episode.ascii — live render
● episode

Supply and Command

TL;DRIn 2011, hackers breached RSA Security via a phishing email, stole the secret seed values behind SecureID tokens, and compromised two-factor authentication used by governments and major companies worldwide. The full story only became…

Or, spooky tech stories with Jordan and Scott, in which we discuss the SecureID hack, and riding into important places on the bottom of important shoes.

Transcript

Machine-generated transcript; may contain errors.

Speaker 1: So there have been these stories over the last few years and they all kinda go the same way. There's this big organization, like a company or a government, and they spend a ton of money on cybersecurity And, they put all of this time and energy into erecting these really tall walls around all of their cool cool stuff. But, they're modern companies and modern companies have to use software. So, they have to let some stuff through the really tall wall. They have to have a little door to pull like software updates and all that stuff. So, say you're a really, really ambitious person and you're trying to break into like Microsoft or Intel or the Pentagon, you can try and break into the Pentagon, hard, or you can look at all the like people that the Pentagon lets through that little door in the wall. You can look at the software that your target uses, accounting or project management or IT, and you can just break into that and hitch a free ride in, which is easier. It's called a supply chain attack. And a lot of the big famous hacks over the last couple years have been supply chain attacks. SolarWinds in 2020, Microsoft Exchange Server in 2021. But there's this one, way back in 2011, that precedes all of them. Them. This sort of like warning flare that went up. And it involves a company called RSA. And that's what we're gonna talk about today.

Speaker 2: I'm picking a fight with the big boys,

Speaker 1: Because earlier this year, a ten year non disclosure agreement finally expired. So we finally know what happened during one of the first modern attacks of its kind. This is some name I haven't come up with yet.

Speaker 2: This is spooky shit by Jordan.

Speaker 1: This is spooky text stories with Jordan and Scott.

Speaker 2: RSA is the most notorious security company for sure.

Speaker 1: When you say notorious

Speaker 2: Notorious in a good way. Like, they're the they are based in academia, came out of, like, MIT. Interesting. Very well respected. Yeah. The head of the company was, like, a cryptography, like, professor, and, like, they created the the tokens, like, the security fob tokens, which I feel like we're about to talk about. And, really cool company. Lots of respect in the industry. Very well respected Mhmm. Professionally and academically.

Speaker 1: Even on the far side of this, you still get the sense it's like, oh, this company is still used by large organizations. And when you hear what happens, the fact that they're still the big one Mhmm. Speaks to the fact that they do know what they're doing

Speaker 2: Yeah.

Speaker 1: Even though all this happened.

Speaker 2: Yeah. They're definitely they're definitely somebody that I would take seriously. Mhmm.

Speaker 1: Yeah. I think the people that took them I think the people that did this took them pretty seriously.

Speaker 2: They're also the maker of the tall walls. So it's less of a supply chain attack through, like, some, you know, ancillary vendors. I feel like we're about to talk about a hack through a security solution.

Speaker 1: Yeah. We'll get there. For anyone who doesn't know, what is two factor authentication, Scott?

Speaker 2: Well, it means you have to authenticate twice, essentially. So password one, then it wants you to verify that you were actually the person trying to log in so that if your password typically a password. If your password is correct, you know, it's not being used by somebody that shouldn't be. So they go to a second factor. We've talked about this in numerous episodes, you know, whether it's a text message to your phone that has a code or whether it's, you know, a two factor authentication app on your phone. You know, there's lots of those these days, as well as other things, emails, calls, etcetera, etcetera. Yeah. I think And tokens that have big crazy random numbers on them.

Speaker 1: I think most people's experiences, yeah, you go to log in and they text you a number. So you have your username, your password, and then this kind of other verification method, this this code or something. Yeah. You brought this up a little bit earlier, but have you ever seen a secure ID token? Hundreds of times. What does it like, what does it look like for anyone that doesn't know?

Speaker 2: Looks like a USB key with a tiny little LCD screen on it.

Speaker 1: Yeah. It's almost like a little pager.

Speaker 2: Yeah. It's essentially if you've ever used a two factor authentication, app, typically, it just has a random number generated inside of it. This is kinda like the first version of that. That was a physical thing.

Speaker 1: Instead of getting text to the confirmation code, it's displayed on that little pager.

Speaker 2: So you have to physically be in control of this fob. Makes sense. Yeah.

