SlideShare a Scribd company logo
1 of 48
Download to read offline
Who we are, where we started
My company, CompSec Direct,
started here in PR, renamed,
rebranded but we always keep
deep roots here as much as we
can.
Who we are, where we started
For example, here are some PR related efforts we have done to date:
The Hacienda case, which I will discuss here today.
Spillage of court cases in the Judicial Branch, some involving minors. Still unfixed.
Shodan notices to the former CIO of exposed gov related systems. Fixed*
Data.pr.gov subdomain submissions of open-data suggestions, pending.
Aeronet Whitepages where the provider was providing SNMP information with customer names. Now fixedā€¦.
About Aeronet posting
I had the privilege to work here for a few months, back in 2007.
I am angry at people suggesting drama and taking away from the real
problems.
In Gino's case, he failed to recognize that if one of his former
employees suddenly decides to communicate directly with him after
not speaking for 11 years,
maybe he should have listenedā€¦.
What would you have done?
Lets vote to see who is correct here
https://pollev.com/jf484
About accelerated disclosures, notifications and other contributions
I'll ask you, as IT or non cyber related folks, how
many time do you believe we have been
thanked for our efforts?
How many times have we been thanked publicly
or credited for our efforts?
zero
0https://pollev.com/jf484
Thanks
That is why I'm here today at Bsides PR
for you, not them.
https://pollev.com/jf484
Oh boyā€¦
We are a conquered race
We are good imitators;
We adopted every conquering nations beliefs, ideals, customs and languages
Our laws, our policies, our industries all started or originated somewhere else
https://pollev.com/jf484
Here we goā€¦
We are not good innovators
Except for our GDP in artists, some
notable scientists and doctors
we have not innovated anything as
a country with global impact where
people know and say:
This started from Puerto Rico,
except reggaetĆ³n*
(Started from Jamaican dance hall music)
Hard truths
Truth hurts huh?
https://pollev.com/jf484
The imitation failures
As good imitators, we struggle endlessly to
correct Ineffective policies, ineffective
government since we modeled ourselves as the
US approved; like them
https://pollev.com/jf484
Imitation failure example
One of the ways we imitate is the political
arena and campaign funding,
You see, future or existing politicians are
nominated by political parties that raise funds
https://pollev.com/jf484
Imitation failure explained
When in office, they cannot legally campaign or
aid with resources (people, funds) as sworn
members, since they now serve the country
not the party*
https://pollev.com/jf484
Imitation failure based on relation to host country
Since we imitate the campaign raising circus in
the US, but donā€™t have 350M+ people, the
campaigns cannot generate 100M dollars for re-
election campaigns
Thus there isnā€™t a financial gain here except for
the promise of a trusted (confidant) position if
elected, and perhaps direct contracting for
professional services down the road since you
helped.
https://pollev.com/jf484
Innovation suggestion: Match campaign funds to Education Department
Innovation suggestion: Dollar of Dollar campaign
funds to Dpt. Of Education.
Yes, they will cheat and steal, but at least the money
could be used for good...
Maybeā€¦
https://pollev.com/jf484
How this scenario is different in Federal / other States
Here is the problem, I have more experience in the
federal space submitting bids, proposal and similar
experience at the state level in MD.
Both of these have strict guidelines for fair-
competition in bids, awards.
With the exception of exigent/emergency contracts
https://pollev.com/jf484
How to do business with the PR government through reputation and past efforts
PR is different, if you are well liked by a party, and
offered services during the election process,
you get preference somewhere in the process.
https://pollev.com/jf484
How this applied to us
For us, I met the (US Person) USP0 during the pre-
party nomination,
Gave the 30 second pitch, and was directed to USP1.
After a few months, we gave a presentation about
providing secure comms during the election.
https://pollev.com/jf484
What is secure comms in relation to OPSEC and Tradecraft?
Secure Comms being;
Tradecraft+ training+ security measures = OPSEC
Tradecraft is what you do
OPSEC is how you address risk as a whole by
effectively using tradecraft
https://pollev.com/jf484
Here is an excerpt of what exactly we offered
Secure Communications & Devices Solution for 500 devices for 1 year
(low six-figure sum)
Includes physical, logical and user education trainings for 500 individuals
Trainings done in person for groups of 20+
Trainings done via WebEx/Skype for all others
HQ Security Review included
Requires collaboration and support of users as well as full inventory of BYOD
Malicious Insiders Prevention and Detection for 1 year ā€“ (low six-figure
sum)
Includes unique document tagging and encryption solutions
Secure Social Media and Web presence for 1 year (low five-figure sum)
https://pollev.com/jf484
Why this was never finalized
Sadly, this was not picked up.
And thus I departed PR and starting working CONUS.
Campaigns have a limited budget which is focused on advertising
https://pollev.com/jf484
#DFWO : Donā€™t Forget we offered
Now here is the interesting part.
USP0 was forced to resign from lack of secure comms.
Now, no amount of encryption can prevent someone else from
correlating what you wrote if shared with someone else.
https://pollev.com/jf484
The Old School Politician remembers the past,
GenX and Millennials are more tech focused
In fact, the older generation of politicians understand that
"we are doomed to what we write, not what we say".
They donā€™t trust electronic communications as much as my generation
and Gen X'ers since they lived wire-tapping era, ā€œcarpeteoā€,
frankly, nobody truly understands how digital becomes distributed.
Risk > Convenience
https://pollev.com/jf484
Errors related to lack of secure comms
In this case, USP0 made four critical mistakes that could have almost been prevented:
1. Wrote derogatory statements related to prejudice, discrimination, humiliated fragile
social-groups and implicated himself and his cabinet in multiple ethics and criminal acts
a. Technology cannot change or improve your culture, upbringing or habits
2. Did so in a group setting without compartmentalizing information
a. Almost like talking to intimate friends
3. Publicly attacked a member of said group, USP3
a. By raising conflicts of interest claims related to son, USP4
4. Admitted publicly to the authenticity of transcripts
a. A big no-no in politics.
https://pollev.com/jf484
If you surround yourself with amateursā€¦.
Despite being surrounded by lawyers, no one ever stated to USP0 that:
"hey bro, WTF are you doing here???"
Perhaps something that secure comms oversight could have addressed.
https://pollev.com/jf484
Methodology for attribution of suspected leaker
But wait, are you saying USP4 did this; well here is methodology:
1. Correlate end date of transcripts against members of group, including close-
associations
2. Search endi / elvocero for things that happened around that time related to politics
3. One thing really stands out
https://pollev.com/jf484
Whistleblower laws as they apply to contractors
Criminal whistleblower laws in federal space protects government officials > government
contractors
I know this personally because I have had employment terminated (by employer, not
gov) after raising concerns as a contractor.
In my case, I followed the process; aka a reverse-Edurado-Snowfall
Eduardito, you should really go back and clear out your desk, that says a lot about you.
https://pollev.com/jf484
MMO for criminal cases explained in plain Puertoricanā€¦
Now, USP4 is perhaps liable for a conspiracy amongst other charges.
Means: "Chiko technico" means has knowledge of IT
Motive: Publicly part of nepotism case with state contracts via government/contractor
relationship
Opportunity: "Papi, prestame aca y yo bajo to eso a PDF y se lo doy a CPI"
This is now subject to some form of merit because USP3 made public statements about
technical knowledge of USP4.
https://pollev.com/jf484
On why you should never out yourself on something at this scaleā€¦.
That being said, no public statements of admission from USP4.
ā€œHe's crude, but he's crafty" Mutually-assured destruction via pyric victory.
As they say, "STFU and get a lawyer"
"He's not the hero we wanted, but the one you got"
Which now adds to the corruption narrative in the US, by virtue of reality.
https://pollev.com/jf484
Innovation suggestion
Innovation suggestion: Whistleblower protection laws for also apply to contractors.
All in all, effective tradecraft is tantamount in any organization. #DFWO
Privacy Screen = Mobile and laptop
Disable GPS = Minor annoyance
Disable wifi when not in use = slightly annoying
Disable bluetooth = moderately annoying
Disable Cell = Very Annoying
Don't take phone = Wow, so pay phones?
https://pollev.com/jf484
On the Hacienda case: Day 1
Now, back in 2017, USP1 and I talk.
I hear about ransomware in Treasury Department, and was asked to get involved.
By the time my flight landed, we get some PR actionā€¦. Interestingā€¦ an unusualā€¦.
By the time I make it to Dpt Treasury, it was very late, many IT staff are visibly tired.
I am briefed, I ask the staff to prep written statements to they can start getting their
