WEBVTT

1
00:00:00.320 --> 00:00:03.200
<v Speaker 1>Hey Carl here, we're on a mission to find new

2
00:00:03.240 --> 00:00:05.919
<v Speaker 1>fans of the show. I mean, where else can you

3
00:00:05.960 --> 00:00:10.240
<v Speaker 1>get real life comedy and horror in one podcast. You

4
00:00:10.279 --> 00:00:13.640
<v Speaker 1>can do your part by leaving us a review on iTunes, Spotify,

5
00:00:13.759 --> 00:00:16.879
<v Speaker 1>or wherever you get Security this week. Also, you can

6
00:00:16.920 --> 00:00:19.399
<v Speaker 1>get an ad free feed by becoming a five dollars

7
00:00:19.399 --> 00:00:22.239
<v Speaker 1>a month patron. Go to Patreon dot Security this week

8
00:00:22.320 --> 00:00:26.160
<v Speaker 1>dot com and sign up, and don't forget Discord. Discord

9
00:00:26.199 --> 00:00:28.839
<v Speaker 1>dot Security this week dot com. Lots of good stuff

10
00:00:28.879 --> 00:00:32.439
<v Speaker 1>happening there. Yeah, I think that's it. So on with

11
00:00:32.560 --> 00:00:33.200
<v Speaker 1>the podcast.

12
00:00:34.159 --> 00:00:36.840
<v Speaker 2>Hey guys, I'm sorry I sound like very white today,

13
00:00:36.880 --> 00:00:39.600
<v Speaker 2>but I've got a cold, so I got some sexy

14
00:00:39.640 --> 00:00:45.759
<v Speaker 2>flam going on. Sorry. So, a drunk staggers into a

15
00:00:45.799 --> 00:00:49.000
<v Speaker 2>Catholic church and sits down in a confession booth and

16
00:00:49.039 --> 00:00:52.439
<v Speaker 2>he says nothing, And the priest you know, is waiting

17
00:00:52.560 --> 00:00:56.280
<v Speaker 2>for something and gives a little coffica, and the guy

18
00:00:56.320 --> 00:00:59.960
<v Speaker 2>still says nothing. He taps on the window, the door

19
00:01:00.119 --> 00:01:03.560
<v Speaker 2>or whatever, and the guy still says nothing. And then

20
00:01:03.560 --> 00:01:06.000
<v Speaker 2>he taps a little bit louder. He knocks a little louder,

21
00:01:06.159 --> 00:01:09.400
<v Speaker 2>and he hears this voice say it's no use. There's

22
00:01:09.439 --> 00:01:11.359
<v Speaker 2>no toilet paper over here either.

23
00:01:19.560 --> 00:01:20.439
<v Speaker 3>I've been to that church.

24
00:01:29.640 --> 00:01:32.359
<v Speaker 2>Welcome back to security this week. I'm Carl Franklin. That's

25
00:01:32.359 --> 00:01:35.280
<v Speaker 2>Patrick Kines and Dwayne Laflotte, and we got a few

26
00:01:35.319 --> 00:01:38.359
<v Speaker 2>stories here. This one Reuter's is reporting I ran linked

27
00:01:38.400 --> 00:01:43.920
<v Speaker 2>hackers breach FBI director's personal email, published photos and documents.

28
00:01:45.400 --> 00:01:49.159
<v Speaker 2>So from the headline, is it published photos and documents

29
00:01:49.200 --> 00:01:53.000
<v Speaker 2>like it breaches those or publishes photos in documents.

30
00:01:53.000 --> 00:01:56.439
<v Speaker 3>I think they published their photo, his photos and documents. Now,

31
00:01:57.840 --> 00:01:59.840
<v Speaker 3>some of this guy, you know, the director of the

32
00:01:59.879 --> 00:02:02.920
<v Speaker 3>FBI's public photos that they put out on purpose, are

33
00:02:02.920 --> 00:02:07.480
<v Speaker 3>more embarrassing than anything I've heard about. So I mean, yeah,

34
00:02:07.519 --> 00:02:11.240
<v Speaker 3>this is news, but it's supposedly there's no government information

35
00:02:11.360 --> 00:02:15.360
<v Speaker 3>in here. So far, there's no confidential information, you know,

36
00:02:15.360 --> 00:02:19.240
<v Speaker 3>other than personal So I haven't seen anything surface that

37
00:02:19.319 --> 00:02:23.159
<v Speaker 3>says and here's the scandal. The scandal is he should

38
00:02:23.159 --> 00:02:25.800
<v Speaker 3>have been better about a security. But we have many

39
00:02:26.120 --> 00:02:29.120
<v Speaker 3>historical figures in politics that have been been fished and

40
00:02:29.159 --> 00:02:30.560
<v Speaker 3>hacked and yeah, the same way.

41
00:02:30.680 --> 00:02:33.159
<v Speaker 2>So it's just an embarrassment play kind of I think.

42
00:02:33.199 --> 00:02:36.680
<v Speaker 3>So again, it's early days, but I would assume this

43
00:02:36.719 --> 00:02:39.439
<v Speaker 3>has been sliced and diced, and there's if there was

44
00:02:39.479 --> 00:02:42.919
<v Speaker 3>a smoking gun, you know, admission of something, we'd see it.

45
00:02:43.360 --> 00:02:45.360
<v Speaker 4>And they say this was an old account, right, it

46
00:02:45.439 --> 00:02:51.360
<v Speaker 4>hadn't been accessed since twenty nineteen. The account credentials were

47
00:02:51.400 --> 00:02:58.439
<v Speaker 4>actually in an old breach. Oh wow, So no MFA. Okay,

48
00:02:58.520 --> 00:03:04.400
<v Speaker 4>that's actually pretty terrib But so the prevailing speculation right

49
00:03:04.439 --> 00:03:07.680
<v Speaker 4>now is, well, at least he's not in law enforcement.

50
00:03:08.520 --> 00:03:15.759
<v Speaker 4>Oh wait, the prevailing speculation is the attackers grabbed these

51
00:03:15.840 --> 00:03:18.400
<v Speaker 4>credentials off of an old breach and finally get around

52
00:03:18.439 --> 00:03:22.280
<v Speaker 4>to credential stuffing them into Gmail and then pulled up.

53
00:03:22.439 --> 00:03:24.919
<v Speaker 3>And it's a Gmail account. And I'll be honest, I

54
00:03:25.120 --> 00:03:28.280
<v Speaker 3>don't share my Gmail account, but there's nothing in it

55
00:03:28.319 --> 00:03:30.280
<v Speaker 3>that I would be of any use to anybody. I

56
00:03:30.280 --> 00:03:32.919
<v Speaker 3>don't use it for anything. There's lots and lots and

57
00:03:32.960 --> 00:03:33.719
<v Speaker 3>lots of spam.

58
00:03:33.919 --> 00:03:35.800
<v Speaker 2>Well, what do you use that's better than or more

59
00:03:35.840 --> 00:03:36.759
<v Speaker 2>secure than Gmail?

60
00:03:37.120 --> 00:03:40.240
<v Speaker 3>I use my corporate account. I don't have a personal line.

61
00:03:40.360 --> 00:03:42.719
<v Speaker 2>But what's the what's the system? Is it? Is it

62
00:03:42.759 --> 00:03:43.919
<v Speaker 2>an outlook system?

63
00:03:44.039 --> 00:03:48.080
<v Speaker 3>Is it a It's it's Microsoft off Microsoft hosted Microsoft, okay,

64
00:03:48.120 --> 00:03:52.199
<v Speaker 3>and guarded by Dwayne I almost thought he wasn't going

65
00:03:52.240 --> 00:03:54.360
<v Speaker 3>to say I know, right. He was almost like, I

66
00:03:54.360 --> 00:03:56.800
<v Speaker 3>almost didn't say. I didn't say which Microsoft. It might

67
00:03:56.840 --> 00:03:57.520
<v Speaker 3>be the secret one.

68
00:03:57.599 --> 00:04:00.719
<v Speaker 2>Oh okay, all right, So this is a big story,

69
00:04:00.879 --> 00:04:04.840
<v Speaker 2>so big. My pharmacystem driving through from me, goes Carl.

70
00:04:04.919 --> 00:04:08.599
<v Speaker 2>Did you hear about this Claude code source code appears

71
00:04:08.639 --> 00:04:11.639
<v Speaker 2>to have leaked? And here's what we know. Yeah, this

72
00:04:11.680 --> 00:04:13.400
<v Speaker 2>is from venture Beat, half.

73
00:04:13.280 --> 00:04:16.759
<v Speaker 3>A million lines. What I think the biggest outcome from

74
00:04:16.800 --> 00:04:19.480
<v Speaker 3>this is it's giving a big leg up to the competition.

75
00:04:19.720 --> 00:04:22.720
<v Speaker 3>The competition gets to see what they're doing. You can't

76
00:04:22.959 --> 00:04:25.319
<v Speaker 3>there's no patent on any of this stuff. It's trademark,

77
00:04:25.399 --> 00:04:27.399
<v Speaker 3>but you don't have to change it that much. In hell,

78
00:04:27.639 --> 00:04:29.600
<v Speaker 3>Claude code could probably change it for you enough that

79
00:04:29.639 --> 00:04:35.839
<v Speaker 3>it wouldn't match. So it's a major mistake. It gives

80
00:04:37.639 --> 00:04:39.839
<v Speaker 3>help to those who are trying to catch up to Claude.

81
00:04:39.879 --> 00:04:41.959
<v Speaker 3>It just means they got to run faster. That said,

82
00:04:42.079 --> 00:04:44.839
<v Speaker 3>I think in light of their controversy with the military,

83
00:04:45.120 --> 00:04:47.319
<v Speaker 3>they out came out pretty good. They came out with

84
00:04:47.720 --> 00:04:51.079
<v Speaker 3>rising revenue, and the reaction by open Ai is actually

85
00:04:51.120 --> 00:04:53.639
<v Speaker 3>hurt open Ai more than it's hurt Claude.

86
00:04:53.639 --> 00:04:55.560
<v Speaker 2>Well, they weren't going to play that game. Nope, it's

87
00:04:55.600 --> 00:04:56.160
<v Speaker 2>basically it.

88
00:04:56.360 --> 00:04:59.639
<v Speaker 4>Yeah, and this the way that this quote unquote leaked.

89
00:05:01.600 --> 00:05:04.480
<v Speaker 4>We we look for this type of thing when we're attacking

90
00:05:04.560 --> 00:05:09.000
<v Speaker 4>applications all the time. So they have a you guys

91
00:05:09.040 --> 00:05:10.879
<v Speaker 4>have all like if you've done C plus plus development

92
00:05:10.920 --> 00:05:12.920
<v Speaker 4>and that sort of stuff, or if you've tried to

93
00:05:13.040 --> 00:05:16.920
<v Speaker 4>you know, read. Let's say you're you're trying to debug

94
00:05:17.319 --> 00:05:19.399
<v Speaker 4>a C plus plus program or a driver or whatever.

95
00:05:19.560 --> 00:05:23.199
<v Speaker 4>Good luck, I know, right, there are all these P

96
00:05:23.319 --> 00:05:25.000
<v Speaker 4>two B files and all sorts of things you can

97
00:05:25.000 --> 00:05:27.800
<v Speaker 4>load up so that while that particular code is running,

98
00:05:28.199 --> 00:05:31.480
<v Speaker 4>you know where the code is at. Right, they're debug files,

99
00:05:32.079 --> 00:05:34.639
<v Speaker 4>and there are debug files that you can use to

100
00:05:34.839 --> 00:05:38.199
<v Speaker 4>map the running code to actual code, so you can

101
00:05:38.240 --> 00:05:43.519
<v Speaker 4>debug running live applications. In Java, that's called Java map,

102
00:05:43.600 --> 00:05:46.720
<v Speaker 4>So there's a map file where you can actually see

103
00:05:46.759 --> 00:05:50.399
<v Speaker 4>like comments and code and all sorts of other things.

