1
00:00:11,960 --> 00:00:16,920
Welcome to the Decipher podcast.
It's a week lens where we had a 

2
00:00:16,920 --> 00:00:20,640
name vulnerability which we it's
been a while since we've had one

3
00:00:20,640 --> 00:00:22,560
of those. 
Always fun. 

4
00:00:22,960 --> 00:00:26,120
Yeah, especially around the 
holidays, it's a good time to to

5
00:00:26,120 --> 00:00:30,800
get a like, you know, log for J 
or something like that over 

6
00:00:30,800 --> 00:00:34,520
Thanksgiving weekend here in the
US, it's perfect time to to drop

7
00:00:34,520 --> 00:00:38,160
a really serious bug I. 
Know that's that's always fun to

8
00:00:38,200 --> 00:00:41,680
see. 
Was it react for shell or react 

9
00:00:41,680 --> 00:00:43,200
to shell? 
I've seen both. 

10
00:00:43,440 --> 00:00:44,440
I've seen. 
Yeah. 

11
00:00:45,360 --> 00:00:48,080
So we have two names for the 
same bug, which also happens 

12
00:00:48,080 --> 00:00:51,800
quite often depending on who 
names them and things. 

13
00:00:51,800 --> 00:00:55,480
It's getting to be like the 
threat actor naming conventions 

14
00:00:55,480 --> 00:00:59,520
where you're like, you need one 
of those like Always Sunny in 

15
00:00:59,520 --> 00:01:03,080
Philadelphia, like cork boards 
with like the strings and like, 

16
00:01:03,200 --> 00:01:05,480
how does this connect to that? 
I mean, we can get into that 

17
00:01:05,480 --> 00:01:07,240
later on. 
Who's exploiting this bug? 

18
00:01:07,240 --> 00:01:11,440
But at least this it's only two 
things and you can kind of you 

19
00:01:11,440 --> 00:01:14,600
get what the idea is. 
Yeah, yeah, it is. 

20
00:01:14,800 --> 00:01:16,720
It is always funny. 
I feel like, you know, the 

21
00:01:16,720 --> 00:01:20,200
researchers will come out and 
they'll be like, I dubbed this 

22
00:01:20,200 --> 00:01:23,800
like, you know, log for shell. 
Right. 

23
00:01:24,120 --> 00:01:26,680
It's like a, a nighting ceremony
or something. 

24
00:01:26,680 --> 00:01:29,520
I dub the React for shell. 
Yeah, got it. 

25
00:01:30,360 --> 00:01:33,480
Yeah. 
So I by this point, I'm sure 

26
00:01:33,480 --> 00:01:35,560
everybody is aware of the bug 
we're talking about. 

27
00:01:35,560 --> 00:01:40,480
It's a, you know, 10 out of 10 
unauthoricated remote code 

28
00:01:40,480 --> 00:01:45,560
execution bug in React to React 
framework or React library and 

29
00:01:45,560 --> 00:01:50,560
the Node library, which are, you
know, extremely popular 

30
00:01:50,560 --> 00:01:55,880
JavaScript libraries. 
And the initial disclosure to 

31
00:01:56,040 --> 00:02:01,240
the developers was on November 
29th, which is over the weekend 

32
00:02:01,240 --> 00:02:06,680
here. 
And the public disclosure I 

33
00:02:06,680 --> 00:02:11,360
believe happened on Wednesday, 
so or excuse me, December 3rd. 

34
00:02:11,720 --> 00:02:14,720
So a few days, but very quick 
turn around between initial 

35
00:02:14,720 --> 00:02:17,840
disclosure and public disclosure
and fixed versions and all that 

36
00:02:17,840 --> 00:02:22,840
kind of thing. 
But the bug itself is obviously 

37
00:02:22,840 --> 00:02:28,000
very serious and the two 
vulnerable libraries are 

38
00:02:28,000 --> 00:02:30,840
extremely widely deployed. 
These things are everywhere, 

39
00:02:30,840 --> 00:02:34,400
especially React. 
You know, it's in like 40 or 50%

40
00:02:34,560 --> 00:02:36,920
of apps. 
It's it's all over the place. 

41
00:02:37,480 --> 00:02:42,000
And we were just talking before 
we started recording, I was 

42
00:02:42,000 --> 00:02:46,680
looking at some of the stats on 
how many people have updated so 

43
00:02:46,680 --> 00:02:50,920
far and they're not good. 
It's the, the numbers are very 

44
00:02:50,920 --> 00:02:52,400
low. 
The percentage of people that 

45
00:02:52,400 --> 00:02:57,520
have been able to to update the 
their apps to fix versions of 

46
00:02:57,520 --> 00:03:02,000
the library is not great right 
now, which you know, after 48 

47
00:03:02,000 --> 00:03:06,640
hours isn't shocking. 
But given the nature of this bug

48
00:03:06,640 --> 00:03:12,560
and how many serious level 
headed researchers in threaten 

49
00:03:12,560 --> 00:03:16,560
tell people we've seen saying, 
hey, hey, hey, this is not a 

50
00:03:16,560 --> 00:03:21,040
drill. 
Go fix this like right now you I

51
00:03:21,040 --> 00:03:24,040
would expect a little more 
urgency from folks. 

52
00:03:24,040 --> 00:03:28,680
But it might also be the case 
where these libraries are in 

53
00:03:28,680 --> 00:03:31,360
places that are not easy, easy 
to update to. 

54
00:03:31,480 --> 00:03:34,080
You know some of these apps you 
might not be able to update 

55
00:03:35,520 --> 00:03:38,400
right away. 
Yeah, that's kind of what I was 

56
00:03:38,600 --> 00:03:40,560
gonna. 
What I was thinking is kind of 

57
00:03:40,560 --> 00:03:44,600
the the rollout of patches is 
going to be a little bit slower,

58
00:03:44,600 --> 00:03:47,320
I'd imagine because of that 
reason you just mentioned. 

59
00:03:48,440 --> 00:03:51,960
And this one's tough too, 
because we're, you know, Amazon 

60
00:03:52,320 --> 00:03:56,000
also came out and has said and a
few other researchers that, you 

61
00:03:56,000 --> 00:03:58,560
know, at this point, obviously 
threat actors are trying to 

62
00:03:58,560 --> 00:04:01,240
exploit this. 
And it's it's, you know, fairly 

63
00:04:01,240 --> 00:04:03,520
easily exploitable for the most 
part. 

64
00:04:03,920 --> 00:04:07,800
So I mean, this is one of those 
ones where the pace at which 

65
00:04:07,800 --> 00:04:10,520
threat actors are moving is 
going to be a lot faster than, 

66
00:04:10,960 --> 00:04:14,440
you know, the time it takes for 
organizations to, A, become 

67
00:04:14,440 --> 00:04:20,200
aware of this honestly. 
B be able to kind of find and 

68
00:04:20,200 --> 00:04:23,080
understand where this fits into 
their own internal environments 

69
00:04:23,080 --> 00:04:25,520
and then see actually, you know,
roll out the patch. 

