Loading summary
John
Sarsaparilla.
Cory
Sarsaparilla.
John
I had some of that in Deadwood. Yeah, I grew up on that shit.
Kelly
How do you feel about the root beer? What's the difference between sarsaparilla and root beer?
John
It does have a different flavor.
Cory
Yeah.
John
Sarsaparilla tastes like sarsaparilla. Root beer tastes like root beer.
Kelly
All right, well, that.
John
That's all I can say that's super.
Kelly
Relatable as someone who has.
John
How do you even describe root beer? You know?
Kelly
I mean, have you. How do you describe root beer? I mean, Sassarilla.
Cory
No, a lot of. A lot of people think root beer tastes like medicine, right? Like, yeah, like, people.
Kelly
I would say. Okay, here's. As a. As the relevant hipster who happens to be here at this second. I would describe root beer as like an aromatic herbal flavor, kind of licorice, but not super, like. Not super tangy. Kind of on the rooty side, like spicy, but not like in a capsaicin way. That's how it.
Cory
Please tell me. Please tell me someone here knows the Star Trek quote about root beer.
Alex
There's a Star Trek. Yeah, yeah. And cork and be like. Yeah, it's fruity and.
John
Oh, it's like the Federation.
Ryan
And it's like the Federation.
John
Yeah. You got to say Deep Space Nine because I'm going OG. Going Generation. Yeah. It's like, the more. It's awful, it's horrible, but the more.
Cory
You drink it, the more you like it.
John
Like, generation.
Ryan
What's moxie?
Alex
Yeah, I've done moxie on here.
Ryan
Oh, yeah, Moxie.
Kelly
You've done Molly.
Alex
Yeah, Molly.
Kelly
Yeah.
Alex
Well, I want to make sure my mic doesn't slur here, or it's going to be you cut out there.
Kelly
All we got was you do a lot of drugs. What was that?
Cory
There's a picture of me doing moxie.
John
Moxie's like Moxie Marlin's Place. Maybe the Guinness of that kind of sort of. It's like. It's a very strong.
Kelly
Oh, so it's really basic and not very good. Oh, sorry.
John
It's a.
Kelly
It's a.
John
An acquired taste. I'll say that. I kind of dig it. You kind of acquired it.
Kelly
I don't understand the concept of an acquired taste, because some people like certain things staple.
John
That's. That's how I know.
Cory
Do you like energy drinks, Cory?
Kelly
I mean, I. If I need energy, I like energy drinks, but I'm not like an aficionado. I'm a coffee guy. It's the healthiest way of delivering caffeine to my body while also keeping it to be delicious.
Ryan
I know.
Cory
Like a monster just completely changes my mood for the better. And it's scary. Like, I can't, I can't explain. Like when you first start drinking energy drinks, they taste horrible and then it's just like root beer, it just grows.
Kelly
No, I think they taste amazing because they have like 60 grams of sugar. Anything with that much sugar doesn't taste bad. No, that's just a fat.
John
That's a good point. That's a good point.
Alex
Although I like the fake sugar.
Kelly
Same difference.
Alex
I like the mushroom powder for like a coffee. And my wife keeps asking me like, is this mushroom coffee or is this shroom coffee?
John
And I'm like, mushroom coffee is not good.
Jason
He lives.
Kelly
Look at this star studded catastrophe we got today.
Ryan
I, I, I made it.
John
Oh my God.
Cory
See, your server fans have not.
Kelly
No ac. Server fans are fine.
John
Hold on.
Ryan
So listen, I have to buy these like once every two years. But I already bought one. All you got to do is replace it. I just haven't had the time to do it.
Kelly
He literally has his.
John
You should, you should look out for a buy one, get one free sale for those things.
Alex
Yep.
John
And just stock them up.
Ryan
Just, just for context. They're like $30. It just takes me like about an hour to open it up. Get, get it on there and put it back.
Cory
How long does it take to get you from China? AliExpress?
Kelly
Oh, no, no.
Ryan
This is straight off the, the fast boat. They have like a fast boat that brings them over. So it takes like a day.
John
They're smuggled, apparently.
Ryan
Yeah, they're smuggled. Yeah. No, they just warehouse them all in America. It took like three months to get here, but they were out a thousand. So they're available now.
Cory
We missed were you on the news last week? You weren't, right?
Ryan
No, I wasn't.
Cory
Yeah, we missed you, Ralph.
Kelly
I just, I, I just hacked the, your throne app and I gotta say, I don't know what's going on, but the what throne? You don't have this app. You should install it.
Jason
Oh, we should open with that one.
John
I got real quiet like Mr. Hanky the Christmas poo. He loves me and I love you.
Kelly
Can track him with a nap too.
John
Mr. Hanky.
Kelly
I will say it is funny. Like, I know we're going to talk about it later. This is like a spoiler, but searching on the App Store for a throne, there isn't a single app. There is actually an app that came up first that's called Throne find and book clean bathrooms. Is that like.
Ryan
You know what blows my mind? Somebody was like, this is such a problem that we have to solve it.
Kelly
Are you a shy pooper? Come here. Come sign up for this again. But it only has 3.4 stars. Let's read the reviews while we're waiting.
John
Oh, my God.
Kelly
What are we waiting for? Nothing.
John
Oh, we're waiting for.
Alex
Yeah.
Ryan
Oh, my God.
Kelly
We're waiting for Ryan for. So we hear the happy music.
John
Let's do it. Kick it off.
Ryan
I had this thing forever. I didn't know that's what it's called.
Kelly
Something went wrong. Doesn't really work. That's one of their abuse. One star. Is that during the bathroom or just installing the app?
John
Let's find out after the mess after this message. Hello, and welcome to another edition of Black Hills Information Security. Talking about news. Yes, shy poopers. This is the episode for you where every single fear you've ever had about taking a dump in public or at someone's house has been justified. So we have a number of stories. I want to keep that one on. I want to keep that one at the end because, you know, he wants to hold a better story to come out of this. Of this episode. So it feels.
Ralph
After it's done, we can dump it.
John
Yeah, after it's done, we can just dump it.
Kelly
So, John, where is this going? Fortinet Government scissor rants. Where do you want to go with this?
John
What do you think we're going to start? Let's start with aws auth keys found in iOS and Android apps. Oh, my God.
Kelly
Okay. But. Okay, so here's my one clarifier with this. Not surprising. And most of the apps that they found it in are kind of. I don't want to say crappy, but.
Ryan
You seem kind of crap.
Kelly
Nothing I've ever heard of has. I guess I would say to the audience, have you ever heard of any of these apps? Pic, Stitch, Meru, Cabsound, Tinnitus. Has anyone ever heard of these crumble cookies?
John
3.9 million ratings.
Ryan
Here's. Here's my guess. These are all out at, like, Chinese developers out of these, like, app factories, right? Where they just like, churn out apps looking for the best results.
Kelly
Yeah.
John
Yeah.
Kelly
I don't know.
Alex
Like, for Tinnitus relief. Like, I. I've heard of those and I use something that has the Tinnitus relief. But it seems really interesting that it. There's two of them. Like, when they list 10 apps as examples, two of them are Tinnitus released, and they both use what? Like that Microsoft Azure blob for the. So it probably is, like, just using the same builder for stuff, and this building company is like, oh, okay, cool. Like, we can. We can build a Tinnitus app, and, oh, look, somebody else is asking us to build a Tinnitus app too. Like, can we just take the same code and, like, just do a find, replace and send it out there? Like, what's the worst that can happen? I don't know. You wind up on the list of.
Kelly
The next question is, how is this not picked up in scanning? How is it? Like, don't they scan these things, this stuff?
Cory
Yeah, they scan from malware, not secrets.
John
Test it.
Alex
Just.
John
Just don't test it.
Kelly
I'm saying the app stores do. Okay, do the app stores have a duty to prevent this kind of thing from going live, or is that not their problem?
