Transcript
Greg Conti (0:02)
You're listening to the Cyberwire Network, powered by N2K.
Michael Heller (0:12)
Hello and welcome to Threat Vector. I'm Michael Heller, executive producer of Threat Vector and senior content guru at Palo Alto Networks.
Tom Cross (0:21)
It's not what a product or system claims to do or says it does, or even its marketing copy, you know, says it's what it has the ability to do, the true capability. With that in mind, you can operate more effectively.
Michael Heller (0:53)
I'm filling in for David Moulton with a special episode recorded at DEFCON 26 with Greg Conti, principal at Copidian and Tom Cross, a threat researcher at Getreal and a principal at Copidian. In this episode, we dig into the hacker ethos and how it led Greg and Tom to talk at DEFCON about a gap in security that most don't think about. That is digging into the difference between what a device or company is designed for and what it's actually capable of when put into the hands of someone interested in exploiting that difference. This form of curiosity is at the core of DEF con, and it's what makes the conference special in a world where most professional conferences have become a vehicle for marketing. I had a great time talking with Greg and Tom, and I hope you'll enjoy the discussion.
Interviewer / Host (1:44)
Let's get into it.
Interviewer / Host (1:51)
Welcome to Thread Vector.
Greg Conti (1:53)
Thanks for having us on.
Michael Heller (1:54)
Thanks.
Tom Cross (1:54)
Yeah, it's great.
Interviewer / Host (1:55)
Can you give me a little rundown of your talk today, minus all the technical issues, the technical difficulties that we ran into?
Tom Cross (2:06)
Yeah.
Greg Conti (2:07)
So our talk is called Dark Capabilities When Companies Become Threat Actors. And so what we're talking about is.
Greg Conti (2:17)
It tends to be the case that if you think about a company, there's a set of capabilities that they have that they utilize. Right. And then there's a set of potential capabilities that they have that they don't utilize. And we also think there's probably a set of capabilities that a company has that they don't realize that they have. And so when you think about those things, you know, what if you decided to flip the coin over on that and you said, what if we decided we wanted to be evil?
