1
00:00:25,120 --> 00:00:39,440
None. 
Welcome to the other sport to a 

2
00:00:39,440 --> 00:00:41,560
podcast. 
Today we're talking all things 

3
00:00:41,560 --> 00:00:45,000
security with the author of the 
Amber Harden guides, Bob Planks.

4
00:00:45,080 --> 00:00:47,400
Hey, Bob, welcome to the show. 
Thanks for having me on. 

5
00:00:47,720 --> 00:00:49,920
Ain't no problem, mate. 
This is actually the first time 

6
00:00:49,920 --> 00:00:53,480
that I've got a guest on the 
show where I know that I'm 

7
00:00:53,480 --> 00:00:57,000
probably going to record another
episode because there's so much 

8
00:00:57,000 --> 00:00:58,920
we can talk about when it comes 
to security. 

9
00:00:58,920 --> 00:01:01,040
Security. 
But before we dive into 

10
00:01:01,040 --> 00:01:04,160
security, it's probably good for
you to introduce yourself and 

11
00:01:04,160 --> 00:01:06,240
maybe you can also share a 
highlight of your career because

12
00:01:06,240 --> 00:01:09,240
you've been around for ages. 
Your beard is showing it Bob, 

13
00:01:09,240 --> 00:01:11,520
unfortunately. 
You're calling me grey, and my 

14
00:01:11,520 --> 00:01:14,000
kids say that hey dad, you got 
grey in your beard. 

15
00:01:14,000 --> 00:01:15,640
And I ask him, where do you 
think that comes from? 

16
00:01:15,640 --> 00:01:19,920
Kids, you know, but the they 
don't understand yet, but they 

17
00:01:19,920 --> 00:01:22,480
will eventually. 
But I'm so I'm Bob plankers. 

18
00:01:22,480 --> 00:01:27,080
I do security and compliance and
resilience resilience. 

19
00:01:27,080 --> 00:01:30,480
It's all kind of security is a 
sub topic of resilience. 

20
00:01:30,480 --> 00:01:34,680
So I talk a lot about resilience
and and that, but in technical 

21
00:01:34,680 --> 00:01:39,680
marketing for Broadcom now for 
the VCF division, join VM Ware 

22
00:01:40,720 --> 00:01:44,440
eight years ago, 7 1/2 years ago
now seems like an eternity and 

23
00:01:44,440 --> 00:01:46,600
in a good way in a good way. 
You know, time flies when you're

24
00:01:46,600 --> 00:01:50,480
having fun sort of thing. 
And before that, I spent 23 

25
00:01:50,480 --> 00:01:52,400
years at the University of 
Wisconsin Madison. 

26
00:01:52,920 --> 00:01:57,280
IT guy LED A-Team there. 
And so kind of a diverse 

27
00:01:57,280 --> 00:01:59,280
background. 
I've done a lot of different 

28
00:01:59,280 --> 00:02:00,840
things. 
I started in the help desk. 

29
00:02:00,840 --> 00:02:05,240
I think a lot of folks should 
start in help desks for, for IT 

30
00:02:05,240 --> 00:02:08,320
and because you really get to 
see that side of it. 

31
00:02:08,320 --> 00:02:12,440
And but yeah, that's so I, I 
produce a lot of, I'm like the 

32
00:02:12,440 --> 00:02:14,760
output side of things. 
You know, I'm the face to go 

33
00:02:14,760 --> 00:02:18,720
with all of the, there's 
hundreds of people that work on 

34
00:02:18,720 --> 00:02:22,680
these sorts of things in the 
product building features, 

35
00:02:23,040 --> 00:02:25,160
securing things, all kinds of 
stuff. 

36
00:02:25,160 --> 00:02:29,080
And I, I'm the lucky guy that 
just gets to announce it, you 

37
00:02:29,080 --> 00:02:30,640
know, and put my face on it or 
whatever. 

38
00:02:30,640 --> 00:02:33,400
But I'm like the, I'm the, it's 
an iceberg. 

39
00:02:33,400 --> 00:02:37,040
I'm the very tip sticking out of
the water, you know, So lots of 

40
00:02:37,040 --> 00:02:38,840
other folks working on this 
stuff too. 

41
00:02:40,040 --> 00:02:42,880
That's interesting because I 
still recall that you were at 

42
00:02:42,880 --> 00:02:45,840
the customer back then and that 
you joined us now. 

43
00:02:45,840 --> 00:02:47,640
Since then, a lot of has 
changed. 

44
00:02:48,120 --> 00:02:50,080
I guess from a security 
perspective, a lot has changed 

45
00:02:50,080 --> 00:02:53,240
as well, especially because 
we've seen, you know, the way 

46
00:02:53,240 --> 00:02:58,160
that attackers are breaching 
environments change as well. 

47
00:02:58,160 --> 00:03:01,160
So that's probably the first 
thing that we should talk about 

48
00:03:01,320 --> 00:03:04,520
briefly so people can understand
what they're actually trying to 

49
00:03:04,840 --> 00:03:07,200
secure their environments 
against. 

50
00:03:07,200 --> 00:03:09,360
Maybe you can go over that 
because you're the expert here. 

51
00:03:09,560 --> 00:03:13,320
So what has changed over the 
last probably decade or so? 

52
00:03:13,680 --> 00:03:18,440
Well, over the last decade, I 
mean, lots of stuff, you know, 

53
00:03:18,440 --> 00:03:23,720
but we've had kind of an, A 
seismic shift here in with all 

54
00:03:23,720 --> 00:03:25,840
this AI, this newfangled AI 
stuff. 

55
00:03:25,880 --> 00:03:31,000
You know, AI is, you know, I 
think it was Homer Simpson said 

56
00:03:31,640 --> 00:03:34,520
he was referring to beer, I 
believe, but the the cause of an

57
00:03:34,520 --> 00:03:36,400
solution to all of life's 
problems. 

58
00:03:36,760 --> 00:03:39,480
But AI is seeming that way now 
as well. 

59
00:03:39,480 --> 00:03:43,760
And the to yeah, to paraphrase 
Homer Simpson. 

60
00:03:43,760 --> 00:03:48,040
But the, you know, we've got 
attacker. 

61
00:03:48,040 --> 00:03:52,800
So AI is really good at finding 
vulnerabilities. 

62
00:03:52,960 --> 00:03:55,400
You can point it at a code base.
All of the things that make it 

63
00:03:55,400 --> 00:03:59,800
great, say the vibe coding thing
where you can take, you know, a 

64
00:03:59,800 --> 00:04:03,000
model and you can tell it to 
build, you build you. 

65
00:04:03,000 --> 00:04:07,200
Like the other day I was getting
annoyed with the substituting 

66
00:04:07,200 --> 00:04:10,120
fonts in a PowerPoint deck and I
just told the model, you know, 

67
00:04:10,120 --> 00:04:13,480
build me a Python script to do 
this, you know, and it did. 

68
00:04:13,560 --> 00:04:15,800
Boom, problem solved. 
You know, that sort of stuff. 

69
00:04:16,279 --> 00:04:19,120
You know, attackers can use it 
and say, hey, I want to break 

70
00:04:19,120 --> 00:04:20,200
into stuff. 
Boom. 

71
00:04:20,279 --> 00:04:23,440
You know, I want to find 
vulnerabilities and open source.

72
00:04:23,920 --> 00:04:25,800
Open source, everything is 
public, right? 

73
00:04:25,800 --> 00:04:29,120
You know, you check, you commit 
something, you send it back to 

74
00:04:29,120 --> 00:04:32,520
the Linux kernel and it's 
public. 

75
00:04:32,520 --> 00:04:34,520
You get to see the 
vulnerabilities happen in real 

76
00:04:34,520 --> 00:04:36,400
time. 
You know, there was a joke, I 

77
00:04:36,400 --> 00:04:40,000
think on X the other day is 
where I saw it, 0 days. 

78
00:04:40,280 --> 00:04:42,880
The reason we call it zero day 
vulnerabilities is because 

79
00:04:42,880 --> 00:04:46,560
there's been zero days between 
the last one, you know, and the 

80
00:04:46,720 --> 00:04:51,480
yeah. 
And so the, it, it's, it's going

81
00:04:51,480 --> 00:04:55,000
to be like this for a while and 
where it's just piles of 

82
00:04:55,000 --> 00:04:57,440
vulnerabilities and that so it 
finds vulnerabilities really 

83
00:04:57,440 --> 00:04:59,800
well. 
It chains them together. 

84
00:04:59,800 --> 00:05:02,880
And so there's a lot of 
organizations that for years 

85
00:05:02,880 --> 00:05:06,560
they've been ignoring the 
moderate, the low grade 

86
00:05:06,560 --> 00:05:08,960
vulnerabilities. 
You know, basically if it wasn't

87
00:05:08,960 --> 00:05:11,200
critical, they didn't care about
it and they didn't apply it. 

88
00:05:11,440 --> 00:05:13,960
But now they, so now they've got
10 years worth of 

89
00:05:14,440 --> 00:05:16,680
vulnerabilities that these AIS 
are really good at chaining 

90
00:05:16,680 --> 00:05:20,560
together and making into. 
So you take, you take 3 low 

91
00:05:20,560 --> 00:05:23,080
grade vulnerabilities and you 
stack them up and now you've got

92
00:05:23,080 --> 00:05:26,600
root, you know, or administrator
on whatever system and you don't

93
00:05:26,600 --> 00:05:28,480
want that, you know, and that's 
problematic. 

94
00:05:28,480 --> 00:05:33,920
And so, you know, and so they, 
these AIS, they can also 

95
00:05:33,920 --> 00:05:37,400
customize the malware. 
So it's not attackers used to 

96
00:05:37,400 --> 00:05:40,640
just build their software. 
I mean, this is all the software

97
00:05:40,640 --> 00:05:43,600
and they've got tool kits too 
and releases and all that stuff.

98
00:05:43,600 --> 00:05:46,120
And they would build it once and
then deploy it into victim 

99
00:05:46,400 --> 00:05:49,760
networks and things. 
And so if we, when we saw that, 

100
00:05:49,760 --> 00:05:53,800
you know, when you see that you,
you can develop a signature you 

101
00:05:53,800 --> 00:05:57,600
had, you run it through Shaw 256
or whatever, you get a hash and 

102
00:05:57,600 --> 00:05:59,920
then you can look for that 
everywhere. 

103
00:05:59,920 --> 00:06:01,760
And now that's not the case 
anymore. 

104
00:06:01,760 --> 00:06:05,720
You know, the, IT can, this AIAI
has got nothing but time on it 

105
00:06:05,720 --> 00:06:08,920
stands there and it doesn't get 
bored and doesn't go to sleep. 

106
00:06:09,720 --> 00:06:14,120
And so it just builds, it can 
just build a custom version of 

107
00:06:14,120 --> 00:06:18,120
everything for each victim And, 
and so we can't use signature 

108
00:06:18,120 --> 00:06:22,240
based stuff. 
And then on top of it, lots of 

109
00:06:22,240 --> 00:06:26,360
people that normally, you know, 
there was always sort of the 

110
00:06:26,680 --> 00:06:29,440
distribution of just like any 
skill set or whatever. 

111
00:06:29,440 --> 00:06:31,920
There is the the high grade 
attackers and then a lot of 

112
00:06:31,920 --> 00:06:36,240
like, you know, low, maybe low 
threat level ones or whatever, 

113
00:06:36,240 --> 00:06:38,840
you know, low information, not 
that skilled or whatever. 

114
00:06:39,400 --> 00:06:45,200
You know, AIA, if you're asking 
AIAI is basically a great, the 

115
00:06:45,200 --> 00:06:50,960
great democratizer of attacks. 
And it's, it can give the low, 

116
00:06:51,000 --> 00:06:54,080
the low skill people the same 
level of skill as the high skill

117
00:06:54,440 --> 00:06:57,280
folks used to have. 
And so, you know, anybody can 

118
00:06:57,480 --> 00:06:59,760
the bar is the bar is really low
now. 

119
00:06:59,760 --> 00:07:01,680
And so, and that's a problem all
the way around. 

