(Full Show Audio)

All right folks you have the download button on security assessment podcast

all right guys thank you very much for joining us another episode of the

security assessment podcast I am your host Brandon Lopani and like I said it’s

great to be with you again tons of security news as there always is but a

couple good housekeeping tips first a bunch of you reached out to me on

Twitter to tell me that they noticed that the art changed I did I actually

got somebody to actually help us out and we actually got new show art it’s I

think it looks much better rather than just our business logo they actually

went ahead and actually made the logo a little bit quite a very much cooler

actually and like I said made it look a little more different to our business

name is on there and then the name of the podcast and then like I said she did

a few things with the the art and so that so I really appreciate that looks

much better I think looks much cooler I know the old saying you’re not supposed

to judge a book by its cover but unfortunately the cooler your show art

looked the better change you have the people you know reading your listening

to your podcast just like a book if it’s got a cool cover much better chance of

people reading it so I appreciate that also too we got a lot of people that

wanted to communicate with us so we actually went ahead if you go to our

website LaPani security.com and you go ahead and check it out there’s actually

a forum area there so go ahead and join the forums and we can chat about shows

security news all that stuff on there and again that is the forum so I want to

I guess I give you guys some options how to communicate with us the forums are

pretty cool we’ll use that for the show as well as anybody who wants to talk

other news and like I said of course you can always email us on a website just

hit contact us and shoot me an email you can do that as well so I do appreciate

that like I said you guys have been reaching out and communicating with me I

do appreciate that and I appreciate you listening to the show so thank you very

much for that also – over I’ve been working on a couple of security tools I

added a password strength tool runs locally on your machine you can test

your password strength there’s tons of them online bit Warren and bit warden

and security org and a bunch of places offer great tools like that but I was in

the mood to putz around with some code and I messed around that and that’s on

the site and that’s free it’s also gonna be up on the Windows Store as well so we

are I’m doing that as well so a lot of like it’s a lot of little projects

things going on but over the weekend is always podcast time so again I thank you

all for listening the show now should be on all the services if I did miss one

please reach out to me and let me know like I said my emails on my website if I

missed but I think I have it on all the services now but like I said if I’m

missing any please let me know so a couple things I wanted to wanted to talk

about we have a lot of news to talk about but I thought this was

specifically an interesting article that wanted to kind of start to show off with

apparently there was a on the security now podcast there was actually somebody

who had said that they were actually seeing they were monitoring their

network and they actually were seeing that their wash machine was down was

uploading and downloading like three gigs of data it was it was unbelievable

I was reading about this and apparently somebody had hot I mean we all know IOT

devices like fridges and stuff like that and stoves and stuff don’t get updated

as much but apparently somebody they actually found somebody running a botnet

and it was all these wash machines and they were all all this sort of things

and the reason why I bring this up is somebody it’s somebody it’s in the thing

that got interesting is to me was and it kind of makes sense so if you hijack an

IOT device specifically like a wash machine or a refrigerator now the

specific bug that they’re talking about was actually something that got loaded

into RAM and I know a lot of people that are listening gonna say well that’s easy

