1 00:00:00,049 --> 00:00:03,169 According to CrowdStrike's most recent State of Ransomware 2 00:00:03,179 --> 00:00:08,449 survey, 78% of respondents were attacked by ransomware last year. 3 00:00:09,040 --> 00:00:12,699 With odds like that, we figured it was time to bring on one of our most 4 00:00:12,709 --> 00:00:17,189 popular episodes, and this one's all about stopping ransomware from moving 5 00:00:17,199 --> 00:00:20,209 around once it's already in your network. 6 00:00:20,640 --> 00:00:24,819 I brought on Tom Hollingsworth, who knows networking way better than I do. 7 00:00:25,220 --> 00:00:29,239 Uh, we get into VLANs, zero trust, firewalls, and a few other 8 00:00:29,239 --> 00:00:33,679 things, including some, at least I think, really good war stories. 9 00:00:34,430 --> 00:00:37,389 If this is your first time watching or listening to me, I'm 10 00:00:37,390 --> 00:00:39,989 W. Curtis Preston, AKA Mr. Backup. 11 00:00:40,320 --> 00:00:46,330 I've been obsessing over backup, recovery, and now cyber recovery for over 30 years. 12 00:00:46,699 --> 00:00:48,420 If that's your bag, then I'm your guy. 13 00:00:48,689 --> 00:00:53,389 You're not gonna find anyone that's cares about backups more than me. 14 00:00:53,769 --> 00:00:58,119 Ever since 1993 when I had to tell my boss that there were no backups of 15 00:00:58,119 --> 00:00:59,779 the database that we had just lost. 16 00:01:00,379 --> 00:01:03,700 Now I've written five O'Reilly books, a blog, and a podcast. 17 00:01:03,849 --> 00:01:08,319 Here, we turn unappreciated admins into cyber recovery heroes. 18 00:01:08,550 --> 00:01:10,630 This is the Backup Wrap-Up 19 00:01:25,789 --> 00:01:28,129 Hi and welcome to Backup Central's podcast. 20 00:01:28,129 --> 00:01:33,499 I'm your host, W. Curtis Preston, aka a Mr. Backup and have with me possibly 21 00:01:33,499 --> 00:01:36,159 my Pex consultant Prasanna Malaiyandi. 22 00:01:36,859 --> 00:01:37,279 it going? 23 00:01:37,539 --> 00:01:38,219 Prasanna, 24 00:01:38,239 --> 00:01:38,359 am. 25 00:01:38,569 --> 00:01:39,769 I'm good Curtis. 26 00:01:39,769 --> 00:01:44,869 And just for people that's p e x, not P E C K S. 27 00:01:46,129 --> 00:01:52,619 Yeah, this is the piping, the, the modern piping alternative to copper, 28 00:01:53,219 --> 00:01:55,529 which I think is far superior. 29 00:01:55,619 --> 00:01:56,849 And, You know what? 30 00:01:56,849 --> 00:02:01,529 just for those that are watching this on on video, which is only a handful of 31 00:02:01,529 --> 00:02:06,959 you, but I'm gonna tilt my camera up and this is what my office looks like right 32 00:02:06,959 --> 00:02:15,429 now because I got yet another pinhole leak in my, second story water supply, 33 00:02:15,429 --> 00:02:17,439 which happens to be right above my office. 34 00:02:17,919 --> 00:02:21,819 And yesterday I was just sitting here at my desk and I get this 35 00:02:21,829 --> 00:02:25,069 drip drip on my face and I'm like, 36 00:02:25,314 --> 00:02:27,264 you're like, am I sweating profusely? 37 00:02:27,279 --> 00:02:27,909 Yeah. 38 00:02:27,914 --> 00:02:29,739 And the pipe is actually over there. 39 00:02:29,739 --> 00:02:33,849 the joint that's leaking, it's actually over there, the water finds its way, 40 00:02:34,074 --> 00:02:34,884 down cracks. 41 00:02:34,914 --> 00:02:35,304 Yeah, 42 00:02:35,474 --> 00:02:36,154 it just drips 43 00:02:36,154 --> 00:02:37,564 down onto my face. 44 00:02:37,999 --> 00:02:40,069 Yeah, we wanna bring on our guest. 45 00:02:40,119 --> 00:02:43,389 he is both, I would say, a friend of the pod. 46 00:02:43,389 --> 00:02:45,759 He's also been an enemy of the pod at once. 47 00:02:45,759 --> 00:02:49,659 You may recall that we had an episode where basically we just argued 48 00:02:49,659 --> 00:02:53,619 with Tom without his per, without him being here to defend himself. 49 00:02:53,999 --> 00:02:58,109 that was over a blog post that he said, something about, backup 50 00:02:58,109 --> 00:02:59,699 people reporting to security people. 51 00:02:59,699 --> 00:02:59,969 And, I 52 00:02:59,984 --> 00:03:00,194 Yep. 53 00:03:00,209 --> 00:03:01,559 had an issue with that or something. 54 00:03:01,869 --> 00:03:04,569 Tom has been in the industry about 20 years and he is an 55 00:03:04,569 --> 00:03:06,639 event lead over at Gestalt. 56 00:03:06,819 --> 00:03:08,769 It the, what would you call it? 57 00:03:08,769 --> 00:03:11,859 The makers of the Tech Field Day series, 58 00:03:11,909 --> 00:03:14,339 and, we're glad to have him on the podcast. 59 00:03:14,339 --> 00:03:16,679 Welcome, Tom Hollingsworth. 60 00:03:17,504 --> 00:03:19,154 thank you for having me on Curtis. 61 00:03:19,154 --> 00:03:22,484 It was, it was fascinating to listen to an episode where I was arguing 62 00:03:22,484 --> 00:03:23,864 with somebody and it wasn't even here. 63 00:03:24,254 --> 00:03:27,004 But, I love listening to you guys, and I've learned quite a bit. 64 00:03:27,004 --> 00:03:30,794 In fact, the very first time that Curtis and I ever met at Tech Field Day back 65 00:03:30,794 --> 00:03:34,034 in 2011, he was teaching me about data de-duplication, and I was trying to 66 00:03:34,034 --> 00:03:35,744 convince him that IP V6 was important. 67 00:03:35,744 --> 00:03:38,614 And I can tell you which one of those things panned out a lot better than the. 68 00:03:40,359 --> 00:03:44,379 is it, that the thing where you do the nat behind the thing? 69 00:03:44,379 --> 00:03:47,679 That's what I recall really learning from you was that you gotta do 70 00:03:47,679 --> 00:03:49,359 NAT for I P V C 71 00:03:49,629 --> 00:03:51,249 like the Kool-Aid man, just keep 72 00:03:51,359 --> 00:03:51,849 Yeah. 73 00:03:54,489 --> 00:03:54,999 Yeah. 74 00:03:54,999 --> 00:03:55,419 Yeah. 75 00:03:55,469 --> 00:03:58,409 I wanted to bring on somebody that actually understood networking 76 00:03:58,409 --> 00:04:00,119 far better than me, right? 77 00:04:00,119 --> 00:04:03,299 Which, which is basically many people in the world. 78 00:04:03,669 --> 00:04:05,199 With ransomware attacks. 79 00:04:06,324 --> 00:04:11,444 One of the things that we talk about is once you've, figured out that you 80 00:04:11,854 --> 00:04:14,974 actually have a ransomware attack, you want to isolate the network. 81 00:04:15,334 --> 00:04:20,944 And there's a discussion, I've been talking with CISOs lately and what 82 00:04:20,944 --> 00:04:27,494 appears to be the reality is that few environments do the actual full. 83 00:04:27,494 --> 00:04:29,654 Like we just we're just shutting everything off. 84 00:04:29,754 --> 00:04:31,644 Go grab the cable, pull it out 85 00:04:32,244 --> 00:04:32,934 actually, I know. 86 00:04:32,939 --> 00:04:35,499 Tom, did you ever watch, alias when it was on 87 00:04:36,429 --> 00:04:37,719 with Jennifer Garner and. 88 00:04:38,739 --> 00:04:42,849 Okay, there's an episode in there when they were having a cyber 89 00:04:42,849 --> 00:04:45,739 attack and the, what's his name? 90 00:04:45,789 --> 00:04:48,949 Marshall Flank man comes running into the data center and he just literally 91 00:04:48,954 --> 00:04:51,109 starts flipping, flipping power switches. 92 00:04:51,109 --> 00:04:53,949 He's they're downloading all the files off the server and he down. 93 00:04:53,954 --> 00:04:55,749 He just flips all the power switches off. 94 00:04:57,199 --> 00:04:59,089 on one end there is the 95 00:05:01,384 --> 00:05:05,779 like networking, shutdown, like literally both internal and external, right? 96 00:05:05,809 --> 00:05:08,824 because, once the ransomware is inside, it's gonna try to crawl 97 00:05:08,824 --> 00:05:10,234 around and make things worse. 98 00:05:10,414 --> 00:05:11,644 So that's one way. 99 00:05:11,914 --> 00:05:16,644 And then there are, and then there's the, those that go, I'm just going to turn 100 00:05:16,644 --> 00:05:22,494 it off, I'm gonna unplug the cable at the one server or the three servers that 101 00:05:22,494 --> 00:05:26,004 appear to be infected and I'm not gonna worry about the rest of the network. 102 00:05:26,754 --> 00:05:31,944 And somewhere in the, between those two extremes is what everybody else does. 103 00:05:32,454 --> 00:05:35,544 And maybe we should also talk about basics of networking before we jump 104 00:05:35,544 --> 00:05:37,704 into this to talk about the detail. 105 00:05:37,914 --> 00:05:38,634 Because just 106 00:05:39,314 --> 00:05:39,784 Go ahead. 107 00:05:39,864 --> 00:05:40,074 I, 108 00:05:40,224 --> 00:05:40,854 Prasanna, 109 00:05:40,869 --> 00:05:41,289 no, I, 110 00:05:41,309 --> 00:05:42,519 you think we should be talking about first? 111 00:05:42,939 --> 00:05:46,259 no, I think it's because what you just mentioned, Curtis, like everyone 112 00:05:46,259 --> 00:05:49,469 might think, oh, all computers are plugged into the same network. 113 00:05:49,469 --> 00:05:53,099 I think it's important to talk about some of the best practices from networking, 114 00:05:53,099 --> 00:05:57,479 Tom, if you could, about sort of network isolation, BLANs, other things like that. 115 00:05:57,689 --> 00:05:59,759 Before we get into sort of the other side of things, 116 00:05:59,879 --> 00:06:05,759 Yeah, so please explain all networking technology, period before 117 00:06:05,764 --> 00:06:06,419 we get started. 118 00:06:07,329 --> 00:06:09,164 , you've already talked a little bit about it because it's just 119 00:06:09,164 --> 00:06:12,464 a series of tubes, pipes, if you will, that we send things through. 120 00:06:13,054 --> 00:06:16,204 now the important thing to realize when you're trying to think about how 121 00:06:16,209 --> 00:06:20,984 ransomware propagates through a network is to realize that, the way that networks 122 00:06:20,989 --> 00:06:24,019 have traditionally been built is we have this perimeter on the outside, it's 123 00:06:24,024 --> 00:06:28,459 probably bounded by and a bunch of other stuff, and it looks really imposing on the 124 00:06:28,459 --> 00:06:31,819 castle walls, but inside of the network, it's a whole lot easier to get around. 125 00:06:31,879 --> 00:06:35,119 And that's just due to the nature of the way that networks operate. 126 00:06:35,169 --> 00:06:38,289 ethernet is effectively like trying to shout out somebody's order 127 00:06:38,289 --> 00:06:41,229 number at a fast food restaurant and hoping that you get the right one. 128 00:06:41,349 --> 00:06:43,899 Everybody's gonna hear the message, but if it's not meant for you, 129 00:06:43,959 --> 00:06:45,039 we're just gonna ignore it. 130 00:06:45,429 --> 00:06:49,329 But the problem is that allows you to propagate a lot of information very 131 00:06:49,329 --> 00:06:53,349 quickly, and that's what ransomware is trying to take, advantage of whenever 132 00:06:53,354 --> 00:06:56,829 it's trying to, do almost reconnaissance lateral movement in the network. 133 00:06:56,829 --> 00:07:01,269 So I'm looking for a whole bunch of, , potentially vulnerable servers going 134 00:07:01,269 --> 00:07:04,259 all the way back, to the beginning of my professional IT career, I was 135 00:07:04,619 --> 00:07:08,009 actually working on a help desk, when the S SQL slammer worm came out. 136 00:07:08,309 --> 00:07:11,279 And boy, you'd be surprised how many people had that port open to the 137 00:07:11,279 --> 00:07:13,239 internet, because everything shut down. 138 00:07:13,539 --> 00:07:14,859 And it was really weird to see that. 139 00:07:14,859 --> 00:07:17,894 And you're like, at the time I'm freshly minted in my career. 140 00:07:17,894 --> 00:07:19,434 And I'm like, how could that happen? 141 00:07:19,434 --> 00:07:22,254 and now all these years later, I look at it and go, oh my God, 142 00:07:22,254 --> 00:07:24,894 these people were stupid because you're not supposed to do that. 143 00:07:25,494 --> 00:07:28,984 But that's one of the things that people want to take advantage of because the 144 00:07:28,989 --> 00:07:30,664 systems want to talk to each other. 145 00:07:30,664 --> 00:07:32,704 They want to be able to exchange information. 