[00:01.230 --> 00:06.230] You are about to see SCADA and PLC Exploitation and Disclosure. [00:07.370 --> 00:10.910] I present to you Tiffany Rad, Teague Newman, and Mike Murray. [00:17.430 --> 00:18.390] Thank you very much. [00:18.390 --> 00:20.450] It's great to be back here at HOPE. [00:20.550 --> 00:24.030] This is my fourth HOPE I'm attending, and I think the third at which I'm presenting. [00:24.290 --> 00:26.770] And today we're doing a presentation different than the others I've done. [00:27.390 --> 00:29.670] I do security research and I'm also an attorney. [00:29.830 --> 00:37.190] What you're going to see today is just a technical type of presentation we're doing from a group of independent security researchers that have done stuff with SCADA. [00:37.510 --> 00:41.610] And Mike Murray is here to talk about what he's done with SCADA as well with his company, Mad Security. [00:42.270 --> 00:44.450] And you'll be seeing the three of us here. [00:44.590 --> 00:48.990] And then we're going to have Terry McCorkle and Billy Rios talking with you via Skype. [00:49.510 --> 00:50.930] So they'll be up online. [00:51.050 --> 00:52.130] They can hear everything that we're saying. [00:52.250 --> 00:56.050] We'll be able, if you ask us questions at the end, we'll repeat them and they'll be able to hear those. [00:56.570 --> 00:59.630] The purpose of this panel is to talk about the research that we did last year. [00:59.770 --> 01:01.670] We're going to show two videos. [01:02.170 --> 01:04.330] Mike's going to do an introduction to what he does with MAD. [01:04.450 --> 01:09.350] We're going to show a video that was done by 60 Minutes featuring mine and Teague's research. [01:09.590 --> 01:11.870] And then we're going to show a video that's actually from DerbyCon. [01:12.090 --> 01:14.650] And it's going to be Terry McCorkle and Billy Rios. [01:14.830 --> 01:18.510] And it's only a very short introduction to this is the type of work that we've done with SCADA. [01:19.890 --> 01:20.970] So let's start that. [01:53.310 --> 01:55.130] 60 Minutes Overtime. [01:56.770 --> 01:59.590] This is part of the actual Stuxnet code. [01:59.810 --> 02:00.510] That's correct. [02:01.130 --> 02:10.930] This week on 60 Minutes, Steve Croft reports on a mysterious computer virus known as Stuxnet, which was used to attack a nuclear facility in Iran. [02:10.930 --> 02:15.250] In fact, it turned out to be the most sophisticated cyber weapon ever invented. [02:15.610 --> 02:19.910] No one knows for sure who did it, but we do know where you can find the code. [02:20.450 --> 02:21.250] On the Internet. [02:22.050 --> 02:23.290] Producer Graham Messick. [02:23.530 --> 02:27.610] Right now, the Stuxnet code exists on some hacking sites. [02:27.610 --> 02:29.830] I was able to actually get a copy. [02:30.010 --> 02:32.890] It wasn't super easy, but it took me about a week. [02:33.050 --> 02:37.430] Unlike most computer viruses and worms, Stuxnet doesn't attack other computers. [02:37.630 --> 02:39.790] It attacks things that are in the physical world. [02:39.990 --> 02:42.830] Things like pipes and valves and electrical systems. [02:43.470 --> 02:47.530] The key is it attacks something called a PLC, a Programmable Logic Controller. [02:47.830 --> 02:50.490] They're in all sorts of industrial devices. [02:50.770 --> 02:52.150] They run conveyor belts. [02:52.270 --> 02:53.270] They run elevators. [02:53.410 --> 02:54.470] They run traffic lights. [02:54.470 --> 02:58.490] And if you can get control of one of these, you can do all sorts of mischief. [02:58.710 --> 03:05.390] There are many hackers now who are trying to emulate or copy Stuxnet's basic attack. [03:05.570 --> 03:10.310] So, what if someone wrote a worm or a virus that could affect correctional facilities? [03:10.490 --> 03:11.450] That was our big question. [03:11.750 --> 03:31.150] And one hacker, Tiffany Rad, just showed how she could hack in to the computer systems that control prison doors and open all the doors simultaneously, close all the doors simultaneously, trick the operators into thinking the doors were all locked and closed when they were really open. [03:31.690 --> 03:34.810] Your own creativity is the only limit on what you can do. [03:34.910 --> 03:38.650] As you can see, our PLC that we purchased on eBay and everything is up here on the table. [03:38.810 --> 03:45.030] They're not hackers and kids in the basement in their pajamas just doing malicious things. [03:45.030 --> 03:52.130] There's professionals who work for companies and look for vulnerabilities specifically to mitigate them, to fix them. [03:52.350 --> 03:54.410] Mr. Chairman, you had mentioned Stuxnet earlier. [03:54.590 --> 03:56.910] Sean McGurk was a really interesting guy. [03:57.090 --> 04:05.790] He was, until recently, at the Department of Homeland Security, he was in charge of protecting the nation's critical infrastructure from cyber attacks. [04:06.130 --> 04:08.890] We know there's a guy in Austin named Dylan Beresford. [04:09.370 --> 04:09.950] Do you know who he is? [04:09.950 --> 04:10.710] Yes, yes. [04:10.870 --> 04:12.450] We've communicated with Dylan on many occasions. [04:12.450 --> 04:14.230] He's shared a lot of his research with us. [04:14.410 --> 04:15.750] I don't know where Stuxnet came from. [04:15.830 --> 04:17.530] No, I didn't have anything to do with Stuxnet. [04:17.690 --> 04:18.890] But I just want to say one thing. [04:19.090 --> 04:21.950] Don't underestimate the power of the dark side. [04:22.210 --> 04:26.410] And there are a lot of people who are out there who are looking for ways to attack us. [04:26.690 --> 04:30.310] And we here are looking for ways to attack our adversaries. [04:30.870 --> 04:36.190] It's important to have this information out there so that we can make things safer for everyone. [04:36.190 --> 04:49.810] He's a very energetic and enthusiastic individual that found that, with actually no industrial control experience initially, that if he started looking and probing at these devices, he could identify vulnerabilities. [04:50.170 --> 04:51.610] He's just interested in this? [04:51.750 --> 04:52.070] Yes. [04:52.270 --> 04:54.590] It was an academic research project on his part. [04:54.650 --> 05:01.090] And he had the time and the capability to actually look at the devices and probe them and probe them continuously. [05:01.410 --> 05:04.210] I'm not here to freak anybody out, but I will tell you one thing. [05:04.210 --> 05:09.690] And what he said is if he were able to take over certain PLCs for 24 hours, he could cause explosions. [05:09.890 --> 05:12.330] It might cause pressure to build up inside of a pipe and cause an explosion. [05:12.470 --> 05:14.150] It goes back and it blows up an entire plant. [05:14.350 --> 05:19.970] This hack was done by a 29-year-old kid with a tattoo on his neck working from his living room. [05:20.090 --> 05:23.150] If we wanted to take it a step further, we could get to other PLCs. [05:23.710 --> 05:34.610] Dylan's hack of these PLCs was so extensive that the Department of Homeland Security and Siemens, the maker of the PLCs, asked him to hold back on his talk that he was about to give about this. [05:34.730 --> 05:40.330] And he voluntarily agreed to do so, to give Siemens more of a chance to patch these holes. [05:40.850 --> 05:46.330] Was there a moment that really made you step back and think, wow, this could be bad? [05:46.330 --> 05:53.210] In this story, the thing that scared me the most was the fact that this can be cheaply done, relatively cheaply done. [05:53.430 --> 06:00.530] A small country, a failed state, a terrorist group, if it had a couple of million dollars, could go out and hire people to wreak havoc. [06:01.690 --> 06:04.910] All right, let me tell you what was incorrect about this video. [06:05.230 --> 06:08.370] It's not going to take a couple of million dollars or a nation state. [06:08.630 --> 06:16.970] It took literally a bunch of us in the basement for $2,500 on our project doing it, doing this type of security research. [06:17.150 --> 06:18.250] We did another correction. [06:18.250 --> 06:19.750] It was not just me on the team. [06:19.930 --> 06:21.390] It was unfortunate that's the way it was portrayed. [06:21.970 --> 06:24.690] Teague Newman was also on this project. [06:24.850 --> 06:31.890] My father, John Straux, who's a physical security engineer, designer, he was also working on this with us, as well as Dora, the SCADA explorer. [06:32.090 --> 06:35.830] He was our exploit writer who didn't want his name released, so he's Dora. [06:36.670 --> 06:40.030] So those are the differences that we had from this video. [06:40.030 --> 06:42.310] But we wanted to give you an introduction to what Teague and I did. [06:42.570 --> 06:44.850] And now let me turn this over to Mike. [06:45.030 --> 06:46.610] And