enough to fix you just restart the the device you’re absolutely 100% right but

I never really thought about this but it really got me thinking how often do you

actually unplug your washing machine think about it how often do you actually

unplug your refrigerator or even think about something like your dishwasher

that you can’t even get to the plug right kind of an interesting thought

think about where if you hijack an IOT device you actually have control of this

thing for quite a while unless the people have a power outage and since

these devices obviously most of them don’t get regular updates or I mean

obviously you’re a lot of times your refrigerator is going to last a lot

longer then probably the support from you know from the manufacturer as far as

like the updates for the software so they go really makes these these

connected devices especially vulnerable and and even if they are being updated

if you get a vulnerability you can load into the RAM like I said think of how

many times you’ve ever restarted your washing machine or restarted your fridge

or like I said or something like a while I guess it or a dishwasher where you

can’t even get to the plug in most cases really doesn’t happen often so if you

hijack those devices you could have a bot like I said until people have a

power outage so and if that’s the case you just go back and reinfect them and

then you’re gonna have them again until people you know until people come I mean

it kind of is a scary thought if you really think about it because you know

people will you know have these these connected devices that never get

restarted so all you need to do is load a you know something into RAM and and

it’s gonna be there until they have a power outage and think about this well

the people have a generator what if you have a generator now think now you’re

never gonna have a real power I mean so I mean a kind of an interesting scary

thought to think about and something I heard about security now made me really

you know really think about the IOT devices that I have in my house and all

that and you know how how you know if somebody got a control of one you know

it’s it’s it’s pretty brutal and a lot of people especially like the security

like security people network people tinker or stuff that we’re gonna monitor

our network traffic and stuff like that but a lot of people like think about

older people and some of that really don’t really you’re not gonna monitor

you know don’t don’t monitor their network traffic they just the Internet’s

there and that’s it so specifically kind of a scary kind of a scary thing to

think about and something to really think about if you do have IOT attached

devices you how often they are getting patched so interesting interesting very

interesting topic I need like I said on security now I really was interested in

that one this week I don’t listen to it every week I do like Steve Gibson I do

like spin right wonderful hard drive recovery tool I mean he doesn’t need our

plug he’s got twit but really is a great hard drive recovery tool he does do a

great podcast so security now is one I do listen to on occasion and like I said

it’s really worth listening to also to this week not really security news but

the the pre-orders for Apple’s vision Pro started like I said really not

security news but the reason I’m bringing it up is there are already

people hacking or hawking them excuse me up on eBay already for double the price

it always happens when there’s a shortage on things Apple specifically

doesn’t you know only has a limited amount of them to start with I know the

I believe if I’m not mistaken the a lot of the reviewers and stuff I’ve seen on

YouTube and all that already have them but apparently if you break the screen

see almost $800 to fix the screen if you are going to get the vision Pro I

recommend the Apple care one thing I will say I’ve always said this to people

especially maybe not so much with the Apple stuff because Apple’s got pretty

good control that stuff but I do want to say that if you do buy anything like

that online like I said that’s not much Apple because apples usually got pretty

good control their stuff but if you do buy any of that stuff online be very

careful I’ve actually seen people not myself personally but I have actually

seen online people that actually will will get old laptops you know load you

know Windows or Linux on them and then load a key logger or load a virus I’m

like that I’m saying keep an eye on things or use it as a botnet and then

sell it online if people say oh wow look I got this cheap computer for a hundred

bucks well yeah you did get a cheapie for a

hundred bucks but now everything you type is being logged or you know every

time there’s an attack or something like that your computer is gonna be the one

used being used as the you know the botnet so you know be very careful when

you buy cheap electronics online you never know what people do to them I think

that they call that a supply chain attack obviously we all know we’ve seen

the videos and some of that what happens with that but again be very very careful

with that I always encourage people if you are going to get a used computer

make sure you wipe it the other thing that’s really concerning about that too

is I see especially especially online on Facebook marketplace a lot you see a lot

of people that are actually okay you know I’m just I didn’t use this computer

I’m just selling it online because I don’t need it anymore and then you open

and I see people you know you started up and oh hey look there’s people’s crap

still on this computer they never even wiped it clean that happens a lot as

well especially without recycle electronics and stuff like that happens

a lot so just another thing to be aware huh so speaking of that too by the way

one of the other interesting things like I said I was reading very interesting to

me anyway talking about the Google keyboard how the Google keyboard has

really got grown in popularity I avoid I mean I’m always concerned about all the

stuff to get Google collects it’s only gonna be a matter of time before somebody

eventually hacks them and and we really know how much data they are collecting

on us we know they’re collecting a lot of data on us but like I said this

specifically I’m eventually it’s going to happen but anyway you know especially

when I have a keylog if you think about using the Google keyboard I mean that

thing basically is a legalized key logger I mean it’s I’m sure Google’s logging

everything you’re typing specific keywords and all that kind of stuff I

know I mean I know it I mean I know Google has good security I’m not saying

they don’t but you think about it using the Google keyboard is basically allowing