stories straight, and depart late in the evening.
Guess what, no one did written statements <shocker> so I can't even get a good grasp at
what everyone had done until that point.
Everyone is tired and no one works over time from home.
One thing we did suggest; pay the ransom.
https://pollev.com/jf484
On the Hacienda case: It could have been prevented but it was too late
Not only was Dpt of Treasury breached; through brute-force of a public facing service,
it affected the backups as well.
The staff involved for IT was professional, knowledgeable and obviously concerned with
the incident.
To my surprise, every time I asked for something besides statements, they were diligent
in ensuring my requests were being acted on.
https://pollev.com/jf484
On the Hacienda case: If, Else, Finallyā€¦
At the time, ransom for decrypt backups was less than $1,300.
To them, this seemed like an impossible option.
I suggested to one contractor, UNUSP1, to try and decrypt one file from said backup
solution to test if this was even possible.
When you get hacked, ransomed, and have no alternatives; you pay the ransom since
Recovery Time Objectives (RTO) for businesses trumps everything.
Us talking about what to do next, cost over $1,300 so I reminded them of this fact.
https://pollev.com/jf484
On the Hacienda case: A case for hack naked?
Oddly enough, UNUSP1, was not able to accomplish this; which personally seems odd.
You see, no one ransoms anything if they cannot make money.
The service was up according to UNUSP1, but the statement "maybe it was a
dependency of the victim system for bilateral communications that simply caused it to
fail" was odd.
Communications with the ransomware operators also provided "no communications
established the next day".
However, since we had not been officially contracted to perform malware analysis, we
did not.
Instead, I uploaded the "alleged" ransomware virus into Virus Total on March 7, 2017.
You may say, upload the hash, not the file.
That depends on what side of the fence your on. More on that laterā€¦
https://pollev.com/jf484
On the Hacienda case: The malware
We are sharing this after the conclusion of the event by providing an indirect link.
https://pollev.com/jf484
On the Hacienda case: Day 2
By the second day, I re-experienced a common situation when this scenario happens, the
system experts, which until the day of the incident had normal responsibilities, day to
day duties and obligations, suddenly became engaged forensicators with investigative
responsibilities; that was our job.
I reminded the team that the situation was not contained, they needed to focus efforts
on remediation first and help us collect artifacts of evidence of the crime for us to
analyze; not them.
Another common occurrence during this scenario is talks related to budget, which serves
no purpose during a time sensitive situation like this.
At one point, I had to re-address marching orders, since the suggested plan by USP5 was
not necessary for purposes of containment.
https://pollev.com/jf484
On the Hacienda case: It always sucks when it happens to you
USP5 had the recently started this position. This is a normal occurrence between
government as new elected officials place individuals of trust into government offices.
This is why Ben Carson, a neurosurgeon by trade, is in charge of HUD.????
He inherited all of these problems prior to starting and less than 3 months is not
sufficient time to get a grasp on even what your environment is.
https://pollev.com/jf484
On the Hacienda case: Resist customer bias when conducting investigations
Let's take a break here on memory lane, whenever I approach any situation involving LE,
I think of the movie "Rising Sun".
In the film, the protagonist use digital video evidence to help solve a murder case in
Japan.
Much like the movie, the IT department at Hacienda presented some initial evidence,
potential suspects and MMO.
Somethings seemed the result of causality, others pure luck, others "very interesting
timing".
As an IR person, you have to resist your customer bias, opinions and statements and
collect the entirety of evidence you can to support any claims.
This is difficult when you are not LEO, and you are being paid by a customer.
https://pollev.com/jf484
On the Hacienda case: Resist customer bias when conducting investigations
During our involvement, we provided strategic leadership advisory during the first days
for the IR. This resulted in actions with consequences:
1. We brought some systems back online vs forensicating.
2. We provided questions and action plans for the government to ask and do.
3. We provided oversight to the battle plan
4. We briefed the director of Hacienda and the FBI
All under less than 3 days.
https://pollev.com/jf484
On the Hacienda case: On impostor syndrome
As I reflect on this event, I felt I was unprepared to accomplish what we were asked to
do based on scope, almost like pre-engagement jitters.
Those immediately went away the more I talked with the staff, not because of they
didn't know what they were doing, but because I have done this before, in a larger scale,
with less options.
I knew I was in the right place by then.
https://pollev.com/jf484
On the Hacienda case: Ingles con fronteras
Now, for us, we did not sign contracts or agreements with the government to formally
do any work.
The reason still baffles me, our NDA had jurisdiction in Maryland, which the government
rightfully refused, but more so;
the document was in English?
How can a country that is attempting statehood claim such a thing?
To date, I have no regrets as to not jumping in head first in this engagement.
https://pollev.com/jf484
On the Hacienda case: As a small company, your capped by your ā€œwarchestā€
A few weeks earlier, PR announced bankruptcy and I had no expectations of being paid
in a timely manner.
For us, we have native islanders that would have assisted us during the IR, but we don't
have that capital to pay our staff when it could have taken X months to be paid.
So as I'm finalizing this contract, I had a gut feeling that we simply can accomplish this IR,
but I had no idea when we would get paid, so I said no to the IR, and instead suggested
we do a case study and in the mean time, address language and contract barriers that we
as a small company faced.
https://pollev.com/jf484
On the Hacienda case: Hurricane relief efforts > the cybersā€¦
Maria changed everything.
As I was trying to maintain good relationships with USP1, it became clear to me that I did
have impact on the IR and other efforts.
Sadly, priorities change, so does staff.
I don't have the same relationship with the current CIO, but I would like to.
https://pollev.com/jf484
On the Hacienda case: Well, itā€™s almost like you paid for it indirectly, so itā€™s yours
This case study sadly was never purchased, lucky for you, we are providing a redacted
version of the case study tonight after the event on our site.
The link will only work from PR IP space for the first week, and then becomes public to all
visitors.
Password to get inside is: <so secure joseā€¦ā€¦>Yes</so secure joseā€¦ā€¦>
We are also providing adaptable parts of the questionnaire used during the IR in hopes of
getting more C suite visibility on things they can do prior and during an IR.
Personally, I really tried to have Hacienda look over the redacted version. ĀÆ_(惄)_/ĀÆ
Our case study was evaluated by a staff member at Hacienda, which commended our
case study in relation to other deliverables.
https://pollev.com/jf484
On the Hacienda case: Closing thoughts
Since this event was essentially caused by poor change management and poor
preventative actions, we can expect this to continue happening.
Since then, at least 4 more government agencies have been breached.
To date, neither the FBI or Hacienda have ever reached out to us for further assistance.
However, they're dependence on non-cyber focused companies continues to grow
based on practical needs for PR.
They donā€™t have to be secure, they simply need to improve the quality of life for citizens.
Placing a Fortinet, (im sorry, youā€™re a sponsor but ĀÆ_(惄)_/ĀÆ ) , does not solve for:
any-any rules.
https://pollev.com/jf484
The appearance of PR on the Net
We are a susceptible country on the net.
The biggest challenge cyber security has is also stemmed from the same problem
security has in general;
it produces zero income.
The next problems are simply based on awareness of issues and willingness to adopt
measures to reduce risk.
How can we change that?
https://pollev.com/jf484
Letā€™s actually be innovators for once
We need to change the way government operates.
For example, we have an unemployed labor force with some knowledge of IT.
We can build a non-profit to help organize the labor pool, provide opportunities to defend and improve
gov networks and at the same time pay the participants for their efforts.
Im not talking about making Hacker1 or a bug-bounty, Not That, I'm taking about making this a thing in PR
where we can build a vetted pool of defenders similar to our National Guard.
None of the existing companies already embedded in gov can improve the problem, since they essentially
made the problems, you need a third party.
This can be done, Glorimar, I'm serious about this. We need to protect ourselves and improve
opportunities for those that still live here.
If your part of those companies, we want to help your staff become better so they don't accidentally cause
these problems. We donā€™t want your jobs, we want to help you be better at it.
https://pollev.com/jf484
Gracias
Enjoy the event