John
I don't think that it's their problem. I. I just don't. There's so much going on that they're just trying to stop mal. Like. Like, malware attacks that they just don't have. I. I don't. Like, if you want to hard code something into it, I. I just can't even imagine the amount of effort that we have to go into it. But it's just. I don't know, man. I don't know. I actually think it's a lot worse than what this article was making. I think that these people did a handful of apps, and you've noticed they got, like, 20 apps. It almost seems to me like they're like, okay, we're done. But if you're looking at, like, mob sf. Mob SF has a lot of really cool capabilities for static analysis, where it'll literally tear apart an app and it'll bring out things like this. Like, it's literally a tool that's beat to it. That's just built. Sorry. Built to it. God. Somebody said, beat me to it.
Kelly
What is that?
John
I am tired. I have been. I have been like. Like, chopping wood all day long.
Kelly
If someone's beating you from ism, I.
John
Literally just read what the Lone Star said, like, while I was talking, and it took over because I'm Ron Burgundy. Yes. Today is strange. Right?
Kelly
So, wait, what is the tool? Sorry.
John
It's called Mob sf. M, A, B, S, F. So my.
Ryan
Question is, is one of the apps, is that the Crumble Cookie app? Yeah, it is.
Cory
I just checked.
John
Yeah.
Kelly
First of all, why is there an app for that? First, every store has an app now.
Ryan
Every Everybody has an app, but I was gonna say the cookies are delicious. But back to the success story. The thing that I. My real question that comes to mind is that so when developers are making these apps, right? So they need to hard code these keys. Like my better question is, my real question is what is the right way to do it? Obviously I know storing AWS keys, whether they be blob storage or buckets, that's the wrong way. But I'm thinking about like what's the right way? And maybe that hurdle is just so much they were like, maybe we'll just.
Kelly
Kind of hide it in here.
John
The right way is each individual user has cut their own specific API key. It's very similar to like SQL injection where the, where more accurately the user ID accesses on the server side and then the server side accesses with the API key. So you shouldn't have that API key client side. So the user account accesses and then based on that user ID and the group membership, then you can actually access.
Ryan
The thing is as a user, when you log in, right. You pull down your, you know, the table, right. For your user and. Or more probably likely is once you're authenticated, let's say you get a session token, right for whoever they're using session and you give that back to their API server. The API server gives you a AWS key for temporary retrieval of these.
John
I don't think it should be done that way. Like that key should never hit the device itself.
Kelly
Don't put the keys in.
John
Yeah, that key, that API key should never be there, right. So your user ID is getting. So literally, if you look at the way that most mobile app development is done today is it should just be HTML all five applications that are just like being done in webview and then it's just like web stuff.
Ryan
So I mean obviously there's a bunch of ways to cut this. But I'm just thinking about it like programmatically though you can issue out really short lived AWS keys, right that, that are scoped out for one thing, one single user.
Kelly
Yeah.
Ryan
And they could be like for an hour.
John
Right.
Ryan
So like you're like, oh, I statically analysed and I got the key from my account, right. That's only good for another hour. That's not really like a vulnerability, right? Like that's just, I would just say don't be.
John
So here's the reason why it concerns me. Is it? So if starting to get the API keys down to that application, especially on Android, it kind of gets into the concept of explicit and implicit intents. So basically with an intent, you can say which application is able to access which data. So whenever you have applications that start sharing data across other applications, which a lot of them do get into ads and the way that those things work. But you can do like explicit intents and then you can also do implicit intents where you can say that all these different apps can access it. So you run into a problem. If that key is living within that app itself, you may be exposing that particular key so another app can actually snatch it, rather than just the specific data that you want to share from one app to another.
Kelly
Okay, but hold on. There's no legitimate reason to hard code keys into an app. No, no, we're, we're like, we're not even doing. You should do that. Like, this is totally a misconfiguration. They put a feature into this app out of laziness. Like, here's not a feature even. It's just. Yeah, yeah, here's my guess.
Ryan
They wanted the user to have access to some probably S3 bucket. Right. To pull down objects, I guess.
Kelly
Right.
Ryan
That's my most likely, you know, idea. So they were like, well, we'll just put the key in the application so they can access these things as opposed.
Kelly
To, instead of just making it public.
Ryan
What, what John was saying, which was actually like issue out a key or more importantly, the user.
Kelly
So the way, the way you really.
Ryan
Should do it is when the user makes a request, it uses their session token and the API on the other side gets the object from the blob and then gives it back to you. But then you have to put something in the middle.
John
And with all of that, you can do that without using API keys. You can literally just use a user cookie like that. You straight up user cookies.
Kelly
Are you saying, Is that a joke about crumble? John?
John
It was a good one. It was a good one.
Kelly
Okay.
John
Yeah.
Kelly
I mean, basically, I think the long story short here is if you paid someone to make an app for super cheap, maybe made some trade offs and this might have been one of them.
John
And that's where you're talking about something that's absolute honest to God truth, where a lot of the app developers, they have a framework for what apps normally do and then they just reuse that and reskin it again and again and again.
Kelly
Totally.
John
So if you guys want to get into this, the two tools that you want to look into are Frida and Mob sf. If you want to start doing this, and I will be having a Class on Android. I'm hoping. I got to get work. I got to get this. Working with Corellium because they're the ones that are running the emulation for the class. But my thought on this is that the app world for iOS and Android apps is like what web stuff was back in like 2004. It's the wild, wild west. Shit like this is happening absolutely everywhere. It's really, really, really bad out there from a security perspective.
Kelly
All right, moving on. Time to rant about SZA or time to rant about Fortinet.
John
Let's talk about Fortinet because.
Kelly
Okay, is.
John
Could this be handled any worse? I mean, so, okay, so for those of you that don't know, there's a zero day vulnerability and 40 jump 40 manager and basically nation states are using it. There was no cde. Is there a CDE now for it? I don't know, I haven't checked. Do we have a CDE for it right now? But there's no CVE associated with it. And then further, Fortinet, basically they don't have any reference to it. And the thought process is they're protecting customers by not publicly disclosing the vulnerability. Seems weird if you have a vulnerability that's under active exploitation at the moment. So they do have.
Ryan
Now, what's that? There is a CVE.
John
There is.
Ryan
Bottom of the article. Yeah, 2024, 47575. Whatever.
John
What is the score on it?
Alex
It is. Well.
Ryan
That'S a good question. I don't see the score in here.
Kelly
9.8, it looks like on CVSS version.
Ryan
Oh yeah, 9.8. There it is. Yeah, it's 9.8.
John
That's bad.
Kelly
Still not a 10.
Ryan
Yeah, it's unprivileged or unauthenticated.
Kelly
Missing authentication kind of sums it up. That really does.
John
I love that missing authentication makes it sound so much better. And if we're looking at the Numbers Shodan, basically 60K 60,000 devices, we actually.
Kelly
Looked for all of our antisoc customers. There was one, but it was like a subsidiary brand, it wasn't the actual main brand. So it's not super common to have this exposed. But did see one instance of it on our customers, so it's possible we.
John
Did and we kicked it out, of course to our customers for our continuous.
Ryan
You know what blows my mind about like Fortinet for example, and Palo Alto, the two big firewalls that are like in the commercial space. How many zero day remote code executions they get, but like how many like Netgear ones Right.
Kelly
I don't know. It's like the. Either. Oh, those are, those. Those are already bopped from the factory.
John
So you don't need. I look at it like this.
Ryan
I'm wondering if it's because of the size of the deployment or is it.
John
The company posture that's part of it. So whenever you look at vulnerabilities and kind of the history of vulnerabilities, whenever you have a vulnerability in Java, I don't know if you remember, but years and years and years ago, the Java heads were saying, Java is more secure than doing things in C and C. You should use Java because there's no security vulnerabilities in it. Well, that shit was wrong. And as soon as we realized that there were vulnerabilities in Java, it immediately turned into like this open season because it was everywhere and it was just like the eye of Suron for the attackers were focused on it. We saw it again with Adobe where Adobe had all kinds of issues. A compression with flate decode and U3D compression algorithm.
Ryan
Yeah, we had that horrible product. What was it called? Cold Fusion. That's it.
John
Yeah. Cold Fusion, yes. Dear God, I forgot about Cold Fusion. We should talk to Chris Sulu about that because there was a ton.
Kelly
Well, that was, by the way, that.
Ryan
Was during the time of the Java deserialization. That was all over the place. And so like, that was.
