Download on the App Store

episodes

  • Podcast Episode 111: Click Here to Kill Everybody and CyberSN on Why Security Talent Walks
    In this week’s podcast (episode #111), sponsored by CyberSN: what happens when the Internet gets physical? Noted author and IBM security guru Bruce Schneier joins us to talk about his new book on Internet of Things risk: Click Here to Kill Everybody. Also: everyone knows that cyber security talent is hard to come by, and even harder to keep. But why does precious cyber talent walk? In our second segment, we’re joined by Deidre Diamond of cyber security placement firm CyberSN, who has all the answers.

    “I don’t think this issue will end our society”
    “I don’t think this issue will end our society.” Those were what counted as words of comfort by Bruce Schneier at the tail end of our recent discussion about his latest book, Click Here to Kill Everybody: Security and Survival in a Hyper Connected World. Still, its hard to see that statement as hyperbole. The subject of this latest book  (Bruce’s 15th by my count) is cyber physical risk – or what happens when we connect all the stuff that populates our environment to the Internet.
    This isn’t a new concern if you’ve been reading Security Ledger’s coverage of Internet of Things insecurity. In fact, our very earliest conceptions of malicious computer hacking -including the 1980s classic War Games – imagined the possibility that computer mischief could have real world consequences. (In the case of War Games, that was nuclear war).
    Only today, 35 years after War Games’ release, are we on the precipice of an era in which cyber attacks with physical consequences are the rule, rather than the exception to the rule. That’s because the fast-growing Internet of Things is wiring the machines that populate our homes, businesses and communities to the global Internet. And that includes “stuff” like cars, hospitals, dams, power stations and water treatment plants. In other words: the very systems that protect our life and property are now vulnerable (at least in theory) to cyber predation. The consequences of this shift are already manifest, even if they are yet to be fully comprehended.
    That fact prompted Bruce Schneier to write Click Here to Kill Everybody, in which he takes a deep dive into the security implications of the Internet becoming physical. The wiring of the physical world, which Schneier dubs the “Internet Plus” is happening in almost every sector of the economy, he notes. With it, organizations are realizing huge productivity games. But at the same time, security and physical risk is metastasizing in ways that, barring an intervention, could lead to a disaster. What’s needed, Schneier argues, is more government oversight of The Internet Plus in the name of public safety.
    [You might also like: FDA Medical Device Plan: a Baby Step in the Right Direction]
    In this conversation with The Security Ledger, Schneier talks about the dangers that the IoT poses and why he thinks government oversight of the Internet of things is inevitable. I started by asking Bruce to talk about the theme of his new book.
    Got security talent? Fear the Holidays!
    It is common knowledge that there aren’t enough information security professionals to fill all the cyber security jobs that our economy is...
    1 hr
  • Podcast Episode 110: Why Patching Struts isn’t Enough and Hacking Electricity Demand with IoT?
    In this week’s episode (#110): the second major flaw in Apache Struts 2 in as many years and has put the information security community on alert. But is this vulnerability as serious as the last, which resulted in the hack of the firm Equifax? We talk with an expert from the firm Synopsys.  And: we’ve heard a lot about the risk of cyber attacks on the critical infrastructure used to generate and distribute electricity. But what would happen if someone figured out to how to hack electricity demand? The Internet of Things just might make that possible. We talk to a Princeton University researcher behind a paper that discusses how even small changes in demand can have big consequences for the grid.

    Struts 2: why this is bigger than a patch
    Last week brought us news of yet another remotely exploitable vulnerability in Apache Struts 2, the open source framework that powers many modern web applications. This is the second major flaw in Struts 2 in as many years and has put the information security community on alert. A similar flaw in Struts in 2017 was weaponized by cybercriminals and used to hack into high profile organizations including Equifax.

