Thought Behind Things · Dec 15, 2021 · 57:37
Pakistanis don't care about their own data
Senior security consultant Mirza Burhan Baig walks through bug bounties, the social-engineering attacks that actually work on Pakistani banks, why iPhones are harder to hack than Androids, and what made the Pegasus exploit a state-grade weapon.
with Mirza Burhan Baig
9 min read
From Karachi web developer to bug-bounty hunter
The episode opens with Muzamil introducing Mirza Burhan Baig over the line from Riyadh, where Burhan is a senior security consultant at Riyad Bank and an international speaker on information security. Muzamil’s first question is the obvious one: how did someone end up here, in a field that most computer-science graduates in Pakistan still do not consider a career?
Burhan’s path is conventional on the surface and deliberate underneath. School and university in Karachi, then a master’s at Iqra in Islamabad, all in computer science with security as the personal interest he ran in parallel. He started, like everyone else, as a web and mobile developer — “once you are a developer, you know how to develop, then you go for the security” — and from there moved into bug-bounty work in 2013, when the idea that companies would pay strangers in dollars to find holes in their websites was still novel in Pakistan.
He delays his graduation to take a full-time job at Delta Tech in Karachi, where he ends up spending five years and watches the team grow from one room to thirty people. The work is core banking security for Bank Alfalah. He moves to Riyadh in January 2021 after a year of working there remotely.
The bounty economy: hundreds of bugs, dollars on rare occasions
Muzamil asks Burhan to expand on the vocabulary. White-hat, black-hat, grey-hat. Burhan walks through it cleanly. Black-hats use their ability for destructive purposes — phishing attacks, account takeovers, scams. He pauses on phishing specifically: a domain that looks like Facebook with an extra letter, an SSL certificate purchased to make the lock icon appear, credentials typed in and lost.
White-hats do the same work in reverse. They find a vulnerability, report it, and sometimes get paid. The infrastructure for getting paid is what changed the industry — Burhan names Bugcrowd, HackerOne, and Synack as the platforms that publish programs, set minimum and maximum bounty ranges, and pay in dollars routed through PayPal or Payoneer.
“Hundreds of them,” Burhan says, when Muzamil asks how many bounties he has found. Five to seven public listings on Facebook, Google, and Microsoft. A larger number on smaller sites no one would recognise. He is honest about the Pakistani end of the market: he once found a vulnerability in a well-known Pakistani website and was offered two cinema tickets as a reward.
Why universities aren’t producing security people
Muzamil widens the question. Pakistan’s freelancer boom, he argues, is stuck at the low-value end of the supply chain — design tools, basic content writing — because the country has no clear ladder to the more technical work above it. Where does that ladder come from? Four years of computer science?
Burhan’s answer is sharper. The field is not waiting on degrees; the field is starving for people. The good resources are not in Pakistan. Universities are not teaching security. He tells a story about a friend’s final-year project: the supervisor sat through a half-hour presentation on network attacks, malware, and viruses, and at the end said he did not understand the topic but would not be fooled, and would read up before the next session. Burhan is generous about it — the supervisor did, in the end, let the project go through — but the point lands. Even the people grading the next generation of security graduates are learning on the job.
Why Pakistani banks keep getting breached
The conversation turns to the recent leak of Pakistani bank data on the dark web. Muzamil asks the direct question: why are banks, of all institutions, still getting hacked?
Burhan’s first answer is organisational. Inside a bank, the CIO, CISO, and CTO have overlapping mandates, and the security team and the IT team end up blocking each other. A business team wants to launch a product on a specific date; the security team finds a problem; the launch slips or the problem ships. The hierarchy is built for friction, not for shipping secure software.
But the second answer is the one he keeps returning to. “We — as a nation, as Pakistanis — we don’t care about our own data,” he says. “I’m telling you honestly.” Every person on the call has four contacts whose phone-number databases are sitting in someone’s leaked spreadsheet. The most valuable thing on the dark web, he notes, is not credit cards but medical records — and Pakistan has no compliance regime tracking which clinics and pharmacies hold what. There is no functioning national computer emergency response team. The groups that have tried to build one, he says, have been blocked.
The bank phishing red-team that worked seventy percent of the time
The most concrete moment in the episode is Burhan describing a red-team service his firm sold to multiple Pakistani banks. The setup is almost embarrassingly simple. They registered a domain along the lines of abcbankhealth.com — a dollar’s purchase. They built a one-page site with the bank’s logo, colour theme, and a COVID dashboard with live-updating graphs. They wrote a single line of copy: COVID testing is free for bank employees and their families. To register, submit your employee ID, your username, and your national ID number.
They emailed that link to bank employees on their official addresses.
“If a hundred people were there, seventy gave the data,” Burhan says. “Without verifying.” This was not one bank. They ran the same exercise on five to eight banks. The follow-on sale was awareness training — which the same firm could provide.
The lesson he draws is the one he kept returning to throughout the conversation: “The system is secure, but the end user is not.” Burhan is clear that the new wave of Pakistani fintech licences — SadaPay, NayaPay, TAG, FonePay — have, as systems, tight security. The hole is in the person.
Hospitals, mobile phones, and the cost of a pirated copy of Windows
Muzamil asks where else the same problem shows up. Burhan names hospitals next. He cannot disclose the institution, but his team ran a red-team assignment on a major Pakistani hospital that included physical access to the data centre, RFID card cloning, Wi-Fi compromise, and the kind of deep network access that should not have been possible. The exercise was contractually consented to; no one was prosecuted; the hospital, he implies, has work to do.
Then he turns to personal devices, and the answer becomes a small parable about the Pakistani computing culture. People run pirated copies of Windows and install pirated antivirus on top of it. “First your Windows is not right, then your antivirus is not right,” he says, “and then you complain that you got hacked.” Every cracked installer carries malware that opens a command-and-control channel out of the network — webcam access, screen capture, file exfiltration, ransomware encryption. The mobile equivalent is the photo editor that asks for contact-list permissions and is granted them because the user clicks through.
Why iPhones are harder to hack than Androids
Muzamil brings up the obvious comparison. Burhan does not hedge. “Yes, way too secure from Android,” he says, “because Android is open source.” On Android, anyone can modify the kernel, sideload a custom ROM, root the device in minutes. Apple’s App Store requires code signatures and verification before an app reaches a phone, and although things still get through, the bar is meaningfully higher.
He uses the moment to explain DNS spoofing and a more specific public Wi-Fi trap: hotel and café networks that ask you to install a certificate to access the captive portal. Installing that certificate authorises the network operator to read your traffic in plain text, including data that would otherwise be encrypted end-to-end. His rule for public Wi-Fi is short. Use it if you have to. Do not install any certificates. Do not do anything financial on it.
