[00:01.240 --> 00:03.420] I'm going to move very quickly through this slide. [00:03.600 --> 00:07.040] I have lots of slides, very graphic intensive talk. [00:08.640 --> 00:12.380] Just to start off a little bit, I want to involve you guys a little bit. [00:12.640 --> 00:16.020] Shout it out if you have any idea what the importance is of this date. [00:19.380 --> 00:19.820] Sorry? [00:19.820 --> 00:21.500] Hey, you got it on the first try. [00:21.700 --> 00:26.340] Yes, this is the date that is really the reason why we're all here today. [00:26.340 --> 00:33.000] The date that Mosaic, the first publicly available Internet web browser was released. [00:33.440 --> 00:37.300] And here we are over 30 years later. [00:38.040 --> 00:38.960] Who am I? [00:40.800 --> 00:41.960] I have a day job. [00:41.960 --> 00:43.520] I didn't change out the slides. [00:43.700 --> 00:47.440] I'm not mentioning my company, but that's my email address. [00:47.560 --> 00:50.500] My phone number, if you want to call me. [00:50.560 --> 00:52.760] If I don't recognize the number, I won't answer it anyway. [00:52.900 --> 00:55.020] But people have called me a couple of times over the years. [00:56.680 --> 00:59.480] My career spans five decades. [00:59.540 --> 01:04.040] I started this back in the early 80s, roughly around the time 2600 started. [01:05.540 --> 01:08.520] Kind of cut my teeth at the National Security Agency. [01:08.980 --> 01:12.120] Came out into the private sector almost 30 years ago. [01:13.100 --> 01:15.860] Been doing information security, that's what I called it. [01:15.940 --> 01:18.760] That's how I was trained back in the day and been doing it ever since. [01:20.060 --> 01:23.280] I am a co-host on a podcast called Paul Security Weekly. [01:23.460 --> 01:25.040] I've been doing that for about nine years. [01:26.020 --> 01:27.660] Anybody a Security Weekly listener? [01:28.240 --> 01:29.440] A couple of people out there. [01:29.820 --> 01:31.860] Thank you for being listeners, watchers. [01:33.460 --> 01:34.620] I am a hacker. [01:35.060 --> 01:37.700] I didn't always realize that. [01:38.040 --> 01:43.060] But during COVID, I had a lot of time to clean my closets and do some things. [01:43.580 --> 01:46.560] So I organized and hung up on my hoodies, put that out there. [01:47.100 --> 01:51.460] One of our listeners modified the picture for me a few years back. [01:54.480 --> 01:58.300] This has been a bucket list for me for a while to talk at this conference. [01:58.340 --> 02:10.480] And it occurs to me that when I got started in doing pen testing, which I'll get to in a minute, a lot of the people that were involved in this probably considered me the enemy because I worked for the government. [02:11.360 --> 02:14.320] And my name's Mann, so I'm literally the Mann. [02:15.940 --> 02:23.980] I hope you'll bear with me because I left there and I've been out in the private sector trying to fight the good fight for a long time. [02:26.260 --> 02:30.220] There's a series of books that came out a couple of years ago called Tribe of Hackers. [02:30.560 --> 02:33.120] I'm one of two people that's actually in all four editions. [02:34.220 --> 02:37.780] You can go buy all the editions to find out who the other person is. [02:38.060 --> 02:39.880] Also an ex-NSA person. [02:40.000 --> 02:40.820] I'll give you a clue. [02:42.860 --> 02:44.880] Anybody listen to Darknet Diaries? [02:46.720 --> 02:48.120] Of course, I'm behind the podium. [02:48.480 --> 02:49.580] Notice the artwork. [02:51.660 --> 02:59.580] Episode 83 is... I'm interviewed as well as a gentleman named Marcus Carey, who also did the Tribe of Hackers books, coincidentally. [03:01.020 --> 03:17.620] It's been seven years ago now, but I was invited to join something called the Cabal of the Curmudgeonists, which is a group of industry information security old-timers that are kind of grumpy and pretty much cynical and pessimistic, but we haven't completely given up hope. [03:18.120 --> 03:21.020] You might recognize one or two faces in that picture. [03:22.280 --> 03:31.580] But I was invited to join, and now I am happy to wear the moniker, amongst others, of being a curmudgeon. [03:33.560 --> 03:35.640] This is the third installment of the talk. [03:36.000 --> 03:39.360] In some ways, I wish I could have given other talks here. [03:39.800 --> 03:47.900] The first talk I gave, probably about ten years ago, was sort of an intro to cryptology talk, because that's what I did the first couple years at NSA. [03:49.440 --> 03:54.100] Just real briefly, I am a certified cryptanalyst from the National Security Agency. [03:55.620 --> 03:58.100] This is actually my favorite hack of all time. [03:58.100 --> 04:03.100] I went to work for NSA, and I was working for an office called Manual Crypto Systems. [04:03.340 --> 04:11.440] We were responsible for the paper systems, the manual systems, the things that you hear about in history books, codes and ciphers. [04:11.440 --> 04:15.000] And I was responsible for upgrading systems. [04:15.480 --> 04:26.680] But I had a customer early on come to me and say, we're using this thing called a one-time pad, and it takes us hours to encrypt and decrypt these messages one character at a time. [04:26.800 --> 04:28.900] If you don't know what a one-time pad is, I apologize. [04:29.300 --> 04:31.780] But they said, we've got this IBM PC on our desk. [04:31.800 --> 04:37.520] Is there any way we could do the encryption and decryption on the computer? [04:37.520 --> 04:41.080] And I was young and naive, and I thought, yeah, I don't see any reason. [04:41.280 --> 04:47.520] So I ended up becoming a project manager and figured out a way to get this thing produced. [04:47.940 --> 04:52.100] So it ended up being a one-time pad for the spies in the field. [04:52.560 --> 04:58.080] And for the caseworkers, the people that were receiving the messages, they got to use a PC. [04:58.320 --> 05:02.000] To do that, we had to put the one-time pad key on a floppy disk. [05:02.000 --> 05:07.540] That was significant because at the time, NSA was in the business of hardware. [05:07.900 --> 05:11.180] I had a chief scientist tell me, look, there's no such thing as software. [05:11.580 --> 05:13.000] Everything we do is hardware. [05:14.200 --> 05:19.840] I had to go through an approval committee that was all the executives, what we called suits. [05:20.140 --> 05:25.680] And I had to get this whole project approved before it could be fielded. [05:25.680 --> 05:29.800] I was able to do that, and looking back, I'm like, that's the biggest hack. [05:29.920 --> 05:39.640] Because the person that was sort of the chairman of the board that accepted this, he said, all right, we'll let you do this once, but don't do this again. [05:41.160 --> 05:47.280] So anyway, first software, to my knowledge, it was the first software-based crypto system that NSA ever produced. [05:47.540 --> 05:52.280] The other thing I did early on was I was working with a customer, U.S. Special Forces. [05:52.280 --> 05:54.200] They also used one-time pads. [05:54.440 --> 05:59.700] The algorithm that they used for the encryption-decryption was based on something called a Visionaire Square. [06:00.180 --> 06:04.320] And long story short, I came up with a way to turn that into a cipher wheel. [06:04.400 --> 06:07.080] So I invented, essentially, a cipher wheel. [06:09.480 --> 06:17.920] Recently, that wheel was put on display at the National Cryptologic Museum, which is down outside of NSA headquarters. [06:18.220 --> 06:19.440] Feel free to come visit. [06:19.440 --> 06:21.640] It's on display through September. [06:22.140 --> 06:25.060] Take an exit off of the BW Parkway. [06:25.320 --> 06:27.140] Turn left to get to the museum. [06:27.520 --> 06:29.000] Turn right, you get shot