Download on the App Store

episodes

  • Breaking the Ice on DICE: scaling secure Internet of Things Identities
    In this Spotlight Podcast, sponsored by Trusted Computing Group*, Dennis Mattoon of Microsoft Research gives us the low-down on DICE: the Device Identifier Composition Engine Architectures, which provides a means of  solving a range of security and identity problems on low cost, low power IoT endpoints. Among them: establishing strong device identity, doing device attestation and safe deployment at scale and verifying software updates. 

    Secure identities are the foundation of secure ecosystems. At the risk of oversimplifying: without a foundation of strong identity, there can be no real security. We know that intuitively just from our experiences online, where phishing attacks and identity theft are rampant – often taking advantage of weak identities like user names and passwords, or Social Security Numbers.

    It’s especially true of the Internet of Things, where both the diversity and scale of connected endpoints create endless opportunities for mischief and mayhem. We have seen, for example, how weakly configured IP cameras and routers can be compromised and enrolled in global botnets like Mirai used to siphon sensitive data from corporate and personal networks. Hacks of connected cars and implantable medical devices have been shown to have potentially lethal consequences, while Hacks of point of sale systems have long been the bane of retailers.
    The challenge is how to create secure and irrefutable identities on IOT endpoints that aren’t suitable for deployment of a Trusted Platform Module or similar component because they’re resource or cost-constrained – or both.
    Dennis Mattoon of Microsoft Research says that TPM’s just aren’t practical for the vast majority of IoT endpoints. “In just about every way you can measure the cost of a device, and an element of your IOT ecosystem, the TPM will eat up those resources,” he said. That includes the amount and complexity of code needed to implement a full TPM, as well as the infrastructure and services needed to manage and intermediate TPM interactions. “Its just a big complicated thing,” Mattoon notes. “That’s fine for PCs and servers. We have those libraries and we’ve wrapped our heads around how that works. You have BitLocker working in the background and that’s great on a PC, which has so much room to spare you don’t even know it’s there.”
    But the economics of IoT endpoints are the exact opposite. “I can’t afford to waste space in flash on unnecessary code,” Mattoon notes. “I don’t want to take my carefully crafted ROM on a micro contoller and introduce complicated code to deal with the TPM. That’s a big ask.” The practical result of that “big ask” is that lots of connected product designers just say “no,” he said.
    One answer is DICE, a new secure architecture designed by Microsoft and the Trusted Computing Group specifically for resource and cost constrained endpoints like those on the Internet of Things.DICE – or the Device Identifier Composition Engine (DICE) Architectures – was released in September, 2017. It provides both security and privacy benefits to IoT and embedded systems unsuitable for traditional Trusted Platform Modules.
    But what is DICE and how can connected device and “thing” makers best take advantage of the technology? In this Spotlight Podcast, we sat down with  Mattoon, a senior software development engineer at Microsoft Research to learn more about how the new architecture c...
    34 min
  • Episode 105: Is Trolling a Human Rights Abuse? Also: the Do’s and Dont’s of Ransomware Negotiation
    In this week’s podcast: a report out last week from The Institute for the Future makes clear that state sponsored trolling has gone global and is now a go-to tool for repressive regimes worldwide, constituting a new form of human rights abuse. Ben Nimmo of The Atlantic Council joins us to discuss. Also: ransomware is one of the most effective forms of online crime. Despite that, many organizations have no formal plan for responding to a ransomware attack: we talk with Thomas Hoffman of the firm Flashpoint*, which has launched a new service to help firms prepare for and respond to ransomware.