120
00:07:01,680 --> 00:07:04,120
So that's kind of what we're 
thinking about nowadays when 

121
00:07:04,120 --> 00:07:08,080
we're talking about security an 
AI and that everyone's really 

122
00:07:08,080 --> 00:07:11,040
worried about AI, We're talking 
about patching a lot. 

123
00:07:11,040 --> 00:07:13,720
It's all these vulnerabilities, 
it's this big, you know, all we 

124
00:07:13,720 --> 00:07:19,040
just need to patch faster. 
No, you well, yes, but you also 

125
00:07:19,040 --> 00:07:20,440
need to change how you're doing 
it. 

126
00:07:20,440 --> 00:07:23,240
You know, you need to to have 
defense in depth and a lot of 

127
00:07:23,240 --> 00:07:25,720
the stuff that people glossed 
over in the past because it 

128
00:07:25,720 --> 00:07:29,040
seemed to be working 
survivorship bias, you know, oh,

129
00:07:29,040 --> 00:07:30,880
we well, we haven't been broken 
into. 

130
00:07:31,160 --> 00:07:33,800
So what we what we're doing must
be working. 

131
00:07:33,800 --> 00:07:39,360
Well, one, everything changed 
and two, yeah, that's 

132
00:07:39,360 --> 00:07:42,320
questionable to start with. 
And so just getting people to 

133
00:07:42,320 --> 00:07:46,120
rethink a lot of a lot of their 
assumptions really actually 

134
00:07:46,120 --> 00:07:47,640
doing this whole zero trust 
thing. 

135
00:07:47,640 --> 00:07:50,120
We've been talking about zero 
trust for 20 years, something 

136
00:07:50,120 --> 00:07:54,760
like that, you know, but 
actually doing it is is helpful.

137
00:07:54,760 --> 00:07:57,920
And so, yeah, that's kind of the
state of things right now. 

138
00:07:58,200 --> 00:08:00,160
So. 
Yeah, I think it's a very valid 

139
00:08:00,160 --> 00:08:03,240
point to say that AI is up 
leveled everyone and not just, 

140
00:08:03,240 --> 00:08:06,160
you know, from a security side 
of things or a development side 

141
00:08:06,160 --> 00:08:07,880
of things, but also from the 
attack point of view. 

142
00:08:07,880 --> 00:08:10,520
I think the other thing which 
you've already mentioned, which 

143
00:08:10,520 --> 00:08:13,120
you also mentioned, which I 
think is interesting, as you 

144
00:08:13,120 --> 00:08:16,800
said, you may not have been 
broken into at the moment or 

145
00:08:16,800 --> 00:08:19,040
probably yet, I should say. 
And it's probably going to 

146
00:08:19,040 --> 00:08:20,600
happen or maybe you don't even 
know about it. 

147
00:08:20,600 --> 00:08:23,440
So that's probably a good 
starting point as well, right? 

148
00:08:23,440 --> 00:08:26,560
So because if you look at the 
vsphere stack or even the VCF 

149
00:08:26,560 --> 00:08:31,840
stack in general, we've had a 
lot of technology available over

150
00:08:31,840 --> 00:08:34,799
the last decades that people 
could use to protect themselves,

151
00:08:34,799 --> 00:08:37,840
but not everyone are using some 
of the things that we have as 

152
00:08:37,840 --> 00:08:39,840
part of the platform. 
Now, I know we announced a lot 

153
00:08:39,840 --> 00:08:43,159
in 9.1, but maybe we can start 
up with explaining what people 

154
00:08:43,280 --> 00:08:46,320
already have available today, 
not even discussing 9.1 just 

155
00:08:46,320 --> 00:08:48,080
yet, but just what they have 
available today. 

156
00:08:48,080 --> 00:08:49,800
What can they do to protect 
themselves? 

157
00:08:50,880 --> 00:08:53,960
Yeah, we've got all kinds of 
layers of stuff even inside ESX 

158
00:08:53,960 --> 00:08:56,240
itself. 
You know, we've got secure boot,

159
00:08:56,240 --> 00:08:58,960
we've got code signing, the exec
installed only stuff. 

160
00:08:58,960 --> 00:09:03,360
We've got, you know, well, the 
isolation between VMS that's 

161
00:09:03,360 --> 00:09:06,000
actually proven out by various 
world governments and things, 

162
00:09:07,960 --> 00:09:10,200
you know, and just the VMS 
themselves, you know, like you 

163
00:09:10,200 --> 00:09:13,800
look at that and and there's 
like a virtual machine runtime 

164
00:09:13,880 --> 00:09:16,840
there, the virtual machine 
monitor, that's a security 

165
00:09:16,840 --> 00:09:20,720
boundary that's hardened and 
it's got a sandbox around it. 

166
00:09:20,720 --> 00:09:23,600
It's got mandatory access 
controls around that, you know, 

167
00:09:23,600 --> 00:09:26,880
so if somebody does get through 
the virtual machine monitor, you

168
00:09:26,880 --> 00:09:29,360
know, the sandbox will catch it,
you know, and sometime around 

169
00:09:29,360 --> 00:09:31,040
sandbox doesn't catch everything
either. 

170
00:09:31,040 --> 00:09:34,720
And so, you know, but that's the
layering these defense in depth 

171
00:09:35,080 --> 00:09:37,520
sorts of things. 
We've got, you know, identity 

172
00:09:37,520 --> 00:09:41,680
federation, we can federate with
with modern identity sources to 

173
00:09:41,680 --> 00:09:44,440
do MFA. 
We've got all kinds of 

174
00:09:45,120 --> 00:09:47,680
protections, CPU scheduler 
changes. 

175
00:09:47,680 --> 00:09:50,320
So if you don't want, if you 
know, the hardware 

176
00:09:50,320 --> 00:09:52,680
vulnerabilities, you've got to, 
you know, because hardware makes

177
00:09:52,680 --> 00:09:55,560
promises, CPU's, memory 
controllers makes, they make 

178
00:09:55,560 --> 00:09:58,600
promises that they don't always 
keep, you know, they're 

179
00:09:59,120 --> 00:10:02,200
fundamentally their software 
too, you know, and they're just 

180
00:10:02,200 --> 00:10:06,000
it's harder to update, you know,
because it's hardware, you know,

181
00:10:06,000 --> 00:10:09,480
and but you know, we can cope 
with a lot of that stuff. 

182
00:10:09,480 --> 00:10:12,640
We've got well, 91, you 
mentioned 91. 

183
00:10:12,640 --> 00:10:15,880
We made a lot of changes in nine
one at these layers too, you 

184
00:10:15,880 --> 00:10:19,640
know, memory protections, stack 
smashing attacks, being able to 

185
00:10:19,640 --> 00:10:23,080
stop those. 
We deep privileged the the 

186
00:10:23,080 --> 00:10:25,800
virtual machine monitor that the
thing that runs if you log into 

187
00:10:25,800 --> 00:10:30,040
ESX and type PS, you see all 
these processes there and that's

188
00:10:30,040 --> 00:10:34,000
the virtual machine monitor 
running and and so we've we've 

189
00:10:34,000 --> 00:10:36,880
actually 91 we've deep 
privileged that, you know, 

190
00:10:36,880 --> 00:10:40,480
instead of running it in kernel 
mode in the operating system, we

191
00:10:40,480 --> 00:10:42,960
run it in user mode where 
there's permissions kernel mode.

192
00:10:43,720 --> 00:10:48,320
So for the, yeah, simply putting
it simply, basically operating 

193
00:10:48,320 --> 00:10:51,000
systems basically have two 
modes, kernel mode, where it 

194
00:10:51,000 --> 00:10:52,960
goes really fast. 
But that's because there's no 

195
00:10:52,960 --> 00:10:55,920
permissions, you know, and 
you're not really supposed to be

196
00:10:55,920 --> 00:10:58,400
there. 
And only the kernel is supposed 

197
00:10:58,400 --> 00:11:00,680
to be there. 
But everyone is always run 

198
00:11:01,560 --> 00:11:04,240
hypervisors, their virtual 
machines there because it's 

199
00:11:04,240 --> 00:11:05,800
fast, right? 
You know, and who's going to 

200
00:11:05,800 --> 00:11:08,440
break in, Right. 
Well, yeah. 

201
00:11:08,880 --> 00:11:11,720
And so there's user mode, it's 
got, it's a little slower, but 

202
00:11:11,720 --> 00:11:15,080
it's got permissions. 
And so the goal was always to to

203
00:11:15,080 --> 00:11:18,560
get that down, get all that 
stuff down into the user mode. 

204
00:11:18,560 --> 00:11:20,440
But we needed hardware to help 
us with it. 

205
00:11:20,680 --> 00:11:23,680
CPU manufacturers have done a 
really good job in helping us 

206
00:11:24,120 --> 00:11:25,840
with some of this 
virtualization. 

207
00:11:25,840 --> 00:11:28,040
So we can push stuff down. 
We can be privileged it. 

208
00:11:28,040 --> 00:11:31,480
So if somebody does break out, 
you know, the elusive VM escape,

209
00:11:31,480 --> 00:11:34,720
that sort of thing, you know, 
then they break out into 

210
00:11:34,720 --> 00:11:36,520
somewhere where they don't have 
any permissions, they're not 

211
00:11:36,520 --> 00:11:39,280
root like in kernel mode, 
They're nobody, you know, and 

212
00:11:39,360 --> 00:11:41,160
good luck doing anything, you 
know. 

213
00:11:41,160 --> 00:11:44,040
And so, yeah, we've made a whole
lot of changes there. 

214
00:11:44,640 --> 00:11:49,280
We've made a whole bunch of 
other changes to just general 

215
00:11:49,280 --> 00:11:51,680
CPU schedulers. 
And you know, security always 

216
00:11:51,680 --> 00:11:54,080
comes at a cost. 
You know, whether, and I'm not 

217
00:11:54,080 --> 00:11:57,360
talking about actual money that 
happens too, but you know, it's 

218
00:11:57,360 --> 00:12:02,080
usually performance that you 
have to pay something in CPU 

219
00:12:02,080 --> 00:12:05,800
time or IO or whatever. 
But we've made a ton of changes 

220
00:12:05,800 --> 00:12:11,200
in 9-1 to NUMA scheduling and V 
SAN, the V SAN compression 

221
00:12:11,200 --> 00:12:14,000
algorithms and all that stuff 
that all of the stuff actually 

222
00:12:14,000 --> 00:12:17,720
Nets out to be. 
It's a faster system now, even 

223
00:12:17,720 --> 00:12:21,160
with the additional security. 
So yeah, that turned out really 

224
00:12:21,160 --> 00:12:23,400
well. 
But yeah, just a lot of 

225
00:12:23,400 --> 00:12:25,040
different layers. 
You can go up the stack too. 

226
00:12:25,040 --> 00:12:28,480
We've got monitoring, we V 
centers got remote attestation 

227
00:12:28,760 --> 00:12:32,280
to actually check whether a host
booted in a configuration that 

228
00:12:32,280 --> 00:12:36,160
it's is good, you know, all 
kinds of stuff, encryption, all 

229
00:12:36,160 --> 00:12:40,200
sorts of encryption everywhere, 
you know, and yeah, I don't 

230
00:12:40,200 --> 00:12:42,800
know, I can go on for hours 
about all this. 

231
00:12:43,320 --> 00:12:47,440
I know I'm not too worried about
us not filling up the time in 

232
00:12:47,440 --> 00:12:51,000
this particular case, but there 
were two items that I noticed 

233
00:12:51,000 --> 00:12:54,920
during the the the launch and 
and some of the blog posts you 

234
00:12:54,920 --> 00:12:56,760
wrote as well. 
I probably had a link to the 

235
00:12:56,760 --> 00:12:59,320
show notes, but there were two 
specifically that stood out to 

236
00:12:59,320 --> 00:13:03,120
me. 
One was we announced that we're 

237
00:13:03,120 --> 00:13:08,560
going to provide the option for 
EDR solutions to run directly on

238
00:13:08,560 --> 00:13:10,640
top of the execs. 
So maybe you can talk about that

239
00:13:10,640 --> 00:13:12,400
for a bit. 
And was also this thing about 

240
00:13:12,400 --> 00:13:15,440
file integrity monitoring, which
I hadn't heard about myself. 

