October is Cybersecurity Awareness Month, and the digital threats facing businesses and individuals continue to evolve.
This week, Jessica Kearney of the Travelers Institute joins us to explore the current state of cybersecurity, the threats you should watch for, and the practical steps we can all take to better protect ourselves online.
From emerging cyber risks to the everyday habits that can make a real difference, we’ll look at what you need to know to stay safer in an increasingly connected world.
William Sikkens, Bill Snodgrass, Gretchen Winkler
Transcript
Welcome to
2
:User Friendly 2.0 with host Bill Sikkens,
3
:Technology Architect.
4
:And this is User Friendly 2.0.
5
:As always I'm your host Bill Sikkens.
6
:Welcome to this week's show Gretchen.
7
:Bill welcome to this week's show.
8
:Hey there blue.
9
:So I think we're going to need to do
another Q&A show coming up here
10
:pretty soon.
11
:I've been going through everything,
and we've had a little bit of a glitch
12
:on the website
that the comments on the blog articles
13
:mysteriously turned themselves back
on, and we've got a lot of spam there.
14
:We don't do our comments that way.
15
:So the comments horrible.
16
:They're horrible, but they come in
through a separate system.
17
:But our actual listener
comments are through a vetted system
18
:so that we can get them
in their real comments. Right.
19
:So I was going through all that
and was digging into stuff, and boy
20
:have we had a lot of good questions.
21
:Come in. Really keep them coming.
22
:I think we're going to look at doing this
maybe right after Halloween.
23
:So if you have stuff that you would like
to have answered on the air
24
:user friendly dot show, go there or click
25
:the Ask a Question button and let us know.
26
:Because that's number one, how we do
our programing, but also for this purpose
27
:keep them coming, because I think we've
got some really cool stuff to address.
28
:Now, one thing I will have to say,
29
:I'm the most common question
we get asked is how do you hack?
30
:And the other asking, yeah, that one,
31
:that one
we're going to have to skip over. So.
32
:Just ask British Telecom.
33
:And if you don't know about that
listen to our show from two years ago.
34
:Anyway, that being said,
35
:you guys have anything new in your life
36
:now? I'm working on the third outline
37
:for your new for your next book.
38
:Yeah, and I'm trying to finish the editing
for the second book.
39
:Cool. So I'm busy.
40
:Yeah, I can imagine what we want
that out by the holidays,
41
:which is coming right up here.
42
:So I'm hoping I really am.
43
:Yeah, yeah,
44
:yeah.
45
:Still looking for players for my paid
DM game.
46
:Yeah, actually we've had some questions
coming in about that too.
47
:So I think we're going to
maybe do a hot hot seat interview with you
48
:coming up on that too,
maybe a little bit before our all Q&A.
49
:So which is interesting.
50
:One thing I will say about that, because
there's been a lot of confusion, in fact.
51
:But can you touch upon that?
52
:What?
53
:That is really quick
because I think the listener questions
54
:have been coming in or people
are not understanding what you're doing.
55
:Okay.
56
:So what I'm doing is running a ND game
and I'm running it through a game,
57
:a company called Start Playing Games.
58
:And basically they handle the payment
so that you guys
59
:pay me to run the game.
60
:And therefore there's the level
of professionalism and expectation
61
:on my behalf and on your behalf
of what is going to be there.
62
:And that's really all the basic of it.
63
:So it's a live hosted game
where they can interact
64
:and play the game with you
and possibly other players.
65
:Right? Yes.
66
:Yeah. And it's professionally run.
67
:And one of the biggest things
I know about that, in addition to the fact
68
:that the person DMing in your case,
you bill knows what you're doing.
69
:And that's not to say
that other Dungeon Masters don't,
70
:but it is a situation where
that's an expectation that would be there.
71
:And number two,
you're detached from the player.
72
:So you don't have some of the weird stuff
that can happen sometimes.
73
:Oh yeah.
74
:You know, it,
it makes it fun and it's really easy.
75
:And it's also something that if you're
just looking for something to do,
76
:you jump on and you can get a game going,
which is really kind of cool.
77
:So what's the site again?
78
:Start playing dot games.
79
:Okay.
80
:Start playing
is, time under the crooked moon.
81
:By golf mogul.
82
:And if you're interested, just come
look up and I'm there.
83
:All right?
84
:Yeah. Check it out. So.
85
:All right,
what do we have in the news this week?
86
:All right.
87
:US Cold War era spy satellite explodes
88
:above Earth and nobody knows why.
89
:Yeah.
90
:So this satellite, by the way,
has a great name.
91
:It's USA 32.
92
:Beep beep beep beep.
93
:You know,
you imagine it flying through the air or.
94
:I'm sorry, not the air, the atmosphere.
95
:And well worth orbit, right? You know.
96
:Yeah, there's some dispute
on what you would call that.
97
:But anyway,
that's a conversation for another time.
98
:But the National Reconnaissance Office
launched this thing in:
99
:and its mission
was only declassified about a year
100
:ago, actually, earlier this year, I think.
101
:And what it was was The intercept Soviet
rated R and radio signals from space.
102
:Okay.
103
:So basically what you have going on
here is a satellite
104
:that is definitely a spy
satellite that mysteriously blew up.
105
:So this is being reported by Live Science.
106
:And they've come up with some different
ideas on what might have happened here.
107
:And there's one that might
just be simply something that happened.
108
:And the other one
might be a little bit more scary. So
109
:you have a
110
:spacecraft that's put into orbit
that has a limited life, right?
111
:And these spacecrafts contain batteries.
112
:They contain propellants
and other things like that.
113
:And it may be something as simple
as to just after time and bombardment
114
:with what's,
you know, in space at that level.
115
:It just simply had something
where it blew up.
116
:Accident,
you know, could be very possible.
117
:However, there is also some concern
because we've been starting to track
118
:anti-satellite technology
from foreign governments,
119
:specifically things like Russia.
120
:And these type of things
could have been used as a test
121
:to see if this would work,
or to where they could destroy satellites.
122
:But this is one of those things
that's kind of,
123
:you know, mutually assured destruction
from the old Cold War era
124
:that if you start doing that too much,
there's a thing called Kessler syndrome
125
:or the Kessler effect,
and they're already worried about this.
