Download on the App Store

episodes

  • Episode 234: Rep. Jim Langevin on Cyber Policy in an Age of Political Polarization

    In this episode of the podcast (#234) US Representative Jim Langevin (D-RI), joins Paul to talk about the flurry of legislation passed on Capitol Hill in recent months to boost the U.S.’s cyber defenses. Rep Langevin and Paul talk about how cybersecurity legislation receives bipartisan support -a rarity in Congress these days – and the challenges of protecting U.S. critical infrastructure in an age of sophisticated cyber adversaries like Russia and China.



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and Spotify. Or, check us out on Google Podcasts, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted. 



    [MP3]







    Political dysfunction is the Zeitgeist on Capitol Hill, where divisions between the two, main political parties have taken center stage and distrust runs deep after a violent attempt by supporters of former President Trump to overturn the November presidential election on January 6.



    But even in these challenging times, there are areas of cooperation between the two major parties. One is cybersecurity, where recent months have seen progress in funding improved cyber readiness at the local level. 



    Episode 222: US Rep. Himes on Congress’s About-face on Cybersecurity



    Cyber Policy: An Area of Agreement



    One example is the Infrastructure Investment and Jobs Act, passed in November and signed into law by President Biden on November 15. That bill allocated $2 billion to improve the nation’s cyber defenses. That includes $1 billion in grants to improve state and local government cybersecurity and a quarter billion dollars each to fund cyber improvements in rural and municipal utilities and to develop advanced cybersecurity applications and technologies for the energy sector. 



    Jim Langevin is a Democratic Representative from...
    26 min
  • Spotlight: COVID, Cloud Sovereignty and Other 2022 Trends with DigiCert

    In this Spotlight edition of the podcast, we’re joined by Dean Coclin, the Senior Director of Business Development at DigiCert. Dean and I discuss the trends that will shape the New Year, from cloud sovereignty to the growing reliance on PKI to secure digital identities, DEVOPs and more.



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and Spotify. Or, check us out on Google Podcasts, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted. 



    [MP3]







    If 2021 taught us anything, it is to expect the unexpected. The year started with an attack on U.S. democracy that few foresaw. A pandemic that was supposed to be on the run ended the year with a global blitz of almost unprecedented magnitude.



    Those kinds of unexpected surprises might make you wary about predicting the future. But when it comes to phenomena like online security, encryption and digital identities, some of the trend lines evident at the end of 2021 are a bit easier to extend into the future. “The future is already here,” the author William Gibson famously observed. “It’s just not evenly distributed.”



    Dean Coclin is the Senior Director of Business Development at DigiCert



    So it is with predictions for this new year, 2022. So what are some of those trends and what might we expect on the cybersecurity and digital identity front in 2022? We invited technology and digital identity veteran Dean Coclin from DigiCert into the Security Ledger studios to give us his thoughts.



    Will Vaccine Passports Pave The Way to Digital IDs?



    Dean is the Senior Director of Business Development at DigiCert. He has more than 30 years of business development and product management experience in software, security, and telecommunications to the company.



    In this conversation,
    34 min
  • Spotlight: ShardSecure on Protecting Data At Rest Without Encryption

    In this Spotlight edition of the podcast, we speak with Marc Blackmer of ShardSecure about that company’s new approach to protecting data at rest. Marc and I talk about the challenges of securing data in hybrid cloud and on-premises environments and how ShardSecure’s Microshard(TM) technology is being used to protect firms from inadvertent data leaks as well as threats like ransomware.



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and Spotify. Or, check us out on Google Podcasts, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted. 



    [MP3]







    Marc is the Head of Marketing at ShardSecure



    Securing data at rest seems like a problem that we should have solved a long time ago. And yet, a quick scan of the headlines tells us that the truth is far from that. Barely a week goes by without revelations of large-scale data breaches and leaks from both corporate networks and, increasingly, cloud-hosted infrastructure. 



    Data At Rest = Data At Risk



    In recent days, online gaming firm SEGA Europe admitted that an audit revealed sensitive data was being stored in an unsecured Amazon Web Services (AWS) S3 bucket. In December, it was Audio equipment manufacturer Sennheiser, which admitted that it exposed the personal data of around 28,000 customers through a misconfigured S3 bucket,



    How to Overcome Threat Detection and Response Challenges



    Encryption tools for securing that data are widely available, but they come with costs both in management overhead and in speed of access. Besides, public key encryption has been the go-to for securing digital data for four decades. Isn’t it time for another approach?



