Avast is launching a new series, Avast Hacker Archives, that uncovers the “Aha!” moments that hackers and researchers have had over the course of their careers. Jaya Baloo, Avast CISO and the host of the series, will be chatting with renowned security experts about their backgrounds, education, and, of course, their toughest and funniest hack stories and projects — nitty-gritty and technical details included.
Security professionals, hardware experts, threat intelligence leads, privacy advocates, and vulnerability researchers around the globe will join Jaya in discussing current and future trends in the cybersecurity industry.
“I work in the most interesting field in the world – cybersecurity. I’ve been doing this since I was 14 and I’ve not been bored a single day!” Keren Elazari tells Avast CISO Jaya Baloo early in the interview of our tenth episode and Season 1 finale of the Avast Hacker Archives (AHA) podcast. Keren is explaining how she maintains the energy to do everything she does, which includes:
Being an internationally recognized security analyst, researcher, author, and speaker; working with leading cybersecurity firms, government organizations, and Fortune 500 companies; being the first Israeli woman to give a TED talk at the official TED Conference (her TED talk on hackers has been viewed millions of times and translated into 30 languages); founding BSidesTLV, Israel’s largest cybersecurity community events; founding Leading Cyber Ladies network, a global professional network for women in cybersecurity; and being a senior researcher at Tel Aviv University.
She easily finds time for everything, she says, because she loves what she does. She’s had a curious mind since childhood when her father was an electrical engineer and would leave pieces of gadgets lying around the house. He was also an early adopter, so Keren found herself with all the legacy devices of the time. Then, in 1995, she saw a movie that changed her life – “Hackers.”
Sure, it was Hollywood’s version of the hacking lifestyle, but she was hooked. She wanted to be Angelina Jolie’s character Acid Burn. She began exploring the internet. Before anyone thought of internet crime laws, she was poking around and finding herself in other users’ systems. She learned to speak English by communicating on early IRC channels. Her handle back then? Acid Burn, of course.
But it was her time working in a military security communications unit that instilled the moral compass that would direct her career. She realized that her job was securing the systems on which her country relied and that responsibility was one she did not take lightly.
“I like to believe that I am a techno-optimist at heart,” she admits. “So, while I grew up with cyberpunk movies and books, imagining a dystopian technological future, I like to believe that technology in the big picture has actually helped us in many ways.” And her positive outlook extends beyond the tech to the people who manage it. She led a project at Tel Aviv University that proved the fact that bug bounty hunters are not in it primarily for the money.
In our episode, she explains to Jaya why hacking is like the internet’s immune system. Friendly hackers work to find vulnerabilities and bring them to everyone’s general attention, thus making the overall system healthier. “The mindset of a hacker is one that I think leads us to innovation, to evolution. It forces us to evolve, and I think it’s positive and it actually makes the world more interesting,” she tells Jaya.
What is holding her interest these days? “Today, one of the things I’m researching and that I’m passionate about is a passwordless future.” She is occupying her time researching different technologies in that space, and she is hoping for a future with better forms of authentication. “Passwords belong in our past,” she says, explaining that it’s humanly impossible for people to manually manage all the different usernames and passwords they’re supposed to be managing.
To Keren, the future is about leaving this password era behind us and focusing on a more holistic look at our digital identities. As Jaya says, “Digital identity is definitely the cornerstone of having a good security program, but it’s also the basis for being able to protect your security online.” Keren agrees, commenting that because people now work from anywhere, identity is the new perimeter, the new boundary.
“Start thinking about your digital identity as an expansion of your physical identity,” she says. “Because that’s what it is. It’s part of you.”
When asked what her advice is to young women who look up to her, Keren’s message is simple: You belong. Your voice matters. To provide even more inspiration, she teamed up with eight other women to publish their stories in the book “Women in Tech.”
This season finale is packed with great insights, including Keren’s basic security advice, her take on what the pandemic did for us, and what the cybersecurity needs to change immediately in order to protect our future. It’s a great sendoff to a great season of episodes. We definitely saved one of the best and brightest for last. Check it out at the link below, and we’ll see you back here soon for Season 2!
