Podcasts

News, analysis and commentary

Risky Business #312 -- RSA special edition

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

It's a solid week for BitCoin news. The (maybe) outing of the elusive Satoshi Nakamoto, the MtGox mystery, dead exchanges and even, unfortunately, a suicide of a former BitCoin exchange CEO in Singapore.

But there's been plenty of other news! Apple's gotofail bug, GnuTLS issues, more NTP amplification attacks, and of course YahooWebcamGate. You can find links to the news items discussed in this week's show here.

There's also a stack of interviews in this week's podcast, including a bunch recorded in San Francisco last week. The run sheet looks like this:

\t- The Grugq discussing the news headlines of the last two weeks
\t- Marcus Ranum on the RSA trade floor discourse
\t- RSA CEO Art Coviello on the NSA controversy
\t- ACLU principal technologist Chris Soghoian
\t- RSA Chief Architect Robert Griffin
\t- Jack Daniel of Tenable Network Security (sponsor interview) on the "Threat Intelligence" buzzword craze

Risky Business #312 -- RSA special edition
0:00 / 72:19

Risky Business #311 -- Does NameCoin have legs?

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

This week we chat with a local consultant, Mark Brand of Datacom TSS, about the general topic of authentication. We've seen some interesting cases of things going wrong with auth on consumer sources lately. The @n Twitter username hijacking, the Matt Honan disaster of 2012.

Now Google's run off and bought SlickLogin, a novel approach to mobile app auth. Will that get us anywhere? And what about NameCoin -- a BitCoin protocol-derived peer-to-peer authentication scheme? I'd never heard of it, but the concept is fascinating. Mark pops by to fill us in.

This week's show is brought to you by Senetas. In this week's sponsor interview we're chatting with Senetas CTO Julian Fay about some work they've been doing on their Ethernet products. As it turns out, variable frame sizes can give up too much info to an attacker, so they've worked on some neat new tech that basically forces their stuff to send fixed length frames and make sure everything stays random.

Adam Boileau pops by as usual to chat about the week's security news. Show notes, including links, are here.

Risky Business #311 -- Does NameCoin have legs?
0:00 / 56:41

Risky Business #310 -- Export exploits? Wassenaar says no

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show we're chatting with COSEINC's Thomas Lim about the Wassenaar Arrangement. It's basically a worldwide framework that restricts the sale of munitions and dual use technologies, and it has exploits in its sites.

COSEINC is a security research company that engages in exploit development, and Lim thinks extending regulations to exploit sales is pointless.

This week's show is brought to you by BugCrowd, a company that was founded in Australia but is now based in San Francisco thanks to VC investment.

Bugcrowd runs outsourced bug bounties, and its founder and CEO Casey Ellis joins the show in this week's sponsor interview to talk about the latest goings on in the burgeoning bug bounty industry!

Show notes

Top U.S. Spy Claims 'Terrorists Are Going to School' on Snowden Leaks | Threat Level | Wired.com
http://www.wired.com/threatlevel/2014/02/clapper-snowden-fallout/

Hacked X-Rays Could Slip Guns Past Airport Security | Threat Level | Wired.com
http://www.wired.com/threatlevel/2014/02/tsa-airport-scanners/

Sophisticated Spy Tool 'The Mask' Rages Undetected for 7 Years | Threat Level | Wired.com
http://www.wired.com/threatlevel/2014/02/mask/

Public servant Peter Nash allegedly ran drug ring from Wacol prison | The Courier-Mail
http://www.couriermail.com.au/news/queensland/public-servant-peter-nash-...

400 Gbps NTP Amplification DDoS Attack Alarmingly Simple | Threatpost | The first stop for security news
http://threatpost.com/400-gbps-ntp-amplification-attack-alarmingly-simpl...