    The alarm bells about another round of Struts focused attacks rang louder over the weekend, after a proof of concept exploit for the hole was discovered on the open source code repository known as GitHub.But is the newly discovered vulnerability as serious as the 2017 flaw that led to the Equifax hack? The security community is of two minds about that.
    To understand better what the latest Struts 2 vulnerability is all about, we invited Tim Mackey of Synopsys into the studio to talk about it. Tim is a technology evangelist in Synopsys Software Integrity Group and authored an excellent analysis of the latest Apache Struts vulnerabilities, which you can read here.
    In the first part of our podcast, Tim and I talk about what’s behind the latest vulnerability and why patching this hole is just the beginning of the work that application development shops need to do to harden their applications against attacks.
    Hacking Electricity Demand with IoT
    As smart homes and businesses take root, more and more power hungry appliances are being connected to the Internet. Already, products like air conditioners and HVAC systems, water heaters and kitchen appliances sport IP addresses and web-based interfaces that allow their owners to monitor and control them from a distance. But what if all those power-hungry devices could also be compromised and – like the hundreds of thousands of webcams and video recorders that made up the Mirai botnet – made to do the bidding of a malicious actor?
    [Also listen to: Podcast Episode 94: Black Report takes Hacker View and...
    34 min
  • Spotlight Podcast: Arctic Wolf on Nurturing Talent for the Evolved SOC
    In this Spotlight Podcast, sponsored by Arctic Wolf Networks: sessions at this month’s Black Hat Briefings on on PTSD and substance abuse among security workers are proof that the high pressure, high stakes world of information security can take its toll. So what  does it take to find, train and nurture information security pros? Sam McLane, the Chief Technology Services Officer at the firm Arctic Wolf Networks joins us to talk about how his company holds on to top security talent. 

    It wasn’t so long ago that The Black Hat Briefings in Las Vegas were all about the hacks, the lulz and the 0days. But, slowly, that has changed. As cyber security has matured from a niche of the technology industry to a full fledged, multi billion dollar industry, more and more attention is being paid to the challenges facing the industry itself: from worker shortages to racial and gender imbalances to the stress of front line cyber security jobs.
    That was the case at this year’s Black Hat Briefings and the DEF CON conference, where talks on problems such as PTSD and substance abuse among security practitioners were part of the agenda. But with talent scarce, but burnout commonplace, what is the best way to identify, train and cultivate security talent? What are the problems that front line cyber security professionals working in secure operations centers being asked to handle? And How do modern day SOCs manage threats across both traditional IT environments and newer cloud-based deployments?
    To find out, we sat down on the sidelines of the recent Black Hat Briefings to chat with Sam McLane, the Chief Technology Services Officer at the firm Arctic Wolf Networks, which offers SOC as a Services.
    In this conversation, Sam and I discuss what it takes to develop top notch cyber talent, why the information security profession is so prone to burn out, and how employers can cultivate a work life balance in what is a high stress career.
    Sam said it can take 5 to 6 years of on the job experience to develop a top-notch security analyst – maybe more if employees are stuck in narrowly defined roles or don’t have the opportunity to broaden their skillset.
    “I think the training is getting better but it truly is what you’re exposed to,” McLane said.
    And, while it might be tempting to let your security pros work 60 hour weeks and burn the midnight oil, McLane said,  that might not be the best approach in the long run. If top talent burn out and leave the industry, companies are often left with “really smart people who have no practical experience.” The result, McLane said is that “we’ll have to relive history.”
    Check out our full conversation using the link above. You can also listen to our podcast over at Blubrry or on Soundcloud.
    26 min
  • Podcast Episode 109: What’s The US Freedom Army? Ask Russia.
    In this week’s episode of the Security Ledger Podcast (#109): What lurks in the dark recesses of online information operations? How about a secret “US Freedom Army” organized by Russia linked online “info ops?” Dave Aitel of Cyxtera joins us to talk about it. Also: hacking critical infrastructure isn’t just for nation states anymore. Cybereason joins us to talk about the cyber criminals hacking into industrial control systems. 

