Breaches in 2022 – Mackenzie Jackson, GitGuardian
Mackenzie Jackson, Developer Advocate at GitGuardian, will discuss the major cause of breaches in 2022, look back on the biggest breaches, and discuss how to safeguard against them.
Transcript
This is texturing TV. Hi everyone. Welcome back to text on TV.
Our next guest today on techstrong is Mackenzie Jackson McKenzie is with get guardian and he is going we're going to talk some. Security here with with Mackenzie and in just a second, but first let's welcome him Mackenzie. Welcome to Tech strong TV.
How are you today? Yeah doing I'm doing great doing great. How about yourself?
Very good. So I'm something a little bit of an accent. Where are you from?
So originally I'm from New Zealand. But but now I live in Amsterdam in the Netherlands so really, oh, yeah, we're we're actually heading over to Amsterdam for for kubecon. Awesome.
Yeah. Yeah nice forward to it. So but the key we originally all right.
Yeah. I heard that. Still have that little little bit of a trace of it good for you.
That's another beautiful place as well McKenzie. Why don't you give us a little bit of your stories though? You know, yeah sure.
So I I'm Mackenzie. I've been in tech for for a very long time kind of recently. I was there the founder and CTO of a health tech company could compago which which is still exists and running today, but along that journey, I just became obsessed with security and going through the compliances that we need to have learning more about it and you know following on from that security and understanding it and protecting people's data and and almost in a way realizing how unsecure by default kind of everything is kind of really made me had a passion for it.
So today I'm with a French company who get guardian. We do a lot of code security but one of the cool things that I'm really involved in as we have a research team and we do a lot of research around application security code security and really kind of to do some breakdowns of breaches that have happened. So that's really more my role today is kind of diving into some security security research and that's a little bit just a little bit about where I come from love it.
I love it. Okay. So and yeah, we talked about good Guardian.
I don't think we gave the URL for the get Guardian. com is the is the website we want to check out that and we have plenty of resources on there in terms of Publications that we've written based on on our research. Got it.
All right. so Mackenzie look Though it's only January 2023. Is off to a banging start in terms of security.
We've already seen several major. Breaches announced Circle CI. I think there was a T-Mobile breach.
You know it just the hits just keep coming. And you know, even before that though everything we read in sauroposted or pointed to security really really being job number one in 2023. Now superimposed on that you've got these crazy macroeconomic conditions going on war famine inflation pestilence, right everything that we deal with here in today's world.
And you know that's got to have an effect on business obviously interest rates all of that but yet. You know from what we hear and see. Look, we can't afford to sacrifice security at the altar of inflation, right?
We still got to we've got to invest so from where you sit with your research. What do you see? I want to talk to you about 2023 kind of what do you see as the big trends as things that we need to have on our radar?
Yeah. What's your take? Yeah, absolutely, but you certainly painted a cherry picture.
I'm sorry. Well, yeah. Well, I mean by my predictions and research is a much cheerier.
I will admit we we're what we're really starting to see is is some shifts in security and we're seeing a lot more Investments being made from more. So on the adversarial side, then we are on kind of the business operation side. We're seeing kind of an imbalance of money being spent from the attack is and this is really changed the landscape and we're seeing it it already and coupled with that we're seeing that targets are actually starting to to really kind of shift into Direction.
if we look at 2022 as a bit of a guideline what we started seeing really for the first time in a strong way and it really ramped up kind of towards the end. Is a change in targets shifting towards a lot of developers and a lot of technical people being targeted personally. To try and gain access into an organization.
And this kind of comes from some large profile breaches that you see we're really it was revealed many of you targeting someone that's gonna have the keys to the kingdom. So to speak if you're an organization, then technical Personnel like developers, like you're operations teams, like you said means they're the targets. If you can access them that that will grant you grant you kind of into into the Kingdom.