HVAC Vendor: Data Connection to Target was Billing System | Threatpost | The first stop for security news
http://threatpost.com/hvac-integrators-billing-connection-led-to-target-...

faziomechanical.com/Target-Breach-Statement.pdf
http://faziomechanical.com/Target-Breach-Statement.pdf

Websites of Las Vegas Sands casinos hacked, including Venetian, Palazzo on Las Vegas Strip | Star Tribune
http://www.startribune.com/lifestyle/244922181.html

Errata Security: That NBC story 100% fraudulent
http://blog.erratasec.com/2014/02/that-nbc-story-100-fraudulent.html#.Uv...

Detecting Car Hacks | Threatpost | The first stop for security news
http://threatpost.com/detecting-car-hacks/104190

illmatics.com/car_hacking.pdf
http://illmatics.com/car_hacking.pdf

CoinThief Bitcoin Trojan Found on Popular Download Sites | Threatpost | The first stop for security news
http://threatpost.com/cointhief-bitcoin-trojan-found-on-popular-download...

Bitcoin Foundation, Mt. Gox spar over purported bug | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57618646-83/bitcoin-foundation-mt-gox-s...

Florida Targets High-Dollar Bitcoin Exchangers - Krebs on Security
http://krebsonsecurity.com/2014/02/florida-targets-high-dollar-bitcoin-e...

LinkedIn Intro Service to Shut Down March 7 | Threatpost | The first stop for security news
http://threatpost.com/controversial-linkedin-intro-service-to-shut-down/...

Snapchat hack spams users with smoothie photos | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57618782-83/snapchat-hack-spams-users-w...

Facebook Fixes CSRF Vulnerability in Instagram | Threatpost | The first stop for security news
http://threatpost.com/facebook-fixes-instagram-csrf-vulnerability-to-kee...

Five OAuth Bugs Lead to Github Hack | Threatpost | The first stop for security news
http://threatpost.com/five-oauth-bugs-lead-to-github-hack/104178

Adobe Patches Shockwave, Fixes Two Vulnerabilities | Threatpost | The first stop for security news
http://threatpost.com/adobe-patches-critical-vulnerabilities-in-shockwav...

February 2014 Microsoft Patch Tuesday Security Bulletins | Threatpost | The first stop for security news
http://threatpost.com/microsoft-adds-critical-ie-patches-under-the-wire/...

New IE Zero-Day Found in Watering Hole Attack | FireEye Blog
http://www.fireeye.com/blog/technical/cyber-exploits/2014/02/new-ie-zero...

Operation SnowMan: DeputyDog Actor Compromises US Veterans of Foreign Wars Website | FireEye Blog
http://www.fireeye.com/blog/uncategorized/2014/02/operation-snowman-depu...

Changes to Export Control Arrangement Apply to Computer Exploits and More | Center for Internet and Society
https://cyberlaw.stanford.edu/publications/changes-export-control-arrang...

Bugcrowd | Managed bug bounty programs, better security testing
https://bugcrowd.com/mobile-application-security

Pumped Up Kicks by Hailey-Marie on SoundCloud - Hear the world's sounds
https://soundcloud.com/hailey-marie-mcfadden/pumped-up-kicks

Risky Business #310 -- Export exploits? Wassenaar says no
0:00 / 61:57

Risky Business #309 -- All your clipboards R belong 2 OJ

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

We're back after a nice long rest, and boy oh boy did a lot of stuff happen during the break. Adam Boileau joins the show to discuss the choicest selection of news items to emerge over the last six weeks.

In this week's feature slot we chat to OJ Reeves about his work in upgrading Meterpreter, the Metasploit payload. There are some cool new features on the way, he'll clue us in on those.

This week's show is brought to you by Tenable Network Security.

Tenable's very own Marcus Ranum will be joining us to have a chat about security metrics in this week's sponsor interview, stick around for that.

Show notes for this week's episode are here.

Patrick Gray on Twitter.
Adam Boileau on Twitter.

Risky Business #309 -- All your clipboards R belong 2 OJ
0:00 / 69:20

Risky Business #308 -- 2013 in review

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

This is the final Risky Business podcast for 2013. The show will resume its weekly schedule in February 2014.

Oh, and there are still three sponsor slots left between now and July. If you're interested, drop us a line with the contact form...

This week's show looks back over the key events and trends of 2013; how media focus shifted from focussing on China's cyber-espionage to the scandalous revelations of the Snowden leaks.

We also take a quick look at the Silk Road bust, say goodbye to some friends and check in with Insomnia Security's Brett Moore in this week's sponsor interview.

Risky Business #308 -- 2013 in review
0:00 / 48:42

Risky Business #307 -- So, what about that Bromium stuff?

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show we speak to Bromium co-founder and CTO Simon Crosby all about its tech. We don't normally interview vendors about their technology in the feature slots, but Bromium is very interesting stuff. It's all about hardware-enabled task isolation with Xen-based micro VMs. The way they've implemented this makes it quite difficult for an attacker to gain persistence on a target machine. Simon is a very technical guy, it's a great interview and it's after the news.

This week's show is brought to you by Tenable Network Security, makers of fine, fine, vulnerability scanning tools like Nessus. And in this week's sponsor interview we chat with Tenable's chief architect for the Asia Pacific region Dick Bussiere. Dick is based in Singapore, and surprisingly enough the infosec agenda there isn't being set by the Snowden leaks. So what's driving the infosec narrative in .sg? Dick joins the show with his view.

Show notes

$100 Million Worth of Bitcoins Stolen | Threatpost | The First Stop For Security News
http://threatpost.com/thieves-covering-tracks-following-100m-bitcoin-hei...

Malware jumps 'air gap' between non-networked devices | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57614442-83/malware-jumps-air-gap-betwe...

Huawei reportedly decides to abandon the US market | Mobile - CNET News
http://news.cnet.com/8301-1035_3-57614292-94/huawei-reportedly-decides-t...

Farsnews
http://english.farsnews.com/newstext.aspx?nn=13920909000362

Phone records of Australians may have been offered to foreign spy agencies
http://www.smh.com.au/federal-politics/political-news/phone-records-of-a...

A Few Thoughts on Cryptographic Engineering: How does the NSA break SSL?
http://blog.cryptographyengineering.com/2013/12/how-does-nsa-break-ssl.html

SkyJack - autonomous drone hacking
http://samy.pl/skyjack/

JPMorgan warns 465,000 card users on data loss after cyber attack | Reuters
http://www.reuters.com/article/2013/12/05/us-jpmorgan-dataexposed-idUSBR...

Researchers discover database with 2M stolen login credentials | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57614479-83/researchers-discover-databa...

New Dexter Point-of-Sale Malware Campaigns Discovered | Threatpost | The First Stop For Security News
http://threatpost.com/new-dexter-point-of-sale-malware-campaigns-discove...

Google Nexus phones reportedly susceptible to SMS attacks | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57614074-83/google-nexus-phones-reporte...

Bad apps bypasses Android locks - Applications - SC Magazine Australia - Secure Business Intelligence
http://www.scmagazine.com.au/News/366459,bad-apps-bypasses-android-locks...

IE Reflective Cross-Site Scripting Filter Bypass Discovered | Threatpost | The First Stop For Security News
http://threatpost.com/bypass-of-internet-explorer-cross-site-scripting-f...

TIFF Zero Day Patch Among December 2013 Microsoft updates | Threatpost | The First Stop For Security News
http://threatpost.com/microsoft-to-patch-tiff-zero-day-wait-til-next-yea...

VMware Patches Fix Privilege Escalation Vulnerability | Threatpost | The First Stop For Security News
http://threatpost.com/vmware-patches-privilege-escalation-vulnerability/...

PM - Discovery of more than one whistleblower in East Timor bugging case 05/12/2013
http://www.abc.net.au/pm/content/2013/s3905928.htm

Fact Sheet- Online news sites to be placed on a more consistent licensing framework
http://www.mda.gov.sg/NewsAndEvents/PressRelease/2013/Pages/28052013.aspx

Risky Business #307 -- So, what about that Bromium stuff?
0:00 / 75:38

Risky Business #306 -- Healthcare.gov. Yes. It's that bad.