104
00:05:51.519 --> 00:05:54.040
<v Speaker 4>But it's never supposed to be deployed with the application.

105
00:05:54.959 --> 00:05:57.519
<v Speaker 4>So and we see it all the time where you know,

106
00:05:57.639 --> 00:06:00.319
<v Speaker 4>we'll reach into uh, you know, hosted Java applic cation

107
00:06:00.439 --> 00:06:02.319
<v Speaker 4>in some way and just pull down that map file

108
00:06:02.360 --> 00:06:04.079
<v Speaker 4>and say, okay, cool, now we know how kind of

109
00:06:04.120 --> 00:06:08.040
<v Speaker 4>everything's working on the back end. Yeah, so you got

110
00:06:08.040 --> 00:06:11.279
<v Speaker 4>to be careful with what you actually push into where

111
00:06:11.720 --> 00:06:12.079
<v Speaker 4>all right.

112
00:06:12.680 --> 00:06:14.720
<v Speaker 2>So it's not like you could fork the repo out

113
00:06:14.759 --> 00:06:15.720
<v Speaker 2>and run your own cloud.

114
00:06:15.959 --> 00:06:18.720
<v Speaker 4>No, gosh, I don't know that you'd have the compute

115
00:06:18.800 --> 00:06:24.120
<v Speaker 4>that would be impressive. But the interesting sort of secret

116
00:06:24.199 --> 00:06:29.639
<v Speaker 4>sauce here though, is it defines how claud actually and

117
00:06:29.639 --> 00:06:31.399
<v Speaker 4>one of the things that was the most important thing

118
00:06:31.439 --> 00:06:35.480
<v Speaker 4>to leak was it defines how claud code actually splits

119
00:06:35.480 --> 00:06:39.759
<v Speaker 4>its memory apart. So when you're talking to these lms

120
00:06:41.800 --> 00:06:44.560
<v Speaker 4>as you if you just ask it like information about

121
00:06:44.600 --> 00:06:47.120
<v Speaker 4>the weather or the area whatever, real quick, not a problem.

122
00:06:47.199 --> 00:06:49.120
<v Speaker 4>It has this transient memory. It does a pretty good

123
00:06:49.160 --> 00:06:52.319
<v Speaker 4>job for any of you who are using either GitHub

124
00:06:52.319 --> 00:06:54.959
<v Speaker 4>code or cloud code or whatever. You'll notice over time,

125
00:06:56.040 --> 00:06:59.879
<v Speaker 4>as your conversessions are getting more and more complex, as

126
00:07:00.160 --> 00:07:02.639
<v Speaker 4>it's getting deeper and deeper, as you're talking about multi

127
00:07:02.680 --> 00:07:05.759
<v Speaker 4>layered architecture, et cetera, et cetera, there are times it

128
00:07:05.800 --> 00:07:08.600
<v Speaker 4>loses its mind, right and it's like, oh, I didn't

129
00:07:08.680 --> 00:07:11.879
<v Speaker 4>remember that we were using AWS, and you're like, well.

130
00:07:11.759 --> 00:07:12.199
<v Speaker 2>That's weird.

131
00:07:12.240 --> 00:07:15.000
<v Speaker 4>We talked about it yesterday, but we've had you know,

132
00:07:15.560 --> 00:07:20.800
<v Speaker 4>tons of hours of conversation since then. So Claude code

133
00:07:20.920 --> 00:07:27.079
<v Speaker 4>is actually better at this remembering things than other automated code,

134
00:07:28.360 --> 00:07:34.279
<v Speaker 4>you know, applications and are you know interfaces LMS agents, yeah, agents.

135
00:07:34.279 --> 00:07:37.399
<v Speaker 4>And in this case, what this code revealed was how

136
00:07:37.480 --> 00:07:41.600
<v Speaker 4>they're actually doing that memory management. So they're actually breaking memory.

137
00:07:41.720 --> 00:07:44.079
<v Speaker 4>Usually there's like a memory m D file and people

138
00:07:44.240 --> 00:07:46.800
<v Speaker 4>just you know, the agent's just dump tons of stuff

139
00:07:46.839 --> 00:07:49.000
<v Speaker 4>in there. Everything it remembers is in there, and sometimes

140
00:07:48.800 --> 00:07:51.839
<v Speaker 4>it's it's compressed, and then it extends and it compresses

141
00:07:51.879 --> 00:07:54.959
<v Speaker 4>and extends and that sort of stuff. In Claude code,

142
00:07:54.959 --> 00:07:57.639
<v Speaker 4>what they're actually doing is they have three different memory

143
00:07:57.879 --> 00:08:00.759
<v Speaker 4>layers and one of them is just a pointer, just

144
00:08:00.839 --> 00:08:03.360
<v Speaker 4>a single line for everything it remembers, and it's a

145
00:08:03.360 --> 00:08:06.480
<v Speaker 4>pointer out to another layer. And you can think of

146
00:08:06.519 --> 00:08:12.399
<v Speaker 4>it like they're doing short term, long term instant memory.

147
00:08:13.040 --> 00:08:15.920
<v Speaker 4>So like, oh, well, when we're talking about something, it's

148
00:08:15.959 --> 00:08:17.959
<v Speaker 4>you know, top of mind, right, and then what I'm

149
00:08:17.959 --> 00:08:19.680
<v Speaker 4>going to do is as I compress that, I'm going

150
00:08:19.720 --> 00:08:23.839
<v Speaker 4>to have a pointer out to a longer term memory file, right,

151
00:08:23.920 --> 00:08:25.399
<v Speaker 4>and so on and so forth. So they have this

152
00:08:25.480 --> 00:08:28.720
<v Speaker 4>structured way of managing memory that was giving them a

153
00:08:28.759 --> 00:08:29.480
<v Speaker 4>competitive edge.

154
00:08:29.519 --> 00:08:33.120
<v Speaker 2>It's kind of like skills in GitHub copilot. Gitthub copilot

155
00:08:33.360 --> 00:08:36.120
<v Speaker 2>allows you to have skills which you can, you know,

156
00:08:36.200 --> 00:08:40.759
<v Speaker 2>separate into different columns or whatever, and then those skills

157
00:08:40.759 --> 00:08:44.960
<v Speaker 2>are picked up whenever the keywords are hit yep, yeah,

158
00:08:45.039 --> 00:08:47.080
<v Speaker 2>or whenever the description matches.

159
00:08:46.720 --> 00:08:48.120
<v Speaker 3>And Claude has something similar to that.

160
00:08:48.320 --> 00:08:51.000
<v Speaker 2>Yeah, so it seems similar to that. Yeah, whereas you know,

161
00:08:51.039 --> 00:08:54.840
<v Speaker 2>and then basically anything that goes in that silo gets

162
00:08:54.879 --> 00:08:56.639
<v Speaker 2>updated in that skills MD file.

163
00:08:56.840 --> 00:08:58.840
<v Speaker 3>But it's you know, it's some of their secret sauce.

164
00:08:58.879 --> 00:09:01.120
<v Speaker 3>It's not everything. It's not the game.

165
00:09:01.519 --> 00:09:03.960
<v Speaker 4>It's not like somebody downloaded the entire model in huzza.

166
00:09:04.120 --> 00:09:06.279
<v Speaker 4>Now they're running right clawed at home.

167
00:09:06.600 --> 00:09:09.879
<v Speaker 3>And if this is, if this, if we start seeing

168
00:09:09.960 --> 00:09:13.360
<v Speaker 3>this functionality show up in other models, then it just

169
00:09:13.399 --> 00:09:16.559
<v Speaker 3>shows that Claud's operating at another level. Yeah, okay, that

170
00:09:16.600 --> 00:09:18.799
<v Speaker 3>they deserve to be one of the top two, you know,

171
00:09:18.919 --> 00:09:19.679
<v Speaker 3>frontier models.

172
00:09:19.679 --> 00:09:22.200
<v Speaker 2>All right, So this next story is really cool, and

173
00:09:22.240 --> 00:09:25.000
<v Speaker 2>I know Dwayne's gonna really love this. I love these

174
00:09:25.039 --> 00:09:25.840
<v Speaker 2>types of stories.

175
00:09:25.919 --> 00:09:27.759
<v Speaker 3>I thought this was going to be the topic.

176
00:09:28.279 --> 00:09:30.639
<v Speaker 2>Yeah, I thought so too, because we talked about it

177
00:09:30.679 --> 00:09:34.360
<v Speaker 2>before row Hammer. So new roe Hammer attacks get complete

178
00:09:34.399 --> 00:09:39.759
<v Speaker 2>control of machines running en video GPUs. I remember row

179
00:09:39.799 --> 00:09:44.879
<v Speaker 2>Hammer was one of these things that looked at memory

180
00:09:45.279 --> 00:09:48.279
<v Speaker 2>next to the memory bank that you were on because

181
00:09:48.320 --> 00:09:52.159
<v Speaker 2>it overheated a bit or something like that. It was

182
00:09:52.639 --> 00:09:55.080
<v Speaker 2>the perfect side what do you call it? A side

183
00:09:55.120 --> 00:09:55.679
<v Speaker 2>chain attack?

184
00:09:55.960 --> 00:09:57.080
<v Speaker 4>Side channel? Side channel?

185
00:09:57.159 --> 00:09:59.840
<v Speaker 2>Yeah, side channel. Wow? So what happened here?

186
00:10:00.360 --> 00:10:03.639
<v Speaker 4>So researchers were like, hey, roe Hammer was really kind

187
00:10:03.639 --> 00:10:06.039
<v Speaker 4>of cool, right, that was fun. We listened to security

188
00:10:06.039 --> 00:10:09.879
<v Speaker 4>this week and we think row Hammer's awesome. What if

189
00:10:10.240 --> 00:10:14.720
<v Speaker 4>we could get row Hammer to work on other CPUs,

190
00:10:14.799 --> 00:10:19.080
<v Speaker 4>like maybe GPUs. Right, So if I take a graphics

191
00:10:19.080 --> 00:10:24.399
<v Speaker 4>processing unit, which is it's a CPU just specialized, right,

192
00:10:25.120 --> 00:10:29.039
<v Speaker 4>can I not only manipulate it in a side channel

193
00:10:29.080 --> 00:10:33.080
<v Speaker 4>attack by heating up bits and corrupting bits of memory

194
00:10:33.120 --> 00:10:35.200
<v Speaker 4>and that sort of stuff, but can I do it

195
00:10:35.279 --> 00:10:36.440
<v Speaker 4>in some interesting way?

196
00:10:36.879 --> 00:10:37.039
<v Speaker 2>Right?

197
00:10:37.080 --> 00:10:38.879
<v Speaker 4>Can I do it so I can gain access to

198
00:10:38.919 --> 00:10:41.960
<v Speaker 4>the system. What they were able to do here is

199
00:10:42.519 --> 00:10:49.039
<v Speaker 4>modeling it after the original row Hammer is manipulate the

200
00:10:49.039 --> 00:10:53.159
<v Speaker 4>The RTX you know attack is an RTX attack against

201
00:10:53.240 --> 00:10:57.399
<v Speaker 4>the Nvidia cards. Manipulate it to actually do the same thing,

202
00:10:57.519 --> 00:11:00.799
<v Speaker 4>kind of corrupt memory, flipping bits that's where stuff. But

203
00:11:00.919 --> 00:11:03.519
<v Speaker 4>they did it not so it just crashed. They actually

204
00:11:03.559 --> 00:11:09.159
<v Speaker 4>could infect paging memory that then goes out to the driver.

205
00:11:09.679 --> 00:11:13.039
<v Speaker 4>Oh for the video driver for your computer. Wow, the

206
00:11:13.120 --> 00:11:15.759
<v Speaker 4>video driver, as we all know, is running at like

207
00:11:15.799 --> 00:11:18.840
<v Speaker 4>the highest level privilege. Right, So at this point they

208
00:11:18.919 --> 00:11:24.120
<v Speaker 4>now have and there are two examples of this, they

209
00:11:24.159 --> 00:11:26.919
<v Speaker 4>now have the ability to get a root level shell

210
00:11:28.960 --> 00:11:34.000
<v Speaker 4>on a system by manipulating the bits and using this architecture,

211
00:11:34.000 --> 00:11:34.919
<v Speaker 4>which is really kind of cool.

