Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Andrew Brandt

πŸ‘€ Speaker
451 total appearances

Appearances Over Time

Podcast Appearances

Darknet Diaries
174: Pacific Rim

At a certain point, it just made better sense to end of life the product early.

Darknet Diaries
174: Pacific Rim

I mean, yeah, that's an interesting thing to hypothesize about, but I have no idea about that.

Darknet Diaries
174: Pacific Rim

Don't worry.

Darknet Diaries
174: Pacific Rim

Well, I don't work there anymore, so I don't have to defend them.

Darknet Diaries
174: Pacific Rim

But I do think that Sophos did seem to have better security practices than CyberRome did.

Darknet Diaries
174: Pacific Rim

The threat actors are developing exploits and they're developing malware and they're coming up with new techniques for breaking into firewalls.

Darknet Diaries
174: Pacific Rim

And

Darknet Diaries
174: Pacific Rim

The implant is revealing all of that stuff to the security team.

Darknet Diaries
174: Pacific Rim

So behind the scenes, the security team is rushing into production hot fixes and patches for the operating system that fix these vulnerabilities before the threat actor even knows.

Darknet Diaries
174: Pacific Rim

And because they have this ability to send the hot fixes, you know, not necessarily to every machine, but maybe to every firewall, except the ones that the threat actors are using, they can fix the whole universe of firewalls except for the ones that the threat actor is using.

Darknet Diaries
174: Pacific Rim

And I think

Darknet Diaries
174: Pacific Rim

after you've tried to deploy your second or third or fourth attack and it just doesn't work and you're scratching your head because it works in the lab, look, I can show you.

Darknet Diaries
174: Pacific Rim

I demonstrated it to these guys in the higher-ups at the company or whoever is telling me to do this attack, that it works.

Darknet Diaries
174: Pacific Rim

But in the wild, it suddenly doesn't work.

Darknet Diaries
174: Pacific Rim

I think after two or three times of testing,

Darknet Diaries
174: Pacific Rim

shooting blanks, you're going to start to wonder like, hey, is there something else going on?

Darknet Diaries
174: Pacific Rim

And they started to look at, you know, well, what is this, you know, what's the firewall collecting about us?

Darknet Diaries
174: Pacific Rim

And are we inadvertently revealing as bad guys to the good guys what we were about to do?

Darknet Diaries
174: Pacific Rim

So yeah, so they start looking at telemetry.

Darknet Diaries
174: Pacific Rim

They start looking at log collection.