In short
Darknet Diaries - Episode 166: Maxie
Episode Overview In this episode, host Jack Rhysider interviews Maxie Reynolds, a professional penetration tester with a passion for adventure and physical intrusion. Maxie shares her journey into the world of cybersecurity, discussing her experiences, challenges, and the thrill of breaking into secure environments, all while emphasizing the importance of understanding an attacker’s mindset.
---
Key Themes and Concepts
- Maxie's Background
- Early Life: Grew up in Scotland, left home at 15 to pursue adventure.
- Education: Obtained a degree in underwater robotics, initially aiming for a career that would allow her to travel.
- Career Path: Transitioned into IT and cybersecurity, motivated by challenges faced as a female in a male-dominated field.
- Entering the Cybersecurity Field
- Initial Experiences: Maxie struggled to find job opportunities in underwater robotics due to gender biases but eventually landed a position related to cybersecurity in Australia.
- Penetration Testing:
- Definition: Simulated cyber attacks to test the robustness of security systems.
- Techniques: Emphasizes the use of Open Source Intelligence (OSINT) to gather information about targets.
- Adventures in Penetration Testing
- Physical Intrusion: Maxie details her experiences of physically breaking into buildings to assess security.
- Example: She impersonated a Swedish ambassador to gain access to a transportation company’s premises, demonstrating her social engineering skills.
- Security Breaches: During a test, she inadvertently shut off the water supply to an entire city, leading to tense moments with security and law enforcement.
- The Importance of the Attacker Mindset
- Attacker Mindset: Central to her philosophy, asserting that understanding how attackers think is crucial for building effective defenses.
- Book: Maxie authored *The Art of Attack: Attacker Mindset for Security Professionals*, aimed at helping security professionals adopt this mindset.
- Innovative Security Solutions
- Underwater Data Centers:
- Maxie discusses her project to create underwater data centers as a secure alternative to traditional data centers, which are vulnerable to physical intrusions.
- Advantages:
- Lower capital expenditure.
- Enhanced security from environmental hazards.
- Reduced maintenance due to the absence of dust and physical disturbances.
- Challenges Encountered
- Security Risks: Discusses the inherent vulnerabilities she has encountered during penetration tests.
- Legal and Ethical Considerations: Reflects on the tension between testing security measures and the potential for disruption.
---
Key Takeaways
- Passion for Adventure: Maxie's journey reflects a blend of adventure and technology, showcasing how passion can drive career choices.
- Social Engineering Skills: Highlighting the art of deception in gaining access to secure locations, underscoring the importance of psychological tactics in cybersecurity.
- Evolution of Security Measures: The shift towards innovative solutions like underwater data centers represents the need for out-of-the-box thinking in cybersecurity.
- Learning from Mistakes: Experiences of missteps during testing reaffirm the importance of hands-on learning in developing effective security practices.
---
Conclusion Maxie's story exemplifies the dynamic and often thrilling nature of cybersecurity, where technical skills intersect with creative problem-solving. Her insights into the attacker mindset and innovative approaches to security challenges provide valuable lessons for professionals in the field.
For more about Maxie's work and her book, visit [Subsea Cloud](https://www.subseacloud.com) and check out *The Art of Attack* on Amazon.
---
Additional Resources
- [The Art of Attack: Attacker Mindset for Security Professionals](https://amzn.to/4ojYSVZ)
- [Subsea Cloud](https://www.subseacloud.com)
If you enjoyed this episode, consider supporting Darknet Diaries to keep it running and receive bonus content!
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Transcript
Automatic transcript. May contain errors.0:00The Cardiff Giants is an interesting story. In the Bible, Genesis 6-4, it says, there were giants on the earth in those days, and they made it with people and created mighty men of renown. This guy named George Hall was like, wow, there were giants on earth. But the reverend argued with him and said, no, no, no, there were never giants here. But George was like, no, no, the Bible says so. There's got to be a way to prove it. But George could not prove it, of course. So he decided to fake it. He went to a quarry and dug up a huge block of gypsum, then hired some stone cutters to make the block into the shape of a giant man.
0:35They created a rough statue of a man that was 10 feet 4 inches tall. Then George stained it with acid to make it look old and put it on a train and took it to his cousin's farm in Cardiff, New York. And late at night, he buried it on his cousin's farm. A year later, his cousin went to dig a well and hired a crew to come out and dig the hole. And they ran into this giant in their dig. And one of the workers immediately shouted, this must be an ancient burial site. And so they dug up the giant and the word spread that they found a buried giant. People from all over flocked to the farm to take a look.
1:13It was quite surprising to see a petrified giant of a man. A lot of people believed it was a petrified human. The Bible says so, see? But some thought it was just a statue. But pretty quickly, George's cousin realized how valuable this thing was. So he put a tent over it and started charging people 50 cents to come in and see it. 500 people came a day to see this amazing giant. The whole town started to profit from it. Restaurants were filling up. Hotels were booked. And that's when P.T. Barnum came. And he was like, sir, I will give you$50 ,000 for that giant. What do you say? The farmer was like, no way.
1:50So P.T. Barnum hired someone to make a wax copy of it. and Barnum displayed this unauthorized copy at his circus and claimed it was the actual giant and charged people to come see his fake replica. A year later, George Hall came out and said this whole thing was a hoax, that he's the one who buried it there. But while it didn't prove that giants roam the earth, it did make his cousin pretty wealthy. And that's how scammers would get you in the 1860s.
2:23These are true stories from the dark side of the internet.
2:30I'm Jack Recider. This is Darknet Diaries.
2:51This episode is sponsored by ThreatLocker. Ransomware, supply chain attacks, and zero-day exploits can strike without warning, leaving your business's sensitive data and digital assets vulnerable. But imagine a world where your cybersecurity strategy could prevent these threats. And that's the power of ThreatLocker, zero-trust endpoint protection platform. Robust cybersecurity is a non-negotiable to safeguard organizations from cyber attacks. ThreatLocker implements a proactive, deny-by-default approach to cybersecurity, blocking every action, process, and user unless specifically authorized by your team.
3:24This least privileged strategy mitigates the exploitation of trusted applications and ensures 24-7, 365 protection for your organization. The core of ThreatLocker is its Protect Suite, including application allow listing, ring fencing, and network control. Additional tools like the ThreatLocker Detect EDR, storage control, elevation control, and configuration manager, enhance your cybersecurity posture, and streamline internal IT and security operations. To learn more about how ThreatLocker can help mitigate unknown threats in your digital environment and align your organization with respected compliance frameworks, visit ThreatLocker.com.
