1
00:00:06,480 --> 00:00:09,660
- In 8.7, last lesson of lesson eight,

2
00:00:09,660 --> 00:00:12,603
we're gonna focus in on
cryptographic attacks.

3
00:00:14,340 --> 00:00:16,980
Now, a cryptographic
attack is a circumvention

4
00:00:16,980 --> 00:00:19,650
of a cryptographic system
by exploiting a weakness

5
00:00:19,650 --> 00:00:23,160
or vulnerability in code or in the cipher

6
00:00:23,160 --> 00:00:26,250
or in the cryptographic
protocol or in the key

7
00:00:26,250 --> 00:00:30,420
or key management scheme
or in the implementation.

8
00:00:30,420 --> 00:00:33,000
The process of finding
a cryptographic weakness

9
00:00:33,000 --> 00:00:36,393
or vulnerability is
known as cryptoanalysis.

10
00:00:38,070 --> 00:00:39,780
Because a cryptographic system

11
00:00:39,780 --> 00:00:44,280
is usually a pretty strong
system, attackers are always

12
00:00:44,280 --> 00:00:47,910
looking to take advantage
of a weak implementation.

13
00:00:47,910 --> 00:00:50,510
So they're looking for
things like misconfigurations

14
00:00:51,480 --> 00:00:55,263
or weak keys or broken
or deprecated versions.

15
00:00:57,030 --> 00:00:59,100
As a reminder, we talked
about this earlier,

16
00:00:59,100 --> 00:01:02,010
deprecated means that
there's a weakness, right?

17
00:01:02,010 --> 00:01:04,590
And that the user must accept some risk.

18
00:01:04,590 --> 00:01:07,410
Deprecated in terms of
cryptographic systems

19
00:01:07,410 --> 00:01:09,060
means that the use of an algorithm

20
00:01:09,060 --> 00:01:12,000
and the key length is
allowed, but the user,

21
00:01:12,000 --> 00:01:14,190
again, has to acknowledge
and accept some risks.

22
00:01:14,190 --> 00:01:15,480
There's some weaknesses.

23
00:01:15,480 --> 00:01:16,313
We talked about that.

24
00:01:16,313 --> 00:01:18,660
We talked about symmetric
algorithms, and we said,

25
00:01:18,660 --> 00:01:22,770
you know, DES, which is
broken, Triple DES is weak,

26
00:01:22,770 --> 00:01:26,460
so AES really is our
current government standard.

27
00:01:26,460 --> 00:01:28,290
Now, broken means that the algorithm

28
00:01:28,290 --> 00:01:30,477
and/or the key length is exploitable

29
00:01:30,477 --> 00:01:32,400
and so we don't wanna use it anymore.

30
00:01:32,400 --> 00:01:35,850
So for example, we don't
wanna be using 802.11 WEP

31
00:01:35,850 --> 00:01:39,750
or DES because they're both
been broken and exploitable.

32
00:01:39,750 --> 00:01:43,443
So deprecated, weak, broken, exploitable.

33
00:01:45,720 --> 00:01:48,030
So I wanna introduce you
to a downgrade attack

34
00:01:48,030 --> 00:01:50,850
because this is a fairly common

35
00:01:50,850 --> 00:01:55,110
and very powerful attack that
takes people by surprise.

36
00:01:55,110 --> 00:01:57,120
A downgrade attack is a type of attack

37
00:01:57,120 --> 00:02:01,320
the system forces degradation
to a lower quality crypto mode

38
00:02:01,320 --> 00:02:04,620
and then the attacker exploits
the lesser security control.

39
00:02:04,620 --> 00:02:06,210
So you think you're fine, right?

40
00:02:06,210 --> 00:02:08,670
You're using that strong crypto mode.

41
00:02:08,670 --> 00:02:11,970
Turns out though, that
the attacker can force you

42
00:02:11,970 --> 00:02:15,090
into using a lesser security control.

43
00:02:15,090 --> 00:02:16,890
So let me give you two examples.

44
00:02:16,890 --> 00:02:19,950
SSL has known vulnerabilities
and has been replaced

45
00:02:19,950 --> 00:02:22,620
with TLS in most, if
not all, implementation.

