Pular para o conteúdo
PodcastsTecnologiaThe Backup Wrap-Up

The Backup Wrap-Up

W. Curtis Preston (Mr. Backup)
The Backup Wrap-Up
Último episódio

366 episódios

  • The Backup Wrap-Up

    Endpoint Hardening: Closing Windows Before Somebody Climbs In

    21/09/2026 | 38min
    Endpoint hardening is the unglamorous work of closing the windows and locking the doors before somebody comes along and jiggles the handle. Prasanna, Dr. Mike Saylor and I walk through what that actually looks like: secure builds and golden images, which services to shut off, which ones to uninstall so a bad guy can't just switch them back on, USB lockdown, full disk encryption, BIOS and UEFI, and the phone in your pocket that logs onto your corporate Wi-Fi every morning.
    Mike opens with the analogy he uses in the book. Bad guys casing your organization are doing what a burglar does walking down your street — checking every door, every window, every garage. An unpatched box screaming its version number to the internet is a broken window with a sign on it.
    Then we get practical. Your receptionist's computer is running a web server she will never use. Your new Dell shipped with Xbox Game Bar running by default. Mike's point is that turning those off isn't enough, because an attacker living off the land will just turn them back on. Uninstall the thing.
    We also get into the argument nobody wins: locking down USB ports. Prasanna makes the end-user case, Mike makes the red team case, and we land on data leakage controls as the middle ground. Then Mike explains how he gets into a laptop that's suspended instead of logged off, and why your encrypted drive doesn't help you in that state.
    If you've been told you should harden your endpoints and nobody ever handed you the list, this one's for you. Start with one image, the lowest common denominator, and build from there. Don't let perfect be the enemy of good.
    CHAPTERS
    00:00 Your receptionist's computer is running a web server
    01:39 Welcome, with Prasanna and Dr. Mike Saylor
    03:52 The house analogy: broken windows and unlocked doors
    06:22 Do you just have to be safer than your neighbor?
    08:49 Assume breach, and close the windows anyway
    09:52 Secure builds and golden images
    13:37 One image for everyone, or one per role?
    14:39 Level one hardening: turning off what nobody uses
    16:20 Xbox Game Bar, and why disabling isn't enough
    19:07 The USB lockdown fight
    22:46 BIOS, UEFI, and malware that survives a reimage
    26:35 Full disk encryption only works if you log off
    29:42 Physical access trumps everything
    30:07 Port scans, Nmap, and banner grabbing
    31:50 Building your hardening checklist
    33:14 The endpoint in your pocket
  • The Backup Wrap-Up

    Least Privilege Best Practices: Where to Start

    14/09/2026 | 39min
    Least privilege best practices start with one uncomfortable question: does this person actually need this access? A hospital in Portugal answered yes for everybody, gave every employee doctor-level access to patient records, and got hit with a 400,000 euro GDPR fine. The court's read was that they hadn't even attempted the concept.
    Mike Saylor, Prasanna, and I get into what least privilege really means, then move straight to the part nobody wants to talk about: where you start when everybody already has domain admin. Mike lays out three approaches, from "turn everything off and see who screams" to a real analysis of job roles. We talk about why role-based administration is the vehicle that gets you there, and why role sprawl will eat you alive if you build a custom role for every human in the building.
    From there we get into segregation of duties, which accounting figured out decades before IT did. Your admin account should not be the account you use to check Gmail. That leads into non-repudiation, su versus sudo, and why logs have to leave the box and land in a SIEM before somebody edits them.
    The last third is action items. Inventory your privileged accounts, your service accounts, your support accounts, and the fire call accounts you break glass for. Track more than the name and the privilege level: who owns it, why it exists, when the password changed, when it expires. And if you run backups, split your roles apart. Editing backup configs, running backups, and doing restores should not be the same permission. Somebody quietly shortening retention is invisible to the person watching last night's job reports. A restore never trips an alarm at all.
    If your admins fight you on any of this, Mike has a thought about that too.
    00:00 The hospital where the janitor could read your chart
    04:26 The 400,000 euro fine, and the failed appeal
    07:50 What least privilege actually means
    08:54 Three ways to start when everyone has too much
    11:17 Access that follows people as jobs change
    12:57 Role-based administration is the vehicle
    16:13 Role sprawl and the 80/20 rule
    18:26 Segregation of duties, borrowed from accounting
    20:28 Back when everybody had root: su and sudo
    21:59 Non-repudiation and getting logs into a SIEM
    25:31 Inventory privileged, service, and fire call accounts
    27:41 The three backup roles you should separate
    32:39 What your account inventory should track
    35:31 Expiring accounts nobody uses
    36:42 When admins push back, be concerned
  • The Backup Wrap-Up

