Update metadata and transcripts through end of July 2026
Refreshed episodes/hosts/comments/series from hpr.sql, and added official HPR transcripts for the 180 episodes aired since the last sync (hpr4516-hpr4695).
This commit is contained in:
@@ -0,0 +1,451 @@
|
||||
Episode: 4615
|
||||
Title: Clicking through an audit
|
||||
Source: https://hub.hackerpublicradio.org/ccdn.php?filename=/eps/hpr4615/hpr4615.mp3
|
||||
Transcribed: 2026-07-31 16:15:11 (official HPR transcript)
|
||||
|
||||
---
|
||||
|
||||
This is Hacker Public Radio Episode 4615, for 2026-04-10
|
||||
Today's show is entitled, "Clicking through an audit"
|
||||
The host is Lee and the duration is 00:57:58
|
||||
The flag is Explicit, and the license is CC-BY-SA
|
||||
The summary is "Lee complies with a company audit by clicking 'next' a lot"
|
||||
hello this is Lee today going to kind of walk through the stages of the administration around
|
||||
complying with a security order as an individual employee whose company has been audited and
|
||||
the standard that they're using is ISO 27,000 and one. So you know they've been given what is
|
||||
turned an information security management system and that's a specific term that has been
|
||||
established and now what every employee has been given a checklist effectively or a set of
|
||||
training to go through and you know just see what their compliance is because right firstly I
|
||||
don't think it's sort of expected to be perfect from day one you know goodly it's a process
|
||||
it's not like you tick you tick the box once and then it's done and also it's like it's
|
||||
a responsibility of everyone in the company it's like from the directors to every employee
|
||||
turn them up a computer and I've looked onto the internet and I go to my training dashboard
|
||||
and there's 12 outstanding items that I have to go through and these are ISMS portal access
|
||||
information security management system and actually they're they're actually a company
|
||||
who have taken that on it's their name quite cleverly and policy pack and knowledgeman
|
||||
change management and secure configuration secure software dev security basics access control
|
||||
and lease privilege data classification and handling passwords multifactor authentication
|
||||
security security incident reporting and response phishing and social engineering awareness
|
||||
secure remote working in mobile device security they protection and privacy GDPR awareness and
|
||||
sure no it doesn't know GDPR is the general data protection regulation which this came into
|
||||
force prior to the UK leaving the year and it was you know when Brexit happened then it became
|
||||
in this country the data protection act 2018 but GDPR was the big push that came around
|
||||
the towards the end of the last decade to really take seriously how people's data was being used
|
||||
and it while it was kind of European ladies had global impact anyway so the other training
|
||||
item acceptable use of system and information security awareness and apparently that's an annual
|
||||
thing because it's got in quotes annual so going to the first item in the outstanding list the
|
||||
portal access and policy pack and knowledgeman so it's as login to that I did before but
|
||||
let's just do it again to make sure so it goes to the website of and this and I'll go to login
|
||||
except some cookies the click login except as some cookies then what right after login again
|
||||
go to last pass try and find what my password was and of course it says unsuccessful because
|
||||
always is facing the email address it's in my password again from last pass remember they see
|
||||
my address I guess login no so what can I do all right it gets us if your organization is using
|
||||
our EU dense date center please sign in here they could have led with that and I still sign
|
||||
in unsuccessful need help looking in and to your email address okay it's the company in my address
|
||||
so email mail link to reset my password it says if this is good if the email was registered
|
||||
then we've emailed your link yeah if it wasn't registered you're just elistinating or you
|
||||
some bad hacker person trying to login such is a good team out choose the thing and it says
|
||||
we've locked your that's lovely I mean this is beautiful isn't it we've locked your account
|
||||
and it's in reset your password I mean it's not like I like swearing and it's not like I like
|
||||
using for little words but I have just internally uttered one describing the people who's out
|
||||
the system he is the same email that's registered you know it's spelling of your email address
|
||||
no email link in a second time of asking that so even Gmail thinks this is spam so
|
||||
had I tell you it's not other show images okay for some reason that show me an image of their
|
||||
logo like that was important enough to cause me to have to go through the show images thing
|
||||
that they had to include an image right I've got a link in trainee password well
|
||||
I don't know intranue password paste in the same password that change password yeah
|
||||
great it worked okay this miss um so I'm looking at my my first one is 9 shape sent in the
|
||||
way for a it's called development and of course the truth is I just when you're doing
|
||||
that something like this the truth is if someone if someone gives you a list of 10 things to do
|
||||
you will do those 10 things someone gives you a list of 100 things to do you will just click
