WEBVTT - 7 Types of Malware

0:00:04.400 --> 0:00:07.800
<v Speaker 1>Welcome to tech Stuff, a production from I Heart Radio.

0:00:11.920 --> 0:00:14.520
<v Speaker 1>He there, and welcome to tech Stuff. I'm your host,

0:00:14.680 --> 0:00:17.760
<v Speaker 1>Jonathan Strickland. I'm an executive producer with I Heart Radio

0:00:17.840 --> 0:00:21.040
<v Speaker 1>and how the tech are you So? On the tech

0:00:21.079 --> 0:00:25.079
<v Speaker 1>Stuff news episodes, I often end up talking about stories

0:00:25.320 --> 0:00:30.480
<v Speaker 1>involving malware, and I'm guessing you're all aware of malware

0:00:30.520 --> 0:00:33.080
<v Speaker 1>at least to some degree. If you work for a

0:00:33.120 --> 0:00:37.200
<v Speaker 1>company like mine, you'll hear about malware several times a month,

0:00:37.520 --> 0:00:40.760
<v Speaker 1>as we have an extremely proactive I T security team

0:00:40.840 --> 0:00:43.400
<v Speaker 1>that works hard to keep employees up to speed on

0:00:43.440 --> 0:00:47.000
<v Speaker 1>the dangers of malware and the various tactics used to

0:00:47.040 --> 0:00:51.200
<v Speaker 1>deliver payloads to targets. But I figure it's always good

0:00:51.360 --> 0:00:55.440
<v Speaker 1>to do a quick rundown on different variations of malware

0:00:56.120 --> 0:00:59.760
<v Speaker 1>and what they do. Now, keep in mind, well I'll

0:00:59.800 --> 0:01:04.200
<v Speaker 1>be talking about broad categories. You can sometimes find examples

0:01:04.319 --> 0:01:07.319
<v Speaker 1>of specific malware that kind of belonged to more than

0:01:07.400 --> 0:01:12.360
<v Speaker 1>one type or category. And I'm really I'm using categories

0:01:12.360 --> 0:01:16.720
<v Speaker 1>that are identified by Cisco because you have to take

0:01:16.760 --> 0:01:20.080
<v Speaker 1>definitions from somewhere. But as it turns out, because of

0:01:20.120 --> 0:01:23.880
<v Speaker 1>these similarities between different types, you can sometimes find other

0:01:23.920 --> 0:01:26.720
<v Speaker 1>companies that will define them in a slightly different way,

0:01:27.280 --> 0:01:31.280
<v Speaker 1>but I figure your Cisco is a pretty good authority

0:01:31.319 --> 0:01:35.320
<v Speaker 1>to build this episode off of. Just keep in mind,

0:01:35.319 --> 0:01:38.800
<v Speaker 1>if you do your own research, you might find variations

0:01:38.959 --> 0:01:41.880
<v Speaker 1>on what we'll be talking about here. So starting off,

0:01:41.920 --> 0:01:45.600
<v Speaker 1>before we even get into the different kinds, let's define malware,

0:01:45.760 --> 0:01:52.600
<v Speaker 1>so that term is short for malicious software malware. Back

0:01:52.640 --> 0:01:55.720
<v Speaker 1>in the early days of computing, I always just heard

0:01:55.720 --> 0:02:00.200
<v Speaker 1>of viruses, and you know, viruses are a subcategory. There

0:02:00.240 --> 0:02:05.120
<v Speaker 1>are a type of malware, and I actually to this

0:02:05.240 --> 0:02:09.960
<v Speaker 1>day still have to focus to refer to malicious software

0:02:10.000 --> 0:02:12.400
<v Speaker 1>as malware instead of just doing the lazy thing and

0:02:12.440 --> 0:02:16.040
<v Speaker 1>calling them all viruses. Because when I was a kid

0:02:16.440 --> 0:02:20.160
<v Speaker 1>and personal computers were first becoming a thing, that's what

0:02:20.240 --> 0:02:23.240
<v Speaker 1>we referred to all malicious software. It was all of virus,

0:02:23.680 --> 0:02:26.520
<v Speaker 1>partly because networking was not really a thing with personal

0:02:26.520 --> 0:02:30.520
<v Speaker 1>computers in the early days. So anyway, old habits die hard.

0:02:30.560 --> 0:02:34.000
<v Speaker 1>That's why I sometimes will still do it. But uh,

0:02:34.240 --> 0:02:36.880
<v Speaker 1>as I said, we'll see that virus is one subset

0:02:36.880 --> 0:02:41.360
<v Speaker 1>of malware. And because we're talking malicious software and not

0:02:41.520 --> 0:02:45.480
<v Speaker 1>just cheeky programs that are meant to cause mischief. We

0:02:45.560 --> 0:02:49.040
<v Speaker 1>typically will say that cyber criminals are the ones responsible

0:02:49.080 --> 0:02:51.799
<v Speaker 1>for developing the software in the first place, and they

0:02:51.800 --> 0:02:54.000
<v Speaker 1>may or may not be the same cyber criminals who

0:02:54.040 --> 0:02:58.240
<v Speaker 1>actually distribute the malware. Now, many folks will use the

0:02:58.280 --> 0:03:03.080
<v Speaker 1>word hacker to stand in for cyber criminal, but I

0:03:03.160 --> 0:03:07.960
<v Speaker 1>object to that because it implies that hackers collectively are

0:03:08.560 --> 0:03:12.880
<v Speaker 1>bad people. But if you'll forgive me a short tangent,

0:03:13.120 --> 0:03:16.160
<v Speaker 1>I'd like to explain why that's not really the case.

0:03:16.800 --> 0:03:19.960
<v Speaker 1>So the word hacker in the context of someone who

0:03:20.000 --> 0:03:23.440
<v Speaker 1>works with code dates back to the late nineteen fifties

0:03:23.480 --> 0:03:27.800
<v Speaker 1>and early nineteen sixties at m i T the Massachusetts

0:03:27.880 --> 0:03:33.359
<v Speaker 1>Institute of Technology in other words, and it an originated

0:03:33.400 --> 0:03:37.800
<v Speaker 1>of the college's Tech Model Railroad Club or t m

0:03:37.960 --> 0:03:41.760
<v Speaker 1>r C. In fact, there's this humorous definition that Peter R.

0:03:41.960 --> 0:03:46.280
<v Speaker 1>Sampson created for the term hack, which then could be

0:03:46.320 --> 0:03:51.040
<v Speaker 1>extended to hacker. And the definition for hack, according to Sampson,

0:03:51.320 --> 0:03:57.440
<v Speaker 1>is this hack something done without constructive end, a project

0:03:57.520 --> 0:04:02.720
<v Speaker 1>undertaken on bad self advice, an intrope booster, or to

0:04:02.800 --> 0:04:07.040
<v Speaker 1>produce or attempt to produce a hack. So noun and

0:04:07.160 --> 0:04:10.040
<v Speaker 1>a verb, and I do not wish to put words

0:04:10.080 --> 0:04:13.080
<v Speaker 1>into Mr Sampson's mouth, but I believe he may be

0:04:13.360 --> 0:04:17.040
<v Speaker 1>using the word entropy here to specifically refer to a

0:04:17.080 --> 0:04:22.599
<v Speaker 1>decline into general disorder. Anyway, the blossoming field of computer

0:04:22.680 --> 0:04:25.640
<v Speaker 1>science took on hacker to mean people who were putting

0:04:25.640 --> 0:04:30.559
<v Speaker 1>together code, sometimes fruitlessly, as they were trying to get

0:04:30.600 --> 0:04:34.359
<v Speaker 1>a system to do something specific, Like they had a

0:04:34.400 --> 0:04:38.359
<v Speaker 1>specific goal they were working toward, and they were hacking

0:04:38.440 --> 0:04:42.599
<v Speaker 1>their way to getting that goal to come true. And

0:04:42.760 --> 0:04:46.360
<v Speaker 1>you know, the early days of computer science there was

0:04:46.400 --> 0:04:49.200
<v Speaker 1>a lot of trial and error when it came to

0:04:49.320 --> 0:04:52.520
<v Speaker 1>writing code that could achieve a specific purpose. There are

0:04:52.560 --> 0:04:56.760
<v Speaker 1>a lot of early programs that essentially did what they

0:04:56.760 --> 0:05:00.360
<v Speaker 1>set out to do, but on careful review of the code,

0:05:01.240 --> 0:05:06.800
<v Speaker 1>as as Jonathan Colton might say, it is not elegant, uh,

