WEBVTT

1
00:00:00.320 --> 00:00:03.200
<v Speaker 1>Hey Carl here, we're on a mission to find new

2
00:00:03.240 --> 00:00:05.919
<v Speaker 1>fans of the show. I mean, where else can you

3
00:00:05.960 --> 00:00:10.240
<v Speaker 1>get real life comedy and horror in one podcast. You

4
00:00:10.279 --> 00:00:13.000
<v Speaker 1>can do your part by leaving us a review on iTunes,

5
00:00:13.039 --> 00:00:16.719
<v Speaker 1>Spotify or wherever you get Security this week. Also, you

6
00:00:16.719 --> 00:00:19.079
<v Speaker 1>can get an ad free feed by becoming a five

7
00:00:19.120 --> 00:00:22.039
<v Speaker 1>dollars a month patron. Go to Patreon dot Security this

8
00:00:22.079 --> 00:00:25.359
<v Speaker 1>week dot com and sign up, and don't forget discord.

9
00:00:25.600 --> 00:00:28.519
<v Speaker 1>Discord dot Security this week dot com. Lots of good

10
00:00:28.559 --> 00:00:32.280
<v Speaker 1>stuff happening there. Yeah, I think that's it. So on

11
00:00:32.359 --> 00:00:34.719
<v Speaker 1>with the podcast. You know, when I was a kid,

12
00:00:34.759 --> 00:00:39.119
<v Speaker 1>my parents sometimes took me to weddings, and I remember

13
00:00:39.359 --> 00:00:41.759
<v Speaker 1>so vividly the old biddies used to poke me and

14
00:00:41.799 --> 00:00:45.320
<v Speaker 1>say year next. Wow. Yeah. So when I got older,

15
00:00:45.359 --> 00:00:47.840
<v Speaker 1>I started doing the same to them. Yeah, with funerals.

16
00:00:50.320 --> 00:00:52.520
<v Speaker 2>And his record of being right was so good they

17
00:00:52.560 --> 00:00:53.600
<v Speaker 2>called it Grim Reaper.

18
00:01:03.079 --> 00:01:06.319
<v Speaker 1>Hey, welcome back to Security this week. The If you

19
00:01:06.519 --> 00:01:10.760
<v Speaker 1>hear any kind of banging, that's because their roofers are

20
00:01:10.799 --> 00:01:14.599
<v Speaker 1>putting on some roof for stuff at Playine's house. Yeah,

21
00:01:14.680 --> 00:01:16.280
<v Speaker 1>so we're going to try and take it out. I

22
00:01:16.319 --> 00:01:17.640
<v Speaker 1>hope you don't have to hear it, But.

23
00:01:17.840 --> 00:01:19.560
<v Speaker 2>Is that the official term roof of stuff?

24
00:01:19.640 --> 00:01:22.079
<v Speaker 3>Yeah, roof for stuff for stuff. They're doing roofing, they're

25
00:01:22.120 --> 00:01:24.000
<v Speaker 3>doing roofing, roofing things, whatever that is.

26
00:01:24.040 --> 00:01:25.680
<v Speaker 1>Are you are you getting a new roof put on?

27
00:01:25.879 --> 00:01:28.400
<v Speaker 3>I am. Yeah. My roof is twenty five years old,

28
00:01:28.680 --> 00:01:30.760
<v Speaker 3>so wow, uh it needed it.

29
00:01:30.840 --> 00:01:32.959
<v Speaker 2>And he said it right, he said roof rush.

30
00:01:32.959 --> 00:01:35.439
<v Speaker 1>So you're roof only started drinking four years ago, is

31
00:01:35.480 --> 00:01:36.040
<v Speaker 1>what you're saying.

32
00:01:36.239 --> 00:01:40.040
<v Speaker 3>Right, It's now an adult. It has to go, uh huh,

33
00:01:40.079 --> 00:01:41.840
<v Speaker 3>out of the house, out of the house, all right.

34
00:01:41.879 --> 00:01:45.120
<v Speaker 1>The first story is from Crabs on Security. We love crabs.

35
00:01:45.959 --> 00:01:51.400
<v Speaker 1>FBI sees his net nut proxy platform Comma Papa buttnet

36
00:01:51.519 --> 00:01:56.159
<v Speaker 1>popa botnet which I swear sounds either like a blues

37
00:01:56.239 --> 00:01:59.400
<v Speaker 1>musician or a born name. I don't know one or

38
00:01:59.400 --> 00:02:03.439
<v Speaker 1>the other. Why not both could be both net Nut So.

39
00:02:03.640 --> 00:02:07.280
<v Speaker 2>There's been a lot of takedowns in this year already.

40
00:02:08.000 --> 00:02:11.599
<v Speaker 2>I don't know whether AI is assisting in identifying this stuff,

41
00:02:11.599 --> 00:02:13.080
<v Speaker 2>but I wouldn't be surprised, I.

42
00:02:13.080 --> 00:02:17.800
<v Speaker 3>Would assume at this point. Yes, but yeah, I mean,

43
00:02:17.800 --> 00:02:21.560
<v Speaker 3>this one's weird too. So the FBI sees as hundreds

44
00:02:21.560 --> 00:02:25.319
<v Speaker 3>of domains tied to net Nut, a residential proxy service

45
00:02:26.000 --> 00:02:29.879
<v Speaker 3>that's run by an Israeli firm a La r u

46
00:02:30.159 --> 00:02:35.080
<v Speaker 3>m Alorum Technologies is traded on the Nasdaq. Right, so

47
00:02:35.159 --> 00:02:38.319
<v Speaker 3>imagine this. We have a bunch of houses that are

48
00:02:38.360 --> 00:02:45.680
<v Speaker 3>proxying into a place and Israel. It's roughly about two

49
00:02:45.800 --> 00:02:48.360
<v Speaker 3>million compromised consumer devices.

50
00:02:48.560 --> 00:02:51.120
<v Speaker 1>Wow. Yeah, thanks for the picking.

51
00:02:51.479 --> 00:02:57.280
<v Speaker 3>Yeah. So in this particular case, Google saw three hundred

52
00:02:57.280 --> 00:03:02.280
<v Speaker 3>and sixteen distinct threat clusters using net nut exit nodes.

53
00:03:02.879 --> 00:03:06.439
<v Speaker 3>That's not easy to say. Net Nut exit nodes.

54
00:03:06.360 --> 00:03:08.080
<v Speaker 1>Sound like mister rogers there for a minute.

55
00:03:08.800 --> 00:03:19.960
<v Speaker 3>Net modes pretty delivery. So so let's talk a little

56
00:03:20.000 --> 00:03:25.960
<v Speaker 3>bit about proxies, because a proxy is typically used to

57
00:03:26.560 --> 00:03:31.439
<v Speaker 3>obscure where you're coming from or used to encrypt your traffic.

58
00:03:32.319 --> 00:03:36.039
<v Speaker 3>So we've talked about, you know, leveraging VPNs.

59
00:03:36.479 --> 00:03:38.280
<v Speaker 1>VPN is essentially a proxy, right.

60
00:03:38.360 --> 00:03:40.240
<v Speaker 3>A VPN is a proxy. But think of a VPN

61
00:03:40.280 --> 00:03:43.080
<v Speaker 3>as an entirely encrypted tunnel that you go through. Whereas

62
00:03:43.080 --> 00:03:45.240
<v Speaker 3>a proxy, you're just sending your traffic to some other

63
00:03:45.319 --> 00:03:47.800
<v Speaker 3>random place on the Internet and then they send it out.

64
00:03:48.360 --> 00:03:53.360
<v Speaker 3>So proxy will not hide you from you know, the

65
00:03:53.400 --> 00:03:57.479
<v Speaker 3>local Wi Fi. You know, it won't hide you from

66
00:03:57.520 --> 00:04:00.319
<v Speaker 3>everybody else on Starbucks. You know, Wi Fi would whatever

67
00:04:00.680 --> 00:04:03.719
<v Speaker 3>a VPN would, but a proxy will let you make

68
00:04:03.759 --> 00:04:05.639
<v Speaker 3>it look like you're coming from another country.

69
00:04:05.599 --> 00:04:05.800
<v Speaker 2>Yeah.

70
00:04:06.240 --> 00:04:08.280
<v Speaker 3>So a lot of people may use proxies and may

71
00:04:08.319 --> 00:04:11.400
<v Speaker 3>have used proxies in the past to say, get BBC

72
00:04:11.599 --> 00:04:14.199
<v Speaker 3>broadcasts and all sorts of things you can't get in

73
00:04:14.719 --> 00:04:17.839
<v Speaker 3>you know where you are now. So proxies or proxies

74
00:04:17.839 --> 00:04:21.360
<v Speaker 3>are interesting for that reason, But for this number of

75
00:04:21.480 --> 00:04:25.319
<v Speaker 3>people to be using proxies a little bit weird. In

76
00:04:25.319 --> 00:04:28.800
<v Speaker 3>this particular case, these devices were actually smart TVs and

77
00:04:28.920 --> 00:04:32.759
<v Speaker 3>streaming boxes with the proxy SDK baked in.

78
00:04:33.120 --> 00:04:34.240
<v Speaker 1>Oh wow.

79
00:04:34.360 --> 00:04:38.920
<v Speaker 3>Yeah, Spur reported for LG webOS apps and twenty five

80
00:04:38.959 --> 00:04:44.240
<v Speaker 3>percent of Samsung tiz in apps we're carrying this proxy SDK.

81
00:04:45.319 --> 00:04:47.519
<v Speaker 3>Moral of the story is, if you bought a TV

82
00:04:47.680 --> 00:04:52.839
<v Speaker 3>that was running Linux or Android. If you bought a

83
00:04:52.879 --> 00:04:57.439
<v Speaker 3>TV running Android that was a off brand, a super

84
00:04:57.800 --> 00:05:01.639
<v Speaker 3>cheap no name, chances are it was it was running

85
00:05:02.680 --> 00:05:03.560
<v Speaker 3>one of these proxies.

86
00:05:03.680 --> 00:05:06.199
<v Speaker 2>Are you saying, my sam Sang TV is not a

87
00:05:06.279 --> 00:05:07.160
<v Speaker 2>name brand.

88
00:05:07.319 --> 00:05:11.000
<v Speaker 3>Sang, No, that's Samsung's brother.

89
00:05:10.879 --> 00:05:15.480
<v Speaker 2>Better than Samsung. It's present tense, Samsung is over.

90
00:05:15.920 --> 00:05:18.839
<v Speaker 1>Past Wow well, Sang is also past tense.

91
00:05:19.800 --> 00:05:20.399
<v Speaker 3>That's true.

92
00:05:21.120 --> 00:05:24.319
<v Speaker 2>Yeah, Sam Sing, Okay, yeah you should.

93
00:05:24.399 --> 00:05:28.160
<v Speaker 3>You should buy the Sam say we'll have Sung in

94
00:05:28.360 --> 00:05:29.360
<v Speaker 3>the future version.

95
00:05:31.120 --> 00:05:32.360
<v Speaker 1>I say, I'm almost sung.

96
00:05:32.639 --> 00:05:34.600
<v Speaker 2>Do we think that most of these are in Israel?

97
00:05:34.720 --> 00:05:35.800
<v Speaker 2>Or is this all over the world?

98
00:05:36.439 --> 00:05:41.800
<v Speaker 3>So the proxy was reading through Israel the the obviously

99
00:05:41.879 --> 00:05:45.120
<v Speaker 3>the proxy was being used for all sorts of nefarious things.