3:59That's ThreatLocker.com.
4:06This episode is supported by HIMSS. According to the National Institute of Health, as many as 30 million men in the U.S. experience ED. It's more common than a bad night's sleep. The good news? Hymns makes getting access to treatment simple so you can feel yourself again without distress or awkwardness. Hymns offers access to ED treatment options ranging from trusted generics that cost up to 95 % less than brand names to hard mints if prescribed. This isn't a one-size-fits-all care that forgets you in the waiting room. It's your health and goals put first with real medical providers making sure you get what you need to get results.
4:41Think of Hymns as your digital front door that gets you back to your old self. with simple 100 % online access to trusted treatments for ED and more. To get simple online access to personalized, affordable care for ED, hair loss, weight loss, and more, visit HIMSS.com slash darknet. That's HIMSS spelled H-I-M-S. HIMSS.com slash darknet for your free online visit. HIMSS.com slash darknet. Actual price will depend on product and subscription plan. Featured products include compound drug products, which the FDA does not approve or verify for safety, effectiveness, or quality. Prescription required.
5:18See website for details, restrictions, and important safety information. I want you to meet Maxie. My name is Maxie Reynolds. She grew up in Scotland and had an itch for adventure when she was young. She knew she wasn't fit for a sort of sit down, do a lot of paperwork, office type job. No, her head was always up in class, looking out the window, dreaming of faraway lands that she could visit. I left home at a really early age, about 15, and I had no idea what I was going to do, what I wanted to do. And so I tried everything and I was ending up working in bars and as a cleaner and all these sorts of things.
5:55I just thought, no, this isn't for me and I want a job where I can travel and see outside of Scotland. So I went to a university in England, which is somewhat treacherous, being a Scottish person. and I got a degree in underwater robotics. She was hoping this degree was her ticket to travel. Maybe if you're going to be operating underwater vehicles, you'll get to go to some pretty faraway places. So she started applying to every company she knew that used these remote operating vehicles. And I couldn't get a job. And it was because I was female. The reason why this was a problem is because sometimes she'd have to go out to sea in small vessels or be stationed on some kind of platform at sea, which also had small living quarters.
6:40And the problem was that these companies required men and women to have separate cabins. And they simply couldn't accommodate her because a lot of these cabins had four beds in them. And they didn't have any single bed cabins that she could be in. And there just wasn't enough women to fill up a sleeping cabin. So she just didn't get the job. I was told this same story over and over. But that didn't stop her. She kept applying at places. And eventually, a Norwegian company finally said yes to her. Finally got a Norwegian company to accept me. and they said, if you get your private pilot's license, we will take you on.
7:12So I went to a bank in Scotland and asked for a career development loan and I got my private pilot's license. Well, now this pilot is different than our V-Pilot. This is an airplane. Yes, this is a small, yeah. So I can fly a Cessna, although I haven't in America. I can do that. And so it was supposed to be quite similar. And then I called the company back and said, hey, like I've got this and it takes months. and I was getting further and further into debt. So I called them back and said, here, I've got this. And there had been this change of management and they were like, it's not actually, we don't know why they said that.
7:47It's not a private pilot's license you need for a plane. We're more like as an ROV pilot, it's closer to a helicopter. So I changed my name. I went back to the bank in Scotland, got another career development loan and went back and got my PPL for helicopters. Then I went back to them and said, okay, I've got this, but listen, no more surprises. Can I have a job now? And they took me on and it was sort of life-changing for me. This job required her to travel a lot. North America, South America, Europe, Asia. She got to travel the whole world while working as an underwater ROV pilot and sometimes flying helicopters.
8:27So I lived in Venezuela for a while. I lived in Trinidad. I have been to sort of everywhere from Nigeria to Australia, a lot of coastlines. I've seen a lot of water. While she was doing this work, she started getting more fascinated with IT. Computers became her passion. She was enrolled in remote learning courses and was able to get a degree in computer science. Then she took a month off work and landed in Los Angeles, California, just to take a break for a while. But she fell in love with LA. And while there, she started going to a gym to exercise and work out. One of the people that I was training with in the gym was a stuntman.
9:03And I sort of begged him to please let me hang out with you. Let me be cool too. So eventually he got me some training in stunts. And he actually got me one of my first jobs. She was in a few independent films, did a few stunts for them. She got an opportunity to be in House of Cards. And she does stunt for them. But they decided not to use it for some reason. While that was cool, it was also short-lived, because while it's exciting, she didn't see it as a long-term career. I studied quantum computing, and it was really difficult. It was extremely difficult for my feeble mind, but it was really enjoyable, and I loved it.
9:45This turned her attention to new technologies and companies. At some point, she got a job for a company in Australia and moved there. My first entry point into both social engineering really and pen testing was in Australia and I worked for a big company down there. They gave me a shot on their graduation team for cybersecurity. This company had penetration testers, people who try to break into a building or network to test the security of it. She got to watch one of these pen testers work by monitoring their activity through cameras. and I was witnessing a pen test, but with a social engineering component.
10:24And it was a guy, he was a really good hacker and he had gone into the network of one of our targets and he was opening all of the security doors and automated doors for one of the team, the cybersecurity team. And they were just walking through and they were filming the whole thing and it was being broadcast live back to us. And it was amazing. and I was thinking, okay, this is a good job. This is the kind of job that I would like to do. Being a physical penetration tester seemed like just the thing for Maxie. Breaking into a building, acting like a spy, that seemed really fun. She asked if she could do that.
11:02And they were like, well, your luck is in because we have to test them without these technical capabilities. So we're just doing a physical pen test. Would you like to be involved? And I jumped at the chance. So they gave her an assignment, which was to try to get into a company and film what they were working on inside it. And to start figuring out how to get in, penetration testers often use OSINT, which is just gathering data on a target through open public searches online. So she does a little OSINT and starts learning about the company more. They had some very interest in IP. They were a transport company and they were building some unique buses and large transport vehicles within this whole complex.
11:49So my job was to get into their past reception, past all security, get in and look at all of the assets and the IP. And I didn't need to, you know, hack any computers or even plug into any computers. It was simply to get in and to essentially have a look around. How fun, right? Can you get into this factory, take a few photos of what they're building, and get out without them knowing you're a spy? As she starts learning more about this company, she found out that they had some big connections with Sweden, as in some of their offices were located in Sweden. If you squint your eyes and you were very far away from me, I could probably pass as Swedish.