Speaker 1: On that little fob with the little screen, where do you think that number comes from? Most people, it gets texted from somewhere. We have no idea where that number is produced, how it's produced. Sure. On that little key, it's not Internet connected. Where does that number come from?

Speaker 2: Yeah. So the this has always been the point of you're you're trying to dig into something that I've always found fascinating. So I know might know a bit more than you expect about it is, the server time and the fob time have to be essentially in perfect sync. So you you can assume that the algorithm uses something to do with time because that's the the thing that's common between both of the items. What it does with that time and how it hashes that into the code, who knows? But it is time based.

Speaker 1: The code is generated in real time unique to your little device, and it's unique in that it's generated based on this unique seed number, that that on the device that the company creates when you buy one. Mhmm. The company keeps a copy, the customer has their copy, and when you log in, they check them against each other and, cool, you're done. And to make it extra fun, like you said, the code changes based on the time, based on an a clock inside the device and a clock on the server.

Speaker 2: Thirty second in a roll or something.

Speaker 1: In every thirty seconds, sixty seconds, whatever the device says, both the pager and the company generate a new code based on these seed numbers and the clocks on both devices. This algorithm or what hash or whatever it is generates the codes based on the seeds that they share in common, and every machine and server kind of uses that one process for generating a code based on the script. Mhmm. But the seed, that's what's unique. So it's really, really important in the security of all of this stuff because if you have it, you could theoretically reverse engineer the code out of it because they're all using the same process.

Speaker 2: Yeah.

Speaker 1: So for context, secure ID still sold. It's by all accounts of, like, very well regarded secondary validation method.

Speaker 2: It was one of the first. It was maybe the first. They maybe invented two vector authentication with it, And it was wildly successful. You couldn't work for a major government or be a vendor to a major government without having a secure ID tag.

Speaker 1: And in 2011, some stuff went down with it. Then I'm sure they've fixed. Like, I I know this is a company that takes us really seriously, and I'm sure that they've gone on to make systems that where this could never happen again. But it did happen, and we now know what happened. So now we're gonna talk about it.

Speaker 2: Well, I think they almost certainly fixed it. And I would say that the fact that there was a ten year NDA period is indicative of, you know, security through obfuscation where they needed a period to fix the problem because the it was so widely rolled out that if it had become widely known that these things were, you know, hackable quite easily, you would had a much larger issue globally.

Speaker 1: So back in 2011, on March 8, the systems administrator notices that there's an employee user account on the system acting bizarrely. Their permissions have, like, changed in a weird way, and they've started using a new device they've never been on before. So the admin runs it up the line to their bosses, And the veteran engineers are like, piss off. We're working on, like, cryptography algorithms. It's very high level stuff.

Speaker 2: This is an RSA. Sorry.

Speaker 1: K. We're too busy to worry about this. But the admin is like a pain, and they insist, no. Like, something is actually going on here. And so the engineers take it seriously. They They start to look at it, and it's admittedly pretty weird. So they start to dig around into this user's behavior, looking at what devices the user is accessing and what they're doing. And for the last couple days, this user has just gone off the rails. They finally go, Okay, we need to look into this. First thought, oh, just delete the user's account. That was my thought at least, which ignores the fact that they've already had, like, five days heads up. Yeah.

Speaker 2: That's a that's a terrible idea because you essentially delete the the the breadcrumbs to see what they've been up to.

Speaker 1: This is why I'm not an engineer at one of the best security operations in the world. And they're trying to parse through what this user's been doing, and and stuff that looked kinda weird starts looking like very just outright insidious. And the more that they comb through it, the more it starts to get worse and worse and worse. So they start to piece it all together. And they build out what is to become a war room within RSA because this is about to become a war. And it seems this is what happened. This hacker, this actor or crew, whatever they are, starts by getting access to a single employee's credentials, who we're gonna call the Australian. What would be the most unremarkable way that they could have gotten this one Australian employee's credentials? For as complex as this is all gonna become, what would be the simplest way to get that first set of login credentials?

Speaker 2: You find it. He forgets it somewhere. Leaves it in a bar at the beach, the cafe.

Speaker 1: Wrote it down on a sticky note, and they just saw it with their eyes.

Speaker 2: Oh, you gotta assume that they were probably using secure ID tokens for access. So he probably had to gain access to his secure ID token, which might have been just him finding it.

Speaker 1: They sent the guy an Excel spreadsheet labeled 2011 recruitment plan that he opened, and it had a script that exploited a zero zero day vulnerability

Speaker 2: in Flash. That's very 2011 y. Just fishing. Yeah. Just like a a basic macro inside of a a Excel spreadsheet to hack your system.

Speaker 1: And they use that to install a more useful piece of software called Poison Ivy that gave the hacker this up the the ability to do key logging and remote access. Get a bunch of class control stuff, and they're just off to the races. Once they had control of the Australian's PC, they used a different tool that pulled credentials out of the machine's memory and then reused those usernames and passwords to log in to other machines on the network. Mhmm. They would scrape those computers' memories for more usernames and passwords until they found some belonging to a person with even more privileged power.

Speaker 2: Of course.

Speaker 1: And they just worked their way up until eventually they got to a server containing hundreds of user credentials, and they were

Speaker 2: Yeah.

Speaker 1: They were free. And this technique I was reading about this of, like, combing and hopscotching. Combing and hopscotching is, like, very, very, very common now. That's a recurring theme in this. But back in 2011, in all of these, like, disclosure or, like, interviews, a lot of the engineers are talking about this was pretty novel to watch someone just run through a network this way of finding the credentials and working their way up to better ones each time. It was, like, quite strange to be watching someone doing this, apparently. So by the time the RSA war room catches up, the hacker has basically unfettered access to their entire network, and they're moving around freely. And the hacker would go here, and, like, a second later, RSA would see them and, like, shut that down, but they'd already be gone to something else.

Speaker 2: When you have so many accounts, you either have to shut your whole company down and evaluate from there or you know?

Speaker 1: Yeah. Would it be wild if this is that's where this ends up? So the question starts to emerge in this RSA war room. This is, like, a lot of effort for this hacker. There's gotta be multiple people doing it because they're running twenty four hours. Like, they're just chasing after them. So, like, why? Like, where are these people going? What are they looking for? Are they looking for something in particular? And I bet you can guess where this is going.

Speaker 2: Russia.

Speaker 1: That's closest. And we're brought back to those seeds that I mentioned at the start of the show. Yeah. The seed that is unique to each token and each server.

Speaker 2: Looking for the Excel spreadsheet of seeds?

Speaker 1: The seeds, if you have them, kinda just rips a huge hole into the pocket of everyone using one of these little security tokens.

Speaker 2: Well, at that point, they've probably seen the source code for the tokens themselves, understand the the algorithm, the hashes, and generates the the the number, etcetera, etcetera. So

Speaker 1: A product that if it was compromised, isn't great for a cybersecurity company to have been compromised by a hacker, just PR wise? Like It's a

Speaker 2: big Definitively. Bad bad for national security too because I'm sure SecureID was used throughout all of the American and probably European, security forces and etcetera etcetera.

Speaker 1: Government agencies. 100%. So my question was how did RSA store those seats?

Speaker 2: Tell me unencrypted an Excel file on a shared drive. Do it. Tell me that.

Speaker 1: Do it. Tell me that.

Speaker 2: The d drive slash don't share with anybody slash

Speaker 1: encrypted seeds It was, super

Speaker 2: private underscore confidential dot x l s.

Speaker 1: It was on the desktop on a folder named desktop inside of another folder named desktop.

Speaker 2: So you've seen my desktop.

Speaker 1: Air gapping for anyone that doesn't know, Scott.

Speaker 2: Yes. Air gapping is to literally never plug a computer into the Internet. It is air gapped. Air gapping less cool now with Wi Fi because, technically, that's over the air, but air gapping just used to mean not plugging an Ethernet cable into your computer. Sure.

Speaker 1: A non networked computer.

Speaker 2: Yeah. And then generally never has seen the network. So you buy a new one. You set it up completely independent, and you never put it on the network. It's what you do with things that you definitively never want to see the Internet.

