Mike Ritland

speaker
855 appearances 6 recordings 1 series first heard Nov 2024 last heard Feb 2025

Mike Ritland’s voice in public audio — every appearance, attributed to the second.

Trend

recordings per month · last 12 months
No recordings in the last 12 months.Older appearances are listed below; set an alert to hear about the next one.

Appearances

newest first · ▶ plays the moment
I mean, possibly. I don't know that level of detail and don't really want to, but as long as they're part of the okay entities.
Yeah, I know exactly right.
This is going to be defined on who is or isn't going to put me in prison. So that's my definition of good in this scenario is keeping those people happy. But to be clear, there's another advantage here, which is some of these places are critical infrastructure that they work at or are tasked with. securing or improving the security. So we all benefit from that.
I don't want a place that has some form of nuclear material in it getting compromised because the people who want to compromise those places probably looking to hurt me in some way, right? So let's help them. So the other feature kind of added to these cables recently is we call it HIDX Stealth Link.
It's kind of the branding of it to explain what it is, but ultimately still acting as a keyboard, but now it's got bidirectional data transfer. So like a network interface, but without ever showing as a network interface, you can send data back and forth between the computer, and it just looks like a keyboard to the target system.
This was used by quite a few people in a lot of environments, but in this case, the critical infrastructure was not looking for this type of exfiltration technique. And it worked really well, got them in, and they achieved their objectives with this critical infrastructure and got it fixed. I was told that my name got put into a report that I will never have access to, but that's extremely cool.
It's like, cool, I got my name into a report to fix some critical infrastructure with a technique that we developed with my team. And honestly, I'd love to pause and even talk about that team because... while I make the hardware and the manufacturing and run the business, all the tricks this does heavily about the actual firmware that runs on this and that requires multiple people to pull off.
Yeah, so there's a couple pieces of this, but one guy's retired and just loves working on hardware. Prior to this, I mean, he did a lot of things, but prior to this, he was working on the firmware for police body cameras, so... Very interesting background there. Another guy is blind, and he does kind of the UI you see. It's kind of poetic. The blind guy is in charge of the UI.
He's got a lot of experience. What is UI? Yeah, so the visual interface. When you open it up in the control panel, and you've got all the buttons and stuff in there. Hold on.
Ah, wirelessly. So when you connect to it wirelessly with your web, and then you open your web browser and then connect to the IP address, you get like a web page, right? Okay. With all the buttons on it that give you the controls. You can view the key logs. Gotcha. Open the hundreds of payloads you can save on here and run them. All that's purely visual. Okay. Click on stuff.
It doesn't have to be, you can automate it, but yeah, it's primarily visual and it allows all the cool controls to happen. So got another guy who, you know, in education and a lot of them are familiar with, you know, the government contracting spaces as well. It's a fairly small team, but they've been along for the ride the whole time and just constantly interested in picking up challenges.
And the way the Keylogger works on here is like, that's not supposed to be possible. How did you get this word out? How are you marketing this? That's a really good question, actually. I have not done any marketing yet.
I think I just put a video out. A video of like, hey, I made this with my mail. Check it out. Here's what it can do. Excuse me. Here's what it can do. And then it just took off. That was mostly in the InfoSec space. So it kind of went around the hacker community and the security professionals. Security professionals. Yeah.
And at some point, it just kind of goes outside that bubble because it gets enough traction. Like, Vice took it. Forbes took it. You know, there's so many different high-profile... This has been in Forbes? Oh, yeah, this has been in Forbes a couple times. Look, Bob, I made it to Forbes. Yeah, it's been pretty wild. I am at the point, though, where I am starting to think about...
Focusing purely on this, because this has just become this awesome monster that takes a lot of my time, as well as running Red Team as well. So that's probably something I'm going to be pivoting into very shortly. And focusing on that, helping the team, and seeing what more we can do. Probably going to relax for a bit, though. Good for you.
It's very good. So I'm probably long overdue to jump.
I have no idea. So I've never had a plan ever on any of this. It's just what's the thing and the opportunity at the moment and how can I play with that in an interesting way. Yeah. Which, you know, there's a lot of things why you would want to plan in business, but I just, yeah, I don't know, maybe eventually I'll have a plan.
I mean, it's been five, six years now, and I'm very proud of the results of it with all the places where it's been fixed and the very low abuse scenarios. We're very intentional when we think about... okay, let's add a feature to this, but let's figure out who wants this feature, who's going to make use of it. For instance, the number one that I want to avoid is like stalkerware, spouseware stuff.
People look at this and they're like, oh yeah, I need that for that. I'm like, no, I'm going to make that hard. That's not as valuable to a red team professional. We're trying to get into corporate infrastructure. We're trying to do like Ocean's Eleven shit on... like a Fortune 10 or something like that.
Yeah.
Showing 681–700 of 855 · page 35 of 43 ← Previous Next →