Mike Ritland

speaker
855 appearances 6 recordings 1 series first heard Nov 2024 last heard Feb 2025

Mike Ritland’s voice in public audio — every appearance, attributed to the second.

Trend

recordings per month · last 12 months
No recordings in the last 12 months.Older appearances are listed below; set an alert to hear about the next one.

Appearances

newest first · ▶ plays the moment
watching one pager go from hand to hand to hand, like, it's like, oh, we deployed it to Hezbollah, and it's reasonable to assume that this level of dissemination with this margin of error and other people touching them, and, you know, they probably did the math on that, right? I didn't. But that's kind of a good example of like how far you can go and like the risks of discovery.
Stuff like Stuxnet. Stuxnet's another good example of, I think it was the Iranian enrichment facilities where, oh, I can't remember the full story here, but there was like a thumb drive with a worm on it. And it basically got carried into this enrichment facility, and it would damage part of the enrichment machinery, right? But it didn't do it all at once.
It would randomly pick one or the other because you don't want to be discovered, right? If you did it all at once, you're like, oh, something's up. It's just like, oh, one went out, whatever, it must be bad, right? There's like the psychology of making sure it doesn't seem like it's something to investigate. It's like, oh, bad machines, it must be bad process.
They kept doing that and eventually, I can't remember how it got discovered, But there was an issue where it started spreading around elsewhere, like the worm or something like that. And somebody noticed it, I think. I can't fully remember. But there was a discovery event because it kind of got too wide. And once it's discovered, okay, now you can defend against it.
Now you can find them in the wild. And the moment somebody found anything in our stuff, they're going to tell the world. Like, hey, look at this cool thing I found. I'm a security researcher. That said... On the flip side, there's plenty of places we don't look. Most of the stuff you find in there is just vulnerabilities.
Like, oh, I didn't think there would be a hole on whatever, some aspect of a product. Like, oh, if you just log in 10 times and do this, you get in, you bypass everything. It's like, wait, what? You do what? That's the type of stuff that's typically, well, nobody thought to try that. So yeah, it really depends. Physical implants are much easier to discover. I mean, they're physically there.
You can't revoke them. You can't be like, oh, self-delete. It's there. I mean, not counting the Patriot situation. It's a different type of delete. But, you know, delete in a way that doesn't leave the evidence around.
I don't know yet. What are you thinking about? Like, I have been... Focusing more on personal stuff, just like hanging out with my kids, spending more time with them while I got the time and they're growing, you know, one's 14, so, you know.
No. Learning how to do that is part of it.
Yep.
I mean, here.
Here's an example. So, I'm reusing the same implant in a couple of ways. So, I mean, this is an easy one. So, USB adapters, basically a cable, right? Cool. Uh-huh. I had a thing where customers were enjoying the firmware so much for like payload development, they would get the cable and cut the end off. I'm like, dude, no, that's my baby. What are you doing? So, you know, there we go.
Keychains that, you know, don't have the cable on it. Cool. Got that. Now here's another one. Are you familiar with USB data blockers?
So it's a commonly recommended secure charging mechanism. You're like, oh, I can't trust the airport charger or something like that. You're like, well, get a data blocker.
Mostly. I mean, I'm personally more concerned about the quality of the electricity coming out there frying my phone than I am about like a data situation. Because going back to the discoverability, you put something in a wide space like that, once it gets detected, you hear about it. We've not heard about it.
And especially in a secure space, like all the airport locations, like everybody's on camera, right? Like, good luck. It would be really hard. There's advisories that come out, and I think the FBI was doing them. They get a lot of flack for that because there's no, like, proof it existed, but... I don't know. I don't have the intelligence they have either. So, I mean, there's things you could do.
I also don't consider my creativity to be all-inclusive in all ways. You can do something negative. There's plenty of people with different motives and minds than me. So, yeah. We'll see. It would be a cool story. But yeah, data blockers. That's the idea. You now have safe charging. I'm like, cool. I'll put one of my things in a data blocker. Now, you know, cat and mouse.
I just thought it was funny. But just as an example, just kind of chase that a little bit. Go from there. I don't know. We'll see.
I've done a lot on the manufacturing side, so I've had to invent so many tools and mechanisms, both for creating these cables, which turns into their own products, because I'm teaching other people how to use them, and it breaks, and I've got to do support for those products, and they're their own PCBs and everything.
It's a hardware product with its own firmware, just to test these cables at multiple stages. So I'm still packing these at home with the kids and the envelopes, right? I got to label those. It gets really annoying over time. I'm like, you know what, I'm going to create a machine to label these. So I just keep chasing that down and see how much I can do. You know, there's a guy called Cliff Stoll.
Showing 721–740 of 855 · page 37 of 43 ← Previous Next →