The Security Shit Show

The Security Shit Show

By The InfoSec MissionTechnology
Download on the App Store

The Security Shit Show episodes

  • Episode Forty-Four - Am I Crazy?
    What the hell is going on?! It feels like the world has lost it's mind. Everywhere I look (out there), it's chaos.

    Hypocrisy running rampant.

    Virtue signaling is a "thing", gotta score those popularity points.

    Cancel culture? This is a thing now, maybe, maybe not?

    Politicians preach nonsense, openly lying and manipulating.

    Big societal problems left unsolved, with no (unbiased) solutions.

    Black kids shot (accidental or not, the result is the same) on the streets.

    Cities burning, and we're burning them.

    People hurting (deeply), and we're not helping them.

    Vaccinate! Wait, maybe not. If you do, maybe you'll die?

    Accountability, what the hell is that?

    On, and on.

    The bath water is dirty. Who cares about the baby.
    People spew shit out of their mouths that doesn't make any sense. Nobody speaks up. Worse yet, yahoos sell their souls to support bullshit, because it's better to be in the "in" crowd. Who the hell is the "in" crowd anyway?

    This shit IS NOT computing.

    Not in this brain anyway. Everyone's lost their minds! Not "everyone" everyone, but everyone out there.

    WAIT A SECOND.
    It clicks. Didn't my Dad say something about this once?

    Son, if everyone's an asshole, you're the asshole.
    So, does this mean, if everyone's crazy, I'm the one who's crazy?!

    Dammit! Now, I have some reflection to do. The journey down the rabbit hole begins...

    What does this have to do with information security?
    Simple.

    Everything.

    The hypocrites, the virtue signalers, the cancellers, the politicians, the "illegals", the Blacks, the Whites, the Hispanics, the people who live in our cities, the people who live in our suburbs, the people who are hurting, the people who vaccinate, the people who don't vaccinate, the Liberals, the Conservatives, and everyone in between, is ALSO my co-worker, my relative, my partner, my customer, my friend, my employee, and my fellow human being.

    I may run in my circles, just like you run in yours, but my job is to protect EVERYONE, regardless of who you are, where you come from, what you believe, or what you're struggling with. Knowing that information security isn't about information or security as much as it is about people, makes people my focus. Not just the people I like and agree with.

    This is deep, but sometimes we have to dig deep to find out who we really are and what we're really doing here.

    Looking forward to talking this shit out with my AWESOME friends, Ryan Cloutier and Chris Roberts! Catch us this week LIVE at 10pm/2200 CDT on the YouTube.

    (and yes, I am crazy, but a functional crazy)

    Sorry maybe, but this is me.
    -Evan
    2 hr 18 min
  • Episode Forty-Three - Killed My Grandma (updated)...
    NOTE: #ShitShow​ topic NOT my Grandma in Real Life before anyone gets worried!

    Annually, there are anywhere from 22,000 to 250,000 cases of death in the medical field that really should NOT have happened.

    Firstly, I’m glad the medical field has as many problems as we do in counting how many people they harmed. InfoSec has no REAL idea as to the implications of our actions beyond “Hey, Look! More data’s out there…” At least in the medical field there’s bodies to count.

    The question then is how do you categorize death? IF they were sick before they came TO hospital does that count as malpractice, or “accelerated natural causes”? You get the idea, it’s apparently rather subjective…

    These two fields are coming together on something akin to a collision course of a planet sized scale.

    Technology In/on/around the body (smart pills, nanotechnology, biotechnology, telemedicine, etc.) are all making serious inroads into “us” the human. Analog humans ARE becoming part OF the digital realm.

    We need a LOT more forethought before medical malpractice adds another tick box marked “CAUSE OF DEATH… Kernel Panic”

    So, join Ryan Cloutier, CISSP Evan Francen and the crew tonight on the Shit Show to discuss…
    2 hr 26 min
  • Episode Forty-One - Security Shit Show Jeopardy!
    Security Shit Show and Jeopardy

    Yep, this shit's happening!
    For the first time, we're going to host the Jeopardy game show, Security Shit Show style.

