Download on the App Store

episodes

  • Episode 250: Window Snyder of Thistle on Making IoT Security Easy

    In this episode of the podcast, I speak with Window Snyder (@window), the founder and CEO of Thistle Technologies about the (many) security challenges facing Internet of Things (IoT) devices and her idea for making things better: Thistle’s platform for secure development and deployment of IoT devices.



    [Video Podcast] | [MP3] | [Transcript]







    The growth of the Internet of Things is one of the most significant developments in information technology over the last two decades. During that time our homes, workplaces and public spaces have become populated with a wide range of smart, software driven, and Internet connected devices ranging from printers to cameras and home appliances. 






    It’s no surprise that cyber threats and attacks followed. A recent report from Cisco found that the growth of the internet of things (IoT) and connected devices was the biggest contributing factors to organizations’ expanding attack surfaces. 



    The Future of IoT Security Standards



    IoT security: old-school in the worst way



    Part of the reason that IoT insecurity is such a big problem is that device makers and the development organizations that serve them have struggled to learn the lessons of the last 30 years. Embedded software running smart devices in everything from homes and businesses to critical infrastructure repeat many of the same mistakes – from buffer overflows and SQL injection to weak authentication schemes – that characterized earlier generations of software and services. 



    Episode 241: If Its Smart, Its Vulnerable a Conversation with Mikko Hyppönen



    Given how widespread the issues are with device security, how can we possibly hope to fix this urgent problem? Our guest on this week’s podcast thinks she has a solution. Rather than wagging a finger at IoT device makers (tempting though that is), why not provide them with the tools, technology and support to make developing secure, embedded devices easier? 



    Making IoT security easier



    Window Snyder is the CEO and founder of Thistle Technologies, a start-up seeking to help secure Internet of Things devices. In February, Thistle announced the launch of the Thistle Security Platform, a set of tools and services that bring software updates and other security functionality to the world of embedded devices. While there is no “silver bullet” to securing the IoT, Window argues, giving development organizations the tools and support they need to make smart security decisions about things like usin...
    32 min
  • Spotlight: Traceable CSO Richard Bird on Securing the API Economy

    In this Spotlight episode of the Security Ledger podcast, I interview Richard Bird, the CSO of the firm Traceable AI about the challenge of securing application programming interfaces (APIs), which are increasingly being abused to steal sensitive data.



    [MP3] [Transcript]







    The term “API economy” has been given to the emergence of business models and business practices designed and built around the use of APIs – or Application Programming Interfaces. APIs, today, are everywhere – they’re the foundation of digital transformation initiatives: allowing organizations  exchange of data and instructions seamlessly between  applications – many hosted in cloud environments. 



    APIs abused in cyber attacks



    But APIs can also facilitate cyber attacks and the theft of data. In 2022, insecure and leaky APIs were the common theme behind a number of major cyber incidents, including the leak of data on more than 5 million Twitter account holders as well as other incidents. While development organizations and the downstream consumers of APIs have enabled rapid development of new applications and capabilities – security, h however, has lagged. 






    What is the fix for API security issues? According to our guest today: organizations need to recognize the ability of APIs to be used and abused. Richard Bird is the Chief Security Officer at Traceable.ai., a company that specializes in API security. Traceable’s technology enables organizations to identify and monitor the internal and external APIs in use in their environment and grasp the API risk posture as well as “application context” – the complex interactions of APIs, users, data, and code.



    In this conversation, Richard and I talk about the challenges of securing API ecosystems within organizations. The key, Bird said, is for organizations to understand the security risks that APIs pose and take steps to both monitor and constrain their use. 



    Transcript



    Richard Bird (Traceable): I’m the Chief Security Officer for Traceable. I always like to say that I’m in my Benjamin Button phase of my career. I’m aging backwards. I spent 20 plus years in the corporate world. And about 16 or 17 of those were in banking, financial services, hedge fund administration, all in technology.