More Related Content

What's hot

Municipalities & The Internet: A Few Legal Issues
Municipalities & The Internet: A Few Legal IssuesMunicipalities & The Internet: A Few Legal Issues
Municipalities & The Internet: A Few Legal IssuesShawn Tuma
Ā 
2600 v20 n2 (summer 2003)
2600 v20 n2 (summer 2003)2600 v20 n2 (summer 2003)
2600 v20 n2 (summer 2003)Felipe Prado
Ā 
2012: NJ GMIS: The Double Edge Sword of the Social Network
2012: NJ GMIS: The Double Edge Sword of the Social Network2012: NJ GMIS: The Double Edge Sword of the Social Network
2012: NJ GMIS: The Double Edge Sword of the Social NetworkCarol Spencer
Ā 
Legal Aspects Relating to Social Media in the Workplace
Legal Aspects Relating to Social Media in the WorkplaceLegal Aspects Relating to Social Media in the Workplace
Legal Aspects Relating to Social Media in the WorkplaceBrian Bluff
Ā 
The Form I 9 Compliance and E Verify
The Form I 9 Compliance and E VerifyThe Form I 9 Compliance and E Verify
The Form I 9 Compliance and E VerifyLauren Shreve
Ā 
Social Media in California: Policing Workers Online
Social Media in California: Policing Workers OnlineSocial Media in California: Policing Workers Online
Social Media in California: Policing Workers OnlineAllen Matkins
Ā 
HAR2009 - Your Mind: Legal Status, Rights and Securing Yourself
HAR2009 - Your Mind: Legal Status, Rights and Securing YourselfHAR2009 - Your Mind: Legal Status, Rights and Securing Yourself
HAR2009 - Your Mind: Legal Status, Rights and Securing YourselfJames Arlen
Ā 

What's hot (15)

Municipalities & The Internet: A Few Legal Issues
Municipalities & The Internet: A Few Legal IssuesMunicipalities & The Internet: A Few Legal Issues
Municipalities & The Internet: A Few Legal Issues
Ā 
Immigration News and Updates - March 15th 2015
Immigration News and Updates - March 15th 2015Immigration News and Updates - March 15th 2015
Immigration News and Updates - March 15th 2015
Ā 
2600 v20 n2 (summer 2003)
2600 v20 n2 (summer 2003)2600 v20 n2 (summer 2003)
2600 v20 n2 (summer 2003)
Ā 
2012: NJ GMIS: The Double Edge Sword of the Social Network
2012: NJ GMIS: The Double Edge Sword of the Social Network2012: NJ GMIS: The Double Edge Sword of the Social Network
2012: NJ GMIS: The Double Edge Sword of the Social Network
Ā 
File000098
File000098File000098
File000098
Ā 
Internet Law Primer
Internet Law PrimerInternet Law Primer
Internet Law Primer
Ā 
File000097
File000097File000097
File000097
Ā 
Prepare to practice
Prepare to practicePrepare to practice
Prepare to practice
Ā 
FilmingThePolice
FilmingThePoliceFilmingThePolice
FilmingThePolice
Ā 
Legal Aspects Relating to Social Media in the Workplace
Legal Aspects Relating to Social Media in the WorkplaceLegal Aspects Relating to Social Media in the Workplace
Legal Aspects Relating to Social Media in the Workplace
Ā 
The Form I 9 Compliance and E Verify
The Form I 9 Compliance and E VerifyThe Form I 9 Compliance and E Verify
The Form I 9 Compliance and E Verify
Ā 
Social Media in California: Policing Workers Online
Social Media in California: Policing Workers OnlineSocial Media in California: Policing Workers Online
Social Media in California: Policing Workers Online
Ā 
File000095
File000095File000095
File000095
Ā 
HAR2009 - Your Mind: Legal Status, Rights and Securing Yourself
HAR2009 - Your Mind: Legal Status, Rights and Securing YourselfHAR2009 - Your Mind: Legal Status, Rights and Securing Yourself
HAR2009 - Your Mind: Legal Status, Rights and Securing Yourself
Ā 
OLC Presentation Jipson
OLC Presentation JipsonOLC Presentation Jipson
OLC Presentation Jipson
Ā 