Mike will talk to you about the work that he did. [06:47.230 --> 06:49.630] Yeah, so I've got a very different experience in a lot of this. [06:50.150 --> 06:53.290] Tiffany and Teague and the other guys are all independent researchers. [06:53.310 --> 06:59.510] And I've done most of my research under the guise of other companies and for corporations. [06:59.850 --> 07:05.610] So I think from a disclosure perspective and a lot of those conversations, I have a very different perspective than everybody else on the panel. [07:06.390 --> 07:09.110] And you'll hear that perspective as we go through this. [07:09.250 --> 07:10.510] So that's a bit about me. [07:11.110 --> 07:18.830] I've been doing vulnerable research since the 90s and have played with SCADA and PLCs and not SCADA and not PLCs and everything in between. [07:18.830 --> 07:21.590] So hopefully I bring in a different perspective to that. [07:22.550 --> 07:22.990] Cool. [07:23.930 --> 07:29.170] Okay, so right now what we have is we have a video for Billy and Terry up here. [07:29.330 --> 07:31.810] This is just to give you kind of an intro of what they did. [07:32.110 --> 07:35.690] Their goal was to find 100 bugs in 100 days. [07:35.950 --> 07:40.770] And so we'll play a few minutes of their presentations that they did at DerbyCon last year. [07:40.890 --> 07:42.270] So you get the gist of that. [07:42.490 --> 07:45.490] And then we also have an article that I'll just throw up for a second. [07:46.850 --> 07:53.570] The guys actually had the Washington Post publish an article about one of the particular vulnerabilities that they found. [07:53.770 --> 07:56.030] And I'll let them tell you about that in a moment. [07:56.210 --> 07:57.810] But for now, I'll play their video. [08:05.810 --> 08:09.950] So we set out to find some bugs and we asked ourselves, how are we going to do this, right? [08:10.470 --> 08:13.890] Like, will we be able to just find bugs? [08:37.620 --> 08:38.420] All right. [08:38.540 --> 08:38.840] All right. [08:39.600 --> 08:40.580] Yeah, we'll refresh here. [08:40.680 --> 08:42.020] They found a lot of bugs. [08:42.220 --> 08:42.580] Okay. [08:42.720 --> 08:44.480] That was what he's getting to in the video. [08:45.120 --> 08:46.680] Basically, I'll summarize it. [08:46.680 --> 08:53.660] But what they did is Billy and Terry went out and they took a look at specifically pretty well HMI software. [08:54.380 --> 08:57.420] And everything they got was demo versions or open-source. [08:57.780 --> 09:00.540] And their goal was to find 100 bugs in 100 days. [09:00.880 --> 09:04.720] And so they started looking at all this through a couple of various fuzzing techniques. [09:05.180 --> 09:11.800] And you'll hear from them that they've actually found quite a bit more than 100 bugs. [09:11.940 --> 09:16.280] I'll actually flip it over to them right now and see if you can hear them via Skype. [09:17.320 --> 09:20.660] So, if you guys want to do like a mic check and then try and talk. [09:21.180 --> 09:21.580] Sure. [09:21.900 --> 09:22.280] Can you hear me again? [09:22.680 --> 09:22.860] Terry? [09:23.600 --> 09:25.120] I can hear you try again. [09:25.820 --> 09:26.260] Let's see if... [09:26.260 --> 09:26.540] Terry? [09:26.920 --> 09:27.000] Terry? [09:29.520 --> 09:30.960] It's like not going through. [09:33.620 --> 09:34.660] Terry's the bug. [09:34.900 --> 09:35.580] Can you guys... [09:35.580 --> 09:37.100] It's not coming through over there? [09:38.680 --> 09:39.600] Try again Terry. [09:41.740 --> 09:44.300] I can read locally but it's not coming over. [09:44.540 --> 09:45.740] Change the output on your Skype. [09:47.400 --> 09:47.980] Hang on... [09:47.980 --> 09:48.020] Hang on. [09:48.280 --> 09:48.640] Put the... [09:48.640 --> 09:50.180] On your speakers instead of your... [09:50.180 --> 09:51.720] Or on your headphone jack instead of your speakers. [09:53.080 --> 09:54.760] And that is where... [09:55.420 --> 10:05.660] Okay while they're doing that, let me tell you a little bit about one of the things we wanted to discuss here today is when you do this type of security research where there's some implications for like critical infrastructure, how you handle this information, [10:05.840 --> 10:06.920] how you do this disclosure. [10:07.220 --> 10:09.440] In particular when it's government assets. [10:09.500 --> 10:15.560] Like we were talking about things relating to nuclear power plants, data centers, and correctional facilities. [10:15.820 --> 10:26.460] The reason that we chose correctional facilities was that my father was one of the writers for sneakers and he does a lot of assessments of federal buildings. [10:26.460 --> 10:29.900] And he knew that PLCs were used for different kinds of things. [10:30.040 --> 10:34.820] Everything from climate control and data centers to jails, how the door is open with the PLCs. [10:35.120 --> 10:36.760] So we've kind of put this together. [10:36.760 --> 10:40.320] I was doing some research on Stuxnet at my university. [10:40.320 --> 10:44.440] I'm a professor, adjunct professor at the University of Southern Maine, the computer science department. [10:44.760 --> 10:48.760] And we were talking about, well, this Stuxnet exists. [10:49.020 --> 10:50.920] Will that affect correctional facilities? [10:51.080 --> 10:52.460] Will it affect nuclear power plants? [10:52.560 --> 10:55.020] And this was very early about April of last year. [10:55.200 --> 10:57.980] Then I found out that Dylan Beresford was doing similar research. [10:58.000 --> 11:04.380] And we found out by reading an article in the newspaper that DHS had asked Dylan, please don't present about your research. [11:04.820 --> 11:06.640] He was going to present at Take Down Con. [11:06.640 --> 11:13.260] And they asked him to hold off on that presentation until they were ready for him to release this information publicly. [11:13.520 --> 11:16.660] So that's one of the ways that Dylan had to handle the disclosure. [11:16.880 --> 11:18.860] I mean, how do you tell the public about your research? [11:19.800 --> 11:20.860] I think we're...okay. [11:21.100 --> 11:21.800] I think we're ready. [11:21.900 --> 11:24.620] Let's let Terry and Billy talk about their work. [11:24.620 --> 11:28.000] And then we'll get back to the discussion of how to disclose this type of information. [11:30.080 --> 11:30.900] Can you hear me? [11:31.440 --> 11:32.900] Yeah, there we go. [11:33.120 --> 11:33.500] All right. [11:36.720 --> 11:37.280] Great. [11:37.620 --> 11:39.120] So, this is Terry McCorkle. [11:39.320 --> 11:44.540] Basically, like Teg was saying, we set out to find some bugs. [11:46.380 --> 11:48.360] Essentially, we had a goal of 100. [11:48.360 --> 11:54.640] And I think the date reported over 1,000 to DHS or ICS CERT. [11:55.300 --> 12:01.760] And the main reason we went through ICS CERT for our disclosure process was because dealing with offenders is pretty difficult. [12:01.820 --> 12:05.120] And, you know, you never know what kind of response you're going to get. [12:05.320 --> 12:10.820] So, we went through ICS CERT, let them handle all of the disclosing of offenders. [12:11.160 --> 12:17.820] And then we were on the back end to help validate any patches or anything like that that they went through. [12:19.760 --> 12:24.480] So, and I'm going to let Billy speak a little bit about the Washington Post article that dropped yesterday. [12:26.860 --> 12:27.520] Hey, everyone. [12:27.620 --> 12:28.020] Can you hear me? [12:28.100 --> 12:28.600] This is Billy. [12:30.340 --> 12:30.740] Perfect. [12:31.940 --> 12:38.020] Yeah, about the Washington Post article, it details a vulnerability that we found in the Tritium Niagara framework. [12:38.380 --> 12:40.200] And it's a pretty bad vulnerability. [12:40.400 --> 12:43.720] I don't want to get into the technical details because this is a disclosure panel. [12:43.880 --> 12:53.780] But, you know, we were kind of shocked in that when we reached out to DHS and we reached out to the vendor, they basically didn't want to accept responsibility for fixing the bug, right? [12:53.780 --> 13:02.540] So, we tried to present a case to let them know what the risks were and how prevalent these systems were on facing the Internet. [13:03.060 --> 13:06.380] And even after that, you know, it seems like they really didn't care. [13:06.860 --> 13:10.120] And this wasn't the first time we had encountered such attitudes. [13:10.760 --> 13:16.460] You know, it's like they have this culture within the industrial control systems world where a lot of times they just say, Hey, you know what? [13:16.520 --> 13:17.320] That's not my problem. [13:17.440 --> 13:18.420] That's a customer problem. [13:19.200 --> 13:20.740] They didn't configure it properly. [13:20.780 --> 13:25.540] Or we provide guidance that prevents, you know, exploitations of