CYBR.HAK.CAST

Lying for a Living with Jayson Street

CYBR.SEC.Media

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 33:25

Michael and Phil are joined on this episode of CYBR.HAK.CAST by hacker, author, and speaker, Jayson Street! They discuss his career in physical security, social engineering, and red-team engagements around the world. Jayson also shares how his approach evolved from simply exposing security failures to create teachable moments that celebrate employees who recognize and stop suspicious behavior. Throughout the conversation, he emphasizes that stronger cybersecurity awareness comes from investing in people, improving situational awareness, and helping employees recognize when something is out of the ordinary. 

Do you have a question for the hosts? Reach out to us at media@cscgroupllc.com  

In this episode: 

Keep up with our Conferences and Events: 

Keep up with CYBR.SEC.Media: 

Learn About CYBR.SEC.Careers Non-Profit Efforts 

Subscribe to the podcast:  

Listen to our other shows: 

Thank you to our Media Partners: 

SPEAKER_01

Hello and welcome to another episode of Cyber Hackcast. I'm joined today by my BBFF, Michael Farnum. How you doing, Michael? Does Jason know what that stands for? He probably doesn't, unless he's been watching the podcast. Probably not.

SPEAKER_03

Bald friend, bald best friends forever, Jason. I know, but it's like, but I can shape, I was just offended because I could shave my head. I I wanted to be one. Join the club. You can do it. Would love to see it.

SPEAKER_02

So how are you guys doing? Good, man. Jason, you're in your uh your den of doom. What do you call that?

SPEAKER_03

I call it the lab. The lab. Yep. It's just it's better than saying that you know the nicer part of my dumpster fire.

SPEAKER_01

So yeah, it's looks like it's changed a little bit since last time uh we spoke on a podcast.

SPEAKER_03

Yeah, it's like it's been it's this is literally, I I've been moving for a while now. And so this is literally just what's left over. I mean, trust me, man, if I had all my stuff out, uh that would take a whole episode or two just to go through all that stuff. So this is the this is the downscaled version.

SPEAKER_01

Okay, because I have issues. Jason, I've actually interviewed Jason for a couple different podcasts and really excited to have him on because he really fits the cyber hackcon uh persona since it's a hacking conference. And how can you think of hacking and not think of Jason Street?

SPEAKER_02

What do you think about that, Jason?

SPEAKER_03

I'm not good with compliments, so I'm just like okay. I think I usually usually it's like when I'm there, it's like usually bringing it down or just being the lowest bar possible. So uh so yeah, so it's like when you when you think of hacking, you think of Jason Street, and you can do better than that. So he's a humble guy, such a humble guy.

SPEAKER_01

Speaking of speaking of cyber hack con, so what did you think? Or for a cyber hat con?

SPEAKER_03

Dude, I am telling you, man, I love that freaking con. And and honestly, it's like I can say that because you're not paying me to lie, so I'm not going to lie. I do it for a living. Uh so unfiltered, it was great. I love the whopper. Oh my gosh. It's like I've never met like such a Hollywood royalty before like that. And so I I sort of got a little, I sort of fangirled over it a little bit, and it didn't nuke me, so that made me happy. Um, and so uh no, it was I saw so, and this is the key thing about a conference. It's like all the conferences you go to, they're going to be sharing knowledge. Done. Yeah, of course. It's like, but to go to a con where you feel like a connection to the community, where you meet new people, but also see old friends, that's what makes the conference. It's like, I don't care, it's it's not about the backdrop, it's not about uh the buzz, it's not about anything else about except for the networking and the people that you meet and the people you connect with. And quite frankly, and I told this to so many different people, uh, especially to the volunteers when I thank them, because quite frankly, speakers are a dime a dozen. It's like I ain't no special person over around here. It's like you can replace me easily. It's like, but the volunteers, the organizers that are not just there for an hour, but they're going there all day for uh months and throughout the year prepping and planning it, that's what makes a conference. Those are the people that are giving back to the community. And it's like, and so I'm always in awe of when I see a conference like that where it runs smoothly. It doesn't matter how chaotic and what kind of screw-ups we're in behind the scenes. I don't care about that. I didn't see that. The attendees didn't see that. It's like it ran smooth. It was like, for all intents and purposes, it was all great. Uh, I saw a whole bunch of people, the talks were all good. Uh that you had different events and different places for all different kinds of interests, not just, oh, this is the way we're gonna do it. And if you don't like this, go to another con. It's like I really loved that. So yeah, that was my take on it, like legit. It's like, and I would tell that to anybody on camera or off.