12:34So I had decided, and no one stopped me, I'd like to point out, I decided that I was going to pretext or present myself as a Swedish ambassador for this company. And I had the CEO's name and some other top execs' names and things like that. She does have blonde hair, but even though she may be able to pass as Swedish looking, there's no way she's going to sound Swedish. Not with that Scottish accent. So her plan was just to put ja on the end of everything and hope they didn't notice. No, and it gets worse because even I, because they're Australian, right? They're not idiots. So I was thinking that will never work.
13:15But that was her plan. And she decided to go forward with it. She liked the idea of acting like someone else. So she was set on being the Swedish ambassador for this company. Walk in, tell them she's from the Swedish branch and she's just flown in to inspect the building. But in order to do that, she's got to look the part. So she takes a trip down to a local clothing store, buys a new outfit, something that would make her look like an executive. I bought a clipboard and I looked professional and I had like a little briefcase and I was really trying to look professional. She's all set, ready to go in.
13:46Outfit on, camera rolling, deep breath. Let's go. So I go in to reception and I approach the receptionist with like a warm smile and I'm, you know, being as nice as I can be. and I said, I'm here for this. I'm here for this appointment and this is what I want to do and this is where I'm from. And she said, okay. And I was like, what? It was that easy? This doesn't make sense. But, you know, I'm not going to get in my own way. So I followed her and she took me to this little room just sort of directly behind reception. And I was greeted by this adorable little old lady and there was one other person in the room but we didn't really talk.
14:31So I had to present ID, which is another stumble and talk. And I got to talking to them. So they asked me why I was there again and all those things. And they said they weren't expecting me, but it wasn't a problem. And I thought, well, this is really easy. This is great. And I gave them my ID and I had an Australian ID at the time. And they said, you're from Sweden and you've got an Australian ID. And I said, yeah, and I've got a dodgy accent. I went to school in the UK, so I tried to get around it like that. and it works beautifully and I don't know how. So I got in. Okay, at this point she's doing pretty good.
15:07Passing as this Swedish person from another office. She got into the building, check. Passed reception, check. And passed the two people that she was handed off to. Check, check, check. Now she's in and she's trying to film things, take pictures of what's going on. There's an engine room. That looks interesting. Film that. So she goes in closer to take a look. and I was walking towards one of these large engines, and this man was walking towards me with, I think it was like two other men, and he stood out. He had this beautiful blonde hair and these big blue eyes, like completely stereotypical Nordic look, and he came up to me, and he said something in a language I don't understand, but immediately guessed correctly, this is Swedish.
15:57I'm supposed to be Swedish. I don't know any Swedish. So I'm racking my brain for the limited amount of Norwegian that I know. And whatever he said, I kind of just looked and I felt my body get tense. And I felt like my brain say, get him to open up, let me cannonball into hell. This is torture, please no. And so I said, yeah. and he looked at me like okay maybe that that doesn't make sense but okay and then he repeated it and so I tried the one word I could remember in Norwegian which is nigh for no because if yes didn't work then maybe no would which was maybe one of my dumbest moments but um so then he quickly just understood, like, this isn't right, and then security was called.
16:51They had a very prompt security team. They came, I was detained. Oh no, she was caught. This is every pen tester's fear. But just because she's caught doesn't mean it's over. Maybe she can somehow get out of trouble, convince security that everything's fine, or at least just try to leave the building without being caught more. She tried to change the story. No, no, I'm not from Sweden. I'm just working with the Swedish team. I'm based in England. So they asked to see her ID again, and it just wasn't checking out. They were very confused by the whole thing. At that point, she just couldn't see any way out of it.
17:27So she pulled out her get out of jail free letter. This is a letter that all penetration testers have that gives them authorization to do what they're doing. It has a phone number on it, which is typically the head of security and says, who actually authorized her to sneak in? So they called a number on it. And the head of security says, yep, this is all a planned test. Good job for catching her. We had like this sort of laugh after that. And even the security guy was like, why would you pretend to be Swedish? I was like, I don't know. I'm Scottish. He's like, I can tell. And you don't look Swedish.
17:57I was like, I know. That was Maxie's first pen test where she tried to break into buildings, but she loved it. This was adventurous, adrenaline-fueled, you need to keep your wits, be quick on your toes, and know all about computers all at once, she felt like this is where she was meant to be. This was cool, and decided to pursue a career in pen testing. She did a number of penetration testing engagements while in Australia, learning new techniques and getting official training on how to get better, reading a bunch of books on how to improve. And one of the things that intrigued her was thinking like an attacker.
18:29That attacker mindset was something she spent a lot of time thinking about. How do people with bad intentions act? Soon it was time for another penetration test, still while she was working for a company in Australia. The company I worked for was working with the local government in the city that we were in. And I won't say the name because I don't want any further embarrassment. Now, penetration tests are not always physical. In fact, I'd say most of them are just done over a computer. Like the penetration tester might be outside the company and just trying to hack their way into the company through the internet.
19:01or sometimes companies will just invite the penetration tester right into the building and give them a desk and a network jack and say, go for it from the inside. Because even if you get into the network, there should be layers of security which should still keep you from getting into important things. That's called defense in depth. So this was a pen test on a local government office. And with this one, they invited her to come into the building and plug into a port and see what vulnerabilities she could find from within the company. She wasn't alone on this one, though. There were two other people with her.
19:33And the two other people were very experienced network penetration testers. And she was still learning how to do this. So she was shadowing them and watching what they were doing.
19:44So I wasn't a noob, but this was my first job in cybersecurity. I have a very technical background. Building ROVs, flying them or steering them, I suppose. That's all technical. even stunts are technical to a certain degree. This was a step further because there are no physical components to it. That's why it was so difficult for me. It's all on screen and Linux is its own beautiful, scary world for me. So I was still getting to grips with this whole world and all of the commands and what these things meant and how to undo things. And they all sat down, pulled out their laptops, and plugged into the network.
20:29She starts by firing up a network vulnerability scanner. I got to run the Nessus scan, which was not the most technical job in the world, but it felt good at the time. And I got to look at what vulnerabilities were there. And I got to go and see exploits for those. And I got to run Nmap. These are fine basic tools to start with. It'll scan the network for known vulnerabilities. They're easy to use and typically benign, as in they're not going to cause any trouble on the network just by running them. And when you run these tools, it's not hacking. It's just to try to find what's hackable. And she wasn't exactly sure how to hack into this company.
