Menu

  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
Podnion
No Result
View All Result
Subscribe
  • Login
Podnion
No Result
View All Result
PassW0rd – 14 June 2023

PassW0rd – 14 June 2023

Play

Speaker A: This program is brought to you by Resonance FM.

Speaker B: If you like what you hear, please support our work by making a donation at resonancefm.com/donate.

Speaker C: Hello and welcome to Password on Resonance FM, our monthly deep dive into the world of technology, a world that, as we know, is increasingly dictating every part of our lives. In this month’s episode, We focus on cybersecurity. Cyber is a technology that, because of developments in artificial intelligence, is now essential to protect our existence. We need cybersecurity to guarantee that the databases AI depends on have not been tampered with because of the role AI has now begun to play in our lives. It’s a concern that is hanging over next week’s InfoSec conference at London’s Excel Centre. —the industry’s annual meeting of the great and the good of the UK’s cyber industry. It’s a week full of earnest conversation and serious socialising in the bars and restaurants surrounding the centre, as the companies selling the computer software equivalent of locks, doors and climb-proof fences try to close deals that will bolt down computer databases for another year. But underlying the bravado in the bars this year, there is a whiff of unease because of the news of a constant stream of data breaches. The latest, a hack by a group the cybercrime industry has dubbed MoveIt, saw an attack on the payroll systems of the BBC, British Airways, Boots, and Aer Lingus, among many others, that got away with the personal details of staff. Much to the embarrassment of the companies affected. And that’s the worry for the cybersecurity industry, because even with their tools on the computers that run our trains, planes, and traffic systems, our farms, our entertainment systems, our media and communications, and increasingly since the pandemic, for many of us, our work, the hackers keep getting in. It’s doubly worrying Because technology and AI are central to our defense systems, our satellites and space systems, because it’s the computerized critical national infrastructure of our 21st century. It runs the energy companies and our water supplies. Increasingly, it’s even running our homes via IoT systems, the Internet of Things, the devices that let you turn on the heating remotely can turn on the oven, and that monitor your health via your phone and your watch. The development that is terrifying the cybersecurity industry, because with the explosion in homeworking, our home and work networks have often become entangled, making them each more vulnerable. The boffin has come in from the back room and is now sitting in your front room watching the TV with their feet up on the table. And because most of us don’t understand how technology works We take it for granted that they are entitled to. An attitude of blissful ignorance on our part that the technology world exploits because that computer-based CNI is, according to the people who protect it, riddled with crime and held together with the equivalent of digital string. If it were a building, it would be condemned and we would accept that we would have to start all over again.. But because of the pervasive quality of modern technology and the sheer scale of its penetration, that is virtually impossible to do. The problem, according to Richard Hollis, a former top US government cybersecurity expert and the head of Risk Crew, is quite simply that some of the technology is not fit for purpose. Hollis comes at it from an informed position. Risk Crew is a penetration testing company, a group of white knight hackers who test companies’ Hacking Defenses.

Speaker D: Here he is. The objective of the cybersecurity industry is to prevent the breach. Clearly we failed, and it’s easy to find statistics about that. As far as I’m concerned, from the Economic Forum adding cybersecurity to the top 3 out of the top 10 risks, to just the number of breaches. And the number of breaches, Peter, are— for me, the numbers are overwhelming. I can’t get my head around it. We lose a couple billion in Yahoo, we lose a billion here, a billion there, and suddenly you think, wait a minute, you know, there’s 7, 8 billion people on the planet, and we’ve lost 24 billion records already. Why are we still protecting networks when we’ve already lost over 24 billion? And then I look and say, OK, what is the problem? And clearly, I cannot see— you know me, Peter. For years, I’m a process. Cybersecurity is an oxymoron. There’s no such thing. So it’s about risk management. Identify, minimize, manage. And the industry has started out mistaking product for a strategy, but clearly For me, there’s been a tipping point where the products that we’re using are just not fit for purpose. They don’t meet the threats that are posed by threat actors today, whether that’s a cybersecurity, some threat organized cybercrime gang from Russia, or it’s a nation-state, much less it’s a hacktivist. Things that we’re buying to secure our systems are just not fit for purpose. Every single day there’s a new, and the products that we depend on are full of zero-day vulnerabilities from It’s like we buy knives from our vendors to take to gunfights. We’re just not taking the right tools for this, and the vendors that we’re relying on to give us these materials to fight these fights, these products are not just fit for purpose. They’re not up for the fight. And on top of it, they’re filled with backdoors and zero-day vulnerabilities, and we’re finding the one that just a year or so ago, SonicWall was hacked back in 2021, and they called it, oh, it’s a big zero-day vulnerability in your product, and literally their whole product line from from their encryption to their firewall line had been hacked, and they released a statement, but technically their whole product line that millions of people rely on, they’ve made a public admission that, well, we had a zero-day vulnerability. Well, what’s a zero-day vulnerability? It’s an unknown unknown. How in the world can anybody manufacturing anything have an unknown unknown in something that they built? That logic seems to be escaping consumers. The irony in this complete lack of accountability, a complete lack of legal liability. I just picked up something about a year ago where 95% of the ransomware attacks are associated with 47 different vendor products from Microsoft to SonicWall. And why isn’t that part of the conversation when we talk about ransomware? Why aren’t vendors held responsible if their products are exploited and it results in the encryption of our data? Why aren’t they paying the ransomware legally? I don’t know. So I’m starting to see in the last 4 or 5 years, that’s all I see is a complete lack of consumer awareness in our industry that we settle for less, that the standard that you and I apply when we buy a car or a flat-screen TV isn’t applied to when we buy a cybersecurity product. Does it work? No, it doesn’t work. Oh, well, do we ask for our money back? Heaven forbid. Do we hold the vendor accountable for when his firewall doesn’t work or his anti-malware doesn’t work? Let me back up. Ransomware is a malware problem, period. If we get ransomware, why aren’t we picking up the phone and calling our malware vendor and saying, you let me down. The anti-malware solution I bought from you doesn’t work. I have ransomware.

