1 00:00:00,050 --> 00:00:04,199 Can you imagine finding out that a Chinese state-sponsored hacker group 2 00:00:04,290 --> 00:00:09,880 spent over a year inside your network and your MFA didn't do a single thing? 3 00:00:10,520 --> 00:00:13,810 That's exactly what happened to some academic and medical research 4 00:00:13,810 --> 00:00:19,170 institutions, and why phishing-resistant MFA isn't optional anymore. 5 00:00:19,850 --> 00:00:24,279 Today, Prasanna and I break down exactly how attackers harvested credentials, 6 00:00:24,619 --> 00:00:30,829 hijacked REDCap, uh, which is a thing for research and education, Google 7 00:00:30,830 --> 00:00:35,830 Workspace with fake compliant rules, and exfiltrated sensitive research data 8 00:00:35,839 --> 00:00:38,269 for months without anybody noticing. 9 00:00:38,749 --> 00:00:41,410 We'll also talk about what you need to do right now so that 10 00:00:41,410 --> 00:00:42,449 this doesn't happen to you. 11 00:00:43,190 --> 00:00:46,159 Here we turn admins into cyber recovery heroes. 12 00:00:46,359 --> 00:00:48,500 This is the Backup Wrap Up. 13 00:01:03,245 --> 00:01:04,515 Welcome to the Backup Wrap Up. 14 00:01:04,545 --> 00:01:06,275 I'm your host W. Curtis Preston. 15 00:01:06,285 --> 00:01:09,975 I have with me a guy who is super jealous of the fact that in the 16 00:01:09,975 --> 00:01:15,005 last couple of weeks I have used, I think, every tool that I own. 17 00:01:15,155 --> 00:01:16,225 Isn't that true, Prasanna? 18 00:01:16,367 --> 00:01:18,817 the one that I had you buy 19 00:01:19,405 --> 00:01:20,185 It, that is true. 20 00:01:20,185 --> 00:01:24,045 a significant amount of use, of the one that you basically really talked me 21 00:01:24,045 --> 00:01:27,485 into it, and I was like, "What do I need one of those for?" And now I have it. 22 00:01:27,505 --> 00:01:29,485 We're… What? 23 00:01:30,011 --> 00:01:30,791 I found you the deal 24 00:01:31,355 --> 00:01:32,585 You did find me a deal. 25 00:01:32,675 --> 00:01:35,375 of course that, that, the tool we're talking about at 26 00:01:35,375 --> 00:01:36,905 this moment is the planer. 27 00:01:37,385 --> 00:01:41,545 and if you've never had a planer, it's a, it's an amazing device, but it's 28 00:01:41,595 --> 00:01:45,455 if you've never used one before, you don't know why you would want one. 29 00:01:46,545 --> 00:01:46,885 And then once 30 00:01:46,963 --> 00:01:47,173 use 31 00:01:47,195 --> 00:01:47,685 get one, 32 00:01:47,793 --> 00:01:48,253 "Oh my gosh." 33 00:01:48,575 --> 00:01:51,815 you're like, "How did I ever live my life without this?" like the air fryer. 34 00:01:51,825 --> 00:01:53,525 It's like the air fryer of tools. 35 00:01:55,491 --> 00:01:56,931 I don't know about an air fryer 36 00:01:57,795 --> 00:02:00,375 meaning you don't know if an air fryer is awesome? 37 00:02:02,479 --> 00:02:04,909 Or if I would justify having an air fryer 38 00:02:05,641 --> 00:02:07,171 that's because you've never had an air fryer. 39 00:02:07,171 --> 00:02:07,401 See? 40 00:02:07,401 --> 00:02:08,301 This is what I'm talking about. 41 00:02:08,751 --> 00:02:10,311 That and you know what else? 42 00:02:10,951 --> 00:02:11,571 The West Wing. 43 00:02:11,951 --> 00:02:14,121 if you would just watch The West Wing. 44 00:02:14,761 --> 00:02:18,201 so wait, so here's another interesting thing about Prasanna. 45 00:02:18,461 --> 00:02:23,511 Prasanna owns, because you got a deal on Apple, like Apple, what is it? 46 00:02:23,511 --> 00:02:24,131 Apple Plus? 47 00:02:24,257 --> 00:02:24,517 Yeah 48 00:02:24,751 --> 00:02:29,261 TV, and you bought the entire series for some ridiculous price, right? 49 00:02:29,261 --> 00:02:30,391 Like, how much was it? 50 00:02:30,777 --> 00:02:31,727 It was like $30 or 51 00:02:31,727 --> 00:02:32,167 something 52 00:02:32,701 --> 00:02:33,051 yeah. 53 00:02:33,221 --> 00:02:35,341 and that was, like, a year ago at least? 54 00:02:37,775 --> 00:02:39,095 it might be going on a year and a half 55 00:02:39,291 --> 00:02:44,241 Yeah, and you've yet to see a single episode because you know that the 56 00:02:44,241 --> 00:02:46,941 moment you do, you're gonna get hooked and you're gonna, you're gonna 57 00:02:46,943 --> 00:02:51,423 here's my problem though, Curtis, is this is not atypical for me where I 58 00:02:51,423 --> 00:02:54,743 will buy something and it will sit 59 00:02:54,951 --> 00:02:55,291 Yeah. 60 00:02:55,473 --> 00:02:55,673 for 61 00:02:55,841 --> 00:02:56,331 years 62 00:02:56,779 --> 00:02:58,189 this is something you and I share 63 00:02:58,841 --> 00:02:59,491 Yes. 64 00:03:00,461 --> 00:03:04,491 I w- so recently I've gotten back into watching physical media, right? 65 00:03:04,551 --> 00:03:04,921 Yeah. 66 00:03:05,147 --> 00:03:05,787 and all the rest. 67 00:03:05,831 --> 00:03:06,331 Yeah 68 00:03:06,437 --> 00:03:10,147 I had some which were still sealed for the last, 15 years that had never been 69 00:03:10,377 --> 00:03:10,577 Wow. 70 00:03:12,077 --> 00:03:12,517 Yeah. 71 00:03:12,577 --> 00:03:14,427 that was kinda like me in the wood shop with, 72 00:03:14,477 --> 00:03:14,767 Yeah 73 00:03:14,971 --> 00:03:17,811 some of the, my dust collection, and now that's my new obsession, 74 00:03:17,811 --> 00:03:18,761 is my dust collection. 75 00:03:19,981 --> 00:03:20,221 Yeah. 76 00:03:20,221 --> 00:03:22,351 Anyway, people don't want… They won't, they don't wanna hear about this. 77 00:03:22,361 --> 00:03:24,081 They wanna hear about, Google. 78 00:03:24,103 --> 00:03:24,683 Are you sure? 79 00:03:24,753 --> 00:03:25,243 Are you sure? 80 00:03:25,781 --> 00:03:26,371 yeah. 81 00:03:26,431 --> 00:03:32,761 so this is a, this was, this is another one of those stories where you're like, 82 00:03:33,391 --> 00:03:38,341 "Man," like 'cause it, it's another, living off the land attack where 83 00:03:39,071 --> 00:03:40,711 Wh- what's living off land for our 84 00:03:40,781 --> 00:03:41,261 Yeah. 85 00:03:41,321 --> 00:03:46,541 So basically, living off the land is leveraging, i- is an attack that leverages 86 00:03:46,541 --> 00:03:51,201 y- the tools that you have in your arsenal, against you basically, right? 87 00:03:51,701 --> 00:03:57,101 and, the, what happened here and, so first off, who are we, talking about? 