Download on the App Store

episodes

  • Spotlight: E-Commerce’s Bot and Mouse Game

    This week’s podcast is sponsored by DataDome. In it, we speak with DataDome’s Benjamin Fabre about how bot activity has greatly increased as a result of the COVID-19 Pandemic, and how inauthentic activity driven by bots is driving up operating costs for e-commerce companies of all shapes and sizes. We also talk about how bot prevention is complicated by the shift from web pages to mobile applications and APIs.



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and Spotify. Or, check us out on Google Podcasts, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted. 







    Everyone, no matter their age or origin, can tell you what a “robot” is. A simple Google search will tell you that it’s a machine that resembles a human being, which also performs human-like functions and movements automatically. The word itself is actually derivative of the Czech word “robota,” meaning forced labor. It’s no wonder then that “bot,” which is an automated computer program that pretends to be human, is short for “robot.”



    Benjamin Fabre is the President and co-founder at DataDome



    Turing Tests To Chatbots



    Robot programs, have been a staple of modern computing going back to British computer scientist Alan Turing’s famous Imitation Game – the “Turing Test” – which was designed to judge a machine’s ability to exhibit – or mimic – intelligent behavior well enough to fool a human observer. 



    New Rapidly-Spreading Hide and Seek IoT Botnet Identified by Bitdefender



    But in recent decades, as online commerce and activity have grown to account for a bigger and bigger share of the world’s economy, bots have taken on new prominence and importance. No longer the stuff of laboratory experiments in machine intelligence, bots these days perform a dizzying array of tasks: from indexing the contents of web pages, to assisting online shoppers to providing customer support. 



    On the other side of the ledger, bot driven distributed denial of service attacks are a sou...
    31 min
  • Episode 224: Engineering Trust In The Cyber Executive Order

    In this spotlight edition of the podcast, sponsored by Trusted Computing Group* Thomas Hardjono and Henk Birkholz join us to talk about President Biden’s Cyber Executive Order and how the EO’s call for increasing trust in federal IT systems is creating demand for TCG technologies.







    President Joe Biden threw down the gauntlet last May in the form of a Presidential Executive Order on cybersecurity. Issued amidst the fallout from the Colonial Pipeline ransomware attack, the EO laid out an aggressive schedule of big changes to federal IT, including identifying critical software in use by the government, verifying trust relationships between federal and private sector entities and demanding that IT firms selling software and services to the federal government develop software bill of materials (SBOM).



    In an environment of rampant cyber attacks on federal agencies, porous networks and vulnerable software and services, “trust” is a key concept in the Cyber Executive Order. In fact, the term appears more than 20 times in the EO alone.



    Thomas Hardjono is the CTO of Connection Science and Technical Director of the MIT Trust-Data ConsortiumHenk Birkholz is a researcher at the Fraunhofer Institute for Secure Information Technology



    But it is a lot easier to invoke the concept of trust than it is to engineer it into IT systems. Alas, if the federal government is serious about achieving the goals laid out in the EO, it will need to find a way to do just that. In the process, it will likely build upon the work of our guests this week.



    Henk Birkholz is a researcher at the Fraunhofer Institute for Secure Information Technology – located in Germany and Co-chair of the Attestation Working Group, at the Trusted Computing Group. He also chairs the Operations and Management Area working group and the IoT Operations working group at IETF.



    Thomas Hardjono is the CTO of Connection Science and Technical Director of the MIT Trust-Data Consortium at the Massachusetts Institute of Technology.  He is an invited expert at the Trusted Computing Group and former co-chair of the Embedded systems working group.



    Use the button below to download the MP3 or listen using the player above.




    Download the MP3








    (*) Disclosure: This podcast and blog post were sponsored by Trusted Computing Group. For more information on how Security Ledger works with its sponsors and sponsored content on Security Ledger, check out our About Security Ledger page on sponsorships and sponsor relations.



