452 lines
40 KiB
Plaintext
452 lines
40 KiB
Plaintext
Episode: 4615
|
|||
|
|
Title: Clicking through an audit
|
||
|
|
Source: https://hub.hackerpublicradio.org/ccdn.php?filename=/eps/hpr4615/hpr4615.mp3
|
||
|
|
Transcribed: 2026-07-31 16:15:11 (official HPR transcript)
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
This is Hacker Public Radio Episode 4615, for 2026-04-10
|
||
|
|
Today's show is entitled, "Clicking through an audit"
|
||
|
|
The host is Lee and the duration is 00:57:58
|
||
|
|
The flag is Explicit, and the license is CC-BY-SA
|
||
|
|
The summary is "Lee complies with a company audit by clicking 'next' a lot"
|
||
|
|
hello this is Lee today going to kind of walk through the stages of the administration around
|
||
|
|
complying with a security order as an individual employee whose company has been audited and
|
||
|
|
the standard that they're using is ISO 27,000 and one. So you know they've been given what is
|
||
|
|
turned an information security management system and that's a specific term that has been
|
||
|
|
established and now what every employee has been given a checklist effectively or a set of
|
||
|
|
training to go through and you know just see what their compliance is because right firstly I
|
||
|
|
don't think it's sort of expected to be perfect from day one you know goodly it's a process
|
||
|
|
it's not like you tick you tick the box once and then it's done and also it's like it's
|
||
|
|
a responsibility of everyone in the company it's like from the directors to every employee
|
||
|
|
turn them up a computer and I've looked onto the internet and I go to my training dashboard
|
||
|
|
and there's 12 outstanding items that I have to go through and these are ISMS portal access
|
||
|
|
information security management system and actually they're they're actually a company
|
||
|
|
who have taken that on it's their name quite cleverly and policy pack and knowledgeman
|
||
|
|
change management and secure configuration secure software dev security basics access control
|
||
|
|
and lease privilege data classification and handling passwords multifactor authentication
|
||
|
|
security security incident reporting and response phishing and social engineering awareness
|
||
|
|
secure remote working in mobile device security they protection and privacy GDPR awareness and
|
||
|
|
sure no it doesn't know GDPR is the general data protection regulation which this came into
|
||
|
|
force prior to the UK leaving the year and it was you know when Brexit happened then it became
|
||
|
|
in this country the data protection act 2018 but GDPR was the big push that came around
|
||
|
|
the towards the end of the last decade to really take seriously how people's data was being used
|
||
|
|
and it while it was kind of European ladies had global impact anyway so the other training
|
||
|
|
item acceptable use of system and information security awareness and apparently that's an annual
|
||
|
|
thing because it's got in quotes annual so going to the first item in the outstanding list the
|
||
|
|
portal access and policy pack and knowledgeman so it's as login to that I did before but
|
||
|
|
let's just do it again to make sure so it goes to the website of and this and I'll go to login
|
||
|
|
except some cookies the click login except as some cookies then what right after login again
|
||
|
|
go to last pass try and find what my password was and of course it says unsuccessful because
|
||
|
|
always is facing the email address it's in my password again from last pass remember they see
|
||
|
|
my address I guess login no so what can I do all right it gets us if your organization is using
|
||
|
|
our EU dense date center please sign in here they could have led with that and I still sign
|
||
|
|
in unsuccessful need help looking in and to your email address okay it's the company in my address
|
||
|
|
so email mail link to reset my password it says if this is good if the email was registered
|
||
|
|
then we've emailed your link yeah if it wasn't registered you're just elistinating or you
|
||
|
|
some bad hacker person trying to login such is a good team out choose the thing and it says
|
||
|
|
we've locked your that's lovely I mean this is beautiful isn't it we've locked your account
|
||
|
|
and it's in reset your password I mean it's not like I like swearing and it's not like I like
|
||
|
|
using for little words but I have just internally uttered one describing the people who's out
|
||
|
|
the system he is the same email that's registered you know it's spelling of your email address
|
||
|
|
no email link in a second time of asking that so even Gmail thinks this is spam so
|
||
|
|
had I tell you it's not other show images okay for some reason that show me an image of their
|
||
|
|
logo like that was important enough to cause me to have to go through the show images thing
|
||
|
|
that they had to include an image right I've got a link in trainee password well
|
||
|
|
I don't know intranue password paste in the same password that change password yeah
|
||
|
|
great it worked okay this miss um so I'm looking at my my first one is 9 shape sent in the
|
||
|
|
way for a it's called development and of course the truth is I just when you're doing
|
||
|
|
that something like this the truth is if someone if someone gives you a list of 10 things to do
|
||
|
|
you will do those 10 things someone gives you a list of 100 things to do you will just click
|
||
|
|
through them you know I'm sorry this is human nature and you know they should know this
|
||
|
|