88 00:03:57,481 --> 00:03:59,941 Google's, their threat intelligence group, they have published a really 89 00:03:59,941 --> 00:04:04,531 big report which we'll link, in the show notes, that really detailed, I 90 00:04:04,531 --> 00:04:07,371 have to give them props, that they really detailed what happened here. 91 00:04:07,881 --> 00:04:12,771 It's, it's actually a Chinese, PRC-sponsored attacker, 92 00:04:13,051 --> 00:04:15,861 threat actor called UNC6508. 93 00:04:15,891 --> 00:04:16,521 That is 94 00:04:17,203 --> 00:04:17,393 Is 95 00:04:17,461 --> 00:04:19,861 worst name ever 96 00:04:20,043 --> 00:04:25,021 sometimes they have these Titles, nerd titles, I don't know, labels 97 00:04:25,275 --> 00:04:25,535 yeah. 98 00:04:25,601 --> 00:04:26,431 of these attacks. 99 00:04:26,901 --> 00:04:30,481 But then the same organization, like what we might know externally 100 00:04:30,491 --> 00:04:33,841 as LockBit or we'll take whatever 101 00:04:33,893 --> 00:04:34,413 Yeah. 102 00:04:34,463 --> 00:04:35,283 what's the name of… 103 00:04:35,651 --> 00:04:36,021 ones 104 00:04:36,583 --> 00:04:40,413 Yeah, what's the name of the one, the one that did the last attack that we covered? 105 00:04:40,961 --> 00:04:41,771 Shiny hunters 106 00:04:42,103 --> 00:04:43,123 It was the Canvas. 107 00:04:43,909 --> 00:04:44,189 Go 108 00:04:45,163 --> 00:04:46,883 the, so we didn't cover it, I'm sorry. 109 00:04:47,173 --> 00:04:49,453 It was the last attack you and I talked about. 110 00:04:49,701 --> 00:04:50,231 Yes 111 00:04:50,773 --> 00:04:55,363 and it was the attack of Canvas, which is a learning platform, and, there, 112 00:04:55,393 --> 00:04:58,073 because I saw an article that said it was the same, it was the same group. 113 00:04:58,543 --> 00:05:02,053 I didn't check that, but, Google is calling them UNC6508. 114 00:05:02,473 --> 00:05:06,633 and they targeted mainly, North American institutions, academic, 115 00:05:06,633 --> 00:05:08,663 medical, things like that. 116 00:05:08,693 --> 00:05:16,063 And via this tool, called REDCap, which is a Research Electronic Data Capture, 117 00:05:16,323 --> 00:05:24,113 it's a web-based platform, and, they, th- which has a unique attribute that 118 00:05:24,193 --> 00:05:31,593 allows you to run multiple versions of the software simultaneously. 119 00:05:32,153 --> 00:05:36,043 And so even though you may be upgrading and patching more recent versions 120 00:05:36,043 --> 00:05:40,293 of the software, if there's a, an exploit against an older version of the 121 00:05:40,293 --> 00:05:45,123 software, they, they would be able to do it, and that's what happened here. 122 00:05:45,613 --> 00:05:50,083 And once again, it started with harvested credentials. 123 00:05:50,553 --> 00:05:51,323 we don't know where… 124 00:05:51,791 --> 00:05:52,351 do they get? 125 00:05:53,083 --> 00:05:54,003 they were, it was an admin. 126 00:05:54,003 --> 00:05:58,833 it was an admin's credentials, but the, but again, this is they broke 127 00:05:58,833 --> 00:06:01,173 some of the rules, and we're gonna talk, the meaning the victims. 128 00:06:01,693 --> 00:06:05,123 they, broke some of the rules that, that we talk about, and we're gonna cover 129 00:06:05,123 --> 00:06:09,723 them in the, that, that had they not done that, it would've been a different, 130 00:06:09,743 --> 00:06:11,023 the attack would've been different. 131 00:06:11,453 --> 00:06:15,463 but the scary thing about this is that they put in this, this malware 132 00:06:15,463 --> 00:06:18,893 that's called Infinite, Infinite.red. 133 00:06:19,093 --> 00:06:23,073 it sounds to me like that sounds like it's a s- a specific malware that 134 00:06:23,073 --> 00:06:27,003 they wrote just for REDCap, and it sat there for how long, Prasanna? 135 00:06:28,557 --> 00:06:33,537 It looks like from what I could tell this happened like November 2023 136 00:06:36,375 --> 00:06:36,755 Good. 137 00:06:37,685 --> 00:06:41,465 Yeah, it looks like literally they got in, and then they… 138 00:06:41,515 --> 00:06:43,155 this is we talk about dwell time. 139 00:06:43,165 --> 00:06:48,855 We talk about, just to go back to backups here for a minute, one of the real 140 00:06:48,865 --> 00:06:54,245 problems with these types of attacks is that sometimes having a really good backup 141 00:06:54,385 --> 00:06:57,785 isn't going to be enough because, what… 142 00:06:58,425 --> 00:07:02,705 If they've been in there for over a year, like a year and a half, maybe even more, 143 00:07:03,005 --> 00:07:04,145 probably isn't that far back. 144 00:07:04,685 --> 00:07:05,655 no, right? 145 00:07:05,665 --> 00:07:09,415 You're not gonna, you're not gonna have backups that don't have this. 146 00:07:09,585 --> 00:07:15,115 And they… And what they did was they leveraged these, what do you call it? 147 00:07:15,115 --> 00:07:21,645 v- vulnerable versions of RedCap to harvest their credentials, and 148 00:07:21,645 --> 00:07:24,235 then, and then they somehow… 149 00:07:24,565 --> 00:07:25,645 But wait, go ahead. 150 00:07:25,675 --> 00:07:25,955 Go ahead 151 00:07:26,439 --> 00:07:28,869 But even when they harvest the cred- credentials, it's not 152 00:07:28,869 --> 00:07:29,769 like they wrote it to a file. 153 00:07:29,799 --> 00:07:32,179 They wrote it back to a red capped database, 154 00:07:32,711 --> 00:07:33,221 Yeah. 155 00:07:33,631 --> 00:07:34,121 Yeah. 156 00:07:34,139 --> 00:07:35,159 end product database. 157 00:07:35,261 --> 00:07:35,511 Yeah, 158 00:07:35,589 --> 00:07:36,239 they wrote it to 159 00:07:36,261 --> 00:07:38,711 talk about living off the land, right? 160 00:07:39,291 --> 00:07:45,761 and then they intercepted RedCap's upgrade process, so it then injected this 161 00:07:45,761 --> 00:07:49,071 malware into every new version, right? 162 00:07:49,331 --> 00:07:53,521 even if you were trying to patch things, you would get the new version, right? 163 00:07:53,621 --> 00:07:55,341 It's an interesting question. 164 00:07:55,341 --> 00:07:59,161 I know we talk about patching and, making sure everything's up 165 00:07:59,161 --> 00:08:00,611 to date and having central IT. 166 00:08:01,561 --> 00:08:06,161 Do you think a lot of these issues stem to the, from the fact that these were, 167 00:08:06,821 --> 00:08:14,471 like, IT or software packages targeted at academia and researchers who sometimes 168 00:08:14,471 --> 00:08:15,841 pull things together on their own? 169 00:08:15,841 --> 00:08:19,041 It reminds me of, the shadow IT phenomenon, right? 170 00:08:19,127 --> 00:08:19,277 n- 171 00:08:19,421 --> 00:08:19,681 they're 172 00:08:19,697 --> 00:08:22,947 no, actually, yeah, I don't think so. 173 00:08:22,947 --> 00:08:26,647 From what I'm seeing i- is that, again, we're g- and we're gonna get 174 00:08:26,647 --> 00:08:29,657 to the what could they have done better and what you can do better. 