AI Will Save Us, or Not? - PSW #945
Get every episode summarized
Each time Security Weekly Podcast Network (Audio) publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
About this episode
“In the security news this week, build your own router or just buy one. The AI slow down won't save bad security.”From the transcript
In the security news this week:
- Build your own router, or just buy one
- What to patch first
- But maybe don't buy D-Link
- AI nearly starts a war
- Flock cameras lose their keys
- The AI slowdown won’t save bad security
- Opus at home, just slower
- Black Hat says fundamentals still work
- Hacker gadgets, and my top pick
- Gyazo screenshots
- Fake job interviews, real malware
- VINCE gets a new home
- Munich university gets disconnected
- LinkedIn fights the scraping machine
- SolarWinds hard-codes another bad idea
- Fake LastPass kills 145 security tools
- Colorado water gets its settings changed
- AI CEOs sell apocalypse and bonds
- The AI safety cult gets audited
- Ransomware recovery takes weeks, not hours
- TeamPCP’s supply-chain tour continues
- Zuckoff hunts smart glasses
Visit https://www.securityweekly.com/psw for all the latest episodes!
Show Notes: https://securityweekly.com/psw-945
Get every episode summarized
Each time Security Weekly Podcast Network (Audio) publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Transcript ready
1,995 searchable segments. Every word is indexed and playable.
Full transcript
Security Weekly Podcast Network (Audio) — AI Will Save Us, or Not? - PSW #945. Machine-transcribed; use the interactive transcript above to jump the player to any line.
In the security news this week, build your own router or just buy one. What to patch first? But maybe don't buy Dealing. AI nearly starts a war. Flot cameras lose their keys. The AI slow down won't save bad security. Opposite home, just slower. Black Hat says fundamentals still work. Hacker gadgets in my top pick. Gaiazzo screenshots. Fake job interviews, real malware. Vince gets a new home. Civic University gets disconnected. LinkedIn fights the scraping machine. Good luck with that. SolarWinds hard codes another bad idea. Fake last pass kills 145 security tools. Colorado water gets its settings changed. AI CEOs sell apocalypse and bonds. The AI safety cult gets audited. Ransomware recovery takes weeks, not hours. Team PCP's supply chain tour continues. Zachov Hunt smart glasses. All that and more. On this episode of Paul Security Weekly.
Broadcasting live from G-Unit Studios in Rhode Island. It's the show where exploits run wild. Packets aren't the only things getting sniffed. And the cocktails flow steady. It's Paul Security Weekly. Coming to you from Hacker Syndicate Studios. This is Paul Security Weekly. It is episode number 945 being recorded on Wednesday, September 23, 2026. I'm Paul Sodorian, joined by Mr. Josh Marpett. Josh, welcome. Hey, it is always wonderful to be here. Paul with you in this distinguished crowd of ruffians. Yes. Another ruffian with us. Mr. Dave Johnson is here. Hey, how's it going? It's good to see everybody. Looking ruffian as usual. Mr. Lee Neely is here. Yes, now we're turning from a right around Disneyland. It's me. Back at him. Ready to have some fun. Mr. Sanbound is here with us. Good evening. Glad to be here. A couple of quick announcements. Before we dig into it, Maryx decided to talk about a lot
of the things we have on our list today, all of them, in fact. In September, the identity virtual cybersecurity summits will be taking place. Because attackers aren't breaking in. They're logging in. MFA fatigue, token theft, and lateral movement through identity are real problems in modern environments. So how do you catch it? Well, the identity virtual cybersecurity summit on September 30, learn how to detect identity-based attacks, reduce privilege, sprawl, and improve visibility across your environment. Security Weekly listeners can register for free at securityweekly.com, forward slash identity using the promo code CSS26-SW. Also don't forget, InfoSec World is upon us very soon. They're introducing a fresh experience for 2026 with new voices, a new venue, and new topics reflecting the challenges security teams are facing now. Join practitioners and leading professionals
from across industries in Orlando, October 12 through the 14th. Listeners save 30% on their pass with the code ISW26-SW savings at securityweekly.com, forward slash InfoSec World 2026. All of that is of course in our show notes. As well as all of the stories and articles, news, and other relevant topics that we will be discussing this evening is in the show notes. I would like to start because it goes in order. And if I feel like I don't start with this one first, I'll forget. But I read an article actually like, right before the show, my chair feels off. I'm sorry. So I read this article right before the show. And it was a DIY router on x86 e-waste using open work and open sense. But I don't think you can run. It's either one or the other.
But so e-waste is like older PCs that people are throwing out, which I'm sure you can still get today. I was looking at the all in one iMacs. A lot of schools are getting rid of those. Those are going end of support. I was talking to one of my friends who's got a photography business on the side. And he was like, yeah, he's like, I'm not getting more updates for it. It's like that usually means it's time to upgrade my hardware, which is very smart. When Apple's part, I think they time it very nicely, especially for their audience, like photographers. Like, yeah, I was probably time to upgrade anyway. So we have all this e-waste floating around. We always have for some time. But I'm not sure I would use old e-waste for my firewall at my home. We've covered this before. I've done it. There's a lot of things that can break. Power supplies, fans, cooling, old disks, things like that. It takes up a lot of room. And typically, they only have one ethernet adapter.
So I did some research with AI. It did an OK job. I'm not in the market for a new firewall. So this is for purely academic purposes in the benefit of our audience. I would recommend a fabulous mini PC. Now, interesting. We were just talking about hardware prices before the show. These are also affected because typically, you buy these in like a bare bones, and you have to add your own RAM and storage, which is very expensive right now. So now I get why Hackaday is running the article on using e-waste, because like to cut down to the chase, basically, the e-waste PC you get for free, even if you have to do some upgrades, or especially if you have hardware laying around, even DDR3 RAM. This is perfectly acceptable. I mean, you're going to push full gig, probably not. But if you've got like 150 up and down, you can totally use an old PC for this. But make sure you note my caveat points that at the top of this article of things that can go wrong.
It was interesting in the fanless mini PC. So this is my other big takeaway. Fanless mini PC, protectly, top-ton, N150, and cotom, solid options. The latter of the two are very much Chinese manufacturers. No warranty, no claims. Probably won't get a UEFI BIOS update from them in my experience either. But they're sitting for something you actually runs is between $305, $100 easily. The Intel N100 is a nice platform. Not as great hardware support. I did kind of tell AI, I want to run OpenSense. So the hardware has to support Linux, which sometimes gets rid of Wi-Fi adapters, Ethernet cards, and certain CPU support features and things like that. But when I came down to what I think was Cloud, I ran this through two different frontier models. What I though is interesting is you can buy the smallest Cloud
Gateway from Ubiquity for $129. You can push gig easily with that. If you want to add an access point to that, it's that would bring the cost up to around $247. Now we're not sponsored by Ubiquity. However, it is my recommendation. I get it. It's more expensive than a free EWACE PC. And if you're really on a tight budget, that could definitely work, especially if you or your friends maybe like us have a lot of hardware laying around. It would probably help you out with that. But I would go with Ubiquity for so many reasons that we've talked about on the show. I think there's a big reason why if you talk amongst us and people like us, a lot of us run Ubiquity. So there's lots of resources to that. And $129. I mean, again, that's not going to eat Wi-Fi, but $129. Why wouldn't you just run the Ubiquity router? Says the man who wrote the book with Larry on WRT54GL routers and speaks volumes. Which speaks about, now, if you want to do it to learn,
if you really want to tinker, you want to customize, you want to do, that's great and you should do that. However, I think many of us look at our own, no, there's the book. Yep, told you I got it. Thank you for that, Dave. But our internet, especially when you start having kids, is critical infrastructure in your home. I actually just put in Anchor Solix battery backup as my battery backup to run all of my gear, the switch, the router, the ONT, the firewall, the access points with the PUE injectors. And the Anchor Solix app tells me I can run for 45 days on backup power. And that's how critical the internet stuff is. Yeah, do I like to tinker with it? I have, have I made my own firewalls before? Absolutely. The studio used to run on families, many PCs that I built. But given prices now in the current state of things, 129 bucks is outstanding, in my opinion,
for a solid platform. You guys agree? Disgrace? Oh, I think you're right. If you want to play with OpenWRT, go get an old, links us for 50 bucks. I mean, Sure. And if you want to, I mean, yeah, but for 129 bucks, I mean, I a new one, you know, I mean, why deal with bulging capacitors and lower throughput and or potentially a ghost in the machine has a wonky hardware? Right. That's, I mean, it is cool to take a bunch of parts and turn them into something really cool. And don't, don't give me wrong. I'm just thinking, but if that's going to be your, I don't know, your router, maybe once things that's going to just be there. Yeah, I clearly, you know, take your, take your ubiquity, put it on the edge. And then if you want to segment internally, then tinker with the firewalls and then tinker around. So I see, I see your battery and radio in my Generaq. We had a power outage for two hours yesterday.
My generator, my, my UPS is only ran for about, I don't know, 39 seconds, maybe less. That's great. But I have enough, I have enough UPS to go quite longer in case the generated fails to launch. But yeah, I'm, I'm trying to get off topic a little, but the anchor solics line is really appealing. Oh, they are cool. Yeah, I don't think it's budget. I don't think it's like a price thing. I just think they're really cool. I think I could have a smaller solar panel array with some anchor solics and have a really good power backup solution for my home. Pro tip. Oh, go ahead, sir. Go ahead, tip. Pro tip, both anchor and eco-flow have eBay stores where all their refurbries are sold. Oh, nice. So you can get those way cheaper too. Yeah. And you can use generic panel. I was doing some research. You can use any solar panels. They don't have to come from anchor. Some people were, were big fans on Reddit of the ones that are just sold on Amazon that would work perfectly fine.
So zero trust is clearly the future as threats get faster, quieter, and harder to detect. But implementing it shouldn't disrupt the business. Threat locker enforces default deny at execution in a way that remains enterprise-ready, scalable and operationally clean. Unknown software has stopped cold, trusted app stay contained, and drift is locked down across the environment. It's zero trust that works in real enterprises and prepares you for the threats ahead. CYC'sos are adopting it at securityweekly.com, forward slash threat locker. So I, what I appreciate about this is so much of the technology that I started out with was free dumpstered-ived technology. That was not designed to do what I was doing it was. And so the person with zero budget, like we have been at some point in our lives, is going to look at this and go, hey, I've got this random thing somebody gave me I didn't know what to do with. Now I have a purpose for it potentially. I love pushing the envelope of stuff like this.
You found a special purpose as far. I'm still that way. I still check the auction sites and Facebook marketplace and everything else. Now I'm in this a bit within 30 miles of me has nine tough book tie style laptops for 50 bucks. Holy cow. Those still work. Well, no, they're the newer versions. And it's a different manufacturer, but they're styled like that. And it's like, oh, I don't need them. I have no desire for them. But they were freaking cool. Yeah. They were. And so it's one of them, it's got a screen, it's got a keyboard, it's got a trackpad. So you could turn them into a router, an open-work router, open-sense router, no problem. But yeah, and you put a USB-C to one gig adapter in there and you've got two nicks. Sure, but you're right. It's, but so the capability of people to do find cheap hardware that is coming from a reputable source like a police department. I mean, hell, one of my AI boxes is an old thread forensic box.
