Hanna said. Industrial firms need tools to help them patch and update connected industrial control software, but that a strong identity foundation is paramount.  “The hardware can help with that – to verify that the patches are in place and that the endpoints are trusted and trustworthy.”
    For those interested in making industrial systems secure, Hanna and I talk about established and emerging standards for industrial devices, including IEC 62443, which lays out different levels of device risk and the types of security needed for each. The Trusted Computing Group has also come up with a range of guidance for securing connected industrial systems, which is available here.
    Check out our latest Security Ledger podcast at Blubrry. As always, you 
    28 min
  • Podcast Episode 125: Long After The Election Kremlin’s Computational Propaganda Campaign Rolls On
    In this week’s episode (#125): the November midterm elections are fading into the rear-view mirror. The 2016 presidential campaign is even more distant. But the online disinformation campaign being waged by the Kremlin for the hearts and minds of U.S. citizens hasn’t let up. Priscilla Moriuchi of Recorded Future joins us once again in the Security Ledger studios to talk about the findings of two major reports released this week on Russia’s online campaigns and how disinformation operations by foreign governments may be the “new normal.” 

    If you thought you knew all about efforts by the government of Russia to influence U.S. politics around the 2016 presidential contest, think again. Two major reports prepared for the U.S. Senate’s Select Committee on Intelligence and released over the weekend make the case that Russia’s online influence and disinformation campaigns were far older, more wide ranging and influential than anyone knew.
    The two reports, one prepared by the University of Oxford in the United Kingdom and the other by the consulting group New Knowledge, document Russia’s growing use of social media, including Twitter, Facebook, Instagram and YouTube to sway hearts and minds in the United States. No half-hearted effort, the scale of the online manipulation campaign was massive. It spanned years and reached 126 million people on Facebook, another 20 million on Instagram. It generated more than 10 million tweets on Twitter and was behind more than 1,000 videos posted to YouTube, according to data provided by the companies.
    See also: Feds, Facebook Join Forces to Prevent Mid-Term Election Fraud
    The activity in question stretches back to 2013, long before President Donald Trump declared his candidacy. More important: it has continued long after he won that office in November, 2016. In fact, social media activity linked to Russia’s Internet Research Agency increased in 2017, in the period after the election.
    Our guest this week tells us, Russia’s online influence and disinformation campaigns haven’t let up. In fact: they continued through the 2018 midterms and to the current day. Priscilla Moriuchi is the Director of Strategic Threat Development at the firm Recorded Future. In this conversation, Priscialla and I talk about the joint reports on Russian influence operations, how they work, and what they mean for the future of U.S. politics, US policy and our democracy.
    Check out: Episode 106: Election Trolls Are Afoot. We Talk To The Guy Who Watches Them
    While most of us associate the Russian online information operations with the creation of “fake news” and memes that misled the public, Moriuchi said a much more consistent tactic – and one that continues to this day – is the amplification of conspiracy theories and divisive and hyper partisan voices in the online sphere. “One of the things we saw in the 2018 midterms was the amplification of these hyper partisan narratives. These outlooks and opinion pieces that were really just extreme or used violent imagery. The amplification just raises the temperature on that – raise the number of people who have seen it.”
    Even if those conspiracies are debunked or the extreme voices countered, Moriuchi notes, the campaigns have accomplished their mission – planting seeds of doubt or ...
    30 min
  • Episode 124: The Twitter Accounts Pushing French Protests. Also: social engineering the Software Supply Chain
    In this week’s podcast (#124):  we speak with French security researcher Baptiste Robert about research on the social media accounts pushing the french “Yellow Vest” protests. Surprise, surprise: they’re not french. Also: Brian Fox of the firm Sonatype joins us to talk about the recent compromise of the Github event-stream project and why social engineering poses a real risk to the security of the software supply chain. 