Speaker C: Riz Cruz, Richard Hollis. If in real life we walked along the streets and watched wholesale muggings, house thefts, pocket picking, extortion, kidnapping, and bank robberies, alarm would not really cover our response. It would be panic. But in internet land, we walk along like children, blissfully unaware, holding our web-connected phones and open bank accounts in our hands. It sounds like a Wild West world that we’re painting, but this is the world that cybersecurity experts have spent the last few months painting to us. According to them, a wholesale hacking attack is happening on the internet, and it is increasing at a frightening speed because the hackers are targeting weaknesses in the code that the internet is built on, a process that has been accelerating due to the determined move towards home working. Some 39% of the workforce now say they will not work for an employer who does not allow them to work from home. The cost of this cyberattack to businesses is huge. According to one recent figure, cybercrime by 2025 will be costing £9 trillion worldwide, while the cost of data breaches is growing faster than ever before. According to IBM, the average total cost of a data breach for a company will reach a staggering all-time high of £3.7 million in this year. The overwhelming amount of revenue lost and disruption from large-scale cybersecurity breaches in the last year shows just how important it is for organizations to modernize their security practices. In fact, 80% of consumers would be more likely to engage with an organization online if they had robust identity verification measures, the report went on to say. The impact on you and I is becoming significant, and as IBM pointed out, we are now very well aware of it. New research from the French defense and cybersecurity company Thales has revealed there is a lack of consumer trust across most industries about their ability to protect our personal data. Last October, Thales published its Consumer Digital Trust Index, a report produced in partnership with the University of Warwick. It was based on a global survey of 21,000 consumers by the market research agency Opinion and found that the most untrusted sectors for keeping data secure were media and entertainment organizations at 12%, closely followed by government with a 14% level of trust, and then social media companies at 18%, highlighting just how little trust people now have in any organization to secure their data. And it’s a lack of trust that’s justified because the numbers for loss are alarming, as Richard Hollis pointed out. According to SecureWorks, one of the companies interviewed for this program, the losses have increased by 150%. In the company’s annual State of the Threat report published Last June, researchers working for SecureWorks found 2.2 million stolen identity credentials for sale on the dark web on just one day. SecureWorks said that when they did that same search at the same time last year, the figure was a mere 878,429 usernames and passwords. It might sound stupid to be talking about smart devices like your TV or your fridge, but computers are now at the heart of them too. So much so that the current silicon chip shortage has driven up the cost of cars by 50% over the last 3 years, and the increasing use of intelligence in everyday products now also represents a considerable threat to us. It’s the reason for the EU publishing its Cyber Resilience Act in October of this year that stated that all IoT products with digital elements, from routers to smart refrigerators to televisions, and above all modern industrial equipment, should no longer pose cyber risks to people in the future. Here’s Rick Ferguson of ForeScout Technologies on why having a smart device in your house could mean that a high-tech crime gang could be using your home as its headquarters.

Speaker A: No one goes into your favorite electrical store to buy your new washing machine that happens to have an app associated and internet connectivity and says, “But tell me about the security.” They tell me, they say, “Tell me how white my clothes are gonna be when they come out.” That’s, you know, that’s the problem they wanna solve is dirty washing, not internet security. But as we see CE marks on rechargeable batteries, for example, that reassure you that they’re not gonna catch fire, we need to see a kite mark on devices that are designed to be network connected and internet connected that says this has been engineered in accordance to security recommendations or regulations, and it meets all of those requirements. If it’s got this stamp on it, you’re good to go. And we’re going to keep updating those requirements, and you’re going to see an updated version of the— with another year on the bottom, but still the same symbol, the thing that you can come to rely on that says this at least meets the minimum requirements. Nothing’s going to guarantee safety. Nothing’s going to guarantee security and impossibility to breach. That would be a foolish promise to make. But a kite mark like that at least gives you the reassurance that minimum requirements have been met. Okay, but Rick, why would someone want to hack your fridge? What is the possible value of doing that? These are the questions that get asked a lot. It’s those questions. And also you hear people saying, well, I don’t have any money in the bank. I don’t care if anybody hacks me. That may well be the case. You may have nothing financial to steal. But your data has value. Your data has value to be bought, to be stolen, to be aggregated, and to be resold, not only in the criminal underworld but also in the world of legitimate business. There’s a whole data economy out there that relies on harvesting and trading data above board, and then there’s the whole underworld economy of stolen data. So first and foremost, any information about you has value. But they’re not only looking for information, they’re also looking for resources. And your home or your business is full of resources that can be used to greater advantage by attackers. So if they can use a washing machine, for example, as an entry point to a network, or if they can use the processing power in your TV, they can colonize devices around your home. They can use that processing power to take part in attacks, denial of service attacks, for example, on other entities. So your stuff is being used to attack other people. That will have negative consequences on your own network at home. You might not be able to watch your Netflix or your Amazon Prime because your network bandwidth is being used up. Maybe you pay for that bandwidth, but it means also that your network at home is effectively colonized. And there are many, many things an attacker can do. Just imagine if an attacker within your home or business network has access to your router, and what they can do when they get into your router is simply make one configuration change. Just change, for example, the DNS server settings. Settings in your router. If I can control what DNS is doing on your router and you type www.mybank.com and I say, hey, I know the address for your bank, it’s my evil server. Instead of going to your bank, you go to my evil server and I’m able to intercept your banking transactions and do whatever I want within that. So there are lots and lots of attack scenarios, and any potential point of entry to a home, to a business, is of interest to an attacker. And especially if those things haven’t been designed with security in mind, which is very often the case in industrial and commercial devices.

