The Security Shit Show

The Security Shit Show

By The InfoSec MissionTechnology
Download on the App Store

The Security Shit Show episodes

  • Episode Sixty-Five - Hope Restored Lessons From GrrCON
    Hope in one hand and shit in the other! this is what I was told as a child about hope, this is because hope is commonly associated with expectations, and expectations lead to disappointment.

    It was not until later that I learned hope could also mean a want or desire for something to happen, that hope is about anticipation for positive outcomes.

    Then I remembered I work in information security, an industry that at times appears to be a hopeless wasteland of soul sucking, ungrateful people, never-ending greed, over inflated egos, blaming and shaming and awful behavior. An industry were the vendors treat their customers like victims, while peddling rebranded anti-virus and packet inspection as next gen and don’t get me going on the “Rock stars” of the industry are high on their own farts.

    Work in this industry long enough and you will start to lose hope, lost hope that anything will change, that we can get ahead of the criminals, that we can do the right thing, that we will become diverse and inclusive, that we will help and protect those we serve, that the next generation will know how a computer and network actually works.

    Feeling hopeless makes it hard to get up each day and keep fighting this fight, hopelessness is hard on mental health, passion and drive start to suffer and apathy starts to set in. It was in this spiral of negative feelings about our industry and its future that I found myself, when I arrived at my very first GrrCON.

    What unfolded over the next few days, surprised, renewed, refreshed, inspired, encouraged, empowered, energized and left me with a restored since of hope.

    After spending an amazing time hanging with and learning from some of the kindest, nicest, humblest, smartest people in infosec. I could see we have a chance to do better, to be better and there are some of us in this industry who are in it for all the right reasons. From the amazing folks at ILF to the thoughtful sessions, the openness to share knowledge, and humbleness of some of the biggest names in the game. Every person I met from the newest in the industry to the dusty old dinosaurs (holding up a mirror) every single person was eager to help, excited to grow and learn from one another regardless of experience level.

    We need to take what makes the attendees of GrrCON so special, put it in a bottle and sell it as a service.

    All this and more tonight on the Security Shit Show with Chris, Evan and Ryan.
    2 hr 11 min
  • Episode Sixty-Three - If I Were King of the World
    In the early 1970s (1971 to be exact), a group of wise men (Three Dog Night) were quoted as saying:

    And if I were the king of the world
    Tell you what I'd do
    I'd throw away the cars and the bars and the war
    Make sweet love to you

    Wise, right?

    Wait a second! What is I/you like cars and bars? Some people must like wars too because we keep having them.

    OK, all that aside for now. What if I were king of the world? What would I do?

    In terms of information security:
    Would I fire CEOs for not doing the basics?
    Would I flog the vendor for making crappy stuff?
    Would I define what's negligent and what's not, then throw people in jail?
    Would I fire the CISOs who continue to take shortcuts?
    Would I break up the monopolies that dominate technology?
    Would I, would I, would I...

    This should be a good discussion where we can dream a little bit. How would we right the world and how would you? Join me (Evan), Ryan, Chris, and Rachel (leading the online stuff) for an entertaining (and hopefully helpful) show LIVE on these Youtubes!
    1 hr 41 min
  • Episode Sixty-Two - Over the hill...
    Over the hill and through the woods we go to…
    Where are we going, I can’t recall, I may be going senile.

    To grow old is one of life’s blessings, but it is not all roses, one day you wake up and find you have injured yourself while sleeping. Maybe today is the day you discover you have knees, and they are very unhappy with the way you have treated them over the years. Or maybe this is the day you realize that you can't keep up with all the new things and changes happen around you daily.

    Sometimes, as I reflect on growing older, and the older I grow the more I seem to reflect, not because I am fearful of the aging process, or that I am worried about my final outcome (hint I love Jesus). I reflect because I ask myself what I have done to set the next generation up for success?

    What can (or should) I be doing with the time I have left to help others?

    In my career I have watched the birth and growth on an entire industry. I have seen how the technology we made has had a profound and lasting impact on what it means to be a human, and how you interact with the world. Those who come after us do not have this same luxury, they are lacking the wisdom earned through these gray hairs.

