Download on the App Store

episodes

  • Episode 218: Denial of Sustenance Attacks -The Cyber Risk To Agriculture

    I case you’ve been living under a rock for the last year, let’s review: attacks on critical infrastructure are a thing. In just the past four months, the United States has contended with a major escalation of cyber risk in critical infrastructure with two, major attacks that disrupted critical sectors. First the Colonial Pipeline and then meat processor JBS were hobbled – temporarily – by criminal ransomware. In both cases, the companies quickly paid out ransoms to the attackers rather than face the prospect of rebuilding IT environments from scratch. 



    Episode 158: How NotPetya has Insurers grappling with Systemic Cyber Risk



    Cyber Risk Alert: Critical Infrastructure Attacks Are Here



    The repercussions of those attacks were easy to see. Accounts of long gas lines and high gas prices in the Eastern United states appeared within days of the Colonial Pipeline attack – the product more of panic buying than disrupted supplies. In the case of JBS, the attack caused disruptions up and down the beef supply chain, including the closure of slaughter houses. 



    Rob H. Wood is Vice President of Hardware and Embedded Security Services at NCC Group. (Image courtesy of NCC Group.)



    But what if there was no ransom to be paid and those attacks had lasted longer? What if the target was not just a single meat processor (albeit a big one), but farms throughout the country that grow wheat, soybeans, corn and other staples of the global food supply chain?



    The consequences of any attack on the U.S. agriculture sector could be much more dire than expensive hamburger or a supermarket shopping bag filled with petrol. A coordinated cyber attack on U.S. agriculture could, in short order, lead to foot shortages and hunger in the U.S. and abroad. And history has shown us that when food gets scarce, things get ugly – fast.



    Report: Critical Infrastructure Cyber Attacks A Global Crisis



    Cyber Attacks On The Food Chain?



    But how likely is such an attack? And how vulnerable are U.S. farms to disruptive attacks like those on Colonial or JBS? The answer is: ‘more vulnerable than you might think,’ according to our guest today, Rob Wood. Rob is the Vice President of the Hardware Embedded Systems Practice at the firm NCC Group. In that role, he helps organizations of all kinds improve the security of their embedded devices and equipment. And he warns that the agriculture sector, like other critical infrastructure sectors, is increasingly reliant on vulnerable software and hardware. The consequences of that dependence, and the lax security, are only dimly understood. I
    35 min
  • Episode 217: What Fighting Pirates Teaches Us About Ransomware

    For countries that wished to move goods and treasure back in the 16th and 17th centuries, wind-powered sailing ships and ocean transit were the only option. And pirates were a major, major problem. Pirate gangs like those headed by Edward Teach (better known as Blackbeard), the Barbarossa brothers and Captain William Kidd plied the Caribbean Sea, the Gulf of Mexico and coast of Central and South America (aka “The Spanish Main), the Mediterranean the Indian Ocean and elsewhere, seizing cargo including gold, jewelry and raw materials that fueled the home economies of colonizing nations like England, Spain and Portugal.



    Episode 153: Hacking Anesthesia Machines and Mayors say No to Ransoms



    Andy Jaquith is the CSO at QOMPLX.



    Modern Problem, Ancient Roots



    The groups were a persistent menace, but they weren’t merely crooks. Many operated as “privateers,” helping to further the interests and ambitions of sponsor nations, like England and Spain. Sir Francis Drake is best known for circumnavigating the globe, but he was also a pirate of the first order: raiding Spanish colonial settlements in what is now Mexico and the West Coast of the United States on his way around the world. And he operated with the support of England’s Queen Elizabeth, who was interested in weakening the strength of the Spanish Navy on the high seas.



    Episode 169: Ransomware comes to the Enterprise with PureLocker



    All that complexity bears a striking resemblance to a modern scourge on commerce: ransomware. Today, ransomware gangs – like pirates of yore – swoop in on businesses, critical infrastructure owners and public sector agencies with no notice, holding them hostage for ransoms and stealing sensitive data. Behind these groups lurk sponsor nations, first and foremost Russia, which give them safe harbor to operate and benefit, indirectly, from the chaos they sow in rival economies.



    Joey, Talk to Russia (about Ransomware)



    That’s why ransomware was very much on the agenda when Russian Prime minister Vlad Putin and President Joe Biden met in Geneva this week. Among other things, Biden was expected to push Putin on that country’s practice of allowing ransomware gangs operate from within its borders. And, while there were no clear agreements reached about cyber security cooperation at the summit, there is evidence that industrialized nations are waking up to the threat posed by these groups.