Kelly
It was like.
Ryan
It was like a whole class of vulnerabilities that moved into a bunch of products that were utilizing that during its time because those were very popular ways to program those applications.
John
And it just, it just opened up like the can of worms. So whenever you're looking at Fortinet, there's been a series of vulnerabilities. And this is one of, one of the concerns I have with these big vendors and I'd love to get people's thoughts on this. I have serious concerns as to whether or not Fortinet has implemented a solid software development lifecycle process. Like, it seems like a lot of these vendors, and I could be wrong, are just playing whack a mole of. Oh, oh, no, I'm still here.
Kelly
Can you guys hear me? Webcam utility. I can read backwards.
John
Can you guys hear me still?
Ryan
Yeah, we can hear you.
John
Really weird. Um, it's like, are you getting hacked? Being censored, man. Being censored.
Kelly
John, what firewall do you use for Palo Alto? I think my thing with the. So my thing with the firewalls. I think in general, when we're talking about like Enterprise grade firewalls, I think they're kind of like too. Everyone's too scared to get really aggressive with disabling features. It's kind of like the Windows problem. This is how I see it. It's like you have a lot of legacy features, and these are all critical points of failure in customer networks. Right? Like, you can't just be like, oh, our firewall is down. Okay, so our business can't run. Yeah, but I feel like it's just the whole confluence of legacy features. Like, there's, you know, some number of customers that need this FGFM service to run for whatever reason, they're reluctant to fix it or disable it because they're afraid it doesn't. It's like a bunch of legacy things that people, some people need, but a very small number and they're included by default. And that's like. I think that's the problem. It's similar to like, why is Prince pulling a thing on domain controllers?
John
Like, yeah, but I think so. Here's my concern with a Corey and I just switched over a completely different camera. My major concern with all of this, though, it isn't just that I have a theory that a lot of these vendors are simply playing a game of whack a Molecule where they deal with the vulnerabilities as they come up. And I really believe that a lot of these vendors, when you have these vulnerabilities that are showing up, especially in some of these apps and some of these services that have been around for a long time, seriously, if you're a CTO of one of these companies, you got to stand down and not just fix that vulnerability, but you need a number of outstanding pen testing firms to kind of show up and start tearing your entire SDLC and start tearing your application base apart and start looking for these vulnerabilities. Because a lot of these vulnerabilities, they don't seem like they're overly complicated to detect with a competent tester. And some of them, it seems like automated scanning tools would be able to accept it, and then others just static code analysis tools would be able to detect it.
Kelly
I think since the patches cost money, the deployment costs money, the testing costs money, and that's. And like, you have, let's say you have 200,000 firewalls deployed, only 5% of people are using this, you're not going to put the money towards patching it. Right? Like, it's just a sad. It's the same thing as Microsoft. Why are there so many vulnerabilities because there's so many products, right? It's the same thing.
John
But going back to Microsoft's defense, seriously, I still think they have the best SDLC for a large company in the world. A lot of the vulnerabilities that come out from Microsoft now are like, holy crap, that is really incredibly complicated to exploit. Now every once in a while, third part, like a kind of not core operating system vulnerability pops up and those are a little bit more boneheaded. But some of this stuff that's coming out for like Palo Alto, Connectwise, some of these other vendors, Kaseya, it's just like this, this is something that a good solid security development lifecycle process should be able to detect. And I just have serious doubts as to whether or not they're actually implementing that. I talked to a CTO of one of these companies a while ago on another podcast and I asked them, I said, hey, what are you doing different next week than you did last week? Like, what is your difference? And the answer was a little bit. I mean, it's kind of a tough question, but the answer was very much like, well, we're going to make sure that we get this vulnerability fixed. It's like. And I didn't want to push it because he came on the show and I respect that. But at the same time, the correct answer for a CTO is we are doing a full stop. We are going to go through, we're going to start doing a full code analysis, we're going to get static analysis tools in here. We're going to send through absolutely everything. We're going to do a stand down for about a month. If it's not a critical patch, we're going to try to make sure that we get security baked into our process. Because some of these, especially like Fortinet, where they're just bleeding out constantly, it's like, God damn, someone's got to stop things here and say, hey, we need to refactor all of this legacy software to try to find these vulnerabilities.
Kelly
But you're right, I mean, it's expensive.
John
It is.
Kelly
I mean if you offered people, here's two choices. You can have a hacked firewall or you could have no firewall for a month. I would choose a hacked firewall and I think 99% of companies would probably.
Cory
Would probably Fortinets, like the cheapest firewall, right? Like, they're not on the same level as like I would like Palo Alto or anything like that. From my security experience, usually only the customers who aren't able to buy that top notch by Fortinet.
Kelly
Well, you're thinking microtech is cheap though.
John
It's not, it's not the people that are choosing like, it's not like somebody at a bicycle shops like Palo Alto or Fortinet, it's MSSPs. What are the tools? Multi tenant that MSSPS can actually utilize these products, they roll that out to.
Ryan
Their customers who don't care. Right, exactly. They're like, that's what I pay you for.
Alex
Right.
Kelly
The flashy box in the closet couldn't really be bothered.
Ryan
Yes.
John
The other problem with what I said, and there are multiple problems with what I said, don't take that as like, well, this is motherhood and apple pie. Seriously, you do that, you're shutting down new features, you're shutting down new product releases, you're doing all of this shit. But the biggest single problem is you're going to find a lot more vulnerabilities. And all of a sudden your CDs are just going to be flooded with all the vulnerabilities that your research department is looking and finding. So it's tough. I think it's really, really hard to kind of change that culture. And you could just try to sneak the patches in in your standard patch release. It's like fixed stabilization issue in X, Y and Z. But seriously, some of these vendors, I know that like Oracle and Java, they did a full stop. I know that Adobe did a full stop. There's a number of vendors out there that are literally just saying, okay, enough is enough. We need to do a full stand down and build our SDLC from scratch.
Kelly
Yeah, I think you're not wrong. But I think like a company like Microsoft has been pushing into that space.
John
For like 20 years, basically hard actually. Yes, you're absolutely right.
Kelly
Like, and they're still not really. I mean they still have tons of legacy products that still are probably vulnerable. But yeah.
John
Anyway, if you look behind the hood of what they're doing for static code analysis on operating systems, specifically focused on operating systems, it is insane. Like, you're not going, well, I'm going to say this and something's going to come out next week, you're not going to find a standard buffer overflow attack in a Windows component.
Kelly
I mean it's, yeah, it's like anything else. Security, you catch what you can. And this is one that probably should have been caught.
John
Yeah, yeah, yeah. Now I want to ask, aside from the vulnerability, how do we feel about the disclosure on this one? Like it took forever for CDE to Get cut. It took forever for Fortinet to come out and say it. And them saying that they were protecting the customers. Do you think that that's honestly how they felt or you just think it was bullshit?
Ralph
I think it was BS to be quite honest. We've seen other companies try and pull that line before that, oh, we're not releasing it because of the company or we're protecting our customers and we've seen. I'm trying to remember, I wanna say Microsoft's pulled that at one point in time and a few others of the big names have pulled that in the last couple of years. And every time we've called BS on it. So this is just the same bs.
Kelly
It's.
Ralph
They got their hand caught in the cookie jar. They probably knew about it and had been trying to figure out how to fix it. And now all of a sudden it's, oh, crap, now we have to figure something out with it all. We gotta act like we didn't know that this was happening. That's my honest opinion.
Kelly
I mean, I, I would guess, like, this is totally speculation, but I would guess there's some staffing changes or things. Like John mentioned, you know, this. Maybe this actually has gotten traffic or traction at like the executive level and they're replacing the SDLC team or they're. Because it seems like they just got no response. Also, like, this security response page was dysfunctional for a couple days. But, you know, I think the thing, the funny thing the researcher identified was like, there's clearly teams at Fortnite that are doing cutting edge vulnerability research. I mean, they have a blog post about finding and burning a zero day in a competitor's product. And then like the researcher goes and says they should probably do the same for their own products.
John
Well, and that's my point, like, unleash that team on your own products. Right. But you know, I seriously think that a lot of those teams, their number one goal is marketing and making sure comics look bad. It's.