175 00:08:30,247 --> 00:08:34,107 I think just, i- it's not the upgrade process. 176 00:08:34,117 --> 00:08:36,227 it goes back to the harvested credentials. 177 00:08:36,477 --> 00:08:41,027 It goes back to limiting the ability for products to do what they did, 178 00:08:41,097 --> 00:08:46,657 and then we're gonna get to the next thing, which is once they had… 179 00:08:46,707 --> 00:08:50,187 They had been harvesting credentials for a year, right? 180 00:08:50,237 --> 00:08:51,807 for over a year, right? 181 00:08:52,157 --> 00:08:57,067 And then they took some of those credentials, and they tried to log 182 00:08:57,067 --> 00:09:01,257 into other systems, and this is where Google Workspace comes in. 183 00:09:01,807 --> 00:09:06,357 And so what they had was, once they got… They were able to take those 184 00:09:06,367 --> 00:09:09,730 harvested creden- they started with stolen credentials, then they used those 185 00:09:09,730 --> 00:09:11,380 credentials to harvest other credentials. 186 00:09:11,580 --> 00:09:14,660 Then they took those credentials, and they logged into Google Workspace, 187 00:09:15,472 --> 00:09:15,662 Yep. 188 00:09:16,600 --> 00:09:21,500 into, again, valid admin, as a domain admin, and they created 189 00:09:21,500 --> 00:09:23,420 something called compliance rules. 190 00:09:23,760 --> 00:09:25,080 You wanna talk about what those are? 191 00:09:25,712 --> 00:09:26,102 Yeah. 192 00:09:26,122 --> 00:09:30,032 So in an organization, you might have certain compliance requirements which 193 00:09:30,032 --> 00:09:36,612 are, hey, if an email is from this person or to this person, or if it contains 194 00:09:36,622 --> 00:09:40,702 these types of words, then forward it off somewhere else so then it can be secured 195 00:09:40,962 --> 00:09:45,462 and can't be deleted and is protected for compliance auditing other purposes. 196 00:09:46,102 --> 00:09:53,122 And so they created a compliance rule that said if it matched certain keywords 197 00:09:53,852 --> 00:09:56,922 to send it out to a certain email address. 198 00:09:56,952 --> 00:10:02,082 And this was ingenious because it just looked like normal email traffic. 199 00:10:02,092 --> 00:10:05,482 So even if you were trying to detect something, it was like, oh yeah, 200 00:10:05,482 --> 00:10:10,042 this is just part of your normal systems operations and all the rest of 201 00:10:10,192 --> 00:10:10,682 Yeah 202 00:10:10,912 --> 00:10:12,822 address was controlled by the attackers 203 00:10:13,454 --> 00:10:17,524 And they would, and then it would BCC forward the, to a Gmail 204 00:10:17,524 --> 00:10:18,664 address that they owned, right? 205 00:10:18,944 --> 00:10:20,544 The keywords, very interesting. 206 00:10:20,544 --> 00:10:24,944 The keywords, they're talking about geostrategic policy, military strategy, 207 00:10:24,944 --> 00:10:27,534 advanced tech, and specific pathogens. 208 00:10:27,754 --> 00:10:31,594 And by the way, that one was interesting because one pathogen that 209 00:10:31,594 --> 00:10:33,904 they had on the list was chikungunya. 210 00:10:35,404 --> 00:10:38,024 I don't know how to … Chika- You can say that? 211 00:10:38,024 --> 00:10:38,344 Okay. 212 00:10:38,536 --> 00:10:38,796 checking 213 00:10:38,924 --> 00:10:39,974 I've never heard of that before. 214 00:10:40,294 --> 00:10:43,574 So they're saying it's a mosquito-borne viral disease that's 215 00:10:43,574 --> 00:10:45,784 responsible for an outbreak in China. 216 00:10:46,294 --> 00:10:46,854 Yeah. 217 00:10:47,024 --> 00:10:49,114 so interesting, right? 218 00:10:50,024 --> 00:10:50,524 Oh, okay. 219 00:10:50,564 --> 00:10:51,024 Gotcha. 220 00:10:51,034 --> 00:10:52,904 hence your ability to pronounce that word. 221 00:10:52,954 --> 00:10:54,354 I've never even heard of that word before. 222 00:10:54,954 --> 00:10:55,484 anyway. 223 00:10:55,594 --> 00:11:00,854 so they were… So on one hand, you're saying it just looks like normal 224 00:11:00,864 --> 00:11:06,614 email traffic, but, I do think that perhaps somebody could have noticed. 225 00:11:06,614 --> 00:11:09,934 By the way, the rule that they, the compliance rule they created was called 226 00:11:10,004 --> 00:11:12,854 Patriot, which is interesting, right? 227 00:11:12,932 --> 00:11:13,702 Didn't they misspell it? 228 00:11:14,934 --> 00:11:15,584 You're right. 229 00:11:15,804 --> 00:11:19,164 So they did sp- so it's spelled Patriot. 230 00:11:19,654 --> 00:11:22,994 which again, might have been a, might have been a red flag, right? 231 00:11:23,104 --> 00:11:27,704 but, and so the, basically anything that, that met these, the 232 00:11:27,704 --> 00:11:30,454 filters that they were looking for gets forwarded to the bad guys. 233 00:11:31,784 --> 00:11:35,764 And, d- Google, the Google Threat Int- Threat Intelligence 234 00:11:35,764 --> 00:11:36,694 Group, is that what it's called? 235 00:11:37,264 --> 00:11:38,214 Yeah, GTIG 236 00:11:38,674 --> 00:11:39,674 Yeah, GTIG. 237 00:11:40,154 --> 00:11:43,344 they, it says they disrupted the infrastructure, they disabled the 238 00:11:43,344 --> 00:11:47,974 Gmail account, that was being used for exfiltration, and they notified everybody 239 00:11:47,974 --> 00:11:50,144 and published, rules on how to stop this. 240 00:11:50,144 --> 00:11:57,404 But, I always go back to, what could they have done differently, right? 241 00:11:57,484 --> 00:12:01,804 and I don't wanna focus on just this particular account, but I don't think 242 00:12:01,804 --> 00:12:07,864 Red Cap is alone in this idea of having legacy versions being, run side by side. 243 00:12:08,044 --> 00:12:09,944 Can you think of any other products that work like that? 244 00:12:10,682 --> 00:12:10,692 VMware 245 00:12:12,344 --> 00:12:13,794 Oh, yeah. 246 00:12:15,014 --> 00:12:15,474 Yeah. 247 00:12:15,928 --> 00:12:16,108 Right? 248 00:12:16,108 --> 00:12:18,518 'Cause when you were describing RedCap, 249 00:12:18,558 --> 00:12:18,998 Yeah 250 00:12:19,648 --> 00:12:22,238 I was like, "That sounds exactly like a hypervisor." 251 00:12:23,126 --> 00:12:23,446 yeah. 252 00:12:23,446 --> 00:12:23,906 you're right. 253 00:12:24,286 --> 00:12:24,536 Is 254 00:12:24,642 --> 00:12:24,912 and, 255 00:12:25,036 --> 00:12:26,206 thinking or were you gonna give something 256 00:12:26,206 --> 00:12:26,496 else? 257 00:12:26,612 --> 00:12:27,482 no, I wasn't thinking. 