    Psst! Want to join the Freedom Army?
    In the wake of the 2016 Presidential election, studying social media activity has gone from a niche obsession for a few social scientists to something akin to a national security priority. New analyses of the activity of twitter bots and networks of fake social media profile now pop up frequently, and just as frequently garner mainstream media attention.
    But what is hiding out there among the online influence campaigns? You might be surprised, says Dave Aitel, the Chief Technical Security Officer of the Threat Management and Analytics Division of the firm Cyxtera. Dave recently completed an analysis of Twitter bot data. Among the revelations: the prevalence of online efforts to organize real world gatherings, like the “US Freedom Army,” which appears to be a military organization promoted via Twitter and other social media to U.S. survivalist groups.
    [You might also be interested in: U.S. sanctions Russian companies, individuals over cyber attacks]
    As frightening as that sounds, Aitel is skeptical of both social networks’ efforts to clamp down on bots and other false accounts and efforts to understand the scope of the online bot problem.  Despite recent efforts to shut down bots and other false accounts, he said, platforms like Twitter still have a financial incentive to keep such accounts active. Until the economics of such networks change to penalize traffic from false and automated accounts, Aitel believes, it is unlikely we’ll see progress in reducing the number of bots.
    “In order to get rid of (information operations) we have to find a way to penalize Twitter for having bots, financially, because right now they’re incentivized to encourage bots,” – David Aitel, Cyxtera.
    And for the growing ranks of researchers trying to understand online influence campaigns, Aitel cautions that the sheer volume and diversity in online disinformation and influence campaigns mean that individuals who try to sort or categorize amorphous data sets risk misunderstanding the shape of online activities or, even worse, engaging in what Aitel described as “auto ethnography.”
    Check out our full conversation in this week’s podcast.
    Critical infrastructure hacks: not just for nation states anymore
    When the firm Cyberreason set up a honeypot network designed to look just like a functioning industrial control system environment, they were expecting to attract a few flies. What they weren’t expecting was a swarm of online attackers, including one who managed to compromise the network and then offer it up for sale on a cyber criminal bulletin board.
    But Ross Rustici, Cyber Reason’s Senior Director of Intelligence Services says that we shouldn’t be surprised that rank and file cyber criminals have taken an interest in critical infrastructure systems.
    [You might also like: FBI,
    38 min
  • Spotlight Podcast: Synopsys’ Dan Lyon on the Challenge of Securing Connected Medical Devices
    In this Spotlight Podcast, sponsored by Synopsys: In the wake of a presentation at Black Hat about security flaws in implantable pace maker devices, Synopsys Principal Consultant Dan Lyon joins us to talk about why medical device makers struggle to make their connected medical devices more secure. Dan and I discuss some of the flaws in the approach that medical device makers take to security, and how manufacturers can take a page out of their own book: applying the same standards to cyber security as they do to – say- device safety. 

    The security of medical devices figured prominently at last week’s Black Hat, B-Sides and DEF CON hacking conferences in Las Vegas. In one of the more news-worthy demonstrations, researchers Billy Rios and Jonathan Butts demonstrated how to remotely exploit an implantable pacemaker made by the firm Medtronic, showing how malicious software could be used to take control of the device – even executing shocks to a patients.

    This wasn’t the first demonstration of its type. Rios and Butts have been publicly butting heads with Medtronic for months over the security flaws he found. At Black Hat, he characterized the ponderous process of working with the firm on fixes as “an 18-month roller coaster of unresponsiveness, technical inefficiencies and misleading reactions.” And, of course, hacks and security flaws in implantable devices are not new. The late, great device hacker Barnaby Jack demonstrated an over the air attack on an insulin pump at a hacker conference in Miami way back in 2011.
    The question is this: why is it that sophisticated, multi national firms that make medical devices have such a hard time addressing cyber risk in their products? How is it that a manufacturer can possess the design savvy to make an electronic device that lives within the human body, yet fail utterly to understand and account for the possibility of even trivial electronic manipulation and attacks?
    [You might also be interested in:Spotlight: Deepika Chauhan of Digicert on the Challenges of Securing the Internet of Things]
    Our guest in this Spotlight podcast knows better than anyone the answer to those questions. Dan Lyon is a principal consultant with Synopsys and a seasoned medical device engineer who spent more than 18 years working as an engineer at medical device maker Medtronic.
    In this spotlight conversation, Dan and I talk about the cyber risk and about the many challenges manufacturers have securing connected medical devices from software based attacks. One of the fundamental problems, Lyons tells me, is that medical device makers often focus on a single technology “fix” for cyber security – for example the use of encryption – when they need to take a more holistic approach to securing connected health devices. The job of securing medical devices isn’t akin to plugging a hole in the firewall, Lyons notes. Instead, it is a far bigger job akin to the process of designing medical devices for safety.
    “Manufacturers need to take a step back,” he said. “They need to conduct risk management and take a page from their own safety risk manag...
    28 min
  • Episode 108: DEF CON’s Car Hacking Village and is the Open Source Model Failing on Security
    In this week’s podcast (#108), sponsored by CA Veracode: hacker summer camp wrapped up on Sunday, as the 26th annual DEF CON conference concluded at Caesar’s Palace in Las Vegas. Hacks of connected and smart vehicles were a big theme again this year. We sat down with the organizers of DEF CON’s Car Hacking Village to see what was news at this year’s show.  Also: open source software has revolutionized the way software gets made, and turbo charged the growth of companies like Facebook and Uber. But is the open source model failing us when it comes to security? We’re joined by OWASP founder Mark Curphey of CA Veracode to discuss it.