46
00:02:22,620 --> 00:02:26,010
In a later lesson, we'll
talk more about SSL and TLS.

47
00:02:26,010 --> 00:02:27,570
However, many servers might have

48
00:02:27,570 --> 00:02:30,810
SSL installed for backward compatibility.

49
00:02:30,810 --> 00:02:33,600
So the attacker exploits the configuration

50
00:02:33,600 --> 00:02:36,600
and forces a downgrade to SSL.

51
00:02:36,600 --> 00:02:38,670
Now, what's even more
common than having it on

52
00:02:38,670 --> 00:02:40,530
because of backward compatibility is

53
00:02:40,530 --> 00:02:43,290
it was just on by default
and you're not using it,

54
00:02:43,290 --> 00:02:46,560
but you never turned it off
because you're using TLS.

55
00:02:46,560 --> 00:02:50,790
Just the fact that SSL 2.0
or 3.0 is enabled, right,

56
00:02:50,790 --> 00:02:53,940
even if you're not using it in
any fashion, would be enough

57
00:02:53,940 --> 00:02:56,940
for the attacker to force
the downgrade attack.

58
00:02:56,940 --> 00:03:00,000
Another example would
be redirecting a visitor

59
00:03:00,000 --> 00:03:03,450
from an HTTPS version,
right, of a resource

60
00:03:03,450 --> 00:03:06,990
or secure website to an HTTP copy.

61
00:03:06,990 --> 00:03:11,103
HTTP being insecure,
a clear text protocol.

62
00:03:13,530 --> 00:03:16,470
Now, a side-channel attack is any attack

63
00:03:16,470 --> 00:03:19,110
that's based on information
gained from implementation

64
00:03:19,110 --> 00:03:21,960
of a computer system
rather than the weakness

65
00:03:21,960 --> 00:03:24,690
in the implemented algorithm itself.

66
00:03:24,690 --> 00:03:28,140
So in a side-channel attack,
attackers use physical data

67
00:03:28,140 --> 00:03:30,450
such as monitoring CPU cycles

68
00:03:30,450 --> 00:03:33,870
or power consumption
or radiation admissions

69
00:03:33,870 --> 00:03:37,050
and timing to break the crypto system.

70
00:03:37,050 --> 00:03:38,670
Now, a side-channel attack was used

71
00:03:38,670 --> 00:03:43,670
back in 1995 to successfully
identify RSA keys.

72
00:03:43,800 --> 00:03:46,440
Now a timing attack exploits the fact

73
00:03:46,440 --> 00:03:48,840
that different computations
take different times

74
00:03:48,840 --> 00:03:50,670
to compute on a processor.

75
00:03:50,670 --> 00:03:53,700
So for example, if the
encryption takes a longer time,

76
00:03:53,700 --> 00:03:57,540
it indicates that the secret key is long.

77
00:03:57,540 --> 00:03:59,943
So timing and side-channel attacks.

78
00:04:03,030 --> 00:04:04,590
Of course, there's always, right,

79
00:04:04,590 --> 00:04:07,320
always the motivation to find the key.

80
00:04:07,320 --> 00:04:10,980
So let's look at three types
of cryptovariable key attacks.

81
00:04:10,980 --> 00:04:12,510
There's a brute force attack.

82
00:04:12,510 --> 00:04:14,430
We've talked about brute force earlier.

83
00:04:14,430 --> 00:04:17,910
In a brute force attack, our adversary

84
00:04:17,910 --> 00:04:20,580
is trying to test every possible key.

85
00:04:20,580 --> 00:04:21,780
Now, they could do it in online

86
00:04:21,780 --> 00:04:24,930
or offline mode, until
the key is discovered

87
00:04:24,930 --> 00:04:27,630
that successfully
decrypts the cipher text.

88
00:04:27,630 --> 00:04:29,070
Brute force attacks are going to be

89
00:04:29,070 --> 00:04:30,750
limited by work factor, right?

90
00:04:30,750 --> 00:04:33,000
That's the time and the resources,

91
00:04:33,000 --> 00:04:36,273
I would say also the talent,
and of course, discovery.