at. [06:29.460 --> 06:30.360] Fair warning. [06:31.260 --> 06:35.280] But it's actually a series of cipher wheels that are on display. [06:35.280 --> 06:44.880] They have one that dates back to the 1870s, that actually used to be owned by William Friedman, who was considered the godfather of cryptography. [06:45.520 --> 06:47.120] So that's me being goofy. [06:47.420 --> 06:52.320] And that's the display itself of what Special Forces called the whiz wheel. [06:53.020 --> 06:58.460] More of all those stories you can find online on YouTube called Tales from the Crypt Analyst. [06:59.480 --> 07:08.160] The sequel was the last couple years that I was at NSA, which is more why I hang out at hacker conferences like this. [07:09.980 --> 07:12.260] The sequel, more tales from the crypt analysts. [07:14.160 --> 07:18.180] Basically, there is a book that came out several years ago called Dark Territory. [07:18.380 --> 07:25.240] And in that book, chapter four, which is entitled Eligible Receiver, there's a paragraph that talks about something called the pit. [07:25.240 --> 07:40.360] The pit was actually the nickname for the office that this small group of guys that I was working with, who were basically learning how to do ethical hacking and penetration testing and breaking into networks to test the security of networks back over 30 years ago. [07:41.740 --> 07:48.800] How our office that we called the pit got into this book, I still don't know to this day, but somehow we're in the folklore. [07:50.080 --> 07:52.000] The pit was actually six guys. [07:52.540 --> 07:55.580] One other guy, I'm allowed to say publicly who it is. [07:55.680 --> 07:57.760] Does anybody recognize who that other person is? [07:58.540 --> 07:59.560] One person. [08:01.300 --> 08:04.480] A gentleman named Ron Gula, who is an entrepreneur. [08:04.560 --> 08:07.280] He founded a couple companies early on. [08:07.460 --> 08:09.500] I'll actually have some slides on them later on. [08:09.740 --> 08:12.680] But he's responsible for something called Nessus. [08:12.940 --> 08:13.980] Anybody hear of Nessus? [08:15.320 --> 08:15.900] All right. [08:16.080 --> 08:19.440] So in that office, we were learning how to do pen testing. [08:19.440 --> 08:21.980] We were learning how to break into networks. [08:21.980 --> 08:24.460] We were trying to figure out methodologies. [08:24.700 --> 08:27.420] There were no conferences. [08:27.760 --> 08:28.740] There were no training courses. [08:28.960 --> 08:30.020] There were no certifications. [08:30.380 --> 08:31.840] There were no educational degrees. [08:31.840 --> 08:34.820] We were just kind of figuring it out as we went along. [08:34.820 --> 08:37.140] There were some early resources. [08:37.620 --> 08:41.560] The book there, Practical UNIX and Internet Security, written by Gene Spafford. [08:41.980 --> 08:43.800] You know, the guy that's the curmudgeon. [08:45.380 --> 08:48.940] Cheswick and Bellevin wrote a great book called Firewalls and Internet Security. [08:49.240 --> 08:53.480] These are books that you should read if you haven't, you young people out there. [08:53.880 --> 08:58.720] And of course, The Cuckoo's Egg, which is a famous book, inspired many of us. [08:58.720 --> 09:05.920] The story of Cliff Stahl, who sort of discovered hackers breaking into his university network. [09:06.080 --> 09:07.780] And this was back in the 80s. [09:08.100 --> 09:09.520] Somebody told me the exact year. [09:10.800 --> 09:12.200] But he wrote a book about it. [09:12.280 --> 09:17.600] And part of his experience was he went to NSA, he went to CIA, he went to FBI to try to get help. [09:17.600 --> 09:20.900] And nobody knew what to do because this was all new to everybody. [09:22.600 --> 09:23.980] I put this slide in. [09:24.100 --> 09:26.400] I gave this talk a month or so ago. [09:26.560 --> 09:28.680] A gentleman named Wynn Schwartow was there speaking. [09:28.680 --> 09:30.280] He spoke right after me. [09:30.400 --> 09:33.760] And so I put this slide in mostly for his benefit. [09:34.020 --> 09:37.020] I should have updated this and made it a 2600 slide. [09:37.160 --> 09:40.340] I used to subscribe to 2600 back when I was at NSA. [09:40.880 --> 09:42.100] I think I'm allowed to say that. [09:43.900 --> 09:45.960] We were in demand, as you can imagine. [09:45.960 --> 09:48.120] This was the early to mid 90s. [09:48.300 --> 09:55.000] And this whole computer hacking, network hacking, Internet, we called it Internet security, was kind of a big deal. [09:55.200 --> 09:56.500] It was kind of a new thing. [09:57.380 --> 10:01.800] People started hearing that NSA had a capability of testing it. [10:03.880 --> 10:11.100] Very briefly, I was put in charge of a project to work with an organization called the Department of Justice. [10:11.100 --> 10:15.760] They came to us and they said, hey, we want to have you do a pen test of our Internet presence. [10:16.760 --> 10:18.420] There's a long story here. [10:18.820 --> 10:21.100] But essentially... [10:23.780 --> 10:25.980] I don't know why there's two copies of that slide in there. [10:26.240 --> 10:29.400] We were going to test their security. [10:29.500 --> 10:39.400] But because it was NSA and we were supposed to do classified networks and the DOJ was unclassified, there were some problems and there were some legal loopholes to go through. [10:39.400 --> 10:45.560] And there was... it was a months long process to get through the paperwork and get through the legality of it. [10:46.040 --> 10:50.160] And you can notice the date there, 21 August. [10:50.400 --> 10:52.140] This thing had been signed by our director. [10:52.140 --> 10:54.300] It actually hadn't been delivered yet. [10:54.300 --> 10:58.960] But we were that close to being legal when this happened. [11:00.400 --> 11:06.700] The DOJ website on a weekend, somebody got to break into it and deface it. [11:07.000 --> 11:12.840] This was the first attack, first cyber attack against a DOD Internet presence. [11:13.140 --> 11:17.900] I suspect that there might be somebody at HOPE that might know who did this. [11:18.060 --> 11:21.560] I would love to meet you because nobody ever found out who did it. [11:21.560 --> 11:26.720] But I came in on a Monday morning, the 17th I think was a Saturday. [11:27.040 --> 11:29.880] I came in on a Monday morning, got a call from the customer. [11:30.120 --> 11:31.420] Help, we've been hacked. [11:31.840 --> 11:33.960] So they call it NSA. [11:35.000 --> 11:39.040] And I put together what essentially was a forensics team. [11:39.340 --> 11:42.640] Took a bunch of the guys from the pit down to try to figure out what had happened. [11:42.640 --> 11:45.520] And in those days, everything was hardware-based. [11:45.700 --> 11:47.620] The web server was a physical device. [11:47.620 --> 11:50.020] And it was sitting there, hopefully behind a firewall. [11:50.500 --> 11:57.480] But the first thing that happened when they found out it had been breached, is they pulled the plug on it and stripped it down and rebuilt the entire thing. [11:57.660 --> 12:01.240] So any evidence that was there was lost, obviously. [12:02.140 --> 12:03.180] But we were down there. [12:03.360 --> 12:06.100] There was other systems out there that we were looking at. [12:06.200 --> 12:08.660] We were there for Tuesday, Wednesday. [12:08.940 --> 12:10.460] Thursday morning, I get a phone call. [12:10.460 --> 12:12.320] We were down there in Washington, D.C. [12:12.420 --> 12:13.440] in the DOJ building. [12:13.840 --> 12:16.340] Somebody from the pit called and said, The shit's hit the fan. [12:16.560 --> 12:18.360] You have to come back now. [12:19.960 --> 12:21.020] Something, something. [12:21.540 --> 12:22.320] Church proceedings. [12:22.780 --> 12:23.300] Something, something. [12:23.440 --> 12:24.320] NSA