146 00:07:33,004 --> 00:07:34,594 That's the purpose of a network. 147 00:07:34,859 --> 00:07:35,419 Right. 148 00:07:35,464 --> 00:07:39,224 to do extra work to prevent them from talking to each other. 149 00:07:39,994 --> 00:07:40,384 Right. 150 00:07:40,384 --> 00:07:40,514 Yeah. 151 00:07:40,534 --> 00:07:45,389 I think that's, I, and the number of times I went in and out of data centers, over 152 00:07:45,389 --> 00:07:53,589 the years, I remember only one, where they had very solid firewalls, basically. 153 00:07:53,594 --> 00:07:57,309 That, that it was very difficult to do, to traverse laterally 154 00:07:57,309 --> 00:07:58,659 within the organization. 155 00:07:59,049 --> 00:08:03,179 And that was actually Intuit, and it's because of what they felt they had. 156 00:08:03,179 --> 00:08:07,529 They had all of this very sensitive personal data, thanks to their, 157 00:08:07,689 --> 00:08:10,444 they had QuickBooks, they have TurboTax, they have all of that stuff. 158 00:08:10,834 --> 00:08:15,214 And so they had to basically firewall off systems between each other to 159 00:08:15,214 --> 00:08:19,564 prevent that lateral movement that you're right by design in most networks, 160 00:08:19,894 --> 00:08:24,084 you buy a switch, you buy, a bunch of switches, you plug everything in. 161 00:08:24,579 --> 00:08:27,249 And everything talk, everything can talk to everything. 162 00:08:27,789 --> 00:08:35,049 and unless you do something to prevent it, lot of those ports that you talked 163 00:08:35,049 --> 00:08:39,829 about, just like the SQL, issue, a lot of those ports are visible to the internet. 164 00:08:39,859 --> 00:08:43,264 I think a, another one would be a vCenter Right. 165 00:08:43,264 --> 00:08:47,434 And Hyper V, the, that, those ports being visible to the internet, I suppose 166 00:08:47,434 --> 00:08:48,754 you hear about that a lot as well. 167 00:08:49,489 --> 00:08:49,939 Yeah. 168 00:08:49,939 --> 00:08:50,629 I usually do. 169 00:08:50,969 --> 00:08:53,239 Whenever there's some kind of, a vulnerability that comes out and 170 00:08:53,539 --> 00:08:55,578 everyone's I hope you don't have these exposed to the internet, and 171 00:08:55,578 --> 00:08:58,578 you can literally hear the scrabbling as people run into their keyboards 172 00:08:58,578 --> 00:08:59,958 to figure out if that's the case. 173 00:09:00,348 --> 00:09:00,648 But, 174 00:09:00,698 --> 00:09:03,588 as Prasanna mentioned, we have ways to like segment 175 00:09:03,588 --> 00:09:04,938 networks away from each other. 176 00:09:05,118 --> 00:09:08,678 And it's funny that you bring up that, that Intuit had a rigorous internal 177 00:09:08,683 --> 00:09:12,648 firewall structure because in my experience, companies or organizations 178 00:09:12,648 --> 00:09:14,543 that are very, heavily regulat. 179 00:09:14,903 --> 00:09:17,933 Have much more strict structure. 180 00:09:18,233 --> 00:09:22,193 And the reason for that is because they need the ability to say 181 00:09:22,193 --> 00:09:26,453 for a fact, Curtis cannot see anything on this network because he 182 00:09:26,458 --> 00:09:27,923 hasn't been authorized to see it. 183 00:09:28,283 --> 00:09:31,043 Now, you can do that through software constructs. 184 00:09:31,043 --> 00:09:35,143 VLANs, virtual local area networks are the most common way to do it, where we 185 00:09:35,173 --> 00:09:39,733 effectively divide some, partition on the switch and we say, this port belongs 186 00:09:39,733 --> 00:09:43,543 to this vlan, so it can only talk to other ports that are on that vlan. 187 00:09:43,883 --> 00:09:46,373 but that's not even good enough for some organizations. 188 00:09:46,373 --> 00:09:50,158 and the one that everybody always thinks of is Mission Impossible, the Tom Cruise 189 00:09:50,158 --> 00:09:54,338 movie with the machine that's in a vault that's not connected to anything else. 190 00:09:54,488 --> 00:09:56,438 We would call that an air gap system. 191 00:09:56,438 --> 00:10:01,058 Or you can have an air gap network a lot of times things like, HVAC or 192 00:10:01,058 --> 00:10:03,848 management systems are air gap from the rest of the network because they 193 00:10:03,848 --> 00:10:07,568 have different controls and different needs, but I also don't trust those 194 00:10:07,568 --> 00:10:09,968 people to, secure their stuff. 195 00:10:09,968 --> 00:10:13,868 So I'm gonna build a wall in front of that air gap or just completely 196 00:10:13,868 --> 00:10:17,868 isolate it, itself so that I don't have to worry about securing it. 197 00:10:18,078 --> 00:10:23,098 And if, you say hvac, you say things like, environmental control systems 198 00:10:23,398 --> 00:10:26,488 and any security people listening to this podcast are immediately 199 00:10:26,493 --> 00:10:29,368 thinking, man, those are back doors that I can use to get into the system. 200 00:10:29,638 --> 00:10:32,398 Because no matter what, they're still gonna have to be connected 201 00:10:32,398 --> 00:10:34,078 to the network somehow. 202 00:10:34,078 --> 00:10:38,273 And that just increases your, your threat profile. 203 00:10:41,408 --> 00:10:45,338 Yeah, it's interesting because I think most people who think 204 00:10:45,338 --> 00:10:46,358 about home networks, right? 205 00:10:46,418 --> 00:10:48,728 Everything's typically flat in a home, right? 206 00:10:48,728 --> 00:10:51,788 Everything can talk to everything, every single iot device out there, right? 207 00:10:51,793 --> 00:10:55,568 And they're not always thinking about, Hey, I got this smart light bulb. 208 00:10:55,568 --> 00:10:56,288 Isn't it great? 209 00:10:56,288 --> 00:10:57,128 Isn't it awesome? 210 00:10:57,128 --> 00:11:01,718 And then realizing that's on my network, everything is now exposed and could 211 00:11:01,718 --> 00:11:05,588 be potentially exposed if there's a security issue with that single device, 212 00:11:06,608 --> 00:11:10,238 Yeah, Those devices are, they obviously have an IP address, they 213 00:11:10,238 --> 00:11:12,128 have some kind of a control system. 214 00:11:12,368 --> 00:11:15,668 You would hope that most of them have some kind of a security function that 215 00:11:15,668 --> 00:11:19,498 allows them to securely communicate back to whatever controls them. 216 00:11:19,858 --> 00:11:24,718 But multiply that by a factor of 10 for all of the devices that could be 217 00:11:24,718 --> 00:11:26,698 on your average enterprise network. 218 00:11:26,968 --> 00:11:30,788 And when you start saying things like, access controls for those 219 00:11:30,788 --> 00:11:36,123 devices, or port security like network engineering and operations folks, they 220 00:11:36,123 --> 00:11:37,713 just start breaking out into hives. 221 00:11:38,418 --> 00:11:42,703 the, just the amount of work that it takes to create that level 222 00:11:42,703 --> 00:11:45,763 of security is its own monster. 223 00:11:45,763 --> 00:11:50,053 anyone who's ever deployed a technology like 8 0 2 0.1 x, which is effectively, 224 00:11:50,353 --> 00:11:55,423 I am only gonna allow authorized devices to be plugged into this port, knows that 225 00:11:55,423 --> 00:11:58,963 there's this whole enrollment process and are you on the authorized users list? 226 00:11:58,963 --> 00:12:01,093 And what happens if you're using a different device today? 227 00:12:01,333 --> 00:12:05,093 And it's just, it's maddening and it drives people to insane to the 228 00:12:05,093 --> 00:12:08,153 point where, and that's the normal people who know what they're doing. 229 00:12:08,333 --> 00:12:11,273 Could you imagine an executive plugging their laptop into a network port one 230 00:12:11,273 --> 00:12:12,353 day and going, this doesn't work. 231 00:12:12,803 --> 00:12:15,473 And you tell 'em, oh, it's doing that on purpose because we 232 00:12:15,473 --> 00:12:16,643 want to keep everything secure. 233 00:12:16,793 --> 00:12:17,753 What do you think is gonna happen? 234 00:12:17,753 --> 00:12:19,703 The executive's probably gonna look at you and go, I don't care. 235 00:12:20,018 --> 00:12:20,738 Turn it off. 236 00:12:20,858 --> 00:12:21,398 Exactly. 237 00:12:22,748 --> 00:12:23,648 . We don't need that. 238 00:12:24,653 --> 00:12:24,953 It's getting 239 00:12:24,953 --> 00:12:25,493 Yeah. 240 00:12:25,803 --> 00:12:26,243 Yeah, 241 00:12:26,333 --> 00:12:26,843 Yeah. 242 00:12:27,093 --> 00:12:32,813 I know that when we had, we had a security person on and they had a list of things 243 00:12:32,818 --> 00:12:38,333 that they wanted people to do that they felt were common sense, that were, ways 244 00:12:38,333 --> 00:12:44,583 to prevent basically, I think the proper thing today when we talk about ransomware 245 00:12:44,583 --> 00:12:49,103 is to just assume something in your world is going to get ransomware, right? 246 00:12:49,103 --> 00:12:53,303 It's just, it is, I think it's just impossible to stop it 100% of the time. 247 00:12:53,303 --> 00:12:54,893 So just assume that's going to happen. 248 00:12:55,103 --> 00:12:57,113 So then there's all about. 249 00:12:57,863 --> 00:13:02,363 How to prevent it from activating itself, from talking to the command and control 250 00:13:02,363 --> 00:13:04,913 servers and also the lateral movement. 251 00:13:04,913 --> 00:13:05,153 So he 252 00:13:05,153 --> 00:13:05,963 reducing the black 253 00:13:05,963 --> 00:13:06,623 raised, 254 00:13:07,283 --> 00:13:07,523 right? 255 00:13:07,523 --> 00:13:08,033 So what's that? 256 00:13:08,483 --> 00:13:09,263 Limiting the blast 257 00:13:09,473 --> 00:13:09,923 radius. 258 00:13:10,433 --> 00:13:13,323 so Tom, what kinds of things besides VLANs? 259 00:13:13,323 --> 00:13:17,113 Because even VLANs, we have the VLAN for this and the VLAN for that. 260 00:13:17,113 --> 00:13:19,843 Still all the servers within that VLAN can talk to each other. 261 00:13:20,293 --> 00:13:25,878 What else can companies do, with modern networking equipment to prevent 262 00:13:26,118 --> 00:13:30,008 lateral movement or to basically prevent it from everything and then, 263 00:13:30,268 --> 00:13:32,308 selectively allow it for certain servers. 264 00:13:33,008 --> 00:13:35,948 the first thing you have to do is you have to realize that a completely flat network. 265 00:13:36,878 --> 00:13:38,228 not a stable network. 266 00:13:38,258 --> 00:13:42,728 there is a limit to the amount of chatter that a network can tolerate 267 00:13:42,728 --> 00:13:44,708 before it starts running into problems. 268 00:13:44,958 --> 00:13:50,183 ethernet is not a, a medium that allows for a large number of hosts because 269 00:13:50,183 --> 00:13:53,083 eventually they're gonna, it, it's like recording a podcast eventually 270 00:13:53,088 --> 00:13:54,793 with too many guests on the podcast. 271 00:13:55,033 --> 00:13:56,713 You're all gonna wanna talk over the top of each other, 272 00:13:56,718 --> 00:13:57,883 and ethernet doesn't like that. 273 00:13:58,213 --> 00:14:00,733 So once you had a certain boundary, you have to divide it 274 00:14:00,733 --> 00:14:02,203 up into these little domains. 275 00:14:02,263 --> 00:14:04,183 collision domains are what we call them, and that's one 276 00:14:04,188 --> 00:14:05,503 of the things that a VLAN is. 277 00:14:05,803 --> 00:14:10,423 But as we've learned over the years about what we really should be doing, 278 00:14:10,423 --> 00:14:12,048 we've built a super set of that. 279 00:14:12,318 --> 00:14:16,338 And anyone out there who has been reading any kind of the tech press recently, or 280 00:14:16,338 --> 00:14:19,248 been to any trade show in the last couple of years, probably heard of something 281 00:14:19,248 --> 00:14:23,008 like Zero Trust Network Architecture or, just Zero Trust in general. 282 00:14:23,008 --> 00:14:23,788 It's a buzzword. 283 00:14:23,938 --> 00:14:27,598 I'm, I'll be the first to admit it, but the principles behind it are fairly sound. 284 00:14:28,303 --> 00:14:32,398 what you do is you take the tools that you've already been given, those ones 285 00:14:32,398 --> 00:14:35,938 that I told you, make your network team break out in hives, and you try to 286 00:14:35,938 --> 00:14:40,528 implement them in such a way as to reduce the complexity of the implementation. 