92
00:04:37,290 --> 00:04:40,800
A dictionary attack is when a
list of known keys are tested,

93
00:04:40,800 --> 00:04:42,450
generally common wordlists.

94
00:04:42,450 --> 00:04:45,420
And a frequency analysis analyzes

95
00:04:45,420 --> 00:04:47,970
the pattern of frequencies,
so for example,

96
00:04:47,970 --> 00:04:50,070
specific letters that may show up,

97
00:04:50,070 --> 00:04:53,430
in an encrypted message
to deduce information

98
00:04:53,430 --> 00:04:55,470
about the underlying plain text

99
00:04:55,470 --> 00:04:58,410
or the key that's used
to encrypt the message.

100
00:04:58,410 --> 00:05:02,253
So brute force, dictionary,
and frequency analysis.

101
00:05:04,380 --> 00:05:06,810
Next, we're gonna turn our
attention to hash attacks.

102
00:05:06,810 --> 00:05:08,880
Remember that we use hashing for integrity

103
00:05:08,880 --> 00:05:12,510
and a hashing is a visual
representation of a dataset.

104
00:05:12,510 --> 00:05:14,820
And one of the most
important things about a hash

105
00:05:14,820 --> 00:05:17,400
is that the output is
always unique to the input.

106
00:05:17,400 --> 00:05:19,920
If I put the same input
in a thousand times,

107
00:05:19,920 --> 00:05:22,230
the output will always be the same.

108
00:05:22,230 --> 00:05:24,930
If I make even the slightest
change in the input,

109
00:05:24,930 --> 00:05:26,820
the output will be different.

110
00:05:26,820 --> 00:05:28,650
So here is some of the hash attacks

111
00:05:28,650 --> 00:05:29,970
we need to be concerned with.

112
00:05:29,970 --> 00:05:34,970
Collision, birthday, rainbow
tables, and pass-the-hash.

113
00:05:35,220 --> 00:05:38,040
A collision attack uses
a mathematical technique

114
00:05:38,040 --> 00:05:42,720
to force two inputs into
producing the same hash value.

115
00:05:42,720 --> 00:05:44,430
Well, if two different
inputs are giving us

116
00:05:44,430 --> 00:05:47,010
the same hash value, then the process

117
00:05:47,010 --> 00:05:48,480
is no longer useful for us.

118
00:05:48,480 --> 00:05:51,300
So that hash method can't
be relied on anymore

119
00:05:51,300 --> 00:05:54,570
to identify different data.

120
00:05:54,570 --> 00:05:56,310
Now, the birthday attack just exploits

121
00:05:56,310 --> 00:05:59,280
some mathematics behind
the birthday problem

122
00:05:59,280 --> 00:06:02,193
in probability theory
to cause a collision.

123
00:06:03,510 --> 00:06:07,110
Rainbow tables are
publicly available tables

124
00:06:07,110 --> 00:06:09,300
of pre-computed hashes,
and we've talked about

125
00:06:09,300 --> 00:06:11,460
those earlier, and those can be used

126
00:06:11,460 --> 00:06:13,650
to quickly crack password hashes, right?

127
00:06:13,650 --> 00:06:16,410
If we have these pre-computed
tables, if we capture a hash

128
00:06:16,410 --> 00:06:19,177
and we compare it to our
rainbow table, we can say,

129
00:06:19,177 --> 00:06:22,137
"Oh yeah, this hash is this password."

130
00:06:23,970 --> 00:06:26,190
And then we have a pass-the-hash attack.

131
00:06:26,190 --> 00:06:28,710
In a pass-the-hash attack, attackers use

132
00:06:28,710 --> 00:06:31,470
captured hash credentials from one machine

133
00:06:31,470 --> 00:06:34,410
to successfully gain
control of another machine.

134
00:06:34,410 --> 00:06:37,320
And that's because in
a lot of environments,

135
00:06:37,320 --> 00:06:38,910
passwords are hashed.

136
00:06:38,910 --> 00:06:41,190
So they're not sent encrypted form, right?