So we've seen it with circle CI in these technical, you know, these technical are platforms that are being that are being breached is now kind of the targets are really starting to change and we're we're seeing kind of really really close attacks on that and we think that's going to really kind of Skyrocket in 2023. And there's a couple of easy targets that the technical people have in terms of, you know, you'll get repositories which are shared. Throughout the whole companies which need to be because that's a collaborative.
You know, we're running source code. We're collaborating on all these different things. Lots of people have access to our code repositories, but they're I value Target because they contain lots of information and yeah and and secrets and API keys and even things that shouldn't be there but we all know are there an attack is a figure that out too.
So, I mean there's there's lots of that that definitely happen. But when terms of kind of when you're looking at the targets, definitely we're seeing a shift in the type of personnel that are being targeted and it's getting much more technical. Is the same thing with the LastPass breach?
Right, they were able to get one employee you actually had access. To to some of the cloud even though the they claimed the data was still encrypted and hashed and salted and all of that good stuff. They were able to access it.
Via this one employee say the same thing is Circle C. I think OCTA. You know, the whole actor breached thing is probably tied in.
Here around that as well. But you know the the issue you mentioned with get I'm reminded. Look I Started I've been in cyber many many years.
I remember going to a meeting once with the Department of interior here in the US, right? The department of interior has like I think 16 or 17 agencies in bureaus. That are part of it.
One of them was I think like us Geological Survey. He's a great. These are smart people right?
They're the people who are measuring earthquakes and and all kinds of seismic stuff and and all of that good stuff. They've got sensors on the bottom of oceans on the top amounts and everything in between right because they're sensing they need that info and we spoke to them about securing that securing these sensors and securing that data, you know in their thing was well. No, it's science.
Right and it has to be open if it's not open people can't use it at the same thing at universities. Right where the mission is is sharing. It's kind of the same thing.
You see it get right the whole purpose of get is to be able to have that. code available for the team to use Right that we don't want one person having the code there in another person may have a different version of that code on their machine and a different right? We we all want to work off of one common Repository.
And and so the idea of making it difficult Or you know trying to lock that down kind of runs counter to the mission almost right? And so there's some it's hard. It's hard getting people to wrap their minds around that.
I definitely is and you know, you've kind of two camps in this and it's like saying, you know, the open source can and the lock code down. I'm actually more towards the open source camp. And the reason I say that is is source code doesn't need to be That doesn't need to have vulnerabilities in it.
You know, like it has a source code. It's mapping out your infrastructure and other things like that, but doesn't need to have the keys the kingdom and it shouldn't. But in this gray area where you have private source code shared within the companies.
People often get a bit lazy. They will hard code in API keys and it's all because it's his perceives notion of it's secure because I have to log in to do it not understanding that the security that you should have on your code and the security that you should have on your security certificate. Your API key through credentials is like not even on the same planet.
And if those credentials and other secrets are in the code, just any as an example. Like they have extremely low security the barrier to entry for attacker. You know it comes there.
So it's I think it's kind of less about locking down your source code and more about understanding that it is not secure and that doesn't mean everything has to be open source, and we can't protect Trade Secrets and other elements. I totally understand that but just understanding that. Your Source Code by its very nature is never going to be a secure asset and we just got to stop pretending like it is.
A great I agree with you man. All right, so that was one one. Prediction or you know something for us to be watching what else you got?
Well something kind of interesting along the way here is we've actually noticed a huge increase in the companies using MFA and locking down different systems. This is fantastic. And then last year particularly towards the end of last year.
We saw a huge increase in the sophistication by attack is to get past in their faith. And so we're not starting to realize that that MFA and other type of multi authentication types. Are not sufficient enough to kind of give us a protection that we think that they do.
And you know, we've seen it in an example being last year with their Uber breach where an attack here got access into ubiz internal networks and then got access to their Pam system the privilege access management system and moves through none of that should have happened because all of that was protected by multi-factor Authentication. But at the behind multi-factor authentication a humans and we're always susceptible to fishing campaigns and through some other areas of sophistication. We're starting to see that these additional levels of security are starting to break down and behind systems that have MFA in them.