    Each year that goes by, it becomes clear(er) that I have forgotten more than I (or they) know. With age and experience came a price that must be paid. I don’t know all the latest and greatest things happening, new tech, new vulnerabilities, new exploits. Who does? The good news is, it doesn't matter as much as how you deal with them. How you deal with them hasn't changed much in the last 30 years.

    Experienced professionals have stories to tell, advice to give, and lessons they learned the hard way. They have so much to share!

    Are we doing enough to mentor those coming up in the industry? Hopefully before our minds leave us, spending our waning days rocking in a chair reminiscing about the good old days. You remember yelling at people in your house, “Hey I am on the internet, hang up the phone”, or that one time we waited 4 hours for a .jpeg to download?

    Those were days when you knew what was on your network and could explain what it was doing. "Googling it" wasn't an option.

    I find myself pondering this question as I grow older, I ask myself about the legacy we're leaving for the next generation. Believe it or not, they ARE looking to us for guidance and leadership.

    What lessons have we learned, technical and non-technical, that we want to pass on? There's a story, purpose, and lesson behind every scar.

    In an industry that is as competitive as ours, based on secrecy, are we doing enough to equip the young'uns with the hard-earned knowledge that no book or class can teach? There's something about being in the heat of the batter. If we don't share our knowledge, then the same mistakes will be made over and over again.

    Maybe this is why we're still trying to get people to backup their data?

    I enjoy growing old because I value the experience I've gained and the scars I've earned. There are the joyous moments and there are the painful ones too. Like the title of one my favorite western films, "the good the bad and the ugly".

    Although I may feel like a lost shoe on the side of the highway, we should wonder, where it came from, how in the F did it get here and does it still serve a purpose.

    I used to wonder why all the old people seemed to be cranky and fed up with the world, and each day this worldview makes more and more sense.

    Join us tonight for a discussion on aging, the impact it has on us as humans and security professionals and most importantly, what are we doing to pass on the experience we have to the next generation.

    https://www.youtube.com/watch?v=a2__8xIIa2A

    Evan, Chris and Ryan
    2 hr 26 min
  • Episode Sixty-One - Say Something Nice...
    I remember my Mother teaching me “if you don’t have anything nice to say, then don’t say anything at all” and there’s a LOT of merit in that statement for various situations.... However, when it comes to our industry, and some of the companies, folks, and players INSIDE of it I must admit I’ve broken that rule on several occasions.

    Which brings me to the rather splendid Osthoff Resort, sandwiched between Milwaukee and Green Bay, Wisconsin.

    I’m here...

    Surrounded by a posse of FBI agents, InfraGard folks, and businesses...


    THANKFULLY I’m not alone in this pickle. I’ve got Evan Francen and Ryan Cloutier, CISSP with me to even out the odds a little.

    And we’ve just spent the day (I’m up on stage in a couple of hours to complete the trifecta of apocalyptic horsemen) beating the living snot out of the entire industry, LOTS of folks, companies, and agencies that are in it.

    Which means we should probably end the day thinking/saying something nice. IF nothing else we need to give folks some hope (and ourselves some redeeming qualities beyond just binging the alcohol.)

    SO, this evening the #shitshow IS going to be live FROM the FBI/InfraGard stage and IF we can, we’re going to find some good things to talk about. There might be some pauses, some moments of silence as we work out what IS good....

    Come along, hang out, join in (we’re doing audience participation on this one)

    AND let’s see if there ARE some good things inside InfoSec (aside from the availability of alcohol, tea, and caffeinated beverages)

    Shout out to InfraGard for allowing us in!
    AND to the Federal Bureau of Investigation (FBI) for being nice enough to not arrest us on sight again....
    2 hr 1 min
  • Episode Sixty - Are you driving (your computer) with a gun pointed at your head
    You know about the massive Takata airbag recall story, right?

    No?! Maybe?

    Well, we've got one helluva story to tell you. Takata was (keyword "was") a Japanese company founded in 1933 that started making airbags in 1988. At one time the company owned 20% of the market, and things were good. At least we thought things were good...

    - Honda knew about more than 100 injuries and 13 deaths related to Takata airbags, starting in about 1998.
    - In the Spring of 2013, recalls were issued. Not small recalls either, like 3.6 million cars.
    - In June 2014, Takata admitted that their Mexican subsidiary mishandled "the manufacture of explosive propellants" used in their airbags.
    - Later in June 2014, BMW, Chrysler, Ford, Honda, Mazda, Nissan, and Toyota all announced recalls. The reason? Takata airbags "could rupture and send debris flying inside the vehicle".