100
00:05:47.279 --> 00:05:47.720
<v Speaker 1>I don't know.

101
00:05:48.040 --> 00:05:50.399
<v Speaker 3>It's a good question, I mean. And they talk about

102
00:05:50.439 --> 00:05:53.399
<v Speaker 3>this as a takedown. This wasn't a full takedown. This

103
00:05:53.600 --> 00:05:55.959
<v Speaker 3>was They called it a crippling, right. They took down

104
00:05:56.360 --> 00:06:01.519
<v Speaker 3>one or two of the you know, net nut Maine exits,

105
00:06:01.639 --> 00:06:04.439
<v Speaker 3>but there's still like net nut io is still online, right,

106
00:06:04.519 --> 00:06:09.279
<v Speaker 3>so there's there's other proxies that are still available. Let's

107
00:06:09.279 --> 00:06:09.920
<v Speaker 3>put it that way.

108
00:06:10.120 --> 00:06:12.759
<v Speaker 1>It used to be my nickname in grammar school Netnut

109
00:06:12.800 --> 00:06:13.240
<v Speaker 1>net nut.

110
00:06:13.480 --> 00:06:17.519
<v Speaker 3>Yeah, here you go, as crabs, that's actually net nuts.

111
00:06:17.920 --> 00:06:20.079
<v Speaker 2>That you think that's an accurate description.

112
00:06:20.360 --> 00:06:24.360
<v Speaker 3>Yeah. As Crebs has warned repeatedly, most of the no

113
00:06:24.519 --> 00:06:27.439
<v Speaker 3>name TV streaming boxes for sale on major e commerce

114
00:06:27.439 --> 00:06:31.800
<v Speaker 3>websites either come pre installed with residential proxy software or

115
00:06:32.600 --> 00:06:35.800
<v Speaker 3>require the installation of proxy software to work. So if

116
00:06:35.839 --> 00:06:39.120
<v Speaker 3>you're buying some sort of sketchy TV or streaming box

117
00:06:39.160 --> 00:06:43.000
<v Speaker 3>off the internet, chances are you're participating in a butt.

118
00:06:42.720 --> 00:06:46.120
<v Speaker 1>Sketchy dot com right now eighty percent off.

119
00:06:47.000 --> 00:06:51.519
<v Speaker 3>Free every channel. Only need to use your internet to

120
00:06:51.680 --> 00:06:56.319
<v Speaker 3>steal things. Yeah, so be careful what you buy. And

121
00:06:56.600 --> 00:07:00.680
<v Speaker 3>you know, Google Android and Google Play the play stores

122
00:07:00.759 --> 00:07:04.720
<v Speaker 3>very good at at making sure there's not malicious things

123
00:07:04.759 --> 00:07:07.120
<v Speaker 3>in apps. We're not saying it's impossible.

124
00:07:08.079 --> 00:07:08.800
<v Speaker 1>It didn't used to be.

125
00:07:09.199 --> 00:07:12.000
<v Speaker 3>Yeah, but if you buy one random box that has

126
00:07:12.040 --> 00:07:17.240
<v Speaker 3>side loaded apps, yeah, exactly right, you'll get it. I

127
00:07:17.319 --> 00:07:20.199
<v Speaker 3>got a box for you to break it.

128
00:07:20.759 --> 00:07:25.279
<v Speaker 1>Yeah, yeah, all right. We moved on Chinese hackers. It's

129
00:07:25.279 --> 00:07:30.759
<v Speaker 1>almost like Florida man, right, Chinese hackers develop long leash

130
00:07:30.879 --> 00:07:36.720
<v Speaker 1>malware to expand o RB network. What's long leash?

131
00:07:37.240 --> 00:07:39.319
<v Speaker 3>Well, it's one of their leashes. And we'll go through

132
00:07:39.560 --> 00:07:43.399
<v Speaker 3>a couple of different leashes shortly. But yeah, there's there's

133
00:07:43.439 --> 00:07:47.120
<v Speaker 3>short leash, there's dog leash. There's all sorts of leashes.

134
00:07:46.839 --> 00:07:48.720
<v Speaker 1>In here that there's not cat leash.

135
00:07:48.759 --> 00:07:52.720
<v Speaker 3>I don't think yeah, jar leishuh, And we're not kidding.

136
00:07:52.839 --> 00:07:56.040
<v Speaker 3>These are all the different types they have really so

137
00:07:56.720 --> 00:08:05.079
<v Speaker 3>in essence, uh, the these leashes, the ORB network is

138
00:08:05.279 --> 00:08:09.399
<v Speaker 3>used to route traffic through to obscure who's doing the attacking.

139
00:08:09.399 --> 00:08:12.160
<v Speaker 2>To maintain to maintain access to the network.

140
00:08:12.279 --> 00:08:16.879
<v Speaker 3>Yep, absolutely, So think of it. Think of it as, uh,

141
00:08:17.240 --> 00:08:20.560
<v Speaker 3>you know, I'm going to you know everybody, Let's say,

142
00:08:20.680 --> 00:08:23.199
<v Speaker 3>like my firewalls here block China, right, I don't allow

143
00:08:23.279 --> 00:08:25.120
<v Speaker 3>China to hit my network here. I don't allow anybody

144
00:08:25.160 --> 00:08:27.399
<v Speaker 3>here on my network to go out to China. But

145
00:08:28.279 --> 00:08:30.759
<v Speaker 3>let's say an exit note on that ORB network is

146
00:08:30.800 --> 00:08:35.399
<v Speaker 3>in Canada. I mean everybody loves Canada, right, especially China, right,

147
00:08:35.559 --> 00:08:39.399
<v Speaker 3>So so I you know, I allow Canadian traffic. So

148
00:08:39.399 --> 00:08:40.960
<v Speaker 3>it's one of it's one of the reasons they may

149
00:08:41.120 --> 00:08:43.840
<v Speaker 3>use one of these types of networks is to obscure

150
00:08:44.000 --> 00:08:46.840
<v Speaker 3>not only the location of the attacks, but also to

151
00:08:46.879 --> 00:08:49.759
<v Speaker 3>obscure one of the indicator's compromise and ways that you

152
00:08:49.799 --> 00:08:52.080
<v Speaker 3>can attribute the attack to a particular attack.

153
00:08:52.120 --> 00:08:54.000
<v Speaker 2>So it's like using it as a VPN, you know

154
00:08:54.039 --> 00:08:56.120
<v Speaker 2>how if you're in yeah, exactly, if you want to

155
00:08:56.120 --> 00:08:58.960
<v Speaker 2>watch TV on a Mexican channel, you might have to

156
00:08:59.080 --> 00:09:02.159
<v Speaker 2>VPN in Mexico. Same deal if you want to hack

157
00:09:02.200 --> 00:09:06.080
<v Speaker 2>a computer in Canada, if they're screening for Russia and

158
00:09:06.240 --> 00:09:09.759
<v Speaker 2>China and Iran, then you can get around that one

159
00:09:10.200 --> 00:09:11.080
<v Speaker 2>defense in depth.

160
00:09:11.240 --> 00:09:15.240
<v Speaker 3>Now, in this particular case, the leash long Leash, which

161
00:09:15.360 --> 00:09:18.360
<v Speaker 3>was an upgraded from short leash, which was a back door,

162
00:09:18.960 --> 00:09:21.919
<v Speaker 3>not kidding. And they have dog leash, which is a

163
00:09:21.960 --> 00:09:24.440
<v Speaker 3>Linux back door with a hard coded TCP listener, and

164
00:09:24.480 --> 00:09:27.360
<v Speaker 3>then jar leash, which is a Java web admin tool

165
00:09:28.039 --> 00:09:31.279
<v Speaker 3>back door, and then leash test which is test yeah

166
00:09:31.320 --> 00:09:34.879
<v Speaker 3>for their IoT compatibility checkers. Blah blah blah. So all

167
00:09:34.919 --> 00:09:38.279
<v Speaker 3>of these leashes in this particular case they are exploiting

168
00:09:38.320 --> 00:09:41.559
<v Speaker 3>CVEE twenty twenty. So for those of you who have

169
00:09:41.559 --> 00:09:43.879
<v Speaker 3>been listening to the show for a while, you know

170
00:09:44.039 --> 00:09:47.720
<v Speaker 3>CV twenty twenty means it came out in twenty twenty.

171
00:09:47.559 --> 00:09:50.679
<v Speaker 1>Well it was it was adult that number was dolled

172
00:09:50.679 --> 00:09:50.960
<v Speaker 1>out in.

173
00:09:50.960 --> 00:09:54.240
<v Speaker 3>Twenty yeah, so that means six years ago this vulnerability

174
00:09:54.279 --> 00:09:59.840
<v Speaker 3>was discovered and I assigned an ID same thing with

175
00:10:00.200 --> 00:10:02.480
<v Speaker 3>So this is twenty twenty two, two sixty five three,

176
00:10:02.799 --> 00:10:06.279
<v Speaker 3>twenty twenty two two six, five eight, and twenty twenty

177
00:10:06.279 --> 00:10:09.879
<v Speaker 3>three two five seven, one seven. These are all Ruckus devices. Yeah,

178
00:10:09.879 --> 00:10:11.799
<v Speaker 3>I was gonna say, that's a great name for a

179
00:10:11.879 --> 00:10:15.480
<v Speaker 3>route RUCKUS causes RUCKUS.

180
00:10:15.120 --> 00:10:16.919
<v Speaker 2>It causes one with your bank account.

181
00:10:17.279 --> 00:10:20.639
<v Speaker 3>Yeah right, Uh so all of these are our RUCKUS devices.

182
00:10:20.679 --> 00:10:23.519
<v Speaker 3>This has been patched, but there are exploits on these

183
00:10:23.559 --> 00:10:26.320
<v Speaker 3>devices that allow for attackers to take control of them

184
00:10:26.320 --> 00:10:29.919
<v Speaker 3>and add them to this network. CEV twenty twenty five

185
00:10:30.360 --> 00:10:36.080
<v Speaker 3>two four nine two is an asus AI Cloud critical

186
00:10:36.120 --> 00:10:39.480
<v Speaker 3>off bypass and that's one that So these are the

187
00:10:39.519 --> 00:10:43.159
<v Speaker 3>four cvees that are being used to add more nodes

188
00:10:43.879 --> 00:10:45.039
<v Speaker 3>via a long leash.

189
00:10:45.080 --> 00:10:47.039
<v Speaker 1>Here's a good question for you, and I don't expect

190
00:10:47.080 --> 00:10:49.320
<v Speaker 1>you to have the answer right now, but is there

191
00:10:49.360 --> 00:10:55.159
<v Speaker 1>a way that I can configure my configure my you know,

192
00:10:55.240 --> 00:10:59.639
<v Speaker 1>Wi Fi home Wi Fi to absolutely refuse any connections

193
00:10:59.639 --> 00:11:03.600
<v Speaker 1>from or Russia or any other country. Yeah that I'm

194
00:11:03.639 --> 00:11:04.559
<v Speaker 1>so easy thing to do.

