Phishing For Answers
“Phishing for Answers” brings you insider knowledge from the front lines of cybersecurity. Listen in as we speak with seasoned professionals about overcoming phishing attacks, managing user training, and implementing solutions that work. From practical insights to actionable strategies, this podcast is your guide to strengthening security awareness across your organization.
Phishing For Answers
Phishing for Answers: Cybercrime Lessons from Chris Tarbell
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Joshua Crumbaugh is a world-renowned ethical hacker and a subject matter expert in social engineering and behavioral science. As the CEO and Founder of PhishFirewall, he brings a unique perspective on cybersecurity, leveraging his deep expertise to help organizations understand and combat human-centered vulnerabilities in their security posture. His work focuses on redefining security awareness through cutting-edge AI, behavioral insights, and innovative phishing simulations.
PhishFirewall uses AI-driven micro-training and continuous, TikTok-style video content to eliminate 99% of risky clicks—zero admin effort required. Ready to see how we can fortify your team against phishing threats? Schedule a quick demo today!
Social Engineering As A Mindset
SPEAKER_00Psychology is the new file. We're not hacking systems, we're hacking behaviors for human complicated code. Just try it for science play. Social engineering for good and the best defense is in your mind today.
SPEAKER_01And we have the script on the bad guys by turning students from the easy target into the student line of defense.
Disclaimers And Guest Introduction
SPEAKER_02The views and opinions expressed on this podcast belong solely to the hosts and guests and don't necessarily reflect those of their employers or sponsors. We're seasoned security professionals, but this is a conversation, not a custom consultation. If you need specific guidance, reach out to Joshua Krumba directly.
Human Error Behind Major Takedowns
SPEAKER_04I'll let you introduce yourself.
SPEAKER_03That's all the good ones. Those are the best videos. Thanks, Joshua.
SPEAKER_04All right. Well, hey, it's a pleasure to have you uh with us today. I'm uh I'm really excited to uh to chat with you and just hear some of your uh some of your stories. Um now I'm uh I always focus on the human element. And so I'll just start there. Like, how much did that human error play into you being able to take people down along the way? All of it.
SPEAKER_03It's all human error. I mean, it if they were perfect, we wouldn't be able to catch them. You have to make a mistake in order to get caught. Um, you know, in law enforcement, you know, you're you're doing great if you catch the the bottom 25 uh percent. And so, you know, you know, a couple of the guys I caught, you know, they they only made the one mistake. Um, but there were others, man, they made a whole plethora of mistakes.
SPEAKER_04Yeah, that tell tell me about one of those, just where it's non-stop mistakes.
SPEAKER_03Sure. Um, so well, we we arrested this one guy who uh he he would log in from he thought he was was cool by logging in from his neighbors' IP addresses. Um, but they all came back to the same one. And so a simple uh you know drive-by found his Wi-Fi device, you know, not active, all of his neighbors active. Um, and so it was pretty easy to to narrow it down to the right apartment for the guy doing the stuff. Um, so that was one. But one that is the simple mistake and one of the biggest cases I worked was uh my partner on Hacker in the Fed, um, Hector Monsagore. He was at the time uh went by Sabu. Um, and he simply was emailed a link. Um, he clicked on that link, he thought his VPNs were up. He he used busy boxes to to hide his uh traffic, but the one time just came out of a nap and clicked on a link and it went into a compromise box. Uh, and then I had his IP address.
SPEAKER_04Oh wow, just just like that. So that's simple. So, I mean, there's the opposite side of it. Uh, tell me about well, A V unit.