    State sponsored trolling: the newest form of human rights abuse
    To read the headlines, you’d think that the US was the only country dealing with a wave of politically motivated online campaigns of trolling and disinformation. But a report out last week from The Institute for the Future (PDF) makes the case that trolling has gone global and is now a go-to tool for repressive regimes worldwide. State sponsored trolling, the report concludes, is a new form of human rights abuse that is taking place from Azerbaijan toIndia to Venezuela, often with dire consequences for democracy and civil liberties.
    While the methods used by trolls may vary, the objective is always the same, says Ben Nimmo of the Atlantic Council’s Digital Forensic Research Lab: intimidation. “Its all about intimidation and scaring people offline,” he told me.
    [See also: China Using Big Brother-Like System to Track, Monitor Minorities]
    In our first segment, we invited Ben in to talk about the Atlantic Council’s research on online trolling campaigns. Nimmo said that, while the 2016 presidential election in the US riveted the world’s attention on online disinformation campaigns, in fact they’re nothing new and have played a part in more than one consequential political campaign, including two recent Mexican presidential contests.
    If the Russian influence campaign was a surprise to lawmakers and authorities in the U.S., it shouldn’t have been, Nimmo said. “Online trolling is a worldwide problem and it certainly didn’t start in the United States,” he said.
    [Read more stories about Russian hacking on Security Ledger]
    In fact, online disinformation campaigns have been noticeable in Russian politics for almost two decades. Russian journalists had infiltrated the St. Petersburg troll factory The Internet Research Agency as early as 2013 to document what was going on there. By 2016, Nimmo notes, there was lots of evidence that Russia’s trolls were interested in the U.S. election. “All the clues were there, but nobody in the U.S. were paying attention to them.”
    That’s no longer the case. Ben and I talk about how trolling has spread and how its changing in the face of reforms from social media platforms like Twitter and Facebook. We also talk about how to spot disinformation and the work of trolls and bots when you come across them.
    Ransomware Criminal on Line 2!
    You’ve likely read a lot about ransomware attacks, like the one that laid low the City of Atlanta in recent months. But being aware of a threat is different from being prepared to address it. Should you negotiate with the ransomers? And if so, under what conditions? What is the best way to communicate with them? Should your company keep crypto currency on hand to pay ransom? if so, how much and what types of crypto currency (there are lots of them)?
    43 min
  • Episode 104: Mueller’s Cyber Eye on the Russian Guys also Reaper Drone Docs Stolen
    In this week’s episode of the podcast (#104): the Mueller indictment of 12 Russian GRU operatives for hacking the 2016 presidential election was a bombshell. It was also 30 pages long. We read it so you don’t have to and we’ll talk about the big take aways. Also: when researchers from Recorded Future saw an offer on a dark web marketplace for documentation describing the operation of the US Military’s classified Reaper Drone, they thought it must be a ruse. But they were wrong. We’ll talk with RF researcher Andrei Barysevich about how highly sensitive military drone documents fell into the hands of a low level cyber crook.

