Download on the App Store

episodes

  • Episode 97: On eve of GDPR frightening lack of data privacy, security in US
    In this episode, #97: we talk with Robert Xiao, the Carnegie Mellon researcher who investigated Location Smart, a free web application that allowed anyone track the location of a mobile phone using just the phone’s number. Also: we welcome University of Washington Researcher Kate Starbird back into the SL studio to talk about her latest research: examining the web of bloggers, news web sites, conspiracy theorists and government actors targeting human rights workers in Syria.


    Data security in the US is so bad, it is scaring the researchers
    The end times are upon us. This Friday, May 25th marks the go-live date for the European Union’s General Data Privacy Rule or GDPR. Like a train slowly moving down the track, GDPR’s arrival has been anticipated for months – if not years. (Check out our prior GDPR reporting here.) Still, only a minority of firms say they are prepared to meet the regulation’s stringent requirements to protect the data of EU citizens.
    That’s especially true in the US, where de-regulatory fervor and the lack of a comprehensive, national data privacy law have left consumers and the public at the mercy of ham-fisted data brokers. For proof of that, look no further than the latest data privacy dust up, this linked to the actions of Location Smart, a third party location tracking firm.
    [See also: Report: EU may slap new GDPR Fines on Old Data Breaches]
    In stories last week by Krebs on Security, ZDNet, the New York Times and others  it was revealed that telecommunications firms, working with third party data brokers and mobile phone tracking services like Location Smart make the location of millions of US mobile phones (and thus their owners) available to anyone with the ability to pay for the service. In fact, in the case of Location Smart, that capability was available to anyone, regardless of their ability to pay thanks to a vulnerable web based application intended to demonstrate Location Smart’s abilities for would-be customers.
    Behind it all is a culture of data security and data privacy that has grown so lax that even the security researcher who discovered the Location Smart flaw said he found the whole situation scary and unnerving. I our first segment, we speak with that researcher: Robert Xiao, a graduate student at Carnegie Mellon about his work analyzing the Location Smart web application and the bigger issues facing US consumers.
    False narratives haunt both heroes and victims
    Another week, another deadly school shooting in the United States. This time, death and destruction were visited on the unsuspecting students at Santa Fe High School in Texas. But even as news anchors, parents and students tried to process their shock and horror over the carnage,  a quieter campaign was afoot online to deny the essential truth of the shooting.
    In the hours after the teen-aged shooter was apprehended, unidentified actors sprang into action on Twitter and Facebook, twisting the facts of the event to serve larger narratives and even questioning whether the shooting itself was real.
    44 min
  • Episode 96: State Elections Officials on Front Line against Russian Hackers
    In this episode of The Security Ledger Podcast (#96): with primary elections taking place in states across the United States in the coming weeks, we talk to John Dickson about how state elections offices have become the front line in a pitched battle with state-sponsored hackers – with the fate of a 240 year democracy hanging in the balance. Also: we talk about the looming threat posed by so-called “deep fake” videos that use computer manipulation to make famous celebrities appear to say nearly anything.

