1752 – Unmasking the Cyber Mercenary with Chris Rock

8 Dec 2023 · 19 min

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

The Thoughtful Entrepreneur Podcast Episode Notes

Episode Title

1752 – Unmasking the Cyber Mercenary with Chris Rock

Podcast Overview

  • Host: Josh Elledge
  • Description: Daily, commercial-free entrepreneur spotlight show featuring CEOs and founders of B2B companies sharing success stories and advice for business growth.

Guest Introduction

  • Guest: Chris Rock
  • Title: Chief Information Security Officer (CISO) and Co-Founder of [SIEMonster](https://siemonster.com/)
  • Chris is a hacker by trade with a focus on identifying system flaws and presenting them at cybersecurity conferences like DEFCON.

Key Themes and Discussions

Chris Rock's Professional Background

  • Dual role as a hacker and CISO at SIEMonster.
  • Works with a diverse clientele, including governments and private organizations.
  • Involved in high-stakes investigations, including tracking illegal activities and cybersecurity breaches.

Intriguing Stories from Cybersecurity

  • Chris shares captivating narratives:
  • Employees setting up illegal operations within companies.
  • Tracking individuals escaping authorities in the Middle East.

Cybersecurity Landscape

  • Current Situation:
  • Chris expresses concern about the ongoing vulnerabilities in digital systems.
  • Flaws identified years ago remain unaddressed.
  • Transition from paper systems to electronic systems has exacerbated security risks.

Recommendations for Enhanced Security

  • Account Security:
  • Use account IDs and virtual credit cards instead of traditional credit card numbers.
  • Replace static passwords with tokens for increased security.
  • Two-Factor Authentication (2FA):
  • Essential for all work-related accounts to mitigate risks.
  • VPN Usage:
  • Employees should use VPNs both at work and home to protect data integrity, especially on public Wi-Fi.
  • Regular Verification:
  • Implement a two-check system for payment approvals to avoid fraud from compromised vendor emails.

Chris Rock's Insights on Cybersecurity

  • On the State of Cybersecurity:
  • The lack of progress in addressing vulnerabilities over the past eight years.
  • The necessity of continuous vigilance and proactive measures.

About SIEMonster

  • Overview:
  • Founded in 2015 by Chris and Dez Rock.
  • Offers a cost-effective Security Information and Event Management (SIEM) solution.
  • Focus on automated tasks and data enrichment to reduce reliance on external security consultants.

Chris Rock's Contributions

  • Author of the book "[Baby Harvest](https://www.amazon.com/Baby-Harvest-terrorist-criminal-laundering/dp/1515014576)," which explores cybercrime and virtual exploitation.
  • Speaker at DEFCON, discussing critical security topics and vulnerabilities.

Final Thoughts from Chris Rock

  • Cybersecurity requires constant attention and innovative strategies.
  • The evolution of security practices is slow, but vital for protecting sensitive information.
  • Businesses must adapt to new technologies and risks proactively.

Conclusion

  • Host Josh Elledge emphasizes the importance of sharing knowledge and experiences within the entrepreneurial community to foster growth and resilience against cyber threats.

Additional Resources

  • SIEMonster Website: [siemonster.com](https://siemonster.com/)
  • Chris Rock's Personal Website: [chrisrockhacker.com](https://chrisrockhacker.com/)
  • Podcast Community: Join the listener Facebook group for ongoing discussions and insights.

---

Key Takeaways:

  • Cybersecurity is an ongoing challenge, and proactive measures are essential.
  • Collaboration between businesses and security experts can lead to better practices and protection.
  • Awareness of vulnerabilities can lead to better security solutions and practices within organizations.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:28Hey there, thoughtful listener. million in revenue. Just head to upmyinfluence.com and watch my free class on how to create endless high-ticket sales appointments. You can even chat with me live and I'll see and reply to your messages. Also, don't forget, the thoughtful entrepreneur is always looking for guests. Go to upmyinfluence.com and click on podcast. We'd love to have you.

0:59Well, this ought to be a fun conversation. I've got Chris Rock. No, not the Chris, that Chris Rock. I've got Chris Rock, who is the CISO of C-Monster. CISO, by the way, C-I-S-O, in case you don't know what that is. That's the chief information security officer of a company called C-Monster, and that's S-I-E, Monster. And Chris, you're also a cyber mercenary. But as I was just saying before we started recording, you've got about the nicest personality for someone I'd refer to as a cyber mercenary that I've ever met. So Chris, it's great to have you. Thank you so much, Josh. Lovely to be here. All right.