287 00:14:40,918 --> 00:14:45,173 And think about think about a teenager and they want a list of, things that 288 00:14:45,173 --> 00:14:47,123 they can do when they get a car. 289 00:14:47,333 --> 00:14:51,293 Are you gonna tell them you can do anything you want, but 290 00:14:51,293 --> 00:14:53,333 you can't do this and you can't do that and you can't do this? 291 00:14:53,393 --> 00:14:56,273 Or are you gonna be more explicit? 292 00:14:56,393 --> 00:15:01,733 You can only do these things and if it's not on that list, you can't do it. 293 00:15:02,213 --> 00:15:04,733 most people would say, I'm only go, I'm gonna do the second thing 294 00:15:04,733 --> 00:15:07,463 because I want to make sure that they're only going to school and to 295 00:15:07,463 --> 00:15:09,233 work into this one friend's house. 296 00:15:09,623 --> 00:15:11,393 But we don't build networks that way. 297 00:15:11,398 --> 00:15:15,173 we typically allow as much as possible because of the situations 298 00:15:15,173 --> 00:15:18,083 we find ourselves in where something doesn't work right. 299 00:15:18,083 --> 00:15:19,103 And we don't know why. 300 00:15:19,283 --> 00:15:21,993 So we will put a little catchall at the bottom of the access list 301 00:15:21,993 --> 00:15:23,273 and go permit everything else. 302 00:15:24,213 --> 00:15:24,903 and then we leave it. 303 00:15:25,293 --> 00:15:27,243 And that's the worst thing that you can do. 304 00:15:27,573 --> 00:15:30,213 And what Zero Trust Network architectures try to do is they try 305 00:15:30,213 --> 00:15:33,153 to say, okay, that server over there is running our backup software. 306 00:15:33,543 --> 00:15:36,573 What should it, what should communicate with it? 307 00:15:36,753 --> 00:15:40,153 And how should it be communicated with, maybe it only needs to accept 308 00:15:40,158 --> 00:15:41,833 connections on these three or four ports. 309 00:15:41,838 --> 00:15:45,283 Maybe it only accepts connections from these authorized users. 310 00:15:45,343 --> 00:15:48,373 And you're effectively creating an isolation for that unit. 311 00:15:48,733 --> 00:15:51,553 And if something needs to access it and you're having problems with it, the 312 00:15:52,043 --> 00:15:55,053 software usually allows you to dig into that a little bit and go, oh, it looks 313 00:15:55,053 --> 00:15:58,473 like that this program did an update and it now needs to communicate over this 314 00:15:58,473 --> 00:16:00,943 port, and I need to allow that port. 315 00:16:01,153 --> 00:16:04,877 But you're doing it in a way that allows you to control that access. 316 00:16:05,267 --> 00:16:09,197 But more importantly, what happens is that when something tries to operate outside 317 00:16:09,197 --> 00:16:14,357 of that access control, slams it shut and hopefully will send you some kind of a 318 00:16:14,357 --> 00:16:18,307 warning, Hey, we just noticed that this server over here is trying to communicate 319 00:16:18,307 --> 00:16:20,947 with the rest of the network on Port 4 45. 320 00:16:21,582 --> 00:16:23,077 know it shouldn't be doing that. 321 00:16:23,287 --> 00:16:24,637 You need to take a look at it. 322 00:16:25,057 --> 00:16:29,557 And so limiting that blast radius, that broadcast capability tends 323 00:16:29,557 --> 00:16:31,857 to prevent lateral movement. 324 00:16:31,862 --> 00:16:36,357 And like you said, people who are going to attack you are going 325 00:16:36,362 --> 00:16:37,887 to be dedicated in doing it. 326 00:16:38,157 --> 00:16:41,337 Either they're gonna be dedicated to looking for a very specific exploit 327 00:16:41,337 --> 00:16:45,237 and just hauling in whatever they can do, or they're gonna be looking to 328 00:16:45,237 --> 00:16:49,977 attack you, you specifically, however they can get to you that second kind 329 00:16:49,977 --> 00:16:52,377 of attacker, very difficult to block. 330 00:16:52,377 --> 00:16:57,057 It's like a door lock, a dedicated burglar is gonna get into your house. 331 00:16:57,327 --> 00:17:00,577 You're looking to prevent more of the first one where it's oh, we were able 332 00:17:00,577 --> 00:17:04,207 to get in through your HVAC system and boy, we're gonna turn this thing loose 333 00:17:04,207 --> 00:17:07,807 and see what open file shares you've got out there and what we can do with them. 334 00:17:08,107 --> 00:17:13,597 You, you need to create in the organization that does not allow 335 00:17:13,602 --> 00:17:16,997 people to move laterally that prevents them from accessing things. 336 00:17:16,997 --> 00:17:22,457 Or worse yet, alerts you when things start doing a lot of across your 337 00:17:22,457 --> 00:17:25,957 network, looking for those kinds of things because the rest of the group 338 00:17:26,317 --> 00:17:28,597 that's trying to get into your network doesn't know that stuff's there either. 339 00:17:28,597 --> 00:17:32,047 They're gonna have to go looking and just like the burglars that are casing the 340 00:17:32,047 --> 00:17:34,297 joint, you need to look for those people. 341 00:17:34,402 --> 00:17:37,402 So multiple things popped up in my head, Tom, as you were talking. 342 00:17:37,702 --> 00:17:41,122 So the first is, as you're talking about the burglar example, I'm gonna bring this 343 00:17:41,122 --> 00:17:44,812 up again for the second week, but Curtis had recommended reading The Cuckoo's Egg. 344 00:17:44,812 --> 00:17:45,922 I don't know if you've read that book. 345 00:17:45,922 --> 00:17:46,312 Tom. 346 00:17:47,782 --> 00:17:48,962 Highly recommend you read it. 347 00:17:48,982 --> 00:17:54,137 It's basically, 1980s, a hacker gets into a mainframe and starts moving 348 00:17:54,137 --> 00:17:58,187 laterally across all these like military networks and science networks 349 00:17:58,187 --> 00:17:59,687 because everything was connected. 350 00:17:59,717 --> 00:18:00,227 And 351 00:18:00,387 --> 00:18:00,877 Yeah. 352 00:18:00,977 --> 00:18:04,067 you said, that example was go and try all the door locks and he would 353 00:18:04,067 --> 00:18:07,907 try default passwords and some of these systems, like the mainframes, 354 00:18:07,907 --> 00:18:09,417 people would not change the defaults. 355 00:18:09,647 --> 00:18:12,767 And so he got in and it was just that lateral movement across 356 00:18:12,767 --> 00:18:13,697 everything in the environment. 357 00:18:13,697 --> 00:18:17,207 So that's like the first thing that came to mind as you were talking. 358 00:18:17,927 --> 00:18:22,367 the other thing that also came to mind is I totally get the reason to have that 359 00:18:22,367 --> 00:18:27,887 zero trust and only enables services that, and patterns that are known to 360 00:18:27,887 --> 00:18:30,257 be valid and disable everything else. 361 00:18:30,887 --> 00:18:31,847 my question. 362 00:18:32,627 --> 00:18:36,467 As a network engineer or operations person, how do 363 00:18:36,467 --> 00:18:37,937 you manage that at the scale? 364 00:18:37,937 --> 00:18:42,437 Because there's so many applications, so many servers, it's hard to predict what's 365 00:18:42,437 --> 00:18:46,212 going to talk with what, and coming up with, because everything's all connected. 366 00:18:46,217 --> 00:18:48,467 Like in my mind I think about Facebook and graphs, right? 367 00:18:48,467 --> 00:18:50,057 Everything is connected in the world, right? 368 00:18:50,327 --> 00:18:52,707 And so everything in your network to some extent is probably 369 00:18:52,712 --> 00:18:54,197 connected in some form or fashion. 370 00:18:54,227 --> 00:18:59,087 So how do you go about even coming up with, okay, these things are the 371 00:18:59,087 --> 00:19:01,637 things that should be talking to the backup server in your example. 372 00:19:02,657 --> 00:19:06,802 So it takes a lot of teamwork because as a network person, I don't care 373 00:19:06,802 --> 00:19:09,802 what's running over my network, I just need to make sure that these 374 00:19:09,802 --> 00:19:11,422 two things can talk to each other. 375 00:19:11,812 --> 00:19:15,912 And so in a way, like if you've ever deployed a server, you have a list, 376 00:19:15,917 --> 00:19:19,692 okay, it needs to communicate, using this protocol over these ports or, 377 00:19:19,692 --> 00:19:23,552 think about, opening something like, I need to open HTTPS to the server, 378 00:19:24,002 --> 00:19:27,752 but not http because I don't want it to ever communicate over http. 379 00:19:27,872 --> 00:19:31,022 And that's actually one of the things that we've noticed a lot recently is 380 00:19:31,022 --> 00:19:34,532 that a lot of protocols that used to have their own dedicated ports have 381 00:19:34,532 --> 00:19:40,157 now just started writing over, HTTP and https s. Because it's just easier. 382 00:19:40,187 --> 00:19:43,007 bit Torrent was actually one of the first ones to start doing this because 383 00:19:43,007 --> 00:19:46,367 they're like, eighty's gonna be open anyway, which is the port for http. 384 00:19:46,487 --> 00:19:50,277 So we'll just ride on that because most people fire, most people's firewalling 385 00:19:50,282 --> 00:19:53,267 systems just allow that by default, because that's what the web uses. 386 00:19:53,507 --> 00:19:56,772 And so it gets insidious and you almost have to think at a higher level. 387 00:19:56,777 --> 00:19:57,632 So what. 388 00:19:58,347 --> 00:20:01,197 it crack open any networking textbook in the world, and they're gonna 389 00:20:01,197 --> 00:20:03,507 give you this seven layer model. 390 00:20:03,507 --> 00:20:06,507 It's like a seven layer dip from Taco Bell, but there's no refried 391 00:20:06,507 --> 00:20:08,277 beans in the seven layer OSI model. 392 00:20:08,607 --> 00:20:12,507 But we play a lot in the bottom of that, where the physical connections 393 00:20:12,507 --> 00:20:15,717 happen, where the IP addresses allow systems to talk to each other. 394 00:20:16,077 --> 00:20:19,557 Once we get above a certain level, that's where the applications take over. 395 00:20:19,857 --> 00:20:23,787 And as networking people, we're not as concerned about that. 396 00:20:23,967 --> 00:20:27,357 But boy, the server people are because, oh, I need to be able to have these 397 00:20:27,357 --> 00:20:28,467 two devices talking to each other. 398 00:20:28,467 --> 00:20:29,877 I need to make sure this is all un impeded. 399 00:20:29,877 --> 00:20:32,247 And the first thing that happens when two servers can't talk to each other 400 00:20:32,457 --> 00:20:33,682 is you gotta find the network people. 401 00:20:33,682 --> 00:20:35,782 And you're like, you need to tell me what's going on here. 402 00:20:35,782 --> 00:20:38,842 And then invariably, like the security team gets drawn in because oh no, we 403 00:20:38,842 --> 00:20:41,572 told him that he had to block that because nobody should ever be using that. 404 00:20:41,942 --> 00:20:44,492 and you really do have to pull those people together. 405 00:20:44,622 --> 00:20:47,622 think of, think of a book like, gene Kim's Phoenix project. 406 00:20:47,622 --> 00:20:51,252 Like you can't work in isolation anymore. 407 00:20:51,252 --> 00:20:52,572 As much as we might like to. 408 00:20:53,142 --> 00:20:56,862 Because so many things are so inter interdependent now. 409 00:20:57,072 --> 00:20:58,887 It's the old joke is what does the server do? 410 00:20:58,887 --> 00:20:59,397 I don't know. 411 00:20:59,397 --> 00:21:01,917 Unplug the cable and we'll see who screams the loudest. 412 00:21:02,217 --> 00:21:05,077 You wanna figure out what people, what port is being used. 413 00:21:05,227 --> 00:21:07,687 Let's block it and see who comes to yell at us. 414 00:21:08,027 --> 00:21:09,982 that's the way you have to do some of these things. 415 00:21:09,982 --> 00:21:10,282 Cuz 416 00:21:10,462 --> 00:21:13,822 the other thing, and we all know that nobody ever skips documentation, right? 