On VPNs, Burhan separates the legitimate use case — corporate remote work, accessing services blocked in a particular region — from the consumer-grade free VPNs whose business model is unclear. He flags ProtonMail and ProtonVPN as the example of a privacy-first stack built around the principle that the operator should not be able to read the data passing through their own nodes.
Pegasus, zero-days, and state-level actors
Muzamil brings the conversation to Pegasus. Burhan explains the underlying concept first: a zero-day is a vulnerability that no one — not even the platform’s developers — knows about, which means no patch exists. Pegasus, he says, was built on three chained zero-days, all unpublished, all in the iOS stack.
The economics tell the rest of the story. Microsoft pays roughly a hundred thousand US dollars for a critical vulnerability through its bounty programs. That number is enough motivation for a white-hat. It is not enough motivation for a state-sponsored actor — what the industry calls an advanced persistent threat, or APT — whose budget is essentially political rather than financial. State-level actors can outbid the bounty programs and keep the exploits private. Pegasus, built by an Israeli company that publicly claims to sell only to legitimate governments for legitimate purposes, is what that asymmetry buys.
Muzamil floats the theory that the hacker collective Anonymous is itself a US government asset. Burhan does not confirm or deny — “we can’t say” — but he points out that high-profile hacker groups have been quietly flipped by states before and that the practice continues in Asian countries as well.
What he wants to build next, and what he thinks Pakistan looks like at a hundred
Toward the end, Muzamil asks Burhan where he sees himself in a decade. The answer is short. He wants to build a product, not sell services. Thousands of consultancies sell hours; a product compounds. He points to security.ai’s GDPR product as the kind of shape he has in mind — a tool that earns its keep without requiring its founder to keep selling time.
Muzamil closes the conversation with the question he asks every guest. Burhan is twenty-nine. Thirty years from now Pakistan turns a hundred and three. What does he think the country looks like?
“If the mindset changes, Pakistan will boost,” Burhan says. “If the mindset doesn’t change, Pakistan will remain the same, or worse.” He is talking about a specific mindset — the one that still says votes are bought with biryani, the one that still treats personal data as worthless, the one that runs pirated antivirus on a pirated operating system and then complains about getting hacked. The technical fixes, he implies, are downstream of that.
Full transcript
Sorry, Welcome back from the episode of Thorough Dry and Thing. All the way from Riyadh, Saudi Arabia. रियाद ही है ना? Yep. Right. मिर्ज़ा बर्हान बेग, he's a senior security consultant at the रियाद Bank. NDC के साथ साथ he is an international speaker. He talks a lot about information security, cyber security and a lot of these things जो कि आजकल काफ़ी लोगों का impact करना शुरू हो गई हैं. Sir, thank you so much for being part of the show. Thank you very much for having me. मैं conversation start करूंगा. सबसे पहले just sort of trying to understand your journey from high school till, you know, you becoming this sort of ethical hacker, security consultant. क्योंकि बहुत नई field है, बहुत different field है and generally जब एक even IT में लोग जाते हैं, तो they're looking at web development, app development. They're not really looking at these sort of, कि हम जो है जी, bounties hunt करेंगे, हम जो है जी, वह problems. Thank you. So tell me a little bit about that journey. Okay. So,
high school Karachi से, university भी Karachi.
Karachi ने कहां से किया था high school? Chaptin Wors, Gulcheng Bal में.
Then I'm pursuing master from इरफ़ा इस्लामाबाद. और यह computer science में ही था? Oh, yeah, computer science में था. तो मेरे majors जो थे basically I was into security things from the start. क्योंकि पहले phishing attacks काफ़ी होते थे. तो hacking का बहुत शौक था. Wholesale accountants हैं family में. So, no one knew कि what I was doing. So, I started this journey as a web developer, जैसे हर कोई करता है. Right. Mobile application developers. Then, once you are a developer, right? तो आपको develop करना भी आता है then you go for the security. Right. तो मैं जैसे मिलता हूं you do what? You do data analytics? Yeah. You do big data? Perfect. You are a SQL engineer? Perfect. But उसके अंदर security का element आप add कर दें. Right. So it all started with the bug bounties in 2013. Back जब हमें पता चला कि white hat hackers and bug bounty hunting होती है. Bug bounty hunting for people के बड़ी बड़ी जो companies हैं, they pay you to hunt the bugs on your website and they're paying the dollars. Right. So आजकल one seventy seven? Sir,
180 हो गया. मालूम है. मैं लेकिन लेकिन लेकिन freelancers खुशी हैं sir.
This all is a brief history of myself. Then I started career counselling and the sessions, awareness sessions आपने graduate कब किया था? 2017. मेरी graduation थोड़ी late है. ठीक है. क्योंकि started in 2011 and 2012 था but I started a job क्योंकि उस वक़्त market में लोग नहीं थे and someone approached me कि we want someone for the security. So what I did, मैंने job भी साथ करी और मैंने अपना office भी साथ ही रखा full time. Half time, part time नहीं था. जिसमें मैंने काफ़ी courses drop किए, semester breaks लिए क्योंकि मुझे assignment आगे इस्लामाबाद का दो महीने के लिए. So I have to go there. Right. So फिर मैं semester drop कर देता था. और यह जो drop थी यह किस company में थी? Digit Labs कराची में. बहुत अच्छे लोग हैं मैंने. पांच साल मैंने उनके साथ काम किया from the start, from one room to 30 people. अच्छा. मैं उनमें से शुरू शुरू कर था. So, काफ़ी अच्छा experience है ना वह resident engineer bank अलाभीप. Right. उनका core banking का solution develop हो रहा था उस वक़्त. Right. तो they were into कि हमें security करने वानी है. So लोग कम थे sir, लोग थे नहीं awareness थी नहीं market में तो फिर they hired me for a full time. And when did you end up, going to रेहत? I started remote work last year, April I guess, or I'm still working there. So remotely मैं एक साल काम कर रहा था, then I moved there, January के अंदर. सही है. So, yeah. चलिए, ज़बरदस्त.
