Posts

Part Two: Building Your Home Lab

Image
  Last week we talked about why you might want to own a home lab, if you're keen on the technical side of cyber security. The first impediment to building a home lab can be the cost of equipment, so let’s break through that barrier. Even an older laptop, say from the last 7 to 10 years, can often be more than capable for starting out. If you only have one laptop and it’s your “daily driver,” you won’t want to turn it into Dr Frankenstein’s monster. A better plan is to install a type 2 (host-based) hypervisor such as VirtualBox , and then create your world of fantasy inside it. A type 2 hypervisor is simply an application you install on your existing operating system, such as Linux, macOS, or Windows. Within it, you can create entire systems. For example, you can install and use a Linux operating system even though your laptop runs Windows. This is an excellent way to learn a new OS. Each of these new systems is called a “ virtual machine .” Under the hood, a VM is really just a fi...

What’s in Your Home Lab, and Why I Ask That in Job Interviews

Image
  Anyone who’s had the immense pleasure of sitting across the table from me in a technical job interview knows I like to ask candidates about their home lab. The question usually gets anything from a proud grin to a look of pure shock. I don’t ask because I expect colleagues to spend their evenings “working” in a lab at home. I ask because I want to see what sparks their curiosity - the passion that drives them. And yes, I’ve hired people who’ve said, “Actually, I don’t have a home lab,” because they’ve gone on to share other qualities that matter just as much. A software developer might point me to their GitLab repository or the open-source projects they’ve contributed to. Thinking about this recently over another coffee, I came across a ZDNet article that explains why home labs are worth considering . The author compares a home lab to an artist’s portfolio - a place to showcase skill, knowledge, and the ability to keep up with trends. That portfolio-like quality can be the differ...

Data breaches and old passwords

Image
  TL;DR: Heard about the "16 Billion Credentials Leak"? Don't panic, it's mostly a repackaging of older breaches. ✔ Use a password manager ✔ Enable multi-factor authentication (MFA) ✔ Check your email on Have I Been Pwned ✔ Take action where needed, but stay calm and take a risk-based approach. ☕  And maybe... have a coffee while you're at it. There's plenty of chatter in the news about the " 16 Billion Credentials Leak ". Once again, it's claimed to be " the biggest breach in history ", the result of (insert latest buzzphrase here) "Infostealer malware", and to really  maximise click-bait potential, media outlets throw in "Facebook, Google, Apple services are at risk". Sure, there's elements of truth in these claims, but let's remember what really matters: a calm, measured, risk-based approach. Even better if the discussion can be had over a nice cup of coffee 😉  I've extolled the virtues of password ma...

Anyone can fall victim to scams

Image
I don't like victim blaming. You could say I'm a victim of the avo-smash trend , accuse me of being "one of them", tell me I'm a follower not a trend-setter, and ask when I'm going to switch to cale-based foods . Or you could empathise with me and tell a story about when you've fallen victim to a similarly large nation-wide fad to make me feel included and safe whilst I chow down on delicious sour dough bread smothered in pale green goodness. Which of those two paths will you choose? Now you're in that mindset, let's talk about cyber scams and remember we're all human and we're all unique. That means we all learn differently, we comprehend and process information differently, and we react differently. That's a good thing!   When (not if!) each of us makes a mistake, it's up to everyone to work together to help recover from the mishap and take steps to reduce the likelihood it'll happen again. Done well, this turns t...

"I told you so!"

Image
  I used to be head of cyber security for a store that sells peanuts. Well, it wasn't peanuts, but for the sake of this story and several confidentiality agreements I've signed over the years, let's go with that. Every month or so, all of the cyber security peeps from the peanut stores all around the country would get together and share stories. It was cathartic in a way: one would say "last month I lost nearly half a million dollars in peanut sales to cyber fraud!" and all would commiserate and offer to buy drinks at the pub that evening for the unfortunate soul who'd lost the most.  Importantly though, we'd also share intelligence. We never discussed what sort of peanuts we each sold, or what new and amazing flavours our store would be introducing in the coming months, but we would certainly share details about the types of cyber fraud we'd observed in our stores recently. This elevated the cyber security resilience of all peanut stores , without giv...