    Kaspersky Deems Crypto-jacking the New Ransomware as Crypto-miners up Their Game



    To discuss what lessons history might hold for them as they confront this 21st century form of pirating, we invited Andy Jaquith back into the SL studios. Andy is the CSO at the firm QOMPLX and an expert on cyber security with a background in political science and economics In this conversation we talk about the deep similarities between the ransomware scourge of the early 21st century and the problems posed by pirat...
    25 min
  • Episode 216: Signed, Sealed and Delivered: The Future of Supply Chain Security

    In this episode of the podcast (#216), sponsored by DigiCert, we talk with Brian Trzupek, DigiCert’s Vice President of Product, about the growing urgency of securing software supply chains, and how digital code signing can help prevent compromises like the recent hack of the firm SolarWinds.







    We spend a lot of time talking about software supply chain security these days? But what does that mean. At the 10,000 foot level it means “don’t be the next Solar Winds” – don’t let a nation state actor infiltrate your build process and insert a backdoor that gets distributed to thousands of customers – including technology firms three letter government agencies. 



    Brian Trzupek is the Senior Vice President of Products at DigiCert. 



    OK. Sure. But speaking practically, what are we talking about when we talk about securing the software supply chain? Well, for one thing: we’re talking about securing the software code itself. We’re talking about taking steps to insure that what is written by our  developers is actually what goes into a build and then gets distributed to users.



    Digital code signing – using digital certificates to sign submitted code – is one way to do that. And use of code signing is on the rise. But is that alone enough?  In this episode of the podcast, we’re joined by Brian Trzupek the SVP of Product at DigiCert to talk about the growing role of digital code signing in preventing supply chain compromises and providing an audit trail for developed code.



    Brian is the author of this recent Executive Insight on Security Ledger where he notes that code signing certificates are a highly effective way to ensure that software is not compromised -but only as effective as the strategy and best practices that support it. When poorly implemented, Brian notes, code signing loses its effectiveness in mitigating risk for software publishers and users.



    In this conversation we talk about the changes to tooling, process and staff that DEVOPS organizations need to embrace to shore up the security of their software supply chain. 



    “It boils down to do you have something in place to ensure code quality, fix vulnerabilities and make sure that code isn’t incurring tech debt,” Brian says. Ensuring those things involves both process, new products and tools as well as the right mix of staff and talent to assess new code for security issues. 



    One idea that is gaining currency within DEVOPS organizations is “quorum based deployment” in which multiple staff members review and sign off on important code changes before they are deployed. Check out our full conversation using the player (above) or download the MP3 using the button below.




    Download Episode 216








    (*) Disclosure: This post was sponsored by DigiCert. For more information on how Security Ledger works with its sponsors and sponsored content on Security Ledg...
    35 min
  • Episode 215-2: Leave the Gun, Take the McFlurry

    In this episode of the podcast, we bring you the second installment of our interview with Jeremy O’Sullivan of the Internet of Things analytics firm Kytch. (The first part is here.) In this episode Jeremy talks about the launch of Kytch, his second start-up, which helped owners of soft ice cream machines by the manufacturer Taylor to monitor and better manage their equipment. We hear about how what Kytch revealed about Taylor’s hardware put him at odds with the company and its long-time partner: McDonald’s.







    We generally view and talk about phenomena like “digital transformation” in a positive light. The world’s growing reliance on software, cloud computing, mobility and Internet connected “things” is remaking everything from how we catch a cab, to how we grow food or educate our children. 



    Jeremy O’Sullivan, co-founder of Kytch.



    But what happens when that “digital transformation” is transformation to something worse than what came before, not the better? What happens when technology isn’t used to build a “better mousetrap” but to support a racket that enshrines expensive inefficiencies or a monopoly that stifles competition? 



    What the hell is going on?



    In his week’s episode, we’re digging deep on that question with the second installment of our interview with Jeremy O’Sullivan, the co-founder of the Internet of Things intelligence start-up Kytch. As we discussed last week, O’Sullivan and his wife, Melissa Nelson, launched the company in an effort to use data analysis to revolutionize the industrial kitchen, starting with one common but troublesome piece of machinery: soft ice cream machines manufactured by the company Taylor and used by the likes of McDonald’s and Burger King. 



    Episode 147: Forty Year Old GPS Satellites offer a Warning about securing the Internet of Things



    “What the hell is going on with the software on this ice cream machine? Why as the versions increase…is the software getting worse?” – Jeremy O’Sullivan of Kytch on the Taylor soft ice cream machines.



    The Dark Possibilities of Digital Transformations







    In this episode, O’Sullivan talks about how – as  McDonald’s franchisees scooped up Kytch devices- his understanding of Taylor’s “business model” changed, even as the relationship with the company soured, culminating in what O’Sullivan alleges was the theft of a Kytch device and the reverse engineering of its proprietary technology. 



