https://www.youtube.com/watch?v=przDcQe6n5o
___________________
Links related to video:
Tech Model Railroad Club
- https://wikipedia.org/wiki/Tech_Model_Railroad_Club
Operation Aurora
https://www.youtube.com/watch?v=przDcQe6n5o
___________________
Links related to video:
Tech Model Railroad Club
- https://wikipedia.org/wiki/Tech_Model_Railroad_Club
Operation Aurora
I think there's a pretty good chance the China thing happened first, though. That was 2009, and I like to hope that Google didn't the NSA's activity for over five years.
Btw, circa 2013 for those that are interested: https://www.theverge.com/2013/11/6/5072924/google-engineers-...
From the WashingtonPost article on this, here's a TLDR:
Google didn't use to encrypt traffic between datacenters, as the lines were wholly owned by Google, so they thought they had nothing to fear. Snowden reveled that the NSA had tapped some of these fiber lines, then reverse-engineered the network encoding for protos (it wasn't the same as GRPC now uses), and were using it to decode messages going between datacenters. This ended up speeding up an effort to encrypt all network traffic on Google's network.
- https://www.youtube.com/watch?v=N7N4EC20-cM
Summary: Google covers how they use Google’s web crawler to build a threat analysis database, then cover how they protect users from government backed attackers using phishing by providing two-factor authentication.
Response: Strange, seems like offering end-to-end-encryption would likely protect more users from government backed snooping — but then I guess that would mean Google on was not able to snoop on billions of users.
Links related to video:
"Government backed attackers may be trying to steal your password"
- https://www.google.com/search?q=%22government+backed+attacke...
_______________________
EP002: Detection and Response (3rd video)
Summary: Covers Google’s Incident Response Team and targeted attacks against security experts. Links to topics mentioned in video:
- https://wikipedia.org/wiki/Union_Fire_Company
- https://wikipedia.org/wiki/Incident_response_team
- https://blog.google/threat-analysis-group/new-campaign-targe...
- https://blog.google/threat-analysis-group/update-campaign-ta...
_________________
Response: Targeted attacks and insider threats specifically for security professionals have been around forever. Fake profiles, trust-based pig back attacks, watering hole attacks, hack the hacker, honeypots, bribes, blackmail, break-ins, etc — aka hunting the keys to the kingdom.
Prior examples:
- https://www.latimes.com/archives/la-xpm-2000-sep-19-fi-23373...
- https://www.cnet.com/news/privacy/google-china-insiders-may-...
- https://www.theverge.com/2014/2/24/5441386/ethical-hacking-o...
- https://wikipedia.org/wiki/Vault_7
- https://www.businessinsider.com/fireeye-hacked-nation-state-...
Things are getting interesting! The next video (004) is titled 'BUG HUNTERS'. I think it refers to bug bounty programs?
Response: Red Teams get a lot of hype and even more rules of engagement, which results in false sense of security.
____________
Related links:
- https://en.m.wikipedia.org/wiki/Crash_test_dummy
- https://en.m.wikipedia.org/wiki/Red_team
- https://en.m.wikipedia.org/wiki/Certified_Ethical_Hacker
- https://blog.google/technology/safety-security/meet-the-team...
- https://cloud.withgoogle.com/cloudsecurity/podcast/ep71-atta...
- https://portswigger.net/daily-swig/amp/whid-elite-weaponized...
- https://opensource.googleblog.com/2020/03/usb-keystroke-inje...
- https://www.emergingtechbrew.com/stories/2022/06/14/how-micr...
In the beginning they relate this to an English castle in Normandy that was defeated when in 1204 the French attackers climbed through the latrine chute to get inside. They like to start these off with some vague connection to a historical event.
Its pretty general but does have some valuable key points despite the slick infomerical feel.
Response: As mentioned in the video, Knuth’s bounty program was largely to help him feel better about publishing a book with errors; checks are largely symbolic and rarely cashed, since they’re only worth few dollars. Similarly, black market for bugs continues to offer higher payouts than white hat markets. It’s an issue and building communities alone around bug bounties will neither fix it, nor stop true adversaries from developing talent and technology that exceeds current capacities, capabilities, etc. Obviously, complex problem, but if Google is going to market and position themselves as a community resource for protecting people, they need to be direct and honest about the limits of reality and the constraints they’re forced to work within; for example, that their interests, nation states, etc - frequently have security concerns that conflict with user security.
_______________________
Links related to video:
- https://wikipedia.org/wiki/Bounty_(reward)
- https://wikipedia.org/wiki/The_Art_of_Computer_Programming
- https://wikipedia.org/wiki/Knuth_reward_check
- https://securitymagazine.com/articles/95726-google-launches-...
- https://wikipedia.org/wiki/Market_for_zero-day_exploits
_______________________
Meta: YouTube bug to playing video with audio is fixed. Also, appears this is last full episode in the series; full playlist is now up here:
https://m.youtube.com/playlist?list=PL590L5WQmH8dsxxz7ooJAgm...
_________________________
EP005: Project Zero | HACKING GOOGLE
- https://youtube.com/watch?v=My_13FXODdU
Summary: Covers Google’s Project Zero team, which is tasked hunting zero day exploits across the internet in software, hardware, and Google products.
Response: Beyond basic information and covering already publicly disclosed zero-days Project Zero has discovered, there was not much incite into how they prioritize research or hope to bring zero days down longer even as technology changes.
_________________________
Related links from video:
- https://en.m.wikipedia.org/wiki/Siege_of_Château_Gaillard
- https://googleprojectzero.blogspot.com/?m=1
- https://en.m.wikipedia.org/wiki/Project_Zero
- https://en.m.wikipedia.org/wiki/Zero-day_(computing)
- https://i.blackhat.com/USA21/Wednesday-Handouts/us-21-Can-Yo...
- https://en.m.wikipedia.org/wiki/L0pht
- https://googleprojectzero.blogspot.com/p/vulnerability-discl...
- https://googleprojectzero.blogspot.com/2019/08/a-very-deep-d...
- https://m.youtube.com/watch?v=dhdz5VZ4S88
_________________
Summary: Chief Information Security Officer of Google Cloud, Phil Venables, covers all the teams listed in prior videos and describes how Google Cloud helps secure its customers.
Response: As an outsider watching video series, while it is possible I misunderstood, appears the Google Cloud CISO is the highest-level security leadership role within Google, which might be confusing to random outsider, since generally the public thinks of Google being Google, not Google Cloud. Lastly, as evident by my posts, really wish this had been accompanied by blog posts with links. These videos are obviously targeting general public and potential hires, but Google neither links to job opportunities or submit security issues, nor provides a way generally speaking to engage them with feedback, questions, etc - of the series or Google Security in general.
_________________
Related links from video:
- https://www.google.com/search?q=google.cloud+ciso+phil+venab...
- https://cloud.google.com/security
________
EDIT: Able to access the videos via the direct non-web links, but any of the ones with audio baked in are not accessible; the ones without audio do play. Assuming it’s glitch and will fix it itself.