FROM THE CONVERSATION ARCHIVE
Fireside Chat with Tim Medin
Archive recording · May 22, 2024. Episode notes below reflect the original event; invitations and roles may be out of date.
/
RSS Feed

Join us next Wednesday, May 22 @ 8:00 pm EST!
hashtagthoughtleadership hashtagfiresidechat hashtagoriginstory hashtagciso
Russell Eubanks Tomás Maldonado Katie Hanahan Allie Heeter ⌬ Lisa Beth Lentini Walker Vijay Bala Hussein Syed Larry Whiteside Jr. David Cass Octavia N. Howell, CISSP, GSLC Stephen Garcia Anil Varghese
Conversation transcript
Original conversation: May 22, 2024. Transcript may contain errors; consult the recording for exact wording.
Read the full transcript
Hello and welcome to our fireside chat.. Thank you everybody for joining us. So why don't we get started? It's been a while. Russell, it's been, has it really been a month already so far? I feel like it's been a little bit longer than long, but time has definitely flown by since the last time we gathered to, to have this conversation. So I'm really.
Happy to not only have Tim be our honoree in the in the hot seat this evening to tell us about him and his story, his journey but I'm also happy to see a few friendly faces in the audience. And I'm sure more will join us as we continue on that union. So if the first time is it, if it's the first time you've joined us, we do this every single month.
For about 90 minutes or so, we'll ask our guests, in this case, Tim, questions we'll open up for audience participation or to add and ask a question about 30 to 40 minutes or so into the conversation and then we'll conclude at that 90 minute mark. So we do appreciate everyone's time, attention.
And the likes and just very quick, basic grabbers. Let's have a really good time this evening. It's the middle of the week. Let's have a conversation. If you're a vendor in the audience, I know we, sometimes we have vendors on stage and we have vendors as moderators, but this is a time really to reflect on a journey on a person's personal journey.
So please Try do not try to sell us on your latest and greatest solution. When you do come up on stage and join the conversation. Let's really keep this focused on Tim and his journey and where he's where he's, how he's got to where he's gotten to and where he's going in the future.
Our opinions are our own they do not reflect our current prior or even future employers for that matter. So let's really have a good time and I'll go quickly around the room. Tim, we'll leave you for last. Ali, you're joining us this evening, even though you probably didn't think you were, but you are.
So I'll pass it over to you, Russell. Before that, I am Tomas Maldonado. I am the CISO for the NFL. Russell, over to you. Thanks, Tomas. It does feel like, when we were in the every week groove, we were in such a good cadence. Now when we're at every month, it seems like a long time, and then sometimes it feels like just, The other day.
So great to be here. Russell, you banks, one of the moderators been participating in this for quite some time. And who am I? So Russell, you banks, former CSO for the Atlanta fed last four years, been running a security company called severity and love getting to work with a bunch of companies now instead of just one.
But most importantly, let me throw it over to Allie, a little bit of introduction for you, please. Hi, I'm Allie. I am. I have a background in marketing and now I'm the cybersecurity awareness manager for a non profit called Savvy Cyber Kids. And I'm new to the cyber world, so I just Love being a host with you guys.
And thanks for that. And it's great to have you both join us. So Tim, I'm going to pass it over to you and why don't you take a moment to introduce yourself? And while you're going through that introduction, you can take as long as you want or as short as you want the longer, the better, because that'll give us a really good background on you as a, as an individual.
Why don't you take a moment to introduce yourself, tell us a little bit more about you and tell us about you and your origin story. Sure thing. Yeah. Tim Medina. I run a cyber security company called Red Seeds. Been doing that for coming up on seven years this fall. Been in pen testing for, I don't know, 10, 15 years, somewhere around there.
I should do the math at some point. It really IT background before that, compute programming before that. Industrial control systems and playing with robots and welding. That was fun. That was my way back undergrad. But yeah, so origin story, I guess it really comes back to just a curiosity.
So back in the the eighties my aunt worked at IBM. So from that, we ended up getting a computer in a house, a PC junior, no hard drive, people talk about these. Giant hard drives these days. I didn't have any, just the floppies and these little cartridges. And it was just a curiosity. Just wanted to play with things.
And my aunt was really good at trying to help me out in learning some some of the old school basic. There was a little. You remember 321 contact was a show way back in the day but they had a magazine, they had a little program. You could type it at the end and play games. And it just this playing with that over the years, eventually playing with, I think my first sort of quote unquote hacking was This soccer game, and I remember going in and hex editing and changing people's skills from whatever the decimal was for that character up to FF and just having the extremely dominant soccer team.
So just that, that curiosity and the, what can this thing do that it's, what's it, what can it do that it's. Not supposed to do. If it could do it, it's supposed to do it, is not my mindset. But it was just that curiosity. I just kept digging into that over the years and eventually realized that could be a career.
And I'm like, holy smokes, I can get paid to break things? And just kept running with that ever since. That's that's very interesting. I think, a lot of people would start off like that where they start with just playing around and toying around with a computer and start with that general curiosity. At least the people that I've spoken to that started in cyber, they start with that general curiosity of how does this thing work?
Yeah. How can I break it? Oh, wait, how can I break it? And then if you really want to, not really want, if you depend upon what your train of thought is after that, it's usually how can I break it and keep it broken, or how can I break it, modify it, and not let somebody else break it?
Or how can I break it? Break it, modify it and change it so that it does something different, completely different than what it was originally intended to do. So I find that whole process pretty fascinating. Tim, when you think about like that from that stage in where you started and, just give us a little bit more about that in between stage.
So you started, had that curiosity, You decided to, how did you decide to cultivate that curiosity into what you're doing now? Like what, how long did that take? What were those sort of challenges or trials and tribulations, if you will, that you went? Sure. Yeah. I think the first, I don't know, quote unquote, hacking piece was actually, this is funny.
You know how these days we try to run doom on everything. This is back in the days of, Actual doom. And we just wanted to run doom on the computers we had at school, trying to break out of that and not get caught in the the process, but more on the the professional side of things that technical security.
I was doing some programming and realized I'm not great at it. And I can admit that not the best developer I can write functional code, but chasing down those bugs at the end is just. Soul sucking. And I just hated that piece tracing down and then fixing it. Like I didn't mind trying to trace him down.
That was the interesting piece there. But just got interested. Just remember hearing some podcasts or reading about different hacks that were going on. Or I remember I was running like an FTP server to, to transfer some files on IRC and one day my computer was popped. Somebody had compromised that.
I was like, Whoa, how did that happen? And then just digging into those some of those pieces now from the, on the more professional end of that, it was a lot more of the, Hey, I was at the time I was on the network side, I'd moved from programming well, from the ICS stuff to programming to networking and I always had that interest in security, but I, it wasn't really much of a, it wasn't that big of a thing really yet And I had this interest in it, and I just spent it, it was before we had kids, so I had a ton of extra spare time, and I just remember just reading a bunch, listening to a lot of different podcasts, not that there were a ton back then, I remember a lot of at the time, Paul Paul.
com, Security Weekly, now Paul Security Weekly, a few other podcasts back in those olden days reading some of the blogs associated with that, playing with At the time backtrack and just really experimenting with that and how I turned that into my profession was, Hey, I'm a network person and I really try to take on the projects.
We weren't a big team. We had about 600 people at the entire company, maybe a little bit more than that. IT team was a dozen or so and I just remember that we have a new project coming in and I wanted to do work on those security projects and I would put in some extra time just to play with some of the tools that I had learned on the different podcasts and just see how they worked and what it meant for me.
