1
00:00:06,720 --> 00:00:10,360
Welcome to the Blue Security 
Podcast, a weekly podcast for 

2
00:00:10,360 --> 00:00:13,600
information security defenders 
where we bring you discussions 

3
00:00:13,600 --> 00:00:17,000
on best practices, tools, and 
implementation for enterprise 

4
00:00:17,000 --> 00:00:19,240
security. 
Now here are your hosts for 

5
00:00:19,240 --> 00:00:21,800
today's show, Andy JA and Adam 
Brewer. 

6
00:00:24,360 --> 00:00:27,360
Welcome to this week's episode 
of the Blue Security Podcast. 

7
00:00:27,480 --> 00:00:30,600
I'm Andy, your host. 
I am Adam, your Co host. 

8
00:00:31,440 --> 00:00:34,520
All right, so often times when 
I'm looking for stuff to talk 

9
00:00:34,520 --> 00:00:38,160
about, I'll find things that 
like I'm using personally or 

10
00:00:38,160 --> 00:00:39,520
things that affect me 
personally. 

11
00:00:39,520 --> 00:00:44,160
And so this story really piqued 
my interest because this was 

12
00:00:44,160 --> 00:00:46,360
actually something that came out
a few weeks ago. 

13
00:00:46,360 --> 00:00:49,320
And then I read the story and I 
was kind of a little concerned 

14
00:00:49,320 --> 00:00:52,720
and then I found the story that 
the bug was was fixed. 

15
00:00:52,720 --> 00:00:56,600
So what happened was there was a
story that came out a few weeks 

16
00:00:56,600 --> 00:01:00,600
ago that talked about the Signal
encrypted chat, right? 

17
00:01:00,600 --> 00:01:03,600
So we've talked about Signal on 
this show before. 

18
00:01:03,880 --> 00:01:08,200
It's something that I use daily,
one of the most secure consumer 

19
00:01:08,520 --> 00:01:11,680
end to end encrypted messaging 
apps that's out there. 

20
00:01:12,280 --> 00:01:15,040
And So what happened was, and 
This is why I kind of piqued my 

21
00:01:15,040 --> 00:01:19,680
interest, was there was a story 
that said the FBI was actually 

22
00:01:19,680 --> 00:01:25,000
able to extract deleted signal 
messages from a suspect's iPhone

23
00:01:25,000 --> 00:01:29,920
using some forensic tools. 
And the content of the messages 

24
00:01:29,920 --> 00:01:32,280
have been displayed in a 
notification. 

25
00:01:32,800 --> 00:01:36,400
So like when when you have your 
lock screen and the notification

26
00:01:36,400 --> 00:01:39,320
comes up and might see a preview
or something of that message 

27
00:01:39,880 --> 00:01:44,040
that was stored inside the 
phone's database even after the 

28
00:01:44,040 --> 00:01:47,960
messages inside of the Signal 
app were deleted. 

29
00:01:48,320 --> 00:01:51,120
And so in the specific case that
exposed this, the messages were 

30
00:01:51,120 --> 00:01:54,760
able to be recovered from the 
defendant's phone in connection 

31
00:01:54,760 --> 00:01:58,160
with an attack on the Prairie 
Land ICE Detention Center 

32
00:01:58,160 --> 00:02:00,320
facility. 
And then Signal had been removed

33
00:02:00,320 --> 00:02:03,240
from the device, but incoming 
notifications were preserved in 

34
00:02:03,240 --> 00:02:07,000
the internal memory. 
So when a secure message is 

35
00:02:07,000 --> 00:02:10,440
received, the iPhone generates a
notification preview, and under 

36
00:02:10,440 --> 00:02:14,320
normal circumstances, dismissing
that alert should instruct the 

37
00:02:14,320 --> 00:02:18,040
OS to permanently delete that 
temporary text from memory. 

38
00:02:18,560 --> 00:02:23,280
But due to a specific logging 
error, this deletion process had

39
00:02:23,280 --> 00:02:25,760
failed. 
So notifications that were 

40
00:02:25,760 --> 00:02:30,320
displayed message content were 
cached inside the device for up 

41
00:02:30,320 --> 00:02:32,680
to a month. 
And crucially, the vulnerability

42
00:02:32,680 --> 00:02:37,120
was not in Signal itself, but in
Apple's internal notification 

43
00:02:37,120 --> 00:02:39,640
storage. 
So, you know, that's kind of 

44
00:02:40,560 --> 00:02:44,760
part of the the issue is that 
Signal can only really secure 

45
00:02:44,760 --> 00:02:47,280
what would they own, right? 
This was, this was a problem 

46
00:02:47,280 --> 00:02:51,960
with Apple's iOS. 
So I saw this and again, like I 

47
00:02:51,960 --> 00:02:53,600
use Signal. 
So I was like, yeah, this is 

48
00:02:54,040 --> 00:02:56,160
this is interesting. 
A vulnerability that shouldn't 

49
00:02:56,160 --> 00:02:58,560
happen. 
Something that I also do, which 

50
00:02:58,680 --> 00:03:01,800
you know, it depends on your 
level of risk is I don't have 

51
00:03:01,800 --> 00:03:03,600
any previews that show up on my 
phone. 

52
00:03:03,680 --> 00:03:07,160
If the phone is unlocked, 
nothing can be seen from 

53
00:03:07,160 --> 00:03:10,680
imessages, Signal, whatever. 
Only after I've unlocked the 

54
00:03:10,680 --> 00:03:14,280
phone will it appear in the 
Notification Center and I'll be 

55
00:03:14,280 --> 00:03:16,600
able to see that there was a 
message. 

56
00:03:16,600 --> 00:03:20,000
But I think it sounds like even 
in this case, anytime there's a 

57
00:03:20,000 --> 00:03:23,280
preview in the Notification 
center that's cashed. 

58
00:03:23,280 --> 00:03:26,840
And So what did Apple do? 
They patched the bug. 

59
00:03:27,080 --> 00:03:31,560
And so on April 22nd, so just a 
few days ago, there was an 

60
00:03:31,560 --> 00:03:35,880
update which I have already 
updated my iOS to the latest 

61
00:03:35,880 --> 00:03:43,080
version 26 point 4.2. 
So if you haven't seen that yet,

62
00:03:43,520 --> 00:03:46,160
go ahead and you know, go to 
your settings and look for the 

63
00:03:46,160 --> 00:03:48,440
update because it might not have
pushed through yet. 

64
00:03:49,080 --> 00:03:53,640
Same thing with Pad OS which is 
26 point 4.2 and then iOS 18 

65
00:03:53,640 --> 00:03:57,200
point 7.8 for older devices. 
So Apple described it as a 

66
00:03:57,200 --> 00:04:00,600
logging issue fixed through 
improved data redaction. 

67
00:04:01,000 --> 00:04:05,200
Signal confirmed the patch and 
ensured all inadvertently 

68
00:04:05,200 --> 00:04:10,120
preserved notifications will be 
deleted and no forthcoming 

69
00:04:10,120 --> 00:04:13,320
notifications will be preserved 
from deleted applications and 

70
00:04:13,320 --> 00:04:16,720
said no action is needed within 
Signal itself, just install the 

71
00:04:16,760 --> 00:04:20,560
update. 
So couple of just kind of 

72
00:04:21,079 --> 00:04:24,480
takeaways really. 
This kind of highlights that gap

73
00:04:24,480 --> 00:04:29,360
of expectation like as a user, 
if I delete the app and delete 

74
00:04:29,360 --> 00:04:34,200
the data, I would, you know, 
think that the OS would manage 

75
00:04:34,200 --> 00:04:36,200
that. 
And so there was a gap here and 

76
00:04:36,200 --> 00:04:40,840
and we don't really know for how
long this bug existed and how 

77
00:04:40,840 --> 00:04:45,600
many times, you know, attackers 
were able to to possibly get 

78
00:04:45,600 --> 00:04:48,480
this. 
But you know, Sky's not falling,

79
00:04:48,480 --> 00:04:49,760
right? 
It was fixed. 

