Podcasts

News, analysis and commentary

Risky Business #255 -- IE 0days are news? WINNING

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

This week's show is a shorter one than usual -- we've just got the news segment with Adam and a sponsor interview.

This week's show is sponsored by our benevolent overlords at Adobe! Big thanks to them. And we've got a fascinating chat in this week's show with Adobe's Steve Gotwalls about auto updaters.

How have they been architected? What do the update mechanisms look like? Are the update packages served via https or http? Can you cache them at your border? Should enterprise networks swallow updates without doing independent QA?

This is a surprisingly interesting topic, when we think about how much patch management has changed over the years.

Show notes

Microsoft Will Patch IE Zero-Day on Friday; Fixit Available as Stopgap | threatpost
http://threatpost.com/en_us/blogs/microsoft-will-patch-ie-zero-day-frida...

Sophos antivirus detects own update as false positive malware | ZDNet
http://www.zdnet.com/sophos-antivirus-detects-own-update-as-false-positi...

Feds Charge Activist with 13 Felonies for Rogue Downloading of Academic Articles | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/09/aaron-swartz-felony/

Virgin Mobile Shrugs as Coder Warns Accounts Are Easily Hijacked | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/09/virgin-mobile/

Sprint says Virgin Mobile users are safe from account hijacks - Computerworld
http://www.computerworld.com/s/article/9231470/Sprint_says_Virgin_Mobile...

Coders Behind the Flame Malware Left Incriminating Clues on Control Servers | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/09/flame-coders-left-fingerprints/

Grum Botnet Attempts Another Comeback, Fails Again | threatpost
http://threatpost.com/en_us/blogs/grum-botnet-attempts-another-comeback-...

iPhone 4S, Samsung Galaxy S3 hacked in contest | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57516966-83/iphone-4s-samsung-galaxy-s3...

iOS 6 allows tweets, Facebook posts from locked device | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57517364-83/ios-6-allows-tweets-faceboo...

Apple provides 197 security reasons to upgrade to iOS 6 | ZDNet
http://www.zdnet.com/apple-provides-197-security-reasons-to-upgrade-to-i...

Flaw in Oracle Logon Protocol Leads to Easy Password Cracking | threatpost
http://threatpost.com/en_us/blogs/flaw-oracle-logon-protocol-leads-easy-...

Chat app used by activists has security flaws, say critics | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57513530-83/chat-app-used-by-activists-...

Researchers poke holes through Fortinet, SonicWall UTMs - Applications - SC Magazine Australia - Secure Business Intelligence
http://www.scmagazine.com.au/News/316308,researchers-poke-holes-through-...

Anonymous' Barrett Brown Raided by FBI During Online Chat | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/09/barret-brown-raid/

Executive order drafted following failed Cybersecurity Act - SC Magazine
http://www.scmagazine.com/executive-order-drafted-following-failed-cyber...

Researcher Charlie Miller Joins Twitter Security Team | threatpost
http://threatpost.com/en_us/blogs/researcher-charlie-miller-joins-twitte...

Calendar config triggers Canberra security scare - Risk - SC Magazine Australia - Secure Business Intelligence
http://www.scmagazine.com.au/News/316099,calendar-config-triggers-canber...

Bromium secures computers by holding apps in isolation | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57515558-83/bromium-secures-computers-b...

Bromium ships vSentry micro-hypervisor for foolproof Windows 7 security | ZDNet
http://www.zdnet.com/bromium-ships-vsentry-micro-hypervisor-for-foolproo...

Romanian carders plead guilty to Subway hack - Hackers - SC Magazine Australia - Secure Business Intelligence
http://www.scmagazine.com.au/News/316131,romanian-carders-plead-guilty-t...

Home
http://www.saskwatch.com.au/Saskwatch/Home.html

Breakpoint 2012 Security Conference
http://www.ruxconbreakpoint.com/

,

They are pretty geeky with that one. They are really good at computers and that is good. - Kris Krohn

Risky Business #255 -- IE 0days are news? WINNING
0:00 / 44:28

Risky Business #254 -- Does your pentester team know what it's doing?

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

This week's feature interview is with Wayne Ronaldson. Wayne's a security consultant with a company here called CQR, but he's cobbled together a fascinating little side project called Exploitable Labs.