212
00:11:35.039 --> 00:11:38.000
<v Speaker 3>What this kind of attack reminds me is that, you know,

213
00:11:38.000 --> 00:11:43.279
<v Speaker 3>in twenty fourteen they first demonstrated a repeated like hammering attack.

214
00:11:44.200 --> 00:11:47.279
<v Speaker 3>There was no AI to aid with that, right, And

215
00:11:47.399 --> 00:11:49.519
<v Speaker 3>this is a you'll notice that in this story I

216
00:11:50.000 --> 00:11:52.440
<v Speaker 3>didn't see any reference to and they used AI to

217
00:11:52.480 --> 00:11:56.120
<v Speaker 3>figure it out. This is creative humans looking at a

218
00:11:56.120 --> 00:11:57.759
<v Speaker 3>system and saying, I wonder what I can do with that.

219
00:11:58.440 --> 00:12:00.840
<v Speaker 3>And so it's I think these are advanced attacks are

220
00:12:00.840 --> 00:12:02.720
<v Speaker 3>still the domain of people.

221
00:12:03.200 --> 00:12:06.720
<v Speaker 4>Yeah, I agree in some ways and in some ways not.

222
00:12:06.799 --> 00:12:09.720
<v Speaker 4>I think you're going to start to see research agents

223
00:12:09.759 --> 00:12:12.639
<v Speaker 4>get really really good at understanding Oh okay, this is

224
00:12:12.679 --> 00:12:16.559
<v Speaker 4>the physical architecture, right, and how do we manipulate that

225
00:12:16.600 --> 00:12:20.600
<v Speaker 4>physical architecture to affect the software layer, because in this

226
00:12:20.639 --> 00:12:23.399
<v Speaker 4>case it's it's very similar. Like you know, you might say, well,

227
00:12:23.399 --> 00:12:25.919
<v Speaker 4>how do I fix this right right now that now

228
00:12:25.960 --> 00:12:28.360
<v Speaker 4>that somebody can get something to run on my computer

229
00:12:28.360 --> 00:12:30.919
<v Speaker 4>that's going to get a you know, a highly privileged shell,

230
00:12:31.039 --> 00:12:33.320
<v Speaker 4>how do I fix this? And and the same thing

231
00:12:33.360 --> 00:12:37.840
<v Speaker 4>with CPUs. It's a well from the architecture hardware architecture stance,

232
00:12:38.159 --> 00:12:43.480
<v Speaker 4>you can't or you looks the way the hardware architecture works,

233
00:12:43.639 --> 00:12:46.879
<v Speaker 4>right and how it's late literally laid out, and how

234
00:12:46.879 --> 00:12:50.000
<v Speaker 4>the chips are laid out. But from the software side,

235
00:12:50.320 --> 00:12:52.600
<v Speaker 4>you could say, well, we'll invent a new driver that

236
00:12:52.639 --> 00:12:55.320
<v Speaker 4>actually double checks paging memory or double checks whatever, right,

237
00:12:55.440 --> 00:12:57.320
<v Speaker 4>so there are ways there.

238
00:12:57.399 --> 00:12:59.000
<v Speaker 2>It's going to slow everything down, though.

239
00:12:59.039 --> 00:13:02.000
<v Speaker 4>Yeah, exactly, there will be updates to drivers that will

240
00:13:02.320 --> 00:13:06.480
<v Speaker 4>mitigate this. Luckily, it was researchers that found this, so

241
00:13:07.000 --> 00:13:09.720
<v Speaker 4>you know, it's an interesting find. I love side channel attacks.

242
00:13:09.720 --> 00:13:12.159
<v Speaker 4>I'm glad you know we incorporated in the show.

243
00:13:12.200 --> 00:13:15.559
<v Speaker 2>But here's the real question, which is how luckily am

244
00:13:15.600 --> 00:13:18.080
<v Speaker 2>I to get infected with something that's going to do

245
00:13:18.159 --> 00:13:18.559
<v Speaker 2>that to me.

246
00:13:18.840 --> 00:13:21.240
<v Speaker 3>Well, and what kind of access to you know, you

247
00:13:21.279 --> 00:13:23.120
<v Speaker 3>can't do this over the internet. You have got to

248
00:13:23.120 --> 00:13:25.840
<v Speaker 3>be on the system, I assume.

249
00:13:26.080 --> 00:13:28.360
<v Speaker 4>So, yeah, you do have to be on the system.

250
00:13:28.399 --> 00:13:30.519
<v Speaker 4>This is think of this more like a privesque than

251
00:13:31.320 --> 00:13:34.440
<v Speaker 4>a remote exploit. Okay, right, so if you're on Box

252
00:13:34.799 --> 00:13:37.559
<v Speaker 4>and it's reasonably hardened, this might be a way that

253
00:13:37.639 --> 00:13:41.559
<v Speaker 4>I'd call a command and then exploit the GPU to

254
00:13:41.639 --> 00:13:43.440
<v Speaker 4>then give root level access to that command.

255
00:13:43.559 --> 00:13:45.159
<v Speaker 3>Extreme living off the land.

256
00:13:45.120 --> 00:13:47.279
<v Speaker 4>Yeah, so it's it's very much this is a This

257
00:13:47.360 --> 00:13:49.440
<v Speaker 4>is more a privesque than a remote exploit.

258
00:13:49.559 --> 00:13:54.159
<v Speaker 3>This is like eating crickets. How is this like eating crickets? Well,

259
00:13:54.360 --> 00:13:56.559
<v Speaker 3>Extreme living off the land? You can't find anywhere.

260
00:13:56.559 --> 00:13:58.639
<v Speaker 4>Oh my god, I see what you did there?

261
00:13:58.919 --> 00:14:01.679
<v Speaker 2>I see are you watching Survivor again?

262
00:14:01.840 --> 00:14:02.879
<v Speaker 3>Can't find any squirrels?

263
00:14:02.919 --> 00:14:04.720
<v Speaker 4>So yeah, I see what you did there. I wish

264
00:14:04.720 --> 00:14:07.360
<v Speaker 4>you didn't, but I see. Thank you for that.

265
00:14:07.480 --> 00:14:10.120
<v Speaker 2>Patrick's kind of a sleep would go on Survivor and win.

266
00:14:11.519 --> 00:14:13.639
<v Speaker 4>Yes, I would say like the likelihood of this is

267
00:14:13.679 --> 00:14:18.200
<v Speaker 4>extremely low. You know, first off, if you're running a

268
00:14:18.240 --> 00:14:22.240
<v Speaker 4>hardened PC where they can't get they the attackers can't

269
00:14:22.240 --> 00:14:28.120
<v Speaker 4>get an administrative shell. You probably didn't get infected anyways, right,

270
00:14:28.159 --> 00:14:30.200
<v Speaker 4>because you're very careful with what you're doing. You're very

271
00:14:30.200 --> 00:14:32.840
<v Speaker 4>careful with your architecture. So most home users, if they're

272
00:14:32.840 --> 00:14:35.919
<v Speaker 4>gonna if they run something that exploits their computer, the

273
00:14:36.039 --> 00:14:38.480
<v Speaker 4>chances of them going, oh, now we need a side

274
00:14:38.559 --> 00:14:40.360
<v Speaker 4>channel attack on there is probably low.

275
00:14:40.720 --> 00:14:41.440
<v Speaker 2>Yeah.

276
00:14:41.519 --> 00:14:43.679
<v Speaker 4>Yeah, so just be careful, you know, be careful of

277
00:14:43.720 --> 00:14:46.600
<v Speaker 4>the normal stuff. In this particular case, that's.

278
00:14:46.399 --> 00:14:48.519
<v Speaker 3>Like standing in the living room and saying, can I

279
00:14:48.559 --> 00:14:50.600
<v Speaker 3>get into the kitchen through the bathroom window?

280
00:14:50.919 --> 00:14:54.240
<v Speaker 4>Mm hmmm yeah, and you're like why, I mean, I

281
00:14:54.279 --> 00:14:57.080
<v Speaker 4>probably could, but who cares? Right, Yeah, because that's where

282
00:14:57.080 --> 00:14:57.720
<v Speaker 4>the crickets are.

283
00:14:58.000 --> 00:14:58.799
<v Speaker 2>Yeah.

284
00:14:58.840 --> 00:15:01.279
<v Speaker 4>So, like I said, it's an interesting attack. I love

285
00:15:01.320 --> 00:15:06.080
<v Speaker 4>these type attacks, just you know, physical hardware causing bit flipping.

286
00:15:06.519 --> 00:15:06.919
<v Speaker 2>Yeah.

287
00:15:06.960 --> 00:15:09.519
<v Speaker 3>Well, it's the thinking outside the box. It's the like,

288
00:15:09.960 --> 00:15:11.519
<v Speaker 3>oh my god, well, how did they think of this?

289
00:15:11.919 --> 00:15:14.200
<v Speaker 4>Yeah, that's so cool. In this case, I mean, how

290
00:15:14.200 --> 00:15:16.440
<v Speaker 4>did they think of this? They probably went, hm, roe

291
00:15:16.440 --> 00:15:20.440
<v Speaker 4>Hammer was neat, right, could we do it somewhere else?

292
00:15:20.519 --> 00:15:21.240
<v Speaker 2>And yeah you can.

293
00:15:21.480 --> 00:15:24.600
<v Speaker 3>So you're saying the suspect is someone who likes roe Hammer.

294
00:15:24.759 --> 00:15:28.919
<v Speaker 4>Hmmm, I know, right, huh weird. Time to go, boys,

295
00:15:29.039 --> 00:15:29.440
<v Speaker 4>Time to go.

296
00:15:31.000 --> 00:15:34.720
<v Speaker 2>If we only knew someone like that. Okay, so this

297
00:15:34.799 --> 00:15:38.600
<v Speaker 2>is a good one, not a good one. Adobe data

298
00:15:38.639 --> 00:15:43.639
<v Speaker 2>breach thirteen millions support tickets, employee records, and bug reports

299
00:15:43.759 --> 00:15:48.960
<v Speaker 2>allegedly exposed by hacker mister Raccoon, not the mister raccoon.

300
00:15:49.360 --> 00:15:51.120
<v Speaker 3>And this could be a gift that keeps on giving

301
00:15:51.120 --> 00:15:54.639
<v Speaker 3>because you know, bug reports can also be vulnerabilities.

302
00:15:54.840 --> 00:15:58.759
<v Speaker 4>Right, yikes, yeah, I mean this, this is a time,

303
00:15:59.000 --> 00:16:02.279
<v Speaker 4>This is a this is a tip as old as time. Right, gosh,

304
00:16:02.320 --> 00:16:03.960
<v Speaker 4>how did this or as old as Adobe at least?

305
00:16:04.000 --> 00:16:04.159
<v Speaker 2>I know?

306
00:16:04.240 --> 00:16:05.360
<v Speaker 3>Right, how did this? Well?

307
00:16:05.600 --> 00:16:07.759
<v Speaker 4>You know, it's funny you say that. Uh, they were

308
00:16:07.960 --> 00:16:11.559
<v Speaker 4>for years. My team was always like not today, Adobe,

309
00:16:11.679 --> 00:16:13.759
<v Speaker 4>Like we're like here. Every time it was like you

310
00:16:13.799 --> 00:16:17.480
<v Speaker 4>need to update Adobe, We're like, huzzah, no, that's definitely Russia.

311
00:16:17.720 --> 00:16:20.840
<v Speaker 2>My browsers shows pdf. I was just fine. I do

312
00:16:20.919 --> 00:16:24.840
<v Speaker 2>not need your Acrobat reader. Do you remember going Away?

