Skip to main content
Right of Boom
January 30, 2025

Browser Based Attacks

In this video, Gary and Wes discuss the intricacies of browser security and the challenges MSPs face in managing extensions. They explore why extensions are often overlooked in security frameworks and share insights on best practices for balancing user needs with security protocols. The conversation highlights the importance of staying vigilant and proactive in a rapidly evolving digital landscape, emphasizing the shared responsibility between service providers and users.<ul><li>Sales automation is increasingly using tools to handle tasks traditionally done by SDRs and BDRs, with significant portions of the job now automated.</li><li>Browser extensions pose significant security risks, often being used for malicious purposes, and require careful management and monitoring.</li><li>User awareness and security education are crucial in preventing security breaches, as many incidents stem from users unknowingly clicking or installing harmful content.</li></ul>

Guests

Andrew Morgan

Video Transcript

All right, welcome. Um, Gary, We're, Are we close to year three now? I think we're right. We are. Which means this'll be our last show because we only had a three year plan. It, it's like, uh, Seinfeld, Gary, we'll have to start playing some, uh, uh, uh, uh, gosh, I'm trying to think of the, uh, band, uh, with that, with that song. Green, green, green Day. We'll have to start playing some Green Day and Yeah. Well, uh, Hey Wes, good to see you. Wes, can you hear us? Hey, I think, yeah.

So Wes been, this Is what I'm saying. Wes is like a big important, like executive and stuff. Now he is beyond the cyber Call. I know. Like I, I I forgot about that. We, he's got a big announcement that went out on LinkedIn. Yeah. Well, while Wes reconnects, um, let me kind of do a few things here. Um, one, uh, just kind of let you know, there is a, um, sales automation webinar coming up that I think is gonna be really interesting.

Um, I put together the folks from Roost SA Alerts, 'cause I wanted to have, um, an automation kind of thematic. And, uh, we also have, uh, James Barrow, Gary, uh, Jim, Jim Barrows, you know James Barrow? No, that's, um, so we're gonna, we're gonna be looking at all That's A great combo. Yeah. And we're gonna be looking Gary, at all the automation that is being used today in sales. And it's really, it's alarming and it's also awesome.

I mean, things that an S-D-R-B-D-R typically would do, there's a tremendous amount of tooling these days that take care of a huge percentage of the job. And if you look at the statistics also, you know, and these come from Gartner and the Challenger Sale and others about people do 70% of their research and buying before they even speak to somebody now. And it's increasing every year. So it's gonna be really Fascinating. Listen, it's, it's timely.

I mean, with our peer groups, I, we are all over this right now. It is time for MSPs to charge into the early two thousands for sales and marketing. Yeah, Yeah. And this, you know what I mean? Yeah. It can make some tremendous differences just from, you know, being able to, you know, somebody hits your website to be able to go out and, oh, Gary Peek, hit our website. Or Well, okay, here's his information on LinkedIn. Oh, what are blogs that Gary's interested in?

And now we can curate content automatically with things that an SDR doesn't. Instead of, Hey, how are, you know, just checking in. Or, I mean, it, it's, Do you wanna buy yet? Yeah, yeah. This is Normally what they say. Do you want to buy it? Look, this is, uh, Jim Lippy and I have spent hours, you know, after working in software that's very far down the line, everything is around, um, moving people to the bottom of the funnel. Right? Right. Opposite of what MSPs have done.

And now we see it, we see that gap closing. And so, uh, yeah, it's timely. Yeah. And obviously James, uh, Jim Baros, uh, works with, uh, uh, JB works with like, all the top SaaS companies, so this is very near and dear to him. Cool. So that's going on. Um, I have a few poll questions up. Um, and then let me set the stage That no one will answer. That no one will answer. Yeah. Jason, we basically have hundreds and hundreds and hundreds of people on here every week. You can see our total.

Nice thing. No, I don't say that to impress you. We put up a poll. Three people answer, But we got the idea on this. There's Way more than that. Stop it. Yes. All right. Okay. Um, one more, more announcement, two more announcements. One, Robert Chaffey is joining us today, um, looking like a very sexy, uh, replacement of Phyllis Lee. So thank you for joining us, Robert. And, um, We, he's gone through a lot of changes since I, I, I met him. The hairstyle has changed a lot. Yeah.

Well, I think that was, you know, because you moderated that panel, you know, ever since then, Gary, it's, uh, been, now he's, It's part of my, It's part of my personal branding and marketing. You'd be envious of me, Gary. Um, and then Wes, you got big announcement out there, um, a lot. You got some congrats already, but tell us a little about what's going on with you. Yeah, Yeah. Thanks.

So, um, obviously in, uh, addition to what's going on in Path Cyber, I have, uh, just started a role at Cyber Fox. I'm really excited about, I'm the Vice President of Cybersecurity strategy, so helping all our MSP partners in that journey and, um, where Cyber Fox is going is super excited. And, um, I just, it's, it's a match made in heaven. I love Adam and David and crew. So, yeah, man, it's, it's awesome. Big day. Awesome. Good for you. Congratulations. It's basically now, yeah, thanks.

You've got that many more years here in Tampa West, so getting back to Kentucky is kind of off the table. Uh, yeah, I'm, I'm Tampa bound for quite some time now. It's all Florida, man, over Here. All right. So lemme set the stage and introduce our guests. Um, yeah, so, you know, something we really haven't spoken a lot about or really at all is browsers, right?

And, you know, early on, and Jason will kind of talk a little about this 'cause Eric posed a question earlier on, but really, browser extensions, uh, you know, have been seen a lot as something nefarious. You know, in other words, you'll have something where you'll, somebody will produce something, it'll be in the, um, the app store as an example.

Um, we've seen instances where, uh, an organization will buy it and then turn it, obviously the code into malicious code, um, and things of that nature. So, in essence, browser, and again, really broad browser extensions don't have a great wrap out there. And concomitantly, there's not a lot of browser extensions that, you know, in terms of the security.