थोड़ा सा मैं इसको expand करूं ना जो आपने, you know, you used a few keywords and I'd like to expand on that. First of all, you used white hat
hacking. Oh, yeah. What does that mean? Okay. So we have, two major black hat and the white hat. Gray hat भी एक चीज़ होती है हमारे पास. Black hat are people who use their ability for their destructive purpose, right? किसी का account hack कर लिया, account से पैसा निकाल लिया, और scam run कर दिया, phishing attack कर दिया. The phishing attack is the same. You know that, right? The the look and Phishing feel of the किस तरह से होगी? हां. So the look and feel of the website is really same. जैसे कि मैं facebook.com ही खोल रहा हूँ and the URL is similar to the Facebook. उसमें एक A extra होगा या book में एक O ज़्यादा होगा जो कि आप neglected naked eyes से आप नहीं पकड़ सकते लेकिन आपको पता है कि वह चीज़ ग़लत है. Ok, they purchase a certificate as well जिसके अंदर SSL certificate आता ताकि वह बहुत ज़्यादा legit लगे कि यह website बिल्कुल original है. हां. And you put up your credentials and end up losing your credentials to someone else. Fishing attacks काफ़ी ज़्यादा होते हैं. So, yeah. ठीक हो गया. और WhiteHat फिर क्या होता है? WhiteHat यह होते हैं लोग अपनी ability use करते हैं, for constructive purpose. For example, मेरे पास एक website है, उसका database मुझे नज़र आ रहा है कि यह leak हो रहा है या leak हो सकता है इसमें क्या error है? So I report that website कि आपको legitly यह चीज़ सही कर देनी चाहिए and for that they some people pay, some people don't pay. तो बुरा मानने की बात नहीं है कि Pakistan लोगों को मैंने pay नहीं करती sir मैंने एक website में निकाला था, बहुत बड़ी website है, बहुत मशहूर website है पुरानी. So they offered me कि सैन्मय के दो tickets ले लें sir. मैंने कहा thank you very much sir.
सही है, सही है. और इसी तरह बड़ी companies भी आप
so we we have to arrange PayPal, we have to arrange PayNear and multiple other streams as well. So होता ये है कि अब तो बहुत सारी websites आ गई है. Buckcrowd, HackerOne is the most famous one जहा पे programs list होते हैं. उनकी minimum maximum bounties लिखी भी होती हैं and you earn for them. Report submit करते हैं. They evaluate that and they will pay you in dollars accordingly. वह एक criticality के हिसाब से होता है. Right. So शुरू में ही नहीं होता था जब हम करते थे.
नहीं बिल्कुल. Technical field as I hear it. Exactly. How many bounties have you found for for these, you know, sort of structured organizations?
Sir, hundreds of them. अच्छा. Hundreds of them in the past but अब बहुत कम time मिलता है क्योंकि dedicated Course क्यों drop हो रहा है? किसी ने कोई मुझसे पूछे हो जाए. तो आपको बड़ा patience चाहिए होता है इस चीज़ के लिए. For the Facebook and Google and Microsoft there are five or seven listings till now मेरी जो कि हैं लेकिन multiple websites हैं जिनका नाम नहीं पता लोगों को लेकिन उधर भी हमारी listings होती हैं. Right और यह किस किस्म के bugs थी basically जो आपने यह ढूंढी दी? That depends mobile applications भी होती हैं और web applications होती हैं. अब थोड़े structures बदल गए हैं चीज़ें infrastructure change हो गया है तो लोग अब अपने internal internet जिसको हम बोलते हैं उसकी bounty करने की है या penetration testing basically जो actual word है वो करने के लिए भी invite send करते हैं. There is a website Senec के नाम से Senec वो होते हैं packets होते हैं sing करने के लिए और acknowledge करने के लिए. Right. So there is a website Senec के नाम से. So बड़ी बड़ी companies approach them और पूरा एक program list होता है उसमें hackers को invite send किया जाता है and they
So यह है scene. Interesting. The first come first sir sort of situation है. How big is this industry, information security overall?
Pakistan में? Globally.
Opportunity wise में देख रहा मेरी कल एक साहब से बात हो रही थी इधर podcast पर ही तो हम, you know, we were discussing how Pakistan में freelancers का एक sort of boom आया हुआ है, वह सारा कुछ है but उसमें unfortunately we're still stuck out at very sort of low value, supply chains, right? Like, we're talking about very basic things जिस पर जिसमें आपको कुछ भी नहीं आता तो आप first step में जाएंगे और जाकर आप कोई tool सीख लेंगे और आप कहेंगे कि यार ठीक है मैं you know some sort of logo design या language को use करके मैं content writing कर लूंगा which is fine. Mhmm. Step one, but then उसके अंदर उससे आगे लोगों को अभी तक समझ नहीं आ रहा कि हम अपने आप को upskill कैसे करके, next step है कहां जाएं? Mhmm. ज़ाहिर है कि हम यह तो बात कर सकते हैं कि चार साल का computer science का course करें but वह चार साल personally I think कि it's not necessary.
Projects उस तरह से. Mhmm. बहुत अच्छी बात ने बात है. In future मैंने इसको नहीं देख रहा, मैं उसको in present देख रहा हूं. Right. क्योंकि यह field इतनी इतनी बड़ी है, लोग इसको अभी तक cater कर ही नहीं पा रहा है. जो अच्छी resource आपको मिलेगी वह आपको Pakistan में नहीं मिलेगी. पहली बात यह. Right. जो मिलेंगे फिर आप उनको ही रखते हैं और उनसे आप आगे मज़ीद working करवाते हैं. The second thing कि university नहीं पढ़ा रही. मैं आपको honestly बताता हूं मेरे एक बड़े अजीत sir हैं. अब तो वो माशालाह SOC dean हो गए हैं. So, मेरा एक दोस्त है कराची में मेरे साथ ही होता है. He is in digital marketing for a bank. So, final year project की बात आई. तो उन्होंने बोला क्या बना अच्छा. Problem यह थी कि university में ना तो किसी ने वह course पढ़ाया, ना वह course के बारे में किसी को पता और ना मेरे sir को भी इतना उस वक़्त नहीं पता था. Presentation होती है initial. मैंने पूरी presentation दी आधे घंटे की sir यह यह यूं होगा, यूं होगा, यह network में पकड़ेंगे, ऐसे virus आएगा, malware आएगा. दो minute तक देखते हैं representation कह रहे हैं देखो मुझे इस बार में पता नहीं है लेकिन तुम मुझे बेवकूफ़ नहीं बना सकते. मैं अगली बार पढ़कर आऊंगा.
But in the end he was very cooperative क्योंकि फिर अच्छा उन्होंने करवा लिया आपसे. क्योंकि यह बड़ा यह भी problem होता है कि आप जाते हैं एक project लेकर और university professors को चूंकि खुद idea नहीं होता वह कहते नहीं जी यह बेकार चीज़ है.
Something बनाई थी लेकिन वह अब अब सिर्फ़ USB में ही है. Right. वह physical नहीं आ सकी. So that was my physical मतलब final project as well. Right.