SPEAKER_03A V unit got away. I never was able to get it. So A V unit, so Lulsec was uh Hector Monsagor Sabu was the leader of uh a hacking group called Lulsec. Uh, we were able to arrest all six, all five members except for A V unit. So once I arrested Hector and he started working with the FBI, um, it was pretty easy to track down. Now he didn't know the other people in his crew. Um, that's one thing. These hacking groups, you know, they don't they even don't dox each other. So um, you know, they all they don't know who each other are. So he didn't have a lot of clues, but we had a lot of conversation, so we were able to, you know, get clues from those conversations uh and pull things out. Uh but A V Unit he bailed out before uh before we could get to him. Hector always believed that A V Unit was an undercover Secret Service agent. Um, but uh because he because all the guy did was he provide infrastructure. Um, and so it it it kind of aligns up, but I checked with the Secret Service and they didn't have anybody working undercover those days, at least they admit to me.
SPEAKER_04Oh, that's great. So, you know, cybersecurity and hacking has changed a lot over the years. Uh, before we get to how AI is impacting it today, uh, tell me about how it was different when you first got into uh, you know, when you first started hunting cyber criminals.
SPEAKER_03Man,
From Grepping Logs To Better Tools
SPEAKER_03log files. All we had was like uh HTTPS uh access files and that sort of thing. We we didn't even have Sperlunk. We would have to to grep for for IP addresses and go through things or go through with notepad, uh, you know, or you know, a text editor to look for things and and put things in, you know, Excel was limited to what was it a million two um lines, and if the the log files were bigger than that, then we were screwed. Um literally, that is how we were going through tech through live through uh these uh these access log files. Um, we didn't have the tools, and so that really was the beginning involved for us, you know. And it but it was good because you learned, um, but also the criminals didn't have a lot of good tools either, so you know it was almost a fair fight back then.
SPEAKER_04Uh so what about now? Is it is it a fair fight now?
SPEAKER_03No, no, no, no. The two the the bad guys have much better tools there. So that's the the one problem with law enforcement is we we react to things. Um, not a lot of proactive law enforcement, which is is good because you don't want to stymie. I'm a technologist, I don't want to stymie technology, uh, but you know, it's reactionary and that they can use the tools a lot faster than we can, and they have better access to stuff, you know. Even uh, you know, with tokenization, you know, they still have access. You know, they they had access to GPU boxes to crack passwords long before I had in the FBI. Um, you know, we had a bad guy's computer that we arrested, a guy named Anar Chaos, and we had his computer, but everything was encrypted. It literally took the FBI six months to crack his password. His password was simple, it was Chewy12345. It was the cat's name.
SPEAKER_04Social engineering might have been a quicker way to get it, actually.
SPEAKER_03Probably was well, I would like that's the thing. We so you know, we used to try to go through a computer and used to make a word list and use that word list to crack passwords. Um, maybe he didn't talk about the cat, I don't know. I didn't do that part of the forensics on the on the case, but man, it it would have been great to get that computer long before uh it took the FBI to crack it.
SPEAKER_04Yeah. Well, I
Passwords, Passkeys, And Predictability
SPEAKER_04mean, I I I can say from uh personal experience because I was an ethical hacker and uh and it it was always or almost always stupid passwords. Like um, I remember there was this one guy that would change his password every year, um and but we and multiple times during the year, but it was always predictable. And so since we got his password the first time, we would just be like, okay, how many times has he had to reset his password? Okay, here's what it is, and uh, and we would get in every single time. And so uh, I I mean, I still think passwords are a terrible technology, and I'm glad that pass keys is starting to get replaced them. Um, it's a much better solution.
SPEAKER_03I think it's just a technical savvy, though. I love podcasts like this that get out and tell people how to get on get pass keys, how to make it easy. Um, I love sites that force you to have it, yeah. You know, you know, yeah, they force people, the technology is there, you know, whatever mechanism you have to make yourself more secure and make yourself not the low-hanging fruit, I'm all about it.
SPEAKER_04Well, I also think that the beauty of pass keys is its simplicity. For the longest time, everything cybersecurity made things more difficult, and with pass keys, it makes things easier. And if we really want the average person to be more secure, we gotta make it easier until your mom loses it, and then you you're spending so much time.
SPEAKER_03That's the only downside, is uh there's a general idea out there that doesn't protect their pass keys so well.
