The Adversarial Podcast

The Adversarial Podcast Ep. 11 - Incoming Trump administration, Microsoft's leaked SaaS creds, and software liability policy


Listen Later

Introduction:

  • The episode opens with a discussion on securing devices for employees traveling to high-risk countries, like China, as a way to protect corporate data and maintain customer trust.
  • Hosts Jerry, Sounil, and Mario welcome listeners and discuss recent events, including the FS-ISAC Fall Summit in Atlanta and geopolitical implications of the recent election.

Key Topics:

  1. Geopolitical Risks:
    • The group explores China's espionage activities and Russia's geopolitical maneuvers, predicting shifts in attacker strategies depending on U.S. political leadership.
    • Concerns about China's possible invasion of Taiwan and its implications for global tech, particularly chip manufacturing, are highlighted.
  2. Cybersecurity and Crypto:
    • The hosts discuss the post-election stock market bump, particularly in the tech and crypto sectors, and note the growing reliance on platforms like Coinbase.
    • They debate the perception and reality of cryptocurrency stability.
  3. Travel Security Policies:
    • The panel critiques outdated views on China-focused security policies and suggests broadening these policies to apply to all non-extradition countries.
    • Anecdotes on “burner laptops” and espionage myths are shared, emphasizing a need for realistic threat modeling.
  4. InfoStealers and SaaS Security:
    • Rising threats from InfoStealer malware, which targets stored credentials, are explored.
    • A specific case involving Snowflake and ServiceNow platforms highlights vulnerabilities tied to single-factor authentication and API misuse.
    • Debate on whether such findings should be within the scope of bug bounty programs arises.
  5. Shift Toward Hybrid and On-Prem Models:
    • Discussion on whether critical applications are moving back on-premises due to high cloud costs, especially for AI workloads.
    • The hosts argue the shift is likely economic rather than security-driven.
  6. EU Product Liability Directive:
    • The EU’s new directive introduces potential liability for software developers and companies, even extending to individual coders.
    • The implications for open source and global software markets are debated, with concerns about increased costs for doing business in the EU.
  7. CrowdStrike vs. Delta Lawsuit:
    • The CrowdStrike-Delta legal battle is analyzed, focusing on issues like the discovery of risk registers and internal chats, and how this might expose Delta's cybersecurity weaknesses.
    • Potential ripple effects for CrowdStrike's reputation and customer base are considered.

Closing Thoughts:

  • The episode ends with reflections on regulatory landscapes, including GDPR and how enforcement levels shape software innovation and compliance strategies.
  • The hosts tease ongoing developments in the CrowdStrike case as a topic to watch closely.

This episode combines high-level geopolitical discussions with detailed analysis of pressing cybersecurity trends, offering a mix of technical insights and industry perspectives.

...more
View all episodesView all episodes
Download on the App Store

The Adversarial PodcastBy Jerry Perullo, Sounil Yu, Mario Duarte

  • 5
  • 5
  • 5
  • 5
  • 5

5

22 ratings


More shows like The Adversarial Podcast

View all
Acquired by Ben Gilbert and David Rosenthal

Acquired

4,283 Listeners

Odd Lots by Bloomberg

Odd Lots

1,866 Listeners

Decoder with Nilay Patel by The Verge

Decoder with Nilay Patel

3,146 Listeners

Risky Business by Patrick Gray

Risky Business

374 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,016 Listeners

Click Here by Recorded Future News

Click Here

416 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,010 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

188 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

73 Listeners

Your Undivided Attention by The Center for Humane Technology, Tristan Harris, Daniel Barcay and Aza Raskin

Your Undivided Attention

1,580 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

134 Listeners

Hard Fork by The New York Times

Hard Fork

5,475 Listeners

The Big Take by Bloomberg

The Big Take

156 Listeners

Prof G Markets by Vox Media Podcast Network

Prof G Markets

1,325 Listeners