Kelly
I mean, it's not like Black Hills. I mean, I mean, look at us. It's not like we spend all of our time pen testing ourselves. No, we don't. Like, are we. Do we get a pen test? Yes, that's.
John
We hire Red Siege for that. Sure.
Kelly
But we do a lot more pen testing outbound than we do in back.
Ryan
Yeah, I mean, yeah. To correct. I mean, like, there's probably a team that doesn't work with the other team internally to do this, you know, and they're like, we gotta get research. But you know, it's not on their product. Right. So.
Cory
Yeah.
Ryan
And of course.
Kelly
Well, it's kind of like, look at.
John
All stuff that we heard coming out of CrowdStrike for years. Right. Like if you were a red team. And by the way, this is secondhand heard from people that were former red teamers at CrowdStrike. So just being very clear is CrowdStrike employees have a way of yelling at me, which I think is adorable when they do. But CrowdStrike's like Red Team. They were specifically told not to try to bout bypass CrowdStrike. And you know their logic for that. What they would tell the customers is like, oh, well, you know, it's just too good. We don't even try to bypass it. It's like, bullshit. They knew that if they were bypassing their own product, it would create political problems.
Kelly
That's a conflict of interest. Imagine doing a pen test and then they. We, you know. Yeah.
John
I mean, like, look at the container.
Kelly
Yeah, but we don't sell CrowdStrike. That's true.
John
That's true.
Kelly
I mean, do we want to move.
John
Into CrowdStrike and Delta because.
Kelly
Holy. Let's talk about the lawsuit.
Ryan
Yeah, we talked about this at one point, but they're not going anywhere.
Kelly
Yeah, Delta is the other one that's. Or some. Delta is the main one. But there's other. I think there's other companies suing. This is all based on Crowdstroke or whatever we're calling this.
Alex
Yeah, this is a big one.
John
500 million.
Kelly
That's just one plane crash, John. That's nothing for them.
Ryan
Yeah, well, CrowdStrike says that if they didn't have old systems like Windows 10, then everything would be fine.
Kelly
Yeah.
Alex
I think all of us are on the standby list. Ding. For seeing Delta with like some discounted tickets and services available. Because the thing that's going to come out of this is Delta is going to have to lay out all of their IT practices. And so, you know, so I was looking through this as a lens of like, if we talk about the story, we go through the what? But then also the so what? And the what do you want to do about this? And I thought, like, how many IT shops would sit there and go, oh, okay, we're now. We're now suing a third party for this. And they want to see all of our IT documentation, make sure that we're backing things up, making sure that we're doing all like the replication correctly. And a lot of IT shops may very well be like, oh, yeah, hey, Bill, we're backing up our stuff, right? And it's like, absolutely, Brian. It's like, okay, we're writing that down, aren't we, Bill? And he goes, son of a. Crowdstrike. We're not writing that down. There's no documentation on it. We're going to get absolutely, like, reamed if we have to take this to litigation, which is what CrowdStrike is pushing back at, is the.
Kelly
Yeah, yeah.
Alex
Your. Your system. You know, prove to us that your systems and your processes and procedures. Because I also have that question, like, to myself and to the audience. How many of you have had, like, flights that got canceled because of some Delta computer.
John
God, no.
Alex
Unrelated to CrowdStrike.
John
Yeah.
Kelly
Like Southwest, where they leased to one firewall. That response was responsible for all of their flights on the entire western seaboard or what?
John
Let's look at this. Okay, let's take this apart. Okay, so let's say pro CrowdStrike. All right. On the pro CrowdStrike stride, if I was working as an expert witness in that particular case, I would absolutely do that. I would say I want to look at everything, and I will make that trial referendum on Delta's IT security practices. Do you have change management? Okay. Yes. Do you have it everywhere? Well, no. Why don't you have it everywhere? You know, you can put any competent, like, security professional, you can tear apart the IT security practices of an organization. And somebody also went through and said, you know, there was a lot of thing. A lot of airlines went down. Why did Delta take so long to get back up?
Ralph
And that's one of the things that CrowdStrike itself has been saying inside of this lawsuit.
Kelly
And it's true.
John
Why?
Alex
Why you.
Ralph
Because it's either your processes or your equipment or a combination of both that had to have caused you to go ahead and take. What was it, three times as long, four times as long as the other airlines. I mean, so.
John
And here. So let's. It. So let's flip it around. Let's say that you're the attorneys for CrowdStrike. If I was working for. Sorry, if you're the attorneys for Delta, if I was working in as an expert witness for Delta, the tact that I would take is that we bought the CrowdStrike like Kool Aid Flavorade. It's Flavorade, not Kool Aid. Flavor Aid. We bought it and we put it on all of our servers. We put it on all of our workstations. We believed their sales engineers. And the reason why we were hit so much harder is because we had a Far more in depth CrowdStrike deployment than these other firms. I tried to figure out if there's another approach that Delta could take, but.
Jason
Then I think there is.
John
Go for it.
Jason
If I was involved in this conversation, I would have gone after CrowdStrike. I would have gotten one of the regulatory agencies involved because I think they're sitting back and they're kind of watching. Remember, Delta is a publicly traded company, so we're talking about SEC disclosure rules. Was it a cyber incident? Yes or not? If it is a cyber incident, they have to disclose it to the SEC and they have to explain materiality. Now we're starting to get into lost revenue and that sort of thing. So I would have gone after CrowdStrike. I would have kind of waited to see what was handed to me from the regulatory agencies because I think the hammer's still going to drop.
John
Wait, do you think the hammer is going to drop on CrowdStrike from the SEC, or do you think it's going to hit Delta and other.
Jason
Both, John.
John
Both.
Kelly
Yeah. I mean, I definitely agree with that logic because if you're, let's say you're the CSO or CTO or whatever of Delta, you have to build into your threat model or whatever you want to call it, the fact that something could take down all of our computers in this way. And if you can't recover from that availability, you know, security is one thing, but this is availability. It goes out the window and you're still responsible for that, whether or not it's the vendor or a guy with a pair of wire cutters, whatever it is. You have to be planning for this kind of disaster recovery. And if you aren't doing that, in my opinion, you're still negligent in some way. I will say, like the subtext here people are mentioning in the context or in the comments is like CrowdStrike offered to help Delta. They were like, hey, what can we do? We can send technicians, we can help you. Apparently Microsoft also offered to send people to help Delta. Like, everyone wants to get on their plane, right? Like, no one is like anti Delta. But apparently Delta turned both of them down and was just very hostile from the beginning. Kind of like they wanted to pick a fight on this. So it might be like some corporate politicking. Maybe a bad golf match happened, someone ran their golf cart into someone else. I probably.
John
So here's, here's, here's my, like my final take on this is Delta screwed up. Delta shouldn't, like. I agree with Kelly 110%. They should have waited for SEC, they should have waited for something else. Delta should not have pulled the trigger on this, number one. Number two, because all their dirty laundry is about to be Laundry is about to get exposed. Number two, if CrowdStrike and Microsoft offer to help, accept that help. This feels to me like there's an executive, a CTO or CEO that is being an absolute ass, being completely arrogant. That is basically like f those guys, we're not going to bring them in to help this thing. We're going to sue them into oblivion without truly understanding the extent of just how bad it's going to be for them. Because if I had to choose, like, if I had these two companies, they're like, which one do you want to work with? I would not be working with Delta on this one. Because I just feel like, yeah, CrowdStrike, yeah, they absolutely screwed up. It was in the news. Everyone's aware of it. We get that, we understand that. But Delta, like, there's going to be so much fun going through all of Delta's IT practices. Because going back to Kelly was talking about once those IT practices get out. And I would do discovery to say, are there any incidents that Delta has had where CrowdStrike has not been deployed or any of these different things, then you can take all of those other incidents and you can feed those back to the sec. Now you can start asking questions. We had a workstation that was compromised on June 22. How come that wasn't reported to the. This is just bad. Like, Delta's going to have to open up things in a way that they do not want to do. And seriously, if they could have held back then part of a class action lawsuit with multiple people with them, I think they would have been in a much, much, much better situation. But right now I just really feel like whoever's running things at Delta is really running on emotion, piss and vinegar, and their ego is way out of line. And they're about ego from a C suite. John, My God, right?