241
00:13:15,440 --> 00:13:17,720
So maybe you can explain that as
well, because I think those two 

242
00:13:18,080 --> 00:13:21,040
are also quite crucial for for 
the security of the platform. 

243
00:13:21,600 --> 00:13:23,120
They are. 
And yeah, I should have 

244
00:13:23,120 --> 00:13:25,560
mentioned them. 
There's so much stuff that I'm 

245
00:13:25,560 --> 00:13:27,840
really glad you're keeping track
of our conversation here because

246
00:13:28,680 --> 00:13:31,240
but yeah, EDR, we'll start 
there. 

247
00:13:31,240 --> 00:13:33,800
EDR has been something people 
have asked for for a long time 

248
00:13:33,800 --> 00:13:39,120
and figuring out how to do that 
in the platform, it has been 

249
00:13:39,120 --> 00:13:41,040
really interesting. 
There's been a a number of 

250
00:13:41,040 --> 00:13:44,280
dependencies. 
So I was saying, I was talking a

251
00:13:44,280 --> 00:13:47,760
little bit about the mandatory 
access controls of sandboxes 

252
00:13:48,080 --> 00:13:50,160
around things. 
Well, one of the things that 

253
00:13:50,160 --> 00:13:53,880
we've done in Nine and 9.1 is 
put those sandboxes, those 

254
00:13:53,880 --> 00:13:57,000
mandatory access controls around
everything else running on the 

255
00:13:57,000 --> 00:14:00,040
SX. 
So SSH, for example, or the 

256
00:14:00,040 --> 00:14:03,440
VPXDVPX, yeah, demons and stuff 
like that. 

257
00:14:03,680 --> 00:14:07,320
MTP, all of that stuff has got a
mandatory access control sandbox

258
00:14:07,840 --> 00:14:13,640
there and so does EDR. So that 
was Step 1 was EDR runs it's a 

259
00:14:13,640 --> 00:14:16,040
partner driven thing. 
So you get an agent, you get a 

260
00:14:16,040 --> 00:14:22,840
installable VM Ware installable 
bundle from your EDR partner and

261
00:14:23,320 --> 00:14:27,080
you, you basically load that on 
the ESX and it runs as a 

262
00:14:27,080 --> 00:14:29,800
container. 
And that container has got 

263
00:14:29,800 --> 00:14:32,960
access controls to protect, 
well, to protect the rest of the

264
00:14:32,960 --> 00:14:35,520
machine from the container 
itself, to protect the 

265
00:14:35,520 --> 00:14:39,320
container, all of that stuff. 
And and then it communicates out

266
00:14:39,320 --> 00:14:41,120
it it does. 
There's no direct communication 

267
00:14:41,120 --> 00:14:43,760
out to the world from that 
container. 

268
00:14:43,760 --> 00:14:47,080
It all goes through a proxy 
through ESX itself. 

269
00:14:47,080 --> 00:14:49,000
It all comes out the management 
interface and things. 

270
00:14:49,480 --> 00:14:53,720
And it's read only in 9.1. 
So we're not giving it any 

271
00:14:53,720 --> 00:14:56,280
permission. 
We're starting starting slow. 

272
00:14:56,280 --> 00:14:58,360
Baby steps here. 
Monitoring only. 

273
00:14:59,040 --> 00:15:01,400
We're giving it the ability to 
watch what's going on on the 

274
00:15:01,400 --> 00:15:03,840
host and then report back. 
Hey, I see something bad 

275
00:15:03,840 --> 00:15:07,000
happening, but you know, whether
that's actually something bad or

276
00:15:07,000 --> 00:15:09,480
a false positive or whatever, 
whatever, there's a lot to be 

277
00:15:09,480 --> 00:15:14,480
learned there. 
And so yeah, reporting back, we 

278
00:15:14,480 --> 00:15:17,280
don't want to all VM. 
Some of some customers of ours 

279
00:15:17,280 --> 00:15:20,440
have hosts that are running 
hundreds and hundreds of VMS at 

280
00:15:20,440 --> 00:15:24,040
a time, you know, and having it 
go and, and shut everything 

281
00:15:24,040 --> 00:15:26,040
down, we don't want that to 
happen. 

282
00:15:26,040 --> 00:15:29,560
And so 9.1, obviously there's 
some road map here, you know, 

283
00:15:29,560 --> 00:15:33,400
and working with our partners 
on, on this, but yeah, it'll be 

284
00:15:33,400 --> 00:15:35,400
interesting. 
That's yeah. 

285
00:15:35,400 --> 00:15:38,000
So if you're watching this and 
you're going, oh, I want that, 

286
00:15:38,000 --> 00:15:39,840
you know, like 1, you got to be 
at 9.1. 

287
00:15:39,840 --> 00:15:43,040
And two, you should ask your EDR
vendor when they're going to 

288
00:15:43,040 --> 00:15:44,480
support it. 
And they're probably already 

289
00:15:44,480 --> 00:15:47,480
part of our partner program. 
And so, yeah, it's a generic 

290
00:15:47,480 --> 00:15:50,160
interface, all the partners can 
use it, that sort of thing. 

291
00:15:50,160 --> 00:15:53,400
So and then you mentioned file 
integrity monitoring, and that's

292
00:15:53,400 --> 00:15:58,360
a big thing too. 
How do you know that everything 

293
00:15:58,360 --> 00:16:02,360
is all right on the host, you 
know, and that how do you find 

294
00:16:02,360 --> 00:16:05,440
out that something you know, 
something has changed? 

295
00:16:06,000 --> 00:16:09,480
And this is especially important
too on V center, for example, 

296
00:16:09,480 --> 00:16:12,960
you know, we see bricks brick 
storm was the attack du jour 

297
00:16:12,960 --> 00:16:16,840
last fall basically like and it 
hasn't gone away. 

298
00:16:16,840 --> 00:16:20,360
It's just people have learned to
cope with it a little bit and 

299
00:16:20,360 --> 00:16:22,760
and somewhat one of the ways to 
do that is file integrity 

300
00:16:22,760 --> 00:16:24,960
monitoring. 
And there's a new interface. 

301
00:16:24,960 --> 00:16:28,400
It's API driven right now, it's 
the beginnings of it, but the 

302
00:16:28,400 --> 00:16:35,400
ability to monitor files on the 
host on V center and have a raw 

303
00:16:35,680 --> 00:16:40,160
report out that if anything has 
changed, you know, and so that's

304
00:16:40,160 --> 00:16:43,440
important to V Center. 
I will, I will mention it too 

305
00:16:43,440 --> 00:16:45,720
that the appliances have got 
aid. 

306
00:16:45,720 --> 00:16:50,200
It's the open source aide, it's 
the open source version of 

307
00:16:50,200 --> 00:16:52,160
Tripwire. 
It goes through and hashes all 

308
00:16:52,160 --> 00:16:56,360
the files on a on a machine. 
And so that's been present for a

309
00:16:56,360 --> 00:16:58,680
while too. 
And so that's helpful for file 

310
00:16:58,680 --> 00:17:02,040
integrity monitoring. 
But having an interface that can

311
00:17:02,040 --> 00:17:04,640
warn you ahead of time that 
something's changing, you know, 

312
00:17:04,920 --> 00:17:08,839
send something to VCF operations
for logs 9.1, we're calling it 

313
00:17:08,839 --> 00:17:13,079
just log management now and send
it to log management and set an 

314
00:17:13,079 --> 00:17:16,280
alert on it. 
Hey, if I get something from the

315
00:17:16,280 --> 00:17:19,880
file integrity monitoring 
system, that's a negative 

316
00:17:19,880 --> 00:17:22,440
report, you know, something bad,
you know, actually alert a 

317
00:17:22,440 --> 00:17:25,599
human, you know, because that's 
the thing you want to know. 

318
00:17:26,440 --> 00:17:29,600
You want to know about this 
stuff, even if it's bad news, 

319
00:17:29,600 --> 00:17:32,160
you want to know about it as 
early as possible, you know? 

320
00:17:32,160 --> 00:17:35,440
And so because, yeah, you, you 
don't want to find out when 

321
00:17:35,440 --> 00:17:38,680
you're being ransomed, when you 
are on the news, that sort of 

322
00:17:38,680 --> 00:17:41,560
thing, you know, you want to be 
able to contain this thing. 

323
00:17:41,560 --> 00:17:46,280
So yeah, those are two really 
interesting changes in 9.1. 

324
00:17:47,080 --> 00:17:49,920
I think especially for vsphere, 
the, the file integrity 

325
00:17:49,920 --> 00:17:52,800
monitoring is, is going to be 
important because we've seen 

326
00:17:52,800 --> 00:17:56,560
some customers where, you know, 
the, the ransomware was dormant 

327
00:17:56,560 --> 00:18:00,960
for three, 4-5 weeks. 
So the lower that it takes, so 

328
00:18:00,960 --> 00:18:03,520
the, the, the, the more amount 
of time that has passed, the 

329
00:18:03,520 --> 00:18:05,320
more challenging it will become 
to recover. 

330
00:18:05,320 --> 00:18:08,440
So I think that is fantastic. 
And I can, I can imagine that 

331
00:18:08,440 --> 00:18:10,720
because I know you've got a 
GitHub, there's going to be some

332
00:18:10,880 --> 00:18:14,040
scripts popping up, etcetera, 
and a lot of information around 

333
00:18:14,040 --> 00:18:15,120
that. 
So that, that could be very 

334
00:18:15,120 --> 00:18:16,440
useful. 
And maybe you want to plug that 

335
00:18:16,440 --> 00:18:17,760
GitHub by the way, because I 
think. 

336
00:18:18,320 --> 00:18:20,400
It's one of the. 
Fantastic resources at the 

337
00:18:20,400 --> 00:18:23,000
moment. 
Yeah, so our GitHub repository, 

338
00:18:23,000 --> 00:18:26,800
we've got it's 
github.com/VMware, you know, and

339
00:18:26,800 --> 00:18:29,200
then if you search for security,
you'll find two different 

340
00:18:29,480 --> 00:18:32,600
repositories there. 
One is the disastig stuff, 

341
00:18:32,600 --> 00:18:35,360
that's the US federal government
compliance stuff. 

342
00:18:35,360 --> 00:18:37,560
And the other one is the one 
that I manage. 

343
00:18:37,880 --> 00:18:43,040
It's VCF security and compliance
guidelines, long name, but to 

344
00:18:43,040 --> 00:18:45,920
the, it's got the hardening 
guidance in it, the security 

345
00:18:45,920 --> 00:18:48,640
configuration guide. 
It's got compliance, regulatory 

346
00:18:48,640 --> 00:18:51,080
compliance stuff. 
If you're into that sort of 

347
00:18:51,080 --> 00:18:55,040
thing, well, I'm sorry, but to 
the to start with, but we've got

348
00:18:55,040 --> 00:18:59,840
materials for that and to help 
explain all of the all of the 

349
00:18:59,840 --> 00:19:03,440
features and functions of VCF to
your auditors, for example, 

350
00:19:03,720 --> 00:19:06,560
we've got Q&A. 
And yeah, it's been busy here 

351
00:19:06,560 --> 00:19:09,560
with the launch, but one of my 
things moving forward here, 

352
00:19:09,560 --> 00:19:11,960
probably starting next week, is 
to start going through there and

353
00:19:11,960 --> 00:19:15,800
updating all of the Q&A with all
the new stuff, the new features,

354
00:19:16,560 --> 00:19:18,280
new functionality, sample 
scripts. 

355
00:19:18,280 --> 00:19:20,600
As you're. 
I believe William Lamb is also 

356
00:19:20,600 --> 00:19:22,240
working on some of that stuff 
too. 

357
00:19:22,600 --> 00:19:26,480
And so he's an unstoppable 
force, but, you know, being able

358
00:19:26,480 --> 00:19:28,960
to link to some of his his 
things. 

359
00:19:28,960 --> 00:19:33,120
And yeah, so just, I like it as 
a repository. 

360
00:19:33,320 --> 00:19:37,040
The things change all the time. 
You can always get the latest 

361
00:19:37,040 --> 00:19:38,280
version of it. 
You can check it out. 

362
00:19:38,280 --> 00:19:40,640
You can clone it. 
We operate it kind of as a Mono 

363
00:19:40,640 --> 00:19:44,440
repository, which is good and 
bad, you know, but yeah. 