very very well you're just click click click click click click click click click you know I can't
|
||
|
|
actually see what's going on because my dark mode is interfering but actually these are ticks I've
|
||
|
|
got ticks against everything but why is it saying there's number 92 isn't done so it was social
|
||
|
|
social media guidelines so I mustn't bring the company into disrepair by criticising
|
||
|
|
our argument of customers, colleagues or rivals making the famigy comments about individuals
|
||
|
|
organisations or groups or posting inappropriate images or links to inappropriate content okay
|
||
|
|
well they got fully breached that already just by recording this policy pack overview
|
||
|
|
it's not letting me get out the last policy and I think I had this it was like an empty
|
||
|
|
it was a boiler plate one your policy packs and our value was an app that you can install in your
|
||
|
|
device it's not going to like increase the risk of my device to install their thing on my device
|
||
|
|
did I close that right let's actually go through what these policies are so introduction
|
||
|
|
policies and controls policies for information security information security roles and responsibilities
|
||
|
|
segregation of duties management responsibilities content with authorities content with special
|
||
|
|
interest groups threat intelligence information security and project management in the trip I mean
|
||
|
|
you know this but living in another universe yeah fine if I mean if I can think of how to do better
|
||
|
|
I would do how would I do this better or not give someone 100 things to click for a
|
||
|
|
literally a hundred well 91 92 if you count the one that's broken looking for those is there any
|
||
|
|
that is actually hyper relevant that's something I don't already know I mean yeah this is fine
|
||
|
|
but it's boiler plate you know I should not be I'm not talking about means particular but
|
||
|
|
and employee should not be given stuff that's actually outside their control like access rights
|
||
|
|
and it's like a broad policy about access rights it's like you know denied by default need to
|
||
|
|
know need to use least privilege privacy by design privacy by default access provision
|
||
|
|
access modification access removal privilege access management roles and responsibilities
|
||
|
|
and actually they've got some specific information about who's has different roles which is useful
|
||
|
|
but apart from that it's a boiler plate and it's a completely outside of the person clicking
|
||
|
|
for it this and I'm assuming everyone in the company has to click for it this is outside of their
|
||
|
|
control it's like saying I don't know account provisioning is automated for integration with
|
||
|
|
the HR onboarding presence and it's like okay that's fine I'm happy with that but why am I
|
||
|
|
having to click for it because it's completely outside of my control what the HR onboarding
|
||
|
|
process it's I mean fine this is this is in one place but I should not be the person clicking
|
||
|
|
through something that I have no control over and then you know and somehow that it means that the
|
||
|
|
company is compliant because someone who has no control over something clicked through something
|
||
|
|
telling them stuff they have no control over and I'm not criticizing the terrific company
|
||
|
|
I'm not even maybe criticizing the this particular provider of the security policy I'm just saying
|
||
|
|
that it's a bit ludicrous for an information security management system to be presented in this way
|
||
|
|
to people it needs to be a lot more relevant it needs to be like 10 bullet points of what is actually
|
||
|
|
relevant specifically to you not this is the entire policy read it through and yes it's here as a
|
||
|
|
reference and that's good that it's as a reference but anyway I can't complete this because it's
|
||
|
|
and I actually told my supervisor he got stuck at this point so is there anything else
|
||
|
|
I'm like again this website it's got no navigation so I don't know how to get back to where
|
||
|
|
was it here we go is the dashboard so it's a two list I mean that's useful let's give me a two to do
|
||
|
|
list information asset inventory is interesting this is quite good actually it's got like
|
||
|
|
some third party systems listed like accounting systems it has things like you know the card
|
||
|
|
that would get you in the office it talks about the code repository and for each of these it says
|
||
|
|
whether confidential or sensitive and like customer data and database is what do they mean by digital
|
||
|
|
certificates it's a I'm unclear that specifically what digital certificates it's referring to
|
||
|
|
if it doesn't mean writing encryption keys and see what I'm actually looking for is my
|
||
|
|
private keys that access the server because that's actually something I have a reasonable level of
|
||
|
|
concern over office keys physical yeah so all right so I'm sorry I'm rambling but for each of
|
||
|
|
these information assets we have like the name like backup data we have it a status or it's
|
||
|
|
to do or live a financial value and that seems to be left blank and then the type of thing
|
||
|
|
that it is is it staff as a physical security as an infrastructure as a person of data
|
||
|
|
is it software application and services and then as a classification as it is sensitive or confidential
|
||
|
|
or public and then we have its primary location like third party data sent to or in person
|
||
|
|
and then you have the owner of the lead so is it the CEO or the chief technology officer