313
00:16:24.879 --> 00:16:27.799
<v Speaker 2>Do you guys remember Flash? I mean ye, yeah, you

314
00:16:27.840 --> 00:16:31.159
<v Speaker 2>were updating that player constantly. People just keep clicking yes,

315
00:16:31.840 --> 00:16:34.159
<v Speaker 2>no matter what pop time, and every time it installed

316
00:16:34.200 --> 00:16:35.240
<v Speaker 2>new malware.

317
00:16:37.240 --> 00:16:41.200
<v Speaker 4>Sometimes for Adobe, sometimes for other people. You know, who knew.

318
00:16:42.279 --> 00:16:46.399
<v Speaker 4>So this is this is an initial footholder saying from

319
00:16:46.440 --> 00:16:49.679
<v Speaker 4>the attacker and mister Raccoon sent a militia's email to

320
00:16:49.720 --> 00:16:50.639
<v Speaker 4>a support employee.

321
00:16:50.799 --> 00:16:54.559
<v Speaker 3>The hacker names are getting so much less cool, I know, right, Yeah,

322
00:16:54.639 --> 00:16:56.559
<v Speaker 3>I think that's the story.

323
00:16:57.279 --> 00:17:00.639
<v Speaker 2>Well, I think this is so for sure hacker. When

324
00:17:00.639 --> 00:17:02.919
<v Speaker 2>he was young, his name was Rocky.

325
00:17:03.879 --> 00:17:06.039
<v Speaker 3>So now he's missed your record then you know, now

326
00:17:06.079 --> 00:17:08.559
<v Speaker 3>he's miscud.

327
00:17:11.519 --> 00:17:14.599
<v Speaker 4>Jester was a great name. He's I haven't seen anything

328
00:17:14.599 --> 00:17:18.200
<v Speaker 4>from the Jester in a long time. Yeah, I think

329
00:17:18.200 --> 00:17:22.119
<v Speaker 4>he's he's falling off the face of the planet. But so, yeah,

330
00:17:22.160 --> 00:17:25.119
<v Speaker 4>this is uh, you know, phishing email out to a

331
00:17:25.160 --> 00:17:28.920
<v Speaker 4>support employee who was then conned into installing a rat

332
00:17:29.000 --> 00:17:31.720
<v Speaker 4>remote access trojan and then at that point you have

333
00:17:31.759 --> 00:17:35.720
<v Speaker 4>full control over the employees computer, which means huzza, you

334
00:17:35.759 --> 00:17:38.519
<v Speaker 4>get access to support tickets because you are a support

335
00:17:38.559 --> 00:17:42.200
<v Speaker 4>engineer at this point. So yeah, I don't know if

336
00:17:42.200 --> 00:17:45.480
<v Speaker 4>this is better training for the support engineers. Did did

337
00:17:45.720 --> 00:17:49.440
<v Speaker 4>Did they say whether this was actually uh Adobe supporter

338
00:17:49.519 --> 00:17:51.119
<v Speaker 4>or do they do? We know if they outsource it,

339
00:17:51.599 --> 00:17:53.680
<v Speaker 4>because we've seen those style of attacks quite a bit.

340
00:17:53.759 --> 00:18:00.839
<v Speaker 3>Now, as the outsource stated it just said his support Hmmm, person, if.

341
00:18:00.359 --> 00:18:03.680
<v Speaker 4>I although here, here's what I will tell you. Adobe

342
00:18:03.759 --> 00:18:06.240
<v Speaker 4>at this point has not confirmed that this is a

343
00:18:06.240 --> 00:18:09.160
<v Speaker 4>core system breach. So if this is a third party

344
00:18:09.160 --> 00:18:12.200
<v Speaker 4>support team, you better bet Adobe's going to go Oh,

345
00:18:12.359 --> 00:18:13.079
<v Speaker 4>it wasn't us.

346
00:18:13.240 --> 00:18:14.279
<v Speaker 3>It was true.

347
00:18:14.519 --> 00:18:17.799
<v Speaker 4>It was this third party who had all of our data.

348
00:18:17.839 --> 00:18:19.960
<v Speaker 4>You know, we'll we're going to get rid of them

349
00:18:20.039 --> 00:18:20.839
<v Speaker 4>and get a new Well.

350
00:18:20.920 --> 00:18:22.480
<v Speaker 2>Yeah, this seems like a good time to do a

351
00:18:22.480 --> 00:18:26.640
<v Speaker 2>public service announcement for have I Been Poned? So anytime

352
00:18:26.680 --> 00:18:29.000
<v Speaker 2>there's a massive data breach, or you know, maybe even

353
00:18:29.200 --> 00:18:31.279
<v Speaker 2>every other day, you should go to Have I Been Poned?

354
00:18:31.279 --> 00:18:33.599
<v Speaker 2>Putting your email address and see if it's on the

355
00:18:33.680 --> 00:18:37.839
<v Speaker 2>list of breached accounts. And if it is, it'll tell

356
00:18:37.839 --> 00:18:42.960
<v Speaker 2>you what you know where what website and what a email? Yeah?

357
00:18:43.000 --> 00:18:46.039
<v Speaker 2>What email? And you should change that password right.

358
00:18:46.440 --> 00:18:48.039
<v Speaker 3>And one of the one of the real big tips

359
00:18:48.039 --> 00:18:49.839
<v Speaker 3>here is that if you want to stay in the

360
00:18:49.839 --> 00:18:52.559
<v Speaker 3>good graces of your employer, don't use your work email

361
00:18:52.599 --> 00:18:53.920
<v Speaker 3>for anything other than work.

362
00:18:54.240 --> 00:18:57.480
<v Speaker 2>That's right, all right, Break time, yep, break time. Okay,

363
00:18:57.519 --> 00:18:59.240
<v Speaker 2>we'll take a break. We'll be right back after these

364
00:18:59.319 --> 00:19:05.920
<v Speaker 2>very important sites and we're back it's security this week.

365
00:19:05.960 --> 00:19:08.839
<v Speaker 2>I'm Carl, that's Dwaine, that's Patrick, and we're here for

366
00:19:09.000 --> 00:19:16.079
<v Speaker 2>your informational and educational and entertainmental pleasure. How about that.

367
00:19:16.440 --> 00:19:19.000
<v Speaker 3>So, if there's a if there's a nine point eight

368
00:19:19.880 --> 00:19:23.400
<v Speaker 3>CVSS score, and we've already talked about Adobe, and I

369
00:19:23.599 --> 00:19:26.480
<v Speaker 3>tell you that that Microsoft's not in the news today

370
00:19:26.759 --> 00:19:31.039
<v Speaker 3>for this episode, and WordPress is not in the news,

371
00:19:31.079 --> 00:19:34.519
<v Speaker 3>who could it be? Who's Who's Who's very likely to

372
00:19:34.559 --> 00:19:36.400
<v Speaker 3>have that kind of I don't like to pick on

373
00:19:36.440 --> 00:19:38.920
<v Speaker 3>this company because they have so many products, but they're

374
00:19:39.000 --> 00:19:40.319
<v Speaker 3>really always here.

375
00:19:41.480 --> 00:19:45.839
<v Speaker 4>Cisco, and not the guys who give straws out to McDonald's,

376
00:19:45.839 --> 00:19:47.160
<v Speaker 4>to the other cisca.

377
00:19:48.359 --> 00:19:52.119
<v Speaker 2>So and this Cisco. Their products are not made in America,

378
00:19:52.160 --> 00:19:54.480
<v Speaker 2>by the way, see last week's show.

379
00:19:54.880 --> 00:19:57.160
<v Speaker 4>Yeah, I mean you can't even buy them, can't even

380
00:19:57.200 --> 00:20:01.119
<v Speaker 4>buy them. This one here again, this one's this is

381
00:20:01.200 --> 00:20:04.440
<v Speaker 4>another interesting one. The core issue and I'm going to

382
00:20:04.440 --> 00:20:05.839
<v Speaker 4>read this, I'm going to read this out where the

383
00:20:05.839 --> 00:20:11.279
<v Speaker 4>core issue lies within the password change functionality of the

384
00:20:11.319 --> 00:20:16.559
<v Speaker 4>Cisco IMC software, and that's their integrated management controller. The

385
00:20:16.599 --> 00:20:19.200
<v Speaker 4>CVE is going to be twenty twenty six two hundred

386
00:20:19.839 --> 00:20:21.880
<v Speaker 4>nine to three you'll want to check that out.

387
00:20:22.519 --> 00:20:22.720
<v Speaker 3>Listen.

388
00:20:22.759 --> 00:20:25.000
<v Speaker 4>If you're running Cisco IMC, you're definitely going to want

389
00:20:25.000 --> 00:20:27.200
<v Speaker 4>to patch. Anyways, it's a nine point eight. It's a

390
00:20:27.240 --> 00:20:28.000
<v Speaker 4>nine point eight, so.

391
00:20:28.799 --> 00:20:33.200
<v Speaker 2>And it lets hackers bypass off and admins urged to update.

392
00:20:32.960 --> 00:20:37.440
<v Speaker 4>And get in as admin. So, due to an improper

393
00:20:37.599 --> 00:20:44.799
<v Speaker 4>processing of incoming password change requests, a remote, unauthenticated attacker

394
00:20:45.519 --> 00:20:48.799
<v Speaker 4>can exploit this flaw by sending a specially crafted HTP

395
00:20:48.920 --> 00:20:53.599
<v Speaker 4>request to a vulnerable device. Successfully exploitation allows the attacker

396
00:20:53.599 --> 00:20:57.079
<v Speaker 4>to bypass standard authentication mechanisms and modify the password of

397
00:20:57.119 --> 00:21:00.319
<v Speaker 4>an existing user. So let me break that down. That's

398
00:21:00.359 --> 00:21:07.359
<v Speaker 4>you're saying. The change password page doesn't actually verify the

399
00:21:07.400 --> 00:21:11.480
<v Speaker 4>old password, just changes it. So I say, I want

400
00:21:11.480 --> 00:21:13.839
<v Speaker 4>to be admint. I forgot my password, and it says

401
00:21:13.839 --> 00:21:15.720
<v Speaker 4>what's the old password? And I say I don't know,

402
00:21:15.759 --> 00:21:17.680
<v Speaker 4>and say what's the new password? And it's let me

403
00:21:17.759 --> 00:21:21.000
<v Speaker 4>in and it just changes it. Wow, that doesn't that

404
00:21:21.119 --> 00:21:24.559
<v Speaker 4>sounds like nobody qate that. No, it's so helpful. Nobody

405
00:21:24.559 --> 00:21:27.160
<v Speaker 4>even looked at that, So that makes it I don't know,

406
00:21:27.200 --> 00:21:27.519
<v Speaker 4>you know what.

407
00:21:27.559 --> 00:21:30.079
<v Speaker 2>I bet it was these infuriating I bet it was

408
00:21:30.079 --> 00:21:31.079
<v Speaker 2>a feature request.

409
00:21:31.599 --> 00:21:34.440
<v Speaker 3>It was developed in Canada. They're very polite up there.

410
00:21:34.160 --> 00:21:37.880
<v Speaker 4>They're they're like, hey, what if they don't remember their password? Eh, hey,

411
00:21:38.000 --> 00:21:40.200
<v Speaker 4>just like you know, don't even look at it, just

412
00:21:40.240 --> 00:21:41.279
<v Speaker 4>give them the new password.

413
00:21:42.640 --> 00:21:45.000
<v Speaker 3>I don't know that it's built in Canadian. I'm sorry.

414
00:21:45.079 --> 00:21:48.640
<v Speaker 4>That's I I to all my Canadian friends. I first off,

415
00:21:48.680 --> 00:21:52.200
<v Speaker 4>I apologize at the accent. Secondly, my family's from Canada,

416
00:21:52.279 --> 00:21:53.119
<v Speaker 4>so I can pick on them.

417
00:21:53.240 --> 00:21:57.400
<v Speaker 2>It's fine. Okay, So, yeah, this is bad? Is there

418
00:21:57.440 --> 00:21:57.839
<v Speaker 2>a patch?

419
00:21:58.400 --> 00:21:58.640
<v Speaker 4>Yeah?