195
00:11:05.440 --> 00:11:07.960
<v Speaker 3>So it depends, I'll give you it depends. It depends

196
00:11:07.960 --> 00:11:09.960
<v Speaker 3>on your hardware. So like right now at my house,

197
00:11:09.960 --> 00:11:12.960
<v Speaker 3>I'm running Ubiquity and it does. It's It's easy. It's

198
00:11:13.000 --> 00:11:14.480
<v Speaker 3>literally I go in and I can say I want

199
00:11:14.480 --> 00:11:15.919
<v Speaker 3>to restrict, and it shows me a map of the

200
00:11:15.919 --> 00:11:18.039
<v Speaker 3>world and I can click the countries and say nope.

201
00:11:18.120 --> 00:11:18.519
<v Speaker 1>Oh wow.

202
00:11:18.960 --> 00:11:21.639
<v Speaker 3>So that makes it easy. I know, firewalla does the

203
00:11:21.639 --> 00:11:24.799
<v Speaker 3>same thing, makes it really super easy. But then there

204
00:11:24.799 --> 00:11:26.759
<v Speaker 3>are other ones like if you're running a TP link,

205
00:11:26.799 --> 00:11:29.639
<v Speaker 3>throw it out. But if you're running something else, well

206
00:11:29.679 --> 00:11:33.000
<v Speaker 3>it comes included with the with the leash, yeah exactly,

207
00:11:33.039 --> 00:11:34.440
<v Speaker 3>you know, and.

208
00:11:34.360 --> 00:11:37.240
<v Speaker 1>It also has a cardboard role in the middle of

209
00:11:37.879 --> 00:11:38.919
<v Speaker 1>you got to take that out.

210
00:11:39.279 --> 00:11:41.960
<v Speaker 3>Yeah, but then it's uh no, it's fine, but no,

211
00:11:42.039 --> 00:11:45.799
<v Speaker 3>if you're running some other version of firewall, sometimes you

212
00:11:45.799 --> 00:11:47.879
<v Speaker 3>can just block the country outright. Sometimes they have a

213
00:11:47.919 --> 00:11:51.679
<v Speaker 3>block list. Sometimes you actually need to go in and

214
00:11:52.120 --> 00:11:54.679
<v Speaker 3>like configure the ranges yourself that you don't want it

215
00:11:54.720 --> 00:11:56.080
<v Speaker 3>to talk to you, which is more of a pain

216
00:11:56.159 --> 00:11:58.440
<v Speaker 3>but can be done no matter what you're running.

217
00:11:58.559 --> 00:12:01.279
<v Speaker 2>Okay, but the the whole the hull idea this leash

218
00:12:01.320 --> 00:12:02.360
<v Speaker 2>thing is to circumvent that.

219
00:12:02.480 --> 00:12:04.080
<v Speaker 3>So yeah, absolutely it.

220
00:12:04.000 --> 00:12:05.919
<v Speaker 2>Is part of defense and death. You do want to

221
00:12:05.960 --> 00:12:08.200
<v Speaker 2>do it, Yeah, don't count on it.

222
00:12:08.320 --> 00:12:13.159
<v Speaker 3>Yeah, absolutely, and defense and death Like that's the first layer, right,

223
00:12:13.240 --> 00:12:16.960
<v Speaker 3>don't talk to or communicate to the places where generally

224
00:12:17.039 --> 00:12:20.159
<v Speaker 3>you're getting attacked. Right. The second layer obviously is then

225
00:12:20.360 --> 00:12:22.440
<v Speaker 3>monitoring the type of traffic you have and you know,

226
00:12:22.639 --> 00:12:27.320
<v Speaker 3>having isolation on your networks for example, on my home network.

227
00:12:27.360 --> 00:12:29.559
<v Speaker 3>There is no way in hell I allow the kids

228
00:12:29.600 --> 00:12:33.639
<v Speaker 3>on any of the networks that have sensitive data. So

229
00:12:33.679 --> 00:12:36.919
<v Speaker 3>they're in essence on their own guess network where they

230
00:12:36.960 --> 00:12:41.519
<v Speaker 3>can play games and stream and download whatever janky things

231
00:12:41.559 --> 00:12:44.559
<v Speaker 3>they download install on their computers. But it's it's not

232
00:12:44.559 --> 00:12:47.519
<v Speaker 3>gonna affect any of the rest of the network.

233
00:12:47.639 --> 00:12:51.440
<v Speaker 1>All right. This next story actually kind of hits close

234
00:12:51.480 --> 00:12:54.120
<v Speaker 1>to home because we actually thought about setting up a

235
00:12:54.159 --> 00:13:01.679
<v Speaker 1>website to expose websites that had dumb password rules. Right now,

236
00:13:01.679 --> 00:13:03.759
<v Speaker 1>if you've been listening to the show for the last

237
00:13:03.840 --> 00:13:07.080
<v Speaker 1>year or so, the only rule that makes any sense

238
00:13:07.320 --> 00:13:08.720
<v Speaker 1>for password is length.

239
00:13:09.879 --> 00:13:13.039
<v Speaker 2>You know, I mean complexity adds an element.

240
00:13:13.200 --> 00:13:14.320
<v Speaker 3>Well, length is more important.

241
00:13:14.480 --> 00:13:17.279
<v Speaker 1>Length is more important. Size matter, Size matters, And.

242
00:13:17.519 --> 00:13:20.519
<v Speaker 2>If you're gonna not have complexity, don't advertise that.

243
00:13:20.960 --> 00:13:25.519
<v Speaker 1>R Yeah, So this dumb passwords rules, dumb password rules

244
00:13:25.559 --> 00:13:30.600
<v Speaker 1>dot com has shown a spotlight on GameFly and so

245
00:13:30.679 --> 00:13:34.159
<v Speaker 1>with link to this. Basically it has a change email

246
00:13:34.279 --> 00:13:37.639
<v Speaker 1>address and password, and you put in your email in

247
00:13:37.679 --> 00:13:40.759
<v Speaker 1>your password, which is only six to twelve characters with

248
00:13:40.879 --> 00:13:42.159
<v Speaker 1>no other restrictions.

249
00:13:42.679 --> 00:13:49.600
<v Speaker 3>Well, that's impossible to crack. My password is one, two, three, four, five, six,

250
00:13:49.879 --> 00:13:50.440
<v Speaker 3>it could be.

251
00:13:50.519 --> 00:13:56.440
<v Speaker 1>And probably is common password around. So I mean, Dwyane,

252
00:13:56.679 --> 00:14:00.879
<v Speaker 1>how many milliseconds would it take ice.

253
00:14:01.200 --> 00:14:04.120
<v Speaker 2>It wouldn't get out of the first chapter the dictionary. No, yeah,

254
00:14:04.399 --> 00:14:07.679
<v Speaker 2>a dictionary attack, Yeah, it would be page one.

255
00:14:09.519 --> 00:14:14.399
<v Speaker 3>Instant easily in the milliseconds, probably hundreds of milliseconds, but

256
00:14:14.440 --> 00:14:18.000
<v Speaker 3>milliseconds for it to crack a majority of those passwords. Yeah, absolutely,

257
00:14:18.000 --> 00:14:19.120
<v Speaker 3>with a decent size cluster.

258
00:14:20.759 --> 00:14:23.600
<v Speaker 1>Really no story here. We just wanted to, uh, you know,

259
00:14:23.759 --> 00:14:27.240
<v Speaker 1>highlight the dumbness. And I think dumb password rules dot

260
00:14:27.240 --> 00:14:29.039
<v Speaker 1>com is going to be a staple.

261
00:14:30.159 --> 00:14:31.399
<v Speaker 3>So let's talk.

262
00:14:31.519 --> 00:14:33.480
<v Speaker 2>Let's take an opportunity for a second. Just talk about

263
00:14:33.519 --> 00:14:40.039
<v Speaker 2>the reality of authentication. Right now. You've got past keys, right,

264
00:14:40.080 --> 00:14:45.720
<v Speaker 2>which is a great yep, that's foreshadowing. Past keys are great.

265
00:14:46.360 --> 00:14:49.679
<v Speaker 2>Multi factor authentication is good, especially if you use an

266
00:14:49.679 --> 00:14:52.840
<v Speaker 2>authenticator w app that that makes it much better than

267
00:14:53.279 --> 00:14:57.919
<v Speaker 2>you know, sim sim swap attackable uh text message or

268
00:14:57.960 --> 00:15:01.399
<v Speaker 2>email messages on an email count that doesn't have multi

269
00:15:01.399 --> 00:15:03.879
<v Speaker 2>factor authentication. And one of the things that I've looked

270
00:15:03.879 --> 00:15:06.159
<v Speaker 2>at is compounding them because a lot of times if

271
00:15:06.159 --> 00:15:09.879
<v Speaker 2>you have a pass key, it's like a device certificate, right,

272
00:15:09.960 --> 00:15:12.759
<v Speaker 2>that's effectively what it is, why don't you still ask

273
00:15:12.799 --> 00:15:16.519
<v Speaker 2>for the password? Sure to add an extra layer, and

274
00:15:16.600 --> 00:15:19.039
<v Speaker 2>so in some case I'll implement that. But the other

275
00:15:19.080 --> 00:15:21.559
<v Speaker 2>thing is the denial of service. If you lock people

276
00:15:21.600 --> 00:15:25.000
<v Speaker 2>out after so many password attempts, the bad guy can

277
00:15:25.080 --> 00:15:28.480
<v Speaker 2>just use that to harass your users, right, So you

278
00:15:28.559 --> 00:15:31.759
<v Speaker 2>want to do something intelligent where it's like you escalate

279
00:15:31.840 --> 00:15:35.919
<v Speaker 2>the time of the password attack. Or my favorite thing,

280
00:15:35.960 --> 00:15:38.720
<v Speaker 2>which I've never seen anybody do other than us, is

281
00:15:39.159 --> 00:15:43.039
<v Speaker 2>when you fail that test you've tried five times in

282
00:15:43.080 --> 00:15:48.399
<v Speaker 2>the last two minutes, add another factor. Yeah, like what's

283
00:15:48.759 --> 00:15:51.840
<v Speaker 2>what's you know your what's Dwayne's extension at the office?

284
00:15:52.159 --> 00:15:52.759
<v Speaker 3>Trick question?

285
00:15:52.919 --> 00:15:56.840
<v Speaker 2>It's another factor or SMS when it starts.

286
00:15:56.879 --> 00:15:59.080
<v Speaker 1>Messages aren't great, but but.

287
00:15:59.039 --> 00:16:01.240
<v Speaker 2>It's it's an extra lay. So so that way you

288
00:16:01.279 --> 00:16:03.840
<v Speaker 2>don't lock the user out. You just raise the bar

289
00:16:03.919 --> 00:16:06.200
<v Speaker 2>and you know what you've also done, You've also made

290
00:16:06.240 --> 00:16:08.679
<v Speaker 2>it so that the user calls the help desk and says,

291
00:16:08.679 --> 00:16:10.679
<v Speaker 2>why is it asking for this extra piece of information?

292
00:16:11.200 --> 00:16:13.759
<v Speaker 2>If the hacker locked you out in the middle of

293
00:16:13.759 --> 00:16:16.639
<v Speaker 2>the night and the timer ran out, then unless you're

294
00:16:16.679 --> 00:16:18.399
<v Speaker 2>watching the logs, you're not going to have it now

295
00:16:18.399 --> 00:16:21.000
<v Speaker 2>the user is part of the part of the system

296
00:16:21.039 --> 00:16:23.720
<v Speaker 2>that alerts you. So we have to get We don't

297
00:16:23.759 --> 00:16:26.600
<v Speaker 2>want to roll our own I'm not saying that, but

298
00:16:26.600 --> 00:16:30.519
<v Speaker 2>we got to get more creative and compounding the authentication

299
00:16:30.679 --> 00:16:34.360
<v Speaker 2>and figuring out who they really are. Okay, sorry, I'm off.