And I got it for $865 with 128 gigs of RAM, DDR4 RAM, which by the way, try to buy that right now with bloody luck. Yeah. And I9 and a ridiculous amount of NVMEs in it, because that was all their storage look to image drives with. And I stuck to water blocked 30, 90s in it and started putting agents on it. It's great. It's only my, I only have 130, 90, but it's an I9 with 128 gigs of RAM, but it was the former video editing station for security weekly. And it probably cost us, but even before prices went up with the card, it was probably a $4,000 PC to build. I mean, that's everything from scratch. At the time when it was pretty new, right? And that's when I'm running my local AI models on. Right. So it makes no windows, so it'll run basically indefinitely.
Yeah. And do you know why these threads are, by the way, I know somebody else that bought a Fred from another police department, the forensic workstation. The HTCI threads are getting rid of because the older ones can't upgrade to Windows 11. Right. No. So it's a $20,000 machine that I got for less than 900 bucks. Wow. That has to hurt. I'm not coming. I'm new. I'm at, I'm taking you by the $20,000 machine. And now you can't go to the new OS. You got to buy another one. But hey, when for you, hey, I'll put Linux on anything these days. Yeah, I want to, and I want to come back to that, but I think Sam has to drop before the end of the show. Let's do Sam stories. It will. I actually wanted to get, so like I have a take on this story, but like don't pay attention to it because Sam's take is going to be way better. It's my story number nine. It says quantum computers are not a threat to 128-bit symmetric keys.
And the researcher is arguing that quantum computers do not require organizations to replace AES 128. Shaw 256, but Shaw 256 was in play for Fortabled. We're able to break those without quantum computers, which was interesting. Or other 128-bit symmetric photography with 256-bit versions, who's we get into, I love all the algorithms, right? Because I learn about them and then I forget. Shaw's algorithm creates an urgent threat to public key systems, such as RSA and others. But Grover's algorithm does not make brute forcing AES 128 practical because the attack requires enormous serial quantum computation does not paralyze efficiently. I think we've touched on this before Sam. So I want to get your take on it. This is not new, right? No, it's not. The statement that was made years ago is that AES 128 might fall because in principle, a quantum computer can do it
in two to the 64 calculations. But AES 256 will not fall because it was still needed to do two to the 128 calculations and that's an unthinkable number that could never be done. And the point here is the earlier statement that in principle, it could be done when two to the 64 computations made it sound possibly doable. But what this guy has been saying for, I think the last year or two, is that in practice, there are other obstacles so that wouldn't really be practical either. And this is not really a surprise. I mean, when you're projecting a possible threat of a computer that doesn't exist yet, you settle for a very rough approximation of what it can do. And it turns out that even though in principle, you could do the two to the 64 operations in time less than the age of the universe, the hardware would have to be a lot better than the hardware you're gonna have. Yeah, yeah. It's just not feasible to build the hardware. Well, it just depends on how super secure you wanna be with your cryptography. You know, cryptographers would like to have
an astronomical level of security where all the computers in the universe given all the time in the universe couldn't get in. And AES 128 probably won't have that level of security anymore, but AES 256 will. But for all practical purposes, they're probably both fine for the foreseeable future. Yeah. Yeah, it's more policy-eating. Just, you know, cryptographers spoil us in thinking you can have this unthinkable level of safety. And of course, it's all nonsense because cryptography can only protect you so much. You can just sneak a camera in the room and get the message before it's encrypted, you know. All you do is you block one kind of attack with cryptography. There's always another attack that'll get the secret. There are cryptographic attacks. Yeah. That work. On some systems. And there are some systems that have no no cryptographic attack, and even a pretty good argument that there never will be a cryptographic attack like AES 256 appears to be that way. Well, yeah, I mean, what do you compromise as the key?
You don't compromise the algorithm. Right, that's right. Well, as you know, all the systems like, you know, web turns out you didn't even need to know the key. There's a back door in. Yeah. And as far as we can tell, there is no back door into AES. There is not. But then there's also just like rainbow tables or dictionary brute forcing, which is that you consider. But you know, these ones, those are so big that you never have enough RAM and enough time to do them. So how do they break the shot 256 hashed passwords in fordably? They use the GPU cracking rig of some kind, and I thought it was similar to a rainbow table. Well, I would assume that's probably just a dictionary attack. Yes. How has cracking works? So it's a hashed password. If the thing you hashed was really like 20 random characters, it wouldn't work. It's only going to work if the thing you hashed is in some table of 100 billion possible passwords or something. I got you. So that's feasible today.
Not 100% success guaranteed. Well, that's because you didn't really exploit all that entropy. You know, if you really use the 20 or 30 character random input, then it would be uncrackable. So it comes down to people choosing good past phrases in this case. For example, if you made these keys from like dictionary words, then they would also be crackable the same way. Yeah. So I'm what fordably did is they took advantage of the fact that there are a couple of different JavaScript. They used it. They used it weaker one. And then they leveraged some configuration information that yielded enough information about the key that they were able to take at the rest of the way. It wasn't. What I guess what I'm backing into is it's an implementation flaw, not an algorithm flaw. I see. I think there was some key artifact or something that were deriving from the configuration in the Fort O.S.
Yeah. And the fix was to implement the new, what is it, the PKDF? PVKDF2? Did I say that right? What Paul said. Yeah. Basically, the more robust algorithm. And of course, not keep that stupid artifact. But anyway, that was the issue. It's funny when we're talking about encryption. In the fordably situation, I thought the interesting part was that the old, SHA256 hashed password was still in the backup configuration, even though your password was PVKDF2 encrypted, it still kept the old one. And the thread actors in this campaign actually grabbed the cached copy of the backup configuration file. It still remains, I think, one of the really interesting campaigns. And I'm not picking on, I'm not picking on, I'm not picking on, I'm not picking on, but the way that attack played out was just super, super interesting. And I keep coming back to it as examples,
because a lot of stuff we still, you know, we do today is exemplified in that campaign. You know, if you really, if you really want to raise the bar and have plenty of money to spend, just go get yourself a type one encrypted pair. Okay. So, I have a type one encrypted pair. Of course, you'll need some crypto officers and a few other things. No, no, good dear God, man. Oh, God. If you really want to just make things encrypted, just get yourself a patternizer. Okay. Okay. Come on. I have a number of type one encryption. Sim, I want to go to your story number one. Yeah. Because this, you actually use the word narrative in here. And I think there's a narrative that, when we see, I start a couple of videos of people's opinions on this, and I think it's, I think there's a lot of fud surrounding AI today. I think that, specifically,
andthropic and open AI are severely overvalued. I don't think they're making any money. And I think when we see two things that have happened, one, these AI models that run out of control and start taking over things, and we see developers that helped build those systems, those AI systems, leave the company and say, well, the AI got too dangerous, and therefore I don't want to work on it anymore. I'm like, wait a minute. You helped build it. Aren't you like the best person to help contain it and make it safe? Like, why are you leaving? I think quite frankly, my opinion is, both those things are fud to get money still flowing into the big AI companies. They go, look, AI art, art is so dangerous, it's so good that it just starts taking over things, and it's so good that the engineer is working on it and are leaving, saying it's too dangerous it's going to take over all of humanity.
I don't think either of those things, we all use AI, except for Jeff, very heavily. I don't think either of those things are necessarily true in certainly a lot of different contexts. No, I mean, I think the statement that AI is going to kill the human race is just garbage. It's no more true than pornography or telephones or video games or any of those things we're going to have and didn't human race. It's just another technological advancement, but there are various people find it convenient to say this. Now, some of them are cynical like you say. They say it to prop up their stock price to make it self-seem important. But I think actually the other part, which is in my story number two, is a lot of them actually believe this stuff because they're in a religious cult that believes a whole bunch of science fiction that pretty soon we're going to have AI robots that will do all the work and they'll have robot brains that will move our consciousness into so we'll live forever and we'll go live on Mars in a utopia and we have to bring this about
and they really believe this stuff and they're trying to bring about a positive change. That was the Batman and Superman cartoon clip that I sent everyone. There's a clip from one of the old cartoons where the scientist builds exactly that. He's like, hey, computer's going to replace all the hard work and replace everything and humans just get to sit around and eat fudge and do whatever. And they were like, wait, that's not right. Even whenever that cartoon was produced, people knew like that that shouldn't have. They believe this stuff. Three years ago, open AI hired people and they had to stand in chat, feel the AGI, feel the AGI. And by the way, this is not that new. Remember, IBM had the special socks and the hymnolful of company songs. You had to go on the repeat to be intense seeing the official songs praising IBM. Yes, and McDonald's did it and Microsoft did it. I mean, a lot of businesses are cults
and they force you to believe a bunch of semi-religious stuff about how they're saving the world. And it's big in Silicon Valley. And what's crazy about that is it trickles into popular culture and sometimes belief. So now, friends that I have that don't work in tech, like, I was watching the news and I'm sure all of you get this question too. They're like, is AI going to take over the world and like erase humanity? Like, hey, hey, hey, I only got to my world every day. Hold up. I'm still trying to get it to write more like me, let alone it going off the rails and taking over humanity. So like, let's, let's, let's reel the reins in on this. So we were channel surfing this afternoon to kill some time and TMC had the, had the authoritative documentary forbidden planet on. There you go. I mean, because obviously that's how it's going to work with Robbie the robot. I mean, the, the internet was supposed to end civilization as well. And we've used it for cat videos. Like, we go true.
So, so I joking, dog videos would be all over but cat videos. You got a problem with cat videos, Dave? You got a problem with cat videos joking aside. You know, the internet has the capability to revolutionize the entire human race way more than we're using it for. Reason why it hasn't is because we're inefficient by nature or economies do not, are not driven by efficiency or effectiveness. And I predict that AI is going to succumb to similar problems or challenges or solutions. It depends on how you look at it. You know, I would argue in parallel with what Dave is saying that it's, it's got to find its useful niche. I mean, you know, all kid, I mean, what a, look what, look what the internet did for porn and gaming. I mean, it gave me the hell of a shot in the arm. It really boosted that industry. I'm not, regardless of how you feel about it, I mean, you could do the same thing. And look what, give something a shot in the arm that needs it. And look what porn and gaming did for the internet. I mean, I'm sorry. So it's a, yeah, it's a two-way street there.