420
00:22:01.759 --> 00:22:01.920
<v Speaker 2>Bad?

421
00:22:02.039 --> 00:22:03.480
<v Speaker 3>Understatement of the episode?

422
00:22:04.079 --> 00:22:04.720
<v Speaker 2>Is there patch?

423
00:22:05.440 --> 00:22:07.400
<v Speaker 4>The patch has hit it with a hammer, I believe.

424
00:22:08.160 --> 00:22:12.119
<v Speaker 4>I'm pretty sure that's the that's the patch. I didn't

425
00:22:12.160 --> 00:22:13.160
<v Speaker 4>see anything in here.

426
00:22:13.039 --> 00:22:17.920
<v Speaker 3>In mitigation Admin's urge to update is in the is in.

427
00:22:17.839 --> 00:22:19.599
<v Speaker 4>The Yeah there you go? Okay, all right, so there

428
00:22:19.640 --> 00:22:23.160
<v Speaker 4>is a patch active exploitation. Cisco has found there is

429
00:22:23.240 --> 00:22:26.480
<v Speaker 4>no active exploitation in the public, however, go patch.

430
00:22:27.319 --> 00:22:30.039
<v Speaker 2>Well, our old friend Android is in the news again.

431
00:22:30.279 --> 00:22:34.160
<v Speaker 2>Android Alert fifty Google Play apps linked to no voice

432
00:22:34.440 --> 00:22:39.640
<v Speaker 2>malware reached two point three million downloads. No voice malware.

433
00:22:40.119 --> 00:22:41.960
<v Speaker 2>That's like me, that's what I have right now. I

434
00:22:42.000 --> 00:22:43.279
<v Speaker 2>have no voice malware.

435
00:22:45.960 --> 00:22:49.160
<v Speaker 4>This you know, we always talk about like, oh, there's

436
00:22:49.200 --> 00:22:51.839
<v Speaker 4>malware for Android, there's malware for Android, and then you know,

437
00:22:52.039 --> 00:22:54.160
<v Speaker 4>it comes out that it's like, oh, well, it was

438
00:22:54.200 --> 00:22:56.559
<v Speaker 4>a sideloaded app. And for those of you haven't been listening,

439
00:22:56.720 --> 00:22:59.599
<v Speaker 4>sideloaded apps are like it was never submitted to the

440
00:22:59.640 --> 00:23:02.359
<v Speaker 4>play Store and somebody had to hack their own phone

441
00:23:02.400 --> 00:23:04.680
<v Speaker 4>and then root it so that they could drag the

442
00:23:04.720 --> 00:23:06.759
<v Speaker 4>APK over and blah blah. And of course if you're

443
00:23:06.839 --> 00:23:09.079
<v Speaker 4>running code that's never been checked by anybody, yeah, you

444
00:23:09.119 --> 00:23:12.759
<v Speaker 4>know you're gonna get hacked. In this case, though, this

445
00:23:12.960 --> 00:23:16.880
<v Speaker 4>was not sideloaded really yeah yeah. While many malware targets

446
00:23:16.880 --> 00:23:21.279
<v Speaker 4>Androids usually often come from sideloaded apps or installed app downloaded,

447
00:23:21.319 --> 00:23:24.319
<v Speaker 4>this now instead compromised Google play Store.

448
00:23:24.599 --> 00:23:25.960
<v Speaker 2>Yeah yeah.

449
00:23:26.039 --> 00:23:30.759
<v Speaker 4>Good by building and deploying harmless looking games and cleaners

450
00:23:30.920 --> 00:23:34.519
<v Speaker 4>in image galleries and the Google play Store, the attacker

451
00:23:34.599 --> 00:23:38.720
<v Speaker 4>was able to hide malware behavior during Google's code review

452
00:23:39.240 --> 00:23:42.519
<v Speaker 4>until after somebody had installed it. And we've talked about

453
00:23:42.559 --> 00:23:45.160
<v Speaker 4>this where that's a black guy. Yeah, where you go

454
00:23:45.240 --> 00:23:48.960
<v Speaker 4>and you write up an innocuous piece of software, right right,

455
00:23:49.000 --> 00:23:52.680
<v Speaker 4>it's an app that does something useful or nothing, and yeah,

456
00:23:52.799 --> 00:23:55.319
<v Speaker 4>or well you want to get people to download it, right,

457
00:23:55.440 --> 00:23:58.000
<v Speaker 4>So right, it has to do something useful. Let's say

458
00:23:58.039 --> 00:24:02.240
<v Speaker 4>it's your open claw monitoring app for your entry. Right,

459
00:24:02.839 --> 00:24:05.000
<v Speaker 4>there's there's a lot of people who would downloind that

460
00:24:05.039 --> 00:24:08.599
<v Speaker 4>lottery number pickers. Yeah, yeah, something along those lines. Yeah,

461
00:24:08.680 --> 00:24:12.400
<v Speaker 4>And then in and update, because updates you can push

462
00:24:12.440 --> 00:24:15.279
<v Speaker 4>directly down, right, I can have the app update itself,

463
00:24:15.559 --> 00:24:17.319
<v Speaker 4>and Google place Work can look at updates and that

464
00:24:17.359 --> 00:24:19.440
<v Speaker 4>sort of stuff. But if I obfuscate it, it's much

465
00:24:19.640 --> 00:24:23.680
<v Speaker 4>it goes under less rigorous, let's put it that way.

466
00:24:23.880 --> 00:24:27.880
<v Speaker 4>So yeah, here we say be careful what you download

467
00:24:27.880 --> 00:24:28.880
<v Speaker 4>from the play Store as well.

468
00:24:29.680 --> 00:24:33.079
<v Speaker 2>Unfortunately, and by that we don't mean that you should

469
00:24:33.599 --> 00:24:36.839
<v Speaker 2>practice ESP and know what's coming down in that update.

470
00:24:36.960 --> 00:24:39.640
<v Speaker 2>And so there is no way to be careful, just

471
00:24:40.440 --> 00:24:40.680
<v Speaker 2>you know.

472
00:24:40.960 --> 00:24:44.240
<v Speaker 4>So here's what I do, and I'm going to anytime,

473
00:24:44.319 --> 00:24:47.039
<v Speaker 4>and I've I've trained my kids to do the same

474
00:24:47.079 --> 00:24:51.440
<v Speaker 4>thing painfully, like usually locking them out of their devices

475
00:24:51.559 --> 00:24:56.440
<v Speaker 4>until and and having me approve apps until they know

476
00:24:56.559 --> 00:25:00.960
<v Speaker 4>how to do this. So, like on your device, when

477
00:25:01.000 --> 00:25:03.240
<v Speaker 4>you go to download something from the play Store or

478
00:25:03.279 --> 00:25:06.720
<v Speaker 4>you go to download something from the Apple Store, if

479
00:25:06.759 --> 00:25:10.920
<v Speaker 4>you scroll down, first off, there are two different things.

480
00:25:11.000 --> 00:25:13.920
<v Speaker 4>I look at one, who's the developer, and there's usually

481
00:25:13.960 --> 00:25:16.640
<v Speaker 4>a link for the developer. There's usually more information what

482
00:25:16.720 --> 00:25:18.960
<v Speaker 4>other apps have they put out there? How reliable are

483
00:25:18.960 --> 00:25:19.279
<v Speaker 4>they that.

484
00:25:19.240 --> 00:25:19.799
<v Speaker 2>Sort of stuff.

485
00:25:20.319 --> 00:25:22.680
<v Speaker 4>If it's a developer you've never heard of and this

486
00:25:22.759 --> 00:25:27.160
<v Speaker 4>is their only app, maybe don't download it, right. And

487
00:25:27.240 --> 00:25:29.119
<v Speaker 4>I hate to say that, because I'm sure there's tons

488
00:25:29.119 --> 00:25:32.279
<v Speaker 4>of you know, new developers out there who really want

489
00:25:32.279 --> 00:25:34.160
<v Speaker 4>to apply this, you know, who really want to put

490
00:25:34.160 --> 00:25:37.079
<v Speaker 4>together an app to help people. But if I see

491
00:25:37.079 --> 00:25:38.440
<v Speaker 4>that they only have one app.

492
00:25:38.359 --> 00:25:41.400
<v Speaker 2>Also the developer's name, yes, can can be it, you know,

493
00:25:41.480 --> 00:25:46.440
<v Speaker 2>if it's mister cool wears yes, for example, Yeah, as

494
00:25:46.440 --> 00:25:48.359
<v Speaker 2>opposed to you like Dell support, where you're.

495
00:25:48.240 --> 00:25:52.119
<v Speaker 4>Like, okay, yeah, although I might not download their stuff either.

496
00:25:52.559 --> 00:25:57.079
<v Speaker 4>But secondly, secondly, okay, that's one number two. Each of

497
00:25:57.119 --> 00:26:03.359
<v Speaker 4>these apps is required to request the types of rights

498
00:26:03.359 --> 00:26:05.480
<v Speaker 4>the app needs. I don't know why I'm drawing a

499
00:26:05.480 --> 00:26:11.359
<v Speaker 4>blank on what that's called. It's a permissions. Yeah, it's

500
00:26:11.359 --> 00:26:14.720
<v Speaker 4>not permitted. It is permissions, but there's a requirements or

501
00:26:14.920 --> 00:26:17.480
<v Speaker 4>now all right, discord, tell me what it is at

502
00:26:17.519 --> 00:26:19.759
<v Speaker 4>some point. But there's there's like there's a term for it.

503
00:26:19.799 --> 00:26:23.119
<v Speaker 4>There's where when you submit your app, your app has

504
00:26:23.200 --> 00:26:27.000
<v Speaker 4>to ask for these things. Yeah, and it has to

505
00:26:27.039 --> 00:26:30.079
<v Speaker 4>be displayed. Right, So there's a file that says the

506
00:26:30.119 --> 00:26:33.000
<v Speaker 4>type of permissions you need and if those permissions are egregious,

507
00:26:33.160 --> 00:26:36.440
<v Speaker 4>like oh, this is a screenshot app, but I need

508
00:26:36.519 --> 00:26:39.640
<v Speaker 4>access to your geolocation and they need your name and

509
00:26:39.640 --> 00:26:42.400
<v Speaker 4>I need your contact list and it's so look at

510
00:26:42.440 --> 00:26:44.680
<v Speaker 4>those two right, you should validate those two things. Do

511
00:26:44.720 --> 00:26:47.720
<v Speaker 4>you trust the developer and do you trust the permissions

512
00:26:47.759 --> 00:26:50.240
<v Speaker 4>they need align with what they're saying the app does?

513
00:26:50.480 --> 00:26:52.039
<v Speaker 4>And if you don't, don't download it.

514
00:26:52.079 --> 00:26:56.920
<v Speaker 2>And I need to access via UDP server in Ukraine.

515
00:26:59.680 --> 00:27:02.359
<v Speaker 4>So yeah, I you know, that's my recommendation.

516
00:27:02.880 --> 00:27:03.440
<v Speaker 3>I agree.

517
00:27:03.480 --> 00:27:04.160
<v Speaker 2>You know, we won't.

518
00:27:04.240 --> 00:27:08.119
<v Speaker 4>We all don't have you know, cyber esp but there

519
00:27:08.119 --> 00:27:09.359
<v Speaker 4>are some things you can still do.

520
00:27:09.640 --> 00:27:12.400
<v Speaker 2>Very good you heard it hear from Dwayne. Yeah, all right.

521
00:27:12.480 --> 00:27:17.240
<v Speaker 2>The next story weaponizing the Protectors Team PCPs multi stage

522
00:27:17.279 --> 00:27:22.599
<v Speaker 2>supply chain attack on security infrastructure. So this is basically

523
00:27:22.640 --> 00:27:26.559
<v Speaker 2>people that are using tools that security people use like

524
00:27:26.599 --> 00:27:31.920
<v Speaker 2>you guys, and weaponize them to use them against security people.