417 00:21:13,822 --> 00:21:15,172 You brought up an old memory of mine. 418 00:21:15,202 --> 00:21:20,722 Literally like my first months in being a cis admin, we were trying to 419 00:21:20,727 --> 00:21:26,637 decommission, the, the first computer to run Unix was the three BK and the 420 00:21:26,637 --> 00:21:31,327 at and t had a three BK I think it was like a three B And it was their 421 00:21:31,327 --> 00:21:33,367 attempt at a multiprocessor architecture. 422 00:21:33,757 --> 00:21:36,247 And we had this beast and we were trying to decommission it. 423 00:21:36,817 --> 00:21:40,257 And, we had gotten down to, we had fi and we had gotten down to 424 00:21:40,257 --> 00:21:43,472 that phase where it's we're just gonna turn it off and whoever yells 425 00:21:43,477 --> 00:21:45,212 will be the one that we missed. 426 00:21:45,262 --> 00:21:49,537 But I remember the, We had, stripped it, all of its regular networking cable. 427 00:21:49,537 --> 00:21:53,587 I don't exactly remember exactly why, but I remember that there was one cable left 428 00:21:53,587 --> 00:22:00,247 and it was running across the floor and we were doing the last like download of was 429 00:22:00,307 --> 00:22:03,127 off of this server onto something else. 430 00:22:03,487 --> 00:22:07,237 And the manager for that cost center was in there and he 431 00:22:07,237 --> 00:22:08,977 kept stepping on the cable. 432 00:22:09,937 --> 00:22:12,877 we told him that he was slowing down the download whenever 433 00:22:12,877 --> 00:22:14,137 he would step on the cable. 434 00:22:15,227 --> 00:22:17,747 we actually caught him, we left him into data center. 435 00:22:17,747 --> 00:22:21,677 We actually caught him like watching the monitor and like the 436 00:22:21,677 --> 00:22:25,637 throughput speed and stepping on and stepping up and off on the cable. 437 00:22:27,232 --> 00:22:27,972 Bad Curtis. 438 00:22:28,397 --> 00:22:28,817 Yeah. 439 00:22:28,897 --> 00:22:29,707 good stories. 440 00:22:29,797 --> 00:22:33,757 I, so question I want to ask you about, all of the things you just 441 00:22:33,757 --> 00:22:40,237 talked about, this something built into modern networking equipment or 442 00:22:40,242 --> 00:22:46,032 is this, are these extra applications that I'm buying that then configure 443 00:22:46,032 --> 00:22:47,592 that networking equipment for me? 444 00:22:48,457 --> 00:22:49,567 So it can be both. 445 00:22:49,617 --> 00:22:55,822 the basics of being able to isolate hosts and configure systems 446 00:22:56,152 --> 00:22:57,352 has been built in for years. 447 00:22:57,352 --> 00:22:59,512 anyone can write an a c L, right? 448 00:22:59,902 --> 00:23:04,162 The thing is that scaling that across a large organization is 449 00:23:04,167 --> 00:23:05,512 where it typically falls down. 450 00:23:05,512 --> 00:23:08,602 Eventually, your security team can't keep up with all the changes. 451 00:23:08,602 --> 00:23:11,662 They throw their hands up in the air and it lies fallow for as long as 452 00:23:11,662 --> 00:23:13,042 it takes for you to get infected. 453 00:23:13,372 --> 00:23:17,272 So the additional tools that are basically being brought to market and 454 00:23:17,272 --> 00:23:19,382 are popular now, organize that system. 455 00:23:19,382 --> 00:23:21,237 They put a shiny. 456 00:23:22,172 --> 00:23:25,542 UI on it, if you will, to go in and say, okay, I want to enable port 457 00:23:25,542 --> 00:23:29,652 security on these ports because back when I started this port security was, 458 00:23:29,657 --> 00:23:31,062 if it isn't being used, shut it off. 459 00:23:31,362 --> 00:23:32,667 Just shut down the port. 460 00:23:32,667 --> 00:23:35,767 And then if somebody plugs into it and it doesn't work, then now we know 461 00:23:35,767 --> 00:23:38,257 we need to enable that port and we need to know who's trying to use it. 462 00:23:38,617 --> 00:23:42,667 But now you have the ability to have somebody plug in a device, whether 463 00:23:42,667 --> 00:23:45,037 it's an IOT system or what have 464 00:23:45,037 --> 00:23:48,097 you, and this, the device will register with the system. 465 00:23:48,097 --> 00:23:49,417 It'll say, Hey, I need access. 466 00:23:49,687 --> 00:23:51,967 And then the system can come back and say, Hey, it looks like somebody 467 00:23:51,967 --> 00:23:53,767 plugged in an S thermostat over here. 468 00:23:54,007 --> 00:23:56,997 that's actually a bad example cause they don't use wires, a laptop 469 00:23:57,027 --> 00:23:59,767 or some other kind of device, you need to go, check it out. 470 00:23:59,767 --> 00:24:05,887 Or you can even set a policy that says, I'm going to allow you for now, I have the 471 00:24:05,892 --> 00:24:08,047 ability to just cut it off if I need to. 472 00:24:08,587 --> 00:24:12,097 Or if it's one of these recognized device classes or something like that. 473 00:24:12,337 --> 00:24:18,292 So for smaller systems, for smaller organizations, if your IT department 474 00:24:18,292 --> 00:24:23,572 isn't already completely overworked, you can't implement some of this by hand. 475 00:24:23,572 --> 00:24:28,072 It's just a matter of if it works really well, that means you're gonna 476 00:24:28,077 --> 00:24:32,542 be spending a lot of time tuning that system to keep working effectively. 477 00:24:32,782 --> 00:24:36,322 And once you get past a certain point, the, the solutions that do 478 00:24:36,322 --> 00:24:40,192 this are reassuringly expensive because they're worth it. 479 00:24:41,047 --> 00:24:43,997 Oh, I understood cuz that they would help you save the labor. 480 00:24:44,087 --> 00:24:47,477 And is there a category of these types of tools that, that a 481 00:24:47,477 --> 00:24:49,067 category name that we give to them? 482 00:24:49,782 --> 00:24:51,072 there's a bunch of different ones. 483 00:24:51,102 --> 00:24:54,442 access management is typically one that honestly, tools like Aruba 484 00:24:54,442 --> 00:24:59,892 ClearPass or Cisco ice, ise, integrated services engine, or integrated security 485 00:24:59,892 --> 00:25:01,122 engine, I forget which one it is. 486 00:25:01,452 --> 00:25:04,132 But they're not identity and access management, although 487 00:25:04,132 --> 00:25:05,102 they can be integrated that. 488 00:25:06,212 --> 00:25:08,792 There are some smaller ones that have these capabilities. 489 00:25:09,002 --> 00:25:12,422 A lot of it is mostly figuring out what you need because there's different, 490 00:25:12,422 --> 00:25:16,322 some systems are configured so that you're controlling access to devices. 491 00:25:16,502 --> 00:25:19,022 I only wanna authorize people to be able to log into this 492 00:25:19,022 --> 00:25:20,312 device and make changes to it. 493 00:25:20,532 --> 00:25:26,742 that's different than I want to change the way that people in my network are 494 00:25:26,802 --> 00:25:32,142 accessing data like that is a different kind of identity and access management. 495 00:25:32,292 --> 00:25:35,202 So you need to do a little bit of investigative work to make sure that 496 00:25:35,202 --> 00:25:37,842 you are, properly using the right tool. 497 00:25:37,842 --> 00:25:40,932 Cause if you spend a lot of money on one that doesn't give you what you want or 498 00:25:40,932 --> 00:25:44,797 does a terrible job of it, then not only are you gonna be upset, but the people 499 00:25:44,797 --> 00:25:47,797 that are or authorizing your budget are not gonna be very happy with you. 500 00:25:48,622 --> 00:25:51,802 Now a lot of these changes, if I think about an enterprise 501 00:25:51,802 --> 00:25:56,482 environment, things are easier to a fair extent to control, right? 502 00:25:56,487 --> 00:25:59,302 If you're looking at servers or virtualization, other things like that. 503 00:25:59,962 --> 00:26:04,862 But then I go to think about other environments like a school, where you 504 00:26:04,862 --> 00:26:06,902 have students coming and going, right? 505 00:26:06,902 --> 00:26:10,472 Or a stadium or a conference center, right? 506 00:26:11,102 --> 00:26:16,712 Does it get significantly more difficult to do what you talked 507 00:26:16,712 --> 00:26:18,032 about, Tom, in those environments? 508 00:26:18,032 --> 00:26:20,402 Or can the same tools apply there as well? 509 00:26:21,162 --> 00:26:22,092 Yes and no. 510 00:26:22,142 --> 00:26:23,277 I'm the typical IT nerd. 511 00:26:23,277 --> 00:26:26,307 The answer is, it depends for whatever question you ask, but I'll tell 512 00:26:26,307 --> 00:26:30,557 you that in some ways, schools and other places where your user base 513 00:26:30,557 --> 00:26:32,417 is not employed directly by you. 514 00:26:33,332 --> 00:26:37,862 have a slightly easier time if you're willing to, a little bit. 515 00:26:38,042 --> 00:26:41,252 So I know that there are a lot of colleges out there that treat their 516 00:26:41,252 --> 00:26:44,222 student dorm networks like the wild west. 517 00:26:44,702 --> 00:26:48,452 We don't care what goes on out there, but we're not gonna keep an eye on it either. 518 00:26:48,722 --> 00:26:49,322 So if 519 00:26:49,322 --> 00:26:52,052 there's a, a piece of ransomware or something that's running rampant through 520 00:26:52,052 --> 00:26:55,322 the system, all we did is tell you that you had to have your antivirus up to 521 00:26:55,322 --> 00:26:56,732 date to be able to join our network. 522 00:26:56,867 --> 00:26:57,357 Yeah. 523 00:26:57,752 --> 00:27:01,402 the stadiums are actually a really interesting, problem too, because not 524 00:27:01,407 --> 00:27:04,172 only do you have a, a group of users that are outside of your control, they're 525 00:27:04,177 --> 00:27:06,702 very transient, in a lot of those places. 526 00:27:06,702 --> 00:27:10,382 Like they, they actually have, wireless networks that are set 527 00:27:10,382 --> 00:27:12,182 up so that, they can only talk. 528 00:27:13,102 --> 00:27:15,917 , like they block all device to device communication, which 529 00:27:15,917 --> 00:27:16,907 is something that you can do. 530 00:27:16,907 --> 00:27:20,467 It's a little bit more complicated, but it effectively treats, the 531 00:27:20,467 --> 00:27:24,662 stadium itself like a demilitarized zone in a, in a security structure. 532 00:27:24,842 --> 00:27:27,167 So for most people that are familiar with it, you've got the outside 533 00:27:27,167 --> 00:27:28,577 internet, which is big and scary. 534 00:27:28,727 --> 00:27:32,247 You've got your inside network, which is soft and you don't want it to get hurt. 535 00:27:32,247 --> 00:27:35,937 And then in the middle you have the dmz, which is basically the moat where 536 00:27:35,942 --> 00:27:38,637 you're like, I'm gonna put everything that I don't care if it gets attacked 537 00:27:38,637 --> 00:27:42,927 out there so that if it breaks, it can't get back into my network. 538 00:27:43,077 --> 00:27:46,227 And but the otherwise, the other thing there is I only allow certain 539 00:27:46,227 --> 00:27:47,637 traffic to come back through. 540 00:27:47,787 --> 00:27:51,627 So if something bad were to happen, can just basically cut it off and 541 00:27:51,627 --> 00:27:52,947 sink it into the moat and I'm done. 542 00:27:54,237 --> 00:27:56,702 Yeah, I think, hotels have a similar model, right? 543 00:27:56,702 --> 00:28:01,342 Where the base, I know having plugged in multiple devices that needed to 544 00:28:01,342 --> 00:28:04,582 talk to each other in hotel networks, they don't like that very much. 545 00:28:04,832 --> 00:28:07,932 and you end up having to bring basically your own router if that's 546 00:28:07,932 --> 00:28:08,922 something that you want to do. 547 00:28:09,582 --> 00:28:14,392 the, so it sounded like, if I understood you correctly, the access management 548 00:28:14,392 --> 00:28:18,742 part is this sort of basic security thing, that there are tools that do 549 00:28:18,742 --> 00:28:24,212 just that, and then there's also this identity access, which is a bigger pain. 550 00:28:24,242 --> 00:28:25,022 I would imagine. 551 00:28:25,022 --> 00:28:29,372 But those that want that, and it sounds like when we put those two together, 552 00:28:29,372 --> 00:28:30,957 that's what we call a SEIM tool, right? 553 00:28:30,957 --> 00:28:33,137 Is identity and access management. 