21:10When you're around experienced pen testers who love their job, and these two loved everything. Every line they wrote was sort of like a piece of art for them. They loved it, and they really got this high out of it. And that's contagious. So I started to think, like, this is amazing. This is so cool. Look how far we're in. And one guy, one of the guys that I was there with, got a call from one of our points of contact. And he was saying, I can see you in the network. And it was this big game. And it was fun. And it was interesting. And I got caught up in that. So after seeing all the cool things that those other penetration testers were doing, Maxie wanted to have some fun, too.
21:51How far could she get into this network? She saw there were vulnerabilities on certain systems. on her scan. She tried to exploit those vulnerabilities and get into those systems because there's a sort of high you get from getting into a computer when you shouldn't be able to. And she was making progress. She got into a few systems and she was looking around, making notes on how she got in. She would look over her shoulder and always see those other penetration testers many steps ahead of her. So she kept looking around to see what else she could get into. I found my way to some internal environment and I hit the kill switch on a city's workplace.
22:33She accidentally typed the wrong command into the wrong computer, which controlled the flow of water to the whole city. The person I was with immediately saw within the network that wait, that wasn't right. I will assume that he was sort of with me, like following me throughout the network and could see a lot of what I was doing. And then I was thinking, yeah, this isn't, I don't think that was maybe good, right? And so I looked at him and I could sort of see on his face and he comes over to me and he says like, what did you do? And I, you know, you can look at your history quite quickly and I still had quite a lot on screen.
23:12I showed him and he put his head in his hands and I was like, is it really bad? It was really bad. Shutting off the water to the whole city. Showers, faucets, sinks, even toilets were not functioning citywide. Her two other penetration testers immediately tried to figure out ways to fix the issue. One was looking at how the system operated and if it was possible to just turn it back on. But you don't want to just do that if it's going to cause a problem. The other pen tester immediately phones the point of contact, letting them know this is a major problem. Maxie was sort of in shock and incredibly embarrassed.
Read the full transcript
23:44She took her hands off the keyboard and just waited. I was detained by security guards, and they were not very pleased. Now, this is a completely different situation from the last time she was detained by security. The last time she had a get-out-of-jail-free card. This time they knew that she was supposed to be there. In fact, it was her point of contact that called security on her. She was authorized to be there and do this, but this was not supposed to be disruptive to the organization. Not only was it disruptive to the organization, but it was disruptive to the whole town. So they wanted to at least get her recount of the matter recorded, so they had it for later.
24:22I go down to a windowless room, and I'm questioned. And all of a sudden, one of the sort of accusations, if you want, was that I was a Russian spy. I was thinking, how did we get there so quickly? Like, what happened? Apparently, she spoofed her IP at one point to make herself look like she's coming from Russia. to try to test to see if they could detect that. But that was just very brief. And she was definitely not a Russian spy. But this was becoming scary now because it wasn't just a confession of a mistake she made. It was like they were treating this more like an investigation. So I was held there for like a couple of hours.
25:00And of course, the police were called. The police had to be called. I didn't have any idea on me. I had my work card, but that doesn't really matter because it's just a photo I could have printed it myself. and I kept saying to them, you know, if you let me go back to my apartment, I can get my passport for you. I'm British and I'm not a spy and you can contact my employer and I'm actually here with two people and I kept going and they didn't want to hear it and that's okay. That's kind of their job to do, to not believe me and to, you know, look for the worst because they've got to protect themselves against the worst.
25:35And eventually that at some point I said to them, like, I need a quick, I have a glass of water. And the look would have been enough to like, you know, turn most people to stone. I was thinking, yeah, that was not an ideal question. And then eventually my employers at the time called in and it did get sorted. And I narrowly escaped, essentially what we do, I think you would call it prosecution. I escaped any legal action because of that. and I was on the graduation team. So that lent me some credibility in the fact that, okay, she doesn't know what she's doing and it's okay. And my employer didn't fire me and I will be eternally grateful for that.
26:28She doesn't know how long the water was out that day. It could have been hours, minutes, seconds. It doesn't matter. The fact that it could be shut off and it did get shut off, is why the police had to respond. But she narrowly got out of serious trouble from that one. But this sort of baptism by fire is how we learn the most important lessons in life. I mean, knowing firsthand what kind of true power a penetration tester has is profound. And this feeling sometimes flips back and forth too. Sometimes you feel completely blocked with no access to anything, and it makes you feel dumb. And other days you feel like with a single keystroke, you can wreck this entire business.
27:05It almost reminds me of visiting a barber and getting an old-fashioned shave, the barber has this razor, and they're shaving your neck with it. You feel very vulnerable in that situation. And I think many companies do feel vulnerable when they allow a penetration tester to come in. Who knows what they saw or took? In my last job, we had a penetration tester come in and see what they could do, and they were able to crack 25 % of all our passwords company-wide. That's like thousands of passwords. Of course, I read the report to see whose passwords got popped, but it only contained statistics, not passwords or usernames.
27:40And it made me think, you know, this pen tester is walking out of our building with a bunch of our passwords. I've never felt more vulnerable at work before. We're going to take a quick ad break here, but stay with us because Maxie's going to tell us about a penetration test story that changed her life. This episode is sponsored by Rippling. HR teams were promised modern tools but ended up with a stack of disconnected apps. Onboarding, payroll, benefits, compliance, all in different places. That's not SaaS. That's SAD. Software as a disservice. It's time to spend less time on checklists and more time on strategy.
28:18It's time to run on Rippling. Rippling is the unified platform for global HR, payroll, IT, and finance. They've helped millions replace their mess of cobbled-together tools with one system designed to give leaders clarity, speed, and control. By uniting your employees, teams, and departments in one system, Rippling removes the bottlenecks, busy work, and silos your software created. With Rippling, you can run your entire HR, IT, and finance operations as one, or pick and choose from the products that best fill the gaps in your software stack. And right now, you can get six months free when you go to rippling.com slash darknet.
28:53That's Rippling, spelled R-I-P-P-L-I-N-G. Learn more at rippling.com slash darknet. That's rippling.com slash darknet for six months free. Terms and conditions apply.