0:05:06.839 --> 0:05:10.920
<v Speaker 1>and it does not really do the goal efficiently, and

0:05:10.920 --> 0:05:14.839
<v Speaker 1>that you know, it's it's really a poorly programmed piece

0:05:14.839 --> 0:05:16.720
<v Speaker 1>of code, except for the fact that it actually does

0:05:16.760 --> 0:05:19.840
<v Speaker 1>achieve what it set out to do. Now, later on,

0:05:20.120 --> 0:05:23.119
<v Speaker 1>the word hacker would be used to describe curious folks

0:05:23.160 --> 0:05:27.600
<v Speaker 1>who just wanted to know how different technological stuff works, like,

0:05:27.920 --> 0:05:32.240
<v Speaker 1>for example, how does a telephone network route calls. These

0:05:32.279 --> 0:05:37.200
<v Speaker 1>hackers would explore technology and technological systems. They would learn

0:05:37.279 --> 0:05:40.760
<v Speaker 1>all about the quirks of those pieces of tech, you know,

0:05:40.839 --> 0:05:44.599
<v Speaker 1>what made them tick, and perhaps most importantly, how to

0:05:44.720 --> 0:05:49.600
<v Speaker 1>make the tech do stuff it wasn't necessarily intended to do,

0:05:50.839 --> 0:05:54.360
<v Speaker 1>Because there's something really satisfying about figuring out a way

0:05:54.360 --> 0:05:57.760
<v Speaker 1>to achieve a result using tech that wasn't you know,

0:05:58.760 --> 0:06:02.800
<v Speaker 1>built to do that thing. It I think it kind

0:06:02.800 --> 0:06:06.159
<v Speaker 1>of taps into the same part of our brains for

0:06:06.240 --> 0:06:08.960
<v Speaker 1>the people who really enjoy doing things like designing Rube

0:06:08.960 --> 0:06:14.240
<v Speaker 1>Goldberg devices. Those are those needlessly complex devices that are

0:06:14.920 --> 0:06:20.719
<v Speaker 1>designed to carry out some uh trivially simple task. Well,

0:06:21.600 --> 0:06:24.200
<v Speaker 1>I think the same thing that that pleases folks who

0:06:24.240 --> 0:06:27.800
<v Speaker 1>really love Rube Goldberg devices is what pleases people to

0:06:28.440 --> 0:06:30.599
<v Speaker 1>learn how the system works and then find ways to

0:06:30.720 --> 0:06:35.240
<v Speaker 1>exploit it to do something different, not necessarily something bad,

0:06:36.080 --> 0:06:40.760
<v Speaker 1>but different anyway. The word hacker really is more general

0:06:41.320 --> 0:06:44.480
<v Speaker 1>than the specific use case of, you know, people who

0:06:44.520 --> 0:06:49.200
<v Speaker 1>make malicious software, or even person who wants to infiltrate

0:06:49.279 --> 0:06:53.760
<v Speaker 1>a secure system. There are hackers who fall into those subcategories,

0:06:54.279 --> 0:06:58.719
<v Speaker 1>but I wouldn't use hacker as a broad stroke brush

0:06:59.120 --> 0:07:03.880
<v Speaker 1>to say person with malicious intent. Um, but frequently that's

0:07:03.880 --> 0:07:07.240
<v Speaker 1>how we encounter the word in the media. And you know,

0:07:07.560 --> 0:07:12.200
<v Speaker 1>language is fluid, Language does evolve, so it could very

0:07:12.200 --> 0:07:14.560
<v Speaker 1>well be that I'm trying to hold back a flood

0:07:15.000 --> 0:07:18.080
<v Speaker 1>and I should just accept that. Hacker effectively now means

0:07:18.320 --> 0:07:21.600
<v Speaker 1>jerk face who wants to ruin your day, or maybe

0:07:21.720 --> 0:07:25.280
<v Speaker 1>ruin your computer, or maybe the company you work for,

0:07:25.840 --> 0:07:29.040
<v Speaker 1>or maybe the country you live in. It can get

0:07:29.080 --> 0:07:32.000
<v Speaker 1>pretty scary. Now, one other thing before we start to

0:07:32.000 --> 0:07:36.480
<v Speaker 1>dive into the categories. The folks who distribute malware are

0:07:36.560 --> 0:07:41.600
<v Speaker 1>not necessarily the same folks who built the malware. They

0:07:41.640 --> 0:07:45.120
<v Speaker 1>can be, but they don't have to be. There are

0:07:45.320 --> 0:07:49.720
<v Speaker 1>malware programmers for higher out there. We could actually call

0:07:49.800 --> 0:07:53.600
<v Speaker 1>them hacks, because one of the definitions of hack is

0:07:53.640 --> 0:07:57.080
<v Speaker 1>a person who does you know, work for higher It's

0:07:57.160 --> 0:08:01.960
<v Speaker 1>kind of like the gig economy, and often we associate

0:08:02.000 --> 0:08:05.120
<v Speaker 1>it with someone who does, you know, like bare minimum

0:08:05.200 --> 0:08:08.680
<v Speaker 1>quality work and does a lot of it in order

0:08:08.720 --> 0:08:11.280
<v Speaker 1>to make a living. So like a hack, writer is

0:08:11.320 --> 0:08:15.640
<v Speaker 1>someone who generates an awful lot of writing but isn't

0:08:15.680 --> 0:08:21.119
<v Speaker 1>necessarily deeply concerned about the quality of their work. So

0:08:21.720 --> 0:08:26.240
<v Speaker 1>we could refer to these malicious coders for higher as

0:08:26.360 --> 0:08:30.640
<v Speaker 1>hackers in that sense, slightly different context from what we

0:08:30.640 --> 0:08:34.600
<v Speaker 1>were talking about earlier. Now, these programmers go on to

0:08:34.679 --> 0:08:39.000
<v Speaker 1>create malicious software and then frequently they will sell it

0:08:39.280 --> 0:08:43.480
<v Speaker 1>on a dark market, like on the dark Web, where

0:08:43.480 --> 0:08:46.760
<v Speaker 1>people are are looking for pieces of malware that they

0:08:46.800 --> 0:08:51.959
<v Speaker 1>specifically want to use to target either a specific target

0:08:52.120 --> 0:08:56.200
<v Speaker 1>or general target, and they have a specific goal that

0:08:56.240 --> 0:09:00.040
<v Speaker 1>they want to achieve. Uh. Sometimes they'll even make a

0:09:00.480 --> 0:09:04.199
<v Speaker 1>software available for free for distribution, but more often than

0:09:04.240 --> 0:09:08.320
<v Speaker 1>not you'll find it as like a pay for tool,

0:09:08.480 --> 0:09:11.320
<v Speaker 1>a weapon you can use in your arsenal. Now, often

0:09:11.720 --> 0:09:16.040
<v Speaker 1>cyber criminals who purchase these pieces of malware will then

0:09:16.080 --> 0:09:20.040
<v Speaker 1>go on to tweak that malware put their own spin

0:09:20.120 --> 0:09:24.040
<v Speaker 1>on it. So very frequently we will find lots of

0:09:24.120 --> 0:09:28.320
<v Speaker 1>variations of certain types of malware, and if you do

0:09:28.360 --> 0:09:32.720
<v Speaker 1>a forensics investigation into the malware, you will discover that

0:09:32.760 --> 0:09:38.360
<v Speaker 1>there are some common threads of DNA among different types

0:09:38.400 --> 0:09:41.560
<v Speaker 1>of malware. That can also be useful because if there

0:09:41.600 --> 0:09:47.160
<v Speaker 1>are common elements between different distributions of malware, it can

0:09:47.200 --> 0:09:50.520
<v Speaker 1>be easier to scan for that malware and detect it

0:09:50.559 --> 0:09:55.240
<v Speaker 1>before it does too much damage. Um, the more different

0:09:56.040 --> 0:09:59.760
<v Speaker 1>a version is from its origin point, the more likely

0:10:00.000 --> 0:10:03.520
<v Speaker 1>it is going to escape immediate detection. This is one

0:10:03.520 --> 0:10:06.560
<v Speaker 1>of the reasons why anti virus software, which we will

0:10:06.559 --> 0:10:09.880
<v Speaker 1>talk about towards the end of this episode, is really

0:10:10.000 --> 0:10:13.840
<v Speaker 1>important because we get new variations on old malware all

0:10:13.880 --> 0:10:16.080
<v Speaker 1>the time, and if it's if it's a dramatic enough

0:10:16.080 --> 0:10:19.720
<v Speaker 1>departure from the original piece of malware, your anti virus

