Podcasts

News, analysis and commentary

Risky Business #290 -- A chat with Howard Schmidt

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

This week's show features a fantastic, extended interview with Howard Schmidt, the former White House cyber security co-ordinator and special Assistant to the US President.

We spend about 35 minutes talking about what information security looks like from a high-level policy perspective. It's a long interview but there are some gems in there. We talk about some of the initiatives Howard kicked off at the White House, about the critical infrastructure legislation ping-pong game the executive branch played with congress, about Edward Snowden's leaks, and what it was like to work for Barack Obama.

This week's show is brought to you by a new sponsor -- Context Information Security. ContextIS is a global consultancy and managed service provider and its Australian general manager Scott Ceely joins us this week to talk about watering hole attacks. More specifically he's talking to us about a watering hole attack that managed to hose a few high value targets with some pretty basic exploitation techniques. The Crouching Tiger watering hole attack, a case study, if you will.

Adam Boileau, as usual, joins us to talk about the week's news headlines. Show notes here.

Risky Business #290 -- A chat with Howard Schmidt
0:00 / 75:44

Risky Business #289 -- Smart TVs are kinda stoopid

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

This week's show is brought to you by the fine, fine people at Tenable Network Security, big thanks to Tenable for all its support over the years.

And on this week's show we chat briefly with South Korean researcher SeungJin Lee about Smart TV security. They're equipped with cameras and microphones and they're popping up in living rooms everywhere.

Now, smart phones have cameras and microphones on them, so a lot of the hype around connected home devices seems a bit unreasonable. It's not like this is the first type consumer device that can be turned into a surveillance device. But as you'll hear, Smart TV operating systems are pretty insecure and vulnerable to some pretty basic forms of exploitation, so some of these concerns are actually quite reasonable.

SeungJin Lee will be dropping in to discuss his research into Smart TV security, research he'll be presenting at BlackHat in Las Vegas the week after next!

In this week's sponsor interview we chat with Ron Gula, the CEO of Tenable Network Security. This week we ask Ron if Ed Snowden's revelations on NSA spying could drive non-US companies away from doing business with American cloud service providers.

And we check the week's security news stories with Adam Boileau. Show notes here.

Risky Business #289 -- Smart TVs are kinda stoopid
0:00 / 57:34

Risky Business #288 -- Planet Android safe from flaming pwncomet

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show we take an axe to all the crazy hype around BlueBox's Android research. It's been a shameful, shameful week for the tech media. I half expected to walk outside this week and find crowds of consumers holding pitchforks and burning their Android devices based on the headlines we've been seeing about 99% of all 'droid devices being open to attack!

As you'll hear in this week's interview with Justin Case (jcase), the research is cool -- it's a code signing check bypass for android install packages -- but you can put down the matches and the lighter fluid. It's not that bad.

In this week's sponsor interview we continue the conversation about code signing with Brad Arkin, the CSO of Adobe. Adobe itself had some trouble with an attacker compromising its systems and signing malware with its HSM. Last week, as you would have heard, someone managed to do the same thing at Opera, only that case was worse because they also jacked the browser's update boxes for a short time and served up bogus patches.

Last time Brad was on the show he was the head of security and privacy at Adobe so handling the operational security and code signing wasn't actually his responsibility. But it is now so he's been doing some thinking.

What do these recent developments tell us about distributed trust models for code signing? Are desktop OS's moving towards the mobile app signing model that has worked so spectacularly well for Apple? Well, Brad says they are, with caveats.

Adam Boileau, as usual, joins the show to discuss the week's news headlines. Show notes are here.

Risky Business #288 -- Planet Android safe from flaming pwncomet
0:00 / 69:55

Risky Business #287 -- In Soviet Russia, bugs exploit you!

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

We've got a great show for you this week. Mark Dowd of Azimuth Security pops in to talk about the bugs he found in libraries used by secure telephony providers like Silent Circle. They're serious, serious bugs, and they were easy to find.

Also this week we talk to Les Goldsmith of ESD America. ESD is a pretty interesting outfit. They sell the German-developed GSMK Cryptophone, a product that has been around for a very, very long time and is mostly used by militaries and police. They also sell counter surveillance training, bug sweeping gear, armoured vehicles, tactical training and explosives detection dogs, but hey, today we're focussing on the electronic stuff.