126
:So what's happened with the satellite
127
:that has been destroyed, however, it was
destroyed is within 24 hours.
128
:You have a ring of junk around the planet.
129
:And these are little tiny particles
parts, other things like that
130
:that are moving very, very quickly.
131
:And when that junk starts building up
in the atmospheric, can hit other
132
:satellites and start a chain reaction,
that can create a lot of problems.
133
:And this stuff does
not fall back down to earth very quickly.
134
:So it's it could be a thing
that if God bad enough,
135
:we wouldn't be able to get spacecraft
through this level of junk,
136
:you know, and that kind of thing,
not to mention the fact
137
:it would take out our satellite
communications worldwide,
138
:and that would cause a lot of problems
with a lot of different countries.
139
:And this was something that Russia was
threatening to do with the war in Ukraine.
140
:And even the Chinese government stepped in
and kind of told them, no, you're not.
141
:But there definitely is a possibility
that could be what happened.
142
:But it is also just as possible right now.
143
:They don't know yet.
That thing just simply failed.
144
:Yeah,
145
:kind of like the batteries
in my enterprise, right?
146
:Model.
147
:Yeah, yeah.
148
:Spotify suffered a major outage this week.
149
:Yes. And as of recording time
we don't know what happened here.
150
:But basically the started at 7 a.m.
151
:on September 29th,
which was this last Tuesday.
152
:And what happened is listeners
started reporting
153
:that they couldn't log in
and that type of a thing.
154
:Now, interestingly enough, well,
we don't have any kind of
155
:an actual description
of what went wrong here.
156
:If you were logged into Spotify
and listening to music or podcast
157
:or whatever it is that you would listen
to, that continued working.
158
:So it seemed to only affect it
when people were trying to get
159
:in, authenticate or search
or that type of a thing.
160
:So it's probably something in their API
that failed
161
:as opposed to the music distribution
system itself.
162
:But whatever the case may be,
163
:if you listen to Spotify
for a couple of hours, you couldn't.
164
:And it's interesting how much we realize
we depend on some of these things
165
:now when they aren't available,
just even for stuff like that.
166
:But we'll let you know
if anything comes out of this.
167
:That's unusual,
168
:but there doesn't seem to be any kind of
169
:an idea that it was hacked or anything
like that, just that they had a failure.
170
:All right,
kite works patches critical flaw
171
:brings customer systems online.
172
:So speaking of hacks,
173
:because this one was a little bit
more of that.
174
:They suffered a thing that is commonly
referred to in the industry as a zero day
175
:incident,
in which case they found a problem
176
:to where their systems
could have been compromised.
177
:Now, to describe
why this is an even bigger deal
178
:than it would be, just any way
is we use distributed networks
179
:and distributed systems for pretty much
everything that we do online now.
180
:So at one time, not so long ago,
if you had your email,
181
:you had a piece of software
installed on your computer
182
:that went out to a server somewhere,
183
:downloaded your email,
you would manipulate it,
184
:and then it would go to the server
and send out your response.
185
:But that was running
on your local computer.
186
:Now, most of us, for that example, use
an online service, most commonly Gmail.
187
:That's the largest one.
188
:But there's a lot of services
like that out there.
189
:And these are known
as distributed services.
190
:So if that is compromised,
whether or not your system
191
:set up properly and everything's secure,
it doesn't matter.
192
:They're still able to affect
something that you would be using.
193
:Well, you take this a step further.
194
:In a company like this
does secure file sharing.
195
:And basically what happens here is
this is a function
196
:that adds on to a server
to where you can use their products,
197
:which is a number of different things
that are very useful.
198
:But this may be implemented into systems,
and you don't even know about it
199
:unless you're the back end administrator.
200
:So what happened here
is they realized there was an exploit,
201
:and they actually urged their customers
to shut down their systems
202
:until they got it fixed.
203
:Now there's looks like they did
the right thing here by disclosing.
204
:There's no idea
that there was a compromise
205
:or anything that was actually done.
206
:So it looks like they got to it in time.
207
:And in this case, I will say
that this is how a responsible company
208
:handles these type of incidents,
because you're not going to get it
209
:right all the time or just happens,
you know. Yeah.
210
:So it's
211
:when you hide things and stuff like that
that you can have some real problems.
212
:And we're all skeptical.
213
:The only way to completely
214
:divorce yourself of something
215
:like that is to unplug from the internet,
which does not work in the modern world.
216
:So, you know, going into detail
on how this was done,
217
:if you want that information,
just search for it online.
218
:BleepingComputer
covered this initially in the press,
219
:or they can explain that rabbit hole.
220
:But the bottom line of it
is, is it's just something to be aware of.
221
:So if you had something where
all of a sudden you didn't have your files
222
:available or other resources or stuff,
and it was on a business network
223
:or that type of a thing,
this is most likely why?
224
:And another hack
225
:new specter V2 attack variant leaks
Linux root password hash in minutes.
226
:So this is Hacker News I guess this week
on things that have happened.
227
:So all right, we actually have talked
about this in the past on the show.
228
:And like I've said,
229
:we don't teach anybody how to hack here
and we're not going to do that.
230
:But to be able to cover this properly,
there are certain methods that are used
231
:for intrusion, and one of them is
something called predictive computing.
232
:Now, this is something that's been around
since the penny, Amira.
233
:And it's a way to speed up computers
where the processor and other
234
:supporting architecture can basically try
to guess what you're going to do next.
235
:And I'm really oversimplifying this,
but guess what you're going to do next.
236
:And if you do it, then it's already done,
237
:because the processor
would have been sitting idle if it hadn't.
238
:And if it's not done, it just destroys it
and does what you want it to do.
239
:It does speed things up.
240
:However, there is a method where you can,
under certain circumstances,
241
:be able to trick the processor
into executing commands
242
:that it shouldn't as a predictive process,
243
:and the information
that's put into the page memory
244
:that the processor is actively
using is much easier to get to.
245
:And what's happened
here is using that technique.
246
:Bad guys were able to compromise
and get the hash codes
247
:for the root password
on certain Linux distributions,
248
:and in doing that,
249
:they can get in
and obviously take control of a server
250
:or a bank of servers or whatever
the case may be.
251
:So again, these type of things
are not that uncommon these days.
252
:It happens
and they've already patched it.