    Let's stop for a second... What do you call something that uses an explosive propellant to launch a projectile (or "debris")?

    It's called a gun.

    In July 2014, a pregnant Malaysian woman was killed. A metal fragment sliced into her neck. (she was going 18 MPH).
    -----INSERT MANY STORIES HERE-----
    Late last year, Janett Perez, a U.S. citizen in Mexico was killed when a Takata airbag shot a metallic fragment into her neck too. Another car accidentally backed into her.

    Today, millions of Takata ticking timebombs are still on the road.

    More than 30 car manufacturers have been affected, and the NHTSA ordered an (ongoing) US-wide recall of more than 42 million cars (the largest automotive recall in U.S. history). Worldwide, the estimated size of the recall is roughly 100 million cars.

    So what does this have to do with information security? Lots actually! The parallels include consumer ignorance, manufacturer negligence, regulatory ineffectiveness, and more. As we integrate technology more and more into our physical world, the parallels become even more frightening.

    Let's have a truthful (and downright scary) talk about this shit tonight!

    Join us LIVE @10pm CDT, August 26th.

    Evan, Ryan, and Chris are sure to have one helluva discussion about this!
    2 hr 28 min
  • Episode Fifty-Nine - The times they are a-changing but are we? (Part 2)
    Last week we took some time away to do some of the things we love, Chris went to DefCon to taste whiskey with folks, Evan took his beard and bike to Sturgis to make memories, one of his most favorite things to do and I took some time to visit with my wife and dog.

    As I was reflecting on all the things that had happened in just a weeks’ time, it dawned on me we are at the beginning of a new era as a society and as an industry and even as I type this my news feed is full of new discoveries, new legislation, new science and change on a global scale that at times is hard to comprehend.

    The scope and scale of work in front of us is daunting, old thinking and old methods must go, we must get creative, we must innovate, we must simplify.

    What used to work is no longer working, what used to be acceptable is no longer acceptable, what used to be enough is no longer enough. We now must embrace these changes head on and take a whole new approach to a new world, especially in our industry.

    Tonight, we will discuss some of the changes that have happened that affect our industry, pontificate on what we need to change to adapt and adjust to this new world.
    2 hr 4 min
  • Episode Fifty-Eight - The times they are a-changing but are we?
    Last week we took some time away to do some of the things we love, Chris went to DefCon to taste whiskey with folks, Evan took his beard and bike to Sturgis to make memories, one of his most favorite things to do and I took some time to visit with my wife and dog.

    As I was reflecting on all the things that had happened in just a weeks’ time, it dawned on me we are at the beginning of a new era as a society and as an industry and even as I type this my news feed is full of new discoveries, new legislation, new science and change on a global scale that at times is hard to comprehend.

    The scope and scale of work in front of us is daunting, old thinking and old methods must go, we must get creative, we must innovate, we must simplify.

    What used to work is no longer working, what used to be acceptable is no longer acceptable, what used to be enough is no longer enough. We now must embrace these changes head on and take a whole new approach to a new world, especially in our industry.

    Tonight, we will discuss some of the changes that have happened that affect our industry, pontificate on what we need to change to adapt and adjust to this new world.
    2 hr 4 min
  • Episode Fifty-Seven - Hey CISO, You Can't Win
    DAY ONE
    CONGRATULATIONS! You've made it to the top. You're the CHIEF!
    CHIEF INFORMATION SECURITY OFFICER, the CISO.
    Sounds pretty damn good! It's feels pretty damn good too!
    I AM THE CISO!!! YAY ME!!!

    SOMEWHERE BETWEEN DAY TWO AND NINETY
    I'm (still) grateful to be the CISO. I get paid to make a difference, and it's great to be in a position where I can!
    It's a lot of work though. Like ALOT or work. It didn't seem so hard from the outside. Maybe I'm just not doing it right. Or, you know what? I'm still adjusting. Yep, that's it! Still adjusting.
    This will be great!
    Now that I think about it, it's sort of lonely here at the top too.
    Oh well, whatever. Remember, I'm adjusting and I'M CISO!

