Everything Dr. Eduardo Rocha said on any show that made the record, most notable first. Each card names its show and opens the statement there.
Rocha: 70-80% confident cybersecurity will adapt before quantum decrypts systems
“Somewhere between 70 and 80%.”
Rocha: Authentication will shift from accounts to identities within two years
“I think at some point in time, and this might be the year or the next year, we will migrate from accounts to identities, right?”
Rocha: Quantum computing could break current encryption within a decade
“Probably a decade or less.”
Rocha: Launching DDoS and Heavy Scraping Attacks Is Now Very Cheap
“Launching DDoS and heavy scraping attacks are now very cheap, you know”
Rocha: Pegasus spyware bypasses authentication to access all targeted phone data
“Well, it was some kind of spyware developed by some From out in the world that could basically access all the information in your phone, and they could also, assuming they would have your phone in hand, they could basically access all information by breaking a…”
Rocha: Log4j exploit triggered remote code execution via logged HTTP strings
“Well, it was an attack in which A specific string would be sent with HTTP requests that that then this would be logged by this logging mechanism called log for J. But in the background, that information could be properly processed and triggering some download …”
Rocha: Hackers actively embed malicious code into open-source software libraries
“The biggest problem is a lot of people embed open source code in their projects. It's a known problem that hackers contribute actively to, or may try to contribute actively to open source and then embed that code.”
Rocha: Modern bots replicate human behavior too closely for easy detection
“In the bot world, in the automation world, where we constantly battle against web scrapers and fraudsters and try to stop account takeover attacks and credential stuffing. There it's sometimes there's a bit of a gray area where automation replicates so well th…”
Rocha: Log4j Was Exploited Before Security Teams Had Detection Signatures
“So if you think about also the log for J that we had at the end of last year, there was a certain period of time in which that vulnerability was being exploited, but we weren't aware, and we didn't have a signature to properly block it.”