70
00:04:26,440 --> 00:04:29,120
So I think it's just one of 
those tricky situations. 

71
00:04:29,120 --> 00:04:32,160
And then of course, you've got 
all these fake PO CS flying 

72
00:04:32,160 --> 00:04:34,240
around Twitter. 
Got to love that. 

73
00:04:35,080 --> 00:04:39,240
I yeah, that's such a weird 
phenomenon to me. 

74
00:04:39,640 --> 00:04:45,400
Like I, it's a, it's like a 
childish thing of like, hey, I 

75
00:04:45,400 --> 00:04:47,360
was there first. 
Look what I did. 

76
00:04:47,600 --> 00:04:50,920
But then I mean, some of them in
past cases have turned out to be

77
00:04:50,920 --> 00:04:53,080
malicious, like they're 
essentially like malware loaders

78
00:04:53,080 --> 00:04:55,440
or something. 
But I think in some of these 

79
00:04:55,440 --> 00:04:58,120
cases, it's just like people 
thought they had PO CS and 

80
00:04:58,120 --> 00:05:02,000
they're not. 
But like the guy that disclosed 

81
00:05:02,000 --> 00:05:06,440
the bug has a thing on his site 
like saying look we've seen a 

82
00:05:06,440 --> 00:05:13,360
bunch of fake or invalid PO CS 
and it's such a weird thing. 

83
00:05:13,360 --> 00:05:16,360
Like I don't, I don't really 
understand what the point of 

84
00:05:16,360 --> 00:05:20,120
that is. 
Yeah, I think it is like to your

85
00:05:20,120 --> 00:05:23,880
point, it's partially like in my
in my personal opinion like 

86
00:05:23,960 --> 00:05:29,480
probably for clout a little bit.
And then also there's not really

87
00:05:29,680 --> 00:05:34,320
I, I wish there was more of a 
discussion around the exposure 

88
00:05:34,320 --> 00:05:37,640
or disclosure, I guess of PO CS 
in the security industry. 

89
00:05:37,640 --> 00:05:41,400
Like I think there's, it's, it's
something that needs to be done 

90
00:05:41,440 --> 00:05:44,320
responsibly. 
And like, you know, obviously 

91
00:05:44,560 --> 00:05:49,200
UCS have played a valuable part 
in kind of vulnerability 

92
00:05:49,200 --> 00:05:51,000
disclosure and management and 
all that. 

93
00:05:51,000 --> 00:05:54,960
But then there's also a tricky 
situation in times like these. 

94
00:05:54,960 --> 00:05:59,000
I mean, it's definitely an 
interesting topic. 

95
00:05:59,560 --> 00:06:02,320
And then when you have these 
fake ones, it's just like you're

96
00:06:02,320 --> 00:06:06,600
sending research, you know, 
basically like security teams 

97
00:06:06,600 --> 00:06:10,400
down, down the wrong rabbit hole
and taking valuable time away 

98
00:06:10,400 --> 00:06:12,760
when they're already at a time 
crunch for something important 

99
00:06:12,760 --> 00:06:17,680
like this. 
Yeah, it's a weird thing because

100
00:06:17,680 --> 00:06:21,440
sometimes like the thing that 
you just described is like 

101
00:06:21,880 --> 00:06:24,600
sending security teams down the 
wrong path or something like 

102
00:06:24,600 --> 00:06:27,480
that. 
This the researcher who 

103
00:06:27,480 --> 00:06:30,760
disclosed the vulnerability, 
whose name is Lachlan Davidson, 

104
00:06:31,160 --> 00:06:35,440
I hope I'm pronouncing Lachlan 
correctly said that some of the 

105
00:06:35,440 --> 00:06:38,640
PO CS are, you know, would 
likely produce false negatives. 

106
00:06:38,640 --> 00:06:42,280
So if you're running the POC and
it says, oh, you know, it 

107
00:06:42,280 --> 00:06:46,040
doesn't work against your app or
your, your endpoint or something

108
00:06:46,360 --> 00:06:48,400
be like, OK, cool, we're, we're 
good. 

109
00:06:48,760 --> 00:06:51,760
But some of them aren't aren't, 
you know, valid. 

110
00:06:51,880 --> 00:06:54,760
They're they're looking at the 
wrong thing or testing the wrong

111
00:06:54,760 --> 00:06:57,600
thing. 
So you might have a, you know, a

112
00:06:57,600 --> 00:07:00,600
false negative, which is in this
case much more dangerous than a 

113
00:07:00,600 --> 00:07:05,960
false positive. 
Yeah, yeah, My conspiracy self 

114
00:07:06,000 --> 00:07:09,360
wonders if, you know, maybe 
threat actors are like launching

115
00:07:09,360 --> 00:07:12,280
some sort of POC disinformation 
campaign or if that's something 

116
00:07:12,280 --> 00:07:14,760
they're going to be doing in the
future if they're not already 

117
00:07:14,760 --> 00:07:16,160
so. 
I love this. 

118
00:07:16,160 --> 00:07:18,840
You've been hanging out with me 
and donning you too much for 

119
00:07:18,840 --> 00:07:21,240
these conspiracy theories. 
I like it. 

120
00:07:21,560 --> 00:07:25,080
I know. 
Yeah, it's so the bug itself is 

121
00:07:25,080 --> 00:07:30,080
obviously very dangerous. 
And almost immediately, as you 

122
00:07:30,080 --> 00:07:33,160
mentioned, Amazon's threat Intel
team came out with a blog 

123
00:07:33,560 --> 00:07:38,840
describing exploitation activity
from some China aligned threat 

124
00:07:38,840 --> 00:07:43,680
groups. 
And I have to say we the threat 

125
00:07:43,680 --> 00:07:46,280
actor naming conventions, we 
could do an entire podcast on 

126
00:07:46,280 --> 00:07:51,240
that whole thing. 
But the ones in Amazon's blog 

127
00:07:51,240 --> 00:07:54,800
post, which came out yesterday, 
I believe two of the, I don't 

128
00:07:54,800 --> 00:07:59,800
know what these are Earth Lamia,
LAMIA, don't know what that is, 

129
00:07:59,840 --> 00:08:02,760
never seen it. 
And Jackpot Panda. 

130
00:08:04,240 --> 00:08:05,960
Jackpot Panda, I kind of enjoy 
that name. 