जब मैं बात करता हूं information security की तो उसमें क्या क्या different areas हैं जिसमें आपको लगता है opportunities आ सकती हैं? Sir, computer science के वाले से आप digital marketing में हैं और आप different लोगों से मिलते हैं. आप,
guarantee है. अगर आप सौ लोगों से मिल रहे हैं तो पचास ऐसे professions हैं जिसके अंदर information security चाहिए. So competition बहुत ज़्यादा आ गया है. So you have to go for a market और product होना चाहिए आपके हाथ में. जिस तरीके से बड़े मजे की बात है हम लोग दो दिन पहले discuss कर रहे थे meta. Sir next big thing meta. Meta के अंदर इतनी security के concerns अभी आने वाले हैं और बहुत बड़ी opportunity आने वाली है. तो यह तो field ख़त्म ही नहीं होगी. आप जिससे मिलेंगे उस चीज़ के अंदर security का element होना मेरी नज़र में लाज़मी है. हां. तो यह बड़ा मैं तो सलाम करता हूं sir. किसी भी organization में जाता हूं, कोई बड़ा bug मिल जाता है, मैं developer से मिलता हूं, thank you. आप ही ने तो बचाया sir मुझे. तो यह है the market is very very vast. Right.
Recently आपने देखा था कि Pakistan में banks का data चोरी हुआ था. You know, सुनने में आया जी वह पता नहीं. क्या क्या नाम है यार वह उसका alphabet है कौन सा है? उसके ऊपर पड़ा हुआ था सारा dark web में. Why do you think banks are still at a point where they're getting hacked and their data is getting stolen?
एक organization की hierarchy की बात भी हो सकती है और reporting features की बात भी हो सकती है. Reporting features मेरा मतलब यह है कि ज़िम्मेदारी लेना. अच्छा multiple times क्या होता है CIO जो होता है information officer, chief information officer उसके नीचे CISO होता है. ठीक है. NCTO होता है chief technology officer. Sir ये IT वाले और security वाले एक दूसरे के इतने काम आगे पीछे रोकते हैं और इतने hurdles create करते हैं क्योंकि obvious सी बातें देखें business team आती है business team बोलती है यह product launch करना है, ठीक है? वह ज़्यादा security वाले के बाद. Security वाला बोलता है इसके अंदर यही मसला है और यह launch date पर launch नहीं हो सकती.
अगर वो भी हो सकता है तो हम तो छोटे हैं ना हम तो ऐसा ही है. लेकिन
उसके बाद भी सबसे बड़ा मसला है कि हमें ना as a nation as a पाकिस्तानी हमें अपने data की फ़िक्र नहीं है. मैं आपको सच बता रहा हूं. आपके भी चार connections होंगे, मेरे भी चार connections हैं जिनके बाद नाद रखा और आपके mobile phones का data रखा हुआ होगा. Databases हैं जो कि leak हुई हुई है जो कि public के हाथ में है. मैं search करूंगा mobile और हमें मज़ाक लगता है. सबसे ज़्यादा जो research और जो एक data के आप data वाले हैं तो data के point of view से सबसे ज़्यादा जो hot selling item है ना dark web में वह है medical records का. अच्छा. इसके बाद आता है आपकी financial information. आपके credit cards आते हैं, card इनकी information. कोई बात नहीं. सबसे बड़ा मसला यह है. हमें अपनी data की फ़िकार ही नहीं है. आप बाहर चले जाएं. छोटी सी छोटी से छोटी shop होगी ना उसकी भी अगर compliance है तो उसका भी track रखा जाता है क्या? आप data ले तो रहे हैं? आप use कैसे कर रहे हैं?
यह basically यह telcos के साथ ही हुआ था. वह करते यह थे कि वह जो है ना आपको, based on your call record history and your SMS? SMS, वह उसी basis के ऊपर वह आपको Internet history देते थे. बिल्कुल ऐसा ही है. ऐसा ही है. तो स्वामीन data can do do do remarkable things. अभी आपने देखा है recently यह इनका Pakistan की जो embassy है in Siberia. Siberia. Exactly. That got hacked. Exactly. Password issues sir. अभी यह मुझे बताएं कि यह government level के ऊपर considering कि हम एक ऐसे दुनिया में खेल रहे हैं जहां पर it's quite clear कि, you know, Russia और America का हमने देखा कि क्या system चल रहा है. Pakistan, India का we've been we've been seeing recently बहुत ज़्यादा cyber attacks भी हो रहे हैं, सारा कुछ हो रहा है and जो future of war है वह it's not tanks and missiles. It's essentially information, right? Like, you can use information. The right information in the wrong hands or the wrong information in the In in the wrong hands. Whatever hands, yeah. Can change the way that anything works, anything functions. एक WhatsApp पर चीज़ viral होती है, लोग जाते हैं जाकर जी पूरा पूरा शहर जला देते हैं. Exactly. उस, system में बड़ा important बनता है कि जो state है, जो हकूमते वक़्त है, उसकी responsibility यह ज़िम्मेदारी है कि वह security ensure करें data की, आपके critical infrastructure की, जिस तरीके से वैसे भी होती है कि अगर for example अगर मेरे पास एक building है तो मैं मैं assume करूंगा कि मेरी state उसको protect कर रही है. कोई कोई adversary आकर उसको attack नहीं करती चली जाएगी. Exactly. तो digital infrastructure को भी उसी तरीके से protect करना चाहिए but unfortunately हम Pakistan में वह नहीं कर रहे हैं. What are the ways do you think के through which we can actually do that?