    Before I ever got into the solutions side of the business, I had already been a chief information officer and a Chief Information Security officer as I did two tracks in my own corporate career. And I made the decision that I wanted to try and help more than jus...
    40 min
  • Episode 249: Intel Federal CTO Steve Orrin on the CHIPS Act and Supply Chain Security

    In this episode of the Security Ledger Podcast, Paul speaks with Steve Orrin, the Federal CTO at Intel Corp. Steve talks about his work representing Intel and its technologies to the Federal Government and the impact of the recent passage of the CHIPS Act, a huge federal investment in promoting domestic manufacturing of semiconductors. We also talk about the growing focus within the federal space on software supply chain security and how firms like Intel are responding to calls for greater scrutiny of federal software and services.



    [MP3] [Transcript]







    In August 2022, President Biden signed into law the CHIPS and Science Act, one of the biggest federal investments in science and research and development in recent memory. The bill includes a 52.7 billion appropriation over five years to fund grants, loans, loan guarantees, and other programs to incentivize semiconductor manufacturing in the United States, “tax credits to spur the construction of semiconductor fabrication plants in the US and it limits the ability of chip makers to expand operations in China. 



    Episode 214: Darkside Down: What The Colonial Attack Means For The Future of Ransomware



    The CHIPS Act: a game changer



    Steve Orrin is the Federal CTO and a Senior Principal Engineer for Intel Corporation.


    CHIPS is expected to spur investment in the U.S. semiconductor industry, which has long taken a back seat to countries like Taiwan, where most of the world’s advanced semiconductors are manufactured. It’s a boon for companies like Intel, the United States most recognized semiconductor manufacturer. But what about the larger supply chain issues affecting U.S industry and the U.S. government? Including software supply chain? How are the CHIPS Act and other federal initiatives, like President Biden’s cyber Executive Order, changing the way that the federal government is looking at and procuring software, hardware and services from its own suppliers? 



    To help answer these questions we invited Steve Orrin into the studio to talk. Steve is the  Federal CTO and Senior Principal Engineer for Intel Corporation, a job that has him representing all of Intel’s technologies and capabilities to the federal government and the broader public sector.



    New IoT Security Regulations on Tap in U.S., U.K.



    In this conversation, Steve and I talk about Intel’s extensive work as a supplier of software, hardware and services to Uncle Sam, and about some of the initiatives Intel is working on – from confidential computing, to supply chain security and artificial intelligence.







    Transcript



    Steve Orrin (Intel): So I am Steve Orrin. I’m the Federal CTO and Senior Principal Engineer for Intel Corporation. And in that role, I basically represent all of Intel’s technologies and capabilities to the federal government and the broader public sector ecosystem. So that civilian military intelligence, the large system integrators, the federal OEMs and cloud providers really help them to figure out how to adopt and ...
    37 min
  • Spotlight: Making the Most of Cyber Threat Intelligence with Itsik Kesler of KELA

    In this Spotlight episode of the Security Ledger podcast, I interview Itsik Kesler, the CTO of the threat intelligence firm Kela about the evolution of threat intelligence and findings from the company’s latest State of Cybercrime Threat Intelligence report.



    [MP3] | [Transcript]







    In the last decade, so-called “cybercrime threat intelligence” has gone from being the specialty of three letter intelligence agencies to a standard part of many enterprise security portfolios. With threats online proliferating and with a thriving cybercriminal underground, organizations that care about security need an ear to the ground in cybercriminal forums and dark markets, where stolen data, access credentials and more are traded.



    Itsik Kesler, CTO of KELA


    Properly integrated into a cyber response program, cybercrime threat intelligence can give firms early warning about security breaches and alert them to the theft of sensitive data or the compromise of an employee account. It can even tip off firms about attacks that are still in the planning stage – not simply narrowing the “window of compromise” but slamming it shut.