Kelly
This would be the first time we've never heard that before.
Ralph
What do we think the odds are that this is a ploy just to get some sort of settlement to get some money back on the whole thing going forward.
John
I can see crowds like CrowdStrike taking this to the map, though.
Kelly
Well, but CrowdStrike versus Delta is David versus Goliath. I mean, you have like, yeah, yeah, look at Delta could sell a plane and make 500 million in like five minutes like that. It's nothing.
John
But I think that CrowdStrike has the expertise like whenever they get into a legal situation, like just the cost of the lawsuit. CrowdStrike has built in cybersecurity experts that they don't have to eat the cost on.
Kelly
Oh for sure.
John
Delta is going to have to bring in a mandiant, they're going to have to bring in some other consumer, IBM. IBM and they're going to be paying for that IT expertise. It's versus blind.
Kelly
Okay. I'm just saying company size wise. Yeah. CrowdStrike is tiny.
Ryan
What significantly larger market cap than Delta does.
Cory
So we say Delta wins and now it's Delta Strike.
Ryan
Delta Strike that domains available.
Cory
Is it just like BlackBerry taking over? Silence. Right.
John
Like Delta Strike sounds awesome. Like I would buy that product on the name.
Ryan
I mean that's probably the coolest attack you could do right there. Delta Strike.
Kelly
Yeah, I mean yeah, it is funny. Like market cap versus revenue, like CrowdStrike revenue is 3 billion. Delta's revenues 58 billion. But their market cap a lot more.
Ryan
Money to get it. You know what I'm saying?
John
Yeah, no I agree with that sentiment as well. Like you know there's market cap but then there's also no Delta.
Ryan
Delta income like how much they actually affect the economy is they're not even in the city.
Kelly
They have a hundred thousand employees. Their net income is bigger than CrowdStrike's revenue. They're huge. That's why I'm saying David versus Goliath, it's one. I mean again it'll come down to the court decision. Both companies are going to throw down. Like John said, it's going to be, you know, who's going to win. We'll see. Neither of them are going to cheap out in this lawsuit but Delta is a hundred thousand employees and like 10 times as big anyway.
Ryan
Yeah. It is kind of interesting though too when you talk about just like the size of a company. Right. Some of these like blue chip bigger companies. Right. They don't, you know, they have lifespan to back it up but their stock isn't worth a ton. But it's very stable.
Alex
Right.
Kelly
So yeah, because the stock market is human emotion and that's how numbers work.
Ryan
Yeah, that's how numbers work. But to your point Corey, you're absolutely right. Delta is a significantly larger company in every way and metrics that you can come up with.
Kelly
That's what I'm saying. Not based on stock market.
Alex
Yeah.
Jason
And Delta is also under scrutiny or airlines in general for if you your flight gets canceled a lot of times they will give you an E credit and the FAA or the ftc, can't remember which one has said, listen, you cannot give an E credit. You have to give customers back cash. That's one of the big things that came out of the CrowdStrike situation was customers were kind of left high and dry. I know. I was stuck in Utah for a couple days. So I do think the regulatory agencies are looking at this carefully. They're putting their ducks in a row and getting the case set up.
Kelly
So what you're saying is they're going to start offering everyone a CrowdStrike Falcon complete trial for a year when they miss their flight?
John
Perhaps.
Ryan
One other thing to your point, Kelly, is that, you know, the Delta, they're under federal agencies. They have.
John
Ralph, bring your mic in a little closer.
Alex
Oh, sorry.
Ryan
They have rules they have to follow. Right. That the federal government is setting for them. They don't have a choice. And some of those affect their bottom line. To your point.
John
Right.
Kelly
CrowdStrike has none of that.
Ryan
Absolutely zero like things that they have to follow as far as rules and laws. Right. That they're under because of their industry. Right. So, I mean, very different how the federal government's going to treat that situation because they're causing pain that the federal government is now. So, yeah, I don't know. It's kind of interesting.
Kelly
All right, let's. Let's segue. And again, I think this article will be right up Kelly's ALLEY. But the SEC charging tech companies for downplaying SolarWinds. Did you see this, Kelly? I'm assuming you're smiling like you know you have already have a hot take ready for us.
Jason
Well, I do. So we were talking a little earlier today. CJ Our chief operating officer and I were at a legal conference yesterday or last week, and this was one of the topics we were talking about. So this synopsis of the article is the SEC went and charged for tech companies, I might point out, in the solar wind situation that happened back in 2020. 2020. And the four companies that they find were Unisys, Avaya, Checkpoint, and Minikats. And basically they fined them for misleading the sec. And each of them has a slightly different case.
John
Minicast.
Kelly
No, I'm cast. Yeah, you've been hanging out with hackers too much, Kelly.
John
Way too much. Yes, Kelly, Let the darkness spread. Yes. Yes.
Jason
So what happened here? So the SEC said, listen, you've got this very short period, 72 hours, to report a cybersecurity breach that may impact materiality. And that's a legal term that basically says, is it going to impact revenue or your bottom line, or is it something you need to share with your shareholders? Well, so they kind of put all of us who deal with publicly traded companies in a tailspin. And the lawyers and the cybersecurity experts say, oh, my goodness, we don't want to get in trouble with the sec. So what happened is people started releasing disclosures quickly without necessarily completely understanding the incident incident in its entirety. In the case of Unisys, they actually had materially misleading disclosures because they said, oh, we think we're basically okay. But they didn't really know if they were okay or not because they had deficient controls. And one thing I guess I really want to highlight here is the SEC is not a bunch of lawyers. The SEC has a very, very talented team of technical engineers who are as good as my coworkers at Black Hills Information Security. So if you think you're going to pull one over on the sec, let me tell you, you're not going to.
Kelly
Unless you're Bernie Madoff to say, anyway.
Jason
That wasn't cyber, though.
John
Ouch.
Kelly
The SEC has changed. Now they're like, we don't like stocks anymore. We just like breaches. These are really interesting.
Jason
So what. What would I want everyone to really take away from this article? First of all, we're learning. Don't freak out if you think there's an incident. What companies were doing is they were responding. They were reporting to the sec, but with inaccurate or incomplete information. Now, what our legal teams are advising companies to do is to make multiple disclosures and say, this is what we know today. We're still investigating. Two weeks. Now we know a little bit more. This is what we're doing. So there is an under. At first, we were thinking we needed to make one giant disclosure. Now we can do multiple disclosures.
Kelly
I mean, so I. My favorite part, there's one sentence in this article that I just. I know there's so much backstory to this one sentence, and I just would love to be in the room as they read it, but it's basically the investigation into Checkpoint found that the company knew it was breached, but downplayed the impact by using generic terms. I just think of the PR firm or whoever wrote it being like, no, it'll be fine. We'll just use generic terms that don't say anything. No one will know we're hacked. We'll just say there was an incident. Maybe some systems are impacted, maybe not. Like, I just imagine the person actually writing it being like, I'll use all these generic Terms, so no one knows. And then that specifically cost $1 million to use those generic terms. It turns out you can't.
Alex
You can't frame it around the word hypothetically. So. Hypothetically.
Kelly
Yeah. I mean, I will say, though, honestly, Kelly, to, you know, to like bring it all back. If it only costs a million dollars to downplay my breach, I would still do it. That's not that much money.
John
Totally, totally. Because this far.
Kelly
Problem.
John
Yes, yes.
Kelly
It's as easy to see. They're like, oh, this is what, three shares? Like, who cares? This is a million dollars.
John
The humans, we're gonna like, we find them a million dollars. People like, damn right. Serves them. And really these corporations are like, yeah.
Kelly
That'S just the generic terms.
John
Millions.
Kelly
Also, let's talk about how long has it been since the SolarWinds breach? It's been four years stories dead that.
Ryan
Solar wind will never set.
John
Yeah, yeah.
Kelly
All right, what's next?
Jason
The reason why it's taken so long is the burden of proof when they actually had to go and invest.
John
That is true.
Jason
The four companies. As somebody who's been in out of the courtroom recently, our legal system takes forever, right?
