1 00:00:00,049 --> 00:00:03,269 Do you know how hard Russian hackers are trying to get your info? 2 00:00:03,399 --> 00:00:07,289 And a good MFA system is often all that stands in their way. 3 00:00:07,929 --> 00:00:11,349 Today, Prasanna, Dr. Mike Saylor, and I dig into multi-factor 4 00:00:11,349 --> 00:00:15,509 authentication and why old school MFA really isn't enough anymore. 5 00:00:16,129 --> 00:00:19,799 We talk about how bad guys steal your session tokens and wear you down 6 00:00:19,799 --> 00:00:25,609 with fake MFA requests, and why even better than MFA is FIDO2 and passkeys. 7 00:00:26,379 --> 00:00:30,509 We cover a Google Workspace attack that ran undetected for over a 8 00:00:30,509 --> 00:00:34,799 year, and hand you some simple steps that you can be doing right now. 9 00:00:35,579 --> 00:00:39,899 If you're still letting important accounts sit there with no MFA, uh, I got a 10 00:00:39,899 --> 00:00:42,050 name for that, and it's not a nice one. 11 00:00:43,099 --> 00:00:46,109 If this is your first time watching or listening to me, I'm W. 12 00:00:46,120 --> 00:00:51,159 Curtis Preston, AKA Mr. Backup, and I've been obsessing over backup recovery, and 13 00:00:51,160 --> 00:00:54,209 now cyber recovery, for over 30 years. 14 00:00:54,589 --> 00:00:56,349 If that's your bag, then I'm your guy. 15 00:00:56,800 --> 00:01:00,229 You're not gonna find anyone that cares about this topic more than me. 16 00:01:00,749 --> 00:01:05,549 Ever since 1993, when a database died and I didn't have any backups. 17 00:01:05,969 --> 00:01:07,440 Uh, that was not a good day. 18 00:01:07,800 --> 00:01:11,259 Now I've written five O'Reilly books, a blog, and a podcast. 19 00:01:11,520 --> 00:01:15,420 Here we turn unappreciated admins into cyber recovery heroes. 20 00:01:15,719 --> 00:01:17,669 This is the Backup Wrap Up 21 00:01:31,899 --> 00:01:34,059 Hi, and welcome to the Backup Wrap Up. 22 00:01:34,059 --> 00:01:39,229 I'm your host W. Curtis Preston, and today I have with me, my two best friends. 23 00:01:39,549 --> 00:01:43,649 First off, let me just talk about the guy that's currently cooking 24 00:01:43,649 --> 00:01:45,799 in his seat, Dr. Mike Saylor. 25 00:01:46,069 --> 00:01:48,659 How… What's the temperature over there today, Mike? 26 00:01:49,981 --> 00:01:52,661 today it's, I think it's close to just over 100. 27 00:01:52,821 --> 00:01:56,221 we're, we're just getting ready and excited for tomorrow's 106 28 00:01:57,804 --> 00:01:57,944 Ouch 29 00:01:58,109 --> 00:02:01,699 just, that's just, and I shared with you, before the call, it's 30 00:02:01,699 --> 00:02:03,999 also really hot here in, Oceanside. 31 00:02:04,219 --> 00:02:07,699 It's 85, which is, for us is just really high. 32 00:02:07,799 --> 00:02:10,339 I've never tried to cook an egg on my head, but tomorrow I might 33 00:02:14,185 --> 00:02:17,095 And speaking of super hot, how's it going, Prasanna? 34 00:02:18,482 --> 00:02:19,862 I'm good, Curtis. 35 00:02:19,882 --> 00:02:23,802 Nice to see you again, Mike, and I hope you are not planning to 36 00:02:23,802 --> 00:02:25,902 go anywhere outside tomorrow. 37 00:02:25,932 --> 00:02:28,622 Just, like, stay indoors all day long 38 00:02:29,359 --> 00:02:30,449 I've gotta drive to Houston. 39 00:02:30,449 --> 00:02:31,579 I'll be on the road all day 40 00:02:32,372 --> 00:02:33,322 At least air conditioning. 41 00:02:33,861 --> 00:02:35,661 Yes, air-conditioned road travel 42 00:02:38,595 --> 00:02:40,275 quick, completely unrelated story of driving to Houston. 43 00:02:40,335 --> 00:02:45,695 I once had a, situation where I had a, I was flying American Airlines 44 00:02:45,705 --> 00:02:48,965 and I was flying in and out of Houston, but via DFW of course, 'cause 45 00:02:48,965 --> 00:02:50,305 that was American Airlines, right? 46 00:02:50,985 --> 00:02:58,395 And I found myself in Dallas and I, tried to get American to say, "Hey, h- how about 47 00:02:58,395 --> 00:03:01,915 I just hop on the second leg, instead of going all the way to, driving all the 48 00:03:01,915 --> 00:03:05,125 way to Houston just to get on a plane just to come right back where I am at?" 49 00:03:05,125 --> 00:03:08,055 And they go, "No, you gotta do it. You gotta do it or otherwise you're gonna pay 50 00:03:08,055 --> 00:03:15,235 $755 or whatever." So I drove to Houston, and one mile south, or one mile shy of the 51 00:03:15,245 --> 00:03:17,405 Houston Airport, I got a speeding ticket 52 00:03:18,686 --> 00:03:19,666 Oh. 53 00:03:19,739 --> 00:03:20,459 the time, 54 00:03:20,571 --> 00:03:23,591 I really thought where this, this was gonna go is that you got off 55 00:03:23,591 --> 00:03:26,511 the plane in Dallas and went, "Wow, this weather sucks." And then you 56 00:03:26,511 --> 00:03:29,421 got to Houston and you went, "Oh, well maybe Dallas wasn't so bad." 57 00:03:32,077 --> 00:03:34,057 Yeah, the, what I remember at the time was the, trooper, I don't know, 58 00:03:34,067 --> 00:03:38,347 the, the, the cop, told me that, at the time Texas and California 59 00:03:38,357 --> 00:03:43,357 didn't, share, computers or whatever. 60 00:03:43,697 --> 00:03:47,917 And so he said, "You need to surrender your driver's license." And I was 61 00:03:47,917 --> 00:03:51,907 like, "I'm going to the plane." I really don't remember the end of that 62 00:03:51,917 --> 00:03:56,327 story, but I remember the cop took my license, and, somehow I got home. 63 00:03:57,557 --> 00:04:00,007 so gotta love Texas. 64 00:04:00,287 --> 00:04:03,937 anyway, and American Airlines for putting me in that position, and 65 00:04:03,937 --> 00:04:05,127 me for speeding, but whatever. 66 00:04:05,157 --> 00:04:05,967 It's not my fault. 67 00:04:06,027 --> 00:04:06,687 Of course not, 68 00:04:07,368 --> 00:04:07,648 Uh-huh. 69 00:04:07,788 --> 00:04:08,228 Uh-huh 70 00:04:09,527 --> 00:04:12,327 speaking of not my fault, we're gonna start, we're gonna talk about, we're 71 00:04:12,327 --> 00:04:15,877 gonna talk about MFA, multi-factor authentication, and, I thought 72 00:04:15,877 --> 00:04:19,327 you'd start, Prasanna, with a story that we covered not that long ago. 73 00:04:19,557 --> 00:04:20,567 do you wanna talk about that? 74 00:04:21,198 --> 00:04:21,598 Yeah. 75 00:04:21,678 --> 00:04:28,728 So this was, I wanna say it was probably a month ago, maybe two months ago, where, 76 00:04:28,828 --> 00:04:33,478 a bad actor was detected and shut down. 77 00:04:33,948 --> 00:04:38,088 But what ended up happening is there was a software package that was used 78 00:04:38,328 --> 00:04:42,718 mainly, I think, in medical and some of, like, the academics instances 79 00:04:42,718 --> 00:04:47,238 called REDCap, and it basically is a database that allows you to do things. 80 00:04:47,498 --> 00:04:52,138 Anyway, what ended up happening is there were vulnerable, vulnerable versions 81 00:04:52,148 --> 00:04:57,808 of that database out there running, and people, bad actors were able to exploit 82 00:04:57,808 --> 00:05:01,508 it and attack the older REDCap instances. 83 00:05:01,808 --> 00:05:06,158 And then what they did is they just kind of waited around and saw people logging 84 00:05:06,158 --> 00:05:11,168 in, and they somehow got credentials for the Google Workspace admin and kind 85 00:05:11,168 --> 00:05:15,548 of then used that to log into Google Workspace as the admin and then set 86 00:05:15,568 --> 00:05:21,208 up forwarding rules to forward pretty much all emails in the company or 87 00:05:21,208 --> 00:05:27,448 in the institution to a random email address, and it was unmonitored, and 88 00:05:27,758 --> 00:05:31,818 I think it was running for quite a while before they realized that it was 89 00:05:32,403 --> 00:05:33,233 like over a year. 90 00:05:33,750 --> 00:05:34,080 Yeah 91 00:05:34,613 --> 00:05:35,033 yeah. 92 00:05:35,383 --> 00:05:39,813 so this was a multi- multi-stage, it was a three-stage attack, right? 