    Connecting The Dots: The Kremlin’s Links to Cyber Crime



    Despite that, operationalizing the kinds of information that cybercrime threat intelligence firms provide is easier said than done, as a recent survey by the firm KELA shows. That company’s State of Cybercrime Threat Intelligence Report for 2022 surveyed 400 IT pros and revealed ongoing concerns about the risk of corporate information turning up on cybercrime forums, but also concerns about visibility into that risk, and a lack of clear policies within organizations to handle cybercrime threat intelligence. 



    What’s the Future of Detection Teams? Five Predictions for What Lies Ahead 



    In this Spotlight podcast, I speak with Itsik Kesler, the CTO of Kayla about the new report and about the challenges organizations face as they look to leverage cybercrime threat intelligence as part of their security operations.



    Transcript



    Itsik Kesler (Kela): I’m Itsik and I’m the CTO at Kela



    Paul Roberts (Security Ledger): itsik, welcome to the Security Ledger podcast.



    Itsik Kesler (Kela): Thank you Paul. Great to be here. Thanks for having me.



    Paul Roberts (Security Ledger): Okay. So for our listeners who are not familiar with Kela, tell us a little bit about your company, where your C T O and what Kela does.



    Itsik Kesler (Kela): Sure. So Kela is a threat intelligence company focused on providing actionable intelligence. We specialize in this cyber grime on the ground. with the goal of digital crime. To support it. We have to know,
    31 min
  • Episode 248: GitHub’s Jill Moné-Corallo on Product Security And Supply Chain Threats

    In this episode of the Security Ledger Podcast, Paul speaks with Jill Moné-Corallo, the Director of Product Security Engineering Response at GitHub. Jill talks about her journey from a college stint working at Apple’s Genius bar, to the information security space – first at product security at Apple and now at GitHub, a massive development platform that is increasingly in the crosshairs of sophisticated cyber criminals and nation-state actors.



    [MP3] [Transcript]







    Innovation in the cybersecurity industry often starts with the bad guys. Hard as it is to admit, information security firms are often playing catch up with cyber criminals and nation state actors: adjusting their tools and methods to respond to changes in attacks and compromises. 



    We’re seeing that dynamic play out these days in the increasing attention and urgency around attacks on software supply chains, as malicious actors have realized that they can bypass network defenses by insinuating themselves into the software and services that target organizations rely on. 



    Want To Prevent Another SolarWinds? Start With Developers



    Growing threats to open source platforms



    Attacks on open source projects and platforms are part of that trend. Malicious actors are increasingly targeting development platforms — planting malicious modules on platforms like Github, NPM and PyPi that imitate popular and then waiting for unsuspecting developers to download and integrate their malicious code with legitimate applications. Recent months have seen large scale attacks involving scores ore even hundreds of malicious modules designed to steal data or provide remote access to environments on which the tainted applications are deployed. 



    Jill Moné-Corallo, Director of Product Security Engineering Response at GitHub was our guest.



    But the shift left has also put open source platforms in the cross hairs of attackers, as they look for ways to leverage weaknesses to facilitate attacks or avoid detection. As we go to print, for example, the development tool CircleCI urged developers to change “any and all” secrets stored on their system after a compromise that may have resulted in the theft of developer secrets stored in environment variables or in contexts.



    Episode 216: Signed, Sealed and Delivered: The Future of Supply Chain Security



    Organizing chaos



    With attacks like that on the increase, how are the platforms responding? In this episode we speak with someone who knows: Jill Moné Corrallo, the Director of Product Security Engineering Response at GitHub – a position that gives her responsibility for GitHub’s product security incident response and bug bounty teams. 



    26 min
  • Episode 247: Into the AppSec Trenches with Robinhood CSO Caleb Sima

    In this episode of the Security Ledger Podcast, Paul speaks with Caleb Sima, the CSO of the online trading platform Robinhood, about his journey from teenage cybersecurity phenom and web security pioneer, to successful entrepreneur to an executive in the trenches of protecting high value financial services firms from cyberattacks.