For security, it just started really reaching for the area that I was really interested in and then just kept pushing and pushing and pushing. And then eventually started blogging about some of the things that I was learning and eventually turn that into a full time pen test position at the time fishnet now what are they now?
Optive. And then that was just the security side of things just took off from there. Just leaned into that some more. And then more recently instead of just me hacking, now I've got a team of hackers that I work with and work for me. It's like a whole bunch of memory lane right there.
Right, Russell? Absolutely. Yep. For sure. I'll pass it over to you. Yeah, so Tim, so many things. We've known each other for a very long time. And I was thinking when's the last time, or when's the first time I saw you? I'm pretty sure it was when you were with FishNet. Fifteen, sixteen years ago you were a speaker at a SANS pen test event in Baltimore.
And you gave a talk on something and I think we just happened to be leaving about the same time. So I chatted you up a little bit at the airport. I thought, wow, smart guy. And here, fast forward to today with the things that you've accomplished, things you've been involved with with your company.
It's pretty pretty impressive. And again, we've been through a lot together and done a lot together, and it's just amazing to have you on the hot seat for tonight. Tim, I know one of the things that you've done is. Recently got your executive MBA. What were some of the Maybe one of the big lessons or top lessons or ways maybe you've applied that Education not just to have the degree but to help to grow and serve your customers and serve your company Red Siege What was one of the bigger takeaways maybe a surprising takeaway after the fact for that education?
Yeah, I think just let me I'm gonna dig into that I think that's a interesting thing. One of the things that I've always found interesting is just learning And I don't want to, I didn't, I don't want to say I ran out of things to do in tech cause that is not anywhere close to true, but I wanted to add something to add, give myself another dimension.
So I went to the the dark side, if you will, although some people would say that the hacking side is, but whatever, and I did some of the executive MBA. I actually years and years ago, got a a proper MBA, if you will, from a university, Texas system. And. Honestly, it was a little bit too early in my career, at least where I was and focusing much more on the technical side for it to be super useful.
Also it was a lot more, I don't want to say tactical maybe it's the right term, but it just, it didn't quite click with me. So more recently I went back to a school up in Boston and did the executive program. That was. I didn't get what I wanted from the class, but I got more and better.
That's going to sound kind of confusing, but what I thought I was going to get isn't fully what I ended up with. And that's not a bad thing. It's honestly that my assumptions and my expectations were not the right things. I got to meet people with people from all over the world, all sorts of cool, awesome positions.
Very importantly, outside of tech, where I've got the very tech focused, even if you're on the business side of tech, we have a kind of a way of thinking in tech, especially as Americans to, we've got some biases associated with that and getting these perspectives from people all over the world and very different industries, very different positions.
Was incredibly eyeopening. And I think that the fundamental thing that I got that, that, that seems cheesy and seems like it would be the easiest thing to understand. But ironically was one of the most difficult was just that there's just a ton of perspectives out there. And it really helped me understand and see and empathize with those other perspectives.
Where even, I really try, I think, if you're onto something like this, you really do try to have those different perspectives. But this was completely eye opening with that. There was some of the finance stuff, that's not my strong suit. That more tactical piece I found to be very interesting, not the actual accounting itself, because I fricking hate it, but more of the strategic, like based on these numbers, what should we do?
Haven't quite applied that piece yet. We're not quite a big enough, or maybe I'm just too obtuse to realize the the places where we should apply that. The other really interesting thing was some of the I don't know what it was supposed technically a negotiation class. It really wasn't, it was just under that category.
That was really interesting to, to identify biases and ways you can be manipulated by data or you can manipulate or be manipulated by the data. Not taking a step back and saying, Hey, what are we actually seeing with this? Are we making the correct decision? Often people like to say that, Hey, it's better to have a map than no map.
And that's not necessarily true. Yeah, it's oftentimes better to have no map than a map. Let's say if you give me a map of Cleveland and I'm walking around New York City, clearly having no map is better than the map of Cleveland. Because if I think that I'm right and I'm following this correct path, It's going to get me incredibly lost, and I'm going to be very confident that I'm not lost, which is worse than understanding that you are lost, right?
So that was very eye opening. I think one of the pieces that has stuck with me. The most was one of the professors, an accounting professor. He actually, Eugene Stoltz, he actually wrote to folks who were in jail for what we call white collar crime and talk to them, met with them, and.
Just seeing that path, and in every single case, it was one tiny little thing for example, one of them was the quarter ended on let's say, a Thursday, and they had verbally agreed to sign the paperwork, but the paperwork didn't get signed until Friday, but they put it on the previous quarter's results.
And you're like, yeah, okay, technically, yeah, but, they agreed to it. They're like what happens if somebody's in the air? In an on an airplane, you're like then, and it just from there, these tiny little steps where you can think, man, if I was in that situation, I could totally see how I might do that.
And then they had to cover the next day to make up for the next quarter's numbers, and they got just a little bit further and a little bit further. Even the, the famous ones like Bernie Madoff and the was just a little piece and just try to make it look better than it does. Just downward spiraled and went from a little tiny step and I really, it really makes me think so much about what integrity means and it's the littlest ones to some degree mattered more than the big ones.
Because if you can't do the little ones, welcome to the path. That's going to get you in deep trouble. A lot of different perspectives. It was a great opportunity. One of my favorite things too is, and this isn't, business related is explicitly. But as I travel around, Russell and I both teach with SANS.
I get to meet up with friends all over the world. But the cool thing too with that is. I have a, like a Rolodex now of smart people from all over the world. Hey, I got a question about this. Can you help me? And they'll hop on the phone where I would never get access to this type of person, or if I did, it wouldn't be to the same level and be like, Hey, Tim, how's it going?
Let me, Hey, I got some quick questions for you or even vice versa. I get questions. What people ask me stuff all the time. It's just that continual learning. I think it, it always makes you better. You never worse off for that. And this was something that I had always wanted to do. I always wanted to go to a particular university, check that box.
Get a lot of crap for it, which is why I avoid the name, but tremendous opportunity for for all of that. It just. Always make always trying to learn new stuff. Yeah, I love that. And one thing that you said, I didn't know any of that, but one thing you said, Tim, I learned what integrity means.
I heard a neat, so integrity is one of my personal values. And I heard it said recently that a value is something that you've pre decided is most important. And that really stuck with me of making that decision before you're in a situation. If integrity is your thing, that's something that you're going to do no matter the cost.
I like it. I love that. Yeah. So pre deciding what's most important. All right. So before I pass it to Ali, let me ask you a little quick more lighthearted question. So your company's called Red Siege. What's your tagline? What are the stickers on that you hand out? What do they say? We've got one of the first thing that first thing I tried to do when I came up with the company is I need to find a domain name and a Twitter handle that are available and there's no other trademarks for it.
So I came up with the Red Siege after a day of searching for that. And then I thought immediately, Hey, we need cool, one cool sticker. So Kevin Johnson has his professionally evil, And even other consultants at other companies will put his sticker on there. I need to come up with an idea like this.
So I came up with the, I am offensive. We really lead into that. We got the shirts that say the, I am offensive. We got stickers that, I am offensive. I've been walking around in an airport and I saw somebody with a sticker on there. On there. This was years ago when we were maybe a year old. And I don't think I had made that many stickers.