SPEAKER_04Yeah, that's funny.
Deepfakes, Urgency, And Simple Scam Checks
SPEAKER_04So AI is changing everything. What's what stood out to you the most recently?
SPEAKER_03How easy and fast it is to make deep fakes. You know, you and I are putting our voice out there, and deep fakes, they only need apparently it only needs three seconds, is the latest thing. Three seconds of your voice, and you're able to do it. You know, we did a covered a story on Hacker and Fed this week about you know, a woman lost fifteen thousand dollars because she got a call from jail from her daughter, um, and and she sent the money. Um, you know, uh one thing I gotta get out there the police, the FBI will never call you and ask for money. Um, that will never that's never how the process in the United States works. So never fall for that one, you know.
SPEAKER_04Uh well, I mean, to that regard, the CEO's not gonna call you asking for gift cards either. I mean, there's some basics that that I really feel that are still lost on the general populace.
SPEAKER_03You know, if someone's getting a hold of you and trying to make you do something quickly and trying to make things go fast and trying to make you not think about things, and you just stop and take a breath. Wait, does this make sense to me? I had a buddy this week. Uh, my buddy got an email from his the school secretary that his kids go to the school, and there was like some sale coming up because Miss Rhonda was moving and it was like a tractor for 3800. And I'm like, Derek, do you think you can get that tractor for $3,800? Does that make sense? Just Google that tractor and everywhere else, it's fifteen thousand dollars. I mean, you know, and and who's miss rhonda? He goes, I don't know. I was like, Yeah, they're just they're trying to get you to move quickly and you can't miss out, you know. They they they use FOMO against you.
SPEAKER_04Oh, oh, absolutely. I I mean, I think that particularly when it comes to cognitive biases, the bad guys are light years ahead of the defense because they're aware of and exploiting the cognitive biases, and we for the most part are not. And and the like a few that I I find really interesting the authority bias. We were just talking about how you know the state's not going to ask you for money, the government's not gonna ask you for money over the phone, how the your your CEO is not gonna send gift cards. But if we had our defenders just as aware, and if they were using that same authority bias to make sure that they got a message from the CEO or whoever it happened to be first saying, Hey, I'm never gonna ask you to buy gift cards, we could take that bias and flip it on its head. And and I think that's one of the areas that uh that just my opinion, we've really not stayed ahead of the game on.
SPEAKER_03No, I I completely agree. I can't, you know, if people just went into being online is thinking about being in the wild, wild west and everyone's out to get you. You know, I I hate that mentality because I love I'm a humanist, I love people, I love being around people, but on the internet, people are trying to trick you, they're trying to exploit you. Um, so just go in with a guarded mindset of well, this doesn't make sense. If if I wouldn't do this in real life, why would I do this online?
SPEAKER_04Yeah. Well, and I think it doesn't help matters that most of the war modern world has not seen any sort of real threats hitting their, you know, their country in their lifetime. And it makes people they have almost this over over what's the word I'm looking for, they they have too much sense of security when they should realize that the internet's really redrawn the battle lines, and that means the bad guys can be in your living room, they can be in your bathroom, they can be wherever you are, wherever your device is.
SPEAKER_03And people also get complacency thinking that they don't have anything valuable. Like, I don't have any money, I don't have any Bitcoin, I don't have any cryptocurrency. You may work someplace, your husband may work someplace that a client list or some sort of access, you know. You know, when we were during COVID, you know, so many work from homes and you're on the same router. If I can infect that router, then I'm gonna get business traffic, I'm gonna get what I'm looking for, you know. Uh don't get complacent about those sort of things. You know, you may have some sort of connection that you don't even know about that is value to somebody, you know. And if it's not that, they still want to use your home router as a hot point, you know, they're trying to infect you just to just to you to exploit the stuff you have. I mean, we're seeing that big with you know with anthropic, where the you know they put export controls on it. You could go to China and get access to anthropic still because there were so many hot points for sale uh with US IP addresses. Um, and so you know the Chinese still had access. You can put whatever export controls you want on things. Uh, there's plenty of US-based IP addresses you can buy because people's homes routers are have been popped.