    [MP3] | [Transcript]







    These days, every business is online and a huge – and growing – chunk of business activity is transacted online. The “web” has, in the space of 30 years, transformed from a funky little corner of the Internet full of pictures and text to become the bedrock of modern commerce.



    The web: 100% hackable



    Caleb Sima is the CSO at Robinhood.


    But it wasn’t always that way. Our guest today, Caleb Sima (@csima), was there at the beginning, before SQL injection was a thing (or at least a thing with a name). This was in the heady days when prominent firms were keen to get web pages, but didn’t think that web security was anything that warranted their attention. 



    As Mobile Fraud Rises, The Password Persists



    As a security analyst at the pioneering security firm Internet Security Systems (ISS) Caleb was happy to prove them wrong and turned what he learned exposing security weaknesses in corporate websites into a thriving business: SPI Dynamics, which was sold to HP in 2007. 



    Once more unto the (data) breach!



    Caleb followed that with another startup, Bluebox, a mobile application security firm he sold to Lookout in 2016, followed by senior roles as a Managing Vice President at CapitalOne and Vice President of Information Security at Databricks. These days, Sima has situated himself on the other end of the vendor divide as the Chief Security Officer at Robinhood, the Menlo Park based stock trading and investments firm.



    Identity Fraud: The New Corporate Battleground



    In this podcast, which is part of our CISO Close Up series, Caleb and I talk about his work as a pioneer in the field of web application security,
    37 min
  • Spotlight: SIEMs suck. Panther is out to change that.

    In this Spotlight episode of the Security Ledger podcast, I interview Jack Naglieri, the CEO and founder of Panther, about the evolution of incident response, the failures of the current generation of SIEM technology and the growing need for what Naglieri terms “detection engineers” – security analysts who can use their coding skills to create fine grained detections.



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and Spotify. Or, check us out on Google Podcasts, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted. 



    [MP3] | [Transcript]







    One of the biggest challenges for cybersecurity companies that charge to market promising to fight cybercriminals and other miscreants is that the landscape on which they battle is constantly changing. The ongoing parade of major breaches and cyber incidents is the proof of that.  And yet – as in kinetic wars – with each new incident, the seeds of the next generation of defenses and weaponry are sown. 



    Lessons from the Yahoo! breach



    Take our guest this week. Jack Naglieri is the CEO and co-founder of Panther, a company that is trying to reinvent the market for SIEM – Security Incident and Event Management – technology. The germ of the idea for the new company stemmed from Naglieri’s experience, early on, working in incident response at Yahoo! as that company dealt with fallout from a massive data breach at the hands of Russian intelligence that ultimately exposed data on all 3 billion Yahoo! user accounts – the largest known data breach  in history.




    “SIEM vendors don’t understand what the practitioner is doing. There’s a lot of SIEMs that people ubiquitously hate…but I don’t think that has to be the way any more.” —Jack Naglieri, CEO of Panther. 




    The size and scale of Yahoo! operations – complicated by its mix of acquired and developed technologies; on premises and cloud-based systems and more – exacerbated the challenges of doing incident response. Furthermore,
    43 min
  • Episode 246: SOARing out of Lockdown with Revelstoke Security

    In this episode of the Security Ledger podcast, we interview Josh McCarthy, the co-founder of Revelstoke Security, about the challenge of launching a start-up just as the COVID pandemic was breaking across the globe and forcing society – and the economy – into lockdown. We also talk about the growing demand for Security Orchestration, Automation and Response (or SOAR) technology to make sense of the storm of security data and feeds, and Revelstoke’s unique approach to managing security data.



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and Spotify. Or, check us out on Google Podcasts, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted.



    [ Download the MP3] | [Transcript]







    The COVID pandemic proved to be a ‘make or break’ moment for many companies. The sudden shift from in-office to remote work disrupted long established work patterns and had ripple effects throughout the economy – from commercial real estate to the restaurant and dry cleaning businesses.