80
00:04:49,760 --> 00:04:52,960
It was bug. 
And also the FBI had physical 

81
00:04:52,960 --> 00:04:56,720
access to the device. 
So in a lot of cases when we 

82
00:04:57,240 --> 00:04:59,400
lose physical access to 
something, it's kind of like 

83
00:04:59,400 --> 00:05:02,680
security is already lost at that
point, right? 

84
00:05:02,720 --> 00:05:06,280
And so that's something to to 
take into consideration. 

85
00:05:06,280 --> 00:05:09,560
Signal also already had an 
option to prevent message 

86
00:05:09,560 --> 00:05:12,000
content from appearing in 
notifications at all. 

87
00:05:12,360 --> 00:05:15,800
So users can go to the Signal 
settings, notification 

88
00:05:15,800 --> 00:05:20,200
notification content and set it 
to name only or no name slash 

89
00:05:20,200 --> 00:05:21,960
content. 
That's interesting because I 

90
00:05:21,960 --> 00:05:24,760
haven't done that, but I might 
actually go and do that just 

91
00:05:25,280 --> 00:05:28,880
just for kicks because any time 
I want to read a message, I 

92
00:05:28,880 --> 00:05:31,240
still always just go into the 
Signal app itself. 

93
00:05:31,240 --> 00:05:34,080
So yeah. 
And the the fix addresses the 

94
00:05:34,080 --> 00:05:36,920
notification database flaw, but 
it doesn't change how messaging 

95
00:05:36,920 --> 00:05:40,600
apps store data internally. 
Users still need to relay rely 

96
00:05:40,600 --> 00:05:44,040
on app level encryption and 
privacy settings. 

97
00:05:44,040 --> 00:05:47,920
So anytime you're you have a 
chat application, make sure you 

98
00:05:47,920 --> 00:05:51,000
go into the settings and see how
the privacies are for that 

99
00:05:51,000 --> 00:05:53,680
specific app. 
Your thoughts on this, Adam? 

100
00:05:54,040 --> 00:05:57,200
So while you were talking I just
pulled open Signal on my iPhone 

101
00:05:57,280 --> 00:05:59,760
just to take a look because I 
was wondering if they were 

102
00:05:59,760 --> 00:06:03,960
conflating the OS level 
notification settings where you 

103
00:06:03,960 --> 00:06:06,280
mentioned. 
Andy, you can configure do this 

104
00:06:06,280 --> 00:06:08,760
behavior when the phone is 
locked, change the behavior of 

105
00:06:08,760 --> 00:06:12,040
the phone is unlocked, which 
most iPhones do by default 

106
00:06:12,160 --> 00:06:14,360
nowadays. 
Anything with a Face ID iPhone I

107
00:06:14,360 --> 00:06:16,960
should say, blocks most 
notifications unless the phone 

108
00:06:16,960 --> 00:06:18,840
is unlocked. 
Default behavior. 

109
00:06:18,840 --> 00:06:21,320
What this does is this is on the
Signal side of it. 

110
00:06:21,680 --> 00:06:24,360
So if you know how all this 
stuff works, you understand that

111
00:06:24,360 --> 00:06:27,640
Apple operates the Apple Push 
Notification Service, or APNS, 

112
00:06:27,640 --> 00:06:31,040
and your app provider then 
pushes the notification to APNS,

113
00:06:31,080 --> 00:06:32,800
which then pushes it to your 
devices. 

114
00:06:33,320 --> 00:06:37,120
Changing this setting on the 
Signal side prevents the message

115
00:06:37,120 --> 00:06:41,000
content from ever being sent to 
APNS at all, which is something 

116
00:06:41,000 --> 00:06:43,400
you'd expect from Signal. 
Do you have that option? 

117
00:06:44,080 --> 00:06:47,160
I think most other messaging 
apps do not because their 

118
00:06:47,160 --> 00:06:49,520
audience tends to be less 
tinfoil Hattie. 

119
00:06:49,520 --> 00:06:52,800
Although in this case, there was
a setting and it would have 

120
00:06:52,800 --> 00:06:54,920
helped had you, this person 
leveraged it. 

121
00:06:55,000 --> 00:06:57,520
You, you you've summarized well.
I need the the sky is not 

122
00:06:57,520 --> 00:06:59,640
falling. 
It's unfortunate this happened. 

123
00:06:59,640 --> 00:07:04,480
I know on this show, you and I 
have always had a very strong 

124
00:07:04,840 --> 00:07:07,880
opinion of Apple and their 
cybersecurity posture and they 

125
00:07:07,880 --> 00:07:09,840
do a great job. 
And in fact, I don't know if you

126
00:07:09,840 --> 00:07:12,680
mentioned it. 
I was, I think grabbing my phone

127
00:07:12,680 --> 00:07:15,360
at the moment. 
They did actually patch iOS 18 

128
00:07:15,360 --> 00:07:17,720
as well, which they don't always
do. 

129
00:07:17,720 --> 00:07:22,200
So noted that even for down 
level operating system devices, 

130
00:07:22,440 --> 00:07:26,560
they can still take advantage of
this this security fix as well. 

131
00:07:26,840 --> 00:07:29,920
So you know, it's it's 
interesting. 

132
00:07:29,920 --> 00:07:33,960
I think it's it's a good point 
that how something behaves from 

133
00:07:33,960 --> 00:07:37,480
a front end perspective, just 
not necessarily mapped to how it

134
00:07:37,480 --> 00:07:39,320
behaves from a back end 
perspective. 

135
00:07:39,320 --> 00:07:41,920
A lot of modern operating 
systems have a lot of different 

136
00:07:42,200 --> 00:07:46,480
logging and auditing tasks 
always running, and those are 

137
00:07:46,480 --> 00:07:51,520
coded independently from how the
UI is drawn and displayed to the

138
00:07:51,520 --> 00:07:54,240
user. 
So don't always assume that the 

139
00:07:54,240 --> 00:07:58,080
way the UI shows up matches the 
underlying behaviour. 

140
00:07:58,080 --> 00:08:00,800
So that's a good lesson learned 
to take forwards. 

141
00:08:00,800 --> 00:08:05,520
Yeah, it's an interesting event 
and and a good lesson learned. 

142
00:08:05,520 --> 00:08:08,280
And of course, Signal had a 
setting that that would have 

143
00:08:08,280 --> 00:08:11,080
helped. 
And also go patch your iOS and 

144
00:08:11,080 --> 00:08:13,960
Apple devices. 
The problem with the signal 

145
00:08:13,960 --> 00:08:17,520
setting and I went and checked 
WhatsApp as well, just as a as a

146
00:08:17,520 --> 00:08:20,440
double check as you were talking
at home and it does have a 

147
00:08:20,440 --> 00:08:23,560
notifications where you can 
check off the preview. 

148
00:08:24,200 --> 00:08:27,240
But in both of these cases, and 
I'm sure this is the case with 

149
00:08:27,400 --> 00:08:31,920
with all apps for the most part,
is that the default is to show 

150
00:08:31,920 --> 00:08:33,559
the preview. 
Tyranny of the Default. 

