
In last week’s episode, we dove deep into the topic of security awareness training and took a look at why it’s number one on the #TOPcyber21 best security practices. Our cyber expert cast from TBI, IronScales, IDAgent, and KnowBe4 shared insights and thoughts on the vital importance of adopting security awareness training. Everyone agreed, security awareness training is of vital importance and a cyber aware culture from the top down is crucial to mitigating risk from the ninety-five percent of breaches that are result of human error.
If you haven’t had the chance to watch episode zero or one, be sure to catch those on demand on LinkedIn, Facebook or YouTube. And if you’re more of a podcast kind of listener, catch all 23 episodes ahead on Spotify or Google Podcasts. And for direct delivery to your inbox, sign up for our blog at TechOnPurpose.net/blog. Today, we’re discussing #TOPcyber21 Best Practice number two, dark web monitoring. Please join me in formally welcoming our Who’s in Your Cloud cast for today. First up, we have returning cast member Sam Yip, who is the Channel Success Manager from IDAgent. Welcome back and thanks for joining us again.
Don’t forget we’ll be releasing a new episode every Tuesday, starting today 10/20/21 through late spring of 2022 with brief time off for holidays with family & friends. We’ll also follow each Tuesday episode release with subsequent Wednesday, Thursday, and Friday posts highlighting our (3) contributing solution partners from that week’s episode. We hope you’ll find this an immersive, hopefully simple, educational and enjoyable experience. So how do you tune in?
To easily follow the journey ahead we’ve diversified your access options to all (23) of our coming episodes. You can follow long here on our blog, or by any of the following methods:
- Email Newsletter: sign up at techonpurpose.net/blog and have each episode delivered directly to your inbox when released.
- LinkedIn: follow here
- YouTube: follow here
- Facebook: follow here
- Podcast: follow here
Buckle up – it’s time to hit the road to #secure, reliable, trusted technology!
Read Transcript
Welcome back to Who’s in Your Cloud, 21 Steps to Secure, Reliable, Trusted Technology. I’m Lauren Lev, Marketing Manager for TechOnPurpose, and this is Episode 2 Dark Web Monitoring. In last week’s episode, we dove deep into the topic of security awareness training and took a look at why it’s number one on the TOP Cyber21’s best security practices. Our cyber expert cast from TBI, IronScales, IDAgent, and KnowBe4 shared insights and thoughts on the vital importance of adopting security awareness training. Everyone agreed, security awareness training is of vital importance and a cyber aware culture from the top down is crucial to mitigating risk from the ninety-five percent of breaches that are result of human error. And if you haven’t had the chance to watch episode zero or one, be sure to catch those on demand on LinkedIn, Facebook or YouTube. And if you’re more of a podcast kind of listener, catch all 23 episodes ahead on Spotify or Google Podcasts. And for direct delivery to your inbox, sign up for our blog at TechOnPurpose.net/blog. Today, we’re discussing TOP Cyber21 Best Practice number two, dark web monitoring. Please join me in formally welcoming our Who’s in Your Cloud cast for today. First up, we have returning cast member Sam Yip, who is the Channel Success Manager from IDAgent. Welcome back and thanks for joining us again.
Samantha Yip
Thank you for having me again. Great to be here.
Lauren Lev
Yes, thanks for being here. And from our friends at OrbitalFire, let’s welcome CEO, Reg Harnish.
Reg Harnish
Hello, everyone. Good to be here.
Lauren Lev
And next up, we have Zane Bond, the Director of Product Management from Keeper. Thanks for being here, Zane.
Zane Bond
Oh, good to be here. I love talking about dark web stuff.
Lauren Lev
Nice. And then we have Sid Castle, who is the Channel Evangelist from LastPass. Thank you for joining us today.
Sid Castle
Thank you for having me. Hopefully, we don’t have to be talking to you about dark web monitoring.
Lauren Lev
And lastly, we have our TechOnPurpose Founder and CEO, Matt Tankersley.
Matt Tankersley
Hey, everybody.
Lauren Lev
So, Matt let’s take it away. What exactly is dark web monitoring?