|
||||
through them you know I'm sorry this is human nature and you know they should know this
|
||||
very very well you're just click click click click click click click click click you know I can't
|
||||
actually see what's going on because my dark mode is interfering but actually these are ticks I've
|
||||
got ticks against everything but why is it saying there's number 92 isn't done so it was social
|
||||
social media guidelines so I mustn't bring the company into disrepair by criticising
|
||||
our argument of customers, colleagues or rivals making the famigy comments about individuals
|
||||
organisations or groups or posting inappropriate images or links to inappropriate content okay
|
||||
well they got fully breached that already just by recording this policy pack overview
|
||||
it's not letting me get out the last policy and I think I had this it was like an empty
|
||||
it was a boiler plate one your policy packs and our value was an app that you can install in your
|
||||
device it's not going to like increase the risk of my device to install their thing on my device
|
||||
did I close that right let's actually go through what these policies are so introduction
|
||||
policies and controls policies for information security information security roles and responsibilities
|
||||
segregation of duties management responsibilities content with authorities content with special
|
||||
interest groups threat intelligence information security and project management in the trip I mean
|
||||
you know this but living in another universe yeah fine if I mean if I can think of how to do better
|
||||
I would do how would I do this better or not give someone 100 things to click for a
|
||||
literally a hundred well 91 92 if you count the one that's broken looking for those is there any
|
||||
that is actually hyper relevant that's something I don't already know I mean yeah this is fine
|
||||
but it's boiler plate you know I should not be I'm not talking about means particular but
|
||||
and employee should not be given stuff that's actually outside their control like access rights
|
||||
and it's like a broad policy about access rights it's like you know denied by default need to
|
||||
know need to use least privilege privacy by design privacy by default access provision
|
||||
access modification access removal privilege access management roles and responsibilities
|
||||
and actually they've got some specific information about who's has different roles which is useful
|
||||
but apart from that it's a boiler plate and it's a completely outside of the person clicking
|
||||
for it this and I'm assuming everyone in the company has to click for it this is outside of their
|
||||
control it's like saying I don't know account provisioning is automated for integration with
|
||||
the HR onboarding presence and it's like okay that's fine I'm happy with that but why am I
|
||||
having to click for it because it's completely outside of my control what the HR onboarding
|
||||
process it's I mean fine this is this is in one place but I should not be the person clicking
|
||||
through something that I have no control over and then you know and somehow that it means that the
|
||||
company is compliant because someone who has no control over something clicked through something
|
||||
telling them stuff they have no control over and I'm not criticizing the terrific company
|
||||
I'm not even maybe criticizing the this particular provider of the security policy I'm just saying
|
||||
that it's a bit ludicrous for an information security management system to be presented in this way
|
||||
to people it needs to be a lot more relevant it needs to be like 10 bullet points of what is actually
|
||||
relevant specifically to you not this is the entire policy read it through and yes it's here as a
|
||||
reference and that's good that it's as a reference but anyway I can't complete this because it's
|
||||
and I actually told my supervisor he got stuck at this point so is there anything else
|
||||
I'm like again this website it's got no navigation so I don't know how to get back to where
|
||||
was it here we go is the dashboard so it's a two list I mean that's useful let's give me a two to do
|
||||
list information asset inventory is interesting this is quite good actually it's got like
|
||||
some third party systems listed like accounting systems it has things like you know the card
|
||||
that would get you in the office it talks about the code repository and for each of these it says
|
||||
whether confidential or sensitive and like customer data and database is what do they mean by digital
|
||||
certificates it's a I'm unclear that specifically what digital certificates it's referring to
|
||||
if it doesn't mean writing encryption keys and see what I'm actually looking for is my
|
||||
private keys that access the server because that's actually something I have a reasonable level of
|
||||
concern over office keys physical yeah so all right so I'm sorry I'm rambling but for each of
|
||||
these information assets we have like the name like backup data we have it a status or it's
|
||||
to do or live a financial value and that seems to be left blank and then the type of thing
|
||||
that it is is it staff as a physical security as an infrastructure as a person of data
|
||||
is it software application and services and then as a classification as it is sensitive or confidential
|
||||