131
00:08:05,960 --> 00:08:10,480
The other one, I don't know what
the hell that is, but two 

132
00:08:10,880 --> 00:08:13,920
Chinese aligned threat groups 
already out there exploiting 

133
00:08:13,920 --> 00:08:16,720
this. 
I'm sure there's more, I'm sure 

134
00:08:16,720 --> 00:08:21,920
there's individual actors doing 
this, but the Chinese threat 

135
00:08:21,920 --> 00:08:27,640
actors are almost always the 
quickest and you know, a lot of 

136
00:08:27,640 --> 00:08:29,840
times most successful when 
they're jumping on things like 

137
00:08:29,840 --> 00:08:31,640
this. 
They have a lot of resources at 

138
00:08:31,640 --> 00:08:36,200
their disposal and they will 
sometimes pull those resources 

139
00:08:36,240 --> 00:08:40,919
even among, you know, state 
backed ACT, state backed actors 

140
00:08:41,280 --> 00:08:45,240
and contractors and that sort of
thing just to get a jump on 

141
00:08:45,240 --> 00:08:47,120
these. 
And that seems to be what we're 

142
00:08:47,120 --> 00:08:50,840
seeing right now. 
Yeah, it's, I think it's really 

143
00:08:50,840 --> 00:08:54,000
interesting just the operational
alignment for a lot of these 

144
00:08:54,000 --> 00:08:58,800
Chinese, you know, threat groups
versus when you look at that 

145
00:08:58,800 --> 00:09:02,560
stacked up to where we're at on 
the defense side for something 

146
00:09:02,560 --> 00:09:05,480
like this, which is still even 
just in the beginning of the 

147
00:09:05,480 --> 00:09:09,680
roll out of the patches. 
So it's, it's definitely a 

148
00:09:09,680 --> 00:09:13,320
bigger overarching issue that we
deal with when we, when it comes

149
00:09:13,320 --> 00:09:16,800
to kind of more widespread 
vulnerabilities like this. 

150
00:09:17,320 --> 00:09:21,760
You know, there's a little bit 
of a lag, I guess behind how, 

151
00:09:21,920 --> 00:09:24,440
how easily threat actors are 
able to jump on this. 

152
00:09:24,960 --> 00:09:32,240
Yeah, this bug has brought up a 
sort of one of the things that I

153
00:09:32,240 --> 00:09:35,160
think we've written about and 
talked about for many years. 

154
00:09:35,200 --> 00:09:37,440
And lots of people in the 
security community have talked 

155
00:09:37,440 --> 00:09:42,840
about too, which is the value. 
Value is not the right word, but

156
00:09:44,840 --> 00:09:47,600
patching something like this, 
you know, going through a fire 

157
00:09:47,600 --> 00:09:51,360
drill like this when something 
very serious gets disclosed 

158
00:09:52,080 --> 00:09:56,240
versus a comprehensive security 
program that is trying to 

159
00:09:56,240 --> 00:10:00,720
mitigate risk, you know, as a 
broader thing on a, on a 

160
00:10:01,040 --> 00:10:07,280
constant on a continuous basis, 
You know, trying to figure out 

161
00:10:07,280 --> 00:10:10,200
ways where something like this 
wouldn't even if you have 

162
00:10:10,200 --> 00:10:13,000
vulnerable apps, they wouldn't 
be reachable or things like 

163
00:10:13,000 --> 00:10:15,920
that. 
You know, the broader idea of 

164
00:10:15,920 --> 00:10:20,160
risk mitigation versus running 
through these, you know, react 

165
00:10:20,160 --> 00:10:23,560
and patch, God, no pun intended 
there. 

166
00:10:26,120 --> 00:10:30,160
That's so bad. 
These, these patching fire 

167
00:10:30,160 --> 00:10:34,600
drills all the time, which we 
see, you know, not weekly, but 

168
00:10:34,880 --> 00:10:38,040
pretty regularly, at least 
monthly on very serious bugs. 

169
00:10:38,480 --> 00:10:41,560
And that's, you know, it's an 
easy thing to tell people tell 

170
00:10:41,560 --> 00:10:44,400
organizations to go do that, But
a lot of orgs don't have the 

171
00:10:44,400 --> 00:10:46,920
money or people to do those 
things. 

172
00:10:47,400 --> 00:10:49,960
You know, it's, it's really 
tough. 

173
00:10:49,960 --> 00:10:52,400
Even, I mean, you were 
mentioning there was a 

174
00:10:52,440 --> 00:10:56,320
Cloudflare outage last night, 
which you know, isn't connected 

175
00:10:56,320 --> 00:10:59,920
to an attack, but they were, 
they were their logs were 

176
00:10:59,920 --> 00:11:03,240
essentially like overwhelmed 
because of this, which is like 

177
00:11:03,240 --> 00:11:06,280
an insane thing to think of for 
Cloudflare. 

178
00:11:07,280 --> 00:11:10,040
Right to check. 
All the resources on the planet,

179
00:11:10,360 --> 00:11:12,000
literally. 
Yeah, I know. 

180
00:11:12,040 --> 00:11:15,120
Yeah, They said that the root 
cause was disabling some logging

181
00:11:15,120 --> 00:11:17,440
to help mitigate this week's 
React CV. 

182
00:11:17,440 --> 00:11:21,400
So it's yeah. 
Yeah, if they can't, if they 

183
00:11:21,400 --> 00:11:22,880
can't do it, I don't know who 
can. 

184
00:11:23,280 --> 00:11:26,280
Yeah, I know. 
But that's I think you bring up 

185
00:11:26,280 --> 00:11:31,400
a a good point for sure. 
I think organizationally and 

186
00:11:31,400 --> 00:11:35,440
like strategically, it's really 
difficult for a lot of companies

187
00:11:35,440 --> 00:11:42,640
too, just because I mean, we saw
and maybe we saw that this seems

188
00:11:42,640 --> 00:11:45,680
like it was a little more like 
of a well known thing. 

189
00:11:45,680 --> 00:11:49,720
But like even back with a log 4J
or things like that, like even 

190
00:11:49,720 --> 00:11:52,840
being able to understand like 
you don't even know what's out 

191
00:11:52,840 --> 00:11:55,680
there in your in your 
environment for a lot of these 

192
00:11:55,920 --> 00:11:57,400
different types of 
vulnerabilities. 

193
00:11:57,400 --> 00:12:01,480
So I think, I think it's just 
tough to be able to plan ahead 

194
00:12:01,480 --> 00:12:04,880
for that a lot of times. 
I mean, if anything, I guess 

195
00:12:04,880 --> 00:12:08,080
it's planning ahead for what you
don't know and trying to best 

196
00:12:08,080 --> 00:12:10,840
prepare yourself on that front. 
Yeah, which is a really 

197
00:12:10,840 --> 00:12:14,240
difficult theoretical thing to 
do. 

198
00:12:14,920 --> 00:12:18,280
You know, the the unknown 
unknowns or whatever that phrase

199
00:12:18,280 --> 00:12:20,320
is. 
Like it's also a question of 

200
00:12:20,680 --> 00:12:25,640
resource allocation for even 
for, you know, an organization 

201
00:12:25,640 --> 00:12:30,000
with a mature security team and 
a lot of financial and human 

202
00:12:30,000 --> 00:12:31,960
assets to throw at a problem 
like this. 