    Meet the shutdown start-up



    Josh McCarthy is the Chief Product Officer and co-founder of Revelstoke Security.


    For technology start-ups, however, the effects were more muted. The flexible work arrangements and heavy reliance on managed, cloud based infrastructure and tooling often meant that life during COVID was “business as usual.” But what about trying to launch a start up in the midst of an emerging global pandemic? That’s something a lot harder to pull off. But our guest today managed to do it. Josh McCarthy is the chief Product Officer and co-founder of Revelstoke Security, a San Francisco based startup in the SOAR space – that’s Security Orchestration, Automation and Response. 



    SOAR for the non-Jedi



    In this conversation, Josh and I talk about the challenge of starting up Revelstoke just as COVID was shutting down pretty much everything else. 



    24 min
  • Episode 245: How AI is remaking knowledge-based authentication

    In this episode of the Security Ledger podcast, we interview Matt Salisbury of Honey Badger HQ, about his anti-fraud startup and how AI and machine learning are breathing new life (and potency) into knowledge-based authentication. If you find it interesting, check out the rest of our Life After the Password series of podcasts.



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and Spotify. Or, check us out on Google Podcasts, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted.







    Usernames and passwords have been with us almost as long as computers themselves – at least since the early 1960s when MIT introduced the Compatible Time-Sharing System (CTSS), an operating system, that was the first computer system to implement password login. 



    60 years in, passwords at a breaking point



    Matt Salisbury is the co-founder and CEO of Honey Badger HQ


    Six decades later, however, password use has tipped into the absurd. A 2017 study by Lastpass of its business users found that the average employee maintained 191 passwords in their account. That means the average 250 person company maintained more than 47,000 passwords. If the data is right, many of the passwords employees use are weak and easily guessed  – or used across multiple applications. 



    Passwordless? Imagining the Future of Authentication



    The adoption of so-called “two factor” authentication has helped with that problem, but even that technology has its limitations, as the recent hack of ride sharing firm Uber showed. But the key question for companies and employers remains the same: what is the most reliable and secure way to make sure someone seeking access to our network or applications is who they say they are?



    AI juices knowledge-based authentication 



    32 min
  • Episode 244: ZuoRAT brings APT Tactics to Home Networks

    In this episode of the Security Ledger podcast, brought to you by ReversingLabs, we interview Danny Adamitis (@dadamitis) of Black Lotus Labs about the discovery of ZuoRAT, malware that targets SOHO routers – and is outfitted with APT-style tools for attacking the devices connected to home networks.







    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and Spotify. Or, check us out on Google Podcasts, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted. 



    [MP3]



    Cyber attacks on small office and home office (or SOHO) routers aren’t new. Back in 2016, the malware known as Mirai made headlines across the world by infecting hundreds of thousands of weekly protected SOHO routers and DVR devices and stringing them into a potent botnet that could be leased out to distribute spam and launch crippling denial of service attacks. 



    But for all its bluster, Mirai and the IoT botnets that followed it were pretty simple creatures. They infected SOHO routers by exploiting default passwords (mostly). The goal was to own the router itself. The goal was to build  a platform for future, external attacks – not probing the home and small business networks the routers fronted.  



    New Rapidly-Spreading Hide and Seek IoT Botnet Identified by Bitdefender



    ZuoRAT: sniffing around home networks



    Danny Adamitis is a researcher at Lumen’s Black Lotus Labs.


    That’s not the case with ZuoRAT, a mysterious Mirai variant uncovered by researchers at Lumen’s Black Lotus Labs. According to Lumen researcher Danny Adamitis (@dadamitis), ZuoRAT looked like earlier IoT botnets, but behaved very differently: with an intense interest in the devices connected to home networks and the ability to launch extremely targeted attacks on home devices that could steal data, redirect web searches and, potentially, install malware on devices that used the router. Another interesting tidbit: ZuoRAT’s targets,
    22 min