Speaker C: It seems that we never learn. Rick Ferguson of Forescout Technologies. So how does this work? The criminals could be using your technology and your resources without you knowing, making your home, your computer, or your car part of a criminal infrastructure. —an infrastructure that often mirrors our real world. Some 20 years ago, one observer talking to me about the evolution of the organised high-tech crime gangs, which are often based in Russia and often offshoots of conventional crime gangs, said that while the US was developing Silicon Valley, that the Russians were developing Silicon Hell. It may sound melodramatic, but according to the experts we spoke to, It is very real. The criminals have developed a dark web, a shadowy inversion of our high-tech world, and are actively attacking our internetted world from it because of the huge profits they can make from cybercrime for very little risk. The average amount raised from an armed raid on a bank is around £30,000, and the chances of being caught are around 80%. The penalty is usually from 10 to 20 years in prison. The average amount raised from a hacking attack is well in excess of £100,000, and the chances of being caught are a fraction of 1%, while the chances of conviction are only slightly higher, and the maximum sentence is only around 2 years. When you couple this with the Russian regime’s refusal to extradite people accused of crimes to other countries even before it was at war, cybercrime is now an extremely attractive career option in Russia and also in other parts of the world like China, South Africa, Nigeria, North Korea, and South America, and Ukraine. The role that Russia plays in cybercrime has been underlined by Don Smith of the cybersecurity company SecureWorks.

Speaker B: A significant bulk of online criminality comes out of Eastern Europe. Principally Russia. And there’s obviously much debate, particularly this year with the conflict in Ukraine, over are these criminals being tasked by the Russian state, or are they just, you know, accepted and given a kind of a little habitat to live by the Russian state. And I sort of lean towards the latter. There are definitely links. You can imagine that in that mafia state, no criminal organization can survive without having some relationship with the authorities.

Speaker C: And you do mention coming out of Eastern Europe because we have been told that the Ukrainians are no slouches when it comes to cybercrime either.

Speaker B: No, they’re not, and you just have to cast your eyes at FBI indictments over the last decade to see that there’s often Ukrainians that have been either indicted or arrested as well as Russians. And, you know, there was the interesting observation that many of us made in the industry immediately after the invasion of Ukraine, where there was a really marked drop-off in levels of online criminality, which kind of slowly came back 6 to 8 weeks after that initial invasion. And there could be lots of reasons for that, not least of which that if you were in eastern Ukraine or northern Ukraine, you might be more focused on moving yourself and your family out of the way of, of people in green fatigues rather than being an affiliate or initial access broker for a ransomware gang.

Speaker C: Don Smith, the vice president of the cybersecurity company SecureWorks Counter Threat Intelligence Unit. An almost Cold War-style title, but one that underlines how crucial this battle is now becoming, because as we’ve discovered, in the 21st century, our new high-tech economies are dependent on this technological infrastructure. The intelligence agencies are now allied with cybersecurity companies in a conflict with criminal entities that are also merged with hostile nation-states. It’s not been too well publicized, but 90% of hacking activity now involves nation-states. The battle is going high-tech, and a war is going on in our networks. Justin Vaughn Brown of Deep Instinct, a cybersecurity company that uses artificial intelligence to Detect and Respond to Attacks, says that this activity can be predicted by searching for patterns on the internet.