554 00:28:33,377 --> 00:28:36,467 But it sounds like there's just an access management. 555 00:28:37,262 --> 00:28:41,972 That, for those that need just that there, there's smaller and less 556 00:28:41,972 --> 00:28:44,402 expensive than a full SEIM tool. 557 00:28:45,212 --> 00:28:45,542 Yeah. 558 00:28:45,832 --> 00:28:48,202 not inexpensive, but just less expensive. 559 00:28:48,677 --> 00:28:52,132 and it also matters as to what you're spending your resources on, because there 560 00:28:52,132 --> 00:28:53,302 are tools that will do this for free. 561 00:28:54,067 --> 00:28:58,357 But they are not supported at all by anybody other than people on a forum. 562 00:28:58,657 --> 00:29:02,167 And they'll be glad to tell you that you misconfigured something 563 00:29:02,172 --> 00:29:03,367 and go figure it out yourself. 564 00:29:03,667 --> 00:29:04,837 Like we, we've dealt with that. 565 00:29:04,842 --> 00:29:08,257 And I'm not really crapping on the open source community because 566 00:29:08,257 --> 00:29:10,207 they do an amazing job of this. 567 00:29:10,297 --> 00:29:14,617 I'm crapping on the fact that open source communities are not as well supported 568 00:29:14,617 --> 00:29:16,777 as the bigger players in these markets. 569 00:29:16,927 --> 00:29:20,497 And that's the expensive part comes from. 570 00:29:20,707 --> 00:29:23,112 You're not paying for the software, although you are in some ways. 571 00:29:23,292 --> 00:29:27,432 You're paying for somebody to answer the phone when somebody is like breathing 572 00:29:27,437 --> 00:29:31,272 down your neck because something won't work or something won't come online. 573 00:29:31,722 --> 00:29:36,037 And so a and you're also trying to get to that point where not automated 574 00:29:36,042 --> 00:29:39,057 as much as it is as low possible. 575 00:29:39,187 --> 00:29:41,797 Because what you want in situations is people to just 576 00:29:41,797 --> 00:29:43,657 be able to get on the network. 577 00:29:44,092 --> 00:29:44,567 that's the thing. 578 00:29:44,567 --> 00:29:47,837 If you've ever tried to log into a wifi network that has a captive portal 579 00:29:48,047 --> 00:29:50,687 that requires you to accept a whole bunch of licensing agreements and 580 00:29:50,687 --> 00:29:53,567 type your room number in and all the other stuff, you know that it's not 581 00:29:53,567 --> 00:29:57,197 the most frustrating thing, but it's definitely not what you want to hear. 582 00:29:58,247 --> 00:30:01,107 As opposed to oh, this device has already been pre-authorized cuz you logged in 583 00:30:01,107 --> 00:30:02,367 with your active directory username. 584 00:30:02,372 --> 00:30:03,342 we'll just let it on the network. 585 00:30:03,762 --> 00:30:05,292 That's completely frictionless. 586 00:30:05,297 --> 00:30:09,192 But the amount of effort that it takes to make it frictionless is where your time 587 00:30:09,192 --> 00:30:10,992 and resource invests gonna come from. 588 00:30:11,297 --> 00:30:14,807 Tom, I know we started this all out with Curtis asking, how do 589 00:30:14,807 --> 00:30:18,617 you prevent lateral movement in networks right from ransomware? 590 00:30:19,457 --> 00:30:23,777 Just given the fact that ransomware does move laterally in a lot of networks? 591 00:30:23,837 --> 00:30:27,197 Does this mean people are not using these tools or have not 592 00:30:27,197 --> 00:30:28,697 configured the networks correctly? 593 00:30:28,697 --> 00:30:32,237 Because it seems if you did all the things that we just talked about, it 594 00:30:32,237 --> 00:30:36,137 should have prevented a lot of the lateral movement that we see in ransomware today. 595 00:30:36,762 --> 00:30:39,312 Prasanna, I'm gonna tell you something that my dad always tell 596 00:30:39,312 --> 00:30:40,242 me, and you have to understand. 597 00:30:40,242 --> 00:30:41,322 My dad grew up in the country. 598 00:30:41,322 --> 00:30:44,592 If a frog had wings, he wouldn't bump his ass every time he hopped. 599 00:30:46,032 --> 00:30:50,862 yes, if you turn on all of these tools, you will cut down on a lot of this stuff. 600 00:30:50,867 --> 00:30:53,832 But does that mean your network's not working correctly? 601 00:30:54,102 --> 00:30:54,432 No. 602 00:30:54,432 --> 00:30:57,012 It just means that we didn't enable all these extra features that we have 603 00:30:57,012 --> 00:31:03,092 to keep track of because I can get four, four ports on a. and plug four 604 00:31:03,092 --> 00:31:06,242 devices in there and they're gonna work is the best way for them to work. 605 00:31:06,242 --> 00:31:09,782 Absolutely not, but I also don't have to do a whole lot of extra configuration. 606 00:31:10,112 --> 00:31:14,012 A lot of people are looking at this from the perspective of, I need to 607 00:31:14,017 --> 00:31:17,117 make sure that everything is able to communicate with everything else. 608 00:31:17,297 --> 00:31:20,657 They're not looking at it like you, like the example you had earlier, Curtis, when 609 00:31:20,662 --> 00:31:23,687 you log into the hotel wifi and I can't talk to anything else on the hotel wifi. 610 00:31:24,017 --> 00:31:26,867 They're not thinking in a, in an isolation mode. 611 00:31:27,227 --> 00:31:31,837 And we're that ship's turning because a lot of people are now realizing that 612 00:31:31,837 --> 00:31:36,637 traditional idea of having a very stiff, crunchy perimeter with a very soft 613 00:31:36,637 --> 00:31:38,657 internal network doesn't work so well. 614 00:31:39,487 --> 00:31:39,787 Right, 615 00:31:39,907 --> 00:31:43,477 ends up happening is that once people get through the perimeter, they have 616 00:31:43,477 --> 00:31:45,067 free reign to do whatever they want. 617 00:31:45,067 --> 00:31:49,747 You, you do have to build these controls in place to effectively 618 00:31:49,747 --> 00:31:54,127 slow them down or to herd them to places that you want them to go. 619 00:31:54,217 --> 00:31:58,297 And that's what a lot of people have spent time developing and working on. 620 00:31:58,597 --> 00:32:02,197 And there's varying degrees of success to make that work. 621 00:32:03,007 --> 00:32:05,347 It has to shift the mindset though. 622 00:32:05,707 --> 00:32:08,707 application people are just turn on all the ports and I'll turn them off later. 623 00:32:08,712 --> 00:32:11,947 When I tell you which ones I don't need, you won't, because you'll 624 00:32:12,067 --> 00:32:12,457 right. 625 00:32:12,522 --> 00:32:13,237 something else. 626 00:32:13,357 --> 00:32:16,147 It's like developers, they're like, I'm gonna load everything I can possibly 627 00:32:16,147 --> 00:32:19,777 think of in the memory so that I know the library that I need is there. 628 00:32:20,077 --> 00:32:24,647 And then you wonder why your, application is consuming like three terabytes of ram. 629 00:32:24,647 --> 00:32:27,167 It's maybe you need to pa pair back a little bit on that. 630 00:32:28,082 --> 00:32:28,262 Yeah. 631 00:32:28,262 --> 00:32:30,842 So it, it sounds like these tools are there. 632 00:32:31,032 --> 00:32:35,377 I think a lot of people do use them, but you talked about, like in the 633 00:32:35,377 --> 00:32:38,737 very beginning, you said that people's heads are gonna start spinning or 634 00:32:38,737 --> 00:32:43,747 whatever, because there is a lot of work involved in implementing these things. 635 00:32:43,747 --> 00:32:48,427 And the moment you flip that switch from, per, from everything is 636 00:32:48,427 --> 00:32:52,477 permitted to only the things that are permitted or permitted, you're 637 00:32:52,477 --> 00:32:54,587 gonna get 5,000 tickets, right? 638 00:32:54,587 --> 00:32:56,237 I can't do this and I can't do that. 639 00:32:56,237 --> 00:32:57,527 And they see that. 640 00:32:57,932 --> 00:33:00,512 They see that very real worry. 641 00:33:00,762 --> 00:33:04,092 and I think it stops many people from implementing this because they just see 642 00:33:04,092 --> 00:33:08,472 it as the amount of work they're gonna have to do to initially implement it. 643 00:33:08,892 --> 00:33:12,852 they're, and they're not seeing the risk of what's gonna happen when 644 00:33:12,942 --> 00:33:16,122 they get a ransomware infection, and then it just goes crazy. 645 00:33:18,112 --> 00:33:20,422 Most tools that are set up like this. 646 00:33:20,462 --> 00:33:23,852 they have a learning mode where they will, you could put 'em in place and 647 00:33:23,852 --> 00:33:25,652 they just sit there and they watch for at 648 00:33:25,657 --> 00:33:27,222 least the first, week or two. 649 00:33:27,462 --> 00:33:30,642 And they're mapping out all of these application dependencies. 650 00:33:30,802 --> 00:33:34,762 the backup system needs to receive traffic on this port for this 651 00:33:34,762 --> 00:33:36,382 application from this subnet. 652 00:33:36,652 --> 00:33:41,332 And then it allows you to carefully craft that rule so that only devices 653 00:33:41,332 --> 00:33:44,992 from this subnet can talk to that server on these ports and nothing else. 654 00:33:45,292 --> 00:33:48,862 And if you let the tool go long enough, you'll be able to like, suss 655 00:33:48,862 --> 00:33:50,602 out exactly what you need to know. 656 00:33:50,872 --> 00:33:56,422 But yeah, that first day you click the switch to from, allow list to deny 657 00:33:56,632 --> 00:33:59,992 a list is just like you're staring at the ticket queue because you're 658 00:33:59,997 --> 00:34:03,442 like, oh, what happens if I, if this machine hadn't been turned on for a 659 00:34:03,787 --> 00:34:04,267 Yeah. 660 00:34:04,272 --> 00:34:04,627 And this 661 00:34:04,722 --> 00:34:05,212 yeah. 662 00:34:06,032 --> 00:34:06,242 Yeah. 663 00:34:06,242 --> 00:34:10,682 It just, it is, it's maddening because you're always gonna wonder if you didn't 664 00:34:10,712 --> 00:34:15,722 get the right stuff, but like you said, would you rather be worried about one 665 00:34:15,722 --> 00:34:17,522 machine that can't talk to another? 666 00:34:17,672 --> 00:34:21,272 Or would you be worrying about the fact that you're getting a phone call from 667 00:34:21,482 --> 00:34:26,002 the CIO saying, yeah, the database has just got encrypted by this new flavor 668 00:34:26,002 --> 00:34:27,772 of malware that we haven't seen yet. 669 00:34:28,022 --> 00:34:28,772 why did that? 670 00:34:30,077 --> 00:34:30,557 Yeah. 671 00:34:31,247 --> 00:34:33,487 Another thing I want to ask you, I wanna move forward 672 00:34:33,487 --> 00:34:35,377 into the ransomware part here. 673 00:34:35,647 --> 00:34:39,727 Although Prasanna, I'm so glad you basically told us to go backwards. 674 00:34:39,727 --> 00:34:42,452 You always, you're really good at that, you're really good at 675 00:34:42,482 --> 00:34:43,052 I try. 676 00:34:43,812 --> 00:34:47,127 anyway, I wanted, so one of the things, so we talked about 677 00:34:47,127 --> 00:34:48,627 trying to limit lateral movement. 678 00:34:48,657 --> 00:34:52,977 Another thing that was suggested was to not 679 00:34:55,037 --> 00:35:01,697 new either new domains, like domains that just recently were created, or 680 00:35:01,907 --> 00:35:08,477 domains that w got recently active, From a DNS perspective, is that still 681 00:35:08,477 --> 00:35:10,247 fall under the networking purview? 682 00:35:10,307 --> 00:35:11,957 or is that is that another world? 683 00:35:12,492 --> 00:35:16,932 it tend, anything that involves names and not numbers tends to float up towards 684 00:35:16,932 --> 00:35:18,582 the application team or the security 685 00:35:18,597 --> 00:35:18,957 Okay. 686 00:35:19,302 --> 00:35:22,722 and the reason for that is because, like you said, like one of the things 687 00:35:22,792 --> 00:35:26,232 that, that we see a lot in security now is it's this idea that you wanna black 688 00:35:26,232 --> 00:35:28,112 hole things that are relatively new. 689 00:35:28,117 --> 00:35:31,262 Like why is this machine suddenly starting to communicate over a d n 690 00:35:31,262 --> 00:35:32,822 s name that I've never seen before? 