Listen to this episode

Navigating the Stormy Seas of Cybersecurity and Social Media Evolution

0:0022:42

Recorded October 2023. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

Craig and Blake open with recent cybersecurity headlines, including the OKTA breach involving stolen access tokens from its support unit, which Craig compares to SolarWinds, arguing that no single security layer can be trusted. They briefly mention former NSA employees leaking classified data to Russia and a Microsoft Active Directory bug.

The conversation then turns to a coalition of 41 states and the District of Columbia that, at the time of recording, was suing Meta over alleged harm to children from Facebook and Instagram. Blake predicts social media platforms will keep cycling as users chase the next thing, while Craig argues that free platforms treat users as data points, citing Cambridge Analytica and his belief that Meta listens to conversations. They discuss parenting challenges around phones and social media, with Craig describing the locked-down watches he gives his children. Headlines about potential bills banning DJI drones at the time of recording lead to a wider discussion of supply chain trust, vendor vetting, and layered protections such as keystroke encryption. They close by urging listeners to uninstall or turn off unused software and devices.

Worth remembering

Key takeaways

  1. Craig argues that layered security means one failing layer leaves the rest of the system working, so organizations should be careful with vendors.
    “if you had more than one layer and you've got multiple layers, then one layer fails and the rest of the system is still working.”
  2. Craig argues that with a free product or platform, users are the data point, so free services come at the cost of personal data.
    “with a free product and platform, you're the data point right, so it's free for a reason”
  3. Craig believes social media is more harmful than good for children and does not support kids using it.
    “I don't support social media for children, that's for sure. I do think that it's, in my opinion, more harmful than good.”
  4. Blake argues that social media replaces direct communication, so people post updates rather than personally sharing news with friends.
    “I think it pushes people further away, because now, instead of having those direct communications”
  5. Craig explains that every vendor brought into an environment must be vetted and tested, with documentation, policies, procedures, attestation, and evidence.
    “Each vendor we bring into the ecosystem has to be vetted and tested and we need documentation, policies, procedures, you know, attestation, evidence”
  6. Craig argues that big vendors ship too many features turned on by default and should instead follow the Linux approach of starting with everything off.
    “Microsoft, Adobe, all these big vendors keep adding tons and tons of features, apple included. They just put all this stuff on and then they turn it all on.”
  7. Craig urges listeners to turn off or uninstall unused software and devices, treating each removal as an enforcement layer that makes them harder to hack.
    “the more stuff you remove and the more stuff you just get rid of that you don't need, the better, the more unhackable you become.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

Are you prepared to navigate the rocky terrain of today's cybersecurity landscape? This episode is your compass, guiding you through the treacherous twists and turns of tech threats, from the OKTA breach to the leaking of NSA classified data to Russia and the sneaky Microsoft bug within Active Directory and Azure. We don't tiptoe around the controversy, diving headfirst into the lawsuit by 41 states against Meta - accused of crafting addictive features harmful to young users - and scrutinizing the unsettling reality that we, the users, often become mere data points in the world of free platforms and products.

Switching gears, we'll ferry you across the vast ocean of global supply chains, revealing the uncharted security risks lurking beneath the surface. As we set sail, we'll explore trustless manufacturing and vendor relationships, and how sourcing parts for a single iPhone from multiple countries can be a security siren's call. Equip yourself with our insights on the importance of third-party testing, vendor risk and the layers of security critical for survival in our increasingly interconnected world. This episode is more than a discussion - it's a lifeline in the stormy seas of cybersecurity and social media evolution. Tune in and join the conversation.

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.