And I was like, can I ask, where'd you get that sticker? It says Oh, a friend made it, got it for me. They were at a conference and I was like, that's awesome. That made that sticker. And we had a cool little conversation out of that. So yeah, the, I am offensive is that's our shtick that we've leaned into.
Love it, Ellie, over to you. I love that. And I need to get some of those done. So I have a question for someone who cannot attend, but he will listen later. He just got into cybersecurity. He's a cybersecurity analyst right now, and he wants to go into pen testing. Do you have any advice for him on what to do?
Yeah, I honestly, so my, I'll give you some, I have some advice. My advice. Is I don't want to say dated, but it's dated. I came in to pen testing when there weren't, there was like two classes for it. There was not a degree program for it. So many, there weren't a ton of YouTube videos. We didn't have all sorts of the wider range of.
Like cloud was basically non existent or at least non existent to the extent that it is now. I think the big thing is as you're making that transition, try to get as close to that as possible. So if you're in the tech side, whether that's programming or the network side, system administration, dig into the edges where that bumps up against security and then just keep pushing past that.
And. Use that as your way to I don't want to say creep into security, but literally I guess creep into security. That's the way that I ended up doing it so many years ago. I think it's the best way to do it. Making a giant leap is a little bit harder, not. That people can't do it.
It's just, I think that organizations have a harder time accepting people taking that giant leap, which is unfortunate. But just keep digging in other things. I think that are really good blogs, right? Blogs. If you're learning something, write up, write some blogs about it. Coding related to that.
Put some stuff up, up in GitHub. People love those stupid green boxes in GitHub, which is a little ridiculous, but it is what it is. But like the, I got my first job because of some of the blogs that I had put out and it doesn't have to be original and blogs and presentations, I think even more so going to a conference and presenting, but in both of those, it showcases your skills.
Showcases your interest, showcases your passion with that, and you can now use that as part of the interview process, put this on your resume, and say, yeah, I know I'm not here, but I'm demonstrating that I have some of these skills that you folks are looking for, the interest and the passion.
Okay, that's great. Thank you.
Hey Tim, I want to just not go back, but I'm genuinely curious. And I always, I'm always curious about why people do things, do certain things. And my question is, you went from someone doing the task, probably leading a team at some point in time, I would imagine to running a company, how does that occur?
Like, how did that happen? What motivated you to say, you know what? I see a problem. I'm going to go start a company to go solve that problem. What was that? Talk me through that thought process and then, with that thought process what was some of the things that you, I don't know how long, I don't remember how long you've had your company so far.
So maybe you can just. Share some of that and just share like some of your learnings, right? What would you do differently if you had to start another company again today versus, when you started your company? Yeah. Yeah. The, so I started a Red Siege seven years ago. I had been doing the tech side for for years.
If I had to go back and talk to myself, I would have told myself to do it sooner. Only because I was so scared to start. And once I got rolling with it, it wasn't as bad. Now I say that when it's in a new business, it is in its infancy. It's hard. I like, I liken it to having children. Those, when it's an infant waking up regularly, changing diapers.
And once it grows and it's been a few years, things get a little bit easier. We've got. People and processes. I've got a phenomenal team of people that make my life so much easier that years ago, I just didn't have. So like I had to do the marketing and I wasn't great at it. I was writing all the reports coming up with all the findings from scratch.
Whereas now the guys, one can write the findings together. We've got a repository of those. We've got methodology. We've got reports. We actually have the contracts where I was doing all of that. Oh, cool. Hey, I want a gig. Now write a contract. Cool. Literally every single thing from scratch. It was, and this is the best advice that I got.
John Strand is a really good friend of mine. And he was talking to me, he's Hey Tim, I know you're starting your business. First up, first and most important tip. Second, I know you're not going to listen to me, so let me tell you everything that you wanted to know about trying to run your own business in a pen testing business.
And everyone that asks me about it, I give them those same two tips. First off, don't do it. Second, I'll tell you absolutely everything you want to know. And the interesting thing is there are so many people in this space, even people that you would say are quote unquote competitors who are more than happy to talk to you about their experiences to head some of those things off.
Like I, I talked to other folks inside, outside of industry, weekly, almost daily with coming up with ideas, bouncing things off. They're bouncing them off of me. I'm asking them questions. Bryson Bort famously, I don't know, famously, but he says, starting your own or being an entrepreneur, starting your own company is, and being, or being CEO is, was it the.
Most exclusive club. That's the easiest to get into because you're like, yeah, cool. I'll start my own little thing. And it's just a lot of work. The impetus for me is my dad had businesses growing up. My uncle did. It's just something I had always wanted to do. And I'm like, I've got to take this step at some point.
Maybe I fail. Maybe I don't. It was just something that it was an itch where I'm like, I, this is something that I've just got to try. And to some degrees, to some degree is a lot harder than I had initially expected, which is good or else I would never have started it in the first place, much like children Oh, they're going to be fun and cute and snuggly and they are right.
And, but there's those nights where everybody is just crying. It's a lot like that with the business side of stuff here too, where it was just that thing that I was interested in and wanted to learn so I don't want to just stretch. In an industry, in an area where I have interest and I have that passion and just really wanted to continue to roll with that and just now it's just, more of the same.
We're talking about expanding services new uncomfortable areas where I've not as don't have the same level of expertise that I do in pen testing. So it's just a, Continual way of learning and trying new things and honestly failing, ideally failing quicker so that we can get back to the things that actually work.
That's awesome. That sounds great. Russ. I know you you've had your company for a while. Any of that resonated with you and your experience? Yeah, I wish there was more emojis than the four we have in LinkedIn. I'd pump all of them and it's exactly the same story. And to Tim's credit, he shared that with me when I was talking about doing the very same thing four and a half years ago.
And I've always thought about starting a company. I just, I don't know what I would have wanted to do. I would probably want to just retire.
And that's an easy one. Income level sucks, but
I wouldn't be surprised about that. Tomas, you've when had entrepreneurs on as our guest, you've always had questions. And I'm certain that someday when it's the right time for you and your family, you I'd be shocked if you didn't do it as well. Yeah I I tend to agree with you there, Russell.
I'll pass it over to you.
Tim, your business, clearly, you do pen tests, you're the lead author of SANS 560, the network pen testing class that a lot of people in the world have taken. Allie talked about when there's someone new who wants to get into the pen testing arena or start to move in that direction.
What do you do when you have a pen test, whether you're doing it or someone on your team is doing it, you just get stuck and you're I'm not sure if I'm going to get in, I'm not sure if something's going to happen, not sure, all these things that are rattling around in your mind. How do you recognize that?
How do you deal with that? How do you overcome when you get stuck doing what you and your team does? Yeah. And it, and honestly, I would just say broader than just pen testing. I think I learned this years ago. I was doing a test for a client up in the the Northeast and just getting my butt handed to me.
And I'm freaking out. And I think it was either a one man show at the time, or maybe it was two with Mike and I. And I was like, Oh my gosh, I'm getting shut down. Here's the first time on this internal pen test I've ever been shut down. Do I switch to sales now? What? I'm having this existential crisis.
And what I learned then, and I'd heard it so many times, is sometimes the best way to solve a problem is to stop trying to solve the problem. So I literally said, Hey, I'm gonna go next door and get some coffee. He's okay, cool. He's we got to cough in the building. He's no I just need to, I just need to get out and clear my head.