or public and then we have its primary location like third party data sent to or in person
|
||||
and then you have the owner of the lead so is it the CEO or the chief technology officer
|
||||
and then it has an RTO it's going to tell me what RTO means it has an RPO have to look nice up
|
||||
have recovery point objective all right how long right so if this asset get got lost how much
|
||||
data which you lose which you lose a day a week a month or everything yeah I don't know
|
||||
and what's it was RPO so it's RTO there's the downtime so how long until it's back online
|
||||
so like if you lost it how long will it take you not not just how much it
|
||||
RPO is how much you lost and RTO is the recovery time objective which is how long will it take
|
||||
to actually get it back working and then it has the lead wire no like who I'm this thing is
|
||||
of the companies that supplier or I guess is it the customer or someone else and then it has
|
||||
an assignment so it's a scientific and a member of staff some particular person is on the list of
|
||||
what they're responsible for so okay and back here seems like it's in that's at 99% and I'm sorry
|
||||
the the asset inventory doesn't have percentage on it so the policies and controls that's at
|
||||
90% have I don't remember actually looking at that okay it's popped up around and pop up
|
||||
that you just get rid of because I can't even figure out what the pop up is trying to tell you
|
||||
it's just in not that it's not in English it's just the English the English does not
|
||||
process as to anything that I know what it's talking about so it has requirements and it has the
|
||||
number 4.1 to 10.2 organizational controls people controls physical controls technological controls
|
||||
addition so control is basically what we're doing to make sure that things are secure and that
|
||||
and this is what I learned when I was doing the post-graduate course in information security what is
|
||||
a control and most of these are showing us being complete I wonder if that's truly the case that's
|
||||
what it's showing or like most of them I like that could be that 99% of 99% of them are actually
|
||||
trivial and just require a tick by someone and then like the other 1% require masses of time and
|
||||
effort to do so whether this percentage truly represents the security of the organization I don't
|
||||
know all right I mean I've done everything on this I can so I'm going back the inter
|
||||
closed all these tabs you know people get annoyed when I close their tabs and I can't work
|
||||
with with more than one tab you know once I've once I've done with the tab it gets closed
|
||||
so I've done the policy pad read the policies mark the policy pads read I'm not sure I did this
|
||||
try to and then it says start the course it confirms that you can access it oh no they're not
|
||||
going to ask me to give them a screenshot to prove that I accessed it please no it's not all right
|
||||
so I can successfully access it yeah acknowledgement I've read an understood yeah kind of yes
|
||||
evidence optional yeah they they want a screenshot and it says optional but I you know I'm going
|
||||
out by the screenshot so I've got I've got my nice little dashboard here from the compliance website
|
||||
what screenshot you've got I've got spectacle so let me just grab the active window so click on the
|
||||
active window and it's just grabbed it I had a one second did I have a one second delay I
|
||||
give me a chance to like move my mouse out the way or whatever although when you grab I think
|
||||
when you grab the active window it doesn't capture your mouse it's a save as shove on the desktop
|
||||
because it's screenshot do you what does it call it so it has the day in as in the four
|
||||
digit year the two digit month and the two digit date and then it has a number it's maybe the number
|
||||
of seconds zero nine three three one zero because 86 something thousand seconds in the day so
|
||||
now looking through looking up while a little clock here using the time system or friend Ben I
|
||||
invented and it's three sevens of the way through the day so how many seconds it's going to be like
|
||||
out by six thousand we thirty thousand seconds so I don't think this is the number of seconds
|
||||
Ben I's given it a number zero nine three three one zero in the screenshot you'll be
|
||||
interesting to know how those screenshots are derived a screenshot font names right so save that
|
||||
saved go back to there I should drag the image on here and then was the okay
|
||||
bum that it's safe comments okay so let's just say it seemed the last policy could not be
|
||||
access I can down like this course material so it's open it in a new browser window and then
|
||||
I click on the download link I think I've got a security folder so I'm just dropping it into
|
||||
there I've got my own copy of it and click and complete and that's completed I said it would take
|
||||
five to ten minutes so you look at it longer so once done now I've only got 11 outstanding out of
|
||||
12 so now the next one is change management and secure configuration right so you know learning
|
||||
objectives modules why change control matters yeah avoid unsafe shortcuts document changes
|
||||
appropriately prioritize secure configuration so it's good so when subversion I don't know
|
||||
that way so when subversion can be fucks up everything I mean right this is my my human
|
||||
experience of version control systems like get and subversion they work fine until you just
