Podcasts

News, analysis and commentary

Risky Business #432 -- We need to talk about John

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show we’re taking a look at the business dealings of John McAfee. Earlier today the NYSE announced the company that arranged to hire McAfee, MGT Capital, would be de-listed from the NYSE: MKT small cap exchange. This follows a class action investor lawsuit and the unearthing of a remuneration agreement between the company and McAfee that have lead some to suggest the whole company could be a pump and dump scam.

This comes hot on the heels of a release of a Showtime documentary that alleges McAfee’s involvement in two murders and the rape of a scientist working for him. We’ll hear from respected industry analyst Rich Mogull about MGT’s proposed product line while Georgetown Law’s Visiting Professor Russell Stevenson takes a look at MGT’s somewhat strange remuneration agreement with McAfee.

This week’s show is brought to you by Canary.Tools.. If you’re a regular listener you’ve heard me sing the praises of Canary in the past. It’s basically a little honeypot that you can configure to look like anything, you put it on your LAN somewhere and wait for an attacker to mess with it. It’s a great product that’s experiencing amazing growth. Canary.Tools head honcho Haroon Meer will be along in this week’s sponsor interview to talk about how little hacks can help defenders as well as attackers.

Adam is away on his company retreat this week so I’ve actually asked Haroon to fill in for him in the news segment, too. It’s your double dose of Haroon Meer!

Oh, and do add Patrick and Haroon on Twitter if that’s your thing.

Risky Business #432 -- We need to talk about John
0:00 / 0:00

Risky Business #431 -- What should the USA do about Russian hacks?

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show we’re taking a look at what the hell the USA should do in response to Russia’s hacks against the DNC. A few days ago the Director of National Intelligence and DHS issued a joint statement that officially puts blame for the DNC hacks squarely on Russia. Since then the Internets have been in meltdown over what exactly should be done in response.

Cyber policy lady Mara Tam is this week’s feature guest. She’ll tell us what sort of reaction we can expect to see, as well as give us some context around why all this is happening in the first place. That’s this week’s feature interview.

This week’s show is brought to you by the fine folks at Bugcrowd. This week’s sponsor interview is with Bugcrowd founder and CEO Casey Ellis. Recently a company that makes static analysis software took a bit of a poke at bug bounties in its marketing. If anything it was kind of an acknowledgement that Bugcrowd and its competitors have had a pretty substantial impact on how testing actually gets done.

But are people actually thinking of services like managed bug bounties as a substitute for static analysis? And why is every single company that makes developer tools scrambling to become agile or devops ready when hardly anyone is actually doing it yet?

Adam Boileau is this week’s news guest.

Oh, and do add Patrick and Adam on Twitter if that’s your thing.

Risky Business #431 -- What should the USA do about Russian hacks?
0:00 / 0:00

Risky Business #430 -- LulzSec's Tflow talks NSA exploits, justice and remorse

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show we are catching up with Mustafa Al-Bassam. He’s a lovely young chap from England who was once upon a time one of the LulzSec crew. Like all the other guys in that crew he got busted, but he didn’t spend any time in prison and these days he is doing really well. He has finished his undergrad, works with some blockchain technology and is about to start a PhD. He joins us this week to talk about his in depth analysis of the Shadowbrokers dump, as well as to reflect on his crimes. As you’ll hear, he has some regrets.

This week’s show is brought to you by Bromium! And last week you might have caught an announcement that Microsoft has moved virtualisation based security up into the app stack. The Edge browser is getting thrown into a micro VM in certain circumstances. Of course Microsoft worked with Bromium on all this stuff, so Bromium CTO, Simon Crosby will be along to talk about what Microsoft has actually done here. Bromium, of course, makes fully featured micro VM security software in addition to helping Microsoft improve windows, so that chat is interesting stuff and it’s coming up after this week’s feature.

Adam Boileau is this week’s news guest.

Oh, and do add Patrick and Adam on Twitter if that’s your thing.

Risky Business #430 -- LulzSec's Tflow talks NSA exploits, justice and remorse
0:00 / 0:00

Risky Business #429 -- Kreb's dumped, satellite hacking, election insecurity and more

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

This week we’ll be having a chat to Paul Marsh about a recent report from UK think tank Chatham House that says there’s a looming cyber security crisis about to wreak havoc on the satellite ecosystem. But as you’ll hear, Paul thinks the concerns are somewhat overhyped.

In this week’s sponsor interview we chat with Space Rogue, aka Tenable Network Security’s very own Cris Thomas. He’s joining us this week to talk about election security. Two new bills dealing with the security of voting computers have been proposed in the USA. We’ll get Cris’s thoughts on how likely they are to actually make a difference. We also have a general discussion around the security of e-voting infrastructure.

Adam Boileau is this week’s news guest.

Oh, and do add Patrick and Adam on Twitter if that’s your thing.

Risky Business #429 -- Kreb's dumped, satellite hacking, election insecurity and more
0:00 / 0:00

Risky Business #428 -- Cross-platform Tor Browser pwnership with Ryan Duff

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show we’ll be chatting with security researcher Ryan Duff about the rabbit hole that is the Tor Browser Bundle certificate pinning bug. The bug itself is interesting, but the questions it raises about how suitable Tor is for genuinely critical use are, you know, substantial. That’s a really, really interesting chat with Ryan Duff, coming up after the news.

This week’s show is brought to you by Hewlett Packard Enterprise Fortify! Of course HPE Fortify makes both static and dynamic analysis tools to help their customers weed out bugs in their software… but what are the relative strengths of static versus dynamic? Where should you use these tools? As this week’s sponsor guest Michael Farnum explains, the trend these days is to not only use both, but move them both as far to the left as possible in the development cycle. That’s this week’s sponsor interview, coming up a bit later.

Mark Piper is this week’s news guest.

Oh, and do add Patrick on Twitter if that’s your thing.

Risky Business #428 -- Cross-platform Tor Browser pwnership with Ryan Duff
0:00 / 0:00

Risky Business #427 -- Cahill law partner Brad Bondi on MedSec suit

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

We have a great feature interview this week. Risky Business contributor Brian Donohue spoke with Cahill law firm partner Brad Bondi about the suit St Jude Medical has brought against MedSec and Muddy Waters over the short-sell of the medical device manufacturer’s shares. That is an illuminating chat that certainly gave me an understanding of where this all could be heading, both in terms of the upcoming trial and how likely it is we’ll see similar stuff in the future. This week’s show is brought to you by Cylance! These guys basically offer an AV solution that works differently. But you know what? I’ve asked a dozen people what they actually do, and no one has really been able to tell me. So, I talk to Cylance founder and CEO Stuart McClure about the fall out from the House Oversight report into the OPM breach – a report that went in to some detail on Cylance’s role in determining the extent of the breach – but I also talk to him more generally about what it is that Cylance actually does.

Adam Boileau is back in the news chair this week to talk about the week’s information security headlines.

Oh, and do add Patrick or Adam on Twitter if that’s your thing.

Risky Business #427 -- Cahill law partner Brad Bondi on MedSec suit
0:00 / 0:00

Risky Business #426 -- House Oversight Committee drops OPM breach report PLUS St Jude sues MedSec

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

In this week’s feature interview we chat with Stephen Ridley about all things IoT. Stephen is a researcher turned entrepreneur and he’ll be along to talk about the platform consolidation we’re going to see when it comes to “things”. Once that settles, he argues, we’ll get a better idea of the security risks we should really, actually be worried about. In this week’s sponsor interview we’re chatting with Simon Galbally at Senetas.

Senetas, of course, makes high assurance network encryptors and Simon joins us this week to talk about where certification schemes might be headed. Did you know there are no sunset clauses on many of the certification schemes out there? So yeah, you can be using a FIPS certified box that’s riddled with known bugs and yep, it’s still certified. Certifications could start moving towards more continuous models.

Insomnia Security’s Mark Piper is this week’s news guest.

Oh, and do add Patrick on Twitter if that’s your thing.

Risky Business #426 -- House Oversight Committee drops OPM breach report PLUS St Jude sues MedSec
0:00 / 0:00

Risky Business #425 -- MedSec CEO Justine Bone on the Muddy Waters short

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show we've landed what looks to be a fairly exclusive interview -- at least as far as the tech press is concerned. Justine Bone will be joining us to explain why the company she works with, MedSec, decided to use vulnerability information on implantable medical devices to drive a short-selling scheme in partnership with Muddy Waters.

This week's show is sponsored by Tenable Network Security. We're doing something a bit different in this week's sponsor interview -- we're chatting with one of Tenable's customers, City of San Diego CISO Gary Hayslip.

They've just invested heavily in Nessus, among other things. Gary drops by to explain what he's been doing since he took the CISO position a few years ago. If you're a CISO it's actually a pretty interesting interview. That team has to deal with everything from embedded devices in cop cars to control systems to its very own POS network. Hey, citizens have to pay for government services somehow, right?

Trail of Bits head honcho Dan Guido is this week's news guest.

Oh, and do add Patrick and Dan on Twitter if that's your thing.

Risky Business #425 -- MedSec CEO Justine Bone on the Muddy Waters short
0:00 / 0:00

Risky Business #424 -- Jess Frazelle on Docker. So hot right now.

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show we chat with Jessie Frazelle. Jessie is a former Docker maintainer who now works at Google on all things "containery". So we talk to her about what's up with containers, basically, and where the security pitfalls are. Like it or not, containers are likely going to be used in your environment, so getting to know them is a must. That's this week's feature.

This week's show is brought to you by HP Enterprise Security's Fortify! These guys and gals are a new sponsor, and I'm sure most of you know them. They make both static analysis and dynamic analysis code security tools, and this week we're joined by HPE Fortify's James "Jimmy" Rabon to talk about how this whole newfangled devops/agile thing has changed things for them.

The Grugq also joins the show to talk about the week's security news. He's filling in for Adam Boileau who's frantically getting Kiwicon 10 organised.

Oh, and do add Patrick and The Grugq on Twitter if that's your thing.

Show notes

Completely Wrong - Medium
https://medium.com/@thegrugq/completely-wrong-a300246ad316#.h7zsu81sg

CyberSecPolitics: Why EQGRP Leak is Russia
http://cybersecpolitics.blogspot.com.au/2016/08/why-eqgrp-leak-is-russia...

Shadow Broker Breakdown - Medium
https://medium.com/@thegrugq/shadow-broker-breakdown-b05099eb2f4a#.eqou5...

The NSA Leak Is Real, Snowden Documents Confirm
https://theintercept.com/2016/08/19/the-nsa-was-hacked-snowden-documents...

NSA-linked Cisco exploit poses bigger threat than previously thought | Ars Technica
http://arstechnica.com/security/2016/08/nsa-linked-cisco-exploit-poses-b...

Juniper Acknowledges Equation Group Targeted ScreenOS | Threatpost | The first stop for security news
https://threatpost.com/juniper-acknowledges-equation-group-exploits-targ...

Former NSA Staffers: Rogue Insider Could Be Behind NSA Data Dump | Motherboard
http://motherboard.vice.com/read/former-nsa-staffers-rogue-insider-shado...

The Shadow Brokers Mess Is What Happens When the NSA Hoards Zero-Days | WIRED
https://www.wired.com/2016/08/shadow-brokers-mess-happens-nsa-hoards-zer...

Researcher Grabs VPN Password With Tool From NSA Dump | Motherboard
http://motherboard.vice.com/read/researcher-grabs-cisco-vpn-password-wit...

Commentary: Evidence points to another Snowden at the NSA | Reuters
http://www.reuters.com/article/us-intelligence-nsa-commentary-idUSKCN10X01P

The NSA Data Leakers Might Be Faking Their Awful English To Deceive Us | Motherboard
http://motherboard.vice.com/read/the-shadow-brokers-nsa-leakers-linguist...

Someone Rickrolled the Bitcoin Auction for NSA Exploits | Motherboard
http://motherboard.vice.com/read/someone-rickrolled-the-bitcoin-auction-...

Californian gets 50 months in prison for Chinese 'technology spy' work \u2022 The Register
http://www.theregister.co.uk/2016/08/23/50_months_for_chinese_tech_spy_w...

Lawyer: Dark Web Child Porn Site Ran Better When It Was Taken Over by the FBI | Motherboard
http://motherboard.vice.com/read/lawyer-dark-web-child-porn-site-ran-bet...

A 'Tor General Strike' Wants to Shut Down the Tor Network for a Day | Motherboard
http://motherboard.vice.com/read/a-tor-general-strike-wants-to-shut-down...

EFF Blasts Microsoft Over Windows 10 Rollout | Threatpost | The first stop for security news
https://threatpost.com/eff-blasts-microsoft-over-malicious-windows-10-ro...

Australia Post says use blockchain for voting. Expert: you're kidding \u2022 The Register
http://www.theregister.co.uk/2016/08/22/australia_postblockchain_for_vot...

SSA: Ixnay on txt msg reqmnt 4 e-acct, sry - Krebs on Security
http://krebsonsecurity.com/2016/08/ssa-ixnay-on-txt-msg-reqmnt-4-e-acct-...

Epic Games Forums Hacked, 800,000 User Accounts Exposed | Threatpost | The first stop for security news
https://threatpost.com/epic-games-forums-hacked-sql-injection-vulnerabil...

Malware Infected All Eddie Bauer Stores in U.S., Canada - Krebs on Security
http://krebsonsecurity.com/2016/08/malware-infected-all-eddie-bauer-stor...

Massive Email Bombs Target .Gov Addresses - Krebs on Security
http://krebsonsecurity.com/2016/08/massive-email-bombs-target-gov-addres...

New Brazilian Banking Trojan Uses Windows PowerShell Utility | Threatpost | The first stop for security news
https://threatpost.com/new-brazilian-banking-trojan-uses-windows-powersh...

Browser Address Bar Spoofing Vulnerability Disclosed | Threatpost | The first stop for security news
https://threatpost.com/browser-address-bar-spoofing-vulnerability-disclo...

Software-defined networking is dangerously sniffable \u2022 The Register
http://www.theregister.co.uk/2016/08/23/sdns_normal_behaviour_is_sniffab...

How to Dramatically Improve Corporate IT Security Without Spending Millions - Praetorian.pdf
https://www.praetorian.com/downloads/report/How%20to%20Dramatically%20Im...

Risky Business #424 -- Jess Frazelle on Docker. So hot right now.
0:00 / 0:00

Risky Business #423 -- ShadowBrokers PLUS how2pwn Apple's Secure Enclave

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

This week's feature interview is incredible. We're speaking with David Wang from Azimuth Security. He, his colleague Tarjei Mandt and Mat Solnik of OffCell Research delivered an absolutely blockbuster talk at Black Hat. I didn't see the talk at the time but I got a chance to review the slides and oh-my-god I can't believe this one got so little attention.

While everyone was running around talking about hackable lightbulbs, jeeps and trucks, these three guys basically dropped a how2pwn guide for Apple's Secure Enclave Processor. So, you know, you can basically take their slide deck, add a couple of little tweaks and you're unlocking an iPhone 6s and messing around with a thing you're really not supposed to be messing around with. It's really, really good reversing work and you need to hear this interview.

This week's show is brought to you by Bugcrowd, outsourced bug bounty programs. Bugcrowd founder and CEO Casey Ellis is along this week to talk about Apple's newly launched bounty program. Even though other software companies already have bounty programs, the large rewards involved in this one make it a big deal. We'll get his thoughts on that.

Adam Boileau joins us in this week's news segment to discuss the NSA's shiny toys being all over teh torrentz, as well as other assorted infosec news.

Oh, and do add Patrick and Adam on Twitter if that's your thing.

Show notes

What We Know About the Exploits Dumped in NSA-Linked Hack | Motherboard
http://motherboard.vice.com/read/what-we-know-about-the-exploits-dumped-...

The Equation Giveaway - Securelist
https://securelist.com/blog/incidents/75812/the-equation-giveaway/

\u200bWhy Github Removed Links to Alleged NSA Data | Motherboard
http://motherboard.vice.com/read/why-github-removed-links-to-alleged-nsa...

Former NSA Staffers: Rogue Insider Could Be Behind NSA Data Dump | Motherboard
http://motherboard.vice.com/read/former-nsa-staffers-rogue-insider-shado...

The Current Highest Bid for Alleged NSA Data is 999,998.371 Bitcoin Short | Motherboard
http://motherboard.vice.com/read/the-shadow-brokers-auction-nsa-data-bit...

Hack of NSA-Linked Group Signals a Cyber Cold War | Motherboard
http://motherboard.vice.com/read/hack-nsa-linked-equation-group-cyber-co...

Why Did Guccifer 2.0 Evolve from Sloppy Hacktivist to Professional Leaker? | Motherboard
http://motherboard.vice.com/read/guccifer-20-evolution-sloppy-hacktivist...

Patrick Gray on Twitter: "Well this basically confirms it's Russia, right? Trolololol-lolol-lolol-lalalalaaaaa!!! https://t.co/YZ4etnZgO3"
https://twitter.com/riskybusiness/status/765347661587238916

Snowden speculates leak of NSA spying tools is tied to Russian DNC hack | Ars Technica
http://arstechnica.com/tech-policy/2016/08/snowden-speculates-leak-of-ns...

Shadow Brokers NSA exploits: doubts about Edward Snowden's tweets | The Cold War Daily
https://coldwardaily.com/2016/08/17/shadow-brokers-nsa-exploits-doubts-a...

Guccifer 2.0 doxes hundreds of House Democrats with massive document dump | Ars Technica
http://arstechnica.com/tech-policy/2016/08/guccifer-2-0-doxes-hundreds-o...

Democratic, GOP leaders got a secret briefing on DNC hack last year | Ars Technica
http://arstechnica.com/tech-policy/2016/08/democrat-gop-leaders-got-a-se...

Court Rules to Extradite Suspected Silk Road Admin From Ireland to the US | Motherboard
http://motherboard.vice.com/read/court-rules-to-extradite-suspected-silk...

\u200bAustralian Authorities Hacked Computers in the US | Motherboard
http://motherboard.vice.com/read/australian-authorities-hacked-computers...

How Researchers Exposed Iranian Cyberattacks Against Hundreds of Activists | Motherboard
http://motherboard.vice.com/read/iran-cyberattacks-against-activists

Wave of Spoofed Encryption Keys Shows Weakness in PGP Implementation | Motherboard
http://motherboard.vice.com/read/wave-of-spoofed-encryption-keys-shows-w...

Linux bug leaves 1.4 billion Android users vulnerable to hijacking attacks | Ars Technica
http://arstechnica.com/security/2016/08/linux-bug-leaves-1-4-billion-and...

Almost every Volkswagen sold since 1995 can be unlocked with an Arduino | Ars Technica
http://arstechnica.com/cars/2016/08/hackers-use-arduino-to-unlock-100-mi...

Security Fuckup Megathread - v12.1.4 - i need tp-link for my security hole - The Something Awful Forums
https://forums.somethingawful.com/showthread.php?threadid=3771497&pagenu...

Secure Boot snafu: Microsoft leaks backdoor key, firmware flung wide open | Ars Technica
http://arstechnica.com/security/2016/08/microsoft-secure-boot-firmware-s...

Adobe Patches Experience Manager; No Flash Update | Threatpost | The first stop for security news
https://threatpost.com/a-month-without-adobe-flash-player-patches/119770/

Cisco confirms NSA-linked zeroday targeted its firewalls for years | Ars Technica
http://arstechnica.com/security/2016/08/cisco-confirms-nsa-linked-zeroda...

Cisco Patches ASA Zero Day Exposed by ShadowBrokers | Threatpost | The first stop for security news
https://threatpost.com/cisco-patches-asa-zero-day-exposed-by-shadowbroke...

us-16-Mandt-Demystifying-The-Secure-Enclave-Processor.pdf
https://www.blackhat.com/docs/us-16/materials/us-16-Mandt-Demystifying-T...

Risky Business #423 -- ShadowBrokers PLUS how2pwn Apple's Secure Enclave
0:00 / 0:00