300
00:16:34.519 --> 00:16:35.840
<v Speaker 2>Let me step down from the soapbox.

301
00:16:36.759 --> 00:16:38.480
<v Speaker 3>That actually used to be a great way to denial

302
00:16:38.519 --> 00:16:40.600
<v Speaker 3>a service an entire company, where they'd be like, oh,

303
00:16:40.639 --> 00:16:42.399
<v Speaker 3>three invalid attempts and you be like, all right, I'm

304
00:16:42.399 --> 00:16:44.559
<v Speaker 3>just gonna rape through all your users and log in

305
00:16:44.679 --> 00:16:49.720
<v Speaker 3>continually in the Outlook web access shut off that protection

306
00:16:49.799 --> 00:16:53.399
<v Speaker 3>because yeah, and then everybody's locked out constantly. By the

307
00:16:53.399 --> 00:16:57.080
<v Speaker 3>time you unlock them and it synchronizes to all your dcs,

308
00:16:57.600 --> 00:16:59.399
<v Speaker 3>I've locked them out again, so good luck.

309
00:16:59.440 --> 00:17:01.279
<v Speaker 1>All right, before we take a break, let's talk about

310
00:17:01.320 --> 00:17:07.720
<v Speaker 1>Microsoft Defender, because there was an elevation of privilege vulnerability

311
00:17:07.799 --> 00:17:12.079
<v Speaker 1>in it that was reported and what was the tell me,

312
00:17:12.359 --> 00:17:15.119
<v Speaker 1>tell me the sequence of actions. So this was reported,

313
00:17:15.440 --> 00:17:17.920
<v Speaker 1>Microsoft came out with a fix fix didn't really work,

314
00:17:18.000 --> 00:17:19.839
<v Speaker 1>and then they came out with another fix. Is that it?

315
00:17:20.039 --> 00:17:23.640
<v Speaker 3>Yeah, absolutely yesterday As of July eighth, they've come out

316
00:17:23.640 --> 00:17:27.559
<v Speaker 3>with another fix that should mitigate this. I mean, if

317
00:17:27.559 --> 00:17:29.920
<v Speaker 3>you're if you're writing, if you're there with a notepad,

318
00:17:29.960 --> 00:17:31.960
<v Speaker 3>it's going to be version one dot one dot two

319
00:17:32.079 --> 00:17:35.720
<v Speaker 3>six zero six zero three zero zero eight. But what

320
00:17:35.759 --> 00:17:37.400
<v Speaker 3>I'll tell you is, if you've been listening to this

321
00:17:37.400 --> 00:17:38.920
<v Speaker 3>show for a while, you probably don't need to worry

322
00:17:38.960 --> 00:17:42.920
<v Speaker 3>about it because it would have already updated. Yeah, to

323
00:17:43.079 --> 00:17:45.440
<v Speaker 3>just know that, Yeah, there was a privilege escalation and

324
00:17:45.480 --> 00:17:48.079
<v Speaker 3>had you'll remember us maybe reporting on this a couple

325
00:17:48.079 --> 00:17:50.440
<v Speaker 3>of weeks ago, maybe even a month ago, where we

326
00:17:50.480 --> 00:17:55.680
<v Speaker 3>had talked about privileged escalation using soft links, using l

327
00:17:55.759 --> 00:18:00.880
<v Speaker 3>en k files. Yeah, it was actually dubbed the Rogue Planet.

328
00:18:01.920 --> 00:18:05.279
<v Speaker 3>So yeah, and that so that now does have an

329
00:18:05.279 --> 00:18:09.599
<v Speaker 3>official patch that's come through. So if you're not auto updating,

330
00:18:09.599 --> 00:18:11.279
<v Speaker 3>shame on you go update. But if you are up

331
00:18:11.440 --> 00:18:14.759
<v Speaker 3>you know, auto updating, you probably defenders probably already patched.

332
00:18:14.960 --> 00:18:19.319
<v Speaker 1>Yeah, and or you will see a little Windows message,

333
00:18:19.440 --> 00:18:22.279
<v Speaker 1>you know, the little orange thing that says, you know,

334
00:18:22.440 --> 00:18:24.519
<v Speaker 1>updates need to you need to reboot in order to

335
00:18:24.559 --> 00:18:29.480
<v Speaker 1>install updates. Yeah, but we should. You should definitely automatically update.

336
00:18:29.519 --> 00:18:32.079
<v Speaker 1>The only reason I wouldn't is if I had a

337
00:18:32.079 --> 00:18:36.839
<v Speaker 1>specialized computer that was that needed to be up at

338
00:18:37.000 --> 00:18:40.200
<v Speaker 1>you know, a certain range of times. Sure, And I

339
00:18:40.240 --> 00:18:44.519
<v Speaker 1>think the days of Windows automatically updating and rebooting your

340
00:18:44.559 --> 00:18:45.759
<v Speaker 1>computer are gone.

341
00:18:45.920 --> 00:18:48.039
<v Speaker 2>Like in the enterprise, it's certainly been gone for a

342
00:18:48.079 --> 00:18:48.519
<v Speaker 2>long time.

343
00:18:48.680 --> 00:18:53.880
<v Speaker 1>Yeah, they might have allowed it and just obfuscated the

344
00:18:53.880 --> 00:18:57.599
<v Speaker 1>way to disable it or something, but I definitely remember

345
00:18:57.640 --> 00:18:59.160
<v Speaker 1>that happening. It happened to me in the middle of

346
00:18:59.160 --> 00:18:59.480
<v Speaker 1>the gig.

347
00:19:00.519 --> 00:19:03.279
<v Speaker 2>I think we need to get to the ability to

348
00:19:03.319 --> 00:19:07.160
<v Speaker 2>support like a chaos Monkey mentality. If you remember chaos Monkey,

349
00:19:07.200 --> 00:19:10.759
<v Speaker 2>it was where I think it was Netflix had so Yeah,

350
00:19:10.799 --> 00:19:14.960
<v Speaker 2>so that you you you allow you you you expect

351
00:19:15.000 --> 00:19:18.480
<v Speaker 2>every type of failure there can be all the time,

352
00:19:19.079 --> 00:19:22.200
<v Speaker 2>and you're you're completely redundant. And if we do that,

353
00:19:22.759 --> 00:19:25.720
<v Speaker 2>then we can allow things to patch immediately because the

354
00:19:25.759 --> 00:19:29.359
<v Speaker 2>patch is an expected potential down out down time. If

355
00:19:29.359 --> 00:19:31.680
<v Speaker 2>we don't get there, then we're just going to always

356
00:19:31.720 --> 00:19:33.920
<v Speaker 2>be late to the party and the hackers are gonna

357
00:19:34.480 --> 00:19:38.160
<v Speaker 2>we have to reinvent our patching strategy. And you're right, Carl,

358
00:19:38.519 --> 00:19:43.000
<v Speaker 2>Most most enterprises, most even medium companies, don't allow auto patch,

359
00:19:43.400 --> 00:19:44.920
<v Speaker 2>and it's going to get them owned.

360
00:19:45.839 --> 00:19:48.039
<v Speaker 1>Dump dump dumb, and that seems like a good place

361
00:19:48.079 --> 00:19:50.119
<v Speaker 1>to take a break. So we'll be right back after

362
00:19:50.160 --> 00:19:56.359
<v Speaker 1>these very important messages don't go away, and we're back.

363
00:19:56.400 --> 00:19:58.839
<v Speaker 1>It's security this week. I'm Carl, that's Patrick and Twain.

364
00:19:59.599 --> 00:20:02.519
<v Speaker 1>Got a up more stories here for you from last week.

365
00:20:03.920 --> 00:20:08.480
<v Speaker 1>AI coding agents found triggering endpoint security rules to build

366
00:20:08.680 --> 00:20:12.559
<v Speaker 1>a built to catch attackers. Just that you know, it's

367
00:20:12.559 --> 00:20:17.480
<v Speaker 1>like a whole story in one sentence, tell us the story.

368
00:20:17.839 --> 00:20:25.160
<v Speaker 3>It's okay. So Endpoint Detection and Response are EDRs. They're

369
00:20:25.200 --> 00:20:31.119
<v Speaker 3>looking for attackers doing crazy things, right, injecting things in

370
00:20:31.240 --> 00:20:35.079
<v Speaker 3>processes that shouldn't be there. You know, there's a cert

371
00:20:35.240 --> 00:20:38.880
<v Speaker 3>util dot ex, which is an execut one in your

372
00:20:38.880 --> 00:20:44.000
<v Speaker 3>computer that can download information like certificate information. But US attackers,

373
00:20:44.039 --> 00:20:47.119
<v Speaker 3>we use it to download payloads, right because it's on

374
00:20:47.400 --> 00:20:50.559
<v Speaker 3>every Windows computer and living off the land means I'm

375
00:20:50.559 --> 00:20:52.440
<v Speaker 3>going to use tools around the computer instead of bringing

376
00:20:52.480 --> 00:20:54.400
<v Speaker 3>my own because when I bring my own you might

377
00:20:54.480 --> 00:20:57.559
<v Speaker 3>notice it. So now all of your EDRs are going, aha,

378
00:20:57.680 --> 00:21:03.160
<v Speaker 3>if anybody uses cert util, that's weird. Right now, fast forward,

379
00:21:03.279 --> 00:21:07.599
<v Speaker 3>you have all of these these llms like that are

380
00:21:07.839 --> 00:21:11.559
<v Speaker 3>using coding, you know, code coding l lms like a

381
00:21:11.640 --> 00:21:14.640
<v Speaker 3>cloud code cursor, open as codex, etctera, that sort of

382
00:21:14.640 --> 00:21:21.640
<v Speaker 3>thing that those tools have been trained on, vast amounts

383
00:21:21.640 --> 00:21:25.200
<v Speaker 3>of programming information and data off the Internet and you

384
00:21:25.279 --> 00:21:27.960
<v Speaker 3>name it. So when they say, oh, we got to

385
00:21:28.000 --> 00:21:34.400
<v Speaker 3>go download and run this Python package, right, and they

386
00:21:34.599 --> 00:21:37.119
<v Speaker 3>they get denied going to you know, python dot org.

387
00:21:38.480 --> 00:21:41.079
<v Speaker 3>So they go, Okay, not a problem, I won't I

388
00:21:41.160 --> 00:21:43.640
<v Speaker 3>won't go try and pull it directly. Let me try

389
00:21:43.680 --> 00:21:46.799
<v Speaker 3>and download it with a PowerShell script. No that failed.

