Listen to this episode

Living In a Smart Home

0:0033:15

Recorded March 2022. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

In this episode of Encrypted Ambition, BJ and Craig of Petronella Technology Group discuss software supply chain risk and why knowing where software is made matters. Craig explains that Veeam backup software was coded in Russia and later sold in a five billion dollar deal, comparing the situation to concerns around Kaspersky antivirus, and warns that any application could be spying on users.

BJ describes ransomware trend lines showing older attack methods declining while vulnerability-based attacks climb, and argues that an XDR tool is essential. The hosts cover network isolation for smart devices, a livestock tracking software breach affecting 18 states at the time of recording, and Craig's recommendation of third-party code reviews for organizations handling sensitive information. Erin asks why government agencies were not using XDR, and Craig attributes this to tunnel vision and limited staff, noting that CMMC was not yet signed at the time of recording. Craig also advocates zero trust and cold wallets for crypto, and Blake joins as BJ recounts odd smart home behavior he sees as machine learning in action.

Worth remembering

Key takeaways

  1. Craig warns that any application on a phone or computer could be secretly spying and exfiltrating data, so people must know where their software is made.
    “Any one of those pieces of software could be spying on you and exfiltrating information out of your device without even you knowing.”
  2. BJ argues that ransomware attacks centered on software vulnerabilities are sharply rising, making an XDR tool essential because no one can track every vulnerability manually.
    “I feel like there's literally no debate to the fact that you have to have an XDR type of tool.”
  3. Craig recommends segmenting devices across multiple wireless networks, since isolation is often a free router setting that limits a compromised device from spreading laterally.
    “isolation is a free often free configuration type setting that most people could take advantage of that will help increase their security.”
  4. Craig says third-party code reviews, where outside programmers comb through each line of code, are an exhaustive audit he highly recommends for companies handling sensitive information.
    “But that is a audit process. That we highly recommend Especially companies that are dealing with sensitive information go through.”
  5. BJ argues that people must stop blindly trusting and take their own security into their own hands rather than assuming someone else is keeping them safe.
    “they need to stop being autopilot and they need to stop blindly trusting”
  6. Craig explains that zero trust, using protections like end-to-end encryption outside a vendor's control, means you are not holding the bag if the vendor is breached.
    “So you don't have to centrally trust that one vendor, you rely on zero trust technology, like end-to-end encryption and things like that.”
  7. Amid pressure on exchanges to freeze funds, Craig advises storing crypto in multiple cold wallets and protecting the secret phrase.
    “Multiple cold wallets absolutely protect that secret phrase.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.