Matt Tankersley
Well, I don’t know I’m the best guy to answer that. Fortunately, we have some good smart people in the room that’ll help with that. I’m not and let me just say this. I’m not sure most people understand, but dark web is a real thing. Much less, it’s a real thing that needs priority attention, right? So, if you watch movies or TV, you probably heard of this, but it’s not just a Hollywood fabrication, it’s a real thing. It’s a very serious, real threat. So, our personal and business emails and passwords are literally brought and sold online in this thing called the dark web. And when we all refuse to adopt best security practices for our passwords, it’s truly not a matter of if, but when we’ll experience a potentially devastating compromise. We’ll talk more about complex passwords and password management in episode three next week. Let me preface with this if you’re using the same password for multiple accounts, you are highly at risk if you use the same password regularly and you just make simple changes like a letter to a number, say a capital O instead of a zero, or add a dollar sign or an exclamation point or a year, you are highly at risk. So, what does this have to do with the dark web? Well, with bad actors, hack your usernames and passwords, the countless measures like phishing or shoulder surfing or social engineering, they sell those passwords on the dark web. Now malicious actors buy those passwords and then they take your known password and try to compromise every possible system like your bank, you know your lender, your iTunes, or your email account. So, as we’ll learn today, dark web monitoring is a way to know promptly when your credential has shown up for sale on the dark web. And with our dark web monitoring solution partners, you can take quick action to reset those passwords and minimize the risk of your bank account being drained or every email address you’ve ever had falling into the hands of malicious actors, who are going to do the same thing to everybody, you know. By phishing them, right? And pretending that they’re you. So, this is important stuff. This is why dark web monitoring is number two on the TOP Cyber 21 best security practices. So, with that Lauren, why don’t you pass it around? Let’s introduce all of our guests today.
Lauren Lev
We are going to start, let’s start with Sam. So, Sam, if you want to introduce yourself to the audience?
Samantha Yip
Absolutely. My name is Samantha, and I am part of Kaseya IDAgent. We provide MSPs with some security tools for protecting everyone out here.
Lauren Lev
Thanks for coming back. We appreciate it. You’ve been on back to back episodes now, so you’re becoming a pro just like us. Let’s see, let’s go to Reg.
Reg Harnish, CEO and founder of OrbitalFire Security. We are a slightly different, maybe significantly different managed security services partner, not provider. We work differently with MSPs to bring effective and affordable cybersecurity services to small businesses.
Lauren Lev
So next up, Zane
Zane Bond
I’m on the product management team with Keeper Security. You know, Keeper Security without a doubt, the best enterprise password manager out there, just saying. I think, you know, the dark web monitoring really it’s most of the stuff you find out there is passwords. So, we run into that all day, every day. We’re just with managing and handling passwords and breaches.
Lauren Lev
And lastly, we have Sid.
Sid Castle
Hi, I’m the LastPass evangelist overhead LogMeIn. Obviously, we do the go to for work for many word companies, but it’s, LastPass is all about identity access management. So, password management, single-sign-on, MFA, and as you’ve heard from some of the others, dark web monitoring is something you need to be aware of. Everything about selling credentials, those credentials are actually cheap. You can get a, go on an onion browser a tor browser, find these credentials for as low as three to five dollars a person. They do massive amounts, and as you’ve heard, the idea Matt was saying is that they use this to get to other people. And when you get a dark web alert, you’d normally get it in advance to the actors who will actually do something with it. And if you don’t act, that’s where the problem occurs and we can help you change those passwords, update those credentials and ensure that it doesn’t compromise something else.
Matt Tankersley
Thanks. Thanks, guys, for introducing yourselves. And Lauren, remember we said last week, we didn’t necessarily preface it today, but the average malicious actor is present in an environment for two-hundred-and-eighty-seven days before they’re known to be there, right? So, this whole idea of the dark web monitoring thing is that, we’re finding out in days instead of months when those credentials are compromised. We can, we can take action. So why is this important? You know, we’ve said some things about statistics. We’ve sort of said how this is happening, but what does it mean to folks? Why is it important from the perspective of your organizations and the security products and services that you offer?
Lauren Lev
OK, so we’re just going to toss the conversation around the room and we’re going to kick it over to Reg first. So, what are your thoughts on what exactly the dark web is? Why should our audience even care? And how do they plug in to mitigate risk with this vital best security practice?
Reg Harnish
I honestly was hoping to go last because I want to contradict everyone else. However, a couple, yeah, a couple of things. One, it would be the equivalent. So not understanding the dark web is kind of like the equivalent of not knowing where your meat came from. Not that it would necessarily change your decisions or your current behaviors but, but maybe it would. And so, you know, our perspective on this is that the dark web is, is one of many data points that we utilize when we’re managing risk for any of our customers. You know, my own perspective is and experience is that the dark web is not all that useful at times because a lot of the information’s dated. You’re sort of dependent on some of these dark web processors. You know, folks who were out combing through the repositories and the dumps to figure out what credentials are out there. You know, just because your credential is compromised doesn’t mean it’s going to show up in a report or an alert. And I think more and more providers are taking some precautions, whether it’s hashing or encrypting passwords and or just pulling these dumps themselves. But anyway, it is a good indicator for us or one of the things that we use to figure out if our overall program is working. Think of it as the exhaust from a vehicle, and we want to control that as much as possible. So, if you know, if we have a 25 person physicians practice whose credentials are showing up, you know, twice a week, that kind of gives us an indicator that something we’re doing is not actually working, whether it’s technology or process or human beings. It’s not the only indicator, but it is one. However, on the on the sort of false negative side, just because someone’s credentials are not showing up does not mean that they haven’t been compromised. And so, it’s, you know, I think. Too, too many of our customers are some of our customers, the dark web sounds sexy, the fact that we can comb through parts of it and alert on that sounds awesome. But I think it really it needs to be considered as a single data point that’s not infallible. That, but rather is one part of the equation when you’re when you’re building and managing a program and managing risk for an organization.