29:09Making some big mistakes on past pen tests did not make Maxie back down from pen testing. Instead, she doubled down. She was fascinated by the power of the pen tester. But more so, the attacker mindset allured her. But she had to leave Australia. Well, yeah. So I'd come back from Australia. My visa had run out, moved back to the States. my model in life is like if I'm free to do it and I want to do it then I will do it I kind of always want to be infatuated with what I'm doing and focused and I'm okay if whatever the thing is that I want to do changes and it has obviously but I want to love what I do because functionally right well I'll live for 70 years maybe I'll live to 90 but functionally I've got max 70 good years and I want to do, well, we might do two interesting things a year.
30:00So I've got 140 interesting things that I'll do in my life. That doesn't sound like a lot. So I just always wanted to do the things that were most interesting that would give me the most sort of interesting, exciting experiences. And for her, the thing that excited her the most was red teaming, penetration testing, social engineering. Physically breaking into buildings was just a thrill to her. So she looked for more jobs doing that. So I was hired on a sanctioned red team contract to test this high security logistics company. And there were two testers that were booked. It was a large company, but they wanted the two of them to try to get into one of their satellite warehouses.
30:37They told her, look, there's a locked fence around this whole property. Security alarms are on the doors. There's security cameras watching the whole property. There's active security patrols at night. And they just wanted to prove that she could get to them. They didn't want her to do anything to those machines. And they gave her a little USB device and said, hey, if you can actually get to it, plug it in and take a picture that you got there, and this will prove that you made it. Because presumably, if somebody wanted to get a customer list or shipment list or whatever, it would be just as easy for them to plug in a USB device, grab the stuff, and unplug it.
31:09So they asked her to see if she could do that. So her and her co-worker take a drive out to this facility during the day and just drive by, just to look at the place. And driving by is too quick. You can't see anything. So they decided to get out and just walk down the sidewalk and go around the whole property just to see what they can notice. Any points of entry? Are there any areas where the cameras aren't pointed? When we had kind of gone around, the very edge of the perimeter was like metal fencing, like chain link fencing. So the chain link fencing had just, it wasn't, it was years old, probably decades old.
31:48and so it was a bit rickety so you could just kick the edge up so we knew that. They took some other notes and got an idea of what the place was like. There's a two-story warehouse building with loading docks and sort of two parking lots, one normal one with big transport trucks and cargo trucks and a second one that had a chain link fence around it with many more of those big cargo trucks. We're talking eight-wheelers here. They're big trucks. This warehouse would load stuff onto them and then they'd deliver it. So they leave and decide to come back at 9 p.m. But Maxie's co-worker called her up.
32:23He's like, I'm sick. And I was like, I hate you. I know you're not sick. You're hungover. But anyway, last minute he gets sick. So the scope allowed for a solo run. So I was like, I'm going to do it. She waits until night and then drives back to the facility at 9 p.m. By that time, the place was all closed and there should be no workers there. And just those security patrols that she was told about. I then parked behind a tree line outside of the logistics park. I was keeping away from, you know, the lights. I was staying where the shadows fell at night. Okay, it's go time. I like the quiet approach of being on foot myself too.
33:02You can hide easier, change directions more quickly, be more stealthy. So come up through a tree line, off to the side of the whole complex, Moving pretty slow. I'm far enough from the walls to see the whole facade. I'm close enough to spot opportunities, and I do the usual first pass. I don't force anything. I don't touch anything. She passes by the building. The classic first pass gives you plausible deniability, right? If you don't touch anything or don't go on the property, you can just say you're passing by if anyone asks. But it's quiet. There seems to be no signs of life inside. No noise.
33:41No doors open. No lights on. There were a lot of trucks in the parking lot, but all of them were dark and quiet. No regular cars there. But surprisingly, she didn't see any security patrols. So since she's around the back of the building, she starts jiggling doorknobs and windows to see if any of them will open. And everything obvious that you would look at to gain entry was a no. So doors, no. Hatches, couldn't see them. Grimmed windows, they didn't open. they were just double pane windows um so yeah so you know good security is frustrating in some sense um but it was this like corrugated all of the warehouses in the area were these corrugated sort of um steel structures or metal structures and this the warehouse I had there was sort of this grass alley in the back at the back of it and um its neighboring warehouse also had stacks of pallets so there was just these stacks of pallets all the way like through this almost alley and there was this high stack of pallets that kind of touched it was within four three four feet of a second floor window there was just this little it was like a little rectangular window but it was open and I was like oh that sounds like a great way to get in there so kind of moved a couple of pallets start to climb up these other like this other high stack of pallets um and most of them have kind of been um like secured to one another so it's they're still a little rickety it wasn't like I wasn't feeling very confident that they wouldn't crash to the ground but they didn't I'm you know pretty light on my feet I'm built I am built for speed and not power so I do end up getting to the top poke my head through while the building looks two stories tall it's really just a single story but just with really tall walls so when she looks down it's straight down all the way to the warehouse floor that's not good that's too high to jump down so she looks around and notices that the walls are made of like a lock board it is essentially it's pegboard so pegboard is basically if you aren't familiar it's steel or aluminum sheeting and it's got this regularly spaced like square or round holes that you you basically put on walls and warehouses usually and then you hang like heavy tooling on it so i'm looking at this lockboard pegboard and i'm like all right well climbing down it you know gravity is your friend so it's like fingers in and I got my little sneakers on and I actually get down.
36:35It wasn't as difficult as you'd think. Okay, she did it. She got into the building. Nice. Now her objective is to simply see if she could get into those computers in the building. So she looks around for them. They were easy to find since the monitors were on and they were glowing in the dark. Get to the terminals and they're all open. It was beautiful. You know when in movies they're like, ah, like the heaven's light. I was like, this is great. So yeah, they were all unlocked. And so I connected this approved device. I snapped the required foes, you know, proof I could touch one attack I would want to touch.
37:15And then I fell by the exit. And I was like, I looked at the pegboard and I was thinking, well, because climbing up is a little bit different than climbing down. Okay, so climbing out the way she came was not going to work. She looked around for another way out. there are a lot of doors. She's inside. She could just open one up and walk out. No, wait, hold on. That's not going to work because there's security alarms. And she looked around the doors and yes, they were armed. Okay, scratch that. You can't open those doors. It would trigger noises. And since she hasn't had any security on her yet, she doesn't want to get their attention now.