SPEAKER_04Yeah, yeah. Well, I mean, I I I completely agree. It's uh uh well, I think AI in general is one of those things that, well, it's Pandora's box and it's been opened, and unfortunately, there's no closing it now. And uh, and I I mean, I I for one am a little concerned about what that means in the future. The benefit I will say is that we do have AI to fight AI with, but if the bad guys are are so much ahead on weaponizing it and we're behind on, you know, uh using it for defense, then yeah, they're they're gonna win. And we're about to have a really rough cyber year.
SPEAKER_03I think it's gonna be tough at first, but I think we're gonna win in the end. I think the good guys are gonna use it. There are some really good, strong AI defensives coming out. It's just we have to catch up and we have to get access. I mean, you know, these billionaires and trillionaires are they're they're building these models and they need they need to make their money back from this investment. And so, you know, to get access to you know the anthropics and you know the big stuff, it's tokenization is out of control. I mean, I know a lot of the security companies, if you're not spending 25 million a year there, they don't want to even pick up the phone right now. Um, you know, but you know, they're also giving access for free to these big banks and to to big you know industry partners uh to secure their their their stuff. Um, you know, yeah. The problem is is they're finding 25,000 vulnerabilities at once. It takes a long time to fix.
SPEAKER_04Yes, it does. Well, I mean, that's where one of the areas I think that AI is going to be interesting is helping us dot all the I's and cross all the T's. Um, that that's an area I really am excited about because so much, at least every time I broke into a company, it were it was always the things that fell through the cracks that let me in, the things that they forgot about, the things they set up today that were only going to be up for a day, but they left fault credentials on it, or whatever it happened to
Misconfigurations, Basics, And Third-Party Help
SPEAKER_04be. I mean, I and I've got a real story like that where uh we we start with this. It was New York City retailer that we were doing an assessment on. We find a self-password reset tool that is on their uh perimeter. And uh and when we get to the page, we notice that the credentials auto-populate. It's default credentials, but they auto-populate. And it was just admin admin at that. But we click log in, and and so we get in and it says, Okay, would you like to sync your active directory with a third-party database? And we're like, yes, you know, and so we sync it, and this is within uh probably 15 minutes of starting the assessment, and now we've got every single username and password hash for their whole company, and uh and they still had uh I guess I'm dating myself a little bit, but they still had uh quite a few accounts that were land man, so we were able to just pop them like a nothing. Uh, but it's uh it's those things that still happen every day. Uh one of my my newer clients that uh that I recently brought on, um, they came to me after they had had an incident, right? And and so we're helping them. And uh, but it was the same thing. It was a misconfiguration from somebody in ITU that didn't quite understand what was done that led to a ransomware incident that probably wouldn't have happened if it wasn't just for that one misconfiguration or that one bit of human error. So I still see that as the number one thing, even when it's not people clicking on fish.
SPEAKER_03Yeah, yeah. We yeah, we the amount of devices that are bought, you know, these fancy, you know, million-dollar firewalls and plug and play, and they think they don't have to configure them right, you know, that they they need outside help. I mean, so a lot of guy, a lot of these you know, mid-sever level companies, they don't they have IT companies, they I IT departments. Well, IT is about service, providing services. That's not security, security is about limiting services and and making the you know the ship liner, you know, compartmentalized. So if there's a nick in the hull, the whole ship doesn't have to go down. Um, and that's not service-based, you know, you're not getting things out to your to your your clients, your workers, um, like you want to. And and that that is all 99% of the times that's what we're seeing too, is the misconfigurations of these huge devices that could easily be tweaked. Um and and hire a good third party that knows how to do it.