She doesn’t just talk the talk, she also walks the walk every day in and day out for a service most of the planet has come to depend on,” says Avast CISO Jaya Baloo, introducing Heather Adkins, Senior Director of Information Security and Privacy at Google and founding member of the Google Security Team. That “service” Jaya mentions only happens to be keeping the most popular internet tool in the world safe and secure for all.
In Episode 9 of Avast Hacker Archives (AHA), Heather tells Jaya that she didn’t set out looking to work in cybersecurity, cybersecurity just happened to find her. She was studying marine biology at Humboldt University when she took a job at a local ISP. Then something fateful happened that changed the direction of her life – they got hacked.
All at once, Heather was intrigued, curious, and excited. This new cyber world fascinated her, and she headed down to Silicon Valley. She was referred to Google, got the job, and spent the next 19 years of her life dedicated to leading the pack in strong cybersecurity, tweaking as necessary to stay on top of the newest tech, tricks, and traps.
The old way of deploying cybersecurity was site-specific. A company would have a building full of employees, those employees would work within an internal network, and a firewall would be placed around it. This is known, Heather says, as “the bonbon model” – a hard exterior protecting a soft interior. It seemed a sensible and sound method, and at first it worked.
But then, in 2009, Operation Aurora struck. This was a series of cyberattacks that lasted for half a year targeting a variety of organizations like Adobe, Yahoo, Morgan Stanley, and Dow Chemical. The attacks originated from Chinese state-sponsored APT groups, and Heather and her team realized that things needed to change. The problem was that the bonbon model placed too much trust in the internal network. Cybersecurity needed to shift from protecting the building as a whole to protecting the individual machines. The shift would also cater to the emergent trend of remote workers. It required more stringent identity validation and authentication but allowed employees, in theory, to work safely from anywhere.
And that is approximately where we stand currently in the evolution of cybersecurity, but more changes are imminent. Cyberspace is experiencing something of a security paradox at the moment, where most people depend on collected data – search engines, trends, etc. – but at the same time, they want more privacy.
“If I were to make a prediction,” Heather confides to Jaya, “and this is not a Google opinion, this is a Heather prediction – I think consumers will get very comfortable with the idea that data yields solutions, but they’re going to want more control and more insight in simple ways over this data. And because of that, we will see more computing moving down to the endpoints, we will see more cloud-based storage and use by NCrypted, and more agency for the user.”
Heather continues, “It’s all going to come down to the endpoints. That, plus the presidential order that came down in 2021 will really drive this idea of reshaping the ecosystem because we really have to do things differently than we’ve been doing them for the last 30 years or so.”
That presidential order from Joe Biden mandates that all government agencies invest in stronger cybersecurity. This will affect the entire world of security, as vendors will find new solutions to meet the president’s order, and those solutions will then trickle down to the consumers.
Heather is a female leader in a male-dominated field, and she finds inspiration, even a bit of connection, with another female leader from centuries ago – Mary Queen of Scots. Not only was Mary a strong leader of Scotland in the mid-1500s, but she has a historical footnote that still resonates today with the security industry. She met her end due to lack of privacy. Her messages were intercepted. In a way, it was death by 16th-century data breach. She’s both a model of strength and a reminder of caution.
All this is only part of the info-packed conversation Jaya has with Heather. There’s a lot more, including the increased use of homomorphic encryption, the importance of “cyber hygiene,” and Heather’s secret formula for getting the masses comfortable with a new change. You could say Avast Hacker Archives Episode 9 is our only episode where a thought leader from the Googleplex shares a googolplex of her security insights with us. Click the link below to hear it all for yourself!
“I’ve always found the best way to get a kid to learn how to hack is to tell them to just never use the computer,” Dave Aitel confides to Jaya Baloo in Episode 8 of our podcast Avast Hacker Archives (AHA). Dave is speaking from experience. When Jaya asks him about his earliest hacking exploits, he harkens back to high school days, when his parents enforced a strict “hands-off” policy with their home computer. They kept it locked in his father’s office.
Dave saw this as a challenge. And not a terribly difficult one. Before long, he was picking the lock to the office door, booting up the system, and playing Trade Wars on early BBS’s. Finishing his thought on how to create the hacker instinct in someone, Dave adds that, after you forbid them to use the computer, “they will find a way to learn how to erase logs before you have the time to instruct them on that type of thing.”