    Cyber eye on the Russian guys
    The release last week of the latest indictment (PDF) from the office of Special Counsel Robert Mueller was, quite simply, an earthquake in the already shaky political terrain in the United States. The indictment names and described the months long exploits of 12 Russian operatives – employees of Russia’s Main Intelligence Directorate of the General Staff (or “GRU”) – as they planned and carried out cyber attacks on U.S. targets including the presidential campaign of Democratic Party candidate Hillary Clinton, the Democratic National Committee (DNC), Democratic Congressional Campaign Committee (DCCC), state elections offices and even election equipment vendors.
    Excepting the names of the Russian agents who carried out these predations, much of the information contained in the indictment is old news. We know about the spear phishing email sent to Clinton Campaign Chairman John Podesta in the guise of a Google security warning. We had read, as well, about the communications between what were believed to be Russian operatives and organizations like Wikileaks and shadowy social media accounts like Guccifer 2.0 and DCLeaks.
    So what is new and important about the indictment? We read the whole thing so you wouldn’t have to. And here are three key takeaways that every information security pro should know.
    On the Internet, Robert Mueller knows you’re a dog.
    Anonymity was the original killer app of the Internet, as that Peter Steiner New Yorker cartoon from 1993 memorialized. But last week’s indictment makes clear that piercing the Internet’s veil of anonymity is hard, but not impossible. The biggest take-away from reading the 30 page, 11-count indictment is just how much Mr. Mueller and his team have reconstructed of that online campaign and the impressive amount of information they have on the individuals who carried it out.
    The indictment rolls out not just identities, titles and roles, but tools, tactics, processes in minute detail. The indictment not only describes the roles the 12 named Russian operatives played in the conspiracy to disrupt the U.S. election, it provides accounts of specific actions they performed down to the exact day and time they performed them. One of the most impressive “reveals” comes in paragraph 41, in which Mueller’s team is able to link searches for English language phrases conducted on a Moscow-based server operated by the GRU during a 40 minute window on June 15, 2016 with the exact same phrases in a blog entry posted by “Guccifer 2.0” later that day. Wow!
    Three words: Time. To. Detection.
    It’s common for information security vendors these days to throw around nebulous terms like “threat intelligence,” “TTPs” and “time to detection.” It all ends up sounding like so much marketing gobbledygook. But if you read the Mueller indictment closely, you’ll realize that its anything but. The cyber failings of the Clinton campaign and the Democratic Party are well documented at this point: lackluster security, no use of strong second factors and a soporific incident response. And, “yes,” the Dems were being targeted by a nation state actor who was re...
    31 min
  • Episode 103: On the Voice-Controlled Internet, How Will We Authenticate?
    Voice based interfaces are growing in popularity, complexity and influence. But securing these interfaces has, thus far, been an afterthought. If we are destined to interact with the smart systems around us using our voice, how exactly will we manage to authenticate to those devices? In this podcast we speak with Ben Rafferty of the firm Semafone about the challenges of securing voice-based systems. Semafone won the recent PAYMNTS.com Voice Challenge with a way to use Amazon’s Alexa voice assistant as an out of band authentication mechanism.

    Alexa! Authenticate me! Voice based interfaces are all the rage. Anyone with an Amazon Echo or Google Home device in their kitchen knows that. Combining voice recognition and machine learning technology, these devices allow us to interact seamlessly with the Internet – searching the web or even purchasing products with our voice. Voice makes interacting with e-commerce sites like Amazon frictionless, which is why companies like Amazon love them and see them as the future of computing.
    That future seems bright. The industry analysis firm IDC predicts that smart speaker sales will increase from $4.4 billion to more than $17 billion in the next four years.
    But voice technology isn’t without its flaws. Like any software driven devices, connected products like voice assistants pose a range of security and privacy risks. And current generation voice technologies provide far fewer safeguards than traditional IT assets like laptops, desktops or even smart phones. Notably: they can’t distinguish one user from the next. Walk into your friend’s apartment, eye his Echo and say “Alexa, purchase 50 cases of Mountain Dew,” and you’ve successfully hijacked that friend’s account for your own, nefarious purposes.
    [See also: Researchers Warn of Physics-Based Attacks on Sensors]
    That raises the question of how exactly authentication should work as voice based interfaces proliferate. Today, amazingly, Echo and Google Home largely ignore authentication, assuming that if you’ve authenticated to your account when you set up your device, that will suffice. That’s a big assumption.
    That’s why this podcast episode is focusing on the security of voice based systems: how they might prove vulnerable to attackers and – also- how tools like Amazon Echo might provide a means of enhancing the security of online activity and transactions. Our guest is Ben Rafferty, the Global Solutions Director at the firm Semafone, which sells technology for call centers. His company recently won the 2018 PYMNTS.com Voice Challenge, a contest to use Amazon’s virtual assistant, to solve problems, remove points of friction and add value to the payments and commerce ecosystem.
    [You might also like: Opinion: With Internet of Things, Devices become Insider Threat]
    In this conversation, Ben and I talk about Semafone’s winning entry – Three Little Words – a solution that allows organizations like banks to use voice based systems as an out of band authentication mechanism for high value transactions. We also talk about the challenges of securing voice based systems.
    Check out our full conversation above!
    23 min
  • Episode 102: Is Blockchain the Foundation for a Secure Internet of Things?
    In this episode of the Security Ledger Podcast (#102): we think of blockchain as the immutable and distributed ledger that vouches for crypto currency transactions. But is its real potential as a foundation for a secure Internet of Things? We speak with Vaughan Emery, the CEO of the start-up Atonomi, which markets itself as a secure ledger for Things. 