SPEAKER_04Yeah, well, and and to I mean, I think it's the third party is not just about having that expertise, it's about keeping your own people honest. And and I don't say that in a way like the the IT team is going to be lying to you. I mean, that's not that often that they're gonna lie, but what I what I mean is they may make mistakes, they may not realize what happened, and you need that independent, uh, sort of third, uh, third party view, uh, you know, in my opinion, at least once a year, if not more often than that. And I I think with AI, finally, it can be a lot more often than that.
SPEAKER_03But that third party also brings experience, like your guys are seeing the same things over and over on your same systems. You know, a third party can come in and they, hey, we were working with this XYZ company and they were having this problem. You might not be having that now, but we can fill that gap right now. Um, you know, and then also getting some threat intelligence. There's a lot of great companies out there that can kind of what where are things coming from? How are attacks happening? You know, you know, a lot of great companies out there setting up honey pots and seeing where the next attack vector is and what people are working on, and what you know, what North Korea is trying to pop, what China's trying to pop. And you may fall under that. Oh, hey, we have some of those, we should probably change something out, or or not dangle something out there, or GeoFence, or do something simple.
SPEAKER_04Yeah. Well, and I mean the simple point, just to echo what you're saying, I almost never see companies that have done everything they can to just harden their existing infrastructure. It's always let's go buy more tools and all that. And I'm not saying that tools aren't great, but you need to start just with the basics, and that's locking down everything that you have. Because if you don't start there, nothing else is gonna matter.
SPEAKER_03Yeah, new CTO or new CISO comes in and they just want to buy new stuff. They get a they they demand that have a new budget and they buy all these toys and they just don't let them talk to each other, they're not getting the best out of these things. It's fun to get new toys, everyone likes to play new toys. Uh, but you know, uh again, having a third party configure it properly and give you that experience that they're seeing, you know. But you have to do your due diligence on where you're gonna get your third party from. Um because there are, you know, unfortunately in cybersecurity, there are a lot of snake oil salesmen out there.
SPEAKER_04Oh, yeah, yeah. Tell me that.
Silk Road And Catching People On Tor
SPEAKER_04I mean, there there sure are. Um, but so tell let's flipping the subject a little bit. Uh, tell me what was your favorite story? I mean, you spent quite a long time taking down cyber criminals. There must have been one story that really stood out to you.
SPEAKER_03Well, my favorite story and my favorite time are probably two different things. Um, you know, no, because I I mean, not to reiterate, but my partner, you know, Hector, uh, you know, we're best friends now. Like we have a podcast together, we hang out together, we travel together, we go do speeches together. So, someone I arrested in the and I essentially I hung 125 years on it on him. Uh, I had enough things that he would have done 125 years in prison. Um, he worked with me for nine months. We saved 300 hacks into the US government, thousands of hacking other US companies, and then hacks around the world, you know, into the thousands. So, you know, we were able to stop of what was just his access, what he was doing at the time. Um, but the more exciting one that everybody wants to talk about is Silk Road. So I was the the main case agent on Silk Road, which was back then the first uh dark web website, you know. Literally, you could buy anything. Well, there's two things you couldn't buy. You couldn't buy uh guns because that was a different website that in in that was next to it, and then you also couldn't buy fake degrees. Um, come to find out the guy who ran it, he he earned his degree and he thought it was unfair for people to to buy degrees online, but you could buy anything else, you could buy murders for hire, you could buy pure that's where he draws the line. His line was fake fake degrees.
SPEAKER_04That's that's actually quite humorous. Okay, continue.