203
00:12:32,800 --> 00:12:35,680
Do you throw them all at this 
problem or you probably have 

204
00:12:35,680 --> 00:12:37,960
other attacks and other things 
that you're worried about as 

205
00:12:37,960 --> 00:12:41,040
well? 
It's not all one thing, you 

206
00:12:41,040 --> 00:12:44,920
know, there's, there's always a 
variety of problems to deal 

207
00:12:44,920 --> 00:12:48,680
with. 
So you know, even a a good, 

208
00:12:48,800 --> 00:12:52,840
fast, mature security team isn't
always going to be able to react

209
00:12:52,840 --> 00:12:58,840
quickly to something like this. 
Yeah, I did see a post from 

210
00:12:59,080 --> 00:13:05,160
Kevin Beaumont that was talking 
about how basically this, the 

211
00:13:05,160 --> 00:13:09,160
flaw applies to React 19, which 
was I think he said it was 

212
00:13:09,160 --> 00:13:13,040
released in the past year. 
And then it applies when you're 

213
00:13:13,040 --> 00:13:16,600
using React server components, 
which are also fairly new. 

214
00:13:16,600 --> 00:13:21,280
So like, I wonder too, in terms 
of just the overall like when 

215
00:13:21,280 --> 00:13:24,200
we're talking about a tax 
surface and like how 

216
00:13:24,240 --> 00:13:28,640
organizations can approach this,
like maybe that might help like 

217
00:13:28,680 --> 00:13:31,680
cut back a little bit on trying 
to understand how what the 

218
00:13:31,680 --> 00:13:36,480
impact is. 
But that said, like, you know, 

219
00:13:37,240 --> 00:13:40,880
it's hard to even track those 
different types of versions and 

220
00:13:40,880 --> 00:13:43,960
all of these different types of,
you know, things and whether you

221
00:13:43,960 --> 00:13:48,240
do have kind of that React 
server components and where 

222
00:13:48,240 --> 00:13:50,080
those are so. 
Yeah, it's. 

223
00:13:50,360 --> 00:13:52,960
Kind of a mess. 
No, it's absolutely. 

224
00:13:53,440 --> 00:13:57,800
And you know, the, the Chinese 
exploitation part of this is 

225
00:13:57,800 --> 00:14:00,040
interesting. 
It's, it's kind of what you 

226
00:14:00,040 --> 00:14:02,120
would expect honestly, as we 
mentioned before. 

227
00:14:03,360 --> 00:14:06,720
And it kind of plays into a 
separate story that you wrote 

228
00:14:06,720 --> 00:14:13,440
this week on some lawmakers and 
other folks getting a little 

229
00:14:13,440 --> 00:14:17,000
worked up that maybe our telecom
networks aren't, you know, 

230
00:14:17,000 --> 00:14:20,920
completely secure, which is a 
hilarious thing to think about. 

231
00:14:20,920 --> 00:14:26,800
Like, you know, but this is like
kind of pegged to the one year 

232
00:14:26,800 --> 00:14:31,240
after the the Salt typhoon 
intrusions were exposed, you 

233
00:14:32,040 --> 00:14:34,920
know, something that was well 
known in the security community 

234
00:14:34,920 --> 00:14:38,000
beforehand, but you know, became
public about a year ago when the

235
00:14:38,000 --> 00:14:39,760
government woke up and was like,
what? 

236
00:14:40,480 --> 00:14:44,520
Wait a minute, There are there 
are foreign actors in our 

237
00:14:44,520 --> 00:14:46,680
telecom networks. 
What are you talking about You? 

238
00:14:46,680 --> 00:14:49,640
Would have known. 
Who could see it coming? 

239
00:14:50,320 --> 00:14:54,760
Yeah, that was, I remember, I 
think I covered that and maybe 

240
00:14:54,760 --> 00:14:58,640
you covered part of it too. 
But the that the reaction to 

241
00:14:58,640 --> 00:15:01,280
that was one of those ones 
where, you know, you and 

242
00:15:01,280 --> 00:15:05,600
senators like blast putting, you
know, different telecom industry

243
00:15:05,600 --> 00:15:07,120
people on blast. 
Oh yeah. 

244
00:15:07,680 --> 00:15:11,000
Things of being like, we like, 
you know, we're not going to 

245
00:15:11,000 --> 00:15:14,960
stand for this. 
And so just like as background 

246
00:15:14,960 --> 00:15:19,640
context, this was the salt 
typhoon targeting of, you know, 

247
00:15:19,640 --> 00:15:21,200
all those different telecom 
vendors. 

248
00:15:21,200 --> 00:15:24,760
I think it was like AT and TT 
mobile, like all the, you know, 

249
00:15:24,840 --> 00:15:27,520
big ones. 
And then that led to them being 

250
00:15:27,520 --> 00:15:30,840
able to access, you know, some 
communications that were related

251
00:15:30,840 --> 00:15:34,840
to government officials. 
And then also like obviously all

252
00:15:34,840 --> 00:15:40,400
the like Americans, you know, 
that different type of data too.

253
00:15:40,400 --> 00:15:46,120
So it was not great. 
And one of the things that came 

254
00:15:46,120 --> 00:15:49,160
out of that which, you know, we 
talked about this I think on the

255
00:15:49,160 --> 00:15:54,680
last podcast we did two weeks 
ago was the FCC coming out. 

256
00:15:55,440 --> 00:15:59,800
I think it was beginning of this
year, January and saying, hey, 

257
00:15:59,800 --> 00:16:02,520
we're going to start 
implementing some some new rules

258
00:16:02,520 --> 00:16:06,480
for these for communications 
infrastructure companies in 

259
00:16:06,480 --> 00:16:11,240
order to better address security
risks and be able to like 

260
00:16:11,240 --> 00:16:15,520
bolster those types of measures.
And then Fast forward to 

261
00:16:15,520 --> 00:16:20,480
November there, the FCC reversed
that ruling. 

262
00:16:20,800 --> 00:16:24,520
Yes, so. 
And what's happened between 

263
00:16:24,520 --> 00:16:26,400
January and November, Lindsay? 
Yeah, yeah. 

264
00:16:27,120 --> 00:16:27,800
What's? 
Changed. 

265
00:16:28,400 --> 00:16:34,400
So, so the so anyways, all that 
to say, that was like one of the

266
00:16:34,480 --> 00:16:39,200
the big points of discussion 
during this hearing that I 

267
00:16:39,200 --> 00:16:42,040
listened it on earlier this week
on Tuesday. 