Matt Tankersley
That’s great feedback Reg. I couldn’t agree more. That’s why we have 21 best practices in our thing, and this is only one of those. Absolutely. Excellent feedback.
Lauren Lev
Yeah, thank you so much. We’re going to hand it on over to our contributing solution partners, and we’ll start with returning cast member, Sam Yip from IDAgent. Sam, what, why, and how of dark web? You’re up.
Samantha Yip
Perfect. Yeah, I mean, I’d like to just add, add on to what Reg said. The dark web, it does sound sexy, but what exactly is it? Right? I mean, you’re probably asking yourself that. So, I mean, here’s just a quick definition of what the dark web is. The surface web, what we kind of use on a daily basis, you know, Google and Amazon, that is about .04 percent of the web. The 99.96 percent is the deep web, which includes the dark web. And that kind of, that area is where government databases are, some of our health information, and other areas that we don’t actually go to all the time. And we kind of estimate that the dark web is about 500 percent larger than the surface web, that we use on a daily basis. And this is where our kind of all that malicious type activity you hear about kind of take place. But there’s also some good that takes place there. You know it is, it is also used for whistleblowers as well as, you know, countries that don’t have free speech to go ahead and communicate. But unfortunately, because it is anonymous, there is bad actors out there that are stealing our information and selling it. And like I said a little earlier, it is relatively inexpensive to purchase stolen information, compromised information, account information. Some of the latest ones that I’ve gotten my team of analyst to pull, Facebook accounts, they’re selling for about sixty-five dollars in the dark web. You got bank accounts that give you at least a minimum of $2000 balance, and that’s scoring for a hundred and twenty bucks. Pretty affordable, right for, for those cyber criminals, and that’s how they make their money. Our information is their commodity. Now, I want to point out that about 89 percent of the hacking incidents that we see today actually stem from compromised credentials. Probably the biggest one that we’ve heard of recently in, back in May, is Colonial Pipeline. That entire breach happened because of a VPN compromised VPN account that was sold in the dark web. That’s it, it was just one account to completely, completely impact the entire East Coast and the supply chain. So, I mean, it is definitely something that we need to look at and monitor. And what’s great about dark web monitoring is that it’s an early preventative measure. Think of it as an alarm system, right? Like Reg said, just because your information’s out there doesn’t mean that an incident might occur, but we need to know that it’s out there. You don’t know what you don’t know. So, to have that alert system, if we’re aware of a compromise and we need to change that password or even look out for identity, identity theft of our personally identifiable information out there, we can actually take action once we, once we know what’s out there.
Lauren Lev
Yeah, that was a really good explanation. And what stood out to me was you saying our information is their currency. That really made it hit home. Yeah, it’s like very lucrative.
Samantha Yip
That’s their, that’s their job. I mean, I’ll throw in one interesting fact out there. You know, our analysts polled a job post in the dark web and they were looking for a systems engineer, 10-years’ experience and they were going to pay them one point one million year two of their contract. Just think about the return that that individual needs to provide for the organization that has hired them. So, this is, this is a real business out there. This is a marketplace. This is how they conduct their business and this is why they want our information.
Matt Tankersley
And you know what, Lauren I implied this earlier, I think this is worth noting. In a prior conversation, I think it was in episode one, our VIP cast member, Jim Bowers from TBI. You know, he talked about a whole bunch of smart people, really smart people in an email for an event that was a company event of the event. And it was asking them, did they want fish, chicken or steak, right at this company event? It looked as legitimate as could be, and these really smart people, nobody thought twice and they clicked on these things. So, for our viewers that are listening, you know, how are they getting these username and password? There’s tons of ways. That’s a perfect example, it’s really one that clicked home. So, I asked him what was his choice? Did he get fish, chicken or steak? And then one of the guys said, Yeah, he got a mistake as well.
Lauren Lev
So Sid, what are your thoughts on the what, why, and how of dark web monitoring?