691 00:35:33,062 --> 00:35:33,602 But it also 692 00:35:33,602 --> 00:35:37,322 requires that your devices have the intelligence to be able to resolve that 693 00:35:37,562 --> 00:35:42,692 because, application layer firewalls will see, oh, you are trying to access 694 00:35:42,697 --> 00:35:46,382 this service that I don't recognize on a domain that I've never seen before. 695 00:35:46,592 --> 00:35:50,292 Whereas a lower level, almost a packet filtering firewall will say, 696 00:35:50,352 --> 00:35:53,952 oh, that's an IP address connection on this port from here to there. 697 00:35:54,032 --> 00:35:56,252 I don't see a reason why I shouldn't be using that. 698 00:35:56,462 --> 00:35:56,822 Gotcha. 699 00:35:56,822 --> 00:35:59,822 You, have to integrate those two things together because like you said, 700 00:35:59,872 --> 00:36:03,142 something doesn't look right here because why would it be contacting a 701 00:36:03,142 --> 00:36:08,092 brand new DNS name that it should, it has no reason to contact or worse yet? 702 00:36:08,282 --> 00:36:09,692 You can ask the people over at SolarWinds. 703 00:36:09,692 --> 00:36:12,932 Why is this DLL suddenly talking to .ru addresses? 704 00:36:13,622 --> 00:36:14,072 right? 705 00:36:14,072 --> 00:36:14,342 Yeah. 706 00:36:14,392 --> 00:36:18,772 when he says new domain names, he actually means domain names that were 707 00:36:18,772 --> 00:36:23,452 like recently registered, not just domain names that are new to your network. 708 00:36:23,752 --> 00:36:27,297 And then also ones that, that were, they were registered but they hadn't 709 00:36:27,417 --> 00:36:29,247 been active or something like that. 710 00:36:29,397 --> 00:36:33,627 So that sounds like that's a d n s there's a d I world, right? 711 00:36:33,677 --> 00:36:34,997 we had somebody on from that. 712 00:36:34,997 --> 00:36:39,077 I think we need to have some, because this is, I think that's, , if you 713 00:36:39,077 --> 00:36:43,517 can reasonably do that, where you could basically push a button, just 714 00:36:43,517 --> 00:36:45,467 like the deny the allowed deny thing. 715 00:36:45,737 --> 00:36:51,737 If you can reasonably say, I, I don't want, want anybody talking to domain 716 00:36:51,737 --> 00:36:54,077 names that were registered 24 hours ago. 717 00:36:54,147 --> 00:36:57,407 I if you could do something like that, it will of course also 718 00:36:57,407 --> 00:36:59,007 create some trouble, tickets. 719 00:36:59,337 --> 00:37:00,657 But I'm thinking far less. 720 00:37:00,657 --> 00:37:04,957 And if you could do that, it stops to command and control, the ransomware from 721 00:37:04,957 --> 00:37:06,517 reaching out at command and control, 722 00:37:07,102 --> 00:37:07,912 the 723 00:37:07,962 --> 00:37:08,197 down. 724 00:37:08,197 --> 00:37:11,047 But the one thing I will say there though, is that you need to make sure 725 00:37:11,047 --> 00:37:12,907 that your users are expecting that change. 726 00:37:12,912 --> 00:37:17,207 Because if it requires you to go out and check a list or, get some kind of 727 00:37:17,457 --> 00:37:21,047 una authorization to go to this domain name, even if it adds one second to the 728 00:37:21,047 --> 00:37:25,517 resolution time, that's one extra second that people are going to complain about 729 00:37:25,517 --> 00:37:26,777 and you know who they're gonna complain. 730 00:37:27,192 --> 00:37:27,802 mm-hmm. 731 00:37:28,037 --> 00:37:29,882 team, because the network isn't working. 732 00:37:30,122 --> 00:37:35,342 Not the d n s block list checker or the application that has this built into it. 733 00:37:35,372 --> 00:37:35,762 Oh, no. 734 00:37:35,762 --> 00:37:37,592 It's the network's fault because the packets aren't 735 00:37:37,592 --> 00:37:38,552 going where they're supposed to. 736 00:37:39,497 --> 00:37:43,087 we used to say back when I was, when I first said that we would 737 00:37:43,087 --> 00:37:44,617 say the problem's under the floor. 738 00:37:44,987 --> 00:37:46,757 meaning, meaning it was a networking problem. 739 00:37:47,387 --> 00:37:48,577 go ahead, Prasanna. 740 00:37:49,202 --> 00:37:50,252 So moving on. 741 00:37:50,252 --> 00:37:53,402 So we talked about how to prevent lateral movement, how to detect these, 742 00:37:53,732 --> 00:37:55,902 rogue, servers that are coming up. 743 00:37:57,072 --> 00:38:01,512 One thing I wanted to ask is, so say you do get hit by ransomware, right? 744 00:38:01,542 --> 00:38:02,892 They're able to move laterally. 745 00:38:03,342 --> 00:38:05,952 What happens next from a networking perspective? 746 00:38:06,142 --> 00:38:07,092 I guess two questions. 747 00:38:07,312 --> 00:38:10,942 One is how do you, how would you go about bringing down your network or sort 748 00:38:10,942 --> 00:38:12,952 of isolating what needs to be isolated? 749 00:38:12,952 --> 00:38:15,262 Like how do you actually figure out what's going on in your network? 750 00:38:15,532 --> 00:38:18,012 And then the second question is, okay, now that you've identified that, how do 751 00:38:18,017 --> 00:38:21,642 you slowly recover from those situations? 752 00:38:22,617 --> 00:38:25,617 Incident response is never fun because it's a whole lot of cleanup. 753 00:38:25,707 --> 00:38:29,292 And, and the first thing you have to do is you have to get people out 754 00:38:29,352 --> 00:38:31,812 of your network because there's, there's obviously, there's the 755 00:38:31,812 --> 00:38:33,342 tools that kind of run on their own. 756 00:38:33,642 --> 00:38:36,432 And there are tools that kind of have to be piloted by people. 757 00:38:36,642 --> 00:38:41,592 So you have to create, limits on the system to be able to stop that. 758 00:38:41,592 --> 00:38:45,912 And fingers crossed that you're not in a situation where your entire 759 00:38:45,912 --> 00:38:48,852 network has been taken down by whatever is causing the problem. 760 00:38:48,852 --> 00:38:52,482 Because I've seen that before too, where not only does it try to laterally move to 761 00:38:52,482 --> 00:38:57,072 infect systems, it also throws up enough extra garbage that you are, it's Inca, 762 00:38:57,072 --> 00:38:58,542 you're capable of logging into any of your 763 00:38:58,677 --> 00:38:59,027 Oh, 764 00:38:59,232 --> 00:39:00,102 So we're lesson number one. 765 00:39:00,102 --> 00:39:02,532 Make sure all your management networks are isolated so that you 766 00:39:02,532 --> 00:39:04,212 always have the ability to use those. 767 00:39:04,542 --> 00:39:05,742 But the first thing that I would. 768 00:39:06,702 --> 00:39:09,312 As I would cut off outside access immediately, I would 769 00:39:09,462 --> 00:39:11,142 lock the firewall in place. 770 00:39:11,142 --> 00:39:13,212 you don't have to run through the data center screaming with your 771 00:39:13,212 --> 00:39:16,392 hair on fire and start yanking cables out like the alias episode. 772 00:39:16,602 --> 00:39:19,512 But you need to be able to lock all of those connections down. 773 00:39:19,752 --> 00:39:24,242 And specifically you need to look for ones that, could be like, from 774 00:39:24,272 --> 00:39:27,602 really weird external addresses, or worse yet ones that are coming in. 775 00:39:27,962 --> 00:39:31,562 Once you've blocked that external access in and out, you gotta do it 776 00:39:31,562 --> 00:39:34,862 in both directions because obviously you don't want anything getting out 777 00:39:34,862 --> 00:39:37,412 because the two things that I can think of are command and control traffic. 778 00:39:37,412 --> 00:39:41,622 If some kind of tool that's being, orchestrated or data exfiltration 779 00:39:41,862 --> 00:39:42,172 Yep. 780 00:39:42,172 --> 00:39:44,422 and you're like, oh, I can stop those file transfers. 781 00:39:44,427 --> 00:39:45,592 Yeah, look up oil rig. 782 00:39:45,622 --> 00:39:48,452 It was, it was able to exfiltrate data through DNS queries. 783 00:39:48,972 --> 00:39:50,952 that's the kind of crap you have to worry about. 784 00:39:50,952 --> 00:39:52,452 So you've gotta lock it down. 785 00:39:52,722 --> 00:39:54,672 Then you have to isolate because that's 786 00:39:54,802 --> 00:39:55,222 And 787 00:39:55,302 --> 00:39:55,632 too. 788 00:39:56,092 --> 00:39:56,932 before you move on, 789 00:39:56,992 --> 00:39:57,292 yeah. 790 00:39:57,382 --> 00:39:57,802 you there? 791 00:39:57,932 --> 00:40:00,382 so how do you do that, right? 792 00:40:00,382 --> 00:40:03,292 is this something where you have to create. 793 00:40:04,162 --> 00:40:08,142 A button to press up, because this sounds like a lot of little steps you 794 00:40:08,632 --> 00:40:11,292 probably need to do this manually, or is there something I can do 795 00:40:11,292 --> 00:40:15,222 upfront that says, in the event of a ransomware attack, push this button. 796 00:40:15,702 --> 00:40:16,212 Hey, gum. 797 00:40:16,632 --> 00:40:17,472 Shut up. 798 00:40:17,802 --> 00:40:21,592 Anyway, in the event of a ransomware attack, press this button and it 799 00:40:21,592 --> 00:40:24,082 does the 10 things I need to do. 800 00:40:24,482 --> 00:40:24,992 what do you think 801 00:40:25,417 --> 00:40:28,327 Some of them do have a big red button press here to terminate 802 00:40:28,327 --> 00:40:29,557 all firewall connections. 803 00:40:29,557 --> 00:40:32,102 But most of the time you're gonna have to create like a checklist or have 804 00:40:32,102 --> 00:40:34,592 a system of okay, I'm gonna go into these rules and I'm gonna uncheck these 805 00:40:34,592 --> 00:40:37,412 five boxes and then I'm gonna hit the terminate connections button to make 806 00:40:37,412 --> 00:40:38,942 sure that no new connections can be made. 807 00:40:39,092 --> 00:40:41,192 Also, if you have a rule at the bottom of your firewall list that 808 00:40:41,192 --> 00:40:42,572 says Permit ip, any, take it out 809 00:40:42,572 --> 00:40:44,582 now because it's not doing you any good. 810 00:40:44,982 --> 00:40:48,832 but more importantly, you have to, all kill switches have to be wired. 811 00:40:49,717 --> 00:40:53,297 , such thing as a magical switch that you can just hit, even if it's one that the 812 00:40:53,297 --> 00:40:57,197 provider has given you what it does. 813 00:40:57,227 --> 00:40:59,327 Does it dump the rules completely? 814 00:40:59,537 --> 00:41:02,892 Does it just suspend the rules until you go in and manually add them? 815 00:41:03,372 --> 00:41:06,792 Remember that could also cut off your connection to the firewall, so 816 00:41:06,792 --> 00:41:09,432 you need to have another way to get into it just in case that happens. 817 00:41:09,672 --> 00:41:13,877 Another reason for an isolated management network, but the idea is that you need to 818 00:41:13,877 --> 00:41:18,857 investigate what your options are because God help you if you really do have to 819 00:41:18,857 --> 00:41:23,337 run down to the data center and yank the cables out, and if that is a case and 820 00:41:23,337 --> 00:41:25,327 hey, it's just as valid as anything else. 821 00:41:26,057 --> 00:41:29,297 Can you make sure that you have the right keys, that you know which 822 00:41:29,297 --> 00:41:30,587 firewall you're yanking out of? 823 00:41:30,827 --> 00:41:33,107 Are there any other exits off of your network? 824 00:41:33,107 --> 00:41:35,867 Because that's another problem that you may run into. 825 00:41:36,047 --> 00:41:39,527 What happens if someone has created another exit off of your network, 826 00:41:39,527 --> 00:41:41,447 either accidentally or on purpose? 827 00:41:41,897 --> 00:41:43,727 And what happens then? 828 00:41:43,727 --> 00:41:47,267 Because you know it's just as easy for me to plug something into your network. 829 00:41:47,267 --> 00:41:49,517 And if there's another way off of it, I'm gonna find it. 830 00:41:49,727 --> 00:41:49,967 Yeah. 831 00:41:50,267 --> 00:41:53,597 The one other thing though, I know you talked about, and it totally makes 832 00:41:53,597 --> 00:41:58,757 sense to kill all incoming and outcoming traffic, but just thinking a step forward, 833 00:41:58,762 --> 00:42:02,292 like when you're dealing with incident response, doesn't that also take out like 834 00:42:02,292 --> 00:42:06,612 your chat channels, your slack channels, your video conferencing, everything 835 00:42:06,612 --> 00:42:08,772 else, like what do you do at that point? 