    The appreciation in the value of crypto currencies such as BitCoin and Ethereum, the attention of entrepreneurs, investors and Wall Street firms has focused on Blockchain, the underlying distributed ledger technology that is used to record and verify crypto currency transactions.
    The future of currencies like BitCoin is anybody’s guess, but many technologists think that the future of distributed ledgers like Blockchain is bright, with many applications. Those include applications for the Internet of Things, where the scale, diversity and criticality of IoT endpoints and transactions make secure identities and immutable transactions a top priority.
    Can blockchain secure the Internet of Things?
    But how exactly might blockchain enable secure Internet of Things ecosystems? To help answer that, we sat down with Vaughn Emery, the CEO of the firm Atonomi, a start up that is marketing a blockchain -based security solution to protect the Internet of Things and enable secure device-to-device autonomous transactions.
    You might also like: Cyber Criminals Launder Billions with Bitcoin, In-game Loot
    Atonomi has developed its own Security Protocol which can validate device identity, track device reputation, and provides immutable blockchain ledgering of all transactions. The company’s ICO – or initial coin offering – went off in early June to a group of pre-cleared and vetted purchasers. According to Atonomi, the company sold approximately 133 million of its tokens to 14,300 pre-cleared purchasers. In return, the company received 14,000 Ethereum tokens valued (as of this writing) at more than $6.5 million.
    Notably: the list of purchasers did not include US residents, given what Atonomi said was an uncertain regulatory climate in the US in regard to ICOs.
    Also consider listening to Episode 100: Estonia’s Former CIO talks about engineering a secure electronic vote
    In this conversation, Vaughn and I talk about the Atonomi technology and, more broadly, about the application of blockchain technology to IoT security problems like identity and data integrity. That kind of uncertainty is something that makes discussions about blockchain and its various applications tricky – and ICO backed start-ups of particular interest. In this podcast, among other things, I ask Vaughn about the ‘bad rep’ that speculation and scams have given to ICOs and the crypto currency space, in general, and whether that threatens to derail blockchain’s adoption.
    Check out our full conversation using the link above.
    26 min
  • Episode 101: Ink Jet Nation? Doctorow on a Dystopian IoT and City of Atlanta Employees phished on Rogue Wi-Fi
    In this episode of the podcast (#101): will the Internet of Things enable a glorious future of intelligent and subservient “things”? Or will it birth “ink jet nation:” a dystopia of closed and expensive technology silos that use patents, software licensing and lawsuits constrain the use, reuse and repair of connected things? We talk to author and activist Cory Doctorow following his keynote at last week’s Security of Things Forum. Also: the city of Atlanta has made headlines after a ransomware outbreak crippled city services. But the city may have more to worry about: wireless phishing attacks targeting government employees and elected officials. We speak with Dror Liwer of the firm Coronet about what they found. 