Sid Castle
All the what, I mean, I, I agree with everyone. It is something to be worried about and concerned, but it’s almost too much to think about. It’s like trying to figure out for the average user, how does the internet work? You look at what we use and how we interact, and that’s where we need to focus on our strengths as users, as companies and as partners, and then let the vendors, surround yourself with smart people like you see on this panel. Let them worry about more of the details, and we just need to know the surface of it. We need to understand, as Matt said, that that data is out there and that it often takes hundreds of days before they’re acted upon. So, if it’s if you get the alert, then you can act upon it and change it. Matt also made a really insightful comment about passwords and things. Use a password manager and I know we’ll have that in a later session, but no password should be the same. Every single instance should be different and unique. Tools like that will assist you and help you. We’re just one part. Password managers, identity access management, like LastPass does, is one part of a total solution. You know Reg’s company and Samantha’s company will do other things. Zane and I do similar things, but you need all of this together. One part isn’t going to do it alone, and MFA is an incredible tool to move toward when you get credentials out of the way. Now you get to steal my face, you got to steal my location, you got to steal a lot more data, it makes it harder. Reg mentioned salting, we hash, salt, and encrypt data. You should, no matter what you’re dealing with, if you’re working with data, make sure that it’s as such and then salt, hash, and encrypt your backup because once they land, they expand. They’re like termites. You think you got the one post in your house? Now they’re on all four corners, too, in a way just happened to be the one post you saw first. So, like Greg said, you may think there’s no termites, and then all of a sudden we find a few. You better look at all of your foundation because they’re probably everywhere.
Matt Tankersley
I saw you cringe, Reg when he said one of those things at the beginning, and it’s I think we were talking about passwords and complex passwords. And I know that you and I sit back every day trying to go, how do we eliminate a password as a threat in the first place? And we’ve got a lot of tools out there for that, including zero trust technology that we’re going to talk about in some future episodes. And that’s such a deep well, it’s why we have to dissect the conversation into pieces like we’re doing.
Lauren Lev
So, lastly Zane, kick it over to you. Thanks for shoring up the dark web monitoring what, why, and how conversation. What are your thoughts on this?
Zane Bond
No, it’s I think that the team here has done a really good job of representing what exists in the dark web, right? It’s the dark, the deep web/ dark web, its vast. There’s a lot out there, specifically when you get to the dark web, there are real use cases for it. You know, just like might’ve mentioned earlier, where there’s there are reasons for people to be out there. But of course, you know, adversaries exist there, too. So, when we start thinking about what to do with dark web and how to worry about it, it’s it really comes down to how does it affect me, right? There’s lots of stuff going on. There’s a lot out there. How does it affect me and what do I need to act upon? When a threat actor gets into your environment, they in that dwell time that you mentioned, there’s a whole lot of things they do. First, they find the data. Then, they start scouring it and gathering the data. They try to exfiltrate it. They try to understand, is this useful for you? Can I get some ransomware out of this? Can I sell it to somebody else? Can I do something? And it kind of evolves and evolves. And then at once they’re able to realize that they can’t get value directly from the vendor, then they start shopping around to other people, and that’s usually where it shows up in the dark web. Right? So, something that exists and starts showing up on the dark web. It’s probably well into that dwell time. But again, the fact that it goes out there, they try and sell it, try and make some money. Eventually they’re like, I can get no more money for this. Let’s just do a password dump and throw it out there because I’ve bled every dollar I can out of this. And that’s where even some of those lists are, the basement dumps. And those further get picked up later on, thrown into like big password stuffing attacks and things like that. So how does this affect you? How can that? How can that be negative? It’s really about when you have hundreds of credentials, hundreds of access, hundreds of things you get to, knowing that there’s a potential risk on certain items that is more risky than others. But it’s a decent catalyzing event to say, Oh, wow, maybe I should rotate this credential. Maybe I should make sure that it’s out there or if you get more and it’s like, Hey, my email address and this password has been breached by, you know, some website.com, see if that’s been reused anywhere. Because you know, the first thing or one of the things that certain attackers do is they just take the same set of credentials and throw it all over the place. And so, understanding where your credentials are, you know, are you reusing components and has it been leaked? Really allows you to figure out, alright, if I’m going to increase my security, where do I reduce the most risk? If there’s a known breach, if there’s a known password that’s out there, maybe that’s something I bump up on my list. But you know, Reg and Samantha both mentioned that it’s, it’s a larger picture. There’s a lot to consider. This is one aspect of it.