0:10:19.760 --> 0:10:23.160
<v Speaker 1>program may not pick up on it. So these things

0:10:23.160 --> 0:10:30.440
<v Speaker 1>have to be you know, investigated and then updated frequently. Okay,

0:10:30.520 --> 0:10:33.520
<v Speaker 1>I think we have laid all the groundwork we need

0:10:33.559 --> 0:10:36.240
<v Speaker 1>to lay. When we come back, we're gonna start with

0:10:36.480 --> 0:10:41.080
<v Speaker 1>the various types of malware and we'll we'll get it

0:10:41.200 --> 0:10:45.960
<v Speaker 1>going with a good old computer virus. But first let's

0:10:45.960 --> 0:10:57.720
<v Speaker 1>take this quick break, all right. As I said, we're

0:10:57.720 --> 0:11:00.640
<v Speaker 1>going to start with the computer virus. So the heck

0:11:00.880 --> 0:11:04.439
<v Speaker 1>is a virus within the context of malware. So a

0:11:04.559 --> 0:11:08.880
<v Speaker 1>virus is a piece of malicious software that gloams onto

0:11:08.960 --> 0:11:12.720
<v Speaker 1>a file that supports some form of macros like you know,

0:11:12.800 --> 0:11:17.000
<v Speaker 1>most document files do this, and so this this malicious

0:11:17.040 --> 0:11:21.200
<v Speaker 1>code is piggybacking on top of a file and it

0:11:21.240 --> 0:11:24.360
<v Speaker 1>is like a virus inside of a host. The host

0:11:24.400 --> 0:11:27.400
<v Speaker 1>in this case is the file that contains the malicious code,

0:11:27.720 --> 0:11:31.160
<v Speaker 1>and when someone opens up that file that has the

0:11:31.240 --> 0:11:35.720
<v Speaker 1>virus attached, it can activate the virus. So the file

0:11:35.880 --> 0:11:40.040
<v Speaker 1>that you're opening appears to be legit or safe, but

0:11:40.160 --> 0:11:44.320
<v Speaker 1>the malicious code that's within the the file then gets

0:11:44.360 --> 0:11:47.120
<v Speaker 1>to run rampant on your machine. Now, the goal of

0:11:47.120 --> 0:11:51.160
<v Speaker 1>your typical virus is to disrupt a computer system in

0:11:51.240 --> 0:11:54.160
<v Speaker 1>some way. Now may do this by placing a very

0:11:54.280 --> 0:11:58.200
<v Speaker 1>large demands on computer memory. So now your computer can't

0:11:58.200 --> 0:12:01.559
<v Speaker 1>really run anything properly because it's memory is completely taken

0:12:01.600 --> 0:12:05.280
<v Speaker 1>up by dealing with this virus. Or it might replicate

0:12:05.320 --> 0:12:09.880
<v Speaker 1>itself and or otherwise replicate nonsense information and fill up

0:12:10.200 --> 0:12:14.120
<v Speaker 1>your computer storage with garbage data. And it may even

0:12:14.160 --> 0:12:17.200
<v Speaker 1>overwrite files so that you can no longer access key

0:12:17.280 --> 0:12:19.760
<v Speaker 1>data or programs. That kind of thing. By the way,

0:12:19.800 --> 0:12:24.560
<v Speaker 1>overwriting files, that's like scorched Earth policy, because if you

0:12:24.640 --> 0:12:28.240
<v Speaker 1>delete a file, it doesn't actually leave your machine. The

0:12:28.400 --> 0:12:33.000
<v Speaker 1>deleted file is essentially marked by your computer as this

0:12:33.160 --> 0:12:36.360
<v Speaker 1>area of storage is now available, so we can write

0:12:36.400 --> 0:12:39.160
<v Speaker 1>over it if we want to. But if you haven't

0:12:39.240 --> 0:12:44.560
<v Speaker 1>overwritten anything. You can still retrieve deleted files. Overwriting files

0:12:44.880 --> 0:12:50.959
<v Speaker 1>makes retrieval way more difficult. There are entire forensics companies

0:12:50.960 --> 0:12:55.600
<v Speaker 1>out there that will take great strides to try and

0:12:55.600 --> 0:12:59.959
<v Speaker 1>retrieve information from overwritten files, but it's very hard to do. Uh.

0:13:00.520 --> 0:13:03.200
<v Speaker 1>A common feature of computer viruses is that they do

0:13:03.360 --> 0:13:08.960
<v Speaker 1>self replicate. That is a pretty standard uh component of

0:13:08.960 --> 0:13:12.400
<v Speaker 1>of computer viruses, and again they typically do that to

0:13:12.480 --> 0:13:16.040
<v Speaker 1>kind of gum up with a computer with copies of itself. Okay,

0:13:16.080 --> 0:13:21.040
<v Speaker 1>next up, let's talk about trojan's sometimes also called trojan viruses.

0:13:21.120 --> 0:13:25.280
<v Speaker 1>They do share some similarities with your bog standard viruses

0:13:25.280 --> 0:13:29.440
<v Speaker 1>that we just talked about. A trojan is malware disguised

0:13:29.480 --> 0:13:34.400
<v Speaker 1>as a legitimate file or program. So maybe you are

0:13:34.480 --> 0:13:38.840
<v Speaker 1>prompted to download a video player because you're trying to

0:13:39.000 --> 0:13:43.319
<v Speaker 1>play some sort of online content online media, but you're

0:13:43.360 --> 0:13:46.520
<v Speaker 1>getting a message saying, hey, you need to download this

0:13:46.600 --> 0:13:50.120
<v Speaker 1>media player if you want to watch this. Well, in

0:13:50.320 --> 0:13:52.640
<v Speaker 1>some cases, not in all of them. Sometimes this is

0:13:52.640 --> 0:13:56.079
<v Speaker 1>a legitimate message, but frequently this is a tactic that

0:13:56.400 --> 0:13:59.680
<v Speaker 1>criminals use to convince you to download a file that's

0:13:59.720 --> 0:14:04.080
<v Speaker 1>acte a trojan that's housing malicious software. Back in the

0:14:04.080 --> 0:14:08.199
<v Speaker 1>heyday of media piracy, there were lots of trojans disguised

0:14:08.240 --> 0:14:13.559
<v Speaker 1>as useful programs, so everything from pirated video games, to

0:14:14.200 --> 0:14:19.000
<v Speaker 1>productivity software suites, to even anti virus packages. Clever go

0:14:19.680 --> 0:14:21.280
<v Speaker 1>you would go and say, Hey, I don't want to

0:14:21.320 --> 0:14:24.280
<v Speaker 1>pay for this expensive piece of software, I'm gonna find

0:14:24.280 --> 0:14:28.680
<v Speaker 1>it online for free. There was a chance that the

0:14:28.840 --> 0:14:32.440
<v Speaker 1>free version you found was actually a trojan that was

0:14:32.800 --> 0:14:36.960
<v Speaker 1>housing malicious software. Now, typically once a person downloads the

0:14:37.000 --> 0:14:40.360
<v Speaker 1>trojan and then activates it, the trojan jumps in to

0:14:40.480 --> 0:14:46.080
<v Speaker 1>get access to sensitive data on the computer or computer device.

0:14:46.760 --> 0:14:50.000
<v Speaker 1>It might have some code that sends that data back

0:14:50.040 --> 0:14:52.720
<v Speaker 1>to the jerks who distributed the malware in the first place.

0:14:52.760 --> 0:14:55.160
<v Speaker 1>That kind of falls into another category we'll talk about

0:14:55.160 --> 0:14:59.840
<v Speaker 1>a bit later. So in those cases, the militia software

0:14:59.880 --> 0:15:04.920
<v Speaker 1>is collecting information that someone else should absolutely not have

0:15:05.000 --> 0:15:08.400
<v Speaker 1>access to. Could be your personal information, could be stuff

0:15:08.440 --> 0:15:11.840
<v Speaker 1>like your bank account, could be your medical records, could

0:15:11.840 --> 0:15:14.440
<v Speaker 1>be any combination of these, could be everything on your computer.