Speaker E: Here’s the challenge. As technology itself becomes complex, organizations are building, you know, applications, they’re building programs and so forth. But in parallel, there are organizations whose sole function is to identify a weakness or a vulnerability. They do nothing else. And in some cases they’re very, very smart people and they’re doing this every single day. They work not in, in kind of rusty garages in some far-flung country, but they actually work in modern offices. In some cases they have promotions, they have what’s called daily stand-ups, they have reviews, they have management meetings. They just do very bad stuff and they’re very, very good at what they do and they’re very well paid and the pay attracts a lot of very, very smart people. So they’re constantly in an innovation race with those vendors to try and identify a loophole, an in somewhere, and they only need to be right once. The vendors and you and I and organizations need to be right every single time to keep them out. So it’s a little bit like that game whack-a-mole. You’re constantly trying to do that just because of, as technology itself becomes more complex, it’s harder to do. I would love us to get to that perfect state, but I think that’s idealistic. Unfortunately, it just is what it is. That’s human nature. There are bad people out there. They see profit, easy money, and they will keep pushing away and do so until they’re stopped. You’ll notice, sadly, very frequently there is news of organizations, whether it’s hotels, retail companies, banks, and so forth, being breached and they have to publish the fact that their data has been stolen. Be alerted to that if you’re a customer, that you should immediately change your password. You should be diligent, and a lot of it is down to the individual. So update, change your password, make it one that isn’t easily replicable. One interesting side note for your listeners is sometimes you don’t always actually need necessarily numbers and special characters. Sometimes even 4 utterly random words can be harder to crack than some of the more established, powerful, or kind of all traditional or classic passwords that you hear of or read of. So it’s number 1, password hygiene. And then I think the other key factor there is being careful about which sites you download content from or you visit. Those sites could contain malware. They could contain something nasty. Just as if you’re downloading a certain document, we’re seeing organizations what we call weaponizing things like PDFs or Word docs or Excel files. You need to be very careful. And if you’re in any role from a work perspective or even working from home now where you may be hiring or looking at a candidate, just make sure that you have the right technology in place to ensure that you don’t have any malware on a CV that’s sent to you. So I think it’s staying alert, basic hygiene, just being smart about which sites you visit. Just be very careful when you go to certain sites, as tempting as it is, or shops or retail outlets where you see a message that says, you know, unprotected, unsecured network. Be aware that you could have someone sitting around there who’s looking at a laptop, who’s just sitting there and waiting for sitting ducks to come along, hook into the Wi-Fi there and take advantage of them. Justin Vaughan-Brown.

Speaker C: Criminals too are not only exploiting vulnerabilities in the technology infrastructure They are actively corrupting it because of a technology industry practice of copying blocks of code that perform a particular function. This has meant that the criminals can do two things: home in on computer code that they know has a vulnerability in it, or they can find a block of code that is often used by software developers and has been made freely available by a group of well-intentioned computer programmers known as the open source community and corrupt it. So that it becomes malign and steals data. Something that, according to Joseph Haroush Khadouri, head of the supply chain security engineering group at Checkmarx, was done by a group that cybercrime investigators have called the Lofty Gang, which stole credit card information, premium upgrades on the social media platform Nitro Upgrade, and the credentials for streaming services.

Speaker B: The open source ecosystem has no vetting, so anyone can publish any code package as long as the name is unique, and it will go into the website without any checks. Like, no checks, no vetting, because it wasn’t designed to be checked. It wasn’t designed for security, this ecosystem. Comparing that to the marketplace of Chrome browser extensions Whenever you publish or want to publish a browser extension into Chrome’s Marketplace, you need to wait a couple of hours, might be day, for someone to review your new addition. So in the open source ecosystem, generally speaking, you have many package registries. They don’t vet your contribution, so you can publish— attackers can publish whatever they want, and in a matter of seconds It’s online as long as the name is unique. That’s the only check. So attackers can state, yeah, this project is highly popular. It’s even if the name is one letter similar to another package, they can copy the description, they can copy the code, and they can only add a single line that is deadly. And it’s that easy. And we see many attackers, not only Luffy Gang, see many attackers exploit this attack surface.

Speaker A: What you seem to be suggesting is there’s a need for cyber hygiene.

Speaker B: Don’t pick up something from the street, really. Exactly. Don’t trust code from strangers without validating it, as you don’t take candy from strangers.

Speaker C: It seems to be a problem with the cyber world now, because the problem of cybersecurity is that you’re being approached by people who you don’t know, but they seem to know quite a lot about you. There’s some people who are collecting information information about you as an individual, which is a lot of social media companies. Then there are other people who have collected information about you who may be criminals. Then there’s people who are collecting information about your code and you’re on the receiving end of all of these strangers. And really, you should be, as you say, not accepting candy from strangers, not accepting code from strangers.

Speaker B: You have a culture where a lot of people blindly trust code from the internet and use it and move fast and repeating this process. Attackers exploit it. And the solution is validating new contributions into the open source ecosystem before it’s available to consume by, by users. Yes, it will mean some slowness from the side of the contributors because they will need to wait until their contribution is validated. And the organizations, the package managers responsible to host and fetch this for download for many users will need to analyze it as similar to Defender’s, for instance, the sandbox or other engines to analyze this software. But I think this is where the solution needs to come from, vetting the contributions, trying to block it before anyone can— is downloading this.