364
00:19:44,680 --> 00:19:46,240
Yeah. 
I think that's that's fantastic.

365
00:19:46,240 --> 00:19:49,280
I actually when I did a search 
for something specific for the 

366
00:19:49,280 --> 00:19:51,520
native key provider, ended up on
it a couple of times. 

367
00:19:51,520 --> 00:19:54,880
So I can think I could see it 
being very helpful for 

368
00:19:54,880 --> 00:19:56,680
customers. 
Now the other thing you've 

369
00:19:56,720 --> 00:20:00,080
mentioned earlier as well was 
around patching and we've 

370
00:20:00,080 --> 00:20:02,720
introduced a couple of new 
capabilities now. 

371
00:20:02,720 --> 00:20:06,680
I actually quickly looked at it 
and I used quick for a reason, 

372
00:20:06,680 --> 00:20:10,120
because we've got quick boot 
live patch for ESXI, quick patch

373
00:20:10,120 --> 00:20:13,600
for V centre. 
Now I got confused fairly fast. 

374
00:20:13,600 --> 00:20:15,520
I'm guessing the listeners also 
got confused. 

375
00:20:15,520 --> 00:20:18,200
So maybe you can explain what 
those things are and how they 

376
00:20:18,200 --> 00:20:20,200
actually come into play and how 
they should be using them. 

377
00:20:20,320 --> 00:20:28,400
Yeah, So we, so in ESXV Sphere 8
update 3, we introduced on ESX, 

378
00:20:28,400 --> 00:20:32,440
we introduced the idea of live 
patching and what I kind of a 

379
00:20:32,440 --> 00:20:36,640
category I don't like this term,
but I, I think people understand

380
00:20:36,640 --> 00:20:39,080
it and the whole thing better 
when I call it 0 downtime 

381
00:20:39,080 --> 00:20:43,280
patching. 0 downtime is not 
quite right because, but you 

382
00:20:43,280 --> 00:20:44,840
don't have to. 
It's the idea that you don't 

383
00:20:44,840 --> 00:20:47,400
have to take the whole thing 
down, the whole object, whether 

384
00:20:47,400 --> 00:20:51,480
it's ESX or V center now or 
whatever, you don't have to take

385
00:20:51,480 --> 00:20:53,400
the whole thing down. 
It just patches the thing that's

386
00:20:53,400 --> 00:20:55,760
wrong, you know, or the thing 
that needs to be patched. 

387
00:20:56,280 --> 00:20:58,840
And there's a variety of 
different techniques for it and 

388
00:20:58,840 --> 00:21:00,320
that. 
But on ESX, it's called live 

389
00:21:00,320 --> 00:21:02,640
patch. 
We, like I said, we introduced 

390
00:21:02,640 --> 00:21:06,200
that in eight update 3, but the 
scope of it in eight update 3 

391
00:21:06,200 --> 00:21:09,960
was so small that we've actually
never been able to release a 

392
00:21:09,960 --> 00:21:13,760
patch that used it on eight. 
In Nine, we widened the scope of

393
00:21:13,760 --> 00:21:18,720
things so it can patch a whole 
lot of other stuff on ESX, but 

394
00:21:18,720 --> 00:21:21,280
we had still had a problem 
anything that had a trusted 

395
00:21:21,280 --> 00:21:23,640
platform module in installed and
enabled. 

396
00:21:24,440 --> 00:21:27,120
Basically we ran afoul of that. 
The security you get from a 

397
00:21:27,640 --> 00:21:32,360
trusted platform module, the 
integrity checking we basically 

398
00:21:32,360 --> 00:21:36,000
what we what live patching does 
is replacing parts of the the 

399
00:21:36,000 --> 00:21:40,040
running operating system. 
And that's exactly what the TPM 

400
00:21:40,040 --> 00:21:44,040
and the integrity checks inside 
of ESX are built to prevent, 

401
00:21:44,040 --> 00:21:46,440
right? 
So we had to figure out a way to

402
00:21:46,440 --> 00:21:48,280
deal with that. 
Hey, we're the good guys, let us

403
00:21:48,280 --> 00:21:50,560
do this, you know, but don't let
the bad guys do it. 

404
00:21:50,960 --> 00:21:54,800
And so we did that in 9.1. 
So all hosts now can do live 

405
00:21:54,800 --> 00:21:56,640
patching. 
And so that's helpful. 

406
00:21:56,640 --> 00:22:00,880
You know, the idea with is, so 
all security stuff is different,

407
00:22:01,880 --> 00:22:04,040
you know, all vulnerabilities 
are different and different 

408
00:22:04,040 --> 00:22:05,480
things. 
There's different considerations

409
00:22:05,480 --> 00:22:08,840
for all of them. 
But our goal is that 80% of the 

410
00:22:08,840 --> 00:22:12,800
critical patches that we would 
release for ESX would be live 

411
00:22:12,800 --> 00:22:15,840
patchable in this way. 
And so, and that's nice. 

412
00:22:15,840 --> 00:22:17,880
You don't have to clear off. 
So live patch, if you're not 

413
00:22:17,880 --> 00:22:20,880
familiar with it, you don't 
clear off all the workloads. 

414
00:22:20,880 --> 00:22:23,720
Basically the host enter is what
we call partial maintenance mode

415
00:22:24,080 --> 00:22:26,520
where the workloads are still 
there and they're running and 

416
00:22:26,520 --> 00:22:30,240
they're running just fine, but 
nothing comes in or goes out, 

417
00:22:30,240 --> 00:22:32,160
You know, it's sort of a stable 
state there. 

418
00:22:32,480 --> 00:22:34,800
And then whatever needs to get 
updated gets updated. 

419
00:22:34,800 --> 00:22:38,920
If it's just SSH patch SSH. 
If it's the virtual machine 

420
00:22:38,920 --> 00:22:43,560
monitor, then there's basically 
I I've called it like an 

421
00:22:43,560 --> 00:22:48,240
internal process to process V 
motion there it's quick suspend,

422
00:22:48,320 --> 00:22:51,280
fast suspend and resume is what 
engineering calls it. 

423
00:22:51,600 --> 00:22:55,360
Whatever, you know, it just 
basically replacing the virtual 

424
00:22:55,360 --> 00:22:58,720
machine monitor out from 
underneath the running VM and it

425
00:22:58,720 --> 00:23:02,840
goes really fast and most yeah 
workloads don't notice it and 

426
00:23:02,840 --> 00:23:04,800
then it takes it back out of 
partial maintenance mode. 

427
00:23:04,800 --> 00:23:07,560
And the idea is that you can 
patch an entire cluster get a 

428
00:23:07,560 --> 00:23:11,720
critical vulnerability out of 
the way fast, you know and in an

429
00:23:11,720 --> 00:23:15,560
hour rather than days and and 
then be protected again. 

430
00:23:16,000 --> 00:23:19,640
And then as you mentioned, yeah,
quick the quick patch. 

431
00:23:19,640 --> 00:23:22,360
So what we're calling the V 
center version of this is quick 

432
00:23:22,360 --> 00:23:26,520
patch naming is hard. 
I will just tell you that the 

433
00:23:26,600 --> 00:23:29,880
the in fact, the only good name 
we've got the only two good 

434
00:23:29,880 --> 00:23:33,400
names that I can ever think of 
in our whole fleet is V San and 

435
00:23:33,400 --> 00:23:36,120
V motion. 
All the rest are whatever. 

436
00:23:36,520 --> 00:23:40,760
But so we call it quick patch, 
same net effect basically is 

437
00:23:40,760 --> 00:23:44,480
that you don't have to take all 
of V centre down and endure an 

438
00:23:44,480 --> 00:23:47,040
outage there, sit there 
watching, you know, the post 

439
00:23:47,040 --> 00:23:51,720
data post installed data 
conversion dialogue for an hour,

440
00:23:52,320 --> 00:23:54,280
that sort of thing. 
You just update what needs to 

441
00:23:54,280 --> 00:23:56,280
get updated and then you get 
you're back in business. 

442
00:23:56,280 --> 00:23:59,240
But there are service restarts 
sometimes if it's updating the 

443
00:23:59,240 --> 00:24:04,280
management console, the the the 
actual V sphere UI, then you'll 

444
00:24:04,280 --> 00:24:07,800
see an outage there, that sort 
of thing, but very helpful to 

445
00:24:07,800 --> 00:24:10,560
try and just patching is this 
unwanted thing. 

446
00:24:10,560 --> 00:24:14,120
Nobody wakes up today and says, 
you know, I, you know, today is 

447
00:24:14,120 --> 00:24:15,840
a beautiful day. 
I'm going to patch, you know, 

448
00:24:15,840 --> 00:24:18,400
nobody, you know, you wake up 
and discover that you have to 

449
00:24:18,400 --> 00:24:22,240
patch and can we make it less of
a pain to do that? 

450
00:24:22,240 --> 00:24:24,680
And the answer is yes. 
And we have, you know, and so 

451
00:24:24,680 --> 00:24:28,400
hopefully this stuff is helpful.
And then these ideas are 

452
00:24:28,400 --> 00:24:33,640
infectious, you know, like if we
can do this for V center, can we

453
00:24:33,640 --> 00:24:36,000
do it for VCF operations? 
Can we do it for all these other

454
00:24:36,000 --> 00:24:38,320
things? 
And so it will, it will spread 

455
00:24:38,600 --> 00:24:40,360
throughout the stack. 
And so that's really nice. 

456
00:24:42,720 --> 00:24:45,400
Now let me ask you this then, 
because I always think when we 

457
00:24:45,400 --> 00:24:50,680
talk about things like quick 
bats, live bats, etcetera, that 

458
00:24:50,880 --> 00:24:53,080
especially the product 
management team always tries to 

459
00:24:53,080 --> 00:24:58,240
force or direct the customers to
implement the patches as quickly

460
00:24:58,240 --> 00:25:00,800
as possible. 
So preferably not even just the 

461
00:25:00,800 --> 00:25:02,680
batches, but also the major 
releases, right? 

462
00:25:02,680 --> 00:25:05,320
When 9.1 releases, everyone 
needs to use 9.1. 

463
00:25:05,320 --> 00:25:09,080
Now knowing you, you've got an 
opinion about this. 

464
00:25:09,080 --> 00:25:11,080
So what would you recommend 
customers doing? 

465
00:25:11,320 --> 00:25:13,520
Should they be implementing 
those batches the same day? 

466
00:25:13,520 --> 00:25:15,760
Should they be implementing 9.1 
the same day? 

467
00:25:15,760 --> 00:25:18,000
Or, you know, how do you go 
about having these discussions 

468
00:25:18,000 --> 00:25:21,080
with customers? 
Well, one, you know me well, 

469
00:25:21,080 --> 00:25:23,920
Duncan. 
And two, the yes, I do have an 

470
00:25:23,920 --> 00:25:27,360
opinion as it turns out. 
Two, you know, let's go back to 

471
00:25:27,360 --> 00:25:29,440
that AI thing. 
You know, we were talking about 

472
00:25:29,760 --> 00:25:33,760
vulnerabilities and, and patches
being released in volume. 

473
00:25:33,760 --> 00:25:37,040
In fact, there was a big data, 
one of our PMS, Adam Hawley, he,

474
00:25:37,600 --> 00:25:39,360
he used to work on big data 
stuff. 

475
00:25:39,360 --> 00:25:44,720
And there's the four or five VS 
of big data, volume, variety, 

476
00:25:45,000 --> 00:25:48,840
velocity and veracity. 
And it turns out those work 

477
00:25:48,840 --> 00:25:52,360
really well for patching too. 
And especially nowadays where 

478
00:25:52,360 --> 00:25:58,000
there's volume and there's 
velocity and the a lot of 

479
00:25:58,000 --> 00:26:02,200
critical stuff, like I said, you
know, 0 days Linux 0 days are 

480
00:26:02,200 --> 00:26:06,080
one a day basically here. 
And So what, what do you do? 

481
00:26:06,080 --> 00:26:10,760
Do you, you know, patching, I 
guess it's, I'm coming around to

482
00:26:10,760 --> 00:26:14,960
say patching is not, you want to
be able to patch quickly. 