151
00:08:33,880 --> 00:08:36,320
Right. 
And so everyone, the mass 

152
00:08:36,760 --> 00:08:40,080
majority of people are not going
to go in to notifications and 

153
00:08:40,080 --> 00:08:42,840
disable preview unless you're 
like tinfoil, highly like 

154
00:08:42,840 --> 00:08:45,520
myself, right? 
So I didn't even have this set 

155
00:08:45,520 --> 00:08:47,920
within the app, but I went ahead
and disabled it. 

156
00:08:47,920 --> 00:08:50,160
I'm going to see how the 
experience is for a while. 

157
00:08:50,920 --> 00:08:55,840
Well, and and again, it goes 
back to Apple has such a good 

158
00:08:55,840 --> 00:08:59,360
reputation for security. 
I don't think it was something 

159
00:08:59,360 --> 00:09:01,680
that ever crossed anyone's mind 
on maybe I don't want this 

160
00:09:01,680 --> 00:09:03,520
getting handed off to AP and S 
at all. 

161
00:09:03,520 --> 00:09:06,360
Maybe I don't want this going to
the notification system at all. 

162
00:09:06,440 --> 00:09:09,640
I mean, my thought up until we 
just had this conversation 20 

163
00:09:09,640 --> 00:09:12,240
minutes ago would have been 
well, the OS level configuration

164
00:09:12,240 --> 00:09:16,880
is perfectly fine and in in this
case it wasn't and now it is. 

165
00:09:17,320 --> 00:09:19,920
So it's kind of one of those 
things I'm I think we can move 

166
00:09:19,920 --> 00:09:23,040
on, but it's interesting to note
for sure and, and something to 

167
00:09:23,040 --> 00:09:25,520
keep in mind. 
And you know, alternately, I 

168
00:09:25,520 --> 00:09:29,240
think my my point around and you
made the point as well, the gap 

169
00:09:29,240 --> 00:09:32,160
between what shows in the UI 
versus what happens under the 

170
00:09:32,160 --> 00:09:36,640
hood are not one in the same. 
I think my my main take away too

171
00:09:36,640 --> 00:09:39,800
is, you know, as we're where as 
we're thinking about security, 

172
00:09:39,800 --> 00:09:43,440
is that tyranny of the fault? 
Is that what you make default 

173
00:09:43,560 --> 00:09:47,680
wherever that choice is, that is
what the majority of people are 

174
00:09:47,680 --> 00:09:50,360
going to go with. 
It's very rare that anyone is 

175
00:09:50,360 --> 00:09:53,400
going to go beyond, you know, 
like whatever. 

176
00:09:53,400 --> 00:09:58,840
So if you say, you know, phone 
number, MFA is is my default. 

177
00:09:58,840 --> 00:10:01,040
Well, that's what the majority 
of people are going to use. 

178
00:10:01,040 --> 00:10:04,520
If you say, you know, got to use
an authenticator app, that's 

179
00:10:04,520 --> 00:10:06,720
what the majority of people are 
going to use. 

180
00:10:06,720 --> 00:10:11,440
And if you say fish resistant is
going to be the default, then 

181
00:10:11,440 --> 00:10:12,760
that's where everyone's going to
have to be. 

182
00:10:12,760 --> 00:10:17,840
So it's just like insecurity as 
we look at these things, that 

183
00:10:17,840 --> 00:10:20,720
default setting is extremely 
important. 

184
00:10:20,800 --> 00:10:23,400
That's a pretty sick segue to 
our next topic. 

185
00:10:23,600 --> 00:10:26,760
Yeah, you like that? 
I like that so. 

186
00:10:26,760 --> 00:10:31,560
In in other news of the UK 
National Cybersecurity Center 

187
00:10:32,360 --> 00:10:38,320
has now fully backed pass keys. 
They said that consumers first 

188
00:10:38,320 --> 00:10:41,760
choice of login should be pass 
keys and the the key to this is 

189
00:10:41,760 --> 00:10:44,240
to understand that they said 
consumers and not just 

190
00:10:44,240 --> 00:10:47,600
enterprise security. 
So this is a recommendation for 

191
00:10:47,600 --> 00:10:51,280
everyday people. 
The NCSC also no longer 

192
00:10:51,280 --> 00:10:54,520
recommends passwords unless 
they're used where pass keys are

193
00:10:54,520 --> 00:10:57,080
not yet available on a digital 
service. 

194
00:10:57,440 --> 00:11:01,000
And this is really a landmark 
position from a national 

195
00:11:01,000 --> 00:11:05,280
government cybersecurity agency.
So kudos to the UK National 

196
00:11:05,280 --> 00:11:07,040
Cybersecurity Center for coming 
out and say this. 

197
00:11:07,040 --> 00:11:11,400
What has changed over let's say 
the last 12 months that makes 

198
00:11:11,400 --> 00:11:14,880
them kind of say this and 
confident enough to say this is 

199
00:11:14,880 --> 00:11:18,200
that they've worked closely with
the Fido Alliance and they've 

200
00:11:18,200 --> 00:11:22,680
observed positive progress 
across the passkey ecosystem and

201
00:11:22,680 --> 00:11:26,960
saw success in the use of 
passkeys within the NHS, which 

202
00:11:26,960 --> 00:11:33,320
is I think the National Health 
Service, a system within within 

203
00:11:33,320 --> 00:11:36,720
the UK. 
And then in other word, other 

204
00:11:37,200 --> 00:11:39,720
real world large scale 
deployments have really 

205
00:11:39,720 --> 00:11:44,800
validated the technology. 
Previously the NCSC has outlined

206
00:11:44,800 --> 00:11:47,720
challenges around 
inconsistencies in the passkey 

207
00:11:47,720 --> 00:11:51,680
ecosystem, which we have also 
highlighted on our show on 

208
00:11:51,680 --> 00:11:54,000
there's different flavors of 
pass keys, confusing 

209
00:11:54,000 --> 00:11:57,960
terminology, lack of consensus 
on when pass keys should be 

210
00:11:57,960 --> 00:12:00,000
used. 
Also like you know, syncopal 

211
00:12:00,000 --> 00:12:03,160
pass keys weren't available 
right away, but now they are. 

212
00:12:03,160 --> 00:12:07,040
And so there's there's has been 
multiple kind of barriers for 

213
00:12:07,040 --> 00:12:09,160
normal people and consumers 
getting into. 

214
00:12:09,840 --> 00:12:13,560
Pass keys plus other factors 
required. 

215
00:12:13,960 --> 00:12:18,560
There's a lot of sites where 
let's say you had legacy 2FA 

216
00:12:18,560 --> 00:12:21,000
stood up and then they start 
supporting pass keys. 

217
00:12:21,280 --> 00:12:24,080
A lot of them will take your 
pass key and then still hit you 

218
00:12:24,080 --> 00:12:27,760
up for another validation. 
Like Amazon will want your your 

219
00:12:27,760 --> 00:12:30,240
one time passcode on top of it. 
And it's like, guys, what are we

220
00:12:30,240 --> 00:12:32,080
doing here? 
Like this doesn't make any 

221
00:12:32,080 --> 00:12:33,320
sense. 
This bonkers. 

222
00:12:33,320 --> 00:12:35,120
And then it doesn't feel any 
better. 

223
00:12:35,120 --> 00:12:36,640
It doesn't feel more 
frictionless. 

224
00:12:36,640 --> 00:12:39,720
And so it actually feels more 
friction filled in some ways. 