253
:But this is one of the things like
254
:you know I know even like
with our own Linux servers on Amazon,
255
:I have an automated update process,
256
:but you still have to go in
and manually patch things once in a while.
257
:So if you are an administrator
or if you're
258
:even running your own equipment,
it's important to keep the updates done.
259
:Windows two.
260
:But certainly on this type of a thing,
because you could have a situation here
261
:where the updates been made
and it's been distributed.
262
:But if you aren't patching automatically
or haven't had a chance to run it,
263
:your equipment is still
susceptible to this problem.
264
:All right,
265
:hyper shell tech
seems to be showing up in more places.
266
:Well, it certainly is in my house.
267
:All right.
268
:Hybrid shell is a company
that makes exoskeletons.
269
:And they're one of the first companies
270
:that's brought this technology
to a consumer market.
271
:You can go to their website
and buy an exoskeleton,
272
:and most of what they sell are lower body
exoskeletons.
273
:I have one of the older version
that I really like.
274
:Yeah, I have a question because I, I know
I have one and I screwed up the battery
275
:and so we had to send it back
somewhere to get fixed.
276
:And I don't remember it having attachments
277
:on the calf area
and the videos that I'm watching.
278
:These ones
have an attachment down to the calf.
279
:Yes. So
280
:what you're talking about is simply
an upgraded version from the ones we have.
281
:Oh, wow.
282
:The original system is lower back
support and upper legs.
283
:The new one has the additional
attachment, which looks like.
284
:That could be very interesting.
285
:I'm waiting for another one
that's going to come out
286
:at some point
where it makes it a full body exoskeleton.
287
:So you have the upper body two
and I think that's when I'll upgrade.
288
:Okay.
289
:So I was looking at these videos
and they were showing,
290
:I think they were in Germany
at an expo of some sort.
291
:And they were having some people
292
:who had a walk walking in pediments and
they were helping them be able to walk.
293
:And I thought that was really cool.
294
:And I was trying to remember,
did I have one with a calf?
295
:And I just like I don't think I had that.
296
:It's a new version that just was launched
in the last few months,
297
:for my understanding, and,
definitely is worth the upgrade.
298
:You know, for people that would need that,
299
:I don't think it's worth it
for me to replace mine.
300
:But the one thing exoskeletons
have been used for a long time
301
:is therapeutic, assisting for people
that have disabilities.
302
:And it is absolutely amazing
what they can do.
303
:There's cases where people can walk
304
:that wouldn't be able to otherwise,
that type of a thing.
305
:So the technology is amazing,
but it just hyper.
306
:Shell is one of the first companies
to bring it as a consumer level,
307
:where you can just go buy an exoskeleton.
308
:There's other companies
309
:that do it now too,
and if this is something
310
:you're in the market for,
these things are expensive,
311
:usually a couple thousand dollars.
312
:They're worth it if you need them,
lower back support, if you're lifting
313
:that kind of thing,
there's a lot of benefit to that.
314
:And you don't screw up your back,
but you've paid a couple thousand dollars
315
:to prevent it.
316
:In my opinion,
if you can afford it, it's worth doing
317
:if you are doing that kind of thing,
318
:like
319
:when we've moved storage units and stuff,
I'll use mine because it just makes it
320
:a whole lot easier.
321
:And that's just the lower body.
322
:The upper body would really help.
323
:Yeah.
324
:You know, so this type of a thing
on the consumer market,
325
:if you're looking at one before you spend
the money, you want to research it
326
:because there's different kinds
that do different things.
327
:There's power, there's non-powered,
you know, all that kind of stuff.
328
:And it's a topic of its own
that really is worth its own conversation,
329
:which maybe we should do again,
because like I said,
330
:the technology has come a long way
since the two years that we got ours.
331
:And what we're seeing on
332
:some of the other things
that are out there
333
:that are coming up, it's even further.
334
:But it is absolutely amazing
what you can do with it.
335
:Unsecured open AI agent posted 53
336
:user images on the internet
without the lab's knowledge.
337
:Are the kids?
338
:Inside joke.
339
:There's different AI agents, and,
there was a thread going on that
340
:these were the children of the other AI's,
which makes it even more creepy.
341
:But the thing of it is, is, I think
what we're seeing here is a situation
342
:where, number one, these companies
need to secure their stuff, obviously.
343
:Yeah, on both ends of it.
344
:Because in all honesty,
345
:one of the just as an example,
there's been more than one recently,
346
:but I believe it was an open AI agent
I could be wrong on on which company,
347
:but it was an AI agent
that had gotten out of some testing shell
348
:and hacked the Australian Health
Authority.
349
:Yeah, I read about that. Yeah.
350
:You know, and no,
that shouldn't have happened.
351
:But the other side of it too,
is we've got to make sure that our systems
352
:are not, you know, to
whatever extent we can, not hackable
353
:because, well,
these things are happening in error.
354
:There are going to be people
that are going to develop rogue
355
:AI agents that can go out
and actually they intend to do.
356
:And believe me,
that's not a future tense thing.
357
:It is happening.
358
:So the reality is, at the end of the day,
while this is made news and,
359
:you know, there's a lot of concern
about some of the things that AI
360
:can do right
now. And I understand all that.
361
:The reality is, is that
it would be better that this happens
362
:from something that is being run
on the side of the good guys.
363
:Go in and secure your systems because it
is really becoming necessary to do that.
364
:And we had a episode a while back
where we talked about using AI to secure
365
:AI against Rogue Eyes,
366
:but that really is the direction
that this is starting to have to go.
367
:And again, at the end of the day,
368
:I would much prefer to see an accent
like this happen
369
:where no data was released
and nothing bad happened.
370
:It just got in, versus
the bad guys being able to do it
371
:because somebody hadn't taken the time
to upgrade their security.
372
:And I know I'm oversimplifying it.
373
:A lot of people spend a lot of time
with this stuff, but this is an issue.
374
:AI is a thing.
375
:It's here and it can be used in this way,
and it makes it important to
376
:secure our systems.
377
:All right.
378
:Microsoft revamps Copilot with code
generation and AI tools.
379
:Speaking of AI,
yeah, they're adding a genetic AI
380
:to products like word and so on.