Matt Tankersley
And Lauren, I think it’s worth noting. Obviously, we’ve been helping clients to do this for some time now, right? And one of the things that we’ve realized is that when we, when we first introduce a client into the prospect of what exists for them today on the dark web, that’s the starting point. And we find out there’s this huge, these huge number of data points that need to theoretically be remediated. And I’m, you know, poor folks are sitting back right now going, I just want to know what it is. Now you’re telling me there’s work involved with this process. Well, that’s the value of the managed service provider, right? That’s part of, part of what we help you do. But it’s mind blowing, it’s amazing to me. Like we, the whole origin is things. If you guys didn’t catch this in earlier conversation in our media kit and episode zero one, we talked about the origin of the Who’s in Your Cloud campaign. And it was clients that we work with for a long time, consistently refusing to adopt best security practices and this passion to help them understand how we make that better and help them make better decisions, I should say. That was kind of the origin. And literally, these folks come to us once a week, once a quarter, asking us to reset their password to the exact same thing it was before. And they’ve been doing this now for a decade. And would you be surprised when I go run their historical dark web report and it shows that they’ve got 40 or 50 or 60 points of data out there, right? What I’m finding is that that report is helping them to realize, holy smokes, this is real. And I see that same password over and over and over again that’s been compromised that I use just again yesterday on my latest bank account. I’m seeing that as a, as a fabulous tool for them to begin to adopt these security practices that we’re talking about, starting with getting training, starting with right, monitoring the dark web, starting with password management. And in our case, the list goes on about twenty-one topics, right? But it’s a huge thing. And then the ongoing remediation is an important part, too. So, you know what happened yesterday and before, what do you do about what happens next week, tomorrow and so forth? That’s the, I think the value that we’re talking about with all of our partners here about the tools that they use to notify and communicate to us when those new instances are occurring. So, I don’t know if that’s helpful for everybody, but I think what we want to do next Lauren, and I’ll turn it back over to you is go around the room. Let’s ask each of our partners, what is it that you’re doing specifically to help people monitor and be smarter and be safer?
Lauren Lev
Yeah, Reg, why don’t you take it away?
Reg Harnish
Sure. So, for starters, we’re actually thinking about dropping our dark web monitoring service and replacing it with kind of like a poor man’s threat intelligence. Well, not a big fan of threat intelligence, either, because usually, you know, it’s not intelligent and it’s not very actionable. Even if you give someone perfect information about a, you know, a compromise or there’s chatter in the dark web, most companies can’t really do anything with that information anyway, but that’s a total. I’ll be back for the threat intelligence podcast.
Matt Tankersley
Soapbox. Yeah.
Reg Harnish
Soapbox. But I think, so I challenge anyone who suggests the dark web monitoring as a proactive or preventative measure because the compromise or part of the compromise has already occurred, or that information wouldn’t be available to cybercriminals. However, I think if you use it well, it can prevent further bleeding or further compromise, you know in that, in that chain. Because a lot of this compromise may come from just sort of run of the mill garden variety, social engineering and phishing, etc. And maybe that’s the pretext to a much bigger incident. And so, I think if you treat it that way it can actually be very productive, depending on your organization, the kinds of information you have, what your password hygiene looks like and a lot of other things. But our thought right now is, and especially given how the dark web has expanded, almost incalculably. Incalculably, can someone look that up, I’m not sure that’s a word. It’s really hard to figure out how quickly it’s expanding, but we know it’s a lot. And so, we know there’s a lot of data points out there, and if we can take that information and start to turn the time back a little bit so we can be more proactive, that’s really what we’re looking for. So, what we’re doing now is looking at how some of these, you know, dark web breadcrumbs can lead us back to chatter, search terms and expressions, other things that might be out there that are indicators of potential or future compromise so that we can be a little more proactive of further events. And that is kind of the way we see it right now. Again, you know, a lot of the searches because, you know, we’re using an automated, an automated service as well, and most things have become a bit of a commodity. But it’s very inexpensive, so we do it. But we’re looking at that how we, how we start to take another step backward in that and look at more data points and do a better job of being relevant and actionable. And I saw again, coming back to my initial comment, we don’t like charging our customers for stuff that they don’t get a lot of value out of. And when we, I’d say half of the time when we get in an event or an alert from our dark web monitoring service, it’s and we go to do, you know, conduct remediation, you notify the customer, et cetera. In many cases, that password has already been changed. In some cases, the password was changed a year ago, and we’re actually picking up indicators or breadcrumbs that are really, really dated. So, but what we do is we’ll conduct a more in-depth search now with a tool that we’re actually playing around with just to see if there’s ways that we can bring more, more data points to the conversation and something that brings greater value than just saying: Hey, listen, we found a password out there and there’s a 50 percent chance that it’s already been changed. You know, we want to do more for our customers. So, that’s, that’s kind of what we’re thinking about doing right now.
Lauren Lev
So Zane, how is your team equipping organizations to combat dark web risk?