एक customer आप पर दुबारा कैसे भरोसा करेगा? Pakistan में sir वह चीज़ नहीं है. Right. Pakistan में एक hack हो गई organization आप दुबारा वह use करेंगे. हां. लेकिन दूसरा बड़ा problem बड़ी बड़ी companies hack होती हैं. Sony का बहुत बड़ा attack हुआ था पूरा data leak हो गया था. हां कौन सी movie थी उनकी बड़ी मशहूर movie थी वही leak हो गई थी. Pre release से पहले ही हो जाता है data. हां. क्या हो गया इसमें? वह companies आकर on record press conference करके बताती हैं. Electric के अलावा competition आने नहीं देते. K electric के अंदर competition बनता नहीं है. तो वह कहना है जो है बंदे ने तो use करना ही है. Mhmm. अब चाहे है को, चाहे कुछ भी हो. Power grip की आप बात कर रहे हैं तो we also do the red teaming. एक concept होता है red teaming का. Right. Physical penetration testing. उसके अंदर क्या होता है कि बस मुझे hack करना है, मुझे अंदर जाना किसी भी तरीके से. चाहे वह right means हो, wrong means हो. मैं आपको RFID clone करूंगा, मैं social engineering करूंगा, मैं आपका Wi Fi करूंगा, कुछ भी करूंगा. वह कहते हैं नहीं हम देख रहे हैं, हम कर रहे हैं. तो जब तक आप use नहीं करेंगे resources को, सबसे बड़ा इसके अंदर problem यह है. हर बड़ी country का एक cert होता है. Emergency response team होती है जो कि इस hacking की चीज़ों को देखती है. जैसे ना आपके ऊपर different divisions हैं. Pakistan में cert है ही नहीं. Mhmm. और जो बनाना चाहते हैं उनको बनाने नहीं दिया जाता. तो यह government का ही काम है कि वह नज़र रखें. आपने बहुत अच्छी बात करी कि critical assets हैं. Sir आपकी identity है. चाहे Siberia की हो, चाहे US की हो, चाहे Nigeria की हो लेकिन आपकी embassy आपका land, piece of land, है ना? अगर मैं embassy में हूं तो मैं Pakistan में खड़ा हूं. So आपकी ज़िम्मेदारी बनती है उसको secure करना. लेकिन unfortunately अभी तक उस पर इतना काम हो नहीं रहा. Right. Identity की बात की जाए तो अभी recently सुनने में ही आया कि जी नादरा का record जो है वह hack हुआ. ऐसा हुआ? Bicekord की identity जो है वह सारी क्या hackers के पास है? Sir, नहीं. Problem यह है कि हर Facebook के post को हम सच मान लेते हैं.
नहीं ऐसी कोई ख़बर है नहीं. जो आप एक अंड point से data gather हो रहा है just to sort of get context. That means कि किसी shop के ऊपर जाकर जहां पर आप biometric करवाकर के कोई sim निकलवा रही या कुछ करवा रही थी. Exactly. तो वह shop जो है वह basically जो जो लोग उस shop पर आए हैं उस shop
statement आपको web पर नज़र आ रही है वही उसको भी नज़र आएगी. Right. Extra वह अंदर जाकर आपके ना data निकाल सकता ना उसको change कर सकता है. So, यह बड़ी misconception है लोगों में. I feel like कि Pakistan में,
this is old. Not sure कि यह चीज़ change हुई है या नहीं हुई. But we don't have जैसा Europe में ना, for people who are interested they can check their out as well. GDPR बड़ा एक important law है, European Union पूरे के अंदर जो apply होता है. वह कर क्या रहा है essentially? वह यह कर रहा है कि उसने एक set of SOPs बना दिए, guidelines बना दी for, companies to operate क्योंकि जिसके तहत वह जो है वह आपकी data protection और वह तमाम चीज़ें कर सकते हैं. बिल्कुल, ऐसा ही है. Pakistan की telco industry, एक तो Pakistan में उस तरह का कोई law नहीं आई. Believe, मैंने अभी recently सुनाया कि government of Pakistan एक law लिखा दी है. Bill pass हुआ है. I don't know what it's called but it's something to do with, internet information security. But वह जो है उससे पहले this is like seven eight years ago. Remember आपका कोई भी employee जानने वाला हो ना telco का जो कि tech side पर हो. Data निकालाता था. तो वह यार वह उधर है ना वह इस number का देखकर उसने ना callएं किस किस को ख़र्काईं हैं. ऐसा ही है. लेकिन I was always dumbfounded कि यार इतनी random चीज़ है वह employee disgrunted हो. वह बैठकर एक query select sterile लगाकर जाना वह सारा data copy मारे और उसके बाद वह उठाकर लेकर चला जाए. तो it's a it's a very unfortunate और वह वही था कि बड़ी बड़ी companies थी यह काम करनी थी but governments had absolutely no idea कि इसको भी आपने regulate करना है. बिल्कुल ऐसा ही है. Do you think कि now there is a there is a there is a growing sense now within these companies? Now that we've seen, you know, Facebook going to congress. यह चीज़ें ऐसी होती हैं जो globally change लेकर आती हैं. बिल्कुल. Media में बात होती Do you think now there is a better understanding? बहुत सारी क्योंकि particularly fintech में, banks की बात की जाए तो बड़े आजकल scams हो रहे हैं. Mhmm. You know, वह क्या खिलाती है? Call skimming या वह क्या होती कि जिसमें वह number जो है वह दूसरा banks के अपने number से वह आपको call करते हैं और code उठाकर ले जाते हैं या easy पैसा this and that and people are losing a lot of money unfortunately. And ज़हर एक state bank digitization की वजह से वह बहुत सारे licenses तो दे रहे हैं. बिल्कुल. सादा pay को दिया है, उन्होंने नया pay को दिया है, tag है और बहुत सारी स्तरांक्षी. Forepay है. Forepay है. तो क्या कोई guidelines हैं इनकी
security की do you think? Sir जितनी सारी companies अभी launch हुई हैं ना इन सबकी बहुत जिसको बोलते हैं तगड़ी security है. The problem is कि system secure है लेकिन जो end user है वह secure नहीं है. उसको कैसे आप करेंगे? क्योंकि इसमें problem यह है कि आप वह किस तरह की चीज़ें missing है उसकी security में? नहीं, मैं endpoint user की बात कर रहा हूं. हां हां. System की तो मैं बात ही नहीं कर रहा हूं. ठीक है. Sir, सबसे बड़ी चीज़ है social engineering है ना? लोग जो जिस तरह हमारी बात हुई थी 35, forty, forty से plus हैं they trust everyone कि जो बोल रहा है सच बोल रहा है लेकिन the problem is उनको यह नहीं पता कि जो information वह मांग रहा वह बंदा ही नहीं है. Company के साथ, we found an opportunity to throw a service to the banks and all the other people as well. What we did? We did a red teaming assignment. किस तरीके से? जैसे bank है, ABC bank है. हमने पांच छह bank के साथ यह किया था. A b c bank है. मैंने क्या किया? मैंने बोला a bcbankhealth.com. अच्छा. Domain name तो sir आपको पता एक एक dollar में मिल जाता है. हां हां. Domain name ले लिया, hosting अलग करी, अपना एक page खड़ा किया. Same portfolio जैसी website का है, same color theme, logo with association with Synth Health bar and blah blah blah. Content COVID के stats लगाएं, graph लगाएं, जो run time पर change हो रहे हैं, बंदा flat और उसमें हमने यह लिख दिया है कि जो bank के अपने employees हैं उनके लिए COVID testing free है उनकी family के लिए. Submit your employee ID, your username and your NIC. हमने सिर्फ़ तय ही मांगा था. Sir अगर सौ लोग थे ना, सत्तर लोगों ने data दिया है. Without verifying और मज़े की बात, उनके official email पर हमने email किया. और यह एक bank की मैं बात नहीं कर रहा हूं आपसे. हमने कोई पांच से आठ banks के ऊपर यह experiment किया है कि for example फलाना फलाना bankhealth.com. बस. और लोगों से data मांगा है, mobile number दिया है. लेकिन जब होता था तो फिर फिर एक और service, service पर service कि भाई awareness training भी हम ही कराएंगे. तो that was the upscaling, upselling जिसको हम बोलते हैं. हां. So yeah.