525
00:27:32.039 --> 00:27:34.359
<v Speaker 3>Yeah, you know, if you leave a shotgun by your

526
00:27:34.400 --> 00:27:37.640
<v Speaker 3>door and a bad guy gets in, they got a shotgun, handy.

527
00:27:38.440 --> 00:27:41.279
<v Speaker 3>If you have these tools on the system, then they

528
00:27:41.279 --> 00:27:43.720
<v Speaker 3>can be used against the system. It's living living off

529
00:27:43.720 --> 00:27:44.319
<v Speaker 3>the land again.

530
00:27:44.640 --> 00:27:48.079
<v Speaker 2>Yeah, So what happened in this particular situation is a

531
00:27:48.119 --> 00:27:50.759
<v Speaker 2>few attacks, right, Yeah, and a lot.

532
00:27:50.599 --> 00:27:53.920
<v Speaker 4>Of these end up being and we've seen we've already

533
00:27:54.000 --> 00:27:59.240
<v Speaker 4>announced some of these, like trivia, like the Aqua security

534
00:27:59.240 --> 00:28:01.680
<v Speaker 4>trivia we talked about last week, right, and that was

535
00:28:01.720 --> 00:28:03.519
<v Speaker 4>a supply chain attack. So this is just a really

536
00:28:03.559 --> 00:28:06.640
<v Speaker 4>good this article is a really good kind of summary

537
00:28:06.680 --> 00:28:08.440
<v Speaker 4>of some of the ones we've talked about, some of

538
00:28:08.480 --> 00:28:10.680
<v Speaker 4>the ones we haven't talked about, just because you're there

539
00:28:10.680 --> 00:28:14.000
<v Speaker 4>are so many different attacks that go on out there,

540
00:28:14.039 --> 00:28:16.200
<v Speaker 4>so we wanted everybody to have kind of access to

541
00:28:16.720 --> 00:28:18.519
<v Speaker 4>what are the what's the state of the art in

542
00:28:18.599 --> 00:28:22.359
<v Speaker 4>these core sort of supply chain attacks, And like I said,

543
00:28:22.759 --> 00:28:26.799
<v Speaker 4>Trivia was one of them. But k I C S.

544
00:28:27.400 --> 00:28:29.839
<v Speaker 4>I don't know if that's pronounced kicks or you know whatever,

545
00:28:30.119 --> 00:28:31.480
<v Speaker 4>guys is whatever.

546
00:28:32.240 --> 00:28:34.640
<v Speaker 3>Yeah, keeping infrastructure is secure code.

547
00:28:34.480 --> 00:28:37.759
<v Speaker 4>Yeah, and light LLLM. So there's a couple of different

548
00:28:38.599 --> 00:28:41.759
<v Speaker 4>you know, open source packages out there that over time

549
00:28:41.880 --> 00:28:43.920
<v Speaker 4>have been exploited in different ways. So One of the

550
00:28:43.920 --> 00:28:45.119
<v Speaker 4>things we want to do is kind of give you

551
00:28:45.160 --> 00:28:47.359
<v Speaker 4>eyes on this and just be careful with and announce

552
00:28:47.440 --> 00:28:49.200
<v Speaker 4>when you download open source projects.

553
00:28:49.839 --> 00:28:53.559
<v Speaker 2>This thing compromised at least sixteen organizations and they're listed

554
00:28:53.720 --> 00:28:56.759
<v Speaker 2>in this article. Yep, my goodness. Yeah.

555
00:28:56.799 --> 00:28:58.200
<v Speaker 4>And some of this was you know, some of these

556
00:28:58.200 --> 00:29:01.319
<v Speaker 4>are exploits we've talked about in the past, like react

557
00:29:01.319 --> 00:29:05.759
<v Speaker 4>to shell. Some of these are new deployment pipeline attacks

558
00:29:06.200 --> 00:29:08.960
<v Speaker 4>like we had talked about last week. So just this

559
00:29:09.039 --> 00:29:10.720
<v Speaker 4>is a good read to go through and be like, hey,

560
00:29:10.759 --> 00:29:12.279
<v Speaker 4>am I using any of these versions?

561
00:29:13.480 --> 00:29:13.680
<v Speaker 2>You know?

562
00:29:13.759 --> 00:29:15.839
<v Speaker 4>If I think some of my like my open aikeys

563
00:29:15.880 --> 00:29:19.039
<v Speaker 4>were compromised through you know, let's say, like you know,

564
00:29:19.079 --> 00:29:21.799
<v Speaker 4>whatever a package I download, maybe I need to rotate

565
00:29:21.839 --> 00:29:22.599
<v Speaker 4>those that's worst.

566
00:29:22.880 --> 00:29:25.279
<v Speaker 2>Hey Dwayne, yeah, I'm going to send you a hundred bucks,

567
00:29:25.400 --> 00:29:28.599
<v Speaker 2>but you have to download Duke to receive it. Do

568
00:29:28.680 --> 00:29:32.599
<v Speaker 2>you see? Go ahead? I'll wait, go ahead, install that.

569
00:29:33.000 --> 00:29:35.440
<v Speaker 4>This is This is usually where I reply and say

570
00:29:35.640 --> 00:29:37.599
<v Speaker 4>I tried to I tried to install it multiple times

571
00:29:37.599 --> 00:29:39.079
<v Speaker 4>and then there's an error, Am I do I have

572
00:29:39.079 --> 00:29:39.799
<v Speaker 4>the right URL?

573
00:29:39.839 --> 00:29:40.319
<v Speaker 2>Here it is?

574
00:29:40.480 --> 00:29:43.119
<v Speaker 4>And then I give them back another RL that they

575
00:29:43.160 --> 00:29:46.599
<v Speaker 4>click on that's fully loaded with a lot of listeners.

576
00:29:46.599 --> 00:29:49.359
<v Speaker 2>All right, So here's the story. A publicly accessible Amazon

577
00:29:49.440 --> 00:29:53.240
<v Speaker 2>hosted storage server allowed anyone with a web browser to

578
00:29:53.240 --> 00:29:56.279
<v Speaker 2>access potentially one hundreds of thousands of people's personal data

579
00:29:56.920 --> 00:30:00.319
<v Speaker 2>without needing a password. This included driver's life since his

580
00:30:00.440 --> 00:30:04.200
<v Speaker 2>passport's another personal information collected by the Duke app. That's

581
00:30:04.279 --> 00:30:08.839
<v Speaker 2>do you see a money transfer service service owned by

582
00:30:08.880 --> 00:30:14.599
<v Speaker 2>Toronto based Dualles Dualles du A l ees And I

583
00:30:14.640 --> 00:30:18.480
<v Speaker 2>don't know why. I'm close in Mexico than Canada Dualles,

584
00:30:18.519 --> 00:30:20.599
<v Speaker 2>but it could be duels. I don't know if you're

585
00:30:20.599 --> 00:30:22.960
<v Speaker 2>in Canada, be duals A.

586
00:30:23.440 --> 00:30:31.079
<v Speaker 4>I guess duels A, So maybe that's is Canadian. It's

587
00:30:31.079 --> 00:30:36.680
<v Speaker 4>a Canadian app duels A duels Actually it says Toronto based,

588
00:30:37.079 --> 00:30:39.000
<v Speaker 4>so maybe I don't know, maybe it is. Maybe it

589
00:30:39.039 --> 00:30:43.519
<v Speaker 4>is dual Okay, So yeah, and this is a money

590
00:30:43.559 --> 00:30:44.400
<v Speaker 4>transfer service.

591
00:30:44.759 --> 00:30:44.880
<v Speaker 3>Uh.

592
00:30:45.400 --> 00:30:48.079
<v Speaker 4>The interesting thing apart it, this is an Amazon hosted

593
00:30:48.480 --> 00:30:51.920
<v Speaker 4>storage server. And this storage server had three hundred and

594
00:30:51.960 --> 00:30:54.680
<v Speaker 4>sixty thousand files Canadian government issue blah blah blah. Right,

595
00:30:54.720 --> 00:30:58.519
<v Speaker 4>lots of information on it. First off, this is an

596
00:30:58.559 --> 00:31:01.359
<v Speaker 4>app and a lot of people, a lot of developers

597
00:31:01.400 --> 00:31:04.799
<v Speaker 4>think there's no way for people to pull keys and

598
00:31:04.920 --> 00:31:07.759
<v Speaker 4>information out of my app, and that, I will tell

599
00:31:07.799 --> 00:31:11.119
<v Speaker 4>you is entirely wrong. It is very easy to take

600
00:31:11.359 --> 00:31:14.119
<v Speaker 4>you know, either you know an APK or whatever, even

601
00:31:14.119 --> 00:31:17.000
<v Speaker 4>an iPhone app, tear it apart and find what keys

602
00:31:17.039 --> 00:31:19.799
<v Speaker 4>you're using to call them back end and find information

603
00:31:19.920 --> 00:31:22.400
<v Speaker 4>like that, right, I mean, heck, you can even just

604
00:31:22.440 --> 00:31:24.440
<v Speaker 4>pass all that data through a proxy and start looking

605
00:31:24.519 --> 00:31:26.839
<v Speaker 4>at the data. So there's there's many different ways for

606
00:31:26.920 --> 00:31:29.400
<v Speaker 4>you to identify what's getting called on the back end.

607
00:31:29.880 --> 00:31:34.000
<v Speaker 4>So this is really more of a story of if

608
00:31:34.039 --> 00:31:36.759
<v Speaker 4>you assume people are going to get access to this data,

609
00:31:36.839 --> 00:31:39.559
<v Speaker 4>so a CP assume people are going to see these files,

610
00:31:39.640 --> 00:31:43.039
<v Speaker 4>assume people you know a lot of time less developers

611
00:31:43.039 --> 00:31:45.720
<v Speaker 4>when we want to hide something, you know, we don't

612
00:31:45.799 --> 00:31:49.960
<v Speaker 4>use obscurity as the only thing, but a lot of

613
00:31:50.079 --> 00:31:53.000
<v Speaker 4>us do use quidd quitted URLs right or s three

614
00:31:53.000 --> 00:31:57.359
<v Speaker 4>buckets that are massive quitted you know spaces. So you're

615
00:31:57.359 --> 00:31:59.400
<v Speaker 4>not going to guess it, you're not going to perforce it, right,

616
00:32:00.000 --> 00:32:02.039
<v Speaker 4>So but for you to assume that nobody's gonna find

617
00:32:02.079 --> 00:32:03.880
<v Speaker 4>it is absurd, right.

618
00:32:03.680 --> 00:32:07.559
<v Speaker 3>Yeah, Security through obscurity is a layer in a multi

619
00:32:07.640 --> 00:32:10.680
<v Speaker 3>layered defense. But it can't be the only thing.

620
00:32:10.799 --> 00:32:14.440
<v Speaker 2>Right right, Yeah, absolutely, Patrick, It's like rolling the windows

621
00:32:14.519 --> 00:32:15.680
<v Speaker 2>up and keeping your car in lock.

622
00:32:16.279 --> 00:32:16.440
<v Speaker 3>Yeah.

623
00:32:16.640 --> 00:32:16.839
<v Speaker 2>Good.

624
00:32:17.319 --> 00:32:21.160
<v Speaker 3>An analogy he recently is we m one tanks don't

625
00:32:21.200 --> 00:32:24.480
<v Speaker 3>rely on their paint color for their security, but we

626
00:32:24.519 --> 00:32:25.440
<v Speaker 3>don't paint a marge.

627
00:32:25.559 --> 00:32:28.279
<v Speaker 4>Yeah right, exactly. Yeah, so there's still a little bit

628
00:32:28.319 --> 00:32:30.680
<v Speaker 4>of obscure in the area. So in this particular case,

629
00:32:30.759 --> 00:32:33.920
<v Speaker 4>like if I can find that that those shared folders

630
00:32:33.960 --> 00:32:37.720
<v Speaker 4>on this hosted server, you should have another layer that

631
00:32:37.759 --> 00:32:40.160
<v Speaker 4>the data should be encrypted. The data should be pulled

632
00:32:40.160 --> 00:32:41.640
<v Speaker 4>off if not needed on that server.