In essence, Exploitable Labs is an online capture the flag environment. Participants connect to it, then go about finding various types of vulnerabilities -- in Web applications, servers and network devices. At the end of the exercise, the system spits out a report that can tell the participant where they're hot and where they're not.

Wayne designed the service to be used by people who hire penetration testers -- it's not a certification like CREST, it's an evaluation. It's an interesting idea!

Adam Boileau, as always, joins the show for a chat about the news headlines.

Show notes

Pirate Bay Co-Founder Arrested at Airport on Hacking Charges | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/09/pirate-bay-airport-arrest/

Apple Device IDs Leaked by Anonymous Traced to App Developer Blue Toad | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/09/udid-leak-traced-to-blue-toad/

Sleuths Trace New Zero-Day Attacks to Hackers Who Hit Google | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/09/google-hacker-gang-returns/all/

Report: Half of Android devices have unpatched holes | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57512467-83/report-half-of-android-devi...

Microsoft finds malware hidden in new computers in China | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57512703-83/microsoft-finds-malware-hid...

Phony Al-Jazeera text messages sent by pro-Syrian gov't hackers | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57509104-83/phony-al-jazeera-text-messa...

Microsoft axes many of its Forefront enterprise security products | ZDNet
http://www.zdnet.com/microsoft-axes-many-of-its-forefront-enterprise-sec...

Careful Who You Friend: Taliban Posing as 'Attractive Women' Online | Danger Room | Wired.com
http://www.wired.com/dangerroom/2012/09/taliban-facebook/

Microsoft Carries out Nitol Botnet Takedown | threatpost
http://threatpost.com/en_us/blogs/microsoft-carries-out-nitol-botnet-tak...

Apple Fixes Huge Number of Flaws With iTunes 10.7 | threatpost
http://threatpost.com/en_us/blogs/apple-fixes-huge-number-flaws-itunes-1...

CRIME Attack Uses Compression Ratio of TLS Requests as Side Channel to Hijack Secure Sessions | threatpost
http://threatpost.com/en_us/blogs/crime-attack-uses-compression-ratio-tl...

Go Daddy CEO Denies Hackers Behind Major Outage | threatpost
http://threatpost.com/en_us/blogs/go-daddy-ceo-disputes-hack-behind-majo...

Etsy handcrafts rewards for security bug hunters | ZDNet
http://www.zdnet.com/au/etsy-handcrafts-rewards-for-security-bug-hunters...

Google Adds Online Malware Scanner VirusTotal To Security Lineup | threatpost
http://threatpost.com/en_us/blogs/google-adds-online-malware-scanner-vir...

Red Hat Security Advisory 2012-1259-01 \u2248 Packet Storm
http://packetstormsecurity.org/files/116469

No Right Turn: Hacking the Budget
http://norightturn.blogspot.co.nz/2012/09/hacking-budget.html

BitFloor breached, hacker makes off with $250,000 in BitCoins - TechSpot News
http://www.techspot.com/news/50043-bitfloor-breached-hacker-makes-off-wi...

ssl - CRIME - How to beat the BEAST successor? - IT Security
http://security.stackexchange.com/questions/19911/crime-how-to-beat-the-...

Exploitable Labs
http://exploitablelabs.com/

PentesterLab.com
https://pentesterlab.com/

My interview with Gotye:
http://media.risky.biz/fots.mp3

,

The hackers are having their way right now. I guess that is going to be pretty right? - Roger Stanton St. Mary's College

,

Now I am able to take the next phase in my profession and after working security for quite a few years, I would
love to improve up on my current knowledge and gain a few new ones.
Where's the best place to get started on I wonder?

Risky Business #254 -- Does your pentester team know what it's doing?
0:00 / 42:32

Risky Business #253 -- All your internal IP ranges R belong 2 Maltego

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show we're taking a look at the new release of the data mining and network footprinting tool Maltego. it's called Radium and the focus is very much on automation.

One click network footprinting for the win! Maltego creator Roelof Temmingh will be along in this week's feature interview to walk us through the new features. There's some interesting stuff in that interview about network information leaks. All your internal IP ranges R belong to Roelof!

This week's show is brought to you by HackLabs.

In this week's sponsor interview we chat with HackLabs head honcho Chris Gatford about the insider threat.