So I went out and I was just walking, listening to some music, just literally trying to remove all of that from my head. And I'm about, I'm at the coffee shop. In line, and I'm like, Oh, my gosh, that's the idea. But now I have to wait for my coffee and then I have to walk back and I'm like, dang it. I wish I was closer.
And I think that the big one there is that, sometimes you've got to take a break. You can't just brute force the problem and get to the solution. It just doesn't work. Work that way. You need to let that, the creative juices flow. And you can't just force that. You've got to take that break mentally.
Even if just for a little bit, go for a walk or for a jog, gym, whatever you need to do, but something to like. Get your to change the context in your brain so you can help solve the problem without trying to solve the problem. That's one. Two, and this one's hard for people, but literally asks other people.
We got a guy on my team, Ian. This dude has the superpower, and this is gonna sound like a pejorative, like I'm picking on him. But it's not. It's an absolute superpower. He has no fear of asking the quote unquote dumb question. And I'm not saying his questions are dumb. But most other people would be like, Man, I don't have the guts to ask that question.
And getting to the point where you can just say, Hey, I don't know. I need help on this. Is an absolute superpower. And it's so odd because, especially when we become experts It's hard to ask for that because you're supposed to be the expert in the room. What do you mean you don't know? But at the same time, I think we've all been in a room with actual experts and we give them more, I don't know, power.
We we perceive them with more expertise when they hit their wall. I'm like, you know what? I don't know. Here's how I'm going to find out it. But for some reason for ourselves, we so often get in the if I don't know the answer to this, I got a BS way my way through it or a brute force and figure it out on my own when you could just call somebody up.
Hit somebody up on IRC, solve the problem so much faster. And to some degree it, it opens up that discussion with that other person. So the next time they can call you back and say, Hey, I'm having a problem with this. Do you know the answer for this? So it helps both people. So if I narrowed down to the two things, one, sometimes you got to take that mental break.
Don't be afraid to ask the simple questions that is an absolute superpower. Yeah, I love that. Those, both of those responses, I wrote both of those down and it makes me remember, a long time ago, you and I both thought it would be a good idea to run a 10 K and run a half marathon.
Disney, probably because Star Wars was involved. The thing that I learned, I had to learn it the hard way that everything I wanted to be able to do someone else in the world's already done it. So I had to swallow my pride, find and hire a running coach. And all of a sudden the odds of me being successful went up.
So it reminded me as you were telling that story of what Ian's good at asking other people, who out there has done this, who else has figured things out and how can we learn from them and get wisdom as cheaply as we can. So I love that so much. if I can interrupt there and add to that, Russell, like I, we had, it was right when we were coming back first conference back after COVID Russell and I were up running in I think this was the spot and I remember running with him and he had this timer and I'm gonna get the numbers wrong, but it was like two minutes on one minute off pacing thing.
And I thought this is the we're never going to get anywhere. And then I looked at the paces that we were running. I'm like, holy crap. This is a little actually a little bit faster than I normally just jog. And I was like, I don't know. And that's stuck with me going back to the, I tell you like, Hey, don't brute force the problem.
With my running, I was like, don't never ever stop. And it is this alternating approach. I'm like, I actually ended up going a little bit faster, which was a interesting sort of scenario where Hey, push it for a bit, or didn't feel like pushing it. Honestly, take that break. And you end up getting a little bit further for that.
So it reiterates, even in the physical world, if you will. That's some of that point. Sorry, Russell, go ahead. I cut you off there. No, I remember that very well. I remember that. And initially I'm like, I don't want to tell Tim. I don't want to be a chump for not being able to run all the time, but I'm glad it all worked out.
Ali over to you.
I will say. I always say, if you see me running, somebody call the cops because somebody is chasing me. Ha. Go ahead, Allie. Just a quick question, would you prefer to run your business or go back for working for someone else? It's funny, because I've talked about that, I've thought about that a bunch.
What happens if some Buddy else Hey, we want to make red seeds part of a bigger business, a thing. And yes and no. So I like being able to direct and find the right path. The hardest part, I think, is steal the cliche. It's lonely at the top. There is no one above to be like, Hey, here's, let me give you some tips and some tricks, like a mentorship style thing.
So I don't, at this point, I don't know if I can necessarily go back to the traditional sort of a role unless it was a more strategic higher up. And I had somebody above me that can give me some direction and mentorship. But I honestly think that. It'd be a little bit challenging these days. And I've seen that enough times where somebody's had their own business and they've gone back to work from somebody and they're stuck with their same war stories.
Hey, back when I ran my business, it's yeah, but. Okay, but we got to move forward here and try some new and interesting things here. I just, I don't know. I don't know if I could, I don't know if I could do it. I'd like to think that I could, but being realistic, I don't know if it's going to happen.
Yeah, I get that.
Hey, Tim, thinking about advancements and in artificial intelligence, because everybody's got to talk about AI throughout the day. I'm convinced you're AI Thomas, but whatever. I am. I, sometimes I feel like I should be, I should use the AI to clone myself, but question from a, from, I had a few questions that I want to ask you, so maybe before I get to the AI question, I want to ask you about, What do you think about red team, purple team, blue team, yellow team, all this multicolored teams?
What do you think about that? As it relates to AI, I presume. No, not so much for AI, but just pentesting in general, or not not pentesting, but in the cyber world, this concept of these different color teams and how they're being used in to try to enhance, mature Security programs.
I'm just curious what your thought is on that, given that you're closer to that sandbox of selling services in that space than I am. Yeah. The breakup of the teams, I think that's the, and the color coding based on the military background there. I think that's good sort of to define some of the roles the.
Sort of two pieces that I've seen be a problem over the years is the red team, the offense far too often, and it's gotten significantly better, would just dump a report on the defenders, the blue team and say, Hey, your baby's ugly, fix it. And the blue team was like, okay, we don't understand all this.
Can you give us some help? Yeah, and the red team was like, yeah just fix it. And they literally just pulled a pin on a grenade, not literally, but pill dependent pin on the grenade, chucked it over the wall and be like, see a piece out. And that doesn't make things better. It does.
It doesn't help. So we've seen, I think the purple team is a lot of the answer to the problem where the red team wasn't helpful to the blue team. And now they're like no, sit in the room with us. You're not leaving here until we're done. And that's been a good progression to help the defenders actually understand the other thing.
I don't see it as often anymore. Used to see a lot more common. We actually had a big client where this happened late last year, early this year, where they saw the red and the blue, the offense, the defense as adversaries, not as One trying to test the other and stress them to make them better, where in the real world, it should be, Hey, I'm trying to find these problems.
So the bad guys don't actually get it. And at this particular organization, it was just this extremely adversarial so that we on the offense couldn't. They were literally shutting us down from doing our job, which affected the quality of the results that they got, which meant that they couldn't find and resolve these issues and ended up with this, I had the most I don't know what the right word is, but the most adversarial, that's a good word, adversarial phone call of my entire career was other guys just yelling at me and I'm like, look, we're just trying to test, like you knocked our system off the network.
It's been off for a day and a half. Just put it back on. Yeah. It's Oh, we're testing our incident response. I'm like, cool, but it takes you a day and a half and you're losing this much testing. And then, we need to get past that and realize, and so many organizations honestly do understand that the folks that are testing on the offensive side are really here to help.
And we truly want to make a difference. And I say that because there's nothing more soul sucking than doing a test coming back the next year and the previous test. It's just a hack by numbers and it all still works. They're like, Hey man, I did all this work last year and they didn't do a dang thing about it.