37:46So she looks around for other points of exit. It was a loading door that wasn't in the best shape. So a loading door, like a dock where the truck backs in so it can get whatever the load is. it can it can get into the warehouse and you don't always need a forklift and so on so forth so it was um it was it was essentially that so it was on a pulley system and it wasn't attached to an alarm which was mental for what they you know for how secure they want it to be um so yeah so I I kind of it was a little bit buckled at the side and maybe that's why it wasn't on the alarm I'm not sure but a little pulley system pull the chain up just enough to sneak out and I get back to my car through a forest which is by far by the way the worst part of the story for me because I do not like insects but um so yeah so then I'm back to my car or I think I'm roughly back to my car and I phoned my point of contact and I report what is a success I got in, I've managed it, I've got the photos, I'll write you a report.
38:55And he listened and he was like, I want to issue a scope change. A scope change? This means the client wants to change what he wants her to do? I guess he was impressed that she was able to do everything he tasked her with and wants her to try more? So he says to her, you know all those moving trucks in our parking lots? See if you can steal those trucks. And she's like, I don't know how to hotwire a truck. And he's like, no, no, no. See if you can find the keys to any of them. And if so, take them. And I was like, all right, let's do it. Because 140 interesting things in my life, this might be one of them.
39:30She walks back through the woods, cursing at all the spider webs that she comes across. And then looks at the facility. There are a lot of trucks here. And they're the big trucks. Like, they're long trucks. You know, they've got 20 to 40 foot containers on the back. and I've never driven one of them. Some are parked inside the fenced area and some aren't. She starts with the trucks that aren't in the fenced area. Step one, see if the door is unlocked. The first one she tries, the door is unlocked. Whoa, so she opens it, gets in the driver's seat. She looks at the ignition. The keys were not there.
40:03But to her surprise, the key was sitting right there in the cup holder in the center console. A little bit humorous. I'm like, eight billion people on the planet. I'm the best driver, so what I'm going to do as I'm going to move all these trucks. I'm not going to worry about it reversing that truck. I was like, I'm going to have to leave this here because I'm not going to be able to do this. So yeah, so I took them up just other end of the cul-de-sac almost. It was like a little sort of quiet area, a little logistical parking spot, I guess. So I just parked them all up there. She parked it about a quarter mile away and then ran back to get another truck.
40:41The keys were not consistently controlled. And the fleet wasn't consistently parked on the inside of the secure perimeter. So basically, it just became this live demonstration of risk. One after another, she was able to find keys for these trucks. So when a driver comes back to this area and it's past hours, they sometimes leave the keys, like they'll leave them under mudflaps or just actually inside of the truck. It was incredible how many keys she found in and around these trucks. Sometimes they were still in the ignition. Sometimes they weren't on the seat. Sometimes they were in the, you know, the visor, the sun flaps.
41:17Sometimes they were in the mud flaps. And sometimes they weren't there at all. Some trucks were locked and she couldn't get into or move them. She thought about climbing back in through the window of the building and looking for the keys inside. But she already proved she can get in there. Maybe it's just better to try another truck instead. After taking the ones from the unsecured parking lot, she wanted to get into the fenced area and try to take one of those. She remembered where you can lift the fence up and get in there. So she scurries under the fence and looks at the trucks inside. Sure enough, same story.
41:46Keys were typically in and around the trucks there too. So she hops in one, finds the keys, starts it up and starts to drive out, but realizes, oh wait, this fence is locked. She gets out, looks at the padlock. She thinks about picking the padlock. That did not work. And I was like, I bet there's a key for this someplace. And I'm thinking, do I go back inside? Do I climb up the pallets, climb down the grate and look for the keys? and I was thinking, you know what? This is probably proof enough. This is bad enough because the report is going to say, well, I couldn't break into your secure perimeter.
42:18Why don't you park your trucks in there? By 2 a.m., she had stolen a bunch of trucks and felt like she accomplished the mission. Security never stopped her. There was no what around all night. So she goes back to her car and calls her point of contact and says, she stole the trucks. He's like, wow, okay, great. Hey, can you come into the office in the morning and tell us how it went? She's like, sure, but let me sleep first because I'm exhausted. So she goes home and then the workers start coming to the warehouse in the morning. Day shift did arrive and they didn't notice anything was wrong for like a fair amount of time.
42:55When I think it like how I would say it maybe is it took a beat for the penny to drop for them. And yeah, headquarters finally called and my contact, I think, walked them through the findings. and eventually we gave a report and, you know, where was security? They're supposed to have 24-hour rolling security. Where was it? Because I didn't see them. Like, why were there pallets? Why were there unlocked windows? Why weren't the loading base connected to the alarm system? Things like that. Like, it was, you know, treat keys like access badges, not souvenirs. Did you have to give like a debrief to that facility and say, hey, by the way, if you're wondering what happened, let me tell you.
43:42Not to the facility. So I didn't go back to that facility. I gave it to my, like to their headquarters, essentially. We went in and we gave a presentation and a report. And, you know, as is always the case, people's sort of mouths drop. And I think their tummies probably drop too. they're like how has this how has this happened sort of thing but it's another thing to be like wait who did this? we hired this person Max to do it this guy Max it must be a jerk to be breaking in and all this and then if you were to actually show up and be like hi I'm Maxie and I'm the one who stole all your trucks I'm so sorry you have to be soft with them like well maybe that's just personality maybe that's a preference of mine but stylistically I think be soft with them they do not know for the most part that our industry exists yes they know that there are you know bad actors out there but they don't know that some of us are making a career out of it and you have to go in and you have to be soft it isn't their fault there's that's what it is to run a company not everything's safe you can make it a little harder for people but that's our job to tell them and I just think tell them that in the most direct but soft way possible it's not a blame game and so yeah I went to headquarters and I was like hi guys I think you might have heard what happened and like so now on my resume I've got you know expert climber and truck driver she did a lot more penetration tests and got so serious about it that she wrote a book called The Art of Attack, Attacker Mindset for Security Professionals.
45:29Yeah, well, here's what I'd say about my book. I'm going to explain it. If you don't like the sound of it, just buy it for somebody you don't like. If you do like the sound of it, it was on me. You should buy it. It'll be great. No, in all seriousness, it's called The Art of Attack. And its central argument is that in order to design defenses that truly work security professionals must adopt this quote-unquote attacker mindset and its basic position is that simply focusing on tools networks or policies is completely insufficient it's necessary but it's not sufficient so understanding how an attacker thinks how they strategize manipulate persist is fundamental to building resilient systems and I would probably finish on it by saying the skills of a good attacker are the same skills that a I want as a person going through life normal life also the things I would teach and will teach to my children like grit determination we're goal orientated we're resilient so forth so on they They are cognitive skills that we need and how you apply them is what matters.