We started to get a little bit lazy in kind of security. So in the example of uber digest head there was plain text credentials all through the server. Because that's protected by MFA.
So everyone has this false sense of security again. So one of the predictions that we're definitely going to start seeing based on Trends is that we're going to have more and more attacks and breaches. They're going to bypass MFA and the the sophistication of the types of fishing campaigns and the kind of bypass attacks to do this is going to increase based on pretty much that attackers are willing to spend more money than we are as Defenders.
So another one here MFA bypass definitely going to start seeing more of those in you know on that note. I saw Apple actually Apple released an update yesterday. to iPhones iPads and I believe iOS and Mac OS as well as watch OS that's going to allow for a I forget what they call it, but an extra level to MFA.
Yeah, so beyond two factors something about the hardware as well. I don't know if you saw that. I haven't seen that exact Trend but that's exactly you know yet today right?
I have to have a look but you know, that's exactly that the types of security that we need to have something that we know something that we have that you know our Hardware piece and and something that we are. Those are the kind of elements of zero trust and if we can get those three elements together that security you know, it doesn't just go up by another Factor every time we add a level that goes up by, you know, a factor of 10 to difficulty level goes up significantly and it's it's funny the last two years, you know, I've been hammering on about everyone about MFA MFA and now all of a sudden you kind of you look at what we're seeing and research and and Trends you. Oh my God, like now that's not enough.
It was hard enough trying to convince everyone to get on board of innovate and now you know, and that thing too. Yeah. Yeah, but this is look this is security right?
It's oh, yeah. It's a cat and mouse game and you always you know, you need to take you to the next level. So yeah, absolutely.
We've got time for one more. Well, yeah, I've got one more and I think it's as good we finish on something slightly more positive because it's not all bad. All me.
That was a good news, man. Yeah, absolutely. And so one of the areas that we've seen, you know, it's kind of being a big difference is the software supply chain.
We've seen lots of software supply chain attacks. And really what we're seeing is this this is huge lack of understanding about our software supply chain. When you look at all the dependency that we have in open source software and third party applications and third party services and the dependencies that they have we've been completely blind about understanding our software supply chain, but there's been some amazing stuff happening.
So for instance in legislation in America, you have the s bomb which has added in the you know, that this cyber security Bill, that was put out of actually understanding. Yeah software bill of materials, but if bomb means for those that don't know but coupled that with lots of fantastic work by some large companies. So Google has put out what they're calling salsa, which is security levels for software artifacts.
We have missed that is brought out their cyber cyber supply chain risk management. Is and so all of these different levels and what we're starting to see is is taken a while for adoption, you know of the s-bomb it came out, you know a few years ago now. In since then, we've had log4j which is kind of accelerated people's need to to adopt it.
And what we're seeing is that people's understanding of their attack surface and supply chain is really starting to expand. We're getting some great Frameworks and tools to actually see it. So we we're not going to solve the issue of supply chain attacks in 2023.
But this is one Trend that we're really seeing the doors. It's not closing. But at least we understanding where the doors are now.
And it's starting to look a bit more manageable because two years ago. I the concept of software Supply chains. I think was just terrifying for everyone and we all felt completely vulnerable to it.
And you know like passengers in a car crash. And now I feel like at the car still crashing, but at least we're in the driver's seat and every and we're getting better. So I think this well amazing stuff happening awareness.
being aware of the issue Is the first step towards, you know taking that issue on and Mackenzie. I want to thank you for coming on. and talking to us about this today continued success with get Guardian, you know, don't be shy about anything.
You want to come on here and talk about research you're doing we'd love to hear from you. I awesome. I love text from TV.
You guys have great content. So I really really I can be back in and share some some of them more research with you. We'd love to have you.
All right get Guardian here on Tech strong TV. We're gonna take a break. We'll be right back.