We get Les's reaction to the news that the US has been bugging the offices of the European Union, the Ecuadorian embassy and, well, pretty much everyone all the time. He's got some really interesting perspectives on that.

In this week's sponsor interview we chat with Chris Gatford about these awful, awful IPMI vulnerabilities. The Intelligent Platform Management Interface turns out to be anything but! If you haven't heard, it turns out there are serious, protocol-level design flaws in IPMI which are going to make life tough for anyone who's actually using it. it's the sort of thing that will take a long time to truly fix, too.

Risky Business #287 -- In Soviet Russia, bugs exploit you!
0:00 / 66:07

Risky Business #286 -- The one where we talk about Snowden

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

This week's show is a bit shorter than usual. We've got a discussion of the week's news then a great chat with Brian Contos, the VP and CISO of Blue Coat Systems Advanced Threat Protection Group.

It's this week's sponsor interview and we'll be chatting about whether or not cyber warfare is really asymmetrical. It's the accepted wisdom that it is, but I gotta say, when we look at who's using it -- the US and Israel against Iran and Syria, Russia versus Estonia -- it looks to me like it's something used by the big guys to smash the little guys. Brian disagrees, so it's a nice lively discussion and it's coming up after the news.

Show notes

You can find that episode here.

Stolen Opera Code-Signing Certificate Used to Sign Malware | Threatpost
http://threatpost.com/opera-code-signing-certificate-stolen-malware-sign...

Google Adds Feature to Keep Malware Out of Chrome Web Store | Threatpost
http://threatpost.com/google-fortifies-chromes-web-store-vetting-process/

Researcher Hijacks Facebook Accounts Via Mobile | Threatpost
http://threatpost.com/sms-account-hijack-exploit-fixed-by-facebook/

Facebook bug exposed contact info of 6M users | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57590528-83/facebook-bug-exposed-contac...

Senate urged to pass data breach notification law - Risk - SC Magazine Australia - Secure Business Intelligence
http://www.scmagazine.com.au/News/347895,senate-urged-to-pass-data-breac...

Australian AG scraps ISP data retention plans | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57590675-83/australian-ag-scraps-isp-da...

Hackers reportedly release data on U.S. troops in Korea | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57591048-83/hackers-reportedly-release-...

Mobile malware grows by 614 percent in last year | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57591042-83/mobile-malware-grows-by-614...

LG Android Backup Software Vulnerable to Root Exploit | Threatpost
http://threatpost.com/pre-installed-backup-software-on-lg-android-phones...

Researchers Uncover PinkStats APT Toolkit | Threatpost
http://threatpost.com/researchers-uncover-pinkstats-apt-toolkit/

WikiLeaks Volunteer Was a Paid Informant for the FBI | Threat Level | Wired.com
http://www.wired.com/threatlevel/2013/06/wikileaks-mole/

14 Vulnerabilities Fixed in Firefox 22 | Threatpost
http://threatpost.com/14-vulnerabilities-fixed-in-firefox-22/

WordPress Update 3.5.2 Patches Seven Vulnerabilities | Threatpost
http://threatpost.com/latest-wordpress-update-patches-seven-vulnerabilit...

NSA collected Americans' email records in bulk for two years under Obama | World news | The Guardian
http://www.guardian.co.uk/world/2013/jun/27/nsa-data-mining-authorised-o...

U.K. Spy Agency Secretly Taps Over 200 Fiber-Optic Cables, Shares Data With the NSA | Threat Level | Wired.com
http://www.wired.com/threatlevel/2013/06/gchq-tapped-200-cables/

Student group files complaint against U.S. firms over NSA data snooping | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57591122-83/student-group-files-complai...

Whistle-blower update: Snowden lands in Moscow; WikiLeaker's Gmail searched | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57590599-83/whistle-blower-update-snowd...

NSA Surveillance Leaks Prompt Legislation | Threat Level | Wired.com
http://www.wired.com/threatlevel/2013/06/nsa-spy-legislation/

Feds charge Snowden with espionage | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57590549-83/feds-charge-snowden-with-es...

Handling of Encryption, Tor Exposed in Leaked NSA Documents | Threatpost
http://threatpost.com/new-nsa-leak-sheds-light-on-encrypted-data-retention/

Udall: NSA states "significant" errors about privacy protections - The Denver Post
http://www.denverpost.com/ci_23530383/udall-nsa-states-significant-error...

Putin says Snowden is not technically in Russia
http://www.usatoday.com/story/news/world/2013/06/25/snowden-russia-china...

you am i - rumble [audio only] - YouTube
http://www.youtube.com/watch?v=S1wp2D5DM_s

,

Google is trying to step up their game. They are really aggressively making the right steps towards customer satisfaction. - Adam LaFavre

Risky Business #286 -- The one where we talk about Snowden
0:00 / 44:01

Risky Business #285 -- Beating the G20 Internet cafe

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

In this week's show we talk opsec with international man of mystery The Grugq. In light of revelations the Internet lounge at the G20 summit was essentially an intelligence collection system set up by GCHQ, we thought we'd look at what travelling diplomats and executives can do to protect their data when entering a hostile environment where all infrastructure is assumed to be controlled by your adversary.

There's some great practical advice in that segment, and it's after the news.

In this week's sponsor interview we speak with Jack Daniel, Tenable Network Security's product manager about Microsoft's bug bounty program. $100k for a good exploit! The times, they change.

And we check in with Adam Boileau to discuss the week's news headlines. Show notes can be found here.

Risky Business #285 -- Beating the G20 Internet cafe
0:00 / 59:42

Risky Business #284 -- Snowden and the Internet counter-culture

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

In this week's feature interview we chat with author and speaker Richard Thieme about what they used to call the generation gap. NSA leaker Edward Snowden is "Internet generation". Are the ideals espoused by people like Snowden rooted in counter-cultural ideals or are they just generational norms?

Are these ideas around online liberty becoming mainstream? Now that we have so many gen-Ys and millennials actually running the information infrastructure that powers our institutions, could we be on the cusp of serious changes in the way the establishment works? That is an interesting chat.

In this week's sponsor interview we're chatting to John Vecchi, Solera's VP of Product Strategy, all about whether or not we're neglecting mundane threats because we're so focussed on identifying APT.

Adam Boileau joins us for this week's news segment. Show notes, including links to the articles discussed, can be found here.

Risky Business #284 -- Snowden and the Internet counter-culture
0:00 / 69:37

Risky Business #283 -- America, we need to talk

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show we take a look at PRISM, the NSA's recently exposed massive surveillance program. Leaked PowerPoint slides from NSA describe a surveillance system that allows the agency to effortlessly capture a target's YouTube, Google, Facebook and Skype. This has been reported as these companies allowing the US government access to "back doors" on their systems.

In this week's episode we look at an alternative theory: The NSA is actually capturing information on "persons of interest" in real-time via fibre taps, decrypting it with private keys, then storing it. It's our theory and we're sticking with it. Listen to this week's episode to see if you agree!

Also this week we've got Tenable's chief of security, Marcus Ranum, stopping by in this week's sponsor interview to follow up on his keynote speech at AusCERT. The speech was called Never Fight a Land War in Cyber Space and it's really about the idea that conventional military thinking doesn't apply to the Internet.

I published a recording of his talk and it got a great reaction, but I was left with some questions after I saw it. So I rang him up and asked them! It's actually a really, really interesting interview so make sure you tune in for it.

****EDITOR'S NOTE: During the discussion on PRISM, I referenced 5Tb/s of traffic between "the US, Canada and US". That should have been "The US, Canada and Europe". Sorry about that!

Show notes

Report: NSA Was Granted Order to Snag Millions of Verizon Call Records for 3 Months | Threat Level | Wired.com
http://www.wired.com/threatlevel/2013/06/nsa-verizon-call-records/

Assange no concern of ours, says Carr
http://www.smh.com.au/opinion/political-news/assange-no-concern-of-ours-...

Google push for faster zero day fixes hits a wall: Other companies | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57587178-83/google-push-for-faster-zero...

NetTraveler Espionage Malware Campaign Ties to Gh0st RAT | Threatpost
http://threatpost.com/net-traveler-espionage-campaign-uncovered-links-to...

Oracle Java Security Enhancements Get Mixed Reviews | Threatpost
http://threatpost.com/mixed-reviews-on-oracles-java-security-update/

FDIC: 2011 FIS Breach Worse Than Reported - Krebs on Security
http://krebsonsecurity.com/2013/06/fdic-2011-fis-breach-worse-than-repor...