225
00:12:39,800 --> 00:12:43,640
It's truly beneficial when it 
satisfies all factors in which 

226
00:12:43,640 --> 00:12:46,040
while it should, it is 
inherently a multi factor 

227
00:12:46,040 --> 00:12:47,960
authentication. 
But anyhow, that's another 

228
00:12:47,960 --> 00:12:52,120
inconsistency and implementation
where some sites will override 

229
00:12:52,120 --> 00:12:54,760
your two FA configuration if 
you're signing in with a passkey

230
00:12:54,760 --> 00:12:57,280
that's considered sufficient. 
Our employer Microsoft being one

231
00:12:57,280 --> 00:13:00,760
of them. 
And so now the NCSC has said 

232
00:13:00,760 --> 00:13:04,360
that progress within the 
industry have made some of those

233
00:13:04,360 --> 00:13:07,720
concerns addressed enough to 
recommend Passkey's to the 

234
00:13:07,720 --> 00:13:10,520
general public. 
The NCSC has rolled out its 

235
00:13:10,520 --> 00:13:14,200
Passkey a position specifically 
to consumers with more guidance 

236
00:13:14,200 --> 00:13:16,240
for businesses expected in the 
future. 

237
00:13:16,240 --> 00:13:19,360
But for businesses, the 
authentication guidance is still

238
00:13:19,360 --> 00:13:22,280
to use single sign on or SSO 
when possible. 

239
00:13:22,640 --> 00:13:25,240
But this whole announcement that
we're going to have, the link to

240
00:13:25,240 --> 00:13:29,000
the article in the show notes is
specifically for consumers, 

241
00:13:29,000 --> 00:13:32,720
which is, is pretty, pretty big.
Google made passkeys the default

242
00:13:32,720 --> 00:13:37,120
sign in for all users in 2023. 
And then Apple followed in 2024.

243
00:13:37,600 --> 00:13:39,920
Microsoft made passkeys 
available to all consumer 

244
00:13:39,920 --> 00:13:44,040
accounts in 2025. 
And also the default now when 

245
00:13:44,040 --> 00:13:48,600
you make a new Microsoft account
is a passkey. 

246
00:13:48,960 --> 00:13:51,000
So we talked about the tyranny 
of default. 

247
00:13:51,000 --> 00:13:53,680
It's like when if you're brand 
new and you're starting to, to, 

248
00:13:54,120 --> 00:13:57,440
when you go to Microsoft to make
a Xbox calendar, Outlook or 

249
00:13:57,440 --> 00:14:01,520
whatever it is, the default 
experience is a passkey, a 

250
00:14:01,520 --> 00:14:04,960
password list passkey. 
And so now the NCSC is, is 

251
00:14:04,960 --> 00:14:07,760
catching up to a lot of where 
some of these major platforms 

252
00:14:07,760 --> 00:14:09,360
are. 
But again, that governing body 

253
00:14:09,360 --> 00:14:11,720
carries some official weight to 
it. 

254
00:14:12,360 --> 00:14:15,600
You could say that, yeah. 
And it's interesting this is on 

255
00:14:15,600 --> 00:14:18,280
the consumer side first versus 
enterprises. 

256
00:14:18,280 --> 00:14:22,880
And I think in a lot of ways I 
can get why they would go that 

257
00:14:22,880 --> 00:14:28,600
direction that the consumer 
facing organizations, esecially 

258
00:14:28,600 --> 00:14:31,280
Google and Ale have done a very 
good job imlementing it. 

259
00:14:31,320 --> 00:14:35,000
And in fact, Windows has had ass
key support for a long time. 

260
00:14:35,760 --> 00:14:39,040
But it just recently got updated
to where it has very clean 

261
00:14:39,040 --> 00:14:42,520
integration with password 
managers to where they can hook 

262
00:14:42,520 --> 00:14:46,600
in at a operating system level 
and deliver their pass keys when

263
00:14:46,600 --> 00:14:49,360
prompted, which is really nice 
and very well done. 

264
00:14:49,360 --> 00:14:52,320
So generally in a consumer 
experience, I think it's it's 

265
00:14:52,480 --> 00:14:54,040
almost there. 
There's still some 

266
00:14:54,040 --> 00:14:55,880
inconsistencies and some 
challenges. 

267
00:14:55,880 --> 00:15:00,280
And unless you're like 100% in 
the Apple ecosystem or 100% in 

268
00:15:00,280 --> 00:15:02,760
the Google system, you're still 
probably going to need a 

269
00:15:02,760 --> 00:15:05,360
password manager to overcome it.
But it's certainly getting 

270
00:15:05,360 --> 00:15:07,240
better. 
And again, it's, it's a chicken 

271
00:15:07,240 --> 00:15:10,680
and an egg kind of problem where
you have to start pushing these 

272
00:15:10,680 --> 00:15:13,480
defaults and have to start 
driving people that direction. 

273
00:15:13,480 --> 00:15:17,760
And then the pain points will 
get addressed as more and more 

274
00:15:17,760 --> 00:15:21,320
people use it and point out edge
cases and different examples and

275
00:15:21,320 --> 00:15:23,040
different challenges they're 
having. 

276
00:15:23,040 --> 00:15:27,480
So again, great news. 
You and I Andy have been banging

277
00:15:27,480 --> 00:15:32,120
the drum on password list and 
fish resistant MFA forever and 

278
00:15:32,120 --> 00:15:34,200
this is yet another step in the 
right direction. 

279
00:15:34,200 --> 00:15:38,520
So you love to see it. 
Thanks NCSC in the UK and let's 

280
00:15:38,520 --> 00:15:43,640
keep the momentum going forward.
I also think that, like you and 

281
00:15:43,640 --> 00:15:47,400
me, a lot of the people that, 
you know, work in tech and hang 

282
00:15:47,400 --> 00:15:51,720
on tech are a little bit of an 
anomaly, especially in my age 

283
00:15:51,720 --> 00:15:54,920
group too, where like I'm, I'm 
like a, you know, elder 

284
00:15:54,920 --> 00:15:58,280
millennial slash, you know, 
Zennial and you're and you're 

285
00:15:58,280 --> 00:16:00,240
like an elder millennial as 
well, right. 

286
00:16:00,600 --> 00:16:05,000
So we grew up in an era where, 
you know, no, no electronics 

287
00:16:05,000 --> 00:16:07,840
existed and then transitioned, 
you know, from dial up to 

288
00:16:07,840 --> 00:16:09,960
broadband to smartphones and all
that. 

289
00:16:09,960 --> 00:16:14,920
And so I have noticed that there
are a lot of people outside 

290
00:16:14,920 --> 00:16:19,120
attack, maybe in a different age
group, like younger, they don't 

291
00:16:19,120 --> 00:16:21,800
even have computers, They don't 
have personal computers. 

292
00:16:21,800 --> 00:16:24,560
They they literally do all of 
their computing on their phone, 

293
00:16:24,760 --> 00:16:27,640
right? 
And so I think if you're in that

294
00:16:27,640 --> 00:16:31,680
kind of category where you 
don't, you don't use a computer,

295
00:16:31,680 --> 00:16:34,120
like you're not a gamer, you 
don't, you're not in tech. 

296
00:16:34,640 --> 00:16:37,520
You might have a work laptop, 
but you literally only use it 

297
00:16:37,520 --> 00:16:39,840
for work, right? 
And you're on your phone. 

298
00:16:40,320 --> 00:16:44,960
I think in that case, passkeys 
are really seamless because you 

299
00:16:44,960 --> 00:16:48,560
might be on an Android and using
the Google password manager that

300
00:16:48,680 --> 00:16:53,280
integrates well with Android, or
you're on Apple and you have the

301
00:16:53,280 --> 00:16:57,400
vault there and you can just 
store a pass key for a new thing

302
00:16:57,400 --> 00:17:00,160
just right there on the phone 
and key chain. 