Speaker 1: They called it the seed warehouse, and it's this totally air gapped set of computers. It's the most, like, cordoned off part of their system, and it's just for these seed values. Except, sometimes the tiny little door users needed to be able to get their seeds from RSA. So that they could like set up their own servers and it's their property. They can they're allowed to have a copy of it. And the way that RSA handled this was with this one network computer. Its job was to pull the seeds that the customers wanted a copy of so that they could burn them to a CD and ship them off to them. And every fifteen minutes, this computer would connect to the seed warehouse, download the appropriate seeds, and send them off to manufacturing to be printed to a CD. Weird. There was a firewall. IT was very aware of this and really locked that computer down. And people that are really, really good at locking computers down, they saw this, they saw the vulnerability, and they they they were very, very serious about it. But it was technically this one way

Speaker 2: in. It's very surprising to me because you've literally set up an automated process to extract these confidential seed values. So there's clearly, like, an API or something that pro programmatically you're talking to this air gapped system, which is not air gapped at that point. And you're saying, hey. These 12 clients want their seed values. Send them to me. And then it probably sends an unencrypted batch of them to you to burn onto a CD. But it's like, you've literally set up a a find and retrieve process for these hyper confidential things that are never supposed to be found or retrieved. It seems madness, maybe.

Speaker 1: And I'm sure I'm sure that the complexity of that process is, like, underrepresented in Totally. In these interviews and discussions. I'm sure it was would have been maddening for these hackers to get through that one little access point.

Speaker 2: But But they did.

Speaker 1: As there's as RSA is watching this hacker and trying to follow them and trying to keep them out of stuff, one of the engineers in the war room notices, oh, no. That one computer that usually accesses the seeds every fifteen minutes to print CDs is now logging thousands of continuous requests for data every single second. And they're pulling the seeds and amalgamating some of them over here and pulling more and doing them over here and merging those together and moving that over here in this increasingly large file of these seeds is just jumping around their network now. More added to it, more added to it, more added to it.

Speaker 2: It's like that, what was that game? Katari or whatever, where the ball rolled around and just got bigger and bigger.

Speaker 1: Katamari Damacy, but, like, seeds that allow you to get into, like, the Pentagon and stuff. Totally. That's exactly what it is. Just rolling bigger and bigger bigger and bigger. And bigger. Capturing a chair and a school bus and a yeah. A 100%.

Speaker 2: It's like, hey. I got the Pentagon. I got the US military. We got the CIA. We got you know?

Speaker 1: Until they had pilfered and recombined them into what appeared to be the full database of every seed RSA had stored in the warehouse. So even with the company of some of the best minds in the world following behind them, In just a few steps, they'd use this little connection to extract all the seeds and run off with a copy of them. It hopscotched first onto the hacker's remote server and then vanished onto a device somewhere and it was gone. Brutal. Where in the world it went and what happened next. We're going to get to right after the break. Starting some new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button that's used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shop ify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot, and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked.

Speaker 2: Where is Daredevil? Am I right?

Speaker 3: Don't miss the return of Marvel Television's Daredevil Born Again.

Speaker 2: So what's next?

Speaker 4: I feel liberated. We're gonna take this city back.

Speaker 1: Over the medication.

Speaker 3: In an all new season now streaming only on Disney

Speaker 5: plus. They're hunting us. It's time we started hunting them.

Speaker 3: I can work with that.

Speaker 2: This should be tons of fun.

Speaker 3: Marvel Television's Daredevil, born again, now streaming only on Disney plus.

Speaker 2: And, like, the other thing is too is once you've got a hacker running rampant through your network and you're chasing him around like a puppy, air gap the seed computer. Like, literally unplug the network cable that connects it to the one computer that is on the network. Like, just completely be like, okay. We have a problem here. What is the most valuable thing we have? It's that. Let's protect the shit out of that. Because and the fact that they had an API set up because if they were running recursive, like, fetches or queries to the seed database, The fact that they were the fact that that was possible is insane.

Speaker 1: And like I said, I know it's like I'm getting this from one cybersecurity firm's reporting and then the wire coverage on that for secondary verification. Yeah. Okay. This is what happened. Yeah. But it's like I know that I'm sanding off corners of, like, I'm sure that was a really complicated process.

Speaker 2: A zillion percent.

Speaker 1: But enough of the people, like, point to be like, that's that's how they got them was through that connection.

Speaker 2: By the time

Speaker 1: Well, that means that connection existed, which that was the vulnerability.

Speaker 2: And by the time you've got a war room set up A 100%. You've had enough time to respond by unplugging the one Ethernet cable. And none of this problem would have happened.

Speaker 1: On the topic of unplugging some Ethernet cables, if this was you Yes. And you're in the room In the room. And you were in the room. Yeah. You could just watch the hackers dip with all of these seats, these really sensitive seeds. Sure.