charter. [12:25.080 --> 12:25.960] Something, something. [12:26.220 --> 12:28.880] I got in trouble because I was the ringleader. [12:29.340 --> 12:31.660] I was put on double-secret probation. [12:32.660 --> 12:35.940] This is actually photographs of my desk in the pit. [12:36.160 --> 12:39.820] Don't ask me why I have them because I honestly don't remember. [12:39.820 --> 12:44.800] But I found them during cleanup on a floppy disk during those COVID years. [12:44.940 --> 12:46.300] I'm like, oh, I'm going to put these in a slide. [12:47.320 --> 12:48.640] I honestly don't remember. [12:48.780 --> 12:52.460] We weren't allowed to have recording devices, transmitters, cameras, or anything like that. [12:52.500 --> 12:56.740] I think maybe we got a laptop that had a built-in camera or something like that. [12:57.160 --> 13:02.240] But anyway, by the end of September, about six weeks later, I was gone from NSA. [13:03.600 --> 13:06.940] That whole story you can hear about and more tales from the cryptanalyst. [13:07.400 --> 13:09.140] Also, you can find that on YouTube. [13:09.700 --> 13:13.600] And in retrospect, that's probably the talk that I should have given here for my first talk at HOPE. [13:15.540 --> 13:19.400] My takeaway from my time at NSA was really this. [13:19.900 --> 13:23.300] And again, I didn't think of myself as a hacker so much back then. [13:23.480 --> 13:30.400] But the idea that I produced something in software that people in charge said that we couldn't be done. [13:30.400 --> 13:36.120] And created a site for Weill, started something like what came to be known as the first NSA Red Team. [13:36.820 --> 13:42.300] Which brings me back to this talk, the third installment, which I call the afterlife. [13:42.560 --> 13:44.940] The life after NSA. [13:46.260 --> 13:50.580] And when I first put this talk together at the beginning of the year, it was really... [13:50.580 --> 13:56.980] And I apologize for this, but if anybody knows me, they know I've been doing this thing called PCI for about 20 years. [13:57.400 --> 14:04.600] So this was really kind of a... How did somebody from NSA that was doing pen testing end up doing PCI audits? [14:04.700 --> 14:07.160] Which I don't call it an audit, but the rest of the world does. [14:07.720 --> 14:14.420] So let me tell you a little bit of my path from there, NSA, to here where I am today. [14:14.620 --> 14:16.040] Or at least up through 2004. [14:17.380 --> 14:24.720] For the younger people in the audience, I hope there's a takeaway here in terms of learning a little bit about our history and where we've come from. [14:24.720 --> 14:29.180] For the older people in the audience, I hope this is an enjoyable trip down memory lane. [14:30.740 --> 14:33.720] There were not very many companies in the business back then. [14:33.800 --> 14:35.800] This is 1996, 1997. [14:36.320 --> 14:42.460] But several of us had been talking to some companies out in the private sector because they paid better. [14:42.580 --> 14:45.480] And there was less bureaucratic red tape to go through. [14:46.360 --> 14:48.940] I had been talking to a couple companies like this. [14:49.100 --> 14:50.400] Some you might have heard of. [14:51.220 --> 14:52.940] Some of these don't exist anymore. [14:53.460 --> 14:59.420] But I basically, since I was gone in six weeks, I took the first offer that was given to me. [14:59.420 --> 15:02.780] So I went to work for a company called Computer Sciences Corporation. [15:03.340 --> 15:10.580] Not much to say there about that, except for I worked in the same office with this guy, who some of you might know who that is. [15:12.560 --> 15:14.200] Anybody do know who this guy is? [15:14.520 --> 15:15.240] Good, a couple. [15:18.280 --> 15:21.560] It was fast moving times back then. [15:21.680 --> 15:29.180] The guys that hired me that were doing government work, but were interested in doing commercial consulting, commercial penetration testing. [15:31.160 --> 15:36.720] The manager and his deputy both resigned weeks after I went to work for this company. [15:38.180 --> 15:40.020] So I didn't stay there long. [15:40.280 --> 15:43.880] I ended up working for another government contractor called Nichols Research. [15:44.420 --> 15:51.420] They, again, were trying to get into the commercial sector of trying to offer ethical hacking, penetration testing. [15:51.420 --> 15:53.280] Let's test the security of your systems. [15:53.980 --> 15:58.400] We had all sorts of marketing slicks and there wasn't a whole lot to do back in those days. [15:58.740 --> 16:03.100] You know, we could do the pen testing, which we loosely called a vulnerability assessment. [16:03.900 --> 16:06.340] We could help them with architecting their network. [16:06.580 --> 16:08.660] And basically, we could recommend a firewall. [16:08.900 --> 16:11.160] Because there wasn't much more on the market back then. [16:11.520 --> 16:13.500] A conference like this... [16:13.500 --> 16:16.020] Of course, we don't have vendors at this conference, per se. [16:16.700 --> 16:21.240] But a vendor conference back then would have had, like, maybe two or three companies. [16:21.700 --> 16:25.660] There was only maybe two or three firewalls on the market and that was about it. [16:27.240 --> 16:33.080] But we were into it and we were trying to sell our services of penetration testing and security. [16:33.800 --> 16:35.660] Network architecture and things like that. [16:35.920 --> 16:38.580] SANS was at the very beginning of its run. [16:38.880 --> 16:45.360] They used to put out posters that talked about all the different facets of Internet security and network security. [16:45.500 --> 16:46.660] Anybody remember these posters? [16:48.000 --> 16:55.260] On the back of it, they would list companies that did the different types of things or provided the different types of products and services. [16:56.100 --> 17:01.180] And we got our name up there on the list as a penetration testing company. [17:02.820 --> 17:04.660] Our approach was pretty simple. [17:05.000 --> 17:18.620] And to be honest, we really modeled our approach after what we had been doing at NSA and what we were figuring out about penetration testing methodology, which is roughly what it is today. [17:19.560 --> 17:21.700] We had different terminology a little bit. [17:21.840 --> 17:23.100] The terminology has evolved. [17:23.340 --> 17:27.580] But it was really based on this movie that came out in 1992 called Sneakers. [17:28.280 --> 17:29.500] Sneakers fans out there? [17:31.320 --> 17:31.800] Excellent. [17:32.220 --> 17:38.480] I've been going to conferences lately where I ask about that and more and more people have never seen the movie or never heard of the movie. [17:38.480 --> 17:39.300] So thank you. [17:40.360 --> 17:42.720] You all know this movie, many of you. [17:42.920 --> 17:56.920] And you know there's a famous scene in it where they talk about, you know, in the pivotal moment, the bad guy, Ben Kingsley says to Robert Redford, the good guy, there's a war out there, old friend, a world war. [17:57.160 --> 17:59.520] And it's not about who's got the most bullets. [17:59.520 --> 18:05.580] It's about who controls the information, what we see in here, how we work, what we think. [18:05.900 --> 18:07.660] It's all about the information. [18:08.480 --> 18:10.480] Kind of stands true today, doesn't it? [18:12.700 --> 18:16.780] I'm going to go through this pretty quickly because you guys know how this stuff works. [18:16.980 --> 18:22.540] But, you know, we did a site survey, tried to find out what they were doing, what their presence was. [18:23.400 --> 18:27.680] We did network discovery using various tools and techniques. [18:29.240 --> 18:33.180] Kind of the early days of Nmap, that was a primary tool we used. [18:33.920 --> 18:35.880] And then we did the penetration testing. [18:36.060 --> 18:41.900] And to us, penetration testing was there was no rules because the bad guys, the adversaries didn't have rules. [18:41.940 --> 18:48.120] So we tried to emulate as best as we possible what anybody else would do to try to break into a network. [18:48.620 --> 18:51.000] Usually for the purpose of stealing something. [18:51.000 --> 18:57.880] And in those days, few of the quote-unquote bad guys had figured out how to monetize this stuff. [18:58.060 --> 19:10.080] So most of the hacking and penetration testing that was done back in those days, like the DOJ website, was more bragging rights, saying that you could do it, embarrassment and things like that. [19:11.680 --> 19:21.360] One of the tools that was available back in those days as a commercial product, pretty much the first Internet vulnerability scanner was ISS. [19:21.820 --> 19:22.720] Anybody remember ISS? [19:23.280 --> 19:24.740] Started out as open-source. [19:24.740 --> 19:27.040] They got very quickly acquired. [19:27.060 --> 19:32.030] Well, they lasted longer than most companies, but they were eventually acquired by IBM. [19:34.200 --> 19:39.880] BIA, did you know that the origins of where you're working as an intern was ISS? [19:40.100 --> 19:46.820] ISS got acquired by IBM, including their red team, their red... what did they call it? [19:47.160 --> 19:48.460] It's where you work now. [19:48.640 --> 19:48.920] That... [19:49.590 --> 19:50.520] X-Force, thank you. [19:50.880 --> 19:52.100] Yeah, that used to be ISS. [19:54.100 --> 19:59.660] They had one of the early products that was considered to be an intrusion detection system. [19:59.880 --> 20:10.160] Because in the evolution of products, that was sort of the second thing after the firewall, because people were figuring out how to go around the firewall, through the firewall and so on and so forth. [20:11.580 --> 20:19.100] And I hope this is okay, but I wanted to share with you some early marketing literature that was put out for RealSecure. [20:20.080 --> 20:26.000] This lasted for about a week before they pulled it, but they basically put out a graphic novel. [20:26.240 --> 20:28.340] That's actually the good guy, by the way. [20:29.840 --> 20:31.220] That's the bad guy. [20:31.820 --> 20:34.140] Wicked Wanda, I forget what her name was. [20:35.660 --> 20:41.080] That you can understand why they might have pulled this, because they were trying to be a real company and so on and so forth. [20:41.200 --> 20:43.440] But they did have a sense of humor, so that was the back page. [20:45.920 --> 20:48.520] This is stuff that I found during COVID. [20:48.680 --> 20:50.880] I got to do a lot of cleaning and find a lot of stuff. [20:51.140 --> 20:52.900] And I'm apparently a hoarder. [20:53.880 --> 20:55.480] I didn't want to use ISS. [20:55.480 --> 20:57.440] We needed to use a vulnerability scanner. [20:57.620 --> 21:13.700] When we were setting up our practice, about the same time I went to work for Nichols, this guy out in Canada, Calgary, put an announcement out that said, Hey, I'm starting a new company and I've got this new vulnerability scanner, and we're calling it Ballista. [21:13.880 --> 21:15.240] Does anybody remember Ballista? [21:15.480 --> 21:16.700] Any of you old timers? [21:17.400 --> 21:17.880] One. [21:18.400 --> 21:19.160] Thank you. [21:20.280 --> 21:22.340] Early websites were HTMLs. [21:22.400 --> 21:23.180] They had a website. [21:27.480 --> 21:31.420] And their tool, as most of the tools are ISS. [21:31.420 --> 21:34.360] The other one that was available back then was Satan. [21:35.360 --> 21:44.520] They were meant to be used by system administrators and network administrators more than anything, but of course they were great tools for the good guys and the bad guys to use. [21:45.100 --> 21:51.280] Somebody that worked for this company as well, which you guys might know, sort of wrote the definitive paper back in those days. [21:51.780 --> 21:52.300] Tom... [21:52.300 --> 21:54.260] I always pronounce his name wrong. [21:54.460 --> 21:54.980] Patachek? [21:55.980 --> 21:58.380] Forgive me if I've mispronounced it. [21:58.580 --> 22:00.140] But this was a very thick book. [22:00.180 --> 22:01.560] You can still find it on the Internet. [22:01.580 --> 22:03.580] It's downloadable in PDF form. [22:03.760 --> 22:06.420] But, you know, intrusion detection systems are out there. [22:06.600 --> 22:07.680] How do you defeat it? [22:07.800 --> 22:24.460] And it actually goes back very much like the movie Sneakers, where in the movie Sneakers they were defeating all the security controls, and they basically figured out different ways to fly under the radar, which is the essence of this paper that he wrote. [22:26.500 --> 22:32.860] As was the custom in back in those days, this company lasted about 12 months before they got acquired. [22:33.280 --> 22:35.120] They were not alone, certainly. [22:35.920 --> 22:37.120] They happened to be acquired... [22:39.560 --> 22:41.520] I believe Cisco bought them up. [22:41.640 --> 22:44.680] Cisco has been trying to be a security company for 30 some odd years. [22:45.520 --> 22:47.240] Network Associates was another one. [22:47.740 --> 22:50.220] They acquired things like PGP and McAfee. [22:50.880 --> 22:53.780] And this is also an example of their marketing. [22:54.100 --> 22:57.220] You know, we used to have these things called magazines that were printed on paper. [22:57.220 --> 23:02.340] And this was a full-page ad in, I don't know, SC Magazine or something like that. [23:02.560 --> 23:09.440] We were not mad because there was this scantily clad woman being portrayed as a hacker. [23:09.600 --> 23:13.340] We were mad that she was using Windows on a laptop. [23:16.080 --> 23:16.560] Anyway. [23:18.100 --> 23:19.500] Another company that was... [23:20.160 --> 23:23.700] A couple of companies that were really big back then and well-respected. [23:23.700 --> 23:27.340] Most of the people that worked there came out of the government in one way, shape, or form. [23:27.640 --> 23:30.520] Trusted Information Systems, which was local to Maryland. [23:30.680 --> 23:31.880] I'm from Maryland, by the way. [23:32.420 --> 23:33.580] Wheel Group Corporation. [23:34.600 --> 23:36.900] They got snatched up very quickly. [23:37.100 --> 23:47.660] Trusted Information Systems, probably best known for a guy named Marcus Random, who is sometimes credited for inventing the stateful firewall. [23:48.000 --> 23:49.060] He admits later... [23:49.060 --> 23:51.560] He admits now that he got it wrong. [23:52.580 --> 23:55.460] I actually interviewed at Trusted Information Systems. [23:55.620 --> 23:58.300] TIS didn't get hired by their consulting practice. [23:58.520 --> 24:09.820] But I ended up hiring their head of their consulting practice after they got acquired because they got acquired for the product and they didn't really care what happened to the consulting group. [24:10.560 --> 24:14.580] And the woman that came to work for us happened to be Marcus's ex-wife. [24:15.560 --> 24:15.780] Weird. [24:16.620 --> 24:18.580] Weird way this world works. [24:19.660 --> 24:25.900] We used a war dialer that was commercially available because very common back in those days. [24:26.140 --> 24:34.940] And of course, it's not a common anymore, I hope, for a lot of network devices, routers and switches to have modems attached to them. [24:34.940 --> 24:42.120] And like the movie War Games, you could war dial into them and get into the network very often that way. [24:42.960 --> 24:44.520] No firewall required. [24:44.660 --> 24:54.000] We picked this product because it happened to be the company that was founded by a woman named Becky, Becky Base, who was at NSA when I was