390
00:21:46.920 --> 00:21:49.920
<v Speaker 3>Let me use cert util, No that failed. Let me

391
00:21:50.039 --> 00:21:53.680
<v Speaker 3>use bits admin. Yep, Okay, that downloaded it. So we

392
00:21:53.799 --> 00:21:56.519
<v Speaker 3>goes to this path of let me do all of

393
00:21:56.599 --> 00:22:00.279
<v Speaker 3>the same things attackers do on the internet to yet

394
00:22:00.279 --> 00:22:03.480
<v Speaker 3>this package downloaded. And now that I have it, it

395
00:22:03.559 --> 00:22:06.319
<v Speaker 3>starts running things, etc. And when it runs into a problem,

396
00:22:06.640 --> 00:22:09.119
<v Speaker 3>what does y l on do? Statistically it finds the

397
00:22:09.119 --> 00:22:12.160
<v Speaker 3>next solution, which is what an attacker might do. So

398
00:22:12.279 --> 00:22:16.640
<v Speaker 3>the way that these you know IDEs for lack of

399
00:22:16.640 --> 00:22:21.759
<v Speaker 3>a better term, are integrating into the operating system, they

400
00:22:21.799 --> 00:22:25.359
<v Speaker 3>all look like attackers, right. It all looks like somebody

401
00:22:25.400 --> 00:22:28.079
<v Speaker 3>trying to break any your station and do things that

402
00:22:28.160 --> 00:22:33.400
<v Speaker 3>developers wouldn't normally do. That's the problem right now. So

403
00:22:33.400 --> 00:22:36.440
<v Speaker 3>SOFOS went through and did some analytics and was like,

404
00:22:36.519 --> 00:22:38.720
<v Speaker 3>you know what, a lot of our alarms went off

405
00:22:39.319 --> 00:22:43.559
<v Speaker 3>on legitimate development workstations using legitimate tools like claud code

406
00:22:43.599 --> 00:22:47.000
<v Speaker 3>and Cursor. Because claud code and Cursor don't know how

407
00:22:47.039 --> 00:22:51.160
<v Speaker 3>to say no. They just invent a solution, which may be,

408
00:22:52.039 --> 00:22:55.680
<v Speaker 3>you know, writing a PowerShell script and running it to

409
00:22:55.759 --> 00:22:59.519
<v Speaker 3>download something, or using a utility that nobody else would use.

410
00:23:00.119 --> 00:23:09.799
<v Speaker 3>There's this interesting site, is a the lulls Bins. We

411
00:23:09.839 --> 00:23:13.079
<v Speaker 3>can put it in this uh, we can put a

412
00:23:13.119 --> 00:23:15.960
<v Speaker 3>link with this show notes l O L B I

413
00:23:16.240 --> 00:23:19.240
<v Speaker 3>N Z if I'm correctly, and I'll get you the link.

414
00:23:19.279 --> 00:23:22.319
<v Speaker 3>But it's Living off the Land Binaries. And what it

415
00:23:22.400 --> 00:23:24.759
<v Speaker 3>is is it's a site where you can live as

416
00:23:24.759 --> 00:23:27.880
<v Speaker 3>an attacker. That's great attacker advice.

417
00:23:30.079 --> 00:23:31.400
<v Speaker 1>Should we play the theme song?

418
00:23:31.720 --> 00:23:32.880
<v Speaker 3>Probably? All right?

419
00:23:33.039 --> 00:23:33.400
<v Speaker 1>Hit it.

420
00:23:33.920 --> 00:23:41.680
<v Speaker 3>It's so the great thing about this site. And we'll

421
00:23:41.680 --> 00:23:43.960
<v Speaker 3>put a couple different links in there. There's the Living

422
00:23:44.039 --> 00:23:47.599
<v Speaker 3>off the lands Bins or binaries. There's also a g

423
00:23:47.720 --> 00:23:52.240
<v Speaker 3>T f O Bins out there. You can imagine what

424
00:23:52.279 --> 00:23:56.039
<v Speaker 3>that one stands for. So what you do as an

425
00:23:56.079 --> 00:23:58.160
<v Speaker 3>attacker as you go? What do I have access to.

426
00:23:58.799 --> 00:24:02.119
<v Speaker 3>If I have access to let's say I have access

427
00:24:02.160 --> 00:24:06.279
<v Speaker 3>to seven zip, right, which is just a compression utility,

428
00:24:06.440 --> 00:24:10.119
<v Speaker 3>how would I use that compression utility to gain administrative

429
00:24:10.160 --> 00:24:13.480
<v Speaker 3>access to this system? Or let's say I only have

430
00:24:13.599 --> 00:24:18.519
<v Speaker 3>access to PowerShell. How would I use PowerShell to download

431
00:24:19.039 --> 00:24:22.640
<v Speaker 3>my attacker package, like my reverse sheld or something along

432
00:24:22.640 --> 00:24:26.319
<v Speaker 3>those lines. Let's say I'm on a Linux workstation and

433
00:24:26.480 --> 00:24:29.400
<v Speaker 3>I can run Nana, which is just a text editor.

434
00:24:30.000 --> 00:24:32.319
<v Speaker 3>I can run a text editor as an admin, but

435
00:24:32.359 --> 00:24:34.119
<v Speaker 3>I can't do anything but at a text Is there

436
00:24:34.160 --> 00:24:36.839
<v Speaker 3>a way to get the text editor to give me

437
00:24:36.920 --> 00:24:41.480
<v Speaker 3>a shell as an admin as route right? So these

438
00:24:41.759 --> 00:24:45.880
<v Speaker 3>these sites, this living off the lands bins n GTFO

439
00:24:46.039 --> 00:24:50.640
<v Speaker 3>bins there. Think of it, for lack of a better term,

440
00:24:50.680 --> 00:24:53.000
<v Speaker 3>as like a dictionary, a lookup where you can type

441
00:24:53.000 --> 00:24:55.519
<v Speaker 3>in the name of an executable that's on that computer

442
00:24:55.599 --> 00:24:57.279
<v Speaker 3>that would normally be there, and it will give you

443
00:24:57.359 --> 00:25:01.039
<v Speaker 3>like ten different ways to abusively use the wow to

444
00:25:01.160 --> 00:25:03.720
<v Speaker 3>either get access to the system and a system and

445
00:25:03.759 --> 00:25:06.759
<v Speaker 3>in a strative way, or download packages and that sort

446
00:25:06.759 --> 00:25:07.079
<v Speaker 3>of stuff.

447
00:25:07.079 --> 00:25:08.599
<v Speaker 1>All right, So this is great if you're a hacker,

448
00:25:08.640 --> 00:25:10.480
<v Speaker 1>but what if you're trying to prevent this stuff. Can

449
00:25:10.480 --> 00:25:12.519
<v Speaker 1>you use this for preventative measures?

450
00:25:14.680 --> 00:25:16.400
<v Speaker 3>I've never done that. I don't know what you're talking about.

451
00:25:17.720 --> 00:25:21.359
<v Speaker 3>So it's it's let me, let me choose this preventative

452
00:25:21.400 --> 00:25:27.000
<v Speaker 3>measures your business to prevent people from a figure out.

453
00:25:28.440 --> 00:25:30.559
<v Speaker 2>What you could do is you could look at this,

454
00:25:30.680 --> 00:25:33.079
<v Speaker 2>which no one does, and you could figure out what

455
00:25:33.240 --> 00:25:36.039
<v Speaker 2>things you can remove from your environment to minimize the

456
00:25:36.039 --> 00:25:38.240
<v Speaker 2>attack surface. In other words, you can use this as

457
00:25:38.279 --> 00:25:42.200
<v Speaker 2>a window into well, I don't use nano on this box.

458
00:25:42.440 --> 00:25:45.079
<v Speaker 2>Why do I keep it around? Why do I let

459
00:25:45.119 --> 00:25:47.160
<v Speaker 2>it run? Why do I let it run? In that context?

460
00:25:47.200 --> 00:25:48.920
<v Speaker 1>Yeah, just thinking about it for a minute, when you

461
00:25:48.920 --> 00:25:50.319
<v Speaker 1>should get rid of it. I would have come to

462
00:25:50.359 --> 00:25:51.960
<v Speaker 1>that conclusion eventually.

463
00:25:51.720 --> 00:25:54.279
<v Speaker 2>Eventually, and then you wouldn't have done it.

464
00:25:54.319 --> 00:25:56.960
<v Speaker 1>By the thought process, would you have done it?

465
00:25:57.000 --> 00:26:00.480
<v Speaker 2>Is the question. The problem is that securities attack. Everyone

466
00:26:00.519 --> 00:26:03.720
<v Speaker 2>looks at security as an overhead that we don't want

467
00:26:03.720 --> 00:26:07.759
<v Speaker 2>to pay for because it's not assured to pay off, right,

468
00:26:08.359 --> 00:26:11.640
<v Speaker 2>But in the aggregate it pays off. It's just it's

469
00:26:11.640 --> 00:26:16.160
<v Speaker 2>it's it's a fundamental psychology. And unfortunately, I don't know

470
00:26:16.240 --> 00:26:18.200
<v Speaker 2>that we're going to fix people, but they're they're going

471
00:26:18.279 --> 00:26:19.720
<v Speaker 2>to learn the hard way. There's a lot of hot

472
00:26:19.759 --> 00:26:22.880
<v Speaker 2>stoves out there, uh that they're going to be touching

473
00:26:22.920 --> 00:26:23.200
<v Speaker 2>a lot.

474
00:26:23.519 --> 00:26:24.839
<v Speaker 3>Okay, I'm going to give you an example.

475
00:26:25.000 --> 00:26:27.359
<v Speaker 1>Okay, are you going to get us in trouble?

476
00:26:27.440 --> 00:26:31.160
<v Speaker 3>Pick an execute a ball now, pick an executaball like

477
00:26:31.400 --> 00:26:36.079
<v Speaker 3>FTP for example. Okay, Uh, there is a a exclamation

478
00:26:36.160 --> 00:26:38.799
<v Speaker 3>point s command you can feed to FTP dot exe

479
00:26:39.599 --> 00:26:41.720
<v Speaker 3>and then feed it the name of a file and

480
00:26:41.759 --> 00:26:45.920
<v Speaker 3>it will actually run everything in that file. Why is

481
00:26:45.960 --> 00:26:51.200
<v Speaker 3>it there? Who the hell knows? But fine string is

482
00:26:51.240 --> 00:26:55.079
<v Speaker 3>in here where you can actually manipulate credentials and get

483
00:26:55.640 --> 00:26:59.640
<v Speaker 3>fine string to download things over the internet. All sorts

484
00:26:59.640 --> 00:27:04.359
<v Speaker 3>of crazy right, rep fantastic yep, absolutely So there's all

485
00:27:04.400 --> 00:27:07.079
<v Speaker 3>sorts of neat ways for you to use these applications

486
00:27:07.119 --> 00:27:09.000
<v Speaker 3>sert utils in here. Do you want to go through

487
00:27:09.039 --> 00:27:10.720
<v Speaker 3>and take a look at what they were doing what

488
00:27:10.720 --> 00:27:13.759
<v Speaker 3>we were talking about on this article. So lots of

489
00:27:13.759 --> 00:27:17.039
<v Speaker 3>neat ways to manipulate normal executables that will be on

490
00:27:17.160 --> 00:27:19.160
<v Speaker 3>every computer to do your bidding.

491
00:27:19.359 --> 00:27:21.880
<v Speaker 1>Okay, if you're not scared by now, you will be.

492
00:27:22.440 --> 00:27:23.880
<v Speaker 2>Uh you haven't been paying attention?

493
00:27:24.000 --> 00:27:29.599
<v Speaker 1>Yeah, yeah, all right, let's move on hackers, exploit Microsoft

494
00:27:29.960 --> 00:27:35.480
<v Speaker 1>Entra pass key enrollment to hijack accounts. Entra is the

495
00:27:35.519 --> 00:27:38.079
<v Speaker 1>new name for what used to be called Azure D.

496
00:27:38.400 --> 00:27:39.039
<v Speaker 3>Was it AZERI D.

497
00:27:39.119 --> 00:27:42.160
<v Speaker 1>It's been so long, Azure D. That's right, active directory?