Banks के अलावा what other areas do you think need need this sort of service Pakistan में? मुझे तो personally लगता है hospitals like you mentioned are are not secure at all.
आपने अभी throw किया है कि विशिफ़ा या इस तरह के hospitals हैं क्योंकि सारा तब online आ गया ना इनका? Sir, नाम disclose मैं नहीं कर सकता लेकिन एक बहुत बड़े hospital के साथ हमने एक assignment किया था red teaming का. Right. And जो हमारी team है they were able to access their data centers physically and they did an assignment जिसके अंदर RFID card भी clone किया गया है, जिसके अंदर Wi Fi भी hack किया गया है और जिसके अंदर proper proper hacking ही गई है. लेकिन in the end सबको पता था क्या हो रहा है. तो इसलिए कोई आपको file नहीं कर सकता because एक NDA sign होता है कि अब क्या है? So hospitals need to update themselves. क्योंकि मैं जिस hospital की बात हूं ना वह बहुत बड़ा hospital है. बाकी सब तो sir ध्यान ही उसी IP पर चल रहा है मैं और आप भी उसी IP पर चल रहा है. तो अगर मैं एक बार connect हो गया तो I can access. अब उसमें vulnerability है नहीं वह एक अलग बात है. हां. कि उसको मैं कैसे access करूंगा? But I am on the same network तो मैं try कर सकता हूं. Right. So यह बड़ा problem है. Health wise मैं बता रहा हूं. Health हो गया, banking, financial हो गया.
और क्या important होता है?
और important सबसे ज़्यादा है ना sir आपकी personal mobile. अच्छा. लोगों का जो mobile है, हम जो Android वाले users हैं वह application आपको पता है बचपन से अलम्दुल्ला pirated windows चलाएंगे हम सबने, ठीक है? हमें यही बताया गया कि pirated use करेंगे तो फ़ायदा है. पैसे तो देने नहीं है. अच्छा मज़े की बात है मुझे बड़ी हंसी आती है उन लोगों पर जो pirated windows use करते हैं. उसके ऊपर pirated antivirus use करते हैं. तो पहले तो आपकी windows सही नहीं फिर आपकी antivirus सही नहीं है. फिर शिकायत करते कि hack हो गए. क्योंकि आप अगर इसको बड़े chunk में देखें ना तो Windows आपका घर है. Right. ठीक है? उसमें खिड़कियां भी उसमें दरवाज़े भी हैं. आप उसमें एक भी pirated crack software या game use करते हैं ना तो आप एक window खोल देते हैं. तो crack के साथ sir चार चीज़ें और लग के आती हैं जिसको हम malware और virus और इस तरह कहते हैं जो कि C2 connection एक बाहर बनाता है outside the network और वहां से commands आ रही होती हैं कि webcam खोलो, यह करो, data copy करो और यह होता है. Ransomware भी यही चीज़ है कि आपने install किया और थक करके encrypted हो गई सारी चीज़ें. हां. So यह बड़ा problem है. Mobile के अंदर हम क्या करते हैं? Correct applications use करते हैं without. अब तो बहुत अच्छी चीज़ है कि Android के अंदर भी हर application की permission individually आप खोल बंद कर सकते हैं. पहले नहीं था. हां. पहले accept all सभी accept करनी है. अब मैं वह बोल रहा हूं एक photo editor है उसको मेरे context से क्या लेना देना? हां. लेकिन फिर भी मांग रहा है. एक बार आपने allow कर दिया तो legitly वो सब चीज़ें online दो minute में upload हो सकती हैं. Right. तो mobile security problem बहुत ज़्यादा है क्योंकि मेरे पास काफी ऐसे लोग through Instagram आते हैं, LinkedIn आते हैं कि लेकिन they are good doing a very good job. अच्छा your experience with FIU is good? Yeah exactly.
आपने कहा Android. What about iPhones? Pegasys का नाम सुना है आपने? अच्छा, that was going to be my next question as well. अभी अभी Pegasys को site पर रखें. Okay. Generally generally. Are iPhones more secure?
