Keynote - John Strand

John Strand (Keynote Speaker)

SAINTCON 2025 · Day 3 · Keynote

Overview

John Strand's keynote address at SAINTCON, provocatively titled "Onions, Belts, and Fashion," transcends the typical cybersecurity discourse, urging the audience to look beyond the prevailing narratives of ransomware and AI hype. Strand, a seasoned veteran in the information security community and a dedicated educator, challenges the industry's complacent focus on remediating known vulnerabilities while ignoring deeper, more systemic threats. His talk delves into the often-overlooked and uncomfortable truths of modern cybersecurity, from the historically driven cyber ambitions of nation-states like China to the sophisticated, untestable attack vectors employed by groups like NSO, and the pervasive problem of supply chain compromises.

Watch on YouTube

Visual summary for Keynote - John Strand by John Strand
Visual summary for Keynote - John Strand by John Strand

Key moments

  1. 0:00 Host introduces John Strand with a personal anecdote
  2. 2:40 John Strand shares 'the rest of the story' from intro
  3. 4:45 Revealing the talk's mysterious title and its meaning
  4. 5:15 Honest AI image generation disclaimer and hilarious prompt example
  5. 6:10 Introducing the core theme: critical, unaddressed infosec topics
  6. 7:30 Challenging the misleading 'reduced dwell time' metric due to ransomware

Keynote - Onions, Belts, and Fashion

Speakers: John Strand (Keynote Speaker)

Conference: SAINTCON

YouTube: https://www.youtube.com/watch?v=5kXQQopuby8

Overview

John Strand's keynote address at SAINTCON, provocatively titled "Onions, Belts, and Fashion," transcends the typical cybersecurity discourse, urging the audience to look beyond the prevailing narratives of ransomware and AI hype. Strand, a seasoned veteran in the information security community and a dedicated educator, challenges the industry's complacent focus on remediating known vulnerabilities while ignoring deeper, more systemic threats. His talk delves into the often-overlooked and uncomfortable truths of modern cybersecurity, from the historically driven cyber ambitions of nation-states like China to the sophisticated, untestable attack vectors employed by groups like NSO, and the pervasive problem of supply chain compromises.

The presentation serves as a critical examination of the industry's blind spots, highlighting how a reliance on conventional testing methodologies and vendor assurances leaves organizations vulnerable to advanced adversaries. Strand argues that the "war on general-purpose computation" has been lost, and the increasing complexity of IT environments, coupled with a decline in fundamental curiosity and research, is creating an unsustainable security posture. Despite these grim realities, he offers a powerful silver lining: the "golden age of education" driven by community-focused, accessible training initiatives that empower individuals and fundamentally shift the landscape of cybersecurity learning.

Background

▶ Watch: Host introduces John Strand with a personal anecdote (0:00)

John Strand opens his keynote by expressing a growing frustration with the prevailing themes in cybersecurity over the past decade. He observes that much of the training and discussion remains anchored to issues like Active Directory exploitation and web application vulnerabilities, which, while still relevant, overshadow a "whole universe of things we really aren't talking about." He uses the analogy of a magician, suggesting that the industry's fixation on ransomware acts as a distraction, drawing attention away from more subtle, insidious threats. This is further exemplified by the industry's tendency to "boast" about reduced dwell time—a metric Strand ironically points out is often skewed by the swift, overt actions of ransomware operators.

Another major "oxygen suck" in the room, according to Strand, is the pervasive hype surrounding Artificial Intelligence (AI). While acknowledging AI's potential impacts, he firmly dismisses the notion that it will "absolutely save this industry," arguing that such a belief betrays a fundamental misunderstanding of both AI and information security. He points to the alarming trend of junior-level analyst jobs disappearing as executives, swayed by AI hype, prematurely believe the technology can replace human expertise. This backdrop sets the stage for Strand's deeper exploration of the "under the surface" issues he believes the industry needs to confront.

Key Findings

▶ Watch: Revealing the talk's mysterious title and its meaning (4:45)

Strand's talk unveils several critical, often neglected, aspects of the modern cybersecurity landscape:

  • China's Historically Driven Cyber Superiority: Unlike common narratives, China's cyber strategy is deeply rooted in a "century of humiliation" and a profound drive for global cyber superiority, not merely parity. This historical context shapes their unified, highly targeted approach to critical infrastructure compromise, as seen in operations like Volt Typhoon and Salt Typhoon.
  • Untestable Nation-State Attack Vectors: Groups like NSO Group (known for Pegasus malware) demonstrate sophisticated, zero-click malware delivery via malvertisements through ad networks. This highly targeted method is nearly impossible for standard organizations to test or defend against, creating significant blind spots due to legal and technical limitations, echoing Josh Wright's Law that vulnerabilities aren't patched until an exploit is public.
  • The War on General-Purpose Computation is Lost: Mobile ecosystems (iOS, Android) and cloud vendors are increasingly "welding shut" their platforms, restricting independent security research and making it difficult for curious individuals to analyze and understand how these critical technologies work. This trend stifles the very curiosity that drives effective hacking and defense.
  • Pervasive and Ignored Supply Chain Vulnerabilities: From the Cisco Raider attack (2008) to SolarWinds (2020), XZ Utils (2024), and the F5 breach (2023), supply chain compromises are recurrent, sophisticated, and often met with collective shrugs or vendor denials. The XZ Utils backdoor, discovered by Andreas due to a minor login delay, highlights the fragility and reliance on individual, exceptional curiosity for detection.
  • Extrusion Detection as a Critical Neglected Practice: While the concept of watching what leaves the network (coined by Richard Belelch) is fundamental, many organizations still seek "magic" tools for automatic detection rather than actively hunting for anomalous outbound traffic.
  • Vendor Disclosure Failures and Mediocrity: Large vendors often dismiss legitimate vulnerability reports as "features" or irrelevant if not immediately Metasploitable. This attitude, coupled with a lack of transparency (e.g., "proprietary AI algorithms"), hinders effective defense.
  • AI's Double-Edged Sword: While AI is crucial for managing the overwhelming complexity of modern IT, its current application as a "plagiarism engine" is leading to the "standardization of mediocrity" in software development, creating new, subtle business logic errors and reducing developers' understanding of their own code.
  • The Golden Age of Accessible Cybersecurity Education: Despite the challenges, the industry is experiencing a positive shift towards community-driven, affordable, or "pay what you can" training, exemplified by organizations like Anti-Siphon and individuals like John Hammond, Kevin Johnson, and Tanya Janca. This movement is democratizing access to cybersecurity careers and empowering a diverse new generation of defenders.

Technical Deep Dive

▶ Watch: Honest AI image generation disclaimer and hilarious prompt example (5:15)

Strand's technical deep dive begins with a compelling historical analysis of China's cyber strategy. He explains that China's pursuit of "cyber great power" status, envisioned by scholar Jiang Bjan in 2013 and championed by Xi Jinping, is directly influenced by its "century of humiliation"—a period following the Boxer Rebellion (late 19th/early 20th century) and extending through World War II and the loss of cultural artifacts to Taiwan. This history fosters a deep-seated desire for superiority, not just parity, in naval, air, and cyber domains. Historically, Chinese cyber operations were fragmented across various provinces and military units, leading to uncoordinated and often overlapping attacks. However, the perceived failure of Russia's cyber offensive in Ukraine (which aimed to disrupt critical infrastructure but was hampered by Ukraine's bolstered defenses) served as a critical turning point. China subsequently unified its cyber operations directly under the People's Liberation Army (PLA), shifting to a highly targeted, focused strategy aimed at gaining persistent access to critical infrastructure to implement "kill switches" during potential kinetic conflicts. Operations like Volt Typhoon and Salt Typhoon are prime examples of this long-term, strategic dwelling within adversary networks. Strand notes that China has also ceased sending its top talent, like the former Sexy Pandas CTF teams, to external competitions, instead fostering internal talent development and challenges.

Moving to nation-state attack vectors, Strand highlights the NSO Group and their Pegasus malware, but crucially pivots to how such malware is delivered. He reveals a terrifying capability: zero-click malvertisements. NSO Group can allegedly deliver malware through legitimate ad delivery networks by drawing precise geographical boundaries, setting up detailed user profiles, and targeting specific device types. This allows for near 100% accurate, invisible malware deployment without user interaction. The critical technical challenge here is the lack of a robust testing methodology for such attacks. Traditional penetration testing firms are limited to standard reconnaissance, scanning, exploitation, and post-exploitation techniques, none of which adequately simulate or detect this advanced form of malvertisement. Furthermore, legal constraints prevent security researchers from actively testing these ad networks or individual employee devices, creating a massive defensive blind spot. Strand invokes Josh Wright's Law, which posits that organizations often won't patch vulnerabilities until a Metasploit exploit is publicly available, underscoring the danger of untestable, unprovable threats being ignored.