Soon to be "ex" X

Image
We've all had the experience; a coffee shop staffed by frightened employees ducking in fear each time the manager barks the next round of orders. It's unpleasant for customers, and usually the fearful staff end up making a sub-par coffee, but we tolerate it in order to get our caffeine fix.  What about that other coffee shop - the one with the friendly owner who welcomes everyone in and speaks kindly (but firmly, of course) to their team? The coffee always tastes good, doesn't it? And have you ever noticed after a few months or even years that the team hasn't changed much - it's mostly the same staff. Why? They feel secure in their workplace. They know they have a job to do and they do it efficiently, and usually they "go the extra mile" because they genuinely want to. They know the boss treats them kindly (but firmly - boundaries are important), so they WANT to perform better to please their boss.  Sure it doesn't always work, and occasionally a less-...

What did you just dump?

Image
Imagine finishing a delicious cup of coffee and availing yourself of the facilities in your workplace, and on the door of said restroom you notice an educational message from your cyber security team: "what did you just dump?" For context, there is an accompanying photo of a waste paper basket showing discarded papers with credit card numbers, expiry dates and CVVs clearly visible. Simple message; think about what you throw in the trash and ensure you shred confidential and/or personally identifiable information, however it's delivered in a way that you'll probably never forget! This didn't actually happen. My mentor suggested it but management shut it down, thinking that it would not resonate with the conservative nature of the organisation we worked for. However I'm sure you get the point - and with a creative mind, you can come up with one or many ideas of your own to educate those in your workplace about cyber security risk management. Remember, you don...

"Another day, another breach"

Image
"Another day, another breach." I grew tired of hearing that phrase around about 2019! Even back then I thought it's time everyone acknowledges that breaches are inevitable.  Many of us already have, and that's why the cyber security industry has a fantastic set of standards such as NIST CSF to draw upon for incident response and preparedness. However what I mean by "everyone" is just that - not just cyber sec pros. Business experts, CEOs, tradespeople, school teachers, the whole lot, all must acknowledge breaches are inevitable, and be prepared. I'm going to compare this to preparedness for other types of disaster, for the sake of the point I want to make. We accepted long ago that floods, fires and droughts were inevitable, so we have a strong culture of preparedness for these. I'm not going to delve into the truly devastating effects of natural disasters, other than to briefly point out that data breach incidents can result in similar...

Nerding out over patterns in stolen PINs

Image
Has anyone ever completely nerded out over numbers, patterns and maths? I saw this article on ABC News about commonly used PINs, and I clicked into it not expecting to be quite this interested. The authors have taken the four digit PINs from Troy's Have I Been Pwned site (using the API) and split them into the first two digits and the last two, so that the data could be plotted on an X-Y graph. The result is a graph which shows visually the most common combinations of digits. It's a brilliant idea, because it makes the task of identifying patterns very simple, using visual means. Unsurprisingly, PINs like 0000, 1111, 1234, 1212 etc are the most common. The repeated digit combinations nicely show up as a straight diagonal line. There's also a strong representation for PINs beginning with 19 and 20, because these form the first two digits of the birth years of everyone alive today. The visual representation also shows some popular PINs that I didn't expect to be common, ...

I for one welcome our new AI overlords

Image
Everyone is talking about AI. Everyone from politicians to the crowd at my coffee shop, and everyone has either a fear of it, or an enthusiastic story about how it's transformed their lives.  A teacher writing up a behaviour incident report threw a bunch of bullet points containing the raw data at ChatGPT, and it responded with a business-like email, formatted and ready to send (after adding the sensitive info like names etc manually). A small business owner chucked a few words at CoPilot and it formatted that into a well written social media post, ready to go. The fears that people speak of are either job redundancy or "will humans never think for themselves again". I see the emergence of these tools as just that: tools to get a job done. Just like the invention of "wireless" (radio comms), the telephone, the transistor, computers etc, a set of new pathways are created. What are we doing to facilitate the creation of those pathways? The teachers I know ha...