there. [24:54.000 --> 25:02.880] And she was working behind the scenes, talking to all the management in the suits, saying, you need to let those guys in the pit do what they're doing. [25:03.020 --> 25:10.060] So she was really our champion and we benefited from her experience and her stature. [25:10.060 --> 25:11.900] If you've not heard of her, look her up. [25:12.720 --> 25:14.880] She was the one that got me into the curmudgeons. [25:15.080 --> 25:16.480] She was the one that sponsored me. [25:16.800 --> 25:19.880] And unfortunately, she passed away just a few months after that. [25:20.240 --> 25:24.800] But, you know, I owe a lot to this woman as well as all of you, too. [25:24.820 --> 25:25.600] So look her up. [25:25.940 --> 25:27.160] Yes, please give her a hand. [25:31.420 --> 25:34.220] We were able to collect some pretty interesting clients. [25:34.220 --> 25:36.160] Of course, we were government contractors. [25:36.160 --> 25:37.900] We had a little bit of DOD work. [25:37.900 --> 25:44.060] We started working with companies that were providing Internet services, Internet service providers, things like that. [25:44.940 --> 25:48.360] One story I'll tell very quickly, and it's more of an appeal. [25:48.880 --> 25:52.880] We did a pen test for this thing called the MSRC. [25:53.200 --> 25:54.780] It's up there in small print. [25:55.000 --> 26:01.280] But it was on Wright-Patterson Air Force Base, but it was run by the Army at the time. [26:01.540 --> 26:11.920] They had all the different supercomputers of the day in one place and they were learning how to do all sorts of crazy stuff like visualization and 3D graphics. [26:12.260 --> 26:17.500] All the stuff we take for granted these days on our smartphones, they were doing it on mainframes. [26:17.920 --> 26:19.660] They hired us to do a pen test. [26:20.380 --> 26:23.260] And after the first day, we got a call from them. [26:23.520 --> 26:33.860] And apparently, the Army who was running this facility forgot to mention to the Air Force, who was hosting the Air Force, you know, the base, as well as the Internet. [26:34.060 --> 26:37.180] They forgot to tell them that they hired people to do a pen test. [26:37.420 --> 26:41.020] So there was an Air Force cert advisory issued against us. [26:42.740 --> 26:46.420] I have not... I wish I had kept it because it would be a great slide. [26:46.480 --> 26:49.720] And because it was Air Force, it was considered classified. [26:50.020 --> 26:58.340] So, like, I've gone to the Wayback Machine, and I found the page where there's a link to where the thing is, but they haven't cataloged that. [26:59.060 --> 27:07.840] So if anybody knows anybody that has captured, you know, for posterity's sake, Air Force cert advisories, would love to talk to you. [27:09.820 --> 27:11.560] Got to check my tongue. [27:11.740 --> 27:12.640] Yeah, I got to go faster. [27:13.120 --> 27:15.320] We went to work for a company called DigX. [27:15.460 --> 27:22.260] They were an Internet service provider, a hosting provider, back in the day when everything was hardware-based, and they had thousands and thousands of clients. [27:22.260 --> 27:26.780] And we were hired by them to do work with a lot of their clients. [27:27.080 --> 27:31.040] We were branded on their marketing literature. [27:31.520 --> 27:36.720] The one thing we didn't do, though, was firewall installations because that was about the only work that could be done back then. [27:36.900 --> 27:40.960] We farmed that out to another company, a subcontractor. [27:41.180 --> 27:48.180] That company was called RipTech, that was run by a guy named Amit Yoran, who's now CEO of Tenable. [27:48.380 --> 27:50.480] It's a weird little turn of events there. [27:52.880 --> 27:57.960] The company DigX got acquired by a company called Intermedia. [27:58.400 --> 28:11.700] The guy that had started DigX, a guy named Chris McCleary, after he served his time as intermediary, he started what was more or less a cloud provider company, U.S. Internetworking. [28:13.280 --> 28:15.640] We got branded and all that kind of stuff. [28:15.640 --> 28:20.100] But I'll tell you very quickly, my favorite pen test of all time was against USI. [28:20.500 --> 28:25.160] And again, I found the actual pen test report in my cleanup activities. [28:25.900 --> 28:28.300] So this is 1998, September. [28:28.980 --> 28:29.740] So what is that? [28:29.840 --> 28:30.840] 26 years ago. [28:31.140 --> 28:38.460] They hired us to spend a weekend, try to get in and do as much, not damage, but get as far as we could. [28:39.900 --> 28:42.060] Notice that we said, yeah, we got in. [28:42.280 --> 28:44.360] The firewall didn't really stop us. [28:45.160 --> 28:48.260] We go on, we talk about the kind of things that we did. [28:48.940 --> 28:56.000] And down at the bottom, you'll see that we got in primarily because of the misconfigured Microsoft SQL Server. [28:56.140 --> 28:56.820] So what did we do? [28:58.220 --> 28:59.020] SQL injection. [28:59.320 --> 29:00.760] We didn't call it that back then. [29:01.040 --> 29:02.140] But that's what we did. [29:02.280 --> 29:03.520] That's how we got in. [29:03.640 --> 29:05.480] We were able to crack a bunch of passwords. [29:05.480 --> 29:07.460] Look at all those great passwords back then. [29:09.280 --> 29:12.780] And we were even doing Windows passwords. [29:13.080 --> 29:14.340] So there are some Windows passwords. [29:16.520 --> 29:24.300] Another irony of all of this story is Ron Gula, who was in the picture of the pit, he had gone out into the private sector. [29:24.440 --> 29:26.400] He was working at USA at the time. [29:26.580 --> 29:33.820] He was so fed up with the fact that RealSecure had done such a poor job of detecting us because we got in undetected. [29:33.820 --> 29:36.620] We ran amok on the inside undetected. [29:36.940 --> 29:42.580] He went off and started his own company, wrote his own software called Dragon Intrusion Detection System. [29:44.180 --> 29:46.700] It's kind of similar to Snort. [29:47.020 --> 29:48.320] There's a different story there. [29:48.680 --> 29:54.120] But like everything else, his company was acquired after about 18 months. [29:54.120 --> 29:57.700] And he took the proceeds and ended up starting Tenable Network Security. [29:58.280 --> 30:02.020] So I have the role in a lot of people being very successful. [30:02.020 --> 30:04.380] It's one of the morals to the story here. [30:05.740 --> 30:07.700] I got most of our team. [30:07.700 --> 30:12.400] We got kind of bit by the dot-com bug and we went to work for a company called Meta Security Group. [30:13.220 --> 30:15.240] Not a whole lot to say about that experience. [30:15.900 --> 30:20.280] We had an identity crisis because we kept rebranding what our name was. [30:20.740 --> 30:22.680] We were there during 9-11. [30:22.680 --> 30:23.860] That's when that happened. [30:24.260 --> 30:30.060] Which, if you remember that time, that was an amazing time from a cybersecurity perspective. [30:31.020 --> 30:36.860] Because a lot of our customers started saying, Oh, you mean all that stuff you're talking about that could happen to us? [30:37.240 --> 30:38.740] Really could happen to us? [30:38.840 --> 30:40.240] Because, you know, we would point at that. [30:40.420 --> 30:45.660] And it was an amazing time because our companies paid attention for probably a good eight or nine months. [30:48.360 --> 30:49.320] Think about it. [30:50.840 --> 30:55.100] One of the guys that worked for us went on to start a company called InGuardians. [30:56.240 --> 31:02.680] A couple of the guys on our team, they're responsible for doing the Crack Me If You Can contest out at DEF CON. [31:03.440 --> 31:07.500] One of the guys from our team is on the review board for Black Hat. [31:08.860 --> 31:18.240] But