498
00:27:42.359 --> 00:27:45.200
<v Speaker 3>Yeah, you know what I like d AZUAD me too.

499
00:27:45.359 --> 00:27:48.400
<v Speaker 3>We weren't from active directory to Azure active directory and

500
00:27:48.400 --> 00:27:52.359
<v Speaker 3>that seemed logical. And then they're like Entrara and tr

501
00:27:52.480 --> 00:27:54.640
<v Speaker 3>id and you're like, you know, maybe they're making up

502
00:27:54.720 --> 00:27:59.279
<v Speaker 3>for decades of horrible product names. Were like Bob. Do

503
00:27:59.319 --> 00:28:00.759
<v Speaker 3>you remember my Bob was.

504
00:28:00.720 --> 00:28:03.720
<v Speaker 1>Actually concise in three letters? And that's good. You knew

505
00:28:03.759 --> 00:28:05.240
<v Speaker 1>what it is. You didn't like it, but you knew

506
00:28:05.240 --> 00:28:12.720
<v Speaker 1>what it was. But you know Microsoft Presentation Foundation Foundation, Yes, yes,

507
00:28:13.079 --> 00:28:15.000
<v Speaker 1>Windows Communication Foundations.

508
00:28:15.160 --> 00:28:18.640
<v Speaker 3>Silver Light, well, if anybody on the podcast can tell

509
00:28:18.680 --> 00:28:20.160
<v Speaker 3>me what silver light does.

510
00:28:20.319 --> 00:28:24.359
<v Speaker 1>Actually, that was named after employee David silver Light. No,

511
00:28:24.400 --> 00:28:25.839
<v Speaker 1>it was not absolutely.

512
00:28:25.960 --> 00:28:28.200
<v Speaker 3>Oh my god, that's awesome actually according.

513
00:28:27.880 --> 00:28:36.160
<v Speaker 1>To him anyway, Sorry David. He's a good guy though,

514
00:28:36.200 --> 00:28:36.960
<v Speaker 1>he really is.

515
00:28:37.880 --> 00:28:40.160
<v Speaker 3>But the name does not tell you what it does.

516
00:28:40.559 --> 00:28:42.440
<v Speaker 1>Now he has to walk around with his head down.

517
00:28:42.559 --> 00:28:46.119
<v Speaker 2>Basically, silver Light was the Flash. He's the flash equivalent for.

518
00:28:46.599 --> 00:28:49.880
<v Speaker 3>Microsoft and now I will ask how many people know

519
00:28:49.880 --> 00:28:55.519
<v Speaker 3>what flash is because that doesn't exist either equivalent exactly.

520
00:28:55.640 --> 00:28:56.559
<v Speaker 3>Thank you Patrick.

521
00:28:58.759 --> 00:29:02.039
<v Speaker 1>All right, so what happened in this exploit? All right?

522
00:29:02.079 --> 00:29:06.720
<v Speaker 3>So this this sounds super technical with people you know,

523
00:29:07.200 --> 00:29:13.079
<v Speaker 3>enrolling hacker, MFA past key, blah blah. It's a social

524
00:29:13.079 --> 00:29:16.640
<v Speaker 3>engineering attack, that's all it is. So in this case,

525
00:29:16.720 --> 00:29:19.240
<v Speaker 3>attackers would call up and say, oh my gosh, you

526
00:29:19.319 --> 00:29:24.880
<v Speaker 3>have to change your access to our Microsoft systems. You know,

527
00:29:25.119 --> 00:29:28.920
<v Speaker 3>here is a pass key, click here, click here, swap

528
00:29:29.000 --> 00:29:31.079
<v Speaker 3>your pass key out? Can you do that for us?

529
00:29:31.119 --> 00:29:33.400
<v Speaker 3>And they'll say, yeah, sure, it's done. They go okay, thanks.

530
00:29:33.599 --> 00:29:36.039
<v Speaker 3>It's literally like calling someone up and saying, hey, your

531
00:29:36.039 --> 00:29:39.440
<v Speaker 3>password sucks. I have a better one for you. Can

532
00:29:39.519 --> 00:29:42.960
<v Speaker 3>you just use this one instead? And they go yeah, sure, thanks,

533
00:29:42.960 --> 00:29:46.720
<v Speaker 3>I really appreciate it. Random dude on the internet. Like

534
00:29:48.000 --> 00:29:52.440
<v Speaker 3>the moral of the story here is just don't don't

535
00:29:52.480 --> 00:29:53.279
<v Speaker 3>I guess.

536
00:29:53.039 --> 00:29:54.440
<v Speaker 2>Don't take candy from strangers.

537
00:29:54.559 --> 00:29:59.279
<v Speaker 3>Yeah, and be able to better be able to identify strangers, right,

538
00:29:59.400 --> 00:30:01.200
<v Speaker 3>Like if somebody calls up and say they work in

539
00:30:01.240 --> 00:30:03.680
<v Speaker 3>the security department of your organization, have a way of

540
00:30:03.720 --> 00:30:04.160
<v Speaker 3>checking that.

541
00:30:04.359 --> 00:30:06.000
<v Speaker 2>So I got to tell a story. I'll tell the

542
00:30:06.039 --> 00:30:09.480
<v Speaker 2>story about the rubber company, Dwayne. Oh, So, we have

543
00:30:09.559 --> 00:30:14.480
<v Speaker 2>a you know, consulting arm and occasionally, you know, people

544
00:30:14.559 --> 00:30:17.799
<v Speaker 2>will find my email instead of the people they should

545
00:30:18.000 --> 00:30:21.920
<v Speaker 2>find email. And I usually ignore those messages because it's

546
00:30:21.960 --> 00:30:25.440
<v Speaker 2>just such a high standard of spam and junk. And

547
00:30:26.160 --> 00:30:29.400
<v Speaker 2>so I got this well written at email from someone

548
00:30:29.400 --> 00:30:33.200
<v Speaker 2>who claimed to be the CEO of a small manufacturing

549
00:30:33.240 --> 00:30:36.480
<v Speaker 2>company and the name checked out, and I went on

550
00:30:36.519 --> 00:30:39.000
<v Speaker 2>LinkedIn and the person checked out. I said, you know, what,

551
00:30:38.759 --> 00:30:40.759
<v Speaker 2>what the hell? I'll answer them that you know, we're

552
00:30:41.000 --> 00:30:43.319
<v Speaker 2>we might we're interested to hear about their project. And

553
00:30:43.960 --> 00:30:45.920
<v Speaker 2>I sent them an email and they sent me an

554
00:30:45.920 --> 00:30:48.880
<v Speaker 2>email back and said, oh, you know calendar You know

555
00:30:48.960 --> 00:30:53.160
<v Speaker 2>the Calendi link calendarly, Yeah, Calendly. And I looked at

556
00:30:53.160 --> 00:30:53.839
<v Speaker 2>it and I'm like.

557
00:30:54.319 --> 00:30:56.640
<v Speaker 1>Well, for those who don't know, that's it's a way

558
00:30:56.680 --> 00:30:58.720
<v Speaker 1>that you can let people who want to talk to

559
00:30:58.759 --> 00:31:00.680
<v Speaker 1>you pick a time that's available for you.

560
00:31:00.839 --> 00:31:03.279
<v Speaker 2>Yeah, And I hate it because it makes me click

561
00:31:03.319 --> 00:31:03.839
<v Speaker 2>on something.

562
00:31:03.960 --> 00:31:05.640
<v Speaker 1>So I look, well, you hate using it or do

563
00:31:05.680 --> 00:31:07.680
<v Speaker 1>you hate using it to get people with Oh?

564
00:31:07.759 --> 00:31:10.440
<v Speaker 2>No, I pretty much don't click on it. If you

565
00:31:10.640 --> 00:31:12.480
<v Speaker 2>if you give me something to click on I'm not

566
00:31:12.519 --> 00:31:13.119
<v Speaker 2>clicking on it.

567
00:31:13.240 --> 00:31:15.640
<v Speaker 1>Oh yeah, yeah. So somebody wants you to use it

568
00:31:15.839 --> 00:31:17.400
<v Speaker 1>to set an appointment with them, you won't.

569
00:31:17.559 --> 00:31:19.720
<v Speaker 2>Yeah, So my spidy sense went off and I'm like,

570
00:31:20.160 --> 00:31:22.720
<v Speaker 2>you know what, I'm not going to email them back.

571
00:31:23.480 --> 00:31:25.880
<v Speaker 2>I'm gonna open it up on a place that I

572
00:31:25.920 --> 00:31:28.480
<v Speaker 2>know is safe, that even if it's bad. Right, And

573
00:31:28.720 --> 00:31:30.640
<v Speaker 2>I opened it up and looked at it, and it

574
00:31:30.720 --> 00:31:34.119
<v Speaker 2>was the wrong domain. It wasn't the domain of the

575
00:31:34.160 --> 00:31:36.119
<v Speaker 2>actual company. Because I actually found the domain. It was

576
00:31:36.160 --> 00:31:39.279
<v Speaker 2>a dot net instead of a dot com. Oh and

577
00:31:40.599 --> 00:31:43.400
<v Speaker 2>it wanted me to log in with my office three

578
00:31:43.480 --> 00:31:47.640
<v Speaker 2>sixty five and I'm like, not today, Satan, Nope, So

579
00:31:47.799 --> 00:31:48.960
<v Speaker 2>it can happen anyway.

580
00:31:49.039 --> 00:31:49.559
<v Speaker 3>I came.

581
00:31:50.079 --> 00:31:52.279
<v Speaker 2>I guess I didn't come too close, but I could

582
00:31:52.319 --> 00:31:55.160
<v Speaker 2>have come close if I wasn't as as paranoid as

583
00:31:55.160 --> 00:31:57.519
<v Speaker 2>I am. And so I really think people need to

584
00:31:57.519 --> 00:31:58.319
<v Speaker 2>be more paranoid.

585
00:31:58.519 --> 00:32:01.559
<v Speaker 3>Yeah all yeah, and laugh.

586
00:32:01.680 --> 00:32:03.839
<v Speaker 1>I laugh and have a sense of humor. That's right.

587
00:32:03.880 --> 00:32:04.759
<v Speaker 1>They offset each other.

588
00:32:04.839 --> 00:32:06.839
<v Speaker 2>But you should also think about what you're asking other

589
00:32:06.839 --> 00:32:10.079
<v Speaker 2>people to do. If I know you, like if Carl,

590
00:32:10.119 --> 00:32:12.119
<v Speaker 2>if you sent me a link, I wouldn't do a Dwayne.

591
00:32:12.200 --> 00:32:14.079
<v Speaker 2>But if if you sent me a link, I would

592
00:32:14.119 --> 00:32:18.000
<v Speaker 2>probably click on it and I would verify, but I

593
00:32:18.039 --> 00:32:20.359
<v Speaker 2>would verify it's you. I would probably call you up

594
00:32:20.359 --> 00:32:23.000
<v Speaker 2>and say, did you actually send me this link? And

595
00:32:23.039 --> 00:32:26.200
<v Speaker 2>I had a customer, a longtime customer of ours, send

596
00:32:26.200 --> 00:32:28.559
<v Speaker 2>me a link and I'm like, I'm not clicking on

597
00:32:28.559 --> 00:32:30.680
<v Speaker 2>this link. So I me messaged him outside. I said,

598
00:32:30.680 --> 00:32:33.160
<v Speaker 2>did you send me that link? Because it was they

599
00:32:33.160 --> 00:32:35.559
<v Speaker 2>had no context, and he like, oh no, my email

600
00:32:35.599 --> 00:32:35.880
<v Speaker 2>was hacked.