We are thrilled to feature Dave in our 8th AHA episode. He’s the founder of the Aitel Foundation, co-author of “The Hacker’s Handbook,” and listed by eWeek Magazine as one of the 15 Most Influential People in Security. And that’s only part of his resume! Dave is a well-known keynote speaker at industry events such as BlackHat and DEFCON. Lately, he’s been very active with the No Starch Press Foundation, for which he is the Program Committee Chair, and he’s been working heavily in the government cyber policy area.
But it was that early verboten tinkering on his parents’ home computer that gave him his start. After high school, he applied for a scholarship with the National Security Agency (NSA) and got it. The NSA paid for Dave’s college, and, in return, Dave worked for the agency post-graduation. He became an NSA employee at 21, joining the group a lot of his peers saw as “the enemy.”
The NSA were perceived as square, uptight administrators, but Dave quickly learned that they were all essentially cyberpunks, like him. He joined the agency at a time when it was just beginning to diversify, and he tells Jaya how he did his part to neutralize any sense of elitism within the organization by, very rebelliously, parking his ‘85 Toyota Camry in the employee parking space reserved for the Director of the NSA. The agency’s motto is “One team, one mission,” and Dave began to spread his spin on it: “One team, one parking lot.”
But jokes aside, Dave gives the NSA a lot of credit for its evolution, both structurally and culturally, over the last 20 years. It’s progressive in form and function, and it reflects the cybersecurity climate. Dave mentions to Jaya that the Director of the NSA personally posted a Pride Month video. It’s the first time that’s ever happened, which makes it a historic moment, and it’s a direct result of having such a large number of LGBTQIA+ members in the cybersecurity community.
Additionally, they cover a range of topics from the myth that hackers make a lot of money (spoiler: Dave says they usually just break even) to the reason the term “zero-day” is a fallacy (another spoiler: it presupposes that nobody else in the world knows about that vulnerability). Dave explains how security patches can actually hurt cybersecurity in general, and he names the most commonly compromised programming languages (third spoiler: you’ve heard of all of them).
Okay, enough with the spoilers! There’s a lot more in this episode, including Jaya’s question, “If you could go back and tell yourself something to do, or not to do, what would that be?” Dave’s response includes the words “crazy,” “out-of-control,” and “socially awkward,” but you’ll have to hear it for yourself to get the whole answer.
Are you ready to delve into the mind of another hacker? Please enjoy Avast Hacker Archives, Episode 8!
“Here’s how it works!” Dan Aykroyd energetically tells the SNL audience. “Catch a bass, remove the hook, and drop the bass – that’s the WHOLE bass – in the Bass-O-Matic 76!” As he says this in his best punchy announcer voice, he picks up a real fish and drops it in a blender. The audience begins to titter, nervously anticipating what might happen next. When he punches that blender button, turning the fish into puree, the audience loses it, laughing hysterically at what would become one of the most famous SNL sketches in history.
When cryptographer Phil Zimmermann created the first algorithm for his Pretty Good Privacy (PGP) email encryption service, he had to give it a name. That visual of the fish in the sketch getting completely eviscerated was an apt, if not hilarious, representation of what his encryption did to the data – scrambled it up until it was completely unrecognizable from its former self. Phil released his BassOmatic symmetric-key cipher in 1991.
Back then, in ‘91, the only folks using email were the ones who actually had the technical know-how to implement encryption. As 2000 neared, more and more laypeople began using email, and encryption like PGP, involving trust models and public keys, was a bit too much to wrap their heads around. By that time, however, Phil was turning his attention to secure voice protocols, a pursuit, he says, that he found much more fun than encrypting emails.
Today, encryption is more widely accepted, which is a good thing as far as Phil is concerned. Citing nation states, hostile foreign powers, and the recent Colonial Pipeline ransomware attack, he believes we need strong encryption to protect every part of society, from industry and ecommerce to individuals, police, and military. “The damage done to our national security interest by not having end-to-end encryption is worse than the damage done by a few criminals that are doing end-to-end encryption,” he tells Avast CISO Jaya Baloo in our 7th episode of Avast Hacker Archives.
Phil also tells Jaya about his history with cryptography, even including a mini-lesson on the history of cryptography. “Cryptography is the product of an arms race,” he says. “There has been for centuries, many centuries, an arms race between cryptologists and crypto-analysts. The cryptographers make an algorithm, the crypto-analysts break it. The cryptographers improve their algorithm, the crypto-analysts improve their crypto-analytic techniques and break it again. And it goes on and on for centuries.”
