InTechnology

InTechnology

By Camille MorhardtBusinessTechnology
Download on the App Store

InTechnology episodes

  • 61. What That Means with Camille: Gaming

    When gaming first began as a concept, there was no connectivity like we see today in terms of playing with others online. Back then, it was just a controller, a console, and a TV. Simple! Now, the landscape has drastically changed with online gaming. So, how has that affected cybersecurity? Camille is joined by Matt Areno, a PhD in Computer Engineering with 10 years of experience as a hacker and who now leads the Security Assurance and Cryptography Team at Intel — and he’s an absolute wealth of information when it comes to the topic of gaming! The two discuss the definition of gaming, how gaming has changed over the years, how government agencies and the military are now using gaming as a means for recruiting, what to do if your gaming account is hacked, MMOs (massively multiplayer online games), and more. Whether you already know a lot or a little about gaming, you won’t want to skip this one!

    The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

    20 min
  • 60. A CTO Weighs in on Motivation and Automation in Cybersecurity

    As technology rapidly evolves, there’s an ever-growing list of security vulnerabilities that companies should take seriously. Yet, why are so many companies still so immature in their attitudes towards protection? Tom and Camille are joined today by Todd Weber, Operating Partner and Chief Technology Officer at Ten Eleven Ventures, who gives insight based on 20+ years in IT engineering, operations, and cybersecurity experience! Their conversation covers new vulnerabilities companies should consider in their approach to security, why some companies might intentionally choose to not be adequately prepared, what motivates companies to improve cybersecurity, the overlap between automation and artificial intelligence (AI) and machine learning (ML), and more.

    The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

    28 min
  • 59. What That Means with Camille: Federated Learning

    Federated learning is relatively new (less than five years old), but it stands to have a huge impact on the machine learning landscape, especially for healthcare. Camille is joined by Olga Perepelkina, PhD, a Deep Learning Product Manager at Intel, to find out exactly how this field is projected to change the world. Federated learning can be used for things like medical imaging, computer vision applications, natural language processing (NLP), and deep learning. Listen in to learn what federated learning is and why it matters, how it’s protecting sensitive data, how it’s different from other machine learning approaches, the many uses for federated learning, how data is annotated in federated learning, the cyber security concerns about federated learning, and what the future of federated learning looks like!

    For more resources on federated learning, check out these links:

    OpenFL: Intel open source federated learning library: https://github.com/intel/openfl

    Federated Learning in Medicine: A Nature paper:  https://www.nature.com/articles/s41598-020-69250-1

    Intel Federated Learning Slack: https://join.slack.com/t/openfl/shared_invite/zt-ovzbohvn-T5fApk05~YS_iZhjJ5yaTw

    The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

    26 min
  • 58. Mooly Eden on Risk and Betting on New Technologies

    How do you get over the fear of betting on new trends? What makes a great leader? And how do you keep your chin up when your ideas are ridiculed? Tom and Camille are going to an expert for these questions with guest Mooly Eden—Board Member, Speaker, Former Intel Executive, and all-around fantastic innovator and leader. Mooly and our hosts discuss why employees need to be proactive and persuasive about their concerns, how all innovation requires a certain level of risk, how to not be discouraged if your innovative idea isn’t well-received at first, how to improve leadership skills by looking inward, why not to sugarcoat things, why you need to be adaptable in order to thrive, and more. Future leaders, this is an episode you won’t want to miss!

    The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

    34 min
  • 57. What That Means with Camille: Threat Modeling

    Threat modeling is vital to the product development process, and it truly never ends. Camille is joined by Jonathan "Jonny" Valamehr, Principal Engineer at Intel, and Dina Treves, Senior Very Large Scale Integration (VLSI) Engineer at Intel, to talk about the thought processes of threat modeling, why there is currently no standardized threat model, as well as how the ever-evolving vulnerability landscape affects threat modeling. Threat modeling isn’t something to tackle later on in product development—it needs to be done early and repeatedly. Listen in to learn what cyber threats are out there, how to prioritize defending against them, the benefits of biometrics for cyber security, and more! 

    The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

    22 min
  • 56. What That Means with Camille: Offensive Security Research, aka: Hacking

    Hacking is often associated with bad behavior, but there are good guys out there who use hacking models to help ensure products aren’t exploited by ill-intentioned parties. This is part of the offensive security research (OSR) process. Today, Camille’s speaking with Jason M. Fung, Director, Offensive Security Research & Academic Research Engagement at Intel, who breaks down why offensive security research is such a crucial practice. In their discussion, they also cover the importance of thinking like an ill-intentioned hacker, the important skills and traits of ideal hackers, why perspectives from external organizations for offensive security research can be beneficial, and more!

    The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

    29 min
  • 55. Why Firmware Attacks Are Threat Groups’ New Go-To

    Firmware-based attacks are some of the hardest to detect, which is what makes them so dangerous! Once someone has control over your hardware, they can do just about anything. In this episode of Cyber Security Inside, CEO and founder of Eclypsium Yuriy Bulygin joins Tom and Camille to share his expertise on firmware attacks, offering a comprehensive view of vulnerabilities and how threat groups exploit them. Their conversation covers the brutal extent of firmware attacks, how threat groups exploit firmware vulnerabilities, how to tell if you’ve been a ransomware attack victim or if the attack has reached firmware-level, how working from home during the pandemic has changed firmware attacks, and how companies should secure their platforms. You won’t want to miss it!

