• Zine
  • Anonymous
  • Green
  • IT
  • Gadgets
  • Tech
  • Cloud
  • Data
  • Network
  • Security
  • Hosting
    • Sunset Host Co
    • Radio Host Co
  • Media
    • WSCA News
    • Sunset Crypto
    • Sustainable Action Now
    • Life.Style Magazine
    • Sunset Daily
    • Sunset Music News
    • Pro Merch Sports News
    • Explore New Jersey
    • Explore NJ News
    • The Zine Weekly
Facebook Twitter Instagram
Monday, May 16
Facebook Twitter Instagram
The Zine Weekly
  • Zine

    Eurovision 2022: Russian hackers targeted contest, say Italian police

    May 16, 2022

    How to download YouTube videos

    May 16, 2022

    Food Truck Festival Giveaway Rules

    May 16, 2022

    Why Build in Web3

    May 16, 2022

    To Drive Technological Progress, We Need Worker Power

    May 16, 2022
  • Anonymous

    Eurovision 2022: Russian hackers targeted contest, say Italian police

    May 16, 2022

    How Netflix Is a Joke Addresses a Film Distribution Flaw

    May 14, 2022

    How to Fight Foreign Hackers With Civil Litigation

    May 14, 2022

    Former hacktivist provides security advice

    May 13, 2022

    Anonymous appears to slam Elon Musk’s ‘left wing bias’ comment with new Twitter post

    May 11, 2022
  • Green

    Scientists create renewable biocement made entirely from waste materials

    May 16, 2022

    Proposed improvements to SiC MOSFET power converter technology overcome existing challenges

    May 14, 2022

    Emerging hydrogen storage technology could increase energy resilience

    May 11, 2022

    Microgrid demo to lend a helping hand in India’s green energy transition

    May 9, 2022

    California prepares for energy shortfalls in hot, dry summer

    May 7, 2022
  • IT

    How to download YouTube videos

    May 16, 2022

    Roe v. Wade reversal could hinder data privacy rights

    May 16, 2022

    Bumper blast! Apple’s smartphone is available for less than 50,000.

    May 15, 2022

    Aura Review | PCMag

    May 14, 2022

    Policymaker proposes commission to oversee digital platforms

    May 13, 2022
  • Gadgets

    Our study suggests they boost intelligence in children

    May 16, 2022

    Realme TechLife Watch SZ100 India Launch Date Set for May 18, Teased to Offer Up to 12-Day Battery Life

    May 15, 2022

    These high-tech must-have products have actually gotten cheaper

    May 14, 2022

    Musk-Twitter Deal Expected to Close, but Prepared for All Scenarios, Says CEO Parag Agrawal

    May 14, 2022

    Looking for free broadband in Southern California? Here’s how to find it

    May 13, 2022
  • Tech

    Two Twitter bosses ousted ahead of Elon Musk $44bn takeover

    May 13, 2022

    4D composite printing could improve the wings of drones

    May 11, 2022

    How to delete unused styles using VBA in Word

    May 9, 2022

    Best Gas Credit Cards in May 2022

    May 6, 2022

    Eshoo faces rivals from left, right and center in bid to retain Congress seat | News

    May 4, 2022
  • Cloud

    To Drive Technological Progress, We Need Worker Power

    May 16, 2022

    The age of discontinuity | The Manila Times

    May 15, 2022

    Alibaba Cloud-UCSI to support digital economy

    May 15, 2022

    The Matter of Everything, Twelve Experiments that Changed our World: Rich rewards

    May 14, 2022

    VMware sovereign cloud initiative grows to 14 partners

    May 12, 2022
  • Data

    Real-time Analytics News for Week Ending May 14

    May 16, 2022

    Greatest REIT Wannabes Of All-Time: Part I

    May 15, 2022

    Metaverse: ‘Train your robots in the virtual world’ (CXOTalk interview)

