Risky Business Podcast
April 10, 2018
Risky Business #494 -- Cisco customers have a bad week, plus a deep dive on WebAuthn
Presented by
CEO and Publisher
Technology Editor
Regular listeners would know Risky Business is just running the news and sponsor segments at the moment so there’s no feature interview in this week’s show. But that’s fine because we’ve got plenty to get through in the news segment with Adam Boileau.
Then we’ve got a killer sponsor interview for you this week with Nick Steele and James Barclay of Duo Security.
They’re here to talk about WebAuthn. It’s the new authentication spec currently going through the W3C process. Both Nick and James will be along later to talk about what the spec is designed to do, how it works and what its chances of becoming mainstream are, and spoiler alert, those chances are pretty good.
They’ve also provided me with some links for people out there who want to play around with Webauthn, they are below.
Links to all the news items are also below, and you can follow Patrick or Adam on Twitter if that floats your boat.
Brought to you by Duo Security
Identity Security, MFA & SSO
Show notes
Nation-state hackers hit Cisco switches - Cyberscoop
"Don’t Mess With Our Elections": Vigilante Hackers Strike Russia, Iran - Motherboard
With trade war looming, Chinese cyberattacks may follow - CyberScoop
Police could access US cloud data under planned crime-fighting deal
DHS defends media-monitoring database, calls critics “conspiracy theorists” | Ars Technica
After Crackdown, Neo-Nazis Are Hosting Propaganda on Censor-Proof Networks - Motherboard
Chinese Government Forces Residents To Install Surveillance App With Awful Security - Motherboard
A Long-Awaited IoT Crisis Is Here, and Many Devices Aren't Ready | WIRED
DARPA is looking to avoid another version of Meltdown or Spectre - CyberScoop
This Tool Can Help Identify Leakers Who Copy and Paste Secret Info - Motherboard
Beware of Bing Chrome Download Ads Pushing Adware/PUP Installers
Three Execs Get Prison Time for Pirating Oracle Firmware Patches
Russia Readies Telegram Ban After App Refused to Hand Over Encryption Keys to FSB
VirusTotal Launches Droidy, Its New Android Sandbox Technology
Researchers Hijack Over 2,000 Subdomains From Legitimate Sites in CloudFront Experiment
Australia's Offensive Cyber Capability | Australian Strategic Policy Institute | ASPI
GitHub - duo-labs/webauthn: A Demonstration of the WebAuthn Specification
GitHub - duo-labs/py_webauthn: A WebAuthn Python module.
ImperialViolet - Security Keys
Web Authentication: An API for accessing Public Key Credentials Level 1
Using Hardware Token-based 2FA with the WebAuthn API – Mozilla Hacks – the Web developer blog
Trying Out Web Authentication (WebAuthn)
Web Authentication: What It Is and What It Means for Passwords | Duo Security