Google to be your key be a legalized key logger I kind of put that out to people

kind of concerning especially some of the stuff going on with Google now with

the anti ad tracking stuff you know chromium what would have said to me is

you know a lot of companies have gone to the open source chromium which is

maintained by Google and you can create your own browser on chromium but what’s

concerning to me on that specifically is now that people are using chromium to

create their own browser everybody but Firefox it’s a bit concerning to me

because now you know Google is gonna make this ad tracking change to chromium

and it’s gonna basically affect all the browsers everybody’s about all the

browsers except for Firefox so it’s a little bit concerning to me that Google

has kind of kind of because of their open source chromium because everybody

jumping on board with it now has a very easy way to go ahead and pretty much

sway the market however they want if you think about it I mean the only one that

any ad blocker technology and stuff that’s going to work on anymore is gonna

be Firefox you know because I mean edge opera brave all those guys are built I’m

not sure what Braves gonna do crazy see what the Braves gonna do they’re saying

they’re gonna do something I’m curious what they’re gonna do but I mean even

chromium is gonna have this anti ad technology built in basically Google has

a way now of kind of kind of swaying the market however they want it’s very

concerning to me personally I don’t particularly care for it I think that

you know open source is one thing but they’re also using open source to go

ahead and push the market in the direction they want to benefit their

business a little bit a little bit unethical as far as I’m concerned let

me see the ones that won’t be affected obviously are going to be Firefox and of

course Safari isn’t affected but those are gonna be only two of the ads

blocking technology gonna keep working on I recommend to personally if you

don’t like people tracking you which I don’t particularly like with Google’s

doing I recommend using Firefox or specifically sound like Firefox or a

Chrome but like I said I don’t I don’t like I said I’m not very big now the

other thing too like I said Google has been pushing especially to get rid of

you know certain cookies and have their own master cookie and everybody uses

their master cookie and I’m like well yeah that’s great because they’re saying

oh we’re doing this for privacy but you’re also doing it so everybody’s gonna

rely on you now for the ads I mean they’re they’re slowly pushing their way

into being big brother and like I said it’s from a security standpoint concerning

because I mean if Google does ever get hacked the amount of data that’s gonna

be released on everybody it’s gonna be a pretty pretty insane it’s gonna be way

worse than anything we’ve seen I remember when the whole Ashley Madison

hack happened you know we’re talking even worse with Google because they know

what you’re searching where you’re searching what time you’re searching or

pretty pretty concerning so you know something to be concerned about some

other things too I’ve got a ton of stuff things they got tons I want to talk

about oh one of the things too I wanted to talk to somebody I know a couple

people we were talking about how people reached out to me talking about Plex you

know hosting your own stuff and and your own music and your own videos of that I

know Plex said they’re gonna be coming out with their own version of like the

iTunes store and so that’s that you can buy and rent videos right on their

service I think that’ll be pretty cool they’ve talked about that a few times

doesn’t come to fruition yet but eventually maybe we’ll see but one of

things I do want to bring up about that somebody had brought up to me that you

can use Plex to you know if you tore in a video or something like that you can

you know use Plex to you know share it on your local network and while that I

don’t condone that but if you do download a torrent I just want to say

one thing guys you gotta be very careful you download a torrent especially with

the popular movies a lot of those torrent files with the popular movies

have viruses and spyware and some of that built in a lot of times what people

will do is they will say okay well this is a popular movie I’ll rip it but then

what I’ll do is I’m gonna put a little little little piece of code in this

little file here so that this way when they watch the movie and affects their

system so just something to be you know if you’re going to torrent videos or they

don’t like I said don’t condone I don’t recommend but if you do torrent videos

be very careful make sure you scan the files and stuff like that so you don’t

get a virus on your computer very very important one of the other interesting

articles this week on throat calm I read his he’s a really big follows he does

everything with Microsoft and I really follow his stuff because I mean I use I

use both Mac and Windows I like them both actually but specifically he really

gets into the guts of Windows and a lot of my customers have Windows one of the

things he had talked about two specific things was subscription fatigue and the

reason I’m bringing this up is I know it’s not security related but I do want

to bring it up because one of the things that he was talking about is that a lot

of people are starting to host their own files internally people that’s like are

like okay well I can you know if I buy this NAS for $250 $300 this neck gear

NAS whatever I can hold you know host like four terabytes of files and I don’t

have to have any storage online I could save a subscription of $9.99 a month and

by the way do I want to point out that that’s we just saw about Plex similar

concept but one of the things he brought up we were people were commenting on

this and it is very important you know sometimes saving saving money is good

especially with the economy so that always you know try to save where you

can but one of the things I do want to point out as well it’s great to host

your own files and stuff like that heaven forbid you have a fire or

anything like that you just lost all your data there’s no you know you should

always have an off-site backup and I know people are saying themselves well

you know I’ll just save one more sub locally and save a subscription and and

it is I mean I agree with it too I’m sure we’re all trying to cut back

especially with subscription services going up and up and up but specifically

if you if you are going to be saving data locally you really should have

backup I have my own local NAS here that I host and save all my files on that I’m