    Microshard: A New Approach



    Our guest today says that he may have one. Marc Blackmer is the Head of Marketing at ShardSecure, an innovative, Boston-based start up that has come up with a novel way to secure data on premises and in the cloud without using encryption. As its name suggests: Shard fragments and scatters stored data across various data repositories, only to reassemble it on request. 



    In this interview, Marc and I talk about the Shard technology and how it works, and about some of the market and business dynamics are driving companies to look beyond th...
    32 min
  • Episode 233: Unpacking Log4Shell’s Un-coordinated Disclosure Chaos

    In this episode of the podcast (#233) Mark Stanislav, a Vice President at the firm Gemini, joins Paul to talk about what went wrong with disclosure of Log4Shell, the critical, remote code execution flaw in the Log4j open source library. Mark talks about how the Internet community can come together ahead of the next vulnerability to make sure the mistakes that are evident in the response to Log4j aren’t repeated. 



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and Spotify. Or, check us out on Google Podcasts, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted. 



    [MP3]







    Back in 2008, the late, great security researcher Dan Kaminsky discovered a serious security flaw in a ubiquitous Internet technology: the domain name system, or DNS. If widely disclosed and exploited, the flaw – which affected many of the most common DNS name servers – could have facilitated a wide range of attacks, including website impersonation, email interception, and authentication bypass hacks.



    Mark Stanislav is a VP of Information Security at Gemini



    Aware of the risks, Kaminsky worked quietly for months with the Department of Homeland Security, major tech firms like Cisco and Microsoft as well as DNS providers to get patches written and distributed – all before details of the vulnerability were made public. Vendors worldwide were able to take steps that largely mitigated the risk of attack before any details of the flaw became publicly known. 



    Log4j Disclosure Chaos



    That’s not how it happened this month with another ubiquitous security vulnerability emerged: Log4Shell, a flaw in the open source logging library Log4j that is a common element of thousands of on premises and cloud applications used by enterprises, governments, critical infrastructure operators and individuals. 



    Rather than coordinated disclosure along the lines of Kaminsky’s DNS flaw, the world experienced something akin to coordinated chaos with Log4j, which first came to light via a patch by the video game maker Mojang Studios t...
    28 min
  • Episode 232: Log4j Won’t Go Away (And What To Do About It.)

    In this episode of the podcast (#232), Tomislav Peričin of the firm ReversingLabs joins us to talk about Log4Shell, the vulnerability in the ubiquitous Log4j Apache library. Tomislav tells us why issues related to Log4j won’t be going away anytime soon and how organizations must adapt to deal with the risk it poses.







    If you’ve been paying attention to your infosec news feed this week, you’ve been inundated with stories and headlines about something called “log4j, a (previously) obscure library that is a common component of a number of Apache software frameworks. This quiet little soldier of the open source software world,  we now know, has a glaring security hole in it that allows remote code execution on affected systems. 



    Episode 218: Denial of Sustenance Attacks -The Cyber Risk To Agriculture



    Tomislav Peričin is the co-founder and Chief Software Architect at ReversingLabs.



    Log4j: A Very Popular Library



    And that’s a big problem. Why? Well, it turns out that Log4j is a very, very, very popular software library. The firm Sonatype notes that in November, log4j-core, the vulnerable version of the module, was the 252nd most popular component by download volume in Sonatype’s Maven Central code repository. That’s out of a total population of 7.1 million artifacts – that’s the top 0.003% percentile in popularity by downloads. To date, more than 2000 software packages have been identified that are potentially vulnerable to attacks targeting log4j. Those include both the popular Minecraft massively multiplayer online game as well as Apple’s iCloud and Twitter. SAP announced on Wednesday that it, alone, patched 20 applications that used Log4j. In the meantime, threat actors are scanning the Internet to identify servers vulnerable to exploitation.



    Episode 208: Getting Serious about Hardware Supply Chains with Goldman Sachs’ Michael Mattioli



    Supply Chain Risks: The New Normal



    What does this mean for your organization? And what does the Log4j vulnerability tell us about the shape of cyber risks and threats to come? We invited Tomislav Peričin in to the Security Ledger studios to talk. Tomislav is the Chief Software Architect at the firm ReversingLabs and he’s an expert in software analysis and supply chain risks.
    27 min
  • Episode 231: Solving the US’s Endemic Cybersecurity Worker Shortage

    In this episode of the podcast (#231) Rodney Petersen, the director of the National Initiative for Cybersecurity Education (NICE) at the National Institute of Standards and Technology (NIST) joins host Paul Roberts to talk about the massive shortage of information security workers at the United States – estimated at more than 400,000 workers. Rodney talks about how NICE is working to promote information security skills and development.