93 00:05:39,813 --> 00:05:43,743 So the initial identification of the, vulnerable versions, which were 94 00:05:43,743 --> 00:05:47,753 running in parallel with the newer versions, which is just bad, right? 95 00:05:47,893 --> 00:05:51,983 and then, g- the credentials, and then using those credentials to log 96 00:05:51,983 --> 00:05:56,803 into Gmail, and then using that to then do something else, which was 97 00:05:56,833 --> 00:05:58,733 essentially exfiltration, right? 98 00:05:58,883 --> 00:06:01,013 So is that, does that make it a four-stage? 99 00:06:01,343 --> 00:06:03,143 I think that makes it a four-stage attack. 100 00:06:03,383 --> 00:06:05,553 That is very, studious. 101 00:06:05,553 --> 00:06:05,683 would that be the- 102 00:06:06,154 --> 00:06:06,404 Yeah. 103 00:06:06,604 --> 00:06:11,194 Could we also talk about the fact that they also made it such that if someone 104 00:06:11,194 --> 00:06:16,004 tried to upgrade the RedCap instances, it would just redeploy the malware again 105 00:06:16,024 --> 00:06:19,714 and just keep running over and over, and so you could never really fix it? 106 00:06:20,759 --> 00:06:21,519 Good times. 107 00:06:21,569 --> 00:06:23,489 are you impressed, Mike, with that, with that attack? 108 00:06:25,937 --> 00:06:26,307 No. 109 00:06:26,737 --> 00:06:31,267 it's, it's c- common progression of an attack and common creativity. 110 00:06:31,627 --> 00:06:34,217 you know, they were, they were lucky because they found these vulnerable 111 00:06:34,217 --> 00:06:37,037 systems that were out there and, and they were out there intentionally. 112 00:06:37,907 --> 00:06:41,307 They, wanted these older systems out there to ensure usability and 113 00:06:41,307 --> 00:06:45,917 accessibility from, you know, you know, the lowest common denominator. 114 00:06:46,737 --> 00:06:48,647 so yeah, I'm not, not so impressed. 115 00:06:48,797 --> 00:06:54,007 the same, same playbook that most, most bad guys are gonna follow, the, 116 00:06:54,007 --> 00:06:56,137 the, the attack, you know, methodology. 117 00:06:56,777 --> 00:06:59,987 just, they've, they've, they found a vulnerable system 118 00:06:59,987 --> 00:07:00,997 and they took advantage of it 119 00:07:01,600 --> 00:07:04,400 It's like going in and finding Windows XP systems out there. 120 00:07:04,430 --> 00:07:07,470 Come on, if you're running Windows XP at this ti- date, right? 121 00:07:08,539 --> 00:07:08,859 Yep. 122 00:07:10,239 --> 00:07:11,689 some of the server versions, yeah 123 00:07:13,543 --> 00:07:14,403 Could be, what was it? 124 00:07:14,563 --> 00:07:17,063 Yeah, Windows XP. 125 00:07:17,063 --> 00:07:19,513 But, that, that's really old, Windows XP. 126 00:07:19,933 --> 00:07:23,683 Meantime, the compromise is less than 10 minutes if you plug it into the internet 127 00:07:24,503 --> 00:07:28,333 I remember when, when, the, one of the most commonly exploited versions of 128 00:07:28,333 --> 00:07:30,463 Windows Server was Windows Server 2000. 129 00:07:30,463 --> 00:07:36,933 And, and I remember that we discovered this in 2013, and I remember saying 130 00:07:37,203 --> 00:07:38,923 that it's a teenager at this point. 131 00:07:38,933 --> 00:07:40,253 It's time for it to move out. 132 00:07:43,153 --> 00:07:43,773 but, all right. 133 00:07:43,773 --> 00:07:47,033 So old version's bad, but, let's talk about, Mike, 134 00:07:47,308 --> 00:07:48,598 What does this have to do with MFA? 135 00:07:49,693 --> 00:07:50,723 we're getting to the MFA. 136 00:07:51,023 --> 00:07:55,363 So Mike, let's talk about, first why MFA is so important, right? 137 00:07:56,513 --> 00:07:57,453 this is another story. 138 00:07:57,453 --> 00:08:01,553 That story is if they simply had implemented MFA for their 139 00:08:01,553 --> 00:08:05,973 Gmail instance, which by the way, I believe Gmail now requires. 140 00:08:06,482 --> 00:08:07,412 Google Workspace 141 00:08:07,843 --> 00:08:10,803 Google Workspace, requires MFA now, right? 142 00:08:11,163 --> 00:08:15,573 I am… Every time I've set up, even if you don't do like the full MFA, 143 00:08:15,833 --> 00:08:19,903 it's gonna require, you to v- verify who you are, all over the place. 144 00:08:20,153 --> 00:08:24,633 But let's, Mike, I'd like to talk about the concept of social 145 00:08:24,633 --> 00:08:30,223 engineering, which is a very common way that, the, the bad guys are using 146 00:08:30,253 --> 00:08:34,003 phishing, to get, to get credentials. 147 00:08:34,013 --> 00:08:35,423 So you want, you wanna talk about that? 148 00:08:35,433 --> 00:08:36,523 What, what did we talk about that? 149 00:08:37,693 --> 00:08:38,743 There's a lot of different ways. 150 00:08:38,753 --> 00:08:42,483 So it's just, it's understanding your, your victim. 151 00:08:42,923 --> 00:08:44,623 so doing your homework. 152 00:08:44,643 --> 00:08:48,873 So, if you're gonna attack a particular organization or group or system 153 00:08:48,873 --> 00:08:52,193 or you're gonna go research them. 154 00:08:52,243 --> 00:08:53,123 what are their hobbies? 155 00:08:53,133 --> 00:08:55,543 What, what does their social media footprint look like? 156 00:08:55,543 --> 00:08:56,773 What does their credit look like? 157 00:08:56,773 --> 00:08:58,353 What is, what kind of car do they drive? 158 00:08:58,353 --> 00:08:59,713 Where do their kids go to school? 159 00:09:00,343 --> 00:09:03,803 you're gonna find something out of all your research that 160 00:09:03,863 --> 00:09:07,663 is common human interaction. 161 00:09:08,273 --> 00:09:13,043 like, "Hey, my kid goes to school with your kid, and they gave me your email to 162 00:09:13,043 --> 00:09:18,463 see if they could have a play date," or, "Timmy left his lunchbox," or something. 163 00:09:18,473 --> 00:09:22,423 You know, that's, that's kind of, no, no pun intended, but elementary, but 164 00:09:22,423 --> 00:09:26,633 that's, that's how you get people's first response, and that's really what you're 165 00:09:26,633 --> 00:09:28,453 looking for, is that first response. 166 00:09:28,923 --> 00:09:32,533 And in some cases, your social engineering, attack, y- you're 167 00:09:32,533 --> 00:09:36,833 only, you only get one response, so sometimes you gotta be pretty good. 168 00:09:37,413 --> 00:09:41,143 But at the same time, you know, statistically speaking, if your, 169 00:09:42,013 --> 00:09:45,443 your target audience is large enough, statistically you've got 170 00:09:45,443 --> 00:09:49,163 about a 20% or better success rate. 171 00:09:49,443 --> 00:09:55,373 So if I send out a million email… Well, if I send out 10,000 emails, you know, 172 00:09:55,553 --> 00:09:58,603 20% of 10,000 is still a good number. 173 00:09:59,013 --> 00:10:00,543 I just need one, right? 174 00:10:00,563 --> 00:10:04,613 In an organization, I just need one person to click on something that's gonna either 175 00:10:04,793 --> 00:10:10,223 give me, harvest their credentials, or they are going to willingly give it to me. 176 00:10:10,463 --> 00:10:14,113 Like, "Curtis, this is Mike from the IT department. 177 00:10:14,213 --> 00:10:16,913 we have a new help desk, i- interface. 178 00:10:17,193 --> 00:10:21,483 below is the link to automatically submit tickets or, or check on the 179 00:10:21,493 --> 00:10:24,123 status of a, of, of a, of a help call. 180 00:10:24,383 --> 00:10:25,993 here's our new 800 number. 181 00:10:26,393 --> 00:10:27,233 it's gonna be great. 182 00:10:27,233 --> 00:10:32,073 We're looking forward to improving service and, and solving your problems faster." 