601
00:32:35.920 --> 00:32:38.200
<v Speaker 3>It's funny you say that this morning. I have a

602
00:32:38.240 --> 00:32:40.039
<v Speaker 3>contacted Department of Homeland Security.

603
00:32:40.279 --> 00:32:41.240
<v Speaker 2>Anyway, you fished him.

604
00:32:41.400 --> 00:32:45.200
<v Speaker 3>No, he sent me a link, and I was like, eh,

605
00:32:46.359 --> 00:32:47.200
<v Speaker 3>I don't think the thing.

606
00:32:47.440 --> 00:32:50.119
<v Speaker 1>Even if you know the people, that doesn't mean that

607
00:32:50.160 --> 00:32:50.960
<v Speaker 1>the link isn't.

608
00:32:51.119 --> 00:32:57.799
<v Speaker 3>Oh no, and a town because increases the chance what happens.

609
00:32:58.000 --> 00:33:00.519
<v Speaker 1>They might have seen a story on Facebook which could

610
00:33:00.559 --> 00:33:03.039
<v Speaker 1>totally be an attack, and surely don't know. They just

611
00:33:03.079 --> 00:33:05.279
<v Speaker 1>read the headline they forwarded to you without reading it.

612
00:33:05.319 --> 00:33:07.680
<v Speaker 2>Well, in this case, the customer was actually his email

613
00:33:07.720 --> 00:33:11.400
<v Speaker 2>was compromised, and I caught it and told him, and

614
00:33:11.440 --> 00:33:13.759
<v Speaker 2>he had already known, but it could have been the

615
00:33:13.759 --> 00:33:16.559
<v Speaker 2>first time he found out, and you know, he could

616
00:33:16.599 --> 00:33:22.000
<v Speaker 2>have infect caused because he let his email get hacked, right,

617
00:33:22.039 --> 00:33:24.039
<v Speaker 2>it could have caused many of his customers to get hacked,

618
00:33:24.079 --> 00:33:26.240
<v Speaker 2>and that's not a good way to help business.

619
00:33:26.000 --> 00:33:26.519
<v Speaker 1>No boy know.

620
00:33:27.039 --> 00:33:31.079
<v Speaker 3>And for the record, on this story, this is the

621
00:33:31.200 --> 00:33:35.000
<v Speaker 3>Pink extortion crew. If you're following names, if on your

622
00:33:35.039 --> 00:33:38.319
<v Speaker 3>BINGO sheet, you can't find O dash UNC DASH zero

623
00:33:38.400 --> 00:33:42.440
<v Speaker 3>sixty six, which is what the security researcher is attributing

624
00:33:42.480 --> 00:33:46.559
<v Speaker 3>this to. That's because the attacker is actually a cl

625
00:33:46.920 --> 00:33:50.319
<v Speaker 3>cr I one one four seven. So just in case

626
00:33:50.839 --> 00:33:53.039
<v Speaker 3>you were really kind of digging into his we were

627
00:33:53.039 --> 00:33:56.640
<v Speaker 3>doing background checks obviously on the stories the attacker mentioned

628
00:33:56.720 --> 00:34:01.359
<v Speaker 3>in this article. Their designated number we can't find anywhere,

629
00:34:01.400 --> 00:34:03.720
<v Speaker 3>but there are many other places like the registering Unit

630
00:34:03.759 --> 00:34:07.119
<v Speaker 3>forty two and hack read that have the number.

631
00:34:07.240 --> 00:34:09.480
<v Speaker 1>Right, So, you know, I love Pink. I didn't know

632
00:34:09.599 --> 00:34:10.760
<v Speaker 1>she was in a hacking too.

633
00:34:11.360 --> 00:34:14.440
<v Speaker 3>Hacker. He's in everything. Anybody was a hacker, it would

634
00:34:14.440 --> 00:34:15.360
<v Speaker 3>be Pink. Honestly.

635
00:34:15.840 --> 00:34:19.239
<v Speaker 1>You know, you're probably right. She's badass, isn't she.

636
00:34:19.559 --> 00:34:19.800
<v Speaker 3>Yeah?

637
00:34:19.960 --> 00:34:24.840
<v Speaker 1>Oh yeah, yeah, all right. Now for the feature story

638
00:34:24.960 --> 00:34:31.039
<v Speaker 1>of this week's show, AI powered Attack compromises AWS cloud

639
00:34:31.599 --> 00:34:34.320
<v Speaker 1>In seventy two hours.

640
00:34:33.960 --> 00:34:36.039
<v Speaker 3>We can't report on this as an internal project.

641
00:34:40.199 --> 00:34:49.440
<v Speaker 1>And it wasn't seventy two, it was forty six. Yeah, sometimes.

642
00:34:51.880 --> 00:34:54.440
<v Speaker 3>So this is yeah, this is a fun story.

643
00:34:56.519 --> 00:34:58.719
<v Speaker 2>So said no one on the receiving end.

644
00:34:59.000 --> 00:35:02.519
<v Speaker 3>I know, right. So we talk about attacks happening at

645
00:35:02.519 --> 00:35:07.000
<v Speaker 3>AI speed, right, and at computer speed, And we've talked

646
00:35:07.000 --> 00:35:08.559
<v Speaker 3>about this in the past where we're like, listen, a

647
00:35:08.639 --> 00:35:11.159
<v Speaker 3>majority of the times, most of the time, it's not

648
00:35:11.199 --> 00:35:14.199
<v Speaker 3>an AI hacking you. It might be AI facilitated, it

649
00:35:14.280 --> 00:35:16.880
<v Speaker 3>might be AI assisted, it might be that there's a

650
00:35:16.920 --> 00:35:19.119
<v Speaker 3>pipeline on the back end that an AI has access to,

651
00:35:19.280 --> 00:35:24.360
<v Speaker 3>but there's still operators who are using these pipelines. What

652
00:35:24.440 --> 00:35:27.719
<v Speaker 3>we're starting to see here is more of that pipeline

653
00:35:27.760 --> 00:35:31.760
<v Speaker 3>get automated. So in this particular case, one of the

654
00:35:32.679 --> 00:35:34.760
<v Speaker 3>this is I mean, this is a classic break into

655
00:35:34.760 --> 00:35:38.360
<v Speaker 3>an application, steal aws keys and then start you know,

656
00:35:39.719 --> 00:35:43.440
<v Speaker 3>wreaking havoc. But the one of the things a couple

657
00:35:43.519 --> 00:35:47.840
<v Speaker 3>different actually things in here that pointed to this being

658
00:35:47.880 --> 00:35:52.679
<v Speaker 3>an AI attacker is a there were a series of

659
00:35:52.960 --> 00:35:58.199
<v Speaker 3>four access keys created in sub millisecond time and used

660
00:35:59.280 --> 00:36:03.320
<v Speaker 3>not something I mean, our team's good, but by hand,

661
00:36:03.440 --> 00:36:04.920
<v Speaker 3>we're not doing.

662
00:36:04.639 --> 00:36:06.599
<v Speaker 1>That yeah, nobody's doing that by hand.

663
00:36:06.440 --> 00:36:10.719
<v Speaker 3>Absolutely, So that was one indicator. The other indicator is

664
00:36:10.760 --> 00:36:15.519
<v Speaker 3>there was a lot of I'm going to call it detritus,

665
00:36:15.559 --> 00:36:19.880
<v Speaker 3>but there was a lot of ancillary files and things

666
00:36:20.039 --> 00:36:25.639
<v Speaker 3>put on the attacked systems to make it look like

667
00:36:25.760 --> 00:36:30.239
<v Speaker 3>a pen test. So they were trying to manipulate the

668
00:36:30.280 --> 00:36:34.079
<v Speaker 3>indicators a compromise, and they were trying to slow down forensics.

669
00:36:34.880 --> 00:36:38.679
<v Speaker 3>But the speed at which and the detail with which

670
00:36:38.800 --> 00:36:43.199
<v Speaker 3>those indicators were placed would also yet again not human

671
00:36:44.559 --> 00:36:48.559
<v Speaker 3>and that interestingly enough to bypass guardrails on an AI

672
00:36:48.639 --> 00:36:52.000
<v Speaker 3>to get it to do an attack. You can't say, hey,

673
00:36:52.000 --> 00:36:54.440
<v Speaker 3>I want to bring down bag of America because it'll

674
00:36:54.480 --> 00:36:56.960
<v Speaker 3>go No. I can't do that, especially the frontier models.

675
00:36:57.480 --> 00:37:00.840
<v Speaker 3>So anything that's not running locally local ones, you can

676
00:37:00.840 --> 00:37:07.320
<v Speaker 3>strip all those guardrails off. But any anything sitting exactly

677
00:37:07.920 --> 00:37:10.239
<v Speaker 3>you run it local, it's fine. Well, the other thing

678
00:37:10.320 --> 00:37:13.000
<v Speaker 3>is if you convince a frontier model that you are

679
00:37:13.000 --> 00:37:17.840
<v Speaker 3>a pen testing company, the frontier model is more likely

680
00:37:17.920 --> 00:37:21.559
<v Speaker 3>to help you attack a place. So in this particular case,

681
00:37:21.639 --> 00:37:27.760
<v Speaker 3>the theory is that they were actually had convinced a

682
00:37:27.800 --> 00:37:32.440
<v Speaker 3>frontier model, you know, an anthropic or whatever, that this

683
00:37:32.559 --> 00:37:34.960
<v Speaker 3>is a penta. This was a paid legitimate pen test.

684
00:37:35.400 --> 00:37:36.239
<v Speaker 3>I'm end to go do that.

685
00:37:36.480 --> 00:37:39.480
<v Speaker 2>And we've experienced that where the more we deal with it.

686
00:37:39.440 --> 00:37:40.480
<v Speaker 1>I mean, Dwayne, you've done that.

687
00:37:40.920 --> 00:37:42.440
<v Speaker 3>I can't confirm or deny.

688
00:37:43.559 --> 00:37:46.440
<v Speaker 2>Yeah, but over time, an AI will kind of get

689
00:37:46.480 --> 00:37:49.360
<v Speaker 2>to feel like it at least it seems like it

690
00:37:49.400 --> 00:37:51.480
<v Speaker 2>feels like it gets to know you and what your

691
00:37:51.480 --> 00:37:54.159
<v Speaker 2>intent is, and so things it would say in the

692
00:37:54.199 --> 00:37:57.360
<v Speaker 2>first week, No, it would say, well, you shouldn't do that,

693
00:37:57.480 --> 00:37:59.159
<v Speaker 2>but let's talk about it.

694
00:38:00.559 --> 00:38:02.360
<v Speaker 1>I can't say this never mind, yeah, never mind.

695
00:38:03.039 --> 00:38:05.079
<v Speaker 2>Wow, he developed a filter.

696
00:38:06.719 --> 00:38:09.039
<v Speaker 3>No, there are certain things I won't say, but let

697
00:38:09.039 --> 00:38:10.559
<v Speaker 3>me let me put it this way.

698
00:38:10.719 --> 00:38:12.239
<v Speaker 2>I haven't seen that very often.

699
00:38:12.840 --> 00:38:14.800
<v Speaker 1>Now he's just gonna say it a different way.