Um, and I was talking to John Strand about this, and he is like, man, I'll tell you that that's an area that we definitely, you know, could improve upon. And so with that, with those two kind of thematics, um, I wanted to bring on Jason Schiffer, who's knows a lot about this. He's the SVP of technology at Conceal. They're in this space. And, uh, Jason, um, a little bit of background in, uh, a small IR firm right. Uh, out there.

So tell us a little about yourself, your background, and what you do today. Uh, so, um, I, I've been an engineer for 30 years now, and I kind of really dove deep into the, into the white hat side of security, right around 2000 ish. Um, and then very soon after that was hired at Mandiant as their very first engineer. So I kind of started at the ground, uh, there and learned a lot of the IR side and how that pro process works. Stayed there probably the longest I've ever stayed anywhere.

Um, seven years, seven or eight years. And, um, but the rest of my career has all been startups. So I, I deal with small teams, primarily focused on small companies. Ah, see now I'm gonna go do that. Um, small companies, small teams, and, um, but always with a security focus. And primarily because one of the big problems with security from my perspective is it sucks for the end user. They never know what's going on. They don't understand when something breaks, everything.

You know, they doesn't make sense to them why they can't do what they think they should be able to do, and trying to make that better. Yeah. Productivity and security are, are not friends, are they? No, they're not. They, they rarely go hand in hand. Yeah. Very cool. Well, thank you for joining us and thanks for the time, Jason. Absolutely. Um, we're gonna start off with our special guest on the co-host side, Mr.

Choppy, Robert, let you take it away here, and, uh, level set kind of for everybody. Um, some questions. Yeah. Thank you. Andrew, Kind of comes to mind is, you know, just some of the basics, uh, as an MSP, uh, we struggle probably like with most MSPs, um, full well, knowing that browsers have such a broad base of permissions. Uh, so what shouldn't, shouldn't people be doing? Are there, are there a set of best practices that you like or recommend?

So there, this is both easier and harder than it used to be. It used to be flat out, you need to turn everything off just because they were leaking way too much information. Most, as long as you're using a, a recent releases. So I would say anything in the last two years, they're default secure. So they're doing everything that they should be doing. The one thing that I would turn on is HCPS everywhere. Um, most of them now have the setting for that and making sure that that's enabled.

Um, if you have that, then you've covered, let's say, the 90th percentile. There are things you can do to lock it down even further, but then they do really start to impact on compatibility, how it's gonna work on particular websites, that kind of thing. Um, like a very popular one amongst, like my security box. The machine that I go do things on is I turn off JavaScript. If you turn off JavaScript, nothing's gonna work.

The rest of the internet's gonna break for you and nobody's gonna want to use it. So starting there, but I think the key is, is to think about the browser, just like any other third party application. It's got a broad base, but you need to, uh, when you go put word on a box, word can do all kinds of things.

You don't necessarily know what all of those capabilities are out of the box, but you start with, I put it on there and then I just monitor for when things need to be toed down, maybe block its privileges where it's able to write and read from, that kind of thing. Right. Um, thank you for that. Um, so since I'm stepping in for Phyllis, I thought I'd ask some questions that are sort of smelling or a little bit like CIS controls.

Um, I'm centering around some of just the basic hygiene questions, things that, uh, MSPs should be doing to, uh, a inventory, right? 'cause we can't protect what we don't know about. So how do we inventory browser extensions? Uh, should there be some either approved unapproved list, especially when we think about work from home, or really work from anywhere? And are there any kind of policies, uh, or software that helps us or solutions that help enforce these policies?

So I know there was a lot in there, hopefully, Uh, so you should have some form of approval process, just like any other software. I mean, the, the biggest thing with security is knowing what's there. So you're absolutely right. A lot of the RMM tools will do this for you if you're using an RMM. Okay. If you're not, um, and you're using Chrome, Google has a, a policy management tool that's designed around enforcing policy that will give you a list of all the extensions.

And worst case scenario, you fall the way down to the end. The browser will allow you as an admin, particularly in the Chrome and chromium browsers, safari's a little less good at this, but it's getting better. Um, is you can query it via scripts.

So you can actually, uh, ask it and pull back a list of what are the, what are all the extensions, what are their configurations, which is even more important in a lot of cases because you'll have a perfectly good extension like Grammarly that everybody wants to use. It fixes up their grammar. They don't ever have to figure out how to actually write a, a proper sentence.

But there are things you don't want Grammarly being able to do that it accidentally will do, in some cases, like a bad website where it will try to analyze the password field and therefore you're sending your password off to Grammarly. Um, so being able to look in there, see what those are, and kind of tune it. But I think the, For the most part, getting the list of them seeing what they are and looking for the exceptions.

The ones that don't have a, as much as I like open source, there's nobody behind it backing it. And like you were saying, Hey, it may get bought by somebody and then they alter it and they go somewhere. So being able to at least know what those are and then track when their status changes is pretty huge. Okay. I already got something. No, I, I'm just, I'm thinking about like, in the real world, so many things we do, um, and this is not an area that I have, you know, expertise in.

Um, but Ben said, yeah, you know, threat locker can track it, but Right. There's example of a tool, right? People turn it on and so much noise gets created, right? Like how do you manage it just to say like, you know, tracking it is one thing, but managing it to me seems like it would be troublesome. Well, it is. It's a huge pain in the butt. Um, yeah, the, there aren't a lot of good tools.

There are a few, like he was saying, um, there are a few good tools, but If you don't, you need to at least start with what is the list of things that are out there. Um, so it's the same type of thing. When we do go do a man, do an IR audit, we go in, the first step is not to fix a problem. The first step is to see what is the scope of the problem that I'm trying to fix. And there may be certainly a lot of noise.

