Stop 90% of Ransomware Attacks with Basic Cyber Hygiene

Basic cyber hygiene — patch management, password management, and MFA — is responsible for stopping roughly 90% of the ransomware attacks that could hit your organization. This episode is the overview: what those three things are, why they matter, and what happens when you skip them.
WannaCry infected over 200,000 systems worldwide. A patch existed. People just hadn't applied it. Rackspace lost an entire business line — not because the attack was sophisticated, but because a workaround gave them false confidence and they delayed a critical patch. These aren't edge cases. They're the rule.
Dr. Mike Saylor (Black Swan Cybersecurity) and Prasanna Malaiyandi join me to walk through the three pillars of basic cyber hygiene. We cover patch management first — and before you can even patch, you have to know what you have. Inventory is the starting point. Then we get into passwords: why reusing them is a numbers game the bad guys always win, and why a password manager isn't optional anymore. Finally, MFA — what it is, which forms are actually worth using, and why "remember this device" is quietly defeating the whole point.
This is an overview episode. We're going deeper on each pillar in three follow-up episodes. But if you're not doing these three things today, stop reading this and go do them. There's no point talking about EDR, XDR, or any other three-letter security product if you haven't nailed the basics first. It's like researching a Roth IRA when you don't have a savings account.
Chapters:
0:00 Intro
0:59 Welcome & Introductions
4:20 WannaCry: The Patch That Would Have Saved 200,000 Systems
7:33 Rackspace: When a Workaround Isn't Enough
12:12 Defining Basic Cyber Hygiene
14:53 Why These Three Things Stop 90% of Ransomware
17:54 Pillar 1: Patch Management
23:55 Pillar 2: Password Management
31:55 Pillar 3: MFA & Passkeys
37:34 Wrap-Up & What's Next
Most ransomware attacks succeed for one reason, somebody skipped the
Speaker:basics, patch management, password management, MFA or pass keys.
Speaker:These three things, do those right and you stop roughly 90% of the attacks.
Speaker:This week, Dr. Mike Saylor, Prasanna and I walk through each one,
Speaker:what it is, why it matters, and what happens when you ignore it.
Speaker:Things like WannaCry, Rackspace.
Speaker:These, stories are all real, and the lesson is the same every time.
Speaker:The basics weren't done.
Speaker:You don't need a massive budget or a fancy security stack to stop most hackers.
Speaker:You just need to do the boring stuff.
Speaker:Here we turn admins into cyber recovery heroes.
Speaker:This is the Backup Wrap Up
Speaker:Welcome to the backup wrap up.
Speaker:I'm your host, w Curtis Preston, AKA, Mr. Backup, and I have with
Speaker:me, a guy who apparently shaved last week and I didn't even notice.
Speaker:Prasanna, Prasanna Malaiyandi, how's it going?
Speaker:Prasanna.
Speaker:I am good Curtis.
Speaker:Yeah.
Speaker:my wife was very surprised after the podcast recording when she
Speaker:was like, did Curtis notice?
Speaker:of course, I. I texted you and you're like, no, or no, I think
Speaker:No.
Speaker:on the phone and you're like, no, what are you talking about?
Speaker:Yeah.
Speaker:and apparently Mike didn't notice either, so I feel somewhat better, but, yeah.
Speaker:So you've gone down to the goatee,
Speaker:Yep.
Speaker:many, many years since I've done this.
Speaker:I've seen a picture of you with the goatee.
Speaker:yeah.
Speaker:I think you should go back to your cut from college.
Speaker:That's what I think.
Speaker:The buzz cut.
Speaker:Yeah.
Speaker:I'd love to see you in the buzz cut again.
Speaker:Walked away.
Speaker:speaking of buzz cuts, Dr. Mike Sailor, how's it going, Mike?
Speaker:Going Good guys.
Speaker:It's going good.
Speaker:All right.
Speaker:So he of course, is the co-author on, learning Ransomware Response and
Speaker:Recovery, which came out last month.
Speaker:Which, uh, do you have one with you now?
Speaker:Did you, did you prepare this time?
Speaker:I did not prepare this time.
Speaker:I have yet I still don't have mine and I have yet to actually see the
Speaker:a physical printed book even like a video of a physical printed book with
Speaker:the book is gonna be the size of the thing in your background?
Speaker:Curtis?
Speaker:yeah I would dear Lord I hope not And you know what's funny is like in on the
Speaker:camera this thing looks fine but this is like this far back from me right And so
Speaker:this thing is I think it's 15 by 24 That thing is massive so yeah I surely hope not
Speaker:For those
Speaker:but
Speaker:watch us on YouTube, we do have videos out, but Curtis was just
Speaker:pointing at the title page?
Speaker:The front
Speaker:It's the cover the front cover Yeah yeah yeah And uh available at uh
Speaker:So or you can order them directly from O'Reilly for the record if you order
Speaker:directly from O'Reilly Mike and I make more um So uh there's that All right
Speaker:we're gonna talk so we're gonna jump into this week we're gonna talk about
Speaker:the title It's gonna sound I I never know exactly what the title's gonna
Speaker:be but it's gonna be something along the lines of stop 90 of the ransomware
Speaker:attacks that could possibly happen to you That's a really long title but I it
Speaker:may sound like a bold claim but I think it's pretty straightforward And Mike I'd
Speaker:like to start out this week What's that
Speaker:before you
Speaker:Yeah
Speaker:can I make a bold claim?
Speaker:claim
Speaker:A
Speaker:please
Speaker:That you can stop a hundred percent of ransomware if you
Speaker:never do anything online.
Speaker:not, I think there's still some room there for infection.
Speaker:if they do the the drop the one that we covered in the what do
Speaker:you call it when we did the MR Robot remember the drop USB stick
Speaker:Oh, that's
Speaker:Tchotchke drops.
Speaker:Yeah what's that
Speaker:you win.
Speaker:We call 'em tchotchke drops.
Speaker:Tchotchke drops Yeah Yeah So even then but what is this not do things online
Speaker:thing that you're talking about I don't know what in the world I don't even know
Speaker:Like saying you can't get sick if you don't go outside.
Speaker:that's not true either.
Speaker:Exactly all right Mike do you have a story to start us out with this week
Speaker:man, there's so many to pick from, but, from the book, we talk about WannaCry.
Speaker:and similar to kinda what we touched on here, good hygiene
Speaker:can prevent a lot of stuff.
Speaker:And I think WannaCry is an example of bad guys identified of a
Speaker:vulnerability that was out there.
Speaker:They created a. a payload and a, and an attack vector to take advantage of that,
Speaker:realizing that, there's a very large percentage of, company and organization
Speaker:populations that don't have a solid patch management program or, that it's pretty
Speaker:lax, there's a lot of organizations that, that say we have a patch program,
Speaker:but it's, 2, 3, 4 months behind, or it's gotta meet certain criteria
Speaker:and some things never get patched.
Speaker:that's what happened with WannaCry.
Speaker:found a vulnerability,
Speaker:For those of us that haven't lived the cyber world Why don't you tell us what
Speaker:was want Tory What did it make you want to cry Is that why it was called
Speaker:that And what when did it happen and
Speaker:I was
Speaker:I think there was about 200,000,
Speaker:Yeah.
Speaker:200,000 people crying in unison,
Speaker:exactly
Speaker:with WannaCry.
Speaker:I was going to say Curtis, that because there have been so many of these
Speaker:attacks over the years, it's also hard to keep like, which keep it straight
Speaker:in terms of like which one was which.
Speaker:So why don't you tell us the story of WannaCry Mike
Speaker:WannaCry, was developed, to take advantage of a vulnerability in
Speaker:SMB or a, a Windows, service.
Speaker:That had a patch.
Speaker:So Microsoft came out with a patch.
Speaker:So it was several months later that the malware, this
Speaker:attack vector really came out.
Speaker:and it was all of those organizations that did not apply that critical, patch.
Speaker:And if, if you were paying attention at all, you probably got
Speaker:an email from Microsoft saying, you really need to patch this.
Speaker:This, this vulnerability.
Speaker:or you've got automatic patches turned off, which is common too.
Speaker:'cause a lot of organizations don't want to automatically apply
Speaker:patches to production systems and have them reboot and cause issues.
Speaker:But nonetheless, bad guys found a vulnerability, took advantage of it
Speaker:several months after the fact even,
Speaker:yeah
Speaker:and.
Speaker:how many people were impacted
Speaker:not necessarily people, but sy well over 200,000 systems
Speaker:were infected with WannaCry.
Speaker:that's quite a bit that hint your comment earlier 200,000 people all
Speaker:crying out at once just like in what do you call it star Wars I I'm
Speaker:Yes,
Speaker:okay Alright but and the thing is this is yet this is one of many examples of
Speaker:hacks, of attacks that had the victims of the attack practiced basic cyber hygiene.
Speaker:They would not have, been, they would not have been victimized by this attack.
Speaker:Does that sound, is that about right?
Speaker:good chance they would not have been a victim.
Speaker:Yes.
Speaker:the only caveat that is that Ry is one of those ransomware
Speaker:malware that was also a worm.
Speaker:so as it infected a machine, it's worm like behavior was what?
Speaker:What led itself to propagate in kind of an al alternative method.
Speaker:So if you weren't vulnerable to the SMB with Microsoft, you might've been
Speaker:vulnerable some other way that this, uh, this worm was able to compromise you.
Speaker:I think back to the Rackspace hack, because that was one
Speaker:where, again, it was a patch.
Speaker:There was a patch to the vulnerability in Microsoft Exchange that, again,
Speaker:had Rackspace simply applied that patch, they would not have been,
Speaker:subject to this particular attack.
Speaker:And in this case, there was, was a workaround there was a vulnerability.
Speaker:And then there was a workaround to the vulnerability while
Speaker:they were waiting on the patch.
Speaker:But what happened is there was a, an undisclosed, a zero day additional
Speaker:vulnerability that if they had applied the patch to fix the first
Speaker:vulnerability they would not have been subject to the zero day exploit.
Speaker:But they said to themselves, uh, this is my theory, uh, is that they said,
Speaker:well, we, we put in the workaround.
Speaker:And so therefore the criticality of this patch was not, it wasn't as critical.
Speaker:And so they didn't put in the patch yet.
Speaker:And two weeks, after the.
Speaker:this exploit came out.
Speaker:they were attacked and that cost them entire business line.
Speaker:because they had to, they had to stop.
Speaker:and it, there was a, there was lawsuits.
Speaker:it was very messy.
Speaker:so let's talk about, when we talk about, cyber hygiene.
Speaker:do you want to, do you wanna just define that, Mike.
Speaker:And if I could back up just a minute.
Speaker:'cause you made a comment about mitigation, so we weren't able
Speaker:to apply the patch for whatever reason, so we mitigated the risk.
Speaker:something that I think is critically important for people to consider
Speaker:when we talk about mitigation, and this comes from my audit.
Speaker:My audit life, where I had to go and determine if people were
Speaker:following the rules, whether it was hygiene or we also called them,
Speaker:general controls or best practices.
Speaker:If they weren't, then they had to demonstrate what they were
Speaker:doing to mitigate the risk.
Speaker:Presented by the absence of doing what we expected and the audit guidance and
Speaker:what we would tell people and what people should consider is that your mitigation
Speaker:strategy should be more effective.
Speaker:Had you done it the right way to begin with.
Speaker:a
Speaker:So if the control says, do one, two, and three, and you say, I
Speaker:can't do one, two, and three, you better do 4, 5, 6, 7, 8, 9, and 10.
Speaker:Your mitigation needs to be stronger than the original control or activity.
Speaker:which
Speaker:Interesting.
Speaker:But I guess in your experience, Mike, how often were people
Speaker:able to meet that higher bar?
Speaker:if you were a regulated organization, you had to, or you failed.
Speaker:Or,
Speaker:Yep.
Speaker:often would they just say four, five and six, seven are two difficult.
Speaker:Let me just go back and implement one, two, and three.
Speaker:With a grain of salt, obviously.
Speaker:So I was a technology auditor, so I was auditing it people that generally
Speaker:don't run the business, right?
Speaker:They're being, they're given direction from the business of, we can't fix
Speaker:that thing because our website will stop working or it'll be down too
Speaker:long, we'll lose too much money.
Speaker:So businesses directing the technology, groups and infrastructure
Speaker:of what they can and can't do.
Speaker:And so when you talk to them about, you couldn't do one, two, and three, because
Speaker:it'll break things or for whatever reason.
Speaker:So what are you doing?
Speaker:we're doing four, five, and six.
Speaker:four, five and six are okay.
Speaker:I'm gonna say that's maybe effective with opportunity for improvement.
Speaker:or they're doing a whole lot or they're not doing really anything because they.
Speaker:They didn't know.
Speaker:And so those are the really, the three options.
Speaker:you fail 'cause you didn't do what you were supposed to
Speaker:and you weren't mitigating it or mitigating it effectively.
Speaker:You were mitigating it somewhat effectively, but I
Speaker:think it could be stronger.
Speaker:And that's from a, an auditor's perspective, there is that kind
Speaker:of, latitude where I can add some.
Speaker:Objectivity, or I say subjectivity.
Speaker:Uh, and then lastly, wow, you, you really, you really are, you really do understand
Speaker:that mitigation's gotta be stronger.
Speaker:And, and, but that's, that's rare.
Speaker:Very rarely did I see the mitigating controls more effective
Speaker:than the, the original controls.
Speaker:I'm glad that you, you mentioned, the comment that you made, I is one
Speaker:that we make a lot from the opposite side, and that is the backup.
Speaker:People should never be setting policy.
Speaker:They should never be determining, retention periods, RTOs and RPOs.
Speaker:you know that should never be the case.
Speaker:That should always come from the business.
Speaker:and so we say that a lot and so it, it's good to hear it just
Speaker:from a different, frame of view.
Speaker:I don't think you ever got around to defining cyber hygiene.
Speaker:So cyber hygiene.
Speaker:if we keep in our discussions, we keep coming back to the real world.
Speaker:'cause I think that helps people, relate.
Speaker:so applying real world stuff to cyber hygiene is very similar.
Speaker:if you're not.
Speaker:Keeping or maintaining your own personal hygiene, you're gonna get sick.
Speaker:so in cyber there are things that you should be doing just like in real world.
Speaker:Take your vitamins, go see a doctor, get your checkups, do healthy things.
Speaker:One, cyber, those.
Speaker:Activities are making sure that your systems aren't vulnerable.
Speaker:, And we do that through patches.
Speaker:so we subscribe to services.
Speaker:If it's a Windows machine that do it automatically, if you've got it turned
Speaker:on, It and it will check your systems to determine if there's a vulnerable,
Speaker:configuration or a patch that's out, that, that would, address a known problem.
Speaker:so patch management is very important.
Speaker:the other part of that is, who can access my stuff?
Speaker:that's me obviously, and the people that I give access to my systems.
Speaker:But then how do we know that it's really them because.
Speaker:The number one traded commodity on the dark web right now is
Speaker:access, and that's credentials.
Speaker:So how do we, you know, what's a good practice for making sure that
Speaker:you know, someone that, that I trust, uh, that their credentials
Speaker:aren't out there and someone's, you know, some bad guy's not using them.
Speaker:So that's where multifactor authentication comes in, but very similar to.
Speaker:in the real world, vitamins and all these other healthy things, you have
Speaker:to do it responsibly and appropriately.
Speaker:And MFA is definitely one of those that I think the majority of organizations just
Speaker:say we have it and they're not using it.
Speaker:Right.
Speaker:and then lastly, password management, probably, appropriately
Speaker:at the bottom of the list.
Speaker:it's still part of hygiene, but not as effective as it used to be 'cause.
Speaker:bad guys aren't trying to guess your password, they're just stealing
Speaker:it from somewhere else, right?
Speaker:your work password is probably a password you've used somewhere
Speaker:else at some point in time.
Speaker:bad guys are just
Speaker:Yeah, but that's the point of good.
Speaker:Cyber hygiene Is not doing that.
Speaker:We're gonna get to that in, in a
Speaker:So we'll get into the details of what, what a good password practice,
Speaker:would be, similar to patching and MFA.
Speaker:Mike, so these are three great sort of.
Speaker:Things you should be doing from a cyber hygiene perspective.
Speaker:but how did you come up with this list, like right, or, I know you
Speaker:and Curtis have been talking about this for a while, but like, why
Speaker:are these the three most important?