Similar to CompSec Direct Keynote-B-Sides-PR-2019

Writing A Thesis Statement - Book Units Teacher
Writing A Thesis Statement - Book Units TeacherWriting A Thesis Statement - Book Units Teacher
Writing A Thesis Statement - Book Units TeacherJessica Huston
Ā 
Respiratory Medicine Essay Prize. Online assignment writing service.
Respiratory Medicine Essay Prize. Online assignment writing service.Respiratory Medicine Essay Prize. Online assignment writing service.
Respiratory Medicine Essay Prize. Online assignment writing service.Amanda Anderson
Ā 
Staying on the right side of the law
Staying on the right side of the lawStaying on the right side of the law
Staying on the right side of the lawCharityComms
Ā 
How To Write An Essay About My Academic Goals
How To Write An Essay About My Academic GoalsHow To Write An Essay About My Academic Goals
How To Write An Essay About My Academic GoalsNancy Ross
Ā 
Essay Question For Great Gatsby. Online assignment writing service.
Essay Question For Great Gatsby. Online assignment writing service.Essay Question For Great Gatsby. Online assignment writing service.
Essay Question For Great Gatsby. Online assignment writing service.Alexis Thelismond
Ā 
Who Can Help Me Write An Essay - HelpcoachS Diary
Who Can Help Me Write An Essay - HelpcoachS DiaryWho Can Help Me Write An Essay - HelpcoachS Diary
Who Can Help Me Write An Essay - HelpcoachS DiaryDaniel Wachtel
Ā 
9Th Grade Essay Format
9Th Grade Essay Format9Th Grade Essay Format
9Th Grade Essay FormatBrittney Thompson
Ā 
9Th Grade Essay Format
9Th Grade Essay Format9Th Grade Essay Format
9Th Grade Essay FormatKaela Johnson
Ā 
9Th Grade Essay Format
9Th Grade Essay Format9Th Grade Essay Format
9Th Grade Essay FormatBarbara Taylor
Ā 
9Th Grade Essay Format. Online assignment writing service.
9Th Grade Essay Format. Online assignment writing service.9Th Grade Essay Format. Online assignment writing service.
9Th Grade Essay Format. Online assignment writing service.Darian Pruitt
Ā 
Essay Australian History - Lawwustl.W. Online assignment writing service.
Essay Australian History - Lawwustl.W. Online assignment writing service.Essay Australian History - Lawwustl.W. Online assignment writing service.
Essay Australian History - Lawwustl.W. Online assignment writing service.Serena Faye
Ā 
What Is The Most Important Day In Your Life Essay
What Is The Most Important Day In Your Life EssayWhat Is The Most Important Day In Your Life Essay
What Is The Most Important Day In Your Life EssayAngela Jackson
Ā 
Example Of Reflection Paper In Philippine History
Example Of Reflection Paper In Philippine HistoryExample Of Reflection Paper In Philippine History
Example Of Reflection Paper In Philippine HistoryKatrina Duarte
Ā 
Mba Admission Essay Writing Services Onlin
Mba Admission Essay Writing Services OnlinMba Admission Essay Writing Services Onlin
Mba Admission Essay Writing Services OnlinRenee Jones
Ā 
Patents, the Lifeblood of Innovation
Patents, the Lifeblood of InnovationPatents, the Lifeblood of Innovation
Patents, the Lifeblood of InnovationGene Quinn
Ā 
Descriptive Essay About Favorite Place. Online assignment writing service.
Descriptive Essay About Favorite Place. Online assignment writing service.Descriptive Essay About Favorite Place. Online assignment writing service.
Descriptive Essay About Favorite Place. Online assignment writing service.Kara Flores
Ā 
Black Holes Research Paper Outline. Black Holes Resea
Black Holes Research Paper Outline. Black Holes ReseaBlack Holes Research Paper Outline. Black Holes Resea
Black Holes Research Paper Outline. Black Holes ReseaKim Johnson
Ā 
Freedom of information and investigative journalism
Freedom of information and investigative journalismFreedom of information and investigative journalism
Freedom of information and investigative journalismasanders88
Ā 
Causes Of World War 2 Essays
Causes Of World War 2 EssaysCauses Of World War 2 Essays
Causes Of World War 2 EssaysLaura Jones
Ā 
Freedom of information final
Freedom of information finalFreedom of information final
Freedom of information finalasanders88
Ā 

Similar to CompSec Direct Keynote-B-Sides-PR-2019 (20)

Writing A Thesis Statement - Book Units Teacher
Writing A Thesis Statement - Book Units TeacherWriting A Thesis Statement - Book Units Teacher
Writing A Thesis Statement - Book Units Teacher
Ā 
Respiratory Medicine Essay Prize. Online assignment writing service.
Respiratory Medicine Essay Prize. Online assignment writing service.Respiratory Medicine Essay Prize. Online assignment writing service.
Respiratory Medicine Essay Prize. Online assignment writing service.
Ā 
Staying on the right side of the law
Staying on the right side of the lawStaying on the right side of the law
Staying on the right side of the law
Ā 
How To Write An Essay About My Academic Goals
How To Write An Essay About My Academic GoalsHow To Write An Essay About My Academic Goals
How To Write An Essay About My Academic Goals
Ā 
Essay Question For Great Gatsby. Online assignment writing service.
Essay Question For Great Gatsby. Online assignment writing service.Essay Question For Great Gatsby. Online assignment writing service.
Essay Question For Great Gatsby. Online assignment writing service.
Ā 
Who Can Help Me Write An Essay - HelpcoachS Diary
Who Can Help Me Write An Essay - HelpcoachS DiaryWho Can Help Me Write An Essay - HelpcoachS Diary
Who Can Help Me Write An Essay - HelpcoachS Diary
Ā 
9Th Grade Essay Format
9Th Grade Essay Format9Th Grade Essay Format
9Th Grade Essay Format
Ā 
9Th Grade Essay Format
9Th Grade Essay Format9Th Grade Essay Format
9Th Grade Essay Format
Ā 
9Th Grade Essay Format
9Th Grade Essay Format9Th Grade Essay Format
9Th Grade Essay Format
Ā 
9Th Grade Essay Format. Online assignment writing service.
9Th Grade Essay Format. Online assignment writing service.9Th Grade Essay Format. Online assignment writing service.
9Th Grade Essay Format. Online assignment writing service.
Ā 
Essay Australian History - Lawwustl.W. Online assignment writing service.
Essay Australian History - Lawwustl.W. Online assignment writing service.Essay Australian History - Lawwustl.W. Online assignment writing service.
Essay Australian History - Lawwustl.W. Online assignment writing service.
Ā 
What Is The Most Important Day In Your Life Essay
What Is The Most Important Day In Your Life EssayWhat Is The Most Important Day In Your Life Essay
What Is The Most Important Day In Your Life Essay
Ā 
Example Of Reflection Paper In Philippine History
Example Of Reflection Paper In Philippine HistoryExample Of Reflection Paper In Philippine History
Example Of Reflection Paper In Philippine History
Ā 
Mba Admission Essay Writing Services Onlin
Mba Admission Essay Writing Services OnlinMba Admission Essay Writing Services Onlin
Mba Admission Essay Writing Services Onlin
Ā 
Patents, the Lifeblood of Innovation
Patents, the Lifeblood of InnovationPatents, the Lifeblood of Innovation
Patents, the Lifeblood of Innovation
Ā 
Descriptive Essay About Favorite Place. Online assignment writing service.
Descriptive Essay About Favorite Place. Online assignment writing service.Descriptive Essay About Favorite Place. Online assignment writing service.
Descriptive Essay About Favorite Place. Online assignment writing service.
Ā 
Black Holes Research Paper Outline. Black Holes Resea
Black Holes Research Paper Outline. Black Holes ReseaBlack Holes Research Paper Outline. Black Holes Resea
Black Holes Research Paper Outline. Black Holes Resea
Ā 
Freedom of information and investigative journalism
Freedom of information and investigative journalismFreedom of information and investigative journalism
Freedom of information and investigative journalism
Ā 
Causes Of World War 2 Essays
Causes Of World War 2 EssaysCauses Of World War 2 Essays
Causes Of World War 2 Essays
Ā 
Freedom of information final
Freedom of information finalFreedom of information final
Freedom of information final
Ā 

