RB2

RB2: SPONSOR PODCAST: Big security vendors jump into PCLM?

March 4, 2010 -- This is a sponsored podcast. Symantec sponsors the RB2 podcast so once a month we get one of their staff on the line to talk about industry trends, malware... whatever, really!

And today we're speaking with Vincent Weafer, Symantec's director of security response. Regular listeners of Risky.Biz podcasts would have heard me tonking on a LOT about patch management lately, and in particular the moves by large security vendors like McAfee, Trend and Symantec into that space.

RB2: When is a hack a hack?

February 26, 2010 -- In this podcast we chat to a solicitor who specialises in IT. His name is Erhan Karabardak and he's with the firm Cooper Mills in Melbourne.

Erhan mostly specialises in technology-related stuff, and I wanted to get his thoughts on this so-called hacking scandal engulfing the corridors of power in New South Wales.

RB2: Interview with Neil Gaughan, Assistant Commissioner, AFP

February 19, 2010 -- In this instalment of RB2 we'll be hearing from Australian Federal Police Assistant Commissioner Neil Gaughan, who heads up High Tech and Child Protection Operations, for the AFP.

A recent report in the Sydney Morning Herald detailed changes to Australian law that would allow the Australian Federal Police to physically destroy computers if they contain encrypted data the police can't unlock.

The story also talked about further changes to laws that would stiffen penalties for suspects who refuse to hand over encryption keys and passwords.

RB2: Kiwicon 3 presentation: Hacking Scientists by Paul Craig

December 17, 2009 -- In this edition of RB2 you'll hear Paul Craig's Kiwicon 3 presentation, Hacking Scientists. As you'll hear, Paul has developed some fuzzing methodologies that he's applied to scientific software.

This sort of software -- chemistry stuff, fluid dynamics stuff etc -- is used by weapons designers, pharmaceutical engineers, car manufacturers and all sorts of very interesting people.

In other words, this software is found on the same systems as the world's most valuable IP. It's good stuff to find bugs in.

RB2: SPONSOR PODCAST: Vincent Weafer on software safety rankings

December 17, 2009 -- In this sponsored podcast, Symantec's VP of security response joins RB2 to talk about some novel new approaches to the malware problem.

We don't normally talk to sponsors about their own technology, but this is just where the conversation went, and it's pretty interesting stuff!

RB2: Ben Hawkes' Kiwicon talk: A History of Corruption

December 1, 2009 -- This edition of RB2 features Ben Hawkes' recent talk at Kiwicon. It was called A History Of Corruption, and it really is a historical recap of memory corruption bugs. It doesn't exactly sound thrilling from that description, but it's a great talk and it's really well delivered.

Hawkes is a young security researcher based in New Zealand who's well and truly on the way up. His work on hacking the Vista heap was pretty awesome. If you are familiar with it then you know why a talk about memory corruption as done by Hawkes is going to be interesting. He knows what he's talking about.

RB2: Jose Nazario on BGP security

November 24, 2009 -- This podcast features excerpts from Jose Nazario's session at the GovCERT Symposium in Rotterdam. The recording isn't fantastic, but you can understand what he's saying -- it's clear enough.

Jose works for Arbor networks and his talk at GovCERT was on BGP security -- security issues in core routing. He covers off some pretty interesting stuff, like why isn't there some sort of global route registry that actually authorises routes? Currently there's nothing like that.

If you’re not into routing stuff you’ll probably get lost with this one, but otherwise you’ll likely enjoy it.

RB2: Q&A with Bruce Schneier

November 13, 2009 -- In this podcast you'll hear a Q&A with Bruce Schneier of BT Counterpane, as moderated by Risky Business host Patrick Gray at the recent GovCERT Symposium in Rotterdam, Netherlands.

Topics covered include cloud computing, privacy, software manufacturer liability for defects, two factor authentication and more!

RB2: SPONSOR PODCAST: Symantec's Kevin Haley talks malicious AV metrics

October 29, 2009 -- In this sponsored podcast, Risky.Biz chats with Symantec's Kevin Haley about rogue AV. More specifically, how can we measure the extent of the rogue AV problem? How can we know how much money is involved, and what can be done to shut down this nasty trade?

RB2: Script fragmentation PLUS advanced SQLi

October 27, 2009 -- Risky Business 2 is brought to you by Symantec and hosted by Vigabyte virtual hosting!

In this podcast you'll hear our roving reporter Paul Craig interviewing a couple of presenters from BruCon, Belgium's security conference.

In the first interview, Paul chats to Stephan Chenette of Websense about script fragmentation, a concept that's a bit similar to TCP fragmentation for IDS evasion.

Interview number two is about advanced SQL injection attacks, with Gotham Digital Science's Justin Clarke.