Speaker:Is it based on like scenarios you've encountered working with customers,
Speaker:helping them recover from ransomware?
Speaker:Like why should someone believe the sort of 90% of ransomware could be?
Speaker:I can jump in on that one.
Speaker:it's because of the stories that I've read over the last, so many years, it
Speaker:was always one of these three, right?
Speaker:if they had just patched the system, then they wouldn't have
Speaker:the vulnerability if they had just either not allowed the password to
Speaker:be stolen or compromised in some way.
Speaker:And then, if they were just using MFA, then even if they had the password,
Speaker:then they would've been able to get in.
Speaker:Assuming that you didn't have MFA fatigue by the employee?
Speaker:But the thing is, if they had these things when you read back on the stories, and I
Speaker:would add because we're tech technically talking about cyber hygiene here and not
Speaker:backup hygiene, but I'll add to this.
Speaker:Immutable backups, right?
Speaker:If we have that, if we have those four, then not only would you stop the, the bulk
Speaker:of the attacks, you would, also be able to respond to the 10% that, that you get.
Speaker:would your answer be any different there, Mike?
Speaker:Oh, very similar.
Speaker:So yeah, they, these three are the greatest common denominators, of
Speaker:a lot of the, if not the majority of, Incidents that are out there.
Speaker:but to Curtis's point and maybe where you were going, Prasanna.
Speaker:Yeah.
Speaker:This list could get really long.
Speaker:it's, it's not just these three and the backups, it's also network segmentation
Speaker:and turning, secure build guidelines and secure coding and, perimeter protection
Speaker:and vendor management and anti-malware and training and all those things.
Speaker:but when you look at the numbers, the statistics of incidents
Speaker:that are out there and what.
Speaker:You know what, how you boil those down to the Common denominators.
Speaker:it's primarily these three.
Speaker:Because these are, it's this is to, again, going back to the real world, in the real
Speaker:world when we talk about investing, The very first thing they tell you to do is
Speaker:to have, 90 days of an emergency fund.
Speaker:And that should be your first thing because there's no point in talking about
Speaker:4 0 1 Ks and Roth IRAs and all these things if you can't survive, losing a
Speaker:paycheck for a couple of weeks, right?
Speaker:This is the, if you're not doing these.
Speaker:Then just stop.
Speaker:in the book we said if you're not doing these three things, just stop
Speaker:reading right now and go do those three things because it will stop 90%,
Speaker:the other 10%, like everything else.
Speaker:The other 10% is the hard part, right?
Speaker:It's the more expensive part.
Speaker:But doing password management and patch management and MFA or, pass
Speaker:keys, which, we'll talk about that a little bit more, but if we do that.
Speaker:Then it's a, it's the low hanging fruit.
Speaker:that, that allows us to secure the environment, without
Speaker:massive cost or anything.
Speaker:If you're not doing these things and don't, it's like when we start talking
Speaker:about, offsite backups, there's no point in talking about offsite backups if you're
Speaker:not making backups in the first place.
Speaker:this is the, if you're not doing these things, and don't even talk to me.
Speaker:Don't even start, if you're not doing basic cyber hygiene, then,
Speaker:then there's no point in continuing on with further discussions.
Speaker:let's just talk a little bit about, when we talk about patching, how do we know,
Speaker:and we're gonna do an episode on each of these things, but just the basic thing,
Speaker:what do you think would be the easiest?
Speaker:that's what, 'cause that's what we're trying to do here.
Speaker:What would be the easiest way to make sure that we're running all
Speaker:of the appropriate patches, Mike, especially the critical ones.
Speaker:it's easy if you're organized and the first step in getting organized is doing
Speaker:an inventory of the things that you have, because, you have to work off your
Speaker:inventory to know who to get patches from.
Speaker:Right.
Speaker:Is it, is it.
Speaker:Red Hat Linux.
Speaker:Is it Windows?
Speaker:Is it third party tools?
Speaker:Adobe, uh, you know that 3D modeling tool?
Speaker:So you've gotta inventory all this stuff first and then find out if you can
Speaker:actually get notifications from them.
Speaker:For when patches are available.
Speaker:if you don't do that on the proactive side, then you're gonna
Speaker:get it on the reactive side.
Speaker:'cause hopefully part of hygiene is also your periodic vulnerability assessments.
Speaker:And if you need help with that, we can walk you through some
Speaker:free open source ways to do that.
Speaker:Every now and then you need to be scanning all of your assets for vulnerabilities.
Speaker:That's gonna turn up some configuration problems, some missing patches.
Speaker:then, alright, reactively, now I, there's a missing patch and usually it comes with
Speaker:a link from these vulnerability tools.
Speaker:so go do that and while you're doing it, find out if there's a way
Speaker:to subscribe to that information.
Speaker:It's not easy, and that's one of the reasons people don't
Speaker:do it 'cause it's not easy.
Speaker:and there are tools out there that are fairly expensive to
Speaker:do it in an automated fashion.
Speaker:it's gotta start with understanding what it is you have, and then figuring out
Speaker:where to get the information for available patches and issues with those assets.
Speaker:this is the hardest thing today versus back in the day, right?
Speaker:Back in the day, I could walk into a server room and I could literally just
Speaker:have a piece of paper and check off.
Speaker:I have this one, I have this one, I have this one.
Speaker:Now We don't have any service to point at.
Speaker:Everything's virtual.
Speaker:Everything's in the cloud.
Speaker:And we have, IAS we have PAS we have SAS, right?
Speaker:We have all of these different ways where, and I'd say the SaaS is probably the
Speaker:worst because it's so easy to propagate.
Speaker:The, to go across the, the thing and you did remind me when we
Speaker:talk about inventory, you did remind me again back in the day.
Speaker:We had, when I was the backup guy, my very first job in it.
Speaker:we had a very boring naming convention.
Speaker:We had H-P-D-B-S-V-A HP database server, a right, bbc, so on.
Speaker:And I ha I was becoming worried that I wasn't getting all the servers.
Speaker:'cause we started out, we literally, when I started at the bank, we had seven.
Speaker:Anyway, so we went from having seven servers to having 200 servers, and
Speaker:I was starting to panic that we.
Speaker:We didn't have a correct inventory.
Speaker:And but the naming convention was very helpful.
Speaker:And so I had this practice of when you had a new server, you had to give me a
Speaker:form to say, I want this server backed up.
Speaker:And I put this thing on there that said, don't consider it backed up
Speaker:until you get the form back for me.
Speaker:Signed that, said that I saw the form and I put it on the list.
Speaker:And then one day somebody handed me a form and they, it
Speaker:said H-P-D-B-S-V and I'm like.
Speaker:And they're like, yes.
Speaker:I go, so that would by, you know my inference, that means there's
Speaker:an M and an L a K somewhere.
Speaker:And they're like, yeah.
Speaker:And I'm like, I only know up to j. so I'm gonna go find K and l and m and
Speaker:and we'll start backing all of them up.
Speaker:I agree with you, Mike.
Speaker:A hundred percent.
Speaker:That inventory is absolutely the place to start.
Speaker:No, it, that's actually a pretty funny story, Curtis, but I'm not surprised.
Speaker:You always have all these great stories from working at the bank and other places.
Speaker:But Mike, I know you talked about patch management, right,
Speaker:and how to apply patches.
Speaker:is there something similar for cases where maybe patches aren't available?
Speaker:Like, it's great you have an inventory of everything that's
Speaker:there, but how do you deal with sort of, exploits that are currently
Speaker:out there before patches come out?
Speaker:So those are zero days in, in most cases.
Speaker:so zero day is something was identified today, and vendors haven't had a
Speaker:chance to respond to that with a patch.
Speaker:and I'll add real quick, sometimes the patch that's available
Speaker:becomes your zero day because it doesn't work in your environment.
Speaker:and so along with patch management, you need to develop.
Speaker:Process for testing the patch, applying it to a test machine to
Speaker:see its effects on how things run before you move it into production.
Speaker:be mindful of that too, but to your point, Prasanna about things
Speaker:that come up that don't have a fix, those mitigating controls.
Speaker:Like how do we, alright, so there in.
Speaker:So is this a public facing thing?
Speaker:do people log into it?
Speaker:is it a, prized possession of our company with, sensitive data?
Speaker:Or is it just that, that thing I could potentially turn off or isolate?
Speaker:so you've gotta do some analysis first, like what's the risk, what's the impact?
Speaker:And then respond accordingly if it's.
Speaker:Publicly accessible internet facing.
Speaker:Then put some monitoring on it, put some logging on it, try to isolate it.
Speaker:those mitigating controls in the absence of a, a true solution have to be
Speaker:assessed and applied as fast as possible.
Speaker:I like that.
Speaker:and
Speaker:so
Speaker:there are services out there.
Speaker:I ran into one not too long ago.
Speaker:It's outta New Zealand and it's, I don't have a fix for this.
Speaker:It's essentially a proxy.
Speaker:So they stand up a An internet facing version of whatever it is
Speaker:that's fed from your environment.
Speaker:And they analyze and filter all the requests for that information as a proxy.
Speaker:and you can subscribe to that until a solution is, is applied.
Speaker:So that was pretty interesting.
Speaker:I did see that.
Speaker:that's the patches world.
Speaker:Let's talk a little bit about the passwords.
Speaker:and I think we can all agree one.
Speaker:some method.
Speaker:Again, I'm a big fan of a password manager.
Speaker:But you need some method.
Speaker:So you absolutely do not ever use the same password in multiple places.
Speaker:because that is the problem is, I, and I got a, I got in a argument
Speaker:is a strong term, but I got into a discussion with a guy on.
Speaker:I think it was somebody that commented on one of our videos and where
Speaker:he was saying that he was using.
Speaker:this system where he, what he does is he has a password that he uses
Speaker:on like a small subset of systems.
Speaker:Like he has 10 passwords that he uses everywhere.
Speaker:And so his method of mitigating the risk is that he doesn't
Speaker:wanna use a password manager.
Speaker:He doesn't believe in using a password manager.
Speaker:So he has 10 passwords that he sprinkles around and he just has to
Speaker:remember, 10 passwords in his head.
Speaker:and he uses the battery horse staple method.
Speaker:which is a good method, right?
Speaker:I'm sorry.
Speaker:It is just this idea of having an password that is long but actually
Speaker:easy to remember because most of the passwords that we have that are long
Speaker:are total garbly gook and they can only be remembered by a password manager.
Speaker:So he uses that method and then he has 10 passwords and I was like, that's.
Speaker:better than using the same password everywhere.
Speaker:But if any one of those systems where you're using that same password
Speaker:are ever compromised, then you have to change the password everywhere
Speaker:where you're using that password.
Speaker:And potentially by the time you get around to doing it,
Speaker:it's already been compromised.
Speaker:And so this is just, again, my way to do this is password
Speaker:manager and I think that's the number one most recommended way.
Speaker:But besides making sure that we do not use the same password in multiple places.
Speaker:What else?
Speaker:Basic, password hygiene stuff do we need to talk about, Mike?
Speaker:I think a good term for your, your disagreement.
Speaker:and it's an older term, that you just don't hear very often is a kerfluffle.
Speaker:Careful.
Speaker:think that's a good yes.
Speaker:Uh, anyway, so back to passwords.
Speaker:I think a good practice these days, especially as we suggest passwords become
Speaker:longer and longer, and, I don't know if, if you guys realize where that came from.
Speaker:so it stemmed from the length of a password.
Speaker:okay.
Speaker:How long
Speaker:So a stem.
Speaker:compute right?
Speaker:So when Windows or Linux, Unix, encrypts a password, with, a ES
Speaker:2 56 or whatever it is, there's a ma math, there's a mathematical,
Speaker:response to how long it would take to crack a password of certain length.
Speaker:that's been defeated, by a project called Rainbow Tables.
Speaker:Rainbow tables just encrypts and captures the hash value of
Speaker:every conceivable, random known dictionary, multiple languages.
Speaker:And so it's not, I don't have to crack your password anymore, I just have to
Speaker:take your password hash and go look it up.
Speaker:And see if that's already been done.
Speaker:So it's not a math problem anymore.
Speaker:it's a research problem.
Speaker:All right, then a vulnerability came out in, with Windows.
Speaker:'cause if you had, NTLM, the hash in windows turned on, it would take
Speaker:your password hash and break it up into two eight character hashes.
Speaker:now I can crack them individually.
Speaker:Instead of cracking one large, I can do two small ones.
Speaker:And there's vulnerability associated with that.
Speaker:So now we should have greater than 16 character passwords for that reason.
Speaker:and it, and I can drive policy now, it says it's gotta be 16.
Speaker:if it has to be 16, the IT guys that have not wanted to change the LTLM
Speaker:now have to, they have to turn that off to, to generate, and so there's.
Speaker:It's political game, but also based on, some known
Speaker:vulnerabilities around passwords.
Speaker:Alright, now we've got 16 character or greater passwords.
Speaker:How are you gonna get users to remember that?
Speaker:password managers are great because it can also randomize passwords so
Speaker:you don't have to remember it anymore.
Speaker:You just log into your password manager and copy and paste.
Speaker:and so you, you don't have to remember it anymore.
Speaker:And it can be random, which is also.
Speaker:Helpful, but then not everybody can subscribe to that approach.
Speaker:So they want these password phrases now.
Speaker:And so some interesting things about password phrases, and similar to what
Speaker:Curtis was describing with, having a root password and then you know,
Speaker:something at the beginning and something at the end that's helpful, especially
Speaker:if it's, if you want the same route password for everything, and then you
Speaker:just change the front and the back depending on what you're logging into.
Speaker:'cause as a bad guy, I just need two of those to realize that's a pattern and
Speaker:I can just guess, what, what your bank password is if I don't have that already.
Speaker:so some things to think about.
Speaker:if you're logging into your bank, maybe your past phrase is, I like getting paid
Speaker:on Friday, and then at the beginning or the end, and that makes me happy.
Speaker:Or, added emotion or add a color that makes you think of, that emo it's blue.
Speaker:I think that's calming, right?
Speaker:and then change up how it felt.
Speaker:the way, Mike.
Speaker:Green.
Speaker:Green is okay.
Speaker:for money.
Speaker:red.
Speaker:So then, do some substitution.
Speaker:So instead of, ease, use threes and capitalize, the first letter
Speaker:of a word or spell it backwards.
Speaker:I had a password and man, long time, 20, 30 years ago, where it was,
Speaker:I spelled everything backwards.
Speaker:So there, there are some unique things that you can do with passwords.
Speaker:You just have to figure out which one works for you, and that
Speaker:you can be consistent with it.
Speaker:The password manager will also help you remember to, it's about time you've
Speaker:been using this password for 10 years.
Speaker:Yeah.
Speaker:time to change it.
Speaker:basically the idea is the overall overriding concept is to not
Speaker:use the same password anywhere.
Speaker:Never use the same password twice.
Speaker:and if you're not using some kind of system, my method is password manager.
Speaker:the one that you talked about, Mike, the one where you append it and pre-end
Speaker:it with something and you have this core password that used to be my method
Speaker:before I went to a password manager.
Speaker:and the, and then there's this, these other ways to have it, but.
Speaker:I can't, ima I have 500 passwords at this point, right?
Speaker:so I can't imagine, not having, a password manager at this point.
Speaker:But, so that's my way to do that.
Speaker:But the core concept is you cannot use the same password at multiple places.
Speaker:And why is that, Mike?
Speaker:we alluded it to it, a few minutes ago.
Speaker:and the reason you don't wanna use them in more than one place is because
Speaker:you've gotta rely on the security of more than one thing to make sure
Speaker:your password isn't compromised.
Speaker:And when bad guys compromise one data set, they're gonna use that data set
Speaker:across everything they can think of.
Speaker:So if I've got one of Curtis's passwords and I know he has 500 accounts out
Speaker:there, I'm gonna use that one password to try and log into 499 of those,
Speaker:And especially
Speaker:could be.
Speaker:one username is your email address, right?
Speaker:so you already know my email address and you go out there and you use the.
Speaker:Password everywhere.
Speaker:you just, you don't even need to know where I have the thing.
Speaker:you just try it.
Speaker:All the places that you have access and you're, and this is a numbers game.
Speaker:You're trying every account that you have access to with every password
Speaker:you have access to in every place that you have access to the system.
Speaker:so yeah, that's why we don't do it
Speaker:Yep.