Like you're gonna have one user that has 30 extensions plugged in, you have no idea what they are. Half of them are something that they downloaded from some arbitrary website and installed 'cause somebody told 'em to, and the rest of 'em are coming from the app store. Once you have that list, then you can start thinking about the security process of tuning it down, figuring out what it is they're going. And more importantly, in the case of that person, you need to go talk to them.

You've gotta find out what it is that they're trying to do. 'cause probably they don't know they're installing things, trying to solve a problem and have no idea. They just installed that thing, it would help. And they never uninstall it. So it's just sitting there doing nothing. Um, a lot of the time that's what we saw on IR at least. So Gary, that's why we need to charge an excess of $300 in endpoint so we can staff and have the right tools, right?

I mean, I'm Yeah, you're thinking the same thing. I'm thinking Robert is like, uh, you know, you, you, you know, you have 3000 seats under management. There's no talking to pe like, like it, this doesn't exist, Right? That's true In volume. But I I it's a real, this is, this is great. Keep going, Robert. Yeah. So let me move along.

I mean, you know, Jason, um, there's a debate with the, even within my own technical team, and you know, I've got a, you know, I've got a decent sized staff here, but, you know, I'm just a small microcosm of what's out there. And even within the office, there are almost arguments on what browser I should use. So should we consider using less popular ones? Things like, you know, I've heard about like things like Brave or some, some other browsers that are out there.

My answer is yes, by the way, I default to using Brave. Okay. Um, the, the biggest thing, all of them have their trade-offs, right? Chrome, everybody knows Chrome, thankfully in the case of Brave, it's still the core same rendering engine. So everything kind of works the same and looks the same, and technically it can be managed the same. So they're the same tools you use to manage that you use to manage Chrome. You can manage Brave, um, or any of the other Chrome browsers.

What you really get is how much data are you willing to share with Google versus not. That's the number one, because they, they do that. And the same thing with Edge. They recently just changed over to using, taking the Google safe browsing and pointing it at their servers. So now they see every Euro that you're going to and don't share that information with you. Um, so yes, they should be considered there. In my opinion, there is no the best browser.

I wish there was, um, it would make my job a whole lot easier, but, uh, they should be considered at the same time. It's, I said, like any other third party tool, it sucks. You've gotta do an evaluation or at least find out what the differences are and find out where your trade offs are. Um, in a lot of cases, a Firefox or Brave or any of the other third parties are gonna get you 90% of the bang that you would get for the other ones. And you, you don't have to deal with any extra overhead.

And the user gets to be happy with the fact that they've got their own browser that they preferred. Um, yeah, I guess, did that answer your question? That's kind of all over the Map. Yeah. I mean, you know, from the MSP's PERS perspective, it's, you know, it's, it's also a matter of what we're willing to support, right? Exactly. That, that unto itself is just, you know, kind of a giant can of worms. I don't mean to go down that, that road, but, you know, that's at least where my mind goes.

Like, so am I just gonna allow any browser? I mean, that's the philosophical Question that, that one I wouldn't, because while there are a lot of same type of thing, very good, very, uh, direct open source browsers at the same, not Escape Navigator. It's awesome. Um, at the same time, from a support standpoint, from my perspective, there are three, um, and three, uh, there are two that are branded names.

So you've got Firefox and Safari are the two, like by default, you're gonna see 'em on a lot of machines. Yep. And then any of the commercially supported chromium browsers, so Chrome, brave Vivaldi, uh, those are kind of the big three. If you're sticking it there, your management is at least understood. Um, you know, from my standpoint, hey, I put 'em all on a chromium based browser, and I'm just gonna peeve off, you know, a quarter of my, of my clients.

Um, but finding that balance in those three main branches is probably the easiest route. Now there are a bunch of really great browsers that aren't commercially backed, that are still very great, but you can't go supporting Night Fox and, you know, every other rebranded variant of a third party browser. Yeah. We'll go nuts. Yeah.

Um, so my last question, uh, is around making determinations between good and bad extensions, it almost feels like there should be some sort of like good housekeeping seal of approval out there. And then you even see things within the Google Store, for instance, that has, uh, you know, passed all their tests, uh, released out into the public, uh, benign, but then ends up being either used for nefarious purposes or, you know, ended up with some malicious code in there.

So do you have any insights about, like, you know, how do I know whether something's good or bad? Well, one, thank you for the product idea. Now I've gotta go pitch something to my boss. Um, Well, we're partners in this. There you go. All right. Um, it's, it is getting better. So I'm gonna start with that. The app stores are getting better, they're getting more strict.

Um, if you've been involved in browser stuff at all, there's this huge thing happening with Manifest V two versus manifest V three, which is super low level technical, but a lot of what came along with that, um, good, good and bad. But one of them that came along with it is the requirement for all of the permissions that you desire to, for your extension to do now have to be explicitly stated. And it two pieces to it.

One, if you have code that expects that capability and but the capability isn't registered or you put in the capability, but there's no code to sus support that capability, both of them will get rejected. And that's like the simple one for the, uh, Chrome web store to be able to kind of filter out, let's say 80% of the malicious kind of hankness, their review process has gotten, uh, stricter. So it is getting better.

It's not perfect, just like you've got, you know, they've had, well, the strictest one in the world, iOS, um, they've had malicious stuff end up on there. And usually what it is, is that it's not that they're, they're stealing resources, not information. Mm-Hmm. So what'll end up happening is that it'll be running a, a Bitcoin miner on your phone behind the scenes, and nobody will, nobody will see it. Um, that's bad. Do what? That's bad. Well, not if it's yours.

It's your Bitcoin miner, then it's perfect. Um, so there's that. Now the second part to it is they're now, particularly as we've seen with the phones, where you're starting to see more and more of the permissions being exposed and more and more so that people can see what this application is trying to do that's outside of the norm. And yes, this sucks, but it's one of those things. You have to review them. You need to look at it and see what's there.

Now, one of the nice parts is, is I, and it's hard for me, but it's great for you guys. If I go change your permissions on my, on my extension and add in a new capability, let's say I, I add in identity management and I have no, no declared reason for needing identity management, when you go to push it out, it will actually notify you. This things change. The, the permissions on this have changed. Are you sure that you want to have it pushed out?

So my first statement would be, get all of those things under tooling. They give you absolute control to say now. Right. Don't, don't, don't upgrade. Don't, don't do anything with it until, until you have the time, which may be never, but at least you have controls over the known versus the unknown. Um, yeah. Did that, did that get where you were looking for? Yeah, I, I mean it, I think so, uh, since it's a tough Problem. Yeah.

Since there's no good, you know, uh, good housekeeping seal of approval yet, yet, that's the key word, but it's coming, right? Yeah, yeah, that's right. Absolutely. Um, it, it sounds like that we just, you know, we have to do our due diligence to just keep on top of these things, just like security threats, uh, that have nothing to do with browsers, let's say that, you know, we've just gotta stay on top of these things. It's part of the job. It's just like an a non-managed firewall.

It worked the day that you turned it on, but after that, it's slowly degrading over time unless you do something active. Gary, I think I'm at 400 bucks an endpoint now. Yeah. And, and climbing. I'm with you. Yeah, yeah, for sure. You know, Turning this back. Yeah. So, uh, I'm looking at the poll question here, and 90% of people said that they don't have, uh, strict enforcement for their clients. Uh, and almost 70% don't have it for, for their MSP.

So obviously, you know, that, it kind of leads into the question, Andrew, when he was set in the stage, just talking, you know, we hear about mainly when something's bad in turn of actions coming from installing browser extensions. Why have security companies for the most part, really not talked about this? Like, what is it that, like a stigma or what, what, what, why has this not come up for three years on a cyber call? That is a tough question. So That's what we ask here.

We ask the tough Questions. Yeah. Well, the, the, so the thing is, is that there are, It's a combination of things. So the first one being that the security industry primarily started with thinking of protection as building walls or layers of walls around whatever the asset is you're protecting. So you've got your firewall, you've got your DNS filtering, you've got whatever it is, they're all the way out.

So the inside can do whatever they want to be doing while the outside you're being protected from it. Um, however, as those walls got taller, our adversaries, the people that are trying to get your data, are trying to get to it, they're shifting too constantly. And they're not, you know, they make good money doing this. So they're very incentivized to be going after it.

So as they changed the tactics, they started finding, looking for the softer and softer spots, the, the, the equivalent of how do I find the corporate's version of the, uh, Nigerian print scam in order to get data in or out of that, that institution. Um, it's starting to change, but I think there is some stigma around, oh, extensions are, extensions are trivial. One of the other big parts is that extensions can't be closed source.

I can't distribute an extension that you can't go and read the code on. So a lot of companies are really, really concerned about, oh, if we put all of our IEP in there, then it's a problem. Well, from my standpoint, that IP doesn't, that the source, I want everybody to look at it. I want them to find my gaps. I want 'em to see what's going on in it. My intelligence is not in the extension. That is the thing that manages the intelligence.

And so as companies start to shift and think in that realm, then it gets closer and closer. Now we've got good security tools that are out there, browser-based VPNs are becoming more and more popular. Uh, third party password managers are pretty popular. And actually, I very much suggest those. That's probably the number one thing. Um, so slowly but surely getting people thinking about that the browser is actually the endpoint, not the machine.

The machine is important, but the browser is your endpoint. And if you're right now, you're not really protecting that endpoint. And that's, like I said, I think there's a bit of stigma to it. I think it feels a little trivial and people are a little too close to the chest with their car sometimes. Yeah. And, and I guess, yeah, go ahead. We Opinion question.

Um, I think a couple things as well is, in my old perch days, the number one escalation that we had for clients is browser extension, malware, especially our large enterprise, because there was so much sprawl and they never locking that stuff down. What's interesting though is it never got the attention it needed because it is an entry point that then causes problems from there. It's almost like if I do, it's like the symptoms. Like if I don't brush my teeth, I get a root canal.

All we wanna do is talk about root canals. We don't talk about not brushing our teeth. And there's a big element to that that we have not really just in a security world as a whole, like you look at, like if you've shared a bunch of links in chat here already, you look at what some of the stuff does. It has the capability of bypassing MFA has the capability of, um, taking credentials and siphoning 'em out. It has the capability of redirecting you to places.

None of those things are necessarily gonna be a game ending scenario in and of themselves, as long as you have other good controls around it. But it's enough weaknesses in the armor that eventually something happens. And that's, there are breaches, I know of ransomware events that we've, we've dealt with that have come started from a, a, an extension, a malicious extension.

So I think that's part of the answer why is we haven't done a good enough job focusing on this, because it seems to be, it's a little bit more symptomatic than it is like root cause. Um, and, and sometimes we just miss that. Hey Wes, just to your point, I love what you just said, and David McKinnon said this at write a boom. He's like, people think of, you know, an incident is like, it's this massive thing that just happened. And it's typically these breadcrumb of things that happen over time.

And I'm really glad you pointed that out. Again, that's Actually, uh, outside of the security realm, but they look this in aircraft accidents. It is almost never one thing. It's like thing one was missed, thing two was missed, thing three was missed. Thing four somebody thought about and they still decided to do the wrong thing. But the fact that they decided to do the wrong thing at that moment collapsed all the rest of 'em. And now you have an incident, you have a crash. Yep. Interesting.

Interesting. So let's just stay, let, I'm gonna take this thought a, a a step further. And why, for the most part, having the security framework suggest like really a lot of specific controls in this area. Is this the same mentality? Well, uh, partially it used to be early on it was no extensions. Right? Uh, if there was any policy enforcement, but that was all manual policy enforcement. Like you scan the machine, go look at it. Yeah. Oh, I see. They've got an extensions remove them. Right.