    May 15, 2022

    Evoque Partners with Archer Datacenters to Develop 61 Acre

    May 14, 2022

    A Recipe to Migrate and Scale Monoliths in the Cloud

    May 13, 2022
  • Network

    Why Build in Web3

    May 16, 2022

    Broadband Nutrition Labels and Deployment See Renewed Focus in Washington

    May 15, 2022

    BHO Network announces its partnership with ConsenSys

    May 15, 2022

    Twitter’s Parag Agrawal after firing top execs: ‘Expect more change for the better’

    May 14, 2022

    The TRON Grand Hackathon 2022 returns for season 2

    May 13, 2022
  • Security

    Food Truck Festival Giveaway Rules

    May 16, 2022

    Tricity grapples with a new epidemic: Cyber crime

    May 15, 2022

    The foreign diplomatic contingent – Kaieteur News

    May 15, 2022

    What happened when I tried virtual coworking.

    May 14, 2022

    Contest Rules for Dine with Crusher, Wild Florida’s largest gator!

    May 13, 2022
  • Hosting
    1. Sunset Host Co
    2. Radio Host Co
    Featured

    Announcing Reliable Dedicated Server Hosting Provider with USA, US, New York, California, Texas based IP – TheServerHost – IT Industry Today

    By Sunset Host CoMay 16, 20220
    Recent

    Announcing Reliable Dedicated Server Hosting Provider with USA, US, New York, California, Texas based IP – TheServerHost – IT Industry Today

    May 16, 2022

    Elon Musk Takes a Stand in Controversial Disney Copyright Case

    May 15, 2022

    Announcing Reliable Dedicated Server Hosting Provider with Dubai based IP – TheServerHost – IT Industry Today

    May 14, 2022
  • Media
    1. WSCA News
    2. Sunset Crypto
    3. Sustainable Action Now
    4. Life.Style Magazine
    5. Sunset Daily
    6. Sunset Music News
    7. Pro Merch Sports News
    8. Explore New Jersey
    9. Explore NJ News
    10. The Zine Weekly
    Featured
    Recent

    Eurovision 2022: Russian hackers targeted contest, say Italian police

    May 16, 2022

    How to download YouTube videos

    May 16, 2022

    Food Truck Festival Giveaway Rules

    May 16, 2022
The Zine Weekly
You are at:Home » What are hackers thinking? A white hat offers an inside look
Network

What are hackers thinking? A white hat offers an inside look

Sunset Host CoBy Sunset Host CoMarch 15, 2022No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email

ORLANDO – Kevin Johnson, white-hat hacker and CEO of Secure Ideas consultancy, had a statement and a couple questions for the infosec professionals in the audience Monday afternoon at HIMSS22.

“I think that most people don’t understand what they’re actually protecting against,” said Johnson. “I’m going to ask for a show of hands.”

He asked: “How many people here – and we will assume with permission – have dumped credit card data, Social Security data, health records, whatever, from a system they should not have been able to dump that data from? OK, I’ve got like three hands that I can see, other than my own, maybe four.”

Another question: “How many of you have ingested code into a web application that ran somebody else’s browser? OK, a couple more.”

Johnson cut to the chase.

“Here’s what I worry about: They want me to act like the real bad guys do,” he said, referring to the clients, such as banks and healthcare organizations, who hire him to “break in and steal stuff.” (“We always give it back.”)

“But here’s the thing that concerns me,” he told the audience of healthcare IT leaders. “You’re making decisions on what security controls you’re going to implement, either as an individual for yourself or for your organization – yet the vast majority of you have never seen a hack pulled off.”

All day long at the HIMSS22 Healthcare Cybersecurity Forum, ransomware, unsurprisingly, was a constant topic of discussion.

But ransomware “is probably the least of your concerns if you want to truly assess risk,” said Johnson.

“Ransomware is bad, don’t get me wrong. But in most cases with ransomware – most, not all – you’ve lost no data to the attacker. You may have lost data because of [lack of] backups and things like that. But what’s a bigger concern for me – and really should be a bigger concern for you, in my opinion – is the loss of data that impacts patient care. The loss of data that impacts your ability to help patients.”

A good defense must understand how an offense is constructed, said Johnson.