483
00:26:15,000 --> 00:26:18,040
And we would love it if people 
would all stop what they're 

484
00:26:18,040 --> 00:26:20,760
doing and upgrade to 9.1 right 
now because there's all these 

485
00:26:20,760 --> 00:26:24,720
great features, all of the stuff
that we really feel that will 

486
00:26:24,720 --> 00:26:26,920
help people and help 
organizations deal with these 

487
00:26:26,920 --> 00:26:29,760
problems. 
But obviously people running 

488
00:26:29,760 --> 00:26:33,440
eight, people running 9, you 
know, they've got other stuff, 

489
00:26:33,440 --> 00:26:35,640
they've got other plans for 
their summer and stuff like 

490
00:26:35,640 --> 00:26:38,400
that. 
And so it's, it's going to be a 

491
00:26:38,400 --> 00:26:42,520
little bit and you know, you can
defend yourself on the other 

492
00:26:42,520 --> 00:26:46,560
platforms too, you know, like it
going back to patching, being 

493
00:26:46,560 --> 00:26:50,400
able to apply patching, apply 
patches rapidly, you know, is, 

494
00:26:50,600 --> 00:26:54,600
is a technical problem, sure, 
actually getting it done. 

495
00:26:54,600 --> 00:26:56,960
But most often it's an 
organizational problem. 

496
00:26:57,280 --> 00:26:59,880
You know, well, the patches got 
to go to a change change 

497
00:26:59,880 --> 00:27:03,560
Advisory Board and they only 
meet on the 1st of the month and

498
00:27:03,640 --> 00:27:05,720
you know, stuff like that. 
And that's not good enough 

499
00:27:05,720 --> 00:27:07,280
anymore. 
You need to compress that. 

500
00:27:07,280 --> 00:27:11,520
You need to, you need to shorten
those windows and be able to be 

501
00:27:11,520 --> 00:27:14,880
able to look at the look at the 
advisories, look at the security

502
00:27:15,040 --> 00:27:18,200
advisory coming out, make a 
determination, is this something

503
00:27:18,200 --> 00:27:19,840
that we're going to need to 
apply or not? 

504
00:27:19,840 --> 00:27:22,680
And then get it done quickly. 
You know, and so that's going to

505
00:27:22,680 --> 00:27:24,760
be the hardest thing for 
organizations is actually 

506
00:27:24,760 --> 00:27:27,440
getting over. 
And again, I, well, I mentioned 

507
00:27:27,440 --> 00:27:29,960
it earlier to the, the chaining 
of vulnerabilities. 

508
00:27:31,240 --> 00:27:35,480
That's where organizations are 
only choosing to patch the 

509
00:27:35,480 --> 00:27:40,320
critical things, you know, and 
the they're leaving all these 

510
00:27:40,320 --> 00:27:42,520
other vulnerabilities there for 
attackers to use. 

511
00:27:42,520 --> 00:27:45,360
And that's another it's a people
problem is what that is. 

512
00:27:45,720 --> 00:27:47,880
You know, you need to get over 
it and you need to be able to de

513
00:27:47,920 --> 00:27:50,560
risk. 
They think that they're they're 

514
00:27:50,560 --> 00:27:54,800
removing risk from the process, 
but they're not they're they're 

515
00:27:55,040 --> 00:27:57,640
you can't de risk patching that 
way. 

516
00:27:57,800 --> 00:27:59,680
You have to do it on the the 
other side of things. 

517
00:27:59,680 --> 00:28:00,920
You have to protect the 
workloads. 

518
00:28:00,920 --> 00:28:04,520
You have to have backups, use 
snapshots, use the V SAN data 

519
00:28:04,520 --> 00:28:07,680
protection stuff, which is 
glorious, you know, like, and 

520
00:28:07,680 --> 00:28:11,920
people still have this idea of 
snapshots from like V Sphere, 

521
00:28:11,920 --> 00:28:15,640
like Virtual infrastructure 35, 
where snapshots were really kind

522
00:28:15,640 --> 00:28:19,480
of intrusive and they could 
pause if you're deleting them, 

523
00:28:19,480 --> 00:28:21,800
they could really pause the VMS 
and stuff like that. 

524
00:28:21,800 --> 00:28:25,040
That's all gone on V SAN. 
All that stuff is fixed, you 

525
00:28:25,040 --> 00:28:28,960
know, And so people need to to 
get it in their heads and get 

526
00:28:28,960 --> 00:28:33,480
their organizations up to 2026 
here and think about using the 

527
00:28:33,480 --> 00:28:37,840
stuff and de risk the the other 
side of things because not only 

528
00:28:38,160 --> 00:28:40,880
they'll then they can just go 
and hit the, you know, update 

529
00:28:40,880 --> 00:28:43,080
all button on windows, you know,
just patch it all. 

530
00:28:43,080 --> 00:28:44,760
Don't worry about which ones are
important. 

531
00:28:44,760 --> 00:28:48,960
Just go, you know, they can. 
And then if something's wrong, 

532
00:28:49,000 --> 00:28:52,280
you restore the you restore the 
revert the snapshot, restore the

533
00:28:52,280 --> 00:28:55,080
backup, whatever. 
But then they're also protected 

534
00:28:55,080 --> 00:28:59,360
from an application upgrade. 
They're protected from ADR event

535
00:28:59,560 --> 00:29:01,880
all of that stuff. 
You solve all of these problems 

536
00:29:02,080 --> 00:29:05,560
together, and that's what we 
really need organizations to 

537
00:29:05,560 --> 00:29:07,320
think about. 
Not only doing it faster, but 

538
00:29:07,320 --> 00:29:10,640
doing it better too, you know, 
And those two things come hand 

539
00:29:10,640 --> 00:29:13,000
in hand. 
Yeah, I think that that that 

540
00:29:13,000 --> 00:29:15,280
makes a lot of sense. 
Now, the other thing that I also

541
00:29:15,280 --> 00:29:18,680
briefly wanted to discuss is if 
you look at VCF and V Sphere 

542
00:29:18,680 --> 00:29:23,080
actually as well is there's also
a big aspect when it comes to 

543
00:29:23,080 --> 00:29:27,360
security around the network 
itself, right? 

544
00:29:27,360 --> 00:29:29,960
Of course there's the security 
part of it like the firewalling,

545
00:29:29,960 --> 00:29:31,720
et cetera. 
But there's also the networking 

546
00:29:31,720 --> 00:29:35,200
aspect that I know we've had a 
lot of discussions in the past 

547
00:29:35,600 --> 00:29:38,560
in terms of what to do with the 
management network, the emotion 

548
00:29:38,560 --> 00:29:42,640
network, the storage networks, 
the virtual machine networks, 

549
00:29:42,640 --> 00:29:44,960
etcetera. 
So what are your thoughts around

550
00:29:44,960 --> 00:29:46,640
that? 
Maybe you can talk us through 

551
00:29:46,640 --> 00:29:49,160
what that should look like maybe
just at a high level, I don't 

552
00:29:49,160 --> 00:29:52,400
expect you to, you know, give a 
whole best practice or or 

553
00:29:52,400 --> 00:29:55,320
design, but maybe could just 
talk us us through what that 

554
00:29:55,320 --> 00:29:57,640
should look like in in general 
for most customers. 

555
00:29:58,280 --> 00:30:00,240
Yeah. 
Well, if you want the whole 90 

556
00:30:00,240 --> 00:30:02,320
minute version of it, you can 
come see me at Explore. 

557
00:30:02,680 --> 00:30:04,880
I'm doing the tutorial that I 
usually that I've done for the 

558
00:30:04,880 --> 00:30:10,000
last two or three years about 
hardening and securing VCF and 

559
00:30:10,000 --> 00:30:12,120
we walk through the whole 
infrastructure and physical all 

560
00:30:12,120 --> 00:30:15,840
the way up. 
But at a high level it's about 

561
00:30:15,840 --> 00:30:18,200
zero trust. 
You know, organizations have got

562
00:30:18,200 --> 00:30:20,600
a lot of trust. 
We trust an identity provider 

563
00:30:20,840 --> 00:30:25,000
and that's, you know, when that 
identity provider is 

564
00:30:25,000 --> 00:30:29,680
compromised, everything goes, 
you know, and the you talk about

565
00:30:29,680 --> 00:30:32,280
it sometimes blast radius, the 
idea like, you know, what's 

566
00:30:32,280 --> 00:30:35,760
touched when one of these things
explodes and you know, the blast

567
00:30:35,760 --> 00:30:38,160
radius of an identity provider 
is huge. 

568
00:30:38,160 --> 00:30:43,720
It's the whole organization, you
know, and network, network 

569
00:30:43,720 --> 00:30:46,400
perimeters and things like that.
A lot of organizations are still

570
00:30:46,800 --> 00:30:48,720
treat their network like one big
happy family. 

571
00:30:48,720 --> 00:30:51,440
And you know, we're all just 
buddies here on the network and 

572
00:30:51,800 --> 00:30:55,160
no, you know, like that's, you 
can't do that anymore, you know,

573
00:30:55,160 --> 00:30:58,320
and especially backup systems. 
Backup systems should be ultra 

574
00:30:58,320 --> 00:31:01,200
isolated, ultra sequestered in 
that. 

575
00:31:01,200 --> 00:31:05,720
But you know, we, we need to 
practice zero trust and we need 

576
00:31:05,720 --> 00:31:09,120
to, to stop trusting things, you
know, so one of the, one of the 

577
00:31:09,120 --> 00:31:11,440
things that we suggest for 
identity providers, for example,

578
00:31:11,440 --> 00:31:14,600
is have your own identity 
provider inside. 

579
00:31:14,840 --> 00:31:18,920
So 1 build, build a perimeter 
around your, around your 

580
00:31:18,920 --> 00:31:21,320
management interfaces. 
You know that nothing gets in, 

581
00:31:21,320 --> 00:31:25,440
nothing gets out without your 
permission either, you know, and

582
00:31:25,440 --> 00:31:28,760
really lock that down to like a 
privileged access workstation or

583
00:31:29,440 --> 00:31:32,920
or maybe a bastion host, 
whatever, whatever you want to 

584
00:31:32,920 --> 00:31:34,840
do. 
In the past, I've used AVPN 

585
00:31:35,240 --> 00:31:38,680
actually had a a boundary there 
where I'd VPN into the 

586
00:31:38,680 --> 00:31:43,480
management network and seems a 
little seemed a little over like

587
00:31:43,480 --> 00:31:46,120
overkill then totally not 
overkill anymore. 

588
00:31:46,560 --> 00:31:51,080
And the but that level of 
isolation that's really nice. 

589
00:31:51,080 --> 00:31:53,800
So you can monitor the traffic 
in and out, that sort of thing. 

590
00:31:54,960 --> 00:31:58,240
Put an identity provider inside 
that boundary, you know, that's 

591
00:31:58,240 --> 00:32:00,800
just that just belongs to VCF or
just belongs to the 

592
00:32:00,800 --> 00:32:04,680
infrastructure team or whoever, 
you know, And you know, we 

593
00:32:04,800 --> 00:32:08,240
again, we, we see problems with 
the, you know, VCF admins are 

594
00:32:08,240 --> 00:32:11,240
like, oh, that sounds great, 
except the that's not the way we

595
00:32:11,240 --> 00:32:12,760
do things here in the 
organization. 

596
00:32:12,760 --> 00:32:16,640
Well, OK, you know, but what 
we've been advocating for is 

597
00:32:16,640 --> 00:32:20,680
really, you know, if you're 
getting some static from the, 

598
00:32:21,160 --> 00:32:24,040
the identity, so often there's 
like an identity team or 

599
00:32:24,040 --> 00:32:26,760
whatever, the Active Directory 
people or entry ID people or 

600
00:32:26,760 --> 00:32:30,840
whoever, you know, get them to 
give you your own entry ID 

601
00:32:30,840 --> 00:32:34,680
tenant, give them to get them to
help you deploy something in 

602
00:32:34,680 --> 00:32:37,400
your own network, you know, so 
that it's yours, but you still 

603
00:32:37,400 --> 00:32:39,680
got their, their wisdom and 
oversight in that. 