    The topics?
    Come on. You think we plan that far ahead?
    We don't know yet.
    It's the Security Shit Show!
    We'll figure it out when the time is right.

    Participants?
    You and us.
    We'll pull folks from the live stream chat.
    Then we'll find out how much shit they know about some shit.
    The champ stays, chumps go back and sit down.

    Any other questions?
    Save 'em for the show.
    If we like your question, we'll answer it.
    If we don't, we'll probably ignore it.

    I'm the game show host (Evan), while Chris and Ryan will heckle you.
    Tune in, this will be a good time! (or it could suck, but that's unlikely).
    2 hr 12 min
  • Episode Forty - Simplify, then add lightness…
    The late Colin Chapman, founder of Lotus eschewed the pursuit of horsepower in favor of lightness combined with better handling across his road and race vehicles.

    That courage to buck the trend resulted in numerous accolades on both sides of the Atlantic.

    It is that ethos our industry should once again embrace.

    Simplify:
    The interfaces, the barriers to entry, the integration, deployment and overall management of the plethora of technology we eagerly buy, deploy, and then complain about.

    Lightness:
    Adding power is great if you are going in a straight line, however, leave the power alone, remove the complexity, and unnecessary features (the rule of 90%) and reduce the amount of time you have to fettle over the technology.

    How well do your tools integrate?
    How much unnecessary overlap do you have?
    How much of that tool do you REALLY use?
    How many hands does it take to run?
    Do you maintain it?
    Etc.

    Start measuring vendors, technologies and PEOPLE by how well they help you simplify, then that should add some lightness across the board.

    Join Evan Francen, Ryan Cloutier, Rachel Arnold and I as we unpack this tonight on the Shit Show…

    ‘all for now
    Chris
    2 hr 11 min
  • Episode Thirty-Nine - The Tool Fool - Part 2
    THIS IS PART TWO - CONTINUATION FROM EPISODE 38

    A fool is a person who acts unwisely or imprudently. A Tool Fool is someone who unwisely or imprudently loves tools. They don’t necessarily love the tools they have; they just love tools. The more tools, the better.

    Don’t be offended. We’re all fools from time to time. When it comes to our information security, we do the best we know how. We don’t intentionally act the fool, but when it comes to our tools, too many of us ARE the fool.

    Don’t be the Tool Fool!

    Here’s are 10 things about the Tool Fool:
    1. Brags about their tools, but they don’t know how to use them.
    2. Brags about a big budget, but they can’t justify it.
    3. Thinks “tool first” instead of a “needs first”.
    4. Thinks tools fix process.
    5. Thinks tools makes problems easier to solve.
    6. Likes easy but confuses “easy” with “simple”.
    7. Has tools they don’t know they have.
    8. Advocates for tools because fools like company.
    9. Oblivious to they’re most significant risks.
    10. Knows how to use some of their tools but won’t to use them well*.

    The Tool Fool costs the organization more than they know. Tool Fools waste money on tools they don’t need, don’t understand, and/or can’t use. The Tool Fool can convince themselves that their tools will keep them secure when the opposite is true. Worst yet, the Tool Fool’s work has convinced management of the same.

    The Tool Fool has a false sense of security. The Tool Fool makes security worse.

    The Tool Fool is the topic for this Thursday’s (3/4) Security Shit Show with Chris, Evan, and Ryan. Be sure to catch the show LIVE on YouTube at 10pm/2200 CST!

    *This is relevant to a dialog between Senator Wyden (D-OR) and witnesses (Kevin Mandia, Sudhakar Ramakrishna, Brad Smith, and George Kurtz) in the recent open hearing, “Hearing on the Hack of U.S. Networks by a Foreign Adversary” before the U.S. Senate Intelligence Committee (2/23). This particular exchange happens at 1:22:08 in the recording here: https://www.intelligence.senate.gov/hearings/open-hearing-hearing-hack-us-networks-foreign-adversary, and has been transcribed here: https://evanfrancen.com/unsecurity-episode-121-show-notes/
    2 hr 20 min
  • Episode Thirty-Eight - The Tool Fool
    A fool is a person who acts unwisely or imprudently. A Tool Fool is someone who unwisely or imprudently loves tools. They don’t necessarily love the tools they have; they just love tools. The more tools, the better.