183 00:10:32,458 --> 00:10:34,188 Mike, don't give people ideas, Mike 184 00:10:34,813 --> 00:10:37,393 this is the old- this is one of the oldest ones, the help desk one. 185 00:10:37,893 --> 00:10:42,793 But, you know, click here or, open this attachment to, to, for your 186 00:10:42,803 --> 00:10:48,743 chance at winning one of 20 Starbucks gift cards for being the first one to 187 00:10:49,413 --> 00:10:53,183 write a review on the IT department service, you know, level of service. 188 00:10:53,873 --> 00:10:54,713 and you do. 189 00:10:55,013 --> 00:10:58,663 And so, you know, maybe I've got a… Next, next thing that happens 190 00:10:58,663 --> 00:11:01,393 is I've gotta enter my email address and log into the network. 191 00:11:01,443 --> 00:11:04,993 Like, "Please verify your credentials so we know it's you and not, not your 192 00:11:04,993 --> 00:11:09,683 kids or your neighbor." So it's, you know, email phishing is getting a user 193 00:11:09,683 --> 00:11:14,293 to interact with the email in order to either automatically harvest or, prompt 194 00:11:14,303 --> 00:11:19,663 them to provide, credentials because it looks legitimate or, or it appeals to 195 00:11:19,663 --> 00:11:26,023 their humanity or, you know, I want my kid's lunchbox back or whatever it is 196 00:11:27,083 --> 00:11:31,323 I remember one time, and, to this day I don't know if this was a successful 197 00:11:31,333 --> 00:11:36,243 phishing attack or if this was a successful test of my ability to, or 198 00:11:36,263 --> 00:11:38,253 inability to recognize a phishing attack. 199 00:11:38,693 --> 00:11:43,173 When I worked at a former employer, they, they had some sort of incident 200 00:11:43,183 --> 00:11:47,413 where we were given free, we were gonna get free credit monitoring for a while. 201 00:11:47,873 --> 00:11:53,273 And right at that moment is when I got a, a contact from, "Hey, we're gonna, 202 00:11:53,323 --> 00:11:54,873 sign up for your free credit monitoring. 203 00:11:54,873 --> 00:11:55,873 All we need is what? 204 00:11:56,403 --> 00:12:00,043 Your name, your birth date and your Social Security number." And I found 205 00:12:00,043 --> 00:12:02,843 out that it was not, the company indeed that was contacting me. 206 00:12:02,843 --> 00:12:07,603 But it was s- it was so expertly timed that I fell for it. 207 00:12:07,633 --> 00:12:11,443 And to this day, I don't know if, I gave all my, the three pieces of 208 00:12:11,443 --> 00:12:16,773 information that they want all in one go, or if it was just, them testing, 209 00:12:16,823 --> 00:12:19,918 You… But here's a, here's a question for you, Curtis, and also Mike. 210 00:12:21,198 --> 00:12:24,188 At this point, don't you just assume everyone has it out there? 211 00:12:24,188 --> 00:12:26,178 Like, that information's just out there anyway? 212 00:12:26,779 --> 00:12:30,189 Yeah, I kind of joke that I, I, I protect myself from identity 213 00:12:30,189 --> 00:12:31,959 theft by maintaining bad credit. 214 00:12:32,019 --> 00:12:35,069 I mean, you're- you've got access to my stuff, you just don't wanna use it 215 00:12:37,213 --> 00:12:37,823 I like that. 216 00:12:37,883 --> 00:12:41,983 by the way, it's technically not on topic, but I have all my 217 00:12:41,983 --> 00:12:43,533 credit reports locked, right? 218 00:12:43,573 --> 00:12:47,583 And that, I think that's a life, thing that everybody else should have, is 219 00:12:47,583 --> 00:12:52,023 that, in the rare instances where you're actually opening new credit, you can 220 00:12:52,063 --> 00:12:56,893 unlock it for 24 hours, do the thing, and, in fact, most of them allow you, 221 00:12:57,013 --> 00:13:01,503 actually can just y- one of the choices is unlock for 24 hours just for that 222 00:13:01,673 --> 00:13:05,973 situation, and that would at least stop those people, if they get access to that. 223 00:13:06,893 --> 00:13:12,233 Just a note to my US listeners, all three credit reporting agencies 224 00:13:12,263 --> 00:13:17,863 are required by law to allow you to freeze your credit report for free. 225 00:13:18,223 --> 00:13:21,683 So I the, I can't recommend this strongly enough. 226 00:13:21,703 --> 00:13:26,093 It's not technically related to the, um, to this situation, but 227 00:13:26,133 --> 00:13:28,703 it's just something that a lot of people don't realize is there. 228 00:13:28,913 --> 00:13:34,013 You log into Experian, Equifax, and transunion.com you know, get a 229 00:13:34,013 --> 00:13:38,403 login if you don't already have one, log in, and then look for freeze. 230 00:13:38,703 --> 00:13:40,303 You may have to look around for it. 231 00:13:40,323 --> 00:13:42,973 Honestly, some of them really hide it. 232 00:13:43,323 --> 00:13:47,253 But it is there, it's required by law, and then freeze it. 233 00:13:47,603 --> 00:13:50,953 It does mean that when you apply for credit, you will get you will 234 00:13:50,953 --> 00:13:54,183 get initially told, "Hey, you need to go unfreeze your report." 235 00:13:54,503 --> 00:13:58,320 It's a minor inconvenience for the, hopefully, infrequent action of 236 00:13:58,320 --> 00:14:00,560 you actually applying for new credit. 237 00:14:01,030 --> 00:14:04,780 And this is a big identity theft thing that you can do. 238 00:14:05,190 --> 00:14:09,070 I'd love to hear, for those of you are, that are from other countries, I'd 239 00:14:09,070 --> 00:14:12,080 love to hear in the YouTube comments, uh, what you do in your country. 240 00:14:12,490 --> 00:14:15,130 But so you just freeze it and it stays frozen. 241 00:14:15,400 --> 00:14:20,050 And then some of them, and I prefer these, actually allow you to do a temporary 242 00:14:20,190 --> 00:14:22,820 unfreeze, uh, or thaw, if you will. 243 00:14:23,050 --> 00:14:27,500 I actually use the word a lock my c- uh, credit, uh, they actually have a credit 244 00:14:27,510 --> 00:14:29,040 lock, and they will charge you for it. 245 00:14:29,040 --> 00:14:31,190 It does exactly the same thing as a freeze. 246 00:14:31,570 --> 00:14:34,420 And, and by the way, when you're logging into these pages, they all want you to 247 00:14:34,420 --> 00:14:38,400 pay for a membership, but they all, they just immediately throw that in your face. 248 00:14:38,400 --> 00:14:42,310 Just close that out to, These companies are already making enough off of you. 249 00:14:42,320 --> 00:14:44,970 You don't need to, uh, sign up for a membership. 250 00:14:45,000 --> 00:14:47,270 Um, signing up for a credit monitoring service, that's 251 00:14:47,270 --> 00:14:48,310 an entirely different thing. 252 00:14:49,100 --> 00:14:54,160 But anyway, so freeze your credit reports unless you are applying for credit. 253 00:14:54,330 --> 00:14:59,040 And again, I'd love to hear comments from other listeners from other countries 254 00:14:59,040 --> 00:15:02,510 and yeah, I agree, Prasanna, you just assume that all that stuff's out there. 255 00:15:02,800 --> 00:15:06,630 but for the record, I do still have my Facebook birthday and my real birthday. 256 00:15:06,970 --> 00:15:08,180 I don't wanna make it easy for them. 257 00:15:09,510 --> 00:15:10,080 so all right. 258 00:15:10,080 --> 00:15:13,180 So that, there's, so basically 'cause social engineering is just a, a 259 00:15:13,180 --> 00:15:18,490 variety of tactics, as you said, to get people to, either directly give 260 00:15:18,490 --> 00:15:22,350 you the information you're looking for or to get, or to, basically just 261 00:15:22,360 --> 00:15:26,180 open the door in some way to develop a relationship in some way so that you 262 00:15:26,180 --> 00:15:29,500 can then at some point eventually get the, the thing that you're looking for. 263 00:15:29,950 --> 00:15:34,380 I can think of another, of a story that I saw Kevin Mitnick telling once where 264 00:15:34,620 --> 00:15:39,110 he talked about, he, they had a way where they would in, they would find a person 265 00:15:39,160 --> 00:15:44,140 of note in an, in, in an environment, and they would invite them to speak at 266 00:15:44,140 --> 00:15:47,050 a conference, a non-existent conference. 