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You 
    37 min
  • Episode 223: CISA Looks To Erase The Security Poverty Line

    In this week’s episode of the podcast (#223), we are joined by Josh Corman and Lisa Young of the COVID task force at CISA to talk about the agency’s work to improve the security of critical sectors of the U.S. economy. Job #1: erase the so-called security “poverty line” that keeps small, poorly resourced firms from obtaining the skills and talents they need to protect their networks, data and IT assets.







    The phrase “let them eat cake” may have never been uttered by the French Queen Marie Antoinette. But the phrase has stuck to her for centuries – less because of its historical accuracy than for an attitude it epitomized: the detachment and callousness of the French monarchy and landed aristocracy in the face of widespread, abject poverty and hunger. 



    But a very similar attitude is at work these days in the information security space. Rather than standing on a balcony and calling for  cake  today’s cyber security cognoscenti instead mount stages at events like Black Hat and RSA and serve up rich desserts like “zero trust” to throngs of fellow cognoscenti. Outside the conference ballrooms, however technologically impoverished organizations in the for-profit, non-profit and public sectors are being ravaged by ransomware, data theft and corporate espionage, business email compromise scams and denial of service attacks.



    Laissez-les utilizer ‘zero trust’!



    Just as the aristocracy failed to apprehend the depths of hunger and poverty in society at large, large and wealthy information security firms, Industry ISACs and even federal agencies these days have failed to appreciate how unattainable “zero trust” networking is for a company with a constrained budget and without a dedicated security staffer – let alone a team. 



    Microsoft adds voice to calls for federal cybersecurity agency



    Those gaps – between a small number of wealthy and sophisticated firms and everyone else- are getting wider. Sadly, much of what passes for official guidance is targeted to the 1% of firms that can afford the latest technology and services, not the 99% of firms that can’t. Cybersecurity, it turns out, has an equity problem, also. 



    One agency that is trying to change that is CISA, the Cybersecurity and Infrastructure Security Agency. The federal government’s point agency for cyber is young enough to be in the teething stage, but in recent months it has taken steps to address what analyst Wendy Nather termed the “security poverty line” head on. As we noted back in episode 204: that started with work to shore up the COVID vaccine supply chain, which was heavily reliant on a large number of small, specialized equipment and component makers, most of whom lacked any permanent IT security staff. 



    Now the agency is expanding its work to other “NCFs” or “national critical functions. The agency is offering hygiene services like free vulnerability and application security scans for critical infrastructure providers. CISA is also trying to simplify the conversation around cybersecurity and best practices. A new site on the agency website is collecting “bad practices”  R...
    50 min
  • Episode 222: US Rep. Himes on Congress’s About-face on Cybersecurity

    In this episode of the podcast (#222), we speak with Representative Jim Himes (D-CT) about Capitol Hill’s sudden and singular focus on cybersecurity – an about-face that he says was encouraged by the devastating Colonial Pipeline hack.







    It is no news to anyone who has stayed abreast of the cybersecurity space that vulnerable software and hardware pose a serious risk to critical infrastructure in the United States. It is also no secret that sophisticated nation-state adversaries have made a habit of poking around inside sensitive government and corporate networks. 



    For some reason, however, that message has mostly fallen on deaf ears on Capitol Hill. After all, the Senate first got breached on cyber risk to the government and economy more than 20 years ago, when members of the L0pht, an early hacker collective, casually informed Senators in 1998 that they could “shut down the Internet” in 30 minutes, if they wanted. 



    Capitol Hill’s Long Learning Curve



    Between 1998 and today there have been countless hearings on cyber risks and countless reports documenting the federal government’s ineptitude on matters of information security. There have been even more head-slapping pronouncements of lawmakers utter cluelessness when it comes to matters of technology. Senator Ted Stevens’s famous “the Internet is a series of tubes” statement from 2006 is just the most famous, but lawmakers continue to fall for dubious arguments, like intelligence industry assurances that desired backdoors in encryption algorithms are possible without undermining everyone’s security. 