these types of bugs. [13:25.980 --> 13:30.380] And they kind of pushed the responsibility onto the customer to secure against these poor designs. [13:30.900 --> 13:34.640] So, you know, after many, many months, you know, we decided enough is enough. [13:34.640 --> 13:38.120] So, we decided to, you know, go public with some of this information. [13:38.120 --> 13:41.920] And then that's when we see the Washington Post article drop. [13:41.920 --> 13:46.440] So, that's kind of our perspective on the whole disclosure process and industrial control systems. [13:49.940 --> 14:05.120] One interesting thing that I'd like to point out is that when you look across the board here, all of us and, you know, Dylan who couldn't be here, what it comes down to is one of the original things that the vendors were saying is that it would take a nation state to do this. [14:05.360 --> 14:13.900] And I think that, you know, realistically, I don't know if it was Dylan or Tiffany and I's group, but we probably spent the most money. [14:14.260 --> 14:15.840] And we're talking a few thousand dollars. [14:16.760 --> 14:18.900] So, like, Terry and Billy. [14:19.340 --> 14:21.840] Guys, did you even have to spend anything? [14:23.000 --> 14:23.480] No. [14:23.880 --> 14:24.180] Yeah. [14:24.520 --> 14:24.780] Okay. [14:24.820 --> 14:27.000] So, I asked them if they had to spend anything at all. [14:28.060 --> 14:32.960] No, we actually didn't need to spend anything for the research we did. [14:32.960 --> 14:35.400] I think the biggest thing was the time. [14:36.060 --> 14:41.320] And, I mean, we're two married guys with families and day jobs. [14:41.860 --> 14:45.100] And we just found them on nights and weekends to do this. [14:46.900 --> 14:47.400] Yeah. [14:47.400 --> 14:49.100] I just want to echo what Terry said. [14:49.560 --> 14:56.440] In fact, we made it a point not to take any sponsorship, not to take any work time to do this research. [14:56.880 --> 15:00.660] Because, at the end of the day, we wanted people to know that, like, anyone can do this. [15:00.800 --> 15:02.520] Literally, anyone can do this, right? [15:03.060 --> 15:05.020] They don't have to have any kind of sponsorship whatsoever. [15:05.040 --> 15:06.460] They don't have to have any kind of money. [15:07.040 --> 15:10.000] All they have to have is a willingness and some time to look into this stuff. [15:10.300 --> 15:12.100] And they'll basically find what we found. [15:12.820 --> 15:15.360] The scary thing, though, is if you actually did put some money to it. [15:15.360 --> 15:15.700] Yeah. [15:15.700 --> 15:19.720] You know, I mean, we see the results of stuff like this. [15:19.820 --> 15:22.020] And I've worked on projects that actually did have funding. [15:22.340 --> 15:25.980] And, you know, that were, in some cases, vendor-sponsored. [15:26.080 --> 15:27.320] In some cases, other people-sponsored. [15:27.400 --> 15:35.320] And when you actually put some money and some real-time and some, you know, we're not just screwing around with this in our basement in the off-hours, it's scary. [15:35.500 --> 15:36.640] It gets scary real fast. [15:37.080 --> 15:38.160] Yeah, I can imagine. [15:39.540 --> 15:44.120] Yeah, the work that we did, me and Teague, it was, we did this after hours. [15:44.560 --> 15:49.500] And I have to say, too, that some of us work for large companies, including, like, Terry and Billy. [15:49.720 --> 15:52.500] This is not at all the reflection of our work of our employers. [15:52.500 --> 15:53.860] We did this on our own. [15:54.980 --> 15:57.400] So, it's something that didn't take a lot of time to do. [15:57.580 --> 15:59.840] And I want to ask this question, actually, to Billy and Terry. [16:00.020 --> 16:01.580] And Teague, and I'll answer how we did it, too. [16:01.640 --> 16:02.820] And maybe, Mike, you can talk about it. [16:02.880 --> 16:07.600] But what was your experience, Terry and Billy, with dealing with the ICS group? [16:08.640 --> 16:10.660] Which stands for Industrial Control Systems. [16:12.140 --> 16:13.620] Yeah, I can speak to that. [16:13.780 --> 16:20.660] And so, we pushed all of our bugs through the Industrial Control Systems CERT team, which is an arm of the DHS, right? [16:20.740 --> 16:22.000] The Department of Homeland Security. [16:22.400 --> 16:28.040] And the reason we did that is because the control systems world is still very old school, you know? [16:28.220 --> 16:39.800] And the last thing we wanted to do was, as independent security researchers, we didn't want to send an email to these vendors from our Gmail account and get a response that basically says, hey, thanks a lot. [16:39.920 --> 16:41.040] You better lawyer up, right? [16:41.160 --> 16:42.280] Like, that's the last thing we wanted. [16:43.080 --> 16:46.420] So, what we decided to do is just route everything through DHS. [16:46.900 --> 16:51.940] And that way, we have this kind of like a neutral third party that can do the interfacing for the vendors for us. [16:52.060 --> 16:55.100] So, in fact, when we first started, we said, hey, you know what? [16:55.100 --> 16:57.160] We're not talking directly to any vendors. [16:57.560 --> 17:00.360] If you want to talk to us, you need to talk to DHS first. [17:00.620 --> 17:03.240] And DHS will get the communications to us. [17:04.280 --> 17:11.860] And that gives us a little bit of a buffer so we can figure out, you know, which companies are security researcher-friendly and which ones are not, right? [17:11.860 --> 17:15.960] And the second piece to that is following up on this stuff. [17:16.060 --> 17:23.180] When you have a thousand different bugs that spread across hundreds of different vendors, following up and keeping track of this stuff, it's actually a large effort. [17:23.520 --> 17:25.100] And we didn't want to do that, right? [17:25.180 --> 17:33.220] The last thing we want to do is spend our weekends and nights managing spreadsheets about who we need to follow up with and whether or not someone's responded or whether they're going to issue a patch. [17:33.520 --> 17:38.040] And so we kind of threw all that work at DHS and said, hey, you keep track of this stuff. [17:38.040 --> 17:39.640] We're not going to keep track of this stuff, right? [17:39.700 --> 17:42.140] I mean, we keep track of the ones that we find interesting. [17:42.640 --> 17:47.640] But across a thousand bugs and a hundred different vendors, it's just really difficult, right? [17:47.680 --> 17:49.080] We didn't want to get into that. [17:49.240 --> 17:53.520] So I think as far as that role goes, they did a really good job, you know? [17:54.160 --> 18:01.760] I do think they had their hands tied in a couple instances, you know, where like the vendor is not responsive or they don't want to accept responsibility for the bug. [18:02.120 --> 18:03.800] You know, what do you do then, right? [18:03.920 --> 18:06.880] And I don't know if we've entirely figured that out yet. [18:06.880 --> 18:13.540] But, you know, the initial, I think, use for DHS and ICS cert, I think it was met wonderfully. [18:13.880 --> 18:15.660] You know, they managed all the tracking. [18:16.020 --> 18:19.100] They did all the bug pinging, you know, every couple of weeks or whatever. [18:19.400 --> 18:20.440] They gave us status. [18:20.640 --> 18:21.920] And that was pretty good. [18:21.940 --> 18:22.880] I really enjoyed that. [18:23.760 --> 18:29.200] I'd like to point out one thing also with regards to Terry and Billy's work. [18:29.200 --> 18:36.240] Some of you may have heard the term that's been freshly coined because of this, forever day bugs. [18:37.820 --> 18:44.420] Hey, Billy, Terry, why don't you guys, why don't you guys pick that and just describe that little scenario right there with regards to those? [18:45.360 --> 18:45.940] Sure. [18:46.240 --> 18:50.660] So, forever day bug actually was originally coined... [18:50.660 --> 18:57.000] The first time we heard it, we were actually out smoking cigars on a balcony at the S4 conference in Miami. [18:57.000 --> 19:05.100] And it was, it was actually Reed Whiteman that said, he said these forever day bugs, right? [19:05.280 --> 19:15.760] And so when I had the opportunity talking to somebody, basically, like, I started using that term because it really, it kind of sums up what happens. [19:15.760 --> 19:17.960] A lot of these vendors are never going to fix these issues. [19:18.520 --> 19:26.640] And they'll send out a customer advisory that's literally like, hey, your application is broken and you're never going to have a patch for it. [19:27.740 --> 19:29.220] And I don't know. [19:29.360 --> 19:42.920] I mean, it's frustrating for a researcher that's trying to, you know, get things fixed, to have them come back with that kind of response and basically put it on the customer saying, you know, you're always going to have