Mike Ritland

speaker
855 appearances 6 recordings 1 series first heard Nov 2024 last heard Feb 2025

Mike Ritland’s voice in public audio — every appearance, attributed to the second.

Trend

recordings per month · last 12 months
No recordings in the last 12 months.Older appearances are listed below; set an alert to hear about the next one.

Appearances

newest first · ▶ plays the moment
Uh, predecessor, right? So I had been doing lots of designs of malicious cables, right? And I had some really early proof of concept just to show it's possible. No wireless connection, really tiny payload capability, you know, a few dozen, maybe a hundred keystrokes, right? Really limits what you can do. It's really slow. I mean, we're not hitting a thousand keystroke per second thing. We're
Maybe it doesn't. Really slow, right? But it's like, it worked, right? Can't remotely update it, can't do anything, but it worked. I want to show the world, because, you know, hacker, you want to share the information stuff and work with other people. I didn't see it as like a product, it was just more like... more like art, like, hey, cool, look at this thing.
And yeah, he reached out and wanted to kind of collaborate and have me build one for him. And I started on that process, but I didn't have enough time to complete it with his work constraints as well, because he didn't have time and stuff. And eventually what happened... Didn't know about it, but he went to someone else and said, make this for me. Oh, shit.
I didn't know about it until it came out. The thing is, it wasn't very good. I was just like, dude, first of all, this is not very good. This sucks. I wish I was making this a proper product at all. So I was like, hey, if you had the resources, I could have used that. Because I was just doing this on the side. But we have... you know, solved things since then.
You know, I think there's certain levels of communication and misunderstanding, so I don't want to be like, oh, he's the worst. But, you know, lessons learned as well of like, you know, if it's something you can turn into a product, maybe wait until it's ready. You know, things like that. Which is exactly what I did with the OMG cable, right? That's where it's like thousands of times better.
I mean, well, so, RIP. He's no longer around. Oh, really? Yeah, exactly. But, yeah, the way he would be introduced, like, I don't know. But it was always the world's most famous hacker is the tagline that was used.
So, well, he, God, yeah. I need a refresher on this, but basically he had gotten the attention of the FBI, and they were hunting him down for getting into various places. A lot of social engineering tricks and stuff like that. And kind of a cat and mouse game. There's a movie called Takedown, right? So good movie. Check it out. But he went to prison then. and was pretty unfairly treated.
There was a whole free Kevin movement where they were doing, I think they put him in solitary or something because they thought he could whistle into the phones and launch ICBMs or some shit like that. Oh my gosh. This is like back when everybody was like, oh my God, hackers, just evil wizards. It's still like that today, but it was much worse back then. They had no idea what was even possible.
So yeah, he was held for much longer. I don't want to misspeak here because I don't remember the particulars, but he was held for a very long time, pretty unfairly, eventually got out, and then went into InfoSec as a profession using that.
I mean, I guess he knew it looked good, so he's good at that.
Oh, yeah, definitely. And just for the record, he got a pretty unfair shake at life. I think he got pancreatic cancer, and he died before his first kid was born, which is just fucking terrible. Man, that's horrible. I've since met up with his wife and cleared the air. Good for you. We're good.
Yeah, definitely. It depends where we're talking about red teaming, because there's military red teaming, which I would love for you to give me a couple of stories on. I'm sitting in a room with a guy who probably knows that really well, way more than me, so it would be a little ridiculous for me to explain that to you.
But red teaming in terms of corporate cybersecurity is a subset of pen testing. Pen testing is find the holes. tell us the holes, right? I mean, that's cool, but it doesn't quite test how someone responds. I think there's this, I think it's a Mike Tyson quote, where everybody has a plan until they get punched in the face, right? It's like, okay, well,
maybe a little aggressive in context of cybersecurity, but, you know, how do you solve that? Like in boxing, you train, you get punched in the face, right? And then, well, okay, now it's not going to be new when it happens. So you might have a plan, but are you going to execute on the plan? Are you going to, like, miss some steps? Is motion going to get involved? And also, you know, I can...
find holes at different layers, but red taming is going to be repeating exactly the entire chain. It's often called a kill chain, where you're connecting all of these different vulnerabilities to go from completely outside to completely to the crown jewels, take them out and succeed, and then you show how you did it after the fact. How'd you get into that?
good question so kind of almost don't even know but over the course of just life and I started off as just help desk IT sysadmin where you learn a lot of things and at the time I didn't think it was very applicable but like those are all the systems and the nuances and like just the weird compromises you learn like oh I don't have enough budget so I'm going to do it this way or you learn about the end users that you're supporting as help desk and all the
problems they run into, and, oh, they're running into, like, policy that stops them from working, so, oh, they're going to do this. That's going to cause a degradation of security, but it's really common. You know that, having been in helpdesk and sysadmin, so you start to connect these things together, and it becomes this really...
valuable just bucket of information for oh how would i get into the company using that and you know got really into security for a while it's just it's it's also a piece of that role like you're gonna run all the systems for it you gotta keep them secure too especially in small companies where you don't have dedicated security it's like no you you are the security so you gotta learn it that way which requires you to think also how does an attacker do it because
You got to defend against that, right? So eventually, I just kind of got bored of doing IT and made the jump into security. Started learning... Actually, Bryce is a good connection on this as well. So... I had known Bryce for a long time, and I think it was like 2013, first time I went to DEF CON, Hacker Security Conference, biggest one in the world, in Vegas, every year.
And I decided, oh God, what was this? So there's these unrecorded talks they also do in certain areas. He was on stage, I think he was doing something with Bitcoin at the time, and he had this telepresence robot on stage for a guy who was on house arrest. He couldn't come, so he brought a telepresence robot to be Bryce's partner on the stage. It was just wild watching this.
Showing 381–400 of 855 · page 20 of 43 ← Previous Next →