Yes, yes. Way way too secure from the Android because Android is an open source. You can develop, I can develop. पूरा हम kernel change कर सकते हैं और हम पूरा अपनी ROM change कर देते क्योंकि मुझे पहले ROM modify करानी है. हम उसको root पांच minute में कर सकते हैं. IPhone का क्या है? थोड़ा सा problem आता है. IPhone हर, application को upload नहीं करता. Properly upload करके verify करके code signatures करके उसके बाद verify करता है लेकिन उसमें भी कुछ चीज़ें bypass हो जाती हैं. लेकिन iPhone is way secure from मतलब अगर Android से उसको compare किया जाए तो. लेकिन अगर iPhone में कोई DNS is domain name server, right? Right. Which translates your IP address into a domain name. अब मेरे for example मेरा domain है बुरहानबेक.com. हां. उसके पीछे एक IP है. Right. तो IP को convert करके नाम में जुला रहा वह DNS हो गया. ठीक है. अब DNS proofing का मतलब क्या हो गया? नाम तो वही है, Second thing hotels में जाते हैं stay करते किसी भी hotel में जाइए वह आपको देंगे captive portal का URL. आप login करेंगे वह एक portal पर आपको ले जाएगा कि अपना last name और अपना जो भी x y z information दें. वहां तक ठीक है लेकिन अगर कोई आपको cafe या hotel यह बोल रहा कि यह मेरा certificate है इसको install करो तो वह install करने का मतलब यह है कि आप यह सारी information वह plain text में read करेगा. Right. जब तक आप मैं आपका WFI use कर रहा हूं you can you can dump my data but you cannot read it. क्योंकि वो सब encrypted form में जा रहा क्योंकि SSL certificate communication होगी. जहां मैंने आपका certificate अपने mobile में डाला, इसका मतलब you are authorized to read my data. Then you can read my data. Right. So it's not secure to use, Wi Fi on the public Wi Fi's. बहुत ज़्यादा important है, मजबूरी है. Then go for it. But don't open or don't do some critical stuff on the website or something like Financial ना करें, logins ना करें. हां, avoid करें, avoid करें. VPN वग़ैरह से फ़ायदा होता है? कौन से वाले? Paid या free वाले? दोनों बता दें. Sir VPN का problem यह है कि VPN जो है ना बहुत legit और बहुत proper चीज़ है. हम लोग उसको दूसरे कामों के लिए use करते हैं कि हमने website खोलनी है या मुझे कोई data download करना है. For example I have to do a remote work there. मैं direct network से नहीं connect हूँगा. मैं उनके VPN से connect हूँगा. वो एक secure channel से मुझे लेके जाएगा. Right. VPNs use करना है, बहुत सारे लोग हैं जो paid use करते हैं, they are using for legit purposes. हम लोग free में इसलिए use करते कि for example KSM और उस region में WhatsApp नहीं चलता. Right. तो हम VPN use करते हैं कि हमारी WhatsApp पर बात हो जाए. हां. So it depends on your target and your work कि आप किस चीज़ पर काम करने जा रहे हैं but security point of view से अगर आप बात करते हैं, Right. एक proton mail नाम की चीज़ है आप search कीजिएगा. बिल्कुल. Proton के अपना VPN होता था proton mail होता था पहले एक proper तरीके से. उनका concept यह था कि for the public, from the public. कोई record नहीं है, चाहिए रहूंगा anonymous लोग काम करें. Then he open that again किसी और country में जहां जैसे वह नहीं है, problem नहीं है use का. So they are working के node to node ना data नहीं read किया जा सके. जैसे आप WhatsApp use करते हैं end to end encryption. तो यह बात यह है कि मेरे पास से निकला data, आपके पास गया, beach में कोई read नहीं कर सकता. Do you think WhatsApp is truly,
unhackable
end to end encryption के साथ? Depend करता है कि किस context में आप कह रहे Hackable या readable, दो चीज़ है. Read कर लें? Insert करना है आपको और आपको ठक करके आप आप मुझे बताएं ना आप internet retarget marketing. You are working on a data right? Right. Big data किस तरह पूरा आप analysis करते हैं उसका? हां. तो इसी तरीके से internet retarget marketing की अगर हम बात करते हैं तो पांच बार आप यहां shoes search करें mobile पर छठी बार आपको Facebook पर shoes नज़र आने शुरू देंगे. हां. क्योंकि उसको पता है आप search कर रहे हैं. आप किसी आप हम लोगों ने personal try किया not sure लेकिन हम लोग बात कर रहे हैं और बैठकर किसी topic पर बात कर रहे हैं. थोड़ी देर बाद sir मुझे Facebook नज़रान शुरू हो गया. मैंने बोला यार यह voice record भी कर रहा है. तो फिर हम बोलते mark नहीं करो मेरा. So yes, आप अगर इसकी बात करते हैं तो बिल्कुल आपका जो WhatsApp का data है, Telegram में signal है, यह बने इसी वजह से कहते हैं कि आपको anonymous रहना है then use these. लेकिन अगर WhatsApp में है तो not sure कि वह.
अब इसमें मैं add करता हूं Pegasus. So इसमें चीज़ों को राहिम श्रेम राहिमान was act as well through Pegasus. Not sure. जो अभी last इनकी report आई थी उसके अंदर सुनने में यह आया कि जी, the Indian government ask for उन्होंने जो request आई थी ना Pegasus की उस पर यह था कि जी Indian government ने काफ़ी सारे उनको किया था which included the prime minister's phone. जिसमें उन्होंने कहा, हां, there was an ambiguity in a sense कि उन्होंने यह पता लगा था कि request आई हुई थी, यह नहीं पता लगा था कि hack हुआ या नहीं हुआ. उसको let's leave it at that. इससे आसी जवाब, no comments. But obviously that tool is being used for for very very high level SPRMs, right, essentially. What's it? What is it? And how does that work? Okay. So the background is, there are vulnerabilities
in the system. Some hackers report that, white hat hacker. Some don't report that. There's a black hat hacker. So the problem is कि जब उसको report नहीं किया और एक concept होता है zero day. The zero day concept is कि एक vulnerability निकली है system के अंदर. दुनिया में किसी को भी नहीं पता उस बारे में. Even के जो developer हैं उसको भी नहीं पता उसके बारे में. अभी तक नहीं पता. जब तक नहीं पता उसका patch release नहीं हुआ तो वह zero day ही कहलाएगा. Right. The thing in the Pegasus is के तीन exploits थे जो chain करके चले थे and they were zero days. तीनों zero days थे publicly exposed नहीं थे. अच्छा scene ये होता है कि बहुत ज़्यादा critical अगर vulnerability है ना तो Microsoft is paying 1 lakh US dollars. अच्छा. तो यह motivation है मेरे और आपके लिए लेकिन जिनके मकसद ही अलग है उनके लिए motivation ही नहीं है क्योंकि कुछ लोग हैं जो कि state level actors होते हैं जिसके state sponsored या हम उसको APTs बोलते हैं. हम अपनी ज़बान में. तो APTs जो होते हैं they are state sponsored. उनको पैसों से कोई मतलब नहीं होता. There is a group जिसका बचपन से मैंने और आपने नाम सुना है anonymous. बिल्कुल. Right?
Do you think about anonymous? मुझे तो लगता है वह US government का asset है. Sir, कुछ कह नहीं सकते. At this point in time ना मतलब जब आप देखते हैं कि वह randomly उठते हैं और उठकर हमेशा वह ऐसी चीज़ें target कर रहे होते हैं जो somehow is
Connected. Is connected. वह बड़ा आपको तील ऐसा था या तो उनको पकड़ लिया था एक time पर और flip कर दिया but यह तो बहुत होता है. यह अभी भी होता है. यह बहुत होता है even के Asian countries में भी बहुत होता है कि आइए इतना sophisticated था तो कि वो detect नहीं होता था. तो system तो दूर की बात है जो कि server हैं वो भी detect नहीं करते थे. वो करता गया था कि वो malware install करता था और एक बार malware आ गया वो कुछ भी कर सकता है. वह context लेकर जाए, वह pictures ले, वह even के आपका camera भी live open कर सकता है. Right. So that was a legit attack जो था और जिस company ने किया, जो बनाया जिसके बारे में सबको पता है और अभी cases चल रहे हैं. Israeli owned company है और they are working or they are saying कि हम legit purpose के लिए इसको use करते थे for the civilians of the मतलब, कि हम अच्छे लोग हैं. हम हम ख़्याल रखना है, ख़्याल रखना. लेकिन you never know क्या हो रहा और पीछे. Yeah, 100%.