604
00:32:39,680 --> 00:32:42,680
But just feel one of those 
people often create like a, 

605
00:32:43,160 --> 00:32:46,720
create a, a platform team, you 
know, like an infrastructure 

606
00:32:46,720 --> 00:32:48,600
team. 
Let's get an identity person on 

607
00:32:48,600 --> 00:32:51,040
it, for example. 
But you know, and it's stuff 

608
00:32:51,040 --> 00:32:54,120
like that, you know, having hard
boundaries is really important 

609
00:32:54,600 --> 00:32:56,000
there. 
And that's not really a zero 

610
00:32:56,000 --> 00:32:58,880
trust. 
I, I talk about zero trust, hard

611
00:32:58,880 --> 00:33:01,880
boundaries like that are 
actually kind of anti zero trust

612
00:33:02,360 --> 00:33:06,360
because, you know, zero trust is
more about always verifying 

613
00:33:06,360 --> 00:33:08,720
identities and things. 
But at the infrastructure level,

614
00:33:09,560 --> 00:33:11,360
that's hard. 
There's still a lot of trust. 

615
00:33:11,360 --> 00:33:14,120
We trust network switches, we 
trust fiber channel switches, we

616
00:33:14,120 --> 00:33:16,600
trust other hosts and things 
like that. 

617
00:33:16,600 --> 00:33:20,680
And so you got to protect it. 
And having a hard a wall, think 

618
00:33:20,680 --> 00:33:24,520
of a castle, you know, build a 
Moat, build a, a big wall there,

619
00:33:24,520 --> 00:33:28,240
put guards on it, have one entry
point that you can watch very, 

620
00:33:28,360 --> 00:33:30,440
very carefully, that sort of 
thing. 

621
00:33:30,440 --> 00:33:33,880
And so, yeah, that's, you know, 
that's the gist of it. 

622
00:33:34,040 --> 00:33:37,560
Identity is the big one. 
Lately, though, most breaches, 

623
00:33:37,680 --> 00:33:40,440
the most breaches that we see, 
the stuff that that we get 

624
00:33:40,440 --> 00:33:44,360
involved in, the stuff that we 
see in the news and that they 

625
00:33:44,360 --> 00:33:48,880
can't, they, they're coming in. 
They might end up in VCF, in ESX

626
00:33:48,880 --> 00:33:51,440
and all that stuff, but they're 
logging in as an administrator. 

627
00:33:51,440 --> 00:33:54,440
They've stolen credentials from 
somewhere else or they've broken

628
00:33:54,440 --> 00:33:58,080
into the identity provider that 
VCF trusted and just added 

629
00:33:58,080 --> 00:34:01,120
themselves as an admin, you 
know, and you got to find a way 

630
00:34:01,120 --> 00:34:02,320
to stop that. 
You got to find. 

631
00:34:02,360 --> 00:34:04,760
And we've got some suggestions. 
And Speaking of that GitHub 

632
00:34:04,760 --> 00:34:07,920
repository we've got, I've got a
copy of my slides out there from

633
00:34:07,920 --> 00:34:11,760
a talk that I've got out on 
YouTube on identity protections 

634
00:34:11,760 --> 00:34:14,560
and stuff like that. 
But those are the big ones, 

635
00:34:14,840 --> 00:34:17,560
honestly. 
Yeah, When it comes to identity,

636
00:34:17,560 --> 00:34:20,800
I think in the past, at least 
when I was still an 

637
00:34:20,800 --> 00:34:23,639
administrator, I think that you 
know, even up all the way up to 

638
00:34:23,639 --> 00:34:25,760
like 5 or 6 years ago maybe it 
still happens. 

639
00:34:25,760 --> 00:34:27,600
That's probably something I 
should ask you as well. 

640
00:34:27,600 --> 00:34:30,280
Do you still see people using 
just a single account then for 

641
00:34:30,280 --> 00:34:32,320
for vsphere? 
Because I mean in the past 

642
00:34:32,320 --> 00:34:35,840
everyone used Administrator at 
the vsphere dot local and of 

643
00:34:35,840 --> 00:34:37,679
course the root account for ESX.
Yeah. 

644
00:34:37,679 --> 00:34:42,639
So root on ESX is still tough 
because you know, there's been 

645
00:34:42,639 --> 00:34:46,360
improvements in API driven 
account provisioning there and 

646
00:34:46,360 --> 00:34:48,520
things like that. 
And we see a lot of especially 

647
00:34:48,520 --> 00:34:51,560
this is another area of vibe 
coding, you know, just tell 

648
00:34:51,560 --> 00:34:53,400
Claude, just tell codecs, 
whatever. 

649
00:34:53,560 --> 00:34:57,520
Hey, I want to, I want a script 
that automatically adds users 

650
00:34:57,520 --> 00:34:59,440
and deletes users and helps me 
manage ESX. 

651
00:34:59,440 --> 00:35:02,360
And it'll create one for you. 
It looks up the AP is and does 

652
00:35:02,360 --> 00:35:05,680
it, you know, and we've got a 
lot of a lot of organizations 

653
00:35:05,680 --> 00:35:07,520
that are starting to do that. 
They don't want to. 

654
00:35:07,600 --> 00:35:12,040
But ESX is fairly limited right 
now and how it's, it's identity 

655
00:35:12,640 --> 00:35:14,720
capabilities there. 
You can still attach it to 

656
00:35:14,720 --> 00:35:17,240
Active Directory, but which 
Active Directory are you going 

657
00:35:17,240 --> 00:35:19,480
to attach it to? 
You can create one of your own, 

658
00:35:19,840 --> 00:35:23,120
you know, inside that perimeter 
like I was talking about, or you

659
00:35:23,120 --> 00:35:25,320
can just provision individual 
accounts. 

660
00:35:25,320 --> 00:35:28,760
Maybe a lot of organizations 
have a password, a privilege 

661
00:35:28,760 --> 00:35:33,320
access management, Pam solution 
for their for root and that that

662
00:35:33,320 --> 00:35:34,960
where you can check out the root
password. 

663
00:35:35,320 --> 00:35:37,440
It's the cyber arks of the world
and stuff like that. 

664
00:35:37,760 --> 00:35:39,960
And they can check out the root 
password, do what they need to 

665
00:35:39,960 --> 00:35:42,480
do, and then cyber Ark 
automatically rotates the 

666
00:35:42,480 --> 00:35:45,080
password when they check it back
in, that sort of thing. 

667
00:35:45,280 --> 00:35:46,520
That's a good solution. 
All. 

668
00:35:47,120 --> 00:35:48,680
There's a bunch of different 
solutions. 

669
00:35:49,320 --> 00:35:51,080
All organizations are different 
in that way. 

670
00:35:51,080 --> 00:35:55,080
But yeah, we still see people 
with and you still you still 

671
00:35:55,080 --> 00:35:58,040
need administrator at V sphere 
dot local once in a while, you 

672
00:35:58,040 --> 00:36:00,720
know, so you can't get rid of 
all of that stuff completely. 

673
00:36:00,720 --> 00:36:04,320
But you know, ESX you don't 
have, you can set the root 

674
00:36:04,320 --> 00:36:06,920
password to something random 
and, and as long as you've got a

675
00:36:06,920 --> 00:36:10,720
root level other account that 
you can use you, you'll be fine 

676
00:36:10,720 --> 00:36:14,720
Nowadays, you know, once it's 
attached to V center, then then 

677
00:36:14,720 --> 00:36:17,960
you can do some other things 
about locking, locking that down

678
00:36:17,960 --> 00:36:22,520
and that and so, but yeah, it's 
tricky. 

679
00:36:22,520 --> 00:36:24,720
And like I said, there's just a,
a bunch of different ways to do 

680
00:36:24,720 --> 00:36:28,600
it. 
And yeah, it, it depends on your

681
00:36:28,600 --> 00:36:31,440
organization too. 
That's I think the hardest part.

682
00:36:31,440 --> 00:36:33,160
Again, it becomes people and 
process. 

683
00:36:33,920 --> 00:36:34,960
Yeah. 
I think it's, you know, as you 

684
00:36:34,960 --> 00:36:37,920
mentioned, it's good hygiene to 
at least you know, automatically

685
00:36:37,920 --> 00:36:41,240
rotate those, those passwords as
you mentioned, if you could use 

686
00:36:41,240 --> 00:36:43,920
something like I think it was 
Cyber Ark, you said, I think 

687
00:36:43,920 --> 00:36:45,120
that. 
Yeah, there's just a good 

688
00:36:45,120 --> 00:36:46,400
example. 
There's a bunch of tools. 

689
00:36:46,480 --> 00:36:50,920
Yeah, you know, well and then 
having things that automatically

690
00:36:50,920 --> 00:36:54,160
rotate them, some regulatory 
compliance stuff requires you to

691
00:36:54,160 --> 00:36:56,800
rotate them on a periodic basis 
and it's probably a good idea 

692
00:36:56,800 --> 00:37:00,960
anyhow less, you know, if that 
password was used there. 

693
00:37:00,960 --> 00:37:03,520
But yeah. 
And then just monitoring for 

694
00:37:03,520 --> 00:37:05,480
other accounts, you know, 
attackers will create other 

695
00:37:05,480 --> 00:37:09,800
accounts and you know, really 
trying to drive all your 

696
00:37:09,800 --> 00:37:14,000
authentication and I through and
all your day-to-day stuff 

697
00:37:14,000 --> 00:37:16,920
through V Center itself. 
You know, where you've got a 

698
00:37:16,920 --> 00:37:20,640
really robust role based access 
control model there. 

699
00:37:20,640 --> 00:37:24,760
You've got all kinds of stuff 
available to you there to help 

700
00:37:24,760 --> 00:37:27,800
monitor what's going on and help
do day-to-day things. 

701
00:37:27,800 --> 00:37:30,600
You know, ESX, the permission 
model on ESX, it's basically 

702
00:37:31,040 --> 00:37:34,320
administrator read only or no 
access. 

703
00:37:34,320 --> 00:37:35,880
You know, it's, it's a 
hypervisor. 

704
00:37:35,880 --> 00:37:37,920
It's, it's, we want it to be 
simple. 

705
00:37:38,320 --> 00:37:41,400
So it is, but you know, try to 
drive all your stuff through 

706
00:37:41,400 --> 00:37:43,960
the, the main management 
interfaces and then you can add 

707
00:37:43,960 --> 00:37:46,160
MFA. 
You can do that federation stuff

708
00:37:46,160 --> 00:37:50,440
we were talking about the we can
go against a real identity 

709
00:37:50,440 --> 00:37:53,560
provider that does MFA, does 
conditional access. 

710
00:37:53,560 --> 00:37:57,320
Hey, Bob is logging in at a 
weird time from a foreign 

711
00:37:57,320 --> 00:38:01,920
country, country foreign to him 
at least, and typically, you 

712
00:38:01,920 --> 00:38:05,000
know, and from a device that 
hasn't been patched in three 

713
00:38:05,000 --> 00:38:07,360
years, you know, I think we're 
going to deny that, you know, 

714
00:38:07,360 --> 00:38:09,120
like that sort of thing. 
That's the sort of conditional 

715
00:38:09,120 --> 00:38:11,280
access stuff you can set up so. 
Yeah, that makes sense. 

716
00:38:11,280 --> 00:38:14,720
I mean, if Bob is logging in at 
2:00 at night and he's coming 

717
00:38:14,720 --> 00:38:18,240
from China or Russia instead of 
being in the US, it's it's kind 

718
00:38:18,240 --> 00:38:19,440
of weird. 
Yeah, 2 at night. 

719
00:38:19,440 --> 00:38:22,640
Not, not weird for me. 
But, you know, coming from 

720
00:38:22,640 --> 00:38:26,400
China, yeah, you know, coming 
from North Korea, yeah. 

721
00:38:26,480 --> 00:38:29,440
You know, coming from, well, 
wherever you know so. 

722
00:38:29,800 --> 00:38:32,120
I think that's a, that's a very 
valid argument. 

723
00:38:32,360 --> 00:38:34,320
And the other thing that I also 
briefly wanted to discuss 

724
00:38:34,320 --> 00:38:37,400
because I know this is something
that I've seen people asking 

725
00:38:37,400 --> 00:38:39,240
questions about on Reddit as 
well. 

726
00:38:39,560 --> 00:38:44,440
Like for instance, we have a 
firewall in ESX, but there's 

727
00:38:44,440 --> 00:38:48,760
also something like V defense. 
Now, I've never found the the 

728
00:38:48,760 --> 00:38:51,000
firewall in ESX particularly 
useful. 

729
00:38:51,640 --> 00:38:54,560
It's useful to a certain layer, 
but it's not what people expect 

730
00:38:54,560 --> 00:38:56,440
it to be. 
So maybe you can explain what 

731
00:38:56,440 --> 00:38:58,920
your thoughts are around that 
and how people should be using 

732
00:38:58,920 --> 00:39:01,200
it and what they shouldn't 
expect it to do. 

733
00:39:01,200 --> 00:39:02,920
And then maybe also talk about V
defense. 

734
00:39:03,520 --> 00:39:06,120
It is yes. 
It is not a so V defend great 

735
00:39:06,120 --> 00:39:10,120
tool and there's all kinds of 
interesting stuff in the road 

736
00:39:10,120 --> 00:39:14,200
map for for its future with the 
infrastructure itself. 

737
00:39:14,200 --> 00:39:18,560
But the the way things sit right
now, yeah, you're right, ES XS 

738
00:39:18,560 --> 00:39:20,600
firewall is not a modern 
firewall. 

739
00:39:20,600 --> 00:39:22,840
It's more like Acls on a network
switch. 

740
00:39:23,400 --> 00:39:29,760
And so it's pretty primitive. 
The people think ESX is is Linux

741
00:39:29,760 --> 00:39:33,040
and it's not, you know, it 
doesn't have IP tables and all 

742
00:39:33,040 --> 00:39:37,560
that stuff. the V center is 
Linux under the hood. 

743
00:39:37,560 --> 00:39:40,240
We prefer people didn't think 
about it like that, but it is, 

744
00:39:40,240 --> 00:39:43,600
you know, and so we can use IP 
tables and some more interesting

745
00:39:43,600 --> 00:39:46,480
things there. 
But yeah, ESX, it's pretty 

746
00:39:46,480 --> 00:39:50,040
simple, but the, the nice thing 
is you, you can have simple 

747
00:39:50,040 --> 00:39:52,080
rules. 
What is an ESX host need to talk

748
00:39:52,080 --> 00:39:55,920
to it needs to talk to DNS, it 
needs to talk to V center, it 

749
00:39:55,920 --> 00:39:57,720
needs to talk to the other hosts
in the cluster. 

750
00:39:57,920 --> 00:40:01,200
That's pretty much it, you know,
like maybe the console, maybe 

751
00:40:01,200 --> 00:40:04,240
some console access or SSH to a 
privileged workstation or 

752
00:40:04,240 --> 00:40:08,480
something here and there. 
But you know, it's, it's, it's a

753
00:40:08,480 --> 00:40:11,160
pretty simple operation. 
And so you can treat it simply. 

754
00:40:11,160 --> 00:40:13,680
Don't overthink that, you know, 
but. 

755
00:40:14,240 --> 00:40:18,080
You put a good perimeter 
firewall on it there too, you 

756
00:40:18,080 --> 00:40:21,920
know, and so you know something 
at the boundary. 

757
00:40:22,520 --> 00:40:24,000
And that's the nice thing about 
V Defend. 

758
00:40:24,000 --> 00:40:29,880
So V Defend is basically the OG 
of of micro segmentation. 

759
00:40:29,880 --> 00:40:34,520
It was, it's been around 
forever, it seems and it's it 

760
00:40:34,520 --> 00:40:35,960
enforces. 
It's not. 

761
00:40:36,280 --> 00:40:40,000
So a normal firewall that's at 
the boundary, everything on the 

762
00:40:40,000 --> 00:40:42,600
network segment behind the 
firewall could talk freely to 

763
00:40:42,600 --> 00:40:45,280
each other because there's no 
checkpoint there, right? 

764
00:40:45,280 --> 00:40:47,360
You know, that's the normal 
firewall model. 

765
00:40:47,880 --> 00:40:53,360
But the micro segmentation 
applies the firewall rules at 

766
00:40:53,360 --> 00:40:55,680
the virtual network interface, 
the VNIC. 

767
00:40:56,080 --> 00:40:59,880
And so you can have you can have
a whole bunch of VMS on the same

768
00:40:59,880 --> 00:41:03,000
network segment that can't 
actually talk to each other 

769
00:41:03,000 --> 00:41:06,080
without or can you can really 
limit how they talk to each 

770
00:41:06,080 --> 00:41:08,120
other. 
And so that's really kind of 

771
00:41:08,120 --> 00:41:11,360
glorious when it comes to the 
term is lateral movement. 

772
00:41:11,600 --> 00:41:14,200
You get an attacker that breaks 
in, maybe they come into a 

773
00:41:14,200 --> 00:41:17,480
workload somewhere, something 
that hasn't been patched. 

774
00:41:17,480 --> 00:41:19,240
You know, when we've been 
talking about patching, we've 

775
00:41:19,240 --> 00:41:22,640
kind of been VCF centric, but 
workloads are all going to have 

776
00:41:22,640 --> 00:41:25,760
the same problems with AI and 
patching and patching volume and

777
00:41:25,760 --> 00:41:30,800
that, you know, so somebody 
comes in through a workload and 

778
00:41:30,800 --> 00:41:33,680
then they start poking around 
and but if you've got V defend 

779
00:41:33,680 --> 00:41:37,520
on there and you've got it 
locked down, they can't do much,

780
00:41:37,520 --> 00:41:40,680
they can't see much. 
And you start tripping alarms, 

781
00:41:40,680 --> 00:41:44,000
you know, like V defend, you put
a logging rule in there saying, 

782
00:41:44,000 --> 00:41:46,480
Hey, I want to see an alert if 
somebody tries, if one of these 

783
00:41:46,480 --> 00:41:49,520
VMS starts doing something 
unexpected, you know, and you 

784
00:41:49,520 --> 00:41:52,400
catch stuff really quick. 
And actually V defend has got 

785
00:41:52,400 --> 00:41:55,760
this whole network threat 
detection automated capability. 

786
00:41:55,760 --> 00:41:58,760
So when it sees this stuff, you 
know, and again, it's behavior, 

787
00:41:58,800 --> 00:42:03,480
well, it's behavior based the 
going back to the AI thing 

788
00:42:03,480 --> 00:42:06,800
where, where people are AI is 
able to let an attacker 

789
00:42:06,800 --> 00:42:10,360
customize an attack. 
Well, you know, now we don't we 

790
00:42:10,360 --> 00:42:11,800
can't do the signature thing 
anymore. 

791
00:42:11,800 --> 00:42:16,440
And so things that things that 
are based on signatures and the 

792
00:42:16,800 --> 00:42:21,360
and use detect things based on 
things we've seen before, we 

793
00:42:21,360 --> 00:42:23,440
can't use those anymore. 
Those are going out of date. 

794
00:42:23,760 --> 00:42:26,840
But you know, V Defend says, 
hey, this is behavior that 

795
00:42:26,880 --> 00:42:29,160
shouldn't be happening. 
I've never seen this before. 

796
00:42:29,160 --> 00:42:31,960
It's not right. 
Locks it down, you know, and 

797
00:42:31,960 --> 00:42:35,080
that's the way it needs to be. 
We need to lean into the 

798
00:42:35,080 --> 00:42:38,400
automation stuff because it's 
better to frankly, it's my 

799
00:42:38,400 --> 00:42:40,120
opinion, you know, and 
everyone's got a different 

800
00:42:40,120 --> 00:42:43,400
opinion about this, but it'd be 
better to lock it down and maybe

801
00:42:43,400 --> 00:42:48,240
have a false positive then let a
breach happen, you know, let an 

802
00:42:48,240 --> 00:42:51,160
incident continue to, to fester 
in there. 

803
00:42:51,160 --> 00:42:53,720
And so, yeah, V defend a great 
set of tools. 

804
00:42:54,080 --> 00:42:57,320
It's in fact, I'm right after 
this call, I'm going to install 

805
00:42:57,320 --> 00:43:00,080
it in my lab environment and see
what's new in there for 9.1. 

806
00:43:00,080 --> 00:43:02,080
They've made a bunch of 
improvements, too. 

807
00:43:02,240 --> 00:43:06,840
Yeah, I, I saw a session by 
Chris McCain that Viva Connect, 

808
00:43:06,840 --> 00:43:09,080
and I was surprised about what 
it could actually do it, 

809
00:43:09,080 --> 00:43:12,120
especially ATP, as you mentioned
it, it's got a lot of really 

810
00:43:12,120 --> 00:43:13,360
cool functionality. 
I was. 

811
00:43:13,400 --> 00:43:15,360
I was actually shocked, to be 
honest, because I didn't even 

812
00:43:15,360 --> 00:43:17,320
know about all the stuff that it
could. 

813
00:43:17,320 --> 00:43:20,000
Do Chris's talk about how it 
stops Brickstorm with like 3 

814
00:43:20,000 --> 00:43:21,400
rules? 
Yeah, exactly. 

815
00:43:21,440 --> 00:43:25,520
And yeah, Chris is a great 
presenter and that talk that he 

816
00:43:25,520 --> 00:43:28,240
gives is really powerful because
yeah, Brickstorm. 

817
00:43:28,240 --> 00:43:29,520
Everyone's worried about 
Brickstorm. 

818
00:43:29,680 --> 00:43:32,080
Yeah, it's something like 3 
rules in Vdefend. 

819
00:43:32,440 --> 00:43:35,920
And The thing is, it's, it's 
flexible too, you know, And so 

820
00:43:36,160 --> 00:43:39,200
when you go in an organization, 
so security and flexibility 

821
00:43:39,200 --> 00:43:43,440
don't usually go together in 
organizations, but you can, you 

822
00:43:43,440 --> 00:43:46,720
know, and so Vdefend, you can 
set up all these very granular 

823
00:43:46,720 --> 00:43:48,360
rules. 
It can learn about your 

824
00:43:48,360 --> 00:43:50,360
environment too, if you wanted 
to do that. 

825
00:43:50,360 --> 00:43:53,520
The peril and Chris will talk 
about the peril there is if 

826
00:43:53,520 --> 00:43:56,200
you've got an attacker in there 
already, it'll learn, it'll 

827
00:43:56,200 --> 00:43:58,440
learn about the attack and think
that's normal. 

828
00:43:58,880 --> 00:44:02,200
But aside from that, you know, 
you can learn about what's going

829
00:44:02,200 --> 00:44:04,480
on in your environment and then 
turn it on in stages. 

830
00:44:04,640 --> 00:44:08,280
They've got a whole plan of like
A1234 sort of plan for deploying

831
00:44:08,280 --> 00:44:10,200
it. 
And it's, it's cool, you know, 

832
00:44:10,200 --> 00:44:12,920
and it's, but it's very flexible
if you decide that you want to 

833
00:44:12,920 --> 00:44:15,520
do something different, if you 
block something you don't need 

834
00:44:15,520 --> 00:44:19,360
to open, you know, it's not a 
big pain to go and fix it. 

835
00:44:19,400 --> 00:44:22,320
You know you can have really 
great security and then be able 

836
00:44:22,320 --> 00:44:23,840
to change it when you need to 
so. 

837
00:44:24,080 --> 00:44:27,280
Yeah, I mean, if you attend VMA 
Connect or if you're going to 

838
00:44:27,280 --> 00:44:30,040
VMA VMA Explore, then make sure 
to attend Chris's session 

839
00:44:30,040 --> 00:44:32,560
because I'm pretty sure he's 
going to go through that demo 

840
00:44:32,560 --> 00:44:34,200
again. 
I think it was fantastic. 

841
00:44:34,200 --> 00:44:38,080
Now, you already mentioned that 
security is not normally very 

842
00:44:38,080 --> 00:44:41,040
flexible, or at least some of 
the solutions may not be 

843
00:44:41,040 --> 00:44:43,520
flexible. 
I tend to think about security 

844
00:44:43,520 --> 00:44:45,840
people as very black and white 
in general as well. 