The discussion then shifts to the mobile ecosystem and the broader "war on general-purpose computation." Strand laments the rise of monolithic ecosystems (like iOS and Android) where vendors actively "weld shut" their platforms. He cites Google's recent discussions about locking down sideloading of apps as an example, justifying it under the guise of security while the true motive is commercial control. This vendor-driven lockdown makes it exceedingly difficult, if not impossible, for independent researchers—the "kids with a laptop and an obsession"—to conduct good faith security research. Unlike the era of readily available open-source projects or Technet subscriptions for Microsoft products, modern mobile and cloud platforms are opaque, expensive to set up for testing (e.g., requiring specialized environments and tools like Curillium), and often legally off-limits for independent analysis. This loss of general-purpose computing means a significant portion of daily technology remains unaudited by the curious hacker community.

Supply chain attacks are presented as a recurring, sophisticated threat. Strand recounts the Cisco Raider attack of 2008, where counterfeit Cisco devices with specific serial numbers were sold to the Department of Defense. While public reports claimed "no evidence of backdoors," classified sources indicated a strong belief in targeted backdoors, highlighting a discrepancy between public disclosure and private intelligence. The SolarWinds attack (2020) by Russian actors showcased the systematic compromise of a widely used software update mechanism, impacting numerous organizations. More recently, the XZ Utils backdoor in 2024 demonstrated an extreme level of patience and sophistication: a malicious actor infiltrated the development team over five years, eventually gaining commit access to inject a remote control backdoor into SSH installations globally. This backdoor, discovered by Andreas due to a subtle, "hair longer" login delay, was a pre-authentication vulnerability that narrowly avoided catastrophic widespread impact, underscoring the fragility of the software supply chain and the reliance on individual vigilance. The F5 breach (2023), where attackers had access to source code and customer databases since 2023, yet the vendor claimed "no evidence of anything bad," further illustrates the problem of vendor transparency and detection capabilities.

Strand advocates for extrusion detection, a philosophy championed by Richard Belelch and implemented in tools like Security Onion and Rita. This approach focuses on monitoring outbound network traffic for indications of compromise, such as unusual beacons or command-and-control (C2) communications with specific jitter patterns. He cites examples where Rita successfully identified SolarWinds malware and other internal network compromises by German resellers and a large telco provider, demonstrating the efficacy of active hunting over passive prevention.

Finally, Strand dissects the impact of AI on software development and security. He acknowledges AI's necessity in managing the "hyper complex, almost infinitely scaling problem of computer security," particularly for automating the "80/20 principle" of dealing with common vulnerabilities. However, he warns against using AI to reduce headcount or as a panacea. Critically, he describes AI as a "great big plagiarism engine" that has homogenized code quality. He notes a qualitative shift observed by web application penetration testers since 2004, where Stack Overflow's decline in utility correlates with AI's rise. AI, by ingesting vast amounts of both good and bad code, tends to produce mediocre code, leading to a resurgence of easily exploitable flaws and business logic errors that developers, relying on AI, no longer fully understand.

Demo / Proof of Concept

▶ Watch: Introducing the core theme: critical, unaddressed infosec topics (6:10)

While John Strand's keynote did not include a live technical demonstration in the traditional sense, he effectively demonstrated the spirit of his company's approach to cybersecurity through various initiatives and tools, acting as "proof of concept" for his philosophy of accessible education and practical defense.

He highlighted Rita, a free tool developed by his company, Active Countermeasures, for extrusion detection. Strand shared anecdotal evidence of Rita's effectiveness, citing instances where a German reseller's proof of concept using Rita led to the discovery of SolarWinds malware on a customer's server months before the widespread public disclosure. Another example involved a large telco provider detecting internal malware using Rita, emphasizing the tool's capability to identify outbound anomalies like beaconing C2 traffic with specific jitter patterns. This showcases a practical, open-source approach to network defense that empowers organizations to actively hunt for threats rather than relying on automated "magic" solutions.

Strand also showcased Backdoors and Breaches, a competitive card game designed to simulate network attack and defense scenarios. He announced the release of Version 3, which transforms it into a game akin to Magic the Gathering or Dominion, allowing up to four players to engage in offensive and defensive strategies. This game serves as a tangible, engaging way to teach complex cybersecurity concepts and foster practical understanding.

Furthermore, he promoted his company's commitment to accessible education by offering a link to 16 hours of free labs with approximately 30 different environments. This offering, along with free comics and "zines" containing detailed articles, embodies his "pay what you can" training model. This model, which broke webinar platforms during COVID-19 with 7,000 attendees, is presented as a successful proof of concept for democratizing cybersecurity education, reaching diverse groups like stay-at-home parents and truckers, and proving that "there's money to be made doing the right thing." These initiatives collectively serve as a powerful demonstration of his commitment to empowering the community with practical tools and knowledge.