A hundred percent. It is very much a two-way street. The hand gestures are wrong. We start talking about porn anyways. It's, uh, it's a lot of, there's a lot of aspects that they were glossing over as well. Yeah. If you read up on the porn industry. So let me talk about where it's gone, where it was heading. And, you know, there's a great, there's some great documentaries actually on Netflix about what's the parent company in a porn hub? Hmm. Like that, that technology is sometimes enables, I mean, it's like cryptocurrency. Sometimes a technology enables so much on ethical or immoral things to happen that we do have to reel the reins on it. It's interesting. We do have the problem with AI in the deepfakes, certainly. It seems to be somewhat compartmentalized to that. And the problems we have with AI is how it impacts the rest of society. Great article of Case in Point is one of my articles
on how it almost started a war. Yeah. I mean, this literally goes back to the beginning of computing. It goes back to war games. 100 percent. And it's like, it's like, did no one like watch war games? Do we not? Literally, literally. But, there's just so much top 10, an over reliance. People believe what the computer says unquestioningly when it doesn't really deserve that faith. My story number four. In AI hallucination, nearly triggered a US-China military confrontation. So, an AI-generated intelligence report reportedly falsely identified nuclear weapons components aboard a Chinese ship during the Iran War, nearly triggering a US military interception. It gets even closer than that. The report came from two AI assisted steps with no meaningful verification in between. And the article says military aircraft were already airborne before the intelligence
was challenged. How is the danger of confident AI errors entering targeting? Military decision-making systems faster than humans can validate them. I mean, that's the premise of the movie war games. Yeah. Although without the comment about it, it's basically commercial software with lipstick on it. I love that comment in the middle of that article. Yeah. I mean, that's not for formality, certainly. No. No. My first reaction is the male military character in the AI-generated image of this article looks like Sean Williams Scott. Anybody else see that? Stiffler? No. Looks a lot like him. Oh, ironically, they used like a... You couldn't not look at that image and tell me that it's not AI-generated. It's such an AI image. Yeah, the whole AI image. I do want to back. I think they did it on purpose. Other than Stiffler, and talk about AI and P Doom for just a minute.
So you're familiar with P Doom, right? I'm sure. P Doom. No. Oh, P Doom is the probability that you believe that AI will destroy the world or at least humanity. Okay. Okay. And various sources rate P Doom at anywhere from five to 100%. So it's a pretty broad range. Most people think it's about 20 to 30% that I know of. Okay. That's still pretty high for something that could wipe out humanity. So that's a 20 to 30% what? In one year, a hundred years. What? Over the next various, but within our lifetime years. That's a really big dump. According to the Wikipedia article, they're setting it at 100% median value of... Okay. So 100 years, five percent. I feel better about that now. Although I'll be honest, I think the real danger is in the next 10 to 15 years. Well, we give more control to AI without less.
You know, we ought to define what Doom is. I agree. Humanity goes by. How many people have to die for it to be Doom? If it's one percent, then COVID was Doom. No, I think we're going to have to die for it to be Doom. If it's one percent, then COVID was Doom. No, I think we're talking all of them. Killing all of us is almost impossible. This was actually in one of the videos I watched where she talked about. They're saying extinction of the human race. And there are still tribes that have no internet at all, no technology at all. And are far away. You wouldn't even release them with an engineered virus. I mean, killing everybody is damn near impossible. Okay. Also, there's still a lot of physical safeguards to many of our systems. It's not like AI is the first cyber adversary we've had to deal with to have these physical safeguards in place. I would be no, not at all. I think we just do normal security controls.
Yes, no. Like sandboxes that don't leak and monitoring software that notices when your thing is going crazy doing something it shouldn't be doing. But we actually have to do them. That's the key. So previously we could rely on the inefficiency of the attacker not being able to be everywhere at all times. Now they have much greater reach and breadth. So now I'm the more people I talk to that are kind of on the front line of this. The more that they are talking about doing the bear requirements that have been outstanding for quite some time. Knowing what's in their environment and all that jazz and like, shoring up their perimeter, doing internal layered security properly. It's been on their list. Now budget is being opened up to actually do those things. And hopefully AI will help do those things more efficiently. Like Microsoft just passed a thousand vulnerabilities. So after a few months of that, it really should have less holes in it. Well, you know, that's interesting Sam. I don't know whatever you said, trigger this thought.
I'm not sure why, but I think we paint the picture of AI in the future as being this technology or being, if you will, that is this unified. All of AI has unified and has challenged and wants to wipe out the human race where in reality, and that's this classic science fiction thing in reality. We have multiple AI systems that we've tuned that we've created for different goals. So it's more likely that AI and humans will be fighting with each other if you will. I don't know if it ever in our lifetimes or future lifetimes gains any kind of consciousness as a human does. We'll put that aside for a moment. But in my point is you're going to have AI that is centered around defense and corrections and preserving safety.
You're going to have AI that maybe makes a mistake. You're going to have criminal threat actors that create AI to do damage. But we all have the same technology. It's not like AI is this thing that is going to take off someday and just wants to wipe everything out. We're going to have more technology than just the evil AI. We're going to have lots of different AIs that could help preserve the balance if you will. Here's the problem. Even if you accept Sam's very valid point that it's almost impossible to extinct. Is that a way to say that? To cause to go to extinction, the human race, valid. Can a sufficiently motivated attacker cause the failure of civilization such that we are dropped into massive dark agents. Okay. And I'm talking about the last couple of years. Worse. And that is actually very, very viable. Anybody here? Raise your hand if you could cause the breakdown of civilization in the United States.
Everybody raise your hand. I don't really want to know. No, no, we're back at the law. We're back at the law. The record the loft. Right. I don't know. No, no, no, no, wait. We thought we could do that with you. I'm not talking about anything cyber. You can you can take just nuclear bombs so you could do it. No rifle. I could take one rifle. And if you don't know rounds of ammunition and take out the American power grid in about two weeks of driving. Any of you could. It's been public to do that for years now. The power grid goes down and this country falls apart in a matter of weeks. It is really that. It is really that easy. We should do something about it. What are you going to do? We've been relying on the same thing for some time. Is that it's hard for an attacker to do that. It's in what's the what's the value, right? What's the return on investment? That's what's protecting. You've got enemies that would like to do that. I'm sure. I'm sure. For example, and problem.
Yeah, but enemies are on the same boat. There, but they're fragile. They're fragile. The civilization is fragile. Okay. Civilization is fragile. And we have been attacked on our water utilities, which Josh Corman is working on and John. Calvin was working on in the fragile foundation 100 project and undisruptible 27. Our electric utilities are fragile, which I've actually been helping with a few utilities to help with that. And I tell them the ways that they're fragile and they go, we don't have any way to protect against that. Right. Because you, okay, I'll give you the quick and dirty version. This is public, by the way. There's nothing private about this and all. Josh, can you turn your cane up a little, you're a little quiet for how about I move a little closer? Is that better? Yeah, it's better. Thank you. Okay. So a couple of years ago, maybe five years ago, somebody took a half a thousand potshots at a substation. And they drained the transformer of oil from a quarter mile away, half a mile away, whatever. The transfer over heated and blue took the substation out. This is very understandable, right?
There's nothing strange or obscure about this. There's six to 10 substations. I remember correctly that across the US, if you take out, it'll take out the entire grid. Okay. And so all you have to do is take a rifle. A few dozen rounds of ammunition. They're going to drain the oil because those transformers, by the way, have multiple multi-year lead times period. Multi-year lead times in a new one. What's that? These aren't the little ones. These are the little ones. No, this isn't a pole top transformer that they have 50 of them in a depot around the corner. This is something that's around the corner for you behind the chain link fence. These are the really big ones. The big substations. Exactly. And there's several of them. Some of them have millions of gallons of oil in each transformer. Right. So you dump a million gallons of oil. You've immediately got a hazmat unit problem or hazmat problem. You've got a blown up substation sending fire and ash and smoke with God knows how much PCBs remember the PCBs into the air. And you've got a electrical power that's not reaching an entire section of the country.
Gee, you're screwed. So any of us here could take out the entire country's electrical grid. Now, could an AI do it? Yeah, but it's like it's much easier to pay a human to do it. I mean, an AI can pay a human to do that. Ta-da. There's the connection. Maybe. Sorry. I don't mean to be a doomer of lumer, but I just there's. I believe the term is P doomer. Well, there must be some way to protect them. Yeah, you could put bulletproof sheeting around the transformers. That's not cheap date. Yeah. Sounds like it might be worth it. Do you want to convince an electric grid that they need? Now, remember, electric grids are manned, are regulated heavily adding, but it's interesting that. Interesting though that AI is sparking the discussions on how would become more resilient. Yes. And that is a better, we've been our own adversary for a while.
Now, we have this new, newer, I should say, adversary, if you will. And it's triggering these discussions on how to be more resilient. If we heat our own warnings, and AI pushes this to go, well, can automate a lot of these bad things, so we need to be more resilient against these bad things. It was kind of a theme that I'm seeing this week where AI is kind of pushing us to go, you know, we should have the thing we've talked about time and time again in the show. So we should get back to basics and actually secure our system so that they're more resilient against human attacks against AI attacks against humans using AI. It has been a big theme against AI using humans, by the way, as well. To the very first day. It's Dave's fault. Remember every day. I didn't come up with that idea. Actually, that's been a science fiction theme for quite some time. There's a recent Batman movie or TV show. Where the bad guy basically sent all these glasses out to people, you know, and had an AR image of who they had a mark on.
And they would give you X amount of crypto if you took that person out. And so I had like, you know, the chief of police and various other people that were targeted. And they were basically causing chaos by giving people the Batman equivalent of meta glasses. That was a movie tag. There was a movie tag, the assassination game back in the 80s. They probably took it from that. So there's a there's a recent commentary that I've picked up on because I'm hip on Facebook and various other places. And it's the contrary to AI concerns of people saying, hey, you guys are just watching too much sci-fi. And I think it's less about that will happen. It's more of about, that's plausible. Maybe we should do something to prevent the definitive likelihood of that happening. And there's probably some secondary outcomes that could benefit us too. So the likelihood that AI will figure out how to like, throw something from a satellite and hit a transformer on Earth.
Pretty low. But, you know, maybe that's something we should think about in case something else figures out how to do that. I think it's a great point. I think we're saying is when you heat the warning and we need to build resiliency into so many of our systems in infrastructure. Well, just going back to your power transformer thing. In 1984 at large, slow more, we had a transformer fire. And in fact, the transformer was pretty big, but not the really large one. It took a long time to pump the oil in and out like days. And they actually, the new transformer was so heavy, they actually didn't lift it from the flat bed. They drug it across the ground to where it needed to sit. But as part of that work, they actually put in completely redundant LGS as the whole main grid at the lab went from being single to dull. Not every building was double connected, but the capability was there. If the warning it, they could, they could give you dual connections for your facilities.