    That’s not to say that the ship of state isn’t slowly (slowly) turning, with the help of lawmakers on Capitol Hill who “get it” or that the body can’t put past lapses behind it and forge a brighter future for the public and private sector on matters of cybersecurity. The 2015 Cybersecurity Information Sharing Act is one great example. Among other things, it created the Federal Government’s first point agency on Cybersecurity, the Cybersecurity and Infrastructure  Security Agency or CISA.



    DHS announces New Cybersecurity Strategy



    U.S. Rep. Jim Himes (D-CT)



    In this week’s podcast, we invited one of Capitol Hill’s most recognized voices on matters of information security: Congressman Jim Himes, a 7 term Democratic Rep. representing Connecticut’s 4th District.  On Capitol Hill, Himes serves on the Defense Intelligence and Warfighter Support (DIWS) Subcommittee and the Strategic Technologies and Advanced Research (STAR) Subcommittee. He is also a member of the House Financial Services Committee where he serves as the Chair of the Subcommittee on National Security,
    32 min
  • Spotlight: Securing the Great Resignation with Code 42

    This week’s podcast is sponsored by Code42. In it, we speak with Code42’s Mark Wojtasiak about how companies can handle the security risks that accompany the “great resignation” and other COVID -inspired phenomena to prevent data theft and other undesirable outcomes.







    As hard as it is to believe 18 months into a global pandemic and with a 4th wave of Delta variant cases rising in the U.S., there will be a post-COVID reality at some point, and life (and work) will eventually return to normal, or something that is more like the pre-pandemic normal than what we’re living through now. 



    Mark Wojtasiak is the Vice President of Portfolio Marketing and Security Industry Research at Code42.



    Or not. One of the surprising revelations of the past few months, as vaccines have become readily available in the U.S. and Europe, is what some have called the “great resignation” – a wave of voluntary departures by employees who are not ready to return to the office, either because of fear of infection or disaffection with their current employment. 



    Also listen to Episode 176: The New Face of Insider Threats with Code42



    COVID hasn’t interrupted mergers and acquisitions either and may eventually fuel them, as companies battered by the pandemic get scooped up by competitors who were less affected. 



    Resignations and acquisitions are just part of doing business in the 21st century. But they also introduce a lot of risk. To put it simply: employees who are leaving a company these days typically aren’t leaving empty handed. Going with them may be reams of data – files, communications – even source code – to which they feel entitled. And companies, unfortunately, are ill suited to spot and counter such migrations. 



    In this spotlight edition of the podcast, we’re joined by Mark Wojtasiak, the Vice President of Portfolio Marketing and Security Industry research at the firm Code42. Mark and I talk about how companies can handle the security risks that accompany the “great resignation” and other COVID -inspired phenomena to prevent data theft and other undesirable outcomes.



    Listen to our conversation above, or use the button below to download the MP3 recording.




    Download the MP3








    (*) Disclosure: This podcast and blog post were sponsored by Code42. For more information on how Security Ledger works with its sponsors and sponsored content on Security Ledger, check out our About Security Ledger page on sponsorships and sponsor relations.



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and check us out on 
    32 min
  • Encore Podcast: Chris Valasek on Hacking The Jeep Cherokee

    If its midsummer, it must be time for hacker summer camp. The Black Hat Briefings cybersecurity conference kicks off tomorrow in Las Vegas, after a year that saw both Black Hat and DEFCON postponed. Both conferences will be held in person and online And, after a year interrupted by the COVID pandemic, 2021 promises a return to something approaching normal – if you can look past the surging Delta Variant COVID cases in and around Las Vegas. 



    With the event almost upon us, we’re running an encore edition of the podcast and looking back to one of the the most significant Black Hat presentations of all time, the 2015 demonstration of a wireless, software based hack of a Chrysler Jeep Cherokee by security researchers Chris Valasek and Charlie Miller. 



    In this interview from July 2015, I speak with Chis, who was then, the Director of Vehicle Research at IOActive about the work he and Charlie did to develop their wireless attack that gave them remote control the Cherokee’s braking, steering and acceleration of late model Chrysler vehicles. (Chris is now the Director of Product Security at Cruze.)