836 00:42:08,772 --> 00:42:11,322 Is it just hope you have everyone's cell phone numbers? 837 00:42:12,447 --> 00:42:17,367 you need to have a plan for out of band incident response because y 838 00:42:17,537 --> 00:42:19,277 it's, it's just like any crime scene. 839 00:42:19,397 --> 00:42:22,877 I need to figure out what's been hit and I need to figure out how 840 00:42:22,877 --> 00:42:24,797 much of it is going to spread. 841 00:42:25,067 --> 00:42:27,977 And you're thinking to yourself like, I can't shut my network down 842 00:42:27,977 --> 00:42:31,907 permanently because you know it's gonna cost me X amount of dollars. 843 00:42:32,297 --> 00:42:35,477 Yes, but it's also gonna cost you x plus whatever amount of 844 00:42:35,477 --> 00:42:37,247 dollars when the next system gets 845 00:42:37,382 --> 00:42:38,132 If you don't 846 00:42:38,567 --> 00:42:41,387 a device that no, nobody's patched it in years. 847 00:42:41,707 --> 00:42:42,847 I'm not gonna lie. 848 00:42:43,297 --> 00:42:48,187 Incident response can work over iMessage text threads for a good couple of 849 00:42:48,187 --> 00:42:50,437 hours while you try to figure that out. 850 00:42:50,437 --> 00:42:54,327 Or, buy your incident response team like those little, hotspots or enable the 851 00:42:54,327 --> 00:42:57,717 data plans on their phone so that they can join their laptop there and join a 852 00:42:57,717 --> 00:43:00,357 Slack instance outside of your network. 853 00:43:01,032 --> 00:43:01,392 Yep. 854 00:43:01,497 --> 00:43:04,887 way nothing is working internal to your network. 855 00:43:05,097 --> 00:43:06,597 Because that's the other thing too. 856 00:43:06,837 --> 00:43:09,747 If you, if this is something that's particularly insidious on a window 857 00:43:09,747 --> 00:43:13,197 system and your incident responders are using Windows systems and they 858 00:43:13,197 --> 00:43:15,987 join the network to be able to do incident response and their laptops get 859 00:43:15,992 --> 00:43:20,132 compromised because they join the network again, you're gonna feel really dumb. 860 00:43:20,412 --> 00:43:23,302 It's the professional, when they blew up the bomb squad truck, it's come 861 00:43:23,302 --> 00:43:25,102 on guys, what were you expecting? 862 00:43:26,452 --> 00:43:29,962 You just reminded me of the, there's a series of commercials and there's 863 00:43:29,962 --> 00:43:35,117 one where the commercial is it's like a horror movie and the, there's a 864 00:43:35,122 --> 00:43:38,617 bunch of kid, it's like the, I got the guy with the ax murderers looking 865 00:43:38,617 --> 00:43:41,077 for the group of kids, and they're like, why don't we go hang out? 866 00:43:41,077 --> 00:43:44,167 Why don't we go hide in that shed over there with all the, with all 867 00:43:44,172 --> 00:43:45,817 the, machetes or something like 868 00:43:45,817 --> 00:43:49,452 that, so we talked about blocking external traffic. 869 00:43:49,452 --> 00:43:51,792 What about blocking internal traffic? 870 00:43:51,922 --> 00:43:57,452 basically the lateral traffic, be due to the, we know we have ransomware 871 00:43:57,452 --> 00:43:59,072 and we know it's gonna try to crawl. 872 00:43:59,312 --> 00:44:01,552 What about blocking that, access? 873 00:44:02,242 --> 00:44:05,657 So that's where you hope that your management networks are, isolated 874 00:44:05,662 --> 00:44:10,187 because the first thing I would do going into a router is shut down the route. 875 00:44:10,187 --> 00:44:15,317 Tables prevent, traffic from being passed across network boundaries. 876 00:44:15,537 --> 00:44:19,857 what you're effectively doing in there is you are containing the damage to one area. 877 00:44:20,067 --> 00:44:25,407 Now, yeah, you're gonna take things down, but if you can isolate that network as 878 00:44:25,407 --> 00:44:29,847 the location for wherever the problem is, you can then bring other networks 879 00:44:29,847 --> 00:44:34,767 back online be relatively certain that they're not gonna be infected. 880 00:44:35,247 --> 00:44:38,572 I really hope that you're not using just regular routing, that you have 881 00:44:38,572 --> 00:44:41,482 some kind of a security boundary there, because that makes it a whole lot. 882 00:44:42,307 --> 00:44:44,707 But you've got to think in, in phases. 883 00:44:44,707 --> 00:44:48,327 Obviously, using the kill switch is gonna take everything down, but then you have 884 00:44:48,327 --> 00:44:50,387 to start, can I bring this back online? 885 00:44:50,417 --> 00:44:51,917 Is this going to be infected? 886 00:44:51,947 --> 00:44:53,807 What would I be looking for? 887 00:44:54,337 --> 00:44:58,112 so I actually have a story about this, this happened last year to my children. 888 00:44:58,362 --> 00:45:02,462 one of 'em goes to the public high school here, and I got a rocket text 889 00:45:02,462 --> 00:45:07,382 message from their IT department saying, please turn off all public school 890 00:45:07,382 --> 00:45:10,532 issue devices until further notice. 891 00:45:10,532 --> 00:45:12,902 And I'm like, uhoh, somebody got hit with something fun. 892 00:45:13,172 --> 00:45:15,782 And this was like the last day before Christmas break or something. 893 00:45:15,782 --> 00:45:18,422 So we went in and we turned off my kid's MacBook, right? 894 00:45:18,662 --> 00:45:23,042 So now, immediately I, because I know what the thing was, I don't want anybody to 895 00:45:23,042 --> 00:45:26,762 like phone home and get infected and then infect the parents networks or whatever. 896 00:45:27,062 --> 00:45:27,812 Okay, no problem. 897 00:45:27,812 --> 00:45:28,502 We just shut it off. 898 00:45:28,502 --> 00:45:29,732 But then I'm like, I wonder what it could. 899 00:45:30,612 --> 00:45:33,512 like I, I'm curious and they've, to this day, they've never disclosed what 900 00:45:33,512 --> 00:45:36,962 it was, but you would get an email like the next week, oh, if you're using like 901 00:45:36,962 --> 00:45:40,512 a corporate phone or if you're using a MacBook, you can turn it back on. 902 00:45:40,512 --> 00:45:44,462 that automatically lowers the horizon of, it has to be something that's focused 903 00:45:44,467 --> 00:45:45,962 on Windows or something like that. 904 00:45:46,172 --> 00:45:48,692 So then you start running through your head of what it could possibly be. 905 00:45:48,792 --> 00:45:50,472 an incident response, you have to do the same thing. 906 00:45:50,472 --> 00:45:51,402 What server got hit? 907 00:45:51,462 --> 00:45:53,747 Oh, it was the database server and it was running this version 908 00:45:53,747 --> 00:45:55,177 of, windows or SQL server. 909 00:45:55,387 --> 00:45:55,867 Okay. 910 00:45:55,867 --> 00:45:57,697 Does that mean that Max can get on the network? 911 00:45:57,697 --> 00:45:59,047 Do I want them on the network? 912 00:45:59,377 --> 00:46:01,837 Is it a situation where even though they can't be infected, they could 913 00:46:01,837 --> 00:46:04,057 propagate something to another location? 914 00:46:04,187 --> 00:46:07,517 there's a lot that you have to go into because obviously the executives are 915 00:46:07,517 --> 00:46:08,927 gonna be like, when can we do back up and. 916 00:46:09,832 --> 00:46:13,202 and if you're a publicly traded company, oh God, the stockholders are like outdoors 917 00:46:13,202 --> 00:46:16,352 with pitchforks and torches and they wanna know when they can get their dividends. 918 00:46:16,532 --> 00:46:19,222 And you're like, when I figure out how much of this data got encrypted 919 00:46:19,222 --> 00:46:23,362 or stolen, and you're always gonna be fighting that tension and you can't 920 00:46:23,367 --> 00:46:25,012 just shut everything off forever. 921 00:46:25,282 --> 00:46:28,852 So that's part of incident response is you've got one team working on figuring 922 00:46:28,852 --> 00:46:31,372 out how to stop whatever infected you, but you've got another team figuring 923 00:46:31,372 --> 00:46:33,082 out how to bring things back online. 924 00:46:33,322 --> 00:46:35,452 That's why we call it business continuity now. 925 00:46:35,502 --> 00:46:38,102 It is interesting about the incident response. 926 00:46:38,102 --> 00:46:39,482 How have you seen cases? 927 00:46:39,482 --> 00:46:42,162 Like how do you actually, two questions I have. 928 00:46:42,552 --> 00:46:45,642 How do you figure out like that, this segment, going back to what 929 00:46:45,642 --> 00:46:46,932 you said, you kill all the routes. 930 00:46:47,112 --> 00:46:49,662 How do you figure out that this segment is safe or not? 931 00:46:49,722 --> 00:46:53,142 And then I guess that, yeah, that's actually only one question. 932 00:46:53,737 --> 00:46:56,717 so typically what, and you're effectively, when you create these 933 00:46:56,717 --> 00:47:00,897 boundaries, it's like looking for the hot potato effectively, because 934 00:47:00,902 --> 00:47:04,707 unless you, like in the alias episode, just go click all the switches off. 935 00:47:04,977 --> 00:47:08,367 Those devices can still communicate to each other at layer two. 936 00:47:08,637 --> 00:47:11,482 Now, where you don't wanna have a problem is that it's in the data. 937 00:47:12,472 --> 00:47:16,627 because if you isolate the layer two data center, now you've got a real problem. 938 00:47:16,657 --> 00:47:19,897 Because if those servers, if it's looking for servers, those 939 00:47:19,897 --> 00:47:21,247 servers can still get infected. 940 00:47:21,517 --> 00:47:24,362 That's why it's actually better to have a, a host route or something 941 00:47:24,362 --> 00:47:28,952 like that, or something that, that kind of isolates that per unit thing. 942 00:47:28,957 --> 00:47:32,467 honestly, like a V switch is perfect for this because if it's not bound for that 943 00:47:32,467 --> 00:47:34,507 host, I'm not gonna let it go any further. 944 00:47:34,777 --> 00:47:37,777 But effectively what you have to do is you have to look for chatter 945 00:47:37,777 --> 00:47:39,457 that's still going on in the network. 946 00:47:39,877 --> 00:47:41,917 Like you, I've shut all this down. 947 00:47:42,772 --> 00:47:45,962 I told my users to disable their machines or turn them off or 948 00:47:45,962 --> 00:47:48,302 whatever, what's still trying to talk. 949 00:47:48,752 --> 00:47:51,332 And then you go take that on a case by case basis. 950 00:47:51,662 --> 00:47:54,182 Oh, this device is still sending traffic that it's, but 951 00:47:54,182 --> 00:47:55,352 it's looking for this server. 952 00:47:55,352 --> 00:47:57,997 Okay, I'm, I can shut it off because I know that it's probably safe. 953 00:47:58,267 --> 00:48:01,057 But then you run into something like, oh, this thing is chattering 954 00:48:01,057 --> 00:48:04,417 an awful lot and it's chattering on a way that it shouldn't be chattering. 955 00:48:04,577 --> 00:48:07,427 that's how I've gone and found hosts that have been infected, but not 956 00:48:07,432 --> 00:48:10,907 by ransomware, but by early malware because they just kept hammering the 957 00:48:10,907 --> 00:48:12,737 firewall with these outbound requests. 958 00:48:12,737 --> 00:48:14,297 And I'm like, you shouldn't 959 00:48:14,302 --> 00:48:15,047 be doing that. 960 00:48:15,257 --> 00:48:17,297 So it's almost like a little bit of detective work. 961 00:48:17,327 --> 00:48:21,192 The good news is that even though the network devices are like dumb from 962 00:48:21,192 --> 00:48:25,542 the perspective of I don't care what application is trying to talk, where 963 00:48:25,902 --> 00:48:28,902 they're really good at telling you that things are still generating traffic. 964 00:48:28,907 --> 00:48:32,412 It's oh, this port is still sending a ton of packets bound 965 00:48:32,412 --> 00:48:34,272 for this address on this location. 966 00:48:34,662 --> 00:48:37,182 And so then you're like, oh, I think something might be up here. 967 00:48:37,512 --> 00:48:39,912 Do you ever see cases where people. 