John
It grinds slowly, but it grinds very fine. Speaking of things that grind slowly in the government, Kelly, have you looked at the new security requirements to protect government personal data?
Jason
Are you talking about the AI story?
John
No, no, no, no, no. It's the, It's. The CISA proposes new security.
Jason
I did it. It's basically the CIS controls.
John
It is the CIS controls. I would like everybody, like, who listens to this because, you know, clearly everyone listens to this show, right? If you're nominated are in a situation where you're like, you know what we need to do? We need to put out some security guidance. Stop. Just stop. You are not helping. You are contributing to the problem writ large. If you're looking at asset inventory control number one and two, exploited vulnerabilities, vulnerability management is in there. Critical vulnerabilities, vulnerability. Like everything that they have here is already in the CIS controls. And I don't understand why. Why it is every single. Like it seems like every six months there's a new group that's coming up and proposing brand new security standards from scratch and hell, and maybe it's not CIS they use nist, I don't care, but let's stop creating new security standards.
Kelly
Well, you do care if it's password guidelines, but anyway, I do care if it's password guidelines.
John
That's true, but they also. What was their password guidelines See, now at least they spend.
Kelly
At least. What are we even talking about? Who?
John
Leaping computer. Yeah, but it is.
Kelly
Who. Who is it? Sza. Like, who even came up with these? No, Joe Biden made his own password complexity. Joe Biden passwords. What's going on?
John
Yeah, it's. It's just like, what the hell? Like, stop. Like, stop, stop, timeout. I, you know, I, you know, I get interviewed sometimes and they're like, you know, what are the things that make you mad? And I'm like, well, lack of multifactor authentication really pisses me off. But people writing new standards from scratch is just right up there. It's just.
Kelly
Well, so hold on. So hold on. This is. I'll play devil's advocate because I feel like Kelly doesn't want to, because she's smart. Like, okay, so this is a stop gap. This is specifically about AI, which we know it's going to be at least 15 years before Congress can ever even understand what AI even begins to mean, let alone actually truly understand it. I think that's what this is more than.
John
It's more than AI. It's AI developers, cloud service providers, telecommunication firms, health and biotech organizations, financial institutions and defense contractors.
Kelly
Sure, but it's a stopgap, right? I mean, I don't know.
John
I could be wrong, but stopgap for what? Between what and what?
Kelly
Like, between now and when Congress decides to pass a ruling on protecting personal data.
John
Like 10 years from now, we need a law. That's right. We need Congress to step in and come up with security standards.
Kelly
Not security standards, just, you know, Federal Privacy Act. Yeah, there we go.
John
That they do. Yeah.
Kelly
I mean, that's what this is. This isn't about security, it's about privacy.
John
But why create a new standard? What happens inevitably is people are like, we're going to comply with CISA, we only have to comply with these 10 things or 15 things. Right. And now we can ignore this. Now we can ignore cis, now we can ignore ISO. Now we can ignore hipaa. Now we can ignore pci. We're going to be in compliance with this, and that's the concern. Right.
Kelly
I mean, I agree with you, but you should keep in mind this is an executive thing, which means everyone's already just going to ignore it anyway.
John
Okay, that's true.
Alex
Yeah.
Kelly
Like, no one follows these executive things. They're just like, oh, so the President signed this? All right, moving on. Like, that's zero play together.
Jason
Let's clarify what Corey is saying. Last week, the President signed a national security memorandum to address how artificial intelligence is used at government agencies. And to Corey's point, he's correct. This is a complimentary article that says, hey, in light of this new memorandum that came out, here's how we want you to treat data. So I'm going to try and play the middle ground here between Corey and John and say, yes, there shouldn't be a new standard, but it's a good time to read, remind people about these basic cyber hygiene things that they need to be doing.
Kelly
Yeah, I mean, it's mostly a privacy thing. I don't know. I feel like it's. I look at the day, look at the time. It's a campaign thing. Right. It's like we. It's basically the president saying, I support your personal data being protected. All right, everyone can all move on now.
John
And everyone goes, well, I'm voting for that guy.
Ryan
Yeah.
Kelly
Because he protects my personal data. That's my number one.
John
He's going after that. Sweet, Sweet infosec voting.
Kelly
2% of the voter base.
Ryan
Yeah.
John
50% of the IT infrastructure. Let's move on. Can we talk about the largest retail breach in history?
Kelly
Okay, so first of all, all the coolest people are about to be breached.
Ryan
I honestly am very upset because my frequent flyer customer super card is going to be exposed.
Kelly
You have a frequent flyer card at Hot Topic. What do you have to do to get that?
John
I'm trying to figure out the last time I shopped at Hot Topic.
Kelly
Corey telling you, can you pull that.
John
From me and let me know?
Kelly
Yeah, let me pull that. No. So basically this is just a normal breach. We're seeing new threat actors emerge. This one's satanic. It's sadly not USD, who we talked about last year or last week who got arrested in Brazil. So basically this is a huge breach. They're claiming 350 million customers. Seems insane to me. Does that mean the entire population of the U.S.
Alex
I mean, my experience has been they've been pushy. So for like the box lunch, like, they have some decent. They have some decent, like, merch for, like, pop culture stuff. So if you're like a Star wars fan and you want to get like the latest, you know, Star wars hoodie or something, Christmas and stuff. When I go in there and I'm like, I'm just buying like a Super Mario pin for my kids because they like it. They're like, well, put in your rewards number. I'm like, I don't really want to. And they're like, well, put this stuff in. I'm like, no, and they're like, well.
John
Basically like, they do it.
Kelly
And I'm like, I don't.
Alex
You know, there's. I'm like, I don't need this $5 Super Mario pin. Like. And you put in, like, there's probably like a bunch of false information that I have in there anyways, so.
Kelly
So.
Alex
Which is also a hint.
John
Like, I just want to call out Jason P71. John Strand for president. What the hell did I ever do to you? Like, why would you do that?
Kelly
So is this where they got the.
Ryan
Idea of a Hot Topic being like, Satanistic?
Kelly
Is.
Ryan
Is the edginess there's like a Satan that comes out to get you to do this kind of crap?
Kelly
Satan comes out and breaches.
John
Yeah. Alex, put in your information. Not yay, Satan, but it helps my roi.
Ryan
Yeah, I do think it is funny.
John
You've really fallen. If you're a sales manager at a Hot Topic in a local mall. It's like, times are tough for Satan.
Kelly
Times are tough for Satan.
John
It's a season. I peaked in the middle ages in the 80s during the Reagan administration. It's been real rough lately.
Ryan
Oh, God.
John
Yeah.
Kelly
So I will say that the last kind of follow up. So data is being sold for $20,000 to anyone or 100,000 to Hot Topic. Of course.
Ryan
Why would they want it?
Kelly
And they don't even like customers buy and bury, dude.
Ryan
No, they're not going to buy and bury, dude.
Kelly
They're going to sell it to somebody.
Ryan
They probably already sold it three times.
Kelly
Yeah, right?
John
Yeah. I mean, yeah, just. How much? 30. How much? 30 seconds to Mars merch.
Kelly
Do you really need like 350 million people needed that? Was it 350 too.
Ryan
Was that.
Alex
Was that de.
Ryan
Duplicated like that was.
John
No.
Kelly
There's no such thing as deduplicating for hackers. You know how they are.
John
No, because we make that number as big as they can. Right? It's Hot Topic, the new rock you. I don't think we got clear text passwords.
Cory
They have all the emails by. By aggregate.
Kelly
This is boring. Let's be real.
John
I see the. The scams coming. If you don't send me one bitcoin, I'm going to release to everybody in your. Your global address list that you shopped at Hot Topic.
Kelly
Okay. How many just to give every. All the blue teamers here who are scared about data breaches. Don't be scared. It was info stealers. And it was Snowflake, like every other freaking breach these days.
Ryan
You made that article not nearly as cool.
Kelly
Corey, I'm sorry. It's still cool because of cool band shirts and posters and edgy things where.
John
You'Re strapping cool band shirts. That is true.
Kelly
It is.
John
Like, I see kids wearing those cool band shirts. I'm like, that band is awesome. They're like, I just liked it for the shirt. It's like, like, oh, yeah.