    Part 1: the Twitter bots pumping up French Protests? They’re not French.
    French President Emmanuel Macron took to the airwaves on Monday to address a string of long running worker protests that have rocked Paris and other cities in recent weeks. Apparently, his empathy and concessions weren’t enough.  Like so many social protest movements in recent years, the so-called gilet jaune – or “yellow vest” – protests began on social media platforms like Facebook before moving to the street, where they have led to acts of vandalism and scores of arrests. Now similar protests have popped up in Belgium and other neighboring countries.
    Still, no clear leader of the Yellow Vest movement has arisen, nor do the protests have a clear agenda. What is fueling them? Our first guest this week suspects that online propaganda campaigns orchestrated by outside agitators may be one factor. Baptiste Robert is a software developer and independent security researcher who lives in  Toulouse, France. He’s been collecting and analyzing gilet jaune-themed messages on Twitter, capturing more than a quarter million English language tweets using the french “#giletjaune” hash tag. His surprising finding: none of the top 10 English language accounts that are pushing the #giletjaune appear to be french, or to have any direct link to the french protestors. Almost all, however, do appear to be associated with far right nationalist or far left anti-capitalist political ideologies.
    See also: Before Senate Facebook, Twitter Defend Efforts to Stop Fake News
    What’s going on? I asked Baptiste to offer his thoughts, including whether the long arm of Russia’s FSB and President Vladimir Putin might be behind the online campaigns.
    Part 2: social engineering’s threat to the software supply chain
    Microsoft announced last week that it was gutting its proprietary edge browser to port the platform to Google’s open source Chromium platform. The announcement may signal that, after more than two decades, open source may have finally triumphed in the browser wars – as well as most other contests.
    Indeed, open source is an indispensable part of the knowledge economy, these days: allowing organizations to assemble new applications more quickly and cheaply than ever before.
    You might also like to listen to: Podcast Episode 94: Black Report takes Hacker View and Securing the Open Source Supply Chain
    But all that open source dependency also brings with it risk. Heartbleed woke the world up to the risk posed by undetected security vulnerabilities in popular open sou...
    36 min
  • Podcast Episode 123: HaveIBeenPwned’s Troy Hunt on Marriott’s Big Mess and GreatHorn on the Asymmetric Threat of Email
    Thanks to our friends at GreatHorn for sponsoring this week’s podcast. In this episode of the Podcast, # 123: Troy Hunt, the founder of HaveIBeenPwned.com joins us to talk about Marriott International’s big mess: a breach of Starwood Hotels’ reservation system that revealed information on half a billion (with a “B”) guests. And: you’ve heard of Business Email Compromise attacks but what about Business Service Impersonation scams? In our second segment we speak with Kevin O’Brien the CEO and co-founder of GreatHorn about using machine learning to defend against asymmetric messaging threats.

    Part 1: Marriott’s Big Mess
    Marriott International acquired more than a chain of hotels when it bought Starwood three years ago: it acquired a whopper of a security compromise. This week we – almost four years since that deal was consummated – we found out how big a breach it was. Marriott disclosed to the public that information on some 500 million Starwood guests had been stolen and exfiltrated from its reservation system. This follows a 2014 breach of its point of sale system that affected scores of hotels.
    For more than 300 million of those victims, the stolen data included names, email addresses, mailing addresses Starwood’s preferred guest numbers and even passport numbers – a virtual treasure trove of sensitive data that could have value to everyone from rank cyber criminals to sophisticated, nation-state attackers.
    Listen to Podcast Episode 120: They Email Ballots, Don’t They?
    To talk about what all this means, we invited security Researcher Troy Hunt of the website HaveIBeenPwned into the Security Ledger studios to talk about what happened at Marriott and what kinds of crimes might follow on the theft of so much personal data – even if that data is never leaked to the dark web.
    Hunt’s web site has become something of a first stop for victims of data breaches. It now holds information on more than 5.6 billion stolen account credentials from more than 328 web breaches and other attacks. The site gets upwards of 250,000 visits every day from individuals interested in whether their information has fallen into the hands of hackers. Top on the list of threats that victims of the Marriott breach need to be concerned about: credential stuffing attacks, in which attackers leverage credentials taken from Starwood to try to gain access to other online properties.
    Part 2: Email’s Asymmetric Threat
    What do ransomware attacks, executive impersonation scams and remote access trojans all have in common? Well, they’re all likely to visit you by way of email. Nearly half a century old, email is still a vital conduit of personal and business communications and – still – the single largest avenue attack against your organization for everyone from petty cyber criminals to nation state attackers.
    That’s because email threats are asymmetric: simple, inexpensive, highly effective and easy to carry out both at massive scale and in very targeted ways that are difficult to detect. Kevin O’Brien, the CEO of GreatHorn says that business service impersonation attacks are a great example of that: leveraging the widespread use of cloud platforms like Microsoft’s Office365 and Google to fool users into giving up their credentials or installing malicious software that can give malicious actors a foothold on your network.
    You might also like:
    44 min
  • Spotlight: Operationalizing Deep Web and Dark Web Intelligence
    In this episode of the podcast: Chris Camacho of Flashpoint* joins us to talk about “the deep web” and “the dark web.” Chris and I talk about how companies like Flashpoint monitor the dark web for intelligence and, then, how companies are able to operationalize that intelligence as part of their security and incident response programs. 