Um, the problem is, is that there are really useful extensions. So they started making exceptions and then it became that big overhead. You were talking about managing too many things. You've got 40 other vectors coming in, and you just started telling people don't install, install bad extensions, which is the equivalent of saying don't click on bad links. They have no idea of how to manage that or how to even think about it. Yeah.

So, um, even with training, like for instance, I'm telling you guys, oh, you need to go look at, look at what all the settings are for the, for the extension. In some way, that's actually a trite answer because you need to know what those mean and then why you need that particular capability or not for the extension that you're using. So now you need an expert, you need somebody who can, uh, talk through it, but it is the process.

But that doesn't mean that the process selling becomes easy or even manageable in a lot of cases because it is a big project, uh, process. Um, so I said it used to be nothing. Then they just, from my perspective, dropped it on the floor. It became an IR problem, not a prevention problem.

And so we started looking at, uh, much like Wes was saying, it became something of looking at when you started looking for root cause you stopped at this malware ended up on this machine, and the machine did X, Y, and Z, or that malware did X, Y, and Z and you didn't look at, well, how did exactly did that get here? Oh, well it came through a browser. Well, dumb user downloaded it. Yeah. That, that's how far it went.

And so it kind of dropped, it's starting the very beginnings of People are starting to think about, that's what I was kind of talking about, Chrome and those guys building in more protections of trying to analyze and do stuff. The scary part is, from my standpoint, there are a lot of really, really useful tooling as extensions.

And if we continue to go down the road of not managing or not figuring out how to manage this as small companies, uh, anyway, engineers, your security staffing, figuring it out, they're gonna lock it down so far that the only tools that will be up there are meaningless. They don't do anything of any utility at all. 'cause it'll be locked down that tight. You can't do anything. Um, Hey Gary, just a quick question to Jason. Jason. So Google buys Mandian.

Is, is there any foresight there of maybe, well, hey, if we have, man, you know, we have the, as you said, the endpoint now with the browser for most things. Is there possibly some thinking there? Like, well, we also have better telemetry than anybody now if there's an IR issue, because we also have, you know, the cats meow and Mandy under Oath.

Yeah, I was, I suspect, but I also think, I know I wouldn't, it's not exactly insider knowledge, but that they, I think they were looking at it as tooling for them to be able to investigate internally at a much better, at a much better pace. A lot of what they got out of that was, now I don't have to pay this umpteen bajillion dollars for being able to look at my own equipment and be able to do analysis and scanning on it. Um, that's kind of my perception of what they were.

It was a cost cutting process. I was just say, because, because Google was sitting on such a, a cash hoard that buying Mandy. Yeah. It was no big deal. I wish I was there when they did that. I should have stayed just a little bit longer Then you wouldn't be here with us today. Oh no, I'd still be doing this. I love this stuff. Yeah. So Jason, how are malicious sites getting around built-in browser security?

Okay, this one's actually a pretty, pretty common question that I end up with both on the business side of, well, I Google catches all the bad sites. Well, the big thing is to realize what does Google safe browsing do at its core? Google safe browsing takes, they have two big lists. List one known bad sites. We just, we just went out and scraped these websites and we saw that they had some malware on them or a phishing site on it.

Second site is this site used to have malware on it or something? And that's their, that's the one when you click on it, it says, Hey, this site may not be safe. A lot of times that's HGDP or, or port, uh, uh, using an alternate port. But it's also the list of, maybe it's not, it used to be bad. Maybe it's still not bad. All of those sites get updated by a very, I mean, there's an automated processor around it, but it needs to be reviewed.

A human being has to check it, and Google is trying to do this for the end, every user of Chrome in the world. And so from that standpoint, they have to be very, very certain about where they're directing you in one of those two cases. So the way that users or that, uh, the, the, the bad guys are getting around it is either by hijacking sites that have a good reputation that are, they tend to be scraped less often because they have a good reputation.

And, uh, starting at brand new domains, those are the two primary ways that they get around it. Or directing you to IP addresses, which they still fall on the same category, but they get past DNS filters at that point too. Um, so they're, they're doing those two things to be able to get you in. And they're, what we're seeing now, at least in most of our customers, are what we call drive by drive by phishing, drive by malware, where they are targeting you as a company.

If a scraping engine goes to it, it looks completely different. It presents a different website. They, um, if you come from let's say like a Capital One's domain space, you get a Capital One looking image with a, the right, the right colors and the right icons and all of that show up to get people past that first step of, is this where I should be going? Is this where it looks like it is intended?

So there's that combination of really rapid, oh, and those sites will only be alive for eight hours and then it goes away. So they're missing a lot of the automated scanning tools. A lot of that is missing it. And by that point, they've already collected everything that they want to get off of it, and they're moving on. You know, this is making me think, uh, Andrew, um, just why we focus so much on, uh, right of boom. Like this is just another example.

And if you look at the poll and you think through this with all the other stuff we have going, I don't think in any time soon that us as MSPs protecting ourselves and our customers are gonna get great at in the short term. And it just isn't. Right.

Another example, how so much of this every time we bring up and we're all getting better together, but there's so much now and it's changing so fast that, you know, being aware and knowing and having somebody have an eyes on glass, uh, to know when one of one or more of those breadcrumbs have been left becomes the most important thing. Right. We talk, like obviously we talked about it, you know, in, you know, in San Antonio, right. Um, about it.

But it just seems now to be that theme comes up every week, doesn't it? Yeah. Yeah. Yeah. You mean Dallas? You mean with writers? Dallas? That's okay. Yeah. No, it's, it is, it, it it is not getting solved anytime soon. Yeah. Well, the bad news is it's getting harder and harder for MSPs. The good news is valuations are going up. Yeah. Yeah. So it's, it's risk, it's risk reward. Right? Yeah.