303
00:17:00,160 --> 00:17:02,440
Yep. 
And so I think if you're in 

304
00:17:02,440 --> 00:17:05,079
those categories and you're just
throwing your pass keys in there

305
00:17:05,079 --> 00:17:08,359
and you're just doing all your 
computing on the same device, it

306
00:17:08,359 --> 00:17:10,160
works very well and very 
seamless. 

307
00:17:10,160 --> 00:17:13,040
That's a really good point 
because there's Speaking of like

308
00:17:13,040 --> 00:17:15,800
picking on millennials and us 
going through all the things. 

309
00:17:15,800 --> 00:17:18,920
There's a lot of memes that talk
about how millennials when they 

310
00:17:18,920 --> 00:17:21,319
make a big purchase, they have 
to do it on a big screen. 

311
00:17:21,800 --> 00:17:24,400
Like if I'm booking a vacation, 
it's like I got to get my PC 

312
00:17:24,400 --> 00:17:26,200
out. 
I hate doing it on my phone. 

313
00:17:26,319 --> 00:17:27,359
Yeah, I won't. 
Do it on my phone. 

314
00:17:27,839 --> 00:17:30,040
Yeah. 
It's true other generations are 

315
00:17:30,040 --> 00:17:33,520
perfectly fine booking a flight 
on their phone and it's bizarre 

316
00:17:33,520 --> 00:17:35,040
to me. 
Like no, that's a big screen 

317
00:17:35,040 --> 00:17:36,880
purchase. 
So yeah, that's a good point. 

318
00:17:36,880 --> 00:17:40,560
When you're when you're just 
naturally switching devices less

319
00:17:40,560 --> 00:17:44,040
and you're all in one ecosystem,
it's way easier to already be on

320
00:17:44,040 --> 00:17:48,280
board with pass keys. 
OK, so our final topic, and I 

321
00:17:48,280 --> 00:17:52,040
saw this post and I just wanted 
to talk about it because you 

322
00:17:52,040 --> 00:17:55,520
know, it's another person kind 
of hammering the point that 

323
00:17:55,520 --> 00:17:57,200
we've made. 
And if if you're new to the 

324
00:17:57,200 --> 00:18:01,000
podcast or, you know, even if 
you've listened to us a while, 

325
00:18:01,000 --> 00:18:02,640
you've you've heard us say this 
point. 

326
00:18:02,640 --> 00:18:05,080
But if you're new, this might be
the first time you've come 

327
00:18:05,080 --> 00:18:08,320
across this opinion. 
And I just wanted to echo it 

328
00:18:08,320 --> 00:18:12,280
because I follow Marcus Hutchins
on LinkedIn. 

329
00:18:12,320 --> 00:18:15,320
And you might not know that name
if you're new to cybersecurity, 

330
00:18:15,320 --> 00:18:18,640
but Marcus Hutchins has been 
around for a long time and he 

331
00:18:18,640 --> 00:18:21,080
carries some weight in the 
cybersecurity industry. 

332
00:18:21,400 --> 00:18:23,280
And he's known online as malware
tech. 

333
00:18:23,800 --> 00:18:27,720
And the reason why he's kind of 
globally recognized is because 

334
00:18:27,720 --> 00:18:32,280
one of the things that he did 
was he single handedly stopped 

335
00:18:32,280 --> 00:18:35,720
one of the worst cyberattacks in
the world has ever seen. 

336
00:18:36,040 --> 00:18:42,360
So Wanna Cry in 2017 was a 
ransomware attack that just kind

337
00:18:42,360 --> 00:18:47,920
of was rippling across the 
entire world's technical 

338
00:18:48,040 --> 00:18:51,000
ecosystem. 
And that was want to. 

339
00:18:51,000 --> 00:18:54,440
Cry in In case you don't 
remember, it was the one where 

340
00:18:54,440 --> 00:18:57,720
Microsoft patched Windows XP 
because the National Health 

341
00:18:57,720 --> 00:18:59,400
Service hello, coming back up 
again. 

342
00:18:59,400 --> 00:19:02,160
They were hit particularly hard 
by this, and they had a ton of 

343
00:19:02,160 --> 00:19:05,520
XP still in their environments. 
And so at the time, Terry 

344
00:19:05,520 --> 00:19:08,080
Myerson, who was running 
Windows, made the decision like 

345
00:19:08,080 --> 00:19:10,280
we are patching XPI know it's 
out of support. 

346
00:19:10,280 --> 00:19:12,480
I know we told everyone to get 
off it, but we're doing the 

347
00:19:12,480 --> 00:19:14,720
right thing. 
We're not going to keep, you 

348
00:19:14,720 --> 00:19:17,160
know, the entire country, the 
United Kingdom in the dark Ages.

349
00:19:17,160 --> 00:19:19,520
From a healthcare perspective, 
this is the right thing to do. 

350
00:19:19,520 --> 00:19:21,560
We're going to take care of it. 
So that's how bad it was. 

351
00:19:21,880 --> 00:19:24,600
It got Microsoft a patch XP 
years after it went out of 

352
00:19:24,600 --> 00:19:27,320
support. 
Yeah, and it was rampant. 

353
00:19:27,440 --> 00:19:30,480
I mean, it just rippled across 
the world, right? 

354
00:19:30,560 --> 00:19:34,200
And So what Marcus did at the 
time, he was only 22 years old, 

355
00:19:34,320 --> 00:19:39,920
he reverse engineered a sample 
of the malware and what he found

356
00:19:39,920 --> 00:19:46,440
was in the code was Adns entry, 
a website, a URLA domain, so to 

357
00:19:46,440 --> 00:19:49,440
speak. 
And so he he went and he looked 

358
00:19:49,440 --> 00:19:52,000
to see if it was registered. 
It wasn't. 

359
00:19:52,760 --> 00:19:54,760
And so he just went ahead and 
registered it. 

360
00:19:55,320 --> 00:19:59,760
And what happened was that that 
was inherently a kill switch 

361
00:20:00,000 --> 00:20:03,840
that was built into the malware.
And so once he registered the 

362
00:20:03,840 --> 00:20:06,760
domain, the malware's, you know,
beaconed out, saw that the 

363
00:20:06,760 --> 00:20:09,680
register, the website was 
registered and that stopped it. 

364
00:20:09,720 --> 00:20:13,240
And so that's why he's kind of 
like an urban legend in the 

365
00:20:13,240 --> 00:20:17,000
cybersecurity world because, you
know, he, he was able to just he

366
00:20:17,000 --> 00:20:19,640
was the first person to register
that, reverse engineer it, then 

367
00:20:19,680 --> 00:20:23,280
register the domain and, and 
actually stopped the ransomware 

368
00:20:23,280 --> 00:20:26,800
attack that was. 
Globally affecting everyone. 

369
00:20:27,280 --> 00:20:29,680
So pretty impressive resume for 
a 22 year old. 

370
00:20:30,080 --> 00:20:32,480
Right, right. 
Might know a thing or two about 

371
00:20:32,480 --> 00:20:34,040
malware. 
Yeah. 

372
00:20:34,040 --> 00:20:38,400
And so, you know, he had this 
post that was on LinkedIn. 

373
00:20:38,400 --> 00:20:42,080
So if you if you go and you I'll
put the post like in in the show

374
00:20:42,080 --> 00:20:45,080
notes, of course. 
But what he was saying is all 

375
00:20:45,080 --> 00:20:48,040
this fascination with anthropic 
mythos. 

376
00:20:48,040 --> 00:20:52,200
And we had talked about how it 
found a bunch of like bugs in 

377
00:20:52,200 --> 00:20:54,880
these old, you know, open source
software. 