SPEAKER_02

That's greatly appreciated. Yeah, the um I think the one snafu that was very visible actually kind of turned into uh cybersecure or cyber hat con lore at the beginning of it. I don't think you had got there right at the beginning of it. In the very first opening keynote to Jason, oh uh Jason Haddock's we had a uh a snafu, but then we got wirefall on stage and almost started doing some uh some uh impromptu, you know, kind of just talking about what was like what was he, what was the topic? Walking on the moon or whatever. Yeah.

SPEAKER_03

But but see, and how's that the snafu? It's like that's the whole thing. I tell you, it's like if you expect perfection in a talk or a conference, you're just setting yourself up for failure. I know for a fact, every talk that I give, I'm going to screw up. That's why I'm pretty good giving talks because I know it's going to screw up at some point. And I don't let it sidetrack me. I don't let it derail me. It's like I just like, okay, there's the screw up, let's keep going. The people that like crater are the ones that expected perfection because they practiced all the time. And then when it messes up, they're like, oh, I didn't prepare for this. So we're hackers in a hacker conference. It's like you exemplify that because, hey, yeah, there was a screw up. But you know what? We adapted, we overcame, and we made it awesome and something to talk about.

SPEAKER_01

Cool.

unknown

Cool.

SPEAKER_01

So uh before we get too far into conversation, for folks that may not know of you, Jason, if you wouldn't mind kind of sharing about your background.

SPEAKER_03

Um how far do you want me to go? How much time do we have kindergarten? Uh uh Well, actually, it starts there, uh, close to it. It's like, because every uh person on this planet, living or dead, uh, has been a hacker. You ever been around a three-year-old? What exemplifies them? Hacking. Because all the three-year-old does is why? How is that supposed to be like that? Why can't we do it this way? I want to talk. Who is that? What are they doing? Why are they doing it that can't we do it this way? I want to build this. I've got cardboard, let's build it. That's hacking. If the institutionalized school system, your peers or your family don't beat that out of you by the time you're in your 20s, congratulations. You're a hacker. And I don't mean computer hacker, I mean hacker. You could be doing mechanics, you could be doing cooking, you could be doing science, whatever. It's like hacking has nothing to do with computers. It's that train of thought that, like, this is the way I want to do it. One of the best examples of hacking that I love to explain to people that they don't really realize is hacking. Lowriders. In the 1950s, they started creating the whole lowriding movement on the West Coast. They hacked vehicles, putting the hydraulics, changing the frames, changing the way it operated. That how was that not hacking? That's like original car hacking village right there. It's like, so computers are just the newest realm that we're exploring. I started hacking for like in my career as a physical security person. I would go on site and I would look at it and I'll go like, well, yeah, I need to defend this. I want to make this place secure. So the first question I'm gonna ask is, how would I rob this place? Oh, you know what? I should have done a light here. I should have done uh there should have been cameras right here. I could go through this blind spot right here. We need to put that there. And so I defended my my companies and the companies I work for by thinking first of as an attacker.

SPEAKER_02

Well, how do you let's let's segue that then? And I 100% agree, right? It's the people just being curious. And to your point, if they don't beat it out of you over the years and beat that curiosity out of you, you're gonna have some way or shape or form that you're gonna try to use that curiosity. Um, but you talked about like the physical pen testing and how that uh how you got into that. I mean, that's what a lot of people know you for, and I know you go all over the world and try to break into places to to help them, and you're not, you know, doing it for nefarious purposes. Like, give us a rundown of one or two of those that you've gone through and why your background like lent you to be successful there.