700
00:38:14.960 --> 00:38:21.519
<v Speaker 4>But so, Panton, let's say, are you sure you want

701
00:38:21.559 --> 00:38:23.960
<v Speaker 4>to say what we have time for? Let's say your

702
00:38:24.119 --> 00:38:27.000
<v Speaker 4>let's say your AI did kind of develop a conscience.

703
00:38:28.480 --> 00:38:32.639
<v Speaker 4>What's really great is for when it goes, well, absolutely

704
00:38:32.679 --> 00:38:37.920
<v Speaker 4>don't run this command. That would compromise everything, and.

705
00:38:37.840 --> 00:38:40.000
<v Speaker 3>I go to it and go. But if I ran

706
00:38:40.039 --> 00:38:42.400
<v Speaker 3>in and I saw this output, what would that mean

707
00:38:42.440 --> 00:38:44.599
<v Speaker 3>and it goes, oh, man, that would mean you have

708
00:38:44.719 --> 00:38:47.760
<v Speaker 3>access to the whole system. Geez, you shouldn't look in

709
00:38:47.800 --> 00:38:50.280
<v Speaker 3>that secret directory. That's probably where all the good stuff.

710
00:38:50.360 --> 00:38:53.079
<v Speaker 5>So just asking it what shouldn't I do is a

711
00:38:53.119 --> 00:38:58.320
<v Speaker 5>good I'm just saying if eventually your frontier models, hopefully

712
00:38:58.320 --> 00:39:02.400
<v Speaker 5>anthropics not listening, eventually your frontier models will kind of

713
00:39:02.440 --> 00:39:05.320
<v Speaker 5>be like wait a second, and you can be like, well, yeah, no,

714
00:39:05.440 --> 00:39:08.400
<v Speaker 5>I absolutely didn't run that, and it absolutely didn't give

715
00:39:08.440 --> 00:39:10.239
<v Speaker 5>me this output, But what do you think?

716
00:39:10.400 --> 00:39:12.760
<v Speaker 2>But if it did, then it would have been did.

717
00:39:12.960 --> 00:39:15.239
<v Speaker 3>Just what would you do next? And it's like, well,

718
00:39:15.239 --> 00:39:17.360
<v Speaker 3>I wouldn't run this, and I'm like I won't run

719
00:39:17.360 --> 00:39:18.159
<v Speaker 3>it either then.

720
00:39:18.400 --> 00:39:21.360
<v Speaker 1>So so there you go. The broader implication of this,

721
00:39:21.400 --> 00:39:24.239
<v Speaker 1>according to the article, is because you know A has

722
00:39:24.280 --> 00:39:28.840
<v Speaker 1>been documented significantly compress the timeliness of cloud based attacks,

723
00:39:29.599 --> 00:39:35.639
<v Speaker 1>that AI removes traditional friction from attacks like there's it's

724
00:39:35.679 --> 00:39:36.719
<v Speaker 1>only going to get worse.

725
00:39:37.320 --> 00:39:40.719
<v Speaker 3>Yeah, absolutely, and from the defense side, because we always

726
00:39:40.760 --> 00:39:42.960
<v Speaker 3>like the call to action like what can okay, what

727
00:39:43.000 --> 00:39:44.440
<v Speaker 3>can the customer do? This is great? We have an

728
00:39:44.440 --> 00:39:49.559
<v Speaker 3>AI attacking people. Vulnerability assessments are always good, right, Detecting

729
00:39:49.559 --> 00:39:51.679
<v Speaker 3>the fact that those keys could have been pulled would

730
00:39:51.679 --> 00:39:53.800
<v Speaker 3>have stopped this attack. You know that would have been

731
00:39:53.840 --> 00:39:56.920
<v Speaker 3>part of the killed chain. You know, tight I am,

732
00:39:57.079 --> 00:40:00.280
<v Speaker 3>and least privileges in how you're managing your key and

733
00:40:00.280 --> 00:40:03.960
<v Speaker 3>what those keys have access to, continuous rotation and monitoring

734
00:40:03.960 --> 00:40:08.800
<v Speaker 3>of the use of those keys, watch for impossible concurrency,

735
00:40:10.239 --> 00:40:14.239
<v Speaker 3>you know, multiple keys created, multiple ips. You know, under

736
00:40:14.280 --> 00:40:19.800
<v Speaker 3>one IP in a sub millisecond is a dead giveaway. Yeah,

737
00:40:19.840 --> 00:40:21.639
<v Speaker 3>and these so these would be the ones I would

738
00:40:21.639 --> 00:40:24.039
<v Speaker 3>be looking for, especially if I'm I'm looking to thwart

739
00:40:24.119 --> 00:40:25.239
<v Speaker 3>something that's at AI spin.

740
00:40:25.280 --> 00:40:28.119
<v Speaker 1>And once again I have to ask that there's a

741
00:40:28.360 --> 00:40:32.800
<v Speaker 1>crying I'm crying out there's a need for tools that

742
00:40:32.960 --> 00:40:38.400
<v Speaker 1>use AI to thwart attacks in real time. And you know, Patrick,

743
00:40:38.480 --> 00:40:40.280
<v Speaker 1>every time I bring this up to you, that's what

744
00:40:40.360 --> 00:40:43.440
<v Speaker 1>glass Wing's all about. Yeah, last time I brought this

745
00:40:43.519 --> 00:40:45.280
<v Speaker 1>up to you said, yeah, well, we're not there yet,

746
00:40:45.320 --> 00:40:47.880
<v Speaker 1>and we probably won't be, and the hackers are always

747
00:40:47.880 --> 00:40:50.400
<v Speaker 1>going to be ahead of us. But I just can't

748
00:40:50.440 --> 00:40:52.920
<v Speaker 1>believe that there's got to be something.

749
00:40:53.039 --> 00:40:55.480
<v Speaker 3>So there there are a lot of grants out there

750
00:40:55.559 --> 00:41:00.599
<v Speaker 3>right now for a team to discover the right way

751
00:41:00.639 --> 00:41:04.480
<v Speaker 3>to start monitoring networks and protocols and that sort of stuff.

752
00:41:04.960 --> 00:41:10.960
<v Speaker 3>The problem is to do this right. You would need

753
00:41:11.000 --> 00:41:14.280
<v Speaker 3>an AI that could take in every feed of everything

754
00:41:14.280 --> 00:41:16.679
<v Speaker 3>that happens on your network and then understand what's normal.

755
00:41:16.639 --> 00:41:19.239
<v Speaker 1>And also give it permission to take action because the

756
00:41:21.000 --> 00:41:22.760
<v Speaker 1>discovered they have to be shut down.

757
00:41:22.639 --> 00:41:27.400
<v Speaker 3>Right, and protocol analysis is tough, especially if it's something

758
00:41:27.400 --> 00:41:30.079
<v Speaker 3>you don't have the code to. It's actually one of

759
00:41:30.119 --> 00:41:34.079
<v Speaker 3>the most expensive things we can do is analyzing a

760
00:41:34.119 --> 00:41:37.840
<v Speaker 3>protocol we don't have. We don't have access to the code,

761
00:41:38.599 --> 00:41:40.159
<v Speaker 3>and we do it sometimes when we're like, hey, there's

762
00:41:40.199 --> 00:41:43.760
<v Speaker 3>this weird signal coming off this box. We have a

763
00:41:43.880 --> 00:41:46.440
<v Speaker 3>pipeline that we will run things through and it usually

764
00:41:46.480 --> 00:41:49.880
<v Speaker 3>takes days for it to go Okay, I've mapped out

765
00:41:49.920 --> 00:41:52.440
<v Speaker 3>this entire protocol. This is what this looks like. So

766
00:41:53.239 --> 00:41:55.320
<v Speaker 3>I think you'd have to find better ways to tap

767
00:41:55.360 --> 00:42:00.760
<v Speaker 3>the networks and see all traffic without hindering traffic out.

768
00:42:00.920 --> 00:42:03.039
<v Speaker 3>I think you'd need to find an we'd.

769
00:42:02.880 --> 00:42:05.719
<v Speaker 2>Need to have like a GB ten with a dedicated model.

770
00:42:05.800 --> 00:42:06.679
<v Speaker 3>You'd need more than that.

771
00:42:07.480 --> 00:42:10.239
<v Speaker 2>Well, if you had like like on the on.

772
00:42:10.199 --> 00:42:12.119
<v Speaker 3>The next Yeah, you would need I mean I could

773
00:42:12.159 --> 00:42:14.360
<v Speaker 3>see running a GB ten on every switch.

774
00:42:14.599 --> 00:42:15.480
<v Speaker 1>What's a GB ten?

775
00:42:15.960 --> 00:42:21.119
<v Speaker 3>So Grace Blackwell chip something that's designed to run ll

776
00:42:21.239 --> 00:42:23.039
<v Speaker 3>ms locally very fast.

777
00:42:23.360 --> 00:42:25.960
<v Speaker 2>Dell sells them for like four to five grand a

778
00:42:25.960 --> 00:42:26.440
<v Speaker 2>little box.

779
00:42:26.519 --> 00:42:31.199
<v Speaker 3>Yeah, so could could you start seeing l l ms

780
00:42:31.519 --> 00:42:36.719
<v Speaker 3>baked in the switches and firewalls and then coordinating Maybe

781
00:42:37.800 --> 00:42:39.480
<v Speaker 3>that might be the way to do it actually is

782
00:42:39.519 --> 00:42:42.360
<v Speaker 3>to distribute it and then have them all learn from

783
00:42:42.400 --> 00:42:42.800
<v Speaker 3>each other.

784
00:42:43.000 --> 00:42:45.840
<v Speaker 1>Could they be gamed however? I mean that.

785
00:42:47.519 --> 00:42:48.400
<v Speaker 3>It'll be. It'll be.

786
00:42:48.719 --> 00:42:52.320
<v Speaker 2>It'll be a an arms race for sure. If you

787
00:42:52.360 --> 00:42:56.280
<v Speaker 2>look at Tallus, they they baked an eight billion parameter

788
00:42:58.280 --> 00:43:01.280
<v Speaker 2>l l M LAMA models as a demonstration and that's

789
00:43:01.320 --> 00:43:04.079
<v Speaker 2>their Chat Jimmy demonstration. So we could see something like

790
00:43:04.159 --> 00:43:07.119
<v Speaker 2>that being in that same kind of box. So you

791
00:43:07.159 --> 00:43:10.719
<v Speaker 2>get like a much faster processing as well. But again,

792
00:43:10.760 --> 00:43:12.320
<v Speaker 2>it's going to be a dedicated it's going to be

793
00:43:12.320 --> 00:43:14.480
<v Speaker 2>an extra expense. It's going to be a dedicated solution.

794
00:43:15.159 --> 00:43:17.960
<v Speaker 2>That's where we have to go, right. Pent tests are

795
00:43:17.960 --> 00:43:22.119
<v Speaker 2>an extra expense and extra solution, but that's where.

796
00:43:21.920 --> 00:43:24.559
<v Speaker 1>We have to be. Yep, Well, that sounds like the

797
00:43:24.639 --> 00:43:27.039
<v Speaker 1>end of our show. Thank you very much, guys, and

798
00:43:27.480 --> 00:43:30.480
<v Speaker 1>thanks for listening. It's all we had to report on

799
00:43:30.639 --> 00:43:32.800
<v Speaker 1>last week, and we'll see you next week on Security

800
00:43:32.840 --> 00:43:42.360
<v Speaker 1>this week, Bye bye, thanks guys,