Zane Bond
All right. I think there’s, there’s a couple of different components to this. When you, when you think about why do, why do customers, why do users, why do people in general end up with terrible passwords? Like, hey, I’ve got a password. Let me guess, your first letter is uppercase. Then you threw a number and a symbol at the bottom. Your symbol was probably an exclamation point and your number is a single digit one through nine. Right? And then everything in the middle is lowercase, probably some word relative to something, you know, family, pet, something. Right? There’s, there’s so many known patterns and terrible password usage. And when we think about why, you’ve got hundreds of sites you need to access. You need to buy stuff, you get your kids to school, you need to, you know, pick things up, check the status of your orders, log-in’s, social. All that. And there’s this huge cognitive load around, how do I remember all this? How do I even try and handle this? And that, that’s kind of the root of the problem is you have to remember all these things and it’s just easier to, you know, slightly change it or reuse that. So, one of the things we do is we try and break that and get you out of that, make it so that you can get to the information you need, get to your websites, get to your things and you don’t have the load of your password. You just, you know, look at your phone, you do your biometrics, your Face ID. And from there, you access what you want. You type in Facebook and hit go and it launches it. Now on the back end, there’s an enormous amount of, you know, encryption and alerts on dark web like have your credentials been breached and are you using terrible passwords and what’s going on there? But from that component, it’s allowing you to reduce that load. And then when you have time, we come in and tell you, like, Hey, of all these sites you’ve saved, of all the things you access on a day to day basis, these ones kind of have terrible passwords, which would be good to guess. Not a great idea. These ones have, you know, these credentials have been breached on the dark web, and we’re not saying that you’re going to get hammered or it’s going to happen. But out of all 300 things on your list, you know, maybe these five that are out there might be a good candidate to, to change to something else. And also, having somebody else tell you, Hey, I know your password and it’s this and it’s bad that that’s, that’s really a shocker. Like, whoa, I thought that was secret. I thought that was mine. And then when you see it, like out there, it’s like, Wow, OK, well, maybe it isn’t that secure. It really brings the, the thought and assumption of secrecy home, and it’s like, man, these breaches are ephemeral things where pipelines go down and companies pay billions. I’m like, Dude, that’s my password. I’m so not OK with somebody knowing that like, it’s something personal. That’s really it, right? It’s the awareness and the value of that showing it. And then the other thing is we, at least within our platform, we try to make sure that whatever we do is zero knowledge. So, even though we’re telling you, Hey, your credential has been breached, we have no idea. Like, we don’t go to a service and say, Hey, Bob, has all these websites tell me their passwords, right? It’s we have this whole other technology around making sure that everything we do, we don’t know. So even if we as a company do get breached, that’s not a problem because we don’t have your information, we have your cipher-text, we have the access to the targets you need. We have access to all the platforms, but you control your data and only you can decrypt it.
Lauren Lev
You don’t like the feeling of someone knowing your password. It’s kind of akin to knowing that someone has a copy of a key to your house. Yeah, they might not come in, but they still know it and they have the ability to sell that key, use that key, come in.
Matt Tankersley
How am I sleeping at night when I know somebody else has a key that I probably wouldn’t want to have in my house. That’s, that’s a brilliant idea. And so what I, what I heard there Zane is that, you know, you’re basically giving people the intelligence they need to make sure that their credentials aren’t showing up in the dark web in the first place.
Zane Bond
Exactly.
Matt Tankersley
I think that’s what I heard. And then you’ve got some alerting capabilities there that are of value to your subscriber sites.
Zane Bond
Yeah and it also ties into reducing the blast radius, right? If a credential gets breached, which is going to happen, it’s a completely randomized password that exists on one website, eh whatever. OK, I’ll go reset my Twitch password. They got breached a couple of weeks ago, right? Versus, oh wow, that passwords, on like eighty things. OK, this is going to be a long weekend.
Lauren Lev
Mm hmm.
Matt Tankersley
Right? Yeah.
Lauren Lev
Right, that’s a good point.
Matt Tankersley
OK, Mr. Sid, I can tell you, as a longtime user of LastPass, a current user of Keeper, we actually use both in our organization, right? We are, we’re big believers of using the technology that our clients use, right? So, we eat our own dog food. I can tell you, I’ve had many of those weekends that you just described because LastPass does a great job of as well as knowing, did you know you’re using all the same passwords here? So, Sid, give us your perspective at LastPass on what you guys are doing to equip folks to combat dark web risk.
Sid Castle
Great. I prefer drinking my own champagne than dog food. But that’s another discussion altogether.
Lauren Lev
Me too.
Sid Castle
Yeah, great. But as you’d heard, dark web monitoring is reactive, that’s after the fact that something’s happened and then you deal with it. And like you’ve heard from some others, we are very quick to get you that information and instruct you what you should do to change it. But really, you should be proactive in other ways with password management. And as you heard, Matt mentioned with LastPass and we have a security score, we can go in and help talk to you about what you’re doing and how are you doing it. What to change. I have over three hundred and fifty credentials, and my running joke is I know none of them. I don’t know-
Matt Tankersley
Absolutely not.