Speaker C: Joseph Harish Kaduri of Checkmarks, one of the many companies that have sprung up to deal with the incredibly complex world that the software that underpins the internet, the emerging metaverse, and cryptocurrencies is throwing up, and one that is increasingly becoming mainstream, as demonstrated by leading artist Damien Hirst, who gave buyers at a recent auction the option of either buying a physical artwork or a non-fungible token of it. For those opting to buy the NFT, a cryptographic online copy of the artwork, Hirst had agreed that he would burn the physical original. At the auction, over half of the buyers opted to buy the NFTs. A complex world that is terrifying companies around the world, who are often baffled about what they need to do to protect themselves. They know to be competitive that they must adopt new technologies like AI to survive, yet they are also aware that that makes them hugely vulnerable and so are blindly buying in cybersecurity protection tools at huge rates. Today most large companies use more than 130 different systems, each with its own reporting system, to try to deal with the attacks they face. Indeed, the chief of Norges Bank, one of the world’s largest oil funds, recently said that cybersecurity was a bigger concern than markets. And rightly so, because the hackers are now deploying new techniques such as data destruction—destroying data to hamstring a company’s activities on behalf of a country seeking to damage another state’s economy, or on behalf of a rival company. Other developments have seen triple extortion attempts where hackers encrypt data in exchange for a ransom to unlock it, seek more money for not selling that data, and then sell it anyway. Here’s Bernard Montel, the technical director of the multinational cybersecurity company Tenable, on the pace and extent of that attack.

Speaker F: So let’s see the world from the attacker standpoint. What do they do? They do cyber criminality. They try to get money. It’s a business behind it. Okay, now you can go and try to penetrate the houses one by one and target companies with cyber attacks, or you can try to find a way to be clever, to be more efficient if you want. And if I can penetrate only one place, and then because it’s technology, I can then have an impact like a domino effect. Then they are obviously much more efficient. They are— again, this is a business— they want to pay less but having more money at the end of the day. So today there are some attacks which are chained. If you target, for example, the technology which is used by a huge amount of companies embedded inside. You can compromise this one, then immediately all the technologies using that specific sub-part of the technology are then compromised. So you don’t have to go one by one after each and single target, because you only target once and you have many. It’s like a pandemic, it’s like a virus, then it is spread Everywhere. I think it’s a circle. When I said, you know, we don’t have more vulnerability than before. Yes, we do have more vulnerabilities. Why? Because, you know, the business is asking developers to deliver technology quicker than it was before. Today we call that DevOps, where they are publishing code, they are committing code sometimes, you know, twice per week, sometimes 4 times per week. When I was a developer, I committed code every 6 months. So that time frame has forced the developer to commit the code quicker, much quicker, and that is the business responsibility. We also can mention, for example, industrial systems and OT. I’m used to say today that the infrastructure that we are using is much more fragmented From the ground, OT means operational technology. When we compare that with IT, which is information technology, at the end of the day we are talking about two worlds. One is IT, classical, you know, information technology that we are using for all the organization. OT is really focusing on industrial systems, the plants, the factories, have systems inside which are very different. The robot and all those automation tools that are building cars, for example, that’s what we talk about OT. And I suppose there’s probably going to be a bit of a blending in from OT from the Internet of Things as well, because OT presumably is part of that Internet Yeah, I mean, keep in mind, a factory that has been created 30 years ago to build a car, or to build anything else, it’s just a car, it’s just an example, with people and machines, industrial machines and robots, okay, never been designed to be connected at all, and suddenly, A vendor, because it’s also more efficient for, for example, controlling the availability of those devices, now propose some sensors called IoT connected to the cloud. So we have in one single place some very, very, very old technologies and very, very, very new cloud-connected technologies. Working together. Can you imagine the entropy? Can you imagine how it could be complex just to find some vulnerability there? Now, if you step back and we go and look after what we just described and discussed about the complexity, this is really fragmented. I’m used to say, from the ground this factory to the cloud and through home devices, now this is the attack surface.

Speaker C: Bernard Montel, the technical director of Tenable. And it should be remembered that when these cybersecurity companies talk about an attack surface, that now includes you, your data, and your technology, as well as the factory robots and the companies that run the high-tech world. One of the companies that sits at the heart of the web is Akamai, an organization responsible for routing a lot of the internet’s traffic, a role that has led to it becoming heavily involved in cybersecurity to keep its customers running. Here’s Richard Mises, the director of security technology and strategy for Akamai in Europe, on the attacks that the company has seen.

Speaker A: Well, I think with anything that’s open to the internet, there’s always going to be people who would like to exploit any vulnerability that exists within those toolsets. So I think that’s always been increasing just by the tooling organizations and the criminals are able to put together to exploit them. Things like artificial intelligence, machine learning are going to just— it’s just another tool to make that functionality quicker. Do you think that it’s been said by many of the people in the interviews that we’ve been doing for this that there are inherent problems within the software that have often been caused by practices within the technology industry such as the copying of blocks of code and that those have been exploited, are being exploited Can that be stopped? Does that mean that we have to do a sort of wholesale repairing of the technology infrastructure that we’re using? I don’t think it’s necessarily wholesale repairing. I think you’re right in what you’re saying. There are sort of core components of the internet that have been exploited in the past. The OpenSSL vulnerability, which was called Heartbleed, a number of years ago. That was something that was prevalent in many aspects of internet-facing architecture. And that was written by two gentlemen that had never actually met in person. So we know that there are poor aspects of the internet that are built in that way, and they sometimes get quite ubiquitous use. But I think that what happened— I think it was last year— there was a the President of the USA called a group together of industry experts and leading technology organizations to try and analyze a lot of this open source code that’s being used, that’s becoming ubiquitous, to try and do a more thorough analysis of that. And Akamai was invited along to that process as well to try and keep the concept of open source being open source, but also to make sure that there is the right level of technological oversight on that.