    Ink Jet Nation?
    Surely at the check out line at the office supply store, you’ve wondered why it is that a slim cartridge of ink the size of a credit card sets you back close to $30. Printer ink, on a per ounce basis, is among the most expensive stuff you can buy. Depending on the brand, it can be more expensive than Champagne, caviar or Chanel No. 5 perfume. And we know that manufacturers like HP and Dell aren’t harvesting the stuff from the bellies of Sturgeon.
    Why so expensive? Well, because printer manufacturers have been very successful in creating product ecosystems that make it nigh impossible to use ink jet cartridges made – or even serviced by anyone else but them. That has included unsuccessful attempts to sue companies that refill spent inkjet cartridges, accusing them of patent violations. Still, despite losses in court, the defacto ink monopolies of HP, Dell, Lexmark and others have allowed those companies to name their price, and demand that their customers pay it.
    Printer ink is one thing. But what if companies that made cars, home appliances and medical devices were to pursue the same strategy? What if your Kitchen Aide toaster would only work on Kitchen Aide brand bread? What if your GE dishwasher only started when loaded with GE-approved plates, dishes and cutlery?
    The Internet of Things may be tilting us in that direction, says author and activist Cory Doctorow. Speaking ahead of his keynote presentation at The Security of Things Forum last week, Doctorow said that the penetration of software into our daily lives and physical environments creates the pre-conditions for a future in which computers are no longer powerful tools that enable us to do lots of things, but software constrained stuff that insists on us doing things in ways that the device maker intended. In the first part of this week’s podcast, we sit down with Cory to talk about what he calls the coming “war on general purpose computing.”
    Threats in the City
    The City of Atlanta made news back in April when it was revealed that the city had expended some $2.5 million dollars to try to recover from a ransomware outbreak involving the SamSam ransomware program – far more than the $50,000 ransom that was initially demanded.
    But hopes for a recovery may have been premature. In early June it was revealed that the extent of damage from the outbreak and the cost of recovery were greater than first reported. One third of the city’s 424 necessary programs were knocked offline in the attack – 30 percent of them mission critical. The City Attorney’s office lost all but six of its 77 computers and 10 years’ worth of documents, while the police lost their dash cam recordings, the web site Engadget reported.
    54 min
  • Spotlight Podcast: Why North Korean Summit won’t End Hacking Threat
    In this Spotlight Podcast, Jon Condra, the Director of Asia Pacific Research at Flashpoint talks about why U.S. President Donald Trump’s summit with North Korean leader Kim Jong Un won’t put an end to North Korea’s online predation. That is just one conclusion in Flashpoint’s semi yearly Business Risk Intelligence Report. 

    Fresh off a buddy-buddy meeting with Kim Jong Un, the murderous leader of North Korea, the Trump Administration moved this week to abandon the UN Human Rights Council even as President Donald Trump launched withering online criticism of the government of German Chancellor Angela Merkel. These bizarre twists and turns are just the latest evidence that we are in unprecedented times. Longtime friends have become adversaries, if not enemies. Longtime enemies…we’ll, they’re our enemies, too.

    How did we get here? Central to the unsettling of the global order are the growing ranks of nation-backed hackers and their legions of fellow travelers including online influencers, trolls, conspiracy theories and rabble rousers. Online actions – including hacks and other influence operations – have moved to the forefront of nations’ arsenals, becoming one of the most reliable and surgical tools of geopolitical influence.
    [Sign up for News and Updates from The Security Ledger]
    These events beg the question of what lays ahead for world. How will the unsettling of the global order play out online? What impact will geopolitics – as expressed online – have on the countless businesses and organizations who do business on the Internet? That’s what the Flashpoint Business Risk Intelligence (BRI) Decisions Report tries to answer. The semi annual report takes the measure of nation-backed hacking as well as cybercriminals, hacktivists and other online threats.
    [See also: Spotlight Podcast: Is Russia rethinking its Cyber Offense?]
    In this special spotlight podcast, we dig into the latest BRI with Jon Condra, Flashpoint’s Director of Asia Pacific Research at Flashpoint. Jon said that the rapprochement with DPRK shouldn’t give people confidence that the online operations of these nations will cease, even if large scale attacks are less likely.
    For one thing, North Korea’s cash-strapped government expects different military units to support their own operations. In the case of the North’s cyber units, that has prompted a steady stream of attacks on crypto currency exchanges, particularly those operating out of South Korea, Condra said.
    Easing tensions with the South and the U.S. are unlikely to change that activity, even if they make large scale DPRK attacks on U.S. critical infrastructure less likely.
    You can listen to our full conversation, where Jon and I discuss Russia’s changing profile online and what we can expect ahead of the U.S. midterm elections in November.
    26 min
  • Episode 100: Estonia’s Former CIO talks about engineering a secure electronic vote
     
    In this week’s episode of The Security Ledger Podcast (#100 – woot!): Taavi Kotka spent 4 years as the Chief Information officer for the nation of Estonia – whose government is widely recognized as among the most technologically advanced in the world. He talks about the Estonian model for e-governance and how the U.S. has ruined the term “e-voting” for everyone. Also: what happens when discussions about the security of bits and bytes have consequences measured in flesh and blood? Joshua Corman, the Chief Security Officer at the firm PTC joins us to talk about it, ahead of his featured presentation at next week’s Security of Things Forum in Boston.