And guess what the data centers wanted, which is fine. It's just that I would like to avoid the fire and blow up part of this scenario and move to the increased resiliency part of the scenario. That's not way too bad things. So many times in the show when we talk about hacking and cybersecurity is that people wait till something bad happens before they mount up a response and become more resilient. We need to change that mindset and that part of our culture is basically human beings. We don't do things until that bad thing has really happened. Hospital systems for years. Everybody knew everybody knew they had lots of vulnerabilities, lots of opportunities to disrupt or harm human life. And it seems like they did nothing about it until somebody started attacking hospital systems, which there was a I remember hearing about there was a like a bad guy agreement effectively a threat actor agreement to say hey, we're not going to attack hospitals.
Yeah, they said, hey, we're just not going to do that sort of thing. And then after COVID the threat actor economy collapse and they had to find new sources of income and they said, it's good. We're going to start attacking hospitals. And but that was 15 years of technical debt that they could take advantage of that or just security lacksness that they could take advantage of. And now they're starting to catch up. Yeah. Sam, did you have other stories you wanted to get to? Oh, I think the only one that's the only one that's worth mentioning is suck off, which I think is brilliant. If you want to know if the meta smart glasses are around you, it just sniffs Bluetooth to tell you if they're nearby and how far away they are. And I think they should extend this to all the snoopy internet of things like the Apple Watches that might be listening on you. There seems like a great idea. You could probably, these already exist, right? There's probably apps on your phone that you can install that you don't need a fancy gadget to do this.
Your smartphone can do it. Well, there are apps that sniff Bluetooth, but then you just need to check it to a database of the known snoopy gadgets and pop up a pretty alert. Yeah, I mean, it's not this complicated app, but I think it's something we would all like to have. Just warn you if somebody nearby is recording what you're doing. Yeah, I think the slot camera is potentially, I know a story about that. You know, also I got my hack five. Pageer. Oh, no, it's this week. So what is that thing? I haven't done much with it. This is the hack five pineapple. It's basically a hack five pineapple in a page or format. I managed to get it running. I managed to get the firmware updated on it and poke around on the menus, but that was it. I haven't done much else with it. I do want to carry it. I do want to use like the reconnaissance for similar reason I bring it up similar what we're talking about, right? Have it on my belt. Have it record some stuff.
Perhaps and tell me what what was nearby. Also, you can do all kinds of stuff with attacks as you would. I pineapple. So the battery is not that great. So have a battery pack in your other pocket. But yeah, they they they they give it the one and clear. Oh, so you have one just in clear. Yeah, okay. Yeah, this is the latest version is the clear version. It's really cool. They are so much fun to play with. And Dragoorn has optimized the software on this and the hardware. It's unbelievable. This is now as capable. I could tell one reason I could tell Josh when I updated his firmware. It actually did a firmware cryptographic signature validation before it came firmware. Because Dragoorn's care was like Dragoorn's definitely got it. And because as we've talked on the show, not everyone does. Well, so Dragoorn and Dallas and Dragoorn and Dallas are their primary programmers. And Dallas was trained by Rick Farina. Yeah, yeah. And so he's he's super proud of Dallas and Dallas is kicking ass.
But Dallas and Dragoorn are the ones building out the firmware and the software for these now. And the funny thing is I was talking to Darren at DEF CON. And he was telling me that that Dallas is a real pain in the ass. I said, why? He goes, I ask him for a paper airplane. I figured it'll take a week or two. Three months later he hands me a jet engine. At a 747 with a whole friggin' airport attached to it. Right. And then he goes, well, what do you mean? He goes, well, I wanted to add something to Duckiescript. You know, the payloads scripting language, yeah. Yeah. He built an entire IDE for Duckiescript now. Duckiescript now has its own complete and stable IDE. That's pretty awesome. I'm like, that's huge. He goes, I know, but I wanted a paper airplane, not an airport. Like, okay, okay. And you know, what's interesting? While we're on the subject of gadgets, I had a gadget story. And it's a good segue to it. Because I'm, you know, I'd venture to guess maybe you folks might not have seen this particular gadget, maybe you have. But I picked up on a post and this is the everyday carry blog
ran in article written by the Talking Sasquatch. I've ever seen Talking Sasquatch. I'm going to shout out great, informative, kind of sensational, but great, informative videos talking about a lot of different hacking gear in platforms. And when I read this post, my story number 15, it kind of prompted me. I'm like, you know, I got a hack five page. I haven't, I haven't played around it yet. Let me get that up and running. It could be something cool. It, you know, take with me as I go around town. But there's now there's so many gadgets, right? And I used to play very heavily as many of you know, and our listeners, I did a lot with the ESP32 platform, which just keeps getting better and more interesting. Where I see the trend moving towards, or platforms like the the, the page of pineapple, the flipper one, that is basically a full Linux computer in your hands, not constrained by, you know, the microco that has to run directly on a chip like an ESP32.
And I think that's the future. And one of my indicators for that in Linux handhelds, essentially becoming a thing, as M5 has since May of this year, started a Kickstarter campaign. Sadly, I was so early that I got, I think I had to pay a dollar to get on the waiting list to actually pledge. And then I forgot about it. And I missed the cutoff in July to actually pledge to the Kickstarter to get one. And now it's sold out. But M5 will now apparently in November of this year start shipping the cardputer zero, which is a Raspberry Pi based CPU that runs Linux. Your pocket Linux lab for coding creating and exploring. I linked to the Kickstarter campaign. It was $69 to get it on the early bird.
It only goes up from there. I'm not, excuse me. I'm not sure how we now acquire these that I've missed the window. But man, is it awesome. They raised a lot of money. They got a lot of people interested. You know what? I can do this. And I can share here. So there's your cardputer zero. And it looks like an M5 cardputer except it's a CMZero running Linux. I'm credit for size. Yeah. And there's TalkingStaskWatch, who's done a review. It's got add-on boards like many of the M5 stack does. Yeah, it's just got all kinds of there's a whole section on features. So Dean Laura, the whole thing entertainment hub.
Right. So it's kind of competing with the flipper one that we've talked about. Media player screens really really small. The device is very small. But there are all the specs. Right. Battery audio camera, USB sensors, the expansion ports, video codecs, the whole thing. The things thick. It's pretty wild, right? That's cool. Yeah, they're all the prices. So I think this is the future. Now we're seeing it from M5 stack. We're also seeing it from the flipper folks as well. And you know, and again, this is nothing new. Remember the Nokia and 900s Nokia and 770 was at the model before the N900. Was this little pocket size thing that you could put Linux on. And I think they're making they're making a comeback, right? I mean, you can also call it a cyberdeck.
Cyberdeck tend to be a little larger in form factor. But now you've got this pocket Linux. Computing device that you can do all kinds of stuff with now. You know, I think this is the future. I think that's why the flipper folks kind of pivoted towards having a Linux handheld putting a lot of research and development time into a really solid one. I think M5 is not as quite as many features or computationally on par with the flipper one. But it's the same kind of thing. I want just raw Linux in my pocket because it enables so much. And not just hacking stuff, but development and AI models on it, all that kind of stuff. So that's pretty wild. That's my pick. That's my prediction of where a lot of this is going not to say that having some USB 30 to devices flint around is a bad thing. So I'm excited for that to come out. That yeah, they're they're not out.
I don't think they're being shipped yet. Not yet. Yeah, they're like pre shipping. They're close to shipping it. My prediction is that they will ship it. So thanks, Sam. Well, people looks good. Awesome. So. Let's see. So we can't talk anymore about Sam stories, which is basically everything AI hates. And he's definitely pulled a Jeff man today. But I Lee has some really good stories. Lee, pick one. Yeah, let's go to Lee. So I was well, I was thinking the I did the fake last pass one. By the way, it wasn't just last pass, but last pass did the analysis and write up. Basically, they were they got they got a hold of redirect to legit look and update sites for last pass. What is 40 other packages? The the update that was delivered included a sign version of visual studio, which had been.
It should have been renamed and configured to side load. Delicious. DLL. Because of its size, it was like 140 something megabytes. The average scan did not. It was just a catch that it was maliciously just passed it along. And it then loaded a persistent module that turns off your. EDR AV engine. And then it starts sucking credentials out of things like browsers, crypto wallets, etc, etc. And it's using a string of malware call. It's a console, which is actually derived from another one, which I didn't capture the name of or it looks like it is, but it's it hadn't really been seen. So it's, you know, it's got crazy neat technology in it relies on social engineering. And oh, by the way, if you find it, you're going to be changing some credentials pretty much any credentials stored in your browser.
You have a crypto wallet. If you have anything in the credential manager on windows, all those passwords have to be changed. And one of my comments is maybe time to click that MFA button. Well, I think what's really interesting about your article and write up Lee is it says the campaign delivered a Microsoft attested kernel driver with zero virus total detections that terminated 145 antivirus and EDR processes from kernel mode. Until we can figure out a way to make what I just said in terms of an attack super difficult for an attacker because you're not going to wipe it out completely. But if you raise the bar on that significantly, that's what attackers are going to keep doing. I mean, that is why would an attacker do anything else when they get a foothold on the system if they can grab a kernel driver that's been signed by Microsoft.
Right. So here's great. We got routes of trust. Amazing. The attackers are just going to use software as part of the route of trust to do malicious things. That's one we talked about crypto. They're not attacking the crypto. They're like, this is great. It's already signed and they can do malicious things. So that's what I'm going to use. Then we can just go into the windows kernel and we can just start terminating things like an aviracer EDR from kernel mode. And then implement the stealer in the stealer is what was giving attackers that valuable information. It was prepping for an upcoming interview, right there stealing ransomware pay the ransom. Don't pay the ransom. Doesn't matter later they're coming going, well, now it's extortion. I still have your data whether you paid or not and I'm going to extort you for the rest. So much like one of our other favorite movies. It's all about the information. And the access method is bypassing those protections that we have in windows in my mind way too easily way too easily because we don't have a good solution for like we have this great amazing technology implementing routes of trust.
Trying to validate and authorize what should be trusted on your system and attackers are just walking right around it. Until we fix that, we're going to be in this situation. And as you know my day job, my closing short today, I think we will fit. I think we're not going to fix it entirely again, but we're going to make this type of attack much more difficult. And what that's going to do is just push attackers as we've seen historically in cyber security. It's going to push attackers to other areas. They're going to start going well, what if I get in before the root of trust. I'm getting in the bootloader. I want to get in the firmware. Now I can still circumvent that same root of trust. It's doing it deeper inside of the system. They don't need to go there. It is more complex. They don't need to go there because they can just find a driver that lets them do what they need to do. And this particular driver registers itself as an an Nvidia and Nvidia component registered as NVFS filter. So it's going to look legit if you're searching around for the driver because well, that's the thing we preserve operations over security.
And therefore we don't want to revoke a driver. If we revoke it, it won't run. And if it doesn't run, especially if we're talking about, let's see, Nvidia, what do they make? They make a lot of graphics cards. Wouldn't it super suck for you as the user if your graphics driver was no longer part of your root of trust? And if it's a graphics driver, how do you even know? Because you can't see the screen. Well, that was actually when I was wondering, would it, would it, would it, would it know, would it kill the screen or would it fail over to like some 640 by 480 VGA generic driver? I mean, overly dramatic. Yeah, being overly dramatic, you would, you would still see the bios and boot up. Yeah, that in the scenario, you would still see that part because your graphics driver isn't loaded yet. Graphics drivers loaded by your OS kernel. There are other what we call Dixie drivers that are drivers for UEFI to be able to display stuff out to the screen.