    Elon who? A visit to DEF CON’s Car Hacking Village
    Hacker summer camp wrapped up on Sunday, as the 26th annual DEF CON conference concluded at Caesar’s Palace in Las Vegas, ending a week of security conferences including the annual Black Hat Briefings and B-Sides Las Vegas. Some of the headlines out of the shows were predictable: DEF CON’s voting village yielded all too predictable stories about outdated electronic voting equipment making an easy target for hackers – this year it was an 11 year old girl.
    While we always love to see middle schoolers and teens strutting their stuff at DEF CON, we’ve also weighed in on why hacks of aging e-voting systems might not be the best use of the security industry’s time and energies.
    What was of interest at this year’s show were hacks of connected vehicles – including a talk and paper (PDF) by Jeep Cherokee hackers Chris Valasek and Charlie Miller, a presentation of a remote hack of a Tesla vehicle by researchers at China’s Keen Security (a division of Tencent) as well as  — wait for it — a surprise appearance by Tesla Chief Elon Musk, who left with a promise to release Tesla’s security software as open source, clearing the way for it to be used across the industry.
    That’s a great gesture and speaks to Musk’s history and roots as a creator of Internet-powered startups like Paypal. But – as we know, the automobile industry is older and wholly different from Silicon Valley and there’s no indication that the future of connected cars will look anything like that of connected phones, connected homes or anything else.
    To get a sense of where things might be heading, Security Ledger stopped by the Car Hacking Village at DEFCON last week to speak to the folks from Grimm, a top vehicle security consultancy that organizes the Car Hacking Village. In our first segment of this week’s podcast, I speak with Bryson Bort, Grimm’s Chairman and Founder and researchers Tomas Tillery and Aaron Cornelius about the differences and similarities between hacking vehicles and other kinds of connected endpoints, and about what the near future and the advent of self driving and autonomous vehicles may hold.
    We start off by talking about the Car Hacking Village, which this year added a “kidnap challenge,” in which DEF CON attendees were grabbed (with their consent, of course), blindfolded, thrown in the back of a Jeep Cherokee and given a laptop and a connection to the vehicle’s network. Their challenge, manipulate the car to spring the trunk or door locks and free themselves.
    With Many Eyes, Open Source Risk is Deep
    34 min
  • Special Black Hat Coverage: Google’s Parisa Tabriz Says Don’t Be A Jerk
    In this special Black Hat edition of the Podcast, sponsored by UL: Parisa Tabriz, Google’s Director of Engineering for the Chrome Web browser, brought some strong medicine to Las Vegas for her Black Hat keynote speech. We talk about why her simple message was so groundbreaking. Also: Ken Modeste of UL joins us from the Black Hat briefings to talk about UL’s efforts to make cyber security as important to consumers in the 21st century as product safety was in the 20th.

    Don’t be a Jerk: Parisa Tabriz’s Radical Philosophy
    “Be a team player. Don’t be a jerk” These were some of the recommendations that Google Director of Engineering Parisa Tabriz laid on the overwhelmingly male and notoriously ornery security experts in her keynote speech opening this year’s Black Hat briefings.