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

In this week's show we speak with TrustedSec CEO Dave Kennedy about his testimony to the US congress about the Obama administration's healthcare.gov website. It cost over $600m and it's riddled with infosec 101 bugs. We find out just how bad it is and what can be done about it.

This week's show is brought to you by Senetas, makers of fine, fine layer 2 encryption software. In this week's sponsor interview we speak with Senetas CTO and co-founder Julian Fay about the sudden popularity of the layer 2 crypto gear they've been selling for something like 15 years. Have the Snowden revelations actually changed things for encryption companies? Julian says yes, big time, in a tangible way.

Adam Boileau, as always, joins us for a discussion of the week's security news headlines. Links to the news items discussed, plus some other stuff, can be found here.

Risky Business #306 -- Healthcare.gov. Yes. It's that bad.
0:00 / 66:18

Risky Business #305 -- Secure, anonymous IM not a pipe dream

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show, can you have your cake and eat it too? Is it possible to build a usable instant messenger platform that is secure and immune to traffic and metadata analysis?

We speak with international man of mystery The Grugq all about creating a platform that ticks these boxes. As it turns out, it can be done. So goodbye Yahoo, MSN, AOL and Skype... hello to something completely new!

This week's show is brought to you by Tenable Network Security! In this week's sponsor interview we chat with Jeffrey Man of Tenable about why using point to point encryption to dodge PCI scope is an awful idea.

Adam Boileau, as always, stops by to chat about the week's news. Show notes, including links to the week's news items, can be found here.

Risky Business #305 -- Secure, anonymous IM not a pipe dream
0:00 / 70:33

Risky Business #304 -- Tech heavyweights target NSA

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

In this week's show Adam Boileau and I take a look at the technology industry's latest response to the Snowden revelations. The pushback is definitely gaining momentum.

This week's show is brought to you by Tenable Network Security, big thanks to them. And this week's sponsor interview is with Tenable's very own Jack Daniel

We're chatting to him about the bad patches that have been dispatched from Redmond lately. It's been a long time since we've seen dud patches out of Microsoft, but lately, boy, there have been a few. Will you need to change your operating procedures over this? Stay tuned to find out.

Show notes

Google's Eric Schmidt calls NSA's spying 'outrageous' | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57610710-83/googles-eric-schmidt-calls-...

Microsoft may ramp up encryption of customer data post-Snowden - Applications - SC Magazine Australia - Secure Business Intelligence
http://www.scmagazine.com.au/News/363998,microsoft-may-ramp-up-encryptio...

HTTP/2 Supports only HTTPS URIs | Threatpost | The First Stop For Security News
http://threatpost.com/http2-chair-says-protocol-will-work-only-with-http...

NIST Reviews Crypto Standards Development | Threatpost | The First Stop For Security News
http://threatpost.com/nist-initiates-review-of-its-crypto-standards-deve...

Google: We're bombarded by gov't requests on user data | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57612322-83/google-were-bombarded-by-go...

Microsoft, Facebook unite for Internet Bug Bounty program | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57611325-83/microsoft-facebook-unite-fo...

Microsoft Changes Bug Bounty Program to Include Incident Responders, Forensics Specialists | Threatpost | The First Stop For Security News
http://threatpost.com/microsoft-changes-bug-bounty-program-to-include-in...

In Lavabit Appeal, U.S. Doubles Down on Access to Web Crypto Keys | Threat Level | Wired.com
http://www.wired.com/threatlevel/2013/11/lavabit-doj/

NSA workers reportedly shared their passwords with Snowden | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57611528-83/nsa-workers-reportedly-shar...

White House reportedly considers civilian NSA chief | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57611652-83/white-house-reportedly-cons...