Sid Castle
I don’t know Facebook. I don’t know anything. I know two passwords and they’re master passwords for LastPass, and everything’s zero knowledge security based, salted, hashed to decrypt. So, the data is useless. Unless you have my decryption key, my master password, things like that. I used to duplicate a lot, and as Matt said, I thought I was smart. I was indexing things. I had twenty-five plus characters, upper lowercase like the FBI says, take a thousand years to crack it. Well, here’s the problem with that. My password was difficult, very difficult to crack or to discern. But I’m a big fisherman and boater. I buy lures from different places all around the world, from China, Russia, places like that, and they have passwords. And if I use the same password, which I used to have five iterations over three hundred and fifty credentials I’ve gotten a dark web alert a few months back about a password that has been changed probably three times since then. And it was useless, but it was good to see. And as Zane said, it’s very frustrating when you say, see it and it pops up, you know, like, Wow, that was the password I was using on my Chase account as well. Wow. Or it was one digit off. I can rent a password generator on Amazon for a few dollars, and I use the word generator loosely because that’s not what it’s for. But if I give it 98 percent of my incredibly complex 25 character upper lowercase, it can discern the few possible iterations that are left within a few dollars’ worth of generation. And then they could go in and start hacking. Now, if they get one site, that could be bad, but then we mitigate the loss. And if they, that’s where it stops, then we know what to do moving forward. But Dark Web is a great tool to see what’s happened and to help ensure you’re doing what you’re supposed to be doing. We don’t charge for it. It’s part of our products for our business products because we believe in it, but we don’t believe it’s something you should really be paying for. It’s something to help us make sure our other tools are doing their job.
Matt Tankersley
Sid, I love what you said about the not knowing your password thing, and I, I would aspire to having only 350. That would be nice, maybe in retirement. But it’s funny because I tell my clients all day, every day trying to soapbox this thing about the importance of complex passwords in particular so that they don’t end up on the dark web. Right? Is if I don’t know my password, how can the bad guy know it, right? So, it’s good to hear somebody say that besides myself and it’s a good tactic. That said, we’ve been saying the same thing to some of those partners or those clients that just still finally, finally coming around adopting some practices. And by the way, it’s that historical dark web report that really was the catalyst there
Sid Castle
Hey, Matt. I used to be IT, and people would come up to me all the time and say, Hey Sid, I lost my password. Can you reset it? And if I was in a bad mood, I’d walk away and go, I don’t know your password, man and walk away. And they’d have a heart attack and grab me, and say, Sid no, no, you got to help me. I said, do you understand that I never knew your password. I’m going to reset it to password one, two, three, and you’re going to reset it. I’m going to ask you, please, to not reuse whatever you had been using. And now later versions of Windows, I could enforce that, but back then I could not. But the thing is this, you own your password, you’re responsible for it. It’s your credentials. And if they’re compromised, that may not be your fault, but fix it, correct it and move forward.
Matt Tankersley
Well, Lauren, we talked a lot in the last episode about the importance of an organization from the top down having a culture of cyber awareness. Right? And we were talking, I guess, about security awareness training and that. And obviously in our context, we think that’s number one. We think this is number two. All of these are arguable priorities and points, but it becomes obvious that every one of these conversations about how intertwined they all are. Reg, you’ve clearly figured out, right? By, by and I love the creativity that you’re taking to the marketplace to re-engineer old things in new ways. Because guess what? As we talked about in another episode, the bad guys are doing that all day, every day. So we’re constantly behind the rest of these guys and we’ve got to, we’ve got to stay ahead. And I love what you’re doing, your team’s doing Reg to do that. In the meantime, we’re out there trying to keep people safe and doing things the old ways, we’re going to look to you to find ways to do them in some of the new ways.
Samantha Yip
If I could just add on that-
Matt Tankersley
Go! My bad, sorry.
Samantha Yip
Its okay. By no means is dark web monitoring going to save you from all of these security incidents, right? It’s not, right? I mean, what’s cybersecurity? It’s complicated. You know, you can look at the defense in depth solution and layering your security because you do need multiple. You need more than multiple layers of security to kind of protect you or at least try and protect you from a lot of these type of incidents. But for me, I like to know what’s out there. Like, Lauren was saying, Hey, if someone out there has a copy of my home keys, I kind of want to know whether or not they’re going to use it. I still want to know, right? It’s just like having an alarm system, right? Nobody breaks into my home. That’s fantastic. Thrilled, but I’m not just going to get rid of my alarm system because no one broke into my home in like the last 12 months, right? It’s still something that I want to want to kind of keep in check. So, it’s a great step. It’s a great step in understanding what’s out there. It’s a great step in understanding what that data and how that data can actually harm yourself personally and your organization as well. But of course, there are other security layers that Reg have mentioned, and the rest of the panelists have mentioned that we do need to take a look at and incorporate so that we can keep ourselves and our organizations safe.
Lauren Lev
We will wrap it up. Does anybody have any last comments about dark web monitoring?
Sid Castle
This is all about hygiene. This is all about learning the process and sticking to it because there’s ways around things we write things. You can defeat the process through Post-it Notes, all the old school things still, but you need to come up with a password hygiene. Use it, or identity access hygiene, use it personally, use it professionally. You know, I used to joke about things, and I used to use really good password, and no slams on anybody, but like SolarWinds123 when I was an intern and we saw what happened, but it’s all about-
Reg Harnish
Wait, you were the intern?