Speaker:and how do you mitigate that?
Speaker:by using the different password in every place.
Speaker:what if they guess what if they have a password?
Speaker:You forgot you used 20 years ago and now there's an account
Speaker:that password's gonna work on.
Speaker:How do you mitigate that MFA.
Speaker:so MFA, is the final thing on our trifecta of basic cyber hygiene.
Speaker:and I'll put MFA slash pass keys, which is it's like the next thing.
Speaker:'cause we'll, as we, when we talk about MFA.
Speaker:We will mention that MFA is not perfect.
Speaker:Prasanna's already alluded to it.
Speaker:there's this thing called MFA exhaustion.
Speaker:there are other issues with it, but let's just start with what MFA is.
Speaker:Prasanna, why don't you define MFA?
Speaker:What is it, and how does it work?
Speaker:So with MFA, it's really, someone might compromise your password
Speaker:and so it's something you know and something you have, right?
Speaker:And so that something you have piece is normally, say your
Speaker:biometrics like a fingerprint.
Speaker:It could be your face, right?
Speaker:It could be a. Electronic token that gets generated periodically
Speaker:or some other application, right?
Speaker:That generates that such that you have a second factor, which previously was
Speaker:called sort of two-factor authentication.
Speaker:Right now it's multifactor in order to be able to say, yes, this really is me.
Speaker:I'd say the most common one is probably SMS.
Speaker:it's definitely not the best one, but it's certainly the most common, I
Speaker:think the most common use to be email.
Speaker:I really don't like email, like, in good, better, best.
Speaker:It's barely good, uh, because again, if you, uh, if somebody's
Speaker:compromised your email account, especially if it's the email account
Speaker:that you use for everything, right?
Speaker:Think SMS is actually better today than it used to be it's harder to do
Speaker:sim hacking today than it used to be, at least in, in certain circumstances.
Speaker:and then, but then, the, I think the best one that we have today that's
Speaker:available to pretty much everybody is, an authenticator type app.
Speaker:You wanna talk about that, Mike?
Speaker:Sure.
Speaker:Uh, and, and those apps are generally free, uh, and, and don't require any.
Speaker:Infrastructure changes.
Speaker:There are some, like duo, that would require some licensing and set up
Speaker:on the inside of, your organization.
Speaker:but others like the Microsoft Authenticator app, Google
Speaker:has one, they're free.
Speaker:You just get 'em in the play store.
Speaker:And then whenever you want to register your multifactor with a vendor, a
Speaker:lot of times there's like a QR code or a set up your account this way.
Speaker:Similar to a password manager, you would log into your authenticator app and it
Speaker:would show all your different accounts, which you could revoke or delete if
Speaker:you think that's compromised as well.
Speaker:And, MFA, fatigue, MFA fatigue is a real thing.
Speaker:It's more of a. It's just annoyance.
Speaker:so you log into something and you, oh, I've gotta wait for my phone to ding.
Speaker:Now what if you don't have cell phone coverage or data, wireless data?
Speaker:a lot of these authenticator apps also allow you to save.
Speaker:Backup codes, things like, so there's any number of ways
Speaker:of using what works for you.
Speaker:the important thing is to figure out something other than email, for your
Speaker:MFA if the account that you're wanting to apply MFA to will support it.
Speaker:And Mike, I know on a previous podcast you sort of mentioned one of the
Speaker:downsides with many websites, right?
Speaker:Which have MFA, and then they sort of have the remember me
Speaker:next time on this thing, right?
Speaker:So it's whether it's a website like, I don't know,
Speaker:Amazon.
Speaker:Amazon, right?
Speaker:yeah.
Speaker:remember this device, you don't want to do that because your MFA token
Speaker:is then stored in your browser.
Speaker:And so now a bad guy just asked to get you to a position or a situation where I can
Speaker:scrape that MFA token out of your browser if I already have your credentials.
Speaker:The only thing I need now is your MFA token, and now
Speaker:I can get into your account.
Speaker:So good MFA has to come with good policy and good practice.
Speaker:So the point of this episode here is just to if you're not familiar with any
Speaker:of those three things, go get familiar.
Speaker:and the best way to do that is to, log in next week and we'll
Speaker:cover each of these in detail.
Speaker:but, the idea behind MFA is that if somebody gets a hold of your password,
Speaker:they won't be able to log in because they don't have that additional factor,
Speaker:whatever it is, whether it's SMS or, an authenticator app or a token, right?
Speaker:We'll talk about these more and all of those and passwords
Speaker:and MFA have limitations and those limitations are us, right?
Speaker:It's the human, and that's why I think pass keys is the better option.
Speaker:As we move forward in the future, and I've been rolling out Pasky,
Speaker:in many places, wherever I can.
Speaker:it, I'm not sure if it's great for the average Joe, there, it can be confusing.
Speaker:PAs keys can be confusing if you don't, if you don't know what you're doing.
Speaker:But, but I.
Speaker:Did you ever use iron keys?
Speaker:Curtis?
Speaker:what's a iron key?
Speaker:So an iron key is a military grade USB, and in it, it's got its own, TPM chip.
Speaker:Its own encryption, its own password manager, its own MFA.
Speaker:And if you log into it, I think it's 20 times wrong, it self-destructs,
Speaker:it's got a little capacitor in it.
Speaker:and if you try to cut into it to get to the chips, it's also got
Speaker:a sensor and will self-destruct.
Speaker:Yeah,
Speaker:Yeah, it's pretty cool.
Speaker:that, but doesn't surprise me that you probably have.
Speaker:Um, but anyway, so the, again, this is meant to be an overview episode.
Speaker:and if some of this was confusing or frustrating or you felt like we didn't
Speaker:go into detail enough, then just, we're gonna do three more episodes where we
Speaker:go into each of these, in more detail.
Speaker:but it just.
Speaker:start looking into these three things.
Speaker:Make sure you're doing pa patch management, right?
Speaker:that some sort of automated system.
Speaker:and we're gonna start with an inventory, right?
Speaker:A physical inventory, a virtual inventory, and a, an a SaaS inventory
Speaker:of your entire environment to make sure that you know what it is you're
Speaker:supposed to be looking out after.
Speaker:You're gonna have a good password manager and you're gonna have good.
Speaker:you're gonna have an MFA or you're gonna have a passkey based system.
Speaker:because, without these three things, no point in having, like
Speaker:looking into A EDR or an XDR system.
Speaker:and, or any of the other stuff that we're talking about because it's
Speaker:like looking into a Roth IRA if you don't even have a savings account.
Speaker:With that, any final thoughts, Mike?
Speaker:Doing something's better than nothing.
Speaker:one of these and do something about it.
Speaker:absolutely.
Speaker:What about you, Prasanna?
Speaker:Well, I think the three makes sense and hopefully everyone
Speaker:is using a password manage.
Speaker:There.
Speaker:All right, Prasanna.
Speaker:Thanks.
Speaker:Thanks for, being here again as well.
Speaker:Forever.
Speaker:and look, see I shaved, just so you know.
Speaker:Yeah, absolutely.
Speaker:Absolutely.
Speaker:Alright.
Speaker:Actually, I don't know if anybody can tell, but I had my beard trimmed.
Speaker:I had a photo op yesterday, so it, my beard's all nice and trimmed.
Speaker:So anyway, or as my granddaughter said, slay.
Speaker:Um, and that is a wrap.
Speaker:All right.
Speaker:Um,
Speaker:Welcome to the backup wrap up.
Speaker:I'm your host, w Curtis Preston, AKA, Mr. Backup, and I have a, with
Speaker:me, a guy who apparently shaved last week and I didn't even notice.
Speaker:Prasanna
Speaker:Prasanna
Speaker:Malaiyandi how's it going?
Speaker:Prasanna
Speaker:I am good Curtis.
Speaker:Yeah.
Speaker:Uh, my wife was very surprised after the podcast recording when
Speaker:she was like, did Curtis notice?
Speaker:of course, I. I texted you and you're like, no, or no, I think
Speaker:No.
Speaker:on the phone and you're like, no, what are you talking about?
Speaker:And I had to send you a picture,
Speaker:Yeah.
Speaker:And, and apparently Mike, Mike didn't notice either, so I feel
Speaker:somewhat better, but, uh, yeah.
Speaker:So you, you, you've gone down to the goatee,
Speaker:Yep.
Speaker:um, and, um.
Speaker:many, many years since I've done this.
Speaker:Pre
Speaker:I've seen a picture of you with the goatee.
Speaker:Yeah.
Speaker:Pre, yeah, yeah, yeah.
Speaker:I think you should go back to your cut from college.
Speaker:That's what I think.
Speaker:The buzz.
Speaker:The buzz cut.
Speaker:Yeah.
Speaker:Yeah.
Speaker:I, I'd love to see you in the buzz cut again.
Speaker:Walked away.
Speaker:but, uh, anyway, speaking of buzz cuts, Dr. Mike Sailor, how's it going, Mike?
Speaker:Going Good guys.
Speaker:It's going good.
Speaker:All right.
Speaker:So he of course, is the co-author on, uh, uh, learning Ransomware Response
Speaker:and Recovery, which came out last month.
Speaker:Which, uh, do you have one with you now?
Speaker:Did you, did you prepare this time?
Speaker:I did not prepare this time.
Speaker:me Mike I have yet I still don't have mine and I have yet to actually see the a
Speaker:physical printed book even like a video of a physical printed book with with you know
Speaker:The book is gonna be the size of the thing in your background?
Speaker:Curtis?
Speaker:yeah I I would dear Lord dear Lord I hope not And you know what's funny is like
Speaker:in on the camera this thing looks fine but this is this is like this far back
Speaker:from me right And so this thing is like I think it's 15 by 24 That thing is massive
Speaker:Um so yeah I sure I surely hope not
Speaker:For those
Speaker:but
Speaker:watch us on YouTube, uh, we do have videos out, but Curtis was just pointing at
Speaker:the, what do you call it, the title page?
Speaker:The front
Speaker:It's the cover the front cover Yeah yeah yeah And uh available at uh
Speaker:So or you can order them directly from O'Reilly for the record if you order
Speaker:directly from O'Reilly Mike and I make more um So uh there's that All right uh
Speaker:we're gonna talk so we're gonna jump into this week we're gonna talk about the title
Speaker:It's gonna sound I I you know I never know exactly what the title's gonna be but it's
Speaker:gonna be something along the lines of stop 90 of the ransomware attacks that could
Speaker:possibly happen to you That's a really long title but um I I I you know it may
Speaker:sound like a bold claim but I I think it's pretty straightforward And Mike uh I'd
Speaker:like to start out this week What's that
Speaker:before, you
Speaker:Yeah
Speaker:can I make a bold claim?
Speaker:claim
Speaker:A
Speaker:please
Speaker:That you can stop a hundred percent of ransomware if you
Speaker:never do anything online.
Speaker:Um
Speaker:not, I think there's still some, some, some room there for infection.
Speaker:sorry.
Speaker:Well you know like if you if you if they do the um the drop you know the
Speaker:the one that we covered in the in the uh what do you call it Um when we did
Speaker:the MR Robot remember the drop USB stick
Speaker:Oh, that's
Speaker:Tchotchke drops.
Speaker:Yeah What what's that
Speaker:you win.
Speaker:We call 'em tchotchke drops.
Speaker:Tchotchke drops Yeah Yeah So even then um um but what what is this what is
Speaker:this not do things online thing that you're talking about I don't know what
Speaker:in the world Like I I don't even know
Speaker:Like saying you can't get sick if you don't go outside.
Speaker:Well, that's not true either.
Speaker:yeah Exactly all right Mike well do we do you have a story to
Speaker:start us out with this week I
Speaker:I do.
Speaker:Um, well man, there's so many to pick from, but, um, from the book,
Speaker:you know, we talk about WannaCry.
Speaker:Um, and similar to, to kinda what we touched on here, good hygiene
Speaker:can prevent a lot of stuff.
Speaker:And I think WannaCry is an example of bad guys identified of a
Speaker:vulnerability that was out there.
Speaker:They created a.
Speaker:Uh, a payload and a, and an attack vector to take advantage of that,
Speaker:realizing that, uh, there's a, a very large percentage of, uh, company and
Speaker:organization populations that don't have a, a solid patch management program or,
Speaker:uh, that it, it's pretty lax, you know, there's a lot of organizations that,
Speaker:that say we have a patch program, but it's, you know, 2, 3, 4 months behind,
Speaker:or it's gotta meet certain criteria and some things never get patched.
Speaker:Well, that's what happened with WannaCry.
Speaker:Well
Speaker:found a vulnerability,
Speaker:for those of us yeah For those of us that that you know haven't lived uh the
Speaker:the cyber world Why don't you tell us what was want Tory What you know did it
Speaker:did it make you want to cry Is that why it was called that And what you know
Speaker:when did it happen and you know what
Speaker:I was
Speaker:I think there was about 200,000,
Speaker:Yeah.
Speaker:I.
Speaker:200,000 people crying in unison,
Speaker:exactly
Speaker:uh, with WannaCry.
Speaker:I was going to say Curtis, that because there have been so many of these
Speaker:attacks over the years, it's also hard to keep like, which keep it straight
Speaker:in terms of like which one was which.
Speaker:Yeah Yeah So why don't you tell us the story of WannaCry Mike
Speaker:WannaCry, uh, was developed, uh, to take advantage of a vulnerability in
Speaker:SMB or a, uh, a Windows, uh, service.
Speaker:Um.
Speaker:That had a patch.
Speaker:So Microsoft came out with a patch.
Speaker:So it was several months later that the malware, this
Speaker:attack vector really came out.
Speaker:Um, and it was all of those organizations that did not
Speaker:apply that critical, uh, patch.
Speaker:And if, if, uh, if you were paying attention at all, you probably got
Speaker:an email from Microsoft saying, you really need to patch this.
Speaker:This, uh, this vulnerability.
Speaker:Um, or you've got automatic patches turned off, uh, which is common too.
Speaker:'cause a lot of organizations don't want to automatically apply
Speaker:patches to production systems and have them reboot and cause issues.
Speaker:But nonetheless, bad guys found a vulnerability, took advantage of it
Speaker:several months after the fact even,
Speaker:yeah And
Speaker:and.
Speaker:how many people were impacted
Speaker:Well, um, not, not necessarily people, but sy well over 200,000 systems
Speaker:were, were infected with WannaCry.
Speaker:That's that's quite a bit that hint your comment earlier 200,000 people all crying
Speaker:out at once Just like in just like in uh what do you call it Uh star Wars I I'm
Speaker:Yes,
Speaker:a Star Wars reference Um okay Alright but like and the thing is this is yet this
Speaker:is one of many many examples of hacks of attacks that had the um uh victims of
Speaker:the attack practiced basic cyber hygiene They would not have um been they they
Speaker:would not have been victimized by this attack Does that sound is that about right
Speaker:Good, good chance they would not have been a victim.
Speaker:Yes.
Speaker:Yeah yeah
Speaker:The, the, the only, the only, the only caveat that is that Ry is one of those
Speaker:ransomware malware that was also a worm.
Speaker:mm
Speaker:so as it infected a, a machine, uh, it's worm like behavior was what?
Speaker:Uh.
Speaker:What led itself to propagate in kind of an al alternative method.
Speaker:So if you weren't vulnerable to the SMB with Microsoft, you might've been
Speaker:vulnerable some other way that this, uh, this worm was able to compromise you.
Speaker:Okay Okay yeah when when I think back on uh my history I I think back um to shit
Speaker:um what's the name of the company The
Speaker:The one that uh Thank you Thank you Thank you Um I think back to
Speaker:the that was what two years ago
Speaker:I think it was two years ago.
Speaker:Yeah.
Speaker:Yeah Yeah I think back to the Rackspace hack because that was one where again
Speaker:it was a patch There was a patch to the vulnerability in Microsoft Exchange that
Speaker:uh again had Rackspace simply applied that patch they would not have been uh subject
Speaker:to this this particular attack And in this case there was um was a workaround
Speaker:there was a there was a vulnerability And then there was a workaround to the
Speaker:vulnerability while they were waiting on the patch But what happened is there was
Speaker:a um an undisclosed a zero day additional vulnerability that if they had they
Speaker:had applied the patch to fix the first the first vulnerability they would have
Speaker:been they would not have been subject to the to the zero day exploit um But they
Speaker:said to themselves uh this is my theory uh is that they said well we we put
Speaker:in the workaround And so therefore the criticality of this patch was not um you
Speaker:know it wasn't as critical And so they didn't put in the patch yet And two weeks
Speaker:uh after the You know this exploit came out Um they they were attacked and that
Speaker:cost them entire business line Right Um because they had to um they had to stop
Speaker:and it there was a there was lawsuits It was it was it was it was very very messy
Speaker:so let's talk about when we talk about uh cyber hygiene Um do you know do you want
Speaker:to do you wanna just define that uh Mike
Speaker:I will.