What can you do to minimise your chances of getting hosed by a disgruntled former staffer? That's an interesting segment that touches on account and access management, DLP and ghost account audits.

Speaking of sponsorship, we've got some sponsor vacancies opening up from next week and intro next year. So if you fancy sponsoring Risky Business, let me know.

Risky.Biz gets around 25,000 unique visitors a month from all over the globe, with around 16,000-20,000 episodes downloaded each month!

And you know what? It's a high quality audience. If you'd like to see some listener testimonials from enterprise security folks or talk about sponsorship, get in touch with me: patrick [at] risky.biz.

Risky Business #253 -- All your internal IP ranges R belong 2 Maltego
0:00 / 57:19

Risky Business #252 -- Attacks on Aramco likely state sponsored

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show we're talking to Rapid7's HD Moore about recent attacks against the Saudi Aramco oil company that saw 30,000 of 40,000 machines rendered inoperable for around 10 days.

It's the single most destructive attack I've ever heard of.

This week's show is brought to you by Insomnia Security. You might know this week's sponsor guest -- it's out news buddy Adam Boileau, aka Metlstorm.

Adam works for Insomnia! So it's the MOAR METL edition this week! He'll be along a bit later to talk about new trends in security assessments; new ways of doing things that can gauge how effective organisations are at detecting what he calls the "lateral movement" of attackers through networks. As you'd expect, it's very interesting stuff and it's coming up after this week's feature interview.

Show notes

Oracle reportedly knew of critical Java bugs under attack for 4 months | Ars Technica
http://arstechnica.com/security/2012/08/critical-java-bugs-reported-4-mo...

Second accused LulzSec hacker arrested in Sony breach | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57502233-83/second-accused-lulzsec-hack...

Researchers Hack Brainwaves to Reveal PINs, Other Personal Data | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/08/brainwave-hacking/

Researcher reports a CSRF vulnerability in Facebook's App Center, earns $5,000 | ZDNet
http://www.zdnet.com/researcher-reports-a-csrf-vulnerability-in-facebook...

Air Force Openly Seeking Cyber-Weapons | threatpost
http://threatpost.com/en_us/blogs/air-force-openly-seeking-cyber-weapons...

Hackers vow 'hellfire' in latest major data leak | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57501931-83/hackers-vow-hellfire-in-lat...

Looking to Bolster Security, Dropbox Adds Two-Factor Authentication | threatpost
http://threatpost.com/en_us/blogs/looking-bolster-security-dropbox-adds-...

Analysis Shows Traces of Wiper Malware, But No Links to Flame | threatpost
http://threatpost.com/en_us/blogs/analysis-shows-traces-wiper-malware-no...

New Gauss and Flame link was a mistake, researchers say | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57499508-83/new-gauss-and-flame-link-wa...

Citrix Systems \xbb Most Americans Confused By Cloud Computing According to National Survey
http://www.citrix.com/English/NE/news/news.asp?newsID=2328309

Gauss: Abnormal Distribution - Securelist
http://www.securelist.com/en/analysis/204792238/Gauss_Abnormal_Distribution

Virus Shuts RasGas Office Computers, LNG Output Unaffected - Bloomberg
http://www.bloomberg.com/news/2012-08-30/virus-shuts-rasgas-office-compu...

Gh0stRat paper:
http://download01.norman.no/documents/ThemanyfacesofGh0stRat.pdf

Insomnia Security, New Zealand
http://www.insomniasec.com/

,

The hackers surely know what they are doing. They did a good job in making a grand entrance. - Kris Krohn Strongbrook

Risky Business #252 -- Attacks on Aramco likely state sponsored
0:00 / 57:36

Risky Business #251 -- Thunderbolt strikes Mac EFI

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

In this week's feature interview we're getting an update on some research we looked at last year. Loukas of Assurance.com.au in Melbourne had been playing around with some "evil maid" EFI hacks on Macs, but he's done some more work on them and presented his findings at BlackHat in July.

He joins the show to discuss his latest EFI work. See this week's show notes for links to his slide deck and paper, as well as links to this week's news.

This week's show is brought to you by Adobe!

Adobe's head of product security Brad Arkin joins us to give us some development tips for smaller coding teams. He also discusses his involvement with the RSA conference -- he'll be helping to select some talks.