I got to a point where I sort of got to a crossroads because as a person, I was frustrated that I had customers that we would pen test. [31:18.420 --> 31:19.020] We'd break in. [31:19.140 --> 31:20.280] We'd tell them how we did it. [31:20.520 --> 31:22.480] We'd tell them what they need to do to fix it. [31:22.640 --> 31:26.860] We'd come back six months later and everything was the same. [31:27.060 --> 31:33.960] The exact same passwords, the exact same vulnerabilities and weaknesses, misconfigurations were still working. [31:35.300 --> 31:37.460] And that didn't satisfy me. [31:37.600 --> 31:43.280] I wanted to try to find a way to educate and explain to my clients, well, this is important. [31:43.640 --> 31:48.100] You need to do security right and think about it in a different way. [31:48.260 --> 31:51.120] Don't just think you can throw technology and think you're done. [31:52.400 --> 31:54.520] No offense to any technologist out there. [31:54.840 --> 32:01.180] So I ended up going to work for a company called Trustwave, which moments later became Amberon Trustwave. [32:01.180 --> 32:06.940] And Trustwave is the place where I was first introduced to PCI. [32:07.200 --> 32:11.940] And this is not going to be a huge PCI pitch, but 20 years ago it came out. [32:11.960 --> 32:24.980] It was based on six overall goals, which I paraphrase is secure your network, secure your data, keep everything secure, control access, do all the security things, and everything you do, write it down in a policy. [32:24.980 --> 32:27.120] That's the essence of PCI. [32:28.080 --> 32:36.140] Nobody can argue with me that that isn't what organizations and companies should do as a backbone of a security program. [32:37.120 --> 32:38.760] I became a QSA. [32:39.240 --> 32:41.980] These are some of my customers that I've had over the years. [32:41.980 --> 32:44.800] I would tell you stories, but I don't have time. [32:45.040 --> 32:50.880] Of course, PCI rolled out, 4.0 rolled out earlier this year, but nobody wants to talk about that. [32:50.880 --> 32:56.680] So, in the few minutes left, let me talk to you about what's been bothering me. [33:00.400 --> 33:04.040] What we were saying back then, and these are slides that we used... [33:04.040 --> 33:06.040] I think these slides are dated 1998. [33:07.520 --> 33:16.120] This is how we would go into organizations and try to convince them, you need to start thinking about information security, data security, network security, Internet security. [33:17.120 --> 33:18.960] These are some of the reasons why. [33:19.220 --> 33:21.980] And this is why things are bad. [33:21.980 --> 33:25.680] This is what you need to do to make things better and so on and so forth. [33:27.600 --> 33:30.980] We advertise that security is a lifecycle approach. [33:30.980 --> 33:33.500] It's something that you do on an ongoing basis. [33:33.540 --> 33:34.980] There's elements to it. [33:35.100 --> 33:35.940] There's different things. [33:36.120 --> 33:41.520] And of course, in those days, companies existed, but they were plugging into the Internet for the first time. [33:41.520 --> 33:45.880] So, it's kind of made sense to do a pen test and just sort of get a lay of the land. [33:49.020 --> 34:02.780] Personal dislike is that somehow pen testing has become the ultimate test, where in the beginning it was start off with the pen testing, but eventually pen testing should be the test to see how well you're doing security program. [34:03.220 --> 34:04.180] That's an aside. [34:05.480 --> 34:07.140] This is some of the things we said. [34:07.260 --> 34:09.840] And we said, you know, don't think it's just technology. [34:10.400 --> 34:15.740] It's not a matter of buying a bunch of blinky boxes and setting them in the right places and thinking you're done. [34:15.900 --> 34:17.360] You got to think through this stuff. [34:19.180 --> 34:19.980] It's really... [34:20.740 --> 34:24.820] We talked about having a policy, having a plan, having a strategy. [34:25.520 --> 34:29.900] Little things like, what is it that is valuable in your company that you want to protect? [34:30.120 --> 34:34.900] You'd be surprised how many organizations don't know or can't articulate that. [34:35.060 --> 34:43.640] Changing maybe a little bit these days, but back then it was mostly, well, we just don't want to get hacked and have our names on, back in those days, newspapers. [34:43.880 --> 34:48.180] You know, the front page of the New York Times or the front page of the Wall Street Journal. [34:48.460 --> 34:54.240] In modern terms, it would be, we don't want to show up in the next report from Krebs, that type of thing. [34:55.600 --> 35:05.240] We tried to explain to them as best as we could, you know, the pros and cons, what you're up against when you're trying to build a business case. [35:05.400 --> 35:13.120] Again, these slides are almost 30 years old, and I would argue they still stand 100% today for most organizations. [35:16.120 --> 35:18.380] I don't think you have to take notes or anything. [35:22.320 --> 35:28.120] Some of the reasons why security fails, management doesn't get it, the executives don't get it. [35:28.300 --> 35:35.600] We're still having arguments this day, you know, to this day about getting security into the boardroom, getting a seat at the table. [35:35.600 --> 35:43.820] We used to have lengthy arguments about where the security manager or what we call now a CISO, you know, who should they report to? [35:43.980 --> 35:45.860] How should the organizational structure look? [35:46.080 --> 35:48.000] I mean, we solved that a long time ago, right? [35:48.000 --> 35:49.440] We don't argue about that anymore. [35:50.640 --> 35:55.840] The fact that, you know, policies put in place need to be followed, the rules need to be followed. [35:56.100 --> 36:04.040] The worst offenders of all the policy rules throughout time have been admins, and the worst of the worst are the security people. [36:04.040 --> 36:06.060] Well, tell me I'm not wrong. [36:08.360 --> 36:12.620] And again, the idea that technology is going to solve all their problems. [36:12.800 --> 36:15.680] Go to a vendor conference like RSA. [36:16.000 --> 36:19.140] Probably some of us are going to be in DEFCON in a few weeks. [36:19.220 --> 36:20.940] And before DEFCON, there's Blackpat. [36:21.280 --> 36:22.760] It's all about the vendors. [36:22.940 --> 36:23.720] It's all about... [36:24.240 --> 36:26.880] I hate this term, but we call it solutions now. [36:26.920 --> 36:28.920] What have we actually ever solved? [36:29.260 --> 36:31.020] I don't know why we call them solutions. [36:31.900 --> 36:35.300] Anyway, but, you know, what do you have to do to make it work? [36:36.600 --> 36:38.200] That's the biggest one right there. [36:38.720 --> 36:39.380] You gotta... [36:39.380 --> 36:47.300] Everybody at every level needs to be humble and figure out what the ultimate goal or strategy is for security in an organization. [36:47.680 --> 36:50.620] And again, it goes back to it's a life cycle. [36:50.840 --> 37:02.960] When we were pitching this in the late 90s, we were telling companies that the life cycle, similar to like an engineering process back in those days or a software development process might be 12 to 15 months. [37:03.460 --> 37:04.940] Nowadays, it could be weeks. [37:05.160 --> 37:06.480] Nowadays, it could be days. [37:06.700 --> 37:07.920] Nowadays, it could be hours. [37:08.220 --> 37:09.060] But it's still... [37:09.060 --> 37:11.760] There's still a process there that needs to be followed. [37:12.300 --> 37:16.100] And of course, we weren't completely right as an industry back then. [37:16.100 --> 37:25.600] We used to talk about the secure perimeter and we would describe it as, you know, the crunchy exterior and the squishy