    Don’t be offended. We’re all fools from time to time. When it comes to our information security, we do the best we know how. We don’t intentionally act the fool, but when it comes to our tools, too many of us ARE the fool.

    Don’t be the Tool Fool!

    Here’s are 10 things about the Tool Fool:
    1. Brags about their tools, but they don’t know how to use them.
    2. Brags about a big budget, but they can’t justify it.
    3. Thinks “tool first” instead of a “needs first”.
    4. Thinks tools fix process.
    5. Thinks tools makes problems easier to solve.
    6. Likes easy but confuses “easy” with “simple”.
    7. Has tools they don’t know they have.
    8. Advocates for tools because fools like company.
    9. Oblivious to they’re most significant risks.
    10. Knows how to use some of their tools but won’t to use them well*.

    The Tool Fool costs the organization more than they know. Tool Fools waste money on tools they don’t need, don’t understand, and/or can’t use. The Tool Fool can convince themselves that their tools will keep them secure when the opposite is true. Worst yet, the Tool Fool’s work has convinced management of the same.

    The Tool Fool has a false sense of security. The Tool Fool makes security worse.

    The Tool Fool is the topic for this Thursday’s (3/4) Security Shit Show with Chris, Evan, and Ryan. Be sure to catch the show LIVE on YouTube at 10pm/2200 CST!

    *This is relevant to a dialog between Senator Wyden (D-OR) and witnesses (Kevin Mandia, Sudhakar Ramakrishna, Brad Smith, and George Kurtz) in the recent open hearing, “Hearing on the Hack of U.S. Networks by a Foreign Adversary” before the U.S. Senate Intelligence Committee (2/23). This particular exchange happens at 1:22:08 in the recording here: https://www.intelligence.senate.gov/hearings/open-hearing-hearing-hack-us-networks-foreign-adversary, and has been transcribed here: https://evanfrancen.com/unsecurity-episode-121-show-notes/
    1 hr 3 min
  • Episode Thirty-Seven - It's Time...
    That resource we want more of, or less of, the one we want to slow down, speed up, thank, curse, monitor, measure, ignore and obey. All often within the span of the same day.

    The very resource we so often run our lives by, yet waste at every turn. It too, like our digital world is a more abstract concept than the tactile analog world we live in. It too can be captured and tamed for fleeting moments in devices, yet like it’s digital cousin we think we control it, but we are nothing more than custodians of the memories it leaves behind.

    We are not good with time; we’ve had 6,000 years or so to get used to the idea of its passing and the consequences. We used to track it by the moon, nowadays we are ruled by atoms that are accurate to a millisecond every decade.
    So, why should we care?


    We waste so much of it.
    We allow others to dictate our use of it
    Our very existence is tyrannized by it


    We have watched the convergence of our digital world and that of time, and realized the very objects meant to save us are doing nothing more than sucking more and more time from us.

    Like our digital world we need to be better custodians of time (not that it really cares as it marches on no matter what we do) but for our own sanity, stand up, be accountable to time itself.

    Join us for a conversation around time….
    2 hr 14 min
  • Episode Thirty-Six - Timmy is in the well... Nope, that's sodium hydroxide!
    This week we saw an attack against a city water system, in an attempt to poison the drinking water.

    Many of us have been warning about this for years.

    How did this happen?
    It must have been the work of sophisticated nation state attackers, it has to be hard to hack a water treatment plant because you know, people could die if that happened. The people in charge must take extra precautions, and have really good security practices in place to keep our drinking water safe. They must have been unable to prevent or avoid this attack.

    These are all things that we hope would be true, unfortunately the reality of what actually happened is far more disturbing.

    (Channeling my inner security Yoda) Sophisticated this attack was not, difficult to pull off was it not, prevented could have been, security basics lacking they were, practice good they did not.

    What happened was a multitude of failures in requiring and implementing the most basic and foundational of security controls.