    Estonia’s former CIO: this is why we can’t have nice things
    DEFCON’s Voting Village has made an annual ritual of exposing the insecurity of electronic voting machines. But in Estonia, citizens have been voting electronically since 2005: easily, efficiently and without incident.
    And voting is just one of a long list of government services that are now provided to Estonians online. Pretty much everything – in fact – can be done electronically, except getting married and divorced, Kotka said.
    See also: FDA Medical Device Plan: a Baby Step in the Right Direction
    How? The country’s former CIO, Taavi Kotka said the secret is his country’s engineering-centric approach to tackling e-governance challenges including voting. Building from the foundation of a strong, unique government issued identity, Estonia has moved almost all government services online. In this wide ranging conversation, Taavi talks to me about his country’s ascendence to the vanguard of electronic governance and why he thinks privacy advocated in the U.S. who link electronic governance with privacy and security violations have it backwards.
    The goal in Estonia, Kotka told me, isn’t to simply move services to the Internet but, ideally, to have the provisioning of government services so seamless and integrated that, in effect, they disappear completely.
    Contrast that with the United States, he said, where conversations about voting technology and election integrity have become politicized and polarized, making it harder to work towards consensus and solutions. How bad is it? Katka’s countrymen don’t even use the word “electronic voting,” Kotka said. The U.S. and its travails with dodgy electronic voting machines has “spoiled” that term, he said. They call it “I voting” instead. Check out our full conversation!
    Bits and Bytes, Flesh and Blood with PTC Chief Security Officer Josh Corman
    The security of IT systems has long been an abstract problem for technologists steeped in the arcana of hardware, software and communications protocols. The specter of the city of Kiev darkened by cyber attacks against Ukraines electric grid, or of Hollywood presbyterian hospital in the US and National Health Services hospitals in the UK crippled by ransomware are proof that the consequences of cyber attacks – just like kinetic attacks – may now be measured in body counts.
    See also: DHS announces New Cybersecurity Strategy
    Joshua Corman, the chief security officer at PTC, has been raising the alarm about the rising stakes of cyber insecurity for years. Almost five years ago, he was among a handful of security experts who launched IAmTheCavalry, an effort to get the technology industry itself to take the point on improve the security of safety critical systems.
    59 min
  • Episode 99: Are we criminalizing reuse? An Exclusive Interview with Eric Lundgren
    In this week’s episode of The Security Ledger Podcast (#99), we bring you an exclusive interview with Eric Lundgren, the celebrated entrepreneur who has helped revolutionize the recycling of electronic waste through his company IT Asset Partners, but who will soon start serving a 13 month jail sentence for copyright infringement for distributing Microsoft Windows “restore CDs.” Together, we wonder if The Internet of Things is leading us into a future in which giant software companies and thing makers use copyright law and the courts to prosecute non-sanctioned use of their technology. 