Speaker:And if, if I could back up just a minute.
Speaker:'cause you made a, a, a comment about mitigation, so we weren't
Speaker:able to apply the patch for whatever reason, so we mitigated the risk.
Speaker:Right
Speaker:Well, something that I think is critically important for people to
Speaker:consider when we talk about mitigation, and this comes from my, my audit.
Speaker:My audit life, uh, where, where I had to go and determine if people were
Speaker:following the rules, whether it was hygiene or we also called them, uh,
Speaker:general controls or best practices.
Speaker:If they weren't, then they had to demonstrate what they were
Speaker:doing to mitigate the risk.
Speaker:Presented by the absence of doing what we expected and the audit guidance and
Speaker:what we would tell people and what people should consider is that your mitigation
Speaker:strategy should be more effective.
Speaker:Had you done it the right way to begin with.
Speaker:Hmm
Speaker:a
Speaker:So if the control says, do one, two, and three, and you say, I can't
Speaker:do one, two, and three, well, you better do 4, 5, 6, 7, 8, 9, and 10.
Speaker:Your mitigation needs to be stronger than the original control or activity.
Speaker:which
Speaker:Interesting
Speaker:But I guess in your experience, Mike, how often were people
Speaker:able to meet that higher bar?
Speaker:Well, if you were a regulated organization, you had to, or you failed.
Speaker:Or, or I
Speaker:Yep.
Speaker:often would they just say four, five and six, seven are two difficult.
Speaker:Let me just go back and implement one, two, and three.
Speaker:Never, never did they do that.
Speaker:Uh, so they either so and, and it, and.
Speaker:With a grain of salt, obviously.
Speaker:So I was, I was a technology auditor, so I was auditing it people, it people that
Speaker:generally don't run the business, right?
Speaker:They're being, they're given direction from the business of, you know, we
Speaker:can't fix that thing because our website will stop working or it'll be down
Speaker:too long, we'll lose too much money.
Speaker:So businesses directing the technology, uh.
Speaker:Um, you know, groups and, and infrastructure of, of
Speaker:what they can and can't do.
Speaker:And so when, when you talk to them about, well, you, you couldn't do
Speaker:one, two, and three, so, because it'll break things or for whatever reason.
Speaker:So what are you doing?
Speaker:Well, we're doing four, five, and six.
Speaker:Well, four, five and six are kind of, okay.
Speaker:I'm gonna say that's maybe effective with opportunity for improvement.
Speaker:Uh, or they, they, they're doing a whole lot or they're not doing
Speaker:really anything because they.
Speaker:They didn't know.
Speaker:And so those are the really, the three options.
Speaker:You, you fail 'cause you didn't do what you were supposed to
Speaker:and you weren't mitigating it or mitigating it effectively.
Speaker:You were mitigating it somewhat effectively, but I
Speaker:think it could be stronger.
Speaker:And that's from a, an auditor's perspective, there is that kind of, uh,
Speaker:latitude where I can, I can add some.
Speaker:Objectivity, um, or I say subjectivity.
Speaker:Uh, and then lastly, wow, you, you really, you really are, you really do understand
Speaker:that mitigation's gotta be stronger.
Speaker:And, and, but that's, that's rare.
Speaker:Very rarely did I see the mitigating controls more effective
Speaker:than the, the original controls.
Speaker:I'm glad that you you mentioned um the the the the the comment that you made
Speaker:I is one that we make a lot from the opposite side and that is the backup
Speaker:People should never be setting policy They should never be determining you know
Speaker:retention periods uh RTOs and RPOs Uh you know that that should never be the
Speaker:case That should always come from the business Um and so we we we say that a
Speaker:lot and so it it's good to hear it just from a from a from a different uh frame
Speaker:of view Um uh I don't think you ever got around to defining defining cyber hygiene
Speaker:So cyber hygiene.
Speaker:I mean, if, if we keep in, in our, in our, uh, in our discussions, we
Speaker:keep coming back to the real world.
Speaker:'cause I think that's helped, that helps people, uh, relate.
Speaker:Uh, so applying real world stuff to cyber hygiene is very similar.
Speaker:If you, if you're not.
Speaker:Keeping or maintaining your own personal hygiene, you're gonna get sick.
Speaker:Um, or, or people are gonna think you're sick, one of the two.
Speaker:Uh, so in cyber there are things that you should be doing just
Speaker:like in real, in real world.
Speaker:Take your vitamins, go see a doctor, get your checkups, uh, do healthy things.
Speaker:One, cyber, those, those.
Speaker:Activities are making sure that your systems aren't vulnerable.
Speaker:So, uh, inoculating them for, in, in, uh, kind of as a, an analogy there.
Speaker:Uh, and we do that through patches.
Speaker:Uh, so we, we subscribe to services.
Speaker:If it's a Windows machine that do it automatically, if
Speaker:you've got it turned on, um.
Speaker:It and it will check your systems to determine if there's a vulnerable,
Speaker:uh, configuration or a, a, a patch that's out, that, that would,
Speaker:um, address a, a known problem.
Speaker:Um, so patch management is very important.
Speaker:Um, the other part of that is, well, who can access my stuff?
Speaker:Uh, that's me obviously, and the people that I give access to my systems.
Speaker:But then how do we know that it's really them because.
Speaker:The number one traded commodity on the dark web web right now is
Speaker:access, and that's credentials.
Speaker:So how do we, you know, what's a good practice for making sure that
Speaker:you know, someone that, that I trust, uh, that their credentials
Speaker:aren't out there and someone's, you know, some bad guy's not using them.
Speaker:So that's, that's where multifactor authentication
Speaker:comes in, but very similar to.
Speaker:You know, in the real world, vitamins and all these other healthy things, you have
Speaker:to do it responsibly and appropriately.
Speaker:And MFA is definitely one of those that I think the majority of organizations just
Speaker:say we have it and they're not using it.
Speaker:Right.
Speaker:Um, and then lastly, you know, password management, um, probably, um,
Speaker:appropriately at the bottom of the list.
Speaker:Uh, it's still part of hygiene, but not as effective as it used to be 'cause.
Speaker:You know, bad guys aren't trying to guess your password, they're just
Speaker:stealing it from somewhere else, right?
Speaker:Your, your work password is probably a password you've used somewhere
Speaker:else at some point in time.
Speaker:Well I
Speaker:bad guys are just
Speaker:Yeah but that but that's the point of of good Cyber hygiene Right Is
Speaker:not doing that Right We're gonna get to I think we'll get to that in in a
Speaker:right.
Speaker:Yep.
Speaker:So we'll get into the details of what, uh, what a good password
Speaker:practice, uh, uh, would be, uh, similar to patching and, and MFA.
Speaker:Mike, so these are three great sort of.
Speaker:Things you should be doing from a cyber hygiene perspective.
Speaker:Um, but how did you come up with this list, like right, or, I know
Speaker:you and Curtis have been talking about this for a while, but like, why
Speaker:are these the three most important?
Speaker:Is it based on like scenarios you've encountered working with customers,
Speaker:helping them recover from ransomware?
Speaker:Like why should someone believe the sort of 90% of ransomware could be?
Speaker:I can jump in on that one I mean it it's because it of the stories that
Speaker:I've read over the last you know so many years it it was always it was always
Speaker:one of these three right If if if they had just patched the system then they
Speaker:wouldn't have the vulnerability if they had just either not allowed the password
Speaker:to be stolen or if they had the if or or compromised in some way And then uh
Speaker:if if if that had happened if they had just had MFA And you know in uh you know
Speaker:what's the word I'm looking for Um if they if they were just using MFA then
Speaker:then even if they had the password then they would've been able to get in Right
Speaker:Assuming that you didn't have MFA fatigue by the employee?
Speaker:But yeah we're we're gonna get to that We'll get to that But the the thing
Speaker:is if if if they had these things when you when you read back on the stories
Speaker:and I would add like because we're tech technically talking about cyber
Speaker:hygiene here and not backup hygiene but I'll add to this Immutable backups
Speaker:right If we have that if we have those four then um not only would you stop
Speaker:the you know the bulk of the attacks you would uh also be able to respond
Speaker:to the 10 that that you get Uh would your answer be any different there Mike
Speaker:Oh, very similar.
Speaker:So yeah, they, these three are the greatest common denominators, uh, of, of
Speaker:a lot of the, if not the majority of, uh.
Speaker:Incidents that are out there.
Speaker:Uh, but to Curtis's point and maybe where you were going, Prasanna Yeah.
Speaker:This list could get really long.
Speaker:It's, it's, you know, it's not just these three and the backups, it's also network
Speaker:segmentation and turning, you know, secure build guidelines and secure coding
Speaker:and, uh, you know, perimeter protection and vendor management and anti-malware
Speaker:and training and all those things.
Speaker:Uh, but when you look at the numbers, uh, the statistics of incidents
Speaker:that are out there and, and what.
Speaker:You know what, how you boil those down to the common denominate.
Speaker:Common denominators.
Speaker:It's, it's primarily these three.
Speaker:Because these are it's like this is to again going back to the real world this
Speaker:is the um I This is the have in in the real world when we talk about investing
Speaker:The very first thing they tell you to do is to have uh you know 90 days of
Speaker:of an emergency fund And that should be your first thing because there's no
Speaker:point in talking about like you know 4 0 1 Ks and Roth IRAs and all these things
Speaker:if you can't survive uh you know losing a paycheck for a couple of weeks right
Speaker:This is the um if you're not doing these Then just stop Like you know in the book
Speaker:we said like if you're not doing these three things just stop reading right now
Speaker:and go do those three things because it will stop 90 the other 10 like everything
Speaker:else The other 10 is the is the hard part right It's the more expensive part
Speaker:But doing password management and patch management and and MFA or um uh pass
Speaker:keys which we'll we'll talk about that a little bit more but if if we do that
Speaker:Then it it's it's a it's the low hanging fruit Um you know that that allows
Speaker:us to secure the the environment um without without massive cost or anything
Speaker:weird I I still hear your your fan
Speaker:came back on.
Speaker:Yeah it just came back on even though we have the noise reduction on
Speaker:And there, there's zero change on my side, so there's no extra noise or anything.
Speaker:And then it and then it just left
Speaker:It's like a power surge or something.
Speaker:I'm not sure.
Speaker:I got nothing Um I So weird Um all right Well luckily it was me that was talking
Speaker:so I could mute it out Um yeah so this this is like this is the if you're not
Speaker:doing these things and don't it's like it's like when we start talking about
Speaker:uh offsite backups there's no point in talking about offsite backups if you're
Speaker:not making backups in the first place Right Right This is the this is the if
Speaker:you're not doing these things and don't even talk to me Don't even start if you're
Speaker:not doing basic cyber hygiene then um then there's no point in in continuing
Speaker:on with with further discussions
Speaker:Uh let's see here Um all right so I Let's just let's just talk a little bit about
Speaker:when we talk about patching how do we know uh and we're gonna do an episode
Speaker:on each of these things but just the basic thing what what do you think would
Speaker:be the easiest That that's what cause that's what we're trying to do here What
Speaker:would be the easiest way to make sure that we're running all of the appropriate
Speaker:patches Mike especially the critical ones
Speaker:It's, it's easy if you're organized and the first step in getting organized is
Speaker:doing an inventory of the things that you have, because, you know, patch,
Speaker:you have to work off your inventory to know who, who to get patches from.
Speaker:Right.
Speaker:Is it, is it.
Speaker:Red Hat Linux.
Speaker:Is it Windows?
Speaker:Is it third party tools?
Speaker:Adobe, uh, you know that 3D modeling tool?
Speaker:You use AutoCAD?
Speaker:What is it?
Speaker:So you've gotta inventory all this stuff first and then find out if you can
Speaker:actually get notifications from them.
Speaker:For when patches are available.
Speaker:Uh, if you don't do that on the proactive side, then you're gonna
Speaker:get it on the reactive side.
Speaker:'cause hopefully part of hygiene is also your periodic vulnerability assessments.
Speaker:And if, if you need help with that, we can, we can walk you through some
Speaker:free open source ways to do that.
Speaker:But.
Speaker:Every now and then you need to be scanning all of your assets for vulnerabilities.
Speaker:That's gonna turn up some configuration problems, some missing patches.
Speaker:Well then, alright, reactively, now I, well there's a missing patch
Speaker:and usually it comes with a link from these vulnerability tools.
Speaker:Uh, so go do that and while you're doing it, find out if there's a way
Speaker:to subscribe to that information.
Speaker:Um, so.
Speaker:Easy.
Speaker:It's not easy, but organi, and that's one of the reasons people
Speaker:don't do it 'cause it's not easy.
Speaker:Um, and there are tools out there that are fairly expensive to
Speaker:do it in an automated fashion.
Speaker:And then somewhere in between there's managed services and other
Speaker:things, but it's gotta start with understanding what it is you have,
Speaker:uh, and then figuring out where to get the information for available patches
Speaker:and issues with those, those assets.
Speaker:this is the hardest thing today versus back in the day right Back in the day I
Speaker:could walk into a server room and I could I could literally just have a piece of
Speaker:paper and check off I have this one I have this one I have this one Now we have
Speaker:a We don't have any service to point at Everything's virtual Everything's in the
Speaker:cloud And we have we have you know um IAS we have PAS we have SAS right We have all
Speaker:of these different ways where uh and and I'd say the SaaS is probably the worst
Speaker:because it's so easy to to propagate Um The you know to to go across the um the
Speaker:thing and and you did you did remind me when we talk about inventory you did
Speaker:remind me again back in the day We had uh when I was the backup guy my very first
Speaker:job in it We had we had a very boring naming convention We had H-P-D-B-S-V-A
Speaker:HP database server a right bbc so on And I ha I was I was becoming worried that I
Speaker:wasn't getting all the servers cause we started out we literally when I started
Speaker:at the bank we had seven Servers at T three B twos by the way for those you
Speaker:know that's what we had which was for the record the first computer designed to run
Speaker:Unix so they were old right Anyway so we went from having seven servers to having
Speaker:like 200 servers and I was starting to panic that we We didn't have a correct
Speaker:inventory And so um but the the naming convention was very helpful And so I had
Speaker:this this practice of when you had a new server you had to give me a form to say I
Speaker:want this server backed up And I put this thing on there that said don't consider
Speaker:it backed up until you get the form back for me Signed that said that I saw the
Speaker:form and I put it on the list And then one day somebody handed me a form and they
Speaker:it said like H-P-D-B-S-V and I'm like And they're like yes I go so that would by by
Speaker:you know my inference that means there's an M and an L a K somewhere And they're
Speaker:like well yeah And I'm like I only know up to j So so I'm gonna go find K and l
Speaker:and m and uh and we'll start backing all of them up I agree with you Mike A hundred
Speaker:percent That inventory is absolutely the place to start And Prasanna you were
Speaker:about to say something before I waxed up
Speaker:No, it, that's actually a pretty funny story, Curtis, but I'm not surprised.
Speaker:You always have all these great stories from working at the bank and other places.
Speaker:But Mike, I know you talked about patch management, right,
Speaker:and how to apply patches.
Speaker:is there something similar for cases where maybe patches aren't available?
Speaker:Like, it's great you have an inventory of everything that's there, but
Speaker:how do you deal with sort of, um, exploits that are currently out
Speaker:there before patches come out?
Speaker:So those are zero days in, in most cases.
Speaker:Uh, so zero day is something was identified today, and vendors haven't had
Speaker:a chance to respond to that with a patch.
Speaker:Um, well, and, and I'll add real quick, sometimes the patch that's
Speaker:available becomes your zero day because it doesn't work in your environment.
Speaker:Uh, and so along with patch management, you need to develop.
Speaker:Process for testing the patch, applying it to a test machine to
Speaker:see its effects on how things run before you move it into production.
Speaker:So, uh, be mindful of that too, but to your point, Prasanna about things
Speaker:that come up that don't have a, a fix, uh, those mitigating controls.