1:36Well, listen, I just want to have you kind of share your story and the work that you do. And I think you're going to be quite interested in this topic. Chris, give us an overview of your impact in the world today. So I am a hacker by trade. So a cyber mercenary, keyboard for hire. And I essentially have two roles in this world. I look for holes in big systems, which I then present in front of the world. So DEF CON is the largest hacking conference in the world. So I present flaws in systems. So I did a talk on how you can kill somebody virtually and how to birth somebody. I did a talk on how to overthrow our government digitally with a mercenary called Simon Mann back in 2016.

2:16and we used the country of Kuwait as an example. And then last year, I did a talk at DEF CON on how you can circumvent military jammers. That's my, what we'd say, day job. But my other job is I am the CISO of a company called Sea Monster that does seam services for large enterprise companies. That's essentially how I split my load between day and night. Yeah. So what work, do you work then as a consultant for companies? Yes, I work for governments, private organizations, and everyone in between. And who hires you and what is their objective? So there's multi-objectives. So it might be a government needs to pay like a jailer in another country so that a female citizen gets feminine hygiene products.

3:05It might be a company that suspects their employees of embezzling money. So they get me to go in digitally to find out where the money's going. but stealthily. And so I just get a tap on the shoulder, mostly from Middle East countries to say what's going on here. And then it's my role and my team's role to find out what's going on. That is just fascinating. So naturally, I think we all want to sit back and say, Chris, tell us a story or two. I've got many stories, Josh. Look, I've got stories that will blow your mind. I've got stories where I've got employees of setting up another company within a company, moving money from the head company to their company, and then doing illegal activities.

3:48And then I've been asked to find out what's going on and then follow their whole lives inside and out what they're up to. I've seen people escape countries in burkas. I've seen people on jet skis in the Middle East go from one country to another to escape authorities. And I've seen everything, Josh, everything. Yeah. You know, I think what you're talking about makes it feel like, gosh, we live in kind of a scary world sometimes, and there's so many vulnerabilities among us. I hope you come with a bit of a message of hope. Unfortunately not, Josh. It's really bad out there. That's why I do these talks at Las Vegas Def Con, is just to show how bad it is.

4:30And so I'll find a topic that interests me and I'll present it that birth and death one for me was really bad and I had to present that it's essentially I could kill you and then take all your assets virtually of course and then I own all your assets and you are now declared dead I could then create a thousand fake joshes and then kill a thousand fake joshes and put I have a life insurance policy on all of them and then take all that money and for me that was a flaw that was not only in the US but it's a worldwide flaw and then I just wanted to show the world that this is bad because you do not want a million fake people virtually walking around because I mean anyone who's listening in the audience who've got kids you know you buy cars from people and you don't trust them in the first place but at least you can tell the cops here's the email here's this here's there's a person at the other end of it for the police to arrest but if it's a virtual person there's nobody uh you know you're paying for a car that doesn't exist you know the kids pay for a deposit and it's gone there is no coming back from that because it's a fake you've got fake bank accounts fake driver's license fake firearms licenses it's chaos and hence why i presented that topic yeah you're the author of the book the baby harvest how virtual babies became the future of terrorist financing and money laundering well i hope chris that you know what you're sharing and what you've been sharing stimulates activity, right?

5:52And it says, oh, well, there's a security gap. Hopefully folks are taking action on what's presented at DEF CON and other areas where this is being talked about and revealed and shared. Your assumption is spot on, Josh, but the answer is no, nothing actually changed. Since eight years since I presented that topic, it still exists today, the exact same floor. Nothing has changed at all. I can still become a doctor online in about five minutes get their registration number, their office address, and their phone number, and become a doctor to kill somebody off. And I can be a funeral director in five minutes to do the other part of killing somebody, as in burying a person as well.

6:31So you can do that online. So 10 minutes, you could kill somebody, and officially off the record. Okay. So this is all very fascinating. What do we do with this information you're sharing? The whole idea is to show that the problem, when governments want to go from a paper-based system to an electronic-based system, and they want to make it easy for doctors, and funeral directors to go down that path. Don't assume that just because you make it easier for doctors and funeral directors, then people like myself, hackers, pen testers, anyone in between will then look for flaws in that system along the way.