Risky Business #251 -- Thunderbolt strikes Mac EFI
0:00 / 61:49

Risky Business #250 -- Hack it like it's 1999

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show we chat with Recurity Labs' Felix "FX" Lindner and Greg Kopf in the feature segment.

These guys recently shredded some Huawei equipment. They owned it hard and turned it into a DEFCON talk [pdf]. They'll be along a bit later on to tell us why hacking away at Huawei kit made them feel nostalgic.

This week's show is brought to you by the fine folks at Australian pentesting firm HackLabs, so I hope you'll keep them in mind next time you're firing off those RFPs!

HackLabs founder and main man Chris Gatford joins us in this week's sponsor slot to discuss the extremely clever social engineering attack against accounts belonging to technology journalist Mat Honan. he got owned pretty hard. No clientsides, no exploits, no bruteforcing. Just a few phone calls.

Show notes

http://phenoelit.org/stuff/Huawei_DEFCON_XX.pdf

THIS WEEK'S NEWS ITEMS:

Stratfor emails reveal secret, widespread TrapWire surveillance system - RT
http://rt.com/usa/news/stratfor-trapwire-abraxas-wikileaks-313/

Is TrapWire surveillance really spying on Americans? - Technolog on NBCNews.com
http://www.technolog.msnbc.msn.com/technology/technolog/trapwire-surveil...

New Gauss Malware, Descended From Flame and Stuxnet, Found On Thousands of PCs in Middle East | threatpost
http://threatpost.com/en_us/blogs/new-gauss-malware-descended-flame-and-...

Amazon addresses security exploit after journalist hack | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57488759-83/amazon-addresses-security-e...

Apple responds to journalist's iCloud hack | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57487873-83/apple-responds-to-journalis...

One way to make passwords obsolete -- just keep typing | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57492355-83/one-way-to-make-passwords-o...

DOJ Won't Ask Supreme Court to Review Hacking Case | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/08/computer-fraud-supreme-court/

Goldman Sachs Programmer Back in Court on New Charges | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/08/sergey-aleynikov-new-charges/

FTC Dings Google $22.5M in Safari Cookie Flap | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/08/ftc-google-cookie/

Microsoft Releases Attack Surface Analyzer Tool | threatpost
http://threatpost.com/en_us/blogs/microsoft-releases-attack-surface-anal...

#684121 - libotr2: Buffer overflows in libotr - Debian Bug report logs
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=684121

Anonymous targets ASIO, government websites | ZDNet
http://www.zdnet.com/au/anonymous-targets-asio-government-websites-70000...

Oracle Warns Users About Privilege Escalation Bug in Database Server | threatpost
http://threatpost.com/en_us/blogs/oracle-warns-users-about-privilege-esc...

,

The secret is already out there. You don't need to become so sensitive about that one. - James Cullem

Risky Business #250 -- Hack it like it's 1999
0:00 / 57:34

Risky Business #249 -- Did the BlueHat prize experiment succeed?

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show we chat with Microsoft's Katie Moussouris about the company's BlueHat prize. How successful was the prize, and did it get Microsoft value for money in terms of quality entries?

Katie took some time out from her maternity leave to join the show.

This week's show is brought to you by Tenable Network Security.

In this week's sponsor interview with Tenable founder and CEO Ron Gula we get a bit philosophical. Has it become culturally acceptable in the business world to get owned?

If LinkedIn and Sony can have such a bad time, are major incidents therefore seen as routine?

Follow Patrick Gray on Twitter.

Show notes

Get the podcast here.

Expert: Huawei routers are riddled with vulnerabilities | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57482813-83/expert-huawei-routers-are-r...

Divide and Conquer: Cracking MS-CHAPv2 with a 100% success rate
https://www.cloudcracker.com/blog/2012/07/29/cracking-ms-chap-v2/

Full Disclosure: nvidia linux binary driver priv escalation exploit
http://seclists.org/fulldisclosure/2012/Aug/4

Firm Sees More DDoS Attacks Aimed at Telecom Systems | threatpost
http://threatpost.com/en_us/blogs/firm-sees-more-ddos-attacks-aimed-tele...

Republicans block vote on cybersecurity bill | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57485404-83/republicans-block-vote-on-c...

