3 Security Fixes Every SaaS Founder Should Make This Week

MicroConf· 13 min· 2,484 words· 11 min read· English ·Watch on YouTube

This is the full transcript of 3 Security Fixes Every SaaS Founder Should Make This Week, published on YouTube by MicroConf. Every paragraph carries the moment it was spoken, so you can click any line to jump straight to that point in the video, search the whole thing for a word, or copy it out.

0:00Howdy folks, that was a really good lead in, and I'm not Kevin Mitnick, very important to clarify. He was a friend of friends, so RIP Kevin. This is what I'm here to talk to you about. I'm also going to go fast, there's a lot of specifics in here. I do not expect you to memorize it, the slides are going to be up at this link,

0:16so just pull that up on your phone. And they'll be up after the conference. So, I'm going to tell you about some interventions that I've made in my own business to keep us delivering customer success and not getting hacked, because it's really embarrassing if you're a cybersecurity consultancy and you get hacked. So, there's a joke in cybersecurity that we all think that we're this guy, and we all really think that this is what we do all day, and the reality is that we're this guy, and this is what we do all day. We yell

0:50at our computers a lot. And as a bootstrap founder as well, not of a SAS business, but of my little cybersecurity consultancy, you know, I would really like to believe that I'm this guy every day, you know. Um, I would really like to believe, you know, ton of happy customers, you know, revenue graph up into the right, which is how which is how it is every

1:11day, right, Rob? Like, 100%. Oh, yeah. Yeah. But the reality is that as a bootstrap founder, I am still this guy. I spend most of my day yelling at computers, staring at my screen. It's not great. So, when some well-meaning colleague of mine, I love his theory, comes to me and is like, "Don't click links in emails. You know, set up your firewall properly. Like, buy our, you know, security solution." I You could be asking me if my TPS reports are

1:42filed properly. They're not. My taxes are also not filed. Don't tell the IRS. We're working on it. And the plain fact is we've been giving bad security advice for a long time as a cybersecurity community, and it's kind a problem. Uh there are good reasons for this, uh but the biggest reason is that it's not the 1990s anymore. Uh and that is where our advice continues to be stuck. Um it it's probably good that it's not the '90s. It is definitely not this '90s anymore. Uh but it is also not this '90s anymore, and a lot of our security advice assumes that these are still the computers that

2:19we're using. Uh so, from you know, the and the the the TLDR did not fit in this talk. Believe me, I tried. Uh find me afterwards. But the the reason here is that the internet happened. Like, we connected all of our computers together. Uh and now, you know, the advice that worked when we were all sitting in cubicles in, you know, uh beige offices uh 20 years ago just

2:43doesn't apply. Um yeah, yeah, yeah. But the internet is the reason that we're all here. So, we have to figure out what to do about it. Uh and so, uh from the background of working in security at one of the software companies, some of which you might have uh heard of, uh like how do people actually get hurt? Like, what did we see being on the receiving end of a lot of adversarial behavior, uh like we were just talking, uh that actually mattered? And the flip side of that being, like, where then can we target the most effective interventions so that we are, you know, making the most uh best use of our time,

3:19our money, our energy, and our customers' time, money, and energy? Uh so, that brings me to to the subject of my talk. Uh these are again, like, interventions that I made in my own organization, little organization, um about three people. It's me and a few 1099s, uh but that have really moved the needle for us, and that were, you know, straightforward things that we could do just every day as part of our processes to, like, improve uh the way that we work. Um and so, you know, the first threat that gets people in trouble, uh one of the first threats that get people in trouble is password reuse. This is where your

3:55CFO or your bookkeeper turns out to have used the same password uh on a Minecraft forum that they use for a bank. That's bad. And you you wouldn't think that it happens, but oh boy. [laughter] Stuff like that happens too often. Uh and so what I want to encourage you all to do is to start using a password manager uh if you're not already. Now, audience participation time. Quick show of hands, who here is already using a password manager? That can be LastPass, that can be Oh my god. I'm going to need to update my advice. This is great. Uh you can be writing something down on a

4:24piece of paper. This is another way our advice has changed since the '90s. Write your passwords down if it means you're not reusing them. Um awesome. So, for all of you who just raised your hand, that's incredible. I love you. Uh if you didn't just raise your hand, come join us. It is better over here. Using a password manager has genuinely made my experience of the internet way better. It's just easier,

4:43it's faster. Come join us. I use and recommend LastPass. Uh I use and recommend LastPass for a whole host of reasons, that it works great for teams. So, like I can share my airline password with my admin through a secure vault. Uh when I change my airline password, she can still log in. When she changes my airline password, I can still log in. Um it's subscription-based, which means you can be assured that you'll get security updates and they won't sell out to Russia anytime soon. It is worth every penny. Uh I have a giveaway at the end of the talk, but uh we'll get to that in

5:14a second. Uh we're actually going to pause now. If you do not have a password manager, get out your phone. Uh You said one password. Is there LastPass or one password? One password. Did I say LastPass? Oh my god. I'm so sorry. Uh I recommend one password because LastPass has had a bad history of security breaches and I'm tired of and I'm tired of answering the question every 6 months like is LastPass still okay to use? Just use one password. So,

5:42anybody take out your phone. Going once, going twice. All right, great. Um So, that's password reuse. Uh start using a password manager. You don't have to get all your passwords in. Uh you can add them as you go. Uh don't boil the ocean, but get started. Um second threat, something called spear phishing. Uh you might think the answer to this is

6:02implementing two-factor authentication. It's not. Uh implement an agreement with your staff that money never moves without strong authentication and authorization. So, what's the threat here? Uh me, Kevin, sends an email to my admin Sasha, which is like, "Just get on the plane. Uh close the deal. Please wire money to this uh account number. I