|
||||
accidentally click or type the wrong thing then you're in the world of pain and you're then
|
||||
spending hours or whatever trying to undo the thing that you've done like I accidentally on subversion
|
||||
I was gonna use a change list so I was only gonna commit the few changes that I wanted to
|
||||
and leave out the files that didn't want it to because I was working on two three different
|
||||
projects at once then one of lumped them all into one commit and I accidentally committed everything
|
||||
and then you go to like google you go to um large language model and you say like right how
|
||||
do I undo this and it says oh to undo this just type this and it's a type here and oh look it's
|
||||
screwed up even more and then I'm not like saying tell it well now this is what the situation is
|
||||
I'll now just do this and so I can't do that and now it's completely fucked up beyond the
|
||||
recognition and in the end you end up you just I think I'm just gonna
|
||||
nuke from all the I just completely abandoned the repository that was on and create a new repository
|
||||
a new development branch and just reclaim the development branch from the
|
||||
source and then just copy my files that I've got you know on my own like machine
|
||||
copy the files that you've been working to back on and of course you know because I've just
|
||||
just because of because I've now got the latest code running you know there's configuration issues
|
||||
because I've failed to coordinate with other people in the team who have updated the data by schema
|
||||
and so the you know the entire my entire development platform is now not working it's now down
|
||||
because it's falling over something and the schema is different and not in line with the code
|
||||
so I mean that's that's the reality of third of I guess they call it change control version
|
||||
chart I mean the lucky thing is I just have not been given access to anything where I could
|
||||
damage a production system I could damage my own system and to some extent I could
|
||||
insert unhelpful data you know by mistake into the shared the shared where we keep the
|
||||
database not the database schema not the level I level one but the customer level database schema
|
||||
and the you know the different templates and forms and how they're managed how their
|
||||
data is synchronized between different instances of the server there's a central location for that
|
||||
and yeah I could in some way insert things into there then there would then you know need to
|
||||
kind of undo that and restore that because then it makes it unusable for other people if they
|
||||
wanted to sink from it but you know I'd have to be willfully and willfully stupid if I was
|
||||
doing that so all right so I'm just looking at the learning objectives for this yeah I mean yeah
|
||||
back in the 90s I worked a company that had proper change control and it was as in you know
|
||||
in in in in some ways it kept you safe in other ways it's and as annoying as hell if you make a
|
||||
tiny little error and it means you're having to walk through the entire change control
|
||||
processes taking two or three days you have to get customer approval again just because you
|
||||
made a typo that you didn't spot and it didn't get spied until later in the change control process
|
||||
and you know probably reasons like that that you have this is why they invented DevOps
|
||||
is to reduce the amount of friction for developers while keeping things reasonably safe for the
|
||||
ops team that things are going to kind of flow and not be complete headache and then I like
|
||||
this is like if there's an emergency change you still you have to like because you know there are
|
||||
times when a production system actually needs an intervention there and then and you can't go
|
||||
through the whole change control but when that happens that the same that needs to be documented
|
||||
and followed up you know that's a nice happy wish I would say change management school not
|
||||
to check all right here's a quiz right why do we change the control I love this to slow down work
|
||||
I mean honestly yes yeah we're still to reduce attitudes yeah and security risks and improve
|
||||
accountability right misconfiguration is a common course of incidents yes all right some bit you
|
||||
know can do this quiz all right I'm spacing right secure configuration practising include
|
||||
default deny and release privilege I guess yeah disabled unused services yes public by default
|
||||
for convenience now avoid public access unless and quiet and approved yes after deploying a change
|
||||
what should you do I think we want to invalidate emergency changes should be documented
|
||||
good rollback plan is and now not wait to refer on where to go quickly okay so I've got to take from
|
||||
that month that is complete cause it's completed to significantly less than 23 minutes I don't know
|
||||
what my past month was didn't tell me what my month was they said the past month was 80% cool that
|
||||
once that's off the list so secure software dev security basics protects secrets and credentials
|
||||
never encode tickets or chat by secure coding hygiene validation or frozen what is off said me
|
||||
no okay don't know offset what is off said in information security which means authorization okay
|
||||
I've got feeling in English in the English language authorization has got an S I think often