Kangaroo-related passwords

Image
Everyone loves a good story. And every time a cyber security breach occurs, the pros spring into action, attempt to recover what was stolen, and deal with the aftermath. Perhaps one day I'll blog about a few of those incidents, because there's some fascinating stories to be told! For now over this cup of coffee, a thought occurred to me: Troy Hunt's blog on info stealer malware logs is readable on multiple levels. I hadn't considered this earlier, but the information he often writes about can be used by individuals who are tech-curious, right through to professionals in cyber, IDAM, etc. For example, how many times have you explained the perils of malware on the interwebs to non-tech friends and family and wished for written resources and advice to point them at? Amanda-Jane Turner also has a fantastic set of resources for that . Troy's opening paragraph in that blog is ideal for this purpose. He states quite clearly a few simple actions which could lead to passwor...

A voice in my imagination

Image
Small business cyber security risks, part 4: In the last few blogs we focused on advice for small businesses, although really this has been relevant for all of us whether we’re talking about personal, small or large business information security. Reaching for the ideal situation is certainly important and, in many cases, particularly for larger businesses, it’s the law . However last week in my imagination I heard the quiet voice of a small business owner saying, “but what if I’m struggling just to stay financially afloat and keep customers happy, I know cyber security is important, but I just don’t have time unless someone tells me exactly what to do!”  Perhaps that thought came to me because I was looking on with admiration at our local cafe, amazed at the hard-working team, always with smiles on their faces and a kind word for everyone. Whilst they're not struggling financially, I know how busy they always are, and I wondered how they manage information security risk. In a rare ...

Impossible travel, MFA and making passwords easier

Image
Small business cyber security risks, part 3: In my last blog we discussed passwords, including their major shortcomings . In this next blog we'll dive a little further into passwords, particularly in a work environment, but firstly we'll discuss one of the most common mitigating controls for many of the shortcomings of passwords: multi factor authentication (MFA) . You'll almost certainly have used a form of multi factor authentication before, most likely your financial institution will send you a prompt on your phone or perhaps an SMS when transferring funds. The usual form of MFA is the concept that you’re using something you know (your password) and something you have (which is the SMS, or the mobile phone prompt), although there’s a little more to it which we’ll discuss later in this blog. It’s far more difficult for the attacker to get hold of both of those things at once to impersonate you and carry out financial transactions on your behalf. Not impossible, but very u...

Correct horse, that's a battery staple!

Image
Small business cyber security risks, part 2: In my last blog in this small business cyber security risk series, we looked into third-party risk and how small to medium sized businesses can manage their exposure. We covered quite a range of concepts quickly, and as I wrote that blog I’d hoped to revisit each one in a little more depth, one at a time. That’s exactly what we’re going to start doing with this blog, and the first concept I’m going to cover is passwords. Yes, I know, it’s not a fun topic, and I just heard a collective groan from all of you as you read that last sentence! Bear with me, please. In my opinion, the problem with passwords is the IT industry didn’t get it right from the start. Technology evolved relatively quickly compared to say, the automotive or building industries. As consumers, we’ve only had technology that needed passwords since the mid to late nineties. In the business world, some of us encountered mainframes and their “ dumb terminals ” du...

Founding a cyber champions club

Image
Small business cyber security risks, part 1:  Many of the cyber security professionals around the globe are concerned about third-party risk . What exactly is that, and why should you care? Personally, I like to apply what I consider to be a layer of common sense across these sorts of things, but I feel that I’m very privileged to constantly learn from some of the very best cyber security professionals in Australia and nearby, so perhaps what I assume is common sense is actually their knowledge “bleeding through” me! So let me impart some of that knowledge I’ve accumulated, and hopefully you can benefit from it as I have done. Let’s consider a small business, a hairdressing salon. Typically the team interacts directly with clients of course, although in order to service those clients, there’s very likely a CRM (customer relationship management system) to handle appointments, hold client information, and possibly even manage a pipeline of new clients. Additionally, there’l...