267 00:15:47,300 --> 00:15:51,090 and then they would say, we just need to do a quick Zoom interview with you prior 268 00:15:51,090 --> 00:15:55,760 to the thing to talk about, whatever." And they give them a Zoom link, and it's 269 00:15:55,760 --> 00:16:01,220 a bad Zoom link, and that link downloaded the, the, the dropper, to do the bad 270 00:16:01,220 --> 00:16:03,030 thing, and then took them to Zoom. 271 00:16:03,990 --> 00:16:07,120 so the person had no idea that anything had just happened, and they just, at 272 00:16:07,120 --> 00:16:10,000 that point, they were just at, they were completely controlling their computer. 273 00:16:10,330 --> 00:16:10,710 So yeah, 274 00:16:10,780 --> 00:16:10,970 Yeah, 275 00:16:11,080 --> 00:16:12,240 engineering, yeah. 276 00:16:12,320 --> 00:16:12,780 What's that? 277 00:16:12,990 --> 00:16:14,400 it's kinda like a s-spoof in the middle. 278 00:16:15,090 --> 00:16:15,570 Yeah 279 00:16:16,300 --> 00:16:18,990 bank, bank, bank account logins are the same way. 280 00:16:19,740 --> 00:16:23,380 the most, the, the cl- the most recent one that I've seen that's pretty clever 281 00:16:23,400 --> 00:16:29,200 is, you know, when, when you get a, a phishing email and you wanna report it 282 00:16:29,230 --> 00:16:32,964 as phishing, know, there's the button at the top that says, "Report as phishing." 283 00:16:33,138 --> 00:16:33,548 Yeah 284 00:16:33,734 --> 00:16:36,474 Well, bad guys are sending phishing emails with the report 285 00:16:36,504 --> 00:16:38,244 phishing button in the email. 286 00:16:39,594 --> 00:16:42,014 So you, you know it's bad, it looks bad. 287 00:16:42,014 --> 00:16:45,954 I'm gonna click the mu- button to report it as bad, but clicking that button is 288 00:16:45,954 --> 00:16:48,134 the trigger for the malware in the email. 289 00:16:48,477 --> 00:16:49,247 Oh, man 290 00:16:49,944 --> 00:16:50,174 Yeah 291 00:16:50,802 --> 00:16:53,422 Tell you what, man, that, that's just not good. 292 00:16:53,692 --> 00:16:54,012 hang on. 293 00:16:54,042 --> 00:16:55,122 Let me pull up my, All right. 294 00:16:55,392 --> 00:16:58,562 let's talk about, Fido2, right? 295 00:16:58,612 --> 00:17:01,467 do you wanna talk about what Fido Fast Identity Online 296 00:17:02,333 --> 00:17:02,873 Well, there you go. 297 00:17:03,163 --> 00:17:08,023 It's kinda like the one-time password stuff, but it's a little more permanent. 298 00:17:09,013 --> 00:17:15,533 so strong, a, a good, a good FIDO, profile, and I think there's, there's 299 00:17:15,533 --> 00:17:17,463 different versions of FIDO out now too. 300 00:17:18,283 --> 00:17:19,483 in fact, I think it's called FIDO2. 301 00:17:20,363 --> 00:17:24,593 the, the idea though is something more than, you know, just your 302 00:17:24,983 --> 00:17:29,403 username and password, but also something outside of just an email 303 00:17:29,403 --> 00:17:30,793 or a text message you would get. 304 00:17:31,693 --> 00:17:33,153 Could you give examples, Mike? 305 00:17:33,383 --> 00:17:37,763 Like based on what you just said, like what would that potentially encompass 306 00:17:39,316 --> 00:17:45,246 Well, so traditional MFAs, you know, an SMS message or a 307 00:17:45,246 --> 00:17:47,286 one-time password or, an email. 308 00:17:47,996 --> 00:17:52,866 FIDO is, is true encrypted token. 309 00:17:53,206 --> 00:17:59,486 you can install it on a, on your laptop or your phone, but it has to be paired, 310 00:17:59,566 --> 00:18:01,006 so it's public and private keys. 311 00:18:01,016 --> 00:18:05,206 So it's got a… Your, your public key's out there, so if I wanted to have a 312 00:18:05,206 --> 00:18:11,186 communication with Prasanna, in order to encrypt that, you would get my public 313 00:18:11,186 --> 00:18:14,286 key, I would get your public key, and then our private keys would match those up. 314 00:18:14,786 --> 00:18:17,806 and those, those private keys are on our device. 315 00:18:19,216 --> 00:18:25,516 so it's, it's kind of an old school asymmetric encryption approach that 316 00:18:25,516 --> 00:18:28,556 they've just kind of put a new name on it and attached it to a new way 317 00:18:28,556 --> 00:18:31,126 of talking and encrypting our stuff. 318 00:18:31,476 --> 00:18:35,256 But it's, it's really re- it's, it's designed to be transactional instead 319 00:18:35,256 --> 00:18:38,156 of like normal email communication. 320 00:18:38,156 --> 00:18:43,356 It's, it's a, it's assigned to a authentication or a purchase or, 321 00:18:45,486 --> 00:18:46,486 it's more transactional 322 00:18:48,552 --> 00:18:52,582 When we get to the actual, action points or, acti- when we get to the actual ac- 323 00:18:52,582 --> 00:18:54,472 action items, it's gonna be really simple. 324 00:18:54,622 --> 00:18:58,182 So we just need to drive home the point here of why this is such a big deal. 325 00:18:58,422 --> 00:19:02,352 and I think the ArcGIS story is another scary one where there was 326 00:19:02,352 --> 00:19:06,002 an entire year that went by where they had control of something, and 327 00:19:06,002 --> 00:19:07,672 that all started with what, Mike? 328 00:19:07,954 --> 00:19:12,124 Well, the, the, the Flax Typhoon, and, and I think that's the, the case 329 00:19:12,124 --> 00:19:17,964 we're talking about here, is actually the, the name of But the, the initial 330 00:19:18,204 --> 00:19:21,114 identification of this particular attack was because of their botnet. 331 00:19:21,864 --> 00:19:27,514 and so looking for vulnerable systems, looking for a way in, Flax Typhoon is 332 00:19:27,534 --> 00:19:32,184 primarily a, an espionage campaign, s- so it's not so much access as it 333 00:19:32,184 --> 00:19:39,164 is true information and, and, and more specifically government-level information. 334 00:19:39,164 --> 00:19:44,804 So, pretty confident that Flax Typhoon is run by the Chinese government. 335 00:19:45,294 --> 00:19:49,984 targets were primarily government organizations, 336 00:19:50,024 --> 00:19:53,824 Taiwan, Asia, America, Canada. 337 00:19:54,794 --> 00:19:55,854 the, the, 338 00:19:57,864 --> 00:20:05,524 the initial compromise was VPNs and firewalls, vulnerabilities, web servers. 339 00:20:05,954 --> 00:20:12,804 and then from there, that compromise allowed them to based on tools and 340 00:20:12,804 --> 00:20:17,324 s- and software available to them, so living off the land, type of attack. 341 00:20:17,334 --> 00:20:23,014 So, you know, PowerShell, Python, Sysinternals, RDP, 342 00:20:23,064 --> 00:20:24,464 from one machine to the next. 343 00:20:24,944 --> 00:20:28,864 one of the things that makes me smile about this, this particular campaign is, 344 00:20:28,894 --> 00:20:35,074 is all of the fun cyber threat acronyms and, and code words, like Juicy Potato. 345 00:20:36,484 --> 00:20:36,894 so, 346 00:20:37,276 --> 00:20:38,026 Sweet potato 347 00:20:39,934 --> 00:20:45,354 so, so many of the tools and, and techniques in, in, in Flax Typhoon were, 348 00:20:46,364 --> 00:20:49,834 were pretty kind of… I, I don't know who came up with the words or the code names. 349 00:20:49,934 --> 00:20:51,434 Mimikatz has been around for a while. 350 00:20:51,434 --> 00:20:52,764 That's a good credential harvesting. 351 00:20:52,784 --> 00:20:56,584 Anybody that hears Mimikatz knows it's, it's associated with, 352 00:20:56,644 --> 00:20:58,004 with malware and cyber attacks. 353 00:20:58,044 --> 00:21:02,674 But the privilege escalation tool that they used was called Juicy Potato. 