|
||
|
|
and then it has an RTO it's going to tell me what RTO means it has an RPO have to look nice up
|
||
|
|
have recovery point objective all right how long right so if this asset get got lost how much
|
||
|
|
data which you lose which you lose a day a week a month or everything yeah I don't know
|
||
|
|
and what's it was RPO so it's RTO there's the downtime so how long until it's back online
|
||
|
|
so like if you lost it how long will it take you not not just how much it
|
||
|
|
RPO is how much you lost and RTO is the recovery time objective which is how long will it take
|
||
|
|
to actually get it back working and then it has the lead wire no like who I'm this thing is
|
||
|
|
of the companies that supplier or I guess is it the customer or someone else and then it has
|
||
|
|
an assignment so it's a scientific and a member of staff some particular person is on the list of
|
||
|
|
what they're responsible for so okay and back here seems like it's in that's at 99% and I'm sorry
|
||
|
|
the the asset inventory doesn't have percentage on it so the policies and controls that's at
|
||
|
|
90% have I don't remember actually looking at that okay it's popped up around and pop up
|
||
|
|
that you just get rid of because I can't even figure out what the pop up is trying to tell you
|
||
|
|
it's just in not that it's not in English it's just the English the English does not
|
||
|
|
process as to anything that I know what it's talking about so it has requirements and it has the
|
||
|
|
number 4.1 to 10.2 organizational controls people controls physical controls technological controls
|
||
|
|
addition so control is basically what we're doing to make sure that things are secure and that
|
||
|
|
and this is what I learned when I was doing the post-graduate course in information security what is
|
||
|
|
a control and most of these are showing us being complete I wonder if that's truly the case that's
|
||
|
|
what it's showing or like most of them I like that could be that 99% of 99% of them are actually
|
||
|
|
trivial and just require a tick by someone and then like the other 1% require masses of time and
|
||
|
|
effort to do so whether this percentage truly represents the security of the organization I don't
|
||
|
|
know all right I mean I've done everything on this I can so I'm going back the inter
|
||
|
|
closed all these tabs you know people get annoyed when I close their tabs and I can't work
|
||
|
|
with with more than one tab you know once I've once I've done with the tab it gets closed
|
||
|
|
so I've done the policy pad read the policies mark the policy pads read I'm not sure I did this
|
||
|
|
try to and then it says start the course it confirms that you can access it oh no they're not
|
||
|
|
going to ask me to give them a screenshot to prove that I accessed it please no it's not all right
|
||
|
|
so I can successfully access it yeah acknowledgement I've read an understood yeah kind of yes
|
||
|
|
evidence optional yeah they they want a screenshot and it says optional but I you know I'm going
|
||
|
|
out by the screenshot so I've got I've got my nice little dashboard here from the compliance website
|
||
|
|
what screenshot you've got I've got spectacle so let me just grab the active window so click on the
|
||
|
|
active window and it's just grabbed it I had a one second did I have a one second delay I
|
||
|
|
give me a chance to like move my mouse out the way or whatever although when you grab I think
|
||
|
|
when you grab the active window it doesn't capture your mouse it's a save as shove on the desktop
|
||
|
|
because it's screenshot do you what does it call it so it has the day in as in the four
|
||
|
|
digit year the two digit month and the two digit date and then it has a number it's maybe the number
|
||
|
|
of seconds zero nine three three one zero because 86 something thousand seconds in the day so
|
||
|
|
now looking through looking up while a little clock here using the time system or friend Ben I
|
||
|
|
invented and it's three sevens of the way through the day so how many seconds it's going to be like
|
||
|
|
out by six thousand we thirty thousand seconds so I don't think this is the number of seconds
|
||
|
|
Ben I's given it a number zero nine three three one zero in the screenshot you'll be
|
||
|
|
interesting to know how those screenshots are derived a screenshot font names right so save that
|
||
|
|
saved go back to there I should drag the image on here and then was the okay
|
||
|
|
bum that it's safe comments okay so let's just say it seemed the last policy could not be
|
||
|
|
access I can down like this course material so it's open it in a new browser window and then
|
||
|
|
I click on the download link I think I've got a security folder so I'm just dropping it into
|
||
|
|
there I've got my own copy of it and click and complete and that's completed I said it would take
|
||
|
|
five to ten minutes so you look at it longer so once done now I've only got 11 outstanding out of
|
||
|
|
12 so now the next one is change management and secure configuration right so you know learning
|
||
|
|
objectives modules why change control matters yeah avoid unsafe shortcuts document changes
|
||
|
|
appropriately prioritize secure configuration so it's good so when subversion I don't know
|
||
|
|
that way so when subversion can be fucks up everything I mean right this is my my human
|
||
|
|
experience of version control systems like get and subversion they work fine until you just
|
||
|
|
accidentally click or type the wrong thing then you're in the world of pain and you're then