7:01So you need to be aware that there's people like me looking at these sort of policy changes and then looking for flaws in these paper-based systems or electronic-based system. We're always looking for something's changed. Let's look at the security of this situation. Yeah. And in terms of like, let's say, say, you know, you're just talking to a room of, we're not in security necessarily. We're just, you know, regular run of the bill, business owners doing the best we can, trying to help good people and, you know, make a living. Are there any best practices? Are there any things that you'd recommend?

7:34Listen, you know, if I could, to that audience, if I were to give you a charge to do two to three things in your life, here's what I'd recommend. Is anything come to mind there? Yeah, there's a lot of things and I'll go through the list, but the most common one we see is where a hacker will penetrate an email system of your vendor. So if you're buying an Oracle subscription, an office subscription, maybe some new office equipment for your business, that if you must, someone in the business from the payment team must speak directly to the person you're buying and confirm those bank account details.

8:09Because we see the most common thing we see is scammers hack into the email system of a vendor. They'll then send an email to the company is saying, hey, we've changed our bank account details. Please pay here and not here instead. The company then will transfer that money, whatever figure that is, to the fake vendor, and the money is then gone, completely gone. So always do that two-check system for any payments. Have somebody from payroll or accounts receivable make those phone calls. If you get an email with an invoice on it, don't use the phone number on the invoice. Go through an outside channel and verify that so the biggest saving of save a business is make sure you ring out what we call out of bounds that vendor to make sure you're paying the right account that's the first thing that i would suggest for businesses second thing is something called one password or there's a last thing called last pass make all your users use this software so they don't have the same password for all their systems so you know you might have a user at work and also at home they may use uh let's say they use a sony for example sony playstation they might have a password they use the same password at work.

9:13Sony gets compromised. And then that user password can be used for your work. So make sure your staff use different passwords for work at home. They don't even need to know their password. It's just stored in a wallet. And also two-factor authentication for everything. I can't stress that enough. 2FA for any work-related thing is in this day and age, it's a must-have. And if it doesn't have 2FA, it's not worth using. It's just wait till 2FA is available. Are we, and I've seen some headlines, haven't read the stories yet, but I think, was it Google or someone who's, you know, really trying to champion, and maybe this is well underway, but are we going to get to a point where we can kind of evolve from passwords?

9:52We're getting there now very slowly. I mean, we've been, you know, as a packer myself, I've been using user password for a long time. You know, I've been doing that for 20 years and now coming up against 2FA over the last probably eight years. To answer your question, it's evolving, Josh, but very slowly. What is the future? Where do we go from beyond passwords? That's a really good question. I think tokens is probably the best one. So you have a token on your phone, like you probably, a lot of your users will use things like authenticator apps and stuff like that. You don't use a password. It's essentially, it's a password or token that's good for 30 seconds and then moves on to the next one.

10:27I don't think passwords are actually required. I think the token's the best way. So if someone's not familiar with what I've got through LastPass, they've got now a separate token app that I use Can you explain that just a little bit more? Because if that's an option, generally, would you say, well, that's a little bit more secure than a password? The answer is yes, because it's always changing. It's not a static thing. It's not something you write down on a piece of paper. It's not something that's sitting on a Word document on your computer. It's not something that you give to your kids to access something.

10:59And then all of a sudden, all their friends have got it as well. So essentially, it's a number that changes every 30 seconds, can be anywhere between six and nine digits. And then it's not good. In the same token, I think credit cards are stupid as well. I don't think we should be using credit card numbers as well. I think we should have, I think we should be using an account ID and then we have 20 virtual credit cards that are only good for one use on every card. But businesses want credit cards so they're on file so you can do repeat charges and stuff like that. For me, we don't need that anymore.

11:29Yeah, I agree. Yeah. In fact, I've got the Apple card and this is the very first card I've gotten. There's no number on it. And I'm like, yeah, I don't need a number on there. And I'm always going to swipe it or use the chip anyway, or just make a virtual transaction. I'm like, why do we still have numbers? And again, it's silly. It's silly. Josh, you go to Hawaii on holidays and you go to a hotel and you give them the number at reception. And all of a sudden, that number is written down on a piece of paper and given somewhere else and sold on the black market. We don't need... I mean, that's old school technology.

11:59We really need to move from that sort of stuff. Yeah. I think, remember, you need a number with the raised numbers so you could slide it through the credit card thing. Like we haven't used those in 20 some years. So you don't need a number with raised, you know, all that stuff on there. So only a backup if the other stuff doesn't work, I guess. But so, Chris, how can I help you? I mean, who can I help connect you with or, you know, who might be listening to us right now that should engage with you? And what does that look like? Yeah, so great question, Josh. So how we got into the SIEM business, we're hackers by trade.

12:32And a SIEM is essentially a piece of software that monitors inside your company's environment. So the common flaw that we saw when we were hacking into companies was we'd hack into a company and we'd produce a report maybe a month later saying we hacked in here and we did X, Y, Z. And the company would say, we didn't even know you were inside. We had no visibility into our own network to say what you were up to. And then that's where we then went into the SIEM business. So we created software so that you can actually show people that if someone gets in, you can actually follow their path. So if you're thinking the physical security world where you've got proximity cards and door locks and door codes, in the event of a breach and cameras, you can actually follow the path.

13:12You can see someone swiped in with a stolen proximity card. There they are on camera. They went into the staff room. They stole some cakes out of the fridge. And you actually have some evidence. So this SIEM software essentially does that evidence trail used for things like forensic purposes and also it clobbers attacks as well. So if anyone's in the SIEM business, we created this thing to essentially protect people's networks because we're the perfect person to come up with this software because we hacked into companies. And so we're essentially creating what we call a blue team tool to show people what we were doing inside the network.

13:47And again, SIEM, what does that stand for? Yeah, Security Information Event Management. So essentially, you've got a computer, Josh, right in front of you right now. It creates logs. Where do those logs go? You probably don't know, probably nowhere. But in a business situation, those logs go to a central scene. And then that collects all events from routers, firewalls, printers, the works. And then it analyzes that and looks for floors. So Josh, if you click on a link and it's a ransomware link, the scene will get a record of that. And then the scene can make a choice. Do we then just kick Josh off the network so he can no longer create any more havoc?

14:22When I say Josh, someone that you've clicked on an email, of course, and then the scene will actually make a decision. Let's remove Josh's computer from the network. Let's notify the IT guys that there's something on Josh's machine. And let's take a forensic image of Josh's machine so that we can take it to the next level. Are you lawyers and all that sort of stuff? Yeah. Well, Chris Rock, let me share again. And you're the CISO of CMONSTER, S-I-E-M, MONSTER, 1M, CMONSTER.com. And then your personal website is chrisrockhacker.com. Chris, it's been a fantastic, fascinating conversation. Great having you here.

15:00And is there anything else you'd recommend someone that's been listening to our conversation of kind of their next steps? The only other thing that I missed out, Josh, is VPNs. make sure that your staff members within the company use VPNs both at work and home. So if they're using a work computer, VPN also at home. So they're not using your, you know, they're not using company information at coffee shops on free wifi. So use a VPN. A VPN essentially protects the traffic between your machine and your company's network. And they're very cheap. Yeah. Okay. So VPNs for me are a little confusing in that I just see so much debate about, oh, use this one.

15:32No, don't use that one. They're hackers. Use this one. No, don't use that. Like, it's been confusing for me to know who a good VPN provider is. Any commercial VPN provider based in the US is fine. If you don't use anything, you're essentially, you think of a hose and water. If you don't have the hose, everyone can see the water. Who cares who makes the hose? We can get in a debate of who makes the best hose or whatever. But at the end of the day, you're using a VPN that's protecting data from your company's network. But go with any top five US VPN provider, Surf Patrol, Norton, who cares? They all do a NordVPN.

16:07They all do a great job. Oh, OK. That's really because I went down that rabbit hole. And unfortunately, I think there are a lot of YouTubers that get paid by certain providers. And so then they start putting out misinformation and stuff. It's OK. Thank you. That's great to hear. And the VPN, would you recommend that for folks that are doing all their company business from home as well? Yes, definitely. I mean, a home user are using it on their own network is probably safe. But as soon as you leave the home with your laptop, and I use VPNs on my phone as well, then essentially anyone can then see those communications go between yourself and your company's network, or even personal.

16:44If you want to protect your banking information, your emails, I would recommend a VPN. Because if you travel overseas, you can't assume the same laws are going to protect you in the US. You go to any country in Europe, you're going to get done over. I guarantee your credit card is going to get done over. Your information is going to get stolen. It's just, I travel the world a million times. And if I don't have a VPN, I know about it. So on your phone in particular, like the same thing, like especially if you're connecting to public Wi-Fis, make sure that you've got a VPN installed on your phone because you're going to be, especially if you're, I guess maybe, I don't know if it's any more safe or less safe on, you know, your cellular connection as opposed to, you know, if you're starting to join hotspots and Wi-Fis and that's certainly a little bit more vulnerable.