0:15:14.520 --> 0:15:19.240
<v Speaker 1>Really Now, something else that a trojan virus might have

0:15:19.640 --> 0:15:23.400
<v Speaker 1>within it is what's called a root kit attack. So

0:15:23.600 --> 0:15:27.600
<v Speaker 1>root kit it's attacking the root of your operating system

0:15:27.720 --> 0:15:30.920
<v Speaker 1>and the purpose of this is to give a cyber

0:15:31.000 --> 0:15:34.680
<v Speaker 1>criminal access to your machine, almost as if the cyber

0:15:34.680 --> 0:15:38.320
<v Speaker 1>criminal was sitting down at your keyboard directly. And when

0:15:38.320 --> 0:15:42.720
<v Speaker 1>a criminal gets administrative access to a computer, that's super

0:15:42.800 --> 0:15:45.240
<v Speaker 1>bad news. It can also lead to the criminal not

0:15:45.280 --> 0:15:49.760
<v Speaker 1>only just compromising one machine, but potentially launching attacks on

0:15:50.200 --> 0:15:54.840
<v Speaker 1>connected systems, so networked devices that that machine can is

0:15:54.880 --> 0:15:57.640
<v Speaker 1>connected to that could be the next vector of attack.

0:15:58.200 --> 0:16:02.920
<v Speaker 1>Trojan malware is often the delivery system for other specific

0:16:02.920 --> 0:16:07.240
<v Speaker 1>subcategories of malware, such as ransomware. So let's go ahead

0:16:07.280 --> 0:16:10.040
<v Speaker 1>and do that one now because it is so closely connected.

0:16:10.040 --> 0:16:12.840
<v Speaker 1>So this is category number three. We've had virus, we

0:16:12.880 --> 0:16:16.280
<v Speaker 1>have trojan virus. Now we have ransomware. And it's been

0:16:16.320 --> 0:16:18.880
<v Speaker 1>in the news a lot over the last couple of years.

0:16:18.920 --> 0:16:22.720
<v Speaker 1>There's been some high profile ransomware attacks over the last

0:16:22.760 --> 0:16:26.360
<v Speaker 1>few years. And it's similar in many ways to viruses,

0:16:26.400 --> 0:16:28.640
<v Speaker 1>and that the goal is to cut off access to

0:16:28.840 --> 0:16:34.240
<v Speaker 1>important programs, files, folders, entire directories, that kind of thing.

0:16:34.760 --> 0:16:37.320
<v Speaker 1>But the way it goes about this is slightly different

0:16:37.360 --> 0:16:40.960
<v Speaker 1>from viruses. So once ransomware has been injected into a

0:16:41.000 --> 0:16:44.840
<v Speaker 1>computer system, it will run an encryption program and it

0:16:44.920 --> 0:16:49.720
<v Speaker 1>will encrypt data on part or all of the computer system.

0:16:50.000 --> 0:16:52.800
<v Speaker 1>Often it will encrypt data on any part of the

0:16:52.800 --> 0:16:56.080
<v Speaker 1>computer system it can get access to, so the computer's

0:16:56.160 --> 0:17:00.360
<v Speaker 1>user will be unable to access those encrypted files because

0:17:00.560 --> 0:17:02.600
<v Speaker 1>to the computer all that data will just appear to

0:17:02.640 --> 0:17:06.480
<v Speaker 1>be gibberish. It won't look like useful files or programs,

0:17:06.480 --> 0:17:10.240
<v Speaker 1>it will just look like random data. And the companying

0:17:10.320 --> 0:17:14.200
<v Speaker 1>message will alert the user that some criminal has locked

0:17:14.200 --> 0:17:18.040
<v Speaker 1>away important stuff on this computer and that only by

0:17:18.080 --> 0:17:22.120
<v Speaker 1>paying a ransom, typically in some form of cryptocurrency, will

0:17:22.160 --> 0:17:25.639
<v Speaker 1>the user regain access to their programs and files. This

0:17:25.720 --> 0:17:28.400
<v Speaker 1>can also end up being a type of blackmail as

0:17:28.400 --> 0:17:32.159
<v Speaker 1>well for personal stuff. Like let's say that you have

0:17:32.400 --> 0:17:35.240
<v Speaker 1>your computer. You're not necessarily part of some big company,

0:17:35.280 --> 0:17:39.080
<v Speaker 1>but you get by ransomware, and the people who have

0:17:39.600 --> 0:17:41.960
<v Speaker 1>locked away your data are saying, hey, if you don't

0:17:42.000 --> 0:17:46.120
<v Speaker 1>want sensitive stuff on here leaked to the public, you've

0:17:46.119 --> 0:17:48.439
<v Speaker 1>gotta pay me. So that this can also come in

0:17:48.480 --> 0:17:52.399
<v Speaker 1>the form of blackmail. Well, what they're saying is if

0:17:52.400 --> 0:17:55.160
<v Speaker 1>you pay us, then we will give you the key

0:17:55.200 --> 0:17:59.320
<v Speaker 1>that will allow you to access your programs and files. Again. Uh,

0:17:59.400 --> 0:18:03.160
<v Speaker 1>so the criminal can grant access by sharing this mathematical key,

0:18:03.240 --> 0:18:06.440
<v Speaker 1>and that does allow for decryption, you can reverse the

0:18:06.560 --> 0:18:11.720
<v Speaker 1>encryption process and regain your files and programs and turn

0:18:11.760 --> 0:18:14.840
<v Speaker 1>it back into useful stuff. So the criminal is essentially

0:18:14.840 --> 0:18:18.679
<v Speaker 1>holding a user's programs and files or directories or whatever

0:18:18.800 --> 0:18:22.560
<v Speaker 1>hostage until they get paid a ransom. Now I've said

0:18:22.600 --> 0:18:25.440
<v Speaker 1>this many times on tech news episodes, but it bears repeating.

0:18:25.840 --> 0:18:28.880
<v Speaker 1>It is pretty much always a bad idea to pay

0:18:29.240 --> 0:18:33.280
<v Speaker 1>the ransom. It can be very hard to resist the

0:18:33.520 --> 0:18:37.280
<v Speaker 1>urge to pay to get to regain control of your systems,

0:18:37.520 --> 0:18:41.600
<v Speaker 1>but it's bad to do because paying reinforces that method

0:18:41.640 --> 0:18:46.120
<v Speaker 1>of attack. If criminals see that ransomware can make them money,

0:18:46.200 --> 0:18:49.600
<v Speaker 1>even if it only works one time out of five

0:18:49.640 --> 0:18:52.520
<v Speaker 1>times or anything like that, well that could be enough

0:18:52.560 --> 0:18:55.400
<v Speaker 1>to keep these attacks going. It's it's proven to work,

0:18:55.480 --> 0:18:58.119
<v Speaker 1>so they're going to keep doing it. So paying ransoms

0:18:58.160 --> 0:19:00.760
<v Speaker 1>really just ensures that more attack X will follow in

0:19:00.800 --> 0:19:07.080
<v Speaker 1>the future, maybe not directly against you, but definitely against others. Also,

0:19:07.160 --> 0:19:08.520
<v Speaker 1>another thing you need to keep in mind is the

0:19:08.600 --> 0:19:11.280
<v Speaker 1>victim can never be really sure that the criminal is

0:19:11.320 --> 0:19:14.800
<v Speaker 1>actually going to hand over the key needed to decrypt

0:19:14.800 --> 0:19:17.359
<v Speaker 1>the data. They could just take the money and run

0:19:17.800 --> 0:19:21.119
<v Speaker 1>and leave you with an encrypted system and then you

0:19:21.160 --> 0:19:24.240
<v Speaker 1>don't really have any options. You can try and decrypt it,

0:19:24.359 --> 0:19:29.280
<v Speaker 1>but like decryption programs can take a lot of computational

0:19:29.359 --> 0:19:31.879
<v Speaker 1>processing and a ton of time. This is one of

0:19:31.920 --> 0:19:36.640
<v Speaker 1>the things that quantum computers will completely transform in the future,

0:19:36.680 --> 0:19:40.719
<v Speaker 1>but we're not there yet. Well, criminals could do that.