46:48And that is basically the premise of the book.
46:54Somewhere in her life, she went on a penetration test that changed the whole trajectory of her life. It was probably the most highly strung, you know, tensioned job of my career. It was for a company that we've all heard of and that we all use. And we had their internal red team accompanying us. This company had a big data center, and they wanted to see if they could get unauthorized access inside. Now, I don't know if you've ever gone into one of these data centers, but sometimes these things are extremely secure. I've seen them where there's like a big fence around the company, and just to get into the parking lot, you have to go through a gate guard.
47:38and they'll check your ID and make sure that you're authorized to be there. And then when you finally park your car and get to the front door of the building, the front door is locked. And so you need a badge to get in. Forget about any open windows. They don't open ever. Then upon walking in, there's a security guard watching what you're doing, but you're only in the lobby. You're not even in the data center part of the building yet. To get in there, you need a second key. And sometimes you do an eyeball scan to verify your identity. And there are man traps, meaning there's only one person allowed through at a time so they can check you.
48:05Then once you're in the data center, there's sometimes a cage around the server racks you need to get to. And you might need a third key to get into those and maybe an extra form of identification like a fingerprint scan or something. In short, it's extremely hard to sneak into a data center. There are actually, on this job, armed guards patrolling this perimeter. And there are vehicles that are scanned for anomalies. It is a very, in terms of security, a very robust comprehensive site. and you know inside everything it's a data center everything is controlled temperature humidity are controlled to the decimal the power and the fiber run through they're redundant there's blast proof like conduits every corridor every door every bite is sort of like a log but once you're in you're in and nation state actors will will get in and they're willing to do what it takes.
49:01And so that was our job. Well, she decided to try going right in through the front gate. So she just drove her car right to the security checkpoint and acted like she was supposed to be there and talked to the guard. Hello. Yeah, we're visitor. Yeah, like, hi, can we, you know, we're here to do this. Because you're also can find you some of those entry points. Like if they're doing immersion cooling, we know there is maintenance required on immersion cooling for the fluid, for instance. So you go up and you're like, here, we're here to do this. And you, some sites that will work and they'll be like, oh, okay, let me just tell the right person or here, wait, here.
49:38They were like, you're not on the list. You're not coming in. Okay, so there's a list. This is a clue. Maybe she could get on that list. Who maintains that list? What if she called acting like the maintenance team and says they have to do a fluid change or something and they're coming out? So we had tried to get on that list. We tried to call ahead. We tried to spoof phone calls so that it looked like Like we were calling from hopefully the right point of contact. It wasn't working. There was too many checks. They were comprehensive. They were robust. They were sharp. And so we're like, how are we going to get in here?
50:12And it's like, you know, sort of a bit like they've built a wall. Do we dig under it? Do we go over it? Like it wouldn't have mattered. It was the sensors, the security. They were on top of it. And so we're like, all right, what do we do?
50:34Time to step back and think about some sort of out-of-the-box way to get into this data center. One way to try to think through something like that is just to learn more about this company. Maxie was curious how the building was built. So we actually went to the municipalities. We'd gotten some, like, almost you could think of them as blueprints. and we figured out that there was in fact a sewage line. Sewage lines are too small and would be way too disgusting for a person to go into. However, they sometimes run through underground tunnels that are accessible by service workers, like a smaller pipe inside a big tunnel.
51:13So she traced where the lines leave the property. It sat at a point where we could get to another access point through basically a junction. Well, it's worth a shot to try. So they drive over to where they expect there to be a manhole which is off the property. And if their calculations are right, these pipes would lead right into the data center. But the question is, will there be a service tunnel also leading to the data center? So they pried open the manhole lid and looked in. It was big enough to crawl down into, so they did. And then they saw a tunnel going towards the data center. So they crawled through it.
51:55And it's a long, shall we call it, journey from one access point, one manhole to the other. But we have to do it. It's not glamorous. It wasn't that enjoyable. But we got through it. Sure enough, it led them right to the data center. And then make our way up into the site and then into the data center. They got in, snapped a few photos to prove they were in there, unauthorized. And then they called the security team to tell them they got in. And the security came and was like, what? How did you get in here? And so our report was, your guy's security is bob on. We hate it. It was amazing. You didn't let us in here.
52:37We weren't able to phone ahead. We weren't able to forge documents. We weren't able to do any of the things that we would try to do ordinarily. We couldn't have created a diversion to have security take their eyes off of the gates to get through us. They weren't looking. It wasn't going to happen. We got into your data center through a manhole for a sewer line. And that was the bulk of our report. The rest of it was going, but it kind of didn't matter to them. They're like, yeah, but you still got in. But this made Maxie think even more. If a data center wants ultimate security so nobody ever gets in, how could they improve this?
53:18And that's when it occurred to her. And I was like, well, if you want to keep them that safe, you put them underwater. An underwater data center? Could that even work? Then I started to think, oh, is that? Did I just have a good idea? Amazing. So I called my old boss, who I used to work offshore for and with. I was like, hey, what do you think of this? And he's like, I've actually thought of someone fairly similar. And I had this like autocad drawn at this point. he tweaked it, tweaked the design. I was like, would you consider working with me? Here's what I want to do. I want to put data centers underwater.
53:56I want to do it in a modular fashion. And I want to do it because it keeps them safe. So the two of them got busy designing and building modular underwater data centers, where you load up the servers into what looks like a small shipping container that's watertight, and she will then drive them down to a safe spot on the bottom of the ocean. It's also a lot cheaper to do. So it's about 80 % less expensive in terms of CAPEX to get compute underwater the way we do it. I don't know anything about underwater data centers. This is all new to me. So I didn't even know this was possible or even this was happening.
54:32But you're telling me this is something you made. This is something we've made. This is something we've done, performed, and now there are actually a lot of companies popping up. Is there like a long extension cord that goes to these things? Yes, there essentially is. So what's really interesting about the subsea environment, and we touched upon it earlier, is that everything you and I use, one way or another, so there are power cords under the water. That's how we light up oil and gas platforms. That's how we manage to eat on them and things like that. And there are also countries that export, So France exports power to Denmark.
55:13We not so long go laid a cable to do that for them. So there's actually a lot of subsea cables. There's also a lot of subsea cables for, there's like 700 cables or something like that, maybe more now, that carry this internet signals. So they pulse the light. So you don't have to lay your own cables. You could just tap off some of the stuff that's there? Yeah, it depends. So if we're in a port, then we might extend from an on-land substation. If we're further offshore, then we'll splice the power cable, put it in wet. So we've got offshore, they're wet-mate cables. So they look like headphones with mic jacks on them.