|
||||
not try and use the American version cause when you're coding you try and use the American English
|
||||
like color no color right when it's dependent since supply chain that's yeah okay
|
||||
understand what that means I use code review and continuous integration controls to reduce
|
||||
vulnerabilities code review yes C I controls I don't know if that's kind of a happy wish at this point
|
||||
avoid risky logging and sorry I'm using the word happy wish I just wish the original
|
||||
then even know where I got that from what is the origin of the term happy wish and how does this
|
||||
seem to be keep coming to mind as I fail in the information security or the compliance
|
||||
question it tell me it's a psychological reaction to inherent tension of compliance work
|
||||
is a gap between policy and reality aspirational compliance you may be looking at question
|
||||
like are all administrative actions logged and reviewed weekly and thinking I wish they were
|
||||
or in a perfect world they would be the checkbox track the term captures the feeling of providing
|
||||
a happy answer yes we're doing this well internally now it's more of a wish than the consistent
|
||||
enforced control it's a mental shorthand for wishful thinking masquerading as a security control
|
||||
I mean I've been doing this for like a half and 25 minutes I've already got ordered with
|
||||
he so I can well let's start the course I mean ideally it should be prompting you to
|
||||
actually do something not just think I'll idea so here we go knowledge check I mean it was telling
|
||||
me stuff I just give that go straight to the knowledge check right authentication is
|
||||
who you are authorization is what you're allowed to do if you're an authenticated they can access
|
||||
any object of the name where should secrets not be stored when a QR code on your front door
|
||||
that source code repository is tickets chat see I've got all of the above
|
||||
and except for the approved secrets manager you accidentally committed the API key
|
||||
I revoke and rotate as I find side validation is sufficient yeah no it's not it's not
|
||||
best protection against SQL injection yeah prepared statements I don't see that a lot in the code
|
||||
place supply chain risks include what is type I squatting all right okay you give you the
|
||||
main like google dot com you go to google dot com you type in some secure information
|
||||
come for myest maintainer accounts code reviews in the risk it's negative
|
||||
pinning and reviewing dependency changes can reduce risk yeah pinning is where you fix it
|
||||
certain version you don't just automatically update to the next version until you've decided that it's
|
||||
safe to do so yeah they're talking about pull requests here that that may exist on
|
||||
may exist in other parts of the universe it I've never seen it in this context so why
|
||||
while do we disable CI checks ask for justification yeah least privilege for service account
|
||||
remains I give any permissions needed right production access should be limited in the trial
|
||||
to guess yes good logging practice include for that thing yeah deadlock for personal data
|
||||
payloads control access to logs yeah using production data and development is yeah with approval
|
||||
controls temporary secrets in code all right I mean I might disagree with this it depends what
|
||||
codes but okay yeah not acceptable anyway I can download that PDF save it I think that one's done
|
||||
that click on complete or I'll neatly the deadline is the first of April but I'm down to nine
|
||||
outstanding things so access controls in this privilege right it's a completely skip everything
|
||||
I just click start course completely skip everything down to acceptable use of systems
|
||||
that owned by the organization personally use maybe committed a bit of different ways in the
|
||||
level well I use chat GPT to write a book then I have that's reasonable okay which statements
|
||||
about monitoring privacy is most accurate personal information accompanied devices is private
|
||||
I'll be going to ease confidentiality of personal information accompanied may want to
|
||||
use the school Jamaicans to not assume privacy I think getting stressed about protecting
|
||||
your privacy just come to accept no just never ever assume privacy ever never assume it
|
||||
selectable good password practices keep passwords and authentication in face secure
|
||||
and then I guess I share your account now is MFI yes yeah doubt approval once you didn't
|
||||
initiate doubt share the codes good right when should you lock your screen I heavily disagree with this
|
||||
if there are other controls in place because there are situations you do not want to be
|
||||
unlocking your screen every fucking five minutes you know because for the sake of the little
|
||||
sanity that one has left right only at the end of the day whenever you step away from your
|
||||
office your device yeah all right I mean yeah if I'm sharing this if I'm physically sharing the
|
||||
space with other human beings yes I will want to look my screen I guess if I'm not sharing
|
||||
you know well one my mom may be a secret hacker for the Russian government you know
|
||||
I'm pap she isn't right do you want to instill a new tool on your laptop
|
||||
what should you do yeah get permission I don't I don't have a laptop or I do but I don't use it
|
||||