SPEAKER_03So, so yeah, so this came up. Um, the DEA was working on it, and a whole bunch of HSI was working on it, Secret Service was working on it, and we just had a big success. Uh, one of the guys I told you that we took down was using this thing called Tor, and we were able to find him even though he was using Tor, a guy in Chicago, um Anar Chaos. And so Southern District of New York came over to us and says, Hey, we got this problem, we have this. Website that's using um Tor to hide with the IP addresses and then using this cryptocurrency called Bitcoin. Now remember, this was 2012, 2013. You know, no one knew about Bitcoin. And so we're like, all right, we'll take a look at it, we'll see what we're gonna do. You know, normally they take a drug approach and they'll address arrest a drug dealer and kind of work their way up the chain until they get to the head of a mob family. Um we couldn't didn't have that, we didn't have no one knew each other. It was all done through, you know, anonymous online, anonymous currency, and anonymous uh uh mailings back and forth. Uh and it was drugs and everything, anything you want. It was it literally was the wild, wild west of the internet. And so uh we started taking a look at it in a different technical way. Um, and so we were eventually able to find some infrastructure. We found the server running out in Iceland, um, and then we found the US infrastructure, which I mean, I'm not gonna tell somebody how to make commit crime, but if you're in the United States, don't leave your infrastructure in the United States, it's too easy for the FBI to get there.
SPEAKER_04Um, I would agree. I mean, just half of like one foot over the border, and it requires a lot more uh jurisdictional uh set something up in Russia or China or someplace, you know, it's not as reliable, but man, if you have redundancy, you'll be okay.
SPEAKER_03So we traced our guy out to San Francisco and made a big arrest out there. So it was uh they made a couple movies about it, they written a bunch of books about it. So it's it was an exciting time.
SPEAKER_04Yeah, it recently was back in the news again.
SPEAKER_03Yeah, yeah. Trump, uh Trump issued a pardon.
SPEAKER_04Yeah. Any opinions on that that you'd care to share with us?
SPEAKER_03Um, yeah, I mean, I don't
Pardons, Bragging, And Leaving Receipts
SPEAKER_03I don't mind. I I don't think he should have been pardoned. Um to so a full pardon means your records wiped clean and you get to go. Um, you know, presidents have you know can also commute sentences. So if he thought that, you know, so Ross was sentenced to two life terms plus 40 years, um, so he got more than uh most major drug kingpins, but he was charged with kingpin status. Uh in the United States, and the kingpin status is if you make more than 10 million dollars in drug sales and have more than five employees, then you're a drug kingpin. Um, and and Ross met that qualifications on almost every drug. Um, and so uh, you know, I guess uh I guess Trump thought thought he should should have that whole thing pardoned. I disagree with that. I mean, again, uh could have commuted it, but but good on Ross for you know, he he he the time I knew him, he was he was a decent guy. Uh he get out got I think he got in and over his head. Um, I think it snowballed, and then you know, he had a libertarian viewpoint that you know um he believed that anyone should have access to drugs, and so you know that that was his view. Unfortunately, we had we had UF laws that I that I was my job was to enforce the US laws. Uh fair.
SPEAKER_04So, to that, uh I was speaking with the former head of cyber for Europol, and one of the things that she mentioned was that more often than not, they got their convictions because people would brag about what they did. Um, did you find that to be the case where they were like so proud of what they did or um how they got in that the Tism took over for lack of a better term, and and they just spilled the beans?
SPEAKER_03I've seen it, you know. Well, I mean, not to keep Harbin on the same thing, but but Ross had a diary. Uh, I mean, if you're you're committing things that can get you life in prison, why would you keep a record of it? So, you know, somewhat maybe you think you're untouchable and never will get caught. But I mean, when we arrested him in the library, on his laptop was a diary of all the bad things he's done, um, and kept the records. Uh, he had a backup server of all the illegal conversations in uh sitting in in Philadelphia. Um, if you were going to run a drug empire online, why would you keep everyone's conversation on a backup server?
SPEAKER_04I feel like if I'm doing it, I'm having that wipe like at least every 24 hours, if not more frequently than that.
SPEAKER_03I mean, yeah, there was there was a a low a lull sec hacker, Kayla, ended up being a guy named Ryan Aykroyd. He had a computer in his house that literally had two wires touching. And if he hit it, hit it as the police came through the house, it wiped everything out. I mean, it wiped his whole computer completely out.
SPEAKER_04You know, that's more like what I would expect out of a I mean, maybe I've watched too many movies, but in the movies, they have a set to blow up.