0:19:40.840 --> 0:19:43.320
<v Speaker 1>It is risky for a criminal to just take the

0:19:43.359 --> 0:19:45.639
<v Speaker 1>money and run because if folks figure out who carried

0:19:45.680 --> 0:19:48.960
<v Speaker 1>out the attack, even if it's just like in general terms,

0:19:49.000 --> 0:19:52.160
<v Speaker 1>like you kind of know what hacker network was likely

0:19:52.240 --> 0:19:55.119
<v Speaker 1>responsible for the attack, well, that sends a message to

0:19:55.160 --> 0:19:58.320
<v Speaker 1>future victims that even if they pay the ransom, they'll

0:19:58.320 --> 0:20:00.479
<v Speaker 1>still get stuck. So there's no point in hang. So

0:20:01.480 --> 0:20:04.480
<v Speaker 1>criminals are not likely to hold back on it, but

0:20:04.560 --> 0:20:07.919
<v Speaker 1>it is a possibility still. It's always a bad idea

0:20:08.119 --> 0:20:11.600
<v Speaker 1>to really pay the ransom, but it can be difficult

0:20:11.600 --> 0:20:15.600
<v Speaker 1>to hold off. Criminals like to target companies and organizations

0:20:15.640 --> 0:20:20.320
<v Speaker 1>that have critical sensitive data on them, which obviously ups

0:20:20.359 --> 0:20:24.240
<v Speaker 1>the stakes considerably. So hospitals and other healthcare facilities are

0:20:24.280 --> 0:20:29.000
<v Speaker 1>frequent targets because there are literal life and death situations

0:20:29.000 --> 0:20:32.679
<v Speaker 1>connected to that data. It is not easy to deny

0:20:32.720 --> 0:20:36.600
<v Speaker 1>a ransom. When you think that people's lives literally hold

0:20:36.800 --> 0:20:41.320
<v Speaker 1>in the balance, that's a difficult thing to do. Um

0:20:41.359 --> 0:20:43.160
<v Speaker 1>The same can be said of a lot of government

0:20:43.160 --> 0:20:47.159
<v Speaker 1>agencies that have really sensitive information that they need access to.

0:20:47.720 --> 0:20:52.280
<v Speaker 1>It is difficult to resist paying that ransom. There are

0:20:52.280 --> 0:20:54.560
<v Speaker 1>a lot of potential ways that ransomware can find its

0:20:54.560 --> 0:20:58.360
<v Speaker 1>way onto a system, from targeted attacks to more kind

0:20:58.359 --> 0:21:02.399
<v Speaker 1>of broad approaches, like a phishing scam can be a

0:21:02.480 --> 0:21:06.080
<v Speaker 1>very broadway to get ransomware onto machines. If you don't

0:21:06.080 --> 0:21:09.200
<v Speaker 1>know what fishing is, then you are a sweet summer child,

0:21:09.480 --> 0:21:11.680
<v Speaker 1>and I really hate to chip away at your innocence.

0:21:11.760 --> 0:21:15.480
<v Speaker 1>But a phishing attack is when criminals create what seems

0:21:15.520 --> 0:21:20.280
<v Speaker 1>to be a legitimate message, or legitimate website or email,

0:21:20.480 --> 0:21:23.280
<v Speaker 1>that kind of thing, but it actually directs people to

0:21:23.359 --> 0:21:26.840
<v Speaker 1>either voluntarily give up information that they should not give up,

0:21:27.280 --> 0:21:31.119
<v Speaker 1>such as like a bank account number and log in information,

0:21:32.080 --> 0:21:35.160
<v Speaker 1>or it will direct people to a link that will

0:21:35.760 --> 0:21:40.040
<v Speaker 1>have them download the malware. Okay, we've got a couple

0:21:40.119 --> 0:21:42.639
<v Speaker 1>more types to talk about, but before we get to that,

0:21:42.720 --> 0:21:54.840
<v Speaker 1>let's take another quick break. Okay, next up, we're gonna

0:21:54.880 --> 0:21:58.040
<v Speaker 1>talk about worms so not the squiggly little guys who

0:21:58.080 --> 0:22:00.600
<v Speaker 1>live in apples and that kind of thing. We're talking

0:22:00.640 --> 0:22:04.040
<v Speaker 1>computer worms. And a computer worm is malware designed to

0:22:04.119 --> 0:22:07.640
<v Speaker 1>replicate itself very quickly and then to spread across numerous

0:22:07.680 --> 0:22:10.440
<v Speaker 1>connected devices on a network. So it's only job really

0:22:11.040 --> 0:22:14.440
<v Speaker 1>is to replicate and infect, and to do that as

0:22:15.000 --> 0:22:17.840
<v Speaker 1>as widely and quickly as possible. So if one machine

0:22:17.840 --> 0:22:20.800
<v Speaker 1>on a network gets hit, others on that same network

0:22:20.800 --> 0:22:24.399
<v Speaker 1>are in immediate danger. But how does the initial attack happen?

0:22:24.480 --> 0:22:27.560
<v Speaker 1>How does the worm get on you know, patient zero

0:22:27.760 --> 0:22:30.760
<v Speaker 1>in the computer network. Well, unlike a virus, a worm

0:22:30.840 --> 0:22:34.400
<v Speaker 1>doesn't rely on a host file in order to execute

0:22:34.400 --> 0:22:37.119
<v Speaker 1>its attack, So this isn't a case where a file

0:22:37.280 --> 0:22:39.639
<v Speaker 1>like a PDF or something happens to be carrying a

0:22:39.680 --> 0:22:44.000
<v Speaker 1>worm as well. The worm can infect through a direct download,

0:22:44.560 --> 0:22:46.840
<v Speaker 1>or it can be injected through some other means, such

0:22:46.880 --> 0:22:49.480
<v Speaker 1>as on a USB drive. By the way, just in

0:22:49.520 --> 0:22:53.760
<v Speaker 1>case you haven't heard this for a while, never connect

0:22:54.160 --> 0:22:58.280
<v Speaker 1>some found USB drive to your computer. You never know

0:22:58.760 --> 0:23:02.240
<v Speaker 1>if the drive on that USB drive has some executable

0:23:02.240 --> 0:23:07.280
<v Speaker 1>code on it that's just waiting to infect a network. Anyway,

0:23:07.520 --> 0:23:10.919
<v Speaker 1>once the worm is on an infected system, it copies

0:23:10.960 --> 0:23:13.920
<v Speaker 1>itself and sends those copies to other machines on the network,

0:23:14.200 --> 0:23:17.600
<v Speaker 1>all with the goal of disrupting operations and or destroying

0:23:17.680 --> 0:23:22.280
<v Speaker 1>data in the process. So those are also bad news.

0:23:23.440 --> 0:23:26.199
<v Speaker 1>The next two types of malware are very similar, so

0:23:26.240 --> 0:23:29.919
<v Speaker 1>we're just gonna put them together. We're talking spyware and

0:23:30.080 --> 0:23:34.000
<v Speaker 1>add ware. So spyware, as the name suggests, is this

0:23:34.080 --> 0:23:36.800
<v Speaker 1>malicious software that runs in the background on a machine,

0:23:37.200 --> 0:23:40.879
<v Speaker 1>real secret like, and then it sends information back to

0:23:40.920 --> 0:23:43.720
<v Speaker 1>a remote user. You heard me talk about this kind

0:23:43.720 --> 0:23:47.800
<v Speaker 1>of with the trojan viruses. Spyware can be delivered via

0:23:47.880 --> 0:23:53.879
<v Speaker 1>trojan and the whole purpose is to send sensitive information

0:23:53.960 --> 0:23:57.800
<v Speaker 1>back to the criminal. So spyware can also include specific

0:23:57.840 --> 0:24:01.080
<v Speaker 1>stuff like key loggers. These are programs that, as the

0:24:01.119 --> 0:24:05.640
<v Speaker 1>name suggests, record or log every single key stroke made

0:24:05.720 --> 0:24:09.320
<v Speaker 1>on a computer, so the criminal back home can use

0:24:09.320 --> 0:24:12.120
<v Speaker 1>that information to figure out stuff like log in credentials,

0:24:12.760 --> 0:24:17.200
<v Speaker 1>you know, banking information, all sorts of stuff. Well made

0:24:17.240 --> 0:24:20.719
<v Speaker 1>spyware will not alert the target that something is wrong.