    The Russians are Voting! The Russians are Voting!
    Knox County Tennessee might not be on anyone’s map of election day “hot spots” where the fate of Congress will be decided. But the County may be a harbinger of things to come. On the evening of Tuesday, May 1, as polls were closing and results were beginning to roll in from that day’s primary election, a distributed denial of service (or DDoS) attack took out the web site used to display election results for the County.According to reports, the page was down for about an hour starting around 8 p.m. local time before officials were able to restore it, according to the county’s Election Commission.
    The primary season has been uneventful so far. But votes in November will determine control of the US House and Senate, governorships and the control of state legislators. There is deep concern that a repeat of the 2016 presidential election is on tap, when disinformation campaigns and other actions by groups affiliated with the government of Russia are believed to have played a part.
    In this week’s podcast we speak with John Dickson, a principal at The Denim Group, who has been interviewing and advising state and local election officials. Dickson believes that the November midterm elections are likely to be a “warm up act” for the real show: the 2020 Presidential contest. Even so, November 2018 will hardly be a fair fight.
    [See also: Autonomous vehicles could save more lives than they take. That might not matter.]
    “It’s a force mismatch,” said Dickson. “It is a fair fight between the Russian government and the US Military, US government and the agencies of the government – nation state to nation state. It is a force mismatch when you have the Russian state going after the secretary of state of North Dakota.”
    [You might also like: Podcast Episode 90: WannaCry zombie haunts Boeing, UL tests for cyber security and Harvard war games election hacking]
    The consequences couldn’t be higher. Dickson notes that there are 9,000 entities who administer elections in some form or fashion in the U.S., but malicious actors who are interested in tipping the results of a vote one way or the other may only need to influence a small number of precincts. That puts local election officials and administrators on the front lines of a cyber war between Russia and the US. In our conversation, Dickson talks about why 2018 won’t play out like 2016, what kinds of attacks the secretaries of state are likely to face and what state officials should be doing to prepare.
    42 min
  • Episode 95: Copyright Insanity sends E-Waste Recycler to Prison and IoT Inspector finds Insecure Things
    In this episode of The Security Ledger podcast (#95): has the Digital Millennium Copyright Act taken us over a bridge too far? We talk with two experts about the case of Eric Lundgren, a celebrated e-waste recycler who has been sentenced to 15 months in prison and fined $50,000 for DMCA violations. Also: we speak with one of the Ivy League students who designed IoT Inspector, software that can analyze your home network for vulnerable devices.

    Is Eric Lundgren’s Case the Bridge Too Far for the DMCA?
    When celebrated electronics recycler Eric Lundgren was sentenced to 15 months in prison and fined $50,000 last month for distributing Microsoft Windows “restore disks” to extend the lives of recycled computers, the most common reaction in the mainstream media was “how could this happen?”
    “All too easily,” has been the answer of digital rights- and legal activists. Indeed, the ruling by The U.S. Court of Appeals for the 11th Circuit was just the latest skirmish in a decades long battle over the extent and intent of the 1998 Digital Millennium Copyright Act. Those nearly two decades have seen a steady erosion of consumer rights and a tendency towards harsher and more punitive enforcement of copyright laws.
    A landmark piece of legislation, the DMCA was written to protect movies, video games and other intellectual property from piracy by criminalizing the production and dissemination of technology, devices, or services intended to circumvent measures that control access to copyrighted works. It also criminalized the act of circumventing any access control used to secure copyrighted material – the (in)famous Section 1201 – requiring petitioners to ask the government for waivers to conduct security- or academic research or explore fair use of electronic devices.
    But, as Lundgren’s case shows nearly 20 years after the DMCA was signed into law, it is not only being used to secure copyrighted material from piracy but also to proscribe use of products in ways that benefit the manufacturers’ bottom lines. Increasingly, copyright protection tools – so called “digital rights management – is being used to lock out third party service providers, repair technicians and even the devices rightful owners from simple acts like replacing broken parts or installing software or hardware of their choosing.
    In that light, Lundgren’s case marks just the latest battle on the DMCA’s ever expanding front. But could it also mark a turning point? In the first segment of our podcast, we invited two experts into the studio to discuss the U.S. Government’s case against Mrl Lundgren and where things go from here:
    Jennifer Granick (@Granick) is a surveillance and cybersecurity counsel with the ACLU’s Speech, Privacy and Technology Project and the author of the book American Spies: Modern Surveillance, Why You Should Care, and What To Do About It. And Kyle Wiens (@kwiens) is the founder of iFixit.com , the free repair manual and an outspoken advocate of the right to repair.
    In our interview, we talk about the Lundgren and his passion for electronic waste reuse and recycling, the long and complicated partnership between Microsoft and the US Department of Justice in pursuing DMCA violations and how it is that distributing software images that Microsoft gives away for free amounted to $700,
    35 min
  • Spotlight: Deepika Chauhan of Digicert on the Challenges of Securing the Internet of Things
    There’s an epidemic of insecure Internet of Things devices. But why? And what is the shortest path to ending that epidemic? In this Spotlight Edition* of The Security Ledger Podcast, we speak with Deepika Chauhan, the Executive Vice President of Emerging Markets at DigiCert. Her job: forging new paths for the use of public key encryption to secure Internet of Things ecosystems.
    The Internet of Things is poised for massive growth in the years ahead, as billions of new, connected devices come online including physical infrastructure, medical devices, connected vehicles and – of course – consumer goods like home appliances and wearable tech.
    Concerns about security and privacy threaten to undermine that growth, however, with polls of consumers and the public revealing deep reservations about the security and trustworthiness of connected devices.
    Deepika Chauhan knows all about those challenges – and the possible solutions to them. She is the Executive Vice President of Emerging Markets at the firm DigiCert, where she leads that company’s initiatives and strategy in adapting PKI to the Internet of Things market and driving Digicert’s overall strategy.
    [Check out: Black Box Device Research reveals Pitiful State of Internet of Things Security]
    Security Ledger had the chance to sit down for an interview with Deepika on the sidelines of the recent RSA Conference in San Francisco. In this spotlight podcast, we’re bringing you that interview. In it, Deepika talks about the unique security challenges of the IoT presents and the factors and habits that are contributing to epidemic IoT insecurity.
    At the most basic level, she notes, connected device makers often lack an interest in security as a feature of their products and focus more on functionality and time to market.
    In this podcast, we also talk about Deepika’s path to the software engineering field growing up in India, the information security industry, her experience as a female engineer in the male dominated techn industry and the important role of mentors in fostering professional success and the security industry’s struggles with diversity.
    Check out our full conversation above!
    (*) Spotlight podcasts are custom recordings that are offered as a premium service by The Security Ledger. To schedule a Spotlight podcast for your firm, please use the contact page to send an inquiry. 
    26 min
  • Podcast Episode 94: Black Report takes Hacker View and Securing the Open Source Supply Chain
    In this episode of the Security Ledger Podcast we do a deep dive into the recent Black Report by NUIX – which flips the script by asking hackers and pen testers their opinions about how they hack firms and what defensive strategies and technologies work best at stopping them. Also: Rami Sass the CEO and co-founder of this week’s sponsor, WhiteSource Software, joins us in the Security Ledger studios to talk about how a white knuckle audit of his company’s open source dependencies eight years ago prompted him to start WhiteSource, which makes a tool for managing the open source software supply chains. 