But after that, it's going to be. But after that, once it passes to the OS, yeah, what you see is to my, to my knowledge, there's a lot of moving parts here, but to my knowledge, what you see once your kernel starts loading comes from your graphics driver. Yes. Yeah. So that's when that's the screen changes from whatever, you know, you see that Blake and it re-res isn't everything that's that's now the OS and the current and the video driver from the OS. I've run Linux long enough to have Nvidia graphics driver issues. So I know that problem. I know the blank screen very well. Like, hey, I was seeing stuff. And as soon as I always start as a load, I don't see anything anymore. I'm like, crap. And by the way, Linux has gotten much better with that. Oh, yeah. It really has. When I did my mengero desktop experiment, video drivers literally almost no part of the frustration. Yeah, it was honestly applications. It was teams. It was business apps, things like that. Sure. The actual functioning of the computer was no frustration at all. I just except for the fact that men are better now.
There's a native, not official, but native app for teams on Linux that some folks are maintaining and developing and it works really well. It actually did work pretty well. Yeah. Yeah, it just, you know, Linux still you still got to be patient. There's going to be things that don't work. They're going to resolve themselves eventually. I think that, I don't know if I stated on the show before we talk about the year of the Linux desktop. I might, in lary now, we're talking about this, right? Like, I don't think there's going to be a year of the Linux desktop. I think it's going to be a slow burn. I think as more and more people get frustrated with Microsoft and Apple. Not to say that Lee, your story speaks to any of this, right? Because Microsoft does maintain that root of trust for kernel drivers. Linux is the Wild West and there's lots of different ways perhaps to protect. But it's up to you. And how you want to protect your kernel and your kernel drivers and your applications.
And so it's not any better or worse, necessarily, than Windows. Maybe maybe Apple has a leg up because they control more of the full stack. But, you know, this Linux is not anymore secure. I'll go on record stating that not anymore secure in this aspect, certainly. But one thing I wanted to mention is that, you know, if you're trying to talk about this to like your your your your syso, give him the bleeping computer article. If you're talking to a Paul Acidorian or a Josh Barbit, give him the last past blog. Yeah, because that's got all the cool details in there that will put that management to sleep. Where you'll be like, I don't need coffee today. I got this. Yeah, do you need a nest of ways? This is a nasty info stealer, you know, an info stealer that's wiping out your EDR via a kernel driver and going after all of those different.
That's a pretty sophisticated info stealer. You ever stop and think, damn, how could I pull all that off and be this stealthy? I mean, it's a, you know, I just think that's a lot to do. A lot of little hacks to get all that stuff. Yeah. Although it's not always that sophisticated. No, well, I don't see the story anywhere. Did anybody put the FBI story in which one? The FBI got hacked today? No, no, no. Oh, I put in the FBI story about him warning about the fake interviews stuff. No, no, no. The FBI had every bit of employee information, according to the cyber criminal group, the shiny hunters stolen and over two terabytes of data. You could see that. And though, that was shiny hunters response. What I saw briefly, it was shiny hunters response for the FBI, misattributing something to the shiny hunters and they got mad.
So they hacked the FBI was the headline. And it's been confirmed as far as I have been told that they're every single employee profile basically is been taken. And their families and friends and all of the lovely information you give up when you become a federal law enforcement employee shiny hunters has. Interesting. Didn't the attack like an HR related company though? It wasn't the FBI directly. It was the FBI jobs.gov portal. So it was still a.gov website. But they from there understandably. They got in and got everybody's stuff because FBI jobs everybody in the FBI supplied through there at some point. Oh, and they they did it exploiting a new people soft zero day. Yeah, that's it was. So it's. And I love the fact their statement was we were very disappointed to see an agency of your standing resorting to such circulation of disinformation in an attempt to disrupt our operations.
An effort that ultimately proved unsuccessful. It's like damn, they're being diplomatic. It's crazy. And it said it would publish all the hacked data in a week. If that public service announcement wasn't retracted. So somewhere between two and three terabytes worth of files. That's a lot of personnel files. I'm very. I'm very concerned about this attack because you know protecting the privacy of those working for three letter government agencies is a huge safety issue. I'm listening to the good segue into my new podcast. So I apologize to all our cyber security podcast friends that I normally listen to. I'm putting on hold for now. And I am enthralled with John Kiriaku's dead drop podcast.
I've seen John Kiriaku. But John was a CIA agent in the 90s when he joined. And it is the most fascinating. I mean, crossover into cyber security talking about national security, national defense. He is an amazing storyteller. He is on a section out. And this is what we'll kind of prompted it where there was a station chief in, I believe, Kuwait. That was captured by Hasbala. Unfortunately, he was tortured and killed. And so protecting the identity, the information, the privacy of those working in those kinds of agencies. As we all know, it's a life and death situation. So the episode I'm on now is talking about this person, his life and the events that transpired. But I'm learning like all these little insights and snippets from history, from the Gulf War to the, so John was stationed in Kuwait.
The story that led up to that is also amazing. But he was stationed in Kuwait in somewhat also monitoring Iraq. And he's like, it was the most boring job ever in the 90s before the Gulf War broke out. He's like, to no one wanted this assignment, nobody cared what was happening in Kuwait in Iraq. And he's like, you know, one day, I won't spoil it. But like basically one day we're like, you know, we noticed that, like most of the Iraqi army is positioned in the Gulf War. And that's probably significant. It ends up in a meeting with the president at the time. And his work becomes obviously far more valuable from that point moving, you know, moving, moving forward. And it's just, it's an amazing, again, amazing storyteller and amazing, like little insights that I'm learning about national security, which transfers into cyber security. Great podcast. Highly highly recommend it.
So yeah, I mean, I, yeah, we got to protect those, those folks that are doing sensitive work. We really don't want them known. I mean, I, you know, with the, was it the NSA hack that we had, all of us had mutual friends get out and they're fairly pissed off about it. Yeah, still still still so about that. The OPM breach. You know, I mean, if you'll talk, if you, if you, if you, if you will often hear me, you use the word again when it comes to having information breach because I was in the OPM breach. So it was my wife. And so. And that was clearance data. So there's nothing sensitive there, right? All of your friends, all of your previous addresses, all of your contacts, all of your foreign contacts, all of anybody you've ever talked to from a foreign country. Everybody, you know, a lot of friends that that vouch for you. So I'm sorry. What was that word, leverage, right leverage.
So, yeah, so that, you know, but then, you know, and then then followed up with not that long after that they had the V. A breach, which got my wife, not me. Speaking of clearance to me, we've talked about polygraphs, you know, before on the show. It talks about his experiences in the 90s having to do his first polygraph to get, you know, as part of the CAA interview process. I think we've actually talked about, you know, with people on the show, you know, about that. And it wasn't a shock when he was like, you know, I had to call one of my mentors and be like, like, look, I'm freaking out. And he's like, look, you're going to be in a very non-descript room. And it's likely going to be white walls and no decorations, nothing. But inevitably, there's going to be some imperfection, a spec on the wall. And I want you to focus on that for like the entire polygraph. And he's like, sure as shit, I get there and he's like, it's nerve wrackingly strap all the things to you. And he's like, sure as shit, there's like a little, little spec on the wall and help focus on that.
Right. And we've all read about polygraphs, probably many of us have done polygraphs. And no, you just need to calm your nerves and focusing on a spec. I've also heard people put in a, like a thumbtack in their shoe. So you're focusing on the, you know, pain caused by the thumbtack rather than freaking out about the questioning on stuff. So the other thing is don't overthink the questions. Yes, yes or no, that's exactly the advice is meant to give him a little shoe on it. No, he's like, you're crossed your eyes and raised your left eyebrow. No, just answer and move on. I mean, he wouldn't have had to have gotten that pro tip about focusing on the spec on the wall if he had spent more time and detention in high school. True. Because you just learn that automatically. True. It doesn't sound like he was the person that spent a lot of time in detention or was a troublemaker. Wasn't like that. Yeah. Was it a full scope poly or just the lightweight work question? It was the first, it was an introduction like the first poly just to apply to the agency, which I think is in talking to our friends, right, they've worked in similar agencies.
It's just the first screening, right? It's the about your relationships about your finances. And he even says it in the parties like, you know, future polygraphs were very different once I was working for the agency. They were less about my relationships and finances and more about secrets and other kinds of stuff. So I would imagine they would have to be conducting effectively personality and truth telling baselines like even without the formal a catramon of a polygraph. They would have to be testing that constantly. Oh, yeah, he without them knowing he just in the process he describes is not all that dissimilar to other people that that probably mutual friends of ours that have gone to work for NSA FBI. They know their agencies, this is not just a polygraph. There's also your meeting with people. Those people happen to be psychiatrists and are also evaluating you like asking questions in the whole.
The testing that he describes was super interesting. It was, you know, they put you in an auditorium with all the people who are applying to the CIA and they give you a series of like four tests in each test has hundreds of questions. And it's not about your answer to the question. He's like, I was taking the test and it asked me like, do you like the sport of boxing? And he was like, I had to answer that. And then like, you know, a hundred questions later, they were like, do you like the sport of boxing? And he had to remember what his answer is. And if you think about that in a context of a spy, you're basically lying as a profession in your job. And if you can't keep the lies straight, your brain's not wired to keep those lies straight in your mind, you're going to be a really bad spy. And so that's what they were testing for. Other those super interesting. It's kind of cool. What about the water utility story that you pulled out?
So yeah, who had the water utility story? Was that right? You mean the ones in Colorado? Yeah. So there was a couple of small, I think is it? There are under 200 or under 2000. I forget customer water utilities that they didn't necessarily disrupt the service to the end customers. But they were mucking with their OT systems. And as near as I can tell, it was OT exposed to the internet. Why? Well, actually, I mean, I know understand why. It's got to be the age old argument that it's so we can support you, right? And keep the cost down. We're talking small, right? So you're not going to necessarily getting them get them to implement a VPN. Never mind about tail scale. Paul. I get it. Yeah. But actually, we could back up and say a remote to have them put in a and fund a remote accident. A remote access system for remote support, whether it's a tail scale or a traditional VPN.
I think we sometimes underestimate what is muscle memory for those of us working in cyber security for over 20 years. Yeah. And what could also be challenging for those working for a small water utility company. Exactly. Setting up remote access of any kind. They're just not trivial. Not trivial. I mean, many of us have done it so many times in the past 20 years that again, it's muscle memory for us. Right. That's not everyone. And I think that the challenge is how do we develop that muscle memory for these smaller utilities that are protecting this critical infrastructure. So they're not exposing stuff to the internet. And on the one extreme, we had a I worked with a person that had a Motorola trunk radio system. And a role that was doing remote support remote support equals a T1 link to Schomburg. Yeah. I mean, it was separate computers in Schomburg. It was an isolated network there, which was cool, but a T1 link. We had a system now your money when I worked for university.