258 00:12:28,422 --> 00:12:29,932 My brain was blank. 259 00:12:30,232 --> 00:12:33,462 but yeah, no, that's… I think that's a per- that's a perfect example, right? 260 00:12:33,482 --> 00:12:35,692 where you leave, you leave many versions running. 261 00:12:36,142 --> 00:12:41,912 and so really what they could have done in this case is, again, obviously 262 00:12:42,112 --> 00:12:47,822 general password… we can start with general password, hygiene, right? 263 00:12:47,862 --> 00:12:50,992 The, that if they had been doing normal password hygiene, the 264 00:12:50,992 --> 00:12:53,912 passwords wouldn't have been harvested out there somewhere in the wild. 265 00:12:54,502 --> 00:12:58,182 And then because the initial attack started with, passwords that have 266 00:12:58,182 --> 00:12:59,762 been harvested out somewhere. 267 00:12:59,792 --> 00:13:00,962 they don't know where that happened. 268 00:13:01,312 --> 00:13:04,372 and if that means that they were… somebody was using a username and 269 00:13:04,372 --> 00:13:09,212 password externally, potentially that, that then was used internally. 270 00:13:09,462 --> 00:13:12,172 so if they had good password hygiene, that wouldn't have happened. 271 00:13:12,562 --> 00:13:14,082 The next thing is to not… 272 00:13:14,992 --> 00:13:15,422 Go ahead 273 00:13:15,436 --> 00:13:17,736 I'm surprised you didn't start with the number zero. 274 00:13:17,746 --> 00:13:20,186 What's the first thing that you do before password? 275 00:13:21,036 --> 00:13:23,096 list of three things, if you did these three things, 276 00:13:23,196 --> 00:13:23,866 Oh, patching? 277 00:13:24,786 --> 00:13:25,246 You talking about 278 00:13:25,556 --> 00:13:28,976 And so for patching, I was gonna say inventory management, 279 00:13:29,578 --> 00:13:30,858 Yeah, absolutely. 280 00:13:30,968 --> 00:13:34,108 and you knew what was out there and then you were able to patch 281 00:13:34,108 --> 00:13:37,348 it, you probably may, or you may have avoided some of these issues 282 00:13:37,814 --> 00:13:38,264 Yeah. 283 00:13:38,314 --> 00:13:43,174 and then the big thing with the legacy version, support is to not do that, right? 284 00:13:43,494 --> 00:13:47,334 you don't run things that you don't, at a minimum you disable them. 285 00:13:47,564 --> 00:13:50,894 the best practice is actually to remove the old version completely. 286 00:13:51,224 --> 00:13:52,444 don't leave it sitting around. 287 00:13:53,094 --> 00:13:57,774 so another thing is, to not trust application-level 288 00:13:57,774 --> 00:13:59,664 authentication by itself. 289 00:14:00,204 --> 00:14:04,464 to use something like SSO, this is an important enough thing that you don't 290 00:14:04,494 --> 00:14:11,574 trust the IAM system of just any old, piece of software that you use SSO to 291 00:14:11,574 --> 00:14:13,954 log into important things like REDCap. 292 00:14:14,374 --> 00:14:18,134 and had they done that… A- and by the way, this had, when we go back to 293 00:14:18,134 --> 00:14:22,894 the, we talked about the Canvas hack, same thing there that, I'm currently 294 00:14:22,894 --> 00:14:28,844 talking with a client that they were hit by the Canvas hack, but it was very 295 00:14:28,994 --> 00:14:34,034 minor because they use SSO for the vast majority of accounts when logging into it 296 00:14:35,764 --> 00:14:38,874 One other thing, and I don't know if we've necessarily touched on 297 00:14:38,874 --> 00:14:44,174 it in past episodes, using SSO or a central identity provider, 298 00:14:44,894 --> 00:14:48,144 you can enforce requirements. 299 00:14:48,144 --> 00:14:53,444 So if a password needs to be rotated, do you use MFA, minimum number 300 00:14:53,444 --> 00:14:55,614 or, minimum number of characters? 301 00:14:55,864 --> 00:15:00,734 All the rest of these things you can enforce versus if Redcap had their own 302 00:15:00,734 --> 00:15:04,944 password system and, say, didn't have this functionality, kinda limited. 303 00:15:04,954 --> 00:15:07,344 Maybe someone hasn't changed their password in seven years. 304 00:15:07,534 --> 00:15:07,704 Who 305 00:15:07,884 --> 00:15:10,544 Yeah, or even if it had that functionality, that means you're 306 00:15:10,554 --> 00:15:16,494 managing that functionality in every, SaaS app that you use, right? 307 00:15:16,534 --> 00:15:16,744 Yep. 308 00:15:17,454 --> 00:15:17,774 yeah. 309 00:15:17,854 --> 00:15:18,254 Good point. 310 00:15:18,344 --> 00:15:23,184 you're an organization, you really should have a central password system, 311 00:15:23,922 --> 00:15:24,452 Yes. 312 00:15:24,874 --> 00:15:25,244 system 313 00:15:25,312 --> 00:15:28,122 There's an, entire, there's an entire industry built around 314 00:15:28,122 --> 00:15:29,642 that and, thumbs up to that. 315 00:15:30,302 --> 00:15:32,012 the next one… Go ahead. 316 00:15:32,272 --> 00:15:32,662 What? 317 00:15:32,724 --> 00:15:34,644 I touched on something which I think might be the next one 318 00:15:35,910 --> 00:15:36,310 Okay. 319 00:15:36,650 --> 00:15:37,230 Touch away. 320 00:15:37,310 --> 00:15:37,990 one MFA? 321 00:15:38,150 --> 00:15:38,820 Is it MFA? 322 00:15:38,850 --> 00:15:39,210 It's always 323 00:15:39,270 --> 00:15:39,820 the next… 324 00:15:39,990 --> 00:15:41,230 like it's always DNS 325 00:15:41,930 --> 00:15:43,740 specifically phishing-resistant MFA. 326 00:15:44,720 --> 00:15:45,190 yes. 327 00:15:45,320 --> 00:15:46,500 You wanna talk about what that is? 328 00:15:47,126 --> 00:15:47,436 Yeah. 329 00:15:47,446 --> 00:15:52,176 So like we've talked about, someone can guess your password or steal your 330 00:15:52,176 --> 00:15:53,756 password, like what happened here. 331 00:15:54,226 --> 00:15:57,346 But with MFA or multi-factor authentication, just having 332 00:15:57,346 --> 00:15:58,726 the password isn't enough. 333 00:15:59,086 --> 00:16:04,586 It should also send you a way to authenticate in addition to just knowing 334 00:16:04,586 --> 00:16:05,976 the password, the username and password. 335 00:16:06,316 --> 00:16:10,556 Typically, you see this as, a code that shows up on your phone. 336 00:16:10,826 --> 00:16:14,196 email is not great, SMS is not great, but it's better than nothing. 337 00:16:14,636 --> 00:16:14,756 but 338 00:16:14,756 --> 00:16:15,186 you really 339 00:16:15,186 --> 00:16:17,166 should be using like a one-time password 340 00:16:17,842 --> 00:16:18,192 Yes 341 00:16:18,196 --> 00:16:18,526 there. 342 00:16:18,596 --> 00:16:19,806 Many versions are out there. 