    We hear a lot of talk about the “dark web” or the “deep web” these days: shadowy nether regions of the Internet – beyond the reach of Google’s crawlers. These un-indexed and often password protected sites are where cyber criminals, terrorist groups, drug dealers, hacktivists, and nation state actors and privacy extremists congregate, chat, plot and do business.
    But what is the deep and dark web, exactly? And what value does the information gathered there have to a security-conscious organization? Just as important: how can organizations that benefit from this kind of threat intelligence operationalize it to put them a step ahead of malicious actors and targeted attacks?
    See also: Military documents about MQ-9 Reaper drone leaked on dark web
    Those are questions we posed to our guest this week: Chris Camacho is the Chief Strategy Officer at Flashpoint. In this podcast he and I talk about what people are referring to by the deep web and dark web, how companies like Flashpoint monitor the dark web for intelligence and, then, how companies are able to operationalize that intelligence as part of their security and incident response programs.
    Far from being a bleeding edge service, threat intelligence is becoming a critical and even required component of mature information security programs, Camacho tells me.
    Check our full conversation in our latest Security Ledger podcast at Blubrry. As always, you can also listen to it on iTunes and check us out on SoundCloud.

    (*) Flashpoint is a sponsor of The Security Ledger. For more information on how Security Ledger works with its sponsors and sponsored content on Security Ledger, check out our About Security Ledger page on sponsorships and sponsor relations.
    31 min
  • Podcast Episode 122: will 5G increase Internet of Things Risk?
    Telecommunications firms like to talk up all the great things that so-called 5G cellular networks will bring to smart phones. But what new kinds of Internet of Things use cases may become possible? And, just as important, what are the security implications of massively distributed IoT endpoints connected to capacious 5G cellular infrastructure? Jason Ortiz of the cybersecurity services firm Pondurance* joins us to talk about the impact of 5G on the IoT. 

    In this week’s podcast: major telecommunications carriers like to talk up the advantages of so-called 5G connectivity to their customers. Videos and games will stream much faster over cellular networks. Web based applications will grow to support more robust features that the increased cellular bandwidth will accomodate. But what about the Internet of Things? Many IoT endpoints today – from cars to surveillance cameras and “smart” garbage receptacles- communicate using 4G LTE or even older 3G networks.
    With the arrival of 5G, what new kinds of Internet of Things use cases may become possible? And, just as important, what are the security implications of massively distributed IoT endpoints connected to capacious 5G cellular infrastructure?
    That’s a question our next guest, Jason Ortiz of the firm Pondurance, a cybersecurity services firm based in Indianapolis, Indiana.  Ortiz, who works as a senior engineer at Pondurance, said that 5G networks will narrow the gulf between wired, wireless and cellular networks. That, in turn, will make cellular networks appealing to a much wider array of endpoints than existing 3G and 4G networks.
    Practically, that will pose a major challenge to organizations that wish to monitor their networks. “What start to see is a lot of IoT devices directly connecting to 5G networks versus traditional WiFi networks,” he said. “That will make them harder to monitor. You’ll have sensors and cameras directly connecting via 5G instead of through your router and you’ll have very limited or no visibility at all into communications for those devices.”
    In this podcast conversation, Jason and I talk about how the advent of 5G cellular networks might exacerbate IoT security woes. Check our full conversation in our latest Security Ledger podcast at Blubrry. As always, you can also listen to it on iTunes and check us out on SoundCloud.