अभी आप, you know, you you are a cyber... Like, a information security consultant? Yep. What are your own goals over the next decade or so? Where do you see yourself growing? Sir,
I want to see myself in a product. Some kind of a product but a product. Because services, thousand of people offering services and product feeds you for years. Right. And जिस तरह आप GDPR की बात कर रहे थे security.ai जो है उनका एक product GDPR भी है. Sir job कब तक करोगे आप? You have to go somewhere कि जो आपकी identity हो कि हां या आप trainer भी हो, आप speaker भी हो and there is a product जो कि आपने खुद develop किया and you are working on that. I think utility भी है. Because while we are talking about, you know, better compliance, better यह याद आ रहा है मुझे याद आ रहा इसका कोई या 80,000,000 US dollars वहां से निकाले गए थे और different different accounts में बाहर offshore किए गए थे. उसका मैंने पूरा जब देखा था तो sir वह इतना मज़ेदार planned attack था कि Friday वाले दिन GCC region में छुट्टी होगी. Then मतलब Friday को off होता है और फिर आगे जिस country में route कर रहे थे वहां का national day था और इस तरह की दो तीन चीज़ें और connect हुई और उसके बाद हुआ ये कि जब आप बड़ा चंग भेजते ना दो करोड़ तीन करोड़ बड़ा तो आप पकड़े में आते जैसे आप अभी अभी भी अगर transactions करते है तो पांच लाख दस लाख खैर होती है दो करोड़ transaction करे foreign phone आ जाएगा sir verify तो
how do you see cryptocurrency in all of this? Or wrong word. How do you see blockchain in all of this? Yep. You know, in terms of, making the system much more robust because वही वाली बात है कि अब जैसे जैसे हमने start किया है, technology थी, बड़ी important थी, बड़ी utility थी, उसकी digitalization बड़ी अच्छी थी, यह वह सारा का सारा. But the technology that we were working with for most parts and we were creating sort of layer after layer on top of that वह, it's it's something जो कि, primitive है और उसके ऊपर जो धारे के हम जो हमारे अच्छे थे उन्होंने भी सीख लिया लेकिन बुरे थे उन्होंने भी सीखना शुरू And कर दिया हुआ so, अब अब बात यही आ रही है कि how do you sort of create, you know, layers जो कि which are much more difficult to hack. उसके ऊपर भी ख़ैर अब तो बात यह आ गई. Cryptocurrency को भी you know या blockchain को भी quantum computing वगैरह जो Exactly. Track कर But for most part, how do you see that change or the web three point o change in terms of security?
Blockchain एक technology है. The people are using that technology for the cryptocurrency as well. Basically blockchain is a laser system कि हर सब क्या maintain हो रहा है. Right. So you can use that technology in your medicine, medical field as well, your financial institutions as well and your मतलब crypto तो financial में ही आ गया ना. So it's a very good approach लेकिन अब हमारे पास जो ethereum वगैरह है उनके platforms हैं जो कि खुद bug bounty program launch करके बैठे हुए हैं कि हमारा यह पूरा एक process है ledger management का. If you crack that up तो we'll give you certain amount जो कि ethereum में ही होंगे. उनके लिए. So, yeah, the future of blockchain is very good and very secure as well. Right, makes sense.
बुरहान भाई, generally this is a question I ask everyone. You're 29 years old right now. Thirty years from now, you you should be around 59, 60. Yeah. Pakistan will be a 103 years old and, you know, you've been around, you've been आप Pakistan में grow किए, karaks में grow up किए. Knowing what you know now, seeing what you see, over the past few years, how do you see Pakistan of, 2050?
Sir, mindset अगर change होगे तो Pakistan will boost और अगर mindset change नहीं हुआ तो Pakistan will remain same or the worst. ये मैं इसलिए बोलता हूँ हर चीज़ को. Problem ये है कि हम लोग बोलते हैं, अभी भी हम बोलते हैं कि votes बिरयानी पे जाते हैं. यह mindset जब तक change नहीं होगा ना क्योंकि जितने लोग जैसे मैं आपसे generations की बात कर रहा था. हमारे बहुत सारे लोग हैं जब बाहर गए हुए हैं अब वह जब आकर नए काम शुरू करेंगे नई generation आएगी then उसको follow करेगी. Then we will be parents को क्या करना है? जैसे हम ही है ना, next generation हम ही है, हम भी marshallah से बनेंगे parents. तो हमने किसी field पर नहीं रुकना है. यार यह कर लो, नहीं you want to do something euro. NFT का game strong हो गया sir. हां. लोग sneakers बना बना के, है ना? हां.
You can join the TBD community as well. इसके साथ साथ हमें नई podcast start किया it's called the Pakistan pivot. We talk to different, you know, government officials, different policy makers. Try to understand, कि Pakistan में जो major decisions हो रहे हैं, उसके पीछे what's the thought behind that. The link is down below, check that out as well. इसके अलावा easy पैसा jazz cash यहां पर कहीं पर आ रहा है. If you'd like to support the channel, you can do that as well. We accept anything from one repeat to as much as you'd like. It's the thought that counts. But anyways, this was Sayur Mazamela Sanzedi. You were watching Thought Behind Things. Thank you so much for watching and I'll see you in the next one.
More from Thought Behind Things
Jun 30, 2026
Simon Dixon: the US empire is being wound down by design
with Simon Dixon
Simon Dixon argues the American empire isn't collapsing — transnational capital is deliberately unwinding it, and Pakistan's military has become its leverage in the transition.
Listen →
52:45 Jun 9, 2026
How Asad Mehmood landed Mattermost from Pakistan before A levels
with Asad Mehmood
Asad Mehmood walked into Mattermost before he had A levels, crossed two million dollars on Upwork, and now runs a design agency from Pakistan. He sat with Muzamil to lay out the framework underneath it: become undeniably good, then become visible, then sell outcomes.
Listen →
59:04 Jun 5, 2026
A 22-year-old Pakistani's road map to space by 2050
with Hassan Mossin
Hassan Mossin, a 22-year-old Pakistani astrophysicist training with the International Institute for Astronautical Sciences, walks Muzamil through the next twenty-five years of space — commercial stations by 2030, a lunar base by 2032, and why the bottleneck isn't food or oxygen, it's energy.
Listen →Never miss what's next.
The dispatch - new writing and conversations, straight to your inbox.
First name, last name, email - in your inbox weekly. No spam.