Jaya asks Phil what he makes of the sweeping migration of WhatsApp users to Signal when WhatsApp announced that it was changing its terms of service to work more with Facebook. His answer was simple: “Facebook is in the metadata business. And WhatsApp started collecting a lot more metadata and sending it to Facebook. And that means that even though you have an end-to-end secure channel for talking or texting with someone, the metadata is still being collected.” That metadata includes with whom you’re chatting, how long the chat lasted, the time stamp of the chat, and other details. “I think social networks, and Facebook especially, have done a great deal of harm to the world. They might be fun for a lot of things, but they come at a steep price,” he adds. “If you’re not paying for the product, you are the product.”
Click the link below to hear Phil and Jaya cover more topics, including how nuclear power could save the world and how Phil’s pursuit of cryptography fell perfectly in line with his passion for activism and social justice. “PGP was originally designed for withstanding the attacks of nation states,” he reveals, expounding on how encryption protects civil liberties. It’s with great pride that we kick off Episode 7 of Avast Hacker Archives. Please enjoy!
At the age of 12, Wendy Nather was living in Israel. Her father was a professor at the University of Tel Aviv, and when she complained to him one day that she was bored, his response launched her on the course that quickly became her life’s calling. They had an electronic console known as a “teletype” in their home – essentially a primordial fax machine – and it had a little bell inside it. Wendy’s father tossed her a BASIC programming manual and challenged her to figure out how to make the teletype bell ring on command. She did.
As a young woman, Wendy got a job at a bank in Zurich, where she took on her first cybersecurity duties. She stayed in the financial services industry for 12 years, specializing in IT and security. She served in the positions of strategist, research director, industry analyst, and CISO. She’s worked in both the public and private sector, including 5 years in state government. Today she heads up the Advisory CISO team at Cisco. Wendy is a cybersecurity guru with decades of experience, and she shares some of her most practical wisdom with Avast CISO Jaya Baloo in Episode 6 of Avast Hacker Archives.
One CISO to another, Jaya asks Wendy what she finds most burdensome for a chief information security officer these days. Having started in security back when the only things that needed protection were mainframes, Wendy has witnessed every new evolution of technology since, each with its own specific security needs. “You’re having to cover all of that,” she says “And where everyone else has the luxury of forgetting the old stuff, you can’t.” A CISO ready for any threat is a CISO armed with an arsenal of knowledge that spans, essentially, the history of technology. And the new tech just keeps coming.
This front row seating to emergent technology revealed a pattern, Wendy tells Jaya. The same security mistakes are being made over and over again when a new technology comes out. She witnessed it when computers went online, then again when computers went mobile, and now again as computers become IoT. The problem is that the teams introducing each new development seem to be doing so in a silo, without assimilating the lessons learned by their predecessors.
Which brings us to Wendy’s main message for the security industry: more communication is essential, across all channels – device manufacturers, IT departments, security services, and even the consumer. Security needs to be understandable to everyone at this point in our technological development. “Everyone needs to know the basic security principles and how to implement them,” Wendy tells Jaya. “It can’t be the wizards versus the muggles anymore.”
In fact, Wendy welcomes more muggles to step into the field. “You don’t have to have had 25 degrees in certifications and all this kind of stuff to be ‘a security person,’” she says. “There are just so many ways that you can contribute to the state of knowledge and security coming from wherever you’re coming from,” she adds. “Don’t let the gatekeepers get in your way. We’re all making this up together and you can do it just as well as we can.”
Click the link below to hear more of Wendy’s wisdom and advice as she and Jaya discuss these topics and more, such as IoT sneakers, the reason Wendy doesn’t use parental controls on her kids’ devices, and certain ways CISOs can improve security without spending a penny. Wendy gives security advice that makes good, practical sense to everyone, so kick back and check out Episode 6 of Avast Hacker Archives.
t’s no coincidence that when our pandemic-stricken world went into lockdown mode in 2020, incidents of abuse via stalkerware spiked, especially in situations where the victimizer did not live with the victim. Then, as the lockdown began to be lifted in early 2021, stalkerware abuse spiked yet again. Abusers have learned over the past couple of years that certain apps facilitate or outright promote spying capabilities without the need for malware. The subterfuge hangs simply on a shared or compromised account, which makes it all the more sinister. And much like COVID-19, stalkerware is a worldwide problem.