working on some of that but I do also have it set up so that it backs up to

the cloud any changes I know I think carbonite offers a service like that I

know I think carbonite I think I think fast go back or a fast backup or go back

fast or any of those I think junk I think it’s what jungle backup or

whatever that well that’s an encrypted one but they um they offer where they’ll

back your NAS up for you every night even if you’re using any if you’re using

anything any of the popular NAS is like Synology or anything like that they have

services built right into it but like I said if you are going to be saving your

stuff locally to try to save money backing it up to an external hard drive

and leaving it is not I mean a NAS little bit different because you have

usually have two hard drives that are redundant but if you are going to be

just backing up your data to a hard drive saying oh yeah I’m gonna back my

data up this fancy money that one hard drive sitting in your you know your

living room or your kitchen if there’s a fire you lost all your stuff so I don’t

particularly recommend that I know we’re all trying to save money on subscription

services but it’s not exactly the safest and best way to do things so like I said

just be very careful sometimes you are saving money but you’re also exposing

yourself possibly to you know you know losing your data so be very very careful

with that one of the things one of the things somebody did show me this week

that I like I said I have not I didn’t I knew I knew about it but never actually

messed with it we’re all on social media these days and there’s a site online

called red act dev r-e-d-a-c-t dot dev and what this service actually does and

like I said I have to look because there is a paid version and there is a a free

version what you can actually do is you can actually go on here and you link

your social media accounts and it will actually delete all your posts it does

it all for you so something to think about like I said um like I said it’s

you can look at it it’s also a mobile app as well but I guess it’s something

to think about I know a couple people have asked me how do I go ahead and get

rid of my you know how do I go ahead and get rid of stuff that I posted that I

don’t want like I said you can go in and actually clear out an entire account of

data especially Twitter and some of that so just something to look at somebody

that showed that to me the other day and I really liked it and I wanted to bring

it up to you guys so they know some people want to kind of prune back some

of their social media so getting into some of the news of the week that I

actually collected tons of it we’re not gonna go through all of it because

there’s so much of it I remember when a friend of mine started a security

podcast back like maybe 15 years ago he had said I wonder if I’m gonna have

enough to talk about it seems like now it’s just so much of it but avante has

had a rough couple weeks the security vendor like I bring this up because I

know I have had people with the vante and I’ve had a kind of run around

pre nuts apparently avante their remote so their remote software that last people