this issue. [19:44.000 --> 19:46.420] We, Teague and I handled this in a little bit of a different way. [19:46.540 --> 19:48.800] We didn't go directly through ICS cert. [19:49.560 --> 19:53.020] That reason being is what we were looking at were correctional facilities. [19:53.320 --> 19:57.700] So we reached out to the Federal Bureau of Prisons, didn't get much of a response back at that time. [19:58.060 --> 20:01.720] So we talked to some contacts, Teague and I both were in the Washington DC area. [20:02.160 --> 20:04.880] And we wanted to tell the U.S. government about this. [20:04.980 --> 20:14.000] This is one of these things where if we didn't, and we felt like if it came out in the press in like the wrong light, and the government didn't know about it, we'd have some problems. [20:14.500 --> 20:17.720] So a meeting was set up in Washington DC at an agency. [20:17.720 --> 20:19.380] And we said, hey, this is what we've done. [20:19.960 --> 20:21.380] We're going to go public with it. [20:21.500 --> 20:22.400] Is that okay? [20:23.180 --> 20:29.140] It was really one of these things where all of us walked into the meeting thinking, okay, if they're going to, if they're going to tell us, we're not ready. [20:29.400 --> 20:32.300] We knew that it happened to Dylan about two months earlier. [20:32.540 --> 20:33.500] We were going to wait. [20:34.220 --> 20:35.960] But they actually said, you know what? [20:36.160 --> 20:37.520] Go ahead and talk about it. [20:38.800 --> 20:45.340] Which gave us a lot of like relief that we could go to DEFCON and not feel like we were going to get a cease and desist order. [20:45.560 --> 20:49.020] It was like a little bit in the back of our minds, but we're like, all right, I think that'll be fine. [20:49.720 --> 20:53.340] I wonder if you can talk about, Mike, how the government handles some of the work that you do. [20:53.340 --> 20:57.060] Actually, before that, I just have to say I'm jealous of all of you guys. [20:57.660 --> 21:01.640] Because the first time I reported one of these bugs to a vendor was 2004. [21:02.400 --> 21:05.100] And so I'm kind of in some ways the old guy of the group. [21:05.400 --> 21:09.980] But things like ICS cert and stuff like that, we didn't have any of that. [21:10.060 --> 21:16.640] And so I was dealing with these vendors and somebody, it was either Billy or Terry earlier, mentioned something about the attitude you get from a lot of these vendors. [21:17.160 --> 21:22.680] And I know of a bunch of quote unquote for everyday bugs that have existed since 2004, 2005. [21:22.680 --> 21:26.980] That I think me and the vendor are the only ones that know about today, right? [21:27.320 --> 21:30.000] And they have no intention of ever fixing it and never will. [21:30.460 --> 21:36.120] And to the point that was made earlier, I'm bound by the NDAs of my companies at the time. [21:36.460 --> 21:37.660] I can't talk about them. [21:38.220 --> 21:39.600] And the vendor never will. [21:39.800 --> 21:41.980] So nobody's going to know about it until somebody gets owned. [21:42.380 --> 21:53.240] And their attitudes back then, I mean, people are at least opening up, you know, the 60 Minutes report, the Wall Street Journal coverage, the Washington Post coverage, everybody's covering it now. [21:55.040 --> 22:01.160] Back then, these guys, their attitude was just, hey, you know, if you're putting this thing on the Internet, you're an idiot. [22:02.640 --> 22:06.660] And while I might agree with that, it doesn't stop customers from doing it. [22:07.120 --> 22:07.240] Yeah. [22:09.060 --> 22:22.620] One of the interesting things that Teague and I found after we did our research is at conferences, or usually, shall I say, after conferences as we're on our way out, someone will stop us and say, hey, I can't tell you who I am or who I work for, but I just want to tell you, [22:22.720 --> 22:27.500] I'm really glad some independent security researchers such as your group, you don't have NDAs. [22:27.500 --> 22:32.460] You can go out and tell people about this, warn customers, consumers. [22:32.920 --> 22:37.260] Because he said, I've known about this for so many years, just like Mike's saying, and I couldn't tell anyone. [22:37.760 --> 22:41.960] Now, we get into this interesting debate about, you know, is security through obscurity working? [22:41.960 --> 22:47.480] I believe that all of us talking here on this panel would say it's not working for ICS. [22:47.480 --> 22:56.180] And in fact, when you have some things such as very important critical infrastructure up, it's more important, we believe, to get the word out, these are vulnerabilities. [22:56.680 --> 23:08.660] Because from what we found, at least in the correctional institutes that we talked to, to some government agencies who run these and manage these, a lot of them sort of had an idea what SCADA was, didn't know it was in their facilities. [23:08.940 --> 23:19.160] And in particular, the people that were working in the correctional facilities, when we got a tour of one of them in the United States, they were checking email and Twitter from the control computer for the PLCs. [23:19.960 --> 23:21.520] That's not a big no-no, yeah. [23:21.760 --> 23:29.440] Those types of things are easy to fix in the sense that you tell people, that computer, there's a reason that this acceptable use policy exists. [23:29.760 --> 23:30.400] Follow it. [23:30.560 --> 23:33.960] Or, you can have all the prisoners escape and then you've got a real big problem. [23:34.340 --> 23:35.300] They got that. [23:35.560 --> 23:44.140] So, telling them, you have these vulnerabilities, really was rewarding for us as a group, for the research we did, that it looks like some changes are being made. [23:44.140 --> 23:46.020] You know, it finally can change the culture. [23:46.180 --> 23:47.760] I mean, a war story for a second. [23:48.480 --> 23:53.620] To give you guys an idea of how ridiculous some of this stuff is, and especially in the control systems world. [23:53.680 --> 23:57.680] I mean, you guys kind of made a funny noise when they talked about checking email. [23:57.840 --> 24:00.160] But let me give you a story from 2005. [24:00.800 --> 24:04.860] I was the head of vulnerability research for a scanning vendor, and we did a lot of stuff. [24:05.040 --> 24:12.240] We would drop the scanning tools into environments and just sort of, you know, set it and forget it, and start knocking stuff over. [24:12.580 --> 24:21.880] And I went to a major vendor and who was dealing with, who had a control system in a major hospital that controlled a bunch of medical devices. [24:22.100 --> 24:23.760] And we were just destroying these things. [24:23.880 --> 24:28.340] Like, you know, you turn on the scanning tool and all of these medical devices would just shut off. [24:28.420 --> 24:29.800] We had no idea what was going on. [24:29.800 --> 24:36.840] I'm sitting with the head architect of this, and he said, you don't connect to port 10,000, do you? [24:37.760 --> 24:39.440] And I said, yeah. [24:39.980 --> 24:42.760] And he said, well, you can't do that. [24:44.160 --> 24:45.320] And I said, why not? [24:45.620 --> 24:47.500] And he said, that's the shutdown port. [24:50.670 --> 24:52.990] I kid you not, I couldn't make this up. [24:53.150 --> 24:57.550] If you opened a TCP connection to port 10,000, the entire system shut down. [24:58.990 --> 25:00.870] That's the kind of stuff that these guys were doing. [25:00.870 --> 25:02.390] It's like, why would you ever do that? [25:03.070 --> 25:08.070] And so this kind of research comes out actually changes the culture a whole lot. [25:08.150 --> 25:09.630] They can't be that stupid anymore. [25:09.890 --> 25:11.530] It's not really stopping them, but that's not the point. [25:11.810 --> 25:11.890] Yeah. [25:12.650 --> 25:13.810] They can try, though. [25:14.290 --> 25:15.150] Yeah, exactly. [25:15.770 --> 25:27.650] You know what's interesting, too, is part of Tiffany and I's research, you know, after Stuxnet, everyone pretty well heard that, you know, SCADA, ICS, power plants, water treatment, et cetera, et cetera. [25:27.650 --> 25:32.750] And one of our things was we wanted to see where else it was that people probably wouldn't expect it. [25:32.810 --> 25:34.230] And we ended up taking a look at prisons. [25:35.370 --> 25:42.950] I know in the video I was going to show you of Terry and Billy's, Terry talks about a lot of things like, all right, Budweiser plant uses it. [25:43.410 --> 25:46.030] So, I mean, this stuff is literally everywhere. [25:46.230 --> 25:47.170] It's in manufacturing. [25:47.430 --> 25:47.950] It's in transportation. [25:48.550 --> 25:48.930] Here in New York City. [25:49.490 --> 25:49.610] Yeah. [25:50.750 --> 25:51.630] It's everywhere. [25:52.430 --> 25:53.310] Amusement parks. [25:53.310 --> 26:00.210] I mean, there was a lot of places, you know, that I don't think people would have guessed that it was initially. [26:00.810 --> 26:09.590] So, that was kind of an interesting thing to see over the course of the past year, all the different places that it starts to become public where it actually is located, too. [26:09.970 --> 26:10.170] So... [26:10.170 --> 26:19.150] I think also, like, one of the things that a lot of normal companies don't consider themselves to have these systems, right? [26:19.150 --> 26:23.210] And one of the things that I point out is data centers. [26:23.710 --> 26:28.590] So, you have HVAC and you have building management and a lot of it. [26:28.870 --> 26:34.530] And these systems and the systems made by these same manufacturers run those. [26:35.430 --> 26:42.010] So, if that goes down, think about the ramifications without having your data center for, you know, a while. [26:42.610 --> 26:43.130] All right? [26:43.210 --> 26:45.890] If you don't have cooling, you can't run your machine. [26:47.210 --> 26:57.170] So, it's one of the things that I always try to hit on because that way people understand that this isn't just, you know, conveyor belt systems or some automated system there. [26:57.410 --> 26:59.730] These systems are running like building management. [27:00.530 --> 27:02.790] And it's pretty critical. [27:03.870 --> 27:04.350] Yeah. [27:04.910 --> 27:05.390] Absolutely. [27:05.730 --> 27:12.210] And one of the things, if you take a look at Terry and Billy's presentation, Terry talks about that in there. [27:12.210 --> 27:13.590] What was it, Terry? [27:13.730 --> 27:20.530] The average time to shut down once a data center loses cooling is like three minutes and nine seconds. [27:20.710 --> 27:21.490] Does that sound right? [27:21.950 --> 27:22.190] Yeah. [27:22.270 --> 27:24.510] There was a report that I read that had that in there. [27:24.650 --> 27:29.490] And I've actually been in a data center where their cooling shut down. [27:29.890 --> 27:34.530] And you see people running around frantically trying to turn off machines before they overheat. [27:34.530 --> 27:37.390] And it's an interesting thing to watch. [27:37.970 --> 27:38.490] So... [27:38.490 --> 27:41.110] And that wasn't related to my research at all. [27:41.250 --> 27:42.030] I have to clarify that. [27:42.150 --> 27:43.130] Like, I didn't shut it down. [27:43.490 --> 27:44.010] But... [27:45.950 --> 27:46.850] So, yeah. [27:47.050 --> 27:47.550] Just... [27:47.550 --> 27:50.290] It's something to keep in mind if... [27:50.290 --> 27:50.790] For those... [27:50.790 --> 27:53.030] For the people that are like, I don't have these. [27:53.450 --> 27:56.870] I think most companies have these in their environment. [27:57.050 --> 27:58.110] And they just don't realize it. [27:59.370 --> 28:07.550] Well, last summer, all of us did this type of independent security research about 10 to 12 months ago when a lot of it became public for the first time. [28:07.730 --> 28:09.010] I wanted to ask... [28:09.010 --> 28:11.550] And I'll talk about how our research may have changed some things. [28:11.690 --> 28:16.930] But, Terry and Billy, did you find that some changes have been made as a result of your research? [28:17.090 --> 28:18.970] Like, either with the vendors or the government? [28:19.230 --> 28:20.930] I mean, do you have any comments about that? [28:23.250 --> 28:24.510] Yeah, I can take that. [28:24.790 --> 28:26.230] There are some changes, actually. [28:26.950 --> 28:34.970] There are some policy changes from various government agencies, some of which will actually be made public, I think, here in the next couple of weeks, which is awesome. [28:35.550 --> 28:45.990] Some of the vendors that we spoke to, we could definitely see some changes in attitude, especially after, you know, they have their dirty laundry aired in a public, you know, in the media or somewhere, something like that. [28:46.230 --> 28:59.570] But I think one of the things that we're most proud of is, when you take a look at the number of researchers that are looking at industrial control systems, HMI, and the software that's associated with that, it's just dramatically increased over the last year. [28:59.810 --> 29:06.270] You know, I know when I was looking at the ICS CERT monthly monitor, and they have recognition for various researchers. [29:06.930 --> 29:09.430] You know, at the time, there was like five people, you know. [29:09.930 --> 29:14.330] And now, if you look at it, it's like 30 people, or 40 people, or sometimes 50 people. [29:14.330 --> 29:16.730] And so, and I'm happy to see that, you know. [29:16.890 --> 29:24.730] I hope more people continue to shine a light on this whole industry, you know, and get them to where they need to be, because they're light years behind modern software security. [29:25.270 --> 29:29.770] You know, they're light years behind modern, you know, security practices that you see in other places. [29:29.890 --> 29:32.750] So, we've still got a long ways to go, you know. [29:32.870 --> 29:34.270] But I think we're making some progress. [29:34.310 --> 29:36.130] I just hope it's fast enough. [29:37.030 --> 29:41.490] I want to speak for a second on behalf of Dylan, who unfortunately couldn't make it. [29:42.810 --> 29:50.350] I know I was speaking on the phone with him probably about two weeks ago now, and we were just discussing some exploits in general. [29:50.870 --> 29:55.850] And I know that he'd said a lot of the stuff he found last year still hasn't been patched. [29:56.050 --> 30:05.390] And actually, if you check his Twitter feed, I believe, like, two days ago, he just released a whole bunch of Metasploit modules for some of the stuff that he did last year. [30:05.390 --> 30:10.230] I think maybe potentially to urge the patches along a bit. [30:10.770 --> 30:13.330] Yeah, I was going to say, some very good pen-testing tools have come out. [30:13.410 --> 30:19.810] So, if you're in that industry doing penetration testing and doing large facility tests, you've got a lot more tools now to do it. [30:19.890 --> 30:27.090] So, we're from the perspective that these types of modules in Metasploit and whatnot do help us do our jobs to make things safer. [30:27.250 --> 30:33.730] So, when people do some of these releases, we, in turn, are able to turn their tools and make things better. [30:33.730 --> 30:43.550] And what we found after our research is that the correctional facilities have actually upped some of their funding that they have for information technology. [30:43.990 --> 30:48.310] One of the things that Teague looked at with the networks is how things were connected within the prison. [30:48.430 --> 30:54.010] Like, you should not be able to get from the commissary, like, on computers there, like for ordering food, into the PLC computers. [30:54.030 --> 30:54.870] We did see that. [30:54.870 --> 30:57.450] So, that shouldn't be connected. [30:57.750 --> 31:00.350] So, they're looking right now at how things are set up with IT. [31:00.610 --> 31:05.210] And they're doing more of a convergence, too, with physical security and also with electronic and computer security. [31:05.390 --> 31:10.050] That these... you can't just say the physical security is something else and computer security is here. [31:10.210 --> 31:14.970] They're together, especially when you have, you know, a closed-circuit TV that's on the same type of system. [31:14.970 --> 31:19.490] So, they're really looking at more of a holistic view of how these facilities are set up. [31:19.610 --> 31:24.510] So, we're glad that a lot of states, including the one where we did our tour, were able to get some more funding. [31:24.690 --> 31:31.950] And we're not... we were never suggesting rip out the PLCs, because we know that right now the vendors don't really have a lot of fixes for them. [31:32.350 --> 31:35.230] From what we've heard where they're working on them, but they're not quite there yet. [31:35.230 --> 31:43.130] But until then, physical security might be... and training might be the way to kind of patch in somewhat of the vulnerabilities we have now. [31:43.490 --> 31:48.790] Let your people know, the guards who are working in the control booth, what... you know, don't check your email on that computer ever. [31:49.070 --> 31:50.030] Don't bring in USB. [31:50.410 --> 31:51.570] You know, just don't do it. [31:51.950 --> 31:54.110] And then also, the physical security. [31:54.290 --> 31:58.290] We personally and somewhat actually shouldn't have been in that control center either. [31:58.290 --> 32:00.530] We were just security researchers on a tour. [32:00.530 --> 32:05.550] So, locking down where you have, like, switches for trains and transit in, like, New York City. [32:05.750 --> 32:09.890] Knowing where these are and