268
00:16:42,040 --> 00:16:46,000
It was basically kind of a 
culmination of some government 

269
00:16:46,000 --> 00:16:50,320
officials and then also some 
private sector folks, which, you

270
00:16:50,320 --> 00:16:54,880
know, I always like that because
it's, it's good to hear out of 

271
00:16:54,880 --> 00:16:58,480
their own, you know, mouths like
how a private sector is like 

272
00:16:58,480 --> 00:17:01,960
dealing with this, like what 
their, what their opinions are 

273
00:17:01,960 --> 00:17:05,280
on it. 
So we got to hear from a couple 

274
00:17:05,280 --> 00:17:09,359
of different people that were 
either working at telecom 

275
00:17:09,359 --> 00:17:14,800
companies or who were part of 
kind of an alliance that was, 

276
00:17:14,839 --> 00:17:16,760
you know, supporting that 
industry. 

277
00:17:18,720 --> 00:17:21,400
So, you know, it was 
interesting, you know, you kind 

278
00:17:21,400 --> 00:17:23,440
of got the arguments on both 
sides that you would have 

279
00:17:23,440 --> 00:17:26,079
thought and that we talked about
on the podcast last time, which 

280
00:17:26,079 --> 00:17:30,840
is, you know, on the on the pro 
side of the FCC reversal. 

281
00:17:31,160 --> 00:17:35,960
People were saying, you know, 
this is prescriptive, it's 

282
00:17:35,960 --> 00:17:38,360
ineffective. 
It doesn't hold up to the 

283
00:17:38,520 --> 00:17:42,680
environment of how like telecom 
organizations are operating 

284
00:17:42,680 --> 00:17:45,760
today. 
And then the critics were coming

285
00:17:45,760 --> 00:17:48,920
back and saying, well, now we 
don't have any sort of 

286
00:17:48,920 --> 00:17:54,360
understanding publicly of like 
how telecom companies are, you 

287
00:17:54,360 --> 00:17:58,680
know, aligning to standards set 
in place about security and how 

288
00:17:58,720 --> 00:18:00,920
we can address threats like Salt
Typhoon. 

289
00:18:01,320 --> 00:18:04,280
So it was, yeah, there was a lot
of talk around that. 

290
00:18:05,120 --> 00:18:08,680
One of the, I don't know if they
discussed this in that specific 

291
00:18:08,680 --> 00:18:10,360
hearing, they they almost always
do. 

292
00:18:10,360 --> 00:18:14,080
Somebody from the telecom side 
will will explain this, but one 

293
00:18:14,080 --> 00:18:21,040
of the big problems is the 
telecom networks, like most old 

294
00:18:21,040 --> 00:18:27,960
networks, are extremely 
heterogeneous and have extremely

295
00:18:27,960 --> 00:18:33,160
old hardware and software in 
places that they can't be 

296
00:18:34,600 --> 00:18:38,600
swapped out or, you know, 
upgraded in a lot of cases. 

297
00:18:38,600 --> 00:18:44,720
You know, some of the the stuff 
that some of the attacks that 

298
00:18:44,800 --> 00:18:48,200
that we've seen against telecom 
networks take take advantage of 

299
00:18:48,200 --> 00:18:51,240
bugs in software that people 
have never heard of because it 

300
00:18:51,240 --> 00:18:54,880
was implemented like 45 years 
ago or things like that. 

301
00:18:56,280 --> 00:18:59,920
So there's always that 
underlying issue of, OK, this is

302
00:18:59,920 --> 00:19:04,680
a really rapidly aging network. 
You know, the obviously the 

303
00:19:05,080 --> 00:19:09,160
front end of it is upgraded all 
the time with, you know, 5G and 

304
00:19:09,160 --> 00:19:11,080
all that kind of stuff that 
they're always trying to get us 

305
00:19:11,080 --> 00:19:14,840
to buy new devices for. 
But the a lot of the underlying 

306
00:19:14,840 --> 00:19:20,920
infrastructure is real old and, 
you know, not fixable in a, in 

307
00:19:21,000 --> 00:19:24,960
a, you know, broader sense. 
Yeah, I think it's really 

308
00:19:24,960 --> 00:19:30,160
important to to note that 
because it is really easy from 

309
00:19:30,240 --> 00:19:34,680
kind of the security industry 
like almost bubble to be like 

310
00:19:34,680 --> 00:19:39,040
you need to apply these, you 
know, checklist basically of 

311
00:19:39,040 --> 00:19:43,560
like different standards that 
make sense from a if, if you're 

312
00:19:43,560 --> 00:19:48,120
in a environment that maybe is 
more a standard business 

313
00:19:48,120 --> 00:19:50,520
environment. 
But like to your point, if you 

314
00:19:50,600 --> 00:19:53,800
are in like a very specialized 
critical infrastructure 

315
00:19:54,880 --> 00:19:57,360
environment, it's going to be 
very, very different. 

316
00:19:57,360 --> 00:20:00,680
And when you're dealing with 
those issues, obviously you need

317
00:20:00,680 --> 00:20:04,520
to be dealing with them and, and
being able to secure those. 

318
00:20:04,520 --> 00:20:07,440
But it's, it's going to have to 
be in a very different way than 

319
00:20:07,440 --> 00:20:10,640
kind of what what most people 
are used to within our industry 

320
00:20:10,640 --> 00:20:12,360
when they're talking about these
things. 

321
00:20:13,320 --> 00:20:17,280
And they talked about that a 
little bit in terms of the need 

322
00:20:17,280 --> 00:20:22,560
for like a meeting of like a 
better understanding of standard

323
00:20:22,560 --> 00:20:24,880
when we talk about standards and
things like that. 

324
00:20:25,840 --> 00:20:28,120
So. 
You know, I thought there was, 

325
00:20:28,200 --> 00:20:31,400
there was a lot of different 
advice that was thrown around 

326
00:20:31,400 --> 00:20:35,520
and, you know, I appreciated the
the brainstorming and like all 

327
00:20:35,520 --> 00:20:38,560
these different things. 
But there was, you know, there 

328
00:20:38,560 --> 00:20:42,240
was talk of everything from 
like, you know, all the same 

329
00:20:42,240 --> 00:20:46,520
things we've really seen people 
discuss like cultural shifts or,

330
00:20:46,640 --> 00:20:51,720
or like threat intelligence 
sharing, public private 

331
00:20:51,720 --> 00:20:53,600
collaboration, all those 
different things. 

332
00:20:54,720 --> 00:20:58,400
So you know, I personally I 
didn't walk away from the 

333
00:20:58,400 --> 00:21:04,160
meeting like fully understanding
like if there was 1 correct 

334
00:21:04,160 --> 00:21:06,720
action that like everyone 
totally agreed on. 

335
00:21:06,720 --> 00:21:08,680
I guess like maybe info sharing 
but. 

336
00:21:09,120 --> 00:21:12,960
Oh good, it's. 
Like easiest thing to do moving 

337
00:21:12,960 --> 00:21:15,720
forward. 
And I think it's just like a 

338
00:21:15,720 --> 00:21:20,440
broader recognition to your 
point is needed about like that 

339
00:21:20,720 --> 00:21:24,520
there is like a very specific 
internal environment for a lot 

340
00:21:24,520 --> 00:21:28,720
of these organizations. 
And like how do we, how do we 

341
00:21:28,720 --> 00:21:32,040
come together and like 
understand how we can kind of 

342
00:21:33,040 --> 00:21:38,560
have both security and then also
like understand that there's 

343
00:21:38,560 --> 00:21:43,840
very custom requirements that 
businesses in that industry need

344
00:21:43,840 --> 00:21:49,480
to kind of be so? 
And the other sort of related 

345
00:21:49,480 --> 00:21:53,160
part of that is these big 
telecom companies are companies.