    Password Length vs Complexity: Why Longer Always Wins

    07/09/2026 | 33min
    Password length vs complexity isn't a close call. Dr. Mike Saylor joins Curtis and Prasanna to explain why the capital letter, the number, and the special character your bank demands do less for you than simply adding characters.
    Mike walks through the rainbow table project — an operation that has spent years computing password hashes nonstop and will sell you 20 terabytes of the results. Nobody cracks your password. They look it up. The catch, and the whole reason this episode matters, is that the project has only reached ten characters after all that work.
    The three also cover why some LastPass customers had their vaults drained and others didn't, where the 16-character recommendation comes from, how to build a passphrase you'll remember, whether forced password rotation accomplishes anything, and what happened when Mike rolled out fingerprint-locked laptops to fifty field employees.
    Get the book: Learning Ransomware Response and Recovery at stopransomware.com
  • The Backup Wrap-Up

    RDP Security Best Practices Every Admin Ignores Until It's Too Late

    31/08/2026 | 33min
    RDP security best practices come down to one rule most admins break on day one: that protocol has no business facing the internet. Dr. Mike Saylor and Prasanna Malaiyandi join me to break down why RDP earned the nickname Ransomware Deployment Protocol, who's out there scanning for your open port right now, and what to actually do about it.
    Here's the part that gets me. Every Windows box ships with this thing turned on. You didn't ask for it. Nobody handed you a manual. It's just there, running, waiting. Mike calls it a dollar store hammer — still a tool, still gets the job done, just not the one you'd pick if anybody gave you a budget. I call it a hack-me sign taped to your back.
    We get into how initial access brokers work, and it's less sophisticated than you'd hope. Somebody runs a Shodan query, gets a list of every exposed RDP service on the planet with IP addresses and device types, cross-references it against leaked credentials, packages the whole thing up, and sells it. Mike says the recon that used to take days now takes about 30 seconds with the AI tools floating around the dark net.
    Then there's the credentials-don't-even-matter problem. Default RDP traffic isn't encrypted internally. Mike walks through a routing table poisoning job where his team captured an admin's keystrokes going to a server. No login required. Just be in the middle.
    The back half is all fixes. Block the protocol and the port, not one or the other, because attackers will happily move to a different port. Check 3389 before you kill it — your database might be sitting on it. Enforce network level authentication. Put a VPN or a zero trust product in front, and Mike points out enterprise-grade stuff runs about six bucks a user now, so the "no budget" excuse is thinner than it used to be. Bastion hosts. Group policy. Monitoring at the endpoint, network, and firewall layers, with a governance layer on top so you know what's allowed before something breaks at 2am.
    Prasanna plays devil's advocate the whole way through and swears he isn't pro-RDP. Mike wears three hats and can't pick one. I have exactly one opinion and I'm not moving off it.
    CHAPTERS:
    00:00 Windows ships with a back door
    01:26 Welcome and my Facebook Marketplace weekend
    03:18 Why RDP means Ransomware Deployment Protocol
    04:46 What RDP actually does
    05:51 Blue hat, red hat: Mike's split opinion
    06:11 Does RDP deserve its bad reputation?
    08:10 On by default, and you can't fully kill it
    09:30 The back door nobody locks
    11:52 Does the cloud secure RDP for you?
    14:12 Who scans for exposed RDP, and how Shodan works
    17:10 Initial access brokers explained
    18:36 Vulnerabilities that skip credentials entirely
    19:08 Unencrypted traffic and stolen keystrokes
    20:38 The never-on-the-internet rule
    20:59 The network survival stack: VPN and zero trust
    23:22 Block the port and the service
    24:17 Stopping lateral movement once they're inside
    25:25 Network level authentication
    27:50 Port 3389: check before you block it
    29:44 Bastion hosts
    30:26 Monitoring, auditing, and governance
    31:19 Blue, red, and purple hats
  • The Backup Wrap-Up