making sure you have better physical security will kind of patch some of that. [32:09.990 --> 32:13.510] Or, not patch it, but kind of make the gaps kind of come closer together. [32:13.570 --> 32:17.270] The interesting thing, just generically, with what we saw is... [32:17.270 --> 32:21.630] One of the things that we did see was some extremely poor network segmentation. [32:21.830 --> 32:25.730] And, you know, obviously, you can always throw money at a problem to fix it. [32:25.810 --> 32:28.870] But sometimes, you can start to do other things that don't cost a lot. [32:28.870 --> 32:34.690] Like, you know, restricting physical access to the particular machine that controls your jail cell doors. [32:34.950 --> 32:42.730] It's probably a lot cheaper than hiring someone in, you know, to redesign the entire network and segment it properly. [32:42.950 --> 32:45.610] And probably buy new routing gear and who knows, you know. [32:45.830 --> 32:47.890] But there's... there are... [32:47.890 --> 32:50.330] It's the typical layered defense is the answer. [32:50.530 --> 32:54.050] And you just implement as much as you can when you have the opportunity. [32:54.050 --> 32:56.570] Yeah, sometimes it's actually... it's the easy stuff. [32:56.750 --> 32:59.210] It's the physical security stuff that's actually the simplest. [32:59.410 --> 33:02.990] I mean, there was a story two years ago now about a kid. [33:03.090 --> 33:04.950] And I don't remember the exact details of it. [33:05.070 --> 33:05.990] You'll have to Google it. [33:06.110 --> 33:10.150] But some kid, I think it was in Denmark, who crashed a light rail train. [33:10.310 --> 33:11.290] Did you guys hear this story? [33:11.490 --> 33:18.970] Crashed a light rail train in his city by reprogramming his VCR remote outside his house. [33:18.970 --> 33:23.290] The light rail train had an infrared interface for signaling. [33:23.790 --> 33:27.750] And I mean, literally, this kid's like, oh, look, I can play with my VCR remote and I can do stuff. [33:27.870 --> 33:32.890] And eventually figured out how to change the switch with his VCR, like his TV remote and crash this train. [33:33.050 --> 33:34.370] It was bizarre. [33:34.650 --> 33:39.470] But to that point, I mean, I was on a TRB panel about six months ago. [33:39.530 --> 33:44.890] And to the point about the research finally getting out there, people are starting to actually understand that this is a problem. [33:44.890 --> 33:51.150] You know, when kids are crashing trains with television remotes, like, oh, or we can open all the doors in the prison or whatever. [33:51.350 --> 33:53.750] Like, oh, maybe I really shouldn't check my email. [33:54.010 --> 33:56.310] And that's starting to get some play. [33:56.310 --> 34:00.150] And we can actually start to get some leverage and hopefully make some of those changes. [34:00.690 --> 34:01.470] Yeah, absolutely. [34:03.370 --> 34:05.350] Do you have any other comments, Terry and Billy, about that? [34:05.410 --> 34:07.090] And then we'll open this up to questions. [34:08.390 --> 34:09.990] Yeah, I do have one last thing. [34:10.490 --> 34:17.490] It's probably the one thing that I'm probably the most disappointed about when it comes to, like, the vulnerability disclosure and stuff that we did. [34:17.650 --> 34:21.070] And, you know, we did push everything through DHS and the vendors were notified. [34:21.070 --> 34:26.850] But to us, it always seemed like the people that really needed to fix this kind of stuff, a.k.a. [34:26.870 --> 34:36.790] the implementers, the buildings that had this stuff in their buildings, you know, the PLC, the guys who actually implement or have a PLC running somewhere, they were, like, the last to know, right? [34:36.970 --> 34:40.830] So the government knew, you know, the vendors definitely knew. [34:41.050 --> 34:46.210] And then it became this argument as to, like, when and how, you know, do you, like, tell the public? [34:46.750 --> 34:50.190] And it's like, well, honestly, those guys should probably be the first to know, right? [34:50.390 --> 34:53.830] Because they're the ones that are running this and they're the ones that are actually accepting all this risk. [34:54.450 --> 34:57.510] But it always seems like they're the last one to know, you know? [34:57.910 --> 35:04.530] And I hope, like, in the near future, we can solve that problem where the people that actually really need to know this stuff are the first to know, right? [35:04.590 --> 35:09.750] So they can take the right steps to protect themselves or protect whatever it is that they're running, you know? [35:11.650 --> 35:12.150] All right. [35:12.350 --> 35:12.670] Great. [35:12.830 --> 35:13.130] Okay. [35:13.170 --> 35:14.370] We'll take some questions. [35:14.430 --> 35:16.950] And if you can't hear Terry and Billy, we'll repeat them for you. [35:17.190 --> 35:19.550] Actually, we'll repeat them to make sure everyone does hear them. [35:19.550 --> 35:27.930] Some years ago, I did an assessment of a badge access control system and discovered that it was listening on 22 ports. [35:29.290 --> 35:33.550] Its root password was R00T documented in the manual. [35:33.910 --> 35:42.770] The firm advised that the dial-up modem that was attached to the computer always be on for better maintainability of the system. [35:42.990 --> 35:52.690] And this was in use at all the British airports, at prisons, at consulates, at the Library of Congress, at the U.S. House of Representatives, Senate. [35:54.290 --> 36:01.310] And I started calling inspector generals, inspectors general of various agencies, and got them to recognize the problem. [36:01.450 --> 36:03.850] But the vendor, of course, was in great denial. [36:04.210 --> 36:05.190] It was used at prisons. [36:05.230 --> 36:08.270] And, of course, you could open all the prison doors using this thing. [36:08.810 --> 36:09.910] Elevate your badge. [36:09.910 --> 36:14.770] You could create events that were not logged because of a misplaced write. [36:14.930 --> 36:15.050] Oh! [36:15.370 --> 36:16.770] The system was open-source. [36:17.030 --> 36:20.410] Not for any political or technical reason. [36:20.570 --> 36:24.410] But just because they wanted to ifdef in features into the system. [36:24.930 --> 36:30.730] So there was, you know, ifdef embassy, ifdef Heathrow, ifdef names of customers in their code. [36:30.730 --> 36:39.430] So we could actually find bugs in the system, including misplaced write, curly brackets, which prevented certain events from being logged. [36:40.510 --> 36:42.170] You could create stealth badges. [36:42.370 --> 36:43.470] It was really just terrible. [36:43.810 --> 36:45.110] Ended up in the New York Times. [36:45.330 --> 36:46.990] But the vendor was in complete denial. [36:49.190 --> 36:50.350] That was a great story. [36:50.370 --> 36:53.190] But I don't think you saw a surprise on any of the faces up here. [36:54.030 --> 36:55.070] There's a reason for that. [36:55.110 --> 36:55.590] No, I saw amusement. [36:56.410 --> 36:57.310] It is amusing. [36:57.430 --> 37:03.170] And that is a tough thing is when you're a security researcher, for any of you out there who are doing this work, how do you, who do you tell? [37:03.950 --> 37:07.250] There's some security researchers that use ICS-CERT. [37:07.550 --> 37:19.930] Then there are some security researchers in this that, independent security researchers we've met who've said, they've said, well, one of the, what kind of made them annoyed someone with ICS-CERT is that there was something that was a bug, but they called it a feature. [37:20.590 --> 37:24.050] And it was something that they're like, they're not going to release that as a warning. [37:24.050 --> 37:27.510] Oh, I forgot to mention the back door that was in every implementation. [37:27.830 --> 37:35.510] If you typed the right magic function of the date into any of the attached terminals, it would open a root shell for you. [37:36.090 --> 37:39.070] And this was undocumented, but we found it in the source code. [37:39.730 --> 37:40.710] It was amazing. [37:42.590 --> 37:43.310] Hi, guys. [37:44.050 --> 37:45.270] Great show. [37:45.510 --> 37:46.290] It was lovely. [37:47.670 --> 38:00.410] We're all hackers, and we appreciate all the stuff you give us for information, but when you present to the organizations and groups, do they ever try to kind of post it as, hey, you're a terrorist, or ever try to blacklist you like that? [38:01.690 --> 38:04.870] It has happened to security researchers, yes. [38:05.730 --> 38:08.570] Especially when the assets are... [38:08.570 --> 38:21.100] I don't want to say targets, because that would make it seem like terrorists, but when the asset is, you know, transit in New York or D.C., or when we were talking about some of the country's greatest liabilities, which are, you know, maximum