6:22can't talk now. Bye." Uh you would be surprised how often this uh works. Uh it's been hitting a lot of nonprofits lately. They have a decent amount of money and a wide variation, let's say, in their accounting controls. Um my bookkeeper and my admin and I have a pre-existing agreement that I will never ask them to move money via email. Uh they know there are some invoices that are automatically approved, like my admin's invoice comes through first of

6:47the month, uh $900 goes out to Sasha. Everything else I log into our accounts payable system and manually approve. No exceptions. They know that if they get an email from me saying, you know, "Hey, Darcy, go move the money." it's it's it's an attack. Um This tactic accounts for millions of dollars in fraud every year. People do not get their money back. Uh this puts people out of business. They have to go ask friends and family to bail them out. It is bad. Uh and it is really simple. It is cheap for

7:17advertisers. They find you on LinkedIn. They send some emails. Uh they don't get caught. Little bit of planning and process discipline. I it feels silly. And, you know, if this has happened to you, like, no judgment here. Um we've all been there. We're all firing out of system one. It's just like getting through the day, closing our inbox out, and it happens to people even after you implement this, it might still happen to you, but a little bit of process here, a little bit of pre-existing agreement uh can save a lot of heartache. So, now set up two-factor authentication on your

7:47primary email domain. Okay. [laughter] Just got to get that out of the way. Um So, that's spear fishing. The last thing is credential stuffing attacks. That's what happens when that Minecraft forum gets knocked over by a hacker. They take the the password database dump and they run it against your site. Uh this is what happens as soon as you put a login

8:04form on the internet. Ask me how I know. Um The solution is to rate limit all your authentication endpoints. And there are two kinds of people in the world, people who are like, "Obviously, Kevin. What are you talking about?" and people who are finding this out for the first time, sometimes face first. So, uh if whichever kind of person you are, uh

8:22yeah, that's why I'm bringing this up. Um I'm really not kidding about the Minecraft forum thing. Uh my email address and password are in that lower one. Uh yours may be in that upper one. Uh it's You don't want to find out uh when somebody takes over your bank account. Uh You also don't want to find out when someone takes over one of your customers' accounts. Uh any login form on the internet can and

8:46will get these dumps tried against them. Again, ask me how I know. Um And you might be like, "I'm running a bookmarking site. I'm running a family photo sharing site. I run a recipe site." Like, if your users are paying for it, they value it. What I'm trying to tell you is that you're all worth it. Uh and you're worth it. Your users, you're worth it to yourselves, and you're worth it to your adversaries. If you build it, they will come. Um They're also account takeovers. They really suck. They're an enormous support burden. If you've ever been on the support side of this, you're helping somebody who's having the worst day of

9:16their life, and you're also having a really bad day, and you often can't tell if that person is genuinely having the worst day of their life or if they're an adversary trying to, you know, deepen their attack. Um So, the details did not fit in this talk. I don't think the details would fit in any 12-minute talk. The key insight is just more friction, the more requests you get. If you're getting more than one login request a second, that's not a human typing at a keyboard. That's an automated system. Um Also, so there are a bunch of useful tools. This is the good news provided by

9:49everybody in your ecosystem uh from your your hosting provider AWS. There's this vendor called Stanza who are doing this as a service. They seem cool and like bootstrappy. Um you can also just roll this with Redis. A lot of people do. Uh whichever way you go, you know, whatever works for you. Um do this for both your user authentication endpoints and your API authentication endpoints. You would be surprised how many people rate limit one but not the other. Uh you're like, "Oh yeah, obviously we have to rate limit off, you know, automated systems." And people forget that your adversaries can just view source, find your user login

10:22uh endpoint, and you know, run their dumps at that. Um and they will. Um the alternative to doing this uh before you launch is doing this while you're under active attack. Uh I'm friends with a bunch of people who were launching cryptocurrency projects for a while, and I lost count of the number who had, you know, launched on Product Hunt and then told me they had to implement rate limiting while they were under active attack, you know, within hours after launch. Um so, if you're dealing with money, you know, you're more likely to get hit uh fast and hard, but yeah. Any login form on the internet is going to

10:56see this or can see this. So, those are my three recommendations. Uh there's a bunch of stuff that I missed, but these are things that are important to start doing and start doing early. Um they're relatively straightforward, they're relatively inexpensive, and they move the needle in ways that nothing else does. Um So, yeah, that's the that's the call to action. It's like whichever one of these, you know, start today. Um if you're already doing one, do the next one. If you're not doing any of these, pick whichever one sounds like the most fun. Uh if you're doing all of these, you're doing better than some many of your peer

11:34organizations and there is a certain element of like having to run faster than the guy next to you rather than having to run faster than the bear. Security is a process, not a product despite what my colleagues will tell you. The goal is this is how we keep our customers happy. This is how we keep that revenue graph

11:52going up into the right. This is how we keep enjoying and being bootstrap founders and I just keep like you know, may realizing you know, the dream that we all have of doing this on our own terms. Um So, that's the advice. This is me. If you email me, the first three people to email me at hello@complexsystems.group about either where you are in your cybersecurity journey or an essential intervention that you've implemented that I didn't talk about. First three people free goodie bag with a YubiKey

12:24and a month of one password. Um Thank you. Also, this is my podcast. So, check it out. All right. Take care everybody.

Where these words come from. This is the caption track YouTube holds for this video, written automatically by YouTube rather than by the creator. We read it, tidied the line breaks and laid it out so it can be read. The plain text version is at https://viewrankai.com/tools/youtube-transcript/DaBHWCugIzo.txt.

All rights in this video belong to MicroConf. Watch it on YouTube. If this is your video and you would rather this page did not exist, tell us and we will remove it.