346
00:21:53,160 --> 00:21:56,240
They're, you know, they're 
enterprises. 

347
00:21:56,240 --> 00:21:57,840
They are not government 
agencies. 

348
00:21:58,320 --> 00:22:01,720
And but the networks that they 
operate are essentially critical

349
00:22:01,720 --> 00:22:06,560
infrastructure for the nation 
and are treated as such by the 

350
00:22:06,560 --> 00:22:09,400
government. 
So they sort of have this like 

351
00:22:10,520 --> 00:22:14,840
government oversight in a lot of
ways that can be, you know, kind

352
00:22:14,840 --> 00:22:18,360
of onerous, but also in other 
ways their businesses that have 

353
00:22:18,360 --> 00:22:22,040
to run like businesses, you 
know, they have to have to turn 

354
00:22:22,040 --> 00:22:25,640
profits. 
They have to, you know, compete 

355
00:22:25,640 --> 00:22:28,760
against each other, even though 
in a lot of cases they are 

356
00:22:28,760 --> 00:22:31,840
cooperating and, you know, in 
certain ways as well. 

357
00:22:32,120 --> 00:22:36,440
So it's a weird sort of dynamic 
among the companies themselves 

358
00:22:36,440 --> 00:22:39,520
and also between the companies 
and the government because they 

359
00:22:39,520 --> 00:22:43,040
get treated like, yet you're 
part of a government agency 

360
00:22:43,040 --> 00:22:46,000
because you're, you know, 
everything you do like the 

361
00:22:46,000 --> 00:22:50,640
nation's business depends on 
these networks running, you 

362
00:22:50,640 --> 00:22:53,480
know, efficiently and being up 
all of the time. 

363
00:22:53,800 --> 00:22:56,760
If there's and, you know, a 
billionth of a percent of 

364
00:22:56,760 --> 00:23:00,440
downtime in any of these major 
telecom networks, people lose 

365
00:23:00,440 --> 00:23:05,040
their shit, you know, and it's a
it's a weird dynamic. 

366
00:23:05,040 --> 00:23:07,960
There's no real way around it. 
Like we're not going back to 

367
00:23:07,960 --> 00:23:10,760
government owned, but actually I
take that back. 

368
00:23:10,760 --> 00:23:14,160
I don't know. 
I I don't know. 

369
00:23:14,960 --> 00:23:18,840
Yeah, let's hope we're not going
back to government owned telecom

370
00:23:18,840 --> 00:23:24,120
infrastructure, but who can say?
That's a good point too. 

371
00:23:24,120 --> 00:23:26,440
And you know, we see that with a
lot of even, I mean we're 

372
00:23:26,440 --> 00:23:29,480
talking about these massive orgs
right now, but this is, this 

373
00:23:29,480 --> 00:23:32,360
applies to a lot of different 
sectors within that are 

374
00:23:32,360 --> 00:23:34,280
categorized as critical 
infrastructure. 

375
00:23:34,280 --> 00:23:37,920
And like, for instance, even 
like, you know, local water 

376
00:23:37,920 --> 00:23:41,960
utilities or things like that, 
there's a lot of pressure now 

377
00:23:42,120 --> 00:23:45,720
to, you know, now that those 
have been categorized under 

378
00:23:47,080 --> 00:23:53,320
this, this particular, you know,
sector that SISA has put it, you

379
00:23:53,320 --> 00:23:55,960
know, under something that is 
really important when it comes 

380
00:23:55,960 --> 00:23:59,000
to cybersecurity. 
There's a lot of pressure for 

381
00:23:59,000 --> 00:24:02,360
them. 
But then at the same time, it's 

382
00:24:02,360 --> 00:24:05,960
not like tit for tat, but you 
know, when you look at kind of 

383
00:24:05,960 --> 00:24:10,520
more of those local water 
utilities, like they still have 

384
00:24:10,960 --> 00:24:14,320
their own way that they need to 
get budget, which is, you know, 

385
00:24:14,400 --> 00:24:16,400
through kind of these local 
processes. 

386
00:24:16,400 --> 00:24:18,800
So it's Oh yeah. 
Interesting the different 

387
00:24:18,800 --> 00:24:20,720
dynamics there that need to go 
into play. 

388
00:24:21,240 --> 00:24:23,640
Yeah. 
And another thing, just like the

389
00:24:23,720 --> 00:24:28,120
the water utilities, these large
telecom networks are not a 

390
00:24:28,120 --> 00:24:32,360
network in the sense of like 
they're wholly, you know, 

391
00:24:33,800 --> 00:24:36,840
discreet things. 
They're built up of pieces of 

392
00:24:36,840 --> 00:24:41,360
little regional telecoms that 
were, you know, absorbed over 

393
00:24:41,360 --> 00:24:44,720
decades, you know, little 
regional like New England 

394
00:24:44,720 --> 00:24:47,480
telecoms and Midwest telecoms 
and all that kind of stuff that 

395
00:24:47,480 --> 00:24:51,560
had their own infrastructures 
and ways of doing things and 

396
00:24:51,560 --> 00:24:53,400
processes and all that kind of 
stuff. 

397
00:24:54,400 --> 00:24:55,680
And that's all happened over 
time. 

398
00:24:55,680 --> 00:25:00,080
So it's not like one thing, you 
know, the, the AT&T network is 

399
00:25:00,080 --> 00:25:03,800
not like a homogeneous thing 
that they, you know, that all 

400
00:25:03,800 --> 00:25:06,680
operates the same way. 
It's, you know, it's a weird 

401
00:25:06,680 --> 00:25:09,320
kind of Frankenstein's monster 
of things. 

402
00:25:09,800 --> 00:25:12,960
Yeah, Yeah, that's, that's a 
good point. 

403
00:25:12,960 --> 00:25:15,400
And then looking at the other 
side of the coin, when, when 

404
00:25:15,400 --> 00:25:18,680
we're talking about Salt Typhoon
and these, you know, different 

405
00:25:18,920 --> 00:25:23,360
threat actors that have been 
targeting these networks, the 

406
00:25:24,040 --> 00:25:27,040
like, the thing that I think 
could have been discussed more 

407
00:25:27,040 --> 00:25:30,240
was like just this extreme 
persistence of, of these threat 

408
00:25:30,240 --> 00:25:34,840
actors. 
You know, I don't like, I, 

409
00:25:34,960 --> 00:25:38,720
we're, we're not ready for that 
from, from the communications 

410
00:25:38,720 --> 00:25:42,920
infrastructure side of things. 
And like, I, I think that's what

411
00:25:42,920 --> 00:25:48,440
worries me most is just like 
exactly how long and like easy 

412
00:25:48,440 --> 00:25:52,960
it is for Chinese threat actors 
right now to stay in, in these 

413
00:25:52,960 --> 00:25:55,640
networks. 
I mean, they're probably in 

414
00:25:55,640 --> 00:25:57,440
there right now, so. 
Yeah. 