security prisons. [38:21.380 --> 38:22.320] It's kind of hard. [38:23.040 --> 38:24.000] It was challenging. [38:24.200 --> 38:26.820] It took some... a lot of preparation. [38:27.320 --> 38:37.240] And we wanted to tell them, because they're really the only ones who can somewhat fix their... you know, get aware that this is a problem, and government try to fix this and get the vendors to patch. [38:37.420 --> 38:42.980] I think that we were lucky in our experience, you know, because we approached them directly. [38:43.380 --> 38:46.800] You know, we said we want to talk about this publicly, but you guys make the call. [38:47.480 --> 38:50.180] And they were pretty, you know, pretty good with us. [38:50.360 --> 38:52.180] Nobody tried to pan us out to be the bad guy. [38:52.320 --> 38:53.820] You know, it's more like, thank you for telling us. [38:53.920 --> 38:54.240] We're glad. [38:54.600 --> 38:56.640] We'd appreciate it if you didn't release it publicly. [38:56.980 --> 38:57.600] All right, fine. [38:58.380 --> 39:00.820] But they... we had a pleasant experience. [39:01.740 --> 39:03.100] Yeah, I think that's actually... [39:03.100 --> 39:06.020] that's part of that is just the timing on what you guys have done. [39:06.300 --> 39:14.360] You know, like I said, in 2004, 2005, 2006, people weren't nearly as aware of the kind of problems you guys have been bringing up. [39:14.540 --> 39:18.100] And they haven't heard of, you know, Dylan's research and your research and things like that. [39:18.300 --> 39:18.620] Yeah. [39:18.620 --> 39:20.840] You guys are... have the benefit of... [39:20.840 --> 39:22.520] everybody's kind of coming out at the same time. [39:23.080 --> 39:24.760] You know, seven or eight years ago, absolutely. [39:24.760 --> 39:26.660] It was like, why are you doing this? [39:26.860 --> 39:27.660] Why are you looking at this? [39:28.000 --> 39:28.720] What's your problem? [39:29.380 --> 39:30.560] You trying to be a troublemaker? [39:30.820 --> 39:31.000] Yeah. [39:31.400 --> 39:31.760] No? [39:32.160 --> 39:33.480] No, your stuff's broken. [39:34.200 --> 39:34.780] Like, fix it. [39:34.940 --> 39:39.720] But, yeah, I think that there are industry groups like ICS Cert and stuff like that. [39:39.880 --> 39:42.520] It makes it easier to have those conversations in a sane way. [39:42.520 --> 39:47.240] And do you think it would be different between you as a professional and an organization? [39:47.520 --> 39:47.540] Yeah. [39:47.540 --> 39:51.420] It definitely does help going through ICS Cert. [39:51.540 --> 39:53.380] Like, we had organizations, though. [39:53.960 --> 39:56.680] You've got to realize the software's made around the world, right? [39:56.780 --> 40:00.340] There's not just American companies doing it. [40:00.520 --> 40:06.300] I mean, Siemens is a huge company, international, but they're big enough that they kind of have a process to handle this. [40:06.300 --> 40:23.120] We actually had some firms over in, like, Israel that when ICS Cert went to talk to them, they basically gave them the who are you and we're going to do a full background check and make sure that you're legit before we even talk to you, right? [40:23.360 --> 40:29.120] Because they were ultra-paranoid about, you know, these hackers bringing bugs to them, right? [40:29.700 --> 40:32.880] And those are the sort of things, like, we didn't want to have to deal with. [40:33.000 --> 40:37.920] But you do have to realize that the software is... it crosses a lot of borders. [40:38.140 --> 40:45.780] And so when you're talking about these bugs and some of the software manufacturers out there, like, you will get some weird responses like that. [40:48.670 --> 40:49.690] Okay, thank you. [40:50.030 --> 40:50.650] Thank you. [40:50.890 --> 40:51.430] Thank you. [40:52.550 --> 40:53.310] Hey, how are you doing? [40:54.030 --> 40:54.250] Good. [40:54.950 --> 41:13.670] So one of the things that I was thinking while you were giving this speech is just the general age of a lot of this equipment is not really taken into consideration in the information that you're portraying, particularly because, you know, a lot of these factory PLCs were designed before, [41:13.670 --> 41:16.690] you know, Ethernet interfaces were even on the equipment, right? [41:16.690 --> 41:25.870] So you've now got, you know, second-generation engineers attaching Ethernet interfaces to analog interfaces, right? [41:26.270 --> 41:40.410] So, you know, so two things to consider, you know, while we're busy, you know, slamming Siemens and these guys for not considering this stuff is that, you know, they didn't design the device initially to be on an Ethernet interface. [41:40.690 --> 41:44.430] It's now just being connected to one via some third party in some cases. [41:44.930 --> 41:56.170] And, you know, and secondly, you know, a lot of the times these devices are, you know, you wouldn't find any other manufacturer be Microsoft or Apple support devices that are God knows how many years old, you know? [41:56.770 --> 42:00.350] Yeah, no, that absolutely is true in certain cases. [42:01.090 --> 42:04.290] And that was one of the things that we found out as well. [42:04.290 --> 42:12.770] So some of them, like, okay, in ICS, we found that very often availability was of greatest priority. [42:12.970 --> 42:16.690] And so sometimes when the patching cycle could be up to like six years. [42:16.690 --> 42:25.030] So you are looking, you know, at older device, and that is correct, but it doesn't make it any less of a problem because it's so widely deployed. [42:25.230 --> 42:35.910] And so there's got to be stuff in between, you know, the implementation of the next-gen and what we have now to make it better and safer as it exists. [42:35.910 --> 42:36.110] Yeah. [42:36.370 --> 42:44.110] Well, I think to your point earlier on about the physical segmentation of those networks is probably far more important than most of these other topics. [42:44.110 --> 42:53.270] That was one of the things that we really, like, the whole way along when we were going through, we were like, okay, this would be a neat idea, but there's no way it's going to work out. [42:53.590 --> 42:56.830] We're like, it's going to be air-gapped, or it's going to be this, it's going to be that. [42:56.910 --> 42:59.950] And we got in there and we saw none of that. [43:00.290 --> 43:18.170] Something else that I thought would be useful, you know, while portraying your statistics was the, I guess, the character of the statistics, because, you know, you could take any level of code and, you know, pull out thousands of potential security problems. [43:18.370 --> 43:27.930] But, you know, are you, when you're reporting statistics like, you know, a hundred, a thousand bugs, are you talking about, like, external vendor firmware bugs? [43:27.950 --> 43:35.350] Or are you talking about bugs that are exposed due to the implementation of the way that the device is being used? [43:35.350 --> 43:40.690] Because those programming languages are, you know, it's up to every engineer. [43:40.910 --> 43:49.350] And the engineer in this factory is far more concerned about whether the car is going to fall off the conveyor belt than whether someone can actually get into the device. [43:50.910 --> 43:52.450] Terry, Billy, did you guys hear that? [43:53.210 --> 43:54.770] Yeah, I heard the question. [43:54.970 --> 44:05.710] I actually want to talk about the first point that you brought up, where you say, you know, some of this stuff was designed in an age before they realized it was probably going to be connected to the Internet and facing the entire world, right? [44:05.830 --> 44:07.510] Like, we understand that. [44:07.770 --> 44:11.810] You know, but at the same time, you can't let the vendors off the hook, right? [44:11.990 --> 44:17.310] So, if you give them the opportunity to say, hey, you know what, we never designed it to do that, I'm sorry. [44:17.790 --> 44:20.910] Like, they'll just take that stance and just move forward, right? [44:21.530 --> 44:23.230] And you can't let them do that, right? [44:23.230 --> 44:24.130] The world has changed. [44:24.310 --> 44:29.530] The world has changed around their software and their hardware, and they have to adapt, right? [44:29.530 --> 44:31.790] And if you don't force them to adapt, they won't. [44:31.950 --> 44:34.190] They'll just keep doing the same things that they're doing. [44:34.510 --> 44:35.730] And we've seen that, right? [44:35.830 --> 44:48.930] Like, some of the newer software that's released by a lot of different vendors, I'm talking, like, within the last couple of years, it shows the same design principles, the same code flaws, the same errors that they have, you know, the same bugs that they've had, [44:48.950 --> 44:50.010] like, 20 years ago, right? [44:50.250 --> 