Speaker 2: I my letter of resignation has been written or

Speaker 1: I was gonna say what would your next step be?

Speaker 2: Yeah. Write the letter of resignation

Speaker 1: or at least put

Speaker 2: it in the envelope and drop it on my boss's desk.

Speaker 1: So their next steps were to then rip all the Ethernet cables out of the wall.

Speaker 2: Which is too late.

Speaker 1: It's far too late. Yeah. Not just the ones to the warehouse. They're like, we need to get everything offline right now. Because if they can get anything else out of our system, they might be able to start getting the, like, login credentials that are stored stored. Yeah. And then it's not a question of you have part of the puzzle. You have the whole thing.

Speaker 2: Yeah. So they they they had the right response just too late by the sounds of it.

Speaker 1: So the engineering team walks into the data center and they just start ripping cables out of the wall, air gapping kind of the whole company, cutting off the company's connections to manufacturing, custom orders, and even, like, their website. They just go offline. One employee later described it as like crippling the entire company in order to stop any potential further release of data. They go dark. So the hacker has the seeds, RSA backpedals and tries as best they can to just turn their whole system offline and in doing so turning off their business because now no one can log in with their stuff.

Speaker 2: Well, the so the crazy thing is is, like, you don't know a ton about network infrastructure and stuff, but most big businesses like that will have two, maybe three Internet connections. So they'll have redundancies and failovers and stuff, and they'll have it all crisscross through switches and stuff. But you can pretty much disconnect a large physical company. So, like, a a building with a company in it, which is probably what RSA had with, like, three Ethernet plugs. It's like, you know, it's pretty it's pretty easy. Like, it's pretty like, a kid could do it accidentally.

Speaker 1: Like, you trip and turn around.

Speaker 2: Yeah. Exactly. We're, like, ripping every single cable out of a switch would just be madness, but, like, you know, it would have been the second you had like, I think we've seen it before or I sense

Speaker 1: Mhmm.

Speaker 2: That when, you know, a big hack happens, some companies will just go dark. They'll just be like, oh, we have a problem, and their response is to just completely isolate themselves, which is great. Makes sense. An external attacker coming in through the wires. If you disconnect the wires, all of a sudden you're like, okay. What was the problem? We can have time to fix and patch and and plug, shut the little doors. And, you know, that's a great thing to do when you do it early enough.

Speaker 1: You you turn a a privacy and security crisis into a PR crisis, but that's a more manageable crisis. 100%.

Speaker 2: Yeah. Especially when you can blame it on whatever you feel like. Nobody has to know that you've pulled the pin because of, you know, the Russians.

Speaker 1: You're gonna owe some Russians some apologies to the

Speaker 2: Sorry, Russians. Estonians.

Speaker 1: So they've gone dark, and they all look at each other and they just go, we do need to tell the CEO right now.

Speaker 2: If the CEO didn't know already, that would be shocking.

Speaker 1: The CEO knew that something was going on. So they go to tell the CEO, this guy named Art Coviello. And Art had been following it. He knew there was something up, something unfolding, and it wasn't great. But the engineers are handling it. The team

Speaker 2: knows got a brilliant brilliant group of people.

Speaker 1: They'll get an update if anything happens. And here comes the update that something has happened. And one of the engineers trudges upstairs to deliver the news to the CEO in person. They have not handled it. Whoever this person is, they've got the seeds. It's a bad situation. In the hours that followed, RC's executives had this big debate about how to go public with this. One person in legal suggested they did not need to tell their customers, and to the CEO's credit, tells they gotta piss off. Yeah. Another guy named Joe Tucci, CEO of the, like, parent company that owns RSA gets brought into this discussion, quickly suggests, hey, we have lots of money. Let's just replace all 40,000,000 of these, like, little secure ID tokens right now and we're done. But RSA didn't have anywhere near enough of them sitting around.

Speaker 2: Manufacturers. Yeah.

Speaker 1: And since the breach had forced them to shut down their manufacturing capacity, they couldn't actually make more. So basically, they were stranded. The only solution to all of this which is going offline made it so they couldn't saw start solving any of the ways that they were stranded. They're just floating in the dark.

Speaker 2: Oh, but not only that, but, you know, to talk about little doors, if the system itself had some form of reset functionality, that would become a vulnerability. So so they probably didn't include anything like that because they thought they could keep Yeah. You know, all of the honey in the pot. And and when they didn't, you really have no other choices probably.