    The Black Report: Hacker Eye on the Security Admin Guy
    The information security industry is full of surveys and trend reports that mull over cyber crime data and reports from the victims of hacks and other security incidents. Documents like the Verizon Data Breach Investigations Report tell us all we want to know about what industries are most affected by malicious actors, what kind of attacks they launch and what types of IT assets they’re most interested in hacking.
    But how useful are victim reports in actually thwarting cyber crime? “not very” according to our first guest, Chris Pogue of the firm NUIX. His company recently released its Black Report, a survey of hundreds of penetration testers and other white, gray and black hat hackers. The report assesses the kinds of attacks that cyber attackers themselves use, what types of security approaches and tools they find effective and their feelings about the state of security.
    Pogue said that the survey of hundreds of professionals who do security offense revealed that few thought much of venerable defensive tools like firewalls and anti virus software. The best security investment, according to the report, wasn’t even a security product. It was basic endpoint hardening: essentially – doing a better job deploying the software you’ve already purchased by taking advantage of security features that are already in the product and not making dumb mistakes when you roll it out.
    Check out our full conversation in the first part of this month’s podcast.
    GitHub’s Revenge: managing the open source software supply chain
    There’s a saying that modern software is no longer written so much as it is composed. And, indeed, most modern, agile software applications aren’t made from whole cloth. Rather, they’re expertly knitted together with bits of new, proprietary code and lots of pre-packaged third party and open source components that have been written by others – often years ago.
    The ease with which new applications can be assembled from these pre-written components is a huge win: drastically shortening the time it takes to develop and launch a new software tool. But, as often happens, that convenience comes at a cost: security vulnerabilities that may lurk undiscovered even in widely used open source libraries. (Consider the Heartbleed vulnerability, for example.)
    [This episode of The Security Ledger podcast is sponsored by WhiteSource Software. ]
    Those third party and open source dependencies are increasingly a cause for concern. The hack of Equifax, for example, was traced back to an attack on a known flaw in Apache Struts, a widely used open source package. Rami Sass, the CEO and co-founder of the firm Whitesource Software, told us that open source dependency is an issue that he’s intimately familiar with. In fact, the origins of Whitesource lay in a white knuckle audit he and his co-founders had to do prior to selli...
    36 min
  • Spotlight: Philippe Courtot, CEO of Qualys: We Need to Change How We Do Security
    In this Spotlight Podcast*, Philippe Courtot of the firm Qualys discusses being an early innovator in the software as a service space and how the market for cloud based security services has evolved since he launched his firm, Qualys, almost two decades ago. 