    The issue is one that has taken on even more importance in the six years since this interview aired. For one thing: the role of software in modern vehicles has only grown, with software based hands free and “autonomous” driving features now common in late model vehicles. Tesla recently released FSD v9 – an update to its “fully self driving” software that – the company admits – is a bit of a misnomer. NHTSA is investigating three dozen crashes involving vehicles using driver assistance features.  



    Autonomous vehicles could save more lives than they take. That might not matter.



    As it has in recent years, DEFCOn will feature a Car Hacking Village this year that brings together some of the world’s top automotive cyber experts (and a lot of tinkerers) to poke holes in common vehicle hardware and software systems. With US roads being used as a test bed and drivers filling in as “crash test dummies” for companies like Tesla, the concerns about vehicle cyber security have never been higher.



    That makes this conversation all the more interesting, with Chris telling me about the work he and Charlie did to reverse engineer both the wireless UConnect technology that is used to connect Chrysler vehicles to the Internet, and then jump from UConnect to the internal CAN bus that is used to control the critical functions of the vehicles.



    Valasek said that the hacks he and Miller demonstrated took months to develop. But he also noted that the barrier to such hacks is low in many, late model connected vehicles. The biggest obstacles to hacking a vehicle, Valasek argued, may be researchers’ unfamiliarity with vehicle systems and the cost to obtain a vehicle to test – not any technical impediment in the hardware or software that runs the car.



    “This is like hacking web browsers 10 years ago where people are just learning about how they work and what you can do with them,” Chris told me. Check out our full interview above, or by clicking the button below.




    19 min
  • Episode 221: Biden Unmasked APT 40. But Does It Matter?

    In this episode of the podcast (#221): Andrew Sellers, the Chief Technology Officer at QOMPLX joins us to unpack the revelations this week about APT 40, the Chinese group that the US has accused of a string of attacks aimed at stealing sensitive trade secrets. Also: is Salesforce the next SolarWinds? In our second segment, we continue our series on Left-Shifted Security with Waqas Nazir of DigitSec, a start up that helps secure Salesforce apps.







    The Biden Administration continued its forceful diplomacy on the issue of cyber security this week, with an announcement on Monday that named four Chinese nationals the U.S. says are responsible for a string of attacks on companies in the aerospace, biomedical, defense, healthcare, and manufacturing sectors, as well as academic research institutions. 



    Naming Names With APT 40



    The announcement was just the latest by the U.S. government – dating back to the Obama Administration, and continued during the Trump Administration to name not only foreign governments responsible for disruptive cyber attacks (as with North Korea’s hack of Sony) but to specifically calls out individuals working on behalf of foreign governments, as with the six, Russian GRU officers named in a DOJ indictment related to the hack of the 2018 Olympics.



    Episode 211: Scrapin’ ain’t Hackin’. Or is it?



    It’s a tactic that experts note is designed as much as a message to foreign nations about the U.S.’s intelligence prowess as it is an effort to inform the public. But is the strategy working? And what can companies in sensitive industries do to protect themselves from incursions like those mentioned in the indictment?



    Andrew Sellers is the Chief Technology Officer at QOMPLX



    To answer those questions we invited Andrew Sellers, the Chief Technology Officer at QOMPLX* back into the studio to talk about the indictment. Andrew previously led enterprise network modernization and design efforts for the Air Force and large Department of Defense initiatives that included critical and global aspects of security architecture and information transport infrastructure.



    In this conversation, he and I talk about the limits of the U.S. government’s “name and shame” campaign, and we did into some of the tactics, techniques and processes used by APT 40, the chinese advanced persistent threat group believed responsible for the attacks. 



    Is Salesforce The Next SolarWinds?