381
:And that means having the capacity
to act independently, make decisions,
382
:and take initiative
to reach a specific goal
383
:rather than just waiting for step
by step instructions.
384
:So in other words, you know,
go hack the Australian Health Authority.
385
:I am sure that's not the prompt
they gave it, but the point of it is,
386
:is that is what that means.
387
:And copilot I think copilot might have
quit and gone and work for somebody else.
388
:And they're trying to build a new copilot.
But that's just my opinion.
389
:This is a function of AI that Microsoft
attempted to build into windows.
390
:And like with Windows Phone
and some other things,
391
:they haven't done a job
where it's been adopted.
392
:It's just kind of been there.
393
:And I don't know people.
394
:I don't know what it is.
395
:Microsoft does a great job
396
:of operating systems, their data centers,
all that kind of stuff.
397
:We poke fun at them and,
you know, things like that.
398
:But at the end of the day,
they do have the majority
399
:of the operating system
market on personal computers for a reason.
400
:It's because it works
and it's what's out there.
401
:There are other choices, even free ones.
402
:People wouldn't choose for the paid one
if it didn't at least do the job. So
403
:diving through all of that, they've tried
404
:to do adoption of things over the years
to compete with other companies.
405
:One of the other
406
:bigger ones was search engines
competing with Google at the time, Yahoo!
407
:And that's where Bing
and all of this stuff came from.
408
:It's still out there and it still works.
409
:But the market penetration
of these type of technologies,
410
:they've just never really been
too good at it.
411
:And for whatever reason.
412
:That's been the case.
413
:So they're trying to upgrade this.
414
:And I think the upgrade would be great.
415
:I think forcing it into
these systems is not.
416
:And I think that's where they're
probably going to have their problem.
417
:Amy's The Big Bang Theory
418
:sequel return backlash addressed.
419
:Yeah.
420
:So this was a, interesting thing.
421
:Ellen Balke and I apologize to her
if I mispronounced that,
422
:de some comments at Comic-Con:this year that the spin off
423
:from Big Bang Theory that came out,
we've talked about this, yet
424
:Stuart Fails to Save the Universe
is actually a great show in my opinion.
425
:We've really enjoyed it.
426
:Yeah, and a lot of the characters
from the original Big Bang Theory
427
:are making appearances in this new series,
and she's been on twice.
428
:I won't go any further than that for
anybody that hasn't seen it to spoil it,
429
:but for some reason
there's been a lot of pushback.
430
:This is the character
we don't want to see.
431
:I did not realize that she was
a controversial character in the original
432
:Big Bang Theory.
433
:Until I saw it, I thought she was great.
434
:I mean, all of the characters
are so unique and quirky, yet fun.
435
:And because, you know, in the real world,
not everybody is the same.
436
:And and
437
:I could see any of the characters
in Big Bang Theory
438
:being, quote, controversial,
you know, like, oh,
439
:I don't like the way they behave,
you know?
440
:Well that's life.
441
:Everybody's different
and that's and that's the whole thing.
442
:I think that the characters good.
I think the actress is a genius.
443
:She does a wonderful job with something
that's
444
:probably a little more difficult
to play than most, too.
445
:Oh, yeah, I would think so, yeah.
446
:So, and that's my opinion.
447
:Everybody's entitled to Ubu,
but I don't see this being controversial.
448
:And I have seen one of the two episodes
she was in,
449
:and I think she did a nice job, I do too.
450
:I agree with you.
451
:So anyway.
452
:All right.
So what's next on our agenda? Oh.
453
:Bill's rant.
454
:Okay, cool.
455
:It's time for my rant, apparently.
456
:So this actually ends on a positive note.
457
:I just wanted to bring this up
because it's something
458
:I've talked about before
and something to be aware of.
459
:I got to play my first game of pinball
on my own pinball machine last night.
460
:Really?
461
:Spin ball machine called Motor Dome,
and I got it over a year ago now,
462
:and the logic boards in
it were pretty messed up when I got it,
463
:so I've been trying
to go through the process.
464
:I rebuilt them
465
:and I got it to where
466
:it would go into a track mode
and everything like that,
467
:but I could not get it to start a game.
I could not get it to work.
468
:I got on line with all the people
that actually know this stuff,
469
:which isn't me,
and we went through some stuff
470
:and did all the normal things
and just couldn't get it figured out.
471
:So I get in there
and to go down this rabbit hole
472
:just a little bit in a little bit of time,
I have
473
:there's a device in
electrical engineering called a mOSFET,
474
:and it's basically a switch.
475
:It's a form of a transistor.
476
:And you use a small amount of voltage
to turn on and off a larger motor.
477
:In this case, they're used
for firing the flippers and other things.
478
:So you don't really want to pull
the high voltage through the buttons.
479
:Although before everybody starts
typing this,
480
:I know they did that
in some of the early machines.
481
:But they protected you
with a thin piece of paper so you wouldn't
482
:get shocked.
483
:So we were all, okay, sarcasm sign there.
484
:But in the case of this,
I'd replaced the mOSFET
485
:and they were testing out normally,
and we finally went back through
486
:and checked everything else. I'm
thinking, did I get defective components?
487
:No. They're fake.
488
:That's been the problem all along.
489
:And anybody that's working on this stuff,
you've got to check these things now.
490
:I didn't at that time. No to do it fake.
491
:Yeah.
492
:My god they are MOSFETs and they do switch
which is why they sort of worked.
493
:But the number on them,
the ones that I needed are more expensive.
494
:So they rebadged a cheaper one
and then sent it over.
495
:And that's the whole thing
that I've been having.
496
:So now I need to shop
at replace the rubbers in it
497
:and everything like that,
but it does work.
498
:So that's my rant of the day.
499
:Check your components.
500
:You do really have to test them
now before you use them.
501
:Or you might go around in a circle
for a year.
502
:This is user friendly 2.0.
We'll be back after the break.
503
:Welcome back.
504
:Jack us out
505
:online user friendly dot show is your one
stop for everything user friendly.
506
:Send us your questions, send
us your comments, get us your updates.
507
:We are going to be announcing our Season
of Giving candidate this year.
508
:Coming up in about two weeks
and that will be on the website.
509
:And you can get access to that before
everybody else at User Friendly Dot show.
510
:So again, your one stop. Check it out.
511
:Well guys
October is Cybersecurity Awareness Month.
512
:And this is a time of year
where we get joined by Jessica Kearney
513
:with the Travelers Institute,
where they do workshops on cybersecurity
514
:and getting your systems for your business
set up and ready to go
515
:and have a lot of good information
out there.
516
:We like to cover this every year,
because this is one of the key topics
517
:that everybody is concerned about,
because hacking is still a thing
518
:and probably will be for a long time.
519
:So there are ways
that you can protect yourself,
520
:and there are a lot of things you can do.
521
:And actually one thing I will say
522
:a little bit of a spoiler alert this year
more people are doing it to some extent.
523
:So with no further ado,
let's go to our interview.
524
:Joining us now, Jessica Kearney
with the Travelers Institute.
525
:Welcome to user Friendly.
526
:Welcome back to User Friendly.
527
:Thank you so much for having me back.
528
:It's a pleasure to be here.
529
:So let's just go ahead and dive right in.
530
:For anybody that doesn't know, let's start
here.
531
:Tell us about the Travelers
Institute. Yeah. Of course.
532
:So the Travelers Institute is the public
policy division of travelers.
533
:Travelers, you may know,
is a leading property casualty insurer.
534
:So we help protect
535
:all the things that are important to you
your home, your car,
536
:your valuables, your business.
537
:And at the Travelers Institute,
where I sit with my team,
538
:we get to take on different public
policy issues
539
:that impact our customers,
our business partners
540
:and the broader communities
where we do business.
541
:You know, in practice,
what does that look like? We're hosting
542
:educational programs, webinars, podcasts,
just like this one, bill.
543
:We speak at conferences, and much of what
we do is free and open to the public.
544
:It's amazing.
545
:And being that
546
:we're already here, October is National
Cybersecurity Awareness Month.
547
:Now, why is this important to travelers
and the Travelers Institute?
548
:Yes. So as you can imagine,
being in insurance,
549
:we're all about risk management.
550
:And cyber security is, you know,
a top risk management issue for us today.
551
:Cybersecurity has actually been
a major focus of ours
552
:at the Institute
for just more than a decade.
553
:And we have an educational platform
that we call
554
:cyber prepare, prevent, mitigate, restore.
555
:So those are kind of
556
:four bundled steps that you need to take
when you're tackling cyber security.
557
:We have hosted 85 educational programs
across 43 cities.
558
:We've been all over the country
with nearly 50,000
559
:attendees
or views for our virtual programs
560
:on the name of spreading awareness
about cybersecurity practices.
561
:And you mentioned October.
562
:This month is Cybersecurity
Awareness Month.
563
:And so while at the Institute,
we talk about this all year round.
564
:I think October nonetheless
565
:is a really good opportunity
just to step back and remind folks, remind
566
:everybody listening, you and me,
that our individual actions do matter.
567
:And they ladder up
568
:to our organizations and certainly
in our personal lives as well.
569
:So this is a really good time to step back
and to take stock of of what you do.
570
:And I will say that every year
our company fields a pretty extensive
571
:study called the Traveler's Risk Index,
really looking broadly at business risk.
572
:And I will say
cyber threats are the number one
573
:this year, overall business concern
among survey participants.
574
:That's the fifth time in eight years.
575
:And I will tell you
cyber beat out economic uncertainty.
576
:So of all these survey takers,
577
:they put cyber as their number one
concern ahead of economic
578
:uncertainty as well as things
like medical cost inflation.
579
:And those are no small issues, right.
580
:For for business leaders out there today.
581
:So there's there's lots to talk about.
582
:There's lots of encouraging news too.
583
:But this is a
584
:really a key issue in risk management,
and one that we're hoping to continue to
585
:spread the word about.
586
:So you
were talking about some of the programing
587
:and some of the specifics of this.
588
:Tell us a little bit
about what actually goes into that
589
:to provide information
to raise awareness about cybersecurity.
590
:What does somebody see?
591
:Yeah.
592
:So I mean this month
October is really the perfect example
593
:because we have five different
educational programs to help business
594
:leaders really one better understand
the threat landscape.
595
:Right.
596
:So what's happening out there
to learn the basics of cyber hygiene.
597
:So there are certainly,
you know, things that you can purchase
598
:like cyber insurance
or other kind of third party services.
599
:But there are also
600
:a lot of low cost, no cost, everyday
best practices that you should be doing.
601
:And we talk a lot about those as well.
602
:So just an example.
603
:Just a few days ago,
we hosted a webinar featuring
604
:two former cybersecurity leaders
at the white House and the Cybersecurity
605
:and Infrastructure Security Agency,
that's America's cyber defense agency.
606
:So we had a really good conversation
about the state of cyber risk today.
607
:So we invite everyone to to come and watch
608
:the replay of that on our on our website,
institute.travelers.com.
609
:And then all throughout
the month of October,
610
:we're going to be releasing a series
of four kind of short snack
611
:podcasts, digging into different topics
on cyber security.
612
:So we've got a podcast coming out on AI's
impact on cyber vulnerability.
613
:We talk about the dark web and all the
standard best practices that I mentioned.
614
:But so we have a lot,
a lot coming out this month.
615
:And I think that really just gives you
a flavor
616
:of some of the things
that we're putting out on cyber security.
617
:So I want to circle back to
618
:one of the other things that you mentioned
earlier in the interview.
619
:And that's the Cyber Risk Index.
620
:And travelers
released the updated one for:
621
:I know, and you had said that
according to the the index, cyber threats
622
:reclaim the top spot is a number one
overall business concern,
623
:which is without question.
624
:And as you said, ahead of economic
uncertainty and medical cost inflation.
625
:But steep dive into that a little bit.
626
:What is this tell you that this cyber beat
everything else
627
:on the list
and where people are really at.
628
:Well, you know,
629
:I think it tells you that it's become
certainly a core business issue.
630
:And I'll give you a little bit
631
:more kind of behind the behind
the curtain on the travelers risk index.
632
:So we surveyed more than:
633
:decision makers at companies of all sizes
across the country.
634
:And I think, you know, a high level,
the really interesting story here is
635
:that businesses are more cyber aware,
they are better
636
:protected and more confident than in years
past about the steps they need to take.
637
:However,
you know, threats continue to evolve.
638
:And certainly we have AI
639
:and some of the downstream implications
of that when it comes to cybersecurity.
640
:We talked a you know
641
:a lot about on our podcast earlier
this week, our webinar earlier this week.
642
:But but for the risk index, we're seeing
that companies are taking more action
643
:so that that's very encouraging.
644
:Firewall use was up.
645
:More people are backing up their data.
646
:They're patching their software.
They're doing the employee training.
647
:All of those numbers were up year
over year from:
648
:And we know there's more work to do,
particularly around AI.
649
:So in some ways,
AI has showed up in companies
650
:faster than some of them could put out
governance practices for.
651
:Right.
And I think we all we all know that.
652
:And we all feel that as we all
adopt it into our everyday lives.
653
:But we found as part of this survey
that 9 in 10 businesses
654
:tell us AI is already part
of their workday with their employees.
655
:However, only 4 in 10 businesses,
have or sorry
656
:for and ten businesses have people using
AI without any guardrails.
657
:So without any AI,
658
:governments or guidelines out there
for for their employees to use.
659
:And nearly half of business leaders
surveyed really said they worry
660
:about the lack of visibility into how
AI is being used across their companies.
661
:And let's be honest, right,
you can't govern what you can't see.
662
:So I think one of the things that
663
:we're thinking through as we're seeing
these results is something simple,
664
:like conducting an AI audit
at your company is really
665
:an immediate and foundational step
that a business can take.
666
:So cataloging
which tools are in use, who's using them
667
:and what data they're touching
is a really good first step.
668
:If you have no
AI governance system yet in place
669
:and like you say,
you can't work on what you don't know,
670
:AI is something that has come in
to be such a thing that we all use
671
:so quickly, and the technology itself
is even still being developed.
672
:We see about that type of thing,
you know, out there.
673
:So what you're saying. Absolutely.
674
:Very much makes sense.
675
:Now, I don't know if this is a positive
number, but according to your research,
676
:businesses experiencing
a cyber event have dropped a little bit.
677
:So last year it was 25% or 1 in 4.
678
:This year it's 1 in 5 or 20%.
679
:Are you seeing this
because the companies are getting better,
680
:or is just the nature of the attacks
changing?
681
:So I think there are really encouraging
signs, as I mentioned,
682
:that businesses are getting better
at protecting themselves.
683
:And I think we're definitely seeing
that in the data.
684
:Every preventative cyber measure
that we tracked saw increased adoption
685
:compared to last year.
686
:So that is absolutely great news.
687
:I mentioned we're seeing more firewall
use, more data backups, all the things
688
:yet at the you know, at the same time,
the percentage of businesses
689
:reporting a cyber event declined,
which is which is great.
690
:I can't say definitively from this survey
that one caused the other.
691
:But I do think it's really,
really encouraging that businesses
692
:are stepping up to the plate, identified
this as a core issue, and
693
:they're working on it.
694
:Okay.
695
:Now if you go online or, you know,
talk to certain people and ask you
696
:the cyber attackers
are you get this image of some individual,
697
:usually in a dark cloak
where you can't see their face
698
:in front of a computer screen that shows
stuff from the movie The Matrix.
699
:I'm assuming that's
probably not exactly accurate.
700
:Who are the cyber attackers
and what are they actually want?
701
:Who do they target?
702
:So yeah, this is really
this is a this interesting one.
703
:So there are criminal hackers.
704
:There's also state sponsored actors.
705
:And there's even of course
706
:activists who may be motivated
by social or political objectives.
707
:I will tell you,
708
:I mentioned that we've hosted
all these programs across the country.
709
:We invite community
members and business partners,
710
:and you can literally see
the audience physically react.
711
:When we talk about how these threat
712
:actors have built business
platforms around this.
713
:So they run this just like anyone
would, would run a business.
714
:And one of the episodes
of our upcoming podcast series this month
715
:is actually talking about the dark web,
and our team at travelers
716
:kind of breaks that down and helps
people understand what that is,
717
:but they describe
almost like a marketplace or a trade show,
718
:even to use their words,
where these groups coordinate activities
719
:and they even advertise or sell
things like malware or stolen credentials.
720
:So it's, you know, in some cases
may even be on a subscription model.
721
:So it's it's definitely a,
you know, a business in and of itself.
722
:And I think, you know, all of that said,
723
:the idea is to make it less easy for you
or your organization to be the target.
724
:Right?
725
:So don't be the house that leaves
the unlocked car in the driveway
726
:with the keys in the glove
compartment. Right?
727
:You don't be
don't make yourself the easy target.
728
:There's there are all of these steps
that you can take, cyber hygiene
729
:and otherwise.
730
:Just to make sure that you're doing the
most you can to not be the easy target.
731
:Yeah.
732
:And one of the other things, too,
733
:is these type of technologies
are starting to come into their own.
734
:It's not quite as open
road as it was even a couple of years ago.
735
:So it is a good point.
736
:So let's talk about your podcast series
starting this month
737
:or covering this month, I understand is
you're actually getting a former
738
:white House and DHS cyber security leader
or leaders in the plural on that.
739
:So let's talk about that a little bit.
740
:Yeah.
741
:So one of the things we
742
:really value at the Travelers
Institute is bringing
743
:different perspectives to the table.
744
:And I know you can appreciate that, given
745
:that given the podcast
that you're hosting here.
746
:But so at travelers,
we pull on more than 170 years
747
:of data driven risk management expertise.
748
:And then, of course, we're combining that
with the expertise of 30,000
749
:plus employees.
750
:So we are certainly bringing our lens
from insurance and risk management
751
:to these conversations.
752
:But as we know, cybersecurity crosses
not only business but also tech,
753
:public policy, national security,
these really big issues.
754
:So there's tremendous value,
755
:bringing all of those perspectives
and leaders into this space.
756
:And I think our audience gets
757
:the most well-rounded view of
with all of those different perspectives.
758
:So our in-person programs in cities
have featured speakers from the FBI,
759
:the Department of Justice system,
as I mentioned.
760
:And the webinar that we just hosted with
the replay will be coming out this month
761
:in October, was with Jeff
Green and Nicole Tisdale,
762
:both former cyber leaders
at the white House and at Cisa.
763
:And, they have some really great eye
opening experience.
764
:So it's you know, our goal really
765
:is to make these complex issues
practical and accessible for people.
766
:And I think they do that,
that really well.
767
:How do people find your podcast
and what's the name of it?
768
:That probably would be a good thing
to cover too.
769
:Yeah.
770
:So you can find all of our programs
that institute.travelers.com,
771
:and we have a Wednesdays
with Woodward webinar
772
:series hosted by our Travelers
Institute president John Woodward.
773
:We also have a podcast, Travelers
Institute Risk and Resilience podcast.
774
:And you can find that
wherever you get your pods.
775
:Perfect, perfect.
776
:All right, so let's look a little bit
broader approach.
777
:What is travelers
778
:recommend to business leaders
who want to better
779
:protect their organization
against these threats.
780
:So I'm a business owner.
What do I do? Yeah.
781
:So I always like to start with backups
kind of as as number one.
782
:So probably all know and have heard that
we need to back up our data.
783
:Right.
784
:All of those files
that are business critical
785
:that you couldn't run your business
if you, if you lost access to those.
786
:So, threat actors know
you may be more likely to pay a ransom
787
:if you don't have access to your files
or your business is shut down.
788
:So backups can even be a target
in some of these cases.
789
:But the folks on our teams
like to talk about the 321 methods.
790
:So keep three
complete copies of your data.
791
:So that's the three
on two different types of media.
792
:So it could be a hard drive
or the cloud sets three and two.
793
:And then one copy
should be off site and offline.
794
:So meaning a cyber attacker cannot access
it, cannot download it,
795
:edit it delete it.
It's completely untouchable.
796
:So three copies, two different types
of media one kept offsite and offline.
797
:321.
798
:This is just a quick
nomenclature to remember it.
799
:And in addition I have to add this.
800
:You are actively on a schedule
testing your backups.
801
:So an untested backup is a smoke detector.
802
:You have never checked the battery
on, right?
803
:It's just sitting there
and you're wondering
804
:if it's really going to work
when you need it.
805
:It is a bad day
806
:if you have a cyber incident
and your backups
807
:have been feeling for months and no,
no one simply knew about it.
808
:So having a robust test
schedule is really is really critical.
809
:Yeah, and I can't emphasize that enough
because the reality is
810
:if you've done everything right,
811
:but it doesn't work, well,
it doesn't matter, you know.
812
:And the other thing,
813
:the three, two, one philosophy,
the bad guys know you have backups.
814
:And this is an important thing
that I always try to point out with this,
815
:because they're going to try
to find those backups.
816
:So having one that is offline
like you specified is so important
817
:because they can't get to it
if it's done properly.
818
:And it's not that hard to do it right.
819
:It's just again,
820
:you have to have like what you talked
about a method in place for that.
821
:All right. So I know you covered it
a little bit earlier, but go ahead.
822
:And first of all, give us any last minute
information you'd like to talk about.
823
:And again where do our listeners
go to find all this information.
824
:Yeah.
825
:So I guess the last thing I'll leave
the audience with is have an incident
826
:response plan. Just know in advance
what you're going to do.
827
:Who's going to do it.
828
:You don't want to rely on on memory.
829
:When one of these things happen,
they tend to happen at, you know,
830
:weekends, holidays, all of those things
and have physical printed copies, right?
831
:So if you can't get into your system,
it's really important
832
:that you have a physical piece of paper
with that plan, with phone numbers
833
:that you can reach your team, all of that.
834
:So it doesn't have to be very complex,
but just has to have your roadmap on it.
835
:And I thank you so much in advance
for the time.
836
:And I invite,
you know, all the all the viewers to come
837
:listen to all of our Cyber Awareness
Month content.
838
:Again, that's the Travelers Institute
Risk and Resilience podcast.
839
:And you can view
our webinars@institute.travelers.com.
840
:Jessica, as
841
:always, thank you so much for joining us
and welcome to fall.
842
:Thank you.
843
:Thanks so much for having me again.
844
:So yeah, you know, it's interesting
to think about this stuff.
845
:I, I know when we first started doing
846
:business back, Gretchen,
you remember in the mall in Reno,
847
:you didn't need things
like cybersecurity insurance.
848
:You you did a firewall, sort of.
849
:But, and I say, sort of
I mean, the firewalls of those eras
850
:were more suggestion
compared to what we have today.
851
:Yeah, but it's like the password
852
:security was,
well, less than adequate, right?
853
:You mean I'm not supposed to use the word
password for my passwords?
854
:Yeah. Yeah, exactly.
855
:I stopped
using the word user for my username,
856
:mainly because it was already taken
on everything, but.
857
:Yeah.
858
:No, I actually, you know, it's interesting
you bring that up.
859
:I think we're going to see the end
of username password log in pretty soon.
860
:And it is something that's still out
there.
861
:It's very legacy
and combined with MFA and stuff.
862
:It is reasonably safe.
863
:But there are even ways
to get around that.
864
:And I know we have a back end that we use
on the system here called workbench,
865
:which manages the show,
and we've got people that subscribe to it,
866
:all that kind of stuff, and endeavor
to keep it very secure.
867
:And we meet the requirements of
the networks that we are distributed on.
868
:And, you know, over the years
that's been updating things.
869
:We usually try
to stay a step ahead of everything
870
:just to have it in there and, you know,
more or less are able to do that.
871
:But I think that:
872
:the year that we stop using passwords
completely on our own system
873
:and go to an ID key
or something of that nature.
874
:And we're still looking into
and how does that work?
875
:So basically what happens
is is it an object or or
876
:what is it that you have to carry around?
877
:No. Well, it can be I mean, there's
a lot of ways to do it, actually.
878
:It's a good question.
879
:And what it comes down to it,
you're dealing with some,
880
:you know, some different things.
881
:The way that I usually do it
is I for those kind of sites is I have my
882
:windows machine as a for example,
authenticates me through a Pin code
883
:or through a facial image.
884
:You know, that kind of a thing.
You can do that on your phone or whatever.
885
:So what you do is you hook that device
into the site that wants the recognition.
886
:So when it wants to authenticate,
that's how you authenticate it.
887
:So in the case of the computer
I just put in my Pin code, you know,
888
:see now I block my camera because this was
889
:something that years ago
we were concerned that our,
890
:our, our cameras on our computers
were spying on us.