British Spies Hacked Telecom Network by Feeding Engineers Fake LinkedIn Pages | Threat Level | Wired.com
http://www.wired.com/threatlevel/2013/11/british-spies-hacked-telecom/

Power Plants and Other Vital Systems Are Totally Exposed on the Internet | Threat Level | Wired.com
http://www.wired.com/threatlevel/2013/11/internet-exposed/

iOS, Samsung apps popped at Pwn2Own - Applications - SC Magazine Australia - Secure Business Intelligence
http://www.scmagazine.com.au/News/364113,ios-samsung-apps-popped-at-pwn2...

MacRumors Forums Hacked, Passwords Stolen | Threatpost | The First Stop For Security News
http://threatpost.com/macrumors-forums-hacker-says-passwords-wont-be-lea...

Vice.com hacked by Syrian Electronic Army - Applications - SC Magazine Australia - Secure Business Intelligence
http://www.scmagazine.com.au/News/364015,vicecom-hacked-by-syrian-electr...

millions stolen in Bitcoin heist | Threatpost | The First Stop For Security News
http://threatpost.com/attackers-lift-1-2m-from-bitcoin-wallet-service/10...

Bitcoin Selfish Miners | Threatpost | The First Stop For Security News
http://threatpost.com/selfish-miners-could-exploit-p2p-nature-of-bitcoin...

Pen test firms Securus Global, Hacklabs to merge - Applications - SC Magazine Australia - Secure Business Intelligence
http://www.scmagazine.com.au/News/363334,pen-test-firms-securus-global-h...

Microsoft Warns Customers Away From RC4, SHA-1 | Threatpost | The First Stop For Security News
http://threatpost.com/microsoft-warns-customers-away-from-sha-1-and-rc4/...

New zero-day bug targets IE users in drive-by attack | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57611691-83/new-zero-day-bug-targets-ie...

November 2013 Adobe Flash, ColdFusion security patches | Threatpost | The First Stop For Security News
http://threatpost.com/adobe-patches-flash-coldfusion-flaws-unrelated-to-...

New security holes found in D-Link router | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57611824-83/new-security-holes-found-in...

OpenSSH Fixes Memory Corruption Bug With Update | Threatpost | The First Stop For Security News
http://threatpost.com/openssh-fixes-memory-corruption-bug-with-update/10...

Windows XP End of Life a Security Milestone | Threatpost | The First Stop For Security News
http://threatpost.com/microsoft-xp-end-of-life-an-important-security-mil...

Super Micro IPMI zero-day vulnerabilities disclosed | Threatpost | The First Stop For Security News
http://threatpost.com/seven-ipmi-firmware-zero-days-disclosed/102848

Cisco Fixes Blank Admin Password Flaw in TelePresence Product | Threatpost | The First Stop For Security News
http://threatpost.com/cisco-fixes-blank-admin-password-flaw-in-teleprese...

ANZ Falcon 24 7 Credit Card Security - YouTube
http://www.youtube.com/watch?v=0dYhc4ciqEo

PILOTS - Artist - triple j Unearthed - free music | new Australian music | independent music
http://www.triplejunearthed.com/PILOTS

,

Yes, you are really back. That is the attitude we all want to have right there. - James Cullem

Risky Business #304 -- Tech heavyweights target NSA
0:00 / 47:06

Risky Business #303 -- The one with John McAfee

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

In this week's show we chat to McAfee antivirus founder John McAfee about his D-Central project and touch on the events of the last 12 months.

Is he funny "ha ha" or funny "look out"? Have a listen, judge for yourself.

This week's show is brought to you by Context Information Security, and we've got a great sponsor chat with Context's Alex Chapman this week about an evaluation they did on mobile platforms and MDM solutions for the Communications-Electronics Security Group, the part of GCHQ that handles the defensive side of things. Does Android suck as badly as everyone thinks it does? Is Good for Enterprise... umm... good for the enterprise?

Adam Boileau, as always, stops in for the week's news headlines. Show notes, including links to the items discussed, can be found here.

Risky Business #303 -- The one with John McAfee
0:00 / 69:42