633
00:32:41.799 --> 00:32:43.880
<v Speaker 2>The data like should have an authentication layer.

634
00:32:43.960 --> 00:32:47.640
<v Speaker 4>There should be Yeah, absolutely, there should be other ways

635
00:32:47.640 --> 00:32:50.000
<v Speaker 4>that you're protecting this data other than just this is

636
00:32:50.279 --> 00:32:52.240
<v Speaker 4>you know, a server you hope nobody finds.

637
00:32:52.119 --> 00:32:55.640
<v Speaker 3>Exactly the same as an unencrypted AWOS bucket. Yeah, it's

638
00:32:55.680 --> 00:32:56.519
<v Speaker 3>exactly the same.

639
00:32:56.680 --> 00:32:56.880
<v Speaker 2>You know.

640
00:32:56.920 --> 00:33:00.400
<v Speaker 4>It's funny, that's really It used to be everybody had

641
00:33:00.440 --> 00:33:03.440
<v Speaker 4>these open s three buckets, right, and you could just

642
00:33:03.480 --> 00:33:05.480
<v Speaker 4>find all sorts of cool data, and there were all

643
00:33:05.519 --> 00:33:09.160
<v Speaker 4>sorts of hacker tools to just sort of surf them. Now,

644
00:33:09.359 --> 00:33:11.640
<v Speaker 4>if you want to have an open s three bucket

645
00:33:11.799 --> 00:33:14.960
<v Speaker 4>in Amazon, it's like you got to sign away your

646
00:33:15.000 --> 00:33:20.160
<v Speaker 4>first born. It is almost to approve it to come

647
00:33:20.200 --> 00:33:25.519
<v Speaker 4>to your house. But the interview you yeah, exactly, it's insane,

648
00:33:25.680 --> 00:33:29.119
<v Speaker 4>Like yeah, so, I mean, kudos to Amazon Web Services

649
00:33:29.200 --> 00:33:31.680
<v Speaker 4>for for locking a lot of that stuff down.

650
00:33:32.200 --> 00:33:35.319
<v Speaker 2>Well, but yeah, here's the thing. I have no problem

651
00:33:35.319 --> 00:33:39.839
<v Speaker 2>with buckets that are publicly allowed read access right because

652
00:33:39.839 --> 00:33:41.880
<v Speaker 2>there's just a bunch of files. Go ahead, download all

653
00:33:41.880 --> 00:33:43.720
<v Speaker 2>the files you want, but not going to allow write

654
00:33:43.720 --> 00:33:47.720
<v Speaker 2>access right right, no surre, Yeah, absolutely, yeah.

655
00:33:47.759 --> 00:33:49.440
<v Speaker 4>And it depends on the type of data like if

656
00:33:49.440 --> 00:33:54.200
<v Speaker 4>this is you know, W two's for everybody at you

657
00:33:54.200 --> 00:33:56.599
<v Speaker 4>know IBM, right right, all right, maybe you don't want

658
00:33:56.640 --> 00:33:57.319
<v Speaker 4>read only there.

659
00:33:58.240 --> 00:34:00.079
<v Speaker 2>But if they're like security this week ap is so

660
00:34:00.279 --> 00:34:01.200
<v Speaker 2>for example.

661
00:34:00.920 --> 00:34:04.440
<v Speaker 4>Yeah, absolutely great, place yourself out, yep, yep, yep.

662
00:34:04.480 --> 00:34:06.799
<v Speaker 2>We're not going to complain if you download them and

663
00:34:06.839 --> 00:34:12.639
<v Speaker 2>distribute them yourself, go ahead, go for it. Yeah I

664
00:34:12.639 --> 00:34:14.840
<v Speaker 2>would want to do that. I have no idea. But okay,

665
00:34:15.039 --> 00:34:16.239
<v Speaker 2>all right, are we done with that one?

666
00:34:16.360 --> 00:34:18.960
<v Speaker 4>I think uh no, I want to say I think

667
00:34:18.960 --> 00:34:20.519
<v Speaker 4>we're going to start to see a lot more of

668
00:34:20.519 --> 00:34:23.679
<v Speaker 4>these types of things. I think as we see as

669
00:34:23.719 --> 00:34:26.039
<v Speaker 4>we're seeing vibe coded applications. And I'm not saying this

670
00:34:26.079 --> 00:34:27.920
<v Speaker 4>is vibe coded. I'm just I'm going more on the

671
00:34:28.000 --> 00:34:30.360
<v Speaker 4>ranti of AI and vibe coding where we see things.

672
00:34:30.400 --> 00:34:32.119
<v Speaker 4>As we start to see a lot more vibe coding

673
00:34:33.079 --> 00:34:35.280
<v Speaker 4>and we see vibe coded by people who are either

674
00:34:36.000 --> 00:34:44.079
<v Speaker 4>new to development or don't understand architecture like production secure architecture,

675
00:34:44.119 --> 00:34:46.480
<v Speaker 4>We're going to see a lot more applications and files

676
00:34:46.480 --> 00:34:47.119
<v Speaker 4>being you mean.

677
00:34:47.039 --> 00:34:48.360
<v Speaker 3>Most of the developers have ever met?

678
00:34:48.400 --> 00:34:49.800
<v Speaker 2>Wow, this is wow.

679
00:34:50.079 --> 00:34:52.079
<v Speaker 4>We're going to see a lot more files and sensitive

680
00:34:52.159 --> 00:34:55.519
<v Speaker 4>data being deployed into cloud environments where they where the

681
00:34:55.559 --> 00:34:58.079
<v Speaker 4>developers may or may not understand the ramifications of what

682
00:34:58.119 --> 00:34:58.559
<v Speaker 4>they're doing.

683
00:34:58.800 --> 00:35:02.000
<v Speaker 2>Right. Well, all right, main story this week and this

684
00:35:02.039 --> 00:35:08.079
<v Speaker 2>should scare you. Axios NPM package compromised supply chain attack

685
00:35:08.199 --> 00:35:12.719
<v Speaker 2>hits JavaScript HTTP client. Think about that for a second.

686
00:35:12.800 --> 00:35:16.440
<v Speaker 2>JavaScript HP how important is that? Right? I mean?

687
00:35:16.480 --> 00:35:17.280
<v Speaker 3>Who uses that?

688
00:35:17.440 --> 00:35:21.280
<v Speaker 2>Okay, anybody whouses a JavaScript framework to do any kind

689
00:35:21.280 --> 00:35:23.880
<v Speaker 2>of UI at all is using a JavaScript HTD client

690
00:35:24.239 --> 00:35:29.199
<v Speaker 2>with one hundred million plus weekly downloads weekly. Yeah.

691
00:35:29.559 --> 00:35:32.840
<v Speaker 3>To put this in context, if you if you updated

692
00:35:32.880 --> 00:35:36.840
<v Speaker 3>Claude code after the act, after the you know the

693
00:35:36.840 --> 00:35:41.840
<v Speaker 3>code source code exposure from slightly after midnight to about

694
00:35:41.880 --> 00:35:44.840
<v Speaker 3>three point thirty in the morning London time on the

695
00:35:44.880 --> 00:35:48.800
<v Speaker 3>thirty first, you may have received the trojanized version of Axios.

696
00:35:48.920 --> 00:35:49.239
<v Speaker 4>Yes.

697
00:35:49.280 --> 00:35:49.599
<v Speaker 2>Wow.

698
00:35:49.840 --> 00:35:52.599
<v Speaker 3>So just to put it in perspective of like it's

699
00:35:52.639 --> 00:35:57.000
<v Speaker 3>it's like it's like they said, like, you know, transparent

700
00:35:57.119 --> 00:36:01.239
<v Speaker 3>food dye number fifteen will kill you and you have

701
00:36:01.360 --> 00:36:02.119
<v Speaker 3>no idea what.

702
00:36:02.039 --> 00:36:08.559
<v Speaker 2>It's in transparent food due Yeah, exactly, Yeah, it's Axios.

703
00:36:08.599 --> 00:36:11.159
<v Speaker 4>Is interesting. So, like Carl had said, this is an

704
00:36:11.440 --> 00:36:16.639
<v Speaker 4>HTTP client right for JavaScript, so calling back in pages

705
00:36:16.679 --> 00:36:19.280
<v Speaker 4>and that sort of stuff, which JavaScript heads up does

706
00:36:19.360 --> 00:36:22.960
<v Speaker 4>all the time. Interestingly enough, all the time. There is

707
00:36:23.000 --> 00:36:26.360
<v Speaker 4>a client in Java, in the Java script world that

708
00:36:26.480 --> 00:36:30.519
<v Speaker 4>does this. It's actually a native library, but it didn't

709
00:36:30.559 --> 00:36:32.719
<v Speaker 4>have as many features as people had liked early on,

710
00:36:33.079 --> 00:36:36.599
<v Speaker 4>and a lot of people had adopted Axios. You know,

711
00:36:36.679 --> 00:36:40.639
<v Speaker 4>fast forward to bajillion years and people just keep using Axios.

712
00:36:40.199 --> 00:36:41.400
<v Speaker 2>Because they're used to it.

713
00:36:41.440 --> 00:36:43.599
<v Speaker 4>You know, they like Axios, And I'm sure on our

714
00:36:43.639 --> 00:36:46.559
<v Speaker 4>discord people can tell me why they would use Axios

715
00:36:46.559 --> 00:36:50.880
<v Speaker 4>as opposed to the local libraries. But in this particular case,

716
00:36:50.880 --> 00:36:56.639
<v Speaker 4>what happened is a lot of these libraries are sometimes

717
00:36:56.679 --> 00:37:00.280
<v Speaker 4>sort of supported by an individual developer or or a

718
00:37:00.320 --> 00:37:02.840
<v Speaker 4>small group of developers who don't you know, don't work

719
00:37:02.840 --> 00:37:05.360
<v Speaker 4>for a large corporation, don't go through the normal sort

720
00:37:05.360 --> 00:37:08.239
<v Speaker 4>of rollout process and that sort of stuff. And in

721
00:37:08.239 --> 00:37:11.480
<v Speaker 4>this particular case, the developer who one of the developers

722
00:37:11.480 --> 00:37:17.239
<v Speaker 4>who maintains this repository got hacked, social engineered, lost is

723
00:37:17.519 --> 00:37:23.400
<v Speaker 4>you know access. We see that his repository accounts got

724
00:37:23.440 --> 00:37:27.119
<v Speaker 4>switched over to a proton mail account and then there

725
00:37:27.159 --> 00:37:32.519
<v Speaker 4>were new uh, you know, new updates coming down. So

726
00:37:32.599 --> 00:37:38.480
<v Speaker 4>what's what's actually sort of really interesting about this is

727
00:37:39.239 --> 00:37:45.199
<v Speaker 4>the way how Cleannes was in installing a back door.

728
00:37:45.239 --> 00:37:46.519
<v Speaker 4>So one of the things you're gonna want to look

729
00:37:46.519 --> 00:37:48.599
<v Speaker 4>for if you're if you're using Axios and you're using

730
00:37:49.400 --> 00:37:52.880
<v Speaker 4>the corresponding versions, which are one dot fourteen dot one

731
00:37:53.519 --> 00:37:57.920
<v Speaker 4>or notice not through but or zero dot thirty dot four,

732
00:37:58.679 --> 00:38:02.360
<v Speaker 4>if you're using those, you'll want to look for and

733
00:38:02.400 --> 00:38:05.119
<v Speaker 4>I want to get the library right.

734
00:38:05.599 --> 00:38:08.960
<v Speaker 3>Well, while you're doing that, remember that most people don't

735
00:38:09.000 --> 00:38:11.800
<v Speaker 3>go and get Axios. They're using it because they're using

736
00:38:11.840 --> 00:38:13.599
<v Speaker 3>something that uses it, just like log forge.