354 00:21:03,394 --> 00:21:07,394 and some of the web shells, like one of the web shells was called, China Chopper. 355 00:21:08,354 --> 00:21:12,434 just so just some, some fun acronyms and, and, and terminology. 356 00:21:12,434 --> 00:21:15,464 But, was actually big problem 357 00:21:15,952 --> 00:21:20,572 at some, point, didn't they get access to an administrator, like 358 00:21:20,582 --> 00:21:25,162 login again that, that again didn't seem to have any MFA on it? 359 00:21:27,078 --> 00:21:31,608 they did, and some of those systems were like IoT devices, like cameras. 360 00:21:31,698 --> 00:21:35,888 So if you remember back in the day, I'm talking, man, had to have 361 00:21:35,888 --> 00:21:40,528 been almost 10 years ago or more, the Mirai, the Mirai, botnet. 362 00:21:40,747 --> 00:21:40,887 Got it. 363 00:21:41,077 --> 00:21:41,247 Yep 364 00:21:41,618 --> 00:21:47,448 And so in Flax Typhoon, they w- their botnet was called Raptor Train. 365 00:21:48,088 --> 00:21:53,918 and so the Raptor Train using the Mirai-type virus compromised hundreds of 366 00:21:53,918 --> 00:21:57,318 thousands of IoT devices in this campaign. 367 00:21:57,708 --> 00:22:03,688 And so that was cameras, routers, switches, network storage devices. 368 00:22:04,098 --> 00:22:09,478 so that Mirai, i- you remember back, it, it, in that case, M- the Mirai 369 00:22:09,488 --> 00:22:14,068 botnet was successful because some of the credentials for those devices were 370 00:22:14,078 --> 00:22:18,838 hard-coded on the chips, and the, the manufacturer of those chips didn't care. 371 00:22:18,858 --> 00:22:20,418 They're like, "I just produce chips. 372 00:22:20,568 --> 00:22:25,318 It goes in something, I have no control over that." so very similarly, this 373 00:22:25,508 --> 00:22:30,138 attack group and their botnet, were able to leverage hard-coded credentials to 374 00:22:30,138 --> 00:22:35,058 get access to the device, and in some cases, it was root level device, access. 375 00:22:35,378 --> 00:22:35,538 And 376 00:22:35,587 --> 00:22:35,597 Oof 377 00:22:35,628 --> 00:22:38,908 other cases, it got them on the device where they were then able to deploy 378 00:22:39,248 --> 00:22:44,628 Mimikatz or use some of these other, available tools to, to harvest credentials 379 00:22:45,654 --> 00:22:50,584 The way I would put all of that together is that the, the bad actors have a, 380 00:22:50,644 --> 00:22:54,594 a seemingly infinite number of ways that they can harvest credentials. 381 00:22:54,594 --> 00:22:58,094 We talked about phishing, we talked about using old versions of 382 00:22:58,094 --> 00:23:01,974 software that have vulnerabilities, and we talked about just, botnets. 383 00:23:02,274 --> 00:23:05,404 th- they just have a seemingly… and d- I think we pr- we've probably 384 00:23:05,404 --> 00:23:06,774 just scratched the surface, Mike? 385 00:23:06,954 --> 00:23:08,264 Of, a seemingly infinite, 386 00:23:09,404 --> 00:23:13,274 Well, it is seemingly infinite, because we don't do… We don't 387 00:23:13,284 --> 00:23:16,634 think like they do, and they do this 24 hours a day, seven days a week. 388 00:23:17,354 --> 00:23:19,264 we only do it 8:00 to 5:00, Monday through Friday, a lot, 389 00:23:19,364 --> 00:23:20,834 as, as a normal user, right? 390 00:23:20,954 --> 00:23:22,614 and probably not the full eight hours. 391 00:23:22,614 --> 00:23:25,614 We're, we're doing other stuff, or just not focused. 392 00:23:25,644 --> 00:23:30,634 But yes, it is seemingly un- unending, and, and ever-evolving 393 00:23:30,754 --> 00:23:33,054 ways of harvesting our credentials 394 00:23:34,570 --> 00:23:35,330 Prasanna 395 00:23:35,337 --> 00:23:36,497 have a question for you now. 396 00:23:36,720 --> 00:23:37,150 Sure 397 00:23:37,867 --> 00:23:42,257 So we've talked about all these scary ways that they're always gonna be 398 00:23:42,257 --> 00:23:46,617 ahead of us, that we're never gonna be able to catch up because we don't have 399 00:23:46,617 --> 00:23:51,997 the time or effort or expertise to be focused on securing things all the time. 400 00:23:52,007 --> 00:23:58,567 S- so like, do we just like sort of call it quits, unplug 401 00:23:58,567 --> 00:24:02,617 ourselves from the internet, and just go back to sticks and fire 402 00:24:02,726 --> 00:24:02,776 that, 403 00:24:02,826 --> 00:24:03,226 out in the- 404 00:24:03,785 --> 00:24:05,995 that's a great question, Prasanna, but that is the only way to 405 00:24:05,995 --> 00:24:08,545 have a truly system, right? 406 00:24:08,825 --> 00:24:12,525 I think my point, and Mike, feel free to enhance this point, but my 407 00:24:12,525 --> 00:24:17,815 point is you have to assume that the bad guys are going to get someone's 408 00:24:17,815 --> 00:24:20,115 credentials in your environment. 409 00:24:20,545 --> 00:24:24,475 And so the idea, this is the whole point of MFA, right? 410 00:24:24,685 --> 00:24:30,375 The whole idea of MFA is that, that th- there is a seemingly limitless number 411 00:24:30,375 --> 00:24:35,765 of ways, you know, that the bad guys can get, the other is, the, the purchasing 412 00:24:35,765 --> 00:24:38,805 of the, the dumps, the credential dumps that are available online, right? 413 00:24:38,805 --> 00:24:43,045 th- there's so many ways for them to get access to credentials that you are 414 00:24:43,105 --> 00:24:47,265 committing, I'll say this again, you are committing professional malfeasance 415 00:24:47,555 --> 00:24:56,075 if you are allowing access to important accounts without MFA turned on, right? 416 00:24:56,125 --> 00:24:59,555 you're noticing this, and we're gonna go a little bit, it's, we're gonna 417 00:24:59,555 --> 00:25:01,165 talk about phishing resistant MFA. 418 00:25:01,425 --> 00:25:05,355 But you've noticed this happen in your personal life, Prasanna? 419 00:25:05,385 --> 00:25:07,955 can you think of what's happened to you over the last, I wanna say 420 00:25:07,975 --> 00:25:12,235 10 years with things like your bank, with things like Gmail, with 421 00:25:12,236 --> 00:25:16,486 Oh, yeah, everything, yeah, everything's going multi-factor authentication, right? 422 00:25:16,876 --> 00:25:20,906 It's you log in, it sends something, because now you also have phones, right? 423 00:25:20,906 --> 00:25:24,306 And so everything gets sent to your phone where it's like, "Hey, did you try to log 424 00:25:24,306 --> 00:25:28,506 in on this laptop? Accept or deny from your phone or some other device," right? 425 00:25:28,506 --> 00:25:35,146 And so you see this happening because it's becoming easier, I guess. 426 00:25:36,106 --> 00:25:39,786 Do you, do you think it's becoming easier to enforce MFA versus before? 427 00:25:40,036 --> 00:25:43,376 Like I remember when I was working and you'd sort of walk around 428 00:25:43,376 --> 00:25:45,716 with the little key fob, right? 429 00:25:45,716 --> 00:25:48,456 With the rotating code, and that you always had to have it in order 430 00:25:48,456 --> 00:25:50,816 to be able to log in, and if for some reason it wasn't there or 431 00:25:50,816 --> 00:25:52,396 the battery died, you're screwed. 432 00:25:53,126 --> 00:25:55,876 I think MFA has made it a little easier. 433 00:25:55,886 --> 00:25:59,316 And so kind of over the last 10 years, like you're saying, yeah, I think 434 00:25:59,826 --> 00:26:03,236 back then there was nothing, and now it's sort of become commonplace 435 00:26:03,747 --> 00:26:08,167 now I think the difference bet- between back then and now is that we always 436 00:26:08,177 --> 00:26:10,687 have this other thing on us now, right? 437 00:26:10,717 --> 00:26:15,607 We always have our s- we should always have our smartphone with us, 438 00:26:16,174 --> 00:26:16,954 Where's your phone, Curtis? 