137
00:06:41,190 --> 00:06:42,870
They're sent in a hashed format,

138
00:06:42,870 --> 00:06:46,230
which is better than clear
text but still problematic.

139
00:06:46,230 --> 00:06:48,180
In older Microsoft's environments.

140
00:06:48,180 --> 00:06:51,210
Like in NTLM, NT LAN Manager, again,

141
00:06:51,210 --> 00:06:52,680
all of our passwords were hashed.

142
00:06:52,680 --> 00:06:55,260
This was in pre-Active Directory days.

143
00:06:55,260 --> 00:06:57,750
But even if you're running
AD, you still might have

144
00:06:57,750 --> 00:07:01,020
NTLM turned on by
default, which means that

145
00:07:01,020 --> 00:07:04,560
your system is creating
hashes of passwords.

146
00:07:04,560 --> 00:07:07,140
Capture that hash and
reuse it on another system,

147
00:07:07,140 --> 00:07:10,113
and voila, the attacker has access.

148
00:07:12,540 --> 00:07:14,070
Let's look a little
deeper to rainbow table.

149
00:07:14,070 --> 00:07:15,150
I keep describing them to you,

150
00:07:15,150 --> 00:07:16,920
but I want you to see what they look like.

151
00:07:16,920 --> 00:07:19,410
And so let's say we have
the string Password99.

152
00:07:19,410 --> 00:07:20,400
That's somebody's password.

153
00:07:20,400 --> 00:07:23,760
Terrible password, but let's
say that's what they're using.

154
00:07:23,760 --> 00:07:26,880
So a SHA-256 hash, you can
see what it would look like.

155
00:07:26,880 --> 00:07:29,610
A SHA-512, right, It's
gonna have a longer hash.

156
00:07:29,610 --> 00:07:31,410
You can see what it looks like.

157
00:07:31,410 --> 00:07:35,130
So if I capture, I'm the bad
guy, and I capture the hashes,

158
00:07:35,130 --> 00:07:38,190
I can compare it to the 256 or the 512.

159
00:07:38,190 --> 00:07:40,830
And if either those match, I know that

160
00:07:40,830 --> 00:07:42,963
the password string was Password99.

161
00:07:45,960 --> 00:07:48,570
So let's look next at
rainbow tables and salting,

162
00:07:48,570 --> 00:07:51,570
how we can use salting
to diminish the impact

163
00:07:51,570 --> 00:07:54,030
or the usability of a rainbow table.

164
00:07:54,030 --> 00:07:56,550
So in our example here,
we've got Mary and Tom.

165
00:07:56,550 --> 00:07:58,650
They're both using Password99

166
00:07:58,650 --> 00:08:00,780
and their passwords are being hashed.

167
00:08:00,780 --> 00:08:02,790
And if that hash was captured, right,

168
00:08:02,790 --> 00:08:05,910
and compared to a rainbow
table, well we'd be able to see

169
00:08:05,910 --> 00:08:07,760
that their passwords were Password99.

170
00:08:08,820 --> 00:08:10,440
But what if I add a salt?

171
00:08:10,440 --> 00:08:15,440
A salt is just a random bunch
of numbers and letters, right,

172
00:08:15,540 --> 00:08:19,650
that are added to in
string that's inputted

173
00:08:19,650 --> 00:08:21,540
before we create the hash.

174
00:08:21,540 --> 00:08:24,660
So we add as salt to Mary's,
we add a salt to Tom.

175
00:08:24,660 --> 00:08:27,390
Now, if we're looking at a SHA-256 hash,

176
00:08:27,390 --> 00:08:29,400
not only do they not match each other

177
00:08:29,400 --> 00:08:31,530
because they have this additional salt,

178
00:08:31,530 --> 00:08:33,090
they're not gonna match anything

179
00:08:33,090 --> 00:08:36,480
that's in a rainbow table
unless, for some reason, right,

180
00:08:36,480 --> 00:08:38,160
the attacker knew to add that salt

181
00:08:38,160 --> 00:08:39,750
but they're not going to, right?