|
||
|
|
spending hours or whatever trying to undo the thing that you've done like I accidentally on subversion
|
||
|
|
I was gonna use a change list so I was only gonna commit the few changes that I wanted to
|
||
|
|
and leave out the files that didn't want it to because I was working on two three different
|
||
|
|
projects at once then one of lumped them all into one commit and I accidentally committed everything
|
||
|
|
and then you go to like google you go to um large language model and you say like right how
|
||
|
|
do I undo this and it says oh to undo this just type this and it's a type here and oh look it's
|
||
|
|
screwed up even more and then I'm not like saying tell it well now this is what the situation is
|
||
|
|
I'll now just do this and so I can't do that and now it's completely fucked up beyond the
|
||
|
|
recognition and in the end you end up you just I think I'm just gonna
|
||
|
|
nuke from all the I just completely abandoned the repository that was on and create a new repository
|
||
|
|
a new development branch and just reclaim the development branch from the
|
||
|
|
source and then just copy my files that I've got you know on my own like machine
|
||
|
|
copy the files that you've been working to back on and of course you know because I've just
|
||
|
|
just because of because I've now got the latest code running you know there's configuration issues
|
||
|
|
because I've failed to coordinate with other people in the team who have updated the data by schema
|
||
|
|
and so the you know the entire my entire development platform is now not working it's now down
|
||
|
|
because it's falling over something and the schema is different and not in line with the code
|
||
|
|
so I mean that's that's the reality of third of I guess they call it change control version
|
||
|
|
chart I mean the lucky thing is I just have not been given access to anything where I could
|
||
|
|
damage a production system I could damage my own system and to some extent I could
|
||
|
|
insert unhelpful data you know by mistake into the shared the shared where we keep the
|
||
|
|
database not the database schema not the level I level one but the customer level database schema
|
||
|
|
and the you know the different templates and forms and how they're managed how their
|
||
|
|
data is synchronized between different instances of the server there's a central location for that
|
||
|
|
and yeah I could in some way insert things into there then there would then you know need to
|
||
|
|
kind of undo that and restore that because then it makes it unusable for other people if they
|
||
|
|
wanted to sink from it but you know I'd have to be willfully and willfully stupid if I was
|
||
|
|
doing that so all right so I'm just looking at the learning objectives for this yeah I mean yeah
|
||
|
|
back in the 90s I worked a company that had proper change control and it was as in you know
|
||
|
|
in in in in some ways it kept you safe in other ways it's and as annoying as hell if you make a
|
||
|
|
tiny little error and it means you're having to walk through the entire change control
|
||
|
|
processes taking two or three days you have to get customer approval again just because you
|
||
|
|
made a typo that you didn't spot and it didn't get spied until later in the change control process
|
||
|
|
and you know probably reasons like that that you have this is why they invented DevOps
|
||
|
|
is to reduce the amount of friction for developers while keeping things reasonably safe for the
|
||
|
|
ops team that things are going to kind of flow and not be complete headache and then I like
|
||
|
|
this is like if there's an emergency change you still you have to like because you know there are
|
||
|
|
times when a production system actually needs an intervention there and then and you can't go
|
||
|
|
through the whole change control but when that happens that the same that needs to be documented
|
||
|
|
and followed up you know that's a nice happy wish I would say change management school not
|
||
|
|
to check all right here's a quiz right why do we change the control I love this to slow down work
|
||
|
|
I mean honestly yes yeah we're still to reduce attitudes yeah and security risks and improve
|
||
|
|
accountability right misconfiguration is a common course of incidents yes all right some bit you
|
||
|
|
know can do this quiz all right I'm spacing right secure configuration practising include
|
||
|
|
default deny and release privilege I guess yeah disabled unused services yes public by default
|
||
|
|
for convenience now avoid public access unless and quiet and approved yes after deploying a change
|
||
|
|
what should you do I think we want to invalidate emergency changes should be documented
|
||
|
|
good rollback plan is and now not wait to refer on where to go quickly okay so I've got to take from
|
||
|
|
that month that is complete cause it's completed to significantly less than 23 minutes I don't know
|
||
|
|
what my past month was didn't tell me what my month was they said the past month was 80% cool that
|
||
|
|
once that's off the list so secure software dev security basics protects secrets and credentials
|
||
|
|
never encode tickets or chat by secure coding hygiene validation or frozen what is off said me
|
||
|
|
no okay don't know offset what is off said in information security which means authorization okay
|
||
|
|
I've got feeling in English in the English language authorization has got an S I think often
|
||
|
|
not try and use the American version cause when you're coding you try and use the American English