343 00:16:19,806 --> 00:16:21,316 So that helps. 344 00:16:21,346 --> 00:16:24,806 And then the other thing that you mentioned, Curtis, is phishing-resistant, 345 00:16:25,816 --> 00:16:30,656 So you wanna make sure that someone doesn't go and steal your, MFA 346 00:16:30,656 --> 00:16:34,996 token and then start to use it, that you do have … I know we've 347 00:16:35,016 --> 00:16:36,476 talked about this in past episodes. 348 00:16:36,936 --> 00:16:40,326 There's this notion of MFA fatigue, right? 349 00:16:40,346 --> 00:16:43,866 Where people constantly keep pinging you, being like, "Is this you? Is 350 00:16:43,866 --> 00:16:46,716 this you?" And then you click yes because you're tired of saying 351 00:16:46,726 --> 00:16:48,116 no and responding all the time. 352 00:16:48,576 --> 00:16:49,606 So you want 353 00:16:49,606 --> 00:16:50,146 something that 354 00:16:50,146 --> 00:16:51,756 is more resilient to those. 355 00:16:52,424 --> 00:16:56,664 I think the big thing with truly phishing-resistant MFA is that MFA 356 00:16:56,674 --> 00:16:59,044 that is tied to something, right? 357 00:16:59,054 --> 00:17:03,214 The ph- it's tied to a security key, it's tied to a particular location, 358 00:17:03,224 --> 00:17:07,184 it's tied to a particular device, so that even if, a- again, just 359 00:17:07,184 --> 00:17:08,754 the… It's MFA for the MFA, right? 360 00:17:09,064 --> 00:17:13,624 That, that, that if they steal a session cookie, which is what was happening here, 361 00:17:13,634 --> 00:17:17,914 they were stealing session cookies, then they wouldn't be able to just replay 362 00:17:17,914 --> 00:17:21,574 that because the system would notice that it was coming from other place. 363 00:17:21,574 --> 00:17:21,864 Yeah. 364 00:17:21,964 --> 00:17:22,284 Yeah. 365 00:17:22,598 --> 00:17:22,768 Yeah. 366 00:17:22,774 --> 00:17:28,004 and then of course you can and should investigate, passkeys, right? 367 00:17:28,004 --> 00:17:32,714 and again, the beautiful thing about passkeys is that it solves all of this and 368 00:17:32,714 --> 00:17:35,254 it's, they're tied to a location, right? 369 00:17:35,346 --> 00:17:36,056 What's a passkey? 370 00:17:37,144 --> 00:17:37,704 thank you. 371 00:17:37,714 --> 00:17:40,784 So a passkey is basically a complete replacement for passwords 372 00:17:40,804 --> 00:17:42,884 and, MFA, and it's basically a… 373 00:17:43,064 --> 00:17:47,764 Think of it as a locally stored, I was gonna say password, but it is a key that 374 00:17:47,764 --> 00:17:51,324 is stored locally with the device that you have, that is tied to that device and 375 00:17:51,364 --> 00:17:55,854 tied to that account, and it's basically played on your behalf, whenever you 376 00:17:55,874 --> 00:17:57,394 need to log into that, that account. 377 00:17:57,774 --> 00:18:02,684 So passkeys fall under what's called FIDO, which is Fast Identity Online, 378 00:18:03,134 --> 00:18:05,774 and the common thing that is stated… 379 00:18:05,794 --> 00:18:13,204 There are multiple, there are many known attacks for passwords in MFA, 380 00:18:14,114 --> 00:18:17,314 and you taught, you touched on one of them, which is the concept of, 381 00:18:17,524 --> 00:18:21,094 becoming, an MFA fatigue attack, where they send you so many things 382 00:18:21,104 --> 00:18:22,314 that you accept one of them, right? 383 00:18:22,644 --> 00:18:25,444 And then they take the accepted one, and then they go do bad things, right? 384 00:18:25,774 --> 00:18:31,644 there are known, there are no known attacks against FIDO-compliant passkeys. 385 00:18:31,934 --> 00:18:36,894 So if you're not doing them everywhere you believe you can be doing them, you 386 00:18:36,894 --> 00:18:38,784 should be investigating that right now. 387 00:18:39,074 --> 00:18:42,644 if y- if you're familiar with that and you're working your way, I would just 388 00:18:42,644 --> 00:18:44,404 say prioritize that wherever you can. 389 00:18:44,724 --> 00:18:48,074 if you don't know anything about it, then, you should be looking into passkeys, 390 00:18:48,594 --> 00:18:53,224 One of the things that GTIG pushed, in terms of what could have helped here 391 00:18:53,564 --> 00:18:59,124 is the concept of device-bound session credentials and context-aware access. 392 00:18:59,434 --> 00:19:01,534 And w- we talked about this a little bit. 393 00:19:01,894 --> 00:19:06,814 Context-aware access, if you enable that on an account, it's going to do things 394 00:19:06,814 --> 00:19:11,764 like, why is this coming from a different place than it was 30 seconds ago, right? 395 00:19:12,184 --> 00:19:14,454 and why is it coming from this IP address? 396 00:19:14,474 --> 00:19:15,734 Why is it coming from this country? 397 00:19:15,734 --> 00:19:17,284 I thought this person was in California. 398 00:19:17,594 --> 00:19:17,944 Whatever. 399 00:19:17,944 --> 00:19:19,244 It's a context, right? 400 00:19:19,244 --> 00:19:22,814 A con- and every time you go to access, it's gonna check that context. 401 00:19:23,154 --> 00:19:27,614 And then you have the device-bound session credentials, or DBSC, and 402 00:19:27,614 --> 00:19:29,844 what they do is, they're tying each… 403 00:19:29,984 --> 00:19:34,524 'Cause when you authenticate with a, a browser, that creates a session, 404 00:19:34,894 --> 00:19:40,804 and if you're using DBSC, those credentials only work in that session 405 00:19:40,824 --> 00:19:42,354 and they tie it to that device. 406 00:19:42,354 --> 00:19:45,804 It's a little bit like passkeys in that regard, and Google is just 407 00:19:45,804 --> 00:19:49,274 talking about these especially for highly sensitive accounts. 408 00:19:49,594 --> 00:19:53,834 If you turn on these two features, it would tie, once you authenticate, 409 00:19:53,834 --> 00:19:57,664 it would tie that authentication to that session, and then context-aware 410 00:19:57,664 --> 00:20:01,144 access would check that, so the two work together hand-in-hand. 411 00:20:01,154 --> 00:20:07,524 And what that meant was if and when someone, like this malware, steals 412 00:20:07,574 --> 00:20:12,104 your session credentials, they wouldn't be able to use those anywhere else 413 00:20:12,398 --> 00:20:12,648 Yeah. 414 00:20:12,848 --> 00:20:17,378 And specifically, this is the case where they're not just stealing 415 00:20:17,388 --> 00:20:19,248 your password, but they're actually 416 00:20:19,258 --> 00:20:20,848 stealing, say, your browser cookie 417 00:20:21,306 --> 00:20:26,026 your cookie and trying to replay and reuse your cookie on a different device. 