It was cool, but I was doing security auditing. Even though I was working in the systems administration group, my role was security. And we had this system. I even forget now what the purpose of this system was. But it had a modem attached to it where the vendors were able to remote in to perform maintenance. And this is performed some kind of critical function, whether it was timekeeping, access badges, payroll, something along those lines. And I remember people still kind of like freaking out about it back then. There was essentially a back door that we had to, you know, to get our rains in on it. There was no password associated with it. Like basically, if you had this phone number and you knew how to dial into it, you could gain access to this system. And we don't want our critical infrastructure to suffer from the same type of exposure that even in 2001,
we identified as an exposure. Right. I mean, actually, so sort of corollary. Did you see the news that Iran is threatening that if Trump does whatever, that they're going to start a new type of war and they've already won we just don't know it yet. No, I've not seen it. It was in the news yesterday or the day before. And Trump was making some thread about we're just going to go destroy them and rinse it. Hey, come on. And if you do, we're going to start a new type of war and we've already won you don't know it yet. And I went, oh, that's the water you do. In my opinion, that's possibly the water utilities. It's some type of critical. It's quite, yeah, very likely it's critical infrastructure, right? Yeah. And I, you know, because there is a lot of critical infrastructure that can be impacted larger ones less so, but the small ones definitely in there's the majority isn't the majority of majority of it is on a small.
There's 150,000 water utilities. Yeah, under a thousand of them are in the water isac. And I mean, if you think about how many towns and cities and states there are 150,000 water utilities is a lot of small ones in my opinion. That was also fascinating, fascinating the dynamics with countries like Iran. I guess I guess I've always sucked at history, which is why I'm liking the podcast I'm listening to because I get little snippets. I'm like, oh, that's another reason why they hate us so much. And I'm like, but that actually factors into what's happening now. In fact, it's into what we're talking about in cyber security. And the fact that I ran still today is like, we're going to mess your shit up. You're like, well, what's fueling that? Now this goes back 50, so much so long in such a rich history of maybe now questionable decisions by previous leaders of the country.
Previous decisions made by those in power 50 plus years ago have all led up to this now situation where we're like, oh shit, we really need to protect our critical infrastructure because we're still at war with the same countries that we've had these at sometimes maybe good relationships with, but we screwed that up along the way. You know, you could be a showdown search away from a really bad day. I mean, they're in the place that's the birthplace of math. We should probably be a bit more cautious. Like the Samarians invented base 60 mathematics. I had to learn it once it hurt my brain. If they can handle that stuff, then they're probably going to be pretty good at programming things just to be extremely extrapolative. I have some reason to be optimistic regarding OT at least. So a few weeks ago is having conversation at dinner and the folks around the table were talking about how they were leveraging their Claude system to do the thing that they had wanted from the industry, which is better protection around OT.
And so what they're, what they're, it seems like, and these were like a couple of individuals who'd come to this conclusion organically separately and just said, oh, hey, you're doing that too. They're creating universal translators for generating and doing heuristics to understand what a security alert is out of their OT systems or their IoT systems as well. And theoretically, there's some products that do that. Clarity comes to mind, but they still, they still didn't see what they needed in the marketplace. So like I see AI as an opportunity to create universal translation between both people and computers. Yeah, I have the money fairly. The problem with that though is multiple aspects. I still think today, AI in that defensive aspect. Yeah, is prone to many false positives and false negatives. Like we've worked so hard in our industry to reduce false positives and false negatives.
And now we're just kind of turning over these artifacts to AI in trying to tell us, like, just show me what the bad things are in here. And perhaps not giving it enough context to recognize false positives and false negatives. And as we all know, either one can be extremely detrimental to ability to detect some type of incident. You need, I think you need one more components. And now, OT protocol aware, scan passive scanners that can tell when there's a, there's a protocol speaking improperly or it didn't exist before. And can, you know, you're capturing all that stuff all your own, but to then take that data stream now that you have something that knows what's time. And parse it down to something that you're not overwhelming the humans, you need the AI to do the data reduction. But my other point is when you do that for AI, I think attackers are very astute in knowing that if data that they can influence or change goes to an AI that the way AI treats data is very much the way it treats code.
Therefore, your prompt injections and all of that stuff are in play for attacker. So my fear is we today have an over rely, we gain an over reliance on AI to analyze and tell us is that a bad thing or is that a good thing or so right between. But the attackers are embedding inside of that data ways to manipulate the AI to, for example, always tell it that it's a good thing or a false positive. And so I don't want to, I want us to still like don't take your eye at the ball. I think we still need really smart ways to detect threats that are not based on AI. Because if we over rely on it, I think a, you know, attackers are going to manipulate that data and manipulate our AI systems as well. And I don't, I don't think we've got enough processes and understanding to be able to combat that threat today. Because the AI systems are moving really fast. They're not as well understood as we all might think and they're going to give you the wrong result.
I think you might want to tighten that not just a I mean, I'd be more concerned about say, agenda AI in the loop versus just machine learning. Yeah, I mean, she learned different. I think machine learning is a little more than AI. Machine learning is perhaps a little more resilient to that because it doesn't have that that prompt injection data code as much of an issue as we do with LLM's. Yeah. Right. So not only have to worry about AI, you have to learn about what kind of AI has what kind of risks, which we're all working to teach everybody about. No, you know, and because if you've got to help yourself produce the data. I mean, you know, if I can just imagine somebody embedding in a proprietary protocol, what amounts to a prompt injection that the human is going to miss. But then, you know, but it's a chuck you farly to the AI. Now can it help with correlation? I think we've always we've had this problem with correlation. We've tried to solve it with machine learning.
We've tried to solve it with traditional computer science, if you will. I think LLM's are a really great way, perhaps to start correlating some of this data. Yeah. You know what I'm looking at happening on especially a lot of these network edge devices is example. I was talking about this in a webinar earlier today. And I do think it's a great example. I was analyzing one of the network edge router attacks. One of the things the attackers were doing is they're like, hey, I'm just going to add like I compromise your Cisco router. And I'm going to add a tunneling interface to your Cisco router. I'm going to tunnel that back to my to my network. And maybe I'm also going to in my campaign add an admin user to your system. And I'm like, none of those things by themselves, like it's difficult for an anomaly detection system to identify any single point there. This is again, it's nothing new. We've talked about anomaly detection forever. But just a, hey, I had a new tunnel interface without context.
It's kind of like a nothing event. A new admin interface by itself, kind of a nothing event. But now let's let's paint a bigger picture and so many startups in cyber security where they've tried to address this problem. Someone's done it actually pretty well, even without LLMs. What we need to be focused on is tuning LLMs to correlate these things for us to be like, hey, if in this time window, the version of that network device didn't change. There was a new tunnel interface added. The tunnel interface goes to the internet and an admin account was added. Now that's an event. And this is, I mean, I can nothing new. A lot of actually outside of startups, very successful companies have helped us correlate these events. Prior to them, I think you've worked for some of these companies, right? Yeah. Like this is a correlation that it's fine is if we can use LLMs to help elevate the company. LLMs to help elevate that expand that and accelerate those type of correlations. I think that's an exciting frontier.
I'm seeing a lot of that shift in the industry where they're getting into a human on the loop model with correlation. And like, they're not just correlation, but also checking the results of the AI. But it's the hybrid approach seems to be the right way to go right now to enable the humans. Because when I first saw a whole bunch of like AI agentics, socks, come out of the gate, there were liability for anything of tier one was pretty low. And it's that the market basically said, you know what, we should probably improve our reliability. And that's been basically analysts leveraging the AI and the sock as well. It's been pretty cool to watch. It's been gaining generations of accuracy in weeks of time. Yeah. So we implemented something recently and we shaved something like 25 analyst hours a week off of it off of our workload.
It was like one small thing. And then the reliability went up by like a micro percentage, but it didn't go down. And it was phenomenal to watch. And then you're retooling your analyst to look for more interesting things, more complicated things and simple stuff. Turning your analyst into threat hunters. And your threat hunters into specialists. And you're upskilling your entire workforce. And it's been really it because now you've got the humans able to look for the weird stuff. And then you're able to catch the normal, the normal. Right. Air quotes, air quotes, we are listeners. So I'm thinking how hard was it to get from, you know, AI to help the workload to doing enough of the backlog. So you actually could do the stuff, the hunting stuff that you couldn't get to at all because the other pile was too tall. You know, I'm thinking of that commercial with the yellow sticky monster and it right.
If you don't deal with that, you can't get to hunting. You just, you mean you reduce the pile, but the pile is still there. You've got to get it down until you have time to do this stuff. So we don't, yeah, hard is that. We don't always need to advance hunting, right? Sometimes hunting is just very, it's very basic. And you know, my article number 11 talks about 10 lessons reshaping security at blackout. And a lot of it is themed around getting back to basics. Perhaps AI can help us get back to some of those basics. But also, I think sometimes we just, we want to create this really new innovative thing. But we haven't done the basic blocking and intact. Oh, yeah. And I think a lot of, well, we talked a little bit about sophistication with the info stealers. But when I see threat actors using AI, I don't see it necessarily making them more sophisticated. I see it allowing them to automate and move more quickly, not more sophisticated.
So they're able to, because AI is based on the body of knowledge we have today. And so they can just move faster. Right, they can move their campaigns faster. They can use tried and true methods and stitch them together way more quickly. It's not developing new sophisticated attacks. I think those are still being developed by really smart humans, not regular skilled attackers moving more quickly with AI. That's where I see them, I see them going. I'll give you an example. As I analyze the threat landscape for Linux based systems, especially Linux based systems that are part of network edge devices, the underlying underpinnings of network edge devices. I largely see these attacks. I'm talking about this on the show for it. I largely see these attacks that I'm like, if you had read an incident response in forensics book on Unix 30 years ago, you would have noticed these TTPs.
And now I see attackers using those same TTPs. But now it's like great scale. They can scan the internet. They can find vulnerabilities. They can get a foothold. They can implement these already known tried and true methods for persisting on Linux systems. But the persistence is nothing new. It's hitting all the categories I talked about in my technical segment. Right? It's hitting the scheduled services. It's hitting the startup services. It's how to hide a process very basically on a Linux system. They're just doing an at scale. They're not most of the time doing very advanced implantation into the kernel and really hiding themselves. Most of this is, again, basic blocking and tackling. There's pretty tried and true means to figuring out if something's lying to you on a Linux system. Because there's multiple ways to get access to the same data. Right?