work remotely actually has a vulnerability in it and it was actually

made NBC News last night apparently top US cybersecurity watchdog issue an

emergency directive federal agencies about popular software saying that they

need to go ahead and either patch it or remove it because I guess the government

uses avante so pretty important if you remember last week I think on the show

we talked about the VPN had an issue so now they’re remote software which allows

for remote desktop some of that and now there was this week and then their VPN

and then earlier this week they had another issue that they released so

avante is really getting picked apart so something if you do have an avante

system make sure you are patched and ready to go VPN the remote software

remote desktop all that stuff that they provide is been having some

vulnerability so please if you are somebody with avante go ahead and get

that patched on another site this week you actually says export experts warn of

Mac OS backdoor hidden in pirated versions of popular software now while

this is a great article okay the backdoor in the dot dig but they’re

saying legitimate software like navicat premium ultra edit final shell secure

CRT and Microsoft remote desktop or have been found to have even though they are

legit they actually have backdoors into the system so something to be very

careful of you do use any of those softwares I actually do myself make sure

you either uninstall them or you patch them very important kind of surprised me

too because Microsoft had heck of a week this week as far as their stuff

Microsoft executive said that their emails were hacked by their top guys

like people they haven’t said names but a match by Sasha and people like that

the CEO they’re saying that Microsoft actually their emails got hacked by a

Russian intelligence group the interesting thing about this while we

weren’t doing the podcast at the time obviously if you remember the solar

winds attack that happened back in I believe was 2000 or 20 20 20 it’s the

same they’re saying it’s the same group how they know they have not said how but

that was something in the news this week that really is kind of really was

concerning Microsoft obviously I’m waiting to see what’s gonna happen I can

only imagine that they’re gonna be there’s gonna be a lot of cleanup

because when you when you’re that high of an executive at a company like that

you get emails that are not supposed to be out in the world like trade secret

stuff and things about purchases and things like that that can really be

dangerous they get out in the wrong hands so I’m sure Microsoft’s in cleanup

mode right now for that one of the the other interesting articles I’ve

followed this this pretty closely actually and I take this with a grain

of salt personally because it’s Kaspersky and they’re rushing company

and that’s concerning to me because I know there’s been always been

speculation about Kaspersky and their ties with the government some of that so

I take this at value but one of the things Kaspersky has recently launched

is a tool called I shut down and it’s designed basically to detect notorious

spyware that is on your iOS device I’m not really sure I know cup I’ve seen

this going around the internet people talking about this I am personally a

little hesitant with anything from Kaspersky right now because of

everything going on in the world I know I have seen a bunch of people that used

it and they said they did find stuff I’m again it’s supposed to be for that

Pegasus that quad dreams rain and the other one predator so again I mean I

think you know that it’s well it could be a good tool I would be hesitant to

use it right now anything like that from Kaspersky that’s that’s just me

Microsoft having a heck of a week – by the way I had another story here in my

show notes a critical Microsoft SharePoint bug now actively exploited CIS a

warns that the attackers are now exploiting a critical Microsoft

SharePoint privilege escalation vulnerability that can be chained with

another critical bug now one thing that I do point out that I went through the

this and read through this whole thing it says the Microsoft SharePoint server

exploit chain was successfully cut founded by star labs researcher they

earned $100,000 reward from from what I could take from this because the they

weren’t overly descriptive about this Microsoft I’m guessing it’s going to be

if you have in-house SharePoint running that’s a big business for Microsoft

SharePoint a lot of people don’t know they actually bought SharePoint they

didn’t actually build it but one of the things like I said if you are running

SharePoint make sure you go ahead and patch your service but I believe it is

internal SharePoint it has to be because if it was its external SharePoint

Microsoft will patch it for you so yeah like I said but they didn’t because one

of the things somebody had asked was on the forums was is is this currently

being exploited on 365 and if it is I mean there’s nothing we could really do

about it Microsoft’s got a patch it but I would imagine they’re probably gonna

patch it so if you’re running internal SharePoint go ahead and patch immediately

Microsoft had a lot of big bugs over the last year or so you remember I think it

was last right around Christmas time whatever they had an issue with exchange

it got to the point rack space actually had a shut all their servers down

because it was that vulnerable a lot of stuff going on with that but that is

something by the way that is going to be coming to an end Microsoft has said that