Peer-to-Peer Botnets Grow Fivefold | Threatpost
http://threatpost.com/number-of-peer-to-peer-botnets-grows-5x/

Systems are now secure: Govt CIO | Computerworld New Zealand
http://computerworld.co.nz/news.nsf/news/systems-are-now-secure-govt-cio

Windows 8.1 to let you secure folders with your fingerprint | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57587535-83/windows-8.1-to-let-you-secu...

Two-Factor Authentication Options for Web Services | Threatpost
http://threatpost.com/web-services-finding-religion-with-two-factor-auth...

Pills and Tattoos to Replace Passwords for Authentication | Threatpost
http://threatpost.com/former-darpa-head-proposes-pills-and-tattoos-to-re...

Microsoft, feds disrupt massive Citadel botnet | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57587935-83/microsoft-feds-disrupt-mass...

Schneider Patches 18-Month Old SCADA Bugs | Threatpost
http://threatpost.com/schneider-patches-18-month-old-scada-bugs/

Five Bulletins, One Critical in Microsoft's June Patch | Threatpost
http://threatpost.com/five-bulletins-one-critical-in-microsofts-june-patch/

Google Fixes Security Vulnerabilities with Chrome Update | Threatpost
http://threatpost.com/google-ships-12-security-patches-in-latest-chrome-...

Apple Patches Mass of Security Bugs in OS X and Safari | Threatpost
http://threatpost.com/apple-patches-mass-of-security-bugs-in-os-x-and-sa...

Internet Systems Consortium Resolves Critical BIND Flaw | Threatpost
http://threatpost.com/isc-patches-known-bind-9-dos-vulnerability/

STORIES DISCUSSED IN FEATURE SEGMENT:

U.S. intelligence mining data from nine U.S. Internet companies in broad secret program - The Washington Post
http://www.washingtonpost.com/investigations/us-intelligence-mining-data...

Verizon Breaks Silence on Top-Secret Surveillance of Its Customers | Threat Level | Wired.com
http://www.wired.com/threatlevel/2013/06/verizon-responds/

DHS Watchdog: 'Intuition and Hunch' Are Enough to Search Your Gadgets at Border | Threat Level | Wired.com
http://www.wired.com/threatlevel/2013/06/border-gadget-searches/

Teen Jailed for Rap Lyrics Posted After Boston Bombings | Threat Level | Wired.com
http://www.wired.com/threatlevel/2013/06/teen-jailed-for-terror-rap/

PRESENTATION: Marcus Ranum on militarisation trends | Risky Business
http://risky.biz/ranum_auscert

,

Oracle has really embraced the fact that they should be more careful with their security. They need to do that. - Kris Krohn Strongbrook

Risky Business #283 -- America, we need to talk
0:00 / 62:52

Risky Business #282 -- The future of hacktivism

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

This week's show is a cracker! We've got a great feature interview with journalist and author Parmy Olson about what the future might hold for Anonymous. Is it time for the Anonymous brand to be retired? The media has largely lost interest in its activities -- how could the hacktivism phenomenon bounce back to the same levels of notoriety as it experienced in 2011?

Tune in to find out!

This week's show is brought to you by Senetas, makers of absolutely kick-ass layer 2 encryption equipment.

In this week's sponsor interview we're chatting with Senetas co-founder and CTO Julian Fay about homomorphic encryption. This is where you can actually perform operations on data while it's still encrypted! It's all a bit twisted, but it's fascinating stuff and it's this week's sponsor interview topic.

Show notes

You can click through to the recording page here.

ASIO blueprints, Defence documents stolen - Hackers - SC Magazine Australia - Secure Business Intelligence
http://www.scmagazine.com.au/News/344763,asio-blueprints-defence-documen...

Confidential report lists U.S. weapons system designs compromised by Chinese cyberspies - The Washington Post
http://www.washingtonpost.com/world/national-security/confidential-repor...

U.S. Government Seizes LibertyReserve.com - Krebs on Security
http://krebsonsecurity.com/2013/05/u-s-government-seizes-libertyreserve-...

Liberty Reserve Founder Indicted on $6 Billion Money-Laundering Charges | Threat Level | Wired.com
http://www.wired.com/threatlevel/2013/05/liberty-reserve-indicted/

Anonymous Hacktivist Jeremy Hammond Pleads Guilty to Stratfor Attack | Threat Level | Wired.com
http://www.wired.com/threatlevel/2013/05/hammond-plea/

Guantanamo Wi-Fi shuttered after Anonymous hacking threat | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57585420-83/guantanamo-wi-fi-shuttered-...