The good news is that some very capable people are on the case, working to identify and eradicate stalkerware around the globe. Leading the charge is the brilliant Eva Galperin, key figure in launching the Coalition Against Stalkerware, a group of cybersecurity experts (including Avast) dedicated to educating the public and providing resources for victims and survivors. Eva is our very special guest in Episode 5 of Avast Hacker Archives (AHA), the podcast series spotlighting hackers who have shaped and continue to shape the digital world.
Eva is currently Director of Cybersecurity at the Electronic Frontier Foundation (EFF) and Tech Advisor at Freedom of the Press Foundation. She’s on the front lines of the fight against stalkerware, and she tirelessly works to protect the digital freedom of the individual, particularly those likely to be preyed upon, like journalists, activists, and victims of abusive relationships. In our podcast, she explains to Avast CISO Jaya Baloo how she got so involved in the fight against stalkerware.
Eva was studying APTs back in 2018 when she discovered the horrible truth that one of her fellow researchers was a serial rapist! Being tech savvy, he allegedly threatened to compromise his victims’ devices if they ever reported him. Outraged, Eva tweeted the following message:
If you are a woman who has been sexually abused by a hacker who threatened to compromise your devices, contact me and I will make sure they are properly examined.
Three years and 10,000 retweets later, Eva is still being contacted by victims. Law enforcement is not helpful in this area, she tells Jaya, as the legality of stalkerware usually falls in a gray area. Identifying stalkerware, however, is not too difficult – it’s a product that needs consumers in order to survive. “In some ways, it’s even easier to find and detect stalkerware than it is to hunt APTs,” Eva says, “because you can just Google for it and follow the ads. They have to go find their users somewhere, whereas APTs are all hiding.”
In addition to the severity of stalkerware, Jaya and Eva also discuss the perils of being a journalist and the protections that the Freedom of the Press Foundation provide. “Good journalism speaks truth to power,” Eva comments. “It pisses power off. If, as a result of pissing power off, power decides that what you are doing is illegal, and you should be sent to jail or you should be sent to court, that’s really one of the areas where the Freedom of Press Foundation steps in.”
When asked how the cybersecurity industry can do more good, Eva says, “Everybody has a community that they care about, and that they know. Everybody has a family….Or a church, or mosque, or temple, or coven that they’re super into. Or a school. And those communities need help. They’re often being surveilled by governments, by law enforcement, by predatory companies and corporations. And reaching out to these communities and seeing what they’re concerned about, and figuring out ways to protect them, is really one of the ways in which security researchers can use their skills for the greater good.”
Jaya and Eva discuss these topics and more, such as the reason Eva passionately disagrees with the school of thought that “privacy is dead,” and the question of whether current security protocols place power in the hands of too few people. Eva voices her controversial opinion on the new “ghost protocol” and divulges what she considers to be one of the weakest links on the internet. Click below and prepare to be inspired by Eva in Episode 5 of Avast Hacker Archives!
Troy Hunt is an Australian web security consultant known for public education and outreach on security topics. He created Have I Been Pwned?, a data breach search website that allows non-technical users to see if their personal information has been compromised. He has also authored several popular security-related courses on Pluralsight, and regularly presents keynotes and workshops on security topics (Source).
He holds the title of Microsoft Regional Director and Microsoft Most Valuable Professional for Developer Security. He doesn’t work for the company but the brand recognises his community contributions through their award programs which he has been a part of since 2011.
For fourteen years prior to going fully independent, he worked at Pfizer; the last seven of these years being responsible for application architecture in the Asia Pacific region. Time spent in a large corporate environment gave him huge exposure to all aspects of technology as well as the diverse cultures my role spanned. Many of the things he teaches in post-corporate life are based on these experiences, particularly as a result of working with a large number of outsourcing vendors across the globe.
He regularly speaks to the US Congress about the impact of data breaches.