    If you walked the trade show floor at last week’s RSA Conference as I did, it is easy to forget that cloud-based security used to be considered so far out as to occupy the realm of science fiction. As recently as 10 years ago, many otherwise sophisticated firms were of the opinion that, no matter the benefits the cloud bestowed on= other business functions, security was a bridge too far.
    Philippe Courtot saw things differently. Just months after Mark Benioff stood up his hosted customer relationship management (CRM) platform, Salesforce.com, Courtot launched his firm Qualys, which took what was at that time relatively new security function – software vulnerability management – and ported it to the cloud.
    [Also listen to: Podcast Episode 93: Talking GDPR with Cisco’s Chief Privacy Officer and RSA 2018 Recap]
    No good deed goes unpunished. Well ahead of the SAAS (or “software as a service”) market, let alone the security software as a service market, Courtot would spend the next 10 years evangelizing not just for his company, but for the grander notion that companies of all sizes would be better off swapping out their expensive and hard to manage physical IT assets for managed cloud services.
    His evangelism involved creating not one but two industry groups: the Cloud Security Alliance, to promote cloud based security and a group called the CISO Interchange to help evangelize the notion that vulnerability management was a critical security function, not a nice to have.
    It wasn’t easy.
    “I was not well received. I felt like Galileo trying to convince the church that it was the Earth that revolved around the Sun and not the other way around,” he told me. “Thank God, though, that we live in America and I did not have to abjure and I was not put in house arrest for the rest of my life!”
    Security as a service took a long while to gain adoption – perhaps longer than Courtot had bargained for.

    “It took much longer than I thought,” he told me. Still, history has proven the CEO right. Vulnerability management is a sanctioned and – in fact – mandated security function. Cloud security is front and center as organizations of all sizes migrate critical functions to reliable, managed cloud services like Amazon Web Services and Microsoft Azure. Qualys is a publicly traded company with a $3 billion market capitalization.
    Courtot said that the kind of security tools companies use will need to rely more on automation and centralization, akin to how the home security market has come to rely more on remote sensing, cloud and automation. “Look at the way we secure our homes: we have sensors that manage our home and our home security. They can notify the cops or the fire marshal. (Enterprise) security will have to be that way,” he said.
    I caught up with Philippe at the RSA Conference to record this special spotlight podcast. In it, we talk about Qualys founding and growth, the tremendous changes in the security industry in the last 15 years and about his latest initiative: the CIO/CISO Interchange, which is about educating C-level executives about how to enable digital transformation...
    25 min
  • Podcast Episode 93: Talking GDPR with Cisco’s Chief Privacy Officer and RSA 2018 Recap
    This episode of The Security Ledger Podcast (#93) was sponsored by Keysight Technologies, a leading technology company that helps enterprises, service providers, and governments accelerate innovation to connect and secure the world. Check them out at Keysight.com.
    In this episode: with the May 25th go-live date of the EU General Data Privacy Regulation (GDPR) just around the corner, we talk with Cisco Chief Privacy Officer Michelle Dennedy about her expectations for the May 25th deadline and what lies beyond it. Also: with the 2018 RSA Conference now in the history books, we invited Steve McGregory, the Senior Director of Application and Threat Intelligence at Ixia in to talk about his big takeaways from the show. Steve also weighs in on one of the big trends this year: machine learning. 