Vasillis Pappas Wins $200,000 Microsoft Blue Hat Prize | threatpost
http://threatpost.com/en_us/blogs/vasillis-pappas-wins-200000-microsoft-...

In First Black Hat Talk, Apple Reveals Little New About iOS Security | threatpost
http://threatpost.com/en_us/blogs/first-black-hat-talk-apple-reveals-lit...

Facebook aims 'bug bounty' at in-house network | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57480383-83/facebook-aims-bug-bounty-at...

More information on Security Advisory 2737111 - Security Research & Defense - Site Home - TechNet Blogs
http://blogs.technet.com/b/srd/archive/2012/07/24/more-information-on-se...

Anonymous in a tizzy over logo trademark | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57484468-83/anonymous-in-a-tizzy-over-l...

Does Cybercrime Really Cost $1 Trillion? | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/08/cybercrime-trillion/all/

Illinois Outlaws Employer Requests for Facebook Passwords | threatpost
http://threatpost.com/en_us/blogs/illinois-outlaws-employer-requests-fac...

Anonymous dumps hacked AAPT data - Hackers - SC Magazine Australia - Secure Business Intelligence
http://www.scmagazine.com.au/News/310159,anonymous-dumps-hacked-aapt-dat...

OAuth 2.0 and the Road to Hell \xab hueniverse
http://hueniverse.com/2012/07/oauth-2-0-and-the-road-to-hell/

FX's Huawei slides:
http://phenoelit.org/stuff/Huawei_DEFCON_XX.pdf

,

A VERY ENTERTAINING SITE!
vacation rental koh samui

,

They surely are riddled with uncertainties. It will become a little bit better if you ask me. - Reputation Advocate

Risky Business #249 -- Did the BlueHat prize experiment succeed?
0:00 / 54:47

Risky Business #248 -- Being Big Brother on a budget

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

I've been busy preparing my debate speech for tomorrow's Splendour in the Grass music festival, so this week's show is a shorter one than usual; there's no feature interview.

But we've got a fascinating sponsor interview with SensePost's Glenn Wilkinson coming up. He's a lead security analyst with SensePost in its London office. He and his colleague Daniel Cuthbert are doing a talk and tool release at 44con in September called Terrorism, Tracking, Privacy and Human Interactions.

They set about writing some really creepy Big Brother-style tools for doing massive surveillance by dropping a few wireless access points around London. And you know what? As it turns out it's really easy to be really creepy!

Show notes

Australia, Canada 'primary spy targets'
http://www.theage.com.au/opinion/political-news/australia-canada-primary...

Nearly 5 Million People Have Government Security Clearances | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/07/security-clearances-increasing/

AAPT hacked by Anonymous - Security - Technology - News - CRN Australia
http://www.crn.com.au/News/309915,aapt-hacked-by-anonymous.aspx

Anonymous hackers cripple Aussie government websites | Information, Gadgets, Mobile Phones News & Reviews | News.com.au
http://www.news.com.au/technology/anonymous-hackers-cripples-aussie-gove...

Par:AnoIA | Meanwhile in Australia
http://par-anoia.net/queensland/

Watching the crooks: Researcher monitors cyber-espionage ring | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57479682-83/watching-the-crooks-researc...

Microsoft implements BlueHat prize tech | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57479407-83/microsoft-implements-blueha...

Charlie Miller Takes on NFC, Charlie Miller Wins | threatpost
http://threatpost.com/en_us/blogs/charlie-miller-takes-nfc-charlie-mille...

Reverse-Engineered Irises Look So Real, They Fool Eye-Scanners | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/07/reverse-engineering-iris-scans/

Siemens Patches Stuxnet-Like SCADA Bugs | threatpost
http://threatpost.com/en_us/blogs/siemens-patches-stuxnet-scada-bugs-072...

Grum Botnet Briefly Revived, Now Dead Again | threatpost
http://threatpost.com/en_us/blogs/grum-botnet-briefly-revived-now-dead-a...

Black Hat: Phishing E-Mail Scare A False Alarm | threatpost
http://threatpost.com/en_us/blogs/black-hat-phishing-e-mail-scare-false-...

Termineter Security Framework for Smart Meters Released | threatpost
http://threatpost.com/en_us/blogs/termineter-security-framework-smart-me...