    The speech was remarkable for a number of reasons. For one, Black Hat made its name by celebrating cyber offense. It is a show that regularly makes headlines with eye popping software exploits, from Barnaby Jack’s famous “jack potting” attack that had an ATM machine spitting out cash on stage to Charlie Miller and Chris Valasek’s remote takeover of a Jeep Cherokee. But Tabriz squarely represents the perspective of a defender. But the talk was remarkable not only because of what Tabriz said, but because of who she was: a 36 year old female engineering lead at perhaps the world’s most important and consequential technology company.
    In an industry known for bluster , Tabriz’s message was also a departure. Talking about Google’s efforts to improve the security of its Chrome browser, she spoke candidly about the obstacles her team faced both internally and externally as they worked to make Chrome more secure.
    Rather than presenting security improvements to Chrome as foregone conclusions, she spoke about the practical and cultural challenges that confronted even simple changes, like warning users about insecure websites. As an example, she talked about how the introduction of Chrome’s Site Isolation feature trickled down to affect even basic functionality like the “Control – F” search feature.
    At a show known for its bro-culture and in your face attitude, Tabriz emphasized the need to humanize security work: celebrating those in the audience who do the hard work of securing software systems and talking about how Google’s Chrome team found motivation in personal stories of friends and relatives affected by browser insecurity and used everything from poetry slams, to stickers to cake parties to celebrate their successes along the way.
    In all, a project to secure Chrome that Tabriz and her team slated for one year took more than six and required a massive investment of time and resources from Google the company and from Google’s many employees. The lesson is that better security won’t come from a team of ninjas repelling into your company to ferret out and fix all the flaws. Rather, it will be a longer, harder and much less sexy scene: a group of dedicated professionals in khakis and jeans, working tirelessly to overcome technical, cultural and economic hurdles” respecting each other, working together as a team. Learning from their mistakes. Fighting and winning internal battles and – most importantly – not being a jerks. That’s a really powerful message.
    Ken Modeste of UL on the Challenge of building a Culture of IoT Security
    What is Underwriters Lab, the venerable product safety and testing firm doing roaming the halls of the Black Hat briefings? Ken Modeste, the Director of Connected Technologies at UL, says the 124 year old company is on mission to do for product cyber security in the 21...
    30 min
  • Episode 107: What’s Hot at Black Hat & does DHS need its new Risk Management Center?
    In this episode of The Security Ledger Podcast (#107): Hacker Summer Camp takes place in Las Vegas this week as the Black Hat, DEFCON and B-Sides conferences take place. We’re joined by DigiCert Chief Technology Officer Dan Timpson to talk about the presentations that are worth seeing. And, in our second segment, The Department of Homeland Security launched a new Risk Analysis Center that sounds a whole lot like some programs it already runs. Is this bureaucratic overkill or is DHS on to something?

    Black Hat: Algorithms are not our Friends
    The Black Hat Briefings conference kicks off this week in Las Vegas. The annual event, jokingly referred to as “hacker summer camp,” has long been a proving ground for top researchers and a stage for headline grabbing hacks and exploits.
    This year will be no different, with attacks on implantable medical devices and smart cars on the agenda.
    What are the big trends at this year’s show? To find out, we invited Dan Timpson the Chief Technology Officer at DigiCert* back into the Security Ledger studios to talk about what talks and demonstrations caught his eye, and about the most important themes to emerge from this year’s show.
    Dan said that the security and integrity of machine learning systems and the algorithms that are dictating security behavior is a major area of interest and concern. He recommended the Raffael Marty’s talk on Thursday on “Why Algorithms are Dangerous.”
    Dan and I also talk about DigiCert’s latest foray into the BlockChain scene as a new member of the Linux Foundation and also the HyperLedger initiative. While BlockChain is no (clear) replacement for traditional PKI deployments, there are many potential applications of the technology. “There is some magical thinking (about) blockchain topic. It’s in the point of time where its still being proven,” Timpson told me. “But on the legit side, I think we see opportunities with electronic health records or supply chain management.” Blockchain, he said, could be used to track food within complex food or technology supply chains and DigiCert sees opportunities to use its background as a Certificate Authority and managing digital identities to further Blockchain adoption.
    Some other presentation that Dan and I discus:

    * Understanding and Exploiting Implanted Medical Devices
    * Over-the-Air: How we Remotely Compromised the Gateway BCM and Autopilot ECUs of Tesla Cars
    * Deep Neural Networks for Hackers: Methods Applications and Open Source Tools
    * Applied Self Driving Car Security
    * Breaking the IIOT: Hacking Industrial Control Gateways
    *
    47 min
  • Spotlight Podcast: CSS on why Crypto Agility is the Key to Securing Internet of Things Identities
    In this Spotlight Edition of the Security Ledger Podcast: identity is at the root of many of the security problems facing the Internet of Things, from vulnerable and “chatty” endpoints to a lack of robust update and lifecycle management features. To figure out how we might start to build a more secure IoT ecosystem, we invited Judah Aspler, the Vice President of IoT Strategy at Certified Security Solutions, or CSS Security in to talk about how more agile PKI infrastructure is one element in scaling the Internet of Things without creating a giant security mess. 

    Most of the information technology field embraced public key infrastructure (or PKI) technology decades ago, recognizing it as the best way to manage identity and secure sensitive software updates and transactions over distributed networks. But in the world of Operational Technology, or OT, the embrace of PKI and cryptographically strong, immutable digital identities is still a work in progress.