SPEAKER_03Yeah, they they always talk about de Gausers or something sitting around there, a big magnet that wipes your hard drive as soon as you hit a button or you sit get up out of your seat or something like that. Um, I never saw one, but it was always fun to talk about it. And you know, you can always rile up a judge or two and be like, Judge, they may destroy evidence with a de Gausser, and then you explain to Degouser for 10 minutes.
SPEAKER_04Oh, that's that's great.
Pig Butchering And Practical Home Hardening
SPEAKER_04So um I I guess what has stood out to you the most across just all of the different crimes and and in terms of the the victims, like is there one thing that the victims of these crimes have in common or something that they can do to uh you know make themselves less likely to be a victim? And I know you've done uh a lot of work on different sides, but uh, you know, one of the things that I've seen a lot of uh and that the I guess the FBI agents uh from well where I used to live, they have the cyber division there in Huntsville. And uh and they said that you know one of the number one things that they were investigating were all the romance scams and stuff like that that are hitting people.
SPEAKER_03Um yeah, so that it's called pig butchering. Yeah, we get it every single day. I get emails all the time about people. You know, I was on a podcast last week and got emails and LinkedIn messages about how what can I do, and there's not a lot of good resources. The problem with like pig butchering is it's all through crypto. And so your best thing to do is to go into IC3 and fill out a form and but give as much detail as possible. You know, this was the wallet, give the whole wallet address that was stolen, you know, from and all that. Because maybe one day, if they catch the guy, you may be able to get some restitution for some of it. Um, unfortunately, a lot of it's going overseas. Um, you know, the the easiest thing is to just harden yourself a little bit, you know, understand that you are possibly a target, you know. We're seeing a lot of you know, internet of things uh being taken over. Um, whether it's you know the Chinese wanting hot points in the United States to use AI or you know, the bad guys needed hot points, home routers. You know, you the FBI is putting out this certain home routers that you shouldn't be buying. But if you your home router, just recycle it every 90 days, just walk by on the first of every month. Turn your router off for five minutes and then turn it back on. And maybe it'll have a firmware update that month and it'll make it a little bit more secure, or if somebody's in it, it's gonna boot them out of there. Um, you know, and they might not be able to get back in with that firmware update, you know. So simple things like that. Understanding that, you know, your thermostat that you plugged in and it was in admin admin, uh, you know, change the password. You know, if anything comes with a standard password, just make it more difficult. Um, you know, so many people are making it too easy to be victimized.
SPEAKER_04Yeah, yeah, no, I I agree. Okay, so probably our last question because we're about out of time. Uh, but as I talk to you, I'm thinking about this guy that I worked with earlier in my cybersecurity career. Not gonna name any names, um, but he definitely gave me the might be a closet black hat vibe. Um, and and and he was always doing things like, oh, I'm writing my own ransomware. Well, why? Right? Um, but it's always made me question and and I guess I have this theory that there's at least a small group of the ethical hacking community that I question if they're actually ethical and if it's not just a cover. Well, what do you think about that? I mean, have you ever seen anything like that, or is it just me?
The Thin Line Of “Ethical Hacking”
SPEAKER_04All the time.
SPEAKER_03I see it all the time. I I think the term ethical hacker most times is an oxymoron, uh, because it's a hard line to cross. Like, I'll give you an example. There's a lot of great places now for people to go and learn how to hack and learn how to do things. But back in the day, back when this ethical hacking first started, there wasn't. You had to hack into boxes if you want to use box. Certain OSs, if you didn't have access to it, didn't you know, you you had to hack into one of those boxes to learn how to use it. Um, and so that line of, well, I'm not doing anything, I'm just learning. Uh, that's still a violation of 18 USC 1030. You're still breaking into something that you it's it's exceeding authorized access, you know. Um, well, it's not a felony unless you do $5,000 worth of damage, but what part of the damage is investigating what you did in there. And if it takes a consultant to get in there and you know $5,000 worth of investigation, now you got a felony.