439 00:26:17,947 --> 00:26:20,727 my phone is right here, sir. Thank you very 440 00:26:20,818 --> 00:26:21,248 Okay. 441 00:26:21,507 --> 00:26:25,207 and by the way my life is, I can't go anywhere without my phone. 442 00:26:25,217 --> 00:26:29,277 My car runs from my phone, so as soon as I step… And which is perfect for me, 443 00:26:29,277 --> 00:26:33,937 'cause I, I got serious, By the way, I've officially been diagnosed with ADHD now, 444 00:26:33,947 --> 00:26:39,197 'cause I had to wait 60 years to find out, "Yeah, Curtis, you got ADHD." So the 445 00:26:39,197 --> 00:26:43,257 fact that I can't leave the house without a phone, I get in my car, that means 446 00:26:43,257 --> 00:26:44,597 I always have my phone with me, right? 447 00:26:44,597 --> 00:26:48,037 'Cause otherwise I definitely would be the guy that's 40 miles away 448 00:26:48,037 --> 00:26:50,377 and going, "Oh, crap, I left my phone back at my house," right? 449 00:26:50,787 --> 00:26:53,427 but yeah, we have that device with us, and now we have a number of 450 00:26:53,427 --> 00:26:58,717 pieces of software, commercial ones like the Symantec VIP, tool. 451 00:26:58,717 --> 00:27:01,847 I know that a couple of my different vendors require that. 452 00:27:02,157 --> 00:27:07,787 or, free versions from Google or Authy or, pr- Mike, you mentioned you use a- another 453 00:27:07,787 --> 00:27:11,397 tool that, you mentioned that I think on, I don't know, a few recordings ago. 454 00:27:11,397 --> 00:27:13,487 You use a, a, a completely different tool. 455 00:27:13,617 --> 00:27:14,517 I don't remember what it was. 456 00:27:14,517 --> 00:27:15,207 It doesn't matter. 457 00:27:15,557 --> 00:27:17,287 But yeah, there are a number of tools. 458 00:27:17,657 --> 00:27:22,947 and yes, there are also the truly secure ones are the, those things that, you 459 00:27:22,947 --> 00:27:25,357 know, the, like the YubiKey, right? 460 00:27:25,367 --> 00:27:28,997 The, that, that is a truly secure, one-time password thing that, 461 00:27:29,557 --> 00:27:34,017 that isn't… the only downside to the phone is potentially somebody 462 00:27:34,017 --> 00:27:35,177 could hack your phone, right? 463 00:27:35,597 --> 00:27:40,197 So if you're seeing this happen in your personal life, and you're in your 464 00:27:40,197 --> 00:27:44,907 professional life, and you're in and you care at all about cybersecurity, if 465 00:27:44,907 --> 00:27:48,437 you've got important accounts that are just sitting there waiting for you to 466 00:27:48,437 --> 00:27:53,477 just log in with no, other authentication, then again, professional malfeasance. 467 00:27:53,577 --> 00:27:57,257 I don't wanna, call you nasty names, but don't know what el- I don't 468 00:27:57,257 --> 00:27:58,687 know what else to say at that point. 469 00:27:58,867 --> 00:28:02,667 Mike, let's talk a little bit about… I know this is something you've 470 00:28:02,677 --> 00:28:05,057 talked about before multiple times. 471 00:28:05,527 --> 00:28:10,577 We talk about this idea of killing the trust button, right? 472 00:28:10,667 --> 00:28:12,237 this is something you talk a lot about. 473 00:28:12,247 --> 00:28:13,487 You w- you wanna talk about that? 474 00:28:15,079 --> 00:28:15,279 Sure. 475 00:28:15,289 --> 00:28:19,249 I think a lot of organizations and a lot of systems and networks have 476 00:28:19,249 --> 00:28:23,009 this inherent trust out in the world that, you know, we need to be able 477 00:28:23,009 --> 00:28:25,249 to, we, we need to be accessible. 478 00:28:25,699 --> 00:28:28,549 we want, Well, and, and there's a couple of reasons for that. 479 00:28:28,549 --> 00:28:31,579 One is just making it easy so that I don't have to go do 480 00:28:31,589 --> 00:28:33,659 custom rules or manage something. 481 00:28:34,089 --> 00:28:35,909 and so that. 482 00:28:35,919 --> 00:28:39,569 Well then, there's also a level of skill required for, in a lot of 483 00:28:39,569 --> 00:28:43,939 cases, for implementing changes that, could filter or restrict access. 484 00:28:43,939 --> 00:28:49,199 So it- it's just easy to, to leave the door open or the doors 485 00:28:49,199 --> 00:28:51,319 unlocked or, or have fewer layers. 486 00:28:51,389 --> 00:28:55,079 I see it a lot where organizations call and say, "Hey, I've got this problem. 487 00:28:55,079 --> 00:28:58,739 I think someone's trying to get me- to me from Germany." I said, "Okay. 488 00:28:58,739 --> 00:29:01,859 Well, we can look into that, but in the, in the meantime, do you guys care 489 00:29:01,869 --> 00:29:06,049 about people from Germany hitting your network?" "No." Well, just block Germany. 490 00:29:06,109 --> 00:29:07,489 Well, that's an easy problem. 491 00:29:07,839 --> 00:29:08,299 It's solved. 492 00:29:08,789 --> 00:29:11,029 then, you know, all right, so there's, there's website traffic, 493 00:29:11,029 --> 00:29:15,179 there's network traffic, there's VPN traffic, there's cloud. 494 00:29:16,159 --> 00:29:19,699 all of those things, and this goes back to, you know, how do 495 00:29:19,699 --> 00:29:22,899 we, how do we better protect ourselves, whether it's MFA or not? 496 00:29:22,949 --> 00:29:27,989 And, and it's, it's really about understanding the risk to us, us as 497 00:29:27,989 --> 00:29:32,499 an individual, us as a, a company, then what kind of things can we put in 498 00:29:32,499 --> 00:29:35,189 place to mitigate those risks, right? 499 00:29:35,189 --> 00:29:38,389 So if, if we're concerned about people stealing our, our users' 500 00:29:38,389 --> 00:29:42,439 credentials, what can we do to reduce the likelihood of that happening? 501 00:29:42,869 --> 00:29:47,339 Well, we could really focus in on who should have the ability to log in. 502 00:29:47,359 --> 00:29:51,139 So even if Curtis's were compromised, if he's logging in 503 00:29:51,259 --> 00:29:54,129 from Germany, it won't work, right? 504 00:29:54,325 --> 00:29:54,535 Right 505 00:29:54,679 --> 00:29:58,889 Well then, all right, so we implement MFA so that… You know, Curtis figures 506 00:29:58,889 --> 00:30:03,609 that out, so he compromises a, a machine in, in the US to log in from 507 00:30:03,689 --> 00:30:07,819 the US, and now the credentials work, but he's being challenged with MFA. 508 00:30:08,569 --> 00:30:14,779 he steals, he steals Prasanna's MFA token by phishing it, sending him a phishing m- 509 00:30:14,789 --> 00:30:16,559 email that gets him to go to a website. 510 00:30:17,259 --> 00:30:20,699 because he's already trusted in his browser, the website 511 00:30:20,799 --> 00:30:22,719 scrapes that MFA token. 512 00:30:22,719 --> 00:30:26,049 Now I have all three things, U- ID, password, MFA. 513 00:30:27,559 --> 00:30:34,869 But I can configure my system to only allow one login, no concurrent logins. 514 00:30:34,869 --> 00:30:39,859 Definitely no logins across, know, land speed travel distances. 515 00:30:40,239 --> 00:30:42,589 so there's… I mean, there's tons of things you can do 516 00:30:42,803 --> 00:30:42,963 You've 517 00:30:42,979 --> 00:30:43,999 to mitigate all of this 518 00:30:44,353 --> 00:30:45,043 before, right? 519 00:30:45,861 --> 00:30:46,191 Right. 520 00:30:46,351 --> 00:30:50,681 It just takes time and effort and skill and an understanding, and all 521 00:30:50,681 --> 00:30:54,431 of that is great on the technical side until you implement it and then you 522 00:30:54,431 --> 00:30:57,301 get your users going, "Well, that's too difficult, and I don't like that." 523 00:30:57,301 --> 00:31:01,641 And so now you've got the political fight, and a lot of technical people 524 00:31:01,641 --> 00:31:04,171 will give up on the political fight. 