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and Spotify. Or, check us out on Google Podcasts, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted. 



    [MP3]







    Rodney is the director of the National Initiative for Cybersecurity Education (NICE)



    The U.S. is struggling with a multitude of economic challenges these days. On top of a pandemic, which is crippling sectors like retail, entertainment and restaurants, companies are struggling with what’s been termed the “Great Resignation” – a nation-wide wave of quitting by workers worried about risks to their health or just fed up with substandard salaries, working conditions or both. 



    Episode 207: Sarah Tatsis of BlackBerry on finding and Keeping Women in Cyber



    But in the information security field, a “Great Resignation” would be considered a good problem to have. After all, in order to have workers resign, you first have to find and hire them, and that’s been a nearly constant challenge for organizations in need of information security talent in a country that has an estimated 465,000 unfilled cybersecurity jobs. 



    What is the source of the U.S.’s chronic information security worker shortage and what can be done about it? To answer those questions, we invited Rodney Petersen into the studios to talk. Rodney is the director of the National Initiative for Cybersecurity Education (NICE) at the National Institute of Standards and Technology (NIST) in the U.S. Department of Commerce. In this conversation, we talk about the challenges of developing the cybersecurity workforce and why “teach...
    27 min
  • Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security

    In this Spotlight edition of the podcast, we’re joined by Mackenzie Jackson, the Developer Advocate at the firm GitGuardian. Mackenzie and I discuss the problem of so-called “secrets sprawl” – the migration of all manner of sensitive information, from credentials to private keys -into public source code repositories on sites like GitHub.



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and Spotify. Or, check us out on Google Podcasts, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted. 



    [MP3]







    “Given enough eyeballs, all bugs are shallow.” That is “Linus’s Law.” First formulated by Eric Raymond in his 1999 book “The Cathedral and the Bazaar,” and named after Linus Torvalds, the creator of Linux. It speaks to a hidden value of open source code: with an unbounded population of developers given access to source code, security and quality issues will quickly bubble up and be discovered, improving security rather than undermining it. 



    Mackenzie Jackson is a Developer Advocate at GitGuardian



    All Secrets Are Shallow, Too!



    Two decades later, open source culture is now firmly entrenched, open source code and libraries are part and parcel of nearly every software development project, and massive, online repositories like GitHub put code at the fingertips of a population of millions of developers and billions of Internet users.



    In that new milieu, something like a corollary to Linus’s Law has emerged: given enough eyeballs, all secrets are shallow, too. 



    In other words: having thousands of developers crawling over your source code may expose hidden flaws in your application code. (Though there is ample reason to doubt that happens.) But it may also reveal secrets you weren’t aware were buried in your code, or that you hoped nobody would notice. 



    Credentials: Gone in 60 Seconds

    33 min
  • Episode 230: Are Vaccine Passports Cyber Secure?

    In this episode of the podcast (#230) Siddarth Adukia, a regional Director at NCC Group, joins host Paul Roberts to talk about the (cyber) risks and (public health) rewards of vaccine passport systems: how they work, how they can be compromised and what to do about it.







    As the world struggles to emerge from the COVID 19 pandemic, countries face one of two distinct challenges. Many poor and developing nations still struggle to obtain vaccines to inoculate their citizens and halt spread of the virus. However, in industrial nations in North America, Europe and parts of asia where vaccines are readily available, a secondary challenge has emerged: how to manage large and strident populations of unvaccinated residents who harbor doubts about the vaccines themselves, or are hostile to government and private sector vaccine mandates. 



    In many of those countries, vaccine passports have emerged as a popular tool to help manage the spread of COVID. In much of Western Europe as well as some U.S. states, residents have had to present proof of vaccination to receive a digital pass – often in the form of a QR code – that then grants them access to stores, restaurants and entertainment venues.  



    Episode 179: CISO Eye on the Virus Guy – Assessing COVID’s Cyber Risks



    But – like any technology – vaccine passports can, themselves, become a target of those who wish to siphon off sensitive information,  create forged credentials or merely sow chaos and distrust in the passport system. 



    That was the case last week after security researchers discovered valid, signed vaccine passports issued in the name of Adolph Hitler and Mickey Mouse were passing checks by state-run vaccine passport scanning apps like Germany’s Green Pass and Italy’s VerificaC19. The forged passports immediately led to speculation that digital keys for signing vaccine passports had been leaked – potentially undermining the entire European vaccine passport system. 



    The Spectrum of Mobile Risk: Protecting Your Corporate Data



    That begs the question of how vaccine passport systems work and what risks exist as countries look to implement vaccine passports to help them curtail the spread of COVID 19 amid populations of vaccinated and unvaccinated citizens. 