Speaker:Like how do we, alright, so there in.
Speaker:It does depend.
Speaker:So is this a public facing thing?
Speaker:Uh, do people log into it?
Speaker:Is it a, is it a, you know, prized possession of our company
Speaker:with, you know, sensitive data?
Speaker:Or is it just that, that thing I could potentially turn off or isolate?
Speaker:Um, so you've gotta do some analysis first, like what's
Speaker:the risk, what's the impact?
Speaker:And then respond accordingly if it's.
Speaker:Publicly accessible internet facing.
Speaker:Then put some monitoring on it, put some logging on it, try to isolate it.
Speaker:Uh, those mitigating controls in the absence of a, uh, a true
Speaker:solution have to be assessed and applied as fast as possible.
Speaker:I like that Um
Speaker:and
Speaker:so
Speaker:there, there are, there are services out there.
Speaker:I ran into one not too long ago.
Speaker:It's outta New Zealand and it's, I don't have a fix for this.
Speaker:It's essentially a proxy.
Speaker:So they, they stand up a uh, um.
Speaker:An internet facing version of whatever it is that's fed from your environment.
Speaker:And they analyze and filter all the requests for that information as a proxy.
Speaker:Uh, and, and you can, you can subscribe to that until a solution is, uh, is applied.
Speaker:So that was pretty interesting.
Speaker:I did, I did see that.
Speaker:Yeah that's that does sound interesting uh from the so that's the the patches
Speaker:world and again we're gonna do an episode on each of these three Uh but that's the
Speaker:patches world Let's talk a little bit about the passwords Um and and I think we
Speaker:can all agree one some method Again I'm I'm a big fan of of password management
Speaker:like a password manager But you need some method So you absolutely do not ever
Speaker:use the same password in multiple places because that is the problem is uh I and
Speaker:I got a I got a um I got in a argument is a is a strong term but I got into a
Speaker:discussion with a with a guy on I think it was somebody that commented on one
Speaker:of our videos and um where he was saying that he was using Uh this system where
Speaker:he what he does is he he has a password that he uses on like a a small subset
Speaker:of systems Like he has like 10 passwords that he uses everywhere And so his method
Speaker:of like mitigating the risk is that he doesn't wanna use a password manager
Speaker:He doesn't believe in using a password manager So he has like 10 passwords that
Speaker:he sprinkles around and he just has to remember uh 10 passwords in his head um
Speaker:and he uses the the battery horse staple method Um right which is which is a good
Speaker:method right Uh for those of you who don't know what I'm talking about This is
Speaker:the um the idea of what we're gonna talk more about I'm sorry It is just this idea
Speaker:of having an password that is long but actually easy to remember because most of
Speaker:the passwords that we have that are long are total garbly gook and they can only
Speaker:be remembered by a password manager So he uses that method and then he has like
Speaker:10 passwords and I was like well that's Again better than nothing better than
Speaker:using the same password everywhere But if if there's avol if there if if any one
Speaker:of those systems where you're using that same password are ever compromised then
Speaker:you have to change the password everywhere where you're using that password And
Speaker:potentially by the time you get around to doing it it's already been compromised
Speaker:And um so this is just again my way to do this is password manager and I think
Speaker:that's the number one most recommended way But besides making sure that we do
Speaker:not use the same password in multiple places What else Basic uh password hygiene
Speaker:stuff do we need to talk about Mike
Speaker:Real quick, I think a good term for your, uh, your disagreement.
Speaker:Uh, and it's an older term, uh, that, that you just don't hear
Speaker:very often is a kerfluffle.
Speaker:Careful
Speaker:I think that's a good yes.
Speaker:Uh, anyway, so back to back to passwords.
Speaker:Uh, I think a good practice these days, especially as we suggest passwords
Speaker:become longer and longer, and, uh, I don't know if, if, uh, if, if you
Speaker:guys realize where that came from.
Speaker:Uh, so it stemmed from the, the, the length of a password.
Speaker:okay
Speaker:How long
Speaker:So a stem.
Speaker:compute right?
Speaker:So that's.
Speaker:A combination of things, right?
Speaker:So when, when Windows or, or Linux, Unix, uh, encrypts a password, uh, with,
Speaker:you know, a ES 2 56 or whatever it is, there's a ma math, there's a mathematical,
Speaker:um, response to how long it would take to crack a password of certain length.
Speaker:Well, that's been defeated, uh, by a project called Rainbow Tables.
Speaker:Rainbow tables just encrypts and, and captures the, the hash value
Speaker:of every conceivable, random known dictionary, multiple languages.
Speaker:And so it's not, I don't have to crack your password anymore, I just have to
Speaker:take your password hash and go look it up.
Speaker:And see if that's already been done.
Speaker:So it's not a math problem anymore.
Speaker:It's, it's a, it's a, it's a research problem.
Speaker:All right, well then a vulnerability came out in, uh, with Windows.
Speaker:'cause if you had, uh, um, NTLM, the, the hash in windows turned on, it would
Speaker:take your password hash and break it up into two eight character hashes.
Speaker:Well, now I can, I can crack them individually.
Speaker:Instead of cracking one large, I can do two small ones.
Speaker:And there's vulnerability associated with that.
Speaker:So now we should have greater than 16 character passwords for that reason.
Speaker:And, and it, and you know, I can drive policy now, it says it's gotta be 16.
Speaker:Well, if it has to be 16, the IT guys that have not wanted to change the LTLM now
Speaker:have to, they have to turn that off to, to generate, you know, and so there's.
Speaker:It's political game, but also based on, um, some known
Speaker:vulnerabilities around passwords.
Speaker:Alright, well now we've got 16 character or greater passwords.
Speaker:How are you gonna get users to remember that?
Speaker:Password hackers are great.
Speaker:Uh, password managers are great because it can also randomize passwords so
Speaker:you don't have to remember it anymore.
Speaker:You just log into your password manager and copy and paste.
Speaker:Um, and so you, you don't have to remember it anymore.
Speaker:And it can be random, which is also.
Speaker:Helpful, but then not everybody can subscribe to that approach.
Speaker:So they, they want these password phrases now.
Speaker:And so some interesting things about password phrases, uh, and similar to
Speaker:what Curtis was describing with, you know, having a root password and then
Speaker:you know, something at the beginning and something at the end that's helpful,
Speaker:especially if it's, if you want the same route password for everything, and then
Speaker:you just change the front and the back depending on what you're logging into.
Speaker:Uh, that can be troublesome though.
Speaker:'cause as a bad guy, I just need two of those to realize that's a pattern
Speaker:and I can just kind of guess, uh, what, uh, what, what your bank password
Speaker:is if, if I don't have that already.
Speaker:Um, so some things to think about.
Speaker:Um, you know, if you're logging into your bank, maybe your past phrase is,
Speaker:uh, I like getting paid on Friday, and then at the beginning or the end, uh,
Speaker:you know, uh, and that makes me happy.
Speaker:Or, you know, added emotion or add a, add a color that makes you think
Speaker:of, you know, that emo it's blue.
Speaker:Uh, I think that's calming, right?
Speaker:Uh, and then, and then change up how it felt.
Speaker:the way Mike I was gonna
Speaker:Green.
Speaker:Green is okay.
Speaker:for for money
Speaker:red.
Speaker:So then, you know, do some substitution.
Speaker:So instead of, you know, ease, use threes and capitalize, you know, the first
Speaker:letter of a word or spell it backwards.
Speaker:Um, I had a password and man, long time, 20, 30 years ago, uh, where it
Speaker:was, I spelled everything backwards.
Speaker:Um.
Speaker:So there, there are some unique things that you can do with passwords.
Speaker:You just have to figure out which one works for you, uh, and that
Speaker:you can be consistent with it.
Speaker:The password manager will also help you remember to, it's about time you've
Speaker:been using this password for 10 years.
Speaker:Now
Speaker:Yeah
Speaker:time to change it.
Speaker:you if you do use it in multiple places right It was like Hey you you've used
Speaker:this password elsewhere I'm I'm a big fan of password Brandon I know
Speaker:Prasanna You have one right What
Speaker:do, should we wait to talk about this on the
Speaker:Yeah Yeah you're right You're right you're right Yeah Yeah All right So yeah
Speaker:so basically the idea is the the the overall overriding concept is to not use
Speaker:the same password anywhere Never use the same password twice And and if you're not
Speaker:using some kind of system my method is password manager Um you know the the the
Speaker:the one that you talked about Mike the the one where you append it and pre-end
Speaker:it with with something and you have this core password that used to be my method
Speaker:before I went to a password manager Um and the the you know and then there's there's
Speaker:this these other ways to to have it but I I can't ima I have like 500 passwords
Speaker:at this point right so I can't imagine um not having uh a password manager at
Speaker:this point But so that's that's my way to do that But the core concept is you
Speaker:cannot use the same password at multiple places And why is that Mike We we kind
Speaker:of alluded it to it uh a few minutes ago
Speaker:You remember, we call those coincidental passwords.
Speaker:Uh, and and the reason you don't wanna use them in more than one place
Speaker:is because you've gotta rely on the security of more than one thing to make
Speaker:sure your password isn't compromised.
Speaker:And when bad guys compromise one data set, they're gonna use that data set
Speaker:across everything they can think of.
Speaker:So if I've got one of Curtis's passwords and I know he has 500 accounts out
Speaker:there, I'm gonna use that one password to try and log into 499 of those,
Speaker:And especially
Speaker:could be.
Speaker:one username is your email address right So you so you already know my email
Speaker:address and you go out there and you use the Password everywhere You know you
Speaker:just you don't even need to know where I have the thing You just you just try
Speaker:it All the places that you have access and you're and this is a numbers game
Speaker:You're trying every every account that you have access to with every password
Speaker:you have access to in every place that you have access to the the system Right
Speaker:Um so yeah that's why we don't do it
Speaker:Yep.
Speaker:And, and how do you mitigate that?
Speaker:by using the different password in every place Right
Speaker:Well, well, how so?
Speaker:What if, what if they guess what if they have a password?
Speaker:You forgot you used 20 years ago and now there's an account that
Speaker:that password's gonna work on.
Speaker:How do you mitigate that MFA.
Speaker:Oh okay I was I I should have known this answer Dammit Uh yeah So yeah so so MFA
Speaker:uh you know is the final thing on our on our on our trifecta of of basic cyber
Speaker:hygiene And I and I'll put MFA slash slash um you know pass keys which is like it's
Speaker:like the next thing cause we'll as we when we talk about MFA We will mention that
Speaker:MFA is not perfect Uh Prasanna's already alluded to it You know there's this thing
Speaker:called MFA exhaustion There are there are other issues with it but let's just
Speaker:start with what MFA is Um uh Prasanna why don't why don't why don't you define MFA
Speaker:What is it you know and how does it work
Speaker:Sure.
Speaker:So with MFA, it's really, Mike said, someone might compromise your
Speaker:password and so it's something you know and something you have, right?
Speaker:And so that something you have piece is normally, say your
Speaker:biometrics like a fingerprint.
Speaker:It could be your face, right?
Speaker:It could be a. Electronic token that gets generated periodically
Speaker:or some other application, right?
Speaker:That generates that such that you have a second factor, which previously was
Speaker:called sort of two-factor authentication.
Speaker:Right now it's multifactor in order to be able to say, yes, this really is me.
Speaker:The most common one I'd say
Speaker:I'd say the most common one is probably SMS Um it's definitely not the best
Speaker:one uh but it's certainly the most common I think the most common use to
Speaker:be email I really don't like email like in good better best It's barely good uh
Speaker:because again if you uh if somebody's compromised your email account especially
Speaker:if it's the email account that you use for everything right Um SMS is not as
Speaker:good because SMSI think SMS is actually better today than it used to be uh it's
Speaker:harder to do sim hacking today than it than it used to be uh at least in in
Speaker:certain circumstances Um and then but then uh the I think the best one that
Speaker:we have today that's available to pretty much everybody is uh an authenticator
Speaker:type app You wanna talk about that Mike
Speaker:Sure.
Speaker:Uh, and, and those apps are generally free, uh, and, and don't require any.
Speaker:Infrastructure changes.
Speaker:There are some, uh, like duo, uh, that would require some licensing and set up
Speaker:on the inside of, uh, your organization.
Speaker:Um, but others like the Microsoft Authenticator app, uh,
Speaker:Google has one, they're free.
Speaker:You just get 'em in the play store.
Speaker:And then whenever you want to register your multifactor with a vendor, a
Speaker:lot of times there's like a QR code or a set up your account this way.
Speaker:Um.
Speaker:Similar to a password manager, you would log into your authenticator app and it
Speaker:would show all your different accounts, uh, which you could revoke or delete if
Speaker:you think that's compromised as well.
Speaker:So you can manage it that way, but pretty, pretty straightforward.
Speaker:And, you know, MFA, uh,
Speaker:um, fatigue, MFA fatigue is a real thing.
Speaker:It's more of a. It's just annoyance.
Speaker:Uh, so you log into something and you, oh, I've gotta wait for my phone to ding.
Speaker:Now what if, what if you don't have cell phone coverage or data,
Speaker:uh, you know, wireless data?
Speaker:Um, a lot of these authenticator apps also allow you to save.
Speaker:Backup codes, um, things like, so there's, there's any number of ways
Speaker:of, of using what works for you.
Speaker:Um, the important thing is to figure out something other than email, um, for your
Speaker:MFA if, if the, the account that you're wanting to apply MFA to will support it.
Speaker:And Mike, I know on a previous podcast you sort of mentioned one of the
Speaker:downsides with many websites, right?
Speaker:Which have MFA, and then they sort of have the remember me
Speaker:next time on this thing, right?
Speaker:Right.
Speaker:So it, it's, it's whether it's a website like, um, I don't know,
Speaker:Amazon I was gonna
Speaker:Amazon, right?
Speaker:yeah
Speaker:either one of those, there is a, remember, it's, it's, remember this device, um,
Speaker:you don't want to do that because your MFA token is then stored in your browser.
Speaker:And so now a bad guy just asked to get you to a position or a situation where I can
Speaker:scrape that MFA token out of your browser if I already have your credentials.
Speaker:The only thing I need now is your MFA token, and now
Speaker:I can get into your account.
Speaker:So
Speaker:I was gonna say, so MFA good MFA has to come with good policy and good practice.
Speaker:So the the the point of this episode here is just to just if you're not familiar
Speaker:with any of those three things go get familiar Um and the best way to do that
Speaker:is to uh log in next week and we'll cover each of these in detail Um but uh You
Speaker:know the idea between behind MFA is that if somebody gets a hold of your password
Speaker:they won't be able to log in because they don't have that additional factor
Speaker:whatever it is whether it's SMS or or um you know an authenticator app or a token
Speaker:right We'll talk about these more and and all of those and passwords and MFA have
Speaker:limitations and those limitations are us right It's the human and that's why
Speaker:I think pass keys is the better option As we move forward in the future and I
Speaker:I've been rolling out Pasky uh in many places wherever I can Uh it I'm not sure
Speaker:if if it's great for like the average Joe there it can be confusing Um PAs
Speaker:keys can be confusing if you don't if you don't know what you're doing But um but I
Speaker:Did you ever use iron keys?
Speaker:Curtis?
Speaker:Uh what's a iron key
Speaker:So an iron key is a, it's a military grade USB, and uh, in it, it's
Speaker:got its own, you know, TPM chip.
Speaker:Its own encryption, its own password manager, its own MFA.
Speaker:And if you log into it, I think it's 20 times wrong, it self-destructs,
Speaker:it's got a little capacitor in it.
Speaker:It like, it'll smoke, uh, and if you try to cut into it to get to the chips, it's
Speaker:also got a sensor and will self-destruct.
Speaker:Yeah
Speaker:Yeah, it's pretty cool.
Speaker:that, but doesn't surprise me that you probably have.
Speaker:Um, but anyway, so the, again, this is meant to be an overview episode.
Speaker:Um, and if some of this was, was confusing or frustrating or you
Speaker:felt like we didn't go into detail enough, then just, uh, we're gonna do
Speaker:three more episodes where we go into each of these, uh, in more detail.
Speaker:but it just.
Speaker:You know, start looking into these three things.
Speaker:Password man, regular password management.
Speaker:I'm gonna start with that Inventory, right?