    SOMEWHERE BETWEEN DAY NINETY AND WHAT SEEMS LIKE ETERNITY
    Wow. Now I realize that it's lonely at the top, AND the wind blows the strongest at the top of the mountain!
    Between the unrealistic expectations of the "business", lack of collaboration with other executives (namely the CEO), preaching the same shit everyday, the politics, and very limited resources, I'm starting to miss the good old days.
    WAIT?! What am I saying?! I'm the damn CISO! I'm the the top dog, and this is awesome!
    Now I need to figure out how to tell my wife I'm going to be late again tonight...

    IF YOU'VE BEEN PAYING ATTENTION...
    You may have noticed that you're playing a game that you CANNOT win. You are being held accountable for things you're not empowered to control. Everybody looks at you when you know they should be looking at themselves.

    That damn head of research and his damned grants! There's no way in hell I'm going to get him to use MFA on the data repository.

    Bill in sales is a real turd too! Just because he brings in millions of dollars of business, it shouldn't exempt him from following the rules! He's putting the business at risk!!!

    Crap, and what about Sally, the head of the London office? She keeps playing the politics card with me and I don't have the same kind of pull she does.

    My budget keeps getting cut, I feel like I'm losing the respect of my peers, and I always feel like I should be leading my team better. Speaking of my "team", I'm running at 40% staffing level right now! THIS IS HARD!

    To top it all off, I'm not sleeping very well, my wife is distant (and usually pissed at me), and I have no time to take the new boat out.

    THAT'S IT!!! I CAN'T WIN!!!
    Oh this sucks! Now what? I've got two kids in college, a big house payment, this nice car I've got to pay for, and this fricken boat I never get to use!
    I can't quit! What will happen with everything I worked so hard for?

    Shit.

    I'll just go with the flow and try not to make waves anymore. That "change" I was so excited about at the beginning? Yeah, screw it. I'll just play the game to lose.
    1 hr 48 min
  • Episode Fifty-Six - You Got Breached, Congratulations
    You Got Breached.

    Congratulations.
    You’re NOT a special snowflake
    You can’t go round pouting
    You don’t need to find anyone to blame
    No, the Russians probably didn’t do it
    No, I don’t need tagging in the post
    Yes, likely you DO need to change some things
    No, you probably couldn’t have stopped it
    Yes, you could have likely detected it sooner
    Yes, you could probably have remediated it faster
    No, don’t you DARE blame the users!
    No, your annual training for 30 mins isn’t effective (it sucks)
    Yes, you can recover from it (hopefully)
    No, it won’t kill you JUST yet, wait a few more years though…
    More budget? Stop wining and spend what you have wisely
    Yes, it means you have to roll up your sleeves
    Yes, interns or apprentices can help remediate this
    Yes, get off your ass, it got pwned, get over it
    No, you’re still NOT a special snowflake.

    Congratulations.
    You’re JUST like all the other breaches
    You can sit down and plan
    You should go look in the mirror
    You likely did it to yourself, we’ll get to that.
    Yes, you can reach out for help and advice
    NO, you don’t need to buy everyone’s cyber-crap
    NO, everyone’s cyber-crap isn’t going to stop it either
    YES, it would be good to know what you actually have
    YES, it would be great to know WHERE your data IS
    Yep, IF you can track it back, it probably starts on a users machine
    Yes, ongoing education HELPS (doesn’t fix, but helps)
    Yes, you can recover from it (get the basics in order)
    Yes, we are working on hacking the chips in humans, fun eh?
    Nope, don’t expect more money, so work smarter
    Yes, it means you can now get your house in order, good!
    Yes, you can probably justify headcount but save $$ and get folk TO train
    Yea, it sucks, sorry, but it’s the way of the new world.
    And no, you’re not special, you CAN however be a good example.

    Get the basics sorted out BEFORE your ass is delivered TO you on a silver platter

    * Assets, what do you have?
    * Assets, where are they?
    * Who’s got access to them, and why?
    * What DO they do, what is their purpose?
    * What’s on them?
    * Which ones do you need to care about?

    Got it? Good, now go get a cuppa tea or coffee and go deal with it…. I’m going to go make breakfast.

    ‘all for now

    Chris
    1 hr 25 min

About The Security Shit Show

From the publisher's feed

Information security is mostly a shit show, so we made the Security Shit Show.

This is the place where shit gets real. No filter. Straight talk about shit that ain’t right in the information…