968 00:48:40,592 --> 00:48:46,047 , almost do a, create a black hole on the device itself sync the packets there so 969 00:48:46,047 --> 00:48:48,937 it doesn't go out, rather than having to necessarily do it on the switch. 970 00:48:49,377 --> 00:48:52,207 you can, that's actually a really great way to determine what it's 971 00:48:52,207 --> 00:48:55,207 trying to contact is to create like a null route on the system. 972 00:48:55,547 --> 00:48:57,177 going all the way back three or four years. 973 00:48:57,182 --> 00:49:00,567 Like Mark Marcus Hutchins, that's how he actually stopped a major outbreak 974 00:49:00,567 --> 00:49:03,577 of malware, for all the good it did, and he got arrested by the FBI later. 975 00:49:03,727 --> 00:49:05,407 But he basically black hole the dns. 976 00:49:05,727 --> 00:49:06,217 yeah. 977 00:49:06,382 --> 00:49:09,442 He bought the domain black hole it because if that domain name was 978 00:49:09,442 --> 00:49:11,212 active, then it would stop propagating. 979 00:49:11,362 --> 00:49:14,662 And so he figured that out by saying, oh, I wonder where this is 980 00:49:14,662 --> 00:49:15,862 going and I wonder what it's doing. 981 00:49:16,012 --> 00:49:16,852 You can do that. 982 00:49:16,852 --> 00:49:19,492 And it's actually the next step in incident response, which you've isolated 983 00:49:19,492 --> 00:49:22,972 the system, is I wanna see how it behaves and what it's trying to do. 984 00:49:22,972 --> 00:49:25,702 Cuz that could give me a clue as to what I got hit with and 985 00:49:25,702 --> 00:49:26,962 what they could be looking for. 986 00:49:27,142 --> 00:49:29,392 And that gives you, a little bit of opportunity, but that's 987 00:49:29,392 --> 00:49:31,952 a little bit more of an advanced tool that you would want to use. 988 00:49:32,202 --> 00:49:36,127 just because black holding traffic on a device takes a little bit of setup, 989 00:49:36,127 --> 00:49:38,947 especially if you're fighting against people who don't want you to do that. 990 00:49:39,307 --> 00:49:39,547 Yeah. 991 00:49:40,402 --> 00:49:44,542 Yeah, so it sounds a lot of the things that you talked about in the last 992 00:49:44,542 --> 00:49:49,102 couple of minutes, would be a lot easier to do again, if we segmented 993 00:49:49,102 --> 00:49:50,542 the network in the first place, 994 00:49:50,777 --> 00:49:51,387 Mm-hmm. 995 00:49:51,472 --> 00:49:54,022 We put people with Windows laptops on one network. 996 00:49:54,022 --> 00:49:56,722 We put people with Mac laptops on a network, another network. 997 00:49:56,727 --> 00:49:58,147 We put the phones right? 998 00:49:58,337 --> 00:49:59,417 That are doing the wifi. 999 00:49:59,417 --> 00:50:00,857 We put them on another network. 1000 00:50:01,197 --> 00:50:03,297 and we put servers on a different network. 1001 00:50:03,297 --> 00:50:06,117 We put, maybe we put servers of a different type on a different network. 1002 00:50:06,387 --> 00:50:09,987 So that way you could basically say you don't have to tell 1003 00:50:10,257 --> 00:50:12,027 the users to not do anything. 1004 00:50:12,027 --> 00:50:14,712 You can just say shut off the laptop, network. 1005 00:50:14,762 --> 00:50:17,042 and you shut off the laptop network and so on. 1006 00:50:17,202 --> 00:50:20,622 and all the networks that where we don't currently, what we're not looking at. 1007 00:50:20,832 --> 00:50:23,142 And then, okay, who's trying to talk? 1008 00:50:23,142 --> 00:50:24,012 Who's trying to talk? 1009 00:50:24,132 --> 00:50:25,602 Why is this server surfing? 1010 00:50:25,602 --> 00:50:26,052 The web 1011 00:50:26,872 --> 00:50:27,362 Yeah. 1012 00:50:27,522 --> 00:50:28,842 There's nobody over there. 1013 00:50:29,052 --> 00:50:30,942 Why is this server going over report 80? 1014 00:50:31,762 --> 00:50:34,672 a lot of places already have this by default, even if they didn't realize 1015 00:50:34,672 --> 00:50:37,342 they were doing it because you have different classes of devices that 1016 00:50:37,342 --> 00:50:38,482 you wanna treat them differently. 1017 00:50:38,752 --> 00:50:41,642 Like for example, the the server network, we want to have a little 1018 00:50:41,642 --> 00:50:42,722 bit more security in there. 1019 00:50:42,722 --> 00:50:45,452 Maybe a little less host to host East to west traffic kind of thing. 1020 00:50:45,722 --> 00:50:48,812 The wireless network where all the laptops and the devices connect. 1021 00:50:48,812 --> 00:50:51,632 I'm a little less careful about that because I actually have identity 1022 00:50:51,632 --> 00:50:54,212 management in place that validates the users when they try to log in. 1023 00:50:54,422 --> 00:50:57,782 Maybe I have a guest wireless network for my, for people that come into the lobby. 1024 00:50:58,022 --> 00:51:00,872 That one's wide open to the internet outbound only. 1025 00:51:01,022 --> 00:51:03,032 So I don't need to worry about that quite as much. 1026 00:51:03,032 --> 00:51:06,302 And then, like phones and printers and things like that, that have very specific 1027 00:51:06,302 --> 00:51:10,092 things like, I wouldn't enable Bonura in my internal network, but maybe for 1028 00:51:10,092 --> 00:51:13,062 the printer vlan I would, because I want people to be able to find a printer. 1029 00:51:13,917 --> 00:51:14,907 Open up their laptop. 1030 00:51:15,147 --> 00:51:17,607 So they've already created these segments. 1031 00:51:17,787 --> 00:51:20,397 You just have to know where the buttons are to shut them off. 1032 00:51:20,397 --> 00:51:23,397 So maybe the example is I wanna isolate the servers from the rest 1033 00:51:23,397 --> 00:51:26,277 of the network, cuz I think there's something in there, but I can still 1034 00:51:26,277 --> 00:51:27,927 leave the wireless network up. 1035 00:51:27,927 --> 00:51:31,077 Maybe have everybody join the guest access network and force them all out 1036 00:51:31,077 --> 00:51:34,997 to the internet to do, incident response or chat channels or something like that 1037 00:51:35,147 --> 00:51:39,007 where I'm, but I'm creating these bounds so that traffic flows one direction 1038 00:51:39,012 --> 00:51:43,997 only, or it prevents certain things inside of other areas because, there's 1039 00:51:44,002 --> 00:51:48,202 nothing to say like the, the, s IDs that are on printers that are like, set up, 1040 00:51:48,572 --> 00:51:48,867 Yeah, 1041 00:51:48,932 --> 00:51:51,062 up or something like that can't be compromised. 1042 00:51:51,062 --> 00:51:53,042 And then if they can get into your printer network, it's oh 1043 00:51:53,042 --> 00:51:54,182 crap, where can they go from? 1044 00:51:55,747 --> 00:51:56,237 Yeah. 1045 00:51:56,292 --> 00:51:58,972 and Bonjour of course would be the, I don't know how would 1046 00:51:59,032 --> 00:52:00,382 apple file sharing. 1047 00:52:01,747 --> 00:52:05,217 it is, it's almost like an auto configuration announcement, setting where, 1048 00:52:05,247 --> 00:52:07,042 it, and you can thank Steve Jobs for this. 1049 00:52:07,042 --> 00:52:08,272 He's I hate setting up printers. 1050 00:52:08,512 --> 00:52:10,882 And so basically what he did is he set up a system so that the printers 1051 00:52:10,882 --> 00:52:12,082 can announce that they exist. 1052 00:52:12,082 --> 00:52:14,062 And your laptop is constantly listening for these. 1053 00:52:14,302 --> 00:52:17,992 Bonura is another one of those protocols that is extra chatty and you kinda 1054 00:52:17,992 --> 00:52:21,652 wanna put bounds on it so that like you don't have the Apple TV four hallways 1055 00:52:21,652 --> 00:52:25,852 down announcing itself to the people in accounting because one, it's annoying. 1056 00:52:25,857 --> 00:52:28,042 And two, you never know when you're gonna do something you're not supposed to. 1057 00:52:31,002 --> 00:52:31,362 Interesting. 1058 00:52:33,642 --> 00:52:40,132 So yeah, I guess a lot of these are really around setting up 1059 00:52:40,132 --> 00:52:41,812 that initial network properly. 1060 00:52:41,872 --> 00:52:46,222 So then when you do have these issues, you can recover quickly and 1061 00:52:46,372 --> 00:52:48,142 identify and then recover quickly. 1062 00:52:48,332 --> 00:52:52,172 But if you don't have that initial setup done, then you're in for a world of hurt, 1063 00:52:52,322 --> 00:52:53,822 and not just initial setup. 1064 00:52:53,822 --> 00:52:58,442 You actually do have to treat the network like a living, breathing organism. 1065 00:52:58,447 --> 00:53:01,562 I can't think of a single server admin out there that installs, 1066 00:53:01,722 --> 00:53:04,632 windows What are we up now? 1067 00:53:04,662 --> 00:53:08,862 20 20, 20 23 Windows, server X, I don't know, installs it 1068 00:53:08,862 --> 00:53:09,942 and then never patches it. 1069 00:53:10,002 --> 00:53:10,332 Never 1070 00:53:10,472 --> 00:53:10,672 Yeah. 1071 00:53:10,727 --> 00:53:11,142 it again. 1072 00:53:11,172 --> 00:53:14,062 like you people are probably just shaking, even thinking. 1073 00:53:14,817 --> 00:53:17,817 , you cannot configure a network and then just leave it alone. 1074 00:53:18,087 --> 00:53:22,232 You do have to go in and tweak things and move things and change things. 1075 00:53:22,232 --> 00:53:24,822 And, not just when you're trying to fix a broken thing, 1076 00:53:25,167 --> 00:53:25,657 Yeah. 1077 00:53:25,667 --> 00:53:28,242 have to like, okay, is this subnet big enough for the 1078 00:53:28,242 --> 00:53:29,382 number of hosts that are in it? 1079 00:53:29,382 --> 00:53:31,062 Should I create routes over here? 1080 00:53:31,302 --> 00:53:34,422 It looks like there's a lot of extra traffic going on over this direction. 1081 00:53:34,422 --> 00:53:37,242 Maybe I need to disallow that because it looks like it's something 1082 00:53:37,242 --> 00:53:38,262 that shouldn't be happening. 1083 00:53:38,502 --> 00:53:44,262 if you're not pruning back what you are working on then, and that's the 1084 00:53:44,267 --> 00:53:48,092 problem that a lot of the, ransomware writers have figured out, like a lot of 1085 00:53:48,097 --> 00:53:52,202 their secrets, if you wanna call them, that are just inadequate it support. 1086 00:53:52,392 --> 00:53:55,632 we're gonna hope that you had left this on by default and we're gonna 1087 00:53:55,632 --> 00:53:57,732 take advantage of it and use it. 1088 00:53:57,792 --> 00:54:03,312 And if you did, sorry, but if best practices guide out there says, shut 1089 00:54:03,317 --> 00:54:06,492 that off, and you didn't shut it off, are you in that big of a hurry? 1090 00:54:07,887 --> 00:54:10,197 Yeah, we're living in a world where, people don't even 1091 00:54:10,197 --> 00:54:11,537 change their default password. 1092 00:54:11,552 --> 00:54:16,002 listen, here's the thing, Tom, my plumber's here, I, I got a tradesman that 1093 00:54:16,412 --> 00:54:19,002 actually showed up at two o'clock when he said he was gonna be here at two o'clock. 1094 00:54:19,002 --> 00:54:21,552 So I gotta , we gotta shut this baby down. 1095 00:54:22,062 --> 00:54:23,892 Tom, this has been a great conversation. 1096 00:54:24,092 --> 00:54:25,182 so thanks a lot. 1097 00:54:26,127 --> 00:54:26,877 thanks for having me. 1098 00:54:26,877 --> 00:54:30,417 it's been fun to talk about networking with, with some folks that coming at it 1099 00:54:30,417 --> 00:54:33,727 from a slightly different perspective and understanding, what are we trying 1100 00:54:33,727 --> 00:54:36,937 to accomplish with it, and in some cases, what are we trying to disallow? 1101 00:54:37,432 --> 00:54:37,942 Absolutely. 1102 00:54:37,942 --> 00:54:40,612 Thanks again, Prasanna, once again, making me go backwards, 1103 00:54:41,122 --> 00:54:44,992 I, you know me, I try, you take one step back, two steps forward 1104 00:54:44,992 --> 00:54:46,102 or something like that, right? 1105 00:54:46,282 --> 00:54:47,182 something like that. 1106 00:54:47,187 --> 00:54:47,342 I 1107 00:54:47,342 --> 00:54:47,662 like that. 1108 00:54:47,782 --> 00:54:48,262 All right. 1109 00:54:48,472 --> 00:54:49,944 And thanks again to our listeners