    (*) Clarification: an earlier version of this blog post included an inaccurate description of cybersecurity firm Pondurance. The post has been updated to accurately describe the firm’s services. PFR 11/27/2018
    19 min
  • Podcast Episode 121: DMCA Exemptions Set Stage for Right to Repair Fight and DHS Cyber Makeover
    In this episode of the Security Ledger podcast (#121): the Librarian of Congress gave a big boost to right to repair advocates in late October when she granted exemptions provisions of the Digital Millennium Copyright Act covering repair of most electronic devices. We talk to US PIRG’s Right to Repair campaign coordinator Nathan Proctor about the ruling and what it means for efforts to pass state level right to repair laws. Also: President Trump signed a major overhaul of the Department of Homeland Security’s cyber security operation into law last week. Jamil Jaffer of the firm IronNet joins us to talk about what it will mean for U.S. cyber readiness and about the need for more international coordination on cyber threats. 
     DMCA: Hacked by Librarian
    One of the strangest rituals in modern American life comes every third year, when the obscure Librarian of Congress finds him or herself thrust into the center of an always-roiling controversy over software piracy, software protection and consumer advocacy. That’s because it is the Librarian’s responsibility to issue exemptions to copy protections enshrined in the 1998 Digital Millennium Copyright Act. With the stroke of a pen, the Librarian can wave rules preventing owners from circumventing digital rights management (DRM) protections covering everything from software to movies and music. As DRM has been used to constrain use of more and more software-driven “stuff,” the Librarian of Congress and her exemptions have become a set piece in the technology culture wars.
    So it was on October 25th, when the Librarian handed down the latest list of exemptions (PDF) -the first since 2015. She renewed existing exemptions, including those for “jailbreaking” smart phones and for “motorized land vehicles” including tractors and other farm equipment. Going further, the Librarian of Congress created a broad exemption for “jailbreaking” computer programs for the purposes of repair. That exemption includes  smart vehicles, appliances, computers, toys, and other Internet of Things devices.
    Media outlets trumpeted the ruling as a big win for right to repair advocates. But was it? Our first guest this week, Nathan Proctor, heads up the US Public Interest Research Group (PIRG)’s right to repair campaign. In this Security Ledger interview, Proctor notes that having the right to defeat DRM is different from actually being able to do it. He and I talk about how the long arm of the DMCA now stretches deep into our economy, depriving owners and consumers of the right to modify and repair a wide range of devices. We discuss the ongoing effort to pass right to repair laws in 19 states and how the Librarian of Congress’s ruling may play into the national conversation about the right to repair.
    Is the world ready for a cyber NATO?
    In our second segment this week: U.S. President Donald Trump signed bi-partisan legislation last week that shook up the Department of Homeland Security. The new legislation consolidates DHS’s role as the U.S. government’s main agency for managing cyber security and creates a new, independent branch dedicated to cyber security: the Cybersecurity and Infrastructure Security Agency (CISA). The bill was hailed as a much needed reform that will consolidate both offensive and defensive cyber capabilities under one roof and hasten U.S. government response to critical threats and incidents<...
    44 min
  • Podcast Episode 120: They Email Ballots, Don’t They?

    In this week’s episode (#120): more than 100,000 U.S. voters submitted their ballots in the last presidential election via email in 2016. Despite that: hardly any attention has been paid to the security of email and online voting systems used by 32 states.  Also: anxiety about hacking of the midterm elections put the spotlight on state IT systems – particularly Secretary of States offices. But what is the state of state security? We’ll speak with Srini Subramanian of Deloitte about that company’s latest survey of State CISOs!







    Vote by email? What a great idea!



    It might be the election insecurity scandal you never heard of. In 2016, more than 100,000 voters across the globe, many of them U.S. service members, voted in federal state and local elections by email or using an online voting portal.



    If emailing a ballot to a random address sounds like a sketchy way to vote, that’s because it is. Online voting options in 32 states have been subject to hardly any scrutiny by computer security experts or regulators, despite warnings about the inherent risks of such systems.



    See also: As Election Threats Mount, Voting Machine Hacks are a Distraction





    Jeremy Epstein, Association for Computing Machinery





    In our first segment of the podcast, we’re joined by Jeremy Epstein of the Association for Computing Machinery (or ACM) and co-author of a recent report: Email and Internet Voting: The Overlooked threat To Election Security.



    The report, conducted by ACM, Common Cause, R Street and the National Election Defense Coalition advises that states that offer vote by email or online voting options to abandon them pending “a major technological breakthrough or fundamental change to the nature of the Internet.”



    The report also recommends a number of stop-gap security measures that can help limit the risk of voting by email – advice that Epstein likened to advising would be drunk drivers to refrain from driving “really drunk.”



    “This is pervasive and a lot of it is quite risky,” he told me. “The technologies being used are developed in most cases by private companies with no standards. And there’s no certification or validation by any meaningful organization.”



    State elections officials and Secretary of States offices often lack cyber security expertise to push back on vendors and insist on better security. However, even if they did it might not make a difference: the email system is inherently insecure. 



    You might also listen to this podcast: Episode 96: State Elections Officials on Front Line against Russian Hackers



    In this interview, Epstein tells us that experiments with email voting go back more than two decades – and that warnings about the security of such systems have gone right along with those experiments. Twenty years later, Epstein said, the fundamental risks haven’t changed, including malware, hacks of email voting systems, phishing and man in the middle attacks.



    The State of State Insecurity



    The midterm elections shone the spotlight on the security (and insecurity) of state IT networks,
    48 min