182
00:08:39,750 --> 00:08:43,863
So that really negates the
use of those rainbow tables.

183
00:08:46,830 --> 00:08:48,270
Now, another form of cryptography

184
00:08:48,270 --> 00:08:51,510
that we wanna talk about is
adversarial cryptography.

185
00:08:51,510 --> 00:08:53,220
Adversarial cryptography is when

186
00:08:53,220 --> 00:08:56,130
our adversaries use
cryptography to harm us.

187
00:08:56,130 --> 00:09:00,390
And ransomware is really
one of the best examples

188
00:09:00,390 --> 00:09:02,340
of adversarial cryptography.

189
00:09:02,340 --> 00:09:04,950
Ransomware being a form
of malware designed to

190
00:09:04,950 --> 00:09:08,760
encrypt files on a device,
rendering them unusable.

191
00:09:08,760 --> 00:09:10,410
Now, we know that
ransomware generally adds

192
00:09:10,410 --> 00:09:12,180
an extension to the encrypted files.

193
00:09:12,180 --> 00:09:13,950
There's a whole bunch there

194
00:09:13,950 --> 00:09:15,900
to show that the file's been encrypted.

195
00:09:15,900 --> 00:09:18,030
And the file extension is generally unique

196
00:09:18,030 --> 00:09:19,200
to the ransomware.

197
00:09:19,200 --> 00:09:22,170
And once the ransomware has
completed its file encryption,

198
00:09:22,170 --> 00:09:24,930
it creates and displays a file or files

199
00:09:24,930 --> 00:09:28,080
to the user saying, "Hey,
I've encrypted all your files.

200
00:09:28,080 --> 00:09:29,820
If you want a decryption key,

201
00:09:29,820 --> 00:09:31,857
you need to pay me some ransom."

202
00:09:34,200 --> 00:09:35,610
But I want to illustrate to you

203
00:09:35,610 --> 00:09:39,330
how ransomware uses cryptography.

204
00:09:39,330 --> 00:09:41,040
So I know that for some of you,

205
00:09:41,040 --> 00:09:43,020
you might still be struggling
a little bit with cryptography

206
00:09:43,020 --> 00:09:44,670
and you might get a
little overload on this,

207
00:09:44,670 --> 00:09:46,800
but once you've gotten the concepts

208
00:09:46,800 --> 00:09:50,130
of the keys and encryption,
this is a really cool thing

209
00:09:50,130 --> 00:09:51,573
to come back to and look at.

210
00:09:53,160 --> 00:09:56,193
So in ransomware, the attacker's
gonna generate a key pair.

211
00:09:57,090 --> 00:10:00,120
The public key is going to
be embedded in the malware.

212
00:10:00,120 --> 00:10:01,980
Remember, the public key
can be freely distributed

213
00:10:01,980 --> 00:10:04,020
so it's embedded in the malware.

214
00:10:04,020 --> 00:10:06,753
The malware generates a symmetric key.

215
00:10:08,190 --> 00:10:10,710
The symmetric key is used
to encrypt the files.

216
00:10:10,710 --> 00:10:11,790
Why a symmetric key?

217
00:10:11,790 --> 00:10:15,780
Because a symmetric key is
computationally efficient

218
00:10:15,780 --> 00:10:18,153
and works well on large blocks of data.

219
00:10:19,440 --> 00:10:24,270
The malware public key is used
to encrypt the symmetric key,

220
00:10:24,270 --> 00:10:27,680
because what is the corresponding key

221
00:10:27,680 --> 00:10:29,640
to the malware public key?

222
00:10:29,640 --> 00:10:30,630
The malware private key.

223
00:10:30,630 --> 00:10:32,280
And who has the malware private key?

224
00:10:32,280 --> 00:10:33,780
Well, the attacker.

225
00:10:33,780 --> 00:10:35,160
So the malware public key is used

226
00:10:35,160 --> 00:10:37,410
to encrypt the symmetric key.

227
00:10:37,410 --> 00:10:41,433
The payment response includes
that encrypted symmetric key.