Speaker C: Richard Mises of Akamai. So what’s the impact of this on you and I? Hardly a day now goes by without the news of a huge data security breach, as Richard Hollis pointed out at the start of this program. We seem to have lost most of the account records of all of the people on the planet. What’s the impact of that on us? Well, not surprisingly, we are taking an increasingly dim view of it. We might not know too much about cybersecurity, but we’re very concerned about our data, according to researcher Professor Carsten Maples of Warwick University and Chris Harris of the French defense company Thales, who commissioned the research into consumer confidence we heard about earlier.

Speaker B: I think one of the things we’ve got to think about is we’ve had a lot of data breaches.

Speaker E: We’ve got good regulation, certainly in the UK, and, and good globally now that helps protect data in some sense.

Speaker B: It gives companies obligations on what they should do to protect data, but we’re still seeing a lot of data breaches. And in particular, what we were looking at in this work was around how does a data breach affect a user of a system across a number of different sectors in a number of different countries. So you would think that your trust in a company’s ability, an organization’s ability to keep your data safe would be degraded if you’ve suffered from data breaches yourself.

Speaker A: Okay.

Speaker C: I mean, but does this also mean that there’s a growing expectation from the consumers on technology that they’ve suddenly, you know, the glitz has gone off technology to an extent and people are beginning to say, hang on a minute, this isn’t quite doing what it’s meant to do.

Speaker A: We’re probably in a world now that’s in many ways safer than it ever has been because of the focus on technology, because of the focus on security, and because of some of the education that’s gone ahead of us. But we’re also working at a scale that’s different to how we used to work. So technology, you know, used to be a small part of people’s lives. Now it’s the majority of many people’s lives. And so the number of touchpoints that we have every day with technology is just so vast that your data has to be everywhere. You know, there’s very few interactions that you have where the other side don’t know something about you, something simple, your name or your email address, or more complex data about, you know, who you are and your preferences and your shopping history and so forth. And so, yeah, I think that the world is probably a safer place. It just doesn’t seem like it because of the amount of technology that we use.

Speaker E: One of the things that we found in the survey, that those that had had negative consequences from a data breach, 1 in 5 said they wouldn’t use the service again, which is a considerable minority.

Speaker B: But 80% of those people do actually still use the service.

Speaker A: And why? Because we sort of need to.

Speaker B: We live our lives online as well as offline now.

Speaker A: So can we just stop even using social media, right? So social media is something you might say, oh, well, that’s optional, but how optional is it to be a functioning part of society for many people these days by not being on social media at all?

Speaker B: And of course, social media goes a bit wider. There’s also messaging services that we rely on to look after our parents, our family, many different reasons. So Many people will still engage with services because out of necessity, I feel, or the fact that they want to.

Speaker A: But some of them will want action taken should they have suffered a data breach. There’s arguments for and against, is the truth of it. In many ways, you’re absolutely right. You know, the more exposure we have, the more touchpoints there are out there where somebody could threaten us or attack us. If you live in a world and you disconnect yourself from social media and you bank in the bank down the high street and so forth, then you’ve got a lot of physical protection around what you’re doing because you’re keeping your data within the room that you’re sat in. But it’s not realistic, as Carsten said, you know, the world isn’t like that. We’re being encouraged to move online in many cases by almost every organization. For benefits from cost saving, but also benefits in terms of service, in terms of the services they can deliver to us. And so there’s a balance. And the climate. Exactly as well. You know, if we can do something without jumping in our car to drive to the local town to do it, then that’s better in many ways. So the answer is kind of yes and no. You know, you can live in a world that’s very safe and you can live in a world that’s is, you know, realistic, I suppose, in the modern times.

Speaker C: Chris Harris, the technical director of Thales for Europe, the Middle East, and Africa, and Professor Carsten Maples of Warwick University. So if we are losing confidence in companies and governments, presumably our response would be to make sure that we are looking after ourselves, putting technological bolts on the doors and checking the windows. Unfortunately, not so. Individually, we are the weakest link. We hate security. It gets in the way of the instant technological gratification we crave. We want things now, right now. Anything that gets in the way frustrates us. Indeed, the cybersecurity industry has come up with a name for that frustration. It calls it friction. The cybersecurity industry has introduced multi-factor authentication using your mobile phone and maybe an app and an email address to send a number of messages to us to make sure there is a human being on the end of the authentication request. And we hate it because it slows us down. Here’s Matt Aldridge, Principal Solutions Consultant of OpenText Security Solutions.

Speaker A: It is essential that we get away from using passwords because passwords are just far too easy to steal, far too easy to reuse. And we see things like credential stuffing attacks where people get hold of millions of passwords and usernames from attacks and breaches, and then they’ll just recycle those, feed them into other systems, and try and break into those systems using those same credentials. So passwords just need to be put to bed as soon as possible. And what we have right now is different techniques for multi-factor authentication, and it is a step forward, but there’s definitely challenges involved in making it usable for, for everybody.

Speaker C: But I mean, there have been several cases where people have got locked in a loop from hell where they can’t actually make the phone authentication software work the phone authentication software is sending messages to the phone to authenticate itself during the setup. People are getting really frustrated.