okay right select elections that reduce risk yeah why about touchments and verify unusual
|
||||
requests yeah I mean this was I was not I don't know if I was not thinking I actually just
|
||||
like I was working an unusual location I did not have my public key for my device I was working
|
||||
instilled on my dev server so I just emailed my colleague and said I can you shove this
|
||||
public key on the dev server and you know he did it but he was like they he came it's actually my
|
||||
self fuzzy he came to me it later and he said actually that seemed a bit like a fishing attempt
|
||||
and I just only realized oh yeah my ver well it was convenient because it allowed me to get some
|
||||
work done that that it didn't actually much big I didn't actually do much that day so it wasn't
|
||||
necessarily all that useful and I think next time I think I might just say well if it's not on this
|
||||
device I just not not work at the moment I just leave the work for a time that I'm actually at
|
||||
my my own device so I think part of fishing is not just don't be fished yourself but don't ask
|
||||
other people to do things that they that they themselves will find a comfortable I don't know
|
||||
and I've got an email just seeing if this okay just confirmation that something will be passed
|
||||
on to the relevant person but we're talking about why I shouldn't have reduced my risk
|
||||
don't forward customer files to personal email well I mean I use I'm sorry but
|
||||
if it's not on my personal email don't see it and well these are not customer files these are
|
||||
these things like API specs or and I just general discussion it's not sensitive information right
|
||||
checks and address carefully yeah okay is acceptable to let a family member use you work can't
|
||||
probably not which is prohibited reports using malicious introducing malicious problems it's
|
||||
systems I mean I can't imagine what would be wrong with that I mean I think wished in in still
|
||||
the virus and that every system you have access to it's just a matter of course
|
||||
port scanning or security scanning a lad with prior authorization
|
||||
but I'm gonna click this one but I'm sorry I'm never ever gonna use any computer system
|
||||
that I have not scanned the ports of I mean I'm sorry that's just it's in my blood you know
|
||||
I will always scan the port right you receive an unexpected invoice attachment from an unknown
|
||||
send a reporting of I don't mean you should I need you should only access systems and that
|
||||
you're offers to use yeah making fraudulent offers I guess prohibited select or
|
||||
prepped installing part of software things in your definition but yeah sharing passwords
|
||||
the nav service attacks keeping your device updated and accepting network traffic not intended for you
|
||||
I I question whether intersection network traffic not intended for you is really prohibited
|
||||
I mean if it's not intended for you it should be encrypted not that I've ever done this but
|
||||
don't put it on me to to be accountable if someone is not if I'm having to use some system
|
||||
and this is not a specific example of something that's actually happened but if I'm using some
|
||||
system and someone is not encrypting their network traffic it's almost my duty you know it's
|
||||
oh yeah I should downwell intercept it and downwell tell them by the way your traffic is not encrypted
|
||||
yeah I don't know you know I tell you this I take it seriously but if someone's telling me
|
||||
something that has right I'll have to chat get my thoughts clarified on this right right I am
|
||||
told in an info set or it never to intercept network traffic not intended for me I have
|
||||
crimes this will be negligent on my part not to be aware of potential hunting
|
||||
cryptid traffic on the network I am connected connecting to as if a security risk affects
|
||||
someone just on the network it then well affects me also so I say there's a
|
||||
monitoring for safety versus another threat's intersection I mean they're saying right I'm
|
||||
getting private data passwords emails are personal browsing of colleagues but I'm not because it
|
||||
is it should be a secured HTTP you know secured DNS oh yeah trigger an ideas an
|
||||
intrusion detection system I forbid sniffing traffic so it's not it's not necessarily because
|
||||
there should be encryption at the app level and endpoint prediction well this is how it puts it says
|
||||
the order isn't asking you to be negligent it's asking you to respect the boundaries of
|
||||
authorization think of it like a hotel you should lock your own door and report fire in the hallway
|
||||
that you aren't allowed to put a glass to the wall to listen to what's happening in the next
|
||||
room just in case there's a thief in there yeah okay like I don't want to sneak on anything
|
||||
and I inherently would not would not but if network traffic is passing through
|
||||
my system such that it can be sniffed it is inherently no longer private it is part of the network
|
||||
traffic I would not on principle try to sneak but I need to be aware of what is going on
|
||||
the network because it also affects me so this depends on putting your network card into
|
||||
promiscuous mode yeah all right so I'm not putting my network card in promiscuous mode
|
||||
what prevent someone else doing so I mean all right it's their risk and it's not my responsibility
|
||||
so yeah you can use ARP watch your neighbor discovery egress monitoring to see what I'm sending