0:24:21.960 --> 0:24:26.200
<v Speaker 1>It doesn't necessarily impact computer performance that much, at least

0:24:26.240 --> 0:24:29.040
<v Speaker 1>not to a noticeable degree. So the goal is to

0:24:29.080 --> 0:24:32.520
<v Speaker 1>stay under the radar for as long as possible to

0:24:32.600 --> 0:24:35.120
<v Speaker 1>get as much information as possible. This, by the way,

0:24:35.200 --> 0:24:38.000
<v Speaker 1>is why I say that James Bond is a terrible,

0:24:38.119 --> 0:24:41.200
<v Speaker 1>terrible spy. I mean the guy goes around and introduces

0:24:41.240 --> 0:24:45.200
<v Speaker 1>himself everywhere he goes. He violates like rule number one

0:24:45.280 --> 0:24:49.600
<v Speaker 1>of spy ishness, so that spyware. But then what is

0:24:49.640 --> 0:24:54.080
<v Speaker 1>adwere well, similar to spyware, adware monitors your computer use,

0:24:54.160 --> 0:24:58.120
<v Speaker 1>but instead of using the information to steal your personal

0:24:58.280 --> 0:25:02.480
<v Speaker 1>details or gain access to your accounts, adware is spying

0:25:02.520 --> 0:25:07.359
<v Speaker 1>on you in order to serve up more applicable ads

0:25:07.480 --> 0:25:11.800
<v Speaker 1>to you. This can include stuff like even hijacking your

0:25:11.800 --> 0:25:15.240
<v Speaker 1>web browser so that when you open up your web browser,

0:25:15.280 --> 0:25:18.840
<v Speaker 1>your homepage is no longer whatever it was before, but

0:25:18.920 --> 0:25:22.000
<v Speaker 1>now it goes to some other site that's connected to

0:25:22.040 --> 0:25:26.040
<v Speaker 1>the adware creators or their distributors. This can also lead

0:25:26.119 --> 0:25:29.760
<v Speaker 1>down pathways to other types of malware, so adware, while

0:25:29.880 --> 0:25:33.399
<v Speaker 1>it is not necessarily malicious on its own, can lead

0:25:33.920 --> 0:25:38.600
<v Speaker 1>you to downloading stuff that is malicious. Um and as

0:25:38.680 --> 0:25:42.440
<v Speaker 1>much nastier machines can also get bogged down with adware.

0:25:42.800 --> 0:25:46.080
<v Speaker 1>So even if it's not outright malicious, if a lot

0:25:46.119 --> 0:25:49.000
<v Speaker 1>of different adware gets on your computer, it can start

0:25:49.040 --> 0:25:54.359
<v Speaker 1>to affect your computer's performance over time. So because it

0:25:54.440 --> 0:25:58.680
<v Speaker 1>has been used for malicious purposes, because it's often part

0:25:58.680 --> 0:26:03.560
<v Speaker 1>of the the entire strategy of attack that that criminals

0:26:03.560 --> 0:26:08.560
<v Speaker 1>are using, it gets lumped in as a version of malware,

0:26:08.960 --> 0:26:14.680
<v Speaker 1>so it's it's not necessarily malicious, but it's used frequently

0:26:14.760 --> 0:26:18.400
<v Speaker 1>enough to be included on lists of malware. And finally,

0:26:18.440 --> 0:26:22.600
<v Speaker 1>the last version we have is called fileless malware. Now,

0:26:22.600 --> 0:26:25.520
<v Speaker 1>as that name alright says, this malware is not attached

0:26:25.640 --> 0:26:28.840
<v Speaker 1>to some sort of file that you download off the internet. Instead,

0:26:29.640 --> 0:26:33.960
<v Speaker 1>this malicious code lives in computer memory, so as long

0:26:34.000 --> 0:26:37.000
<v Speaker 1>as the computer is on, the code can do whatever

0:26:37.000 --> 0:26:40.240
<v Speaker 1>it was designed to do. You know, malware does different

0:26:40.280 --> 0:26:44.600
<v Speaker 1>things depending upon the attackers goals, but it just lives

0:26:44.600 --> 0:26:47.480
<v Speaker 1>in your computer memory, which means that if you reboot

0:26:47.520 --> 0:26:52.840
<v Speaker 1>your computer, while rebooting clears computer memory. Right. Memory is volatile,

0:26:53.240 --> 0:26:56.280
<v Speaker 1>meaning that when you turn off your machine and then

0:26:56.320 --> 0:27:00.159
<v Speaker 1>turning back on, well, the memory has been wiped. It

0:27:00.240 --> 0:27:02.400
<v Speaker 1>was it was white clean as soon as you turned

0:27:02.440 --> 0:27:03.720
<v Speaker 1>it off, and when you turn it back on, you've

0:27:03.720 --> 0:27:07.000
<v Speaker 1>got a blank slate. That's good in the sense that

0:27:07.040 --> 0:27:10.879
<v Speaker 1>you could then eliminate the malware that was living in

0:27:10.920 --> 0:27:13.639
<v Speaker 1>your computer memory, but it also erases all trace of

0:27:13.720 --> 0:27:18.000
<v Speaker 1>the fileless malware, so it makes investigating and computer forensics

0:27:18.520 --> 0:27:23.600
<v Speaker 1>really challenging. There are ways, by the way, that cybercriminals

0:27:23.600 --> 0:27:29.520
<v Speaker 1>create to create persistent fileless malware, where then involves infecting

0:27:29.640 --> 0:27:33.359
<v Speaker 1>some element of your computers operating system so that every

0:27:33.400 --> 0:27:37.040
<v Speaker 1>time it boots up, it injects this malware back into

0:27:37.080 --> 0:27:40.480
<v Speaker 1>computer memory. So there are those versions as well. Those

0:27:40.520 --> 0:27:43.760
<v Speaker 1>obviously are easier to investigate because if you find that

0:27:43.760 --> 0:27:48.720
<v Speaker 1>that root code in the operating system, you know what's happening.

0:27:49.280 --> 0:27:52.520
<v Speaker 1>But how do you inject malicious code into computer memory

0:27:52.560 --> 0:27:54.960
<v Speaker 1>to start with? There are actually a lot of potential

0:27:54.960 --> 0:27:59.640
<v Speaker 1>delivery systems, including piggybacking onto other types of malware, so

0:28:00.600 --> 0:28:03.600
<v Speaker 1>that that's one possibility, But another one is to leverage

0:28:03.640 --> 0:28:08.399
<v Speaker 1>vulnerabilities in known legitimate pieces of software. These kind of

0:28:08.440 --> 0:28:12.879
<v Speaker 1>exploits allow criminals to lean on trusted code to deliver

0:28:13.040 --> 0:28:16.360
<v Speaker 1>malicious payloads, and we've seen an increase in that kind

0:28:16.400 --> 0:28:19.119
<v Speaker 1>of activity over the last couple of years. It's really insidious,

0:28:19.200 --> 0:28:23.320
<v Speaker 1>right because you trust the software. It's software from a

0:28:23.400 --> 0:28:27.720
<v Speaker 1>legitimate source. It is not designed to be malware. It's

0:28:27.800 --> 0:28:31.159
<v Speaker 1>maybe it's productivity software, maybe it's you know something, It

0:28:31.200 --> 0:28:34.720
<v Speaker 1>could even be something that your your organization has installed

0:28:34.840 --> 0:28:38.720
<v Speaker 1>onto your work computer. Right, you might not have had

0:28:38.800 --> 0:28:42.360
<v Speaker 1>any hand in that. But if there's a vulnerability in

0:28:42.400 --> 0:28:46.760
<v Speaker 1>there that has not yet been patched out, and a

0:28:46.800 --> 0:28:49.960
<v Speaker 1>criminal figures out how to exploit that to deliver payloads,

0:28:50.560 --> 0:28:53.120
<v Speaker 1>that can be the vector where you get things like

0:28:53.240 --> 0:28:57.600
<v Speaker 1>fouleless malware injected into machines. There's really nothing you can

0:28:57.640 --> 0:29:01.680
<v Speaker 1>do about it because the the solution is further up

0:29:01.720 --> 0:29:06.640
<v Speaker 1>the chain. It's over with the the designers of that

0:29:06.640 --> 0:29:09.880
<v Speaker 1>that software that's been exploited, and you need to get

0:29:09.920 --> 0:29:13.640
<v Speaker 1>an update patched out to fix that problem, and that's

0:29:13.640 --> 0:29:17.320
<v Speaker 1>not up to you most cases. So that's really the

0:29:17.320 --> 0:29:20.080
<v Speaker 1>breakdown of the different types of malware. As I mentioned,

0:29:20.600 --> 0:29:23.920
<v Speaker 1>the delivery systems for these attacks are varied. You can

0:29:23.960 --> 0:29:27.800
<v Speaker 1>get these types of malware in various ways. There's no

0:29:28.000 --> 0:29:32.040
<v Speaker 1>single vector that's used by each and they can also

0:29:32.080 --> 0:29:34.120
<v Speaker 1>be used in combination with one another. So how do

0:29:34.160 --> 0:29:37.720
<v Speaker 1>you protect yourself against all these kinds of malware? Well,

0:29:37.760 --> 0:29:41.000
<v Speaker 1>one thing to do is to practice good computer security etiquette,

0:29:41.440 --> 0:29:44.600
<v Speaker 1>which includes careful web browsing. That means, you know, you

0:29:44.640 --> 0:29:47.360
<v Speaker 1>make certain that the sites that you're visiting are legitimate

0:29:47.880 --> 0:29:50.080
<v Speaker 1>and you're not just clicking on random links that have

0:29:50.120 --> 0:29:53.000
<v Speaker 1>been sent to you from like strange email addresses or

0:29:53.080 --> 0:29:56.640
<v Speaker 1>messaging services or something like that, or even text messages.