they will not be releasing exchange server anymore that I think they said

they’re releasing their last version of local exchange I don’t know that’s gonna

fly a lot of people really upset about that and it’s not so the reason why that

is an issue is because you do have stuff people like lawyers and stuff like that

that do host their own exchange servers because of the whole security and

privacy of what they’re actually doing and they don’t want stuff exposed out to

the cloud specifically because they don’t you know how cloud is redundant

well they there’s just some kind of rules where they can’t have data being

backed up in other countries if it’s certain things regarding certain it’s

all law and stuff I don’t really understand that well but like I said

it’s there’s something about that I know lawyers specifically upset about that

some doctors are really upset about that because of the whole HIPAA thing which

I mean obviously 65 in the cloud is HIPAA compliant but especially people

with trade secrets or stuff like that you know are concerned and stuff like

that so we’ll see I mean Microsoft I mean the end of the day Microsoft’s

gonna keep releasing it if it’s making them money that’s what it comes down to

you know so you know as things you know stop making Microsoft money is when

they’re pushing it to the cloud so you know Microsoft’s legacy business of

Windows Server and Exchange SharePoint all that sort of stuff is still making

them a lot of money on-prem so until it doesn’t they’re gonna keep releasing it

so like I said we’ll see what happens with that I would imagine a lot of people

really complained about the SharePoint going into the cloud I’m sorry about

exchange going into the cloud I actually am all for it SharePoint I don’t think

should be in the cloud because SharePoint is very customizable and you

can do a lot with it where exchange not so much and it’s much more secure in the

cloud like I said I think I don’t think you’re gonna see I don’t think you’re

gonna see SharePoint stop being released locally but I do think exchange

eventually will go all in the cloud but I guess I do like SharePoint locally

because it is very customizable and I have seen some companies with very

elaborate SharePoint setups speaking of things that are hacked and secure lush

cosmetics I know they’re pretty popular company I don’t know a lot about them

but I do know that they had a they got hacked pretty bad and they have somebody

coming in an IT company doing an independent security audit to check their

system so really glad they’re doing that but they did get hacked they haven’t

released I obviously want the report as the people to come in and do a search

and spec see I don’t think they know what got hacked a lot of these places

like cosmetics companies and stuff of that don’t really know the security

infrastructure too well so they you know they’re gonna somebody come in do an

audit see what got tampered with and then obviously make recommendations but

to tighten the place up so if you are somebody that uses them you might want

to keep an eye on your credit cards or whatever you use on there so our friends

down under had a substantial breach labor was hit by a major government data

breach millions of files stolen from key departments labor has admitted it

suffered Australia’s largest ever government data breach with key

intelligence defense economic department information files were stolen from

Australia’s largest commercial law firm so those people in Australia I can

imagine I really hope they have good cyber insurance because they are going

to need it the interest the other interesting thing about this they said

in April of 2023 of 2023 ransomware group stole more than 2.5 million files

from the firm so this is you know something that’s this is a pretty big

deal because a lot of government stuff has gone out so like I said I saw that

I’m like oh interesting so it’s not just our government that gets hacked by the

way it’s everybody else as well also – there are a bunch of those of you that

use WordPress for your website there has been a lot of stuff coming out about

this obviously WordPress always has issues with hacks and some of that so

you have to make sure you keep all your stuff up to date but they said over 6700

WordPress sites using outdated version of the pop-up builder plug-in have been

infected and are suffering from malware so if you are somebody that uses the

pop-up builder plug-in on your website I would make sure to get that hack get

that fix so you don’t get hacked or if you are hacked roll back to a backup

there’s another one as well this week about WordPress over 300,000 WordPress

sites vulnerable to post SMTP plug-in so if you are somebody that uses SMTP on

WordPress and you use the post SMTP plug-in you have to patch that as well

so it’s a busy week for security stuff going on I mean always is but

specifically this week there’s a lot of a lot of hacks and stuff like that

opera has a bug in it which is going to let hackers run any file on your Mac or

Windows PC that was in the news this week as well opera obviously pretty

popular I mean it’s definitely it’s not on chrome level or Firefox level but

definitely is pretty popular but like I said security researchers disclosed a now

patch security floor in opera web browser that was allowing people with

Microsoft Windows or Apple OS that could exploit any files or run any files on

their system so the remote code execution vulnerability my flaw they’re

calling it was discovered and apparently it is patched now so if you are if you’re

using opera browser or opera GX make sure you go in patch that’s actually

pretty concerning thing because anybody can run any files on your machine pretty

scary so team viewer apparently has another big attack right now that people

figure out how to remotely gain access to systems team viewers saying to patch

it any of that stuff especially team viewer and any desk and a lot of these

things they’re always very vulnerable to attacks is obviously you get remote

control so nice a machine so I know these things are important are very

well used but you got to make sure you keep up to date because these companies

have quite that I would not want to be on one of these security teams for one

of these companies I can only imagine what they go through the amount of just

stuff that they have to deal with with attacks and all that cuz I mean

basically think about it I mean somebody I mean you’re basically if you get

hacked is basically give somebody remote access to a system so it’s a it’s a

really tough really tough thing to you know deal with I give any of these guys

that work on these teams tons and tons of credit because it definitely is a

home edge is gonna be hard work so the one the last article I want to talk

about is an interesting one they are actually saying that there is a lack of

cybersecurity experts in the industry and the same part of the problem is that

a lot of the kyber security experts don’t have the degrees required to get

the job this is an interesting article it’s from the national was at the

national the national cyber director he addressing the cyber talent shortage

this is actually like I said this is actually on the actual news site clear

news dot clearance jobs calm which is where you would look for federal jobs

he’s actually saying that he working that they want to remove the degree

requirement most jobs in the US government for skyber secure car for

your degrees many people don’t have a four-year degree that our security

experts and they want to go ahead and remove that just way they will not get a

shortage as people without four-year degrees are not being considered so

basically what this is the government is is lowering their standards for getting

people and and honestly I don’t blame them I know a lot of good cybersecurity

people myself included that don’t have four-year degrees that went maybe to

college for two years have associates and they got into cybersecurity I know

many people that didn’t go to college at all and when it got into cybersecurity I