    To help us understand the vaccine passport landscape a bit better, we invited Siddarth Adukia, Regional Director at NCC Group into the studio. Siddarth recently authored a blog post that explored both the security features and associated threats of vaccine passports. He says that risks abound: from dodgy mobile applications that siphon off sensitive data, to attacks on core passport infrastructure like cryptographic signing keys. 



    Check out my full conversation with Siddarth above, or by clicking the download link below.




    Download the MP3

    29 min
  • Episode 229: BugCrowd’s Casey Ellis On What’s Hot In Bug Hunting

    When the first bugs for cash programs emerged almost two  decades ago, they were controversial. Programs like  iDefense Labs Vulnerability Contributor Program (VCP) (launched in 2002) and TippingPoint’s Zero Day Initiative (2005) were accused -at the time- of incentivizing the work of criminals and bad actors. 



    Today, however, bug bounty programs are part and parcel of the software industry. Companies like Microsoft, Google and Apple all offer them, as well as countless other software firms. In recent years, even “old economy” industrial and manufacturing firms like Ford, GM and John Deere got into the act.



    Careers Built on Bugs



    That has spurred growth in the demand for vulnerability hunters. These days, talented bug hunters and pen testers can make six figure salaries – or higher – on crowdsourced bug bounty marketplaces: finding and reporting flaws in software in accordance with corporate bug bounty programs. 



    Security Holes Opened Back Door To TCL Android Smart TVs



    Casey Ellis is the CTO and Founder of BugCrowd.



    But standing up a bug bounty program is no easy task. Apple, for example, has faced criticism for how it manages its disclosure program, with many vulnerability researchers claiming the company is too slow to address issues they report. For the countless other companies without big budgets and deep roots in the information security community, the logistics of standing up a bounty program and managing the flow of submissions are daunting. For those firms, bug bounty platforms have been a critical bridge to the global community of “white hat” security pros.



    Report: Critical Infrastructure Cyber Attacks A Global Crisis



    In the last decade, such programs have become a staple of countless software security and software assurance programs: crowd sourcing the work of finding and reporting software flaws that leverages the “wisdom of the crowd.”



    BugCrowd: Bug Bounty Programs 10 Years On



    What does it take to stand up a bounty program? And what skills are in demand on the bug bounty marketplaces today? To answer those questions, we invited Casey John Ellis into the studio. Casey is the founder and Chief Technology Officer at BugCrowd, an online marketplace that helps connect independent bug hunters, pen testers and software security experts with software publishers of every stripe. 



    Episode 200: Sakura Samurai...
    49 min
  • Spotlight: Your IoT Risk Is Bigger Than You Think. (And What To Do About It.)

    In this Spotlight edition of the podcast, we’re joined by Curtis Simpson, the Chief Information Security Officer at Armis. Curtis and I discuss the growing cyber risks posed by Internet of Things devices within enterprise networks. IoT and OT (operation technology) deployments are growing and pose challenges to organizations that are still focused on conventional IT systems and threats, and that struggle to detect such devices in their environments.



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and Spotify. Or, check us out on Google Podcasts, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted. 







    In the past decade, security threats posed by the “Internet of Things” have gone from a curious “what if” to an urgent problem affecting national security. Earlier this month, for example, CISA warned of ongoing cyber attacks targeting water and wastewater facilities. Those attacks are targeting both IT and OT – or operational technology – networks and systems including industrial control system (ICS) and SCADA systems, CISA said. (PDF)



    But, in truth, IoT risk is something that affects organizations of all types – from critical infrastructure owners and operators down to small businesses. Network connected printers, door/badge and HVAC systems, CCTV installations – all are common fixtures of modern workplaces – from defense contractors to doctors’ offices.



    Curtis Simpson is the Chief Information Security Officer at Armis.



    Still, the vast majority of security technology available to these organizations to manage their cybersecurity was designed to fight the “last war”: securing mostly Windows laptops, desktops and servers, even as non-traditional endpoints proliferate – most running operating systems other than Windows has cropped up on corporate networks. Consider, for example, the so-called “Urgent11” software vulnerabilities that were discovered to impact real time operating systems including VxWorks, OSE, Integrity and ThreadX RTOSs that, collectively, run billions of connected devices.



    Identifying these devices is critical if they are to be managed and secured. But what does that take? In this episode of the podcast we are joined by Curtis Simpson, the CISO at Armis, a cybersecurity firm that offers a knowledge base and tools for fingerprinting IoT devices and then monitoring and sec...
    29 min