525 00:31:04,271 --> 00:31:05,261 It's just like, you know what? 526 00:31:05,384 --> 00:31:06,804 as you were talking… Oh. 527 00:31:07,181 --> 00:31:08,671 it's not worth losing my job over 528 00:31:09,114 --> 00:31:12,294 As you were talking through that last point, Mike, I was just thinking in my 529 00:31:12,294 --> 00:31:16,984 head, I'm like, "Why do all products and companies just do this by default?" And 530 00:31:16,984 --> 00:31:18,394 you hit on it at the very end, right? 531 00:31:18,394 --> 00:31:20,454 It's like users are gonna complain. 532 00:31:20,464 --> 00:31:22,264 There's gonna be friction in their experience. 533 00:31:22,264 --> 00:31:25,744 They're not gonna like it, and then you're gonna get so many support tickets. 534 00:31:25,744 --> 00:31:27,464 You're gonna be like, "Whoa, whoa, whoa, what do we do? 535 00:31:27,474 --> 00:31:28,574 Let's go back to the old way." 536 00:31:29,533 --> 00:31:29,803 Yep. 537 00:31:30,053 --> 00:31:35,213 And so it, it comes down to a balance of security and usability from a, a technical 538 00:31:35,213 --> 00:31:38,933 and controls perspective, and then a personal administrative, it's do I wanna, 539 00:31:39,333 --> 00:31:43,193 do I wanna fight this battle or do I wanna live to, you know, work another day? 540 00:31:43,853 --> 00:31:47,763 'cause I mean, your time's, your time's limited in either way, in either case, 541 00:31:47,763 --> 00:31:51,153 but would you rather be fired because you, you tried to do something good, or you 542 00:31:51,153 --> 00:31:55,933 got fired because you didn't do something good and the, the company was compromised 543 00:31:55,933 --> 00:31:57,603 and you were fired for that reason? 544 00:31:58,489 --> 00:31:58,739 Yeah 545 00:31:58,783 --> 00:32:00,533 there's… I mean, it's a struggle 546 00:32:01,447 --> 00:32:03,517 I think a place to start, I, the- I've seen that. 547 00:32:03,557 --> 00:32:06,347 I've seen that where, and I've seen it in backups, right? 548 00:32:06,347 --> 00:32:09,997 I've seen it where you're trying to do the thing and you get the group that's like, 549 00:32:09,997 --> 00:32:11,457 "Ah, I don't wanna do the thing," right? 550 00:32:11,457 --> 00:32:14,627 Whatever, whether it's, in my case, in backups, I go all the way back to 551 00:32:14,637 --> 00:32:19,057 when I was that oil and gas company and, I was just trying to enable 552 00:32:19,067 --> 00:32:24,187 backups for the first time this really big Oracle database, right? 553 00:32:24,507 --> 00:32:25,567 that was really important. 554 00:32:25,567 --> 00:32:30,087 It had never been backed up, and it involved me doing a couple of things 555 00:32:30,087 --> 00:32:31,677 that the DBA was fighting me on. 556 00:32:32,137 --> 00:32:36,847 I, I, it's in, in, it- I can't fathom the idea of having a m- a 557 00:32:36,847 --> 00:32:40,917 valid system that isn't backed up and anybody being okay with that. 558 00:32:40,947 --> 00:32:42,237 But still, that would happen. 559 00:32:42,237 --> 00:32:44,187 The same thing happens in cybersecurity, right? 560 00:32:45,027 --> 00:32:51,837 Ca- do you think it would be easier to at least, and perhaps more important to 561 00:32:51,837 --> 00:32:55,147 start with administrative accounts, right? 562 00:32:55,187 --> 00:32:56,357 privileged accounts, right? 563 00:32:56,377 --> 00:33:00,097 It's, at first off it's a smaller number, and possibly it's a different group 564 00:33:00,097 --> 00:33:07,247 of people that will have some better understanding of the importance of this. 565 00:33:07,247 --> 00:33:08,447 does that sound like a good idea? 566 00:33:09,481 --> 00:33:10,131 Absolutely. 567 00:33:10,131 --> 00:33:14,471 You can, you can log and alert on, privileged account use, whether 568 00:33:14,471 --> 00:33:16,601 it's an admin or a service account. 569 00:33:17,241 --> 00:33:20,351 and all of that stuff should be tracked, both successful and failed 570 00:33:20,371 --> 00:33:22,241 login attempts for privileged accounts 571 00:33:23,527 --> 00:33:26,947 Now, the things that you suggested earlier, th- those all sounded great, 572 00:33:26,947 --> 00:33:28,527 but they sounded complicated, right? 573 00:33:28,537 --> 00:33:30,117 it sounds easy to turn off Germany. 574 00:33:30,117 --> 00:33:31,807 It turns out easy to turn off Russia. 575 00:33:32,157 --> 00:33:37,477 but the, some of the o- other stuff, it sounded like it starts to get complicated. 576 00:33:37,807 --> 00:33:42,307 So my question is, you're like, it's not complicated for you, Mike," but I'm just 577 00:33:42,307 --> 00:33:45,867 saying for maybe the aver- person, is 578 00:33:45,879 --> 00:33:46,649 It's really not 579 00:33:47,017 --> 00:33:50,727 are there tools that can help this be easier to do? 580 00:33:51,935 --> 00:33:54,645 There's tons of tools, but then you've gotta go learn a tool. 581 00:33:54,955 --> 00:33:58,215 a lot of, a lot of these, capabilities are built into stuff 582 00:33:58,215 --> 00:33:59,625 you probably already pay for. 583 00:34:00,085 --> 00:34:04,715 So your normal Windows machine, Windows 11 as an example, you've got a 584 00:34:04,715 --> 00:34:06,345 firewall, you've got Windows Defender. 585 00:34:06,345 --> 00:34:09,335 All that stuff comes with the, your Windows license. 586 00:34:10,185 --> 00:34:13,205 watch a YouTube video on how to configure it to protect you better. 587 00:34:13,245 --> 00:34:16,885 You'll learn, you'll learn everything you need to know in, like, 15 minutes, and 588 00:34:17,042 --> 00:34:17,252 Could you… 589 00:34:17,295 --> 00:34:18,005 walk you through it. 590 00:34:18,905 --> 00:34:25,615 If you're an administrator in Office 365 as an example, there are hundreds of hours 591 00:34:25,625 --> 00:34:30,545 of training videos for free that walk you through all this stuff step by step. 592 00:34:30,595 --> 00:34:34,245 And if you don't wanna watch a video, it's all lined out in a nice Microsoft 593 00:34:34,245 --> 00:34:38,005 document that'll s- take you through it, step one through whatever with links. 594 00:34:38,885 --> 00:34:41,375 you click the link, and it takes you right into your admin console, 595 00:34:41,375 --> 00:34:43,165 the exact right spot to do it. 596 00:34:44,515 --> 00:34:48,095 there are tools in Office 365 that allow you to test. 597 00:34:48,245 --> 00:34:52,125 Like, I wanna turn this on, let me test it make sure I don't, you know, 598 00:34:52,135 --> 00:34:53,855 break the, break the environment. 599 00:34:55,471 --> 00:34:56,081 pick a user. 600 00:34:56,191 --> 00:34:57,941 Start with, start with your admin account 601 00:34:58,221 --> 00:34:58,591 Yeah 602 00:34:59,356 --> 00:35:03,966 So, so the, here's my biggest thing, like given it's 2026 and we're in 603 00:35:03,976 --> 00:35:09,796 the age of AI, like why don't you just go ask like Claude or Gemini 604 00:35:09,846 --> 00:35:12,856 or take your pick of AI assistant 605 00:35:12,957 --> 00:35:16,757 even, even, more succinctly with Microsoft, you know what? 606 00:35:17,237 --> 00:35:22,327 Buy a Copilot license, it's like $100 a year, and tell Copilot now 607 00:35:22,327 --> 00:35:25,317 that you're the licensed- you're the admin and you've got a Copilot 608 00:35:25,317 --> 00:35:27,307 license, ask Copilot to help you. 609 00:35:27,877 --> 00:35:31,157 It has the same privileges that you do and can see all that stuff 610 00:35:32,891 --> 00:35:37,911 I had a mission critical system that went down yesterday, right 611 00:35:37,941 --> 00:35:39,571 at the very inopportune time. 612 00:35:39,571 --> 00:35:40,411 You know what that was? 613 00:35:41,428 --> 00:35:42,038 Your TV 614 00:35:42,821 --> 00:35:43,161 Yeah. 615 00:35:43,441 --> 00:35:47,611 My TV, stopped working just before we had invited a bunch of people over to 616 00:35:47,681 --> 00:35:50,691 , watch the World Cup final, and I used AI. 617 00:35:50,691 --> 00:35:52,201 I was like, I got three different pieces. 