418 00:20:26,508 --> 00:20:26,848 Right 419 00:20:26,956 --> 00:20:30,096 By using device-bound session credentials, you're guaranteed that 420 00:20:30,106 --> 00:20:33,186 even if they stole that session cookie, it's not gonna be usable anywhere else 421 00:20:33,878 --> 00:20:37,128 again, it's specifically something that, that they, talked about, 422 00:20:37,348 --> 00:20:38,428 or that Google talked about. 423 00:20:38,998 --> 00:20:43,298 so the next is this idea of compliance rules, and they're not… Th- this is, 424 00:20:43,358 --> 00:20:45,038 that's what Google Workspace calls it. 425 00:20:45,048 --> 00:20:50,628 Every system has something like this, and the idea is look at any 426 00:20:50,648 --> 00:20:52,608 standing rules that are there. 427 00:20:52,888 --> 00:20:55,178 In a large company, you may have tons of them. 428 00:20:55,478 --> 00:20:58,038 This is where I think AI can be helpful here. 429 00:20:58,698 --> 00:21:03,958 Look for things that are created that are forwarding email out to 430 00:21:03,978 --> 00:21:06,658 especially external accounts, right? 431 00:21:07,016 --> 00:21:07,336 Didn't you 432 00:21:07,378 --> 00:21:08,258 that's what's- 433 00:21:08,876 --> 00:21:11,826 anytime something gets touched in these compliance rules? 434 00:21:12,618 --> 00:21:12,998 yeah. 435 00:21:12,998 --> 00:21:13,848 A- agreed, right? 436 00:21:13,958 --> 00:21:15,878 Ha- have a compliance rule for the compliance rule. 437 00:21:16,048 --> 00:21:21,318 that anything that's a new compliance rule, th- it should trigger some sort of 438 00:21:21,318 --> 00:21:23,088 event so that you can then go check that. 439 00:21:23,138 --> 00:21:24,618 That's a great, that's a great point. 440 00:21:24,938 --> 00:21:29,098 So then the next one they recommend is something you might think 441 00:21:29,098 --> 00:21:33,388 is obvious, but I guess a lot of people get this incorrect. 442 00:21:33,398 --> 00:21:36,738 It's separating your credentials across security domains. 443 00:21:36,748 --> 00:21:42,388 So as we looked at this case, RedCap, one security domain, Google Workspace, another 444 00:21:42,388 --> 00:21:47,758 security domain, the two streams shall never cross, and yet someone used the same 445 00:21:47,758 --> 00:21:53,378 credentials across the two, and that's what sort of allowed a breach of RedCap to 446 00:21:53,378 --> 00:21:56,228 now impact their Google Workspace account. 447 00:21:57,000 --> 00:21:57,350 Right 448 00:21:57,398 --> 00:22:02,328 really should be keeping credentials separate if they need, if they don't need 449 00:22:02,338 --> 00:22:08,098 to be common, or using SSO or an identity provider which deals with all of this for 450 00:22:08,098 --> 00:22:09,428 you so you don't have to worry about it. 451 00:22:10,476 --> 00:22:13,676 Yeah, or also PAM, so privileged access management, right? 452 00:22:14,136 --> 00:22:14,966 and go ahead 453 00:22:15,578 --> 00:22:17,128 Would… Here's a question for you, Curtis. 454 00:22:17,674 --> 00:22:18,044 Yeah 455 00:22:18,128 --> 00:22:21,308 this comes up a lot of times when we talked about backup systems, how keep 456 00:22:21,318 --> 00:22:24,386 backup systems separate than your production systems, from a credential 457 00:22:24,386 --> 00:22:26,606 management, active directory perspective. 458 00:22:27,496 --> 00:22:33,776 When a company is using SSO, say O- Okta or someone else like that, 459 00:22:36,336 --> 00:22:42,346 do you think it is important to still think about these security domains and 460 00:22:42,346 --> 00:22:50,246 so have a different SSO user for Red Cap versus their Google Workspace account, 461 00:22:50,256 --> 00:22:55,546 or is that overkill since you have Okta providing some of that control? 462 00:22:55,656 --> 00:22:59,676 W- yeah, when it comes to admin accounts, I don't think there is 463 00:22:59,686 --> 00:23:01,756 such a thing as overkill, right? 464 00:23:01,946 --> 00:23:05,066 I think you, you need to treat admin accounts differently. 465 00:23:05,416 --> 00:23:08,236 perhaps you do one thing for, regular users. 466 00:23:08,436 --> 00:23:13,436 And again, going back to the client that I was talking about, that they, 467 00:23:13,606 --> 00:23:17,986 the reason why they were only, they used SSO for all the normal users, 468 00:23:18,006 --> 00:23:19,656 but admin accounts were separate. 469 00:23:19,856 --> 00:23:21,506 so I think that is, that is important. 470 00:23:21,736 --> 00:23:25,386 You can use SSO to layer on top of that, right? 471 00:23:25,396 --> 00:23:26,606 So that they work together. 472 00:23:26,896 --> 00:23:31,126 But I think, I still think you need to, keep that separate for the, for all 473 00:23:31,126 --> 00:23:32,456 the reasons that we just talked about. 474 00:23:33,676 --> 00:23:39,326 and then the next thing, we talk about here is get some logging, man. 475 00:23:40,056 --> 00:23:45,636 Some sort of XDR, some sort of SIEM, some sort of, some sort of monitoring going on, 476 00:23:46,776 --> 00:23:49,906 looking for the kind of things that were happening here, because they had to be 477 00:23:49,916 --> 00:23:57,956 sending a butt ton of sensitive e- email out to external accounts, for a really 478 00:23:57,956 --> 00:24:00,526 long time, and, nobody seemed to catch it. 479 00:24:00,666 --> 00:24:03,076 I don't, that, that's quite disconcerting 480 00:24:03,322 --> 00:24:08,482 did they say when they actually breached Google Workspace? 481 00:24:09,612 --> 00:24:10,112 'Cause I know 482 00:24:10,200 --> 00:24:11,330 I, it was towards the end. 483 00:24:11,420 --> 00:24:12,810 It was towards the end of the attack. 484 00:24:13,280 --> 00:24:13,590 Yeah. 485 00:24:14,540 --> 00:24:16,660 It was the last thing they did after they'd been harvesting 486 00:24:16,660 --> 00:24:17,960 credentials for over a year 487 00:24:18,720 --> 00:24:18,930 Yeah. 488 00:24:20,384 --> 00:24:20,714 Yeah. 489 00:24:20,750 --> 00:24:21,260 Crazy 490 00:24:22,134 --> 00:24:22,754 Crazy. 491 00:24:22,854 --> 00:24:23,774 So here's a question. 492 00:24:23,774 --> 00:24:25,564 So we talked about this, right? 493 00:24:25,594 --> 00:24:27,324 And things you could do to prevent attacks. 494 00:24:28,274 --> 00:24:36,914 Given the name of the podcast, is there anything that you would think 495 00:24:37,028 --> 00:24:37,368 Did we forget something? 