Sid Castle
Sure. And then I went on the dark web and got a job for 1.1 million, but they never paid me on my second year of my contract, so I came back to the white side.
Reg Harnish
Like anything else in cybersecurity, you need to be able to think critically about what it is that it’s doing for you. And it’s a system and you’re never done. There’s lots of complexities to cybersecurity and I think just given how available dark web monitoring has become, there’s nothing wrong with utilizing those, those services, especially if you have a way to make it actionable and relevance. What I would say just be careful not to get distracted by it either. And I had a few customers, or prospects I guess they were, who were talking to us specifically about dark web monitoring. And meanwhile, we offer like, you know, a dozen other really important things. And so, it turned out that they really weren’t a good fit for us because they saw a lifelong commercial and thought that this was going to be, you know, awesome. This is all, all they need. So, I think, you know, the ability to think critically about what we’re doing in cyber is really important and it’s no different with dark web.
Zane Bond
There’s value in dark web data, but finding ways to make it just seamless and actionable within your organization and having it drive good security behavior. If you can do that, then it’s awesome. If you’re focusing on why is my source code out there, it’s probably not going to be that useful and less actionable.
Matt Tankersley
Sam, final words?
Samantha Yip
Well, I absolutely agree with, with everyone, and I’m not going to be too long winded. I think it is necessary to monitor the dark web so that we can, you know, we can action what we do find out there. And of course, at that point I don’t, I still don’t think it’s too late. I know Reg, you might disagree with me, but I also don’t want to kind of hold you back from having that margarita. So, I’m going to say, Hey, I think you do need that monitoring and then we can we can look at how to prevent those credentials from going, to kind of getting out there and, and stop any malicious activity from happening to our organizations.
Matt Tankersley
Lauren, let me throw something out there and then let’s go ahead and let you close this out, right? So, Reg I like what you said about, I mean, if you read between the lines and hopefully most people aren’t deer in the headlights because they’re trying to learn about dark web. And I think the key message here is this is not the solution to your cybersecurity problem. This is a small part of the whole. And I do think it’s important we, you know, we sell a la carte cybersecurity services like dark web monitoring. I had one of our folks come to me an hour ago right before this conversation going, Hey, can I sell endpoint security to these folks? I, my first response was no, right? Because we don’t just sell endpoint security. We’re enabling poor behavior if we do that. We need to really understand their environment, what their needs are, what do they do with their business. And oh, by the way, endpoint security is one small part of what we’re going to provide them if they want to do it right. And if they don’t want to do it right, then we’re right back into where we started this conversation with clients not accepting or not adopting best security practices. That’s not a client that I can serve. I mean, they’re going to, they’re going to have problems left and right. So, yeah, Reg, we bundle that stuff into, as a small part, a small value added to the whole, right? And I think that’s an important way to approach the marketplace.
Lauren Lev
So that was such a great segment, you guys. We are so grateful each of you took the time to join us today. For all of our viewers out there, dark web monitoring, you need this and we are all here to help. So, connect with us at TechOnPurpose to get started or email learn more at WhosinYour.Cloud and a member of our cyber team will get back with you ASAP. A special thank you to all of our subscribers and viewers for following the Who’s in Your Cloud, 21 Steps to Secure, Reliable, Trusted Technology journey. I’m Lauren Lev, Marketing Manager for TechOnPurpose and coming up next week, we have episode three complex passwords and password management. So, we learned in episode one that ninety five percent of compromises were related to human error. Today, we learned the scary truth about compromised usernames and passwords available on the dark web. It should be no surprise that our next stop is related to complex passwords and password management. Sid from LastPass, we’re looking forward to you joining us for that episode ahead. And Zane from keeper, I believe we’re expecting Marcia Dempster for that episode as well. So, we are going to be excited to have you guys represented.
Sid Castle
Excited to be there.
Zane Bond
Absolutely.
Lauren Lev
To our viewers out there, if you you’re ready to claim your free NIST cyber security assessment, don’t forget to visit WhosinYour.Cloud to get started today. And remember, you can catch each episode of Who’s in Your Cloud by following TechOnPurpose on LinkedIn, Facebook, YouTube and Spotify. Or sign up for our blog to have episodes delivered to your inbox weekly at TechOnPurpose.net/blog. Thanks to everyone for joining us, and we will see you next week!
Ready for your free cybersecurity survey? Discover potential vulnerabilities for your business and get a copy of our #TOPcyber21 Best Security Practices to help get you started on the road to #secure, reliable, trusted technology!
Subscribe to our blog to get episodes of “Who’s In Your Cloud?” delivered direct to your inbox weekly.



