SPEAKER_03

Well, I I think one of the key things is to help uh is to show how I actually started doing the the pen testing. Um it's like is the fact that in 2009, uh I was working as the AVP of information security for a bank, a national bank, and I built defenses from 2003 to 2009 at that point, as I would like, how was I going to rob this this company? How was I gonna like try to breach the security of the this uh the websites of the processes of the bank itself? And in 2009, I was giving a talk at DEF CON, and then I was giving a talk uh at a couple other locations uh about what I was interested in at the time, which was cyber warfare and stuff, which don't uh don't go back and watch it because it's eerie what I predicted back then. But um I met another speaker um who was like talking about this thing called red teaming and physical compromise and stuff, and I was so inspired by this guy that I was like, man, that is definitely something it's like I want to do, something I want to learn about. Uh and so I go back to my bank company, and I was like, hey guys, I've been building all these defenses. We haven't had a breach or a virus outbreak in over uh six years since I've been there, you know, from 2003 to 2009. There has not been one breach or anything like that. It's like uh it's like, but what would happen if someone physically got in through and connected directly to the network? I want to try to rob our our banks and our branches and see if I can what I can do. And they said, okay, there's here's some branches that you can go and try uh and let us know uh if you're successful or not. And so as a blue teamer, I went and started attacking my my uh bank. And that's when I learned a really good thing. I'm really good at robbing banks, and they were not prepared for the success. Uh so uh so I learned how to start looking at the defenses, not just as the blue teamer. And that's why I always tell people if you want to do red team, always start off on the blue team, always start on the defensive side, learning the bureaucracy, learning how the the policy decisions get made, what the real things that people have to secure and have to protect against. And so I started doing that, and then I gave a talk on it or two. Uh, and that's when I got disillusioned about the my inspiration because it turned out he was a huge bully and a-hole, so I don't mention his name. Very good. Will not lie. I will not lie and say that he is not a freaking massive expert on red teaming, better than I'm ever going to be. And I'm not going to lie and say that he doesn't care about this community and is a wonderful influence on our community. I just think he's a personal piece of human garbage. But uh, that's neither here nor the. When I tell my children when they were dealing with bullies in high school, he was the one that I talked about uh to give them the understanding of how what I had to deal with. Uh and so I started doing the red teaming. And after the talks that I did, more and more companies wanted me to try to rob them. And then in 2016, I learned a valuable lesson. And this is when I stopped doing red teaming and I started doing security awareness engagements that I do now and that I train people how to do. I was robbing a uh government facility in in Virginia somewhere, and uh what happened was I had just using how the co-pilot operates, the mind and the brain operate. It's like the mind is the consciousness, our soul, our spirit. The brain is the co-pilot, it operates our shell. And it has a preset of firmware that takes in our surroundings and stuff and dictates how we look at things in the world based off of its firmware settings. And so what I did was using that, I was able to trick the employee that was going through this one door to let me go in behind them, even though I had plainly a printed visitor's badge with you know Gregory D. Evans' name on it, too. But it's like I I got them to go in. And so they let me in. And when I saw her face, though, because I am like part of my TISM superpowers, I'm very good at reading and people's facial expressions and body language and understanding what they're I immediately realized she regretted letting me in. But it's a it's an office setting. You don't want to be rude, you got to be polite. So she just kept going. She went right, I went left. I immediately compromised an employee. So, yay, I won. I did the red team. I broke them. I found a vulnerability, I did a good job because that's how my mentality was. That if I didn't break in, if I didn't find a vulnerability, then people were gonna think I was a fraud and that I was not good at what I did. And then I went across the hallway to compromise this other person, and I looked down the hallway and she's talking to another person who's standing up, and they're both looking at me. And quite frankly, I don't read lips, I can tell you exactly what they were saying. Like, yeah, he is sketchy up. I don't know why he came in right behind me, but we should be doing something about this. I don't know what to do. And so I go in and compromise the second person. Double success. Now I have to go down the hallway and I have a choice. I can immediately go out the door. I came in and I won. I was like, I won. I showed them that they they had vulnerable, I showed that they did. I was a good red team. That's what I was supposed to be doing. But then I had an epiphany because I saw the way she was looking and the earnestness and the distress that she had. And it just it just hit me. What if I let her win? What if I don't exit? What if I go past them? Keep trying to see what I can get away with, and give her the opportunity to correct her mistake. What will be the impact then? Because then that's going to be heard from everybody's gonna be talking about that. That's what ultimately I'm supposed to be doing is providing security for this company or this organization. So would it be better, served, that they got a memo three months later showing how they failed? Or having like a teachable moment right then and there of them detecting someone that was able to be an actual threat and could do damage, but the that fast acting and the fast inking response of an employee caught them. So I walked by the hallway, walked down the hallway, walked past the two ladies, literally said, Hi, how you doing? Kept walking, went to another office, compromised that machine. Less than two minutes later, I instantly regretted that decision because it was a six foot seven, you know, five thousand-pound ex-Air Force Marine, scary person, military dude who decided to storm in, going, who are you? What the? I'm like, okay, you know, it's like I'm gonna surrender. It's like, you know, I was literally about to start quoting Geneva Convention, okay, rules and ethics. Uh and but that was a teachable, it was such a great engagement because servers don't get mad when you pop them with MSO867. Still, today, happening. People get upset. People will not learn the lesson because they're so traumatized by the event. So I guarantee with all my clients now that I will get caught. I guarantee them that. It's like at least one part during the engagement. If I'm successful through the whole thing on the last day, I do nothing but get caught. And I've literally had to go to great lengths to make sure I got caught. I mean, horribly. But it's like, but I give them a win because I want to teach up to people. I want them to learn what their employees did the right thing. Well, they caught me by doing this. They thought about this, and that's what they were looking, and that's what they noticed. Instead of punching down all the time, going, here's all your failings, here's your findings, and here's what you did. So that's all I do now is social engineering engagements. It's like I do or security awareness engagements because I want to create situational awareness and the employees, not try to do security awareness dictated by policy, but make the employees and the humans more default situationally aware. It's a great lesson.