It's surprisingly more soul sucking than you, one might think, but we do care. Now, if they fix everything, it gets harder and harder, which is a different level of difficulty. But the real thing is that we are on the same team. And I just. We have gotten better in that space, my personal experience, but there's still plenty where it's just far too adversarial.
And we're not focusing on the real end goal or the focused on winning the pen test, whatever that means versus winning against the real bad guys and not getting things like ransomware. It's interesting. And thank you for your perspective on that. The. . Thinking about thinking about AI in the context of pen testing, do you see AI as being a good tool to help the profession?
The, the pen testing profession? If you'll, do, you see it as something that'll be leveraged as a crutch? Do you see it as something that will allow for ease of ease of entrance, if you will for folks trying to get into pen testing as a background and as a profession.
I don't see a ton of benefit yet in the offensive space. I think there are some opportunities for newer folks to use that to help give them a better path. But once you get to a certain point, I don't see the significant benefit for AI for the offensive side. Now. I will say for the defensive side, and I think we're only now starting to realize that, and we're only now getting the technology to do some of those, these things, but I think things like, the anomaly detection, right?
Sorting through millions or billions of an events and finding the thing that's different, finding the thing that's odd, that's what these things are great at. They call it a large language model because it's supposed to filter through like large quantities of data. Let it rip through. Let us find those weird things those needles in the haystack that might be interesting.
That's the side where I think we're going to have a lot of really cool opportunities, more so on the offensive side of things. And on the offensive side of things too, a lot of the new stuff that we're coming up with, It hasn't been done before. And AI is not as good as coming up with, it's not going to come up with a brand new attack vector.
It's going to use its knowledge of previous attacks and roll with that instead of, and say, Hey, here's some suggestions for the things you can do next, things that already knows about not, Hey, here's a brand new buffer overflow thing like that. It's just, I just don't see it in that particular space.
That's interesting. I think I'll. I see an opportunity for it to be leveraged for people that are very skilled at doing what they do and having having a lot more creativity to ask or entering to enter in prompts that are probably things that normal people may not think about, or even a speed up some of the script writing. I think that may be something that'll be useful for patents but okay.
It's, if anybody has a question in the audience and you want to raise your hand and jump up on stage and ask a question, I've got one while we're waiting, Tomas, where are you work? I've got to ask your favorite team, my favorite team, drum roll, please. I like all 32 teams equally. It's like having 32 babies.
You got to love them all. Can't have any favorites. I feel like you got a a script next to you. I love all 30. No, I'm just kidding. I'm I'm always on brand. Let's put it that way. But if there's anybody in the audience that has a question other than what Tim just asked me, feel free to raise your hand and when we'll bring it up on stage Russell, I'll pass it over to you.
That's funny. I may or may not have suggested that as a question. We've not heard that one in a while, but I was going to ask anyway. So you, if you could see my, my, I've got my streaming desk. And I got lights. I got my lights on my right side is propped up by three cheese heads. I grew up in Wisconsin behind me.
I've got a sign helmet with a bunch of the greats from the green bit. I got good stubs, all sorts of stuff. I am a huge football fan. Oh, man, I expect to see you in the, in in in Green Bay next year for the draft. I, me and some friends are working it out. If you got any ways to get in the nice seats, I will happily pay for those tickets.
Most of those events are free, so you should be fine. I'm looking forward to it. We're good. Yeah, I'm trying to get, I'm trying to get some friends to go up there. I go up there every I like to go up to Lambeau. For those of you who don't know, it's up in Green Bay, Wisconsin.
And I like to go up in the later part of the year, November and December. Cause any wuss can show up to Green Bay in September when it's, 60 degrees. But you gotta wanna be there when it's December or January. And it's well below zero like that. That's the hardcore. That's when I like to show up and it's a it's a lot of fun.
I've been at a game. It was supposed to be the coldest game of all time, but it warmed up just enough where it wasn't even in the top 10 anymore, I was a little disappointed because I'm like, Hey, we're going to be miserable. I may as well get like a record book out of my misery. And we just missed on that one.
I'm over here laughing out loud to myself. Cause one, I'm that wuss that will not be there in December. I've actually never been to, to to Lambeau field. I haven't been there yet. I'll say not never. I haven't been there yet, but I do plan on getting over there for draft and I will probably be there in that draft time period, which is usually April or May.
So yeah I don't anticipate stepping foot into Lambeau Field in December or January or any of that winter time. Because it is cold. Oh man, it's cold. You know it's cold when you start seeing people breathe and instead of it being like a cloud of air, it's like a, it's like an icicle forms and it just drops to the floor.
I've overexaggerated, but it is cold over there. All right, Russell, I'll pass it over to you. No worries. I'm I love that. I could just I've seen Tim on video. I've seen the things he's talked about. Glad everybody got to hear about his setup. So Tim on Pintest, is there if you had a magic wand, it can make one problem that you see a whole lot just go away versus.
Almost like you go into a pen test and may be able to see or anticipate or expect to find one. Is there a common finding? Is there a easy fix or a a problem you just wish could be fixed and move on and not have to deal with it anymore? I'm a pen tester. If I made this problem go away, we'd be out of business.
But no, but seriously, the, the biggest thing it's been there for, literally decades is the crap passwords. It's so often the first way in, it's so often the lateral movement and just getting rid of that and, there's so many different varying solutions. I thought past keys were going to be the answer, but it's just, I don't see that past panning out.
But something like that where we've got better authentication to prevent just the crap. I was talking to a family member. It's Oh, my Netflix was hacked. I'm like, you use the same password in every single account, don't you? And they're like, but this is different. No, it's not. It's not don't like, and it's just so tiresome to see those same sort of things where we have solutions for that.
And maybe not the best, but we have solutions for these things to make them go away. And it just keeps lingering and lingering. So that would be, I think the first one I would check off that box.
Got it. Cool. And it was neat to hear that. It just a, it's almost like a free consultation there at the same time. So maybe I'm you, but I I tend to agree with you on that. Russell, you want to say something? You want to add to it? Yeah, sorry, I was on double mute there. As I was going to say, it's almost like a little bit of free consulting, but then also this idea of, what's some things that we can do, or check on or make sure we don't have that problem ourselves.
But it's great to see, and thanks for the save there, Tomas, and Fleetus, always great to see you. Welcome on stage, and what's your question or questions for Tim? Thanks for the invite. As always Tim, good to see you again. It's been a while. On that note, as I come from the cyber defense side, what is one thing you wish blue teamers would do during a purple team engagement is question one.
And then to add onto that, if you weren't a pen tester, what would you do now? Ooh. Ooh. All right. So let me go with, I'm going to go in reverse order. If I wasn't a pen tester, what would I do now? I love in response. I absolutely love it. There is, you go in head to head and the keyboard with the bad guy, there's this whole overarching strategy to kick the bad guys out and keep them out.
And how long do you monitor them before you decide to start slamming some of the doors? I absolutely love it. The problem is schedule completely sucks. Oh, I've done IR for a while and invariably you get the call on a Friday afternoon and you get the call then because the internal team is tired of fighting it and now they want consultants to work on it over the weekend.
But I absolutely love it. Just the hard part is that schedule is just an absolute killer. As for the purple team, what would I like to see them do? Ooh, I don't know if I have the right answer for that. I have never even. Thought about some of that. I think one of the big things is. And not that it needs to be adjusted, but I think once you get to the point of going purple blue team has accepted like, Hey, we know we have issues let's work on this together to fix it, which I think is the first step in, in not the first step, but it's a big step.