|
||
|
|
like color no color right when it's dependent since supply chain that's yeah okay
|
||
|
|
understand what that means I use code review and continuous integration controls to reduce
|
||
|
|
vulnerabilities code review yes C I controls I don't know if that's kind of a happy wish at this point
|
||
|
|
avoid risky logging and sorry I'm using the word happy wish I just wish the original
|
||
|
|
then even know where I got that from what is the origin of the term happy wish and how does this
|
||
|
|
seem to be keep coming to mind as I fail in the information security or the compliance
|
||
|
|
question it tell me it's a psychological reaction to inherent tension of compliance work
|
||
|
|
is a gap between policy and reality aspirational compliance you may be looking at question
|
||
|
|
like are all administrative actions logged and reviewed weekly and thinking I wish they were
|
||
|
|
or in a perfect world they would be the checkbox track the term captures the feeling of providing
|
||
|
|
a happy answer yes we're doing this well internally now it's more of a wish than the consistent
|
||
|
|
enforced control it's a mental shorthand for wishful thinking masquerading as a security control
|
||
|
|
I mean I've been doing this for like a half and 25 minutes I've already got ordered with
|
||
|
|
he so I can well let's start the course I mean ideally it should be prompting you to
|
||
|
|
actually do something not just think I'll idea so here we go knowledge check I mean it was telling
|
||
|
|
me stuff I just give that go straight to the knowledge check right authentication is
|
||
|
|
who you are authorization is what you're allowed to do if you're an authenticated they can access
|
||
|
|
any object of the name where should secrets not be stored when a QR code on your front door
|
||
|
|
that source code repository is tickets chat see I've got all of the above
|
||
|
|
and except for the approved secrets manager you accidentally committed the API key
|
||
|
|
I revoke and rotate as I find side validation is sufficient yeah no it's not it's not
|
||
|
|
best protection against SQL injection yeah prepared statements I don't see that a lot in the code
|
||
|
|
place supply chain risks include what is type I squatting all right okay you give you the
|
||
|
|
main like google dot com you go to google dot com you type in some secure information
|
||
|
|
come for myest maintainer accounts code reviews in the risk it's negative
|
||
|
|
pinning and reviewing dependency changes can reduce risk yeah pinning is where you fix it
|
||
|
|
certain version you don't just automatically update to the next version until you've decided that it's
|
||
|
|
safe to do so yeah they're talking about pull requests here that that may exist on
|
||
|
|
may exist in other parts of the universe it I've never seen it in this context so why
|
||
|
|
while do we disable CI checks ask for justification yeah least privilege for service account
|
||
|
|
remains I give any permissions needed right production access should be limited in the trial
|
||
|
|
to guess yes good logging practice include for that thing yeah deadlock for personal data
|
||
|
|
payloads control access to logs yeah using production data and development is yeah with approval
|
||
|
|
controls temporary secrets in code all right I mean I might disagree with this it depends what
|
||
|
|
codes but okay yeah not acceptable anyway I can download that PDF save it I think that one's done
|
||
|
|
that click on complete or I'll neatly the deadline is the first of April but I'm down to nine
|
||
|
|
outstanding things so access controls in this privilege right it's a completely skip everything
|
||
|
|
I just click start course completely skip everything down to acceptable use of systems
|
||
|
|
that owned by the organization personally use maybe committed a bit of different ways in the
|
||
|
|
level well I use chat GPT to write a book then I have that's reasonable okay which statements
|
||
|
|
about monitoring privacy is most accurate personal information accompanied devices is private
|
||
|
|
I'll be going to ease confidentiality of personal information accompanied may want to
|
||
|
|
use the school Jamaicans to not assume privacy I think getting stressed about protecting
|
||
|
|
your privacy just come to accept no just never ever assume privacy ever never assume it
|
||
|
|
selectable good password practices keep passwords and authentication in face secure
|
||
|
|
and then I guess I share your account now is MFI yes yeah doubt approval once you didn't
|
||
|
|
initiate doubt share the codes good right when should you lock your screen I heavily disagree with this
|
||
|
|
if there are other controls in place because there are situations you do not want to be
|
||
|
|
unlocking your screen every fucking five minutes you know because for the sake of the little
|
||
|
|
sanity that one has left right only at the end of the day whenever you step away from your
|
||
|
|
office your device yeah all right I mean yeah if I'm sharing this if I'm physically sharing the
|
||
|
|
space with other human beings yes I will want to look my screen I guess if I'm not sharing
|
||
|
|
you know well one my mom may be a secret hacker for the Russian government you know
|
||
|
|
I'm pap she isn't right do you want to instill a new tool on your laptop
|
||
|
|
what should you do yeah get permission I don't I don't have a laptop or I do but I don't use it
|
||
|
|
okay right select elections that reduce risk yeah why about touchments and verify unusual
