Mike Ritland

speaker
855 appearances 6 recordings 1 series first heard Nov 2024 last heard Feb 2025

Mike Ritland’s voice in public audio — every appearance, attributed to the second.

Trend

recordings per month · last 12 months
No recordings in the last 12 months.Older appearances are listed below; set an alert to hear about the next one.

Appearances

newest first · ▶ plays the moment
Yeah. So here's the thing, though. That's the other aspect is there's a lot of very detectable defaults. You have to really know how to use the tool to work around these things. But by design, it's supposed to be detectable if you're doing good security. This is going to light up. It's literally, it announces itself as an OMG cable effectively out of the box, right?
So hopefully you're at least checking that.
So here's the thing. Is the people who are that low on the bar of security, I don't need these to get in. I just pick up a phone. I send an email.
That's that sweet spot where it's like all, you know, you map out all the desires, the capabilities and the threats and the negative consequences and just thread the needle to get just that sweet spot. And we spend a lot of time thinking about that. But right now, I just point to the last five years of like, look, the results.
And that way, you know, I can talk all day about how much intent we put into it. But the results are far better than the intent in terms of convincing somebody. Another thing, so I think I showed you These should actually ship deactivated for multiple reasons, which you can imagine. There's a little, we call it the programmer. It's kind of a firmware tool.
So you plug this into your computer to activate it, right? This doubles for multiple other things. So if you do like a self-destruct on it, you recover the cable with this if you wanted to. You have to get it back out of the field. But self-destruct, we'll just put it into a neutral cable that's just... Not harmful at all. Really good if you can't pull the thing back out of the field.
You want to neutralize all your stuff. However, if you're blue team and you found this, you can also use one of these to dump every bit of firmware that's running on here, which will include payloads and all this stuff. So as long as, you know, it hasn't been self-destructed, you can just dump that and do a full forensics on it. So they get to practice as well. Wow.
So, yeah, we've done a lot of things that kind of show off the forensic capabilities and ways of approaching. So it's meant to be holistic for security, not just purely offensive use. But it's really about raising the bar, basically.
I doubt it. So these are highly targeted. So it's kind of... Things like this. Yeah, exactly. But I think it's good to think about it. Like, let's step back to, like, a different type of crime. Like, pickpocketing versus, like, Ocean's Eleven bank job, right?
Like, this is more on the, you know, the bank job, whereas pickpocketing, that's what you're more likely to experience as just a random individual.
that's going to be more equal to like phishing emails, like really low-grade commodity malware type stuff that's delivered over email. Like the risk of physically delivering this stuff is too high. Or in the case of like, oh, we're going to contaminate the shelves, right? effectively, online or not, that's so high cost and so easy to find.
You just need one person to detect that this happened and we'd all hear the news story. Which kind of reminds me of that Bloomberg grain of rice story, right? Which was complete bullshit. My friend Joe Fitzpatrick is a great guy to talk about this, but basically there was this Bloomberg news story that a little grain of rice component was found implanted in a bunch of servers, right?
And it just doesn't make sense, which is why that story didn't make sense, because there are so many other ways of approaching that that are way less detectable. Does anybody, like, how do you control where that goes? It's very hard to control where implanted hard work goes. And if you don't have control, anyone's going to find it.
I think the closest you can get to that might be that Israeli pager story. where they had to create a fake manufacturing plant to develop these things. And that is how they controlled where it went.
Yes, exactly. Fascinating. So thousands of pagers. I think it was a batch of 5,000 and 4,000 went out. So yeah, a lot of booms. But basically what they did is set up a fake manufacturing company, right? And I think they had their own manufacturing plant and everything. They licensed a legitimate – model of pager from a legitimate company, well-known.
This is a typical relationship for a lot of hardware. You just license it and you sell it. And then you're like, yeah, put my name on it. Depends on what it is. Like, obviously Apple's going to do their own thing, but we're talking pagers, right? This is like 30-year-old technology here. So they did that.
They had a bunch of, they even went as far as getting a bunch of random customers and gave them good pagers. But then they got their Hezbollah client And I'm always curious about how they did that. I have some postulations, but they got their Hezbollah client and they made exploding pagers for them. They put high explosives in part of the battery,
and a detonator in there, and basically it was configured to explode, detonate this thing, after a specific message was sent to the pager. And the way pager networks work are all broadcast, so you can send one message that goes to all pagers in the network, which is probably what they did. Anyway, this was in play for, I don't know, I think it was like one or two years.
These were out there and slowly going through the IT operations of, hey guys, we've got new hardware and slowly sending them out to the field. I think they were encrypted pagers. It was funny in some ways that this pager focus was entirely because they knew their cell phones were compromised. Like, oh, start using pagers. Maybe it was the walkie-talkies, I forget.
But they were moving away from one comms to another to avoid surveillance. And as a result, they got explosions. But that's the kind of level of control. Like, if those got out to someone else, which, I mean, there's still opportunity for that. Like, they're not...
Showing 701–720 of 855 · page 36 of 43 ← Previous Next →