In resolving some of these cyber security issues, and it's that big step in the openness and the communication related to that. I don't know if I have anything specifically, I'd love to hear if anybody else has thoughts on that. Yeah, I don't have a great answer. No, I appreciate that. This is something that in several engagements I've done, I've asked the red team, what would you have done if you were in my seat?
And they look at me like I've never been asked that question. So I wanted to ask you. No, that's a great question. I have no idea. Most of the time what I heard from them is they appreciate that we're willing to do an ADSIM, so that we're willing to do the simulation, so that we can understand their pitfalls.
That they run into, as you said earlier in your conversation, what are you knocking your head against? Because as you already alluded, we're hands on keyboard. We're monitoring, we're chasing, we're deciding when you're also hands on keyboard, but you're also looking for that one gap you're looking for that race condition to get by my control, right?
And sometimes you can't do it multiple times. So you get lucky to get in and you can't clean up behind us or behind yourself. And that's when we have to get involved. If you tell us you left something there so that we can clean it up. So it's not showing up in our logs or alerts or scans, et cetera. So it's funny you say that I want more partnership.
I was just having a truly this morning somebody from a I'll just say on LinkedIn was asking this same, the same sort of thing. Hey. How do you handle some of the cleanup? And I'm like I try to clean up, but sometimes there are certain cases where you can't, because if you're in, that's your access mechanism and you can't kill it because that's what you're using for your access.
So it becomes a circular things. You need somebody else to clean some of that up. And like you said, there's sometimes where Hey, it worked and I can't recreate it. I don't know what happened or it's a, one in a. Couple hundred thousand whatever chance and it just happened to work this one time and I can't get back into it to clean it up safely.
So no, that's a very interesting
cool. Cool. Cool. Thanks for question of late. It's always great to see and hear from you. Hey, for everyone. It's just a quick little reset. Here is at the top of the hour. We've had the last hour. Basically had Tim Medin in the hot seat from pen tester to run his own company, education, his loyalty to a certain football team up in Green Bay, talked about a lot of things and about a half an hour more time for us to be able to do this and spend time just learning from each other, a mid midweek a way to just reset and think about some questions that you might want to ask.
So folks in the audience, feel free to raise your digital hand. Feel free to bring up any questions that you might have for Tim. That's what we're here for and love to be able to do this once a month like we've been doing for over three and a half, almost four years now. I've been having conversations just like this to hear someone's origin story, how they got where they're at and little nuggets of wisdom that we've learned.
Some things that I've taken away is, learned what integrity means. I think that's huge. I just have to start my company, is what Tim said. You can't just brute force the problem. I wrote that down. A couple more things. When you're stuck, ask other people. And then, the tension between winning the pen test versus Winning against the adversary.
So big big takeaways for me so far and really appreciate the time for the last hour. So again, questions, feel free to raise your hand, bring you up on stage or send Tomas, Allie or myself a message. We'll be happy to ask that question on your behalf. So my next, Oh, by all means, please lead us. I wasn't sure yet.
By all means, go ahead. Yeah, I just have another one that I would like to get Tim's buy in. Again, coming from my lens of the blue team, what is the scariest pen test you've completed, either physical or digital, and why?
Oh god. There's there's, I don't know how to explain this one without giving away what it was. I'm not even sure it's fixed yet. Cause it was a, like a hardware related issue. But it impacted like. Children's safety. And that one was, and we had to actually pull off to do this was freaking, and I take zero credit.
It was all a colleague of mine Josh, but the stuff that we pulled off, or I should say he pulled off was freaking amazing. Gosh, I wish I could. So I wish we could have the NDA, the friend DA thing with all of us and just tell everybody tells their war stories and nobody does anything bad with it and no one gets sued in the the process, but that one without question, it's that one, which I've given you no information.
So you're like, yeah, cool. Great story, Tim.
Did you have a follow up to that? Or was there a second part to that fleet is.
No problem. I just wanted to ask the question, the reason I asked in social engineering slash the new deep fakes. I didn't know if you've tried any of those and were successful. No, this one was more of a hardware related. The physicals, those are interesting, but honestly, you're always going to get in with those.
It just depends on how hard you try, how many tries you get. Someone's always going to, someone's going to have a bad day. The door is not going to close correctly. It's just always there's something that's always going to happen with those. Unlike, the computers where they're really good at repeating the same process over and over again.
You say that until something goes wrong in Excel and you can't fix it, but whatever. With the social, the physical, that aspect it's just, I think there's just always a way in now to test it for repeatability. And are you following the processes? I think that's where some of that is good. But you're always going to get into those.
It's just, it is what it is.
Thanks Toledos. Thanks for contributing to the conversation. I want to go back to Tim, to something you said earlier, and I just feel the need to say this, what you said. You love incident response. I just want to go on record and say that's Tim speaking about loving incident response. Try doing this in response when you've got millions of eyes watching you, because it's a big Super Bowl event that you got to secure.
I don't think you, I don't think you would love it. So I just want to say for the record that was Tim that says he loves Tomas likes a quiet day. That's all I have to say on that. But but joke aside, it does give you a bit of adrenaline and adrenaline boost and it does really help you.
Really help you see what people are made of, if you will, who's going to overreact or underreact or just freeze up and not be able to deal with the situation. So really interesting different types of incidents obviously have different anxiety levels. I'll just put it, but question for you, Tim, what are you, I like updating my, I'm an audio book guy.
I don't know if you do audio books or you do real books where you got to flip pages, whatever it is that you do. What are you reading? What's on your reading list or what have you read? That's been very interesting for you lately that you would recommend or even read again. Yeah. So what I had a international trip, so I alternate between fiction and nonfiction.
I'm going through some of the Michael Connelly series that are those are some good writing. Great stories. For the non, what do you call it? For the nonfiction stuff the real world stuff. I'm starting off, I don't know if folks know Andy Ellis. He was the former CSO at Akamai.
He's got his book, 1 percent leadership. I just started that one. Really like that one. One of the ones has been a few years since I went through it, but thinking fast and slow by Danny Kahneman. Unfortunately he just passed, but phenomenal book about thought processes and some of the mis the misconceptions, misperceptions the biases the poor analysis that we can make on a decision.
And frankly being manipulated by I just, I, that was the one that I think resonates in my head the most that I keep going back to and be like, Hey, all right, remember this? And I probably don't remember the exact, he may have addressed the specific point. That's very critical to what I'm thinking about the moment, but at least he causes me to, Hey, let's take a step back.
Let me think. Is this the right, do I have all the right information? Am I making the correct decision, blah, blah, blah, blah, blah. And it's really try to analyze it a little bit better. I absolutely love that book. The trying to think of some other ones that were on my team.
There's another really great one. It's actually some very well written. The Phoenix project. It's actually written like a novel, like a book. It's actually quite readable. It doesn't have that same sort of nonfiction tone. Like you could, I think you could read it and actually have a interesting read out of it, even if you're not trying to get the business side of it, but it's an extremely well written book.
About teams and working with teams, some of the dysfunctions and handling some of those things in better ways. I'll give you those as my sort of top ones at the moment. I'd love to hear ideas if there's a book that you folks love.