415
00:25:57,640 --> 00:26:03,200
I mean, yeah, we've talked about
this a million times, but the 

416
00:26:03,200 --> 00:26:06,920
thing that maybe some of these 
legislators and lawmakers and 

417
00:26:06,920 --> 00:26:09,720
regulators don't may not 
understand, some of them do. 

418
00:26:09,720 --> 00:26:13,280
But this is a job for those 
threat actors. 

419
00:26:13,320 --> 00:26:17,000
You know, many of them, 
especially the the Chinese and 

420
00:26:17,000 --> 00:26:20,240
Russian and North Korean ones 
are employed by their 

421
00:26:20,240 --> 00:26:22,200
governments to go and do this 
thing. 

422
00:26:22,240 --> 00:26:24,680
You know, this is their job that
they get up and do every day for

423
00:26:24,680 --> 00:26:31,400
8 hours or 10 hours is to find a
way into US or other Western 

424
00:26:31,600 --> 00:26:34,640
telecom networks and sit there 
and be pre positioned for 

425
00:26:34,640 --> 00:26:37,360
whatever operations may come 
next. 

426
00:26:37,360 --> 00:26:40,680
That's that's what they do, you 
know, and it's a weird thing to 

427
00:26:40,680 --> 00:26:44,640
explain and be like, yes, there 
are offensive cyber teams all 

428
00:26:44,640 --> 00:26:47,040
over the world that, you know, 
just get up everyday looking for

429
00:26:47,040 --> 00:26:51,760
ways to attack us. 
You know, the parallels with 

430
00:26:51,760 --> 00:26:55,560
like military are not exact. 
They're always used, but they're

431
00:26:55,560 --> 00:26:57,880
not. 
We don't just have foreign 

432
00:26:57,880 --> 00:27:03,160
armies pre positioned on, you 
know, in like Louisiana or North

433
00:27:03,160 --> 00:27:05,640
Dakota all the time, as far as I
know. 

434
00:27:07,040 --> 00:27:10,880
But we do have foreign threat 
actors in our networks at all 

435
00:27:10,880 --> 00:27:13,880
times. 
And it's just one of those weird

436
00:27:13,880 --> 00:27:15,760
things you have to wrap your 
brain around and be like, 

437
00:27:16,000 --> 00:27:17,840
they're here. 
We just have to find a way to 

438
00:27:19,040 --> 00:27:23,240
mitigate their access. 
And you can try and eject them, 

439
00:27:23,560 --> 00:27:27,120
but they have they've shown over
and over again that they don't 

440
00:27:27,120 --> 00:27:32,000
find a way back in. 
Yeah, even the SYSA advisory 

441
00:27:32,000 --> 00:27:35,320
that I think it was yesterday or
the day before on on Brick Storm

442
00:27:35,320 --> 00:27:39,440
that came out basically warning 
that Chinese threat actors have 

443
00:27:39,440 --> 00:27:45,040
been targeting Gov orgs in the 
tech sector with this malware, 

444
00:27:45,120 --> 00:27:48,960
which, you know, they described 
as sophisticated that 

445
00:27:49,200 --> 00:27:54,680
essentially has enabled threat 
actors to, I think they said 

446
00:27:54,680 --> 00:27:59,280
achieve persistent access an 
average of 393 days. 

447
00:27:59,680 --> 00:28:01,600
That's not good. 
It's not what you want. 

448
00:28:01,880 --> 00:28:05,600
That's a long time. 
It's a really long time. 

449
00:28:06,080 --> 00:28:09,600
Yeah, so and I think, you know, 
it's, it's a good point that 

450
00:28:09,600 --> 00:28:12,480
these are, this is their full 
time job is like trying to 

451
00:28:12,640 --> 00:28:15,680
figure out the best way to 
maintain that access because 

452
00:28:16,160 --> 00:28:19,560
that level of persistence is is 
extremely valuable for threat 

453
00:28:19,560 --> 00:28:20,960
actors. 
Yeah. 

454
00:28:21,280 --> 00:28:23,440
You know, think of all the 
things that they can collect and

455
00:28:23,760 --> 00:28:27,360
you know, data isn't an 
information, it's not it's, it's

456
00:28:27,560 --> 00:28:30,520
constantly changing and like 
being able to stay on top of 

457
00:28:30,520 --> 00:28:33,200
that is is really valuable. 
So. 

458
00:28:33,640 --> 00:28:35,280
Yeah. 
I mean, they can sit there and 

459
00:28:35,280 --> 00:28:38,360
depending on their level of 
access, look at, you know, the 

460
00:28:38,360 --> 00:28:40,640
way that the network is 
changing, the way that personnel

461
00:28:40,640 --> 00:28:44,120
is changing inside the 
organization, what they're, you 

462
00:28:44,120 --> 00:28:47,680
know, patching levels are how 
they're thinking about their, 

463
00:28:47,920 --> 00:28:51,080
you know, annual budgets and all
that kind of shit. 

464
00:28:51,080 --> 00:28:54,880
It's just, you know, 390. 
I mean, by my math, that's more 

465
00:28:54,880 --> 00:28:57,280
than a year. 
I think that's a long time. 

466
00:28:59,000 --> 00:29:01,200
Yeah. 
Yeah, it is. 

467
00:29:01,200 --> 00:29:04,200
You'll. 
Get a full FCC role enabled and 

468
00:29:04,200 --> 00:29:06,400
then reversed in that time. 
We sure did. 

469
00:29:06,680 --> 00:29:09,640
Yeah. 
It's wild what can happen inside

470
00:29:09,640 --> 00:29:12,000
of a year. 
Yeah. 

471
00:29:13,200 --> 00:29:18,280
All right, so between now and 
Christmas, which is holy shit, 

472
00:29:18,280 --> 00:29:23,480
three weeks away, I'm sure we'll
do a couple more of these 

473
00:29:23,480 --> 00:29:25,680
podcasts, but also some more 
movie podcasts. 

474
00:29:25,680 --> 00:29:28,800
We were talking about doing Die 
Hard, which I'm one of the 

475
00:29:28,800 --> 00:29:31,000
people that is like, this is not
a Christmas movie. 

476
00:29:31,000 --> 00:29:35,920
So it's a movie that take place 
at Christmas, but we can save 

477
00:29:35,920 --> 00:29:40,800
that for the podcast. 
But so we'll do that in the next

478
00:29:40,800 --> 00:29:42,920
week or two. 
Are there any? 