    The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

    29 min
  • 54. Why Capture the Flag is More Than Just A Game in Cybersecurity

    You may have played the game capture the flag as a kid, but did you know it has another meaning in cybersecurity? Capture the flag (CTF) events in a cybersecurity context ask teams to hack into devices in order to detect vulnerabilities. In this episode, Camille is joined by award-winning academics Ahmad-Reza Sadeghi, a professor at TU Darmstadt in Germany, and JV Rajendran, an assistant professor at Texas A&M, to shed light on these important security exercises and how they’re such a great intersection of industry and academia. Their discussion covers the history of CTF for improving hardware security, what goes into a CTF event, how participants look for vulnerabilities and what those vulnerabilities may be, how CTF events can lead to the discovery of new vulnerabilities on top of the ones already injected into the codes at hand, and more!

    The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

     

     

    We cover:

    -  The meaning and history of “capture the flag” (CTF) in the digital realm, especially as it applies to hardware security

    -  The structure of a CTF event and the kinds of tools and resources made available to participating teams

    -  How people are trained to look for vulnerabilities, and how they might look for those even without a CTF event

    - The various classes of vulnerabilities, and why the trend of replicating them exists in the first place

    -  How the pandemic has impacted CTF

    ... and more.  Tune in!

     

    The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

     

    Here are some key take-aways:

    -  The purpose of capture the flag events is for great minds around the world to use their hacking skills to detect vulnerabilities that have purposefully been injected with bugs; that way, product security can be improved based on the findings.

    -  Similar to the children’s game, CTF events are competitive; they’re all about picking up “digital flags”, trying to outscore competitors along the way.

    -  CTF participants report back to judges to claim their points at the end of an event, and the results are then used to boost existing and future product security.

    -  A fantastic outcome of CTF events is that they sometimes lead to the discovery of new vulnerabilities on top of those that have been injected into the codes at hand.

    -  In addition to CTF events, academia is key in training students what to look for when detecting vulnerabilities in hardware.

    -  When selecting devices to experimentally hack into, it’s important to consider the popularity of the device, as well as the device’s ability to connect to other devices.

     

    Some interesting quotes from today’s episode:

    “That's the beauty of the human mind - you can run a lot of artificial intelligence, but nobody has these flashy ideas that come to the human brain.”

    “If a device exceeds a certain popularity, that means more people are using it, so we buy this device, and we hack into it.”

    “Jason Fung from Intel came to us and said, ‘Hey, I want to have a discussion with you.’ He was pitching this idea of running the Capture the Flag competitions where he would provide buggy Verilog code, and ask students to find the bugs in the code and start exploiting them. And this was immediately great for me because I was looking for buggy Verilog code, and this guy from Intel comes and says he can provide that. And that's great, not just for training students, but also for my research. So that's how I got attracted to this line of work.”

     

    “Sometimes they even find errors and vulnerabilities that we didn't inject into the code that we sent them. That's also the most important part of it. New vulnerabilities that teams find.” 

     

    “There are certain bugs that are more severe. That can be, as I said, remotely exploited even by an attacker who doesn't have the right privileges. Those kinds of attacks are far more serious. And our judges tend to value those attacks a lot more.”

     

    “We cannot put it on a commercial platform because companies would not provide that. But this open source platform, on the other hand, is a good vehicle.”

     

    “That has been a big influence, even for our research, because now we know like, ‘Hey, these are the bugs and the problems that the companies care about. So let's use those things to actually kind of reflect the real world scenario’.”

     

    “Our lab aims to develop techniques to protect the designs against these kinds of attacks.”

     

    “We do a kind of market research. If the device exceeds a certain popularity, that means more people are using it, so we buy this device, and we hack into it.”

    27 min
  • 53. What That Means with Camille: Medical Devices

    As we continue to navigate a global pandemic, the security of medical devices and hospitals is particularly pertinent. Today, Camille’s exploring this timely topic, as she is joined by three well-versed guests on medical devices and cyber security: Matt Russo, Senior Director of Product Security at Medtronic, Priya Upendra, Senior Director of Customer Success at Asimily, and Stephanie Domas, Director of Security Communications in Intel's Product Assurance Division. The group discusses the many types of medical devices, the challenges hospitals and medical providers are facing when it comes to hacking devices, the types of cyber threats for medical devices, how security guidelines are still growing and changing, the role of telehealth in all this, and more!

    The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

    32 min
  • 52. Who Benefits from Cyber Security Insurance and How

    We’re all familiar with home and auto insurance, but what cybersecurity insurance? Cybersecurity insurance is vital for mid-size or large companies who want to mitigate threat risks. In this episode of Cyber Security Inside, Malcolm Harkins joins Tom and Camille again to unpack everything you need to know about cybersecurity insurance. Now the Chief Security and Trust Officer at Epiphany Systems, Malcolm’s 30+ year career in the tech industry gives him a unique and valuable perspective. The discussion covers what cyber insurance is and who might need it, how it’s similar to other forms of insurance, what expenses cyber insurance will usually cover, whether or not cyber insurance providers employ requirements or stipulations and what those may be, how insurance may influence whether or not a company reports a compromise to authorities, and more!

    The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

    34 min

About InTechnology

From the publisher's feed

Welcome to InTechnology, hosted by Camille Morhardt. In this podcast you will hear conversations with industry leaders and technical experts in cybersecurity, sustainability, and technology.