Trying to switch back from my from my audio book. Yeah, so the Andy Ellis book, I actually have a copy of that. Okay. I have an autograph copy of that, actually, my my bookshelf last time I saw Andy in Israel last year, I think that was when he gave me a copy of his book, but I do I'm more of an audio book guy, so I didn't know that he does have it.
He does have an audio book, so I'm going to probably download it and and listen to that one on my way in and that other book that you referenced thinking would think fast, thinking fast and slow. Yeah, I've actually, I had, I've actually listened to that book. I've got a. Probably go back and listen to it again.
One that I just finished wrapping up was from our prior guest last month, Katie, the book on Radical Candor. It was actually pretty . Ooh, that's a good book. Yeah, that's a pretty decent book. I may actually recommend that to my leadership team. I usually recommend a book for them a year. A book, every year I'll recommend a book for them to read and this may, I'm debating which one to recommend to them this year, but there's one.
This one may be a good one for them. But no, that's good. Good. Good titles. Good titles. Thank you for that. Russell, what are you reading today? Not today, but what are you reading lately? Today I'm reading not books. No, seriously, the things that came to mind and always love extreme ownership, that's always a really good one.
Business made simple. Timmy may like this one from Donald Miller. Actually his podcast and all of his books are really clear. Really? Here's how he uses the analogy of running a business is like flying an airplane, like six different components you need for an airplane and what the, Analog is for running a successful business.
And I just listened to the audio book by John Acuff called Soundtracks. Really good. I love when the author reads the book and I give it like a minus one when the author doesn't read the book. But that one is, was very good and just looking at the Kind of mindset and how you approach things and positioning yourself to be more successful than Often what you give yourself credit for.
So yeah, those are the three For me that I've been in lately. That's funny I usually hate it when they read their own books because they're usually sometimes are really bad there's a couple like there's one called blue fish That's the author is phenomenal. Like I could listen to that guy to read the phone book, but there's so many others were like, Holy smokes, this guy's dude is laughing at his own jokes and the jokes weren't funny.
And that was rough. Yeah. I laugh at my own jokes all the time. What's wrong with that, Tim? No, I know. Same. And now you're calling me out. Tim. Sands 12 plus years of sands. How did that start? Why did that start? Why are you still do it? Yeah. I started with sands many moons ago. It was that I got my first pen test position that I went to to counter hack and worked there with ed SCOTUS was my boss.
He's my boss twice. I always joked that if I screw up bad enough, I can get fired twice in one phone call. Cause he was my boss at CounterHack, my boss at at SANS. But just got to use his leadership, his mentorship into getting into that process to to teach there. That has been tremendously valuable for me as a public speaker.
As a teacher, not just teacher in that public that, that setting, but just in general, it helps you break concepts down, how to. More simply explain things. I have found that so tremendously valuable. And then from there ended up taking over the sec five 60 class being the author for that recently gave that up.
So we'll see an update coming out from Jeff McJunkin, John Gorin flow here shortly. And then I guess we'll keep an eye out. What's what's next. Maybe do some sand stuff. I still don't know what's going on with all that stuff. We'll see if they want me to stay around. There's not, it's not as many the in person classes as we we once used to have necessarily.
Yeah, that is true. And look, the real reason why I asked that question, and I could probably, I'm going to ask Russell the same question as well, even though I know he's not an artsy, but he's a long time SANS instructor. The real reason I asked that question is primarily because you're not, you're doing it and you're not getting rich, right?
That's not the goal of why you go in and teach SANS. And, it takes a certain type of person to want to educate. Other people, and that was really why I was asking that question because you seem like someone who wants to share his knowledge with the community and and knowing very well that you're, you're not going to get rich and retire off of a sans paycheck.
Although they do charge a lot to the attendees, but yeah, it's, I'm not going to say it's not nice money. It's not retirement money or anything close to that, but it's nice, extra on top of whatever you're making a thing. And now it all goes into the business. It just disappears.
So it's a different calculus, but yeah, we'll see what's coming up. We've got some folks on my team that are doing some training, so we'll see where all that lands.
Speaking of getting rich, Russell. Wait, what? I was enjoying Tim being an Aussie there. That was a, and I have to say, I've if you were to ask me that question and you did as well, I'm a product of SANS. I remember it was 2003. I took my first SANS class because I worked at a place that had an annual training budget.
You can just go take whatever you want to take, pick it out. No big deal. And I did it and I got pretty addicted to learning and applying it and the concepts and just really getting into that ecosystem. Tim mentioned Ed Skoudis of the, he's had such a huge impact on my career. Me as a father, a husband, a teacher so many things and had lunch with him at RSA a couple of weeks ago.
And it just, every time it's Hey. Ed, you're still the reason I get up at five in the morning and work on stuff. It's your fault. I blame you. And I'm grateful to you him at the same time, just the influence and how he's a great father, great husband, phenomenal communicator for sure. Yep. Yeah.
Although if Ed made me get up at five in the morning, I would hunt him down and punch him in the neck. Screw five in the morning. Yeah. I'm jet lagged coming back from Singapore. I woke up at 4. 30 today and I hate life. So the Tim of today is not too happy with the Tim that said, yes, I want to go to Singapore.
I love Singapore. I'd still go back. I love it there. Absolutely love it. A little
piece of history for you guys. My first science class. Was Tyler and Bruce Schneier. Whoa. What, really? I didn't know that. Yes, sir. Yes, sir. He was teaching something about encryption and cryptography, if I'm not mistaken. Interesting. Fascinating. I didn't know that was a thing.
It was back in the yonder days of of what we call now cybersecurity. Wow. Wow. Yeah. And now I'm looking at your LinkedIn profile trying to figure out how old you are, because your picture makes you look younger, clearly, I'm only 27 years old there, Tim. It looks like it on your picture.
It does.
Tim, another question for you. All the things you've done, accomplished, accolades beyond imagination. But how do you stay current? Tomas was asking some questions about AI, and you were ready to go. Good luck. It's a newer topic or newish topic, but where you're running a business, you got people that you're depend on you for their paycheck and their mortgage and their kids going to college.
How do you stay? How do you have that balance enough to be able to stay current on things while still doing all the other things you talked about? Do you have a strategy or a hack or a way that you do that? And yes and no. So like I've got next to my desk, I have a paper notebook. And I write down the things that I need to work on shorter term not the longterm goals kind of thing, but the shorter term whether it's because it's, because it used to be like back in the day when I was purely technical all I really, I don't wanna say needed to do.
Or that all that I did, but I really focused on the technical now, because I've got a team of fantastic, smart folks who are better at it than I am now. I learned by proxy, looking at their reports, looking at their discussions, talking to them for some of that for the business sides of things just reading articles, digging into specific topics, talking to other smart folks it's a lot more in this position, a lot more.
For lack of a better word, ADD which is what I figured. I'm learning now that I am at, cause my son got diagnosed where my wife's telling me, he's he can't do such and such. I'm like, nobody can. She's are you kidding me? Go. Okay, cool. It's but I always put my keys back in the the tray.
My wife's no, honey, you've never put your keys back in the tray. I put them there. You just think you always put them there. Yeah. Okay, cool. Anyway. With this type of position, it's a lot more. Interrupt driven where, Hey, let's work on this issue. Let's work on this issue. Let's work on this issue, which really helps place in my, I don't want to say strengths, but my best weaknesses.