    Far more than a story about massive, wealthy incumbents crushing a smaller challenger, the Kytch story is one that hints at the dark possibilities of digital transformation,
    43 min
  • Episode 215-1: Jeremy O’Sullivan of Kytch On The Tech Serving McDonald’s Ice Cream Monopoly

    We all harbor magical and romantic ideas about the transformative power of both technology and entrepreneurship. “Build a better mousetrap and the world will beat a path to your door.” That romantic idea is at the heart of many start ups, and the Internet has created a platform on which a never ending stream of new “mousetraps” can be conceived. Think, for example, of the NEST thermostat – that iconic Internet of Things product, which stylishly re-imagined the boring old thermostat: outfitting it with brains, motion sensors, a cool graphical interface and a powerful, web-based back end.  



    Company Town 2.0



    But technology can just as easily create dystopias as utopias: obscuring the operation of formerly mechanical instruments whose workings were easily observable, or harvesting data from unwitting users and ferrying it off to the cloud for use by shadowy global corporations. Technology can even trap owners and business people in a kind of servitude – like the share croppers or the residents of “company towns” in the 19th and 20th centuries whose lives were prescribed and diminished by invisible bonds of contract and dependence, rather than by physical chains. 



    Jeremy O’Sullivan, Co-Founder, KytchMelissa Nelson, Co-Founder, Kytch



    Report: Companies Still Grappling with IoT Security



    As the Internet of Things expands from “smart thermostats” to cars; home appliances; the agricultural equipment that plants and harvests our food; or the machinery that businesses rely on; the chances that you or someone you love might end up as a digital share cropper or the resident of one of these virtual  “company towns” are growing. 



    And that’s what our podcast this week is about. In the first part of a two part episode, we’re joined by Jeremy O’Sullivan, co-founder of the IoT analytics company, Kytch. Jeremy and his wife and co-founder, Melissa Nelson, were the subjects of an amazing profile in Wired Magazine by Andy Greenberg that described the young company’s travails with the commercial ice cream machine manufacturer, Taylor, a storied multi-national whose equipment is used by businesses from the corner soft serve joints to giants like Burger King and McDonalds. 







    TV Maker TCL Denies Back Door, Promises Better Process



    Despite the company’s sterling reputation and dominant position in the marketplace, O’Sullivan found that the Taylor equipment was notoriously unreliable – to the point of becoming an Internet meme. Today, sites like McBroken.com use McDonald’s online ordering websites to determine that anywhere from 5% to almost a quarter of all McDonald’s ice cream machines in major U.S. metro regions are not operational at any given time.



    O’Sullivan’s big idea for Kytch: use technology he had developed to allow franchise owners bet...
    38 min
  • Episode 214: Darkside Down: What The Colonial Attack Means For The Future of Ransomware

    In this episode of the podcast (#214), Brandon Hoffman, the CISO of Intel 471 joins us to discuss the recent ransomware attack on the Georgia-based Colonial Pipeline, and the suspected group behind it: DarkSide a ransomware for hire cybercrime outfit.







    It was just a week ago, May 7th, 2021, that a successful cyberattack against one of the largest U.S. oil and gas pipelines, operated by the Colonial Pipeline Company, forced it to shut down and plunged the U.S. government into an unanticipated crisis. Within days, there were reports of consumers panic-buying petrol leading to gas shortages in the southeastern United States.



    Do Cities deserve Federal Disaster Aid after Cyber Attacks?



    Then, almost as suddenly as the crisis appeared it was over. Colonial, which was reported to have paid the Darkside group a $5 million ransom to regain access to their servers, announced that it would restore pipeline operations by the end of the week. And, in a message to a private forum on Thursday captured by the firm Intel 471, the ransomware group credited with the attack, known as “Darkside,” said that it was shutting down after its blog, payment server and Internet infrastructure were seized by law enforcement and cryptocurrency from a Darkside controlled payment server was diverted to what was described as an “unknown account.” 



    An image of the message posted by the Darkside group ceasing operations. (Image courtesy of intel 471.)



    Other news reports suggests the cyber criminal underground was getting skittish about ransomware groups, now that the full force of the U.S. government appears to be focused on rooting them out. Reports out Friday claim that the Russian cyber hacking forum XSS has banned all topics related to ransomware. 



    Episode 169: Ransomware comes to the Enterprise with PureLocker



    What happened? And who – or what – is the Darkside group responsible for the Colonial pipeline attack? We invited Brandon Hoffman, CISO at the firm Intel 471 back into the studio to talk about Darkside, which Intel 471 has followed and profiled in depth since it emerged last summer.