479
00:29:42,920 --> 00:29:45,840
I was thinking about Home Alone 
because it's been on all the 

480
00:29:45,840 --> 00:29:50,600
time and it's such a like 
delightful, like, you know, 

481
00:29:51,160 --> 00:29:52,800
social engineering isn't the 
right word. 

482
00:29:52,800 --> 00:29:56,040
I guess it is, but that could be
a fun one too. 

483
00:29:56,520 --> 00:29:58,840
Yeah, I think so. 
I love home alone. 

484
00:29:59,160 --> 00:30:01,720
Home alone too. 
Yeah, Home Alone too I think is 

485
00:30:02,120 --> 00:30:06,000
honestly more of my favorite. 
Yeah, aside from the bird lady 

486
00:30:06,000 --> 00:30:10,040
who just freaks me out, I can't 
like the pigeon lady. 

487
00:30:10,040 --> 00:30:12,240
Just every time she's on screen,
I'm just like, oh. 

488
00:30:13,280 --> 00:30:16,320
Man is what's who's the better 
side character, the pigeon lady 

489
00:30:16,320 --> 00:30:17,640
or the old man in Home alone 
The. 

490
00:30:18,120 --> 00:30:21,400
Old man, I always forget about 
him in the in the home alone 

491
00:30:21,400 --> 00:30:22,440
every time. 
I'm like fight. 

492
00:30:22,920 --> 00:30:25,400
With his. 
Son, why is this like Dickens 

493
00:30:25,400 --> 00:30:29,520
ghost guy shoveling snow and 
showing up in the church and 

494
00:30:29,520 --> 00:30:31,760
being a weirdo? 
I always forget about it. 

495
00:30:33,400 --> 00:30:35,760
Yeah, I don't know. 
He freaks me out too, honestly. 

496
00:30:36,320 --> 00:30:38,280
Yeah, both of them scary. 
Characters. 

497
00:30:38,880 --> 00:30:41,360
Yeah, and his name is literally 
Marley, right? 

498
00:30:41,720 --> 00:30:44,560
The old man. 
I'm pretty sure it is. 

499
00:30:44,720 --> 00:30:49,600
Yeah, just like in A Christmas 
Carol. 

500
00:30:49,600 --> 00:30:50,280
Yeah. 
I don't. 

501
00:30:50,840 --> 00:30:52,480
I don't know. 
They both weird me out. 

502
00:30:52,720 --> 00:30:54,760
John Hughes. 
Interesting dude. 

503
00:30:56,840 --> 00:30:59,000
But yeah, I don't know. 
We could. 

504
00:30:59,200 --> 00:31:01,000
We can talk it out. 
I don't know which one we 

505
00:31:01,000 --> 00:31:05,520
should. 
I think the first Home Alone is 

506
00:31:05,520 --> 00:31:10,400
maybe the more like, although he
does a lot of damage at the 

507
00:31:10,400 --> 00:31:12,800
townhouse in in home loan too 
too. 

508
00:31:13,560 --> 00:31:17,560
So that's, yeah, I maybe we 
could put it up to vote on 

509
00:31:17,560 --> 00:31:20,600
Twitter or something, see what 
more people want, yeah. 

510
00:31:21,640 --> 00:31:24,000
I do feel like I don't know 
about your generation but like 

511
00:31:24,360 --> 00:31:26,920
my kids like home alone too 
more. 

512
00:31:27,240 --> 00:31:31,840
It's like their thing. 
Yeah, I don't know if it's like 

513
00:31:31,840 --> 00:31:34,560
a generational thing, but 
personally I like the New York 

514
00:31:34,560 --> 00:31:36,480
City. 
Like I like the vibe of New York

515
00:31:36,840 --> 00:31:40,680
more. 
So yeah, I mean, I'm, I'm down 

516
00:31:40,680 --> 00:31:43,560
for both, for either. 
Do both. 

517
00:31:44,080 --> 00:31:45,720
Yeah. 
I mean, the the first one is 

518
00:31:45,720 --> 00:31:49,800
obviously it's like it's set in 
Chicago in the same like area of

519
00:31:50,160 --> 00:31:51,920
every John Hughes movie from the
80s. 

520
00:31:51,920 --> 00:31:54,840
You're like, OK, Ferris Bueller 
probably lives around the 

521
00:31:54,840 --> 00:31:56,920
corner. 
Like, you know, the pretty and 

522
00:31:56,920 --> 00:31:59,280
pink kids live down the street 
or whatever it is. 

523
00:31:59,680 --> 00:32:02,960
It's like OK. 
Massive houses by the way where 

524
00:32:02,960 --> 00:32:07,080
like 6 kids live in one like. 
Their house is crazy. 

525
00:32:07,520 --> 00:32:11,080
That thing is so weirdly The 
thing is filmed in. 

526
00:32:11,080 --> 00:32:12,560
Like the town that my mom is 
from. 

527
00:32:13,480 --> 00:32:15,000
Really. 
Yeah, all. 

528
00:32:15,000 --> 00:32:17,760
They're all filmed in this 
little suburb outside of 

529
00:32:17,760 --> 00:32:21,360
Chicago. 
But the the old man in Home 

530
00:32:21,360 --> 00:32:22,760
Alone one, we're getting 
sidetracked here. 

531
00:32:22,760 --> 00:32:26,040
But the old man, he lives by 
himself on that same St. like 

532
00:32:26,040 --> 00:32:30,560
next door to the Home Alone 
family. 

533
00:32:31,080 --> 00:32:35,640
Like, how is he affording that? 
Their house is like a $9 million

534
00:32:35,640 --> 00:32:37,280
house. 
He's just. 

535
00:32:37,960 --> 00:32:40,960
He looks like he's barely 
hanging on. 

536
00:32:41,080 --> 00:32:44,240
I don't. 
Yeah, I I think it's time to go 

537
00:32:44,280 --> 00:32:49,240
to retirement. 
Yeah, also houses way more 

538
00:32:49,240 --> 00:32:51,320
affordable in the 80s kids. 
Yeah. 

539
00:32:51,760 --> 00:32:55,080
Oh, must be nice. 
Yeah. 

540
00:32:55,120 --> 00:32:56,560
Oh man. 
Yeah, born too late. 

541
00:32:56,560 --> 00:32:58,080
We. 
Can discuss during the podcast. 

542
00:32:58,480 --> 00:32:59,720
Oh, we will. 
We're. 

543
00:32:59,720 --> 00:33:04,280
In cybersecurity conversations. 
That's right, housing prices and

544
00:33:04,320 --> 00:33:06,880
old men. 
Yeah, yeah. 

545
00:33:06,880 --> 00:33:08,760
All right. 
Well, good to see you. 

546
00:33:09,120 --> 00:33:12,720
Have a good weekend and talk to 
you next week all. 

547
00:33:13,360 --> 00:33:14,320
Right, see you in tennis. 
Bye.