“In football, they’re trying to get that weirdly-shaped ball from one end of the field to the other end, and there’s a couple of ways they can do it. But if the defense doesn’t know those couple of ways they can do it, how are they going to defend against it?”

Even worse, some healthcare organizations are embracing the wrong approaches.

The answer, said Johnson, is not to compel employees to attend “yet another stupid damn user-awareness training!”

“The number of times that I see people get an email, that they click on to go to a training that tells them not to click on links and email is asinine,” he said.

“Let me be very clear,” he added: “I took complete control of a hospital organization by sending out a user-awareness email. The guy who hired me clicked the link and logged in!”

Here’s how it works.

“You hire me. I say, ‘OK, we signed a contract.’ I come up with a ruse. I send it to you for your approval because I want to make sure that I’m not doing something that’s going to cause you problems. And I want to let you know what the ruse is, so when you start getting the questions, you know what’s going on. So, I sent the email back. And he said, ‘Yes, that looks good.’ Five minutes after him approving the email, he clicked the link and logged in.

“It took us half an hour to get domain admin credentials,” said Johnson. “When we were doing our debrief that evening, I said to the guy, ‘Hey, dude, you didn’t need to test that email. We tested it before we sent it to you. And the guy let out an obscenity I’m not repeating here. And that’s when I realized he hadn’t tested it. He was an enterprise admin on the Windows network and gave us his credentials. Oh, and they didn’t have multifactor authentication.

“One of the attacks I do quite regularly is I will send an email to you that tells you it’s time to change your password,” he explained. “And there’ll be a link for you to change your password. I hate to break it to you, but that link doesn’t go to your system. It comes to mine. And we get to play.

“The reality is, and this is the bad news, I do not care what you do. I will break in. And I want to be clear. I’m not saying that like, ‘Man, I’m a badass hacker and I’m getting in.’ I’m not even that smart. I’m telling you, I’m going to get in because I’m going to keep trying until I do.”

Share this:

  • Twitter
  • Facebook

Related

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleThe role of cloud services, public tools in the Russia-Ukraine cyber conflict
Next Article Anonymous Hacker Group Targets German Subsidiary of Russian Oil Giant Rosneft: Reports
Sunset Host Co
  • Website
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • Tumblr
  • LinkedIn

Related Posts

Why Build in Web3

May 16, 2022

Broadband Nutrition Labels and Deployment See Renewed Focus in Washington

May 15, 2022

BHO Network announces its partnership with ConsenSys

May 15, 2022

Leave A Reply Cancel Reply

Categories
  • Anonymous (96)
  • Cloud (151)
  • Data Center (134)
  • Gadgets (173)
  • Green Tech (39)
  • Hosting solutions (96)
  • IT News (97)
  • Network (142)
  • Security (135)
  • Tech (96)
  • Web hosting (58)
  • Zine
  • Anonymous
  • Green
  • IT
  • Gadgets
  • Tech
  • Cloud
  • Data
  • Network
  • Security
  • Hosting
    • Sunset Host Co
    • Radio Host Co
  • Media
    • WSCA News
    • Sunset Crypto
    • Sustainable Action Now
    • Life.Style Magazine
    • Sunset Daily
    • Sunset Music News
    • Pro Merch Sports News
    • Explore New Jersey
    • Explore NJ News
    • The Zine Weekly

Subscribe to Updates

Get the latest tech news from the Zine at the Sunset Host Co. and the Radio Host Co.

Eurovision 2022: Russian hackers targeted contest, say Italian police

May 16, 2022

How to download YouTube videos

May 16, 2022

Food Truck Festival Giveaway Rules

May 16, 2022

Why Build in Web3

May 16, 2022

To Drive Technological Progress, We Need Worker Power

May 16, 2022

Real-time Analytics News for Week Ending May 14

May 16, 2022

Announcing Reliable Dedicated Server Hosting Provider with USA, US, New York, California, Texas based IP – TheServerHost – IT Industry Today

May 16, 2022

Our study suggests they boost intelligence in children

May 16, 2022
Copyright © 2022. The Zine Weekly, an SCA Entertainment & Media Company. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.