    We have reached a point in our technology journey as a society, that we need to pause for one moment and take stock of the giant mess we have created.

    We need to figure out what minimum safety standards are needed for critical infrastructure.

    We need to ask ourselves should the things that can kill us be connected to the internet in the first place?

    Knowing that the security posture of the affected water treatment plant, borders on gross and willful negligence, what should the legal and criminal consequences be for those who made these shit decisions in the first place.

    It's 2021 and computers can kill you, so let's act accordingly.

    We will be discussing this and more tonight on the Security Shit Show, join us for what is guarantied to be a lively discussion, and you never know Chris may do some show and tell as well.
    1 hr 40 min
  • Episode Thirty-Five - The root of all information security industry problems
    Here's a question for you:
    What is at the root of all information security industry problems?

    Oh shit! Talk about an ambiguous question. Yes, but who said ambiguous questions are bad?

    Alright, let's break this down then.

    First, the question assumes there are "problems". Are there? We think so, but...

    - ~942,000 people in the U.S. are gainfully employed in this industry, and most of us are getting paid pretty well. Good paying jobs doesn't seem like a problem to me.
    - Worldwide, the cybersecurity market is valued at $173B. Seems the people selling shit are doing alright, no problem here.
    - Global "cybercrime" losses for 2020 were estimated to be $945B. The crooks DEFINITELY aren't experiencing any problems either!

    So, where are the problems then?

    Simple, look for the people who suffer, the victims.

    They're the ones who get the short end of the stick. They feel the brunt (or symptoms) of the problems. They lose money, they lose businesses, they lose income, they lose peace of mind, they lose time, they lose productivity, they lose their privacy, they lose their innocence (especially kids), and they lose life.

    So, yeah. There are problems!

    One group clearly takes advantage of the other. We'll call them "Profiteers" and "Victims". There's one more group. There's a group of us who are trying to protect Victims from the Profiteers. We stand in the void.

    - Profiteers: Cybersecurity practitioners who don't serve the (potential) victims, companies hocking products that don't serve the (potential) victims, and the crooks who steal outright.
    - Us: Practitioners who stand in between, serving (potential) victims.
    - Victims: Governments, companies, non-profits, schools, everyday people (grandparents, parents, kids, etc.)

    OK, so we've got problems. The masses become victims and feel the result(s) of the problems, the symptoms. Oh shit! The rabbit hole goes deeper.

    We'll stop here, before things get too out of hand.

    We need to save some shit for the Shit Show. Chris, Ryan, and I will take it from here. Maybe we'll get far enough down the rabbit hole, and deep enough into the shit to find some semblance of the "root of all information security industry problems".

    Regardless of how far we make it, it should be entertaining!
    2 hr 25 min
  • Episode Thirty-Four - From the Sublime to the Ridiculous
    There’s been a lot of hand wringing these last few weeks as ALL sorts of folks have woken up to, realized, or started to question their online presence. Their digital world has crumbled around them as they’ve realized not only don’t they own anything they commit to the keyboard, but whatever they do is, controlled by someone else.

    Congratulations you are no longer the master (or mistress) of your own destiny, welcome to the digital world, please get in a queue like a good subservient population and tow the line or else.

    No?

    Then please leave. Leave the digital world behind, after all WE still have all that you were while you WERE here…

    But, you can’t can you?

    Someone somewhere HAS a digital record of you, it’s out of your control, welcome back peasant.

    What IF you could be YOU on a digital medium? How DO you secure AND use it, yet ensure that nobody keeps nicking it? (Stealing for the colonials here)

    THIS is the topic of this evenings Security Shit show with Rachel, Ryan, Evan and I

    IS it possible?

    Does it mandate lead lined boxes?

    Will there be volcano’s?

    IS Cerberus with us?

    Will hiding it under the mattress work?

    OR are we screwed and should simply give it all up as a bad job?
    2 hr

About The Security Shit Show

From the publisher's feed

Information security is mostly a shit show, so we made the Security Shit Show.

This is the place where shit gets real. No filter. Straight talk about shit that ain’t right in the information…