Recently uploaded

Dreaming Marissa SƔnchez Music Video Treatment
Dreaming Marissa SƔnchez Music Video TreatmentDreaming Marissa SƔnchez Music Video Treatment
Dreaming Marissa SƔnchez Music Video Treatmentnswingard
Ā 
Causes of poverty in France presentation.pptx
Causes of poverty in France presentation.pptxCauses of poverty in France presentation.pptx
Causes of poverty in France presentation.pptxCamilleBoulbin1
Ā 
BDSMāš”Call Girls in Sector 93 Noida Escorts >ą¼’8448380779 Escort Service
BDSMāš”Call Girls in Sector 93 Noida Escorts >ą¼’8448380779 Escort ServiceBDSMāš”Call Girls in Sector 93 Noida Escorts >ą¼’8448380779 Escort Service
BDSMāš”Call Girls in Sector 93 Noida Escorts >ą¼’8448380779 Escort ServiceDelhi Call girls
Ā 
SaaStr Workshop Wednesday w/ Lucas Price, Yardstick
SaaStr Workshop Wednesday w/ Lucas Price, YardstickSaaStr Workshop Wednesday w/ Lucas Price, Yardstick
SaaStr Workshop Wednesday w/ Lucas Price, Yardsticksaastr
Ā 
The workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdf
The workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdfThe workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdf
The workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdfSenaatti-kiinteistƶt
Ā 
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdf
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdfAWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdf
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdfSkillCertProExams
Ā 
Introduction to Prompt Engineering (Focusing on ChatGPT)
Introduction to Prompt Engineering (Focusing on ChatGPT)Introduction to Prompt Engineering (Focusing on ChatGPT)
Introduction to Prompt Engineering (Focusing on ChatGPT)Chameera Dedduwage
Ā 
ANCHORING SCRIPT FOR A CULTURAL EVENT.docx
ANCHORING SCRIPT FOR A CULTURAL EVENT.docxANCHORING SCRIPT FOR A CULTURAL EVENT.docx
ANCHORING SCRIPT FOR A CULTURAL EVENT.docxNikitaBankoti2
Ā 
Mohammad_Alnahdi_Oral_Presentation_Assignment.pptx
Mohammad_Alnahdi_Oral_Presentation_Assignment.pptxMohammad_Alnahdi_Oral_Presentation_Assignment.pptx
Mohammad_Alnahdi_Oral_Presentation_Assignment.pptxmohammadalnahdi22
Ā 
Re-membering the Bard: Revisiting The Compleat Wrks of Wllm Shkspr (Abridged)...
Re-membering the Bard: Revisiting The Compleat Wrks of Wllm Shkspr (Abridged)...Re-membering the Bard: Revisiting The Compleat Wrks of Wllm Shkspr (Abridged)...
Re-membering the Bard: Revisiting The Compleat Wrks of Wllm Shkspr (Abridged)...Hasting Chen
Ā 
My Presentation "In Your Hands" by Halle Bailey
My Presentation "In Your Hands" by Halle BaileyMy Presentation "In Your Hands" by Halle Bailey
My Presentation "In Your Hands" by Halle Baileyhlharris
Ā 
No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...
No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...
No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...Sheetaleventcompany
Ā 
VVIP Call Girls Nalasopara : 9892124323, Call Girls in Nalasopara Services
VVIP Call Girls Nalasopara : 9892124323, Call Girls in Nalasopara ServicesVVIP Call Girls Nalasopara : 9892124323, Call Girls in Nalasopara Services
VVIP Call Girls Nalasopara : 9892124323, Call Girls in Nalasopara ServicesPooja Nehwal
Ā 
Presentation on Engagement in Book Clubs
Presentation on Engagement in Book ClubsPresentation on Engagement in Book Clubs
Presentation on Engagement in Book Clubssamaasim06
Ā 
BDSMāš”Call Girls in Sector 97 Noida Escorts >ą¼’8448380779 Escort Service
BDSMāš”Call Girls in Sector 97 Noida Escorts >ą¼’8448380779 Escort ServiceBDSMāš”Call Girls in Sector 97 Noida Escorts >ą¼’8448380779 Escort Service
BDSMāš”Call Girls in Sector 97 Noida Escorts >ą¼’8448380779 Escort ServiceDelhi Call girls
Ā 
Air breathing and respiratory adaptations in diver animals
Air breathing and respiratory adaptations in diver animalsAir breathing and respiratory adaptations in diver animals
Air breathing and respiratory adaptations in diver animalsaqsarehman5055
Ā 
Dreaming Music Video Treatment _ Project & Portfolio III
Dreaming Music Video Treatment _ Project & Portfolio IIIDreaming Music Video Treatment _ Project & Portfolio III
Dreaming Music Video Treatment _ Project & Portfolio IIINhPhngng3
Ā 
lONG QUESTION ANSWER PAKISTAN STUDIES10.
lONG QUESTION ANSWER PAKISTAN STUDIES10.lONG QUESTION ANSWER PAKISTAN STUDIES10.
lONG QUESTION ANSWER PAKISTAN STUDIES10.lodhisaajjda
Ā 
If this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New NigeriaIf this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New NigeriaKayode Fayemi
Ā 

Recently uploaded (20)