    In a matter of two weeks, Eric Lundgren will be heading off to federal prison for a period of between 13 and 15 months. His crime? Selling -for a nominal fee- so-called “restore disks” containing versions of Microsoft’s Windows operating system to accompany PCs and laptops that he refurbished and restored. Never mind that the software he was selling on the CDs was available for free online, or from companies like Dell, which mailed them to customers at no cost. Never mind that without a valid license from Microsoft the software on the CDs was un-usable. Never mind that the only “customer” Lundgren sold his CDs to was a straw buyer operating on behalf of the U.S. government as part of a sting operation.
    Criminal copyright infringement isn’t a new thing. In fact, since the passage of the Digital Millennium Copyright Act in 1998. But Lundgren’s case is notable as perhaps the first of someone being sent to jail for distributing so-called “freeware” -software that companies give away at no cost.  Those externalities didn’t matter much in the Florida courtroom where Lundgren’s fate was in the hands of a U.S. prosecutor who indicated to him that Microsoft had asked for Lundgren’s “head on a platter.”
    “Companies profit off of waste,” Lundgren told me. “I thought I was providing this wonderful solution that was going to help everybody and I came to realize that I got in the way of a certain profitable agenda for another company.”
    [Also listen to: Episode 95: Copyright Insanity sends E-Waste Recycler to Prison and IoT Inspector finds Insecure Things]
    That company, of course, was Microsoft, which has a long history of working hand-in-hand with the U.S. Justice Department to pursue software pirates and other infringers of commercial copyrights.
    But Lundgren’s case doesn’t fit the mold of a piracy case. And the implications of Microsoft and the Department of Justice’s pursuit of him could be much more broad. It has, for example, implications for the growing Internet of Things. As companies such as Microsoft, Apple, Samsung, Google and others use software licenses and digital rights management to exert control over more and more of our physical world, the specter of Lundgren carted off to prison in shackles could be a kind of canary in the coal mine: an early glimpse of dystopian future that may await us in which corporations use muscular copyright laws and sympathetic prosecutors and courts to punish what they consider commercially unacceptable or unauthorized use of their intellectual property. As software and copyrighted intellectual property come to control our vehicles, our homes, cities and even our bodies, the criminalization of pro-social activities like resale, recycling or repair could have a stifling effect on all of our lives.
    As Eric prepares to serve his time in Federal prison,
    28 min
  • Episode 98: using Physics to crash hard drives and making sense of IoT standards
    In this episode of The Security Ledger Podcast (#98): can sound waves be used to crash a hard drive? We’ll talk to one member of an international team of researchers who showed that, yes they can. And Fractional CISO Rob Black joins us to talk about Internet of Things security standards. With so many to choose from, will we ever see “one standard to rule them all”?

    Bad vibrations: sonic attacks could crash hard drives
    In the information security space, most of the ‘bad stuff’ we talk- and write about concerns attacks on software. SQL injection, buffer overflows, cross site scripting attacks – all seek to subvert the proper operation of software and applications.
    But what about the hardware that software runs on top of? Isn’t that also vulnerable? We know, of course, about flaws buried in processor chips like the Meltdown and Spectre bugs as well as newer variants of those flaws. But what if you go even deeper – not just at the brain of a system but the physical properties of hardware that allows the machine to operate.
    That’s what researcher Kevin Fu has been up to with his graduate students at the University of Michigan: examining what he calls “physics based hacks” that seek to manipulate the operation of an IT system by leveraging the physical properties of the device itself.
    His lab’s latest work, conducted with researchers from Zhejian University in China, involves ultrasonic and sonic attacks on magnetic hard disk drives. Fu and his team found that they could cause the drives to malfunction and crash using nothing more than commodity, $20 speakers and targeted sonic and ultrasonic blasts.
    [See also: Report: Major attack on critical infrastructure expected due to increased risk from IoT]
    In our first segment, I spoke with Connor Bolton, a graduate student who was part of the University of Michigan team about that research and what the implications are for companies with sensitive IT systems and operations.
    One IoT standard to rule them all?
    Our fifth Security of Things Forum is happening in less than a month. (June 19 in Boston – get your tickets now!) At this year’s show in Boston, we’ll be looking hard at the fast evolving but crowded field of Internet of Things security standards. Among the fundamental questions we want to answer: what commonalities exist between these many competing standards, whether its practical to have one to govern the security of connected devices and – if so- what that standard might look like.
    To help sort through that issue, I invited the moderator of our June panel, Rob Black into the studio. A principal at Fractional CISO, Rob is an expert on all things security and IoT. In this conversation, Rob talks about the IoT standards that are most promising and gives his vision of a successful security standard for connected devices. Rob says that the IoT may be too broad to ever be governed by a single security standard.
    That said: the need for functioning standards is greater now than ever before, especially as software driven systems come to govern life and safety critical machinery.
    Check out our conversation!
    32 min