378
00:20:54,880 --> 00:20:59,120
And, you know, he, he was saying
that for, for this, it's not 

379
00:20:59,120 --> 00:21:02,040
necessarily that it's like 
something that's earth 

380
00:21:02,040 --> 00:21:05,200
shattering because no one's 
really looking for these bugs 

381
00:21:05,200 --> 00:21:07,480
because no one's getting paid to
look for these bugs. 

382
00:21:07,480 --> 00:21:12,360
That's the whole problem. 
It like BSD, which is, you know,

383
00:21:12,480 --> 00:21:16,600
a Linux operate Unix operating 
system. 

384
00:21:16,680 --> 00:21:21,600
Berkeley Software Distribution. 
Mythos was able to find that 

385
00:21:21,920 --> 00:21:26,680
remote code execution, 17 years 
old remote code execution 

386
00:21:26,680 --> 00:21:31,960
vulnerability and with no 
authentication running, and it 

387
00:21:31,960 --> 00:21:37,480
found another one in open BSDA 
27 year old bug, right? 

388
00:21:37,480 --> 00:21:41,640
And so BSD doesn't have a bug 
bounty program. 

389
00:21:42,280 --> 00:21:45,240
So there's no financial 
incentive for anyone to be 

390
00:21:45,240 --> 00:21:48,560
looking over these, over the 
code and to report them. 

391
00:21:49,160 --> 00:21:53,920
And in fact, if I found the bug,
I would make more money selling 

392
00:21:53,920 --> 00:21:58,800
it to attackers than I would 
reporting it to BSD. 

393
00:21:59,040 --> 00:22:03,440
You know, like he said, ABSD 
kernel, a remote code execution 

394
00:22:03,440 --> 00:22:07,600
RCE would probably fetch around 
somewhere 100,000 to 200,000 on 

395
00:22:07,600 --> 00:22:10,560
the black market. 
So that's a lot of money to just

396
00:22:10,560 --> 00:22:13,880
give up. 
If you found it and you know it,

397
00:22:13,880 --> 00:22:17,880
it might not be useless. 
He said while most bugs look 

398
00:22:17,920 --> 00:22:20,800
mostly useless, you never truly 
know whether a bug is useless or

399
00:22:20,800 --> 00:22:22,680
not. 
Sometimes a seemingly useless 

400
00:22:22,680 --> 00:22:25,840
bug can be chained with another 
vulnerability to receive or 

401
00:22:26,160 --> 00:22:28,880
achieve RCE, remote code 
execution. 

402
00:22:29,400 --> 00:22:33,320
So he also said that anyone that
found the bug would have been 

403
00:22:33,560 --> 00:22:35,520
financially incentivized to keep
it quiet. 

404
00:22:35,520 --> 00:22:39,640
And BSD has about .1% of the 
market share, so there's 

405
00:22:39,640 --> 00:22:43,320
probably not a whole lot of 
people bothering to even bother 

406
00:22:43,320 --> 00:22:45,320
to audit the code in the 1st 
place. 

407
00:22:46,160 --> 00:22:50,520
And there's a big difference 
between a bug going unnoticed 

408
00:22:50,520 --> 00:22:55,000
and unreported. 
So what Mithos was able to do 

409
00:22:55,640 --> 00:22:58,440
was not necessarily something 
that no one could do. 

410
00:22:58,440 --> 00:23:01,880
It's just that it performed the 
work that no one else wanted to 

411
00:23:01,880 --> 00:23:07,040
do at the cost of, you know, 
$20,000 worth of tokens or 

412
00:23:07,040 --> 00:23:11,800
something like that, right? 
And so it's it's able to do this

413
00:23:11,800 --> 00:23:15,520
meaningless work that no one 
will just go and do on their 

414
00:23:15,520 --> 00:23:18,880
own, which is the problem with 
open source software, which Adam

415
00:23:18,880 --> 00:23:23,360
will probably go on a rant on. 
But that's the that's the danger

416
00:23:23,360 --> 00:23:27,680
by using open source, especially
if you don't know if there's a 

417
00:23:27,680 --> 00:23:31,040
bug bounty program or no one's 
looked at it just because it's 

418
00:23:31,600 --> 00:23:33,960
it could be widely used but 
still have bugs. 

419
00:23:33,960 --> 00:23:39,480
So it's just, I think in 
general, if your S BOM includes 

420
00:23:39,480 --> 00:23:42,680
open source software, you really
need to be on it and careful 

421
00:23:42,680 --> 00:23:46,000
about where you're using it, 
especially if it's a critical 

422
00:23:46,000 --> 00:23:50,360
application for your enterprise.
Andy, I think it was you, maybe 

423
00:23:50,360 --> 00:23:55,360
it was someone else who made the
point that commonly used 

424
00:23:55,360 --> 00:24:01,920
components in a software bill of
materials will actually start to

425
00:24:01,920 --> 00:24:07,080
benefit from being frequently 
scanned with AI tooling and 

426
00:24:07,080 --> 00:24:09,560
should get really, really 
hardened as a result of it. 

427
00:24:09,840 --> 00:24:13,200
Provided there's enough of 
volunteer software developers 

428
00:24:13,200 --> 00:24:15,840
willing to take those pull 
requests and implement those 

429
00:24:15,840 --> 00:24:18,880
changes, which is no given 
thing. 

430
00:24:19,400 --> 00:24:24,440
And there's potentially, and 
we'll see if this is FUD or if 

431
00:24:24,440 --> 00:24:27,520
it's reality. 
Potentially there's could be a 

432
00:24:27,520 --> 00:24:29,680
lot of those. 
It could be a lot of work comes 

433
00:24:29,680 --> 00:24:32,880
in instead of shipping features 
for playing catch up and doing a

434
00:24:32,880 --> 00:24:36,240
lot of patching of 17 year old 
vulnerabilities. 

435
00:24:36,400 --> 00:24:40,200
Could be not fun for a while to 
be a contributor to an open 

436
00:24:40,200 --> 00:24:43,640
source project. 
But I think most widely used 

437
00:24:44,280 --> 00:24:48,040
components will probably benefit
from very thorough and 

438
00:24:48,040 --> 00:24:51,360
consistent checking across a lot
of orgs kind of redoing the same

439
00:24:51,360 --> 00:24:53,960
thing. 
And they'll get really, really 

440
00:24:53,960 --> 00:24:57,480
hard and they'll be excellent. 
So this could in the long run be

441
00:24:57,480 --> 00:24:59,680
in that positive. 
But for something like this, 

442
00:24:59,680 --> 00:25:02,480
Open Bsdi keep wanting to say 
Free Bsdi think that's another 

443
00:25:02,480 --> 00:25:04,160
distribution. 
They they found both. 

444
00:25:04,520 --> 00:25:08,240
OK, Yeah, yeah, not as widely 
used. 

445
00:25:08,240 --> 00:25:10,680
You know, it's not a Linux 
derivative, it's a Unix 

446
00:25:10,680 --> 00:25:13,640
derivative to be specific. 
I guess we'll see how this plays

447
00:25:13,640 --> 00:25:16,320
out and we'll see how much 
Mythos is never going to ship by

448
00:25:16,320 --> 00:25:18,840
the way. 
And Tropic is said Mythos is a 

449
00:25:19,080 --> 00:25:21,800
research preview. 
These changes will ship in a in 

450
00:25:21,800 --> 00:25:25,800
a more Consumer Focus, but like 
a shipping focused product, like

451
00:25:25,800 --> 00:25:29,160
a new, a cloud opus, a release 
as an example. 

452
00:25:29,160 --> 00:25:32,800
And 4.7 was a step in that 
direction. 