|
||
|
|
requests yeah I mean this was I was not I don't know if I was not thinking I actually just
|
||
|
|
like I was working an unusual location I did not have my public key for my device I was working
|
||
|
|
instilled on my dev server so I just emailed my colleague and said I can you shove this
|
||
|
|
public key on the dev server and you know he did it but he was like they he came it's actually my
|
||
|
|
self fuzzy he came to me it later and he said actually that seemed a bit like a fishing attempt
|
||
|
|
and I just only realized oh yeah my ver well it was convenient because it allowed me to get some
|
||
|
|
work done that that it didn't actually much big I didn't actually do much that day so it wasn't
|
||
|
|
necessarily all that useful and I think next time I think I might just say well if it's not on this
|
||
|
|
device I just not not work at the moment I just leave the work for a time that I'm actually at
|
||
|
|
my my own device so I think part of fishing is not just don't be fished yourself but don't ask
|
||
|
|
other people to do things that they that they themselves will find a comfortable I don't know
|
||
|
|
and I've got an email just seeing if this okay just confirmation that something will be passed
|
||
|
|
on to the relevant person but we're talking about why I shouldn't have reduced my risk
|
||
|
|
don't forward customer files to personal email well I mean I use I'm sorry but
|
||
|
|
if it's not on my personal email don't see it and well these are not customer files these are
|
||
|
|
these things like API specs or and I just general discussion it's not sensitive information right
|
||
|
|
checks and address carefully yeah okay is acceptable to let a family member use you work can't
|
||
|
|
probably not which is prohibited reports using malicious introducing malicious problems it's
|
||
|
|
systems I mean I can't imagine what would be wrong with that I mean I think wished in in still
|
||
|
|
the virus and that every system you have access to it's just a matter of course
|
||
|
|
port scanning or security scanning a lad with prior authorization
|
||
|
|
but I'm gonna click this one but I'm sorry I'm never ever gonna use any computer system
|
||
|
|
that I have not scanned the ports of I mean I'm sorry that's just it's in my blood you know
|
||
|
|
I will always scan the port right you receive an unexpected invoice attachment from an unknown
|
||
|
|
send a reporting of I don't mean you should I need you should only access systems and that
|
||
|
|
you're offers to use yeah making fraudulent offers I guess prohibited select or
|
||
|
|
prepped installing part of software things in your definition but yeah sharing passwords
|
||
|
|
the nav service attacks keeping your device updated and accepting network traffic not intended for you
|
||
|
|
I I question whether intersection network traffic not intended for you is really prohibited
|
||
|
|
I mean if it's not intended for you it should be encrypted not that I've ever done this but
|
||
|
|
don't put it on me to to be accountable if someone is not if I'm having to use some system
|
||
|
|
and this is not a specific example of something that's actually happened but if I'm using some
|
||
|
|
system and someone is not encrypting their network traffic it's almost my duty you know it's
|
||
|
|
oh yeah I should downwell intercept it and downwell tell them by the way your traffic is not encrypted
|
||
|
|
yeah I don't know you know I tell you this I take it seriously but if someone's telling me
|
||
|
|
something that has right I'll have to chat get my thoughts clarified on this right right I am
|
||
|
|
told in an info set or it never to intercept network traffic not intended for me I have
|
||
|
|
crimes this will be negligent on my part not to be aware of potential hunting
|
||
|
|
cryptid traffic on the network I am connected connecting to as if a security risk affects
|
||
|
|
someone just on the network it then well affects me also so I say there's a
|
||
|
|
monitoring for safety versus another threat's intersection I mean they're saying right I'm
|
||
|
|
getting private data passwords emails are personal browsing of colleagues but I'm not because it
|
||
|
|
is it should be a secured HTTP you know secured DNS oh yeah trigger an ideas an
|
||
|
|
intrusion detection system I forbid sniffing traffic so it's not it's not necessarily because
|
||
|
|
there should be encryption at the app level and endpoint prediction well this is how it puts it says
|
||
|
|
the order isn't asking you to be negligent it's asking you to respect the boundaries of
|
||
|
|
authorization think of it like a hotel you should lock your own door and report fire in the hallway
|
||
|
|
that you aren't allowed to put a glass to the wall to listen to what's happening in the next
|
||
|
|
room just in case there's a thief in there yeah okay like I don't want to sneak on anything
|
||
|
|
and I inherently would not would not but if network traffic is passing through
|
||
|
|
my system such that it can be sniffed it is inherently no longer private it is part of the network
|
||
|
|
traffic I would not on principle try to sneak but I need to be aware of what is going on
|
||
|
|
the network because it also affects me so this depends on putting your network card into
|
||
|
|
promiscuous mode yeah all right so I'm not putting my network card in promiscuous mode
|
||
|
|
what prevent someone else doing so I mean all right it's their risk and it's not my responsibility
|
||
|
|
so yeah you can use ARP watch your neighbor discovery egress monitoring to see what I'm sending