496 00:24:37,464 --> 00:24:42,674 from a data protection, data recovery perspective, from a 497 00:24:42,674 --> 00:24:46,174 cyber recovery perspective they could have, should have done? 498 00:24:46,644 --> 00:24:49,604 Or is this even if you had the most amazing 499 00:24:51,644 --> 00:24:57,484 cyber recovery plan in place, you didn't do any of these basics, you're hosed 500 00:25:00,240 --> 00:25:05,180 I don't think, this is one of the situations where I'm not sure how much 501 00:25:05,190 --> 00:25:07,230 backups would have actually helped, right? 502 00:25:07,820 --> 00:25:11,960 Because it, you do need, obviously, you, you're never gonna be saying 503 00:25:12,190 --> 00:25:13,880 you don't need backups, right? 504 00:25:14,310 --> 00:25:18,150 one of the things we talk a lot about is just please, for the love 505 00:25:18,150 --> 00:25:23,130 of everything, please make sure that you have regular, automated backups 506 00:25:23,180 --> 00:25:28,450 of everything that are on a sec- separate security domain, and also that 507 00:25:28,490 --> 00:25:31,170 use truly immutable backups, right? 508 00:25:31,670 --> 00:25:34,395 That i- you, 'cause the worst thing is when you hear something 509 00:25:34,395 --> 00:25:37,495 like this, and then you see that the backups were also impacted. 510 00:25:38,305 --> 00:25:43,495 The downside here is that backups quite possibly aren't going to 511 00:25:43,505 --> 00:25:46,645 help you because d- two things. 512 00:25:46,655 --> 00:25:51,645 One is, many people don't store their backups longer than the amount of time 513 00:25:51,645 --> 00:25:54,085 that this attack took, number one. 514 00:25:54,285 --> 00:25:57,285 Number two, what are you going to recover? 515 00:25:57,825 --> 00:26:02,355 Are you going to literally, like you found out that they first compromised 516 00:26:02,355 --> 00:26:03,905 your system a year and a half ago. 517 00:26:03,905 --> 00:26:08,875 Are you going to restore your database to a year and a half ago? 518 00:26:08,885 --> 00:26:10,285 You're not going to do that. 519 00:26:10,815 --> 00:26:15,875 so the related topic here is, from a system standpoint, one of the 520 00:26:15,875 --> 00:26:18,725 things that we came to in the book, which we haven't mentioned the book. 521 00:26:18,775 --> 00:26:21,105 if you're not familiar with the book, that should be over my, 522 00:26:21,515 --> 00:26:22,875 right shoulder in your view. 523 00:26:22,925 --> 00:26:25,795 if you're watching this, it's my left shoulder, but it's 524 00:26:25,805 --> 00:26:27,125 right in the video, right? 525 00:26:27,505 --> 00:26:28,655 I think I'm pointing right. 526 00:26:28,865 --> 00:26:30,765 Yeah, it's to my right in the video. 527 00:26:31,275 --> 00:26:34,385 Anyway, the, is, Learning Ransomware Response and Recovery, 528 00:26:34,385 --> 00:26:35,855 which, I wrote with, Dr. 529 00:26:35,855 --> 00:26:38,665 Mike Saylor, who is a frequent podcast, guest. 530 00:26:39,185 --> 00:26:41,955 that, Dang it, I lost my train of thought. 531 00:26:41,985 --> 00:26:44,265 We were talking about the… Oh. 532 00:26:45,893 --> 00:26:50,403 So you really have to approach backup a- as two things. 533 00:26:51,563 --> 00:26:59,223 We really came to the r- reality that th- there, there were three ways to 534 00:26:59,243 --> 00:27:01,473 restore after something like this. 535 00:27:01,483 --> 00:27:08,333 One is to just restore back to a point in time before you, you know that you 536 00:27:08,333 --> 00:27:14,063 were attacked, and that's like the last thing we want you to do, actually, i- in 537 00:27:14,063 --> 00:27:18,973 terms of restoring the operating system and the applications, because it's really 538 00:27:18,973 --> 00:27:22,793 hard to know when that point is, and it's really easy to reinfect your systems. 539 00:27:23,323 --> 00:27:24,583 So that's one method. 540 00:27:25,063 --> 00:27:30,273 The other is this idea of, restore and then go in and surgically 541 00:27:30,273 --> 00:27:34,873 clean each system before you release it to the public, right? 542 00:27:35,433 --> 00:27:40,813 And that is better than just knowingly restoring, without doing any cleaning. 543 00:27:41,173 --> 00:27:44,393 But again, it still could be really difficult to find some 544 00:27:44,393 --> 00:27:46,123 of this very pesky malware. 545 00:27:46,123 --> 00:27:49,053 You talk about the malware here that could- kept reinfecting. 546 00:27:49,063 --> 00:27:52,303 Sometimes the malware will be, in the firmware, and it will 547 00:27:52,683 --> 00:27:54,693 reinfect you after a reboot. 548 00:27:55,153 --> 00:28:00,623 So really, I think the only real method here isn't just, I guess it's 549 00:28:00,623 --> 00:28:05,563 technically backups, but it's really an automated, like infrastructure as 550 00:28:05,583 --> 00:28:08,823 code type environment, where what… 551 00:28:08,833 --> 00:28:14,133 you know what your… when we talk about VMs and applications, you know what 552 00:28:14,133 --> 00:28:17,333 version of the OS you're running, you know what version of the app you're running. 553 00:28:17,603 --> 00:28:20,813 You should be able to push a button and boom, you have a new 554 00:28:20,833 --> 00:28:24,783 VM of that from a trusted source 555 00:28:24,937 --> 00:28:25,117 yeah 556 00:28:25,153 --> 00:28:29,543 that is, that was created when you first made that system. 557 00:28:29,543 --> 00:28:31,063 This isn't something you're backing up. 558 00:28:31,423 --> 00:28:36,493 So what you're backing up is the application data, the database and, 559 00:28:36,513 --> 00:28:42,703 and the documents and all of that stuff, and then you, when it's time 560 00:28:42,703 --> 00:28:49,913 to, to rebuild, you rebuild the OS and the application, and then you restore 561 00:28:50,123 --> 00:28:52,293 the actual data for that application. 562 00:28:52,633 --> 00:28:55,693 And generally speaking, the data itself won't be infected. 563 00:28:56,023 --> 00:28:56,353 Go ahead. 564 00:28:56,483 --> 00:28:57,263 I have a question for you. 565 00:28:57,753 --> 00:28:58,093 Yeah 566 00:28:58,423 --> 00:29:06,273 Do you know, and maybe this is also a Dr. Mike question, any ransomware actors 567 00:29:06,273 --> 00:29:08,253 who have attacked the Golden Images? 568 00:29:10,635 --> 00:29:12,325 I am not aware of any, right? 569 00:29:12,375 --> 00:29:15,785 I would I think I would argue… You mean the actual s- so 570 00:29:15,935 --> 00:29:17,465 where the images are stored? 571 00:29:18,503 --> 00:29:22,123 in the sense of if they infected the golden image, right? 