Twitter Enables Two-Factor Authentication | Threatpost
http://threatpost.com/twitter-enables-two-factor-authentication/

Kim Dotcom Claims Ownership of Two-Factor Authentication | Threat Level | Wired.com
http://www.wired.com/threatlevel/2013/05/kim-dotcom-two-factor/

Holder Signed Off on Warrant Identifying Fox News Reporter as Criminal Conspirator | Threat Level | Wired.com
http://www.wired.com/threatlevel/2013/05/holder-signed-off-on-warrant/

WikiLeaks Donations Down to a Trickle | Threat Level | Wired.com
http://www.wired.com/threatlevel/2013/05/wikileaks-donations-down/

Drupal hacked, resets passwords after millions of accounts exposed \u2022 The Register
http://www.theregister.co.uk/2013/05/30/drupal_sites_hacked/

Ruby on Rails Exploit Harvests IRC Botnet | Threatpost
http://threatpost.com/ruby-on-rails-exploit-builds-irc-botnet-of-comprom...

Report Says Active Recovery Efforts Could Deter IP Theft By Foreign Attackers | Threatpost
http://threatpost.com/report-says-active-recovery-efforts-could-deter-ip...

Hackers Who Breached Google in 2010 Accessed Company's Surveillance Database | Threat Level | Wired.com
http://www.wired.com/threatlevel/2013/05/google-surveillance-database/

ReVuln Discovers Zero Day Vulns in Gaming Clients | Threatpost
http://threatpost.com/researchers-discover-dozens-of-gaming-client-and-s...

PayPal to Fix XSS Flaw, But No Reward For Researcher | Threatpost
http://threatpost.com/paypal-to-fix-xss-flaw-but-no-reward-for-researcher/

Vulnerabilities Plague File Lite, File Pro iOS Apps | Threatpost
http://threatpost.com/remote-code-injection-vulnerabilities-discovered-i...

Click-Fraud Falls as Microsoft Fights ZeroAccess Malware | Threatpost
http://threatpost.com/microsofts-curbs-click-fraud-in-zeroaccess-fight/

Mac OS X Backdoor Found in Wild | Threatpost
http://threatpost.com/another-mac-os-x-backdoor-reported/

Apple Patches QuickTime on Windows, Fixes 12 Bugs | Threatpost
http://threatpost.com/new-apple-quicktime-update-patches-12-vulnerabilit...

Google Fixes More Than a Dozen Flaws in Chrome 27 | Threatpost
http://threatpost.com/google-fixes-more-than-a-dozen-flaws-in-chrome-27/

Skype Beta Plugs IP Resolver Privacy Leak - Krebs on Security
http://krebsonsecurity.com/2013/05/skype-beta-plugs-ip-resolver-privacy-...

Google Strengthening Keys on SSL Certificates to 2048 Bits | Threatpost
http://threatpost.com/google-strengthening-keys-on-ssl-certificates-to-2...

IBM open sources new approach to crypto \u2022 The Register
http://www.theregister.co.uk/2013/05/03/ibm_open_source_homomorphic_crypto/

Rokia Traor\xe9 "Sikey" - Acoustic / TV5MONDE - YouTube
http://www.youtube.com/watch?v=U2OnJvbEiHc

We Are Anonymous: Inside the Hacker World of LulzSec, Anonymous, and the Global Cyber Insurgency: Parmy Olson: 9780316213523: Amazon.com: Books
http://www.amazon.com/dp/0316213527

Senetas - Data Protection through Encryption
http://www.senetas.com/

,

The blueprints are already laid out. They need to execute the plan right there. - Mission Maids

Risky Business #282 -- The future of hacktivism
0:00 / 68:34

PRESENTATION: Marcus Ranum on militarisation trends

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

The following is a recording of Marcus Ranum's AusCERT keynote speech on CYBER WAR. Marcus was doing the circuit a few years ago with a talk titled "Cyber war is bullshit", which I think makes clear his position, but this one is titled Never Fight a Land War in Cyberspace. He basically argues that the application of traditional military thinking to the cyber domain is flawed. He also argues there's a massive money and power grab taking place as the military and the private sector defence base tries to set the agenda so it can profit from it. It's a really worthwhile talk, and delivered with typical MjR flair. Enjoy.

PRESENTATION: Marcus Ranum on militarisation trends
0:00 / 53:07