Ep. 94, No punches pulled (with Eliza-May Austin)
May 11, 2021
Show notes
(2020-11-12)purple teaming, enhancing women abilities, LHS, HCSP, breaking into infosec
[00:25:55] “[…] and although people do say you don't have to be technical to be inside of it, that's correct. But it is also not true. So you don't have to be technical to be a cybersecurity recruiter, for example, or sales or service management. But it does help, hopefully, if they understand at least the technologies that their company is managing. Well, actually, whether or not you mean like a GRC role or project management role, you do actually have to have a good grasp of the technical in order to be good at what you're doing.”
Much overdue podcast guest – Eliza-May Austin - the founder of the Ladies Hacking Society (LHS), CEO and co-founder of th4ts3cur1ty.company and PocketSiem – HCSP (Hybrid Cyber security Provider) tool.
Amazing conversation touching on:
Infosec beginnings
Job satisfaction - Red teaming, blue teaming and purple teaming
Stu’s London landmarks sightseeing trip after one award ceremony
BSides Manchester
Ladies Hacking Society – how/why it came about, core values and ethos of the community
Top Hats and Tails LHS/THMC meet up
PocketSiem
How to break into the industry, importance and respect for fundamentals and the long-term learning journey
Being banned on LinkedIn
Threat Intel
[00:35:48] “It's a non-professional event for professional people […] they're turning up, they know that they're going to have a good time, people genuinely have made friends that are potentially friends for life. They've met just having a laugh and having fun, and we stick to our core value, and that is to enhance women's technical ability and stature in cybersecurity community in the U.K. And that's what we do in and I think I think we're doing a good job with that.”
[00:56:36] “[...] if you really wanted to get into the industry and you don't really know where to start. My advice has always been - go on edx[.]org, go on Udemy, Microsoft Academy or whatever it's called now. There’re all these free resources out there, that are genuinely really good. They're good quality. You don't need to pay for them, and you can just experiment doing a couple of courses, maybe Cybrary or something like that and just see what you like. You know, if you get like a few modules and anything fucking this artwork and if it's hart works, it's boring. Don't do it. Go and do something else and just see what aspect of cybersecurity you like. Because it's not just one job. There's so many jobs in this industry.”
(00:28:15) “[…] I think people need that as well, you know, that they need somebody to believe in them, you know, because… because people surprise you when you believe in them, right? And when you give them time to grow.”
We are joined by Ian Murphy whose cyber awareness videos are truly something I look forward to every time. If you haven’t yet watched those hilarious and so creative masterpieces – you are up for a treat! Please check the links below. During this podcast you will hear about:
Working for the MOD, Symantec and moving to Australia
MDR - Managed detection and response
(Un)realistic job specs and recruitment issues
Marketing BS – how much more secure are we because of that?
LinkedIn and how it is failing
Ian’s awareness videos and other methods to educate about cyber risk
Importance of educating our next generation
(01:05:50) “[…] I think kindness is magic […] when you see somebody doing stuff or trying to do stuff, the easiest job in the world is to criticise from the side lines. […] the bit about respect or the bit about kindness is, maybe sometimes trying to see the context from what other people are trying to say. And if you're going to offer constructive criticism or opinion, do that in a way that is respectful […] Let's be a little bit more considerate of the other people we're trying to engage in.”
(01:16:50) “[…] go after your niche, find your niche, find the thing that makes you you and go after it and you'll have a lot of fun doing it, you know, and don’t listen to anybody who says you can't do it. What they mean is they can't do it and they don't want to see you trying to do it as well. So find your niche, go after it and have an unwavering belief in yourself.”
(00:50:46) “[…] We're not working in a pandemic, we are in a pandemic – working”
Please join Stu in this deep and though provoking conversation with Nicola Whiting, Chief Strategy Officer of Titania Group. In January 2020 Nicola was awarded MBE (Member of the Most Excellent Order of the British Empire) for services to International Trade and Diversity. Their discussion touched on: • MBE and meeting Prince Charles and the Queen • Basic cyber hygiene and cyber essentials • Compliance vs security • Diversity and importance of including Roy Disney and Walt Disney kinds in your company • Kindness, mental health and device detox
(00:23:17) “[…] Dan Ariely quote, where he says Big data is like teenage sex, I think that applies to, you know, basic housekeeping in networks. It’s like - Everyone talks about it, nobody really knows how to do it, everyone thinks everyone else is doing it, so everyone claims they are doing it too”
(00:30:00) “[…] we're all in this to do the same thing. We want to help people innovate. We want to help people drive business, and we want to help people protect the things that they've built. So we've only really got two jobs in our industry: making new stuff and protecting the stuff that we've made”.