Dreaming Marissa SƔnchez Music Video Treatment
Dreaming Marissa SƔnchez Music Video TreatmentDreaming Marissa SƔnchez Music Video Treatment
Dreaming Marissa SƔnchez Music Video Treatment
Ā 
Causes of poverty in France presentation.pptx
Causes of poverty in France presentation.pptxCauses of poverty in France presentation.pptx
Causes of poverty in France presentation.pptx
Ā 
BDSMāš”Call Girls in Sector 93 Noida Escorts >ą¼’8448380779 Escort Service
BDSMāš”Call Girls in Sector 93 Noida Escorts >ą¼’8448380779 Escort ServiceBDSMāš”Call Girls in Sector 93 Noida Escorts >ą¼’8448380779 Escort Service
BDSMāš”Call Girls in Sector 93 Noida Escorts >ą¼’8448380779 Escort Service
Ā 
SaaStr Workshop Wednesday w/ Lucas Price, Yardstick
SaaStr Workshop Wednesday w/ Lucas Price, YardstickSaaStr Workshop Wednesday w/ Lucas Price, Yardstick
SaaStr Workshop Wednesday w/ Lucas Price, Yardstick
Ā 
The workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdf
The workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdfThe workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdf
The workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdf
Ā 
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdf
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdfAWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdf
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdf
Ā 
Introduction to Prompt Engineering (Focusing on ChatGPT)
Introduction to Prompt Engineering (Focusing on ChatGPT)Introduction to Prompt Engineering (Focusing on ChatGPT)
Introduction to Prompt Engineering (Focusing on ChatGPT)
Ā 
ANCHORING SCRIPT FOR A CULTURAL EVENT.docx
ANCHORING SCRIPT FOR A CULTURAL EVENT.docxANCHORING SCRIPT FOR A CULTURAL EVENT.docx
ANCHORING SCRIPT FOR A CULTURAL EVENT.docx
Ā 
Mohammad_Alnahdi_Oral_Presentation_Assignment.pptx
Mohammad_Alnahdi_Oral_Presentation_Assignment.pptxMohammad_Alnahdi_Oral_Presentation_Assignment.pptx
Mohammad_Alnahdi_Oral_Presentation_Assignment.pptx
Ā 
Re-membering the Bard: Revisiting The Compleat Wrks of Wllm Shkspr (Abridged)...
Re-membering the Bard: Revisiting The Compleat Wrks of Wllm Shkspr (Abridged)...Re-membering the Bard: Revisiting The Compleat Wrks of Wllm Shkspr (Abridged)...
Re-membering the Bard: Revisiting The Compleat Wrks of Wllm Shkspr (Abridged)...
Ā 
My Presentation "In Your Hands" by Halle Bailey
My Presentation "In Your Hands" by Halle BaileyMy Presentation "In Your Hands" by Halle Bailey
My Presentation "In Your Hands" by Halle Bailey
Ā 
No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...
No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...
No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...
Ā 
VVIP Call Girls Nalasopara : 9892124323, Call Girls in Nalasopara Services
VVIP Call Girls Nalasopara : 9892124323, Call Girls in Nalasopara ServicesVVIP Call Girls Nalasopara : 9892124323, Call Girls in Nalasopara Services
VVIP Call Girls Nalasopara : 9892124323, Call Girls in Nalasopara Services
Ā 
Presentation on Engagement in Book Clubs
Presentation on Engagement in Book ClubsPresentation on Engagement in Book Clubs
Presentation on Engagement in Book Clubs
Ā 
BDSMāš”Call Girls in Sector 97 Noida Escorts >ą¼’8448380779 Escort Service
BDSMāš”Call Girls in Sector 97 Noida Escorts >ą¼’8448380779 Escort ServiceBDSMāš”Call Girls in Sector 97 Noida Escorts >ą¼’8448380779 Escort Service
BDSMāš”Call Girls in Sector 97 Noida Escorts >ą¼’8448380779 Escort Service
Ā 
Air breathing and respiratory adaptations in diver animals
Air breathing and respiratory adaptations in diver animalsAir breathing and respiratory adaptations in diver animals
Air breathing and respiratory adaptations in diver animals
Ā 
ICT role in 21st century education and it's challenges.pdf
ICT role in 21st century education and it's challenges.pdfICT role in 21st century education and it's challenges.pdf
ICT role in 21st century education and it's challenges.pdf
Ā 
Dreaming Music Video Treatment _ Project & Portfolio III
Dreaming Music Video Treatment _ Project & Portfolio IIIDreaming Music Video Treatment _ Project & Portfolio III
Dreaming Music Video Treatment _ Project & Portfolio III
Ā 
lONG QUESTION ANSWER PAKISTAN STUDIES10.
lONG QUESTION ANSWER PAKISTAN STUDIES10.lONG QUESTION ANSWER PAKISTAN STUDIES10.
lONG QUESTION ANSWER PAKISTAN STUDIES10.
Ā 
If this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New NigeriaIf this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New Nigeria
Ā 