SPEAKER_01

It's really great. So, what is one of your latest experiences with uh one of these engagements?

SPEAKER_03

Oh, um funny, you should say that. Um, I literally the I think one of the funniest ones is like because I have not robbed a bank on site for like over two years. Like wasn't until uh in the US. It was like two years ago in 2024. And uh, but I have not robbed a uh a bank in another country organization on site in like since South Africa in 2019. So I was so happy that this last um about three or four weeks ago, I would literally I came straight from, I was literally at CyberpatCon, then B, uh then somewhere else, I think, then B sites Maine, then DC, uh, then you know, a small dip to the Pentagon, then straight to Central America, where I robbed a bank there. Uh, and it was so cool because it's like the first time I've done it in a while. And it was the first time I had actually had a partner. Uh, one of my uh covert swarm uh partners in crime, literally, uh Alex Dodd, is like uh he's X Special Forces, and I was able to proudly say that I gave X Special Forces guy almost a heart attack. Uh, because let's just say that my methods are a little bit different than his. Uh, he's more about the covert and covert swarm, and I'm more of the swarming you and over-empowering you with just my wonderful adorableness. Uh, and so, but the funniest part about the whole engagement was just showing you how much prep is important before you do an engagement. Because this one was like, I got this in uh I was introduced late into the project and I wasn't able to do enough recon or prep on where I was going. I didn't even book the tickets. I was just like, hey, while I was traveling, they were like, okay, we'll book your tickets. You are going to definitely be going boom. So I go there and I'm thinking, well, I'm gonna do my first day is always recon. I always dress up differently. So like I will have a goatee. I won't have any gel on my hair, so it looks way brighter and lighter and you know, more gray, but we're not gonna mention that part. Uh, and it's like, and then I'll like have glasses. And I'm thinking, it's in the Central America, it's like, you know, nice little Pacific Coast kind of town thing. And I'm like, okay, this is gonna be fun. I'm gonna go in as a tourist that needs to do a currency exchange, and I have my hearing aids with me, and I was gonna go up to them and literally I had it all planned. I was gonna go right up to the bank. What monster is not gonna let me charge my hearing aids, which is actually an OMG cable connected to my hearing aids. So they plug in the OMG cable, ba-boom, uh, because I'm a horrible person because I'm robbing you. Uh, it's like, so I always you always go like, how horrible, Jason. I'm like, remember the kittens. Hello. It's like I'm a criminal. I'm trying to rob you. We've established my moral fiber. You're being robbed. Would you prefer a gun? It's like, so I go there on that first day as a tourist, everything really set up to go. Their customers are not tourists. This Bank of America kind of thing for the name. Well, it was the bank of this country. It was literally that country's bank, like the Federal Reserve. It was like their customers are other banks in their country. And so I don't blend on the best of days in certain other countries and continents, okay? In a Hawaiian DEF CON shirt. Okay. And I put a tactical vest under my shirt so I would look even bigger. Not that that's difficult for me. And yeah, let's just say recon was successful. I knew what wasn't going to work. The second day I go in as a Microsoft employee, tuck my shirt in. I had a your company's computer guy patch on the shirt. I've got a Microsoft Lanyard compromised 10% of the workforce. And uh and literally every day I did not give, I went for the record, I did not give them one win. They got them all on their own. Every single day, there was at least one employee that did the right thing or said the right thing and stopped me and was successful in thwarting the attack. And I love that. I love it when the clients do the right thing. And if you're a red teamer and you're not celebrating the successes of your clients for doing the right thing and stopping you and thwarting you, you suck. Yeah. It's like, I mean, let's be honest. It's like your ego is getting in the way