Ep. 91, #VerifyIanColdwater (with Infosec Taylor)
Dec 26, 2020
Show notes
(2020-10-19)SANS, Incident Management, DEF CON, WISP, Diana Initiative, mental health
(00:25:07) “[…] I'm one of those people that I don't really feel like there are mistakes, there's learning opportunities. And that probably sounds really lame, but everyone's going to make mistakes. And it's what you do with that. If you're going to, you know, take a bunch of time to be hard on yourself for it, you're never going to learn and grow because literally everyone makes mistakes. There's not a single person alive who has not made a mistake”
Whist sitting in some random car park at night, Stu is having conversation with Ashley Taylor about her infosec journey. Join in to listen about:
SANS programmes
Business risk vs technical risk
SWOT analysis
Advice on starting in Incident Management and good practice examples
Drama, bulling, harassment and impact on mental health
"#VerifyIanColdwater" and the disappointing Twitter verification process
As well as the awesome questions from the community
Quotes (00:47:10) “[…] I'm kind of in that generation of people where I have this very clear line between real life and online life, and I know I can separate that.”
(01:06:54) “[…] Everybody in the information security community is going to give you advice and you're going to think that you need to learn everything all the time and - don't! You are in charge of your own journey, and if that takes you years or you want to do it in days, it's fine. Whatever you want to do, it's your journey. Don't let other people define that for you. And it's such a, I feel, a such a young field that there's plenty of room, even if it takes you a decade to get up to speed it. There is plenty of room for you to make your mark. So don't be afraid, just - jump in!”
Ep. 90, Dead Cows (with Deth Veggie)
Dec 25, 2020
Show notes
(2020-10-01)Hacking, Phreaking, History lesson
00:40:26 "[..] And so all of a sudden, people became less and less free with their information, less free about sharing stuff, both because, hey, now for the first time, we all knew people would be busted because so many people were being busted."
So we were extremely lucky to be joined by DethVeggie the Minister of Propaganda for the CDC aka The Cult of the Dead Cow. In this episode we discussed the following:
How Stu and DethVeggie met
How DethVeggie joined CDC
Some interesting stories about the early days of CDC and groups that emerged from CDC
What CDC are up to now and some exciting future projects
Conspiracy Theories (╯°□°)╯︵ ┻━┻
Discussion around privacy
Communities then vs Communities now
An amazing rant
And the usual questions from our audience live
Quotes: 00:10:14 "[..] And then came the day my parents got a six hundred dollar phone bill because I'd been calling BBSes and other parts of the country. And in fact, in other parts of the world, I remember calling places. In Sweden, for instance, and, you know, my you know, my dad kind of sat me down, was like this, this will not happen again, but in his thick German accent and I was OK, well, I'm not going to stop calling these places. So I guess they're going to figure out how to call them for free." 00:46:06 "Any time you introduce money into an equation, it is going to radically change it. So, you know, you can you can make an argument whether it's changing it for the better, for the worse on an on an individual basis. But, it will change it [...]" 00:59:38 "Somebody be busted for hacking and they would be in news stories like, oh, they cost three hundred thousand dollars worth of damage, it's like, no, they didn't cause any damage. What you're saying is that it cost the company three hundred thousand dollars to fix the hole that this person found it. They didn't make this hole. They didn't break anything. They didn't destroy anything. They just found a hole that was already there that it cost you a thousand dollars to fix your own holes."
Ep. 88, You Got Mail (with James Linton)
Dec 10, 2020
Show notes
(2020-07-23)Social Engineering, Pranks, Infosec
*00:06:10 "[...] maybe the first time I've ever read Daily Mail comments, but it kind of said, you know, this guy is clever and he looks to be working in security next. And I guess at the time so I thought maybe I could do that." *
We love social engineering here at The Many Hats Club, so were simply stoked when we were joined by the awesome James Linton aka @SINON_REBORN, famed for being a email prankster who targeted officals at the White House and many other high profile executives. His story is very interesting, in this episode we learn:
Background into Email Pranking and Social Engineering, Web Designer > Social Engineer
Email Pranking Banks Executives
OSINT and Pranking the White House- Lessons learnt from the pranks
Writing a blog post with the NCSC
Phishing threats and BEC scammers
Pranking infosec people, and how that ended!
Getting into infosec and what he is doing now
Public speaking and talks
What training works, and what really doesn't
Scammers
And much more!