What's the kernel telling me? What's the usual end process telling me? Let me look at all of those. And then I can figure out something's lying to me. If that's not really that complex when you think about it, do we need a complex AI model to figure that out? Not even. We collect the right artifacts. We can figure that out. And we should do that. So I don't see attackers being that sophisticated with AI. I know you don't like the phrase for a multiplier. But what I want to say is it's basically regent taking that security by obscurity or the thing you've been ignoring because nobody's going after it. That's no longer a thing because the AI can try air quotes all the things, right? It can go out. I mean, the human could only go after so many exploits before they, you know, whereas the AI you can line a whole much longer list of them up and let it go to town. I mean, I'm overstating to make my point a little bit, but I just think you can't leave that neglecting blinking light in the background anymore if you give the analogy.
It's not even a technological requirement, the technological shift either. It can be a cultural one that affects the way attacks occur. So, uh, case in point, uh, there was a string of car burglaries in a town called Lincoln, Rhode Island, a few years ago. And what it basically, all of a sudden, there were all these burglaries. And effectively, what it came down to was that for decades, people were used to leaving their cars unlocked and their keys in it sometimes. I mean, I'm happy to have you in too Dave. I know exactly what you're going to say. Yep. I glitched at you guys still there. I mean, at a pivotal moment, you glitched. Good time. Pause for effect. And basically overnight, the threat actors in this case, you know, thieves had discovered this soft spot and had shifted their, their targeting system and a whole bunch of people were basically attacking this town and stealing things at a car.
And they were actually stealing cars themselves. Uh, the folks who were there didn't really plan for this. And so they, they, you know, they weren't really adjusting their behavior. Um, I feel like we're kind of in that circumstance right now. It's very similar. Uh, actually Dave, and I've talked about both physical and the cyber attacks in this realm, right? Um, I was a victim of it years ago. The, the criminal is just prey upon like a few very basic things. One, the cover of night, darkness, um, the fact that everyone's asleep at a certain time. The fact that you left your car door unlocked. And there might be valuables inside of the car. And attackers use other vehicles and backpacks and get dropped off into a neighborhood and can very quickly just go like, port scanning, right? Just go try every door handle on every car on foot in the cover of night with a backpack.
If it's open, anything valuable, is it placed? There's no alarms that go off. Cameras are, or meaningless. The attackers can wear a mask and quite frankly, most people don't have a really good camera at night. They can pick up on a face where someone is accessing a car in the driveway or God, I do. I do. I mean, some of us do. Even if you did, if you brought that to the police, what are they going to do with that? What are they? You can have every police officer in your town or state go like look for that person, put a wanted signs or whatever. Like usually that level of crime doesn't warrant that response. And that's what the criminal in cyber security criminals are the same way. It doesn't warrant that response. It hasn't caused that much damage to warrant that response. So they're flying under the under the radar. And there's a lot of parallels between that exact attack you talked about in the physical world to the cyber world. I can go scan the internet for for the net Cisco Palo Alto extreme networks, whatever your vendor is, find the vulnerability now with AI, develop an exploit or acquire that some way.
And it's basically a smashing grab, except you're not smashing anything, which is, which is awesome about this. Right. I don't need to smash them when they'll need to make a lot of noise. I don't need to go spend six months developing a zero day exploit like those exist. I can walk in. Visibility is poor in both of these situations so they can accomplish their attack. So at your remind me of a story I heard when I first moved into Idaho about, you know, the level of threat for this kind of attack. I mean, a guy had when he was a kid, his dad had to drive his pickup every day. But, you know, he wanted to make it easier. So first, he relocated the keys right by the front door. It was a little much because he saw the unlock and he stopped locking the truck. That's till too hard. So he put the keys in the truck with the door unlocked. That was better, but nah, I still didn't work for him. So he's in the ignition in the truck with the door unlocked. That was better than any point of the truck in the direction of travel.
That was even better. But what really worked for him was keys in the ignition truck pointed in the right direction with the door open. Yeah. And actually, I remember here in like back in the 90s where a lot of states and insurance companies would would would not do anything about that. If you left your vehicle in such a poor security state, if you will, that they'd be like, that was your fault. Like there's, we're not covering you. We're not even prosecuting you like, but also on the flip side, I'm less worried about someone stealing the vehicle. Because then it's Grand Theft Auto and that does that does garner some attention. Right. And there's tracking in all the vehicles today as well. Right. So again, I'm less, I mean, you still should lock your cars at night, but I'm still kind of less worried about someone stealing the car. I think the one kind of parallel that doesn't hold up is I cannot put anything valuable in my car.
I can just, I just gotten a habit actually over the years since we were victims of that attack. Like they stole that old Garmin GPS at the time when cell phones were just getting like a record. Just getting like a really good Google maps and it kind of didn't matter. And they stole my Garmin GPS. I'm like, everything's okay. Finally, I was not going to use that anymore anyway. It was low value at the time. But after that, I'm like, you know what? Let's just not leave anything valuable in our cars. Yeah. And I get after my kids about that now, I'm like, do not leave like especially cash. Don't leave cash in your car. If someone gets in, they're just going to take the cash. And if it's, if it's a hundred bucks, if it's five hundred, the police aren't going to care. They're like, well, you lost five hundred bucks. Like, big, whoop, we're not going to go on a statewide man hunt for someone's soul, even five hundred dollars. Could you describe those? Yeah, it's still a lot of money, right? But they're just, they're just not. So don't leave it. But we don't have that luxury in cybersecurity.
It's a different realm. Right? We can't just go, oh, we're not going to, we're not going to leave the routing tables on the routers because they have to be there. Like the password hashes, they have to be there. You can't just clean it out like you, like you would a car. Yeah. So yeah, I'm, I'm glad you brought that back up because that was not just in another town in Rhode Island, but also in my town. Can I get a sounding town as well? I got to tell you this story. I used to work on bourbon street. I bounced on bourbon street. And I had an ancient suburban at the time that I drove into New Orleans. And it was so old that it wouldn't lock. Oh, sorry, it would lock, but it was so old that it was barely locked. I would just leave it unlocked. Like if you want something out of the car, just go in and take it. Okay. And I come back one day. And remember the triangular windows at the front of the, yeah, yeah, yeah. They'd smashed the triangular window to unlock the car that was already unlocked.
Their method was so they no wasted motion. Smash unlock, get in, rifle the car, take stuff and go. And I literally would put notes on my car after that. It's already unlocked. Stop that. Yeah. Rifle through. So you'd be fine. Anything. But again, we have that luxury with a vehicle. Yeah. So it was, it was just so annoying. And if you go to San Francisco right now, and if you don't, there's people that actually leave their trunks open just so that nobody smashes their window with a center punch and pops their rear seat down to go into the trunk. Right. If you rent a car in the, at least in Oakland and San Francisco, well, in Oakland, they say, do not stop in Oakland. I mean, there have been stories like somebody will be pumping gas and somebody will go around the other side of the car and steal or something. Yeah. Not even smashing. They'll just, well, if they have, they have to, but they'll open the door if it's on log.
And who locks their doors and when people come in having had their stuff stolen. Who locks their doors when you're pumping gas? Nobody. Unless you don't even stop in Oakland. Gas is so expensive that they're drilling gas tanks now for gas. Wow. Probably surprise, but that's a whole different threat. Damn it. Forget the cat converter. Just drill for the gas. Yeah. If they start stealing electric vehicle batteries, I'll be concerned. Yeah. That could be dangerous though. Yeah. I hope it's terrible. You know, I, you know, I have, I'm on my second Tesla and you a lot of my friends and family ask me about electric cars. We get that a topic of maintenance. And I'm like, it can be very dangerous to work on electric vehicles. Like they're, they believe our certifications. You can't just willy nilly go work on electric vehicle. So the ton of current running, you make a mistake.
It could be the last mistake that you make on those electric vehicles. We could date to your point someday. See where people are stealing batteries out of them. So figure out how to do it safely, right? That'll happen. That will happen. Oh, yeah. Sorry. I predict that'll happen when we start making vehicles with like quickly replaceable batteries. Swapping. What are the major complaints? Yeah, swapping them. They do that go go carts or in a few play or scooters in a few places. We don't have that in the US. That infrastructure yet. I think Japan or China, they might. China, I think China. China, they do. China, I read an article years ago. There are electric trucks. The hall. Gear and you know, truck calling. And they have stops. So truck goes, they stop. Takes batteries out of the truck, swapping them with fresh batteries. And they go on their way. Yeah. It was years and a quarter that store it. So I'm sure it's even more advanced now. Yeah.
Fire to your point about maintenance, Paul. Fire companies are taught if an electric vehicle is on fire, get the people out and step back. Yeah, unfortunately, that even scales down to scooters, ebikes and things like that. It's been tons of tret. We had a tragedy in our own town, where if family's house was, was actually burned down. We did a part of our soccer family. We did a fundraiser for them. Tragically, the husband passed away in the fire. It was caused by a battery. And so. So, I don't know, more positive note from that. Again, I, you know, goes back to my comment. We don't want to wait for bad things to happen until we mount a response. Unfortunately, this was me mounting a response to something bad that did happen to another family, which is absolute tragedy. But in, so in my kind of side garage shed now.
I installed a heat sensor and a smoke detector in, in the side shed to get some kind of early warning system. And I think it's what we're talking about. There's lots of parallels to what I'm observing in the threat landscape against network edge devices. And all the things that we're talking about with electric vehicles and scooters in, in protection, right? Is visibility is poor, right? You're asleep. It's dark. Your car, your electric vehicle or whatever device you have is potentially a threat, whether from a threat actor or from, you know, the device itself. How do we gain better visibility early warning systems? We don't want to wait until something bad have. Unfortunately, that was, that was my approach. I do use a company called XSense to do that. And they make a lot of great sensors. Same thing. So I was like, well, like what else do you make? Turns out they make water sensors to detect leaks.
And they're not very expensive. And I can put them in my house. I'm like, you know what? I'm like, I'm going to go buy a bunch more. I'm going to put them under every sink in my house. I'll put one behind my refrigerator. And when it detects water, it alerts me on my phone and audibly in the house through the hub. Same thing, temperature and humidity. Like, you know what? Yes, could I program ESP32s with home assistant to do this? And why would love to do that? I've got other projects that take priority. Or I could just go purchase this system to know my humidor's for my cigars have the same safeguards. And if a temperature or humidity goes past a certain threshold, I get an alert. And, you know, these are again, it's the visibility and monitoring that that is important. And it's the same thing for our our systems and our enterprise networks. We want that visibility and warning systems. The hard part when we get to network edge devices that everyone's heard me talk about is we don't have that a lot of great visibility.
It's really hard to gain that visibility on proprietary systems. Interesting to think about what the parallels would be. If I don't have access inside the system, I can't can I monitor the temperature of the battery in my $100 e scooter? Maybe. I put a lot of work into it and hack the interface. I might be able to get some telemetry into that, but it'd be super hard because the manufacturer doesn't want me mucking around there. Same thing with my network edge router. They don't want me mucking around with the internals to monitor it. So how do I monitor the other environmental controls to detect something bad? For maybe that's part of the answer. For a lot of those scooters too, there's not an easy way to interface with those. Some of them you can probably even have like a data port, like a UR port or something. Yes, something. So, the LCD screen that you know that's on the scooter, there's a that's a terminal.