    We see this truth borne out in the news almost daily. Read a story about independent security researchers uncovering evidence of sensitive and even safety critical systems that are vulnerable to man-in-the-middle attacks or malicious software updates and absent, weak or brittle digital identities are probably to blame. Even worse: that sad state of affairs is the norm on the burgeoning Internet of Things, as well, where lax management of identities is more the rule than the exception.
    How is it that our most sensitive systems and IT environments are so woefully behind? To find out, we invited Judah Aspler into the Security Ledger studios. Judah is Vice President of IoT Strategy at CSS Security, which works as a PKI enabler for companies of all sizes and across industries.
    Judah says that operational technologies and Internet of Things technologies lag behind traditional enterprise IT in a number of areas, from software signing to secure update and lifecycle management. Often, problems creating and managing digital identities lie at the root of those problems. For example, many legacy OT applications emphasized continuity and simplicity over security, using shared PKI keys across their whole installation base and/or relying on signing keys with expiration dates set decades or more into the future.
    While those decisions made sense at the time, they’re no longer suitable for a fast-moving technology and threat environment in which Certificate Authorities, themselves, may fall victim to cyber criminals or encryption algorithms might fall to powerful super- or quantum computing systems.
    In the years ahead, what Aspler calls “crypto agility” will be paramount, as changing technology and new threats put pressure on connect device makers and infrastructure owners to rely on strong but replaceable digital identities.
    In this podcast, Judah and I talk about the need for what he terms “crypto agility”  and how the advent of quantum computing and changes in the risk environment are raising the bar for PKI technology providers.
    35 min
  • Episode 106: Election Trolls Are Afoot. We Talk To The Guy Who Watches Them
    In this episode of The Security Ledger Podcast (#106): with the November midterm elections in the U.S. fast approaching, election related shenanigans have already cropped up in connection with contested races in swing states, as well as around “hot button” issues such as gun control and race. To find out what the trolls are trolling about, we speak with Jonathan Morgan, the CEO at the firm NewKnowledge, which provides disinformation defense services for organizations. 

    As July passes into August, the political season is kicking into high gear ahead of the November mid term elections. And, right on schedule, the warning signs are flashing about malign influence operations that are trying to use platforms like Facebook and Twitter to provoke partisan anger and sow division within the voting public. The latest warning flare came from Facebook, which on Tuesday said that it removed the first of eight Pages and 17 profiles on Facebook for violating the site’s rules against “coordinated inauthentic behavior.” Despite the popular conception of election trolls ginning up right wing outrage, the groups Facebook found were often promoting left leaning causes including so-called “resistance” groups opposed to the administration of President Donald Trump.
    But our guest on this week’s podcast says that nobody should be surprised to find that the people and governments backing online influence and disinformation campaigns flexible have a flexible attitude towards political messaging is a hallmark of minority issues. To paraphrase political consultant James Carville: “It’s the anger and division, stupid!”
    Jonathan Morgan is the CEO of the firm NewKnowledge, which offers disinformation defense services for organizations of all stripes. In this exclusive interview with The Security Ledger podcast, Morgan talks about what his company has observed in recent months and how the  face of online trolling operations changed in the wake of the 2016 Presidential race and what can we expect from online actors this campaign season? To find out we sat down with Jonathan Morgan, the CEO of the firm NewKnowledge, which offers online disinformation defense services for organizations.
    [Spotlight Podcast: Why North Korean Summit won’t End Hacking Threat]
    In our conversations, Jon and I talk about why online disinformation campaigns like those seen during recent elections are different from the kinds of influence campaigns that have come before, and how organizations facing online disinformation campaign can take steps to counter their damaging affects.
    Jon said NewKnowledge is seeing “a steady stream of campaigns” that are trying to co-opt the national conversation around the mid terms using socially divisive issues. “We’ve seen everything from the way the NFL is interacting with players who are protesting police brutality…to gun reform and gun legislation…to topics around immigration,” Morgan said. “The typical divisive topics of conversation that end up being hot button issues in political campaigns? We’re seeing campaigns targeting these issues day in and day out.” Race figures prominently among those issues, with ads and groups targeting the Black Lives Matter movement prominent both in 2016 and during the 2018 midterms.
    [RSA Labs: cloud, microservices,
    24 min