0:29:56.680 --> 0:29:59.800
<v Speaker 1>I get a lot of uh spam text messages now

0:29:59.840 --> 0:30:03.800
<v Speaker 1>that are clearly attempting to get me to visit some

0:30:04.240 --> 0:30:07.800
<v Speaker 1>link and are a phishing scam. Uh. Same with email.

0:30:08.200 --> 0:30:12.280
<v Speaker 1>Gmail in particular, A lot of phishing attacks have been

0:30:12.360 --> 0:30:16.760
<v Speaker 1>coming to my Gmail address, and Gmail usually was pretty

0:30:16.760 --> 0:30:20.440
<v Speaker 1>good at weeding those things out, but every now and

0:30:20.480 --> 0:30:24.479
<v Speaker 1>then I get a new kind of slate of of

0:30:24.720 --> 0:30:30.240
<v Speaker 1>clearly clearly they're phishing attacks. They're not well made because

0:30:30.480 --> 0:30:34.479
<v Speaker 1>if you even just look at the scent field, like

0:30:34.600 --> 0:30:37.400
<v Speaker 1>who these emails are going to, you'll see like, oh,

0:30:37.480 --> 0:30:40.560
<v Speaker 1>they're literally just doing a dictionary attack of email addresses,

0:30:40.600 --> 0:30:43.640
<v Speaker 1>and mine just happens to be in that list. So

0:30:43.720 --> 0:30:46.960
<v Speaker 1>this is not some sort of personalized message, but it

0:30:47.080 --> 0:30:51.040
<v Speaker 1>is a way of trying to cast a very wide

0:30:51.080 --> 0:30:53.760
<v Speaker 1>net and at least get a few bites where I

0:30:53.760 --> 0:30:57.200
<v Speaker 1>guess that's mixing metaphors. But if you catches in that

0:30:57.360 --> 0:31:01.320
<v Speaker 1>in that effort um. But that's not the only thing

0:31:01.360 --> 0:31:03.280
<v Speaker 1>you need to think about when it comes to good

0:31:03.280 --> 0:31:07.640
<v Speaker 1>computer security etiquette. Another is being super careful about who

0:31:07.680 --> 0:31:11.120
<v Speaker 1>you allow to access your physical computer, because a lot

0:31:11.160 --> 0:31:14.719
<v Speaker 1>of the quote unquote hacking attacks that we hear about

0:31:15.160 --> 0:31:18.680
<v Speaker 1>are not actually the result of some hoodie wearing hacker

0:31:18.800 --> 0:31:21.720
<v Speaker 1>wearing fingerless gloves and tapping away on a keyboard in

0:31:21.760 --> 0:31:25.120
<v Speaker 1>a dark room somewhere, their face only lit by the

0:31:25.160 --> 0:31:29.040
<v Speaker 1>screen across from them. Instead, a lot of the hacking

0:31:29.040 --> 0:31:31.640
<v Speaker 1>attacks are carried out by people who just get physical

0:31:31.680 --> 0:31:35.080
<v Speaker 1>access to machines. Typically they do this by posing as

0:31:35.120 --> 0:31:38.840
<v Speaker 1>someone like an I T professional who comes around and says, Oh,

0:31:38.880 --> 0:31:41.840
<v Speaker 1>I need to update your computer with this new security

0:31:41.840 --> 0:31:46.040
<v Speaker 1>package or new software update, something like that. That's a

0:31:46.160 --> 0:31:49.600
<v Speaker 1>very common way to get access to a machine. So

0:31:49.640 --> 0:31:54.480
<v Speaker 1>it's always vitally important to verify that someone who's claiming

0:31:54.960 --> 0:31:57.600
<v Speaker 1>to be updating your machine is actually who they say

0:31:57.600 --> 0:32:00.360
<v Speaker 1>they are, that they are authorized to do this before

0:32:00.360 --> 0:32:04.160
<v Speaker 1>you allow it to happen, because countless attacks start through

0:32:04.480 --> 0:32:08.480
<v Speaker 1>this very kind of social engineering, rather than you know,

0:32:08.600 --> 0:32:10.920
<v Speaker 1>trying three times to guess the password and getting it

0:32:11.000 --> 0:32:14.480
<v Speaker 1>right on the third time. Anti virus software is also

0:32:14.480 --> 0:32:18.320
<v Speaker 1>an important piece um. This kind of software can affect

0:32:18.360 --> 0:32:22.360
<v Speaker 1>computer performance during scans in particular, and I know that

0:32:22.400 --> 0:32:26.080
<v Speaker 1>gets frustrating, but it's still a good idea to have it. Essentially,

0:32:26.120 --> 0:32:30.360
<v Speaker 1>anti virus software typically refers to a library of known

0:32:30.520 --> 0:32:35.280
<v Speaker 1>malicious code. So there's this growing database of all the

0:32:35.360 --> 0:32:37.600
<v Speaker 1>kinds of malware that have been found out in the

0:32:37.680 --> 0:32:42.760
<v Speaker 1>wild and identified by various security experts. So that library

0:32:43.080 --> 0:32:46.560
<v Speaker 1>is updated frequently. No matter which anti virus software you're

0:32:46.840 --> 0:32:50.320
<v Speaker 1>you're subscribed to or using, they are relying on a

0:32:50.360 --> 0:32:53.600
<v Speaker 1>library like this. Some of them are updated more frequently

0:32:53.680 --> 0:32:56.080
<v Speaker 1>than others. Some of them are better and have more

0:32:56.080 --> 0:33:00.400
<v Speaker 1>examples than others because new code is constant a being

0:33:00.520 --> 0:33:04.040
<v Speaker 1>churned out as far as malware is concerned. So your

0:33:04.040 --> 0:33:08.840
<v Speaker 1>antivirus programs scans your computer for evidence of these examples

0:33:08.840 --> 0:33:11.840
<v Speaker 1>of known malicious code, and if it finds one, it

0:33:11.880 --> 0:33:15.320
<v Speaker 1>will sequester and isolate that code to mitigate any harm,

0:33:15.560 --> 0:33:18.720
<v Speaker 1>and often will automatically remove the code as well. Some

0:33:18.840 --> 0:33:21.800
<v Speaker 1>programs might actually require you to give the command to

0:33:21.880 --> 0:33:26.400
<v Speaker 1>remove the malware, but it will isolate it so that

0:33:26.480 --> 0:33:29.280
<v Speaker 1>it can't do any more harm. And I know that

0:33:29.320 --> 0:33:33.280
<v Speaker 1>a lot of antivirus programs can get expensive. Goodness knows

0:33:33.600 --> 0:33:36.560
<v Speaker 1>that they can really be obnoxious. Once your subscription is

0:33:36.560 --> 0:33:38.720
<v Speaker 1>starting to get close to the end, you'll just get

0:33:38.800 --> 0:33:42.320
<v Speaker 1>notification after notification of hey, your protection is expiring, do

0:33:42.360 --> 0:33:45.160
<v Speaker 1>you want to renew? But they really are a good

0:33:45.160 --> 0:33:50.000
<v Speaker 1>component for computer security. UH. They're also free antivirus programs

0:33:50.000 --> 0:33:53.000
<v Speaker 1>out there, and you know they vary in quality, but

0:33:53.120 --> 0:33:56.240
<v Speaker 1>really some protection is better than no protection at all.