And, you know, and the ones that are on with us here, Gary, and the ones that are showing up at the security events, um, you know, that I, I am optimistic, you know, I, you know, when, you know, I think about 2016 when I really started focusing in on this area where we are now, it's dramatically different. I mean, I remember Wes and I first started working together and we used to sit there, uh, get off a call and be like, did you just hear that?

You know, and, and you know, 'cause of Wes was just coming out of, you know, corporate security, you know, and so I I'm with you. I, my balance between excitement and nauseousness has changed. Right. In a positive, in a positive way. Um, but I, but I will say though, I deal with the broader audience. And so there's still a big swath of it providers, I'll use the word it providers first before MSP. Yeah.

Um, That are still where, what you're describing when you and Wes were, you know, early in this. So really good. Wes, I'm gonna make sure you have time. So, uh, I'm gonna, I'm gonna hand it over to you. All right. No, that's cool. Uh, and we'll see how this goes. I may hit the mute immediately when the uh, the intercom guy comes back on. But this has been a great conversation. I wanna zoom back into what Lisa said. I love that she said, why are we not talking about this more?

Why has it been years and we're just getting into it? But, you know, Gary, it goes right to your point. It's very well said that like, there's just so much to talk about and, you know, we just can't possibly get to all of it. So don't feel like you're, you really are eating an, an elephant here for sure. And there's so many things that you, you do need to focus on. And one thing leads to another For sure. So maybe we'll just start with this one, Jason.

'cause this has been such a great conversation. Um, we do train, like what's the role? Let me, let me come back to the user responsibility for a minute. User awareness, security, education, all that kind of stuff that we talk about. How does that play into all of these things? 'cause you gotta think, you know, see something safe. Something could be helpful here too, right? Uh, actually I think it's critical.

Um, everything that we, everything that every security tool I've ever built has always comes back to somebody clicked too quick or installed something without thinking about it or whatever. E every single, I mean, well not everyone. We've had a few that were actual external attacks, but those are way more rare now. So I think, So there's one problem I like, uh, I like, uh, phishing simulation as an example. I use that, um, one, there's a real problem. I think we use it wrong.

I think that when we use, uh, phishing simulation, one, it is too fun for the guy who's doing it. Lemme see how many people I can trick, right? Where, what I really need to be seeing is how do I give, how do I present a very realistic example of what we are actually seeing as a company which is very specific to the company, and see who, who fails through so that I know who to put more focus on, add more security barriers to do that type of thing.

Whether it's the CEO or the, the, the front desk. Um, I need to know who they are. We, we recently did a simulation, um, at work. And that's one of the reasons why it's very fresh in my head of, of how much fun it is because I, this thing looked like it came from me, it came from my account. All the normal attacks. We know that they can happen. Absolutely. And we've actually seen them coming in, in-house. And the only distinction that I made between them was that I changed the tone of the mail.

And the number one thing that I got back from people was, it didn't sound like you. So kind of the, the point getting to training people to look for, not look for, oh, that email address doesn't look right. That's great. But that's just a signal that if it, if it, what, what's the old phrase? If it sounds too good to be true, then it probably is. Well, you have the other, the one we used when I was at a OL doing security is if it seems hinky, then it probably is. Right?

If anything about it throws you off, make positive contact with the other side of this thing. Don't try to, you know, oh, oh, the boss just messaged me with, uh, uh, saying that he needs, uh, $10 'cause he is stuck at the whatever to go get him a card. My wife knows better than that. Matter of fact, her, her, when I told her about one of those events, um, her first statement was, anybody who's asking you for a to go to the, to the store to get a, uh, a card, there's something wrong with that.

So, but we don't talk about it. That's never really part of the training. But that's an ab absolutely. The type of thing that, that's happening constantly. So getting out of the, oh, I ran a simulation. I had three people fail. They went through remedial training. Um, great. The same two of those same three people fell the next simulation attack. I need to be raising barriers around them to, to make sure that they're in. 'cause people are always gonna fall for stuff.

I mean, I can just spell guarantee. Yep. We, as your example, you've, there's, well, yeah, I'll use myself. So I don't even point everybody's done this. You're super busy, you've got 40 other things going on. Email shows up and you go click, you know, you just do the fast scan and you click through it.

So getting it away from it, just being the security training and getting it to the follow on, which is one that I constantly think about is how can I take the fact that I detected this event and turn that into a training event. So neuter the, neuter the tool that whatever it was doing, and then point out all the indicators that were happening inside of that at that moment.

So maybe the person can learn in line as opposed to being a completely separate training that they're gonna figure it about. They just wanna get back to work or go pick up their kids to school. They don't, You know? Yep. Yep. Well said. Andrew, you gonna say something? I saw you call off mute for a second.

Well, I was just gonna, I wanna give you time wise, but I was simply gonna say that to Jason's point, like we, with spearfishing, it's a really good point, Wes, and, and count compromise these days. You have to maybe think a little more about tonality, you know, does, does that really sound like Wes? Because certainly looks like his email, right? Right. So Yeah. Was that, did that email, was he threatening to throw you off a helicopter? 'cause if he wasn't, it might not have been.

We it might been chatting, it might not have been. Yes. Makes you wonder. Yeah, like If, if I get an email from we, and it wasn't really snarky. I know it wasn't from him Or chatting Right. Exactly. That Or Yes, that day's coming. Yeah. I think it's that day's coming, uh, yep. Uh, and, and even the voice stuff, you know, has gotten really good. If you've got enough voice samples.

Uh, Joe Rogan was talking about that recently, that there's now ads that sound just like him and it is him, but it's not him. It's been all sampled. Yeah. You did a whole podcast. Well, particularly if you can increase the stress level on the person on the other side of that, the, the social engineering side of it, all those normal detection signals go right out the window. Um, so yeah.