    “They (DarkSide) don’t necessarily want to have their affiliates attack Critical Infrastructure or the government.” -Brandon Hoffman, CISO Intel 471



    The quick collapse seen in recent days may be a case of Darkside biting off more than it can chew by attacking a target that managed to put it in the cross hairs of the U.S. government. But, as we discuss, the Colonial Pipeline hack also raises a number of questions regarding the state of America’s Critical Infrastructure,
    22 min
  • Seeds of Destruction: Cyber Risk Is Growing in Agriculture

    In this episode of the podcast (#213): Molly Jahn of DARPA and University of Wisconsin joins us to talk about the growing cyber risk to the Food and Agriculture sector, as industry consolidation and precision agriculture combine to increase the chances of cyber disruption of food production.







    Just as it has in other sectors, technology and digital transformation has remade the agriculture sector over the century. The image of farm life in early 20th century looked something like Steinbeck’s Of Mice and Men, where teams of migrant workers like the characters George Milton and Lennie Small, who labored under close, human supervision to bring in the harvest. 



    Spotlight Podcast: Synopsys’ Dan Lyon on the Challenge of Securing Connected Medical Devices



    In 2021, George, Lennie and the countless men they worked alongside  are gone. Their work is not mostly performed by mechanized, Internet connected and GPS-guided equipment that can sow, tend and harvest crops with astounding speed. That technological revolution, driven by companies like the US agriculture giant John Deere, has made US farms among the most efficient and profitable in the world. 



    Molly Jahn is a Program Manager at DARPA.



    Food production in the US is highly concentrated. An open market institute report from 2019 found extreme concentration in areas like meat production and dairy. There were close to 650,000 dairy farms operating in the US in 1970. Today, there are just 40,000.  Market share for the largest four U.S. corn seed companies grew from 59 percent in 1975 to 85 percent in 2015.  And on and on. 



    Episode 147: Forty Year Old GPS Satellites offer a Warning about securing the Internet of Things



    So what do we have? A handful of companies responsible for producing the lion’s share of US food, and doing it through heavy reliance on precision farming technology that runs on software and – increasingly – cloud based management platforms. What’s missing, according to researchers, is an understanding of the digital risk that has been a byproduct of this digital transformation. 



    In this episode of the podcast we dig deep on that issue. Our guest is Molly Jahn. Molly is a program manager in the Defense Sciences office at DARPA, a faculty member at the University of Wisconsin Madison and the Principle investigator at Jahn Research Group. She’s also a co- author of a 2019 report for Lloyd’s of London on Evolving Risks in Global Food Supply. (https://www.lloyds.com/news-and-insights/risk-reports/library/evolving-risks-in-global-food-supply) 



    Spotlight Podcast: Managing the Digital Risk in your Digital Transformation



    In this conversation, Molly and I talk about how the US food system became so vulnerable to cyber attack, what a coordinated attack to compromise food production in the US might look like. We also discuss steps that the federal government should take to address the cyber risk to food and agriculture. 



    Molly Jahn is a program manager in the defense sciences office at DARP...
    31 min
  • Episode 212: China’s Stolen Data Economy (And Why We Should Care)

    In this episode of the podcast (#212), Brandon Hoffman, the CISO of Intel 471 joins us to discuss that company’s latest report that looks at China’s diversified marketplace for stolen data and stolen identities.







    Data leaks, data breaches and data dumps are so common these days that they don’t even attract that much attention. Back in 2013, news that hackers stole data on tens of millions of customers of the software maker Adobe dominated the headlines for days. These days, news that companies like Facebook or LinkedIn exposed data on hundreds of millions of users barely registered a collective shrug. 



    “What’s a better way to understand a person you’re trying to victimize than to understand their habits? That way you can have a better chance that whatever scam you’re trying to run has success.” -Brandon Hoffman, CISO Intel 471



    Data leaks and data breaches, for all intents and purposes, have become just the price of doing business online. But those who are ready to be blasé about breaches may be overlooking the role that leaked and stolen data plays in other, more serious problems such as targeted cyber attacks.



    Waiting for Federal Data Privacy Reform? Don’t Hold Your Breath.



    A Stolen Data Ecosystem Grows In China



    Data lifted today from a health insurer, government agency or retailer often informs tomorrow’s targeted spear phishing attack that can steal sensitive intellectual property, redirect government secrets or fuel attacks on critical infrastructure. That’s the conclusion of a recent report by the company Intel 471. That company recently made a study of how Chinese cyber criminal groups were using big data technology to monetize the data they obtained (often: stole) in the Chinese language underground. The company’s research revealed a sophisticated, cybercriminal ecosystem involving cybercriminals, data brokers and insiders as well as cybercriminals who obtain sensitive data. 