Speaker 1: So March 17, they go public, and they post an open letter to their customers.

Speaker 2: How many days was it between the hack and the things?

Speaker 1: They first noticed the Australians' weird activity Yeah. On March 8.

Speaker 2: Oh, so pretty pretty pretty fast. Pretty quick. That's good. Kudos to you.

Speaker 1: The letter read, recently, our security systems identified an extremely sophisticated cyberattack in progress. While at this time, we are confident that the that the information extracted does not enable a successful direct attack on any of our customers, this information could potentially be used to reduce the effectiveness of a current two factor authentication implementation as part of a broader attack, which is a it's quite a diplomatic way of putting what has occurred here.

Speaker 2: I think the the other perk is that it is a second factor, so it's not the whole thing.

Speaker 1: It's not the whole piece.

Speaker 2: If it was the password and the the Would

Speaker 1: be worse.

Speaker 2: The two f a, it would be a big deal.

Speaker 1: But the whole story starts with showing just how easy it can be to get someone's username and password. Like That's very true. So the company six this rotating crew of, like, 90 staffers on a weeks long, like, day and night process of having one on one calls with every single customer working from, like, a script in a call center just trying to handle the response to this. And the public response about how you would imagine, like their customer base is very high level people there. Angry. And the government responds about how you'd imagine, very very curious. They wanna know what is going on here. So the NSA swoops in and the FBI swoops in, and

Speaker 2: Well, they're probably all clients too.

Speaker 1: Northrop Grumman, like, swoops in. Like, all these big players suddenly get very interested in what is occurring in this war room at RSA. And, basically, the place this is outside the bounds of the cybersecurity and more just the social response which I found interesting. Apparently, people who work there said the physical office briefly, normally a pretty good place to work just descends into this very paranoid chaos because they don't know who's responsible for it. They're papering up like executives windows in case people have like like view finders to see passwords that were written on stuff because again they don't know. They're sweeping for bugs which some executives in the like interviews claimed they found like it's this very intense little two months that follows. They're getting new phones, and they're not trusting the old phones, and they're sharing paper documents hand to hand, and there's cybersecurity company.

Speaker 2: Air gapped communications.

Speaker 1: FBI is afraid that there's an accomplice inside of RSA's ranks because of the, like, level of knowledge that these intruders showed, and they start doing, like, background checks on these, again, very high level people. It's wild. And so they're trying to rebuild this whole company back to back with people that they don't wanna turn their back on. It's not a good situation. And there's this natural question that all of it raises, which is, like, hey. Once those seeds jumped off our servers onto the cloud servers down into some laptop somewhere in the world, what happened to them? Two months has gone by. We haven't heard anything. In case it wasn't clear, the wall metaphor from the top of the show, RSA is not the company with the walls. They're the one that all the companies let through the little door, obviously. Because as an authentication service, RSA got to go through some very, very, very fancy doors. And two months later, we find out which door the hackers had hitched a ride through. This tech blog called cringly.com, later verified by the New York Times, reported on a hack. The article was based on a tip from a source inside of like a major defense contractor who had told Cringly that the company was responding to an attack by hackers who seemed to have stolen RSA seed values to get into the company. And right at the same time, everyone at this big unnamed defense contractor gets contacted by RSA saying, hey, you need to have your secure ID tokens replaced right now. And all of a sudden, this breach that RSA had kind of said, you know, something might happen, it's a five, was starting to look like kind of a 10 for at least this one very large defense contractor.

Speaker 2: Can I guess who it was? Please. Lockheed Martin.

Speaker 1: Two days later, Reuters reveals the name of the company, little little tiny little upstart called Lockheed Martin. A company that held behind those walls a wealth of very, very secretive stuff.

Speaker 2: Yeah. The number one DARPA contractor in the world.

Speaker 1: Which kinda explains the speed at which, like, the FBI and NSA just, like

Speaker 2: Yeah.

Speaker 1: Rocketed in there.

Speaker 2: It's like, what do you guys do here? It's like, I don't know. We make drones and stuff.

Speaker 1: Why are those important? Yeah. So the Lockheed Martin story goes public, and everyone realizes that they use the RSA seats to do it. And all the good PR that they've been building for the last two months just goes right out the window.

Speaker 2: K. Wait. So can I change all the Russia things to North Korea? Is it too late?