Even if the sound's not perfect, if it's close enough and I can make you stressed enough, you're gonna fall for it. Yep. Alright, let's jump to Lisa's question in the sidebar. It was really good. And I'm gonna give you, so Lisa asked, what are the top, I love so practical, what are the top three things we should be doing in relation to all this? Let me give you my top three, Jason. Um, and then I want you to add or remove or whatever. And anyone in chat, feel free to do the same.

And Gary, we, we gotta know from you too, my friend. So here's, here's my three. First of all, I would go down this journey of what browsers do you even allow. I would start thinking through what is you, this goes back to CIS one and two, what browsers are even running in your network, right? And then you need to standardize. You need to say, which one or ones will we accept? You need to understand there's pain and punishment.

If you accept more than one, I know there's a Holy war, but step one is what browsers are we gonna allow? Step two is based on that browser. I gave a link way early in the chat. Let's say you standardize on Chrome and chromium. Step two is then how do we control what Chrome can and cannot do?

Whether you use a third party product, whether you use just native stuff, whether you use GPO, you need to then go and lock down what are the capabilities and extensions that we're going to approve and, and go from there. And then the third step that I would give is what you just sort of mentioned, Jason, which is the security awareness element. So make sure they understand why this is important.

So make sure that they can point out some signs of weirdness here and understand how these things can be so damaging and kind of go through that route. So that'd be my top three. Jason, I'll put you on the spot. What are your top three? Uh, I actually agree with yours, but I would add a fourth. And that is to have some type of review process that, uh, that does two things.

One is allows the users to the people that are on the endpoint that are actually trying to get work done to be able to say, I, I agree or disagree with the decision and here's why. So maybe I will make the case for, I need this other extension. I need whatever. And then make some case for it. And then two, that that the second step of enforcement.

As much as you can automate that so that you're always pushing for the newest, newest versions of the browsers, unless you hear about events that are, are associated with that newest version of the browsers. So being able to roll backwards and forwards with rapidity. Alright. So the faster you can do that, the safer you'll be. So that when Chrome, whatever, oh, we found this new zero day. It's only in the latest version, there'll be a patch out in two weeks. Yep.

Roll back and everybody just gets rolled back. Um, being able to do that, I think, uh, kind of closes out those three. And I agree, um, with you on the others, It's almost like though what Wes um, what Jason's just sharing there, very similar to when you look at, um, privilege changes, right? You know, roles in an organization, right? Someone changes roles. Do they still have access to this data? Do they still need access to this share? Do they, it it's, it seems very similar.

Jason is, again, it's about do you have good process in your company Actually yeah. That, that is one other one that there, you have to, we have to stop thinking about one browser configuration fits all. If you, you're falling into that same trap of, if I, if I lay out one exact one, and it may be you only have three, right? You have engineering, you have executive staff, and then you have everybody else. Whatever it is, you've gotta have the ability.

'cause that way you're not, what's the worst thing in the world you can ever do is tell an engineer that he can't do that. He's gonna find a way to work around it, right? Oh, I'm just gonna boot up with my own USB stick and be doing whatever the hell I want to. So you want to make it so that they can get exceptions that allow them to be verified and validated and or at least known about, right?

If nothing else, I know that this guy's doing X so I'm locking off all his access to all the, the, the crown jewels. 'cause he's gotta have whatever. Um, I, I do without one actively on ours, on our development team, I'm the only person who runs everything off of a Lennox box. Well that takes me outside of the controls of a lot of the other things. So what do I do? No, it happens that I'm enforcing it. I have no direct access to any of our core data.

Not because I think Lennox is insecure, but because they cannot monitor my machine in the same level. So I do not get direct access. Alright. So making those balancing choices between there I think makes a huge amount of difference. I I wanna point out what Eric, uh, said over here. That they, uh, catalog the apps, create approved list and then remove unapproved and they review those and the extensions in the VCIO process.

The thing I like about that approach is he's putting it within his current motion, right? And his current cost structure. As soon as you start to get beyond that and you're dealing with things now in a reactive basis, what do I say, every week? Right? Uh, that sounds expensive. Right? Well I love, I love what you just said, Gary. 'cause again, you know, Eric's a student, right? It's on the Fairway. Depend on the fairway. Yeah. And he, he has a role assigned to it.

He probably can tie an, you know, a number of users to that. The it's in his process. And also the dude charges a lot more than most. And, and he can under that standpoint, in his cross structure, he can afford to do it. Yeah. We can't do things for people no matter how well intended that we can't afford to do. Yeah. Right. We either have to find another way to do 'em or we gotta change the commercial structure of our relationship. So this is a great, this is a great conversation, Gary.

One of the things Andrew I think would be really healthy as a follow up at some point soon would be just talking about SaaS management and kind of diving in a bit deeper to what Eric said. Maybe we could get like Eric on and we could get, um, like John Harden from SaaS. Leon might be a good guest and just sort of talk through like, because I don't think a lot of MSPs, let me just pull the audience here.

And then Gary, I wanna pull you and Robert, I wanna pull you too, how many MSPs are really doing a good job of what Eric just expressed around SaaS management, reporting, understanding what's happening, having a process to talk with clients about it, even knowing how to discuss with the client, why it matters that they're all signed up for Dropbox Home. I don't think we renew Anything. Not a lot. It's not a lot are we had, we were talking with Chip buck right. About this.

And um, yeah, we can get Lippy involved in a conversation too, but yeah, not as many. If you think about it, Wes, it's, that's where you really should be starting working backwards today, right? Well, and it's what people, you know, Jason, you said about, you know, the engineer work array around, but if you think about it, users, you constrain a user too much with a policy. The, hey, there's this fast app over here, I'm just gonna go do that.