    Report: Critical Infrastructure Cyber Attacks A Global Crisis



    In this interview, we invited Brandon Hoffman, the CISO at Intel 471 into the studio to talk about the report and the way that the market for stolen data has created a number of “sub economies” that help fuel cyber crime. 
    20 min
  • Episode 211: Scrapin’ ain’t Hackin’. Or is it?

    In just the last two weeks, three of the world’s most prominent social networks have been linked to stories about data leaks. Troves of information on both Facebook and LinkedIn users – hundreds of millions of them – turned up for sale in marketplaces in the cyber underground. Then, earlier this week, a hacker forum published a database purporting to be information on users of the new Clubhouse social network. 



    Andrew Sellers is the Chief Technology Officer at QOMPLX Inc.



    To hear Facebook, LinkedIn and Clubhouse speak, however, nothing is amiss. All took pains to explain that they were not the victims of a hack, just “scraping” of public data on their  users by individuals. Facebook went so far as to insist that it would not notify the 530 million users whose names, phone numbers, birth dates and other information were scraped from its site.



    So which is it? Is scraping the same as hacking or just an example of “zealous” use of a social media platform? And if it isn’t considered hacking…should it be? As more and more online platforms open their doors to API-based access, what restrictions and security should be attached to those APIs to prevent wanton abuse? 



    To discuss these issues and more, we invited Andrew Sellers into the Security Ledger studios. Andrew is the Chief Technology Officer at the firm QOMPLX* where he oversees the technology, engineering, data science, and delivery aspects of QOMPLX’s next-generation operational risk management and situational awareness products. He is also an expert in data scraping with specific expertise in large-scale heterogeneous network design, deep-web data extraction, and data theory. 



    While the recent incidents affecting LinkedIn, Facebook and Clubhouse may not technically qualify as “hacks,” Andrew told me, they do raise troubling questions about the data security and data management practices of large social media networks, and beg the question of whether more needs to be done to regulate the storage and retention of data on these platforms. 







    (*) QOMPLX is a sponsor of The Security Ledger.
    23 min
  • Episode 210: Moving The Goal Posts On Vendor Transparency: A Conversation With Intel’s Suzy Greenberg

    This week’s podcast is sponsored by Intel. In it, we speak with Intel’s Suzy Greenberg about a recent study Intel sponsored with the Ponemon Institute looking at the need for greater vendor transparency around cyber security. Suzy is a vice president at Intel and general manager of security communications and incident management in the Intel Product Assurance and Security group.







    The compromise of firms such as SolarWinds and Accellion in recent months have made clear to everyone that the fate of your organization’s cyber security concerns doesn’t stop at the firewall. Indeed, as digital transformation takes hold across industries, the security of the software providers and third parties is now integral to the security and safety of pretty much every organization. Security teams, trained to monitor corporate perimeters and network traffic, now need to concern themselves with flaws buried deep in third party products and attacks that come wrapped as software updates. 



    Episode 208: Getting Serious about Hardware Supply Chains with Goldman Sachs’ Michael Mattioli



    Suzy Greenberg, Intel Corp.



    But what does that increasing reliance and interdependence mean for the relationships between software providers and their customers, particularly around information about software flaws and vulnerabilities? Do software and service providers owe it to their customers to be fully transparent about flaws or weaknesses in their platforms even in advance of patches, or is the byword still “say nothing unless asked”?



    Those are questions I put to our guest this week. Suzy Greenberg is a vice president at Intel and general manager of security communications and incident management in the Intel Product Assurance and Security group. Suzy leads the execution of Intel’s global security communications strategy as well as the company’s response to matters involving product assurance and security.



    In this conversation, Suzy and I talk about a survey (PDF) the company conducted with the Ponemon Institute to measure attitudes about vendor transparency about security. Among the survey’s findings: 47% said that their technology provider does not provide transparency surrounding security updates and mitigations. 



    Futility or Fruition?Rethinking Common Approaches To Cybersecurity



    To start off, I asked Suzy about Intel’s Product Security  Incident Response Team (PSIRT) and how the company that makes the chips that power modern technology manages its own product security challenges. You can check out the full podcast above or download the MP3.







    (*) Disclosure: This podcast and blog post were sponsored by Intel. For more information on how Security Ledger works with its sponsors and sponsored content on Security Ledger, check out our About Security Ledger page on sponsorships and sponsor relations.



    As always,  you can check our full conversation in 
    32 min