    GDPR’s New Era: a Conversation with Cisco’s Chief Privacy Officer
    In a little more than a month the EU’s General Data Privacy Regulation – or GDPR – will take effect. Ahead of that much anticipated event, companies of all stripes are updating their privacy policies and their internal controls to secure customer and employee data.
    Among other big changes that GDPR will prompt is giving a much higher profile to the Chief Privacy Officer, a previously obscure role, mostly limited to very large firms, that is poised to become much more common and widespread.
    To understand a bit more about the work of Chief Privacy Officers and about the other likely effects of GDPR on the way companies operate, we met up with Michelle Dennedy, the Chief Privacy Officer at Cisco Systems on the sidelines of the RSA Conference last week. In a wide ranging interview, Michelle talked about how the new EU regulations will change our business culture. GDPR, she said, marks the beginning of a new era in which “data is looked at with the same level of scrutiny and care and risk as anti trust violations and food safety.”
    I started our conversation by asking Michelle what’s on her to-do list and how she’s getting ready for GDPR. Check out our full talk in this week’s podcast.
    RSA 2018 recap: making sense of the trends
    The 2018 RSA Conference took place last week in San Francisco. Security Ledger was at the show and we were busy.
    As the information security industry’s biggest conference, RSA is always a reliable bellwether for what’s hot and happening in cyber security. But while “cyber” is a word that’s on everyone’s tongue right now, the message out of the RSA show was, to use the words of our special guest this week “murky.” Steve McGregory is the Senior Director of Application and Threat Intelligence at Ixia, a division of Keysight. He presented at last week’s RSA Conference in a session entitled “Network Visibility and AI: You’re Our Only Hope!”
    We invited Steve in to our studio to talk about his impressions of the show and to weigh in on one of the big trends this year: machine learning and artificial intelligence. Despite the hype, Steve argues that an absence of quality network data may be limiting the usefulness of machine learning to aid in security incident response.
    Check out our full conversation on this week’s podcast.
    34 min
  • Podcast Episode 92: Uncle Sam Ices Tech Acquisitions and RSA Conference 2018
    In this episode of The Security Ledger Podcast (#92): Adam Isles of The Chertoff Group joins us to talk about the growing specter of software supply chain risk the recent trend of the US Government shooting down major tech acquisitions by Chinese firms.  Also: with the RSA Conference * kicking off in San Francisco, we hear from two experts from LookingGlass, this week’s podcast sponsor, about how to make sense of the hot threat intelligence space. 

    Uncle Sam is icing Tech M&A. Why?
    What do firms like chip testing firm XCERRA, in flight wi-fi provider Global Eagle and money transfer firm MoneyGram have in common? They’ve all had acquisitions by willing foreign firms blocked by the US Treasury Department’s Committee on Foreign Investment in the US (CFIUS) in recent months.
    What’s going on? In our first segment this week, we speak with Adam Isles, a principal at The Chertoff Group, which has highlighted the increasing risk posed by third party software and supply chain partners as a trend to watch in 2018.
    [Check out: Podcast Episode 88: Inside Russia’s DragonFly Group and How Cyber Crooks Launder Money]
    Isles says that the increased scrutiny of mergers and acquisitions is  just one manifestation of the broadening understanding and scope of cyber risk. We also talk about another of the Chertoff Group’s prognostications for 2018: increased attacks on The Internet of Things.
    RSA 2018: Understanding Threat Intelligence
    As attendees gather at The RSA Conference in San Francisco, they’re being barraged with marketing pitches of all stripes. One of the most persistent is about the need for organizations to make use of cyber threat intelligence. That sounds good: but what does it mean exactly? And what are the different ways that threat intelligence can be applied to real world threats? Is there a hierarchy of threat intelligence and if so, what is it? How exactly does one tell useful threat intelligence from expensive digital clutter?
    This week’s podcast sponsor, Looking Glass, thinks they can answer those questions. We sat down with two LG experts in the Security Ledger studio: James Carnall, VP of Customer Support at the firm Looking Glass Cyber and Eric Olson, SVP of Product to talk about the evolving threat intelligence space, how threat intelligence is best put to use in combatting sophisticated threats and how to make sense of the cacophony of pitches and solicitations from the countless threat intelligence vendors.
    To start out with, I asked James and Eric to tell us a little about LookingGlass’s platform and what it does.
    (*) Disclosure: Security Ledger’s coverage of RSA Conference is sponsored by the following organizations: RSA Security (a division of Dell), LookingGlass Cyber Solutions, Qualys Inc., Pulse Secure Inc., DigiCert Inc., and Keysite Technologies. For more information on how Security Ledger works with its sponsors and sponsored content on Security Ledger, check out our About Security Ledger page on sponsorships and sponsor relations.
    32 min
  • Podcast Episode 91: Fighting Fake News with or without Facebook and whats with all the Cryptojacking?
    In this episode of The Security Ledger Podcast (#91): with Facebook CEO Mark Zuckerberg saying he will testify before Congress, we ask Harvard’s Matthew Baum about what Congressmen and women should ask him and how to best fight fake news. Also: Adam Kujawa of Malwarebytes updates us on that company’s latest quarterly threat report and helps us answer the question “what’s with all the cryptomining”?