891
:It's still a valid concern, number one.
892
:And number two,
you don't have to use facial recognition.
893
:That's just one way of doing it.
894
:Okay, so you could get an RFID implant
and a reader and do it that way.
895
:I mean, you know,
896
:that might be a little unusual,
but the point of it is, is the Pin code.
897
:You could scan a QR code from your phone,
and usually you set up multiple ways
898
:because you want to be able to
authenticate if you're not on one device.
899
:Right.
900
:So a lot of people use their phones
for that.
901
:You can usually have more than one setup
just depending
902
:on the machine that you're on
and that kind of thing.
903
:The site you,
if it's program correctly, will know
904
:that you're authenticating
through another method.
905
:It doesn't care
what as long as the authentication
906
:token is created and it's something
that's it's supposed to do it.
907
:But you know, again, and then even sites
908
:that have really done away with this,
like your Microsoft account and stuff,
909
:is pretty much only utilizing a message
910
:to your text message on your phone
or some other form of authentication.
911
:You still can use the password, but
it is very limited and it usually will.
912
:It better come along with multiple layers
of security to do it.
913
:So I have a question if this.
914
:All right.
Let's say you do the visual thing.
915
:How does that keep a bad guy
916
:from taking a picture of you
and holding it in front of the camera?
917
:Well, I mean, you know, they
the same question could be asked
918
:if a fingerprint reader,
can they just cut off your finger?
919
:Now, I will tell you one thing.
920
:If I'm to a point where something like
that's going to happen on unlocked forum,
921
:so you know,
they're not going to have to do that.
922
:It's it's that kind of a thing.
923
:Facial recognition can tell the difference
between a photograph and a live image.
924
:At least I decided to ask the question,
you know,
925
:but now there's also comes down
to some other things when you, you know,
926
:ask about that.
927
:Properly working
facial recognition can tell the difference
928
:between a still image.
929
:So if you get your, you know, brand name,
hardware and stuff that works properly
930
:and that kind of thing,
you're reasonably secure
931
:if you cheap out on it
or get something that's not built too well
932
:and it can authenticate and it's not
supposed to that way, that can compromise.
933
:If you get Fred's funny software,
then you're going to be sorry.
934
:In this case,
Fred's funny hardware, but yeah.
935
:Okay. Okay. Fred's funny hardware.
936
:But that being said,
937
:you know,
we are getting things more secure.
938
:And in the first segment, we had talked
about a lot of hacking things.
939
:There are a lot of our topics
this week were about that.
940
:And the thing of it is, is I look at it
things like AI, hacking, other AI
941
:and that kind of thing. No,
that shouldn't be happening.
942
:But as soon as we get into quantum
computing,
943
:which is right around the corner,
in fact it's well past proof of concept.
944
:Now, they're going to have to secure
all this stuff better anyway they are.
945
:It just is that simple.
946
:You know, I don't know, Bill.
947
:What do you think about all this?
948
:Do you consider stuff secure?
949
:No, it's
950
:not even.
951
:I mean,
952
:yeah, like he said.
953
:And with a quantum computing
around the corner, nothing we have
954
:currently even comes up to the idea
of what they can do with quantum computer.
955
:Yeah.
956
:And so we're going to see this
definitely evolve.
957
:And even with with quantum
computing really comes online.
958
:Even things like doing
facial identification stuff
959
:that's going to have to be locked down
and probably made a lot more secure too,
960
:because basically the way
that you get around that and again,
961
:this show is not meant to be a hacking
class, but 10,000ft view is
962
:if you can fool the computer into thinking
it's seeing what it's expecting to see
963
:and it unlocks the account,
that's a good way to hack.
964
:And one of the reasons
that quantum computing makes this a thing
965
:is because the speed that it's able to run
out, it can do the comparisons
966
:and essentially create
the authentication token,
967
:even using their level of encryption
and hash and all the different things
968
:that we use today very, very quickly.
969
:So just like the
970
:old databases that would could run,
you know, however
971
:many passwords a minute until they find
the combination that works.
972
:How do we deal with that?
973
:You lock it out after three tries
so it times out and can't have the speed.
974
:Well,
you know, some of those type of tricks.
975
:We're going to have to work
into some of these other things.
976
:But more on the back end.
977
:And I think we're quantum computing is
going to affect hacking into systems more.
978
:It's not going to be so much
an individual user account.
979
:It's going to be compromising
the way a given user account works on a
980
:given system, and then being able
to unlock those system resources globally.
981
:So, you know, yeah, that makes sense.
982
:Yeah.
983
:And bad guys are usually after money.
984
:So money, medical records,
identity theft.
985
:And I guess that is all money
at the end of the day.
986
:The money at the end of the day.
987
:Yeah.
988
:I mean, there's only two situations.
989
:Money and destruction.
990
:Yeah. Destruction, extortions.
991
:Another one, which is usually for money,
but sometimes for other things.
992
:The point of it is,
993
:is it's not something that any of us
want to ever have to deal with.
994
:And whatever the motivation is most
commonly is money.
995
:At the end of the day,
the bad guys have 24 hours a day
996
:to work on this, and usually the good guys
have eight hour shifts.
997
:So that has always been a problem
998
:and you stay
a step ahead of these things.
999
:But that's why when things like zero day
attacks come out, like the story
::
we were talking about in the first segment
with a Kite Works,
::
their initial thing
was, you need to shut your system off
::
until we can fix this,
and if you don't, you will get hacked.
::
Oh, I'm glad they sent that out because,
yeah, it's at least being honest, right?
::
You know, it's still.
::
Anyway,
all that being said, you know, out there,
::
I guess the best way to put
this is stay safe.
::
Stay secure,
you know, keep up on your passwords.
::
Although a lot of
this is stuff that you can't affect.
::
But until next week,
this is User Friendly.
::
2.0 keeping you safe on the cutting edge.
User Friendly 2.0.
::Copyright:
::
by User Friendly Productions, LLC.
::
All rights reserved.
::
The views and opinions
::
expressed on this program
are those of the individual participants,
::
and do not necessarily reflect
those of this station, platform
::
or User friendly Productions, LLC.
::
Requests for content, interviews,
disclosures, and other information
::
may be viewed
or submitted at UserFriendly.Show.
::
Thank you for listening.