Defensive Implications

▶ Watch: Challenging the misleading 'reduced dwell time' metric due to ransomware (7:30)

John Strand's keynote provides several critical defensive implications for cybersecurity professionals:

  1. Deepen Understanding of Nation-State Adversaries: Defenders must move beyond generic notions of "Chinese hackers" and understand the profound historical and political drivers behind nations like China's pursuit of cyber superiority. This context helps anticipate their highly targeted, long-term strategies for critical infrastructure compromise (e.g., Volt Typhoon, Salt Typhoon) and shifts focus from immediate, noisy attacks to persistent dwelling and "kill switch" capabilities.
  2. Rethink Testing Methodologies for Advanced Threats: Traditional penetration tests are insufficient against sophisticated, untestable attack vectors like zero-click malvertisements from groups like NSO Group. Organizations need to explore new, creative, and potentially legally complex ways to simulate and detect such attacks, acknowledging that "if we're not testing for it, we don't fix it." This may involve advocating for changes in legal frameworks (e.g., good faith security research policies) to enable more comprehensive testing.
  3. Prioritize Extrusion Detection: Instead of solely focusing on inbound prevention, organizations must rigorously implement extrusion detection based on the principles of Richard Belelch. Actively hunting for anomalous outbound network traffic, including subtle beaconing and jitter patterns, using tools like Security Onion and Rita, is crucial for detecting sophisticated malware that has bypassed initial defenses.
  4. Demand Vendor Transparency and Accountability: Defenders should challenge vendors who offer "black magic handwaving" or dismiss legitimate vulnerabilities as "features" or non-Metasploitable. Demand transparency regarding AI algorithms, security practices, and breach telemetry. The F5 breach and the multi-million dollar fraud case highlight the dangers of blindly trusting vendor assurances.
  5. Foster Human Curiosity and Deep Technical Understanding: The XZ Utils backdoor incident underscores the irreplaceable value of human curiosity and deep technical digging. Organizations must cultivate environments that encourage engineers to question, investigate, and understand their technology at a fundamental level, rather than relying on automated tools or accepting surface-level explanations. This means pushing back against the "war on general-purpose computation" and supporting internal research.
  6. Leverage AI Strategically, Not as a Headcount Reducer: AI is a necessary tool for managing complexity and automating the "80% garbage" of common vulnerabilities. However, it should be integrated to augment human capabilities, not replace them. Defenders must be aware of AI's potential to standardize mediocrity in code and introduce new business logic errors, requiring enhanced human oversight and specialized testing.
  7. Embrace Accessible Education and Community Collaboration: The "golden age of education" offers unparalleled opportunities. Security professionals should actively seek out and support accessible, community-driven training (e.g., "pay what you can" models, free labs, CTFs). This not only enhances individual skills but also strengthens the collective defense posture by fostering a diverse, knowledgeable, and interconnected community of defenders.

Key Takeaways

  • Cybersecurity threats extend far beyond common narratives like ransomware and AI hype, with critical, overlooked areas such as nation-state motivations and untestable attack vectors.
  • Nation-state adversaries, particularly China, are driven by deep historical grievances to achieve cyber superiority, leading to highly targeted, long-term compromises of critical infrastructure designed for future "kill switch" capabilities.
  • Advanced attack vectors, including zero-click malvertisements and sophisticated supply chain compromises (e.g., XZ Utils), bypass traditional defenses and testing methodologies, creating dangerous blind spots.
  • Over-reliance on vendors, the decline of general-purpose computing, and a lack of transparency from major tech companies impede effective security research and foster a culture of unverified trust.
  • While AI is crucial for managing complexity, its current application as a "plagiarism engine" risks standardizing mediocrity in software development and should not be seen as a replacement for human expertise or critical thinking.
  • The "golden age of education" through accessible, community-driven training and practical tools is vital for empowering a diverse new generation of defenders and fostering a culture of curiosity and continuous learning.

About the Speaker(s)

John Strand is a highly respected and selfless keynote speaker in the information security industry, known for his deep technical expertise and dedication to education. With over 15 years of experience, he has been a prominent Black Hat trainer, often going above and beyond by staying late with students to ensure their understanding, exemplified by a memorable one-on-one training session in Seattle. Strand has a background in cyber offensive operations for the United States government and is the founder of Black Hills Information Security (BHIS) and Anti-Siphon. He is a passionate advocate for accessible cybersecurity education, championing the "pay what you can" training model to remove financial barriers and empower a diverse range of individuals to enter and excel in the field. His talk reflects his commitment to challenging conventional wisdom and addressing the uncomfortable truths necessary for advancing the security posture of organizations and individuals alike.

All talks from SAINTCON 2025