And there's a data connector that goes down through the neck. How else does it know the speed and also the battery life? How it would know the battery life. So you could definitely interface that way. I mean, one of mine has a USB-C plug. It's supposed to only pass power, but we know how that works sometimes. I haven't tested it. But no, there's battery management monitoring systems that are cool. Although you said you put a smoke detector in your shed. That means we can't go and podcast and smoke in there anymore. Correct. Well, that's the reason it. Well, that's why I like the heat sensor. So I actually, in here where I smoke, I can't have a smoke detector or carbon monoxide detector. I guess I could have, I guess I could have, could I have a carbon monoxide detector? Yeah, you could have a carbon monoxide detector. Actually, those went on sale and I bought a couple of those as well. That's another tragic story. All these things are dangerous and can cause tragedies.
But I put a heat sensor in. Like your next best thing is a heat sensor. It's not as an early warning system. Yeah, my carbon monoxide detector looks very similar to that. Yeah. But those, those leak detectors, I got several of them, put them under all the sinks as well. And my wife thought I was nuts. And I was like, no, we live with two insider threats. One is four years old and one is seven. And sometimes they play in the sink. And sure enough, it happened, finally happened. They plugged the sink, overflowed a little bit. I got, I heard it going off, got there within a few seconds. It took care of it. Worked exactly the way it was supposed to work. Yeah, see, I put them in because my sink was leaking. Because like, the one connection that happened to be 20 years old, like I had replaced the sink, I had replaced the trap. But the connection between the sink and the trap was still 20 plus years old,
had disconnected. And it was leaking. Fortunately not enough to cause any serious damage to the home. But I think it was last night I put the water sensor underneath the kitchen sink. Because I'm like, I don't want that happening again. So back to the conversation about Lake. It's several conversations as we've had over this episode. We have talked about changes, how people kind of lower or change their security posture. I couldn't find like a term that I really liked for that. So I asked Gemini, it just security drift seems to fit the bill. So that, I don't think we give enough attention to that. I think we have like policies, procedures, standards and so on and so forth. And testing and we periodically reinvigorate those from time to time. But it might be, I don't know, is anybody doing this? I'm just not aware of it. People looking for posture drift, that kind of thing, anticipating it, planning for it,
looking for those kind of things outside of like point in time testing. I think it depends on who you are. I mean, if you're heavily regulated or other, what you have to do that, I think so. I suspect the average entity, not very often. You know, posture drift might translate to a bone scan. Yeah, effectively. I know this very just sorry. I got stuck on the Sasquatch EDC blog. Oh, I know it's always the question. I'm sorry. I glossed over that and when I covered that Josh, but there's a lot of, a lot of cool gadgets in there. So, so we talked about like physical security drift or posture drift quite a few times over this conversation. Whether it's utilities, whether it's like individuals with hardware, etc. or you know, the dreaded any, any rule in your firewall.
The utility, not like from a utility company, but like the utility of a system, trumping the security of the system at some point in the history that's going to happen. Hey, I can't log into my laptop. Can you just get me into my laptop? Yeah, sure. I've got a local admin credentials that I put in there. Just drop that in there. Right. Somebody just does that to make their lives easier, etc. There's theoretically ways to protect against that policies, procedures, testing. Doesn't seem like enough though. Like we can anticipate, like is it a system design or periodic system redesign that needs to happen with things like that? I'm coming up with this on the fly. Yes, and we thought it through. Well, so, so I actually just had to think about this for agent systems. They're for agent drift, for model drift, for MCP drift, for that kind of thing. And actually I had to come up with a name for all of this. So we came up with the agent reconciliation protocol. And the agent reconciliation protocol talks about the variance.
How far do you allow a system to vary or how big the variance to get before you go, oh, Helmo. And then there's actually a concept called hysteresis, which is where you have to have it well within the variance before you'll say, okay, stable again. And you have to notice, you have to observe expected drift versus unexpected drift. Yeah, the big, the big one for me, right, the context of my day job and what we're monitoring is when you're doing it in, this is even outside of what Eclipseium does and systems we monitor is that when you do something like an upgrade, that's expected drift. Right. So you need to observe and catalog those, those changes and correlate that into your model to go that was expected versus not expect. So there's expected defense to cause drift and then there's normal drift and then how much tolerance do you have for that before you go is something suspicious happening.
Right. And that's a valid point, expected drift or expected change because drift by definition is sort of unexpected change, but expected change like an update, an upgrade, a change through change management, ticketing, whatever. Yeah, and how do you, but that's a great point. So how do you catalog like, it's a great thing for an LLM to give it context. You can say, hey, I'll monitor my system, tell me about drift, but by the way, lots of holes in this, but because of AI the way we do it, but like you could also say, by the way, you are linked into my, Gira system, my ticketing system, my change process system, and your monitoring drift, now you can correlate like, oh, by the way, Dave filed a change request to upgrade this router version one to version two. And by the way, we notice some drift and since it has the context of, well, Dave filed a change request and actually upgraded that system, I can see the version change correlated with the dates when the change request was filed when the work was supposed to be done, that's expected.
That's amazing, that's something we've been trying to build. Again, none of this concept is not new, but albums, I think, can give us a unique perspective in tracking that that even better. And an LLM can then say, hey, let me go grab that package and simulate it on a containerized version of the router that he's updating and make sure that the router that I simulated and the router that he did matches. I'm also going to examine that package, rip it apart, rip the binary apart, look and see what's in that package and make sure that the automation aspect of it, like it enabled, we've had automation, but it's based on machine learning and tools that we've built. Now the automation is enabling an LLM and agents to go, and I've done this, like, go stand up that system, go scan it, then go make this change scan it again, and just go do all of that in the background and give me the results and then build that into your model basically for how you're doing change detection or whatever, normally detection moving forward.
We're starting to be able to link our change management, our ticketing systems, our actual updates and upgrades, our log system and a correlation system, call it an LLM or a SIM, I don't care. But when you have the LLM able to access all of these things to make sure that the changes are expected and proper changes other than there was an update that happened, well there was no change ticket. Okay, let's go investigate and spend five hours trying to figure out that some shrub left the local admin logged on and then Jimmy went, oh, I'm going to install a package. Okay, so this is the kind of coordinator. But it comes down to the security basics security basics dictates that we should document these changes that there should be a change control process. If you don't have that, you can't give that context to an LLM. Therefore, you won't know if that's expected change or not.
So much like the offensive security articles back to their takeaways from black head and defcon right is, yes, very much it's underscoring this like security basics, the blocking and tackling. We've known that we need to have a great asset inventory track all of our changes on our systems. If you're not doing that, you can't take advantage of the AI system, because you're not giving it enough, it's all about context for an LLM. The more accurate and the more expanded scope of context, you give it, the better the results are going to be. We've all noticed that with since we've first started prompting chat GPT, you know, when we first had LLMs. The more data we give it, the more data it can use to as inputs to enrich what we're asking. But the more level of access we need to give the AI agents, which is scary. So it's, so okay, so when it's humans, we call it least privilege, right?
Yes, the same identity we talked about this like last week or week before, right? It's an identity just like a person. Yes. Privileged probably. It's least privilege, least variance, they're, you know, least access, whatever you want to call it. When we put an LLM on the job, we do the exact same thing or we should do the exact same thing we do to a human. Don't give it access to things it doesn't need. Now, can you ask, do you need this and why? Absolutely, because there's all sorts of factors that you might not realize that may influence that that may correlate, that may give me more accuracy on my correlation, my contextualization, my enrichment. Okay, that's interesting. I've learned more about data by asking my LLMs, hey, can you use this data for that? No, but we can use it for this other project that we were working on 10 minutes ago because I'm not ADHD at all. And that would be awesome. I never thought of using that data that way. It's crazy. The correlations you can make with data.
You know, you brought up ADHD earlier, I asked Gemini because we were talking about like, why do we get focused on these bright shiny objects of new technology? And not, you know, do the diligence of the basics and the best practices first or long. So I asked Gemini, like, what percentage of the cybersecurity industry has EDD or ADHD? The estimate it gave me was roughly 13%, which is four times the average employment. So it's kind of an us thing. It's part of who we are to look at the new thing and go, I want to mess with that. And I'm going to go do cool stuff with that. It's part of our identity and how we think. That's also how we're able to make these strides and technologies that otherwise would not have happened. You know, this is how we're able to put unnecessary cameras in glasses, for instance, you know, who would think to do that? Nerds, us. Zach off.
We did, we did really quick. We did talk about routers at the top of the show. My story number three talks about a dealing router that has a stack base for overflow and DHCP. I'll spare everyone. We could do a whole segment on DHCP options, what they are, how they're processed, what they're used for. The big takeaway is when you're taking in unexpected data from the network, don't use stir copy, which is the dealing router. That caused a buffer overflow that could potentially lead to code execution. And I also think that the state of IoT security, when we talk about inexpensive routers, Wi-Fi routers, when we talk about inexpensive Android TVs, you certainly get what you pay for.
And you feel that today in security. Yes, there's some things I can and cannot talk about in this context, but the, I can't say that the lower end of a lot of these products that are produced out of China has carries a high likelihood of many vulnerabilities, back doors, and just nefarious activity. And these unfortunately are sometimes end up in enterprises. They end up in commonplace on the internet from regular users. And the security model is severely flawed in many of these. And unfortunately, the link has had a track record of having these vulnerabilities. This is many manufacturers have. That's one of the reasons why I wanted to lead him with our story of if you're using e-waste or building your own from going with a reputable company such as ubiquity,
when they do find flaws, they do fix them kind of thing. And to my knowledge, don't have these persistent back doors that many of these less expensive devices have. And so, you know, that's a theme we'll always come back to because it persists over the years. There are everything's going to have vulnerabilities, back doors that are found eventually intentional and unintentional. I think part of the equation is which, what thing am I buying that's going to have the least quantity or the least likelihood in the time period that I'm going to be using it in? So it should shape the purchasing decisions. Yeah. 100%. Definitely. All right. Awesome. Well, gentlemen, thank you for participating in this episode. Thank you everyone for listening and watching this edition of Paul Security Weekly. That'll do it for this week. Over and out.
More episodes
More from Security Weekly Podcast Network (Audio)
Defending at AI Speed as Quantum Threats and AI Policies Won't Save You - Nolan...
Security Weekly Podcast Network (Audio)
Venus in Furs, Money Laundering, AI Hijinx, MCP, Thunderbastard, and Aaran Leyla...
Security Weekly Podcast Network (Audio)
Going From Bug Bounty Bugs to More Secure Systems - Shlomie Liberow - ASW #402
Security Weekly Podcast Network (Audio)
Measuring the Value of SecOps; BH Interviews with Fortra, Helmet, Above, & Keepe...
Security Weekly Podcast Network (Audio)