Several years ago, Chris Roberts was waiting for a train in Chicago. Bored, he found himself staring at one of the station’s LED display screens. Twenty minutes later, he had that screen programmed so that it pulsed the lyrics of “God Save the Queen” in Morse code for 30 seconds at a certain moment every single night. From what he understands, it’s still doing it to this day.
Chris has what he calls “the hacker mentality” – a constantly inquisitive state of mind that whirs into action whenever technology is near. He describes the thought process as “It’s there – what can I do with it? How does it work? Can I improve it? Could I do something different with it? And can I make it, you know, sing in a strange language just for the hell of it?”
Avast CISO Jaya Baloo has that same hacker mentality, and she and Chris have been kindred spirits in the world of breaking-things-open-to-see-how-they-work for years now. She is nothing less than overjoyed to feature her friend, the hacker virtuoso and consummate jester Chris Roberts, in our third episode of Avast Hacker Archives (AHA). Stream the episode below, where Jaya asks Chris about everything from his earliest “Aha!” moments to his wildest hacks to his incredible, game-changing designs for the future.
Security guru and head hillbilly in the cutting-edge cyber braintrust known as the Hillbilly Hit Squad, Chris Roberts likes to test boundaries. How far will he go? The outer edges of our own galaxy may not be far enough. Sure, he’s hacked Fort Knox, the White House, the Pentagon, and the aforementioned train station, but Chris wasn’t satisfied until he quite literally reached for the stars. He managed to successfully adjust the temperature in the International Space Station, a stunt which garnered him some flack from NASA. He’s proud of that one, but prouder still of hacking the Mars Rover. He programmed the exploratory vehicle to play a Freddie Mercury song. What song? Why, “God Save the Queen,” of course.
As brilliant as he is mischievous, Chris provides defensive services to enterprise and government clients alike. When he’s not consulting with organizations that value his white hat hacking skills, he’s working with fellow Hillbilly Hit Squad members on a new security model simply called “Dave.” Dave is something of a cybersecurity watchdog designed to help small businesses through a simple, easy-to-understand interface and sophisticated, dynamic security.
In the episode, Jaya asks Chris what he would like to see changed in the cybersecurity industry, and his answer is clear and passionate – more communication, more collaboration, and more humanity. He’s discouraged by the commercialization of digital security, and he strongly believes that we should all be working together, sharing discoveries and building on each other’s ideas in the name of good for all. Instead of 50 different security options clamoring for the consumer’s attention, Chris feels there should be just 1 or 2, bolstered by the combined discoveries and developments of the best brains in the field.
Chris also talks about the utmost importance of “soft skills,” the human side of all this digital interplay. Users who are not tech-savvy need patience, clarity, and kindness from their security experts. Only with that kind of real communication can we move forward as a society and advance our collective technological abilities.
An even bigger problem facing the general populace of internet users, according to Chris, is the emergence of digital identity. We as humans, he feels, have not gotten used to the concept yet, and as a result there is too much vulnerability and confusion surrounding the issue. Everyone has a list of passwords a mile long, and Chris firmly believes we can approach our online identities in a saner, calmer way. He tells Jaya about a project he has in the works that will address that very issue.
Conversations with Chris always bring out thought-provoking points and hilarious anecdotes. This episode has no shortage of either. When Jaya asks him about his earliest hack, Chris begins the story with its repercussions – “My father had me arrested at 14…”
Check out the episode to hear the rest of this tale, in addition to some other “Aha!” moments Chris has experienced. Learn what started him out on his hacking journey and hear his advice to young hackers just beginning. He shares his views on social media, he talks about his personal project where he is creating a fully digital version of himself, and he recounts some rowdy antics, such as the time he and Jaya got in trouble with the Turkish police for hacking some robots.
All of this and more is in Episode 3 of Avast Hacker Archives, our most epic episode yet! Watch, be astounded, and enjoy.
Katie started with computers at age eight in her bedroom on a Commodore 64. She was the first female in her high school to take AP Computer Science and has continued to achieve many firsts in the hacking community. Katie is now an established pioneer and expert on bug bounty programs, vulnerability disclosure standards, handling processes and secure development, and a recognized cybersecurity public speaker.
In our episode, Katie tells the story of how a presentation she made at a grad-school symposium led to the first ever cash-incentivized bug bounty program for the Department of Defense called Hack the Pentagon.