228
00:10:42,450 --> 00:10:44,700
The attacker uses the malware private key,

229
00:10:44,700 --> 00:10:46,470
the one they have in their possession,

230
00:10:46,470 --> 00:10:49,170
to decrypt that symmetric key.

231
00:10:49,170 --> 00:10:50,640
And then the symmetric key is sent

232
00:10:50,640 --> 00:10:53,040
to the user to decrypt files.

233
00:10:53,040 --> 00:10:55,230
I think this is just a
fascinating illustration.

234
00:10:55,230 --> 00:10:57,060
And if you're really comfortable already

235
00:10:57,060 --> 00:10:59,940
with asymmetric and symmetric
and private and public keys,

236
00:10:59,940 --> 00:11:01,890
you'll be like, "Wow,
that's really something."

237
00:11:01,890 --> 00:11:04,080
If you're not, after you
do become comfortable,

238
00:11:04,080 --> 00:11:05,640
I wanna once again implore you

239
00:11:05,640 --> 00:11:06,720
to come back and look at this.

240
00:11:06,720 --> 00:11:09,690
It'll really help you
understand how ransomware works.

241
00:11:09,690 --> 00:11:12,120
And that, my friends, brings
us to a three-second challenge.

242
00:11:12,120 --> 00:11:14,370
Five challenge questions,
three seconds each.

243
00:11:14,370 --> 00:11:15,203
Let's do it.

244
00:11:16,140 --> 00:11:17,970
When two different hash inputs

245
00:11:17,970 --> 00:11:20,070
produce the same hash output.

246
00:11:20,070 --> 00:11:21,330
What is that called?

247
00:11:21,330 --> 00:11:23,073
One, two, three.

248
00:11:24,030 --> 00:11:25,503
And that's a collision.

249
00:11:26,640 --> 00:11:29,040
Number two, an attack that forces a system

250
00:11:29,040 --> 00:11:31,473
into using a lesser crypto mode.

251
00:11:32,490 --> 00:11:33,990
Really dangerous attack.

252
00:11:33,990 --> 00:11:35,373
One, two, three.

253
00:11:36,240 --> 00:11:38,103
And that's a downgrade attack.

254
00:11:39,090 --> 00:11:41,880
Number three, term used
to describe an algorithm

255
00:11:41,880 --> 00:11:46,560
or a key length that's exploitable
and should not be used.

256
00:11:46,560 --> 00:11:49,170
One, two, three.

257
00:11:49,170 --> 00:11:50,523
That's gonna be broken.

258
00:11:52,080 --> 00:11:56,433
Number four, an attack that
uses physical data inputs.

259
00:11:57,570 --> 00:11:59,163
One, two, three.

260
00:12:00,330 --> 00:12:02,730
That's a side-channel attack.

261
00:12:02,730 --> 00:12:06,210
And lastly, number five,
an attack which captured

262
00:12:06,210 --> 00:12:08,340
hash credentials from one machine

263
00:12:08,340 --> 00:12:11,433
are used to gain control
of another machine.

264
00:12:12,300 --> 00:12:14,400
One, two, three.

265
00:12:14,400 --> 00:12:17,430
And that's a pass-the-hash attack.

266
00:12:17,430 --> 00:12:19,110
Right, let's do a security-in-action.

267
00:12:19,110 --> 00:12:20,580
This one's about downgrade attacks.

268
00:12:20,580 --> 00:12:22,860
I'm glad we're talking about
downgrade attacks again

269
00:12:22,860 --> 00:12:24,900
because they're really dangerous,

270
00:12:24,900 --> 00:12:27,000
and, you know, there are
so many things we can do

271
00:12:27,000 --> 00:12:28,683
just so that they never happen.

272
00:12:29,850 --> 00:12:32,730
So one of the most infamous
crypto downgrade attacks

273
00:12:32,730 --> 00:12:36,840
is FREAK which stands for
Factoring RSA Export Keys.

274
00:12:36,840 --> 00:12:40,110
This is a vulnerability in SSL and TLS

275
00:12:40,110 --> 00:12:42,480
that allows an attacker
to force a target system

276
00:12:42,480 --> 00:12:44,730
to use weaker encryption ciphers,

277
00:12:44,730 --> 00:12:48,180
which can be easily cracked
using brute force methods.

278
00:12:48,180 --> 00:12:51,450
Now the attack works by
exploiting a flaw in the way

279
00:12:51,450 --> 00:12:56,190
SSL and TLS handle
export-grade encryption keys.

280
00:12:56,190 --> 00:12:58,710
You've been asked to recommend
preventative controls

281
00:12:58,710 --> 00:13:00,960
against a downgrade attack.

282
00:13:00,960 --> 00:13:04,020
So really, we've told you a
lot about this FREAK attack,

283
00:13:04,020 --> 00:13:05,250
but that's not really the question.

284
00:13:05,250 --> 00:13:06,900
We're not asking you how to defend against

285
00:13:06,900 --> 00:13:08,760
a FREAK attack specifically.

286
00:13:08,760 --> 00:13:10,110
You've been asked to recommend

287
00:13:10,110 --> 00:13:13,500
preventative controls
against a downgrade attack.

288
00:13:13,500 --> 00:13:15,840
You don't wanna be subject
to a downgrade attack.

289
00:13:15,840 --> 00:13:17,460
So put me on pause, write some notes,

290
00:13:17,460 --> 00:13:20,910
tell me what those preventative
controls are gonna be.

291
00:13:20,910 --> 00:13:23,640
All right, let's talk about
those preventative controls.

292
00:13:23,640 --> 00:13:25,500
Downgrade attacks are particular dangerous

293
00:13:25,500 --> 00:13:28,140
because they exploit
vulnerabilities in older,

294
00:13:28,140 --> 00:13:31,860
widely-used software protocols
and communication channels

295
00:13:31,860 --> 00:13:34,923
which can be difficult
to update and replace.

296
00:13:35,940 --> 00:13:38,100
So to protect against downgrade attacks,

297
00:13:38,100 --> 00:13:41,370
we wanna keep our software and our systems

298
00:13:41,370 --> 00:13:44,130
up-to-date with the
latest security patches.

299
00:13:44,130 --> 00:13:46,860
We always wanna use the
most secure versions

300
00:13:46,860 --> 00:13:49,080
of protocols and communication channels.

301
00:13:49,080 --> 00:13:51,480
And probably the most important thing here

302
00:13:51,480 --> 00:13:56,480
is that we want to disable
older, insecure versions.

303
00:13:56,940 --> 00:13:58,620
We shouldn't ever say,
"Well, we're not using it,

304
00:13:58,620 --> 00:14:00,390
so not a big deal that it's there."

305
00:14:00,390 --> 00:14:02,220
No, we always wanna make sure

306
00:14:02,220 --> 00:14:04,803
we are disabling those versions.

307
00:14:05,790 --> 00:14:08,520
And we should also enable
firewall filtering.

308
00:14:08,520 --> 00:14:10,020
So in this case, we wouldn't allow

309
00:14:10,020 --> 00:14:12,690
any SSL traffic to come through.

310
00:14:12,690 --> 00:14:14,910
So really understanding what you can do

311
00:14:14,910 --> 00:14:17,340
to prevent an attack is very important.

312
00:14:17,340 --> 00:14:19,320
Of course, there are
other controls we can put.

313
00:14:19,320 --> 00:14:23,940
Deterrent, right, detective,
corrective controls,

314
00:14:23,940 --> 00:14:26,160
but if we can prevent
something from happening,

315
00:14:26,160 --> 00:14:28,740
isn't that really the best of all actions?

316
00:14:28,740 --> 00:14:32,010
And that, my friends, is
definitely security-in-action.

317
00:14:32,010 --> 00:14:33,300
There's your word cloud.

318
00:14:33,300 --> 00:14:34,133
A lot here.

319
00:14:34,133 --> 00:14:36,240
Make sure that you, again,
know all of these terms.

320
00:14:36,240 --> 00:14:38,670
You can speak to all of them confidently.

321
00:14:38,670 --> 00:14:41,580
When you're ready, we've got
a 10-question quiz coming up

322
00:14:41,580 --> 00:14:42,680
so I'll see you there.