CompSec Direct Keynote-B-Sides-PR-2019

  • 1.
  • 2. Who we are, where we started My company, CompSec Direct, started here in PR, renamed, rebranded but we always keep deep roots here as much as we can.
  • 3. Who we are, where we started For example, here are some PR related efforts we have done to date: The Hacienda case, which I will discuss here today. Spillage of court cases in the Judicial Branch, some involving minors. Still unfixed. Shodan notices to the former CIO of exposed gov related systems. Fixed* Data.pr.gov subdomain submissions of open-data suggestions, pending. Aeronet Whitepages where the provider was providing SNMP information with customer names. Now fixedā€¦.
  • 4. About Aeronet posting I had the privilege to work here for a few months, back in 2007. I am angry at people suggesting drama and taking away from the real problems. In Gino's case, he failed to recognize that if one of his former employees suddenly decides to communicate directly with him after not speaking for 11 years, maybe he should have listenedā€¦.
  • 5. What would you have done? Lets vote to see who is correct here https://pollev.com/jf484
  • 6. About accelerated disclosures, notifications and other contributions I'll ask you, as IT or non cyber related folks, how many time do you believe we have been thanked for our efforts? How many times have we been thanked publicly or credited for our efforts? zero 0https://pollev.com/jf484
  • 7. Thanks That is why I'm here today at Bsides PR for you, not them. https://pollev.com/jf484
  • 8. Oh boyā€¦ We are a conquered race We are good imitators; We adopted every conquering nations beliefs, ideals, customs and languages Our laws, our policies, our industries all started or originated somewhere else https://pollev.com/jf484
  • 9. Here we goā€¦ We are not good innovators Except for our GDP in artists, some notable scientists and doctors we have not innovated anything as a country with global impact where people know and say: This started from Puerto Rico, except reggaetĆ³n* (Started from Jamaican dance hall music)
  • 10. Hard truths Truth hurts huh? https://pollev.com/jf484
  • 11. The imitation failures As good imitators, we struggle endlessly to correct Ineffective policies, ineffective government since we modeled ourselves as the US approved; like them https://pollev.com/jf484
  • 12. Imitation failure example One of the ways we imitate is the political arena and campaign funding, You see, future or existing politicians are nominated by political parties that raise funds https://pollev.com/jf484
  • 13. Imitation failure explained When in office, they cannot legally campaign or aid with resources (people, funds) as sworn members, since they now serve the country not the party* https://pollev.com/jf484
  • 14. Imitation failure based on relation to host country Since we imitate the campaign raising circus in the US, but donā€™t have 350M+ people, the campaigns cannot generate 100M dollars for re- election campaigns Thus there isnā€™t a financial gain here except for the promise of a trusted (confidant) position if elected, and perhaps direct contracting for professional services down the road since you helped. https://pollev.com/jf484
  • 15. Innovation suggestion: Match campaign funds to Education Department Innovation suggestion: Dollar of Dollar campaign funds to Dpt. Of Education. Yes, they will cheat and steal, but at least the money could be used for good... Maybeā€¦ https://pollev.com/jf484
  • 16. How this scenario is different in Federal / other States Here is the problem, I have more experience in the federal space submitting bids, proposal and similar experience at the state level in MD. Both of these have strict guidelines for fair- competition in bids, awards. With the exception of exigent/emergency contracts https://pollev.com/jf484
  • 17. How to do business with the PR government through reputation and past efforts PR is different, if you are well liked by a party, and offered services during the election process, you get preference somewhere in the process. https://pollev.com/jf484
  • 18. How this applied to us For us, I met the (US Person) USP0 during the pre- party nomination, Gave the 30 second pitch, and was directed to USP1. After a few months, we gave a presentation about providing secure comms during the election. https://pollev.com/jf484
  • 19. What is secure comms in relation to OPSEC and Tradecraft? Secure Comms being; Tradecraft+ training+ security measures = OPSEC Tradecraft is what you do OPSEC is how you address risk as a whole by effectively using tradecraft https://pollev.com/jf484
  • 20. Here is an excerpt of what exactly we offered Secure Communications & Devices Solution for 500 devices for 1 year (low six-figure sum) Includes physical, logical and user education trainings for 500 individuals Trainings done in person for groups of 20+ Trainings done via WebEx/Skype for all others HQ Security Review included Requires collaboration and support of users as well as full inventory of BYOD Malicious Insiders Prevention and Detection for 1 year ā€“ (low six-figure sum) Includes unique document tagging and encryption solutions Secure Social Media and Web presence for 1 year (low five-figure sum) https://pollev.com/jf484
  • 21. Why this was never finalized Sadly, this was not picked up. And thus I departed PR and starting working CONUS. Campaigns have a limited budget which is focused on advertising https://pollev.com/jf484
  • 22. #DFWO : Donā€™t Forget we offered Now here is the interesting part. USP0 was forced to resign from lack of secure comms. Now, no amount of encryption can prevent someone else from correlating what you wrote if shared with someone else. https://pollev.com/jf484
  • 23. The Old School Politician remembers the past, GenX and Millennials are more tech focused In fact, the older generation of politicians understand that "we are doomed to what we write, not what we say". They donā€™t trust electronic communications as much as my generation and Gen X'ers since they lived wire-tapping era, ā€œcarpeteoā€, frankly, nobody truly understands how digital becomes distributed. Risk > Convenience https://pollev.com/jf484
  • 24. Errors related to lack of secure comms In this case, USP0 made four critical mistakes that could have almost been prevented: 1. Wrote derogatory statements related to prejudice, discrimination, humiliated fragile social-groups and implicated himself and his cabinet in multiple ethics and criminal acts a. Technology cannot change or improve your culture, upbringing or habits 2. Did so in a group setting without compartmentalizing information a. Almost like talking to intimate friends 3. Publicly attacked a member of said group, USP3 a. By raising conflicts of interest claims related to son, USP4 4. Admitted publicly to the authenticity of transcripts a. A big no-no in politics. https://pollev.com/jf484
  • 25. If you surround yourself with amateursā€¦. Despite being surrounded by lawyers, no one ever stated to USP0 that: "hey bro, WTF are you doing here???" Perhaps something that secure comms oversight could have addressed. https://pollev.com/jf484
  • 26. Methodology for attribution of suspected leaker But wait, are you saying USP4 did this; well here is methodology: 1. Correlate end date of transcripts against members of group, including close- associations 2. Search endi / elvocero for things that happened around that time related to politics 3. One thing really stands out https://pollev.com/jf484
  • 27. Whistleblower laws as they apply to contractors Criminal whistleblower laws in federal space protects government officials > government contractors I know this personally because I have had employment terminated (by employer, not gov) after raising concerns as a contractor. In my case, I followed the process; aka a reverse-Edurado-Snowfall Eduardito, you should really go back and clear out your desk, that says a lot about you. https://pollev.com/jf484
  • 28. MMO for criminal cases explained in plain Puertoricanā€¦ Now, USP4 is perhaps liable for a conspiracy amongst other charges. Means: "Chiko technico" means has knowledge of IT Motive: Publicly part of nepotism case with state contracts via government/contractor relationship Opportunity: "Papi, prestame aca y yo bajo to eso a PDF y se lo doy a CPI" This is now subject to some form of merit because USP3 made public statements about technical knowledge of USP4. https://pollev.com/jf484
  • 29. On why you should never out yourself on something at this scaleā€¦. That being said, no public statements of admission from USP4. ā€œHe's crude, but he's crafty" Mutually-assured destruction via pyric victory. As they say, "STFU and get a lawyer" "He's not the hero we wanted, but the one you got" Which now adds to the corruption narrative in the US, by virtue of reality. https://pollev.com/jf484
  • 30. Innovation suggestion Innovation suggestion: Whistleblower protection laws for also apply to contractors. All in all, effective tradecraft is tantamount in any organization. #DFWO Privacy Screen = Mobile and laptop Disable GPS = Minor annoyance Disable wifi when not in use = slightly annoying Disable bluetooth = moderately annoying Disable Cell = Very Annoying Don't take phone = Wow, so pay phones? https://pollev.com/jf484
  • 31. On the Hacienda case: Day 1 Now, back in 2017, USP1 and I talk. I hear about ransomware in Treasury Department, and was asked to get involved. By the time my flight landed, we get some PR actionā€¦. Interestingā€¦ an unusualā€¦. By the time I make it to Dpt Treasury, it was very late, many IT staff are visibly tired. I am briefed, I ask the staff to prep written statements to they can start getting their stories straight, and depart late in the evening. Guess what, no one did written statements <shocker> so I can't even get a good grasp at what everyone had done until that point. Everyone is tired and no one works over time from home. One thing we did suggest; pay the ransom. https://pollev.com/jf484