This Xbox HDMI cable has 'anti-virus protection' | ZDNet
http://www.zdnet.com/this-xbox-hdmi-cable-has-anti-virus-protection-7000...

Skype makes chats and user data more available to police - The Washington Post
http://www.washingtonpost.com/business/economy/skype-makes-chats-and-use...

McKinnon extradition decision date set for mid-October | ZDNet
http://www.zdnet.com/mckinnon-extradition-decision-date-set-for-mid-octo...

Power Pwn: This DARPA-funded power strip will hack your network | ZDNet
http://www.zdnet.com/power-pwn-this-darpa-funded-power-strip-will-hack-y...

Eight million passwords stolen from gaming site - Crypto - SC Magazine Australia - Secure Business Intelligence
http://www.scmagazine.com.au/News/309627,eight-million-passwords-stolen-...

,

And why is Canada a target of spies? I don't quite see what is with Canada that makes them so. - Feed the Children Reviews

,

Following on from the uses of smart-phone wifi detection comes the interesting idea from GM - identify pedestrians before you see them in low-visibility situations.

http://mobile.slashdot.org/story/12/07/29/1412252/gm-working-on-wi-fi-di...

Great show - high point of weeks technical listening

Risky Business #248 -- Being Big Brother on a budget
0:00 / 40:37

Risky Business #247 -- Could a quantum leap spell the end of crypto?

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show the NSA's former Technical Director of Information Assurance, Brian Snow, joins the program to warn us that recent advancements in quantum computing could invalidate all of our cryptographic systems within 15 years.

So we'd better get cracking on finding alternatives!

This week's show is brought to you by the security team at Adobe! Big thanks to them. And Adobe's head of security and privacy Brad Arkin will be along later in the show to discuss Adobe's planned deprecation of Flash on mobile devices. As of September 2013 the whole lot goes dark permanently, so how DO you manage that sort of support withdrawal?

That's this week's sponsor interview.

Show notes

Password Leaks Continue: Billabong, NVIDIA Accounts Compromised | threatpost
http://threatpost.com/en_us/blogs/password-leaks-continue-billabong-nvid...

Hacker Claims Compromise of IT Recruiter | threatpost
http://threatpost.com/en_us/blogs/hacker-claims-compromise-wall-street-i...

Yahoo gives all clear after hack attack | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57472023-83/yahoo-gives-all-clear-after...

Microsoft: Fake Skype For Android App Linked To SMS Scams | threatpost
http://threatpost.com/en_us/blogs/microsoft-fake-skype-android-app-linke...

Google Hardens Chrome To Block Malicious Extensions | threatpost
http://threatpost.com/en_us/blogs/google-hardens-chrome-block-malicious-...

Former Pentagon Analyst Warns China Has Back Doors To Global Telcos | threatpost
http://threatpost.com/en_us/blogs/former-pentagon-analyst-warns-china-ha...

FBI Investigating Major Chinese Firm for Selling Spy Gear to Iran | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/07/fbi-zte/

Senators introduce amended cybersecurity measure | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57476215-83/senators-introduce-amended-...

Skype squashes bug that sends messages to random contacts | ZDNet
http://www.zdnet.com/skype-squashes-bug-that-sends-messages-to-random-co...

Symantec antivirus software update crashes some PCs | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57472624-83/symantec-antivirus-software...

Oracle won't patch zero-day hole in Database | ZDNet
http://www.zdnet.com/oracle-wont-patch-zero-day-hole-in-database-7000001...

Nike hacker steals over $80,000 | ZDNet
http://www.zdnet.com/nike-hacker-steals-over-80000-7000001177/

Officials attack Grum: World's third largest botnet (18% of spam) | ZDNet
http://www.zdnet.com/officials-attack-grum-worlds-third-largest-botnet-1...

Security flaw found in Amazon's Kindle Touch | ZDNet
http://www.zdnet.com/security-flaw-found-in-amazons-kindle-touch-7000001...

Apple iOS in-app purchases hacked; everything is free (video) | ZDNet
http://www.zdnet.com/apple-ios-in-app-purchases-hacked-everything-is-fre...

Charlie Miller: 'Difficult to write exploits' for Android 4.1 | ZDNet
http://www.zdnet.com/charlie-miller-difficult-to-write-exploits-for-andr...