737
00:38:13.840 --> 00:38:16.280
<v Speaker 4>Correct, right, yeah, absolutely, it's just a library, right, so

738
00:38:16.360 --> 00:38:19.280
<v Speaker 4>you supply chain, Yeah, you don't know NPM. You pull

739
00:38:19.360 --> 00:38:22.760
<v Speaker 4>this stuff down and it's just installed. So what happens

740
00:38:22.920 --> 00:38:26.400
<v Speaker 4>is this Axios. What they've done is they've said, oh,

741
00:38:26.440 --> 00:38:30.119
<v Speaker 4>by the way, we have a dependency now of plane

742
00:38:30.199 --> 00:38:36.039
<v Speaker 4>Dash Crypto dash JS version four, dot two, dot one.

743
00:38:36.159 --> 00:38:39.559
<v Speaker 4>There is a crypto dash JS which is pretty common

744
00:38:39.559 --> 00:38:42.840
<v Speaker 4>to have, so Plane Dash Crypto dash JS. If you

745
00:38:42.880 --> 00:38:46.159
<v Speaker 4>see that you've been compromised, you want to be careful.

746
00:38:47.280 --> 00:38:50.320
<v Speaker 4>But what's really interesting is it says it's a requirement.

747
00:38:51.159 --> 00:38:55.440
<v Speaker 4>So the initial check on Axios is obviously virus free.

748
00:38:56.079 --> 00:38:59.559
<v Speaker 4>It pulls down this requirement, it installs the remote access trojan,

749
00:38:59.639 --> 00:39:02.719
<v Speaker 4>and then it cleans itself up, so when the install

750
00:39:02.840 --> 00:39:06.400
<v Speaker 4>is done, it still looks like it's virus free. Although

751
00:39:06.400 --> 00:39:07.719
<v Speaker 4>now you have a backdoor installed.

752
00:39:07.800 --> 00:39:08.079
<v Speaker 2>Wow.

753
00:39:08.719 --> 00:39:12.480
<v Speaker 4>So this one's reasonably hard to find and with one

754
00:39:12.519 --> 00:39:16.920
<v Speaker 4>hundred million weekly downloads. Yeah, you want to double check

755
00:39:16.960 --> 00:39:18.760
<v Speaker 4>and see if you actually have this installed.

756
00:39:18.800 --> 00:39:21.039
<v Speaker 2>So if you have it installed, are you screwed?

757
00:39:21.639 --> 00:39:26.599
<v Speaker 4>Yes? Yeah, I mean literally the comments on the internet

758
00:39:26.719 --> 00:39:28.280
<v Speaker 4>or if you have this installed, you need to go.

759
00:39:29.320 --> 00:39:32.920
<v Speaker 4>First off, you need to burn down the infrastructure you

760
00:39:32.960 --> 00:39:34.960
<v Speaker 4>have there. Ideally it's in a cloud and you can

761
00:39:35.000 --> 00:39:36.679
<v Speaker 4>just burn it down and roll it back and whatever.

762
00:39:37.360 --> 00:39:39.119
<v Speaker 4>But the other thing you need to do is you

763
00:39:39.159 --> 00:39:42.679
<v Speaker 4>need to assume that any keys anything in your dot

764
00:39:42.679 --> 00:39:45.840
<v Speaker 4>E and V file, any whether it's opening eye keys,

765
00:39:45.920 --> 00:39:50.039
<v Speaker 4>whether it's back end keys, whether it's aki a ki

766
00:39:50.199 --> 00:39:53.159
<v Speaker 4>K keys. Yeah, anything you have access to that doesn't

767
00:39:53.159 --> 00:39:54.800
<v Speaker 4>prompt you for a password.

768
00:39:54.360 --> 00:39:55.280
<v Speaker 2>Any configuration.

769
00:39:55.639 --> 00:39:58.199
<v Speaker 4>Yeah, whatever you would have keys for, whatever you would

770
00:39:58.199 --> 00:40:01.079
<v Speaker 4>have in your environmental file, whatever you would have for

771
00:40:01.199 --> 00:40:04.159
<v Speaker 4>passwords for local databases like, you can assume all of

772
00:40:04.159 --> 00:40:06.519
<v Speaker 4>that's probably already been taken and you need to go

773
00:40:06.559 --> 00:40:08.320
<v Speaker 4>start rotating keys and passwords.

774
00:40:08.360 --> 00:40:11.280
<v Speaker 2>Wow, yikes, that's a that's a bad one.

775
00:40:11.440 --> 00:40:15.920
<v Speaker 3>Do we think something like an a virus is going

776
00:40:16.000 --> 00:40:17.960
<v Speaker 3>to pick this up looking for this file?

777
00:40:18.280 --> 00:40:18.360
<v Speaker 2>No?

778
00:40:18.559 --> 00:40:21.239
<v Speaker 4>I don't think so. Uh. I mean, could you have

779
00:40:21.320 --> 00:40:24.360
<v Speaker 4>a could you could there be a package or a

780
00:40:24.400 --> 00:40:27.400
<v Speaker 4>custom you know, thing deployed that only looks for this

781
00:40:27.559 --> 00:40:31.480
<v Speaker 4>version of you know, playing crypto jass maybe And then

782
00:40:31.880 --> 00:40:34.400
<v Speaker 4>but the problem is there's no known malware in it, right,

783
00:40:35.920 --> 00:40:41.199
<v Speaker 4>So yeah, eh so ultimately yes, could could we say, oh, well,

784
00:40:41.239 --> 00:40:44.079
<v Speaker 4>if you find this, just assume they've been compromised.

785
00:40:44.159 --> 00:40:45.800
<v Speaker 2>Maybe? So it be nice to have a tool that

786
00:40:45.840 --> 00:40:48.880
<v Speaker 2>you could run on your machine that would look at

787
00:40:48.880 --> 00:40:51.519
<v Speaker 2>all your NPM installs and see if you could find it.

788
00:40:51.880 --> 00:40:56.119
<v Speaker 3>It really should be something that the antivirus looks for us,

789
00:40:56.159 --> 00:40:58.079
<v Speaker 3>Like you know with this this this file name is

790
00:40:58.159 --> 00:41:00.400
<v Speaker 3>up to no good. Let's look at it, let's look

791
00:41:00.400 --> 00:41:03.440
<v Speaker 3>at its size, and we know it's not it doesn't

792
00:41:03.440 --> 00:41:07.159
<v Speaker 3>have malware in it. It is malware, right, Yeah.

793
00:41:06.880 --> 00:41:11.239
<v Speaker 2>Well do modern antivirus applications allow you to enter file

794
00:41:11.320 --> 00:41:13.440
<v Speaker 2>names that you wanted to find, so.

795
00:41:13.480 --> 00:41:17.159
<v Speaker 4>You can you can block certain files by name. The

796
00:41:17.159 --> 00:41:19.119
<v Speaker 4>problem with that is a lot of them don't take

797
00:41:19.159 --> 00:41:24.519
<v Speaker 4>that as sort of an important feature because viruses can

798
00:41:24.559 --> 00:41:27.559
<v Speaker 4>generally and more often than not, will change their names,

799
00:41:28.000 --> 00:41:28.920
<v Speaker 4>especially malware.

800
00:41:29.079 --> 00:41:29.239
<v Speaker 2>Right.

801
00:41:30.079 --> 00:41:32.079
<v Speaker 4>So it's like, oh, well the file name doesn't matter

802
00:41:32.119 --> 00:41:34.480
<v Speaker 4>in this particular case because we can isolate it to

803
00:41:35.119 --> 00:41:36.559
<v Speaker 4>a small version.

804
00:41:36.840 --> 00:41:37.719
<v Speaker 3>And they caught it quick.

805
00:41:37.800 --> 00:41:39.639
<v Speaker 4>That was deployed and it was real, It was caught

806
00:41:39.639 --> 00:41:42.119
<v Speaker 4>relatively quickly. Yeah, you know what the name of the

807
00:41:42.119 --> 00:41:42.599
<v Speaker 4>file is.

808
00:41:42.719 --> 00:41:45.639
<v Speaker 2>But so you could do a duras slash ass if

809
00:41:45.639 --> 00:41:46.400
<v Speaker 2>you really wanted to.

810
00:41:46.559 --> 00:41:49.239
<v Speaker 4>And there's there's a couple IP addresses in this article

811
00:41:49.599 --> 00:41:51.599
<v Speaker 4>from trend that we put out here. There's a couple

812
00:41:51.639 --> 00:41:55.880
<v Speaker 4>IP addresses for the command and control structure. Obviously don't

813
00:41:55.960 --> 00:42:00.719
<v Speaker 4>click on any of them, but s fr clak is

814
00:42:00.760 --> 00:42:06.960
<v Speaker 4>one of them. Call are hys dot com is another one,

815
00:42:07.000 --> 00:42:09.599
<v Speaker 4>and there's a couple IP addresses. So just needless to say,

816
00:42:09.639 --> 00:42:13.000
<v Speaker 4>if you see you know, that's another way we would

817
00:42:13.000 --> 00:42:16.239
<v Speaker 4>detect it as hey, what what's coming off the box?

818
00:42:17.159 --> 00:42:20.280
<v Speaker 4>And especially in custom ports in this particular one port

819
00:42:20.360 --> 00:42:22.360
<v Speaker 4>eight thousand is what it calls off the box, which

820
00:42:22.400 --> 00:42:22.840
<v Speaker 4>is weird.

821
00:42:23.719 --> 00:42:26.239
<v Speaker 2>So yeah, all right, So let's answer the question, Duane,

822
00:42:26.320 --> 00:42:27.760
<v Speaker 2>you think this is worse than Log for J.

823
00:42:29.360 --> 00:42:32.679
<v Speaker 4>I do? And I yeah, I do, I actually do. Well,

824
00:42:33.239 --> 00:42:35.880
<v Speaker 4>let me put it this way. I think the the

825
00:42:35.920 --> 00:42:38.840
<v Speaker 4>blast radius won't be as big. Okay, because Log for

826
00:42:38.960 --> 00:42:42.159
<v Speaker 4>J nobody knew where log for J was. Right in

827
00:42:42.239 --> 00:42:45.800
<v Speaker 4>this particular case, the blast radius could potentially be in

828
00:42:45.840 --> 00:42:49.480
<v Speaker 4>that time frame I don't know, I'll call it hundreds

829
00:42:49.519 --> 00:42:55.639
<v Speaker 4>of millions of people. But the damages could be greater

830
00:42:55.840 --> 00:42:58.440
<v Speaker 4>with this right problem being is LOG for J you

831
00:42:58.440 --> 00:43:00.880
<v Speaker 4>needed to go find the person who install that version

832
00:43:01.320 --> 00:43:03.519
<v Speaker 4>so that you could exploit them. In this case, if

833
00:43:03.559 --> 00:43:06.239
<v Speaker 4>you installed this version, it reached out to you. Right,

834
00:43:06.280 --> 00:43:08.000
<v Speaker 4>It reached out to the hackers, so the hackers didn't

835
00:43:08.159 --> 00:43:10.719
<v Speaker 4>have to go discover you. Yeah right. There was a

836
00:43:10.800 --> 00:43:14.599
<v Speaker 4>ten hour window where you just called into the hackers environment.

837
00:43:15.480 --> 00:43:19.480
<v Speaker 4>So the damages can be greater. But I don't think

838
00:43:19.480 --> 00:43:21.159
<v Speaker 4>it's going to be as ubiquitous. I don't think you're

839
00:43:21.159 --> 00:43:24.159
<v Speaker 4>going to see this for the next six months like

840
00:43:24.199 --> 00:43:26.079
<v Speaker 4>you did with log for j where it was hard

841
00:43:26.119 --> 00:43:27.159
<v Speaker 4>to find what was using it.

842
00:43:27.239 --> 00:43:30.159
<v Speaker 2>Well, we'll see because there's going to be more episodes

843
00:43:30.159 --> 00:43:32.960
<v Speaker 2>of security this week. But that's all for this week,

844
00:43:33.159 --> 00:43:35.199
<v Speaker 2>So we'll see you next week on Security this week,

845
00:43:35.480 --> 00:43:36.840
<v Speaker 2>Bye bye bye. I gues