at that point. The only job a red teamer has is to validate the security of their client. And if they come across a finding to report it in an effective and proficient manner, that management will take the necessary changes and finances to fix it. Because they're getting attacked 24-7 from all over the world. They're paying you for the report and motivating management to actually make the changes. Half the security people that you're working with, they know what's wrong. They know what you're going to find, but management's not listening to them. They're going to listen to you. So I love it when the client does the right thing. I just, oh my gosh, it's the best because that's my assignment is to validate their security. So yeah, it was a great job. It was like the point of contacts were really great. Uh, the security, it's like uh when they had the when we had a debrief with them was wonderful. All like there were three ladies I thought, like, I have not been that terrified uh on an engagement uh since I accidentally robbed the wrong bank in Lebanon. These three women, their executive assistants, they they were out for blood. They realized after they let me do it that they they started talking amongst themselves and realized that I they shouldn't have let me do it. So they were hunting me down in the building, like looking and like they had literally cornered the head of IT, dragged them out of a conference room meeting, and had surrounded them. And I was like, I hated to do it because better him than me, but I was like, well, he doesn't deserve that. So I got to him and ushered them into the conference room and just prayed that I'd get back out alive. It's like, so that was hilarious because I was literally, they were not happy. Uh so um it was a great engagement. So I loved that because I mean, it wasn't about the robbing, it was about the education part and the way the people uh responded to it. And that client was like amazingly well. Uh, they did a great job on the defensive side already. Uh, but every teachable moment that I had, every thing that I did, they just responded wonderfully to it.

SPEAKER_01

Awesome. Yeah, it's pretty interesting story, kind of interesting. I'm sure you've seen kind of evolution in that type of uh engagement because I'm pretty sure earlier on you probably were successful every single time. And now to see people that are actually doing these type of uh uh engagements, which you can kind of see that I'm pretty sure this is someone that probably has this done, you know, annually or whatever, because if you're not doing that, you're not knowing how to lock this down and and really train your people to protect. So it's kind of cool to see see the evolution of seeing this working, and it's a you know, a statement of how people need to do these type of assessments.

SPEAKER_03

Oh, for sure. And I mean, I have a hundred percent success rate because I always get in, but I love it when I get caught. It's like even when I'm successful breaking into a place, I want there to always be at least one person or a group of people that say, no, not today, mother, not today. And that's when you know it's good because it's like it's not about my ego. It's not about that. It's about are they being serviced, are they being helped? Am I making things better than when I got there? Are they better before me having been there? Or did I just make a memo and a report that I need to give them? It's like I want to leave knowing that they're better secured and they're thinking of it in a different frame and mindset now.

SPEAKER_02

Yeah. I mean, that's even a trend in cyber security awareness as the you know, the products is like contextual training in the moment. What can you learn right then? Not make you go take you know five hours of security awareness training, but like let's let's teach you something very contextual to what what happened in that very instance. Let's take five minutes, 10 minutes at the most, to get that that in. That sticks in your brain a lot more than having to do all of that other crap. So I love that you give them wins, even if they don't, because that's an exact teaching moment. And that's a story, somebody like that that did that, they're likely going to get praised within their company, and that story is gonna float around. To me, that's a report.