  • 32. On the Hacienda case: It could have been prevented but it was too late Not only was Dpt of Treasury breached; through brute-force of a public facing service, it affected the backups as well. The staff involved for IT was professional, knowledgeable and obviously concerned with the incident. To my surprise, every time I asked for something besides statements, they were diligent in ensuring my requests were being acted on. https://pollev.com/jf484
  • 33. On the Hacienda case: If, Else, Finallyā€¦ At the time, ransom for decrypt backups was less than $1,300. To them, this seemed like an impossible option. I suggested to one contractor, UNUSP1, to try and decrypt one file from said backup solution to test if this was even possible. When you get hacked, ransomed, and have no alternatives; you pay the ransom since Recovery Time Objectives (RTO) for businesses trumps everything. Us talking about what to do next, cost over $1,300 so I reminded them of this fact. https://pollev.com/jf484
  • 34. On the Hacienda case: A case for hack naked? Oddly enough, UNUSP1, was not able to accomplish this; which personally seems odd. You see, no one ransoms anything if they cannot make money. The service was up according to UNUSP1, but the statement "maybe it was a dependency of the victim system for bilateral communications that simply caused it to fail" was odd. Communications with the ransomware operators also provided "no communications established the next day". However, since we had not been officially contracted to perform malware analysis, we did not. Instead, I uploaded the "alleged" ransomware virus into Virus Total on March 7, 2017. You may say, upload the hash, not the file. That depends on what side of the fence your on. More on that laterā€¦ https://pollev.com/jf484
  • 35. On the Hacienda case: The malware We are sharing this after the conclusion of the event by providing an indirect link. https://pollev.com/jf484
  • 36. On the Hacienda case: Day 2 By the second day, I re-experienced a common situation when this scenario happens, the system experts, which until the day of the incident had normal responsibilities, day to day duties and obligations, suddenly became engaged forensicators with investigative responsibilities; that was our job. I reminded the team that the situation was not contained, they needed to focus efforts on remediation first and help us collect artifacts of evidence of the crime for us to analyze; not them. Another common occurrence during this scenario is talks related to budget, which serves no purpose during a time sensitive situation like this. At one point, I had to re-address marching orders, since the suggested plan by USP5 was not necessary for purposes of containment. https://pollev.com/jf484
  • 37. On the Hacienda case: It always sucks when it happens to you USP5 had the recently started this position. This is a normal occurrence between government as new elected officials place individuals of trust into government offices. This is why Ben Carson, a neurosurgeon by trade, is in charge of HUD.???? He inherited all of these problems prior to starting and less than 3 months is not sufficient time to get a grasp on even what your environment is. https://pollev.com/jf484
  • 38. On the Hacienda case: Resist customer bias when conducting investigations Let's take a break here on memory lane, whenever I approach any situation involving LE, I think of the movie "Rising Sun". In the film, the protagonist use digital video evidence to help solve a murder case in Japan. Much like the movie, the IT department at Hacienda presented some initial evidence, potential suspects and MMO. Somethings seemed the result of causality, others pure luck, others "very interesting timing". As an IR person, you have to resist your customer bias, opinions and statements and collect the entirety of evidence you can to support any claims. This is difficult when you are not LEO, and you are being paid by a customer. https://pollev.com/jf484
  • 39. On the Hacienda case: Resist customer bias when conducting investigations During our involvement, we provided strategic leadership advisory during the first days for the IR. This resulted in actions with consequences: 1. We brought some systems back online vs forensicating. 2. We provided questions and action plans for the government to ask and do. 3. We provided oversight to the battle plan 4. We briefed the director of Hacienda and the FBI All under less than 3 days. https://pollev.com/jf484
  • 40. On the Hacienda case: On impostor syndrome As I reflect on this event, I felt I was unprepared to accomplish what we were asked to do based on scope, almost like pre-engagement jitters. Those immediately went away the more I talked with the staff, not because of they didn't know what they were doing, but because I have done this before, in a larger scale, with less options. I knew I was in the right place by then. https://pollev.com/jf484
  • 41. On the Hacienda case: Ingles con fronteras Now, for us, we did not sign contracts or agreements with the government to formally do any work. The reason still baffles me, our NDA had jurisdiction in Maryland, which the government rightfully refused, but more so; the document was in English? How can a country that is attempting statehood claim such a thing? To date, I have no regrets as to not jumping in head first in this engagement. https://pollev.com/jf484
  • 42. On the Hacienda case: As a small company, your capped by your ā€œwarchestā€ A few weeks earlier, PR announced bankruptcy and I had no expectations of being paid in a timely manner. For us, we have native islanders that would have assisted us during the IR, but we don't have that capital to pay our staff when it could have taken X months to be paid. So as I'm finalizing this contract, I had a gut feeling that we simply can accomplish this IR, but I had no idea when we would get paid, so I said no to the IR, and instead suggested we do a case study and in the mean time, address language and contract barriers that we as a small company faced. https://pollev.com/jf484
  • 43. On the Hacienda case: Hurricane relief efforts > the cybersā€¦ Maria changed everything. As I was trying to maintain good relationships with USP1, it became clear to me that I did have impact on the IR and other efforts. Sadly, priorities change, so does staff. I don't have the same relationship with the current CIO, but I would like to. https://pollev.com/jf484
  • 44. On the Hacienda case: Well, itā€™s almost like you paid for it indirectly, so itā€™s yours This case study sadly was never purchased, lucky for you, we are providing a redacted version of the case study tonight after the event on our site. The link will only work from PR IP space for the first week, and then becomes public to all visitors. Password to get inside is: <so secure joseā€¦ā€¦>Yes</so secure joseā€¦ā€¦> We are also providing adaptable parts of the questionnaire used during the IR in hopes of getting more C suite visibility on things they can do prior and during an IR. Personally, I really tried to have Hacienda look over the redacted version. ĀÆ_(惄)_/ĀÆ Our case study was evaluated by a staff member at Hacienda, which commended our case study in relation to other deliverables. https://pollev.com/jf484
  • 45. On the Hacienda case: Closing thoughts Since this event was essentially caused by poor change management and poor preventative actions, we can expect this to continue happening. Since then, at least 4 more government agencies have been breached. To date, neither the FBI or Hacienda have ever reached out to us for further assistance. However, they're dependence on non-cyber focused companies continues to grow based on practical needs for PR. They donā€™t have to be secure, they simply need to improve the quality of life for citizens. Placing a Fortinet, (im sorry, youā€™re a sponsor but ĀÆ_(惄)_/ĀÆ ) , does not solve for: any-any rules. https://pollev.com/jf484
  • 46. The appearance of PR on the Net We are a susceptible country on the net. The biggest challenge cyber security has is also stemmed from the same problem security has in general; it produces zero income. The next problems are simply based on awareness of issues and willingness to adopt measures to reduce risk. How can we change that? https://pollev.com/jf484
  • 47. Letā€™s actually be innovators for once We need to change the way government operates. For example, we have an unemployed labor force with some knowledge of IT. We can build a non-profit to help organize the labor pool, provide opportunities to defend and improve gov networks and at the same time pay the participants for their efforts. Im not talking about making Hacker1 or a bug-bounty, Not That, I'm taking about making this a thing in PR where we can build a vetted pool of defenders similar to our National Guard. None of the existing companies already embedded in gov can improve the problem, since they essentially made the problems, you need a third party. This can be done, Glorimar, I'm serious about this. We need to protect ourselves and improve opportunities for those that still live here. If your part of those companies, we want to help your staff become better so they don't accidentally cause these problems. We donā€™t want your jobs, we want to help you be better at it. https://pollev.com/jf484