interior. [37:25.900 --> 37:29.980] And the challenge for us as pen testers was just to get beyond that exterior. [37:30.260 --> 37:34.020] And once we were inside, pretty much everything was available. [37:34.020 --> 37:41.300] I mean, this was a concept that's based on military tactics and it made sense at the time, but it goes back, you know, a thousand years. [37:41.480 --> 37:56.540] This is an aerial view of a city that I think is in Italy that was built in like Renaissance times, medieval times, where, you know, the lord of the manor, he's going to be in the innermost part with lots of walls and layers of protection. [37:56.540 --> 38:01.340] And that's kind of how we brought the idea of security to the Internet. [38:01.620 --> 38:02.740] Worked for a little while. [38:02.920 --> 38:04.080] Doesn't work so much today. [38:05.080 --> 38:08.620] But of course, the problem was also that nobody was listening to us. [38:08.980 --> 38:11.440] These are slides from Meta Security Group. [38:12.440 --> 38:15.100] And these are the last couple of slides that I'll share with you. [38:15.240 --> 38:17.840] Just sort of as an object lesson or a lesson learned. [38:18.060 --> 38:21.800] These are the five worst security mistakes that end users make. [38:21.800 --> 38:28.020] I would argue with you, I mean, change things a little bit, but they're all pretty much true today, right? [38:29.280 --> 38:32.080] We don't talk about opening up attachments anymore. [38:32.080 --> 38:33.740] We talk about clicking on the fish. [38:34.020 --> 38:34.880] Still an issue. [38:36.240 --> 38:40.080] Patching has been a problem since the beginning of time. [38:42.300 --> 38:45.920] From a malware perspective, of course, we're defeating the backups. [38:46.180 --> 38:50.460] The bad guys are feeding the backups now for malware attacks and ransomware attacks. [38:50.460 --> 38:52.600] But these were problems then. [38:52.860 --> 38:54.180] These are still problems today. [38:55.180 --> 38:58.120] We don't do modems as much anymore, I hope. [38:58.460 --> 39:00.220] But I'm sure they're out there somewhere. [39:00.680 --> 39:11.160] But, you know, connecting to Wi-Fi, connecting to untrusted networks, networks that we connect to at home as we're working virtually, especially the last couple years. [39:12.820 --> 39:16.080] Seven worst mistakes executives make. [39:17.560 --> 39:18.780] They don't get it. [39:20.600 --> 39:22.900] They think technology is going to solve the problem. [39:23.100 --> 39:24.340] Just tell us what we need to buy. [39:24.500 --> 39:25.700] How much do we need to spend? [39:25.960 --> 39:26.600] Now go away. [39:28.860 --> 39:33.840] I don't know how many times I've had clients tell me, well, I don't know why we should worry about this. [39:34.080 --> 39:35.440] Nothing's happened yet. [39:35.440 --> 39:37.060] We've not had a problem yet. [39:37.060 --> 39:41.720] And then, you know, a day or a week or a month later, the bad stuff does happen. [39:42.440 --> 39:47.820] And then finally, the ten worst mistakes that the IT people make. [39:49.080 --> 39:51.100] I clicked on most of them. [39:56.260 --> 39:58.400] Anyway, this is all I'm learning. [39:58.880 --> 40:01.600] A trauma response, mostly. [40:02.780 --> 40:10.060] If you do happen to want to use these slides, I was glad to see that QR code on the previous talk. [40:10.420 --> 40:13.220] If you don't trust the QR code, that's the URL. [40:13.220 --> 40:25.040] But if you would like to take these slides back to your organization and say, look at this, it's like almost 30 years old, and we're still arguing about the same stuff, and we're still making the same mistakes. [40:25.760 --> 40:35.180] If for a change of pace you want to hear more of my story, I was interviewed a couple months ago on a podcast called The Team House. [40:35.420 --> 40:37.960] The guys that do it are actually over in Brooklyn. [40:38.220 --> 40:41.660] I was hoping to try to meet them this weekend, but I haven't connected with them yet. [40:41.660 --> 40:45.380] But there's an episode that's called The Team House. [40:46.240 --> 40:49.060] Just search Team House on YouTube and type in NSA. [40:49.060 --> 40:50.140] You should find it. [40:50.560 --> 40:55.560] And finally, if you're interested, I do have some stickers to give away. [40:57.060 --> 40:59.120] And if you're going to be at DEF CON, I'll have more. [40:59.300 --> 41:09.100] I feel bad that I've got only the third, because I had stickers for the first two talks, but I just ordered some, so I will have stickers for all three talks at DEF CON if you happen to be out there. [41:10.200 --> 41:17.420] And if there is any time left, and it looks like we have a few minutes, I'd be happy to field questions. [41:17.420 --> 41:22.660] If you ask me about NSA and Snowden, it's not going to work here, because I'd say, buy me a drink. [41:25.620 --> 41:26.720] We'll work something out. [41:26.860 --> 41:33.360] Anybody have a question, comment, want to agree or disagree with me on the state of the industry today? [41:43.150 --> 41:44.310] I think that's better. [41:46.490 --> 41:47.350] There it is. [41:48.690 --> 41:52.230] And thank you also for remembering Becky Bass. [41:52.550 --> 41:55.430] I wish that I had gotten the chance to know her. [41:56.390 --> 42:09.510] I was wondering if you could share, for those of us who want to both learn from the work that others have done, who have done a lot of work that often goes unacknowledged. [42:09.890 --> 42:21.910] Could you talk a little bit more about Becky, or maybe some other people who did a lot of work behind the scenes who are not often acknowledged today, that we should be acknowledging? [42:24.510 --> 42:26.810] Well, I'll talk a little bit about Becky. [42:28.470 --> 42:42.170] When we next had our gathering of curmudgeons, and there's about a dozen of us, we were reminiscing over Becky, and lamenting, and crying, and drinking, and hugging each other. [42:42.450 --> 42:47.210] And we were talking about how there was such a need for us to carry on her work. [42:47.630 --> 42:55.410] And at some point, we got really sad, because we were sitting around, and these are industry professionals, well-known people, they've done a lot. [42:55.410 --> 43:02.630] And we sort of recognized that us collectively could not fill her shoes. [43:02.910 --> 43:03.950] That's how much she did. [43:05.290 --> 43:14.290] Her website, which I think is still up, infidels.net, for a while they had a bunch of information about her and things like that. [43:15.110 --> 43:16.770] I think she had a book published. [43:17.090 --> 43:18.130] She was sort of... [43:18.130 --> 43:19.490] An IDS book. [43:19.790 --> 43:20.410] Thank you. [43:21.490 --> 43:22.570] Ask people that know. [43:22.710 --> 43:24.530] Which is still probably the best IDS book. [43:25.350 --> 43:26.110] out there. [43:26.410 --> 43:27.750] Yeah, I mean she was... [43:27.750 --> 43:34.910] Also a free NIST download, which was like an 80-page precise of the book. [43:35.270 --> 43:35.430] Right. [43:35.930 --> 43:43.290] Yeah, she's probably, for those that know her, I guess in the private sector, she was best known for sort of pioneering the idea of intrusion detection. [43:44.470 --> 43:46.110] It wasn't real secure. [43:46.430 --> 43:47.590] That's for... [43:47.590 --> 43:47.910] Yeah. [43:48.170 --> 43:48.710] A question. [43:49.050 --> 43:49.670] Yeah. [43:50.110 --> 43:56.890] So Marcus Ranum sort of famously gave this metaphor about pen testing. [43:56.890 --> 44:10.110] He said, it's like an old-fashioned voltmeter that has a needle and the scale says your security sucks at one end and don't know at the other end. [44:10.110 --> 44:16.030] And you pour money into the meter and then the needle settles somewhere in the