Speaker A: Yes, and it can be many reasons. It can be that the admin hasn’t quite set things up right as the user is expecting. The admins may be actually asking users to do something that then it’s not possible for them to do because of the state of their account. It’s also challenging because there are certain apps that you sometimes have to use and they all have their own challenges. But there’s a whole lot of education that’s needed to help people understand what their options are. But these things are not obvious to most people. What’s the solution to this?

Speaker C: Is it that the technology providers have to come up with systems that are more friendly to those people who are trying to make them work, or is it that the people who are using these systems have to make a bit of an effort to become a bit more aware?

Speaker A: It’s actually both of those things, and also the organizations have to play their part in training and awareness for their users. And so yes, users do need to take some element of responsibility here. They do need to take a bit of an interest in why they’re being asked to do what they’re needing to do, and then what is the best way that’s going to work both for them and for their organization to keep everybody secure. And also allow everyone to get on with their daily activities without having too many barriers in place causing them problems.

Speaker C: Matt Aldridge. So the technology industry should improve its communications, and we should make more of an effort to understand the world that we now depend on. And we should stop being lazy, because that laziness causes most of the cybersecurity issues for our world. We don’t like security or maintaining our systems, and it is a picture that tends to be mirrored by industry in general. The criminals, on the other hand, are very aware of any of our weaknesses, which they call opportunity, and they jump on them at high speed because they are anything but lazy. Here’s SecureWorks’ Don Smith again.

Speaker B: We’ve seen some significant changes in the sort of modus operandi of the groups. I think the one key statistic that we highlighted in the report is that for ransomware incidents, we are now seeing that 52% of those in our observations of our incident response team, the way in was through exploitation of internet-facing infrastructure, you know, unpatched firewalls, VPN routers, Exchange servers. And if we look back to previous years, we had the the sort of the evil triptych of loaders, what we used to call banking Trojans, you know, Quackbot and Emotet and things like that, password replay for people who didn’t have multi-factor auth, and the scan and exploit stuff. And they were maybe roughly a third, a third, a third. And where we are now with our observations is over half are scan and exploit, people not patching internet-facing infrastructure, perhaps as much as another 30%. is password replay, and then the traditional loaders, banking trojans, are way down in third place. And I think that couples to potentially a slight change of focus for the bad guys.

Speaker C: I mean, it’s interesting, isn’t it, that every industry has its little sort of aphorisms, and the cybersecurity industry is no slouch in that. It’s got all of its little phrases, and one of the phrases is amateurs attack systems, professionals hack people. That’s not really true, is it? What you’re laying out is a world where people are looking very, very intently for these errors in software, for these zero days, or for things where the software’s not been updated.

Speaker B: So people are actually homing in on known weaknesses. They are, they are absolutely honing in on known weaknesses., and with alacrity, we’re seeing taking— and this goes, I mean, goes back decades in terms of how quickly do criminals jump on an available exploit, but we’re seeing ransomware crews do that within days, and then they’re scanning. And you know, why are they doing that? Is it because they’re interested hackers and they like using cool new exploits, or is it just because it gives them a better return on investment. It’s a lower effort way of achieving that initial foothold in an organization where they can then choose whatever methods they want to choose to, to kind of monetize that and get some return on investment from the intrusion.

Speaker C: And that was Don Smith of SecureWorks. According to his industry colleague Paul Bruciani, the cybersecurity advisor of the Finnish company WithSecure, literally on the front line with Russia. The situation will change, but not because of consumer concern or even regulatory compliance, but more because the companies will face potential legal costs for not doing so.

Speaker A: You can lump all that together. In the US, for example, in, I think, 2017-2018, of the 10 largest breaches that took place, the average cost to a company was $136 million. As a result of those three things: compensation to consumers through class actions, regulatory fines, and the legal fees. Legal fees alone were 17% of the cost of dealing with incidents. So I think it’s numbers like that that are used to haphazardly enable decisions to be made about what’s, you know, how much to spend on security, how much is appropriate.

Speaker C: So that’s what the Chief Information Security Officer wants. He wants to be able to make a case to the Chief Finance Officer. But what’s the damage to consumers?

Speaker A: What do they feel? It’s a good question. It depends what the breach involves. If it’s, if it’s, you know, simple sort of name, address, and so forth, well, you can pick that up in a telephone directory or used to be able to when they had them. You could argue the loss is pretty minor other than perhaps a breach of privacy, but the consequences of that breach aren’t high. If it’s financial data, it gets more serious, especially if they can be— then they can be targeted by criminals and suffer financial loss. But then again, there are controls that can be taken to minimize that. In Finland, which is where my company WithSecura is headquartered, there was a famous case just last year where a health service provider providing mental health services was hacked, and the hacker not only ransomed— held the company to ransom— it eventually published all the medical records of its patients, you know, who had had nervous breakdowns, who’d talked about affairs that they were having or their partners were having, Really, the most personal private information was out there. This was a big company.