Speaker:Make sure you have an inventory of everything, both your physical, your
Speaker:virtual, and your, and your cloud systems.
Speaker:What,
Speaker:Wait, you said
Speaker:what?
Speaker:You meant patch management?
Speaker:Oh, did I say that?
Speaker:Okay.
Speaker:All right.
Speaker:So again, uh, you know, summary here, we've got three things here, right?
Speaker:Make sure you're doing pa uh, uh, patch management, right?
Speaker:Uh, that some sort of automated system.
Speaker:Uh, and, and we're gonna start with an inventory, right?
Speaker:A physical inventory, a virtual inventory, and a, an a SaaS inventory
Speaker:of your entire environment to make sure that you know what it is you're
Speaker:supposed to be looking out after.
Speaker:You're gonna have a good password manager and you're gonna have good.
Speaker:Um, you're gonna have an MFA or you're gonna have a, a passkey based system.
Speaker:Uh, because, uh, without these three things, no point in having, you know, like
Speaker:looking into an EEDM or, uh, I'm sorry, EDM looking into A EDR or an XDR system.
Speaker:Um, and, um, you know, or, or you know, any, any of the other stuff
Speaker:that we're talking about because it's like looking into a Roth IRA if you
Speaker:don't even have a savings account.
Speaker:Right.
Speaker:Um, so, With that, uh, any final thoughts, Mike?
Speaker:Doing something's better than nothing.
Speaker:one of these and
Speaker:yeah,
Speaker:do something about it.
Speaker:absolutely.
Speaker:What about you, Prasanna
Speaker:Well, I think the three makes sense and hopefully everyone
Speaker:is using a password manage.
Speaker:There.
Speaker:I'm,
Speaker:I've got a story about password management.
Speaker:Please, please,
Speaker:we were doing a, a red team on a, a brick and mortar nationwide retail.
Speaker:Sorry.
Speaker:Yeah.
Speaker:we save this for the actual password manager episode?
Speaker:Yeah, maybe
Speaker:Sure it is a password
Speaker:besides
Speaker:management.
Speaker:it's so weird.
Speaker:The, the, the, the thing came on there for about 30 seconds and then went off again,
Speaker:and you don't hear anything on your end.
Speaker:Nothing changes here.
Speaker:It's completely quiet in this room.
Speaker:That's so weird.
Speaker:Uh, a, it's a, what do they call it?
Speaker:It's ghost and Shell, um, all right.
Speaker:Uh, all right.
Speaker:that up is 'cause we're already at 48 minutes.
Speaker:So,
Speaker:Yeah, yeah, yeah.
Speaker:Well, we're gonna cut, we're gonna cut some of this out pretty much
Speaker:half the time that Mike talks.
Speaker:We're just cut it out.
Speaker:anyway.
Speaker:All right, Prasanna Thanks.
Speaker:Thanks for, uh, being here again as well.
Speaker:Forever.
Speaker:and look, see I shaved, just so you know.
Speaker:Yeah, absolutely.
Speaker:Absolutely.
Speaker:Alright.
Speaker:Actually, I, I don't know if anybody can tell, but I, I had
Speaker:my, I had my beard trimmed.
Speaker:I had a photo op yesterday, so it, my beard's all nice and trimmed.
Speaker:So anyway, or as my granddaughter said, slay Um, and that is a wrap.
Speaker:Why do I stop?
Speaker:Okay.
Speaker:Most ransomware attacks succeed for one reason, somebody skipped the
Speaker:basics, patch management, password management, MFA or pass keys.
Speaker:These three things, do those right and you stop roughly 90% of the attacks.
Speaker:This week, Dr. Mike Saylor, uh, Prasanna and I walk through each
Speaker:one, what it is, why it matters, and what happens when you ignore it.
Speaker:Things like WannaCry, Rackspace.
Speaker:These, uh, stories are all real, and the lesson is the same every time.
Speaker:The basics weren't done.
Speaker:You don't need a massive budget or a fancy security stack to stop most hackers.
Speaker:You just need to do the boring stuff.
Speaker:Here we turn admins into cyber recovery heroes.
Speaker:This is the Backup Wrap Up
Speaker:All right.
Speaker:Um,
Speaker:Welcome to the backup wrap up.
Speaker:I'm your host, w Curtis Preston, AKA, Mr. Backup, and I have a, with
Speaker:me, a guy who apparently shaved last week and I didn't even notice.
Speaker:Prasanna
Speaker:Prasanna
Speaker:Malaiyandi how's it going?
Speaker:Prasanna
Speaker:I am good Curtis.
Speaker:Yeah.
Speaker:Uh, my wife was very surprised after the podcast recording when
Speaker:she was like, did Curtis notice?
Speaker:of course, I. I texted you and you're like, no, or no, I think
Speaker:No.
Speaker:on the phone and you're like, no, what are you talking about?
Speaker:And I had to send you a picture,
Speaker:Yeah.
Speaker:And, and apparently Mike, Mike didn't notice either, so I feel
Speaker:somewhat better, but, uh, yeah.
Speaker:So you, you, you've gone down to the goatee,
Speaker:Yep.
Speaker:um, and, um.
Speaker:many, many years since I've done this.
Speaker:Pre
Speaker:I've seen a picture of you with the goatee.
Speaker:Yeah.
Speaker:Pre, yeah, yeah, yeah.
Speaker:I think you should go back to your cut from college.
Speaker:That's what I think.
Speaker:The buzz.
Speaker:The buzz cut.
Speaker:Yeah.
Speaker:Yeah.
Speaker:I, I'd love to see you in the buzz cut again.
Speaker:Walked away.
Speaker:but, uh, anyway, speaking of buzz cuts, Dr. Mike Sailor, how's it going, Mike?
Speaker:Going Good guys.
Speaker:It's going good.
Speaker:All right.
Speaker:So he of course, is the co-author on, uh, uh, learning Ransomware Response
Speaker:and Recovery, which came out last month.
Speaker:Which, uh, do you have one with you now?
Speaker:Did you, did you prepare this time?
Speaker:I did not prepare this time.
Speaker:me Mike I have yet I still don't have mine and I have yet to actually see the a
Speaker:physical printed book even like a video of a physical printed book with with you know
Speaker:The book is gonna be the size of the thing in your background?
Speaker:Curtis?
Speaker:yeah I I would dear Lord dear Lord I hope not And you know what's funny is like
Speaker:in on the camera this thing looks fine but this is this is like this far back
Speaker:from me right And so this thing is like I think it's 15 by 24 That thing is massive
Speaker:Um so yeah I sure I surely hope not
Speaker:For those
Speaker:but
Speaker:watch us on YouTube, uh, we do have videos out, but Curtis was just pointing at
Speaker:the, what do you call it, the title page?
Speaker:The front
Speaker:It's the cover the front cover Yeah yeah yeah And uh available at uh
Speaker:So or you can order them directly from O'Reilly for the record if you order
Speaker:directly from O'Reilly Mike and I make more um So uh there's that All right uh
Speaker:we're gonna talk so we're gonna jump into this week we're gonna talk about the title
Speaker:It's gonna sound I I you know I never know exactly what the title's gonna be but it's
Speaker:gonna be something along the lines of stop 90 of the ransomware attacks that could
Speaker:possibly happen to you That's a really long title but um I I I you know it may
Speaker:sound like a bold claim but I I think it's pretty straightforward And Mike uh I'd
Speaker:like to start out this week What's that
Speaker:before, you
Speaker:Yeah
Speaker:can I make a bold claim?
Speaker:claim
Speaker:A
Speaker:please
Speaker:That you can stop a hundred percent of ransomware if you
Speaker:never do anything online.
Speaker:Um
Speaker:not, I think there's still some, some, some room there for infection.
Speaker:sorry.
Speaker:Well you know like if you if you if they do the um the drop you know the
Speaker:the one that we covered in the in the uh what do you call it Um when we did
Speaker:the MR Robot remember the drop USB stick
Speaker:Oh, that's
Speaker:Tchotchke drops.
Speaker:Yeah What what's that
Speaker:you win.
Speaker:We call 'em tchotchke drops.
Speaker:Tchotchke drops Yeah Yeah So even then um um but what what is this what is
Speaker:this not do things online thing that you're talking about I don't know what
Speaker:in the world Like I I don't even know
Speaker:Like saying you can't get sick if you don't go outside.
Speaker:Well, that's not true either.
Speaker:yeah Exactly all right Mike well do we do you have a story to
Speaker:start us out with this week I
Speaker:I do.
Speaker:Um, well man, there's so many to pick from, but, um, from the book,
Speaker:you know, we talk about WannaCry.
Speaker:Um, and similar to, to kinda what we touched on here, good hygiene
Speaker:can prevent a lot of stuff.
Speaker:And I think WannaCry is an example of bad guys identified of a
Speaker:vulnerability that was out there.
Speaker:They created a.
Speaker:Uh, a payload and a, and an attack vector to take advantage of that,
Speaker:realizing that, uh, there's a, a very large percentage of, uh, company and
Speaker:organization populations that don't have a, a solid patch management program or,
Speaker:uh, that it, it's pretty lax, you know, there's a lot of organizations that,
Speaker:that say we have a patch program, but it's, you know, 2, 3, 4 months behind,
Speaker:or it's gotta meet certain criteria and some things never get patched.
Speaker:Well, that's what happened with WannaCry.
Speaker:Well
Speaker:found a vulnerability,
Speaker:for those of us yeah For those of us that that you know haven't lived uh the
Speaker:the cyber world Why don't you tell us what was want Tory What you know did it
Speaker:did it make you want to cry Is that why it was called that And what you know
Speaker:when did it happen and you know what
Speaker:I was
Speaker:I think there was about 200,000,
Speaker:Yeah.
Speaker:I.
Speaker:200,000 people crying in unison,
Speaker:exactly
Speaker:uh, with WannaCry.
Speaker:I was going to say Curtis, that because there have been so many of these
Speaker:attacks over the years, it's also hard to keep like, which keep it straight
Speaker:in terms of like which one was which.
Speaker:Yeah Yeah So why don't you tell us the story of WannaCry Mike
Speaker:WannaCry, uh, was developed, uh, to take advantage of a vulnerability in
Speaker:SMB or a, uh, a Windows, uh, service.
Speaker:Um.
Speaker:That had a patch.
Speaker:So Microsoft came out with a patch.
Speaker:So it was several months later that the malware, this
Speaker:attack vector really came out.
Speaker:Um, and it was all of those organizations that did not
Speaker:apply that critical, uh, patch.
Speaker:And if, if, uh, if you were paying attention at all, you probably got
Speaker:an email from Microsoft saying, you really need to patch this.
Speaker:This, uh, this vulnerability.
Speaker:Um, or you've got automatic patches turned off, uh, which is common too.
Speaker:'cause a lot of organizations don't want to automatically apply
Speaker:patches to production systems and have them reboot and cause issues.
Speaker:But nonetheless, bad guys found a vulnerability, took advantage of it
Speaker:several months after the fact even,
Speaker:yeah And
Speaker:and.
Speaker:how many people were impacted
Speaker:Well, um, not, not necessarily people, but sy well over 200,000 systems
Speaker:were, were infected with WannaCry.
Speaker:That's that's quite a bit that hint your comment earlier 200,000 people all crying
Speaker:out at once Just like in just like in uh what do you call it Uh star Wars I I'm
Speaker:Yes,
Speaker:a Star Wars reference Um okay Alright but like and the thing is this is yet this
Speaker:is one of many many examples of hacks of attacks that had the um uh victims of
Speaker:the attack practiced basic cyber hygiene They would not have um been they they
Speaker:would not have been victimized by this attack Does that sound is that about right
Speaker:Good, good chance they would not have been a victim.
Speaker:Yes.
Speaker:Yeah yeah
Speaker:The, the, the only, the only, the only caveat that is that Ry is one of those
Speaker:ransomware malware that was also a worm.
Speaker:mm
Speaker:so as it infected a, a machine, uh, it's worm like behavior was what?
Speaker:Uh.
Speaker:What led itself to propagate in kind of an al alternative method.
Speaker:So if you weren't vulnerable to the SMB with Microsoft, you might've been
Speaker:vulnerable some other way that this, uh, this worm was able to compromise you.
Speaker:Okay Okay yeah when when I think back on uh my history I I think back um to shit
Speaker:um what's the name of the company The
Speaker:The one that uh Thank you Thank you Thank you Um I think back to
Speaker:the that was what two years ago
Speaker:I think it was two years ago.
Speaker:Yeah.
Speaker:Yeah Yeah I think back to the Rackspace hack because that was one where again
Speaker:it was a patch There was a patch to the vulnerability in Microsoft Exchange that
Speaker:uh again had Rackspace simply applied that patch they would not have been uh subject
Speaker:to this this particular attack And in this case there was um was a workaround
Speaker:there was a there was a vulnerability And then there was a workaround to the
Speaker:vulnerability while they were waiting on the patch But what happened is there was
Speaker:a um an undisclosed a zero day additional vulnerability that if they had they
Speaker:had applied the patch to fix the first the first vulnerability they would have
Speaker:been they would not have been subject to the to the zero day exploit um But they
Speaker:said to themselves uh this is my theory uh is that they said well we we put
Speaker:in the workaround And so therefore the criticality of this patch was not um you
Speaker:know it wasn't as critical And so they didn't put in the patch yet And two weeks
Speaker:uh after the You know this exploit came out Um they they were attacked and that
Speaker:cost them entire business line Right Um because they had to um they had to stop
Speaker:and it there was a there was lawsuits It was it was it was it was very very messy
Speaker:so let's talk about when we talk about uh cyber hygiene Um do you know do you want
Speaker:to do you wanna just define that uh Mike
Speaker:I will.
Speaker:And if, if I could back up just a minute.
Speaker:'cause you made a, a, a comment about mitigation, so we weren't
Speaker:able to apply the patch for whatever reason, so we mitigated the risk.
Speaker:Right
Speaker:Well, something that I think is critically important for people to
Speaker:consider when we talk about mitigation, and this comes from my, my audit.
Speaker:My audit life, uh, where, where I had to go and determine if people were
Speaker:following the rules, whether it was hygiene or we also called them, uh,
Speaker:general controls or best practices.
Speaker:If they weren't, then they had to demonstrate what they were
Speaker:doing to mitigate the risk.
Speaker:Presented by the absence of doing what we expected and the audit guidance and
Speaker:what we would tell people and what people should consider is that your mitigation
Speaker:strategy should be more effective.
Speaker:Had you done it the right way to begin with.
Speaker:Hmm
Speaker:a
Speaker:So if the control says, do one, two, and three, and you say, I can't
Speaker:do one, two, and three, well, you better do 4, 5, 6, 7, 8, 9, and 10.
Speaker:Your mitigation needs to be stronger than the original control or activity.
Speaker:which
Speaker:Interesting
Speaker:But I guess in your experience, Mike, how often were people
Speaker:able to meet that higher bar?
Speaker:Well, if you were a regulated organization, you had to, or you failed.
Speaker:Or, or I
Speaker:Yep.
Speaker:often would they just say four, five and six, seven are two difficult.
Speaker:Let me just go back and implement one, two, and three.
Speaker:Never, never did they do that.
Speaker:Uh, so they either so and, and it, and.
Speaker:With a grain of salt, obviously.
Speaker:So I was, I was a technology auditor, so I was auditing it people, it people that
Speaker:generally don't run the business, right?
Speaker:They're being, they're given direction from the business of, you know, we
Speaker:can't fix that thing because our website will stop working or it'll be down
Speaker:too long, we'll lose too much money.
Speaker:So businesses directing the technology, uh.
Speaker:Um, you know, groups and, and infrastructure of, of
Speaker:what they can and can't do.
Speaker:And so when, when you talk to them about, well, you, you couldn't do
Speaker:one, two, and three, so, because it'll break things or for whatever reason.
Speaker:So what are you doing?
Speaker:Well, we're doing four, five, and six.
Speaker:Well, four, five and six are kind of, okay.
Speaker:I'm gonna say that's maybe effective with opportunity for improvement.
Speaker:Uh, or they, they, they're doing a whole lot or they're not doing
Speaker:really anything because they.
Speaker:They didn't know.
Speaker:And so those are the really, the three options.
Speaker:You, you fail 'cause you didn't do what you were supposed to
Speaker:and you weren't mitigating it or mitigating it effectively.
Speaker:You were mitigating it somewhat effectively, but I
Speaker:think it could be stronger.