Speaker 1: You're getting closer. Oh, k. One employee described it as a healing scab being ripped off. You know, we're getting we're getting better. We're earning back some just ripped it right off. Yeah. There's some conflict about how bad the fallout from the Lockheed Martin's hack actually was. RSA has denied that security had anything to do with it. Lockheed Martin says, no. It was explicitly RSA's fault. In a briefing to the Senate Armed Services Committee a year after, NSA's director said that the RSA hack did lead to at least one large US defense contractor, being victimized by actors. So shaking as it will.

Speaker 2: Bunch of lawyers trying to pass liability and

Speaker 1: Which is all to say that some people hitched a ride through some pretty fancy walls, using RSA as their vehicle. And the question, Russia, North Korea, who did this?

Speaker 2: Who done it?

Speaker 1: Who done it?

Speaker 2: Who done it dot IT? Dot gov.

Speaker 1: Let's think about this. So the hacker picks RSA to hack, and they make their way into RSA system, and they go digging around. And then, like, they were looking very explicitly for these seeds. Seeds that compromise this two factor authentication method used by world governments, Fortune 500 companies, and, like, some of the best targets in the world. And the attack was this very complex, high level operation with some large team hackers executing a, like, military precise operation in tandem to avoid RSA's response just to get this key to all of these secrets. And we didn't really know who it was until 2013. And I think it's worth remembering that in 2013, the idea of state sponsored hacking was nowhere near what it is now. And just in the cultural imagination, it was going on, but we didn't really have a sense of it. I think Sony in 2014 was when most people got the sense Sure. Oh, governments do this to each other.

Speaker 2: Yeah. Yeah. Yeah. This is new war.

Speaker 1: Today, we understand it as that, like you said, landscape of new war. But back then, it was kind of a novel ID. And in 2013, the security research firm called Mandiant published this very, like, groundbreaking report about this hacking group that they've been following. And indexing and trying to map out and figure out kind of who they were and what they did. A group that they named a p t one. Advanced persistent threat number one. But that went by this other name, unit six one three nine eight of the People's Liberation Army of China. China. Damn it. You're closer. You're inching closer.

Speaker 2: Getting closer.

Speaker 1: Their victims over the five years preceding this report include the US government, the Canadian government, South Korean government, and a little company, you know them, you love them, RSA. Poor guys. And on 05/19/2014, US Department of Justice announced a federal grand jury, had returned an indictment of five APT one officers on charges of theft of confidential business information and intellectual property. And quite obviously, those officers remain, I don't know if you can even call it at large. They're fine.

Speaker 2: And then I think if you're if you're if you work or own if you're being attacked by the the Chinese government, I could see papering up your walls, and I could see interviewing every one of your staff. Yep. Especially with such a complicated hack and such a such a unique point of entrance data. So, like, the the fact that you'd because I'm sure everything's in DMZs and, like, there's probably so much network security layered in that it would take you so much time just to kind of putz around and find your way around the network unless you kind of knew how it was set up in advance. And if you knew how it was set up in advance, you could probably do it at a much faster pace. Mhmm. So I could see how the FBI was like, you know what? There might be some accomplices in here. And when you're dealing with the Chinese government, you know, there might have been some accomplices in there.

Speaker 1: It the paranoia in those two months that follows makes a lot more sense.

Speaker 2: Yeah.

Speaker 1: I think there's an interesting shift in the story, which is at the start of it, RSA is the giant. They're one of the biggest cybersecurity manufacturers in the world.

Speaker 2: They're best at it. Biggest. Yeah.

Speaker 1: They seem like they're the the Goliath that some little David is coming after. And then when you find out who that David is, it's like that's just two Goliaths fighting. And I think the second one's actually a little bit bigger. Yeah. For sure. This group has a bunch of different nicknames, and they're all interesting for different reasons. Mandiant nicknamed them APT one, which is interesting because the phrase advanced persistent threat has since then entered into the lexicon, and they are functionally the first one. Yeah. For reasons they're quite literally the first for reasons that become clear in a second. The other is Biontin Candor. Cool name. Star Wars name. It's a code name based on US intelligence agencies since they first discovered the group in 2002, which tells you a lot about how long this group has really been going, that they were really the first advanced persistent threat in this ecosystem. So last December, when the story broke that, Russian spies had hacked SolarWinds, I think a certain corner of the tech community opened their eyes to this technique of supply chain attacks.