845
00:44:45,840 --> 00:44:49,680
And we have a document which 
also feels very black and white,

846
00:44:49,680 --> 00:44:52,200
which is the hardening guide. 
At least people treat it as very

847
00:44:52,200 --> 00:44:54,520
black and white. 
Now, I know you've been 

848
00:44:55,160 --> 00:44:57,880
responsible for this for ages. 
Back in the day, of course, it 

849
00:44:57,880 --> 00:45:01,400
was the infamous Mike Foley that
started the whole thing. 

850
00:45:01,400 --> 00:45:03,360
But maybe you could talk us 
through what that thing is and 

851
00:45:03,360 --> 00:45:05,000
how people should actually treat
the document. 

852
00:45:05,000 --> 00:45:07,840
Because I've seen customers 
making, you know, horrible 

853
00:45:07,840 --> 00:45:11,160
mistakes using the document. 
So maybe you can shine a light 

854
00:45:11,160 --> 00:45:14,040
on it. 
So yes, I'm to blame for the 

855
00:45:14,040 --> 00:45:17,760
security configuration guide at 
the, I'm the curator of it. 

856
00:45:18,480 --> 00:45:22,680
There's a number of us that we 
take input from and I work with 

857
00:45:22,680 --> 00:45:25,880
the disastig guys. 
We basically trade information 

858
00:45:25,880 --> 00:45:28,480
and, and security controls and 
things like that. 

859
00:45:28,480 --> 00:45:30,760
We really want all of the 
hardening guidance to be as 

860
00:45:30,760 --> 00:45:36,360
close to each other as possible,
you know, but it's there's a 

861
00:45:36,360 --> 00:45:39,600
reason that the GitHub 
repository is called guidelines,

862
00:45:39,600 --> 00:45:43,640
Duncan guidelines, you know, not
straight jackets guidelines, you

863
00:45:43,640 --> 00:45:47,600
know, and you, so you don't 
like, you don't like something 

864
00:45:47,600 --> 00:45:50,760
we have in there. 
So imagine, I'll take a step 

865
00:45:50,760 --> 00:45:53,200
back. 
Imagine somebody walks up to you

866
00:45:53,200 --> 00:45:57,720
and says, I want to, I want all 
of the security to be turned on 

867
00:45:58,040 --> 00:45:59,880
in the products. 
What do I need to do? 

868
00:45:59,880 --> 00:46:02,600
Well, that the answer is in the 
security configuration guide, 

869
00:46:02,600 --> 00:46:05,160
the hardening guidance, you 
know, do you have to do all of 

870
00:46:05,160 --> 00:46:06,640
it? 
No. 

871
00:46:06,920 --> 00:46:08,520
If you do all of it, will things
break? 

872
00:46:08,600 --> 00:46:11,240
Yes. 
You know, and we've got a nice 

873
00:46:11,240 --> 00:46:14,640
discussion column. 
In fact, I'm having an AI model 

874
00:46:14,800 --> 00:46:18,280
help me audit it to make sure 
that we the discussion and the 

875
00:46:18,280 --> 00:46:22,400
impact and all that stuff is I 
like AI for being in a good, 

876
00:46:22,400 --> 00:46:26,080
it's a good editor human. 
I still like writing my writing 

877
00:46:26,080 --> 00:46:29,280
stuff myself, but going through 
all of the stuff and making sure

878
00:46:29,280 --> 00:46:33,000
that we have good explanations 
of what, what, what stuff is. 

879
00:46:33,000 --> 00:46:35,320
I like having an editor. 
And so we're going through all 

880
00:46:35,320 --> 00:46:36,960
that stuff for 9, not one right 
now. 

881
00:46:37,080 --> 00:46:40,400
So security guidance always 
follows a release by about 30 

882
00:46:40,400 --> 00:46:43,480
days because I, I want to 
actually test it against the 

883
00:46:43,480 --> 00:46:45,760
released product. 
You know, people are going to 

884
00:46:45,760 --> 00:46:47,920
take the stuff, like you said, 
they're going to use it as the 

885
00:46:47,920 --> 00:46:52,040
gospel as far as security. 
And I, I'm with you. 

886
00:46:52,080 --> 00:46:57,160
They we need to be careful about
that, but you know, making sure 

887
00:46:57,160 --> 00:46:59,320
that people understand the 
ramifications of what they're 

888
00:46:59,320 --> 00:47:02,400
going to turn on. 
So like a good example of that 

889
00:47:02,400 --> 00:47:06,920
is in the guest operating 
system, you can turn off all 

890
00:47:06,920 --> 00:47:09,800
guest operations. 
You can say, hey, the hypervisor

891
00:47:09,800 --> 00:47:15,360
doesn't get to, to do any sort 
of operations in the VM anymore.

892
00:47:15,600 --> 00:47:18,280
You know, the VM Ware tools 
through VM Ware tools. 

893
00:47:18,280 --> 00:47:20,680
The VM Ware tools will still 
wrote report out state and 

894
00:47:20,680 --> 00:47:22,760
things like that. 
But you can't run scripts and 

895
00:47:22,760 --> 00:47:24,560
all that stuff. 
It's all authenticated anyhow, 

896
00:47:24,760 --> 00:47:27,480
but you can shut all that stuff 
off and that's great. 

897
00:47:27,760 --> 00:47:31,520
But when you go to restore AVM, 
you're maybe you're using the 

898
00:47:31,520 --> 00:47:36,640
protection and recovery tool set
that's an add on for VCF. 

899
00:47:36,680 --> 00:47:40,160
You can when you go to restore 
that stuff, it wants to run 

900
00:47:40,160 --> 00:47:45,200
tools, it wants to run scripts 
so that it can re IP VMS, it can

901
00:47:45,200 --> 00:47:47,320
do all kinds of stuff. 
And people go, hey, wait a 

902
00:47:47,320 --> 00:47:51,000
second, you know, it's failing. 
You know, well, you've hardened.

903
00:47:51,000 --> 00:47:52,640
There is such a thing as too 
much security. 

904
00:47:53,000 --> 00:47:54,720
And so where's the balance 
there? 

905
00:47:55,040 --> 00:47:57,960
You know? 
And so that's that's important. 

906
00:47:57,960 --> 00:48:01,680
And I don't know, Duncan, were 
you ever a Star Trek like a Star

907
00:48:01,680 --> 00:48:05,320
Trek The Next Generation fan? 
I was more into Star Wars to be 

908
00:48:05,320 --> 00:48:08,520
honest, as you can see behind me
with all the Lego Star Wars 

909
00:48:08,520 --> 00:48:10,520
stuff. 
Oh, yeah, good, good point. 

910
00:48:10,520 --> 00:48:12,200
Sorry, I should look up a little
bit. 

911
00:48:12,200 --> 00:48:17,320
The for Star Trek fans, there 
was an episode where Lieutenant 

912
00:48:17,320 --> 00:48:20,840
Commander Data, they use the 
Android and he sort of had an 

913
00:48:20,840 --> 00:48:23,240
ego that he's always smarter 
than everyone else and better 

914
00:48:23,240 --> 00:48:26,600
than everyone else. 
Some other alien challenges him 

915
00:48:26,600 --> 00:48:30,680
to some game stratagema is what 
it's called and and the alien 

916
00:48:30,680 --> 00:48:34,800
beats Data and data is like, how
does how is this possible? 

917
00:48:34,800 --> 00:48:38,280
You know, like and he goes the 
whole episode, he goes around 

918
00:48:38,280 --> 00:48:41,400
sulking basically, and the 
captain eventually tells him 

919
00:48:41,400 --> 00:48:45,000
that, hey data, you can do 
everything sometimes in life, 

920
00:48:45,000 --> 00:48:47,920
you can do everything right and 
still lose. 

921
00:48:48,240 --> 00:48:50,520
You know, and that's how I feel 
about the hardening guidance. 

922
00:48:50,800 --> 00:48:54,000
You can do everything in that 
list and an attacker still 

923
00:48:54,000 --> 00:48:56,920
steals your administrator 
credentials from a desktop 

924
00:48:56,920 --> 00:48:59,720
somewhere else in the 
organization and breaks in, you 

925
00:48:59,720 --> 00:49:02,280
know, that sort of thing. 
So you can do, is it good to do 

926
00:49:02,280 --> 00:49:05,400
all the hardening stuff? 
Yeah, But you need to do design 

927
00:49:05,400 --> 00:49:07,880
work too. 
You need to add the boundaries, 

928
00:49:07,880 --> 00:49:10,960
you need to do the logging, you 
need to check the logs, all that

929
00:49:10,960 --> 00:49:13,360
stuff you know, and that's all 
really important. 

930
00:49:14,200 --> 00:49:17,040
Yeah, and that's also one of the
reasons I also invited Velina to

931
00:49:17,040 --> 00:49:19,800
the show to talk about the the 
ransomware recovery solution. 

932
00:49:19,800 --> 00:49:22,000
So that's going to be two 
episodes from now because I 

933
00:49:22,000 --> 00:49:25,200
think that the the the 
combination of the hardening 

934
00:49:25,200 --> 00:49:31,400
guides, things like V defense, 
ADP, the the EDR integration 

935
00:49:31,400 --> 00:49:34,800
with VCF file integrity 
monitoring, I think we finally 

936
00:49:34,800 --> 00:49:38,080
got an end to end solution. 
Now, before I let you go, Bob, 

937
00:49:38,600 --> 00:49:41,720
any famous last words or any 
final thoughts who you would 

938
00:49:41,720 --> 00:49:43,720
like to share with the audience?
Because we've probably, you 

939
00:49:43,720 --> 00:49:45,960
know, close to 45 minutes, 15 
minutes or so. 

940
00:49:45,960 --> 00:49:48,360
And I know I need to get you 
back on to talk about the native

941
00:49:48,360 --> 00:49:50,800
key provider because that's one.
Yeah, we should talk about 

942
00:49:50,800 --> 00:49:52,960
encryption. 
Yeah, that's one big ticket item

943
00:49:52,960 --> 00:49:55,000
that a lot of customers want to 
talk about, so we'll do a 

944
00:49:55,000 --> 00:49:57,920
separate episode on that. 
But any final thoughts or any 

945
00:49:58,440 --> 00:50:00,280
famous last words you have for 
the audience? 

946
00:50:00,520 --> 00:50:02,880
Don't freak out in all of the 
security. 

947
00:50:02,880 --> 00:50:06,960
There's always people that are, 
you know, you see social media, 

948
00:50:07,360 --> 00:50:09,720
all these people that are 
talking about AI and all that 

949
00:50:09,720 --> 00:50:14,720
stuff is AIA threat. 
Absolutely, you know, but you 

950
00:50:14,720 --> 00:50:17,760
know, good design, all that 
stuff, you know, you need to be 

951
00:50:17,760 --> 00:50:21,640
thinking about this stuff, but 
have a plan, you know, and don't

952
00:50:21,640 --> 00:50:25,320
freak out. 
Read, read a whole bunch of 

953
00:50:25,320 --> 00:50:26,520
stuff. 
There's a lot of good material 

954
00:50:26,520 --> 00:50:31,400
coming out about AI, the AI 
threats, defending yourself, all

955
00:50:31,400 --> 00:50:32,600
of the stuff I've been talking 
about. 

956
00:50:33,320 --> 00:50:36,160
There's a lot of material like 
that just throughout the entire 

957
00:50:36,160 --> 00:50:38,440
come in the information security
community. 

958
00:50:39,280 --> 00:50:43,640
And so, you know, act, get 
yourself in a position to act 

959
00:50:43,640 --> 00:50:46,520
quickly. 
But yeah, you know, keep your 

960
00:50:46,520 --> 00:50:47,720
head about you. 
And that's it. 

961
00:50:47,920 --> 00:50:50,280
Thanks for tuning in to the 
Unexplored Territory podcast. 

962
00:50:50,480 --> 00:50:53,000
If you enjoyed this episode, 
don't forget to scribe and leave

963
00:50:53,000 --> 00:50:54,440
a reviewer rating wherever 
possible. 

964
00:50:54,440 --> 00:50:57,080
And please join us again next 
time as we cover more insights 

965
00:50:57,080 --> 00:50:59,160
into cutting edge solutions 
shaping the world of IT. 

966
00:50:59,680 --> 00:51:02,120
Until then, staying comfortable,
keep exploring.

