Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Jack Rhysider

๐Ÿ‘ค Speaker
944 total appearances

Appearances Over Time

Podcast Appearances

Darknet Diaries
174: Pacific Rim

Geez, that's another thing that's wild to me.

Darknet Diaries
174: Pacific Rim

The fact that you can take over someone else's domain if you can prove that you're the one who's the rightful owner of it or should be owning it.

Darknet Diaries
174: Pacific Rim

But they gave enough reasons to the courts, who then demanded that the domain registrar give Sophos control of the hackers' malicious domains.

Darknet Diaries
174: Pacific Rim

You convince the Dutch authorities.

Darknet Diaries
174: Pacific Rim

So you're just a company in the UK.

Darknet Diaries
174: Pacific Rim

You're just like, hey, we make this product.

Darknet Diaries
174: Pacific Rim

You can't just call up the Dutch police and say, go get that server, we need it.

Darknet Diaries
174: Pacific Rim

And then they're like, we're on it.

Darknet Diaries
174: Pacific Rim

At the same time, they got control of the domains used by the hackers and sent all the traffic they were getting to a sinkhole and logged it all.

Darknet Diaries
174: Pacific Rim

I couldn't find a single article by Linksys mentioning any of this.

Darknet Diaries
174: Pacific Rim

Netgear put out an advisory saying a Chinese threat actor is attacking their products.

Darknet Diaries
174: Pacific Rim

However, they say they are not aware of any Netgear devices being exploited out in the wild.

Darknet Diaries
174: Pacific Rim

which if they don't have any telemetry from their customers' products, then yeah, of course they're not going to know if any devices are being exploited.

Darknet Diaries
174: Pacific Rim

And that's what's challenging me here.

Darknet Diaries
174: Pacific Rim

Should the firewall vendor be collecting logs off its customers' devices in order to better understand what devices are actively being exploited?

Darknet Diaries
174: Pacific Rim

Or should that be the responsibility of the customer?

Darknet Diaries
174: Pacific Rim

In many organizations, they have their own security logs and even a team to monitor those logs to look for threats.

Darknet Diaries
174: Pacific Rim

But things like Netgear and Linksys are typically home devices, and it's very rare for people in their own homes to be monitoring their logs looking for threats.