Speaker:And that's from a, an auditor's perspective, there is that kind of, uh,
Speaker:latitude where I can, I can add some.
Speaker:Objectivity, um, or I say subjectivity.
Speaker:Uh, and then lastly, wow, you, you really, you really are, you really do understand
Speaker:that mitigation's gotta be stronger.
Speaker:And, and, but that's, that's rare.
Speaker:Very rarely did I see the mitigating controls more effective
Speaker:than the, the original controls.
Speaker:I'm glad that you you mentioned um the the the the the comment that you made
Speaker:I is one that we make a lot from the opposite side and that is the backup
Speaker:People should never be setting policy They should never be determining you know
Speaker:retention periods uh RTOs and RPOs Uh you know that that should never be the
Speaker:case That should always come from the business Um and so we we we say that a
Speaker:lot and so it it's good to hear it just from a from a from a different uh frame
Speaker:of view Um uh I don't think you ever got around to defining defining cyber hygiene
Speaker:So cyber hygiene.
Speaker:I mean, if, if we keep in, in our, in our, uh, in our discussions, we
Speaker:keep coming back to the real world.
Speaker:'cause I think that's helped, that helps people, uh, relate.
Speaker:Uh, so applying real world stuff to cyber hygiene is very similar.
Speaker:If you, if you're not.
Speaker:Keeping or maintaining your own personal hygiene, you're gonna get sick.
Speaker:Um, or, or people are gonna think you're sick, one of the two.
Speaker:Uh, so in cyber there are things that you should be doing just
Speaker:like in real, in real world.
Speaker:Take your vitamins, go see a doctor, get your checkups, uh, do healthy things.
Speaker:One, cyber, those, those.
Speaker:Activities are making sure that your systems aren't vulnerable.
Speaker:So, uh, inoculating them for, in, in, uh, kind of as a, an analogy there.
Speaker:Uh, and we do that through patches.
Speaker:Uh, so we, we subscribe to services.
Speaker:If it's a Windows machine that do it automatically, if
Speaker:you've got it turned on, um.
Speaker:It and it will check your systems to determine if there's a vulnerable,
Speaker:uh, configuration or a, a, a patch that's out, that, that would,
Speaker:um, address a, a known problem.
Speaker:Um, so patch management is very important.
Speaker:Um, the other part of that is, well, who can access my stuff?
Speaker:Uh, that's me obviously, and the people that I give access to my systems.
Speaker:But then how do we know that it's really them because.
Speaker:The number one traded commodity on the dark web web right now is
Speaker:access, and that's credentials.
Speaker:So how do we, you know, what's a good practice for making sure that
Speaker:you know, someone that, that I trust, uh, that their credentials
Speaker:aren't out there and someone's, you know, some bad guy's not using them.
Speaker:So that's, that's where multifactor authentication
Speaker:comes in, but very similar to.
Speaker:You know, in the real world, vitamins and all these other healthy things, you have
Speaker:to do it responsibly and appropriately.
Speaker:And MFA is definitely one of those that I think the majority of organizations just
Speaker:say we have it and they're not using it.
Speaker:Right.
Speaker:Um, and then lastly, you know, password management, um, probably, um,
Speaker:appropriately at the bottom of the list.
Speaker:Uh, it's still part of hygiene, but not as effective as it used to be 'cause.
Speaker:You know, bad guys aren't trying to guess your password, they're just
Speaker:stealing it from somewhere else, right?
Speaker:Your, your work password is probably a password you've used somewhere
Speaker:else at some point in time.
Speaker:Well I
Speaker:bad guys are just
Speaker:Yeah but that but that's the point of of good Cyber hygiene Right Is
Speaker:not doing that Right We're gonna get to I think we'll get to that in in a
Speaker:right.
Speaker:Yep.
Speaker:So we'll get into the details of what, uh, what a good password
Speaker:practice, uh, uh, would be, uh, similar to patching and, and MFA.
Speaker:Mike, so these are three great sort of.
Speaker:Things you should be doing from a cyber hygiene perspective.
Speaker:Um, but how did you come up with this list, like right, or, I know
Speaker:you and Curtis have been talking about this for a while, but like, why
Speaker:are these the three most important?
Speaker:Is it based on like scenarios you've encountered working with customers,
Speaker:helping them recover from ransomware?
Speaker:Like why should someone believe the sort of 90% of ransomware could be?
Speaker:I can jump in on that one I mean it it's because it of the stories that
Speaker:I've read over the last you know so many years it it was always it was always
Speaker:one of these three right If if if they had just patched the system then they
Speaker:wouldn't have the vulnerability if they had just either not allowed the password
Speaker:to be stolen or if they had the if or or compromised in some way And then uh
Speaker:if if if that had happened if they had just had MFA And you know in uh you know
Speaker:what's the word I'm looking for Um if they if they were just using MFA then
Speaker:then even if they had the password then they would've been able to get in Right
Speaker:Assuming that you didn't have MFA fatigue by the employee?
Speaker:But yeah we're we're gonna get to that We'll get to that But the the thing
Speaker:is if if if they had these things when you when you read back on the stories
Speaker:and I would add like because we're tech technically talking about cyber
Speaker:hygiene here and not backup hygiene but I'll add to this Immutable backups
Speaker:right If we have that if we have those four then um not only would you stop
Speaker:the you know the bulk of the attacks you would uh also be able to respond
Speaker:to the 10 that that you get Uh would your answer be any different there Mike
Speaker:Oh, very similar.
Speaker:So yeah, they, these three are the greatest common denominators, uh, of, of
Speaker:a lot of the, if not the majority of, uh.
Speaker:Incidents that are out there.
Speaker:Uh, but to Curtis's point and maybe where you were going, Prasanna Yeah.
Speaker:This list could get really long.
Speaker:It's, it's, you know, it's not just these three and the backups, it's also network
Speaker:segmentation and turning, you know, secure build guidelines and secure coding
Speaker:and, uh, you know, perimeter protection and vendor management and anti-malware
Speaker:and training and all those things.
Speaker:Uh, but when you look at the numbers, uh, the statistics of incidents
Speaker:that are out there and, and what.
Speaker:You know what, how you boil those down to the common denominate.
Speaker:Common denominators.
Speaker:It's, it's primarily these three.
Speaker:Because these are it's like this is to again going back to the real world this
Speaker:is the um I This is the have in in the real world when we talk about investing
Speaker:The very first thing they tell you to do is to have uh you know 90 days of
Speaker:of an emergency fund And that should be your first thing because there's no
Speaker:point in talking about like you know 4 0 1 Ks and Roth IRAs and all these things
Speaker:if you can't survive uh you know losing a paycheck for a couple of weeks right
Speaker:This is the um if you're not doing these Then just stop Like you know in the book
Speaker:we said like if you're not doing these three things just stop reading right now
Speaker:and go do those three things because it will stop 90 the other 10 like everything
Speaker:else The other 10 is the is the hard part right It's the more expensive part
Speaker:But doing password management and patch management and and MFA or um uh pass
Speaker:keys which we'll we'll talk about that a little bit more but if if we do that
Speaker:Then it it's it's a it's the low hanging fruit Um you know that that allows
Speaker:us to secure the the environment um without without massive cost or anything
Speaker:weird I I still hear your your fan
Speaker:came back on.
Speaker:Yeah it just came back on even though we have the noise reduction on
Speaker:And there, there's zero change on my side, so there's no extra noise or anything.
Speaker:And then it and then it just left
Speaker:It's like a power surge or something.
Speaker:I'm not sure.
Speaker:I got nothing Um I So weird Um all right Well luckily it was me that was talking
Speaker:so I could mute it out Um yeah so this this is like this is the if you're not
Speaker:doing these things and don't it's like it's like when we start talking about
Speaker:uh offsite backups there's no point in talking about offsite backups if you're
Speaker:not making backups in the first place Right Right This is the this is the if
Speaker:you're not doing these things and don't even talk to me Don't even start if you're
Speaker:not doing basic cyber hygiene then um then there's no point in in continuing
Speaker:on with with further discussions
Speaker:Uh let's see here Um all right so I Let's just let's just talk a little bit about
Speaker:when we talk about patching how do we know uh and we're gonna do an episode
Speaker:on each of these things but just the basic thing what what do you think would
Speaker:be the easiest That that's what cause that's what we're trying to do here What
Speaker:would be the easiest way to make sure that we're running all of the appropriate
Speaker:patches Mike especially the critical ones
Speaker:It's, it's easy if you're organized and the first step in getting organized is
Speaker:doing an inventory of the things that you have, because, you know, patch,
Speaker:you have to work off your inventory to know who, who to get patches from.
Speaker:Right.
Speaker:Is it, is it.
Speaker:Red Hat Linux.
Speaker:Is it Windows?
Speaker:Is it third party tools?
Speaker:Adobe, uh, you know that 3D modeling tool?
Speaker:You use AutoCAD?
Speaker:What is it?
Speaker:So you've gotta inventory all this stuff first and then find out if you can
Speaker:actually get notifications from them.
Speaker:For when patches are available.
Speaker:Uh, if you don't do that on the proactive side, then you're gonna
Speaker:get it on the reactive side.
Speaker:'cause hopefully part of hygiene is also your periodic vulnerability assessments.
Speaker:And if, if you need help with that, we can, we can walk you through some
Speaker:free open source ways to do that.
Speaker:But.
Speaker:Every now and then you need to be scanning all of your assets for vulnerabilities.
Speaker:That's gonna turn up some configuration problems, some missing patches.
Speaker:Well then, alright, reactively, now I, well there's a missing patch
Speaker:and usually it comes with a link from these vulnerability tools.
Speaker:Uh, so go do that and while you're doing it, find out if there's a way
Speaker:to subscribe to that information.
Speaker:Um, so.
Speaker:Easy.
Speaker:It's not easy, but organi, and that's one of the reasons people
Speaker:don't do it 'cause it's not easy.
Speaker:Um, and there are tools out there that are fairly expensive to
Speaker:do it in an automated fashion.
Speaker:And then somewhere in between there's managed services and other
Speaker:things, but it's gotta start with understanding what it is you have,
Speaker:uh, and then figuring out where to get the information for available patches
Speaker:and issues with those, those assets.
Speaker:this is the hardest thing today versus back in the day right Back in the day I
Speaker:could walk into a server room and I could I could literally just have a piece of
Speaker:paper and check off I have this one I have this one I have this one Now we have
Speaker:a We don't have any service to point at Everything's virtual Everything's in the
Speaker:cloud And we have we have you know um IAS we have PAS we have SAS right We have all
Speaker:of these different ways where uh and and I'd say the SaaS is probably the worst
Speaker:because it's so easy to to propagate Um The you know to to go across the um the
Speaker:thing and and you did you did remind me when we talk about inventory you did
Speaker:remind me again back in the day We had uh when I was the backup guy my very first
Speaker:job in it We had we had a very boring naming convention We had H-P-D-B-S-V-A
Speaker:HP database server a right bbc so on And I ha I was I was becoming worried that I
Speaker:wasn't getting all the servers cause we started out we literally when I started
Speaker:at the bank we had seven Servers at T three B twos by the way for those you
Speaker:know that's what we had which was for the record the first computer designed to run
Speaker:Unix so they were old right Anyway so we went from having seven servers to having
Speaker:like 200 servers and I was starting to panic that we We didn't have a correct
Speaker:inventory And so um but the the naming convention was very helpful And so I had
Speaker:this this practice of when you had a new server you had to give me a form to say I
Speaker:want this server backed up And I put this thing on there that said don't consider
Speaker:it backed up until you get the form back for me Signed that said that I saw the
Speaker:form and I put it on the list And then one day somebody handed me a form and they
Speaker:it said like H-P-D-B-S-V and I'm like And they're like yes I go so that would by by
Speaker:you know my inference that means there's an M and an L a K somewhere And they're
Speaker:like well yeah And I'm like I only know up to j So so I'm gonna go find K and l
Speaker:and m and uh and we'll start backing all of them up I agree with you Mike A hundred
Speaker:percent That inventory is absolutely the place to start And Prasanna you were
Speaker:about to say something before I waxed up
Speaker:No, it, that's actually a pretty funny story, Curtis, but I'm not surprised.
Speaker:You always have all these great stories from working at the bank and other places.
Speaker:But Mike, I know you talked about patch management, right,
Speaker:and how to apply patches.
Speaker:is there something similar for cases where maybe patches aren't available?
Speaker:Like, it's great you have an inventory of everything that's there, but
Speaker:how do you deal with sort of, um, exploits that are currently out
Speaker:there before patches come out?
Speaker:So those are zero days in, in most cases.
Speaker:Uh, so zero day is something was identified today, and vendors haven't had
Speaker:a chance to respond to that with a patch.
Speaker:Um, well, and, and I'll add real quick, sometimes the patch that's
Speaker:available becomes your zero day because it doesn't work in your environment.
Speaker:Uh, and so along with patch management, you need to develop.
Speaker:Process for testing the patch, applying it to a test machine to
Speaker:see its effects on how things run before you move it into production.
Speaker:So, uh, be mindful of that too, but to your point, Prasanna about things
Speaker:that come up that don't have a, a fix, uh, those mitigating controls.
Speaker:Like how do we, alright, so there in.
Speaker:It does depend.
Speaker:So is this a public facing thing?
Speaker:Uh, do people log into it?
Speaker:Is it a, is it a, you know, prized possession of our company
Speaker:with, you know, sensitive data?
Speaker:Or is it just that, that thing I could potentially turn off or isolate?
Speaker:Um, so you've gotta do some analysis first, like what's
Speaker:the risk, what's the impact?
Speaker:And then respond accordingly if it's.
Speaker:Publicly accessible internet facing.
Speaker:Then put some monitoring on it, put some logging on it, try to isolate it.
Speaker:Uh, those mitigating controls in the absence of a, uh, a true
Speaker:solution have to be assessed and applied as fast as possible.
Speaker:I like that Um
Speaker:and
Speaker:so
Speaker:there, there are, there are services out there.
Speaker:I ran into one not too long ago.
Speaker:It's outta New Zealand and it's, I don't have a fix for this.
Speaker:It's essentially a proxy.
Speaker:So they, they stand up a uh, um.
Speaker:An internet facing version of whatever it is that's fed from your environment.
Speaker:And they analyze and filter all the requests for that information as a proxy.
Speaker:Uh, and, and you can, you can subscribe to that until a solution is, uh, is applied.
Speaker:So that was pretty interesting.
Speaker:I did, I did see that.
Speaker:Yeah that's that does sound interesting uh from the so that's the the patches
Speaker:world and again we're gonna do an episode on each of these three Uh but that's the
Speaker:patches world Let's talk a little bit about the passwords Um and and I think we
Speaker:can all agree one some method Again I'm I'm a big fan of of password management
Speaker:like a password manager But you need some method So you absolutely do not ever
Speaker:use the same password in multiple places because that is the problem is uh I and
Speaker:I got a I got a um I got in a argument is a is a strong term but I got into a
Speaker:discussion with a with a guy on I think it was somebody that commented on one
Speaker:of our videos and um where he was saying that he was using Uh this system where
Speaker:he what he does is he he has a password that he uses on like a a small subset
Speaker:of systems Like he has like 10 passwords that he uses everywhere And so his method
Speaker:of like mitigating the risk is that he doesn't wanna use a password manager
Speaker:He doesn't believe in using a password manager So he has like 10 passwords that
Speaker:he sprinkles around and he just has to remember uh 10 passwords in his head um
Speaker:and he uses the the battery horse staple method Um right which is which is a good
Speaker:method right Uh for those of you who don't know what I'm talking about This is
Speaker:the um the idea of what we're gonna talk more about I'm sorry It is just this idea
Speaker:of having an password that is long but actually easy to remember because most of
Speaker:the passwords that we have that are long are total garbly gook and they can only
Speaker:be remembered by a password manager So he uses that method and then he has like
Speaker:10 passwords and I was like well that's Again better than nothing better than
Speaker:using the same password everywhere But if if there's avol if there if if any one
Speaker:of those systems where you're using that same password are ever compromised then
Speaker:you have to change the password everywhere where you're using that password And
Speaker:potentially by the time you get around to doing it it's already been compromised
Speaker:And um so this is just again my way to do this is password manager and I think
Speaker:that's the number one most recommended way But besides making sure that we do
Speaker:not use the same password in multiple places What else Basic uh password hygiene
Speaker:stuff do we need to talk about Mike
Speaker:Real quick, I think a good term for your, uh, your disagreement.