453
00:25:32,800 --> 00:25:36,080
It is not, you know, the full 
kind of mythos implementation. 

454
00:25:36,120 --> 00:25:39,360
A mythos is also, you made the 
good point, very, very expensive

455
00:25:39,440 --> 00:25:42,400
to run today. 
So there still gets into a cost 

456
00:25:42,400 --> 00:25:45,840
element where we are not, we're 
not to the point yet where these

457
00:25:45,840 --> 00:25:48,880
are so commoditized and so cheap
to run that it is trivial to 

458
00:25:48,880 --> 00:25:52,600
point it out a large code base 
like a Unix based operating 

459
00:25:52,600 --> 00:25:54,800
system and say go to town. 
You still have to have some 

460
00:25:54,800 --> 00:25:58,160
money to invest to do that. 
So again, I think it's going to 

461
00:25:58,160 --> 00:26:00,560
start with a lot of folks 
researching their bill of 

462
00:26:00,560 --> 00:26:02,520
materials and we'll go from 
there. 

463
00:26:02,560 --> 00:26:06,160
Ultimately, I think this is a 
short term pain, long term gain 

464
00:26:06,160 --> 00:26:10,960
thing because eventually we are 
seeing kind of Moore's law 

465
00:26:10,960 --> 00:26:15,360
happen in the AI space where the
cost of tokens is decreasing 

466
00:26:15,360 --> 00:26:20,520
exponentially year over year as 
as the entire stack he gets more

467
00:26:20,520 --> 00:26:24,120
efficient. 
You talk about not just the 

468
00:26:24,120 --> 00:26:28,440
silicon, not just the GPU's, but
the CPU's, the interconnects, 

469
00:26:28,440 --> 00:26:32,240
the networking, the memory, the 
software stack it's running on 

470
00:26:32,240 --> 00:26:35,120
top of all of that is getting 
more efficient. 

471
00:26:35,640 --> 00:26:38,320
And you compare where we were 
three years ago, four years ago 

472
00:26:38,320 --> 00:26:41,720
to today, it's like a hockey 
stick curve in terms of the 

473
00:26:41,720 --> 00:26:45,160
difference. 
And so eventually it will get to

474
00:26:45,160 --> 00:26:51,320
the point where a really good 
researcher model is not terribly

475
00:26:51,320 --> 00:26:56,240
expensive to run and we can fire
it off at, again, I mean, all 

476
00:26:56,240 --> 00:27:00,480
the public facing repositories 
on GitHub, I mean, that's not a 

477
00:27:00,480 --> 00:27:03,720
crazy thing to dream about. 
It's not tomorrow, but it's a 

478
00:27:03,720 --> 00:27:06,520
Sunday thing. 
We can effectively put them out 

479
00:27:06,520 --> 00:27:09,160
of business. 
Now it's going to go back to can

480
00:27:09,160 --> 00:27:12,400
we implement the code changes 
And well, we're also going to 

481
00:27:12,400 --> 00:27:16,000
have AI. 
It already can, you can give it 

482
00:27:16,000 --> 00:27:17,840
a pull request and it can go 
write code. 

483
00:27:17,880 --> 00:27:20,800
You still need a human to review
it, I think at this point, but 

484
00:27:21,240 --> 00:27:23,120
even that's going to lessen with
time. 

485
00:27:23,120 --> 00:27:28,360
So I I think the stories of an 
impending cybersecurity 

486
00:27:28,360 --> 00:27:32,520
apocalypse are a little 
overblown because the tools are 

487
00:27:32,520 --> 00:27:35,960
available on both sides and the 
tools can be very powerful in 

488
00:27:35,960 --> 00:27:40,880
the good guys hands too, to 
write much more secure code to 

489
00:27:40,880 --> 00:27:44,080
find more vulnerabilities. 
You talked about chaining 

490
00:27:44,080 --> 00:27:46,600
vulnerabilities as well, and 
that's something these tools are

491
00:27:46,600 --> 00:27:51,120
particularly good at finding. 
When Mythos first got announced,

492
00:27:51,120 --> 00:27:54,360
it was it was noted how clever 
it was at chaining 

493
00:27:54,360 --> 00:27:57,760
vulnerabilities and just doing 
things humans aren't very good 

494
00:27:57,760 --> 00:27:59,520
at. 
I am an eternal optimist. 

495
00:27:59,520 --> 00:28:02,880
I'm almost a toxic optimist at 
times. 

496
00:28:02,880 --> 00:28:08,520
But I, I do think in this case, 
it was there was no human 

497
00:28:08,520 --> 00:28:12,200
solution to hardening cyber or 
to hardening open source 

498
00:28:12,200 --> 00:28:14,440
software. 
Tonya Jenka, our very first 

499
00:28:14,440 --> 00:28:17,720
guest on this show, pointed out 
there's no cybersecurity ferry 

500
00:28:18,080 --> 00:28:21,880
running around and doing 
security evaluations on open 

501
00:28:21,880 --> 00:28:23,720
source software. 
Well, guess what? 

502
00:28:23,880 --> 00:28:26,160
The cybersecurity ferry may have
been invented. 

503
00:28:26,560 --> 00:28:31,600
It's, it's these tools. 
And are they economical to run 

504
00:28:31,600 --> 00:28:33,720
today on every open source tool?
Probably not. 

505
00:28:34,320 --> 00:28:37,200
Can we see a future that's not 
far off where they are? 

506
00:28:37,640 --> 00:28:40,720
Absolutely, yes. 
And do we have a future where we

507
00:28:40,720 --> 00:28:43,680
can help accelerate writing the 
code to fix the vulnerabilities?

508
00:28:43,840 --> 00:28:46,880
Also yes. 
So I think there's a very good 

509
00:28:46,880 --> 00:28:51,440
possibility the the good guys 
here will be the good guys and 

510
00:28:51,440 --> 00:28:53,960
gals will be OK. 
There's going to be a lot of 

511
00:28:53,960 --> 00:28:56,520
work to do and it's going to be 
in on a very accelerated 

512
00:28:56,520 --> 00:28:58,920
timeline where we're going to 
need to work fast and with a 

513
00:28:58,920 --> 00:29:01,120
sense of purpose and a sense of 
urgency. 

514
00:29:01,560 --> 00:29:05,120
And if you work in corporate 
America, you are sick of sense 

515
00:29:05,120 --> 00:29:07,400
of urgency because you, 
everything's urgent, 

516
00:29:07,440 --> 00:29:11,080
everything's now, this will 
actually be something that has a

517
00:29:11,120 --> 00:29:15,040
true sense of urgency and 
actually does impact the world. 

518
00:29:15,040 --> 00:29:19,320
This isn't some, you know, oh, 
we got a fire here and it's, you

519
00:29:19,320 --> 00:29:21,160
know, some manager needs a 
spreadsheet. 

520
00:29:21,160 --> 00:29:24,160
Like it's not a real fire. 
This will actually be that. 

521
00:29:24,440 --> 00:29:28,160
And that's kind of exciting too.
Like I, I know a lot of us got 

522
00:29:28,160 --> 00:29:30,760
into this business to make a 
difference and we're going to 

523
00:29:30,760 --> 00:29:33,320
have a chance to do that in a 
big, big way in the near future.

524
00:29:33,480 --> 00:29:37,360
So I think that's exciting. 
That's the bull view, the 

525
00:29:37,360 --> 00:29:39,360
bullish view on what's lies 
ahead. 

526
00:29:39,440 --> 00:29:41,400
But we're really good note from 
Marcus here. 