|
||||
out through to call auditing so yeah I can it's a user scanner don't sniff but
|
||||
so say the professional approach is too yeah and what do they mean by intercepting network traffic
|
||||
that's not intended for you as as difference between intercepting and I mean I'm stuck at this point
|
||||
because I think there's there's something important there's not being expressed or discussed
|
||||
but the idea that capturing traffic going through my network the interface on my hardware the traffic
|
||||
is reaching the interface on my hardware that I should not be allowed to
|
||||
register that data if it comes to my hardware I find hard because you know if I'm working for someone
|
||||
it doesn't matter what it is I am not going to even look even if I have to process something
|
||||
there's I'm going to look at anything that's private to that person or to that company or whatever
|
||||
I'm just not going to do that okay the next section is data classification handling and this
|
||||
has questions why do we classify information and that's like is it public as a confidential whatever
|
||||
incentive what sort of information should be restricted like passwords API keys
|
||||
should be confidential files in personal cloud storage now
|
||||
had to share a customer report internally but on some approved storage somewhere
|
||||
so good practices for confidential data at least access need to now
|
||||
remove access for no longer needed large exports of personal data or confidential
|
||||
screenshots can expose data what's the best rule for export so I export the minimum
|
||||
so what common lead points so screenshots log status ports so if you accidentally shared something
|
||||
a link should provide kit and restrict access and report to what happens
|
||||
personal data should be confidential yes restricting information should be shared
|
||||
should be shared and you've all fried people and type with type controls
|
||||
it's fairly straightforward so passwords and multifactual authentication
|
||||
if things like the biggest risk of reusing password is the one breach can compromise
|
||||
more than one account so they use this even a strong password they use it everywhere
|
||||
best way to create passwords password manager generator
|
||||
for your password manager use a strong password and they say lock screen and multi-factor
|
||||
I think biometrics nowadays is probably what you should be using so multi-factor
|
||||
have protect accounts even if password is less stolen yeah so if you receive a multi-factor prompt
|
||||
it's reported you know that you didn't initiate your report here and check the account security
|
||||
you know what is the past phrase you know is is a predictable pattern a good password
|
||||
well in principle no but sometimes sometimes there might be the best solution sometimes
|
||||
there might be a more human solution but it actually works better so who had enough accounts
|
||||
been compromised you get password reset and they didn't request looking alert or
|
||||
you're forwarding rules created and that you didn't do if you accidentally put the credentials
|
||||
in a suspicious page you should report it and change your passwords they have a share passwords yeah
|
||||
I mean the kind of repeating themselves a bit but the next section is security
|
||||
instant reporting in response so apparently as well security instant is any event that could
|
||||
affect confidentiality integrity or availability if you're not sure they'll just wait until you are
|
||||
sure right which of the following is an instant a last laptop and expected them a fake prompt
|
||||
I extend the mainly customer report suspected malware warning okay that some of this is just
|
||||
repeating themselves so don't don't destroy evidence unless instructed so evidence could be screen
|
||||
shops email headers or message IDs time and date of the event so the device is done what's your
|
||||
first action report it using an instant process the instant process is that one
|
||||
extended data sent to the wrong person can be a personal data pressure
|
||||
been how many how many times as everyone received a CC of people's email addresses which was meant to be a
|
||||
CC I mean literally how many times that happened and then one person replies to it and right
|
||||
sends out a 2350 emails to everyone else in that CC list I mean you would almost think they should
|
||||
build it into the email client no one in their right mind wants to see see more than like two people
|
||||
you know it's never efficient social engineering awareness so
|
||||
efficient what is efficient trying to do is trying to trick you into a really information
|
||||
take unsafe actions commission reflects could urgency and pressure are requesting passwords or
|
||||
MFA codes look like the mains to good to be true offers so see how usually I see to buy gift cards
|
||||
which should do verify if I'll independent channel yeah now my sport worker he got
|
||||
fine cool telling him he owed some tax you know they said try your credit card and then he gave them
|
||||
their credit card number and then they said oh that didn't work we'll have to find another way
|
||||
you feed send us the tax that you are us I tell you what why don't you just buy Amazon vouchers
|
||||
and they got him to buy 4,000 pounds worth of Amazon vouchers and send them and it's only like
|
||||
when he went to the supermarket the third or fourth time and was buying a stack of Amazon vouchers