And how many times do we see those types of things that come full circle to, well, the policy was so stringent that I went and did this, which was the initial, you know, reason for the, the start of the kill chain that led to all these other things. So yeah, You see what Bob said earlier, Bob Miller, I think it was said, um, you know, we getting to the point where we can't have people save passwords. I'm like, well there's a good example.

Like, you don't find like every single person's gonna find their way around that. Like all day long. All you're doing is you're in your browser and all your apps all day long now. Yeah. That's, that's a great example. Great. I think one of the, the, to me, one of the keys there is to make it actually valuable for the user to do the right thing. Right?

So, uh, getting my wife to start using different passwords on every website that she went to actually was a matter of me getting a, a password manager that she could, that she understood enough that she would click on generate new password whenever she went to a new website. It was easier than typing in her, you know, her single password. And once I got it to that step, it all went away. I never had to deal with that, that failure again.

And that's very specific to the company or the people or the culture more than anything else of what are the things that are actually useful from, you're talking about the business side. I actually think in a lot of ways we have to start giving them trade-offs. Giving people trade-offs of, look, I am unwilling to take this level of responsibility for your security unless you're willing to raise your bar up here. Right?

If you're not willing to install a password manager on your end point, then I can't take ownership for all of the third party sites that you guys are signing into. 'cause one, one loss and, you know, everything gets hacked. Wait, Are you suggesting a shared risk relationship? That's, I know right Now it's 500 an endpoint. Hey Wes, let me flip it on you. Do you think, I mean, maybe Sure.

In the world of insurance, you know, how long before we see this question on an insurance, a cyber, uh, uh, application, you know, how many browsers, You Know, putting, do you manage, uh, extensions, blah, blah, blah. Let me play the pessimist role here, because I think Robert were years, I, I'm just gonna say never at this point.

And the reason I'm gonna say never is because the underwriters that affect what's being asked for and ultimately how they decide on these things, do not see in the forensic data. Going back to what I said before, this is a lot of symptom, not necessarily like what they would call root cause. I don't think they see this enough to start asking for it. And that's a huge problem. It, again, it's a hygiene thing.

So if I had to guess, I would say I don't think it's likely at all that carriers are gonna ask for this stuff. I do think it's likely that carriers are gonna finally get to this world of like SaaS management and what do you have sprawled around? Because you know, now with all these data privacy laws and data leaks becoming a cyber issue, that's a problem. Right? And I think they see that, but I don't think from a browser toolbar perspective that I, I just don't see them asking it.

It's a great Question. No, probably they'll stop at the browser at, at most. I agree with you. Yep. Alright, last question for you, Jason. This has been a really great conversation. Um, anything innovative or interesting you've seen threat actors do in this whole space? Just from your guys' visibility that you'd like to share with us? So, yes.

Um, we had very recently a drive by a spearfishing attack and they had built it in such a way that a, you had the phishing, the initial phishing page and it was targeted at our CEO and he's really, really good at detecting these things primarily. 'cause I think he ignores his email unless, you know, it's a phishing attack and when you click through to it, it had it, it had, uh, embedded code on the URL that told it which campaign it was running. We were able to go and get forensics on that.

And they had a hundred sites and they left some of their tooling. And one of the key parts to the tooling was this entire campaign was automated from the standpoint. They said, I want to go after this company, click a button. It went and scraped our site, pulled our imagery, pulled our, uh, text and language out, shoved it into an email, sent it off, built a website for it to click through to, and then they used multiple redirects.

So they started with the good domain, redirect, redirect, redirect, end up in the, in the bad domain, the brand new site that had only been up for like three weeks or something along those lines. And they just tore it down. The moment that we started fishing into it and digging into it, they just tore down that end point and spun it up in a completely different place. Um, so they are, they know the patterns that get that break.

Most of the tooling, like the redirect chain breaks so much tooling. Um, the, the brand new domains breaks an awful lot of stuff. Uh, if I, if I could put a, a blacklist on all IP address direct sites, I would absolutely do it. It just happens that it breaks almost all SSO login, um, that type of stuff. They're getting around a lot of the tools and every single time we come with a new tool, they're finding a new way around it.

Exactly why I was kind of getting to the point of you've gotta get the user to the point and it's actually the cheapest one to do. If it's, if it seems hinky, it is hinky, don't click on it. You know, if the more we can get people thinking there, you're never gonna get raise away from the guy who's going to answer the Nigerian pres. But at the same time, if you know who that is and everybody else is going, ah, this just seems a little bit off the answer is not the, the, the answer's not.

Lemme click through and find out. The answer is lemme talk to my security staff and have them review it or make positive contact with a person. Something, um, uh, yeah, that's, they're getting around that way and, and always if the, if the person on the other end is trying to increase your stress, just immediately become sensitive, whatever it is. Yep. Good stuff. Ibu me out. I'm getting bummed Out right now. That's what I was thinking. All right. I wrote it in chat.

I'm like, I'm pretty sure no one wants rescue. Thank you, Gary. Thank you. Oh gosh. Great. Um, great, great. Wow, Jason, um, you knocked it out the park for us and, uh, really, really appreciate you joining. Um, I put your LinkedIn while ago up there. Um, I'm sorry. Oh, Kidding. Um, I think it was really bad. Um, no self-deprecation. We'll leave that for Gary. Um, uh, I put your company at the bottom and I really appreciate you, uh, spending some time with us. Um, Wes, congrats again.

Fantastic. Very happy for you, Robert. Thank you for filling in as always, and, and great to see you. Um, so Gary, thanks as always. And um, I think this, you know, I know we've talked about doing a special episode, but I wrote down and I promise I'll get it out there. The kind of a SaaS application slash onboarding process would be a great one for us to do a special project on. We haven't done 'em in a long, long time, so I'll work on that. Jason, again, thank you my friend. It was a pleasure.

And uh, thank you everybody. Next, uh, Monday. Take care. Take Care. Nice to meet you all. See you.

Related Videos