SPEAKER_03

100% way more than a memo. And I will not report a person's name who didn't succeed.

SPEAKER_02

Yeah.

SPEAKER_03

I but I will make sure that management knows every freaking name spelled correctly of the person that stopped me, of the person that did the right thing. Yeah. You want them to be celebrated. And it's like, and but we gotta change how security awareness is being done. That's why I talked about situational worlds, because our industry has failed employees so horribly over the decades. It's like, but they still manage, and I'm not saying they we still manage to find a way to blame the users and the people when it's our failing. It's like employees and humans are not the weakest link, they're the least invested in. It's like you've all done this. This is exactly this is what I'm talking about. You've all done this. Y'all driven from home to work, work from home, home to work, work from home. And by the time you got into your driveway before you got out of the car, or by the time you got to the back door, you said to yourself, you just sat there and you're like, Did I stop at that light?

SPEAKER_02

Yeah.

SPEAKER_03

How did I get? You were in a two-ton vehicle and you were totally okay with your mind, your brain going on autopilot while your mind was preoccupied with processes and things that were going on. Because your brain, your co-pilot, it sees everything that you see. It filters what you look at, but it sees everything. Your brain hears everything that you could hear, but it filters what you listen to. And it controls your body because none of y'all have been thinking about breathing, but yet here we are. It's like that's your co-pilot. So when you went on that autopilot, your brain still saw the road, it still saw the lights, it still saw everything, it heard all the different surrounding noises, and it controlled the body, the foot pedals and the steering wheel. But if a child would have run out in the middle of the road, the better your situational awareness is, the quicker your co-pilot goes, uh uh, take the wheel, not me, mother, you know, and it lets you switch over to handle that situation. And so if we're okay with that, why don't we understand that our employees who are in an air conditioned environment Monday through Friday, at least eight hours a day, sitting at a desk going clickety, clickity, clickity, clicky. And we're our security policy states they can't go on autopilot. Our security policy is hinged on the fact that they are 100% vigilant and aware at all times while they're engaging in that work. Ridiculous and stupid and and and harmful to the company. Teach your employees to look for the child in the road. Acknowledge that they're going to go on autopilot. Help improve their situational awareness. So when they get an email from the CEO, they go, wait, hold on. I usually just click on it, I said, but I don't usually get an email from the CEO. That's like a child in the road. I'm gonna like, I need to stop and think about this for a second. That's what makes all the difference is letting them go into autopilot, but letting them be more situationally aware to switch out of it when they need to.

SPEAKER_02

Agreed. Okay, I'll buy soapbox now. No, I love the human element side of it. I really do. I wish we could go forever on this, but unfortunately we have to wrap it up. Well, we need to have you back, I think, Phil, right? Get him to come back and talk about that side. Yeah.

SPEAKER_03

Definitely. And I will definitely be available and I will try not to triple book you or quadruple book uh the next one. We appreciate that.

SPEAKER_01

Yeah, thanks for joining us. It's been great.

SPEAKER_02

Thank you for having me. Appreciate you.

SPEAKER_01

I appreciate you.

SPEAKER_02

We will see you hopefully at uh Hacker Summer Camp. I hope so.

SPEAKER_03

You better. It's like you'll both owe me hugs. We'll all be there.

SPEAKER_01

Yeah, thanks everyone for joining. Uh until next time, remember a community yields better resilience.

SPEAKER_00

This has been a Cybersec Media production. Cyber Hackcast is hosted by Michael Farnum and Philip Wiley. It's directed by Bill Brenner, produced by Lauren Andress, and edited by Ivan Basconcillo. Our music is by Kike Guts. The views and opinions expressed in this show are those of the speakers and do not necessarily reflect the views or positions of any entities they represent. This show is for informational purposes only and does not render or offer to render personalized advice. Subscribe now so you never miss an episode. You can find all our podcasts, articles, blogs, and conference talks on cybersecmedia.com. That's Cyberwithout the E. And follow Cybersec Media on LinkedIn, X, Instagram, Facebook, TikTok, and YouTube. You can keep up with CyberHackCon by following us on LinkedIn, X, Instagram, and Facebook at Cybersec Events. And you can learn more about the conference or buy tickets at cyberhackcon.com.