618 00:35:52,201 --> 00:35:55,621 I got the Apple TV box, I got the soundbar, and it's going through the 619 00:35:55,621 --> 00:35:58,781 soundbar up to the TV," and I hadn't used this particular TV in a while. 620 00:35:59,231 --> 00:36:02,161 And, I d- just sat there, worked through. 621 00:36:02,401 --> 00:36:04,631 I was like, "I got this,"… The- these are the brands of the 622 00:36:04,631 --> 00:36:08,181 things I have, and Claude, just worked me through, fixing it, and 623 00:36:08,318 --> 00:36:08,398 Yes, I've been replaced. 624 00:36:08,398 --> 00:36:08,478 'Cause last time 625 00:36:08,561 --> 00:36:10,191 I was d- done in a few minutes. 626 00:36:10,371 --> 00:36:12,791 You b- By the 627 00:36:12,908 --> 00:36:14,918 I helped you troubleshoot this, I remember. 628 00:36:15,131 --> 00:36:19,151 I completely agree that, that is definitely, a, a great place to start. 629 00:36:19,491 --> 00:36:23,451 because all of those phishing-resistant things that you talk about… And by 630 00:36:23,451 --> 00:36:27,301 the way, d- let's just talk about, why isn't MFA by itself good enough? 631 00:36:27,301 --> 00:36:28,901 Why can't we just turn on MFA? 632 00:36:29,311 --> 00:36:31,581 And there are a bunch of reasons, right? 633 00:36:31,591 --> 00:36:33,811 you talked about stealing session credentials. 634 00:36:33,851 --> 00:36:35,971 That is a possibility, right? 635 00:36:36,221 --> 00:36:40,231 other things are, the, the MFA exhaustion, right? 636 00:36:40,231 --> 00:36:44,451 Which is something where, you just bombard the, you meaning the, the, the bad guy, 637 00:36:44,641 --> 00:36:48,921 just bombard the person with so many inf- MFA requests that at some point they just 638 00:36:48,991 --> 00:36:53,381 respond just to make it go away, which is a horrible response, but I think we 639 00:36:53,381 --> 00:36:57,281 can agree that there's certain groups of people that would respond that way, right? 640 00:36:57,281 --> 00:37:01,791 And that's why we have to add this extra logic behind MFA, to make 641 00:37:01,791 --> 00:37:03,841 it more resistant to phishing. 642 00:37:07,299 --> 00:37:10,439 there's still that, that usability and culture part behind it. 643 00:37:10,569 --> 00:37:12,409 I mean, you talked about MFA exhaustion. 644 00:37:14,539 --> 00:37:16,599 Do you have locking your house exhaustion? 645 00:37:17,309 --> 00:37:17,629 Right? 646 00:37:17,699 --> 00:37:20,459 You're gonna go back home because you forgot to lock the front door. 647 00:37:21,219 --> 00:37:21,979 You care. 648 00:37:22,109 --> 00:37:23,399 You have a responsibility. 649 00:37:23,409 --> 00:37:29,939 MFA should, should be the same, if you're not requiring MFA every time they log in, 650 00:37:29,949 --> 00:37:31,599 then you've diminished the value of it. 651 00:37:32,019 --> 00:37:35,069 But then also on the back end, on the IT side, or the technical 652 00:37:35,069 --> 00:37:40,619 side, there are controls for limiting the lifespan of MFA also. 653 00:37:40,629 --> 00:37:44,879 So Mike's been logged in for 20 hours on the same MFA token. 654 00:37:45,009 --> 00:37:47,809 That shouldn't l- you know, they should expire at some point, 655 00:37:48,782 --> 00:37:48,882 The… 656 00:37:48,969 --> 00:37:49,849 can configure that 657 00:37:50,272 --> 00:37:52,842 Do you know if they, 'cause I know a lot of websites, right? 658 00:37:52,842 --> 00:37:55,832 It's like you log into your bank and you enter and it's like, "Oh, remi- 659 00:37:55,902 --> 00:37:59,242 reme- remember me for next time," so you don't get the MFA again. 660 00:37:59,882 --> 00:38:02,702 Do you know, Mike, and that's like the exact opposite of 661 00:38:02,702 --> 00:38:04,382 what you want, right, from MFA. 662 00:38:04,842 --> 00:38:09,782 And so I guess the question I had is, Mike, in these tools that you were talking 663 00:38:09,782 --> 00:38:13,962 about where you can set these policies, do you know if they also have that 664 00:38:13,962 --> 00:38:19,402 ability to say, "Hey, by the way, never allow a user to say trust this device"? 665 00:38:20,375 --> 00:38:22,375 Yeah, so that was a group policy you can push out. 666 00:38:22,385 --> 00:38:23,325 So there's a couple things. 667 00:38:23,365 --> 00:38:28,275 As a, as an IT administrator, I can restrict what browsers you can use. 668 00:38:29,005 --> 00:38:32,535 I don't want you to use, Firefox, just as an example. 669 00:38:33,025 --> 00:38:35,775 So you can only use Edge and Chrome, right? 670 00:38:35,775 --> 00:38:40,085 So I-- there's, there… You can, you can push policies out like that, and 671 00:38:40,085 --> 00:38:45,195 then within that policy and within MFA, you can, you can select never allow or 672 00:38:45,195 --> 00:38:52,405 prohibit, you can prohibit users from saving, MFA credentials in browsers. 673 00:38:53,425 --> 00:38:53,665 Yep. 674 00:38:54,285 --> 00:38:55,755 And, and any other credentials. 675 00:38:55,775 --> 00:38:59,265 You can prohibit them from saving credentials in, in the 676 00:38:59,448 --> 00:38:59,668 Yeah 677 00:38:59,935 --> 00:39:00,505 in general. 678 00:39:00,655 --> 00:39:00,895 Yep. 679 00:39:01,487 --> 00:39:02,167 My websites 680 00:39:02,215 --> 00:39:03,335 Or credit, or payment 681 00:39:03,347 --> 00:39:03,757 Explorer 682 00:39:04,816 --> 00:39:05,316 Oops. 683 00:39:06,777 --> 00:39:07,357 Netscape. 684 00:39:08,139 --> 00:39:10,539 That's gave… Wow, you took us back there. 685 00:39:10,939 --> 00:39:12,799 All right, MFA is really important. 686 00:39:12,839 --> 00:39:15,939 and what… as long as we're talking about it, we'll just throw in passkeys is 687 00:39:15,959 --> 00:39:17,979 actually, are actually better than MFA. 688 00:39:18,309 --> 00:39:22,629 But, today we're talking about least have MFA, for goodness sakes. 689 00:39:22,829 --> 00:39:27,559 And also, look into being more resistant to phishing, these extra 690 00:39:27,559 --> 00:39:31,709 features that Mike talked about, to look for things like impossible travel. 691 00:39:31,719 --> 00:39:35,519 how is he in both in San Diego and London all at the same time, right? 692 00:39:35,569 --> 00:39:37,119 that's what they call impossible travel. 693 00:39:37,119 --> 00:39:41,129 And why is he… i- if you can add some logic of like, why is he never 694 00:39:41,129 --> 00:39:42,219 logs in at 3:00 in the morning. 695 00:39:42,219 --> 00:39:43,629 Why is he logging in at 3:00 in the morning? 696 00:39:43,909 --> 00:39:49,639 Perhaps, just add an extra level of security when weird things happen, right? 697 00:39:50,809 --> 00:39:51,239 all right. 698 00:39:52,049 --> 00:39:54,169 thanks, Prasanna and Mike, once again 699 00:39:55,042 --> 00:39:55,752 It's always fun 700 00:39:57,915 --> 00:40:01,205 Never enough time to say all I wanna say, but I'm glad I could contribute 701 00:40:02,235 --> 00:40:03,145 Yeah, All right. 702 00:40:03,215 --> 00:40:05,215 And thanks, to everyone out there listening. 703 00:40:05,505 --> 00:40:06,675 you're why we do this. 704 00:40:06,945 --> 00:40:07,875 That is a wrap 705 00:40:10,769 --> 00:40:15,469 The Backup Wrap Up is written, recorded, and produced by me, W. Curtis Preston. 706 00:40:16,059 --> 00:40:20,819 If you need backup or DR consulting, content generation, or expert witness 707 00:40:20,819 --> 00:40:23,619 work, check out backupcentral.com. 708 00:40:24,129 --> 00:40:27,189 You can also find links for my O'Reilly books on the same website. 709 00:40:27,919 --> 00:40:31,889 Remember, this is an independent podcast, and any opinions that 710 00:40:31,889 --> 00:40:35,859 you hear are those of the speaker and not necessarily an employer. 711 00:40:36,729 --> 00:40:37,389 Thanks for listening