While many companies come to Luta Security – beautifully named after the island in the Northern Marianas where Katie’s mother was born – ready to start a bug bounty program, she encourages them to first seriously consider investing in what they are doing to prevent and self-detect the bugs they want to hunt. She states that cash rewards aren’t always the best solution to solving a company’s digital security.
Katie and Jaya then discuss the Solarwinds supply chain case study. Katie describes how it’s getting more difficult to defend networks with so many pieces and vendors involved. She uses the term multi-party vulnerability coordination to describe studying and solving the vulnerability disclosure capabilities in the networks of many organizations that rely on each other across hardware and software supply chains.
Katie started Luta with a deep-seated sense of knowing that she could help companies and governments better understand what they don’t know, including what tools and talents they need. One of Luta’s first clients was the UK Government. She helped them not only create a vulnerability disclosure program, but also a maturity assessment capability so they could onboard different government agencies in an orderly fashion. This became especially important when the UK’s National Health Service had to roll out a Telehealth program virtually overnight at the start of the pandemic. Currently, the US government is set to release its own vulnerability disclosure program by March 1, 2021.
If Katie could have any wish granted in the cybersecurity industry, it would be that the deployment and implementation of security patches would have a faster and more effective operational process. One of the biggest problems isn’t that new patches aren’t being created fast enough, it’s that they aren’t being applied quickly and thoroughly to networks.
Closing out the episode, Katie raises the topic of gender and racial inequalities in the cybersecurity industry. In order to combat these societal inequalities and drive systemic change, she has founded her own foundation, the Pay Equity Now Foundation.
In this episode, Joe recollects about the first hack he ever presented at a conference. It was a Nikon D800 camera. The high-end apparatus used a very expensive proprietary Wi-Fi adaptor, and Joe didn’t understand why a generic $50 adaptor, at a tenth the cost, shouldn’t work just as effectively. Applying some electrical engineering skill and technical know-how, Joe hacked the device and made the cheaper adaptor work like a charm on it.
Aside from leading Joe down the road to many more camera hacks, this also led him to a passionate new hobby – armchair hacking (his term). Joe says that armchair hacking is among the most important steps in a successful hack because it’s the critical first step. It entails using a discerning eye to study the object that’s going to be hacked, looking at it, seeking holes in the armour, and plotting the angle of approach.
One of Joe’s most significant hacks would be the time he hacked Direct Memory Access (DMA). DMA is a protocol that allows add-in cards to directly access memory instead of asking the CPU to fetch it. After some armchair hacking, Joe took a testing chip that used USB, he added a little hardware, added a little software, wrote a Python script, and suddenly he had a drive-less way to push and pull data from the system’s memory.
The point of all this hacking? It tests the integrity of systems. If there is any vulnerability in the tech being used by governments, businesses, or the masses, it’s a much more desirable situation for Joe and his colleagues to find it first so it can be fixed rather than for bad actors to discover it and cause harm. “We can’t always assume the hardware works as we think it does,” says Joe. “And we can’t always assume the hardware is fully trustworthy and perfect and infallible. A protocol is not secure until you have the tools to poke at it and inspect it.”
Joe offers his own official training to be a white-hat hacker, but he also has advice for those just starting out. “Figure out your core skill set – electronics, software, interpersonal communication, politics, etc. You’re dealing with understanding a system, and when you combine that with the desire to see how a system works, you get the ability to reverse engineer and take apart and manipulate that system, which makes you productive as a hacker, someone who makes a change.” As for where hackers should begin – Joe says hardware hacking villages at conferences are a great place to start. Also, he advises, you can always go to a thrift store, buy some cheap hardware, take it home, and take it apart. That’s hacking at its core.
History can be seen as a series of “Aha!” moments, and we’re excited to trace those milestones that have shaped our digital age. Hear Joe go deeper in-depth on the topics mentioned above as well as much more in our premiere episode of Avast Hacker Archives.
Avast Hacker Archives, new video and podcast series, that uncovers the “Aha!” moments that hackers and researchers have had over the course of their careers. Jaya Baloo, Avast CISO and the host of the series, is chatting with renowned security experts about their backgrounds, education, and, of course, their toughest and funniest hack stories and projects — nitty-gritty and technical details included. Join us as we uncover some of the greatest moments in the careers of top hackers and celebrate their creativity and technological aptitude.