Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Craig Jones

πŸ‘€ Speaker
See mentions of this person in podcasts
3537 total appearances

Appearances Over Time

Podcast Appearances

Darknet Diaries
174: Pacific Rim

And it's not something that's done willy-nilly, you know?

Darknet Diaries
174: Pacific Rim

And you're right.

Darknet Diaries
174: Pacific Rim

I mean, it does feel kind of offensive, someone coming in and tampering with my stuff, you know?

Darknet Diaries
174: Pacific Rim

But effectively, it's written into the EULA, like the End User License Agreement.

Darknet Diaries
174: Pacific Rim

And candidly, you kind of need this.

Darknet Diaries
174: Pacific Rim

And I think that's where a lot of firewall providers actually fail, is the fact that they rely on end users to patch everything.

Darknet Diaries
174: Pacific Rim

And candidly, so many firewalls that just bought and they never updated, you know?

Darknet Diaries
174: Pacific Rim

Very strange.

Darknet Diaries
174: Pacific Rim

One of the things that we've been kind of working on, even before this situation, was, you know, pulling in our telemetry, our firewall telemetry, the kind of basic telemetry I was talking about earlier, into Splunk.

Darknet Diaries
174: Pacific Rim

And I remember talking to Mark, who was just this amazing Splunk engineer in my team, and

Darknet Diaries
174: Pacific Rim

I said, well, can we go back on that data?

Darknet Diaries
174: Pacific Rim

Can we find out when this first started?

Darknet Diaries
174: Pacific Rim

Because I couldn't quite work out the exact moment in time or the first firewall that was hit by this Asnarok attack.

Darknet Diaries
174: Pacific Rim

And then I went back, well, how far does that data go back?

Darknet Diaries
174: Pacific Rim

And then Mark said, well, actually, I think I've got like three months worth.

Darknet Diaries
174: Pacific Rim

So we kind of rolled this thing back three months.

Darknet Diaries
174: Pacific Rim

And there was one single device that had been hit like a month or so beforehand.

Darknet Diaries
174: Pacific Rim

Like sometime in February, if my memory serves me right.

Darknet Diaries
174: Pacific Rim

And it was just really strange.

Darknet Diaries
174: Pacific Rim

So it was kind of registered to like a Chinese 163 address.