know a lot of programmers that are amazing bug finders that never went to

college and do a great job so I actually think this is actually really good most

of your good hackers didn’t go to college I hate to say that but a

majority of your good hackers don’t go to college I know a lot of good good

security professionals and some of that that you bug bounty and some of that

none of them are meant to college they just hang out and just do bug bounty all

day I know a lot of guys that actually did get in trouble and then got jobs

with the government after they got out I know a lot of that kind of stuff happens

so I think this is a specific case where they’re gonna have to you know sometimes

the you know the government needs to understand that they’re you know they

you’re not always gonna you have to look sometimes it’s not even lowering your

standards if the industries have changed so much you know 20 30 years ago none of

your IT people went to college because College for Computer Technology didn’t

exist so I mean a really interesting thing and some of your your best minds

are not college graduates so I think this is actually a good thing by the

government I’m sure they’re gonna have some kind of vetting process where you

have to pass it you know test or something like that I’m sure that

there’ll be something there but like I said I actually think this is actually a

really good idea get more able to get more people get better people sometimes

people that you know there’s a big difference in one thing anybody that

works in cybersecurity or it works any job field whether it’s a skill or trade

will realize there’s always a big difference between knowledge and

experience and that’s really important so I do want to bring that up like I

said some of the best coders I’ve ever met have never went to college and they

were great coders so I mean it’s it’s one of those kinds of businesses where

sometimes you’re not going to always you know college isn’t for everybody some

people are better at educating themselves and I think that is becoming a real

thing now especially with the internet stuff a lot of people go to cyber school

now a lot of people do home school now some of that because they want to move

faster they want to learn more there’s actually quite a bit of that actually I

know quite a few people that are that are cyber schooling or homeschooling

just because they can move at a faster pace and get more done and be more

prepared for college and then some people isn’t you know colleges for

everybody a lot of guys that made good money doing apps on the App Store and

stuff that have never went to college so you know it’s one of those kinds of

things where I think the government realizes that yes we’re holding people

to a ridiculously high standard some of the best people in we need to get the

best so in order to get the best we have to lower the standards of what we want

and you know college is not for everybody like I said there are some

great people in security industry that don’t have four-year degrees so I’m

really happy that they’re doing that we need to really get a handle on this kind

of thing because with all this government sponsored hacking and all

that kind of stuff we are going to need really good people and especially since

there is a shortage of people this is a good way of doing it and I want to point

this out to a lot of people talk about COVID and and I’m not getting political

I’m not but a lot of people say COVID where’d all these people go why didn’t

people go back to work it just shows you too that it’s it’s not just like the job

it’s not just like the food industry it’s not just the you know the the

blue-collar jobs with a shortage of people even in in white-collar fields

there is a shortage of good people so it just shows you it doesn’t matter what

industry your is there is a serious shortage of people in the workforce and

like I said it doesn’t matter you know what industry you’re in there is a

shortage right now so I thought that was interesting like I said I want to go

00:39:12.320 –> 00:39:15.880
ahead and just point one thing out like I said if you want to reach out to me go

00:39:15.880 –> 00:39:20.640
to the website the pain of security comm email me I do enjoy all the emails and

00:39:20.640 –> 00:39:25.760
really appreciate it and like I said I have I do we do have the forums up now

00:39:25.760 –> 00:39:29.400
and a lot of other things so please go with it we also have a lot of free tools

00:39:29.400 –> 00:39:33.360
I have I write a lot of free little tools and give them away for free if you

00:39:33.360 –> 00:39:38.280
go to the pain of security comm click on tools click on software there is tons of

00:39:38.280 –> 00:39:41.480
free software there you can use little security tools little things I write

00:39:41.480 –> 00:39:46.120
that I give away for free go ahead and like I said take you know you know

00:39:46.120 –> 00:39:49.800
download them enjoy them use them like I said all these little goodies that I

00:39:49.800 –> 00:39:52.520
write like I said I give them away for free I enjoy messing with code when I

00:39:52.520 –> 00:39:56.680
have some downtime and it’s nice just make sometimes little tools that people

00:39:56.680 –> 00:40:01.440
can use and kind of help people out just like this podcast so I want to thank

00:40:01.440 –> 00:40:08.000