|
||
|
|
out through to call auditing so yeah I can it's a user scanner don't sniff but
|
||
|
|
so say the professional approach is too yeah and what do they mean by intercepting network traffic
|
||
|
|
that's not intended for you as as difference between intercepting and I mean I'm stuck at this point
|
||
|
|
because I think there's there's something important there's not being expressed or discussed
|
||
|
|
but the idea that capturing traffic going through my network the interface on my hardware the traffic
|
||
|
|
is reaching the interface on my hardware that I should not be allowed to
|
||
|
|
register that data if it comes to my hardware I find hard because you know if I'm working for someone
|
||
|
|
it doesn't matter what it is I am not going to even look even if I have to process something
|
||
|
|
there's I'm going to look at anything that's private to that person or to that company or whatever
|
||
|
|
I'm just not going to do that okay the next section is data classification handling and this
|
||
|
|
has questions why do we classify information and that's like is it public as a confidential whatever
|
||
|
|
incentive what sort of information should be restricted like passwords API keys
|
||
|
|
should be confidential files in personal cloud storage now
|
||
|
|
had to share a customer report internally but on some approved storage somewhere
|
||
|
|
so good practices for confidential data at least access need to now
|
||
|
|
remove access for no longer needed large exports of personal data or confidential
|
||
|
|
screenshots can expose data what's the best rule for export so I export the minimum
|
||
|
|
so what common lead points so screenshots log status ports so if you accidentally shared something
|
||
|
|
a link should provide kit and restrict access and report to what happens
|
||
|
|
personal data should be confidential yes restricting information should be shared
|
||
|
|
should be shared and you've all fried people and type with type controls
|
||
|
|
it's fairly straightforward so passwords and multifactual authentication
|
||
|
|
if things like the biggest risk of reusing password is the one breach can compromise
|
||
|
|
more than one account so they use this even a strong password they use it everywhere
|
||
|
|
best way to create passwords password manager generator
|
||
|
|
for your password manager use a strong password and they say lock screen and multi-factor
|
||
|
|
I think biometrics nowadays is probably what you should be using so multi-factor
|
||
|
|
have protect accounts even if password is less stolen yeah so if you receive a multi-factor prompt
|
||
|
|
it's reported you know that you didn't initiate your report here and check the account security
|
||
|
|
you know what is the past phrase you know is is a predictable pattern a good password
|
||
|
|
well in principle no but sometimes sometimes there might be the best solution sometimes
|
||
|
|
there might be a more human solution but it actually works better so who had enough accounts
|
||
|
|
been compromised you get password reset and they didn't request looking alert or
|
||
|
|
you're forwarding rules created and that you didn't do if you accidentally put the credentials
|
||
|
|
in a suspicious page you should report it and change your passwords they have a share passwords yeah
|
||
|
|
I mean the kind of repeating themselves a bit but the next section is security
|
||
|
|
instant reporting in response so apparently as well security instant is any event that could
|
||
|
|
affect confidentiality integrity or availability if you're not sure they'll just wait until you are
|
||
|
|
sure right which of the following is an instant a last laptop and expected them a fake prompt
|
||
|
|
I extend the mainly customer report suspected malware warning okay that some of this is just
|
||
|
|
repeating themselves so don't don't destroy evidence unless instructed so evidence could be screen
|
||
|
|
shops email headers or message IDs time and date of the event so the device is done what's your
|
||
|
|
first action report it using an instant process the instant process is that one
|
||
|
|
extended data sent to the wrong person can be a personal data pressure
|
||
|
|
been how many how many times as everyone received a CC of people's email addresses which was meant to be a
|
||
|
|
CC I mean literally how many times that happened and then one person replies to it and right
|
||
|
|
sends out a 2350 emails to everyone else in that CC list I mean you would almost think they should
|
||
|
|
build it into the email client no one in their right mind wants to see see more than like two people
|
||
|
|
you know it's never efficient social engineering awareness so
|
||
|
|
efficient what is efficient trying to do is trying to trick you into a really information
|
||
|
|
take unsafe actions commission reflects could urgency and pressure are requesting passwords or
|
||
|
|
MFA codes look like the mains to good to be true offers so see how usually I see to buy gift cards
|
||
|
|
which should do verify if I'll independent channel yeah now my sport worker he got
|
||
|
|
fine cool telling him he owed some tax you know they said try your credit card and then he gave them
|
||
|
|
their credit card number and then they said oh that didn't work we'll have to find another way
|
||
|
|
you feed send us the tax that you are us I tell you what why don't you just buy Amazon vouchers
|
||
|
|
and they got him to buy 4,000 pounds worth of Amazon vouchers and send them and it's only like
|
||
|
|
when he went to the supermarket the third or fourth time and was buying a stack of Amazon vouchers