Assad's sexist email jokes leaked | Herald Sun
http://www.heraldsun.com.au/news/breaking-news/assads-sexist-email-jokes...

[Event] Information Security Awareness Tour 2012 - Registration Open and Call for Speakers/Sponsors | in2securITy
http://www.in2security.org.nz/?q=node/153

,

The recruiter is going to be hunted. He messed up with the wrong people. - Feed the Children Reviews

Risky Business #247 -- Could a quantum leap spell the end of crypto?
0:00 / 65:46

Risky Business #246 -- Here lies password authentication. RIP.

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's edition of the show we catch up with Mark Dowd of Azimuth security for a bit of a chat about Apple's upcoming iOS 6 operating system and its security features. We also wind up chatting about Apple's approach to OS security in general and the whole signed code appstore thing, it's fun stuff!

This week's show is brought to you by Tenable Network Security -- the most long term and loyal supporter of this podcast.

Tenable founder and CEO Ron Gula joins us later on in the show to chat about the media hype surrounding DNSChanger and Flame, as well as talking about some really, really rudimentary approaches to picking up stuff your AV may have missed. That's this week's sponsor interview.

In this week's news segment, Insomnia Security's Adam Boileau joins the program to discuss the following stories:

Govt defends need to snoop on online and phone records | Information, Gadgets, Mobile Phones News & Reviews | News.com.au
http://www.news.com.au/technology/govt-defends-need-to-keep-internet-dat...

1.3M Cellphone Snooping Requests Yearly? It's Time for Privacy and Transparency Laws | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/07/mobile-data-transparency/

AusCERT loses passwords to Govt service - Web/client - SC Magazine Australia - Secure Business Intelligence
http://www.scmagazine.com.au/News/307954,auscert-loses-passwords-to-govt...

Gone in 3 Minutes: Keyless BMWs a Boon to Hacker Thieves | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/07/keyless-bmw-gone/

Android forum site hacked; data swiped on 1 million users | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57471297-83/android-forum-site-hacked-d...

Top domains and passwords compromised by Yahoo breach | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57471299-83/top-domains-and-passwords-c...

Formspring disables user passwords in security breach | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57469944-83/formspring-disables-user-pa...

Apple Receives NFC Patent, But Takes It Slow with Mobile Payments | threatpost
http://threatpost.com/en_us/blogs/apple-receives-nfc-patent-taking-it-sl...

Anonymous Group Says It Gave Syrian E-mails to WikiLeaks | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/07/anonymous-syrian-emails/

WikiLeaks Wins Icelandic Court Battle Against Visa for Blocking Donations | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/07/wikileaks-visa-blockade/

Instagram Patches "Friendship Vulnerability" Privacy Hole | threatpost
http://threatpost.com/en_us/blogs/instagram-patches-friendship-vulnerabi...

Google Adds Full Flash Sandbox to Chrome 21 | threatpost
http://threatpost.com/en_us/blogs/google-adds-full-flash-sandbox-chrome-...

Google Patches Three High-Priority Flaws in Chrome 20 | threatpost
http://threatpost.com/en_us/blogs/google-patches-three-high-priority-fla...

Microsoft Revokes Trust in 28 of Its Own Certificates | threatpost
http://threatpost.com/en_us/blogs/microsoft-revokes-trust-28-its-own-cer...

NSA Chief Says Today's Cyber Attacks Amount to 'Greatest Transfer of Wealth in History' | threatpost
http://threatpost.com/en_us/blogs/nsa-chief-says-todays-cyber-attacks-am...

Deep Packet Inspection Firm Cyberoam Issues Fix Following Private Key Leak | threatpost
http://threatpost.com/en_us/blogs/deep-packet-inspection-firm-cyberoam-i...

Hackers can break into your Cisco TelePresence sessions | ZDNet
http://www.zdnet.com/hackers-can-break-into-your-cisco-telepresence-sess...

Data-breach laws are coming: OAIC assistant | ZDNet
http://www.zdnet.com/data-breach-laws-are-coming-oaic-assistant-7000000761/

Stratfor Class Action Settlement Email
http://cryptome.org/2012/07/sterling-stratfor-email.htm

Risky Business #246 -- Here lies password authentication. RIP.
0:00 / 55:38