SPEAKER_04Um, so and then $5,000 for a cybersecurity incident responder is you're definitely hitting that in a second.
SPEAKER_03So hello, this is cybersecurity.
SPEAKER_04Uh, that's five thousand five thousand. Exactly.
SPEAKER_03So, yeah, so uh yeah, I I think it's it's some you know, when you say you're an ethical hacker and you just kind of shrug off and not know exactly maybe you don't know exactly what the laws are, and maybe you don't, you know, you're pushing things, but it definitely it's hard to not push the bounds and and you want to learn. Like I'm interested, I like to reverse engineer things and see how things work and you know get into some of these things that they're doing.
SPEAKER_04Um we called it dynamic scoping, yeah.
SPEAKER_03Hector calls it free pet tests, uh, for those that don't the unwilling.
SPEAKER_04That's awesome. Well, uh, it's been really a pleasure having you on the show today. Any sort of final thoughts for the audience here?
SPEAKER_03Well,
Know Your FBI Contacts Before Crisis
SPEAKER_03I mean, if I always leave this with the with the audience, if you're in a uh business, if you own your own business or you're in an IT department of business, get to know an FBI agent. Um, your business is going to be attacked at some point, and it's going to be attacked on a Friday right before a long weekend. They always go in on a Friday before a long weekend because they know they you want to leave. So get to know, go to InfraGuard, join your local InfraGuard, join, you know, someplace where you can pick up a phone and you can call the right law enforcement people when the incident happens. Um, FBI agents are happy to come and talk with you, happy to have you out there, happy to know you. You know, they get credit for it. So don't be don't be introduced to the FBI just when the house is on fire. Um, get that relationship long beforehand. So, you know, they're they're happy. If you know one speaking somewhere locally at a at a local conference, go out and meet them. When they come off stage, shake their hand and be like, hey, I just I wanted to meet you and uh because I know I'm gonna need you one day. Uh and I don't want this that to be the first time I meet you. So um, you know, don't be scared of the FBI.
unknownYeah.
SPEAKER_04Well, I mean, I because of my company, I've actually uh worked with the FBI uh quite a little bit. And uh, and that was one of the biggest things that they kept telling me is hey, as you're out there, as you're talking to people, you know, make sure that they know they don't have to be scared to call the FBI when if an incident happens, we're here to help, and there's a lot of tools we have at our disposal. Um,
Travel Risk Story And Closing Thanks
SPEAKER_04what's interesting though, and I I gotta tell you this story, uh, so they warned me, um, they had said, you know, you're I guess I was giving a keynote over in Stockholm, and they said, Hey, just be really careful. You're going over to Stockholm. Uh, we've had uh some issues. And so um I go over, I'm it's the last day of the trip. I'm tired. I leave my laptop in the room. I uh I go for a walk, and uh my wife forgot something. So um we're only out of the room maybe 10 minutes before we get back to it, and all of our bags are open, everything's on the floor. Um, laptop's still there, and uh, and so I go, hey guys, you know, I've I've got my people, but I feel like you'd be better at investigating this. You know, you want to take a look at it, and they're like, Oh, it's uh fully patched MacBook Pro. Yeah, we don't have the the capability. Okay, guys. I just thought it was a good story.
SPEAKER_03We used to bring dummy laptops just to just to make them work more harder. So bring a fully encrypted uh two terabyte drive and leave that in your room. That'll give them some time to mess with things.
SPEAKER_04They did say that as long as I had it fully patched, there wasn't a lot to worry about. But in my experience, you get full access to a Mac. That's the one, that's their Achilles heel. Yeah, yeah.
SPEAKER_03So yeah, it's tough. So, but yeah, thanks for having me on. I really appreciate it. It was great talking to you today.
SPEAKER_04Yeah, thank you so much. It's been a fabulous uh podcast, and uh yeah, thank you. Have a great day.
SPEAKER_03Thanks, bye.