Speaker C: It can ruin lives. Paul Bracciani of WithSecure. So what can we do? Oddly, quite a lot, but only if we take the time to familiarize ourselves with the problem and learn a little about cybersecurity. Most importantly, we do have one advantage over the criminals in the information age. We know what both big tech and the criminals want from us: data. It’s that simple. They’re after our information, and that information, whether it’s bank account details, passwords, or important documents and designs, is all expressed as data. Control access to that and you have some basic protections in place. As Mark Farley of the U.S. private detective agency turned cybersecurity Kroll points out.

Speaker B: It’s all about my data. Where’s the data gone? Where, where’s it being used from, I guess, a personal perspective? It’s kind of like, so each time you are transacting on a website, are you transacting with a secure website? Is it trustworthy? Is it all going to be— is it one that I want to use again type thing? It’s going to be in terms of, I guess, yeah, that question is going to be all around sort of digital trust and how much you can trust the technology you’re dealing with, as well as adding, I guess, protections to your data.

Speaker A: I know the issue of how much can you trust the technology you’re dealing with, that’s a really big issue, isn’t it?

Speaker C: Because we have these zero days, we have these things where companies like Microsoft put out warnings saying that they found a compromise in their technology. That’s very worrying if you can’t even trust the technological infrastructure that we’re using.

Speaker A: Can we solve that?

Speaker B: I guess that’s one of the, I guess, interesting challenges of cybersecurity because it is such a fast-moving field of all the sort of different threats evolving constantly. And it’s why, I guess, one of the battles companies have is keeping up with that cyber hygiene or the cyber or the fundamentals of cybersecurity. Making sure that technology is up to date, making sure that, that they’re actually protecting the data in line with good practices. Because those, as we’ve seen, sort of regulations have changed, people have changed their expectations of technology. So it’s becoming more and more of a challenge for companies to address that. And it is very hard to combat. It’s very much, it’s all about sort of making sure you’ve got the right policies and processes and procedures in place to help manage those risks.

Speaker A: But surely the consumer as well should also be aware of those risks too?

Speaker B: Oh, definitely. Yeah, it’s one of those— it’s not all down to, I guess, who you’re, who you think you’re talking to. It’s also protecting your personal security. So making sure you’re— I know not everyone’s following the news, but keeping sure your actual phones are up to date, making sure you’re following what’s the I guess, good practice with password security and authentication. And it’s why I guess these, these are problems and gaps which obviously threat actors often look to, to exploit, to where I guess there’s a misunderstanding between the consumer on a personal level and the technology they’re dealing with.

Speaker A: Do you think we’re at a bit of a tipping point here?

Speaker C: Because we’re about to go into this new world of VR, the metaverse, these virtual meetings like the ones that we’re currently having?

Speaker A: Trust seems to be the be-all and end-all.

Speaker C: I’ve assumed that you are Mark Farley, for example, and not a deepfake.

Speaker B: That’s a really good question because that’s an area which I’m not an expert on deepfakes, but it’s going to be an area coming up where people have shown interesting research and how they can actually fool people into performing certain actions. In terms of solving the trust problem, I think that’s been around for, for years. It’s been an issue for cybersecurity for a long time. And I think things are getting better. People are getting more aware of what, what is, what’s on the internet and how to interact on the internet. And yes, as you rightly say, that the metaverse and these VR realities are going to make a whole new different ways of these sort of issues for people to address.

Speaker C: Mark Farley of Kroll. There is one more thing that we can do according to Risk Crew’s Richard Hollis, who has a real bee in his bonnet about this. Complain loudly and long, and as Bruciani said, threaten legal action. But to do that, we will have to get cyber aware.

Speaker D: When you start taking back enough flat-screen TVs and say these TVs don’t work, technology gets better and people start improving the service and improving the quality of the product. I think as consumers, we need to start wising up. There’s— I read someplace there’s like over 4,000 enterprise-level cybersecurity products to choose from on the market. I think if there’s going to be any change, the quickest way to get it is by how we apply our security spend. And to start attaching it to some expectations. I told you this, just start asking for excellence, you just might get it. We are sleepy, we settle for anything. It’s a question of raising our expectations and asking for value for money. It’s very much, I think, a question that we’re going to keep getting inferior cybersecurity products until we start acknowledging these don’t work, they’re not fit for purpose, take it back. I just got ransomware, I bought your crappy anti-malware take it back and I’m suing you for product negligence. Vendors, they’re going to keep selling us crap if we keep buying crap.

Speaker C: That was Richard Hollis of Risk Crew talking about the huge threat cybersecurity poses for the world. Expect to hear a lot more about this topic because by March of next year, the cyber insurance industry says it will no longer cover companies for attacks by national state actors. And as we have heard, they appear to be behind most of the attacks. You’ve been listening to Password on Resonance FM, presented and written by me, Peter Warren, and produced by Blue Buffery. To find out more about the technology in our lives, log on to www.futureintelligence.co.uk and listen to our previous programs, or order a copy of my latest book, AI on Trial, co-written with leading technology lawyer Mark Deem.

Speaker D: Thanks for listening.

Speaker A: This program has been brought to you by Resonance FM. If you like what you heard, please support our work by making a donation at resonancefm.com/donate.

ShareTweet
podnion.com

© Sociaall Inc.

Navigate Site

  • Home
  • Privacy Policy
  • Contact Us

Follow Us

No Result
View All Result
  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
  • Privacy Policy
  • Contact Us

© Sociaall Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00