    Salesforce.com on Wednesday announced that it completed its record $27 billion acquisition of Slack Technologies. The deal, which adds Slack’s digital messaging and collaboration platform to the Salesforce roster, is part of a Salesforce plan to create what CEO Marc Benioff called a “digital HQ that enables every organization to deliver customer and employee ...
    34 min
  • Encore Podcast: Is Autonomous Driving Heading for a Crash?

    In this encore edition of the podcast, we revisit a 2018 interview with Beau Woods of The Atlantic Council from episode 89. Beau and I talk about the perils of autonomous driving software and whether automakers and regulators are rushing too quickly introduce autonomous features without adequately understanding the risks they pose.







    Elon Musk has been busy on social media in recent week. Among his usual rounds of SpaceX fanboy videos, memes and Dogecoin boosterism, Musk has regaled his massive social media following with the promises of a software update for Tesla vehicles: so-called FSD v9, or “version 9” of the company’s Fully Self Driving software.



    The software was released over the weekend and pushed out to Tesla vehicles soon thereafter. According to media reports and posts by Tesla users, its pretty impressive: allowing Teslas to navigate city streets – not just highways – pick their way across busy intersections and follow GPS directions to choose forks without driver intervention. The on-board “Tesla Vision” also got a big update, identifying whether cars on the surrounding roadways are slowing, accelerating or stopped…and more!



    Beta Software Behind The Wheel



    As to whether the “beta” software is safe and reliable now that it has been pushed out to millions of vehicles navigating U.S. roadways? That’s another question entirely – and one without a clear answer. Musk himself has admitted that automated driving is a much more complex problem than he initially estimated.




    Haha, FSD 9 beta is shipping soon, I swear!Generalized self-driving is a hard problem, as it requires solving a large part of real-world AI. Didn’t expect it to be so hard, but the difficulty is obvious in retrospect.Nothing has more degrees of freedom than reality.— Elon Musk (@elonmusk) July 3, 2021




    And his company seems eager to cover its butt. The company’s announcement of the FSD v9 release said less about the autonomous driving features in the update than about the abundance of caution Tesla drivers should use.



    Autopilot Accidents Pile Up



    The release – and the hype surrounding it – come at a curious time. As accidents linked to Tesla and its “Autopilot” technology pile up, the company finds itself in the cross hairs of the National Highway Traffic Safety Administration (NHTSA). In June, for example, NHTSA instructed automakers to begin reporting and tracking crashes involving cars and trucks that use advanced driver-assistance technology such as Tesla’s Autopilot and General Motors’ Super Cruise.



    Episode 209: Fortinet’s Renee Tarun on Scaling InfoSec To Meet Tomorrow’s Challenges



    Beau Woods of The Atlantic Council and CISA



    20 min
  • Episode 220: Unpacking The Kaseya Attack And Securing Device Identities on the IoT

    In this episode of the podcast, sponsored by Trusted Computing Group* we dig deep on this week’s ransomware attack on users of the Kaseya IT management software. Adam Meyers, the Senior Vice President of Threat Intelligence at CrowdStrike joins us to talk about the attack. We also talk with Frank Breedijk of the Dutch research group DIVD that discovered the vulnerability used by the REvil ransomware gang and was working with Kaseya to fix it. Finally, Tom Laffey, a product security strategist at Aruba, a Hewlett Packard Enterprise firm, and co-chair of the Network Equipment working group at TCG joins us to talk about the role that strong device identities play in securing Internet of Things endpoints.







    Another week, another devastating ransomware attack. On the heels of attacks on the Colonial Gas Pipeline and meat processor JBS, the last week brought news of a ransomware attack on Kaseya, an IT management platform used primarily by managed service providers. The attack saw Kaseya’s VSA software used to push out copies of the REvil ransomware to hundreds of downstream customers of MSPs that used the on-premises version of Kaseya VSA.



    The issue raises more questions about the security of software supply chains that companies across industries rely on. In this week’s episode of the podcast we dig deep into the Kaseya hack and some of the larger questions it raises about the security of critical technology platforms that are the scaffolding of modern enterprises. 