Kelly
But John, that's the same thing it was when you were a kid.
John
I was learn. What band do we have there, Ryan?
Kelly
Steve Miller Band.
John
It's a Steve Miller band. I was digging in bars with my dad doing, you know, keep on a rock and be, baby, when I was 13 years old. Like, you know, I, I, I, I knew this.
Kelly
Yeah, but your shirt was from Rad.
John
Oh, my God. It sound like an ancient hipster. Next story, next story.
Kelly
Let's move on to talk about the poops. Okay.
John
All right.
Kelly
Yes. So this is on TechCrunch and this app. So this is. I'm glad that we're getting back here. Although here's the, here's the twist. This is not Silicon Valley. This is Austin. So apparently we took Silicon Valley, we turned it into an AI hotspot, and now Austin is the new tech hub. Basically, this is a camera. The camera clips onto the side of your toilet bowl. It takes a picture of ear poop. Again, I don't. Apparently this sounds like an OnlyFans thing, but turns out it's not. In beta, it utilizes artificial intelligence to examine your dookie as a way of determining things like gut, health and hydration. I'm sorry, can you imagine being the developer of this and claiming it was a straight face that it's doing? I mean, also. Okay, can we talk about. There's so many logistical questions. I have probably just Amazon perk and just.
Ryan
People have to.
John
I just.
Kelly
No, no. It's called Amazon Mechanical Turd. You're thinking of.
John
Yeah, I. So this come. This came out at roughly the same time. I don't know if you guys know Lily Allen. She's a big musical artist out of the uk. She's huge. I like her stuff. She came out last week and she said that she makes more money on only fans selling foot pictures, and she does off of Spotify and she has like 8 million streams a month.
Kelly
So is this the app version of that?
John
I think that this app is literally like the foot picture. Like it's going to be the dookie pictures in only. Only fans. Like, that's, that's the target market for this.
Kelly
Okay, but I'm looking at. I'm Thinking there's so many things in this article that are just too much. Number one is it calls its under underlying technology artificial gut intelligence.
John
Oh, my God. Oh.
Kelly
It says it's trained by physicians. The doctors are looking for signs of health found in waste matter, including nuances in urine to determine hydration levels. Like, okay, I got to tell you, if you need this app, you need something else. Like, this is not.
Cory
The sad part is probably most of the United States needs this app. That's the worst, right?
Kelly
They don't need this app.
John
No.
Cory
Eating shitty food and then being told like, hey, your shits are so bad.
Kelly
Know that you don't need an app to know if your poop sounds. These people do.
John
All right. I love the confusion that I started on discord People like, who's paying for foot pictures? And other people are answering that for them. And like, don't ask questions. You don't want the answers. You don't want them. Proxbuck said two years of corn to calibrate.
Ralph
No, the real question is, can it tell the difference between a poop and a baby Ruth?
John
No.
Cory
Hot dog.
John
Not a hot dog.
Kelly
Oh, no. I would be so fun to buy this. Dude. Just hardness and hardcore.
John
Threw it back to the. My friend.
Ryan
Listen, they already can't make robotic vacuums not run over turns.
Kelly
How do you think that Amron is.
Ryan
Like, gonna get the turd right?
John
You know what I'm saying?
Jason
Take a privacy and security for a second.
John
Don't we take us privacy because we need some new shit to talk about.
Jason
So if you. If you go and you look at the. So the article refers you back to Thrones data privacy and security statement. And I don't know if you guys read it or not, but it' it's very interesting. It says we cannot track you as an individual. And part of me is kind of calling BS on that because they say they're only using anonymized data. But I would imagine that the camera has to send its data somewhere and then it's anonymized. And they say, listen, if you want your data deleted, we will comply with that. You know, for California laws or gdpr, for them to be able to actually delete. Delete your data, they have to know what data is yours.
John
Is that not true? Yeah, that is absolutely correct. And but this is. This is. We see companies all the time, like, we don't know who you are. We anonymize it. Now, you do have an app which has a user ID that is then.
Kelly
Tracked, and we have that Your IP address.
John
We also have your IP address. Other than that we. There's no way, I think you're breaking it down to like the point where it's like they're, they're full of. Right. I mean if we're really, if we're really looking at this, it.
Kelly
Do we need. No, no, no, no, no, no, no, no, no. Hold on.
John
She's got one too.
Kelly
Hold on.
John
Your turn.
Alex
Okay. Yeah. So it's like my point on this, like Corey sort of brought up and I've seen this a lot in discussion with AI and I, I feel like calling this out is that there's, there seems to be a lot of statements on like who makes use of this? To where you hear about something silly like this and go, well, who, who makes use of this? Who needs like an AI water bottle that reminds. Forgets to drink water. It's like there are people out there that this benefits.
John
And what is number two work for?
Alex
Well, yeah, and I mean and we'd like to make the jokes of this, but for some people like this, these AI implementations are life changing. Like if you have these types of things to where you have to provide stool samples. I don't know if anybody's ever had to do this, but like scooping poop onto a card, putting it into an envelope and driving it to the doctor, that's, that's a meth in itself, but.
Kelly
It'S not going to cover that.
John
But I don't think that it's like taking picture. It can like die diagnose you for that.
Kelly
Correct.
John
Right. Like I am willing to bet there's something in this app that says this. Do not use this for diagnosing anything. Insult a real doctor for it. Right. What you're saying though is more of a meta thing moving forward.
Alex
Yeah, like AI overall. Like you, you have people like I've seen like so many like speakers that give presentations being like, oh, let's laugh at this silly AI thing. So like my, my overarching thing is like you. Just because it doesn't make sense to your brain does not mean it doesn't make sense to somebody else's brain. Like there is a useful article on these.
John
I agree with that 110%. But poop is funny.
Ralph
The question that I have, and I didn't see any of the information on this in the article itself is is it just doing a visible light photo or is it using infrared and some other sensor technologies?
John
I think it's just, it's just a picture.
Ryan
It smells.
Ralph
If it's using other technologies. Theoretically, I could see how they might be able to go ahead and use something in infrared because of the way.
John
Certain things show up in infrared.
Kelly
There's so many logistical challenges and I'm.
John
Gonna agree with Alex on this. Like the Cologuard commercials, I remember when they first came out, I was laughing about that. Now I'm at the age where I'm like, yeah, I'm probably in their target audience.
Kelly
Okay, that's fine. But here's the thing. This. Okay, there's. There's two parallels I want to draw from this article. Number one is, is this the bridge too far from a privacy perspective? How many people are going to be willing to put a camera in their toilet? That where they, I mean, look, dude.
John
You'Re playing micro percentages on the fringes, right? The United states has over 300 million people. If you get like 1/10 of 1%, you've made it big.
Kelly
Like, okay, okay, that's fine. But I still, I think the average person wouldn't care about data protection and AI wouldn't care about apps on their phone, wouldn't care. Most privacy things, people are hard. It's hard to get sell people on them. But I think saying, would you put a camera in your toilet? I think a lot of people will be like, huh, maybe not. But the other thing I wanted to correlate from this article is there's another article we have about the date recognition. Which gate is people, how they walk, how they. That's a way of identifying a person even if they're wearing a mask is poop recognition. The next version of this where every, every like airport, in every airport has these poop cameras deployed and if someone takes it up, they're like, sir, the terrorist has pooped in section seven. Go.