|
||||
they were like someone said a why do you want these Amazon vouchers and he said oh I have to
|
||||
repay some tax and the person said no perhaps you're being scammed and he's like oh oh yeah
|
||||
I guess I could be cure codes can be used in fishing attempts yeah it's quite a good one actually
|
||||
supply says the bank details changed say what she's doing verify by non-channel
|
||||
the best general mindset for fishing prevention is slow down verify unusual requests
|
||||
secure in my working she perhaps relevant to me I don't generally go around with my laptop all
|
||||
over the place it's working from a home PC mean some of these I just click for it because it's
|
||||
not really relevant that all of them I click for it so data protection this is back on the GDPR again
|
||||
personal data is information relating to my identified or identified person
|
||||
data minimization means click only what you need for the purpose so what counts as a person
|
||||
date breach sending personal date the wrong person losing a laptop that might contain personal
|
||||
data posting use it in final public forum and all price access to the account I don't think
|
||||
I know price access to the account is a personal date breach or is that I guess it is
|
||||
storage limitation delete or I'll call for another required what's a DSAR it's when someone says
|
||||
what tell me what date you have about me it's a data it's a data subject access request
|
||||
so which of these roles align with the principles of data protection is data for intended perhaps
|
||||
I need to keep the data secure don't keep data longer than needed yes and an acceptable use of
|
||||
system occasional personal use of company systems may be permitted if it's reasonable
|
||||
so let's go to good password practices keep passwords and authentication if I secure use
|
||||
multiple authentication do not share multi-factor authentication code select actions there
|
||||
are just email risk be careful with unexpected detachment verify unusual requests with a trusted
|
||||
channel check the send address carefully port scanning is allowed with prior authorization only
|
||||
you should only add to systems and date your offer as to use yes if you lose your work laptop
|
||||
what should you do I think you report it okay information secure some of that seems to be
|
||||
paying itself information security awareness this annual out of C I I what best describes
|
||||
confidentiality they choose any accessible to CIA so CIA stands for confidentiality integrity
|
||||
and authorization not a failability so I there are the three pinnacles of information security
|
||||
are confidentiality integrity and the failability just in my experience of
|
||||
availability is the big one because you're much much much more likely so again to travel just
|
||||
not backing up then you are from someone deliberately trying to harm you or still your data
|
||||
or just deleting stuff yourself by anything or thinking that you have backups that you don't
|
||||
and this is kind of high level stuff like data minimization means and and you collect
|
||||
new data necessary purpose the safest way to share sensitive customer information is approved
|
||||
secure company systems with all price access fair enough I mean this I don't really see much
|
||||
actual customer data message been filled for whatever anonymization or anyway I got the
|
||||
stiff cuts go all the stiff cuts those who have a stiff cut like the or valid until
|
||||
it's got the date on it yeah I mean a lot of this comes down to I know the principle
|
||||
the reason for the audit is it's about protecting company and protecting customers information
|
||||
even protecting your own information and being secure about how you're doing things which is
|
||||
over reasonable but it touches on a few areas of it's something that is kind of incidental to it
|
||||
but it's something that highlights for me is something about if you're a developer or a hacker
|
||||
or whatever you know how do you act ethically and there's an episode HPR 3779 that
|
||||
try recorded which is just because you can do a thing and that kind of says things quite well
|
||||
and then there's HPR ego all the way back to 2009 HPR number 61 and 32 records a
|
||||
conversation about computing which is kind of about Ted Queen dependence and moral autonomy
|
||||
and it's sort of freedom demands responsibility and then even even the fair you go all the way
|
||||
about HPR number 2 you have deep geek talking about customization the loss reason and it's like
|
||||
questioning you know why why do you want to think of everything customized everything and you know
|
||||
access all the units and internals of things and it's not really because just because you can do
|
||||
it is because doing so teaches you why systems work as they do
|
||||
You have been listening to the Hacker Public Radio podcast, at hackerpublicradio.org.
|
||||
Today's show was contributed by a HPR listener like yourself.
|
||||
If you ever thought of recording a podcast, then visit the HPR site to find out how easy it really is.
|
||||
Hosting for HPR has been kindly provided by anhonesthost.com, the Internet Archive, rsync.net, and the HPR Community Content Delivery Network.
|
||||
Unless otherwise stated, today's show is released under a Creative Commons Attribution-ShareAlike 4.0 International (CC BY-SA 4.0) license.
|
||||
Reference in New Issue
Block a user