    Phishing Resistant MFA: Regular MFA Isn't Enough Anymore

    24/08/2026 | 41min
    Phishing resistant MFA is the difference between a bad guy getting one email address and a bad guy getting your entire company's inbox. On this episode, Prasanna, Dr. Mike Saylor, and I dig into why plain old multi-factor authentication isn't the finish line anymore; it's the starting line.
    We open with a real attack: a vulnerable REDCap database, stolen Google Workspace admin credentials, and email forwarding rules quietly running for over a year before anyone noticed. From there Mike breaks down how social engineering actually works (the research bad guys do on you before they ever send an email) and why "report as phishing" buttons have themselves become an attack vector. I share the story of the free credit monitoring scam that got me, and why freezing your credit reports is one of the best five-minute security moves you can make.
    Mike then walks through FIDO2 and passkeys, why they're built on old-school public/private key encryption, and why they're transactional instead of just another code sent to your phone. We cover the Flax Typhoon espionage campaign, the Raptor Train botnet, and how hard-coded credentials on IoT devices turned into root-level access for a foreign intelligence operation.
    Then Mike introduces "killing the trust button," which is phrase for the idea that most networks default to open, and every one of those defaults is a decision somebody made without thinking about the risk. We talk about blocking traffic by country, limiting concurrent logins, expiring MFA tokens, and why starting with your administrative accounts is the easiest place to build momentum. And yes, we talk about just asking an AI assistant like Copilot or Claude to walk you through turning this stuff on, because you probably already have these tools and don't know it.
    We close on why MFA by itself still isn't enough — session token theft, MFA exhaustion attacks, and the "remember this device" setting that undoes everything you just set up. If you're the person responsible for an environment with important accounts sitting there with no MFA, we've got a name for that, and it's not a nice one.
    Chapters:
    0:00 – Cold Open
    1:31 – Welcome to the Show
    4:12 – The REDCap/Google Workspace Attack
    8:38 – Social Engineering: How Attackers Do Their Homework
    13:06 – Freeze Your Credit Reports
    16:55 – What Is FIDO2? (Phishing Resistant MFA Explained)
    18:58 – Flax Typhoon and the Raptor Train Botnet
    24:43 – Professional Malfeasance: No More Excuses for Skipping MFA
    28:05 – Killing the Trust Button
    32:51 – Start With Your Administrative Accounts
    36:36 – Why MFA Alone Isn't Enough: MFA Exhaustion
    39:27 – Passkeys, Impossible Travel, and Final Takeaways
Mais podcasts de Tecnologia
Sobre The Backup Wrap-Up
Formerly known as "Restore it All," The Backup Wrap-up podcast turns unappreciated backup admins into cyber recovery heroes. After a brief analysis of backup-related news, each episode dives deep into one topic that you can use to better protect your organization from data loss, be it from accidents, disasters, or ransomware.   The Backup Wrap-up is hosted by W. Curtis Preston (Mr. Backup) and his co-host Prasanna Malaiyandi. Curtis' passion for backups began over 30 years ago when his employer, a $35B bank, lost its purchasing database – and the backups he was in charge of were worthless. After miraculously not being fired, he resolved to learn everything he could about a topic most people try to get away from.  His co-host, Prasanna, saw similar tragedies from the vendor side of the house and also wanted to do whatever he could to stop that from happening to others. A particular focus lately has been the scourge of ransomware that is plaguing IT organizations across the globe.  That's why in addition to backup and disaster recovery, we also touch on information security techniques you can use to protect your backup systems from ransomware.  If you'd like to go from being unappreciated to being a cyber recovery hero, this is the podcast for you.
Site de podcast

Ouça The Backup Wrap-Up, IA Sob Controle - Inteligência Artificial e muitos outros podcasts de todo o mundo com o aplicativo o radio.net

Obtenha o aplicativo gratuito radio.net

  • Guardar rádios e podcasts favoritos
  • Transmissão via Wi-Fi ou Bluetooth
  • Carplay & Android Audo compatìvel
  • E ainda mais funções
Aplicações
Social
v8.18.0 | © 2007-2026 radio.de GmbH
Generated: 9/22/2026 - 8:37:05 PM