Mike Ritland
speaker
855 appearances
6 recordings
1 series
first heard Nov 2024
last heard Feb 2025
Mike Ritland’s voice in public audio — every appearance, attributed to the second.
Trend
recordings per month · last 12 monthsNo recordings in the last 12 months.Older appearances are listed below; set an alert to hear about the next one.
Appearances
The Shawn Ryan Show · #164 Mike Grover - How Hacking Tools Are Changing Cyber Warfare · 29 Jan 2025
podcast
And just gets you to think like, wait, if I can do that, if they did that, what else can you do? Yeah. Let's play. It's all about exploration, experimentation. It is a frontier, too. There's just unexplored space. What else can you do? Outside of 2600, there's all the tools that people knew of the early online days, like Sub-7 or Netbus.
Kind of like a software trojan, more or less. Basically, you get somebody to run it, or you run it on their computer, And it gives you remote access, right? You can fully control those machines over the internet, right? open up the CD trays, close it up, just all kinds of wonky stuff that could be for pranks or could be criminal. God, okay. Reminds me of one of the ways we used it.
So again, I was way more about just pranking and having fun. My friend in high school, her name was Heather. She was really into like... Just... spiritual stuff and like, you know, she thought like spirits were in her house and stuff like that. It was a phase, right? But a friend and I had that running on our computer and you could play noises at the middle of the night and shit.
And just like, it was terrible. It was so bad. And you know, the CD drives would open just like, you know, She was terrified at the time, but later on thought it was funny. But yeah, for an example, right? Like, you can just have fun. You can play with people. You don't have to actually straight up do crime. Crime does occasionally pay, though, so some people would get into that.
How would they use it? For criminal? Yeah. God, this goes way back. I mean, we're talking like 20 or 25 years ago. So I'm not 100% remembering this, but it would have been... You can do like file system modification, stuff like that. So... You can get access to cookies that will contain login information. You can just get into people's accounts, send mail as them.
Spamming was a huge thing back then. That's where Bryce has gotten a lot of attention.
reputation from from those early days spamming um my my friend at the time uh paid for his first computer by spamming for a porn company actually which is funny because he's uh cashing a check sizable check for a porn company and he's like i don't know he's probably like 14 or something at the time getting like weird eyes from the bank um so yeah that happened but um What else?
So a common misunderstanding about the statute of limitations is it's not just about the time in which has passed since you committed the crime. It depends on the crime, but many times the clock starts from discovery.
It's a common misconception that is good for a lot of hackers to realize. But, I mean, I'm sure, so the CFAA, Computer Fraud and Abuse Act, literally any access to any electronic interface that is not explicitly allowed, that's a federal crime. So, literally what I described, you know, getting onto my friend's computer, that's a federal crime, even though they're cool with it and all this stuff.
So literally any of those things can be heavily punished. So yeah, it's tricky.
Yeah, so first job, IT. Again, security was not really a huge thing for the most part. All that was side stuff. But you still have to be conscious of secure design and My coworker was kind of my mentor at the time. He was ex-DOD, ex-Navy, had a lot of fun stories, but also got me more into security. We actually did our first security presentation For the company, kind of using some classics here.
So the movie Sneakers, amazing movie, still holds up today. If you haven't seen it, go watch Sneakers. It's awesome. But they did a lot of physical security stuff. If the door's got the hinges on the inside, you can kick it open. If it's on the outside, then you can do something different. But what else? There's the social engineering aspect where...
They wanted to get through like a front lobby attendant who had to like buzz them in. So they had someone else come in with like, I think it was like a delivery, like just creating a lot of stress. So one guy's like, yo, I got this delivery. Other guy's like, hey, I got my cake and my balloons. Can you just ring me up?
And it just goes and escalates until he's like, ah, just pushes the button and gets in, right? Of course, you know, he didn't have a cake or anything like that. The balloons were to cover the camera. And the cake was, I think it was like a briefcase of some hardware that he had to like infiltrate into the company that would go attack things, right? Great demo.
We use that like, hey, here's some physical security things. Get you to think about it. Catch me if you can. Another thing where it's, you know, social engineering was used. And believe it or not, that movie based on Frank Abagnale, most of the stuff he said is actually made up. It was like the con on the con.
But anyway, yeah, that was kind of a classic thing that still a lot of security presentations today will still use those. Anyway, long story short, kind of got me into the idea of educating on security instead of just playing and having fun and just the entertainment value. It's like, oh, you got to actually teach people. There's a responsibility here of teach people how to not... Fall victim.
Also did some live password cracking. Back in the day, people were using real terrible passwords. So just adding some extra characters and stuff. We were able to do password cracking just in the middle of this presentation. Like, hey, this password you can get in 15 seconds. This one's going to take us 10 hours.
Basically, I mean, there's a lot of different ways. The way we were doing it was just brute forcing, being able to have the ability to just retry like word sets, like common password sets. You can just get those. There's a lot of password lists, what we call them, that will, when you're going to brute force and you just want to try them, well, like, hey, we know these are the common passwords.
We know these are passwords from leaked breaches. Just shove them all together. good chance somebody's reusing that somewhere. Good approach. There's cryptography and stuff.
Oh yeah, definitely. Highly recommended. Which one? One password's pretty good. There's different ones depending on what you need. Is Keeper any good? I haven't looked too heavily into that one. I know somebody who's very into that space that speaks fairly highly of 1Password, but it's been a while, so I wouldn't want to be like, yeah, this is the one, because that space is always changing.
Showing 481–500 of 855 · page 25 of 43
← Previous
Next →