    Kaseya caught in Pinchy Spider’s Tangled Web



    Adam Meyers is the Senior Vice President of Threat intelligence at the firm CrowdStrike.



    In our first segment, we’re joined by Adam Meyers, the Senior Vice President of Threat Intelligence at the firm CrowdStrike. Adam has been a frequent guest on the podcast. In this interview, he helps us dig into the specifics of the Kaseya hack and the group behind the REvil ransomware, an advanced threat that CrowdStrike has dubbed Pinchy Spider. 



    In this conversation, Adam and I talk about the Kaseya attack and what it means for companies that have come to rely on managed service providers of the type that use the Kaseya software. These firms provide important services for customers, but also demand access to and high levels of privilege on the networks they manage. Adam notes that threat actors recognize that IT suppliers like Kaseya and SolarWinds are an easy avenue to gain access to a large population of networks in one fell swoop.



    To stop these attacks, organizations need to do basic blocking and tackling: patch management, threat detection firewalls, endpoint security and so on. But Customers need to do more to understand what software they’re using internally and what profile that software keeps under normal conditions.



    Spotlight Podcast: Two Decades On, Trusted Computing Group tackles IoT Insecurity



    “Threat actors recognize the power of (this) type of attack. The writing is on the wall. You need to be cognizant of what software you use and what that softwar...
    53 min
  • Episode 219: LGBTQ+Cyber – A Pride Month Conversation On Being Queer In Infosec

    In this week’s episode of the podcast (#219) we speak with four cybersecurity professionals about what it means to be Queer in the industry. We talked about their various paths to the information security community, finding support among their peers and the work still left to do. All in honor of Pride Month, 2021.







    The information security community has grown at a fast clip over the last two decades. What started as a humble collection of small, antivirus software firms is now a sprawling global market worth more than $150 billion, and with projected growth of more than 10% annually over the next decade. Hundreds of thousands of workers have flocked to the industry. And hundreds of thousands of more need to in the months and years ahead. By one count, there are half a million unfilled job openings in cybersecurity in the U.S. alone. 



    How welcoming will the field be to these new workers? If past is prologue, as the saying goes, there is reason for concern. Infosec is one of the most demographically lopsided industries around in terms of gender. Just 14% of cybersecurity workers are women and women are severely underrepresented in leadership roles. A man, for example, is 5x more likely to hold the title of CISO than a woman. And, while minority representation in the industry in the US is about in line with their representation in the general population, an ISC2 survey (PDF) found that minority cybersecurity workers are underrepresented in management roles. 



    But what about sexual orientation and gender identity? How welcoming is cyber security to members of the LGBTQIA+ community and what is their experience like working in information security related fields? If the cyber security field is going to fill those 500,000 open recs, it will need to welcome not just to women, ethnic and racial minorities, but also to workers with diverse  sexual orientations and gender identities. 



    Episode 203: Don’t Hack The Water and Black Girls Hack Founder Tennisha Martin



    According to a 2020 Gallup study, 1 in 6 adults in Generation Z identify as Lesbian, Gay, Bisexual, Transgender, Queer, Intersex, Asexual, Agender, or anything else that is not considered straight and/or cis-gendered (LGBTQIA+). As more young people enter the workforce, the cybersecurity industry must meet the demands of progress in order to minimize its talent gap, and create a more inclusive work environment for all people, regardless of their sexual orientation, gender identity, and/or expression.



    In celebration of Pride month,  Security Ledger podcast is talking to LGBTQIA workers in cyber security about their experience in the field: how they got to where they are, and their experience being “out” and -in many cases – coming out in a high stress, male dominated profession. 



    Our Guests



    Lea Kissner is the Head of Privacy Engineering at TwitterAllisa Knight is a Partner at Knight InkAmèlie Koran is a Senior Technology Advocate at SplunkChris Kirsch is the Chief Revenue Officer at Rumble



    Lea Kissner, Twitter: Engineering Respect



    Our first guest is
    1 hr 3 min