55:54They look like that. They're just really big ones of that, essentially. And we plug them into our units. Our units look like 20-foot shipping containers. And we put them on the subsea floor. we secure them there through guideposts, lock them in, plug in the power wet, wetmate the power, and do the same for the fiber, and then it's up and running. And we can do about three megawatts in a unit just now, which is meaningless to most people, but that's kind of what we need just to do a small amount of compute. And yeah, we set them on the seafloor. But what about maintenance and stuff? Like you need to change out a hard drive.
56:36Yeah, so there's a few ways that we perform maintenance. So it's actually not that much different than online. So what I will say is the maintenance cycles are reduced because there's no dust, right? We've got the servers that are filled or surrounded by this dielectric fluid. So there's no dust. There's no debris. There's no people justling the cables. and those are the biggest factors in maintenance. That's why compute goes down 80 % of the time. We don't have that then. But, you know, it happens. We do have to maintain. There's some faults. So we do that a few different ways. If one server fails, it kind of doesn't matter.
57:17We'll load balance. We'll shift the load and it'll go to some other server or some other site that we have. If a whole rack fails, it may fail in place. and again load balancing or if a rack fails and it's important depend on what the client depend on who the client is and what the client is doing we may have to bring the unit up and it takes we we guarantee you can do it within about 12 hours um so we've got a vessel at site the vessel goes picks the unit up with an rov because that's my background and that's how i know how to do it so picks up put on deck we drain it we do the fixes you can also do them remotely a lot of the time um so it really just depends but then it it doesn't cost any more time and it doesn't cost any more in terms of the financials and and before people like come for me it does not heat the water we are not heating the oceans so I have to say it so water warms up more slowly than air and it can actually hold more heat so the specific key of water is higher than most other substances and what that means is that it absorbs more heat before its own temperature increases by one degree.
58:45So say it another way water needs about four times as much energy to raise its temperature by one degree celsius as the same mass of air does. So what we've measured in our testing is that the water heats up by about a thousandth of a degree which is statistically insignificant and that's within a meter of the unit you put a data center on land first of all you have to use air conditioning to cool it for the most part that's what people are doing so about 40 to 50 percent of all the power that that data center is pulling is used to air condition and then that is pushed out as heat and then the ocean has to take that because that's our heat sink Like the ocean takes that and now you're warming the oceans.
59:31So it's like a very unintuitive, but very like scientifically proven method of getting rid of heat, put it into water. And so, yeah. And I imagine if someone does try to pen test this place or break into it, as soon as they open the door, it just gets flooded and then all the computers shut off. You can't open the door. So it's like you would basically, our biggest threat is like a sub, you know, like a Russian sub movie, let's say. And so what happens is you need a sub or you need a vessel with an ROV attached. Or maybe if we're at like a shallow depth, you could use a diver, but a diver's not going to be able to do anything.
1:00:11You can't pull the door open because of the pressure of the water. So basically, you couldn't really pen test it without getting a vessel, an ROV or a bunch of divers or a submarine. And good luck to you. I don't even know how I would do that. and if anybody's going to pen test it it's going to be me because that is a that is a fun job but basically let's say a nation state sub came along great it would have to connect it and it would have to pull it off of its security mechanisms that we've got sort of fastened to the seabed and once you'd done that, you would basically self-destruct the data that was on the servers because now you've ruined the housing that is keeping them safe from the water and the pressure of the water.
1:01:04So physically, they are very, very secure. Digitally, it's the same footprint. You pen test it the same way you would any other server, data center, company. Incredible. I think I'm stunned by that sort of thing. I mean, my brain goes into weird directions here. Like, are there laws offshore where you can host things that aren't legal in this country or whatever and all this sort of stuff? And now suddenly I like this idea of pirating websites or piracy. There's piracy in the sea as well. My brain just goes in all directions here. It's right. Yes, there are maritime laws. Very difficult to enforce them.
1:01:50And you rely on satellites to some level. You rely on boats to police. But the ocean is vast. So it is very difficult to enforce. So basically we're counting on people doing the right thing. And that doesn't always work. So what we do is we make sure that we're in the green. So we co-locate with existing assets offshore, whether it be in national or international waters. every country has an easy and economic zone essentially and that's about it goes from coastline to about 12 miles out and then just a little further out from that you start to get into what is essentially international waters you can do what you want inside of them who's going to stop you but we choose not to as you know an American company and so we co-locate with other assets in the area, usually like offshore wind platforms or rigs or anchored boats.
1:02:56So yeah, I think subsea is definitely part of the future for data centers.
1:03:11A big thank you to Maxie Reynolds for coming on the show and sharing these stories. You can learn more about her underwater data center at subseacloud.com. If you want to get her book, it's called The Art of Attack, Attacker Mindset. It's the one with the chess pieces on the cover. If you like this show, if it brings value to you, consider supporting the show by giving directly to the show. It helps keep ads at a minimum. It keeps the lights on here. But most of all, it tells me you want more of it. Not only that, but you'll get bonus episodes and an ad-free version of the show, too. So please visit plus.darknetdiaries.com.
1:03:43that's plus.darknetdiaries.com thank you the show is made by me the packet tickler Jack Recider editing by control alt delight Tristan Ledger mixing by proximity sound and our theme music is by the mysterious Breakmaster Cylinder I have a bad habit of doom scrolling social media but lately I've been trying to break it by confusing the algorithm as much as possible I'll play like long recordings of foghorns blaring or I'll watch curling matches from 2006 or I'll just search for like the most bizarre are things I can think of like, can I legally marry a ghost in Ohio? Or Baroque interpretations of dial-up modem sounds.
1:04:23Can you potty train a squirrel using jazz? Not because I'm interested in those results, but because I like tossing the algorithm a bag of trail mix. Just watching it chew on that for a while. This is Darknet Diaries.
1:04:44Thank you.
From the publisher
Maxie Reynolds loves an adventure, especially the kind where she’s breaking into buildings (legally). In this episode, she shares stories from her time as a professional penetration tester, including high-stakes physical intrusions, red team chaos, and the unique adrenaline of hacking the real world.
Her book: The Art of Attack: Attacker Mindset for Security Professionals (https://amzn.to/4ojYSVZ)
Her data center: www.subseacloud.com/