00:29:48 "[..] Oh, do you need an email address? Here it is. Now, that's not going to work every time, but I still had a secondary option to ask directly for the email address after that kind of trust was established. So I use that a few times to be fair, and it seemed to work a lot more than it didn't work, just kind of because, again, you don't look like a threat, is not asked for anything, and it's going under the guise of something that does happen"
(00:09:49) […] it is like steering a super tank on occasion. When someone says “It's been three weeks, why didn't you fix that?” It's like, well, it's just taken me a week to get it all translated into Japanese and arrange a meeting with the right person. Trust me, I'm trying to make this happen. I can't just click my fingers…
Quentyn Taylor is the Director of Information Security at Canon Europe, Middle East and Africa. He talks to Stu about important aspects of vulnerability disclosure and bug bounties programmes, where to start, how to set the boundaries and drive business and budget decisions based on findings – amongst many other things. They also touch on:
Humble beginnings
Passport-less travelling
Amsterdam
Vulnerability disclosure and bug bunty programmes
Challenges for middle to large size organisations
Hyper verticalization of IT organisations
Waterfall vs Agile(ish)
Importance of understanding your own attack surface
Red & Purple teaming and driving budget conversations based on the findings
Internal auditing vs external bug bounty hunters
Value of prior experience and curiosity when transitioning to InfoSec
They finish the conversation with excellent rant about CISO – the sacrificial lamb of data breaches, Cyber threat intelligence and scientific approach to report writing. Excellent conclusion of this interesting podcast episode.
Further spoilers:
(00:23:55) […] people tend to overestimate the pace of change in the short term and underestimated in the long term
(01:11:20) […] don't set yourself up and say:” I must become a CISO is where I must be. Now, there are so many other diversified senior roles that you may actually find more interesting, because if you're not enjoying your life, what the hell are you doing with it? […] do the job you enjoy. So find a place you enjoy, find a company you enjoy and enjoy it!
Ep. 83, Journalism Dot Com (with Geoff White)
Dec 03, 2020
Show notes
(2020-04-03)Infosec, Journalism, Privacy, OSINT
00:04:30 "[..] I find that really disturbing when I see a sci fi cliché and it's kind of coming true in real life. I don't like those moments."
We were very lucky to be joined by the awesome Geoff White @geoffwhite247, author of the fantastic book Crime Dot Com, and Infosec reporter for Channel 4, BBC News and The Sunday Times. In this episode we discussed the following:
Making Risotto with Prosecco :)
His journey into Tech and then Journalism
Discussion around investigative journalism especially in technology/infosec
Importance of Open Source Intelligence, and verification of stories/sources
Leaks and Whistleblowers
Facial Recognition and Privacy
Writing his book, with some amazing insights into the stories behind the book.
And many questions from the audience
00:06:20 "There's no point in doing it if we never get on air. So I started, you know, attending these cybersecurity conferences and learning about cyber crime and just thinking this is where it is"
00:46:10 "I've kind of realised the people in power and responsibility in your life, you kind of take it for granted that they know what they're doing and they make good decisions. And this is the biggest lesson for me is that's not necessarily true..."
(00:09:05) “[…] it's OK to specialize, you don't have to know everything. And I think in today's age, it's obscene. You just wouldn't be able to know everything, you know. And I think this is expectation that, oh, you know, if you're a pentester, you need to know everything. I know a lot of good pentersters (who won't admit it) but they don't know the Cloud. They don't know the real Cloud. I would if I was doing it now, I'd look for what really gets me excited […] So I think pick what really gets you excited and concentrate on that. Ignore what everyone else thinks. They don’t matter. What matters is what you're going to pull your effort into.”
Stu had the pleasure to listen to the incredibly humbling story of Daniel Cuthbert. He is a co-author of the OWASP ASVS standard and currently holds the position of the Global Head of Security Researcher for a large corporate.
This incredible conversation touches on the following subjects:
OWASP and the humbling journey till now
Times when World Wide Web was not a thing
Importance of self-development
How to start in hardware (some great advice there!)
Money vs job satisfaction
Threat modelling and bug bounties
Experiencing Chernobyl as a creative
Photography in a conflict zone
Court case and changes to Computer Misuse Act 1990
(01:06:13) “…submit it and if you see who's on the review board and you want help, reach out. And my offer still stands. My DM’s are open. […] But I will, you know, if I can help the submission, understand it and help you rewrite it and go from that, it doesn't have to be for Black Hats or BruCON or DEFCON or 44CON that I am involved in - it could be for any con”
Ep. 81, Hacker Rhymes With.. (with ytcracker)
Nov 29, 2020
Show notes
(2020-03-13)Hacking, Nerdcore, Appsec, Community
00:03:55 "And I, you know, being on the Internet and then knowing how fragile everything is to is, just kind of scares me because I know what code runs and prod and how terrible it really is. And there's gnomes that are flipping switches at any point and anything could go down..."
In this episode we were dropping some sick infosec rhymes with YT Cracker, who has a facinating infosec journey and music career. He currently works in appsec for a large online company. In this episode we discuss:
Journey into infosec
Hacking "back in the day"
Appsec
Breaches and security culture
His awesome music career
His journey to Sobriety
Attitudes to the community- be happy, be cool to each other.
00:12:20 "There's a there's a maxim that I used to say on digital gangster that was a digital gangster is only as broke as his morals will allow."
00:42:25 "And I just started making beats and then. I was playing guitar, too, but I wasn't really recording the whole thing was, is I just I listen to rap a lot and I liked rhyming words. And so those two things kind of came together and I just was rapping about the stuff that I knew."