Speaker:Uh, and it's an older term, uh, that, that you just don't hear
Speaker:very often is a kerfluffle.
Speaker:Careful
Speaker:I think that's a good yes.
Speaker:Uh, anyway, so back to back to passwords.
Speaker:Uh, I think a good practice these days, especially as we suggest passwords
Speaker:become longer and longer, and, uh, I don't know if, if, uh, if, if you
Speaker:guys realize where that came from.
Speaker:Uh, so it stemmed from the, the, the length of a password.
Speaker:okay
Speaker:How long
Speaker:So a stem.
Speaker:compute right?
Speaker:So that's.
Speaker:A combination of things, right?
Speaker:So when, when Windows or, or Linux, Unix, uh, encrypts a password, uh, with,
Speaker:you know, a ES 2 56 or whatever it is, there's a ma math, there's a mathematical,
Speaker:um, response to how long it would take to crack a password of certain length.
Speaker:Well, that's been defeated, uh, by a project called Rainbow Tables.
Speaker:Rainbow tables just encrypts and, and captures the, the hash value
Speaker:of every conceivable, random known dictionary, multiple languages.
Speaker:And so it's not, I don't have to crack your password anymore, I just have to
Speaker:take your password hash and go look it up.
Speaker:And see if that's already been done.
Speaker:So it's not a math problem anymore.
Speaker:It's, it's a, it's a, it's a research problem.
Speaker:All right, well then a vulnerability came out in, uh, with Windows.
Speaker:'cause if you had, uh, um, NTLM, the, the hash in windows turned on, it would
Speaker:take your password hash and break it up into two eight character hashes.
Speaker:Well, now I can, I can crack them individually.
Speaker:Instead of cracking one large, I can do two small ones.
Speaker:And there's vulnerability associated with that.
Speaker:So now we should have greater than 16 character passwords for that reason.
Speaker:And, and it, and you know, I can drive policy now, it says it's gotta be 16.
Speaker:Well, if it has to be 16, the IT guys that have not wanted to change the LTLM now
Speaker:have to, they have to turn that off to, to generate, you know, and so there's.
Speaker:It's political game, but also based on, um, some known
Speaker:vulnerabilities around passwords.
Speaker:Alright, well now we've got 16 character or greater passwords.
Speaker:How are you gonna get users to remember that?
Speaker:Password hackers are great.
Speaker:Uh, password managers are great because it can also randomize passwords so
Speaker:you don't have to remember it anymore.
Speaker:You just log into your password manager and copy and paste.
Speaker:Um, and so you, you don't have to remember it anymore.
Speaker:And it can be random, which is also.
Speaker:Helpful, but then not everybody can subscribe to that approach.
Speaker:So they, they want these password phrases now.
Speaker:And so some interesting things about password phrases, uh, and similar to
Speaker:what Curtis was describing with, you know, having a root password and then
Speaker:you know, something at the beginning and something at the end that's helpful,
Speaker:especially if it's, if you want the same route password for everything, and then
Speaker:you just change the front and the back depending on what you're logging into.
Speaker:Uh, that can be troublesome though.
Speaker:'cause as a bad guy, I just need two of those to realize that's a pattern
Speaker:and I can just kind of guess, uh, what, uh, what, what your bank password
Speaker:is if, if I don't have that already.
Speaker:Um, so some things to think about.
Speaker:Um, you know, if you're logging into your bank, maybe your past phrase is,
Speaker:uh, I like getting paid on Friday, and then at the beginning or the end, uh,
Speaker:you know, uh, and that makes me happy.
Speaker:Or, you know, added emotion or add a, add a color that makes you think
Speaker:of, you know, that emo it's blue.
Speaker:Uh, I think that's calming, right?
Speaker:Uh, and then, and then change up how it felt.
Speaker:the way Mike I was gonna
Speaker:Green.
Speaker:Green is okay.
Speaker:for for money
Speaker:red.
Speaker:So then, you know, do some substitution.
Speaker:So instead of, you know, ease, use threes and capitalize, you know, the first
Speaker:letter of a word or spell it backwards.
Speaker:Um, I had a password and man, long time, 20, 30 years ago, uh, where it
Speaker:was, I spelled everything backwards.
Speaker:Um.
Speaker:So there, there are some unique things that you can do with passwords.
Speaker:You just have to figure out which one works for you, uh, and that
Speaker:you can be consistent with it.
Speaker:The password manager will also help you remember to, it's about time you've
Speaker:been using this password for 10 years.
Speaker:Now
Speaker:Yeah
Speaker:time to change it.
Speaker:you if you do use it in multiple places right It was like Hey you you've used
Speaker:this password elsewhere I'm I'm a big fan of password Brandon I know
Speaker:Prasanna You have one right What
Speaker:do, should we wait to talk about this on the
Speaker:Yeah Yeah you're right You're right you're right Yeah Yeah All right So yeah
Speaker:so basically the idea is the the the overall overriding concept is to not use
Speaker:the same password anywhere Never use the same password twice And and if you're not
Speaker:using some kind of system my method is password manager Um you know the the the
Speaker:the one that you talked about Mike the the one where you append it and pre-end
Speaker:it with with something and you have this core password that used to be my method
Speaker:before I went to a password manager Um and the the you know and then there's there's
Speaker:this these other ways to to have it but I I can't ima I have like 500 passwords
Speaker:at this point right so I can't imagine um not having uh a password manager at
Speaker:this point But so that's that's my way to do that But the core concept is you
Speaker:cannot use the same password at multiple places And why is that Mike We we kind
Speaker:of alluded it to it uh a few minutes ago
Speaker:You remember, we call those coincidental passwords.
Speaker:Uh, and and the reason you don't wanna use them in more than one place
Speaker:is because you've gotta rely on the security of more than one thing to make
Speaker:sure your password isn't compromised.
Speaker:And when bad guys compromise one data set, they're gonna use that data set
Speaker:across everything they can think of.
Speaker:So if I've got one of Curtis's passwords and I know he has 500 accounts out
Speaker:there, I'm gonna use that one password to try and log into 499 of those,
Speaker:And especially
Speaker:could be.
Speaker:one username is your email address right So you so you already know my email
Speaker:address and you go out there and you use the Password everywhere You know you
Speaker:just you don't even need to know where I have the thing You just you just try
Speaker:it All the places that you have access and you're and this is a numbers game
Speaker:You're trying every every account that you have access to with every password
Speaker:you have access to in every place that you have access to the the system Right
Speaker:Um so yeah that's why we don't do it
Speaker:Yep.
Speaker:And, and how do you mitigate that?
Speaker:by using the different password in every place Right
Speaker:Well, well, how so?
Speaker:What if, what if they guess what if they have a password?
Speaker:You forgot you used 20 years ago and now there's an account that
Speaker:that password's gonna work on.
Speaker:How do you mitigate that MFA.
Speaker:Oh okay I was I I should have known this answer Dammit Uh yeah So yeah so so MFA
Speaker:uh you know is the final thing on our on our on our trifecta of of basic cyber
Speaker:hygiene And I and I'll put MFA slash slash um you know pass keys which is like it's
Speaker:like the next thing cause we'll as we when we talk about MFA We will mention that
Speaker:MFA is not perfect Uh Prasanna's already alluded to it You know there's this thing
Speaker:called MFA exhaustion There are there are other issues with it but let's just
Speaker:start with what MFA is Um uh Prasanna why don't why don't why don't you define MFA
Speaker:What is it you know and how does it work
Speaker:Sure.
Speaker:So with MFA, it's really, Mike said, someone might compromise your
Speaker:password and so it's something you know and something you have, right?
Speaker:And so that something you have piece is normally, say your
Speaker:biometrics like a fingerprint.
Speaker:It could be your face, right?
Speaker:It could be a. Electronic token that gets generated periodically
Speaker:or some other application, right?
Speaker:That generates that such that you have a second factor, which previously was
Speaker:called sort of two-factor authentication.
Speaker:Right now it's multifactor in order to be able to say, yes, this really is me.
Speaker:The most common one I'd say
Speaker:I'd say the most common one is probably SMS Um it's definitely not the best
Speaker:one uh but it's certainly the most common I think the most common use to
Speaker:be email I really don't like email like in good better best It's barely good uh
Speaker:because again if you uh if somebody's compromised your email account especially
Speaker:if it's the email account that you use for everything right Um SMS is not as
Speaker:good because SMSI think SMS is actually better today than it used to be uh it's
Speaker:harder to do sim hacking today than it than it used to be uh at least in in
Speaker:certain circumstances Um and then but then uh the I think the best one that
Speaker:we have today that's available to pretty much everybody is uh an authenticator
Speaker:type app You wanna talk about that Mike
Speaker:Sure.
Speaker:Uh, and, and those apps are generally free, uh, and, and don't require any.
Speaker:Infrastructure changes.
Speaker:There are some, uh, like duo, uh, that would require some licensing and set up
Speaker:on the inside of, uh, your organization.
Speaker:Um, but others like the Microsoft Authenticator app, uh,
Speaker:Google has one, they're free.
Speaker:You just get 'em in the play store.
Speaker:And then whenever you want to register your multifactor with a vendor, a
Speaker:lot of times there's like a QR code or a set up your account this way.
Speaker:Um.
Speaker:Similar to a password manager, you would log into your authenticator app and it
Speaker:would show all your different accounts, uh, which you could revoke or delete if
Speaker:you think that's compromised as well.
Speaker:So you can manage it that way, but pretty, pretty straightforward.
Speaker:And, you know, MFA, uh,
Speaker:um, fatigue, MFA fatigue is a real thing.
Speaker:It's more of a. It's just annoyance.
Speaker:Uh, so you log into something and you, oh, I've gotta wait for my phone to ding.
Speaker:Now what if, what if you don't have cell phone coverage or data,
Speaker:uh, you know, wireless data?
Speaker:Um, a lot of these authenticator apps also allow you to save.
Speaker:Backup codes, um, things like, so there's, there's any number of ways
Speaker:of, of using what works for you.
Speaker:Um, the important thing is to figure out something other than email, um, for your
Speaker:MFA if, if the, the account that you're wanting to apply MFA to will support it.
Speaker:And Mike, I know on a previous podcast you sort of mentioned one of the
Speaker:downsides with many websites, right?
Speaker:Which have MFA, and then they sort of have the remember me
Speaker:next time on this thing, right?
Speaker:Right.
Speaker:So it, it's, it's whether it's a website like, um, I don't know,
Speaker:Amazon I was gonna
Speaker:Amazon, right?
Speaker:yeah
Speaker:either one of those, there is a, remember, it's, it's, remember this device, um,
Speaker:you don't want to do that because your MFA token is then stored in your browser.
Speaker:And so now a bad guy just asked to get you to a position or a situation where I can
Speaker:scrape that MFA token out of your browser if I already have your credentials.
Speaker:The only thing I need now is your MFA token, and now
Speaker:I can get into your account.
Speaker:So
Speaker:I was gonna say, so MFA good MFA has to come with good policy and good practice.
Speaker:So the the the point of this episode here is just to just if you're not familiar
Speaker:with any of those three things go get familiar Um and the best way to do that
Speaker:is to uh log in next week and we'll cover each of these in detail Um but uh You
Speaker:know the idea between behind MFA is that if somebody gets a hold of your password
Speaker:they won't be able to log in because they don't have that additional factor
Speaker:whatever it is whether it's SMS or or um you know an authenticator app or a token
Speaker:right We'll talk about these more and and all of those and passwords and MFA have
Speaker:limitations and those limitations are us right It's the human and that's why
Speaker:I think pass keys is the better option As we move forward in the future and I
Speaker:I've been rolling out Pasky uh in many places wherever I can Uh it I'm not sure
Speaker:if if it's great for like the average Joe there it can be confusing Um PAs
Speaker:keys can be confusing if you don't if you don't know what you're doing But um but I
Speaker:Did you ever use iron keys?
Speaker:Curtis?
Speaker:Uh what's a iron key
Speaker:So an iron key is a, it's a military grade USB, and uh, in it, it's
Speaker:got its own, you know, TPM chip.
Speaker:Its own encryption, its own password manager, its own MFA.
Speaker:And if you log into it, I think it's 20 times wrong, it self-destructs,
Speaker:it's got a little capacitor in it.
Speaker:It like, it'll smoke, uh, and if you try to cut into it to get to the chips, it's
Speaker:also got a sensor and will self-destruct.
Speaker:Yeah
Speaker:Yeah, it's pretty cool.
Speaker:that, but doesn't surprise me that you probably have.
Speaker:Um, but anyway, so the, again, this is meant to be an overview episode.
Speaker:Um, and if some of this was, was confusing or frustrating or you
Speaker:felt like we didn't go into detail enough, then just, uh, we're gonna do
Speaker:three more episodes where we go into each of these, uh, in more detail.
Speaker:but it just.
Speaker:You know, start looking into these three things.
Speaker:Password man, regular password management.
Speaker:I'm gonna start with that Inventory, right?
Speaker:Make sure you have an inventory of everything, both your physical, your
Speaker:virtual, and your, and your cloud systems.
Speaker:What,
Speaker:Wait, you said
Speaker:what?
Speaker:You meant patch management?
Speaker:Oh, did I say that?
Speaker:Okay.
Speaker:All right.
Speaker:So again, uh, you know, summary here, we've got three things here, right?
Speaker:Make sure you're doing pa uh, uh, patch management, right?
Speaker:Uh, that some sort of automated system.
Speaker:Uh, and, and we're gonna start with an inventory, right?
Speaker:A physical inventory, a virtual inventory, and a, an a SaaS inventory
Speaker:of your entire environment to make sure that you know what it is you're
Speaker:supposed to be looking out after.
Speaker:You're gonna have a good password manager and you're gonna have good.
Speaker:Um, you're gonna have an MFA or you're gonna have a, a passkey based system.
Speaker:Uh, because, uh, without these three things, no point in having, you know, like
Speaker:looking into an EEDM or, uh, I'm sorry, EDM looking into A EDR or an XDR system.
Speaker:Um, and, um, you know, or, or you know, any, any of the other stuff
Speaker:that we're talking about because it's like looking into a Roth IRA if you
Speaker:don't even have a savings account.
Speaker:Right.
Speaker:Um, so, With that, uh, any final thoughts, Mike?
Speaker:Doing something's better than nothing.
Speaker:one of these and
Speaker:yeah,
Speaker:do something about it.
Speaker:absolutely.
Speaker:What about you, Prasanna
Speaker:Well, I think the three makes sense and hopefully everyone
Speaker:is using a password manage.
Speaker:There.
Speaker:I'm,
Speaker:I've got a story about password management.
Speaker:Please, please,
Speaker:we were doing a, a red team on a, a brick and mortar nationwide retail.
Speaker:Sorry.
Speaker:Yeah.
Speaker:we save this for the actual password manager episode?
Speaker:Yeah, maybe
Speaker:Sure it is a password
Speaker:besides
Speaker:management.
Speaker:it's so weird.
Speaker:The, the, the, the thing came on there for about 30 seconds and then went off again,
Speaker:and you don't hear anything on your end.
Speaker:Nothing changes here.
Speaker:It's completely quiet in this room.
Speaker:That's so weird.
Speaker:Uh, a, it's a, what do they call it?
Speaker:It's ghost and Shell, um, all right.
Speaker:Uh, all right.
Speaker:that up is 'cause we're already at 48 minutes.
Speaker:So,
Speaker:Yeah, yeah, yeah.
Speaker:Well, we're gonna cut, we're gonna cut some of this out pretty much
Speaker:half the time that Mike talks.
Speaker:We're just cut it out.
Speaker:anyway.
Speaker:All right, Prasanna Thanks.
Speaker:Thanks for, uh, being here again as well.
Speaker:Forever.
Speaker:and look, see I shaved, just so you know.
Speaker:Yeah, absolutely.
Speaker:Absolutely.
Speaker:Alright.
Speaker:Actually, I, I don't know if anybody can tell, but I, I had
Speaker:my, I had my beard trimmed.
Speaker:I had a photo op yesterday, so it, my beard's all nice and trimmed.
Speaker:So anyway, or as my granddaughter said, slay Um, and that is a wrap.
Speaker:Why do I stop?
Speaker:Okay.