0:33:56.360 --> 0:34:00.640
<v Speaker 1>So if you can't afford to subscribe to a like

0:34:01.520 --> 0:34:06.240
<v Speaker 1>big name UH provider like Caspersky or Norton or something

0:34:06.280 --> 0:34:09.640
<v Speaker 1>like that, then you can at least look for a

0:34:09.680 --> 0:34:15.040
<v Speaker 1>good free anti virus suite out there. Also, would the

0:34:15.080 --> 0:34:17.560
<v Speaker 1>operating system that you use on your device will be

0:34:17.600 --> 0:34:20.160
<v Speaker 1>a big factor as to whether or not you should

0:34:20.200 --> 0:34:22.919
<v Speaker 1>really have anti virus on there. I I honestly think

0:34:22.960 --> 0:34:27.040
<v Speaker 1>that for pretty much any device outside of iOS, you

0:34:27.080 --> 0:34:30.399
<v Speaker 1>need anti virus. iOS you really don't, but everything else

0:34:30.440 --> 0:34:34.440
<v Speaker 1>you you kind of do. However, that being said, if

0:34:34.480 --> 0:34:38.120
<v Speaker 1>you use a Windows based machine, you absolutely should have

0:34:38.160 --> 0:34:41.440
<v Speaker 1>antivirus software on there. And the reason is not because

0:34:41.440 --> 0:34:46.800
<v Speaker 1>Windows is just inherently more vulnerable than other platforms. Although

0:34:47.280 --> 0:34:50.799
<v Speaker 1>you know mac OS is locked down pretty tightly. It's

0:34:50.880 --> 0:34:54.640
<v Speaker 1>because there are more Windows based machines out there than

0:34:54.680 --> 0:34:58.080
<v Speaker 1>anything else, which in turn means that when criminals are

0:34:58.120 --> 0:35:01.920
<v Speaker 1>designing malicious software, they want to have the biggest impact

0:35:01.920 --> 0:35:05.080
<v Speaker 1>they can possibly have, So they're going to be programming

0:35:05.120 --> 0:35:08.399
<v Speaker 1>their malicious software for the platforms that are the most

0:35:08.440 --> 0:35:11.920
<v Speaker 1>plentiful out there. When it comes to things like personal

0:35:11.920 --> 0:35:15.960
<v Speaker 1>computers and work computers, that tends to be Windows based machines.

0:35:16.440 --> 0:35:19.760
<v Speaker 1>So when you know that most of the malicious software

0:35:19.760 --> 0:35:22.239
<v Speaker 1>out there is being written for Windows devices and you

0:35:22.320 --> 0:35:25.040
<v Speaker 1>use a Windows device, then in turn tells you you

0:35:25.040 --> 0:35:28.680
<v Speaker 1>should probably have antivirus software installed on your machine just

0:35:28.800 --> 0:35:32.680
<v Speaker 1>because you're more likely to be a target. Um, but

0:35:32.719 --> 0:35:35.319
<v Speaker 1>you know there are other platforms out there and they

0:35:35.320 --> 0:35:38.640
<v Speaker 1>are not immune. Mac operating system, while it has a

0:35:38.680 --> 0:35:42.560
<v Speaker 1>great reputation because Apple really locks down its system and

0:35:42.640 --> 0:35:46.520
<v Speaker 1>makes it very difficult to gain access to it, there

0:35:46.520 --> 0:35:50.920
<v Speaker 1>are still examples of malware written specifically for Mac OS,

0:35:50.960 --> 0:35:54.560
<v Speaker 1>and they have been on the rise in recent years. Uh,

0:35:54.600 --> 0:35:58.040
<v Speaker 1>there were years where Apple was enjoying security through obscurity

0:35:58.080 --> 0:36:01.880
<v Speaker 1>to some extent, meaning the US there were so relatively

0:36:02.040 --> 0:36:06.680
<v Speaker 1>few Apple devices on the market malware authors weren't really

0:36:06.719 --> 0:36:10.680
<v Speaker 1>targeting those machines. But then but that that's no longer

0:36:10.680 --> 0:36:13.480
<v Speaker 1>really the case. And as I said, while Apple takes

0:36:13.520 --> 0:36:18.040
<v Speaker 1>a very lockdown approach compared to the much more open

0:36:18.640 --> 0:36:21.720
<v Speaker 1>approach to seeing things like Linux and Windows based machines,

0:36:22.280 --> 0:36:26.200
<v Speaker 1>it is not immune to malware. There are people who

0:36:26.239 --> 0:36:29.560
<v Speaker 1>still think that max are immune to malware. They are wrong,

0:36:30.000 --> 0:36:34.640
<v Speaker 1>so keep that in mind too. Anyway, that's the rundown

0:36:34.840 --> 0:36:37.919
<v Speaker 1>on the types of malware, and my my cry for

0:36:38.640 --> 0:36:42.480
<v Speaker 1>UH people to install antivirus software on their machines and

0:36:42.520 --> 0:36:45.640
<v Speaker 1>practice good computer security. There are other things you can do.

0:36:46.080 --> 0:36:50.200
<v Speaker 1>Having a firewall installed on your network is really important.

0:36:50.840 --> 0:36:54.840
<v Speaker 1>UM Using VPNs is a good idea too in many cases,

0:36:55.239 --> 0:36:58.879
<v Speaker 1>like the combination of VPNs and anti virus are good

0:36:58.880 --> 0:37:01.560
<v Speaker 1>ways to stay protected. Depending upon the nature of what

0:37:01.640 --> 0:37:04.279
<v Speaker 1>you do on your computer, you probably want to use

0:37:04.280 --> 0:37:08.480
<v Speaker 1>a VPN and anti virus software to protect yourself. This

0:37:08.560 --> 0:37:13.120
<v Speaker 1>includes companies that you know are allowing workers to work

0:37:13.120 --> 0:37:17.520
<v Speaker 1>remotely and deal with sensitive information that the company does

0:37:17.560 --> 0:37:22.439
<v Speaker 1>not want to leave company computers. These are important things

0:37:22.480 --> 0:37:25.920
<v Speaker 1>to keep in mind. So I just wanted to do that.

0:37:26.440 --> 0:37:28.200
<v Speaker 1>This was going to be a tech Stuff tidbits. But

0:37:28.239 --> 0:37:30.640
<v Speaker 1>we're coming up close to forty minutes at this point,

0:37:30.680 --> 0:37:33.880
<v Speaker 1>so once again I babbled too much. But if you

0:37:33.920 --> 0:37:36.280
<v Speaker 1>have suggestions for topics I should cover in future episodes

0:37:36.280 --> 0:37:40.240
<v Speaker 1>of tech Stuff, whether it's a technology personality and tech

0:37:40.840 --> 0:37:44.400
<v Speaker 1>maybe it's a specific gadget and it's evolution that you

0:37:44.400 --> 0:37:47.239
<v Speaker 1>would like me to talk about. Anything along those lines,

0:37:47.320 --> 0:37:52.480
<v Speaker 1>anything really tech oriented or how tech impacts us in

0:37:52.480 --> 0:37:55.600
<v Speaker 1>our lives, I'm happy to hear it. You can reach

0:37:55.640 --> 0:37:57.239
<v Speaker 1>out to me in a couple of different ways. One

0:37:57.280 --> 0:37:59.640
<v Speaker 1>way is to download the I Heart Radio app. It

0:37:59.760 --> 0:38:02.480
<v Speaker 1>is free to download, it's free to use. You can

0:38:02.560 --> 0:38:04.919
<v Speaker 1>navigate over to the tech Stuff part of the app

0:38:04.960 --> 0:38:07.839
<v Speaker 1>just by typing tech Stuff into the search field. There's

0:38:07.840 --> 0:38:10.279
<v Speaker 1>a little microphone icon there. If you click on that,

0:38:10.400 --> 0:38:13.360
<v Speaker 1>you can leave me a voice message up to thirties

0:38:13.440 --> 0:38:16.240
<v Speaker 1>seconds in length, and if you like, you can even

0:38:16.280 --> 0:38:19.040
<v Speaker 1>indicate if I can use the voice message in a

0:38:19.080 --> 0:38:21.839
<v Speaker 1>future episode of tech Stuff. I will never use any

0:38:21.960 --> 0:38:25.000
<v Speaker 1>voice message unless I get your express permission. You have

0:38:25.120 --> 0:38:29.160
<v Speaker 1>my word on that, because I mean, I know I

0:38:29.160 --> 0:38:33.520
<v Speaker 1>wouldn't want someone to play a message just because I

0:38:33.680 --> 0:38:37.760
<v Speaker 1>said something into a microphone unless I intended that message

0:38:37.760 --> 0:38:40.319
<v Speaker 1>to be played, which is a good thing considering what

0:38:40.400 --> 0:38:43.000
<v Speaker 1>I do for a living, or if you prefer not

0:38:43.120 --> 0:38:46.319
<v Speaker 1>to speak into a microphone, which is total legit. You

0:38:46.360 --> 0:38:49.480
<v Speaker 1>can still reach me on Twitter. The handle for the

0:38:49.520 --> 0:38:53.640
<v Speaker 1>show is tech Stuff hs W and I'll talk to

0:38:53.640 --> 0:39:02.680
<v Speaker 1>you again really soon. Text Stuff is an I Heart

0:39:02.760 --> 0:39:06.520
<v Speaker 1>Radio production. For more podcasts from I Heart Radio, visit

0:39:06.560 --> 0:39:09.600
<v Speaker 1>the i Heart Radio app, Apple Podcasts, or wherever you

0:39:09.719 --> 0:39:11.040
<v Speaker 1>listen to your favorite shows.