    Shadowboxing fake news
    Facebook CEO Mark Zuckerberg has promised to testify before the US Congress in the wake of serial revelations about his company’s ties to shady data analytics operations that helped foment social unrest and political tension around both the Brexit vote and the US Presidential election. It is now believed that more than 80 million Facebook users may have had their data exposed to Cambridge Analytica and its many clients.
    Ahead of Zuckerberg’s (presumed) testimony, however, there has been lots of attention to the question of what Congressmen and Congresswomen should ask Mr. Zuckerberg about his company’s role in spreading disinformation. But our next guest, Professor Matthew Baum of Harvar’d Kennedy School, argues that one of the big problems we have right now is a lack of understanding about how big a problem fake news is.
    Baum was a co-author of a paper, recently published in the magazine Science. He notes that we don’t, for instance, know how many human beings actually encountered fake news stories and how they shared it and who they shared it with. One of the biggest challenges, therefore, is to find a way to work with social media companies to get access to data that will help us to understand the scope of the fake news epidemic.
    There are reasons to suspect that fake news limited effectiveness in convincing people to believe false information. Likewise, there is reason to suspect that anti-fake news strategies like the (now) ubiquitous ‘fact checking’ exercises carried out by mainstream publications are also of limited utility in “educating” readers who may not put much value over truth vs. non-truth.
    In our first segment, I speak with Baum about his research, about what we do know about fake news and get his thoughts on some strategies for combatting it.
    What’s with all the cryptomining?
    When the folks at Malwarebytes were putting together their latest quarterly threat report  (out today), one trend stuck out: cryptomining. In fact, the shift within the cyber underground from schemes like ransomware and banking trojans to crypto mining and the less savory cryptojacking (basically: hijacking your phone or PC to do cryptomining) has surprised even hardened security researchers like our guest, Adam Kujawa the Director of Malware Intelligence at Malwarebytes.
    In our final segment this week, Adam and I talk about the latest Malwarebytes threat report and the sharp turn towards cryptojacking scams that it documents. We talk about what may be driving cryptojacking and cryptomining activities. Is it (as I like to think) a preference for cleaner, “victimless” scams? Or, as Adam theorizes, that it is just cyber criminals finding the path of maximum profit and minimum resistance.
    Check out our whole conversation in this week’s SL Podcast!
    25 min
  • Spotlight November 2017 - DevOps Secrets with CyberArk
    In this Spotlight Edition of Security Ledger podcast, we speak with Elizabeth Lawler, the founder of Conjur Inc. and now Vice President of DevOps security at the firm CyberArk. While companies scramble to secure privileged user accounts from threats like “credential stuffing,” Elizabeth’s contention is that they often overlook the most powerful privileged user on their networks: the application code churned out by agile development teams and then circulated to customers and - often -the public
    25 min