44:51.630] And that's not acceptable, you know? [44:51.690 --> 44:53.030] They have to adapt to the world. [44:53.470 --> 45:00.130] They can't just pretend like they're sheltered and, like, no one's ever going to figure this stuff out, because it's, you know, obscurity, right? [45:00.290 --> 45:02.370] So, it's definitely a two-way street. [45:02.550 --> 45:09.450] I think implementers need to understand that some of this stuff probably isn't as robust as the salesperson makes it out to be, right? [45:09.590 --> 45:13.330] And then at the same time, the vendors, they need to get with the real world, right? [45:13.510 --> 45:24.150] I mean, when they look outside and they see everything is connected to the Internet and people are connected directly to the Internet and such, they need to understand that that's their environment, and they need to change their path accordingly, you know? [45:24.270 --> 45:25.610] And I hope that that's being done. [45:26.250 --> 45:32.990] So, but as far as the bugs that we found, most of the bugs that we reported, they're not configuration issues, right? [45:33.110 --> 45:34.650] Like, we don't want to blame the customer either. [45:34.870 --> 45:38.810] So, most of the bugs that we reported, they're straight software bugs, right? [45:38.810 --> 45:45.450] There are bugs where the vendor needs to go back and literally change a couple lines of code to fix the issue. [45:45.790 --> 45:50.210] And that's, I would say, probably, like, 95%, 99% of the bugs that we reported. [45:51.910 --> 45:58.510] Yeah, and I think to your other point, all the software we looked at was just software for PCs. [45:58.790 --> 45:59.830] Most of it Windows-based. [46:00.890 --> 46:03.050] We weren't looking at physical hardware. [46:03.690 --> 46:06.530] So, physical hardware has the same sort of issues. [46:06.810 --> 46:08.270] Dylan's research shows that. [46:08.470 --> 46:11.910] There's a lot of other guys that are doing great research in that area. [46:12.890 --> 46:13.450] Reed Whiteman. [46:13.770 --> 46:17.090] I mean, the issue is across the board. [46:17.090 --> 46:21.690] So, both software and hardware or firmware. [46:22.050 --> 46:23.070] Oh, hey, wait. [46:23.210 --> 46:30.950] So, I was under the impression that the level of bugs you were talking about were all exposed via the PLC hardware itself. [46:32.770 --> 46:33.490] No. [46:33.930 --> 46:40.950] These are all HMIs or other pieces of software that are supported systems. [46:41.670 --> 46:42.010] Oh, I see. [46:42.010 --> 46:42.290] Yeah. [46:42.550 --> 46:45.710] So, Terry and Billy, they primarily looked at HMI systems. [46:46.310 --> 46:49.570] We looked at the PLC and the PLC software directly. [46:50.030 --> 46:50.170] I see. [46:50.550 --> 46:52.990] But there, the large number they have is from HMI. [46:53.510 --> 46:53.730] Okay. [46:53.890 --> 46:57.210] I think part of the thing about these systems is that they are so complex. [46:57.210 --> 47:03.730] And I think one of the things we need to keep, you know, just as an aside, keep the pressure on the vendors for is that wouldn't it be cool factor. [47:04.010 --> 47:11.950] You know, you designed this thing in 1978 to do one function and then somebody comes along this year and thinks, Oh, wouldn't it be cool if we could put it on the Internet? [47:12.150 --> 47:13.490] We could connect it to Ethernet? [47:13.670 --> 47:13.970] Oh, yeah. [47:14.090 --> 47:17.230] Because you know that that factory man wants to manage it from his iPad. [47:17.390 --> 47:17.550] Right. [47:17.690 --> 47:18.010] Yeah. [47:18.450 --> 47:19.990] Let's put an iPad app on this thing. [47:20.190 --> 47:20.470] Right. [47:20.950 --> 47:26.070] And if we can keep the pressure on the vendors to not fall prey to that, I think that would be a good thing for all of us. [47:26.070 --> 47:26.410] Yeah. [47:26.410 --> 47:27.030] I agree. [47:27.230 --> 47:34.610] I just think we should publish the statistics in a more accurate, you know, so that we address the right areas of the problem. [47:34.930 --> 47:35.790] But thank you. [47:35.970 --> 47:38.170] It's definitely worth paying attention to it all though. [47:38.530 --> 47:38.970] All right. [47:39.150 --> 47:42.050] I think we got two minutes left, so one more question. [47:42.430 --> 47:44.350] I guess this ties in a bit to his. [47:45.110 --> 47:48.910] How much success have you had in getting the vendors to think security first? [47:48.910 --> 47:52.890] I did a master's thesis in SCADA back in 2004. [47:53.350 --> 47:58.830] And it was just basically a very brief overview of the security picture in the environment. [47:59.150 --> 48:07.170] And I was hearing about things like the controlling to a, you know, a remote power plant site would be over an unencrypted radio link. [48:07.610 --> 48:13.930] And not even like open Wi-Fi, just long distance radio with no encryption, no authentication, no anything at all. [48:14.230 --> 48:15.870] So you don't even need to find a bug. [48:15.990 --> 48:17.810] You just need to turn on a radio and sniff. [48:18.910 --> 48:19.130] Okay. [48:19.130 --> 48:19.530] Yeah. [48:19.650 --> 48:20.830] That's still the case in a lot of places. [48:21.590 --> 48:21.950] Yeah. [48:22.250 --> 48:25.870] And you just find glaring design homes where nobody's even thought about security. [48:25.870 --> 48:27.110] And, yeah. [48:27.310 --> 48:27.950] Well, that's why we... [48:27.950 --> 48:28.890] What we did is we... [48:28.890 --> 48:30.430] With our group, we brought awareness to... [48:30.430 --> 48:35.010] Directly to the government agencies that we thought would be the ones who'd be most interested in trying to make some changes. [48:35.670 --> 48:36.030] So... [48:36.030 --> 48:38.090] We can probably take one more question real quick if you... [48:38.090 --> 48:39.170] If you have one before you leave. [48:39.490 --> 48:41.410] Yeah, you know, I'd actually like to add something to that. [48:41.590 --> 48:43.390] Like, how do you bring, you know, some of this awareness? [48:43.930 --> 48:50.030] I think, you know, maybe some of the first steps is to let these vendors know that security is not magic, right? [48:50.410 --> 48:52.350] Like, there's definitely some science behind it. [48:52.350 --> 48:57.290] And fixing bugs is literally a matter of adding a couple lines of code in most cases, right? [48:57.770 --> 48:58.150] It's... [48:58.150 --> 49:00.570] Sometimes it's not very complicated to fix certain issues. [49:01.110 --> 49:03.630] Design issues, yeah, of course, it requires a lot more. [49:03.750 --> 49:08.030] But for most of the stuff that we encounter, it doesn't take very much for them to fix, you know? [49:08.950 --> 49:09.430] All right. [49:09.590 --> 49:10.790] We can add one more question. [49:11.130 --> 49:11.470] All right. [49:11.510 --> 49:12.330] I'll try and be quick. [49:13.190 --> 49:16.130] I work in a similar industry, not exactly the same. [49:16.330 --> 49:21.970] But it seems like you're very antagonistic towards the people you've been dealing with. [49:21.970 --> 49:26.650] Not everybody, but, I mean, sometimes those relationships may develop that way. [49:27.650 --> 49:28.050] And... [49:30.130 --> 49:33.770] I could say, like, fixing two lines of code is really easy. [49:33.950 --> 49:36.130] But that's not the expensive part. [49:36.270 --> 49:38.070] It's testing and delivering. [49:38.310 --> 49:40.010] And, you know, they don't work for you. [49:40.130 --> 49:41.150] They work for their customers. [49:41.350 --> 49:43.090] So, I mean, you mentioned it in your talk. [49:43.090 --> 49:52.390] It seems like the culture at the people who are implementing these systems and using them might be a very important kind of vector to get in. [49:54.070 --> 49:59.690] Because, you know, they're not going to spend money just because someone calls them up and says you've got a problem, right? [49:59.690 --> 50:03.210] So, I just wanted to kind of bring that aspect into it. [50:03.590 --> 50:03.990] Yeah. [50:05.210 --> 50:07.110] I think you're absolutely right. [50:07.330 --> 50:11.310] And that's one of the things that the disclosure helps with, right? [50:12.170 --> 50:20.310] Because customers don't know right now that they're exposed and they don't know to ask, like, are we vulnerable, right? [50:21.470 --> 50:24.390] So, I think the culture aspect does need to change. [50:24.570 --> 50:27.530] But I think that's where the awareness helps, right? [50:28.010 --> 50:31.350] Like, it's difficult to change it if people don't even know. [50:31.490 --> 50:33.050] Because the company is not going to tell them. [50:34.350 --> 50:34.750] Okay. [50:35.050 --> 50:35.450] Thank you. [50:35.530 --> 50:36.350] Thank you very much. [50:36.610 --> 50:37.530] We're out of time. [50:37.710 --> 50:38.930] But thanks very much, HOPE.