middle. [44:16.210 --> 44:16.670] I like it. [44:16.690 --> 44:23.170] So the value of pen testing in providing assurance is, to my mind, roughly zero. [44:23.530 --> 44:29.990] I'd like to hear your thoughts on it since you seem to have spent a lot of your career promoting pen testing. [44:30.330 --> 44:36.930] Well, up to a point I promoted it and then I decided it's really not giving the result that people think it does. [44:37.890 --> 44:44.110] In the PCI world, you have a requirement to do a pen test annually and most people treat it as... [44:44.110 --> 44:49.130] and most of our world seems to treat a pen test these days. [44:49.750 --> 44:55.770] And when I say pen test, I'm sort of using that as an inclusive term because that's all we called it back then. [44:55.910 --> 45:00.210] I know that there's red teaming and blue teaming and purple teaming and all that. [45:00.810 --> 45:04.870] But pen testing, trying to break in from wherever, however. [45:06.510 --> 45:10.270] But it's become another way to discover vulnerabilities. [45:10.770 --> 45:29.450] And every pen test report I read is, in many cases, a glorified Nessus report with maybe a little commentary afterwards where by design, in the life cycle of security, and I apologize and I don't apologize for being a little bit PCI-centric. [45:30.170 --> 45:33.510] Vulnerability management in PCI is requirement five and six. [45:33.710 --> 45:40.970] It's anti-virus, anti-mileware, patching, change management, secure application development, training of your developers. [45:41.110 --> 45:44.750] That's what they consider vulnerability management, keeping everything secure. [45:45.210 --> 45:48.650] The vulnerability scan in pen test is way down in requirement 11. [45:48.890 --> 45:49.610] It's really... [45:49.610 --> 45:54.090] Scans are supposed to be a safety net because not everything gets the patches. [45:54.970 --> 45:57.430] Not everything's online at the same time. [45:57.430 --> 46:00.370] And then the pen test to me is the live fire test. [46:00.590 --> 46:03.410] And yeah, it's only as good as the time it's done. [46:03.410 --> 46:07.090] It's only as good for what you give them, the boundaries and the... [46:07.090 --> 46:07.290] Yeah. [46:07.390 --> 46:17.230] What I'm really trying to say is I'd rather spend the money on design review, selective code review, than on, you know, testing the quality. [46:17.230 --> 46:21.090] There's so many other things that you should be doing that should secure things. [46:21.430 --> 46:25.610] And the pen test, while it's not a guarantee, it should give you... [46:25.610 --> 46:27.410] I like the idea of the voltage meter. [46:27.670 --> 46:32.870] Would you mind identifying some of the other curmudgeons besides Becky and Spaff? [46:32.890 --> 46:33.410] Um... [46:33.410 --> 46:35.330] Gene Spafford, Jack Daniel. [46:36.190 --> 46:36.690] Um... [46:36.690 --> 46:37.450] The guy... [46:37.450 --> 46:38.670] You're not gonna remember it. [46:38.710 --> 46:40.350] I had my arm around a guy. [46:40.610 --> 46:44.670] He's actually the attorney that I worked with at NSA that... [46:44.670 --> 46:51.770] I haven't told the whole story of me being on double-secret probation, but he was my buddy up until he wasn't. [46:52.070 --> 46:53.210] And then he yelled at me. [46:53.410 --> 47:00.170] He was the one screaming at me and telling me that I had violated the NSA charter and I could get the director fired. [47:00.250 --> 47:05.230] I didn't talk to him for 20-some-odd years, but I ran into him at DEFCON a few years ago. [47:05.510 --> 47:07.850] And the first thing he said to me is, I forgive you. [47:07.930 --> 47:09.250] I'm like, why are you forgiving me? [47:09.250 --> 47:11.410] I've been pissed off at you for 20-some-odd years. [47:11.430 --> 47:15.110] He said, oh, because I got raked over the coals more than you did. [47:15.110 --> 47:16.450] I was providing air cover. [47:16.450 --> 47:18.310] They wanted to prosecute you. [47:18.890 --> 47:24.890] So I gave a talk several years ago at B-Sides, Las Vegas, on their underground track. [47:25.070 --> 47:27.950] It was titled, I was the first Edward Snowden. [47:28.130 --> 47:32.190] The first time I heard about the church proceedings was when this guy was yelling at me. [47:32.390 --> 47:38.470] The second time, when Snowden was in the news, I saw somebody referencing the church proceedings. [47:38.610 --> 47:39.470] And who is that guy? [47:40.570 --> 47:41.450] Who was... [47:41.450 --> 47:43.510] Oh, his name is Rich Marshall. [47:47.250 --> 47:49.570] Other names escaped me, and we're running out of time. [47:49.710 --> 47:50.810] Let me get the one more question. [47:50.970 --> 47:51.690] We can talk later. [47:52.290 --> 47:52.430] Yep. [47:53.190 --> 47:53.810] Oh, I'm sorry. [47:54.330 --> 47:55.710] There's more microphones. [47:55.930 --> 47:56.450] I apologize. [47:58.710 --> 48:00.330] If you ran over here, this one's on. [48:02.870 --> 48:05.310] Wait, there was a wireless mic this whole time? [48:06.530 --> 48:07.070] Thank you. [48:07.250 --> 48:08.530] I hate standing behind a podium. [48:08.550 --> 48:16.350] Since it seems like you've had quite this illustrious career in pen testing and kind of creating the industry, what would you say to someone who's interested in doing that as a career, like today? [48:17.250 --> 48:23.170] What I say to many people that approach me about this, there's a lot of stuff you can do in this industry. [48:25.470 --> 48:27.450] Find something that you like to do. [48:27.610 --> 48:28.350] Try everything. [48:31.210 --> 48:34.230] Hopefully you'll find something that you enjoy doing and like doing. [48:34.230 --> 48:35.010] Do that. [48:35.610 --> 48:42.110] Also look for things that you seem to have an aptitude or a talent for or maybe a potential for or something just interests you. [48:42.310 --> 48:46.910] If you're really, really lucky, what you're good at and what you like to do will be the same thing. [48:47.090 --> 48:47.470] Do that. [48:47.750 --> 48:53.870] I know everybody has to pay the mortgage and the rent and all that kind of stuff, but I'd say this to anybody. [48:54.670 --> 48:59.510] Find something you like and enjoy doing if you can and do that and hopefully you'll get paid to do it. [48:59.770 --> 49:00.510] And that's gravy. [49:00.810 --> 49:02.350] If not, do the best you can. [49:02.850 --> 49:14.930] But it's a tough question to answer and I don't want to discourage you, but if you're talented and you're sharp and you're curious and hungry, you'll find something. [49:15.170 --> 49:15.750] So keep digging. [49:15.910 --> 49:22.050] That's the essence of being a hacker anyway is the curiosity and the digging trying to find stuff. [49:22.470 --> 49:23.070] Okay? [49:23.390 --> 49:23.990] You're welcome. [49:24.930 --> 49:25.710] One more. [49:26.690 --> 49:28.650] Hopefully it should be relatively short. [49:28.970 --> 49:39.750] I don't know why I suffer PCI at work and then spend my own free time and money to go to a conference where I just think more about PCI and end up asking questions about it. [49:39.870 --> 49:50.050] But I saw that you were in on the PCI standards from the start and so I'm pretty curious, do you have experience with any of the other PCI standards besides DSS? [49:50.210 --> 50:02.510] I know DSS gets the most attention in general, but I have the most experience with PTS, which generally very little is known about since that concerns device security itself and most people don't deal with that. [50:02.510 --> 50:09.070] In the interest of time and not wanting to word the rest of the audience, look for me after the talk. [50:09.210 --> 50:09.490] How's that? [50:09.750 --> 50:10.390] Excellent, thank you. [50:10.730 --> 50:11.630] Alright, thanks everybody.