T1SP: Episode 23

T1SP: Episode 23



[ Subscribe to the Podcast: iTunes | Android | RSS ]

News


* [ ] Juniper backdoor; could have been found with diff; signs point to NSA
* [ ] RCE on FireEye appliances
* [ ] Hyatt got hacked; malware on POS
* [ ] 45K drones registered with FAA within 2 days
* [ ] Industry moving towards password-free logins; still single factor, now the factor is your device; although access to device could require factors
* [ ] Microsoft will now tell you if your account has been targeted by government authorities
* [ ] Tor announced it’s doing a bug bounty, looks like it’ll be internal
* [ ] Steam had a DoS that revealed 34K user details
* [ ] Linode has been suffering a massive DDoS on its datacenters, DNS infrastructure
* [ ] Spy files found in North Korea’s Operating System


Ideas, updates, and discussion


* [ ] 3 things you should do every January
* [ ] Web Scanner Series: Burp vs. Netsparker
* [ ] When you’re interviewing, make sure you make it clear that you’re the asset too, not just them
* [ ] Failing at the basics in intelligence and infosec
* [ ] Why Trump is Winning
* [ ] Sensitive data sent in URL over HTTPS
* [ ] Difference between correlation and causation
* [ ] Paul Graham’s REFRAGMENTATION post
* [ ] The relationship between Relaxation, Fun, and Performance
* [ ] Michael Coates makes the argument that false negatives are way better than false positives because false positives create unnecessary work for his team
* [ ] Brainstorm questions, not solutions


Tools and projects


* [ ] BLUTO
* [ ] Serpico
* [ ] Firmware Extraction from Craig Smith
* [ ] Vulnerability Database Resources
* [ ] IoT Attack Surfaces Project
* [ ] RobotsDisallowed Project
* [ ] Nowhere.net (CyberPunk)
* [ ] EyeWitness
* [ ] REST Security Cheat Sheet
* [ ] Censys.io
* [ ] GithubDorks
* [ ] InstaRecon (DNS lookups, whois, shodan, google dorks, etc)
* [ ] twfactorauth.org


Announcements


* [ ] Speaking at OWASP Cali end of January
* [ ] Currently working on an ICS / SCADA primer


Miscellaneous


* [ ] Need to check out the Benedict Evans blog
* [ ] Serial Podcast / Making a Murderer on Netflix
* [ ] If you know any Army veterans who are getting out and want to get into InfoSec, let me know
* [ ] Twitter account: CISSP Googling
* [ ] Sam Altman (Startup Playbook)


[ Subscribe to the Podcast: iTunes | Android | RSS ]

Notes


* The intro track is from one of my favorite EDM artists: Zomby. The song is ‘Orion’, and it’s from the ‘With Love’ album. Highly recommended if you like chill EDM.

Become a Member: https://danielmiessler.com/upgrade

See omnystudio.com/listener for privacy information.

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(541)

Most Companies Aren't Anywhere Near Ready for AI

Most Companies Aren't Anywhere Near Ready for AI

Most Companies Aren't Anywhere Near Ready for AI. It's not that companies aren't using AI—it's that they can't.Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privac...

3 Touko 5min

We're All Building a Single Digital Assistant

We're All Building a Single Digital Assistant

There's tons of confusion about what we're all building towards with Personal AI. Are we building Agents? AI Harnesses? To what end? In this video I lay why I think we're all heading towards a single ...

15 Huhti 32min

Why AI  Will Replace Knowledge Workers

Why AI Will Replace Knowledge Workers

A longer form discussion on exactly how and why AI will replace knowledge workers.Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

21 Maalis 1h 16min

Why I Believe in SOTA Models Over Custom Ones

Why I Believe in SOTA Models Over Custom Ones

I think the future is cheaper and Open Source SOTA models combined with context, not custom, narrow models.Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy in...

11 Maalis 1min

AI Quality Inversion

AI Quality Inversion

A troubling thought about what we will think about high-quality content in the future. Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

6 Maalis 1min

The Great Transition

The Great Transition

There are a bunch of different transitions happening right now—all at the same time, all (I think) heading in the same direction. Here is a long-form exploration of the various pieces.Become a Member:...

28 Helmi 1h 24min

Starting 2026

Starting 2026

A welcome back and early entry into 2026. Sponsored by: Knocknoc!Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

30 Tammi 25min

Judge AI based on Output, Not Mechanism

Judge AI based on Output, Not Mechanism

How we can use an output-based system to judge whether or not different kinds of technology achieve understanding or intelligence. Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com...

22 Marras 20256min