So it's a lot more of that. Hey, let's burst into this burst into this, where in the olden days, digging through an RFC multiple nights in a row, trying to figure out one specific thing that's no longer in the cards and that's good, I I think I evolved past some of that, but I get to deal with some fantastic people in all sorts of different areas and get to see now, Hey, how can we take the tech and combine it with, the dealing with clients and in, in the marketing and in all these different pieces.
And it's a much broader canvas now, instead of just one particular piece.
Wow. Reading RFPs. So you're one of those guys. Huh? RFCs, yeah. For my Kerberoasting, my baby, I was digging through so many freaking RFCs. It was excruciating.
So tell us a little bit, for those that don't know what that is, tell us a little bit about that. Is it still working today? Still active today? Get us from where that started to where that is now, if you don't mind. Yeah Kerber roasting is a way to do in short version is to an offline attack.
Password guessing attack against service accounts. And let me give you the story here, because I think this is this is the question I get asked all the time is like, Hey, how did you come up with it? And, It wasn't this rebel. It was nothing fancy. It was me and some friends on IRC just chatting about Hey, how does Kerberos work?
And I was like, Hey, I think that the service account, the ticket, the service ticket, it can only be protected by this the password hash for that account. I don't want to get too technical here, but it was then Let me validate this. Let me dig into this particular piece and, figure out how to like, cause it's one thing to know and know how to attack it.
Now I've got to figure out like, how can I extract the ticket and then try to crack it and write a cracker and all these different pieces that were much more difficult than the initial concept. And it was really just that grit determination, the refusing to get, to let the stupid thing win. And just digging into this thing.
And when I presented it at Derby con in 20, 2014, we're coming up on 10 years. Now, I thought it was gonna be cool. I thought it was going to be interesting. I thought realistically it would work for maybe a year or two and then people would update. The passwords for their service accounts, we're still seeing it.
I saw it mentioned numerous times in the most recent Verizon data breach report. In fact, they said that the number went up and I was like, are you kidding me? I also learned some valuable lessons along the way here. I learned that I'm terrible at submitting talks. I got so many talks that specific talk, I got rejected so many stinking times.
Cause I just wasn't good at it. But to be good at writing those, I'm still not good at writing those. And to be fair, it does sound kind of kooky. At first, when you think about, yeah, I'm going to offline brute force the the account for this service without ever talking to the service. It just sounds loony.
But I didn't explain that well enough. So that's a valuable lesson that I try to come back to and be like, what's the point here? What am I trying to communicate? Why does this piece matter? But in short.
I think we may have lost Russell momentarily, but there he is. There he's back. That Kerber roasting. Interesting. That is a, that's an interesting one. I didn't know that you were the the man, the myth, the legend behind that.
So do you hand out like I'm going to stop. I was going to go, I was going to ask if you handed out any any autographs, but I don't know. I don't have a good one. No, they, I get asked for those from time to time and I'll sign stuff.
It's weird.
I put a value. Russell, you back with us? Russell, you want to add on? No, I'm back and I'll just start with it. LinkedIn has issues sometimes. There's not a way to share anything in text here, but fleet has sent me a direct message earlier about a recent talk that you gave on Mark Baggett's YouTube channel.
InfoSecToolShed, I think is the name of that, where you talk more about the origin story. And so more details are out there on the internet there and a whole bunch of other places is all I was going to add.
Yeah, it's a really cool series he's doing on like the invention of he talks to HD Moore about Metasploit and some other, Influential tools. And he, I think he messed up and let me talk for a little bit about Kerberos stain, but it was a cool opportunity to be there.
That's awesome. Look at it. It is getting close to the to the end of our segment. I don't want to be respectful of everyone's time. I'm going to just make a few quick housekeeping items in terms of announcements, and then we'll get to we'll get to wrapping up here. We are we have a great session coming up in a month.
So I encourage everybody to tune in for next month's session. We have Pedro Peralta joining us. So that should be a very interesting conversation learning more about Pedro and his origin story and his current journey that said I do want to take a moment and thank tim for taking again time out of his busy schedule.
He just got back from singapore. I think you said tim yeah, you're probably still Trying to figure out which way is up, down, left center, and what time zone it is. So good luck trying to figure that one out over the next few hours to date as you adjust. But I do want to ask you This last question, and it's a reflection question.
You answered a little bit about it. When you talked about, what would you do if you weren't doing if you weren't a pen tester? But this question is really about It's really focused on the younger Tim. If there was one piece of advice, you've been doing this for a while.
You're an educator, you're a CEO, you've got two master's degrees, and that is just awesome. Clearly, anyways, that's just awesome. I think that's a great thing. But if you have one piece of advice for the younger Tim, what would it be and why? Yeah, I think without question, it's take more chances.
The potential downside of taking those risks is a lot smaller than what we many times perceive it to be. And I was on the TikToks wasting some time. Cause I couldn't sleep the other day. And they were talking to these older people and they're like, what's their biggest regret if they could go back and they're seventies, eighties, nineties.
And their big thing was, I wish I would have taken a chance with this or done this, talk to this girl this guy, this taking this job, try this thing, and it's that thing. Like I said before, if I could go, I mentioned a little bit before I wish I started sooner. And I just didn't have that confidence.
And I just wish I had taken that step a little bit earlier, cause I really like doing this. Like I said it's exhausting, but it was that thing that I've always wanted to do it. Without question. It's take more chances, take them sooner and swing for the fences. And cause the impact, yeah, things might not go with the best, the worst isn't often that bad.
Horribly terrible. That's great advice. That is absolutely great advice. The biggest risk is the one not taking it. I know that sounds very cliche and it probably is a cliche actually. But it's true. So many people go through life and they're like, what if, and you don't want to go through life with the what if I would have done this, why didn't you do it?
Don't let fear or the fear of failure stop you from, taking a step in the direction of success. Yeah. If I can add to that too I forget the exact quote, but it was something to the effect was no one's gonna. Remember that book that you never wrote, but someone might remember that email you didn't respond to where it's such a weird split.
Like that, and for me, it's not writing a book. I don't really have a desire to do that, but that is a stand in for whatever that big thing that's important to you. If you never try it, no one's ever going to know. And to some degree you've never failed at it, even though that, that's definitely a point of maybe disagree with, but there had to be some of those sacrifices.
Of things that aren't important, like responding to that email or things like that. And it's that, Hey, what's the actually important thing versus what's that thing that appears urgent that doesn't really fricking matter. Yep. Prioritization. Agreed. Real quick Russell any final words for Tim as we look to wrap up this evening?
Hey, Tim, you've been a friend for a long time, trust you, modeled a lot of the things that you said and done over your career. Thanks again, as Tomas said, for agreeing to spend the last hour and a half. You had no idea what you're getting into and you did it anyway. So thanks for that and all the nuggets that you shared with us this month.
Yeah. Thanks for having me. I appreciate the the time here. I will, I think another, this, the most valuable lesson we need to learn here. This is more specifically for Tomas. All 32 teams might be equal, but some are more equal than others. And go Packers. Bears suck.
I asked for, for final words, but clearly you've already left the final word. With that, Tim, I look forward to to meeting you in person one of these days. Maybe at a Packer game or maybe some at some point in time in Green Bay. All right, man. So thanks again. Thanks for your time, Ali.
Thank you, Russell. Thank you. It's always great to to be on this with you all and thanks for the folks tuning in. We'll be back online with the replay at some point in time, soon enough, if you missed any segment of today's show, have a good one, everybody. Have a good rest of your week and we'll chat in the month.
Appreciate it. Thanks everyone.