572 00:29:22,163 --> 00:29:23,763 The, like you said in your 573 00:29:24,055 --> 00:29:26,455 Like a supply side type attack, basically. 574 00:29:26,465 --> 00:29:26,485 Yeah 575 00:29:26,923 --> 00:29:27,283 right? 576 00:29:27,283 --> 00:29:28,513 Or it during the attack, yeah. 577 00:29:28,513 --> 00:29:32,843 If they, if they infected those images as you're trying to recover 578 00:29:33,083 --> 00:29:35,363 and rebuild, like you said, right? 579 00:29:35,383 --> 00:29:39,453 Rebuild the OS and everything else, you're basically reinfecting yourself. 580 00:29:39,653 --> 00:29:40,213 Now, hopefully 581 00:29:40,279 --> 00:29:40,589 Yeah. 582 00:29:40,613 --> 00:29:42,743 testing those as well before they 583 00:29:42,929 --> 00:29:43,249 Yeah 584 00:29:43,463 --> 00:29:46,223 them during rebuild, but maybe that's something 585 00:29:46,543 --> 00:29:52,483 yeah, I, that's, I, it's a good risk to think about and I guess, in my mind, 586 00:29:53,333 --> 00:29:59,973 any golden image is stored either on worm media or on, immutable… Like 587 00:29:59,973 --> 00:30:05,993 worm media like a DVD-type situation or on truly immutable storage. 588 00:30:06,333 --> 00:30:09,543 But because again, you gotta think of it like a backup. 589 00:30:09,893 --> 00:30:13,333 you gotta make sure that there's no way they can attack it, right? 590 00:30:13,689 --> 00:30:13,839 And 591 00:30:13,903 --> 00:30:16,583 so this is something that you're creating right in the very beginning. 592 00:30:16,899 --> 00:30:17,229 Yeah. 593 00:30:17,283 --> 00:30:17,493 ahead 594 00:30:17,569 --> 00:30:20,999 do wonder how many people actually think about that, 'cause 595 00:30:21,069 --> 00:30:21,929 I don't think they do 596 00:30:21,989 --> 00:30:24,039 until you were actually just talking through it and 597 00:30:24,633 --> 00:30:24,923 Yeah. 598 00:30:26,333 --> 00:30:29,323 Yeah, you have to think about it like a backup, and that backup has to be stored 599 00:30:29,323 --> 00:30:31,863 in a way that no one can ever get to it. 600 00:30:31,863 --> 00:30:36,603 And again, my standard there is if you can't delete it even 601 00:30:36,603 --> 00:30:38,513 if you want to, then I'm happy. 602 00:30:38,893 --> 00:30:41,323 If it's anything less than that, I'm not so happy. 603 00:30:41,763 --> 00:30:43,593 and there are a bunch of ways to do that, right? 604 00:30:43,593 --> 00:30:48,463 You c- there are truly immutable storage platforms that even you can't delete. 605 00:30:48,473 --> 00:30:49,673 There's different modes. 606 00:30:49,963 --> 00:30:53,353 sometimes you'll see compliance mode and retention mode. 607 00:30:53,623 --> 00:30:55,663 you want the more restrictive of the two. 608 00:30:55,663 --> 00:31:01,293 Again, the standard is i- if you can't delete it, even if you want to, then, 609 00:31:01,563 --> 00:31:03,753 then that's what you want, right? 610 00:31:04,023 --> 00:31:06,703 and, you could also do that with worm tape, and you could 611 00:31:06,703 --> 00:31:10,633 do it with worm, optical media, one of which we'd covered here. 612 00:31:10,693 --> 00:31:11,663 M-Disk, right? 613 00:31:11,683 --> 00:31:13,733 the media that's meant to be around forever. 614 00:31:13,733 --> 00:31:15,593 I wanna see hackers attack that. 615 00:31:15,883 --> 00:31:16,523 good luck with that. 616 00:31:17,641 --> 00:31:18,291 It's a, called a 617 00:31:21,491 --> 00:31:21,571 blowtorch. 618 00:31:21,591 --> 00:31:22,291 Which is what I was saying. 619 00:31:22,301 --> 00:31:28,641 Unless, like the only way you can this media is, like you said, if you 620 00:31:28,641 --> 00:31:30,141 have physical access, all bets are off 621 00:31:32,441 --> 00:31:33,551 Yeah, you, yeah. 622 00:31:33,691 --> 00:31:36,591 That, that's true with any element of cybersecurity, right? 623 00:31:36,941 --> 00:31:41,161 so you, that's why physical access is, paramount. 624 00:31:41,491 --> 00:31:44,281 and I go back to the best that I've ever seen there, where it 625 00:31:44,281 --> 00:31:48,531 took multiple layers to, to get, to just to get in the building. 626 00:31:48,551 --> 00:31:49,081 I remember 627 00:31:49,111 --> 00:31:49,301 Yeah. 628 00:31:49,371 --> 00:31:54,651 I did this a couple years ago with a client where it took a half hour just to 629 00:31:54,661 --> 00:31:57,071 get in the building, and then once you were in the building, you were monitored, 630 00:31:57,361 --> 00:31:59,761 because physical access is king, right? 631 00:31:59,931 --> 00:32:03,421 all thanks again for, chatting about, one of my favorite topics 632 00:32:04,007 --> 00:32:04,447 I know. 633 00:32:04,447 --> 00:32:05,527 I love these topics. 634 00:32:05,527 --> 00:32:05,957 Come on. 635 00:32:06,829 --> 00:32:07,809 I was talking about woodworking 636 00:32:08,757 --> 00:32:09,007 Oh. 637 00:32:10,777 --> 00:32:13,357 I'm glad to see at least you're using the tool which I 638 00:32:13,377 --> 00:32:15,057 guilt-tripped you into buying, so 639 00:32:15,989 --> 00:32:17,509 Yeah, it was a lot of fun. 640 00:32:17,539 --> 00:32:21,659 I made, for a preschool that I work with, I made these, plexiglass 641 00:32:21,669 --> 00:32:25,159 windows that were… I m- I made window frames, out of two-by-threes. 642 00:32:25,615 --> 00:32:25,895 Yeah 643 00:32:26,049 --> 00:32:28,899 They were, yeah, two-by-four plexiglass window frames. 644 00:32:28,899 --> 00:32:33,229 I made seven of them, and they were incredibly inexpensive because I 645 00:32:33,249 --> 00:32:34,719 did them with all of my own tools. 646 00:32:34,719 --> 00:32:36,349 And, yeah, it was very cool. 647 00:32:37,059 --> 00:32:37,489 All right. 648 00:32:37,519 --> 00:32:38,949 folks, thanks for listening. 649 00:32:38,959 --> 00:32:41,009 if you didn't listen, why would we even do this? 650 00:32:41,069 --> 00:32:42,419 that is a wrap 651 00:32:45,313 --> 00:32:50,013 The Backup Wrap Up is written, recorded, and produced by me, W. Curtis Preston. 652 00:32:50,603 --> 00:32:55,363 If you need backup or DR consulting, content generation, or expert witness 653 00:32:55,363 --> 00:32:58,163 work, check out backupcentral.com. 654 00:32:58,673 --> 00:33:01,733 You can also find links for my O'Reilly books on the same website. 655 00:33:02,463 --> 00:33:06,433 Remember, this is an independent podcast, and any opinions that 656 00:33:06,433 --> 00:33:10,403 you hear are those of the speaker and not necessarily an employer. 657 00:33:11,273 --> 00:33:11,933 Thanks for listening