527
00:29:42,120 --> 00:29:45,440
Yeah, I think what you were 
saying in the beginning was a 

528
00:29:45,440 --> 00:29:49,440
point that I made when we talked
about Mythos the first time was 

529
00:29:49,800 --> 00:29:52,560
it's being released in this 
project, right? 

530
00:29:52,640 --> 00:29:57,080
Swear glass wing, I think it's 
called where 40, you know, top 

531
00:29:58,240 --> 00:30:02,200
organizations have access to it 
to test it and run it. 

532
00:30:02,880 --> 00:30:06,120
And Microsoft, our employer is 
one of them. 

533
00:30:06,400 --> 00:30:10,080
So in all of these major 
companies, so I'm sure Apple and

534
00:30:10,080 --> 00:30:13,560
Google also have access to it 
and they're going to they all, 

535
00:30:13,640 --> 00:30:17,520
every one of those companies use
open source software somewhere. 

536
00:30:18,280 --> 00:30:23,880
And so I would assume as part of
that exercise in testing that 

537
00:30:23,880 --> 00:30:27,560
they would also run it on at 
least the open source software 

538
00:30:27,560 --> 00:30:31,000
that they're using and so that 
the more commonly used ones 

539
00:30:31,000 --> 00:30:35,840
across the board would get it. 
I just read an article on how 

540
00:30:35,920 --> 00:30:41,280
Mythos is is helping with 
Mozilla and Firefox. 

541
00:30:41,720 --> 00:30:48,160
It found something like 270 some
bugs in the latest version of 

542
00:30:48,920 --> 00:30:52,280
Firefox. 
And so it's it's something that 

543
00:30:52,280 --> 00:30:57,480
these vulnerabilities were not 
identified by fuzzers or human 

544
00:30:57,480 --> 00:31:00,960
red teamers. 
So AI was just able to find, you

545
00:31:00,960 --> 00:31:05,880
know, 270 some plus bugs and AI 
flag 22 of them as security 

546
00:31:05,880 --> 00:31:08,040
sensitive. 
So I do think you're right, like

547
00:31:08,120 --> 00:31:11,200
this will be a little bit of 
short term pain as we're kind of

548
00:31:11,200 --> 00:31:15,840
fixing and implementing all 
these fixes and patches. 

549
00:31:15,840 --> 00:31:20,400
But in the long term, this is 
definitely A plus for security. 

550
00:31:20,520 --> 00:31:24,920
I just think that in general, a 
lot of organizations don't have 

551
00:31:24,920 --> 00:31:29,880
an idea of what open source 
they're using, and so be very 

552
00:31:29,880 --> 00:31:33,880
cautious of what you're using 
because attackers have access to

553
00:31:33,880 --> 00:31:37,480
these tools too, and they're 
probably scanning a lot of the 

554
00:31:37,480 --> 00:31:41,560
common ones as well, finding 
bugs and using them for their 

555
00:31:41,800 --> 00:31:44,800
own nefarious. 
Purposes 100% and you're right. 

556
00:31:44,800 --> 00:31:47,920
You know when when Microsoft, 
Apple and Google all got their 

557
00:31:47,920 --> 00:31:52,080
hands on this software, you 
know, job one was run it against

558
00:31:52,080 --> 00:31:54,800
the Windows code base or run it 
against the Mac OS code base or 

559
00:31:54,800 --> 00:31:57,400
run it against Android. 
Job 2 was OK. 

560
00:31:57,400 --> 00:32:01,760
Now run it against everything 
that we we import into those 

561
00:32:01,760 --> 00:32:04,680
code bases, any third party 
code, we leverage our libraries 

562
00:32:04,680 --> 00:32:07,360
and go scan all those. 
And that has already happened. 

563
00:32:07,800 --> 00:32:12,640
And by the way, again, you know,
just to close it out here, our 

564
00:32:12,640 --> 00:32:19,040
employer, Microsoft did their 
April monthly Patch Tuesday 

565
00:32:19,040 --> 00:32:23,480
couple a week or two ago. 
And it was relatively large, one

566
00:32:23,480 --> 00:32:27,000
of the larger ones in a while. 
And so there was again, kind of 

567
00:32:27,000 --> 00:32:29,400
some FUD on Z. 
That's this is they found all 

568
00:32:29,400 --> 00:32:31,040
these in mythos and they fixed 
all these. 

569
00:32:31,040 --> 00:32:33,920
And it's like actually, if you 
go look, April is typically one 

570
00:32:33,920 --> 00:32:36,400
of the largest patch Tuesdays. 
That's just very normal. 

571
00:32:36,400 --> 00:32:38,840
So it's actually very historical
and cyclical. 

572
00:32:39,280 --> 00:32:42,440
And it's it's actually not 
abnormal at all for a typical 

573
00:32:42,480 --> 00:32:47,240
April cycle because by the way, 
total side note, Windows hot 

574
00:32:47,240 --> 00:32:50,640
patch, you don't need to reboot 
your Windows systems every month

575
00:32:50,640 --> 00:32:52,920
anymore. 
They can go without reboots 

576
00:32:52,960 --> 00:32:54,280
every two out of three months 
now. 

577
00:32:54,280 --> 00:32:57,320
So February and March are non 
reboot months. 

578
00:32:57,320 --> 00:32:59,680
If you have Windows hot patch 
enabled, the operating system 

579
00:32:59,680 --> 00:33:02,080
just patches on the fly and 
keeps running, no restart 

580
00:33:02,080 --> 00:33:04,520
required. 
April is a restart required 

581
00:33:04,520 --> 00:33:06,640
month. 
So that also is now a thing 

582
00:33:07,000 --> 00:33:10,440
we're seeing where on those 
months that are restart months. 

583
00:33:10,440 --> 00:33:17,120
So January, April, July, October
are all larger patches now as a 

584
00:33:17,120 --> 00:33:19,560
result of it. 
So you know, I'm sure and by and

585
00:33:19,560 --> 00:33:22,160
by the way, Andy and I totally 
do not have access to Mythos, 

586
00:33:22,160 --> 00:33:24,920
have not touched it or anything 
that is definitely above our pay

587
00:33:24,920 --> 00:33:27,480
grade, but it's definitely that 
that is happening. 

588
00:33:27,480 --> 00:33:30,200
So I think both closed source 
and open source is benefiting 

589
00:33:30,200 --> 00:33:32,560
and we'll see that trickle down 
effect for sure. 

590
00:33:33,000 --> 00:33:35,720
All right, well, that's our show
for this week. 

591
00:33:35,880 --> 00:33:37,560
Thanks for watching and 
listening. 

592
00:33:37,560 --> 00:33:40,240
As always, our contact 
information will be in the show 

593
00:33:40,240 --> 00:33:42,840
notes if you have any questions 
or topics you want us to talk 

594
00:33:42,840 --> 00:33:47,480
about in the future, along with 
the links to the stories that we

595
00:33:47,480 --> 00:33:50,120
used for the show today. 
So go ahead and click those if 

596
00:33:50,120 --> 00:33:52,360
you want to read them. 
Thanks and we'll talk to you 

597
00:33:52,360 --> 00:33:58,320
guys next week. 
Thank you for listening to the 

598
00:33:58,320 --> 00:34:01,160
Blue Security Podcast. 
Please check out the show notes,

599
00:34:01,160 --> 00:34:04,000
catch up on episodes you may 
have missed, and subscribe so 

600
00:34:04,000 --> 00:34:05,720
you don't miss any future 
episodes. 

601
00:34:05,760 --> 00:34:10,400
Find Andy on Twitter at a Jaw 
Zero and Adam at AJ Brewer. 

602
00:34:10,639 --> 00:34:12,239
See you at our next episode.