17:26right? You're spot on. You're spot on, Josh. But the beauty is, I mean, we trust AT &T, we trust Spectrum, we trust Verizon in the US. But when you leave the US and you go to another country, you can't assume that that government is not listening to all comms, hence why encryption by people. Yeah. Chris Rock, fascinating conversation. Thank you so much for joining us. Again, your website's cmonster.com. We've got these links in the show notes. You just click around, you'll find that. And of course, your personal website, chrisrockhacker.com. Thanks, Chris. Thanks, Josh. Thank you so much.

18:24Apple Podcasts or join our listener Facebook group. Just search for The Thoughtful Entrepreneur in Facebook. I'd love even if you just stopped by to say hi. I'd love to meet you. We believe that every person has a message that can positively impact the world. We love our community who listens and shares our program every day. Together, we are empowering one another as thoughtful entrepreneurs. Hit subscribe so that tomorrow morning, that's right, seven days a week, you are going to be inspired and motivated to succeed. I promise to bring positivity and inspiration to you for around 15 minutes each day.

19:06Thanks for listening and thank you for being a part of the Thoughtful Entrepreneur Movement.

From the publisher
In this episode of the Thoughtful Entrepreneur, your host Josh Elledge speaks to the Chief Information Security Officer Co-Founder of SIE Monster, Chris Rock. Chris Rock is not your typical CSO. He's a hacker by trade with a dual role that involves finding system flaws and presenting them at conferences like Defcon. Simultaneously, he serves as the CEO of SIEMonster, which provides security services for large enterprises. His clients range from governments to private organizations, each with unique objectives and security needs. Chris shared some intriguing stories from his work. He's uncovered employees setting up illegal activities within companies, helped track people escaping authorities in the Middle East, and dealt with a myriad of other complex situations. These stories, while fascinating, also highlight the darker side of our increasingly digital world. When asked Chris if there was any hope for a safer digital world, his response was sobering. The flaws he identified years ago still exist today, and the transition from paper-based systems to electronic systems has only increased the potential for security breaches. He also recommended using account IDs and virtual credit cards instead of traditional credit card numbers to further enhance security.

Key Points from the Episode:

  • Introduction of Chris Rock as CSO of Sea Monster and cyber mercenary
  • Chris's work as a hacker and consultant
  • Clients and objectives of Chris's work
  • Stories and insights into vulnerabilities of systems
  • Need for increased security measures
  • Use of tokens instead of passwords for account security
  • Risks of using passwords and benefits of tokens
  • Importance of VPNs for data protection
  • Choosing a reliable VPN provider
  • Importance of encryption and protecting personal information

About Chris Rock: As the Chief Information Security Officer and co-founder of SIEMonster, Chris has traversed the cyber landscapes of the Middle East, the United States, and Asia, lending his expertise to governmental and private entities. Renowned for his presentations at DEFCON, the world's largest hacking conference in Las Vegas, Chris has delved into contentious vulnerabilities. His talks covered topics such as the potential manipulation of Birth and Death Registration systems, the collaboration of cyber mercenaries in government overthrows, and innovative methods of bypassing jammers by utilizing the Earth as an antenna. As a thought leader, he authored "Baby Harvest," a compelling exploration of criminals and terrorists exploiting virtual babies and fabricated deaths for financial gain. Notably, Rock has graced the TED Global stage, further solidifying his status as a cybersecurity luminary. About SIEMonster: SIEMonster, established in 2015, is an innovative and cost-effective Security Information and Event Management (SIEM) solution. Founded by experienced hackers Chris and Dez Rock, the platform emerged from a recognized gap in the SIEM market. With over 20 years of penetration testing and white-hat hacking expertise, the founders and their team crafted a scalable and customizable SIEM tool. SIEMonster's pricing model doesn't penalize based on Events Per Second (EPS), offering affordability and automatic scalability as clients expand. SIEMonster incorporates automated tasks and data enrichment, reducing the reliance on external security consultants. The vision, shared by Chris and Lead Solutions...

More from The Thoughtful Entrepreneur

All 987 episodes
1752 – Unmasking the Cyber Mercenary with Chris RockThe Thoughtful Entrepreneur · 19 min
Listen in VO