|
||
|
|
they were like someone said a why do you want these Amazon vouchers and he said oh I have to
|
||
|
|
repay some tax and the person said no perhaps you're being scammed and he's like oh oh yeah
|
||
|
|
I guess I could be cure codes can be used in fishing attempts yeah it's quite a good one actually
|
||
|
|
supply says the bank details changed say what she's doing verify by non-channel
|
||
|
|
the best general mindset for fishing prevention is slow down verify unusual requests
|
||
|
|
secure in my working she perhaps relevant to me I don't generally go around with my laptop all
|
||
|
|
over the place it's working from a home PC mean some of these I just click for it because it's
|
||
|
|
not really relevant that all of them I click for it so data protection this is back on the GDPR again
|
||
|
|
personal data is information relating to my identified or identified person
|
||
|
|
data minimization means click only what you need for the purpose so what counts as a person
|
||
|
|
date breach sending personal date the wrong person losing a laptop that might contain personal
|
||
|
|
data posting use it in final public forum and all price access to the account I don't think
|
||
|
|
I know price access to the account is a personal date breach or is that I guess it is
|
||
|
|
storage limitation delete or I'll call for another required what's a DSAR it's when someone says
|
||
|
|
what tell me what date you have about me it's a data it's a data subject access request
|
||
|
|
so which of these roles align with the principles of data protection is data for intended perhaps
|
||
|
|
I need to keep the data secure don't keep data longer than needed yes and an acceptable use of
|
||
|
|
system occasional personal use of company systems may be permitted if it's reasonable
|
||
|
|
so let's go to good password practices keep passwords and authentication if I secure use
|
||
|
|
multiple authentication do not share multi-factor authentication code select actions there
|
||
|
|
are just email risk be careful with unexpected detachment verify unusual requests with a trusted
|
||
|
|
channel check the send address carefully port scanning is allowed with prior authorization only
|
||
|
|
you should only add to systems and date your offer as to use yes if you lose your work laptop
|
||
|
|
what should you do I think you report it okay information secure some of that seems to be
|
||
|
|
paying itself information security awareness this annual out of C I I what best describes
|
||
|
|
confidentiality they choose any accessible to CIA so CIA stands for confidentiality integrity
|
||
|
|
and authorization not a failability so I there are the three pinnacles of information security
|
||
|
|
are confidentiality integrity and the failability just in my experience of
|
||
|
|
availability is the big one because you're much much much more likely so again to travel just
|
||
|
|
not backing up then you are from someone deliberately trying to harm you or still your data
|
||
|
|
or just deleting stuff yourself by anything or thinking that you have backups that you don't
|
||
|
|
and this is kind of high level stuff like data minimization means and and you collect
|
||
|
|
new data necessary purpose the safest way to share sensitive customer information is approved
|
||
|
|
secure company systems with all price access fair enough I mean this I don't really see much
|
||
|
|
actual customer data message been filled for whatever anonymization or anyway I got the
|
||
|
|
stiff cuts go all the stiff cuts those who have a stiff cut like the or valid until
|
||
|
|
it's got the date on it yeah I mean a lot of this comes down to I know the principle
|
||
|
|
the reason for the audit is it's about protecting company and protecting customers information
|
||
|
|
even protecting your own information and being secure about how you're doing things which is
|
||
|
|
over reasonable but it touches on a few areas of it's something that is kind of incidental to it
|
||
|
|
but it's something that highlights for me is something about if you're a developer or a hacker
|
||
|
|
or whatever you know how do you act ethically and there's an episode HPR 3779 that
|
||
|
|
try recorded which is just because you can do a thing and that kind of says things quite well
|
||
|
|
and then there's HPR ego all the way back to 2009 HPR number 61 and 32 records a
|
||
|
|
conversation about computing which is kind of about Ted Queen dependence and moral autonomy
|
||
|
|
and it's sort of freedom demands responsibility and then even even the fair you go all the way
|
||
|
|
about HPR number 2 you have deep geek talking about customization the loss reason and it's like
|
||
|
|
questioning you know why why do you want to think of everything customized everything and you know
|
||
|
|
access all the units and internals of things and it's not really because just because you can do
|
||
|
|
it is because doing so teaches you why systems work as they do
|
||
|
|
You have been listening to the Hacker Public Radio podcast, at hackerpublicradio.org.
|
||
|
|
Today's show was contributed by a HPR listener like yourself.
|
||
|
|
If you ever thought of recording a podcast, then visit the HPR site to find out how easy it really is.
|
||
|
|
Hosting for HPR has been kindly provided by anhonesthost.com, the Internet Archive, rsync.net, and the HPR Community Content Delivery Network.
|
||
|
|
Unless otherwise stated, today's show is released under a Creative Commons Attribution-ShareAlike 4.0 International (CC BY-SA 4.0) license.
|