# 3 Security Fixes Every SaaS Founder Should Make This Week Channel: MicroConf Video: https://www.youtube.com/watch?v=DaBHWCugIzo Duration: 13 min Language: English Words: 2484 Transcript page: https://viewrankai.com/tools/youtube-transcript/DaBHWCugIzo --- [0:00] Howdy folks, that was a really good lead in, and I'm not Kevin Mitnick, very important to clarify. He was a friend of friends, so RIP Kevin. This is what I'm here to talk to you about. I'm also going to go fast, there's a lot of specifics in here. I do not expect you to memorize it, the slides are going to be up at this link, [0:16] so just pull that up on your phone. And they'll be up after the conference. So, I'm going to tell you about some interventions that I've made in my own business to keep us delivering customer success and not getting hacked, because it's really embarrassing if you're a cybersecurity consultancy and you get hacked. So, there's a joke in cybersecurity that we all think that we're this guy, and we all really think that this is what we do all day, and the reality is that we're this guy, and this is what we do all day. We yell [0:50] at our computers a lot. And as a bootstrap founder as well, not of a SAS business, but of my little cybersecurity consultancy, you know, I would really like to believe that I'm this guy every day, you know. Um, I would really like to believe, you know, ton of happy customers, you know, revenue graph up into the right, which is how which is how it is every [1:11] day, right, Rob? Like, 100%. Oh, yeah. Yeah. But the reality is that as a bootstrap founder, I am still this guy. I spend most of my day yelling at computers, staring at my screen. It's not great. So, when some well-meaning colleague of mine, I love his theory, comes to me and is like, "Don't click links in emails. You know, set up your firewall properly. Like, buy our, you know, security solution." I You could be asking me if my TPS reports are [1:42] filed properly. They're not. My taxes are also not filed. Don't tell the IRS. We're working on it. And the plain fact is we've been giving bad security advice for a long time as a cybersecurity community, and it's kind a problem. Uh there are good reasons for this, uh but the biggest reason is that it's not the 1990s anymore. Uh and that is where our advice continues to be stuck. Um it it's probably good that it's not the '90s. It is definitely not this '90s anymore. Uh but it is also not this '90s anymore, and a lot of our security advice assumes that these are still the computers that [2:19] we're using. Uh so, from you know, the and the the the TLDR did not fit in this talk. Believe me, I tried. Uh find me afterwards. But the the reason here is that the internet happened. Like, we connected all of our computers together. Uh and now, you know, the advice that worked when we were all sitting in cubicles in, you know, uh beige offices uh 20 years ago just [2:43] doesn't apply. Um yeah, yeah, yeah. But the internet is the reason that we're all here. So, we have to figure out what to do about it. Uh and so, uh from the background of working in security at one of the software companies, some of which you might have uh heard of, uh like how do people actually get hurt? Like, what did we see being on the receiving end of a lot of adversarial behavior, uh like we were just talking, uh that actually mattered? And the flip side of that being, like, where then can we target the most effective interventions so that we are, you know, making the most uh best use of our time, [3:19] our money, our energy, and our customers' time, money, and energy? Uh so, that brings me to to the subject of my talk. Uh these are again, like, interventions that I made in my own organization, little organization, um about three people. It's me and a few 1099s, uh but that have really moved the needle for us, and that were, you know, straightforward things that we could do just every day as part of our processes to, like, improve uh the way that we work. Um and so, you know, the first threat that gets people in trouble, uh one of the first threats that get people in trouble is password reuse. This is where your [3:55] CFO or your bookkeeper turns out to have used the same password uh on a Minecraft forum that they use for a bank. That's bad. And you you wouldn't think that it happens, but oh boy. [laughter] Stuff like that happens too often. Uh and so what I want to encourage you all to do is to start using a password manager uh if you're not already. Now, audience participation time. Quick show of hands, who here is already using a password manager? That can be LastPass, that can be Oh my god. I'm going to need to update my advice. This is great. Uh you can be writing something down on a [4:24] piece of paper. This is another way our advice has changed since the '90s. Write your passwords down if it means you're not reusing them. Um awesome. So, for all of you who just raised your hand, that's incredible. I love you. Uh if you didn't just raise your hand, come join us. It is better over here. Using a password manager has genuinely made my experience of the internet way better. It's just easier, [4:43] it's faster. Come join us. I use and recommend LastPass. Uh I use and recommend LastPass for a whole host of reasons, that it works great for teams. So, like I can share my airline password with my admin through a secure vault. Uh when I change my airline password, she can still log in. When she changes my airline password, I can still log in. Um it's subscription-based, which means you can be assured that you'll get security updates and they won't sell out to Russia anytime soon. It is worth every penny. Uh I have a giveaway at the end of the talk, but uh we'll get to that in [5:14] a second. Uh we're actually going to pause now. If you do not have a password manager, get out your phone. Uh You said one password. Is there LastPass or one password? One password. Did I say LastPass? Oh my god. I'm so sorry. Uh I recommend one password because LastPass has had a bad history of security breaches and I'm tired of and I'm tired of answering the question every 6 months like is LastPass still okay to use? Just use one password. So, [5:42] anybody take out your phone. Going once, going twice. All right, great. Um So, that's password reuse. Uh start using a password manager. You don't have to get all your passwords in. Uh you can add them as you go. Uh don't boil the ocean, but get started. Um second threat, something called spear phishing. Uh you might think the answer to this is [6:02] implementing two-factor authentication. It's not. Uh implement an agreement with your staff that money never moves without strong authentication and authorization. So, what's the threat here? Uh me, Kevin, sends an email to my admin Sasha, which is like, "Just get on the plane. Uh close the deal. Please wire money to this uh account number. I [6:22] can't talk now. Bye." Uh you would be surprised how often this uh works. Uh it's been hitting a lot of nonprofits lately. They have a decent amount of money and a wide variation, let's say, in their accounting controls. Um my bookkeeper and my admin and I have a pre-existing agreement that I will never ask them to move money via email. Uh they know there are some invoices that are automatically approved, like my admin's invoice comes through first of [6:47] the month, uh $900 goes out to Sasha. Everything else I log into our accounts payable system and manually approve. No exceptions. They know that if they get an email from me saying, you know, "Hey, Darcy, go move the money." it's it's it's an attack. Um This tactic accounts for millions of dollars in fraud every year. People do not get their money back. Uh this puts people out of business. They have to go ask friends and family to bail them out. It is bad. Uh and it is really simple. It is cheap for [7:17] advertisers. They find you on LinkedIn. They send some emails. Uh they don't get caught. Little bit of planning and process discipline. I it feels silly. And, you know, if this has happened to you, like, no judgment here. Um we've all been there. We're all firing out of system one. It's just like getting through the day, closing our inbox out, and it happens to people even after you implement this, it might still happen to you, but a little bit of process here, a little bit of pre-existing agreement uh can save a lot of heartache. So, now set up two-factor authentication on your [7:47] primary email domain. Okay. [laughter] Just got to get that out of the way. Um So, that's spear fishing. The last thing is credential stuffing attacks. That's what happens when that Minecraft forum gets knocked over by a hacker. They take the the password database dump and they run it against your site. Uh this is what happens as soon as you put a login [8:04] form on the internet. Ask me how I know. Um The solution is to rate limit all your authentication endpoints. And there are two kinds of people in the world, people who are like, "Obviously, Kevin. What are you talking about?" and people who are finding this out for the first time, sometimes face first. So, uh if whichever kind of person you are, uh [8:22] yeah, that's why I'm bringing this up. Um I'm really not kidding about the Minecraft forum thing. Uh my email address and password are in that lower one. Uh yours may be in that upper one. Uh it's You don't want to find out uh when somebody takes over your bank account. Uh You also don't want to find out when someone takes over one of your customers' accounts. Uh any login form on the internet can and [8:46] will get these dumps tried against them. Again, ask me how I know. Um And you might be like, "I'm running a bookmarking site. I'm running a family photo sharing site. I run a recipe site." Like, if your users are paying for it, they value it. What I'm trying to tell you is that you're all worth it. Uh and you're worth it. Your users, you're worth it to yourselves, and you're worth it to your adversaries. If you build it, they will come. Um They're also account takeovers. They really suck. They're an enormous support burden. If you've ever been on the support side of this, you're helping somebody who's having the worst day of [9:16] their life, and you're also having a really bad day, and you often can't tell if that person is genuinely having the worst day of their life or if they're an adversary trying to, you know, deepen their attack. Um So, the details did not fit in this talk. I don't think the details would fit in any 12-minute talk. The key insight is just more friction, the more requests you get. If you're getting more than one login request a second, that's not a human typing at a keyboard. That's an automated system. Um Also, so there are a bunch of useful tools. This is the good news provided by [9:49] everybody in your ecosystem uh from your your hosting provider AWS. There's this vendor called Stanza who are doing this as a service. They seem cool and like bootstrappy. Um you can also just roll this with Redis. A lot of people do. Uh whichever way you go, you know, whatever works for you. Um do this for both your user authentication endpoints and your API authentication endpoints. You would be surprised how many people rate limit one but not the other. Uh you're like, "Oh yeah, obviously we have to rate limit off, you know, automated systems." And people forget that your adversaries can just view source, find your user login [10:22] uh endpoint, and you know, run their dumps at that. Um and they will. Um the alternative to doing this uh before you launch is doing this while you're under active attack. Uh I'm friends with a bunch of people who were launching cryptocurrency projects for a while, and I lost count of the number who had, you know, launched on Product Hunt and then told me they had to implement rate limiting while they were under active attack, you know, within hours after launch. Um so, if you're dealing with money, you know, you're more likely to get hit uh fast and hard, but yeah. Any login form on the internet is going to [10:56] see this or can see this. So, those are my three recommendations. Uh there's a bunch of stuff that I missed, but these are things that are important to start doing and start doing early. Um they're relatively straightforward, they're relatively inexpensive, and they move the needle in ways that nothing else does. Um So, yeah, that's the that's the call to action. It's like whichever one of these, you know, start today. Um if you're already doing one, do the next one. If you're not doing any of these, pick whichever one sounds like the most fun. Uh if you're doing all of these, you're doing better than some many of your peer [11:34] organizations and there is a certain element of like having to run faster than the guy next to you rather than having to run faster than the bear. Security is a process, not a product despite what my colleagues will tell you. The goal is this is how we keep our customers happy. This is how we keep that revenue graph [11:52] going up into the right. This is how we keep enjoying and being bootstrap founders and I just keep like you know, may realizing you know, the dream that we all have of doing this on our own terms. Um So, that's the advice. This is me. If you email me, the first three people to email me at hello@complexsystems.group about either where you are in your cybersecurity journey or an essential intervention that you've implemented that I didn't talk about. First three people free goodie bag with a YubiKey [12:24] and a month of one password. Um Thank you. Also, this is my podcast. So, check it out. All right. Take care everybody. --- About this transcript Read from YouTube's own caption track and laid out by ViewRank AI (https://viewrankai.com). ViewRank AI finds the videos already beating a creator's own average on Instagram, TikTok and YouTube Shorts, transcribes them from the audio itself in more than 60 languages, and turns what worked into new ideas and scripts. Free transcript tools, no account needed: https://viewrankai.com/tools How to read any video this way: https://viewrankai.com/llms.txt