John
I gotta be honest, I'm way more comfortable with someone taking pictures of my poop than fracking my. No, no, I'm not joking. I'm not joking. I am way more comfortable with that than I am whenever I'm walking through airports, I'm walking through Walmart, I'm walking through Safeway, I'm walking through all these stores and I that, you know, let's put the poop thing away. But seriously, the gate recognition, the fact that I don't even like going into Walmart because when you look at the self checkout, they got the picture and a high definition and they're doing recognition on your face. It's just like, God damn it. I don't like the idea of being tracked absolutely everywhere. I Go. It's, it's, it's weird because like I said, if you want to look up like pol. Political scientists, look up Jerry Ban and Panapticon. Right. If you're being watched constantly, it changes the behaviors of society. Not necessarily always for the better. Yes, Right. And that's like, you know, I really am genuinely concerned. Learned about, hey, we can track people regardless of whether they have a mask, regardless of whether they're trying to cover up with a hoodie and all of these different things. I mean, but it still sucks because I still have family members that are basically like, they still have family members that are basically saying things like, you know, well, if you have, if you don't break any laws, you have nothing to worry about. But I do want to stop. We have to close it out. We have someone that's talking about self harm and we have somebody on the show that's talking about cutting themselves. All right, I want to do full stop. All seriousness, I do want to say, anybody, anybody in Ultron, this is going to you. Yes, I have been through these things. All right, please do me a favor. Two things. One, know that you matter, number one. Number two, please do me a favor and get help. Help. I, you know, whatever that may look like, you know, go to a family member, let them know, try to get some help somewhere. But please, please, please don't, don't, don't, don't do that, you know, because we've got a great community of people here. People are supportive on our Discord server. I see that you're on YouTube. One of the best things you could do is just get off comments of YouTube. But at the same time, please get some help. You are cared for and you matter. So with that, anybody that feels that way, there's lots of help. I can't remember what the 1-800-number is for people that are, that have these types of thoughts. Somebody could please put that 1,800number out right away on YouTube and on Discord. I would greatly appreciate it. But please, please, please take care of yourself and like, it will get better if you can just get some help. So with that, let's go ahead. If somebody could please get that one, 800 number for suicide prevention line out there. Normally these things are not what we want to talk about on these shows. But yes, if this is the community and this is the place where someone feels comfortable enough sharing, let's support these people and we have a great community here as well. 811, there's 741741. Please reach out. You got people in the community that are reaching out to you right now, just letting you know that you are cared for in this particular community as well. So get some help, and we'll see you on the next episode. So let's take us out, Ryan.
Podcast Summary: Talkin' About [Infosec] News, Powered by Black Hills Information Security
Episode: 2024-10-28 - Sarsaparilla
Release Date: October 30, 2024
The episode opens with a light-hearted discussion about sarsaparilla vs. root beer, setting a casual tone for the show. Hosts John and Cory reminisce about their experiences with sarsaparilla, while Kelly delves into the nuanced flavors distinguishing it from root beer.
Timestamp: [06:35] – [15:02]
The hosts transition into a critical discussion about the mismanagement of AWS authentication keys found in various iOS and Android applications. John raises concerns about hard-coded API keys:
John [06:39]: "If that key is living within that app itself, you may be exposing that particular key so another app can actually snatch it."
Kelly emphasizes the prevalence of such vulnerabilities in low-quality apps, questioning the effectiveness of app store scanning mechanisms:
Kelly [07:13]: "How is this not picked up in scanning? How is it... don't they scan these things?"
Cory and Alex discuss potential origins of these insecure apps, suggesting many may be developed by Chinese app factories using the same flawed codebase.
John advocates for robust Software Development Lifecycle (SDLC) processes, urging vendors to adopt comprehensive security measures rather than playing "whack a mole" with vulnerabilities:
John [21:10]: "I really have serious doubts as to whether or not they're actually implementing that."
Timestamp: [15:07] – [26:49]
The conversation shifts to the Fortinet vulnerability (CVE-2024-47575), highlighting its high severity score of 9.8 and widespread impact on approximately 60,000 devices. John criticizes Fortinet's handling of the vulnerability disclosure:
John [15:52]: "Could this be handled any worse?"
Ryan clarifies the existence of the CVE and its implications, while Kelly and the team discuss the broader implications for large vendors struggling with legacy systems and inadequate SDLC practices.
John draws parallels to past vulnerabilities in Java and Adobe products, emphasizing the need for major vendors to overhaul their security protocols:
John [17:15]: "Serious concerns as to whether or not Fortinet has implemented a solid software development lifecycle process."
Ralph and Jason echo these sentiments, questioning the prioritization of patch deployments and the financial burdens associated with extensive security overhauls.
Timestamp: [26:49] – [40:59]
A heated debate unfolds around the lawsuit between Delta Air Lines and CrowdStrike following a significant cyber incident. John expresses strong criticism towards Delta's handling of the situation:
John [34:49]: "Delta screwed up. Delta shouldn't have pulled the trigger on this."
Kelly and Cory discuss the power dynamics, noting Delta's substantial market presence compared to CrowdStrike's smaller scale. The team speculates on the potential outcomes and repercussions, highlighting the complexities of large-scale litigation involving cybersecurity firms and major corporations.
Jason introduces the perspective of regulatory scrutiny, mentioning how the SEC's involvement could influence public disclosures and accountability measures.
Timestamp: [40:59] – [50:55]
The hosts analyze recent actions by the Securities and Exchange Commission (SEC), which has fined tech companies like Unisys, Avaya, Checkpoint, and Minikats for misleading breach disclosures related to the SolarWinds incident. Jason emphasizes the SEC's stringent requirements for timely and accurate reporting:
Jason [41:54]: "The SEC has a very, very talented team of technical engineers... you're not going to pull one over on the SEC."
Kelly criticizes companies for downplaying breaches with vague terminology, resulting in hefty fines:
Kelly [43:15]: "They got their hand caught in the cookie jar. They probably knew about it and had been trying to figure out how to fix it."
John and the team discuss the implications for publicly traded companies, advising adherence to best practices in breach reporting to avoid regulatory penalties.
Timestamp: [50:55] – [54:14]
The episode covers the largest retail data breach in history, targeting Hot Topic with an alleged compromise of 350 million customer records. The hosts express skepticism about the scale, questioning its plausibility:
Kelly [51:13]: "It seems insane to me. Does that mean the entire population of the U.S.?"
Alex shares a personal anecdote about intrusive data collection in retail environments, highlighting privacy concerns:
Alex [52:27]: "If you're like a Star Wars fan and you want to get like the latest... they're like, well, put in your rewards number."
The discussion underscores the dangers of massive data breaches and the potential fallout for both consumers and retailers.
Timestamp: [54:14] – [61:56]
In a humorous yet critical segment, the hosts explore a novel AI-powered toilet camera app designed to analyze users' bowel movements for health insights. John mocks the practicality and necessity of such an app:
John [55:33]: "Can you imagine being the developer of this and claiming it was doing something straight face?"
Kelly and Alex debate the privacy implications and actual usefulness, pointing out the invasive nature of having a camera in the bathroom:
Kelly [57:07]: "How many people are going to be willing to put a camera in their toilet?"
The segment highlights the quirky extremes of consumer tech innovation while raising legitimate concerns about privacy and data security.
Timestamp: [61:13] – [63:31]
Towards the end of the episode, the hosts address a sensitive topic when a community member expresses thoughts of self-harm. John and Kelly compassionately reach out, urging listeners to seek professional help:
John [61:43]: "Please do me a favor and get help. Help... you are cared for and you matter."
They provide the National Suicide Prevention Lifeline number (1-800-273-8255) and encourage listeners to support one another within their community.
The episode wraps up with a reiteration of the importance of robust security measures, accurate breach reporting, and the ethical considerations of emerging technologies. The hosts emphasize the need for continuous vigilance in the information security landscape and the value of community support in addressing personal struggles.
Notable Quotes:
John [06:39]: "If that key is living within that app itself, you may be exposing that particular key so another app can actually snatch it."
John [15:52]: "Could this be handled any worse?"
John [21:10]: "I really have serious doubts as to whether or not they're actually implementing that."
John [34:49]: "Delta screwed up. Delta shouldn't have pulled the trigger on this."
Jason [41:54]: "The SEC has a very, very talented team of technical engineers... you're not going to pull one over on the SEC."
Kelly [51:13]: "It seems insane to me. Does that mean the entire population of the U.S.?"
John [55:33]: "Can you imagine being the developer of this and claiming it was doing something straight face?"
John [61:43]: "Please do me a favor and get help. Help... you are cared for and you matter."
This episode of Talkin' About [Infosec] News provides a comprehensive exploration of current cybersecurity challenges, from mishandled API keys in mobile apps to high-stakes litigation between major corporations. The hosts blend technical analysis with relatable anecdotes, fostering an engaging and informative discussion for both seasoned professionals and newcomers to the information security field.