Speaker 2: Yeah.

Speaker 1: They knew it happened, but I think that kind of really codified it. People said, we need to start thinking of this as its own thing. Yeah. The Kremlin operatives who hacked SolarWinds then hid malicious code inside of an IT management tool called Orion, which is used by, like, 18,000 companies around the world. Yeah. And the hacker used that software to ride into all kinds of targets. That technique for a lot of people in this industry, they have described it as really starting with RSA. And it's kind of like when a person invents a new way of doing anything. It's like a new way of building something or growing something, creating something. At first, the technique is new and novel, and everyone pays attention to it. But, eventually, people go, well, this is so much better. Why would we ever do it in any other way whatsoever?

Speaker 2: We talked about this before. Like, when we talked about god. I can't remember what episode it was, but we talked about state sponsored stuff. And and, you know, if you can put a backdoor in a firewall, then it's better than hacking a firewall because people don't expect it. Yeah. And you leave no traces. If you can put a backdoor in management software, IT management software, if you can put a backdoor in exchange server, if you can hack in and insert your own little insert your own little door, then you can come and go as you please. Yeah. Like, imagine, like, you know, we talk about password managers, which I use now. Congratulations. Thank you.

Speaker 3: But if you

Speaker 2: had a backdoor in that, like, think about Yeah. Like, what is a password if you can just walk through people's password management software? And it's like yeah. I think I think picking if I was a state, I would pick targets of high value like that. I would go after stuff like that. That when when you when you succeed once, you actually succeed hundreds of thousands of times. Like, you've got to imagine how secure Microsoft is being the number one commercial platform. Like, you know, it's the number one server platform and stuff like that. Imagine how intense the security measures to get into their code base are. Because if anybody could do it or if you could hack your way to that, literally, Windows 10 is on Everything. Everything in every company and every government. So, yeah, high value.

Speaker 1: High value. Yeah. For the very tiny club of people who are in the business of hacking governments and multinationals, it's just the smarter way to get at those high value targets. Right. So I think my takeaway in this is the the next time I see one of these hacks in the news, one of these big dramatic operations in cyberspace, I'm gonna start by asking what kind of accounting software or email client or two factor authentication tool they used because that's probably what tracked the hackers in on the bottom of their shoe. That or an Australian guy. Big shout out to our new June Patreon supporters, that the the the June goons. June goons include Gene Stover, Guy, and Mike Ferraro. Your support means just the world to me. Thank you so much. If you found the story interesting, there's there's some really really cool new coverage, out on it right now. Andy Greenberg's water is a great place to start. Lots of really cool stuff. Very interesting story. This was kind of a a little bit of a crazy episode to put together. I am moving right now, so I appreciate your patience. We're gonna be back at it next month. If you like the show, if you wanna support the show, patreon.com/hackedpodcast. Best way to support the show. Comment, subscribe, share it, tell people about it. You can follow us on Twitter at hacked podcast. Thank you as always so much for listening.

Speaker 4: If you've got an insurance question, you could talk to your nana. But she'd probably just tell you how she insured her couch from stains by covering it with plastic. Or you could talk to your local GEICO agent. They'll give you a different kind of warm and fuzzy with personalized assistance for all your insurance needs, like how you could be saving on your policies. So let your nana cover her couch in plastic and let a local GEICO agent help cover you, but not in plastic. To find a GEICO agent near you, visit geico.com/local.

Speaker 5: This episode is brought to you by Nespresso. Being the best version of yourself is an everyday journey, and it begins in the morning by taking a moment to ground yourself. With the new Nespresso Vertuo Up coffee machine, morning routines become rituals. Just one gentle press. And coffee brews, unfolding into whatever you need today. Bold or delicate, iced or hot, familiar or new. Press to explore. Every coffee, a new world. New virtual up. Shop now at nespresso.com.

Speaker 6: The right window treatments change everything. Your sleep, your privacy, the way every room looks and feels. At blinds.com, we've spent thirty years making it surprisingly simple to get exactly what your home needs. We've covered over 25,000,000 windows and have 50,005 star reviews to prove we deliver. Whether you DIY it or want a pro to handle everything from measure to install, we have you covered. Real design professionals, free samples, zero pressure. Right now, get up to 45% off-site wide plus get a free professional measure at blinds.com. Rules and restrictions apply.