Risky Business #244 -- Padding oracle attacks on crypto tokens: How bad?

Is the sky falling or is this a case of "nothing to see"?

There's a lot of really interesting news this week. Adam Boileau is back on deck at the top of the show to discuss shitty security at the Ecuadorian embassy in London, the new tool DroidSheep, DARPA's (DERPA? Lol.) attempts at securing the architectural mess that is Android, dudes going to prison, other dudes getting away with stuff and much, much more!

Risky Business #243 -- Quickly! To Ecuador!

How to be a martyr in style...

In this week's news segment we cover Julian Assange's attempt at martyrdom in style, claims of a Twitter outage, the cracking of 923-bit pairing-based encryption in Japan, the blackmailing of an American firm by hackers, Face.com's tragic fail, The Washington Post's stunning (not) revelation that Flame was the work of the US and Israel, AutoCAD worms, bug bounties and more!

Risky Business #242 -- Massive recon with HD Moore

PLUS Marcus Ranum talks password hashing, general auth approaches...

On this week's show we chat with Rapid7's H D Moore about massive recon in both the IPv4 and IPv6 worlds. He's been busy basically banner grabbing the entire Internet and he's found some really, really weird stuff out there. There are some very interesting nuggets in that interview. Check it out.

Risky Business #240 -- FPGA "back doors"

When it's Chinese it's a back door. When it's European it's a debugger.

On this week's show we're taking a look at some research out of Cambridge University that's drawn a lot of attention. It involves a claim that researchers found a hardware back door on a Chinese-made FPGA (Field Programmable Gate Array).

New book claims to expose direct LulzSec-Wikileaks ties

Forbes journalist book alleges close relationship between Assange and FBI snitch...

If people are wondering why on Earth Wikileaks' chief Julian Assange is apparently being pursued by the US Department of Justice, a new book by Forbes' London Bureau chief Parmy Olson might help to clear things up for you.

Assange likes to proclaim that the DoJ investigation is a case of the big bad gummint being out to persecute him for being a truth-teller, but if Olson's book (Amazon) is to be believed it looks like he's been a very naughty boy.

This excerpt [pdf] from the book, published by the pre-Wikileaks leak site Cryptome, describes verified IRC contact between LulzSec ringleader turned FBI snitch Sabu and Assange in which the latter apparently urged the digital outlaws to attack specific targets in Iceland.

Bad activist! No biscuit!

All this under the watchful eye of the FBI's inside man.

This is speculation, but if any of Wikileaks staff were "directing" LulzSec's illegal activities, particularly the exfiltration of stolen information from any of the group's victims -- like Stratfor, for example -- it's my guess the entire organisation is legally fux0red. IANAL, but read the excerpt and tell me if you arrive at the same hunch as me.

Encouraging an FBI snitch to attack systems in Iceland on your behalf when the heat is already on is remarkably daft.

I'll be interviewing Parmy about her book next week.

Risky Business #239 -- The Zetas cartel and social media

The Internet as "tactical cloud computing"...

This week's feature audio is an excerpt from an AusCERT presentation I recorded last week. The talk, by Brad Barker of the HALO Corporation, discusses the Zeta drug cartel's use of technology and social media. HALO Corporation does everything from intelligence support to kidnap and ransom consulting. Barker has an interesting analysis of how civilian technology is altering methods of operation and the wider battlefield. It's good stuff.

PRESENTATION: The risks posed by new wiretapping technologies

Affix your tinfoil hat and tune in...

The following is a recording Susan Landau's plenary presentation. She's a Visiting Scholar in the Computer Science Department at Harvard University. Prior to that she worked as a Distinguished Engineer at Sun Microsystems, and held faculty positions at the University of Massachusetts and Wesleyan University.

INTERVIEW: Connecting the physical with the virtual

The programmable network with Christopher Hoff...

In this interview we chat with Juniper Networks' chief security architect Christopher Hoff. I posted the audio of Chris's plenary talk yesterday... it was very interesting stuff, so check it out if you get a chance. He basically outlined his vision for security automation -- security at scale.

PRESENTATION: Mikko Hypponen on "The Enemy"

Mikko gives his take on Anons, Crims and Spooks...

The following is a complete recording of Mikko Hyppponen's opening keynote to the AusCERT 2012 conference. Mikko is the chief research officer for the Finnish antivirus firm F-Secure.


SUBSCRIBE NOW:
Risky Business main podcast feed:
Listen on Apple Podcasts Listen on Overcast Listen on Pocket Casts Listen on Spotify Subscribe with RSS
Our extra podcasts feed:
Listen on Apple Podcasts Listen on Overcast Listen on Pocket Casts Listen on Spotify Subscribe with RSS
Subscribe to our newsletters: