
News, analysis and commentary

Risky Business #344 -- Super Mario Cisco adventures

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show we're chatting with Alec Stuart Muirk about some of his research into Cisco appliance security. That interview is not so much a blow by blow of the bugs he found, which were pretty devastating by the way, but more about how accessibility is a major hurdle when researching various bits of kit.

As you'll hear, many security vendors are starting to release their kit as VMs, which means researchers will be more likely to poke at them. Does that mean more boneheaded bugs like the stuff he found? Well, probably.

This week's show is brought to you by Bromium. In this week's sponsor interview we're chatting with Bromium's chief security architect Rahul Kashyap about some of his reflections on 2014. Well, two in particular. He says the decision of retailers to skip POS refresh programs during the US recession that began in 2008 is preeeetty much how the retail sector in the USA wound up in so much strife now. And he also shares some interesting thoughts on how standardised indicators of compromise may be turned against attack victims in 2015.

Show notes

Feds Arrest Alleged 'Silk Road 2\u2032 Admin, Seize Servers - Krebs on Security

Blake Benthall Criminal Complaint

Not Just Silk Road 2: Feds Seize Two Other Drug Markets and Counting | WIRED

US Attorney's office: Whoops, Silk Road 2.0 hired a fed [Updated] | Ars Technica

Why Facebook Just Launched Its Own 'Dark Web' Site | WIRED

Active "WireLurker" iPhone infection ushers in new era for iOS users | Ars Technica

WireLurker Mac OS X Malware Shut Down | Threatpost | The first stop for security news

Secret Manuals Show the Spyware Sold to Despots and Cops Worldwide - The Intercept

Hacking Team Responds in Defense of Its Spyware - The Intercept

How to leak sensitive data from an isolated computer (air-gap) to a near by mobile phone - AirHopper | Cyber Security Labs @ Ben-Gurion University of the Negev

Crypto attack that hijacked Windows Update goes mainstream in Amazon Cloud | Ars Technica

Nat McHugh: How I created two images with the same MD5 hash

Flaw in New 'Secure' Credit Cards Would Let Hackers Steal $1M Per Card | WIRED

Who wants to be A MILLIONAIRE? Not so fast, Visa tells wannabe pay-by-bonk thieves \u2022 The Register

Pirate Bay Founder Convicted on Hacking Charges, Sentenced to 3.5 Years | WIRED

Thai police question The Pirate Bay founder | Stuff.co.nz

Cell carrier was weakest link in hack of Google, Instagram accounts | Ars Technica

Ericsson boss sticks a pin in Google's loony Loon bubble \u2022 The Register

Microsoft releases free anti-malware for Azure VMs \u2022 The Register

EFF: VPNs will crumble Verizon's creepy supercookie stalkers \u2022 The Register

Feds investigate Homeland Security background checker security breach \u2022 The Register

Russia to ban iCloud.. to PROTECT iPhone fiddlers' pics 'n' sh*t \u2022 The Register

Critics chafe as Macs send sensitive docs to iCloud without warning | Ars Technica

Thieves Cash Out Rewards, Points Accounts - Krebs on Security

Does your phone company track you? | Ars Technica

Google releases "nogotofail" to detect HTTPS bugs before they bite users | Ars Technica

Yosemite infested by nasty 'Rootpipe' vuln \u2022 The Register

Fatback Band - Tour

https://ruxcon.org.au/assets/2014/slides/Breaking Bricks Ruxcon 2014.pdf

Risky Business #344 -- Super Mario Cisco adventures
0:00 / 0:00

Risky Business #343 -- Special news guest HD Moore

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

This week's show is brought to you by the fine folks at BugCrowd, big thanks to them. BugCrowd CEO Casey Ellis will be along in this week's sponsor interview to talk about what's shakin' in the bounty world. And you know what? There are some interesting engagement models emerging out of the whole paid bounty scene, he's going to talk about that. We also find out that, according to Casey, bug bounty programs will get you a PCI compliance tick from an auditor, which isn't something I knew!

Show notes

Verizon's 'Perma-Cookie' Is a Privacy-Killing Machine | WIRED

Facebook, Google, and the Rise of Open Source Security Software | WIRED

GCHQ views data without a warrant, government admits | UK news | The Guardian

Feds identify suspected 'second leaker' for Snowden reporters - Yahoo News

NY Senator Calls for Renewed Crackdown on Dark Web Drug Sales | WIRED

Now Everyone Wants to Sell You a Magical Anonymity Router. Choose Wisely | WIRED

White House unclassified network hacked, apparently by Russians | Ars Technica

Research links massive cyber spying ring to Russia | Ars Technica

Researchers identify sophisticated Chinese cyberespionage group - The Washington Post

Moscow, Beijing poised to sign deal on joint cyber security ops \u2022 The Register

'Replay' Attacks Spoof Chip Card Charges - Krebs on Security

Hackers Are Using Gmail Drafts to Update Their Malware and Steal Data | WIRED

FBI created fake Seattle Times Web page to nab bomb-threat suspect | Local News | The Seattle Times

Intel bods to detail RSA birko crypto man-in-the-middle diddle \u2022 The Register

Shellshock over SMTP attacks mean you can now ignore your email \u2022 The Register

MacOS X 10.10 & FreeBSD10 ftp Remote Comand Execution - CXSecurity.com

Spiderbait - Run - YouTube

Risky Business #343 -- Special news guest HD Moore
0:00 / 0:00

Risky Business #342 -- The NSA Playset, cloud woes and more!

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

Despite some technical challenges we have a great show for you all this week. We'll be chatting with Mike Ryan of iSec Partners and his pal, independent hardware hacker Joe Fitzpatrick, all about the NSA Playset! It's a hobbyist project that aims to recreate all the awesome tools in the leaked NSA ANT catalogue. Such fun!

We'll also be hearing a tale of cloud woe from the trenches of enterprise IT. A friend of the show had his entire global email infrastructure pulled offline by Symantec with what he says was inadequate warning. And he might just have a point there. Have a listen to the interview and make your own mind up.

This week's show is brought to you by the fine folks at Websense! Websense does Web, email and data security, and this week's sponsoe guest is Neil Thacker, head of information security and strategy for Europe, middle east and africa at Websense. And he's going to tell us that DLP is back baby... it's finding new life for a few reasons... the most interesting of which, I reckon, is as a confirmation tool for detecting when a positive is most definitely not false!

Show notes

Palo Alto Networks boxes spray firewall creds across the net \u2022 The Register

Is your home or office internet gateway one of '1.2 MILLION' wide open to hijacking? \u2022 The Register

Chipmaker FTDI bricking counterfeit kit \u2022 The Register

Kickstarter Freezes Anonabox Privacy Router Project for Misleading Funders | WIRED

In wake of Anonabox, more crowdsourced Tor router projects make their pitch | Ars Technica

The Case of the Modified Binaries | Leviathan Security Group

Google Accounts Now Support Security Keys - Krebs on Security

How to Stop Apple From Snooping on Your OS X Yosemite Searches | WIRED

Apple dumps SSL 3.0 for push notifications due to Poodle flaw - CNET

Whisper CTO says tracking "anonymous" users not a big deal, really | Ars Technica

Guns don't scare people, hackers do: Americans fear identity theft more than shooting sprees \u2022 The Register

Obama Executive Order Forces Chip & Pin, EMV on Government | Threatpost | The first stop for security news

Xen says its security policies might be buggier than its software \u2022 The Register

NIST Publishes Draft Hypervisor Security Guide | Threatpost | The first stop for security news

Chinese APT groups targeting Australian lawyers \u2022 The Register

Chinese government launches man-in-middle attack against iCloud [Updated] | Ars Technica

Quick PHP patch beats slow research reveal \u2022 The Register

DEATH by PowerPoint: Microsoft warns of 0-day attack hidden in slides \u2022 The Register

Cisco Patches Three-Year-Old Telnet Remote Code Execution Bug in Security Appliances | Threatpost | The first stop for security news

Risky Business #342 -- The NSA Playset, cloud woes and more!
0:00 / 0:00

Risky Business #341 -- Beware of the poodle

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

In this week's show we're chatting with Matt Solnik of Accuvant Labs about his stellar presentation at Breakpoint last week. In this interview he describes how he can leverage crappy carrier management client software into full remote compromise attacks against most smartphones, including fully patched iOS8 and Android. It's savage stuff and if you work in telcoland you'd be nuts to miss it.

This week's show is brought to you by tenable network security. Tenable's very own Marcus Ranum will be along in this week's sponsor interview to chime in on desktop virtualisation trends, as well as cloud, remote desktop, the browser as a terminal and enterprise computing in general. The mainframe is dead. Long live the mainframe. It's a great chat.

Show notes

There Is a New Security Vulnerability Named POODLE, and It Is Not Cute | WIRED

Browser Vendors Move to Disable SSLv3 in Wake of POODLE Attack | Threatpost | The first stop for security news

Bahraini Activists Hacked by Their Government Go After UK Spyware Maker | WIRED

NSA May Have Undercover Operatives in Foreign Companies | WIRED

Russian 'Sandworm' Hack Has Been Spying on Foreign Governments for Years | WIRED

With This Tiny Box, You Can Anonymize Everything You Do Online | WIRED

Judge Rejects Defense That FBI Illegally Hacked Silk Road-On a Technicality | WIRED

Snapchat Can't Stop the Parasite Apps That Screw Its Users | WIRED

Developer of hacked Snapchat web app says "Snappening" claims are hoax [Updated] | Ars Technica

Dropbox Denies Hack, Says 'Your Stuff is Safe' | Threatpost | The first stop for security news

Malware Based Credit Card Breach at Kmart - Krebs on Security

Signed Malware = Expensive "Oops" for HP - Krebs on Security

Who's Watching Your WebEx? - Krebs on Security

Doubling up on Ads Code Bounties

Heistmeisters crack cost of safecrackers with $150 widget \u2022 The Register

Shellshock Exploits Spreading Mayhem Botnet Malware | Threatpost | The first stop for security news

October 2014 Oracle Java Security Patches | Threatpost | The first stop for security news

Fixes for IE, Flash Player in October Patch Tuesday Release | Threatpost | The first stop for security news

Firms Detail Zero Days Targeting Windows Kernel | Threatpost | The first stop for security news

Drupal Fixes Highly Critical SQL Injection Flaw | Threatpost | The first stop for security news

SAP Patches Seven Vulnerabilities in Three Products | Threatpost | The first stop for security news

BlackBerry 10 Open to Bug That Allows Malicious App Installation | Threatpost | The first stop for security news

Google Online Security Blog: This POODLE bites: exploiting the SSL 3.0 fallback

Speakers \xbb Breakpoint 2014
https://ruxconbreakpoint.com/speakers/#Mathew Solnik

Tower Of Power - Soul Vaccination - YouTube

Risky Business #341 -- Beware of the poodle
0:00 / 0:00

Risky Business #340 -- BPX droppin' iOS8 remote jailbreaks like it "ain't no thang"

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

This week's show was recorded on site at the Ruxcon Breakpoint conference in Melbourne. There have been a handful of absolute jaw-droppers among the presentations here, including a demo showcasing remote code exec against *most* mobile devices, including fully patched iOS8.

This week's show is brought to you by Context information security and we've got a great chat coming up with Mark Graham, Context's head of threat intelligence. He spends most of his days hip deep in data Context has gathered on APT groups, and he's seen some interesting trends. Bad guys are apparently using vendor analysis/blog posts to improve their "product", the Russians are getting in on the action and there's a renewed effort in keeping APT campaigns stealthy.

Show notes

Shellshock-like Vulnerability May Affect Windows | Threatpost | The first stop for security news

White hat claims Yahoo and WinZip hacked by "shellshock" exploiters | Ars Technica

Yahoo says attack wasn't Shellshock - CNET

That Unpatchable USB Malware Now Has a Patch ... Sort Of | WIRED

Twitter Sues the Government for Violating Its First Amendment Rights | WIRED

Feds 'Hacked' Silk Road Without a Warrant? Perfectly Legal, Prosecutors Argue | WIRED

Finding a Video Poker Bug Made These Guys Rich-Then Vegas Made Them Pay | WIRED

AT&T Hit By Insider Breach | Threatpost | The first stop for security news

Huge Data Leak at Largest U.S. Bond Insurer - Krebs on Security

Arbor: DDoS Attacks Getting Bigger as Reflection Increases | Threatpost | The first stop for security news

Create app-specific passwords for iCloud - CNET

Bugzilla Zero-Day Exposes Zero-Day Bugs - Krebs on Security

Tyupkin ATM Malware Discovered by Kaspersky Lab | Threatpost | The first stop for security news

Reddit-powered botnet infected thousands of Macs worldwide | Ars Technica

FDA: Medical device cybersecurity necessary, but optional | Ars Technica

Adobe's e-book reader sends your reading logs back to Adobe-in plain text [Updated] | Ars Technica

October 2014, Melbourne

Alice Russell - Twin Peaks - YouTube

Risky Business #340 -- BPX droppin' iOS8 remote jailbreaks like it "ain't no thang"
0:00 / 0:00

Risky Business #339 -- Neel Mehta on Heartbleed, Shellshock

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show we're chatting with Neel Mehta, a security researcher with Google. Neel is best known for finding the Heartbleed bug, and he joins us this week to talk about Heartbleed, ShellShock, the security of SSL stacks and where he expects vuln research to go in the future.

Funnily enough this is Neel's first interview about Heartbleed, so I guess we can call this a scoop!

This week's show is brought to you by Bromium, makers of fine, fine exploit mitigation software. Personally I'm a real fan of Bromium's stuff. They're relatively new, but if you have a Java problem in your enterprise, as in, you have to have Java in your enterprise, Bromium has a solution for you -- they make micro-vm software that mitigates memory corruption bugs and it's actually quite good.

Bromium's chief security architect Rahul Kashyap joins us this week to talk about some malvertising research he presented at the virus bulletin conference recently, and he also previews the results of Bromium's code audit. That's right, a security software company actually had their software audited! Bowl me over. The audit report will be available next week, but we get the inside scoop on that before it's out.

Show notes

JPMorgan hack exposed data of 83 million, among biggest breaches in history

Xen Bug Could cause Crashes, Expose Cloud Data | Threatpost | The first stop for security news

Musings on the recent Xen Security Advisories | Bromium Labs

Apple patches "Shellshock" Bash bug in OS X 10.9, 10.8, and 10.7 | Ars Technica

OpenVPN vulnerable to Shellshock Bash vulnerability | Threatpost | The first stop for security news

Fiora\u202e\u2604anreteA on Twitter: "RT "cmd.exe #shellshock" @dakami: "this is why we can't have nice strings" http://t.co/9LPTbtVazr"

Silk Road Lawyers Poke Holes in FBI's Story - Krebs on Security

The Unpatchable Malware That Infects USBs Is Now on the Loose | WIRED

Lacoon Discovers Xsser mRAT, the First Advanced iOS Trojan

If the information from https://www.lacoon.com/lacoon-discovers-xsser-mrat-first - Pastebin.com

Holder urges tech companies to leave device backdoors open for police - The Washington Post

Cops Are Handing Out Spyware to Parents-With Zero Oversight | WIRED

The Criminal Indictment That Could Finally Hit Spyware Makers Hard | WIRED

CloudFlare Rolls Out Free SSL | Threatpost | The first stop for security news

FBI to Open Up Malware Investigator Portal to External Researchers | Threatpost | The first stop for security news

Chrome bug hunters, Google's giving you a raise - CNET

WPScan Vulnerability Database WordPress Security Resource | Threatpost | The first stop for security news

Second Same-Origin Policy Bypass Flaw Haunts Android Browser | Threatpost | The first stop for security news

Advertising firms struggle to kill malvertisements | Ars Technica


The Basics

Leftovers | The Basics

Risky Business #339 -- Neel Mehta on Heartbleed, Shellshock
0:00 / 0:00

Risky Business #338 -- BASHPOCALYPSE 2014

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

In addition to covering the end of the world, this week's Risky Business features Don Bailey of Lab Mouse Security on his excellent IoT blog post, written largely in response to a Daily Dave post by Dave Aitel on so-called "junk hacking".

This week's show is brought to you by Context Information Security, big thanks to them! And in this week's sponsor interview we chat with Context's director of research Michael Jordon about his adventures in getting old computer games to work on printer screens. It's actually pretty cool.

Show notes

Shell Shock: Bash bug labelled largest ever to hit the internet

Hackers Are Already Using the Shellshock Bug to Launch Botnet Attacks | WIRED

The Internet Braces for the Crazy Shellshock Worm | WIRED

Patching Bash Vulnerability a Challenge for ICS, SCADA | Threatpost | The first stop for security news

Bash Botnet Exploit Found, Bash Patches Incomplete | Threatpost | The first stop for security news

Mozilla Patches RSA Signature Forgery in NSS, Firefox | Threatpost | The first stop for security news

Xen security bug, you say? Amazon readies GLORIOUS GLOBAL CLOUD REBOOT \u2022 The Register

Amazon forced to reboot EC2 to patch Xen bug - Storage - News - iTnews.com.au

Terror laws clear Senate, enabling entire Australian web to be monitored and whistleblowers to be jailed

Senate rejects attempt to limit ASIO's access to devices - Security - Telco/ISP - News - iTnews.com.au

Charney on Trustworthy Computing: 'I Was the Architect of These Changes' | Threatpost | The first stop for security news

Kevin Mitnick, Once the World's Most Wanted Hacker, Is Now Selling Zero-Day Exploits | WIRED

Home Depot's former security architect had history of techno-sabotage | Ars Technica

Home Depot ignored security warnings for years, employees say | Ars Technica

MIT Students Battle State's Demand for Their Bitcoin Miner's Source Code | WIRED

PayPal takes second cautious step towards Bitcoin - Finance - Security - News - iTnews.com.au

Why the Heyday of Credit Card Fraud Is Almost Over | WIRED

Small Signs of Progress on DNSSEC | Threatpost | The first stop for security news

Microsoft Online Services Bug Bounty Program Launches | Threatpost | The first stop for security news

Blackphone Bug Bounty Program Launches on Bugcrowd | Threatpost | The first stop for security news

Productivity Trumping Security as BYOD Grows | Threatpost | The first stop for security news

Researcher Discloses Wi-Fi Thermostat Vulnerabilities | Threatpost | The first stop for security news

Kali NetHunter turns Android device into hacker Swiss Army knife | Ars Technica

The Mouse Trap: No Thing Left Behind

[Dailydave] Junk Hacking Must Stop!

Hacking Canon Pixma Printers - Doomed Encryption

Dawn LP/CD | HopeStreet Recordings

Risky Business #338 -- BASHPOCALYPSE 2014
0:00 / 0:00

Risky Business #337 -- The Grugq and John Brooks on invisible.im and Ricochet

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

In this week's show we chat with The Grugq about the latest invisible.im announcement and we'll also meet the creator of the Ricochet anonymous messenger software, John Brooks.

In this week's sponsor interview we chat with Senetas CTO Julian Fay about an interesting paper on defeating traffic analysis attacks against encrypted cloud storage, and also a "sign of the times" Kickstarter... a group has managed to get a weird little crypto device funded... basically a hardware crypto module. You plug your phone in on one end and your headset in on the other. They've raised over $40k, but who's going to use this?

Show notes

WikiLeaks - SpyFiles 4

New Zealand secretly built spying program, report says - CNET

Moment of Truth gifts Team Key a late bounce in polls - National - NZ Herald News

'Speargun' program is fantasy, says cable operator \u2022 The Register

Student Freya Newman pleads guilty to hacking Frances Abbott design scholarship files | The Australian

Tim Cook explains Apple's privacy policies in open letter - CNET

Apple takes 'very different view' on customer privacy, Cook says - CNET

Apple - Privacy

Apple transparency reports allude to Patriot Act demands - CNET

Apple Extends Two-Factor Authentication to iCloud | Threatpost | The first stop for security news

Three Things Apple Can Do to Fix iCloud's Awful Security | WIRED

Despite Apple's Privacy Pledge, Cops Can Still Pull Data Off a Locked iPhone | WIRED

Newest Androids will join iPhones in offering default encryption, blocking police - The Washington Post

Microsoft closing standalone Trustworthy Computing group, folding into other units - GeekWire

Home Depot Data Breach Put 56 Million Cards at Risk | Threatpost | The first stop for security news

POS Service Confirms Goodwill Breach Lasted 18 Months | Threatpost | The first stop for security news

Heartbleed to blame for Community Health Systems breach | CSO Online

Announcing Keyless SSL\u2122: All the Benefits of CloudFlare Without Having to Turn Over Your Private SSL Keys

SNMP DDoS Attack Spoofs Google DNS Server | Threatpost | The first stop for security news

OWASP Releases Latest App Sec Testing Guide | Threatpost | The first stop for security news

\u200bInternet's security bug tracker faces its 'Y2K' moment - CNET

Big Batch of Bugs Fixed in Various Versions of IDA | Threatpost | The first stop for security news

iOS 8 also comes with bucket of security fixes - CNET

Android Browser flaw a "privacy disaster" for half of Android users | Ars Technica

September 2014 Adobe Reader Acrobat Patches | Threatpost | The first stop for security news

My Social SherpaPranking My Roommate With Eerily Targeted Facebook Ads

WikiLeaks posts 'weaponized malware' for all to download | ZDNet

Kiwicon CFP

JackPair: secure your voice phone calls against wiretapping by Jeffrey Chang & the AWIT team - Kickstarter

MS and University Devs Make The Melbourne Shuffle \u2022 Cloudwards.net

Middle-School Dropout Codes Clever Chat Program That Foils NSA Spying | WIRED

Why I started invisible.im | Risky Business

Risky Business #337 -- The Grugq and John Brooks on invisible.im and Ricochet
0:00 / 0:00

Why I started invisible.im

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Before we get started, Ricochet *isn't* ready for mass consumption. It's a really great starting point, but it's currently unaudited and we're making some big changes to it in the next couple of months that will render it incompatible with current versions. If you're still curious, you can download the binaries anyway and have a play with it.

The biggest change is a reimplementation of the comms protocol Ricochet uses to enable chats. The current protocol is a custom binary thing that John Brooks knocked together and a group decision was made to move to something based on a serialisation library like protobuf. John is working on that now under the guidance of HD Moore and The Grugq.

The new protocol will basically be more resistant to attacks. We want Ricochet to be a secure tool, and we must stress that currently it is unaudited. We're planning a code-scan and an informal audit by the invisible.im team, but that hasn't been done yet. So, you know, use a VM if you're the paranoid type.

We're also adding a file transfer capability. John's working full time on both of these features, which should ship around mid November.

After that release we'll look at tightening up the code and shaking out security bugs. The upshot is, from around February next year you'll be able to download a reasonably secure, anonymous chat utility you can use to transfer files.

You can read the Wired story for the background on Ricochet and how the invisible.im team wound up joining forces with John Brooks. But I wanted to spell out the base motivations behind the invisible.im project here in this post.

I've been an information security journalist since around 2001, when I started submitting occasional infosec stories to The Age newspaper in Melbourne. I went full time with journalism in 2002, worked in the ZDNet newsroom (with a fantastic team -- James Pearce, Andrew Colley and Iain Ferguson) in 2003 before going full-time freelance.

I wrote for the Fairfax papers, ZDNet, Wired, Australian Men's Style and a bunch of others, before launching the Risky Business podcast in 2007. It's been my main gig ever since.

During my time in media I've seen some pretty incredible stuff. I've witnessed the rapid decline of newspapers over the last 10 years as they've succumbed to ad dollars going online. And I've also observed the effect readily accessible metadata has had on journalism.

Governments used to respect the media. Not because they admired the role of the media as the fourth estate, but because they knew the media could hurt them. With the fragmentation of the media landscape, that power has been substantially diluted. It's now much more common for authorities to investigate trivial (but inconvenient) leaks -- both from the corporate and government sector -- and the Wikileaks/Manning fiasco of 2010 only served to accelerate the trend.

Every time a source picks up a telephone to call a journalist, there's a record of it. Every time they email, IM, Skype or SMS a journalist, there's a record of it. Authorities can access these metadata records without court issued warrants, and they frequently do. A polite request on a letterhead is all they need.

They won't be able to access the content of those communications without a warrant, but if I publish a story about a leak from the Attorney General's Department and authorities can see that I spoke to someone from AG the day prior, my source is still burned.

Make no mistake: There are serious news and public interest stories that are going unreported because of this.

I founded invisible.im because it solves a need that I've identified in my work -- I need sources to feel confident that they can contact me with public interest information and not be identified by a metadata trail.

Because Ricochet is serverless, there's simply no third party to request metadata from.

This project will, of course, also be of great benefit to non-journalists. People in oppressive regimes can use Ricochet to shield themselves from passive state surveillance. We think there's a lot of promise there, and we'd like to translate the software into languages like Farsi so ordinary people can conduct their risky conversations a little bit more safely.

A lot of people will spend a lot of time asking whether invisible.im is an "NSA-proof" tool. We can't create an "NSA-proof" tool, and we're not claiming Ricochet is, despite the headline on the Wired piece that suggests otherwise.

What we can do is make sure it requires difficult, time consuming, and targeted effort to identify Ricochet users' associations and intercept their chats. We'll also make retrospective identification of leakers by lesser agencies (state police, for example) more or less impossible. (Well, if they're identified it's not because they used Ricochet.)

And while Ricochet may not be "NSA-proof", it certainly makes mass surveillance of its users very, very difficult. Remember that story about the GCHQ grabbing everyone's IM contact lists off the wire as they flew past? Yeah, good luck doing that with Ricochet.

But what about the "tear-rists", I hear you ask?

Well, we're yet to see evidence that mass surveillance has been responsible for any significant wins in the counter terrorism arena. And running Ricochet on your box isn't going to stop the NSA owning you sideways with 0day if you're a legitimate target. Once you're owned you're owned. If you're running Ricochet, the NSA (or equivalent agency) can still map out your IM contacts. But the nice thing is you have to be a target before they own you and do this to you. Until they access your machine, the only person who has your Ricochet contact list is you. Not your IM provider, not your telco. Just you.

I hope this post does something to help people understand why I decided to get involved and bring together some of the smartest people I know to tackle this problem. Invisible.im is seeking to solve a real world problem -- too much metadata is accessible to too many corporate entities and government agencies.

Simple, really.

You can flame Patrick Gray on Twitter.

Risky Business 336 -- Too many cons

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show we've got a great interview with Haroon Meer of Thinkst. Thinkst has a paid service that analysis the output of security conferences and puts together reports. Now, some of you might wonder why such a service would be needed, so let's put things in perspective: there were 2,700 conference presentations in the second quarter of this year at 116 events over 140 conference days. Yikes!

Haroon will be along in a bit to talk about the conference content boom, and he's also made their latest report free for Risky Business listeners! As I say, it's part of Thinkst's paid subscription service, so you'd be nuts not to grab it.

This week's show is brought to you by Tenable Network Security, thanks to the guys and gals over there. In this week's sponsor interview we're chatting with Paul Asadoorian, Tenable's product marketing manager for Nessus.

Paul is also well known as the host of the security weekly podcast! It's an infosec podcast with a massive audience that you've no doubt heard of.

We're chatting with Paul about embedded devices. He co-wrote a book on hacking the WRT54g home wireless gateway some years ago and he's gearing up to teach a SANS course on embedded device assessments. So yeah, Paul's going to stop by and discuss the state of all things embedded.

Show notes

Dread Pirate Sunk By Leaky CAPTCHA - Krebs on Security

FBI's Story of Finding Silk Road's Server Sounds a Lot Like Hacking | WIRED

Should we be worried? Showing on login page : SilkRoad

Troll or thief? User claims Bitcoin founder Satoshi Nakamoto dox sabotage \u2022 The Register

PayPal goes crypto-currency with Bitcoin \u2022 The Register

Feds Threatened to Fine Yahoo $250K Daily for Not Complying With PRISM | WIRED

Five Million Email Passwords, Addresses Leak Russian Forum | Threatpost | The first stop for security news

Home Depot Data Breach Confirmed | Threatpost | The first stop for security news

BlackPOS malware confirmed in Home Depot US hack - Security - News - iTnews.com.au

Apple Plans to Extend 2FA to iCloud | Threatpost | The first stop for security news

After hacking, Apple to send out more security alerts to users | Ars Technica

Barclays brings finger-vein biometrics to Internet banking | Ars Technica

Researchers find data leaks in Instagram, Grindr, OoVoo and more - CNET

Salesforce Warns Customers of Dyreza Banker Trojan Attacks | Threatpost | The first stop for security news

Traffic Networks Firm Patches Sensor Vulnerabilities | Threatpost | The first stop for security news

Microsoft to patch ASP.NET mess even if you don't \u2022 The Register

Cisco Patches Denial-of-Services Vulnerability in IMC | Threatpost | The first stop for security news

September 2014 Microsoft Patch Tuesday security bulletins | Threatpost | The first stop for security news

Critical Fixes for Adobe, Microsoft Software - Krebs on Security

Apache Warns of Tomcat Remote Code Execution Vulnerability | Threatpost | The first stop for security news

Infamous "podcast patent" heads to trial | Ars Technica


Embedded Device Security Assessments For The Rest Of Us

Risky Business 336 -- Too many cons
0:00 / 0:00